CommsPliant Lexicon

AML - Anti-Money Laundering

The laws, controls and practical work used to prevent and detect money laundering and report suspected activity involving criminal proceeds.

Plain English

What does AML mean?

AML stands for Anti-Money Laundering.

Money laundering commonly involves handling money or other property obtained from crime in ways that conceal its criminal origin. Someone might try to present stolen money as ordinary business income. Making it look legitimate does not change where it came from. FATF — money laundering explained.

AML brings together customer checks, monitoring, staff responsibilities and action on concerning information. The controls and duties depend on the business, its risks and the rules that apply. FCA — AML controls.

What does it look like at work?

A payment provider notices activity that differs from its understanding of a customer. Its team examines the circumstances and decides what needs updating, escalating or reporting.

An unusual payment may have an innocent explanation. A Suspicious Activity Report (SAR) supplies information about possible money laundering or terrorist financing; it is not a finding of guilt. In the UK, external SARs go to the UK Financial Intelligence Unit (UKFIU) within the National Crime Agency. NCA — Suspicious Activity Reports.

In practice

The business has changed. Has the activity been explained?

Fictional example.

A payment provider knows a customer as a local catering company. Incoming payments increase, some arrive from unfamiliar businesses, and money is transferred onwards to recipients whose connection to the customer is unclear.

The customer explains that it now organises larger events and provides contracts and invoices.

The analyst checks the documents against the activity. Several incoming payments match identified events. Other receipts and onward transfers remain unexplained.

The review has established something useful: the business expansion explains part of the change. It has not established that every concern is resolved.

The analyst records what the documents support, what remains uncertain and why. The unresolved activity goes to the appropriate financial-crime colleague for assessment. Updating the customer profile does not, by itself, settle the reporting question.

This example illustrates partial resolution. It does not determine whether a real case meets a reporting threshold or justify delaying an existing reporting obligation.

Professional view

Where does KYC end and AML begin?

There is overlap. Know Your Customer (KYC) concerns understanding the customer and the relationship, including keeping that understanding current. Customer Due Diligence (CDD) includes identifying and verifying customers and, where applicable, beneficial owners, and understanding the intended relationship. Relevant changes can require further review. HMRC — customer due diligence.

AML extends across the organisation: business risk assessment, due diligence, monitoring, staff training, escalation, reporting and control oversight. FCA — AML responsibilities.

The practical boundary is not simply “KYC before opening; AML afterwards”. Customer understanding informs monitoring, and monitoring can reveal that the customer understanding needs to change.

Does money laundering always require disguising the money?

The everyday explanation is narrower than the full legal scope. UK offences can include acquiring, using or possessing criminal property, subject to the relevant conditions and exceptions. A complicated series of transfers is not essential to every offence. CPS — Money Laundering Offences.

AML also extends beyond banks and physical cash. Companies, property transactions and professional services can be exploited. NCA — Money laundering and illicit finance.

Which rules decide the firm's obligations?

The Financial Action Task Force (FATF) develops international standards; it does not investigate individual customer accounts. Applicable national law and regulatory requirements determine the firm's obligations. The reporting discussion below uses the UK framework. FATF — institutional role, FCA — UK AML framework.

Professional judgement

1. The explanation is plausible. Does it explain the activity?

A customer's explanation can be commercially credible without accounting for the transactions under review.

In the catering example, a genuine event contract may explain an increase in turnover. It may not explain a payment from a business absent from that contract, or a transfer to an apparently unrelated recipient.

The FCA expects ongoing monitoring to consider whether transactions are consistent with the firm's knowledge of the customer, its business and risk profile. FCA — due diligence and monitoring.

Applied to this example, useful questions are:

  • Relevance: Which payment or pattern does each document explain?

  • Consistency: Do the parties, amounts and timing fit the explanation?

  • Reliability: What supports relying on the information? Has it been checked, or only accepted as stated?

  • Remaining concerns: What still does not fit, and why does that matter?

These are assessment prompts, not a prescribed document checklist.

The review should distinguish a missing piece of information from an explanation contradicted by available evidence. A missing invoice and an invoice inconsistent with the payment record create different questions.

A supported explanation may justify closing a particular concern while other activity still requires assessment. Equally, an unresolved detail does not automatically establish suspicion. The significance of that detail matters.

The record needs to explain why the evidence resolves—or does not resolve—the concern that prompted the review.

2. Does “I am not suspicious” settle the reporting question?

A customer risk rating and a reporting assessment answer different questions.

A risk rating helps determine the controls appropriate to the relationship. The reporting assessment considers whether the information engages an applicable disclosure duty. A high-risk classification does not automatically decide that question; a low-risk classification does not dispose of new concerning information. This distinction follows from the separate risk-management and reporting requirements. FCA — risk-based approach, CPS — failure to disclose.

In the UK regulated sector, section 330 of the Proceeds of Crime Act 2002 (POCA) addresses knowledge or suspicion and reasonable grounds for knowing or suspecting, alongside further statutory conditions and exceptions. The assessment therefore cannot rest solely on an individual's statement that they personally felt no suspicion. CPS — failure to disclose.

The threshold also should not be confused with either proof or general discomfort. UKFIU guidance refers to R v Da Silva: a vague feeling of unease is insufficient, while suspicion can concern a possibility beyond the merely fanciful. The relevant test must be applied to the facts. NCA — Submitting a SAR, page 7.

In the catering case, the question is what the unmatched payments and available explanations actually indicate. “The business has grown” and “the system generated an alert” each leave that assessment unfinished.

An employee's disclosure to the nominated officer and an external SAR to the UKFIU are distinct steps. Responsibility and timing depend on the person's role and the applicable duty. CPS — failure to disclose.

A review process must accommodate reporting when required, even if other enquiries remain open. Completing every internal check is not a prerequisite for recognising an existing duty.

3. We filed a SAR. What decisions are still outstanding?

A SAR does not replace a crime report or another required reporting route. NCA — Suspicious Activity Reports.

It also does not, merely by being submitted, settle whether a proposed transaction should proceed.

Some SARs include a request for a Defence Against Money Laundering (DAML). This concerns specified intended activity that could expose the reporter to a principal money-laundering offence.

A granted DAML:

  • concerns the activity covered by the defence;

  • does not establish that the money is legitimate;

  • does not remedy incomplete CDD;

  • does not remove other legal or regulatory obligations;

  • does not require the firm to proceed.

The NCA also rejects a broad request simply to maintain a business relationship as a request for blanket protection. NCA — Understanding DAMLs and DATFs, pages 4–5 and 18.

Returning to the fictional case, suppose the customer asks the provider to transfer the remaining balance. The firm needs to assess that proposed action, including any relevant defence or exemption, alongside its other obligations. A reporting reference alone does not answer those questions.

A practical workflow should distinguish report submitted, specified activity assessed and relationship decision recorded. These are suggested decision records, not prescribed system labels.

4. What would make the decision understandable to another reviewer?

For this fictional case, a useful decision record would explain:

Decision elementWhat the record should make understandable
Original concernWhich activity differed from the recorded customer profile?
Information consideredWhat was available, how was it checked, and what was missing?
Explanation acceptedWhich transactions or changes did the evidence account for?
Unresolved issuesWhat remained inconsistent or uncertain, and how significant was it?
Assessment and actionWhy was a concern closed, further work assigned or reporting considered necessary?
Timing and ownershipWho decided what, when, and who owns any remaining action?

This is an editorial framework for reviewing decision quality, not a statutory template.

A note saying “customer explanation accepted” obscures the scope of the decision. A more informative note identifies the explanation, the supporting evidence and the activity it covers. If other concerns remain, their owner and next action should be clear.

Where a SAR is submitted, the UKFIU's guidance calls for a clear explanation of the grounds for suspicion. The narrative needs to connect the relevant facts to the concern, rather than leave the reader to infer it from a list of transactions. NCA — Submitting a SAR, reason for suspicion.

A recorded outcome becomes useful evidence of the review when another authorised reader can follow how it was reached.

Why it matters

Money laundering enables criminals to retain and use the benefits of crime, with consequences beyond the institution processing the funds. NCA — Money laundering and illicit finance.

For an AML team, the quality of the work lies in how information changes decisions: what has been explained, what remains concerning, what must be reported and what can happen next.

Common misunderstandings

  • “KYC complete means AML complete.” Customer information, activity and risk can change.

  • “An alert proves money laundering.” An alert identifies activity for assessment.

  • “A genuine document resolves the case.” Its relevance to the activity and concern still needs assessing.

  • “Low risk means no reporting issue.” The reporting assessment must consider the information available.

  • “We need proof before reporting.” Applicable duties can arise before a crime is proved.

  • “A SAR or granted DAML clears the relationship.” Reporting, a defence for specified activity and the firm's wider obligations are separate matters.

Connected terms

Know Your Customer (KYC) · Customer Due Diligence (CDD) · Enhanced Due Diligence (EDD) · Suspicious Activity Report (SAR) · Defence Against Money Laundering (DAML) · Transaction Monitoring · Money Laundering Reporting Officer (MLRO).

Official sources

  1. FATF — Frequently Asked Questions: the concept of money laundering and FATF's role.

  2. FCA — Money laundering and terrorist financing: UK AML controls, risk assessment and monitoring.

  3. HMRC — Your responsibilities under money laundering supervision: customer due diligence and changing circumstances.

  4. CPS — Money Laundering Offences: criminal property, offence scope and failure to disclose.

  5. NCA — Money laundering and illicit finance: exploitation of businesses and professional services.

  6. NCA — Suspicious Activity Reports: SARs and other reporting routes.

  7. UKFIU — Chapter 2: Submitting a SAR: suspicion and reporting narratives.

  8. UKFIU — Chapter 3: Understanding DAMLs and DATFs: specified activity, the scope of a defence and continuing obligations.