top of page
Search

How to Prepare an AML Policy for Your Business

Writer: James Watt
James Watt
Aug 16
6 min read

An AML policy should not be a generic document downloaded, signed and left in a compliance folder. For a regulated UK business, it is the operating framework that shows how you identify financial crime risk, protect the business from being misused, and respond when concerns arise. Knowing how to prepare AML policy documentation properly means turning legal obligations into procedures your team can follow consistently.

The detail required depends on your sector, services, customer base and supervisory authority. An accountancy practice, estate agency business, trust or company service provider, high-value dealer and cryptoasset business will face different risks and controls. The principle is the same: your policy must be proportionate, written, current and supported by evidence that it is being applied.

Start with your business-wide risk assessment

Your AML policy should be built on a documented business-wide risk assessment, not on assumptions. Under the Money Laundering Regulations 2017, relevant persons must identify and assess the risks of money laundering and terrorist financing to which their business is subject. This assessment is the foundation for the policies, controls and procedures that follow.

Consider where risk enters the business. Look at your customers, the countries connected to them, the products or services you provide, transaction patterns, delivery channels and whether you rely on third parties to introduce clients. A UK-based limited company with straightforward trading activity presents a different risk profile from an international e-commerce seller using multiple payment providers, warehouses and overseas suppliers.

Your assessment should explain both the risks identified and the controls used to manage them. Avoid simply scoring every client as low risk. A regulator will expect a reasoned view, particularly where there are complex ownership structures, cash-intensive activity, high-risk jurisdictions, politically exposed persons or unusual payment flows.

Review the assessment at least annually and whenever the business changes materially. New services, international expansion, a change in client type or a significant compliance incident can all alter the risk profile.

How to prepare an AML policy that works in practice

A useful AML policy sets out what the business does, who does it, when it happens and where the evidence is kept. It should translate the risk assessment into clear operational instructions rather than repeat the wording of the regulations.

Begin by defining the policy's scope. State the legal entity or entities covered, the services in scope, the relevant supervisory authority and the employees, directors, contractors or agents expected to comply. If parts of the group operate in different jurisdictions, make clear which local procedures apply and how UK requirements are maintained.

Then set out the roles responsible for oversight. Many regulated businesses appoint a money laundering reporting officer, or MLRO, to receive internal suspicious activity reports and a nominated officer to decide whether a report should be made to the National Crime Agency. In a smaller business, one suitably qualified individual may hold both roles. The policy should still identify deputies, escalation routes and the authority given to those responsible.

A strong policy is specific about the following areas:

  • customer due diligence and identity verification;

  • beneficial ownership and control checks;

  • risk rating, enhanced due diligence and ongoing monitoring;

  • screening for politically exposed persons, sanctions exposure and adverse information;

  • internal reporting of suspicions and external suspicious activity reports;

  • record keeping, training, staff screening and independent review.

These are not separate administrative exercises. They should work together. A customer risk rating determines the level of due diligence required, monitoring may identify information that changes that rating, and a concern may need to be escalated promptly to the MLRO.

Set out a proportionate customer due diligence process

Your policy should explain when customer due diligence is required, what information must be collected and how verification is carried out. This usually includes identifying the customer, verifying their identity from reliable and independent sources, understanding the purpose and intended nature of the business relationship, and identifying anyone who ultimately owns or controls the customer.

For corporate clients, procedures should cover directors, shareholders, beneficial owners and the source of authority for the person instructing you. For trusts and partnerships, the relevant parties will differ. The policy should avoid a one-size-fits-all checklist where the structure requires a more considered approach.

Document how your business assigns client risk ratings. Low, standard and high-risk categories can be useful, provided staff understand the criteria and do not treat the rating as a permanent label. For example, a long-standing UK client may require a revised assessment if ownership changes, payments begin arriving from unrelated third parties or the business starts trading in higher-risk territories.

Enhanced due diligence should be triggered by defined circumstances, including higher-risk third countries and relationships involving politically exposed persons. The measures needed will depend on the risk, but may include obtaining more information about source of funds and source of wealth, senior management approval, or more frequent monitoring.

Do not confuse source of funds with source of wealth. Source of funds concerns the money used in a particular transaction or relationship. Source of wealth concerns how the customer accumulated their overall wealth. In a higher-risk case, understanding one may not be enough.

Explain monitoring, escalation and suspicious activity reporting

An AML policy must make it safe and straightforward for staff to raise concerns. Include examples relevant to your services, such as unexplained changes in beneficial ownership, requests to make payments to unconnected third parties, reluctance to provide ownership information, inconsistent turnover figures or complex transactions with no clear commercial rationale.

Staff should know that suspicion is not proof. They are not expected to investigate criminal conduct or confront the client. Their responsibility is to report concerns internally, without delay, using the business's confidential process. The MLRO then considers whether a suspicious activity report should be submitted to the National Crime Agency.

The policy should expressly address tipping off. Employees must not tell a customer that a report has been made, or that an investigation may be taking place, where doing so could prejudice an investigation. This is particularly important for client-facing teams, who need clear language for handling requests without making inappropriate disclosures.

Ongoing monitoring should also have a practical timetable. Set out when client records are refreshed, who reviews exceptions and what events trigger an earlier review. The right frequency depends on risk. High-risk relationships may need closer review, while lower-risk clients can be reviewed less often if there is a sound rationale.

Build record keeping and training into the policy

A policy is only credible if the business can show what it did. Set out what records are retained, where they are stored, who can access them and how long they are kept. Under the Money Laundering Regulations, customer due diligence and transaction records are generally retained for five years after the end of the business relationship or the date of an occasional transaction, subject to the applicable rules on deletion and data protection.

Your procedures should balance AML record retention with UK GDPR obligations. Collect what is necessary, restrict access to sensitive data and have a clear deletion process once the legal retention period ends. Retaining documents indefinitely is not a substitute for good compliance.

Training must be tailored to the role. A director responsible for governance, a member of the onboarding team and a bookkeeper reviewing transactions will each need different practical guidance. Induction training should be followed by regular refreshers, with attendance and content recorded. Where relevant, include assessment or case-based training so that staff can demonstrate understanding.

Test the policy before relying on it

Before approving the document, walk through it using real client scenarios. Can a new team member identify the correct due diligence steps? Can they find the internal reporting form? Does the MLRO receive enough information to make a timely decision? If the answer is no, the policy needs clearer procedures or better supporting tools.

Senior management should approve the policy and receive periodic reporting on compliance activity, training completion, higher-risk clients, internal reports and outstanding remediation. Larger or higher-risk businesses should consider an independent review of their AML controls. For smaller firms, an objective review by someone not involved in day-to-day implementation can still identify gaps.

Template policies can provide a starting structure, but they cannot account for your actual client base, transaction flows or operational processes. For owner-managed businesses, the most effective AML policy is one that is proportionate enough to be followed every day and detailed enough to withstand supervisory scrutiny.

Good AML compliance creates more than a regulatory paper trail. It gives directors clearer oversight of who they are dealing with, why a transaction makes commercial sense and when a risk requires action. That discipline protects the business while allowing it to grow with greater confidence.

 
 
 

Comments


Contact Us

 

© 2026 by Fortis Accounting Ltd. Powered and secured by Wix

 

Location

Wokingham, United Kingdom

Follow Us

  • Facebook
  • Instagram
  • LinkedIn
bottom of page