Umbragarde Confidential enquiry
Home/AML Compliance Guide
AML compliance

Anti-money laundering compliance that holds up under scrutiny.

Ticking the box is not the same as managing the risk. This guide covers what a defensible AML programme actually requires — and where most compliance failures occur in practice.

Risk-based approachEffort proportionate to risk — but risk must be assessed, not assumed.
EDD for complex casesPEPs, high-risk jurisdictions, opaque structures.
Beyond the listSanctions screening that covers indirect and derivative exposure.
The guide

What AML compliance actually requires.

Anti-money laundering compliance is one of those areas where the paper trail can look complete while the substance is missing. Regulators have been saying this for fifteen years — and still find the same failures in almost every enforcement action. The gap is rarely in the policy document. It is in the judgment: who counts as high risk, what constitutes adequate source-of-funds evidence, when enhanced diligence is genuinely triggered rather than formally avoided.

This guide covers the components of a defensible AML programme, the failure modes regulators consistently find, and where OSINT-grade intelligence fills the gaps that automated screening leaves open.

The legal framework (UK)

The primary legislation in the UK is the Proceeds of Crime Act 2002 (POCA) and the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), as amended by the 2019 and 2022 Regulations. The MLR 2017 implement the EU's Fourth and Fifth Anti-Money Laundering Directives into UK law.

Firms within scope must register with their supervisory authority (FCA for financial services, HMRC for accountants, estate agents, high-value dealers and others), maintain a risk assessment, apply CDD and EDD procedures, screen for sanctions and PEPs, appoint a nominated officer (MLRO), train staff, and file Suspicious Activity Reports (SARs) with the National Crime Agency where required.

POCA creates three principal offences: arranging or facilitating money laundering, acquiring criminal property, and failing to disclose knowledge or suspicion of money laundering where there is a duty to do so. Tipping off a subject that a SAR has been filed is a separate offence.

The risk assessment

The foundation of any AML programme is a business-wide risk assessment that identifies the specific money laundering risks arising from the firm's products, client base, delivery channels and geographies. The assessment must be documented, reviewed regularly, and calibrated to the actual business — not copied from a template that describes a different one.

A risk assessment that rates all customers as medium risk without supporting analysis is not a risk-based approach. It is an avoidance of one. Regulators treat it accordingly.

Factors that typically elevate risk: clients from high-risk jurisdictions (FATF grey or black list, or jurisdictions with weak AML frameworks), complex or opaque corporate structures, politically exposed persons or their associates, high-value or cash-intensive transactions, and industries with elevated exposure to financial crime — real estate, luxury goods, professional services, crypto.

Customer due diligence (CDD)

CDD is the baseline process for every new client relationship. It requires:

  • Identity verification — verifying the customer is who they say they are, using reliable, independent documents or data
  • Beneficial ownership — identifying and verifying the ultimate beneficial owners of corporate clients (typically those with more than 25% ownership or control, though risk-based judgment may require going further)
  • Purpose and nature of the relationship — understanding what the client intends to use the relationship for and what transactions to expect
  • Ongoing monitoring — reviewing the relationship and its transactions for consistency with what was disclosed at onboarding

The standard of CDD is not fixed — it is proportionate to the risk. Simplified due diligence may apply for certain low-risk customers; enhanced due diligence is mandatory for those presenting higher risk.

Enhanced due diligence (EDD)

EDD is mandatory for politically exposed persons (PEPs), customers from high-risk third countries (as designated by the FCA or EU), and any relationship or transaction that presents higher money laundering risk by nature. It is also good practice — and increasingly expected — for any customer where the standard CDD leaves material questions unanswered.

EDD requires:

  • Additional verification of identity and, critically, source of funds and source of wealth
  • Senior management approval for the relationship
  • More frequent and more substantive ongoing monitoring
  • Documentation of the reasoning that the risk is acceptable

Source of funds is not the same as source of wealth. Source of funds means: where did the specific money in this transaction come from? Source of wealth means: how did this person accumulate their overall assets? Both questions need answers in an EDD context, and database checks rarely provide them.

Sanctions screening

Sanctions compliance is a separate legal requirement from AML — and increasingly a more acute one, given the volume of new designations since 2022. Sanctions screening must cover:

  • The customer directly — name, aliases, date of birth, nationality
  • Beneficial owners and controllers of corporate customers
  • The lists that apply to your jurisdiction — OFAC (US), OFSI (UK), EU Consolidated List, UN — and any jurisdiction-specific requirements for your client base
  • Ongoing screening — designations happen between onboarding events; real-time or frequent rescreening is required for higher-risk relationships

List screening alone is insufficient. Sophisticated structures use nominees, trusts, and offshore vehicles to place sanctioned individuals at a distance from named accounts. OSINT-grade sanctions diligence maps the ownership and control chain, not just the named parties.

The failure modes regulators keep finding

Enforcement actions and supervisory reviews consistently identify the same deficiencies. Knowing them is the first step to avoiding them.

  • Generic risk assessments — the document describes the industry, not the business. No firm-specific analysis of client risk, product risk or geographic exposure.
  • CDD that verifies identity but not source of funds — knowing who someone is does not establish whether their money is clean. Source of funds is a separate and harder question.
  • EDD triggered too narrowly — PEP screening that misses second-tier PEPs (family members, close associates), or that treats PEP status as lapsing on leaving office. The risk does not disappear when the mandate ends.
  • Sanctions screening that is list-only — names match lists; ownership structures that deliver economic benefit to designated persons do not. Indirect and derivative sanctions exposure requires analysis, not just matching.
  • Monitoring that is periodic rather than event-driven — annual reviews miss the significant change that happened in month three. Monitoring should be triggered by events — a transaction outside the established pattern, a change in beneficial ownership, adverse media — not just by a calendar date.
  • MLRO without authority or resource — the role exists on paper, the person in it has no budget, no access to senior management and no real independence. SAR decisions are influenced by commercial considerations.

Where OSINT-grade intelligence fills the gap

Automated AML screening — database checks, list matching, adverse media alerts — is a floor, not a ceiling. It catches what is already recorded; it misses what is not yet formalised, what is in local-language sources, what is obscured by structure.

OSINT-based due diligence extends the picture: mapping the full beneficial ownership chain through corporate registries across multiple jurisdictions, identifying adverse reporting in press that did not reach global news wires, finding the court proceedings that predate the current entity name, and establishing whether the source-of-wealth narrative is consistent with what the open record shows.

For higher-risk onboarding decisions — a significant investor, a counterparty in a complex transaction, a client from a jurisdiction where the registry is opaque — OSINT-grade intelligence is not a supplement to automated screening. It is the substantive work that automated screening cannot do.

Common questions

AML compliance, answered.

What is AML compliance?

AML compliance is the set of policies, controls and procedures a business maintains to detect and prevent money laundering and terrorist financing. Core components are a risk assessment, customer due diligence, enhanced due diligence for higher-risk relationships, sanctions screening, ongoing monitoring and suspicious activity reporting.

What does a risk-based AML programme require?

A business-wide risk assessment identifying your specific risks; CDD procedures calibrated to those risks; EDD for PEPs, high-risk jurisdictions and complex structures; sanctions screening at onboarding and ongoing; a nominated MLRO; staff training; and a SAR filing process. Risk-based means effort is proportionate to risk — but low-risk classification must be supportable, not assumed.

What is the difference between CDD and EDD?

CDD is the baseline: verify identity, understand the purpose of the relationship. Enhanced due diligence applies where risk is higher — PEPs, high-risk jurisdictions, opaque structures. EDD requires deeper verification of source of funds and wealth, senior management approval, and more frequent review.

Who needs AML compliance in the UK?

The Money Laundering Regulations 2017 apply to credit and financial institutions, accountants, tax advisers, auditors, insolvency practitioners, legal professionals handling certain work, estate agents, high-value dealers (over €10,000 cash), casino operators and trust or company service providers. Beyond legal obligation, any business with significant counterparty exposure needs a defensible process.

What are the most common AML compliance failures?

Regulators consistently find: generic risk assessments; CDD that verifies identity but not source of funds; EDD triggered too narrowly; sanctions screening that is list-only and misses derivative exposure; monitoring that is periodic rather than event-driven; and MLRO roles without real authority or resource.

How does OSINT support AML compliance?

OSINT-based due diligence extends AML beyond what databases contain: mapping beneficial ownership across multiple registries, identifying adverse media in local-language sources, finding court proceedings under prior entity names, and testing whether source-of-wealth narratives are consistent with the open record.

Related

AML in practice.

Need OSINT-grade AML diligence on a counterparty?

One confidential message is enough. Tell us only what you are comfortable sharing — we take it from there.

Make a confidential enquiry