An AML policy is the foundation document of any anti-money laundering programme | the written statement of how your business identifies, assesses and controls money laundering and terrorist financing risk. For crypto and fintech businesses specifically, it's also usually the first thing a regulator, banking partner or auditor asks to see. This guide covers what an AML policy actually needs to contain, and why so many first drafts fail review.
1. What an AML policy is, and what it isn't
An AML policy is not a compliance mission statement. It's an operational document that should let someone unfamiliar with your business understand exactly how due diligence, monitoring and reporting actually happen, day to day. A policy that reads well but doesn't match your real procedures is arguably worse than no policy at all | it signals a gap between what you say and what you do the moment an auditor tests it.
2. The core components of an AML policy
- A business-wide risk assessment covering customer, product, geographic and channel risk
- Customer due diligence (CDD) and enhanced due diligence (EDD) procedures, including PEP handling
- A defensible country and counterparty risk methodology
- Transaction monitoring rules and escalation thresholds
- Suspicious activity reporting procedures, with a named accountable officer
- Record-keeping requirements and retention periods
- Staff training obligations and cadence
- Governance: who owns the policy, and how often it's reviewed
3. The mistakes that show up most often
A few patterns recur across the policies we review:
- Internal contradictions | a blanket prohibition on PEPs in one section, alongside a detailed PEP EDD acceptance procedure in another
- Country risk lists that erroneously include EU or EEA member states, usually from a copy-paste error inherited from an unrelated jurisdiction's restriction list
- Policies clearly adapted from a different business model, with terminology or products that don't match what the company actually does
- No clear ownership | the policy references "the compliance team" without naming an accountable individual
4. Writing it around your actual business
The strongest AML policies are written around real customer types, real transaction flows and real risk exposure | not adapted from a generic template. This means the risk assessment should drive the policy, not the other way around. If your business model changes materially, the policy needs to change with it, not just get a new date stamp.
5. Keeping it current
An AML policy isn't a one-time deliverable. Regulatory guidance evolves, sanctions lists change, and your own product and customer base shift over time. A policy review cadence | at minimum annual, ideally tied to material business changes | keeps the document from quietly drifting out of date.
The bottom line
A good AML policy does two things at once: it satisfies what a regulator expects to see, and it actually describes how your team operates. Getting both right | and keeping them aligned as the business evolves | is what separates a policy that passes review from one that invites follow-up questions.