Anti-Money Laundering (AML) Regulators by Country
There is no global anti-money laundering regulator. AML obligations are created and enforced country by country, by national regulators, financial intelligence units and sector supervisors. International bodies set standards and assess how well countries implement them, but no international body supervises a bank.
This matters operationally. A firm active in five markets answers to five supervisors whose rules agree on principle and differ on detail — and the detail is what an onboarding flow has to encode.
| Standard setter | Financial Action Task Force (FATF) — assesses countries, not firms |
| Enforcer | National regulators and sector supervisors |
| Intelligence recipient | The national financial intelligence unit (FIU) |
| FIU cooperation | Egmont Group, for cross-border information exchange |
| What varies most | Acceptable ID documents, verification thresholds, review cycles, reporting triggers |
| What rarely varies | The obligation to identify the customer before providing the service |
Who supervises AML in the major markets
| Jurisdiction | Principal supervisor(s) | Financial intelligence unit | Core legislation |
|---|---|---|---|
| United States | FinCEN, with the federal banking agencies, SEC and CFTC | FinCEN | Bank Secrecy Act; USA PATRIOT Act; AML Act of 2020 |
| United Kingdom | FCA, HMRC and the professional body supervisors under OPBAS | UKFIU, within the National Crime Agency | Money Laundering Regulations 2017; POCA 2002 |
| European Union | National supervisors, with AMLA assuming direct supervision of selected groups from 2028 | National FIUs | AMLR and AMLD6; Regulation (EU) 2024/1620 |
| Canada | FINTRAC | FINTRAC | PCMLTFA |
| Australia | AUSTRAC | AUSTRAC | AML/CTF Act 2006, as amended |
| Singapore | Monetary Authority of Singapore | Suspicious Transaction Reporting Office | CDSA; MAS Notices |
| Hong Kong | HKMA and the SFC | Joint Financial Intelligence Unit | AMLO |
| Switzerland | FINMA and the self-regulatory organizations | MROS | AMLA (GwG) |
| Germany | BaFin | FIU, within the customs administration | Geldwäschegesetz |
| France | ACPR and the AMF | TRACFIN | Monetary and Financial Code |
| India | Reserve Bank of India and sector regulators | FIU-IND | Prevention of Money Laundering Act 2002 |
| Japan | Financial Services Agency | JAFIC, within the National Police Agency | Act on Prevention of Transfer of Criminal Proceeds |
| UAE | Central Bank of the UAE and the free zone regulators | UAE FIU | Federal Decree-Law No. 20 of 2018 |
| South Africa | Financial Intelligence Centre and the Prudential Authority | Financial Intelligence Centre | FIC Act |
| Brazil | Banco Central do Brasil and CVM | COAF | Law 9.613/1998 |
Two structures recur. In some countries the supervisor and the FIU are the same body — FINTRAC and AUSTRAC each do both. In others they are separate, so a firm reports suspicious activity to one organization and is examined by another. Knowing which model applies determines who a firm actually talks to.
Two changes worth tracking
The EU is centralizing. The Anti-Money Laundering Authority, headquartered in Frankfurt, took over the European Banking Authority’s AML mandate at the start of 2026. The AML Regulation it enforces applies from July 2027, and from 2028 AMLA directly supervises up to 40 selected cross-border groups, with that selection confirmed during 2027. For everyone else, national supervisors remain the point of contact — but against rules that are becoming a regulation rather than a directive, which removes much of the national variation firms have been managing.
Australia has extended scope. The Tranche 2 reforms brought lawyers, conveyancers, accountants, real estate agents, dealers in precious metals and stones, and trust and company service providers into the AML/CTF regime from 1 July 2026. Roughly 80,000 businesses acquired customer due diligence, screening, reporting and record-keeping obligations. Crucially, the obligations attach to designated services rather than to professions: a firm is in scope for the matters that fall within a designated service, not across its entire practice.
Why identity requirements differ across regulators
Every regime requires a firm to identify its customer. What they do not share is what counts as having done so.
- Acceptable documents vary. Some markets accept a national ID card that does not exist in others. Some require a document establishing address as well as identity; others treat a single strong document as sufficient.
- Thresholds vary. The transaction value or relationship type that triggers full customer due diligence is set nationally, so the same customer crosses the line in one market and not another.
- Review cycles vary. How often identity information must be refreshed, and what prompts a refresh, is a supervisory expectation rather than a universal rule.
- Screening expectations vary. Which sanctions and politically exposed person lists must be checked, and how often, is set by each regime rather than shared.
- Remote verification acceptance varies. Whether a fully digital process satisfies the requirement — and what evidence it must produce — remains one of the widest differences between markets.
For a firm operating internationally, the practical consequence is that document coverage is a compliance property, not a product feature. A verification capability that reads the documents of one region forces manual handling everywhere else, and manual handling is where both cost and inconsistency accumulate.
What this list does not tell you
FATF is not a regulator. It issues the Recommendations that national regimes are built from and evaluates countries against them, including through its increased-monitoring and high-risk lists. It has no authority over an individual firm, and being FATF-aligned is not a compliance status a business can hold.
Supervisors change and lists move. Mandates are reassigned, new authorities are created, and country risk designations are revised at each FATF plenary. This page is a map of who supervises what, not a substitute for checking the current position in each market a firm operates in.
Sector supervision is not shown in full. Most jurisdictions assign different supervisors to banks, securities firms, insurers, casinos, crypto asset businesses and designated professions. The table names the principal financial supervisor, which is often not the one a given firm answers to.
Frequently asked questions
Is there a global AML regulator?
No. FATF sets international standards and evaluates how countries implement them, and the Egmont Group enables FIUs to exchange information, but neither supervises or penalizes an individual institution. Enforcement is always national.
What is the difference between an AML supervisor and a financial intelligence unit?
A supervisor examines firms and enforces the rules. An FIU receives suspicious activity reports, analyzes them and disseminates intelligence to law enforcement. Some countries combine the roles in one body, such as FINTRAC in Canada and AUSTRAC in Australia; many keep them separate.
Which regulator applies to a business operating in several countries?
All of them, for the customers and activity in each market. Group-level policies commonly set a single internal standard at or above the strictest applicable requirement, but that does not remove the obligation to satisfy each national regime on its own terms.
What changes when AMLA begins direct supervision?
For up to 40 selected cross-border groups, the supervisory relationship moves to AMLA from 2028. For everyone else, national supervisors remain the contact point — but the underlying rules become an EU regulation applying from July 2027, which reduces the divergence between member states that firms currently manage.
Related reading
- Anti-money laundering — what the obligations these regulators enforce actually require
- Financial Conduct Authority — the UK supervisor in detail
- IMF Financial Integrity Group — how countries are assessed on effectiveness
- World Bank Financial Market Integrity Unit — how supervisory capability gets built