Licensing
Regime selection, the application file and what a regulator actually asks for.
OpenA framework that answers the only question that matters: can you show why this customer was accepted, and who decided?
An AML framework is judged on one question: when a supervisor picks a customer file at random and asks why that customer was accepted, can you show the decision, the evidence behind it and the person who made it? Everything below exists to make the answer yes.
Downloaded policies fail that test immediately, and they fail it in a specific way — they create obligations your team does not know it has. A policy that says transactions above a threshold are escalated within twenty-four hours is a commitment you will be measured against, whether or not anyone read it.
A complete framework is a hierarchy, not a document. At the top sits a risk assessment; beneath it a policy that responds to that assessment; beneath that the procedures staff actually follow; and running through all three, the records that prove it happened.
The foundation, and the part most often skipped. It identifies the risk your specific business runs across customer types, products and services, delivery channels, geographies and payment methods, and it explains the methodology used to score them. A supervisor comparing your policy to your risk assessment is checking whether the controls answer the risks you yourself identified.
The governing document: scope, roles, risk appetite, the customer acceptance standard, escalation, reporting, training and record keeping. It should be short enough that staff read it and specific enough that it could not belong to another firm.
The operational layer — onboarding, verification, screening, ongoing monitoring, alert handling, escalation and reporting — written as steps with owners and timescales rather than principles.
Who is accountable at board level, how the MLRO reports and to whom, how often the framework is reviewed, and what happens when a control fails. The management information a board receives is itself examined: a board that approves an AML framework and never sees an alert statistic is a finding waiting to happen.
The EU AML package replaces much of the current directive-based patchwork with a directly applicable regulation from July 2027, and establishes a European authority in Frankfurt that will supervise selected high-risk firms directly from 2028. Frameworks built now should anticipate a single rulebook and tighter, more harmonised expectations rather than the current national variation.
Triggered by higher-risk factors — a politically exposed person, a high-risk jurisdiction, unusual ownership, an unclear source of wealth. EDD means more evidence and senior approval, not simply a note on the file. Where it is triggered, the record must show what additional information was obtained and who approved the relationship.
Firms handling crypto-asset transfers carry travel rule obligations: originator and beneficiary information must accompany the transfer, and transfers involving self-hosted wallets require their own verification approach. The procedure has to state what happens when the required information is missing.
The Money Laundering Reporting Officer is a named individual with personal responsibility. In most regimes the appointment is notified to the regulator, and in several the role cannot be combined with operational management — the Curaçao regime, for example, requires the compliance officer and MLRO to be separate from the CEO and the operational director.
An MLRO who reports to the head of sales is not independent, and an MLRO covering five firms is not resourced. Both are visible from the outside, and both are common grounds for a supervisory finding or a refused application.
Training must be role-specific and recorded — a general annual session for all staff does not demonstrate that the onboarding team understands EDD triggers. Internal audit tests whether the framework operates as documented: sampling files, re-performing decisions and reporting to the board on what it found. For smaller firms this can be outsourced, but it cannot be omitted.
Rules, thresholds and scenarios that reflect your business rather than a vendor's defaults. Two things are examined: whether the rules address the risks in your own assessment, and whether you can explain why a threshold is set where it is. Keep the tuning log — a record of what was changed, when and why — because it is the only way to answer that question a year later.
Alerts require an owner, a service standard and an outcome recorded with reasons. A backlog is itself a finding, and a backlog discovered by a supervisor rather than disclosed by you is a worse one.
The internal route from staff member to MLRO must be simple and protected. Tipping-off prohibitions have to be understood by the people who deal with customers, not merely stated in a policy they have not read.
Retention periods generally outlast the customer relationship, and the obligation is to produce records on request — which means a defined location, a defined format and someone who knows where they are. Data protection obligations run alongside: retention for AML purposes is a lawful basis for holding data, not a licence to keep everything indefinitely.
Banks decline regulated digital businesses far more often than they decline anyone else, and the reason is usually procedural rather than substantive. A compliance officer has a list of questions that must be closed before an account can be opened. If your file does not close them, the file is refused — not the business.
Applying broadly is the most expensive mistake available. Each decline is recorded, and later applications ask whether you have been refused before. Matching your profile to institutions that actually serve it, and applying with a complete file, is slower to start and far faster to finish.
Longer treatment: why banks say no to regulated digital businesses.
If you have all fourteen of these, in a form someone outside your company could read, you are ready for most conversations with a regulator or a bank. If you do not, this is the build order.
A framework is only worth what it can evidence. Before a supervisory visit we run the same exercise an examiner would: pick five customer files at random and reconstruct every decision from the record alone. What that exercise finds is usually more useful than any gap analysis.
Usually, and it is often cheaper than starting again. The work is in the risk assessment underneath it — if that does not exist, the policy has nothing to respond to and a supervisor will say so. We review what you have, identify what is generic and rebuild the parts that need to be specific to you.
It depends on size, risk and regime. What is not negotiable is that the person is genuinely available, genuinely independent of commercial pressure, and able to evidence their decisions. An outsourced or part-time MLRO can satisfy that; an MLRO in name only cannot, and it is visible from outside.
Annually as a minimum, and on any material change — a new product, a new market, a new payment channel, a new regulatory obligation. The review itself has to be documented; a framework that has not visibly been reviewed reads as one nobody is responsible for.
Yes, and it is time-critical work. A remediation plan is judged on whether it is realistic and whether the milestones are met, so the plan should promise less and deliver on schedule rather than the reverse. We draft it, sequence it and support the reporting back to the supervisor.
Yes — write to us and we will send the minimum compliance pack as a PDF, with the questions to ask about each item. No form-filling required beyond an email address to send it to.
A short description of the product, the markets and the payment flows is enough for us to say what is required, in what order and at what cost.
We reply within one business day with a scope, the deliverables and an indicative fee — not a brochure.