What is anti money laundering: AML explained
Anti money laundering, abbreviated AML, is the body of law, regulation and internal controls requiring businesses to prevent, detect and report the movement of criminal proceeds through the financial system. It is a legal obligation carrying personal liability for named individuals inside the firm, not an optional standard of good practice.
Written as anti-money laundering or anti money laundering, and often paired with CFT, counter terrorist financing, because the two obligations are almost always legislated together even though the money moves in opposite directions.
What does anti money laundering mean?
Money laundering is the process of making criminal proceeds appear legitimate. AML is everything a regulated firm is required to do so that it neither assists that process nor stays silent about it.
The international frame is the FATF Standards, the 40 Recommendations first issued in 1989 and now committed to by more than 200 countries and jurisdictions. They are recommendations addressed to states. What binds any individual firm is the national law implementing them, which is why AML obligations rhyme across markets without matching.
The three stages the controls are built around
Nearly every regime is taught through the same three-stage model, and it remains a useful map:
- Placement. Criminal proceeds enter the financial system, historically through cash deposits, cash-intensive businesses or the purchase of goods.
- Layering. Transactions are stacked to break the audit trail: transfers between accounts and jurisdictions, purchases and resales, corporate structures.
- Integration. The funds re-emerge with an apparently legitimate explanation, as property, business revenue, settlements or investment returns.
The insurance sector is exposed at all three points, which is why claims sits closer to AML than most claims staff expect. A policy bought with illicit funds and cancelled early returns clean money. An inflated or fabricated loss converts criminal proceeds into a legitimate insurer payment.
How AML works inside a regulated firm
The components are consistent across regimes, whatever the local labels:
- A business-wide risk assessment, documenting the firm's exposure by product, customer type, channel and geography, and reviewed rather than filed.
- Customer due diligence, the checks described in know your customer, applied proportionately and refreshed over time.
- Ongoing monitoring, transaction and relationship surveillance, usually informed by risk scoring to decide which alerts get human attention first.
- Sanctions and PEP screening, at onboarding and on a continuing basis.
- Internal escalation and external reporting, handled through a nominated officer and covered in regulatory reporting.
- Training and record-keeping, including the ability to reconstruct why a decision was taken years afterwards.
Most regimes require a named individual to hold responsibility for the reporting function, variously a money laundering reporting officer, a nominated officer or a compliance officer. In several jurisdictions that individual carries personal criminal liability, which is the reason AML governance is rarely delegated far down an organisation.
AML example: the settlement that did not fit
A commercial property claim settles at a figure the policyholder accepts without negotiation, and the payee bank details are changed three days before payment to an account in a third country held by a company with no obvious link to the insured.
The handler escalates internally rather than resolving it on the phone. The nominated officer reviews, the transfer of the freehold two months earlier turns out to be genuine and documented, and the payment proceeds. The escalation cost an afternoon and produced a written record of why the change was accepted, which is precisely what a supervisor would later want to see.
How AML differs from fraud prevention
They overlap in tooling and often in team, and they answer different questions. Fraud prevention asks whether this transaction or claim is what it purports to be, and the loss it protects is the firm's own. AML asks whether the firm is being used to move criminal proceeds, and the loss it protects is a public one.
The practical divergence shows up at the end of a case. A suspected fraudulent claim can be declined and the customer told why. A money laundering suspicion generally cannot be discussed with the customer at all, because of the tipping-off restrictions covered under regulatory reporting. Handlers who treat the two the same way create serious problems, and the fastest way to make one is to explain a delay honestly to the wrong person.
Where AML obligations differ by country
Presenting one market's rules as universal is the most common error in AML writing. The Standards are shared, the implementations are not.
- Which businesses are in scope, including whether general insurers, brokers, motor dealers and high-value goods traders are caught, and at what thresholds.
- Reporting routes, which financial intelligence unit receives reports and in what format.
- Whether a consent or defence mechanism exists allowing a firm to proceed with a transaction after reporting, and what happens while a decision is pending.
- Penalties and personal liability, which range from administrative fines to imprisonment.
- Record retention periods, which interact awkwardly with data protection minimisation requirements.
Anyone operating across borders should assume divergence and check the local position rather than porting a group policy unchanged. This entry is background, not legal advice.