Skip to main content
Stop Building One AML/CFT Framework Per JurisdictionBeneficial Ownership
4 min readFor AML Compliance Officers

Stop Building One AML/CFT Framework Per Jurisdiction

The conventional wisdom in multi-jurisdictional AML compliance suggests that different regulators require different programs. You create a UK program for the FCA, a US program for FinCEN, and an EU program for AMLD6 requirements. Each jurisdiction gets its own framework, risk assessments, and monitoring rules.

This logic seems sound because regulators want to see compliance with their specific requirements. If you're operating in four jurisdictions, you might think you need four programs.

However, this approach is expensive, fragmented, and increasingly unworkable. It also misunderstands what regulators actually want.

Why a Unified Approach Works

Jurisdictional differences do exist. For example, the EU's AMLD6 defines 22 specific predicate offenses. The US removed domestic beneficial ownership reporting requirements in March 2025, while the UK maintains a publicly searchable PSC register. Hong Kong's Significant Controllers Register exists but isn't public. These are not trivial variations.

The issue is treating these differences as if they require separate compliance architectures.

Major frameworks require the same core elements: customer due diligence, beneficial ownership identification, transaction monitoring, suspicious activity reporting, and record-keeping. The FATF's 40 Recommendations form the baseline. The UK, EU, US, and Hong Kong all built their frameworks on top of it. When FATF's fifth round of evaluations began in 2024, the focus shifted to effectiveness over technical compliance. A country can have perfect laws on paper but still fail if those laws don't work in practice.

Regulators aren't looking for separate programs. They're looking for one effective program that addresses specific implementation requirements.

The Evidence

Consider beneficial ownership. The threshold is 25% across the UK, EU, and Hong Kong. The US used the same threshold under the Corporate Transparency Act before the March 2025 interim rule narrowed its scope to foreign registrants. The core obligation is the same: establish who ultimately owns or controls the entity you're doing business with.

What differs is where you look for verification. In the UK, you check the PSC register. In the EU, you access the central beneficial ownership register. In the US, you rely on direct disclosure from the entity since FinCEN's BOI data isn't accessible to financial institutions. In Hong Kong, the Significant Controllers Register exists but you can't see it without a law enforcement request.

These are data access differences, not due diligence differences. Your risk assessment methodology doesn't change. Your verification procedures don't change. Your documentation standards don't change. What changes is which external registry you query and how you document the limitation when no public register exists.

The same pattern holds for transaction monitoring. Every jurisdiction requires ongoing surveillance to detect suspicious activity. None prescribes specific monitoring rules. You build rules based on your risk assessment, your customer base, and the typologies relevant to your business. A wire transfer structuring rule works the same way whether you're filing a FinCEN SAR in the US or reporting to the NCA in the UK.

What to Do Instead

Build one global AML framework with jurisdictional implementation appendices.

Your core framework documents your risk-based approach: how you assess customer risk, calibrate due diligence, monitor transactions, investigate alerts, and decide when to file a Suspicious Activity Report. This framework applies everywhere you operate.

Your implementation appendices document the local requirements: which regulator oversees you, which forms you file, which registers you access, what your reporting thresholds are, and where you maintain records. These are operational details, not strategic decisions.

This structure gives you three advantages:

  1. Consistency: Your customer in London and your customer in New York are assessed using the same risk methodology. Your transaction monitoring rules detect the same typologies. Your investigators apply the same escalation criteria. You're not running parallel compliance universes that produce different outcomes for equivalent risk.

  2. Efficiency: When FinCEN proposed its April 2026 BSA program reform, shifting focus from volume to effectiveness, you don't need to rebuild four programs. You adjust your core framework's documentation to emphasize demonstrated risk mitigation, and you update your US implementation appendix to reflect the new regulatory expectations. The change cascades once, not four times.

  3. Regulatory Credibility: When FATF evaluates a jurisdiction, it assesses whether the framework works in practice. When your regulator examines you, they're asking the same question. A unified framework with clear local implementation shows you understand the substance of what's required. Four disconnected programs suggest you're checking boxes.

When Separate Programs Are Necessary

There are cases where jurisdictional differences genuinely require separate treatment.

  • Legal Entity Structure: If you're operating through separate legal entities in each jurisdiction, each entity needs its own documented program because each entity has its own compliance obligations and its own designated compliance officer. The framework can still be unified, but the accountability structure must reflect the legal reality.

  • Sector-Specific Rules: If you're a bank in one jurisdiction and an investment adviser in another, the regulatory requirements diverge beyond implementation details. FinCEN's 2024 final rule extending BSA requirements to investment advisers, effective January 2028, creates obligations that don't map directly to banking requirements. In that case, you need separate program documentation for separate business lines.

  • Enforcement Context: If you're operating in a jurisdiction with a history of aggressive enforcement and another with minimal supervision, your risk tolerance and documentation depth should reflect that reality. Hong Kong's 2023 FATF follow-up noted progress on DNFBP supervision but identified persistent gaps in cross-border money laundering prosecution. That context affects how you assess residual risk, even if the technical requirements are similar to other jurisdictions.

These are exceptions, not the rule. For most institutions operating across major financial centers, building separate programs creates complexity without adding control.

The question isn't whether jurisdictional differences exist. They do. The question is whether those differences require fundamentally different approaches to detecting and preventing money laundering. They don't.

You Might Also Like