AML Policy
Pronunciation: A-M-L POL-ih-see
Definition
AML Policy is a compliance or privacy requirement that clearly states an organization's principles, responsibilities, and mandatory rules for managing money-laundering and terrorist-financing risks. An Anti-Money Laundering policy is a governance document explaining how an organization approaches financial-crime risk. It defines scope, objectives, risk appetite, roles, escalation expectations, prohibited relationships, oversight, and the authority supporting operational procedures and controls. The policy typically addresses customer due diligence, sanctions, monitoring, investigations, reporting, records, training, quality assurance, and independent testing at a high level.
Overview
An Anti-Money Laundering policy is a governance document explaining how an organization approaches financial-crime risk. It defines scope, objectives, risk appetite, roles, escalation expectations, prohibited relationships, oversight, and the authority supporting operational procedures and controls.
The policy typically addresses customer due diligence, sanctions, monitoring, investigations, reporting, records, training, quality assurance, and independent testing at a high level. Detailed workflows, thresholds, and system instructions usually belong in supporting standards and procedures.
A policy should reflect applicable law, actual products, customer types, jurisdictions, and delivery channels rather than copying generic language. Management approval, scheduled review, version control, staff communication, and evidence of implementation are necessary for the document to guide behavior.
AML Policy is a compliance or privacy requirement that clearly states an organization’s principles, responsibilities, and mandatory rules for managing money-laundering and terrorist-financing risks. An AML policy sets binding direction, while procedures and controls must translate that direction into consistent, testable daily practice.
Implementation of AML Policy should map a compliance or privacy requirement that clearly states an organization’s principles, responsibilities, and mandatory rules for managing money-laundering and terrorist-financing risks to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for compliance, and responsibilities should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the AML Policy context and compliance, and responsibilities should trigger reassessment instead of silent reuse of an outdated conclusion.
Assurance work for AML Policy should sample records involving compliance, and responsibilities, test whether stated procedures operated in practice, and keep corrective actions open until a qualified reviewer verifies closure.
Key Takeaway
An AML policy sets binding direction, while procedures and controls must translate that direction into consistent, testable daily practice.
Sources
- FATF Documentation: Virtual Assets — FATF (2026-07-30)
- FATF Documentation: Fatf Recommendations — FATF (2026-07-30)