Anti-Money Laundering (AML)

Anti-money laundering (AML) is the body of laws, regulations and internal controls requiring financial institutions and other regulated businesses to detect, deter and report attempts to disguise the origins of criminal proceeds. It obliges private firms to know who their customers are, monitor what they do, and tell the authorities when something looks wrong.

AML is not a law. It is a framework implemented separately in every country, which is why obligations differ by market while the underlying logic does not.

Purpose Detect and report the concealment of criminal proceeds
Who is obliged Banks, payment firms, crypto businesses, insurers, casinos, and designated professions
Core duties Customer identification, due diligence, ongoing monitoring, reporting, record-keeping
Foundational US law Bank Secrecy Act 1970; USA PATRIOT Act 2001; AML Act of 2020
International standard FATF Recommendations
Measured by Program quality and process, not laundering prevented

The three stages of money laundering

AML controls are positioned against a sequence that has been described the same way for decades.

Stage What happens Where controls bite
Placement Criminal proceeds enter the financial system Cash reporting thresholds, account opening, source of funds
Layering Transactions are multiplied to obscure the trail Transaction monitoring, correspondent banking checks
Integration Funds re-enter the economy as apparently legitimate wealth Due diligence on large transactions, asset and property checks

Placement is where controls are strongest and the funds are most exposed, which is why so much AML effort concentrates on the account-opening moment — and why money mules exist as a workaround for it.

What an AML program has to contain

US supervisors assess programs against a set of pillars that most regimes replicate in some form:

  • A designated compliance officer with the authority and resources to run the program.
  • Internal policies, procedures and controls that are written down, followed and proportionate to the risks the firm actually faces.
  • Ongoing training for staff whose roles touch the obligations.
  • Independent testing — audit that does not report to the function it examines.
  • Risk-based customer due diligence, including understanding the nature and purpose of the relationship and, for legal entity customers, identifying beneficial owners.

Underneath sits KYC: identifying the customer, verifying that identity against reliable evidence, screening against sanctions lists and politically exposed person data, and keeping the picture current.

Two US changes that took effect recently

The beneficial ownership picture in the United States has shifted substantially, and the two changes are frequently conflated.

Corporate Transparency Act reporting no longer applies to US companies. After suspending enforcement in March 2025, FinCEN issued a final rule in August 2026 that permanently removes domestic reporting companies from the beneficial ownership information reporting framework. Entities formed under US law have no BOI filing obligation. Foreign entities registered to do business in the US remain in scope for their foreign beneficial owners.

The CDD Rule obligation on banks still stands, in streamlined form. This is a separate requirement, and it is the one that affects onboarding. In February 2026 FinCEN granted exceptive relief removing the need to re-identify and re-verify beneficial owners at every new account opening for an existing legal entity customer. Institutions identify and verify beneficial owners when the customer first opens an account, when they learn something that calls the existing information into question, and as their risk-based ongoing due diligence procedures require.

The practical effect is narrower than the headlines suggest. A firm no longer collects the same information repeatedly from the same customer, but the duty to establish beneficial ownership is intact — and with the CTA registry no longer covering US entities, the institution’s own verification carries more of the weight, not less.

Why it matters for identity verification

Every AML control after onboarding is conditional on one thing the firm established at the start: that the customer is who the file says.

Transaction monitoring compares activity against an expected profile built from the customer’s stated identity, occupation and purpose. Sanctions screening matches a name and date of birth against lists. Suspicious activity reports name a subject. If the identity at the top of the record is fabricated, each of these functions continues to operate correctly against a fiction — monitoring the wrong profile accurately, screening a name that belongs to nobody, and filing a report about a person who does not exist.

That is why the identification step is not one control among several. It is the assumption the rest of the program rests on, and it is the reason a synthetic identity is an AML problem as much as a credit one: it defeats the whole stack at the point of entry, quietly, and leaves every downstream indicator green.

What AML cannot do

It is measured by process, not outcome. A firm is examined on whether it had an adequate program, applied it, and reported what it saw — not on how much laundering it prevented. This is defensible, since no institution can observe the counterfactual. It also means that rising report volumes are evidence of compliance activity, not of effectiveness.

It creates an incentive to exit rather than examine. Where monitoring a customer segment costs more than the relationship is worth, the rational response is to leave the segment. De-risking has withdrawn banking access from remittance corridors, charities and entire correspondent relationships. Activity pushed outside the regulated system does not stop; it stops being visible, which is the opposite of the objective.

Reporting is not investigating. A firm files a suspicious activity report; what follows is a matter for the financial intelligence unit and law enforcement. Filing does not mean anything happened, and the reporting institution usually never learns whether it did.

Identity verification does not detect laundering. It establishes who the customer is. A correctly identified real person can launder money, and frequently does — a mule account passes every identity check, correctly. Verification removes the fabricated-identity population; behavior is a separate problem requiring separate controls.

Frequently asked questions

What is the difference between AML and KYC?

KYC is a component of AML. AML is the whole framework — policies, controls, monitoring, reporting, training and audit. KYC is the part that establishes and maintains knowledge of who the customer is. Every AML program contains KYC; KYC alone is not an AML program.

Who has to comply with AML rules?

Banks and payment institutions everywhere, plus a widening set of other businesses: crypto asset firms, insurers, casinos, dealers in precious metals and stones, and in a growing number of jurisdictions lawyers, accountants, real estate agents and company service providers. Scope is set nationally and has been expanding.

Do US companies still have to report beneficial ownership?

Under the Corporate Transparency Act, no. FinCEN’s final rule of August 2026 permanently exempts domestic reporting companies; the obligation now falls on foreign entities registered in the US. This is separate from the CDD Rule requirement on financial institutions to identify the beneficial owners of legal entity customers, which remains in force.

What happens when a firm fails its AML obligations?

Civil penalties, which have reached billions of dollars for major institutions, plus remediation programs, independent monitors, restrictions on growth, and in serious cases criminal liability and personal action against compliance officers. Penalties usually follow program failures rather than a single missed transaction.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data