Anti-money laundering, or AML, refers to laws, controls and investigations designed to prevent criminals from disguising the proceeds of crime through the financial system. An effective programme is risk-based: it applies stronger scrutiny where products, customers, locations or transactions create higher risk rather than treating every customer identically.
This guide explains the core AML controls, how technology supports them and why compliance requires judgement, governance and proportionality.
What Is Anti-Money Laundering?
Money laundering commonly involves placing illicit funds into the financial system, obscuring their origin through transactions and integrating them into apparently legitimate activity. Real cases do not always follow three neat stages, and digital payments can compress them.
AML controls also interact with counter-terrorist financing and counter-proliferation financing. Terrorist financing can involve legitimately obtained funds, so a system focused only on criminal proceeds may miss relevant risk.
The FATF Recommendations provide the international standard that countries adapt into domestic law. The current framework emphasises identifying, assessing and understanding risk, then applying proportionate measures.
Core Anti-Money Laundering Controls
Enterprise risk assessment
A firm should assess exposure across customers, products, delivery channels, geographies and transaction types. The assessment must influence controls rather than exist only as a document.
Customer due diligence
Know Your Customer procedures identify and verify customers and, where relevant, beneficial owners. Firms also seek to understand the purpose and expected nature of a relationship.
Enhanced due diligence
Higher-risk situations can require additional information, senior approval, source-of-funds or source-of-wealth checks and closer monitoring. Enhanced review should be triggered by evidence and policy, not nationality or stereotypes alone.
Sanctions and watchlist screening
Names, entities, vessels and other identifiers may be screened against applicable lists. Similar names and incomplete data produce false positives, so investigators need matching rules and escalation procedures.
Transaction monitoring
Rules and models identify unusual patterns for review. An alert is not proof of crime. Analysts compare activity with customer context, investigate explanations and document whether escalation is warranted.
Suspicious-activity reporting
Where law and thresholds require it, firms report suspicious activity to the appropriate authority without tipping off the subject. Filing rules, confidentiality and deadlines differ by jurisdiction.
Records, training and independent testing
Organisations retain evidence, train relevant staff and test whether controls operate as designed. Findings should lead to tracked remediation and accountable ownership.
The Risk-Based Anti-Money Laundering Approach
The FATF says the risk-based approach is the cornerstone of its standards. Firms should devote more resources to higher risks while allowing simplified measures where law permits and risk is demonstrably lower.
Risk-based does not mean risk-free. It requires documented reasoning, reliable data and ongoing review. FATF also warns against wholesale de-risking: terminating entire categories of customers can push activity into less transparent channels and undermine financial inclusion.
Anti-Money Laundering Technology and RegTech
Technology can screen large datasets, connect entities, score transactions and prioritise alerts. Machine learning may detect patterns that fixed rules miss, while graph analytics can expose networks and circular flows.
Models can also discriminate, drift or create opaque decisions. Firms need validation, explainability, data-quality controls and human challenge. A vendor score does not replace the institution’s legal responsibility.
For specialised tools, see our guides to Chainalysis and CipherTrace.
Anti-Money Laundering Risks in Digital Assets
Virtual-asset service providers may need customer identification, monitoring, reporting and payment-transparency controls under applicable law. Public blockchains can provide transaction history, but wallet ownership and off-chain activity require additional evidence.
Mixers, bridges, privacy features and cross-chain transfers can complicate tracing. Analytics results should distinguish direct exposure from remote connections and be corroborated before material action.
Common Anti-Money Laundering Red Flags
- activity inconsistent with the customer’s known purpose or profile;
- rapid movement through several accounts or jurisdictions without an economic reason;
- structuring transactions below reporting or review thresholds;
- use of shell entities with unclear beneficial ownership;
- unexplained third-party payments;
- transactions involving high-risk services or sanctioned parties;
- repeated information changes or forged documents;
- unusual cash, trade or crypto flows lacking a credible explanation.
A red flag triggers inquiry; it does not prove laundering. Context, corroboration and consistent investigative standards matter.
Anti-Money Laundering Programme Governance
Senior management should approve risk appetite, provide resources and receive meaningful metrics. Useful measures include alert quality, investigation time, overdue reviews, data failures, reporting timeliness and remediation status—not simply the number of alerts closed.
Independent testing should assess design and operating effectiveness. Compliance, operations, technology, audit and business teams need clear responsibilities and escalation channels.
Anti-Money Laundering Checklist
- Maintain a current enterprise risk assessment.
- Verify customers and beneficial owners proportionately.
- Understand expected activity and update profiles.
- Screen under applicable sanctions requirements.
- Monitor transactions using tested rules and models.
- Investigate alerts consistently and retain evidence.
- File required reports securely and on time.
- Train staff and protect whistleblowing channels.
- Test controls independently and fix deficiencies.
- Review vendors, data and models continuously.
The Future of Anti-Money Laundering
Better data sharing, privacy-enhancing technology and analytics may improve detection while reducing unnecessary friction. Criminal methods will also adapt, so static rules cannot be the entire programme.
Effective AML balances financial integrity, privacy and inclusion. Technology helps most when it supports a clear risk assessment and accountable human decisions rather than maximising alerts.
This article is educational and does not constitute legal or compliance advice. AML obligations vary by jurisdiction, institution and activity.

