Skip to main content
Category: Compliance Program Governance

Written Policies and Procedures

Also known as: Policies and Procedures, P&P, Policies, Procedures and Processes
Simply put

Written policies and procedures are documents that set out an organization's rules and the step-by-step actions its staff are expected to follow. Policies express the overarching framework, standards, and expectations that govern behavior and decision-making, while procedures describe the specific actions taken to carry those policies out. Together they aim to bring clarity to internal processes and help ensure work is performed consistently.

Formal definition

A distinction should be drawn between the two components. A policy is a written statement that establishes the overarching framework for organizational requirements, standards of expectation, and decision-making, and may mandate, specify, or prohibit particular behavior to express an organization's basic values. A procedure describes the actions or steps taken to implement and comply with that policy. In practice, a documented set of policies and procedures typically addresses matters such as organizational mission and structure and administrative processes, and functions to make internal processes clear and to promote consistent execution. The scope and required content of any specific policies and procedures depend on the applicable framework; the evidence here reflects general organizational and drafting guidance rather than the requirements of any particular AML regime, and specific regulatory obligations should be confirmed against the relevant regulation.

Why it matters

Written policies and procedures form the documented backbone of how an organization expects its staff to behave and act. Policies establish the overarching framework for organizational requirements, standards of expectation, and decision-making, while procedures translate those standards into the specific actions staff take day to day. Without this documentation, expectations remain implicit and open to individual interpretation, which undermines the consistency that organizations depend on to operate reliably.

Because policies express an organization's basic values and may mandate, specify, or prohibit particular behavior, they serve as a reference point for both routine work and difficult judgment calls. Clear, well-drafted procedures bring clarity to internal processes and help ensure that work is carried out the same way regardless of who performs it. This consistency is valuable not only for operational quality but also for demonstrating, when required, that an organization has a defined and repeatable approach to its obligations.

It should be noted that the scope and required content of any specific set of policies and procedures depend on the applicable framework. The guidance reflected here is general organizational and drafting guidance rather than the requirements of any particular AML regime. Where policies and procedures are used to satisfy regulatory obligations, the precise expected content should be confirmed against the relevant regulation, as requirements differ across jurisdictions and instruments.

Who it's relevant to

Compliance Officers and Program Owners
Those responsible for designing and maintaining a compliance program rely on written policies and procedures to define expected standards and translate them into repeatable steps. They are typically accountable for ensuring the documents establish a clear framework, describe the actions staff must take, and are kept current. Where documents support obligations under a specific regime, the required content should be confirmed against the applicable regulation.
Front-Line and Operational Staff
Employees who carry out day-to-day work depend on procedures to know the specific actions and steps expected of them. Clear procedures help ensure work is performed consistently and reduce reliance on individual interpretation, supporting more consistent execution across teams.
Senior Management and Governance Bodies
Leadership and oversight bodies use policies to express the organization's basic values, standards of expectation, and decision-making framework. Policies serve as the reference point against which behavior and organizational conduct are set and measured.
Auditors and Internal Reviewers
Those testing whether processes operate as intended use written policies and procedures as the documented benchmark for expected behavior and action. The documents provide a defined standard against which actual practice can be assessed for consistency.

Inside Written Policies and Procedures

Risk Assessment Linkage
A documented connection between the policies and the entity's assessment of its money laundering and terrorist financing risks, so that the depth and nature of controls reflect the risks identified across customers, products, geographies, and delivery channels. Under a risk-based approach, procedures are generally expected to be calibrated to assessed risk rather than applied uniformly.
Customer Due Diligence Procedures
Operational steps for conducting CDD, and where warranted, EDD for higher-risk relationships, including customer identification and verification, understanding the nature and purpose of the relationship, and ongoing monitoring. The precise requirements depend on the applicable regime (for example, FinCEN rules under the BSA, the UK Money Laundering Regulations, or EU AML instruments).
Transaction Monitoring and Reporting Processes
Defined processes for monitoring activity, escalating unusual activity internally, and filing suspicious activity or suspicious transaction reports to the relevant authority. Terminology and filing mechanics differ by jurisdiction (for example, SARs to FinCEN in the US, SARs to the NCA under POCA in the UK, and STRs in many other regimes).
Sanctions and Screening Procedures
Instructions for screening against applicable sanctions lists and, separately, for PEP identification and handling. Sanctions screening and PEP screening serve distinct purposes and should be documented as separate control activities rather than treated as one process.
Governance and Roles
Assignment of responsibilities, including the role of a designated compliance officer or equivalent function where required, and the involvement of senior management and the board in approving and overseeing the framework. Specific role requirements vary by regime and by type of obliged entity.
Record-Keeping Provisions
Rules for retaining CDD records, transaction records, and documentation of decisions, typically for a period specified by the applicable regulation. Exact retention periods should be confirmed against the relevant law rather than assumed to be uniform.
Training and Escalation Protocols
Provisions for staff training and for internal escalation of concerns, so that personnel understand their obligations and know how to raise and route potential issues. These are typically operational components supporting, but distinct from, the formal reporting obligation.
Independent Testing and Review
Arrangements for periodic independent testing or audit of the program and for updating the policies as risks, products, or regulatory requirements change. This supports the ongoing effectiveness of the framework rather than guaranteeing prevention of financial crime.

Common questions

Answers to the questions practitioners most commonly ask about Written Policies and Procedures.

Are written policies and procedures the same thing, or do they serve different functions?
They are related but distinct components and should not be treated as interchangeable. Policies generally articulate an obliged entity's high-level commitments, risk appetite, and governing principles for managing money laundering and terrorist financing risk, while procedures typically translate those policies into the specific, operational steps staff follow to carry them out. Many AML programs also distinguish a further layer of controls, processes, or work instructions. The precise terminology and expected structure can vary by jurisdiction and by the supervisory expectations applying to a given sector, so the exact boundaries should be confirmed against the applicable regulatory framework and guidance.
Does having written policies and procedures in place mean an entity is compliant or protected from enforcement?
No. Documentation is a foundational element of an AML program, but its existence alone does not establish compliance. Supervisors and examiners in many jurisdictions assess whether policies and procedures are risk-appropriate, kept current, actually implemented, understood by staff, and effective in operation. Written measures are tools to help detect, deter, and manage financial crime risk; they do not guarantee prevention, and a documented framework that is not applied in practice may itself be a source of regulatory criticism. Whether a specific program meets an obligation depends on the applicable rules and how the framework functions in reality.
Who within an organization is typically responsible for approving and maintaining written policies and procedures?
Responsibility is usually allocated across governance layers rather than resting with a single role. In many frameworks, senior management or the board is expected to approve or endorse core AML policies and set the tone for compliance, while a designated compliance function or officer often owns the drafting, day-to-day maintenance, and updating of procedures. The specific titles, approval requirements, and accountability expectations differ by jurisdiction and by the size and nature of the obliged entity, so the applicable regulation and supervisory guidance should be consulted to confirm who must sign off and who must maintain the documents.
How often should written policies and procedures be reviewed and updated?
There is no universal frequency that applies across all regimes. Many programs conduct periodic reviews on a defined cycle and additionally update documentation on a triggered basis, for example following changes in the applicable law, the entity's risk assessment, its products, customers, or geographic exposure, or in response to findings from audits, examinations, or internal testing. The expectation is generally that policies and procedures remain current and aligned with the entity's actual risk profile. Any specific required review interval should be confirmed against the relevant regulatory framework and supervisory expectations.
How should written policies and procedures reflect a risk-based approach?
In many AML frameworks, written policies and procedures are expected to be proportionate to and informed by the entity's own risk assessment, so that higher-risk customers, products, services, delivery channels, or geographies are addressed with correspondingly more robust measures. This typically means procedures describe how risk is assessed and how differentiated measures, such as standard due diligence versus enhanced due diligence, are applied. The documentation should describe measures to detect and manage risk rather than present controls as eliminating it, and the required degree of granularity varies by sector and jurisdiction.
How should an entity ensure that written policies and procedures are actually implemented by staff?
Documentation is generally expected to be supported by mechanisms that put it into practice, which in many programs include staff training on the relevant procedures, accessible internal communication of updates, and monitoring or testing to assess whether the documented measures are being followed. Independent audit or compliance testing is commonly used to identify gaps between what is written and what occurs operationally. The specific implementation and oversight expectations depend on the applicable rules and the entity's size and risk profile, and should be confirmed against the governing regulatory framework.

Common misconceptions

A single set of written policies satisfies obligations across all jurisdictions because AML rules are globally uniform.
Requirements diverge by regime. The FATF Recommendations are standards rather than binding law, and they are implemented differently through instruments such as the EU AML Directives and Regulation, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations and Proceeds of Crime Act. Policies generally need to reflect the specific obligations applicable to the entity.
Having written policies and procedures in place prevents money laundering and financial crime.
Written policies are measures designed to detect, deter, mitigate, and manage risk. They do not guarantee prevention, and no single control eliminates financial crime risk. Their value depends on being risk-calibrated, implemented, and kept current.
Written policies can be drafted once and left unchanged.
Policies are generally expected to be reviewed and updated as the entity's risk profile, products, and applicable regulatory requirements change, and to be supported by independent testing to assess whether they remain fit for purpose.

Best practices

Anchor the policies to the entity's documented risk assessment so that CDD, EDD, and monitoring measures are calibrated to assessed risk rather than applied uniformly.
Map each procedure to its source obligation and applicable regime, confirming specific thresholds, retention periods, and filing mechanics against the relevant regulation rather than assuming they are the same everywhere.
Document sanctions screening and PEP screening as distinct processes, and keep CDD, EDD, and suspicious activity or transaction reporting steps clearly differentiated.
Define clear governance, roles, and internal escalation routes, including any designated compliance function required by the applicable regime, with appropriate senior management and board oversight.
Establish a schedule for periodic review, independent testing, and updates triggered by changes in risk, products, or regulatory requirements.
Ensure reporting procedures make clear that filing a report or generating an alert does not itself establish wrongdoing, and provide staff training so personnel understand and can apply the procedures.