Skip to main content
Category: Compliance Program Governance

Anti-Money Laundering and Countering the Financing of Terrorism

Also known as: AML/CFT, AML/CTF, Anti-Money Laundering / Countering the Financing of Terrorism, AML and CFT measures
Simply put

AML/CFT refers to the combined set of laws, regulations, and controls designed to stop criminals and terrorists from abusing the financial system. The anti-money laundering (AML) side targets efforts to disguise proceeds of crime as legitimate funds, while the countering the financing of terrorism (CFT) side targets the movement of funds used to support terrorism. Although the two are commonly addressed together, they are distinct objectives and are implemented differently across jurisdictions.

Formal definition

AML/CFT denotes the framework of measures intended to detect, deter, and disrupt the abuse of the financial system for money laundering and terrorist financing. Money laundering generally involves making the proceeds of criminal activity appear to have been legally obtained, whereas terrorist financing concerns the provision or collection of funds to support terrorism and may involve funds of either illicit or legitimate origin; the two are related but not identical concepts and are typically subject to separate legal and operational treatment. The applicable obligations derive from distinct instruments depending on jurisdiction, for example, the FATF Recommendations operate as international standards rather than binding law, the EU's common AML/CFT rules are developed and enforced through bodies such as AMLA (which also directly supervises selected high-risk financial institutions and coordinates supervisory work), and in the United States the requirements are commonly implemented through the Bank Secrecy Act and related regulations. Because regimes diverge on scope, obliged entities, and specific requirements, no single uniform global rule applies, and precise obligations should be confirmed against the relevant regulation.

Why it matters

AML/CFT frameworks exist because the financial system can be exploited by those seeking to disguise the proceeds of crime or to move funds in support of terrorism. As the FATF describes it, the purpose of implementing these measures is to stop criminals and terrorists from abusing the financial system. When controls are weak or inconsistently applied, illicit funds can pass through banks, payment providers, and other channels with reduced likelihood of detection, undermining the integrity of institutions and markets. For compliance professionals, a robust AML/CFT program is therefore a central mechanism for detecting, deterring, and disrupting this abuse, though no single control eliminates financial crime risk, and these measures manage rather than guarantee against it.

Who it's relevant to

Compliance officers and MLROs
Those responsible for designing and operating AML/CFT programs must align institutional controls with the specific obligations of their jurisdiction, whether framed under the BSA in the United States, the EU's common rules enforced through AMLA, or another regime. Because AML and CFT are distinct objectives with different operational treatment, they should confirm precise requirements against the applicable regulation rather than assuming a single uniform global standard applies.
Financial intelligence analysts and investigators
Analysts working to detect suspicious activity need to understand that money laundering (disguising proceeds of crime as legitimate funds) and terrorist financing (which may involve funds of either illicit or legitimate origin) present different patterns and may require different analytical approaches, even where they are monitored within a combined program.
Supervised financial institutions
Banks and other obliged entities operate within these frameworks and may be subject to direct supervision, for example, AMLA directly supervises selected high-risk financial institutions in the EU. The scope of obligations, including which entities are covered, varies by jurisdiction and should be confirmed against the relevant rules.
Legal and risk professionals
Those advising on regulatory exposure must distinguish between binding law and international standards, given that the FATF Recommendations operate as standards rather than binding law while instruments such as the BSA and EU rules carry direct legal force in their respective jurisdictions.

Inside AML/CFT

Anti-Money Laundering (AML)
The set of measures, controls, and obligations designed to detect, deter, and disrupt the process by which proceeds of criminal activity are disguised to appear legitimate. AML frameworks typically address the conceptual model of placement, layering, and integration, though this model is an explanatory tool rather than a legal test.
Countering the Financing of Terrorism (CFT)
Measures aimed at preventing funds, whether from legitimate or illicit sources, from being used to support terrorism or terrorist organizations. CFT differs conceptually from AML because terrorist financing may involve clean funds moving toward an illicit purpose, whereas money laundering generally involves illicit funds being made to appear clean.
Standard-Setting Body
The Financial Action Task Force (FATF) issues the internationally recognized Recommendations that shape AML/CFT expectations. These Recommendations are standards, not binding law; jurisdictions implement them through their own legislation and regulation, which may diverge in scope and detail.
National Legal Frameworks
AML/CFT obligations derive from jurisdiction-specific instruments such as the US Bank Secrecy Act and FinCEN rules, the EU AML Directives and the AML Regulation, and the UK Money Laundering Regulations together with the Proceeds of Crime Act. Requirements, thresholds, and defined terms vary across these regimes.
Obliged Entities
The persons and institutions subject to AML/CFT obligations, which commonly include banks and other financial institutions and, in many jurisdictions, designated non-financial businesses and professions. The precise scope of who is captured depends on the applicable national regime.
Customer Due Diligence (CDD)
The process of identifying and verifying customers and understanding the nature and purpose of the relationship. CDD is distinct from broader KYC processes and from Enhanced Due Diligence (EDD), which applies additional scrutiny in higher-risk situations.
Risk-Based Approach
The principle that obliged entities allocate resources and apply controls proportionate to assessed risk. Controls are intended to detect, deter, mitigate, and manage financial crime risk rather than to guarantee its elimination.
Suspicious Activity Reporting
The obligation to report suspicious activity to the relevant financial intelligence unit. Terminology differs by jurisdiction, for example, a Suspicious Activity Report (SAR) in some regimes versus a Suspicious Transaction Report (STR) in others. A filing reflects suspicion for compliance purposes and does not itself establish criminal wrongdoing.
Screening Controls
Measures such as sanctions screening and politically exposed person (PEP) screening, which serve distinct purposes and should not be treated as interchangeable. A screening match is an indicator requiring review, not proof of a violation or wrongdoing.

Common questions

Answers to the questions practitioners most commonly ask about AML/CFT.

Are AML and CFT just two labels for the same thing?
No. Although they are frequently combined into a single framework and share many controls, anti-money laundering (AML) and countering the financing of terrorism (CFT) address distinct risks. Money laundering typically involves disguising the illicit origin of funds that are already proceeds of crime, whereas terrorist financing concerns the provision or collection of funds to be used for terrorism, and those funds may derive from entirely legitimate sources. Because the funds in terrorist financing can be lawful in origin and often move in smaller amounts, some detection techniques that focus on tracing the criminal origin of value are less effective, and CFT programs may rely more heavily on sanctions screening, contextual indicators, and intelligence. The FATF Recommendations address both, but they are treated as related, not identical, objectives.
Does implementing an AML/CFT program prevent financial crime?
No. An AML/CFT program is designed to detect, deter, mitigate, and manage the risk of money laundering and terrorist financing, not to guarantee their prevention. Even a well-resourced, risk-based program that meets applicable regulatory expectations cannot eliminate financial crime risk entirely. Controls such as customer due diligence, transaction monitoring, and screening reduce exposure and improve the likelihood of identifying suspicious activity, but they operate on a risk-based rather than an absolute basis and are constrained by available information, resources, and the sophistication of bad actors. Regulators generally expect reasonable, proportionate measures rather than perfect outcomes.
How should an organization decide which AML/CFT obligations apply to it?
The starting point is to determine whether the organization is an obliged entity under the applicable regime, since AML/CFT obligations attach to defined categories of businesses rather than to everyone. The specific obligations depend on the jurisdiction and the applicable source instruments, such as the US Bank Secrecy Act and FinCEN rules, the EU AML Directives or AML Regulation, or the UK Money Laundering Regulations and the Proceeds of Crime Act. Because requirements, thresholds, and covered sectors differ between regimes, an organization operating across borders should map its activities against each applicable framework rather than assume a single global standard applies, and confirm the precise obligations against the relevant regulation.
What are the core components typically found in an AML/CFT program?
In many jurisdictions, an AML/CFT program is generally expected to include a documented risk assessment, internal policies and controls proportionate to that risk, customer due diligence measures (including enhanced measures for higher-risk situations), ongoing transaction monitoring, sanctions and where relevant PEP screening, mechanisms for reporting suspicious activity to the relevant authority, recordkeeping, a designated compliance function or officer, staff training, and independent testing or audit. The exact required elements, their form, and terminology vary by regime, so organizations should confirm the specific mandated components against the applicable regulation rather than assume a uniform checklist.
How does the risk-based approach shape day-to-day AML/CFT implementation?
Under the risk-based approach reflected in the FATF Recommendations and adopted in many national regimes, obliged entities are generally expected to identify and assess their money laundering and terrorist financing risks and then allocate resources and controls in proportion to those risks. Operationally, this means applying more intensive measures, such as enhanced due diligence, to higher-risk customers, products, or geographies, and potentially simplified measures where lower risk is justified and permitted. The approach is intended to manage and mitigate risk efficiently rather than to eliminate it, and it requires documentation of the rationale so that decisions can be explained to regulators. The precise expectations for how risk is assessed and evidenced should be confirmed against the applicable regime.
Does filing a suspicious activity report mean the customer has committed a crime?
No. A suspicious activity report (SAR) or, in some jurisdictions, a suspicious transaction report (STR) reflects a compliance obligation to report activity that meets the applicable reporting standard, which is generally based on suspicion or reasonable grounds rather than on proof. Filing such a report does not establish that money laundering, terrorist financing, or any other offense has occurred; it refers the matter to the relevant authority, such as a financial intelligence unit, for further assessment. The compliance meaning of a report is distinct from any criminal-law determination, which is a matter for competent authorities and courts. Reporting thresholds and terminology differ between regimes and should be confirmed against the applicable rules.

Common misconceptions

AML and CFT are the same discipline addressing the same risk.
Although frequently combined operationally, they target different phenomena. AML generally addresses illicit funds being disguised as legitimate, while CFT addresses funds, potentially from legitimate sources, moving toward terrorist purposes. The typologies, indicators, and analytical approaches can differ accordingly.
The FATF Recommendations are a single set of binding global rules.
The FATF Recommendations are international standards, not directly enforceable law. Jurisdictions implement them through their own instruments, and requirements such as scope, thresholds, and definitions may diverge. Practitioners should confirm obligations against the applicable national regime rather than assuming a uniform global rule.
Filing a suspicious activity report or generating a screening match confirms that a crime has occurred.
A SAR/STR filing or a sanctions or PEP screening match reflects suspicion or a potential concern within a compliance process. It does not establish criminal wrongdoing, which is a matter for competent authorities to determine through separate legal processes.

Best practices

Apply a documented risk-based approach that allocates due diligence and monitoring resources proportionately to assessed risk, and record the rationale behind risk ratings and control decisions.
Map each AML/CFT obligation to its correct source instrument and supervising body for every jurisdiction in which you operate, recognizing that FATF standards are implemented differently across national regimes.
Maintain clear distinctions in policies and systems between related concepts, CDD versus EDD, sanctions versus PEP screening, and SAR versus STR terminology, so that controls are applied correctly for their intended purpose.
Treat screening matches and internal alerts as items requiring review and adjudication rather than as findings of wrongdoing, and document the investigative steps and disposition for each.
Confirm exact thresholds, timelines, and defined terms against the current text of the applicable regulation, since these values vary by regime and change over time.
Frame controls internally as measures to detect, deter, mitigate, and manage financial crime risk, avoiding any representation that a single control eliminates risk entirely.