AML/CFT Framework
An AML/CFT framework is the combined set of laws, rules, and controls that require banks and other businesses to detect, prevent, and report money laundering and the financing of terrorism. It brings together government standards and the measures individual institutions must put in place to manage these risks. The exact rules differ from country to country, so what a business must do depends on where it operates.
An AML/CFT (Anti-Money Laundering / Countering the Financing of Terrorism) framework refers to the combined body of standards, laws, regulations, supervisory expectations, and institutional controls that obliged entities across financial and non-financial sectors implement to detect, deter, mitigate, and report money laundering and terrorist financing risk. It is important to note that money laundering and terrorist financing are distinct predicate concerns addressed together within such frameworks, and the two are not interchangeable. At the international level, the FATF Recommendations set out standards (not binding law) intended to support the design of risk-based AML/CFT measures, as reflected in FATF guidance. These standards are given legal effect through jurisdiction-specific instruments and bodies, for example, the EU's AML/CFT framework as supervised and guided by the European Banking Authority, and the US regime under which FinCEN has articulated considerations for an effective, risk-based AML/CFT framework consistent with the AML Act. Because implementation diverges across regimes, the specific obliged entities, thresholds, and obligations captured by any given AML/CFT framework should be confirmed against the applicable national law and supervisory guidance; a framework is a set of measures to manage risk rather than a guarantee against financial crime.
Why it matters
An AML/CFT framework matters because money laundering and terrorist financing are distinct threats that regulators expect obliged entities to address through coordinated, risk-based controls rather than ad hoc measures. Without a coherent framework tying together applicable laws, supervisory expectations, and internal controls, institutions cannot reliably detect, deter, or report the activity that these regimes are designed to capture. The framework provides the structure through which international standards are translated into concrete obligations that a business can actually implement.
Because implementation diverges across jurisdictions, the practical significance of a framework depends heavily on where an institution operates. The FATF Recommendations set out standards intended to support the design of risk-based AML/CFT measures, but these standards are not binding law; they take effect only through jurisdiction-specific instruments and supervisory bodies, such as the EU's AML/CFT framework overseen with input from the European Banking Authority, or the US regime in which FinCEN has articulated considerations for an effective, risk-based framework consistent with the AML Act. The EU reviewed its AML/CFT framework in 2021, illustrating that these regimes evolve and that firms must track changes in the jurisdictions relevant to them.
It is important to treat an AML/CFT framework as a set of measures to manage and mitigate risk, not as a guarantee against financial crime. A well-designed framework improves an institution's ability to identify and report suspicious activity, but it does not eliminate exposure, and the specific obliged entities, thresholds, and obligations captured by any given framework should always be confirmed against the applicable national law and supervisory guidance.
Who it's relevant to
Inside AML/CFT
Common questions
Answers to the questions practitioners most commonly ask about AML/CFT.