AML/KYC, MLRO and internal control
A framework that answers the only question that matters: can you show why this customer was accepted, and who decided?
An AML framework is judged on one question: when a supervisor picks a customer file at random and asks why that customer was accepted, can you show the decision, the evidence behind it and the person who made it? Everything below exists to make the answer yes.
Downloaded policies fail that test immediately, and they fail it in a specific way — they create obligations your team does not know it has. A policy that says transactions above a threshold are escalated within twenty-four hours is a commitment you will be measured against, whether or not anyone read it.
What the framework contains
A complete framework is a hierarchy, not a document. At the top sits a risk assessment; beneath it a policy that responds to that assessment; beneath that the procedures staff actually follow; and running through all three, the records that prove it happened.
Business-wide risk assessment
The foundation, and the part most often skipped. It identifies the risk your specific business runs across customer types, products and services, delivery channels, geographies and payment methods, and it explains the methodology used to score them. A supervisor comparing your policy to your risk assessment is checking whether the controls answer the risks you yourself identified.
AML/CFT policy
The governing document: scope, roles, risk appetite, the customer acceptance standard, escalation, reporting, training and record keeping. It should be short enough that staff read it and specific enough that it could not belong to another firm.
Procedures
The operational layer — onboarding, verification, screening, ongoing monitoring, alert handling, escalation and reporting — written as steps with owners and timescales rather than principles.
Governance and oversight
Who is accountable at board level, how the MLRO reports and to whom, how often the framework is reviewed, and what happens when a control fails. The management information a board receives is itself examined: a board that approves an AML framework and never sees an alert statistic is a finding waiting to happen.
Where the rules are heading
The EU AML package replaces much of the current directive-based patchwork with a directly applicable regulation from July 2027, and establishes a European authority in Frankfurt that will supervise selected high-risk firms directly from 2028. Frameworks built now should anticipate a single rulebook and tighter, more harmonised expectations rather than the current national variation.
Customer due diligence, EDD and screening
Standard due diligence
- Identification and verification of the customer, from independent and reliable sources
- For legal entities: ownership chain to the beneficial owners, and verification that the chain is real
- Purpose and intended nature of the relationship, recorded in a way that can be tested later
- Risk scoring at onboarding, with the factors that produced the score preserved
Enhanced due diligence
Triggered by higher-risk factors — a politically exposed person, a high-risk jurisdiction, unusual ownership, an unclear source of wealth. EDD means more evidence and senior approval, not simply a note on the file. Where it is triggered, the record must show what additional information was obtained and who approved the relationship.
Screening
- Sanctions screening at onboarding and continuously thereafter, against the lists that apply to you — which may be more than one regime
- PEP identification, including family members and close associates
- Adverse media screening, calibrated so that it produces manageable volumes of meaningful alerts
- A documented process for handling a hit: who reviews, what evidence is gathered, who decides, how the decision is recorded
Transfers of crypto-assets
Firms handling crypto-asset transfers carry travel rule obligations: originator and beneficiary information must accompany the transfer, and transfers involving self-hosted wallets require their own verification approach. The procedure has to state what happens when the required information is missing.
The MLRO and internal control
The Money Laundering Reporting Officer is a named individual with personal responsibility. In most regimes the appointment is notified to the regulator, and in several the role cannot be combined with operational management — the Curaçao regime, for example, requires the compliance officer and MLRO to be separate from the CEO and the operational director.
What the role actually involves
- Receiving internal suspicion reports and deciding whether to report externally
- Making the external report to the financial intelligence unit, and managing what happens next
- Maintaining the record of every internal report, including those not escalated — the decisions not to report are examined as closely as the reports
- Advising the board, with management information that lets the board challenge what it is told
- Annual reporting on the effectiveness of the framework
Independence and resourcing
An MLRO who reports to the head of sales is not independent, and an MLRO covering five firms is not resourced. Both are visible from the outside, and both are common grounds for a supervisory finding or a refused application.
Training and internal audit
Training must be role-specific and recorded — a general annual session for all staff does not demonstrate that the onboarding team understands EDD triggers. Internal audit tests whether the framework operates as documented: sampling files, re-performing decisions and reporting to the board on what it found. For smaller firms this can be outsourced, but it cannot be omitted.
Monitoring, reporting and records
Transaction monitoring
Rules, thresholds and scenarios that reflect your business rather than a vendor's defaults. Two things are examined: whether the rules address the risks in your own assessment, and whether you can explain why a threshold is set where it is. Keep the tuning log — a record of what was changed, when and why — because it is the only way to answer that question a year later.
Alert handling
Alerts require an owner, a service standard and an outcome recorded with reasons. A backlog is itself a finding, and a backlog discovered by a supervisor rather than disclosed by you is a worse one.
Suspicious activity reporting
The internal route from staff member to MLRO must be simple and protected. Tipping-off prohibitions have to be understood by the people who deal with customers, not merely stated in a policy they have not read.
Records
Retention periods generally outlast the customer relationship, and the obligation is to produce records on request — which means a defined location, a defined format and someone who knows where they are. Data protection obligations run alongside: retention for AML purposes is a lawful basis for holding data, not a licence to keep everything indefinitely.
Banking onboarding
Banks decline regulated digital businesses far more often than they decline anyone else, and the reason is usually procedural rather than substantive. A compliance officer has a list of questions that must be closed before an account can be opened. If your file does not close them, the file is refused — not the business.
What the compliance officer needs to close
- Who owns this? An unbroken ownership chain to natural persons, with documents, not a chart.
- Where did the money come from? Source of funds for the capital and source of wealth for the owners, evidenced. This is where most files stop.
- What exactly does the business do? Described in operational terms — who pays whom, for what, through which rails, in which currencies, at what volume.
- Is it licensed, and for what? The authorisation, its scope and its conditions.
- What stops this being used for laundering? A summary of your framework that a non-specialist can follow.
- What is the expected activity? Volumes, counterparties and geographies, stated in advance so that actual activity can be compared against it.
Institution selection
Applying broadly is the most expensive mistake available. Each decline is recorded, and later applications ask whether you have been refused before. Matching your profile to institutions that actually serve it, and applying with a complete file, is slower to start and far faster to finish.
Longer treatment: why banks say no to regulated digital businesses.
The minimum compliance pack
If you have all fourteen of these, in a form someone outside your company could read, you are ready for most conversations with a regulator or a bank. If you do not, this is the build order.
- Business-wide AML/CFT risk assessment, dated and approved
- AML/CFT policy approved at board level
- Customer acceptance policy, including who you will not accept
- Onboarding and CDD procedure, with the evidence standard for each customer type
- EDD procedure and the triggers that invoke it
- Sanctions, PEP and adverse media screening procedure, including hit handling
- Transaction monitoring rules with a documented rationale and tuning log
- Suspicious activity reporting procedure, internal and external
- MLRO appointment, terms of reference and reporting line
- Training plan and attendance records by role
- Record retention schedule mapped to legal obligations
- Internal audit plan and the last report
- Outsourcing register with the agreements behind it
- Management information pack the board actually receives
A framework is only worth what it can evidence. Before a supervisory visit we run the same exercise an examiner would: pick five customer files at random and reconstruct every decision from the record alone. What that exercise finds is usually more useful than any gap analysis.
Frequently asked questions
Can we adapt a policy we already have?
Usually, and it is often cheaper than starting again. The work is in the risk assessment underneath it — if that does not exist, the policy has nothing to respond to and a supervisor will say so. We review what you have, identify what is generic and rebuild the parts that need to be specific to you.
Do we need a full-time MLRO?
It depends on size, risk and regime. What is not negotiable is that the person is genuinely available, genuinely independent of commercial pressure, and able to evidence their decisions. An outsourced or part-time MLRO can satisfy that; an MLRO in name only cannot, and it is visible from outside.
How often should the framework be reviewed?
Annually as a minimum, and on any material change — a new product, a new market, a new payment channel, a new regulatory obligation. The review itself has to be documented; a framework that has not visibly been reviewed reads as one nobody is responsible for.
Our regulator has asked for a remediation plan. Can you help?
Yes, and it is time-critical work. A remediation plan is judged on whether it is realistic and whether the milestones are met, so the plan should promise less and deliver on schedule rather than the reverse. We draft it, sequence it and support the reporting back to the supervisor.
Is the checklist available as a document?
Yes — write to us and we will send the minimum compliance pack as a PDF, with the questions to ask about each item. No form-filling required beyond an email address to send it to.
Tell us what you are building
A short description of the product, the markets and the payment flows is enough for us to say what is required, in what order and at what cost.
Describe your matter
We reply within one business day with a scope, the deliverables and an indicative fee — not a brochure.