Skip to main content
Category: Compliance Program Governance

AML/CFT Framework

Also known as: AML/CFT, Anti-Money Laundering and Countering the Financing of Terrorism Framework, AML/CFT regime, Anti-Money Laundering and Combating the Financing of Terrorism Framework
Simply put

An AML/CFT framework is the combined set of laws, rules, and controls that require banks and other businesses to detect, prevent, and report money laundering and the financing of terrorism. It brings together government standards and the measures individual institutions must put in place to manage these risks. The exact rules differ from country to country, so what a business must do depends on where it operates.

Formal definition

An AML/CFT (Anti-Money Laundering / Countering the Financing of Terrorism) framework refers to the combined body of standards, laws, regulations, supervisory expectations, and institutional controls that obliged entities across financial and non-financial sectors implement to detect, deter, mitigate, and report money laundering and terrorist financing risk. It is important to note that money laundering and terrorist financing are distinct predicate concerns addressed together within such frameworks, and the two are not interchangeable. At the international level, the FATF Recommendations set out standards (not binding law) intended to support the design of risk-based AML/CFT measures, as reflected in FATF guidance. These standards are given legal effect through jurisdiction-specific instruments and bodies, for example, the EU's AML/CFT framework as supervised and guided by the European Banking Authority, and the US regime under which FinCEN has articulated considerations for an effective, risk-based AML/CFT framework consistent with the AML Act. Because implementation diverges across regimes, the specific obliged entities, thresholds, and obligations captured by any given AML/CFT framework should be confirmed against the applicable national law and supervisory guidance; a framework is a set of measures to manage risk rather than a guarantee against financial crime.

Why it matters

An AML/CFT framework matters because money laundering and terrorist financing are distinct threats that regulators expect obliged entities to address through coordinated, risk-based controls rather than ad hoc measures. Without a coherent framework tying together applicable laws, supervisory expectations, and internal controls, institutions cannot reliably detect, deter, or report the activity that these regimes are designed to capture. The framework provides the structure through which international standards are translated into concrete obligations that a business can actually implement.

Because implementation diverges across jurisdictions, the practical significance of a framework depends heavily on where an institution operates. The FATF Recommendations set out standards intended to support the design of risk-based AML/CFT measures, but these standards are not binding law; they take effect only through jurisdiction-specific instruments and supervisory bodies, such as the EU's AML/CFT framework overseen with input from the European Banking Authority, or the US regime in which FinCEN has articulated considerations for an effective, risk-based framework consistent with the AML Act. The EU reviewed its AML/CFT framework in 2021, illustrating that these regimes evolve and that firms must track changes in the jurisdictions relevant to them.

It is important to treat an AML/CFT framework as a set of measures to manage and mitigate risk, not as a guarantee against financial crime. A well-designed framework improves an institution's ability to identify and report suspicious activity, but it does not eliminate exposure, and the specific obliged entities, thresholds, and obligations captured by any given framework should always be confirmed against the applicable national law and supervisory guidance.

Who it's relevant to

Compliance officers at obliged entities
Compliance professionals in financial and non-financial sectors rely on the applicable AML/CFT framework to determine which controls their institution must implement. Because obligations, obliged entities, and thresholds vary by jurisdiction, they must confirm requirements against the national law and supervisory guidance governing where they operate rather than assuming a single global rule applies.
Financial intelligence and investigations teams
Analysts and investigators work within the detection and reporting obligations that a framework establishes. Understanding how international standards translate into jurisdiction-specific requirements helps them apply the correct reporting expectations, while recognising that a framework manages and mitigates risk rather than guaranteeing prevention of financial crime.
Legal and risk professionals
Legal and risk teams must map how non-binding standards such as the FATF Recommendations are given legal effect through instruments and supervisory bodies in each relevant jurisdiction, for example, the EU framework overseen with input from the EBA, or the US regime involving FinCEN and the AML Act. This informs how they assess exposure and advise on evolving requirements, such as the EU's 2021 review of its framework.
Supervisors and policymakers
Supervisory bodies and policymakers design, interpret, and enforce AML/CFT obligations within their jurisdictions, translating international standards into enforceable measures and issuing guidance, such as FinCEN's articulated considerations for an effective, risk-based framework, that shapes how obliged entities implement controls.

Inside AML/CFT

Risk Assessment
A foundational component in which an obliged entity identifies, assesses, and documents the money laundering and terrorist financing risks it faces across customers, products, services, delivery channels, and geographies. It underpins the risk-based approach promoted by the FATF Recommendations and typically informs the calibration of subsequent controls.
Customer Due Diligence (CDD)
Measures to identify and verify the customer and, where applicable, the beneficial owner, and to understand the nature and purpose of the business relationship. CDD is generally distinct from Know Your Customer (KYC) onboarding steps and from Enhanced Due Diligence (EDD), which applies additional scrutiny in higher-risk situations such as certain PEP or high-risk jurisdiction scenarios.
Ongoing Monitoring
The continuous scrutiny of transactions and customer activity over the life of a relationship to ensure consistency with the entity's knowledge of the customer and their risk profile. This may include transaction monitoring systems and periodic reviews, and is a measure to detect and manage risk rather than a guarantee of prevention.
Sanctions and PEP Screening
Screening processes that check customers and transactions against sanctions lists and against politically exposed person (PEP) status. Sanctions screening and PEP screening are separate functions with different legal bases and consequences; a screening match is an indicator warranting review, not proof of wrongdoing.
Suspicious Activity Reporting
The obligation to report suspicious activity to the relevant financial intelligence unit (FIU). Terminology varies by jurisdiction, with a Suspicious Activity Report (SAR) used under some regimes such as the US Bank Secrecy Act and the UK framework, and a Suspicious Transaction Report (STR) used in others. A filing reflects suspicion and does not establish criminal conduct.
Record Keeping
Requirements to retain due diligence records, transaction records, and related documentation for a period specified by the applicable regulation, so that they are available to competent authorities. Exact retention periods vary by jurisdiction and should be confirmed against the governing rules.
Governance and Internal Controls
The organizational arrangements supporting the framework, which may include a designated compliance officer or nominated officer, policies and procedures, staff training, and independent audit. These elements are typically expected of obliged entities, though the specific requirements differ across regimes.

Common questions

Answers to the questions practitioners most commonly ask about AML/CFT.

Do the FATF Recommendations function as binding law that obliged entities must follow directly?
No. The FATF Recommendations are international standards, not binding law in themselves. They set out what countries are expected to implement, but they only create enforceable obligations for obliged entities once a jurisdiction transposes them into its own legal instruments, for example, the EU AML Directives and the AML Regulation, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations and the Proceeds of Crime Act. Because transposition varies, the specific requirements that apply to a given firm depend on the regimes to which it is subject, and exact obligations should be confirmed against the applicable law.
Is there a single global AML/CFT framework that applies uniformly across all jurisdictions?
No. While the FATF Recommendations provide a common reference point that promotes consistency, there is no single global rule set that applies identically everywhere. Regimes diverge on thresholds, the scope of obliged entities, defined terms, and the balance between money laundering and terrorist financing measures. A framework that satisfies one jurisdiction's requirements may not satisfy another's, so firms operating across borders generally need to map obligations regime by regime rather than assuming a universal standard.
What core components does an AML/CFT framework typically include?
Frameworks generally combine governance and accountability, a documented risk assessment, customer due diligence measures (including CDD and, where warranted, EDD), ongoing monitoring, screening processes such as sanctions and PEP screening, suspicious activity or transaction reporting, record-keeping, training, and independent testing or audit. The precise composition and terminology depend on the applicable regime, and firms should tailor components to their assessed risk rather than treating any list as exhaustive.
How should a firm decide where to apply enhanced due diligence within its framework?
Under a risk-based approach, EDD is typically applied where a customer, product, geography, or transaction presents higher assessed risk, rather than uniformly across the book. Many regimes specify certain situations where EDD is generally required, such as dealings involving higher-risk jurisdictions or PEPs, while leaving other higher-risk scenarios to the firm's own assessment. Firms should document the rationale for their risk ratings and the corresponding measures, and confirm any mandatory EDD triggers against the specific regulation that applies to them.
How does the risk-based approach shape the design of an AML/CFT framework?
The risk-based approach means controls are calibrated to the money laundering and terrorist financing risks a firm faces, so that resources are focused where risk is higher and simplified measures may be applied where risk is lower and permitted. It informs the risk assessment, customer due diligence intensity, monitoring rules, and screening scope. These measures are intended to detect, deter, and mitigate risk; they manage rather than eliminate it, and no single control guarantees prevention of financial crime.
What is the relationship between suspicious activity reporting and the rest of the framework?
Reporting is one output of the framework, generally triggered when monitoring, screening, or other processes surface activity that meets the applicable suspicion threshold. Terminology and mechanics differ by jurisdiction, for example, a SAR under US and UK regimes versus an STR in others, as do the reporting body and the point at which a report must be made. Importantly, filing a report reflects a compliance obligation to disclose suspicion; it does not establish that any wrongdoing has occurred, and firms should confirm the exact reporting standard and process against their governing regime.

Common misconceptions

An AML/CFT framework prevents financial crime.
Controls within an AML/CFT framework are designed to detect, deter, mitigate, and manage financial crime risk, not to guarantee prevention. No single control eliminates risk, and the risk-based approach acknowledges that residual risk remains.
There is one uniform global set of AML/CFT rules that applies identically everywhere.
The FATF Recommendations are international standards, not binding law. Actual obligations derive from national and regional instruments, such as the EU AML Directives and AML Regulation, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations and Proceeds of Crime Act, which diverge in scope, thresholds, and terminology.
Money laundering and terrorist financing controls are the same thing addressing the same risk.
While often addressed within a combined framework, money laundering and terrorist financing are distinct. Money laundering typically concerns disguising the proceeds of crime, whereas terrorist financing may involve funds from legitimate as well as illicit sources; the two can require different detection approaches even where controls overlap.

Best practices

Ground the framework in a documented, entity-specific risk assessment and use it to calibrate the intensity of CDD, EDD, and ongoing monitoring rather than applying uniform controls to all customers.
Map each control to its correct source obligation for the jurisdictions in which you operate, and confirm exact thresholds and retention periods against the applicable regulation rather than assuming a single standard applies.
Keep sanctions screening and PEP screening as distinct processes with defined escalation paths, treating matches as indicators warranting review rather than as evidence of wrongdoing.
Ensure suspicious activity or transaction reporting procedures reflect the terminology and filing requirements of the relevant financial intelligence unit, and train staff that a filing reflects suspicion, not established criminal conduct.
Maintain governance elements such as a designated compliance or nominated officer, current policies and procedures, ongoing training, and independent audit to keep the framework effective and evidenced.
Review and update the framework periodically and in response to changes in risk, products, or regulatory expectations, documenting the rationale for control decisions.