An AML policy is a written document that sets out how a firm prevents, detects, and reports money laundering. It records the firm’s rules for customer checks, monitoring, reporting, and record-keeping, turning anti-money laundering law into instructions staff can follow.
Key takeaways
- An AML policy is the written rulebook a firm uses to meet its anti-money laundering duties.
- It sits inside the wider AML compliance program and is not the same thing.
- A sound policy covers risk assessment, customer due diligence, monitoring, reporting, and training.
- Every regulated firm needs one, scaled to its size and risk.
- Regulators expect the policy to be followed in practice, not just filed away.
- A stale policy is a common finding, so it should be reviewed regularly and when risk changes.
On this page
What it isPolicy vs programWhat to includeWho needs oneHow to write oneKeeping it currentCommon mistakesFAQsRead more
1989
Year the FATF set the standard AML policies follow
Source: FATF
$3B
Paid by TD Bank in 2024 after AML failures
Source: US Department of Justice
$800B to $2T
Laundered worldwide each year policies aim to stop
Source: UNODC
What is an AML policy?
An AML policy is the document that tells a firm’s people how to fight money laundering. It sets the rules for onboarding customers, watching transactions, reporting suspicion, and keeping records.
The policy translates law into practice. A rule such as verifying a customer’s identity becomes a specific instruction: what to collect, how to check it, and what to do when something does not add up.
A good policy is written for the people who use it, not just for the regulator who inspects it. Read more: the policy is one piece of a larger AML compliance program.
AML policy vs AML compliance program
An AML policy and an AML program are often confused, but they are different. The policy is the written rulebook. The program is the whole system that puts those rules into action.
Think of it this way. The policy says what should happen. The program is the people, tools, monitoring, and testing that make it happen and prove it happened.
| AML policy | AML program | |
|---|---|---|
| What it is | A written document of rules | The full operating system |
| Answers | What should happen | How it happens and is proven |
| Includes | Procedures, roles, thresholds | The policy plus people, tools, monitoring, testing |
A firm can have a polished policy and still fail, if nobody follows it. That gap between the document and daily practice is what examiners probe first.
What an AML policy must include
A complete AML policy covers the full life of a customer relationship. The exact wording varies, but the parts below are standard.
- Purpose and scope. Who the policy applies to and which laws it meets.
- Risk-based approach. How the firm rates risk and matches controls to it. See the risk-based approach.
- Customer due diligence. How the firm verifies identity and applies enhanced due diligence for higher risk.
- Transaction monitoring. How the firm watches activity and handles alerts.
- Sanctions and PEP screening. How names are checked against sanctions and PEP lists.
- Suspicious activity reporting. When and how the firm files a suspicious activity report.
- Record-keeping. What records are kept and for how long.
- Roles and responsibilities. Who owns the program, usually the MLRO or compliance officer.
- Training. How staff are trained and how often.
Start your AML policy in minutes
Answer a short set of questions and generate a tailored AML policy draft you can adapt and keep for your records.
Who needs an AML policy?
Every regulated firm needs an AML policy. That includes banks, payment firms, crypto businesses, and many professional services such as accountants, lawyers, and estate agents.
Size changes the length, not the need. A global bank may run hundreds of pages across many teams, while a small firm may need only a few well-written ones. What matters is that the policy fits the firm’s real risk.
A firm that operates in more than one country has to meet each local rulebook while keeping one coherent policy. Read more: our guide to AML regulations in the US sets out the detail.
Base your policy on real risk
Get an indicative read on where your money laundering risk is concentrated before you write the policy.
How to write an AML policy
Writing a policy follows a clear order. Each step builds on the one before.
- Start from a risk assessment. Base the policy on the risks the firm actually faces. Our AML risk assessment gives a starting point.
- Map the customer journey. Set rules for onboarding, ongoing monitoring, and exit.
- Write for the user. Use plain instructions a new joiner could follow.
- Set clear thresholds. Say when a check, an alert, or a report is triggered.
- Name the owners. Give each duty to a role, not a vague team.
- Get sign-off. Have senior management approve the policy and record it.
Use the tool: screen customers as part of onboarding with Combined AML Screening, which checks sanctions, PEP, and adverse media in one search.
How to keep your AML policy current
A policy is not a one-time task. It has to keep pace with the firm and the rules around it.
Review it on a set schedule, and again whenever something changes. Common triggers include a new product, a new market, a new customer type, a regulatory change, or a lesson from an incident.
- Scheduled review. Reassess the policy at least once a year for most firms.
- Trigger-based review. Update it when the business or the law shifts.
- Version control. Keep dated versions so you can show what applied and when.
- Board oversight. Have senior management re-approve material changes.
A living policy has one more benefit. When a regulator or a banking partner asks how the firm manages laundering risk, a current, well-kept policy is the fastest way to show a credible answer.
Common AML policy mistakes
Most weak policies fail in the same few ways. Avoiding them keeps the policy defensible.
- A copied template. A generic policy that does not match the firm’s risk is a finding waiting to happen.
- Written for the shelf. A document nobody reads is not a control.
- Vague escalation. If staff do not know who to tell, suspicion goes nowhere.
- Never updated. A policy that describes last year’s business drifts out of compliance.
Screen a name against global watchlists
Run one search across sanctions, PEP, and adverse media data to check a customer or counterparty before you deal with them.
Frequently asked questions
What is an AML policy?
An AML policy is a written document that sets out how a firm prevents, detects, and reports money laundering. It records the rules for customer checks, transaction monitoring, reporting, and record-keeping. The policy turns anti-money laundering law into clear instructions that staff can follow day to day.
What is the difference between an AML policy and an AML program?
An AML policy is the written rulebook. An AML program is the whole system that puts the rules into practice, including the people, tools, monitoring, training, and testing. The policy says what should happen, while the program is how it happens and how the firm proves it.
What should an AML policy include?
An AML policy should include its purpose and scope, the risk-based approach, customer due diligence, transaction monitoring, sanctions and PEP screening, suspicious activity reporting, record-keeping, roles and responsibilities, and staff training. Each part should reflect the firm’s real risk rather than generic wording copied from a template.
Who needs an AML policy?
Every regulated firm needs an AML policy, including banks, payment and crypto firms, and professional services such as accountants, lawyers, and estate agents. Size changes the length of the policy, not the need for one. A small firm may need only a few pages, while a large bank may run to hundreds.
How do you write an AML policy?
Start from a risk assessment, then map the customer journey from onboarding to exit. Write plain instructions a new joiner could follow, set clear thresholds for checks and reports, and assign each duty to a named role. Finally, have senior management approve the policy and keep a record of the approval.
How often should an AML policy be reviewed?
An AML policy should be reviewed on a set schedule, usually at least once a year for most firms, and again whenever something changes. Triggers include a new product, a new market, a new customer type, a regulatory change, or a lesson from an incident. Keeping dated versions helps show what applied and when.
Is an AML policy legally required?
In most countries, yes. Regulated firms are required to have written anti-money laundering procedures under laws such as the US Bank Secrecy Act and the UK Money Laundering Regulations. These rules follow the FATF standard, so a documented policy is a baseline expectation for firms in more than 200 jurisdictions.
What is the escalation path in an AML policy?
The escalation path is the part of the policy that says who a staff member tells when they see something suspicious, and how quickly. A clear path routes concerns to the MLRO or compliance officer for a decision. Vague escalation is a common weakness, because real suspicion can get stuck at the front line.
Can I use an AML policy template?
A template can be a starting point, but a policy copied without changes is a common finding. Regulators expect the policy to match the firm’s actual risks, products, and customers. Use a template to structure the document, then tailor every section to how the firm really works.
Who is responsible for the AML policy?
Senior management owns the AML policy and approves it, while the MLRO or compliance officer usually writes and maintains it. Front-line staff are responsible for following it. Assigning each duty to a named role, rather than a vague team, is what makes the policy work in practice.
What is the difference between an AML policy and procedures?
An AML policy sets the high-level rules and principles, while procedures give the step-by-step detail of how to carry them out. For example, a policy may require identity verification, and the procedure explains exactly which documents to collect and check. Both sit inside the wider AML program.
What happens if a firm has no AML policy?
A firm without a proper AML policy can face fines, license restrictions, and personal liability for its officers, because written procedures are a legal requirement for regulated firms. Beyond the penalty, the absence of a policy leaves staff without clear rules, which lets money laundering pass through the firm unchecked.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: an AML policy is the written rulebook inside a firm’s wider AML program, and regulators expect it to be followed, not just filed.