Learn more about the latest security and privacy threats
Back

Anti-Money Laundering (AML)

Updated July 13, 2026

Table of contents
  • Anti-money laundering is the body of laws, regulations and controls designed to stop criminals disguising the proceeds of crime as legitimate funds.
  • It obliges regulated firms to know their customers, monitor activity, and report suspicion, so illicit money is harder to move through the financial system.
  • The global standard is set by the FATF, and implemented through national regimes such as the US Bank Secrecy Act, the EU AML package and the UK Money Laundering Regulations.
  • A working AML programme rests on a few pillars: risk assessment, customer due diligence, ongoing monitoring, suspicious activity reporting, and a designated officer.
  • AML is not the same as KYC: KYC is the identity-verification part, one input into the wider anti-money-laundering effort.
  • Getting it wrong is expensive, so firms increasingly automate the routine work and focus human judgement on genuine risk.

Anti-money laundering, or AML, is the framework of laws, regulations and internal controls that regulated firms must follow to detect and prevent the disguising of illicit funds as legitimate money. It requires firms to verify customers, monitor activity, and report suspicious transactions, so criminals cannot easily move the proceeds of crime through the financial system.

TL;DR

AML is the framework of laws and controls that stops criminals disguising illicit funds as clean money. It requires regulated firms to verify customers, monitor their activity, and report suspicion to the authorities. The global standard comes from the FATF and is implemented through national regimes like the US Bank Secrecy Act, the EU AML package and the UK Money Laundering Regulations. A working AML programme rests on risk assessment, customer due diligence, ongoing monitoring, suspicious activity reporting and a designated officer. AML is broader than KYC, which is the identity-verification piece within it. Because failures are costly, firms automate the routine work and reserve human judgement for real risk.

What is anti-money laundering?

Anti-money laundering, usually shortened to AML, is the collective term for the laws, regulations and internal controls that exist to stop criminals turning the proceeds of crime into money that looks legitimate. Money laundering is the process of disguising where illicit funds came from; anti-money laundering is the coordinated effort to detect, prevent and report it.

In practice, AML places obligations on regulated firms, banks, payment providers, crypto platforms, and many others, to act as gatekeepers of the financial system. They must know who their customers are, understand the nature of their activity, watch for behaviour that suggests laundering, and report suspicion to the authorities. The purpose is not just to catch criminals but to make the financial system inhospitable to illicit money in the first place. It is the framework within which more specific disciplines, from KYC to transaction monitoring, all sit.

Why does anti-money laundering matter?

AML matters because laundering is what makes serious crime pay. Drug trafficking, fraud, corruption, human trafficking and terrorism all generate funds that are useless to criminals until they can be moved and spent without attracting attention. By making that movement difficult, AML strikes at the financial incentive behind a vast range of harm, which is why it is treated as a matter of national and international security rather than mere paperwork.

For regulated firms, AML matters for a second, immediate reason: the consequences of failure are severe. Weak controls that let illicit money through attract very large fines, enforcement actions, mandatory remediation and lasting reputational damage, as major enforcement cases repeatedly show. Beyond penalties, a firm that becomes a conduit for laundering exposes itself to being used by the very criminals the system is meant to exclude. Effective anti-money laundering therefore protects both society and the firm itself, which is why it underpins every serious AML compliance programme.

What are the key AML laws and regulators?

The global AML standard is set by the Financial Action Task Force, or FATF, an intergovernmental body whose 40 Recommendations form the template that national regimes implement. FATF does not regulate firms directly, but its standards shape the laws that do, and its assessments of countries drive reform worldwide.

Those standards are then implemented nationally. In the United States, the foundational law is the Bank Secrecy Act, administered by FinCEN, supplemented by measures such as the USA PATRIOT Act. In the European Union, anti-money laundering is now consolidated under the AML package, the AML Regulation and the sixth Directive, supervised by the new Anti-Money Laundering Authority, which harmonises rules across member states. In the United Kingdom, the Money Laundering Regulations 2017 and the Proceeds of Crime Act set the duties. Although the instruments differ, they share the same FATF-derived core: verify customers, monitor activity, report suspicion, and keep records. Firms operating across borders must satisfy the strictest applicable standard, which is why a single, consistent approach is the efficient path to compliance.

What are the pillars of an AML programme?

A working AML programme is built on a consistent set of pillars. The first is a risk assessment: understanding the money-laundering risks the firm actually faces, given its customers, products and geographies, so controls can be focused where risk is highest. The second is customer due diligence, verifying who customers are and, for businesses, who ultimately owns them, with enhanced due diligence for higher-risk cases.

The third is ongoing monitoring: watching transactions and behaviour over time for the signs of laundering, rather than checking only at onboarding. The fourth is suspicious activity reporting, escalating genuine suspicion to the authorities through a suspicious activity report. The fifth is governance: a designated, accountable officer, usually the MLRO, plus policies, training, independent testing and record-keeping. Screening customers against sanctions and PEP data runs through several of these pillars. Together they form a lifecycle: know the risk, know the customer, watch the activity, report the suspicion, and prove it was all done.

What is the difference between AML and KYC?

AML and KYC are often used interchangeably, but they are not the same thing. Anti-money laundering is the whole framework of laws, controls and obligations aimed at preventing money laundering. KYC, Know Your Customer, is one part of that framework: the process of verifying a customer's identity and assessing their risk. In short, KYC is a component of AML, not a synonym for it.

The relationship is straightforward once stated. AML sets the goal, stop illicit funds moving through the system, and prescribes the controls needed to reach it. KYC delivers one of those controls, establishing who the customer actually is, which is the foundation everything else depends on: you cannot monitor, screen or report meaningfully if you do not reliably know your customer. Other AML controls, transaction monitoring, sanctions screening, suspicious activity reporting, build on that KYC foundation. We explore the distinction more fully in our guide to KYC vs AML, but the one-line version is that KYC is the identity layer within the broader anti-money-laundering effort.

What stages of money laundering does AML target?

Anti-money laundering is designed around how laundering actually works, which is conventionally described in three stages: placement, layering and integration. Placement is where illicit funds first enter the financial system; layering disguises their origin through complex transactions; and integration returns them to the criminal as apparently legitimate wealth. Different AML controls target different stages.

Strong customer due diligence and cash controls concentrate on placement, the point at which dirty money is most conspicuous and easiest to catch. Transaction monitoring and the ability to resolve ownership target layering, where the launderer works hardest to break the trail. Scrutiny of source of funds and the plausibility of wealth targets integration. Understanding these stages of money laundering is what lets a firm place its controls where they will actually catch something, rather than spreading effort evenly and catching little. It is the conceptual map behind a well-designed anti-money-laundering programme.

How is anti-money laundering evolving?

AML is changing on several fronts at once. Regulation is tightening and harmonising: the EU's single rulebook and new central authority, evolving beneficial-ownership transparency, and the extension of AML obligations to crypto and other newer sectors all raise the baseline. At the same time, the threats are getting more sophisticated, with generative tools enabling more convincing identity fraud and laundering networks exploiting cross-border complexity.

The response is increasingly technological. Firms are automating the routine, high-volume work, verification, screening, first-line alert review, so that scarce human expertise focuses on genuine risk, and reasoning systems now assist with tasks like alert triage and adverse-media review. There is also a growing emphasis on continuous rather than periodic checks, on resolving true beneficial ownership, and on holding the data these controls rely on more securely rather than pooling it into breach-prone stores. The direction of travel is clear: anti-money laundering is becoming more data-driven, more continuous, and more automated, while the underlying obligations, know your customer, monitor, report, remain constant.

How does Zyphe support anti-money laundering?

Zyphe strengthens the foundation that every AML programme depends on: reliably knowing who you are dealing with. It provides chip-based identity verification for individuals, business verification with recursive ownership resolution for companies, and screening of customers and their owners against sanctions, PEP and adverse-media data, all through a single API that integrates in around fifteen minutes.

That clean identity and ownership foundation feeds the rest of the AML lifecycle. Monitoring, screening and reporting are only as good as the data beneath them, and reliable verification makes placement anomalies easier to spot, layering harder to hide behind opaque structures, and suspicion easier to evidence when it arises. Because the platform is decentralised, the sensitive data gathered for AML is sharded rather than pooled into a central store, so stronger controls never create a bigger breach target, and verified users can carry a reusable credential across services. Zyphe does not replace transaction monitoring or a firm's own judgement, but it makes the identity layer beneath anti-money-laundering compliance far more reliable. Book a demo to see how it fits your programme.

The bottom line

AML is the framework that makes serious crime harder to profit from, by obliging regulated firms to know their customers, monitor their activity, and report suspicion so illicit funds cannot move through the system unseen. It is set globally by the FATF and implemented through national regimes that share the same core, and it rests on a consistent set of pillars from risk assessment to reporting. KYC is the identity layer within it, not a synonym for it. As regulation tightens and threats evolve, AML is becoming more continuous and more automated, but its foundation is unchanged: you cannot monitor, screen or report what you cannot reliably identify, which is why knowing your customer sits at the heart of it all.

Cited sources

Frequently Asked Questions

Anti-money laundering is the framework of laws, regulations and internal controls that regulated firms follow to detect and prevent criminals disguising illicit funds as legitimate money. It requires firms to verify customers, monitor activity and report suspicious transactions, making it harder to move the proceeds of crime through the financial system.

AML is the whole framework aimed at preventing money laundering, while KYC, Know Your Customer, is one part of it: verifying a customer's identity and risk. KYC is a component of AML, providing the identity foundation that monitoring, screening and reporting all build on.

The global standard is set by the FATF's 40 Recommendations, implemented nationally through laws such as the US Bank Secrecy Act (administered by FinCEN), the EU AML package supervised by AMLA, and the UK Money Laundering Regulations. They share the same core: verify customers, monitor, report and keep records.

A risk assessment, customer due diligence (with enhanced due diligence for higher-risk cases), ongoing monitoring, suspicious activity reporting, and governance, including a designated officer, policies, training, independent testing and record-keeping. Sanctions and PEP screening run through several of these.

Regulated firms that act as gatekeepers to the financial system: banks, payment providers, money services businesses, crypto platforms, lenders, insurers and many designated non-financial businesses. The exact scope varies by jurisdiction, but the obligations are broadly consistent.

Weak AML controls can lead to very large fines, enforcement actions, mandatory remediation and lasting reputational damage, and the firm risks becoming a conduit for the criminals the system is meant to exclude. Supervisors treat systemic AML failures as serious.

They are closely related and usually addressed together as AML/CFT (anti-money laundering and countering the financing of terrorism). The controls overlap heavily, verifying customers, screening, monitoring and reporting, though terrorist financing can involve small, clean-origin funds, which adds a distinct detection challenge.

Firms automate high-volume routine work, identity verification, sanctions and PEP screening, and first-line alert review, so human expertise focuses on genuine risk. Reasoning systems increasingly assist with alert triage and adverse-media review, while the underlying duties to verify, monitor and report remain unchanged.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML