---
# === IDENTITY ===
id: compliance/financial/aml-kyc-framework/2026
canonical_question: "What are the AML/KYC requirements for financial services companies?"
aliases:
  - "Anti-money laundering compliance requirements"
  - "Know Your Customer obligations for banks"
  - "AML program requirements for financial institutions"
  - "KYC CDD EDD regulatory framework"
entity_type: rule
domain: compliance > financial > AML/KYC Framework
region: global
jurisdiction: global
temporal_scope: 2020-2026

# === VERIFICATION ===
last_verified: 2026-05-31
confidence: 0.92
version: 1.2
first_published: 2026-03-01

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: evolving
  last_breaking_change: "2025-12-31"
  next_review: 2026-08-29
  change_sensitivity: high

# === RULE SCOPE ===
applies_to:
  domain: "compliance > financial"
  price_range: null
  user_segment: "Financial institutions, banks, fintechs, VASPs, insurance companies, investment advisers, designated non-financial businesses and professions (DNFBPs)"
  context: "Global AML/KYC compliance — covers FATF standards, US BSA/AML, and EU AML framework as the three primary regulatory pillars"

# === CONSTRAINTS ===
# Hard boundaries on when this rule applies. Agents: read before recommending.
constraints:
  - "Jurisdiction-specific: exact thresholds, filing deadlines, and penalties vary by country. This unit covers FATF global standards, US (BSA/AML), and EU (AMLR/6AMLD) frameworks — other jurisdictions may diverge."
  - "Temporal: EU AMLR/6AMLD applies from July 10, 2027. US FinCEN investment adviser AML rule effective January 1, 2028. FATF 5th round mutual evaluations running 2024-2027."
  - "Entity threshold: not all entities are 'obliged entities.' Scope depends on jurisdiction — e.g., EU AMLR expanded to crypto-asset providers, football clubs, and high-value goods dealers in 2024."
  - "Prerequisite: organizations must have a designated compliance officer (BSA Officer in the US, MLRO in the UK/EU) before implementing a compliant program."
  - "Interaction: AML/KYC intersects with sanctions screening (OFAC, EU sanctions), data privacy (GDPR limits on data retention), and tax reporting (FATCA/CRS). Conflicts must be resolved jurisdiction by jurisdiction."

# === SKIP CONDITIONS ===
skip_this_unit_if:
  - condition: "Question is about EU payment-services or open-banking obligations (SCA, TPP licensing, PSD2 APIs) rather than AML/KYC"
    use_instead: "compliance/financial/psd2-open-banking/2026"
  - condition: "Question is about investment-firm conduct rules (best execution, inducements, product governance) rather than AML/KYC"
    use_instead: "compliance/financial/mifid-ii/2026"
  - condition: "Question is only about how AML record-keeping conflicts with data-privacy / data-minimization obligations"
    use_instead: "compliance/privacy/gdpr-summary/2026"

# === AGENT HINTS ===
inputs_needed:
  - key: "entity_type"
    question: "What type of financial institution is the user operating?"
    type: choice
    options:
      - "Bank or credit union"
      - "Money services business (MSB) or payment provider"
      - "Investment adviser or broker-dealer"
      - "Insurance company"
      - "Virtual asset service provider (VASP) / crypto exchange"
      - "Designated non-financial business or profession (DNFBP)"
  - key: "jurisdiction"
    question: "In which jurisdiction(s) does the entity operate?"
    type: choice
    options:
      - "United States"
      - "European Union"
      - "United Kingdom"
      - "Multiple jurisdictions (cross-border)"
      - "Other FATF member country"
  - key: "program_maturity"
    question: "Does the entity have an existing AML/KYC program?"
    type: choice
    options:
      - "No program — building from scratch"
      - "Basic program — needs gap assessment"
      - "Mature program — needs update for new regulations"

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/compliance/financial/aml-kyc-framework/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-05-31)"

# === RELATED UNITS ===
related_kos:
  depends_on: []
  related_to:
    - id: "compliance/privacy/gdpr-summary/2026"
      label: "GDPR compliance — data retention conflicts with AML record-keeping"
    - id: "compliance/privacy/cross-border-data-transfers/2026"
      label: "Cross-border data transfers — relevant for multi-jurisdictional AML programs"
    - id: "compliance/financial/psd2-open-banking/2026"
      label: "PSD2 / Open Banking — overlapping EU financial-services obligations"
  often_confused_with:
    - id: "compliance/financial/dodd-frank/2026"
      label: "Dodd-Frank — US financial-stability regulation, not anti-money-laundering"
    - id: "compliance/financial/mifid-ii/2026"
      label: "MiFID II — EU investment-firm conduct rules, distinct from AML/KYC"
    - id: "compliance/financial/sox-compliance-checklist/2026"
      label: "SOX — financial-reporting controls for public companies, not AML"
  solves: []
  alternative_to: []

# === SOURCES ===
# Types: product_testing, primary_research, industry_report, community_resource, government_regulation, official_docs
# Reliability: high, moderate_high, moderate, authoritative
sources:
  - id: src1
    title: "FATF Recommendations — International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation"
    author: FATF
    url: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
    type: government_regulation
    published: 2025-06-01
    reliability: authoritative
  - id: src2
    title: "CDD Final Rule — Customer Due Diligence Requirements for Financial Institutions"
    author: FinCEN
    url: https://www.fincen.gov/resources/statutes-and-regulations/cdd-final-rule
    type: government_regulation
    published: 2024-01-01
    reliability: authoritative
  - id: src3
    title: "Regulation (EU) 2024/1624 — Anti-Money Laundering Regulation (AMLR)"
    author: European Parliament and Council
    url: https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng
    type: government_regulation
    published: 2024-07-09
    reliability: authoritative
  - id: src4
    title: "FinCEN SAR FAQs — Clarifying Suspicious Activity Reporting Requirements"
    author: FinCEN
    url: https://www.fincen.gov/system/files/2025-10/SAR-FAQs-October-2025.pdf
    type: government_regulation
    published: 2025-10-09
    reliability: authoritative
  - id: src5
    title: "AML/CFT and Sanctions Enforcement Actions in 2025"
    author: Institute for Financial Integrity
    url: https://finintegrity.org/aml-cft-and-sanctions-enforcement-actions-in-2025/
    type: industry_report
    published: 2025-12-01
    reliability: high
  - id: src6
    title: "FATF Targeted Update on Implementation of Standards on Virtual Assets and VASPs"
    author: FATF
    url: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-update-virtual-assets-vasps-2025.html
    type: government_regulation
    published: 2025-06-01
    reliability: authoritative
  - id: src7
    title: "Directive (EU) 2024/1640 — 6th Anti-Money Laundering Directive (6AMLD)"
    author: European Parliament and Council
    url: https://fiaumalta.org/app/uploads/2025/02/The-6th-Anti-Money-Laundering-Directive-AMLD6.pdf
    type: government_regulation
    published: 2024-07-09
    reliability: authoritative
  - id: src8
    title: "Global Financial Regulatory Penalties Report 2025"
    author: Fenergo
    url: https://resources.fenergo.com/newsroom/global-financial-regulatory-penalties-fall-by-18-in-2025-as-enforcement-shifts-from-us-to-emea-and-apac
    type: industry_report
    published: 2025-12-15
    reliability: high
  - id: src9
    title: "Final Rule — Delaying the Effective Date of the AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers"
    author: FinCEN
    url: https://www.federalregister.gov/documents/2026/01/02/2025-24184/delaying-the-effective-date-of-the-anti-money-launderingcountering-the-financing-of-terrorism
    type: government_regulation
    published: 2026-01-02
    reliability: authoritative
  - id: src10
    title: "Interim Final Rule — Beneficial Ownership Information Reporting Requirement Revision and Deadline Extension (exempts domestic US reporting companies)"
    author: FinCEN
    url: https://www.federalregister.gov/documents/2025/03/26/2025-05199/beneficial-ownership-information-reporting-requirement-revision-and-deadline-extension
    type: government_regulation
    published: 2025-03-26
    reliability: authoritative
---

# AML/KYC Framework for Financial Services

## What are the AML/KYC requirements for financial services companies?

## Summary

Every financial institution and designated obliged entity must run a risk-based AML/KYC program built on five pillars: a board-approved written AML/CFT policy, a designated compliance officer (BSA Officer in the US, MLRO in the UK/EU), risk-based Customer Due Diligence (CDD) with Enhanced Due Diligence (EDD) for high-risk relationships, ongoing transaction monitoring with timely SAR/STR filing, and independent testing plus staff training. The framework rests on three pillars: FATF's 40 Recommendations globally, the US Bank Secrecy Act (BSA) administered by FinCEN, and EU Regulation 2024/1624 (AMLR) plus Directive 2024/1640 (6AMLD), which apply from 10 July 2027. Two late-2025/2026 US shifts materially narrow the regime: FinCEN's March 26, 2025 interim final rule exempts all domestic US companies from Corporate Transparency Act beneficial-ownership reporting (only foreign reporting companies remain in scope), and the FinCEN investment-adviser AML rule — originally effective 1 January 2026 — was postponed to 1 January 2028 by a final rule issued 31 December 2025. AML enforcement penalties totaled $4.6 billion in 2024 and $3.8 billion in 2025; partial compliance is never an option once an entity is an obliged entity in any jurisdiction. [src1, src2, src3, src9, src10]

## Rule

Every financial institution and designated obliged entity must implement a risk-based Anti-Money Laundering (AML) and Know Your Customer (KYC) program comprising five core pillars: (1) a written AML/CFT policy approved by senior management, (2) a designated compliance officer, (3) risk-based Customer Due Diligence (CDD) with Enhanced Due Diligence (EDD) for high-risk relationships, (4) ongoing transaction monitoring with Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) filing, and (5) independent testing and staff training. This framework is mandated by FATF Recommendation 10 globally, the US Bank Secrecy Act (BSA) domestically, and EU Regulation 2024/1624 (AMLR) across the European Union. [src1, src2, src3]

## Evidence

Global AML enforcement penalties totaled $4.6 billion in 2024 and $3.8 billion in 2025, with the single largest 2024 penalty being TD Bank's $3.09 billion fine for systemic AML compliance failures in the US. [src5, src8] In the first half of 2025, regulators levied approximately 139 financial penalties totaling $1.23 billion — a 417% increase over the same period in 2024 — with the most significant being OKX's $504 million penalty for failing to maintain an effective AML program. [src5, src8] FATF's fifth round of mutual evaluations (2024-2027) places heavy weight on effectiveness outcomes rather than technical compliance, and its June 2025 guidance explicitly requires firms to apply a risk-based approach to AML, CFT, and counter-proliferation financing (CPF). [src1] The EU's AMLR doubles the maximum pecuniary sanctions from EUR 5 million (or 5% of turnover) to EUR 10 million (or 10% of total annual turnover), and the EU has lowered the beneficial ownership identification threshold from over 25% to 25% or more, with a 15% threshold applicable in high-risk cases. [src3] The EU AMLA must deliver Regulatory Technical Standards (RTS) covering CDD requirements and minimum data standards by July 10, 2026, signaling a shift from nationally-interpreted KYC approaches toward harmonized EU-wide frameworks. [src3, src4] On February 13, 2026, FinCEN issued Order FIN-2026-R001 granting exceptive relief to covered financial institutions from the requirement to identify and verify beneficial owners of legal entity customers at each new account opening. [src2, src5] Two further US developments reshaped the 2025-2026 landscape: FinCEN's March 26, 2025 interim final rule narrowed the Corporate Transparency Act's "reporting company" definition to foreign entities only, exempting all domestic US companies and US persons from beneficial-ownership information (BOI) reporting (the Eleventh Circuit upheld the CTA as constitutional on December 16, 2025, but did not reinstate domestic reporting obligations), and FinCEN postponed its investment-adviser AML/CFT program and SAR rule — originally effective January 1, 2026 — to January 1, 2028 via a final rule issued December 31, 2025 and published in the Federal Register January 2, 2026. [src9, src10]

## Key Properties

- **FATF Standard**: 40 Recommendations — the global baseline adopted by 200+ jurisdictions; Recommendation 10 (CDD), Recommendation 16 (Travel Rule), Recommendation 20 (SAR/STR filing)
- **US Framework**: Bank Secrecy Act (BSA) — administered by FinCEN; CDD Rule (2018, updated 2024); SAR filing threshold $5,000+; CTR filing threshold $10,000+ cash; Corporate Transparency Act BOI reporting now applies to foreign reporting companies only (FinCEN interim final rule, March 26, 2025 exempted all domestic US entities); FinCEN investment-adviser AML rule postponed to January 1, 2028 (final rule issued December 31, 2025)
- **EU Framework**: Regulation 2024/1624 (AMLR) + Directive 2024/1640 (6AMLD) — apply from July 10, 2027; supervised by AMLA (Frankfurt, operational July 1, 2025; direct supervision of its first ~40 high-risk cross-border entities begins January 2028); EU-wide cash payment cap EUR 10,000; customer ID required for cash transactions EUR 3,000+
- **Penalties**: Up to $3+ billion (US), EUR 10 million or 10% global turnover (EU), criminal prosecution for willful violations in both jurisdictions [src3, src5]
- **Filing Deadlines**: SAR within 30 calendar days of detection (US); STR timelines vary by EU member state (typically 24-48 hours for terrorist financing, 30 days for ML)
- **Beneficial Ownership Threshold**: 25% or more ownership or control (EU AMLR — lowered from over 25%); 15% threshold in high-risk cases (EU); US CDD Rule requires identification of each individual with 25%+ equity or one individual with significant management control; FinCEN Order FIN-2026-R001 (Feb 2026) provides exceptive relief from per-account BO identification [src1, src2, src3]

## Conditions

- **Applies when**: Any entity classified as a "financial institution" or "obliged entity" under applicable AML legislation — including banks, credit unions, broker-dealers, investment advisers, money services businesses, insurance companies, VASPs/crypto exchanges, real estate agents (EU), lawyers handling financial transactions, high-value goods dealers, and professional football clubs/agents (EU AMLR)
- **Does NOT apply when**: Entity is below jurisdictional thresholds (e.g., sole proprietors below de minimis transaction volumes in certain jurisdictions); entity operates exclusively in a jurisdiction not subject to FATF recommendations (extremely rare — only North Korea, Iran, and Myanmar are fully non-compliant)
- **Confidence degrades when**: New regulations are pending implementation (EU AMLR not applicable until July 2027; AMLA RTS on CDD and group-wide controls due July 10, 2026; AMLA direct supervision of its first ~40 entities begins January 2028); FinCEN investment adviser rule postponed to January 2028 (and FinCEN intends to revisit its substance); the CTA BOI interim final rule (domestic exemption, March 2025) has not yet been finalized; FinCEN BOI exceptive relief (FIN-2026-R001) may alter beneficial ownership requirements; FATF mutual evaluation outcomes may shift national requirements; Australia Tranche 2 entities (lawyers, accountants, real estate agents) coming under AML/CTF regime from March 2026

## Constraints
<!-- Agents: read this section before recommending this rule.
     These are hard boundaries on when and how it applies. -->

- Jurisdiction-specific thresholds and filing requirements vary significantly — US uses $5,000 SAR threshold while EU member states set their own STR thresholds and timelines [src2, src3]
- EU AMLR (Regulation 2024/1624) and 6AMLD (Directive 2024/1640) were published July 9, 2024, but do not apply until July 10, 2027 — until then, existing 5AMLD and member state transpositions remain in force [src3, src7]
- US FinCEN's AML rule for investment advisers (finalized September 2024) was postponed from its original January 1, 2026 effective date to January 1, 2028 by a final rule issued December 31, 2025 — advisers are not yet obligated, and FinCEN intends to revisit the rule's substance before then [src9]
- AML record-keeping requirements (5-7 years typically) may conflict with GDPR data minimization principles — entities operating in the EU must reconcile both frameworks [src3]
- FATF Travel Rule implementation remains inconsistent — only 85 of 117 jurisdictions (73%) have passed implementing legislation as of 2025, and cross-border crypto transfers between compliant and non-compliant jurisdictions create compliance gaps [src6]
- AMLA must deliver Regulatory Technical Standards on CDD and minimum data standards by July 10, 2026 — these will create harmonized EU-wide KYC requirements replacing nationally-interpreted approaches [src3, src4]
- FinCEN issued exceptive relief (FIN-2026-R001, Feb 13, 2026) from beneficial ownership identification at each new account opening — check current scope and expiry before applying [src2, src5]
- Beneficial Ownership Information (BOI) reporting under the US Corporate Transparency Act now applies to FOREIGN reporting companies only — FinCEN's March 26, 2025 interim final rule exempted all domestic US entities and US persons; the Eleventh Circuit upheld the CTA as constitutional (December 16, 2025) but did not reinstate domestic reporting, and a final rule is expected in 2026 [src10]

## Rationale

AML/KYC frameworks exist because the global financial system processes approximately $2 quadrillion annually, and the UN estimates that 2-5% of global GDP ($800 billion to $2 trillion) is laundered each year. Without mandatory identification, due diligence, and transaction monitoring, financial institutions become conduits for drug trafficking, terrorist financing, tax evasion, and sanctions circumvention. The risk-based approach — rather than prescriptive rules — recognizes that ML/TF risk varies by customer type, geography, product, and delivery channel, and resources should be allocated proportionally to actual risk. [src1, src3]

## Framework Selection Decision Tree

```
START — User needs AML/KYC compliance guidance
├── Which jurisdiction?
│   ├── United States (BSA/AML)
│   │   └── AML/KYC Framework (this unit) ← YOU ARE HERE
│   ├── European Union (AMLR/6AMLD)
│   │   └── AML/KYC Framework (this unit) ← YOU ARE HERE
│   ├── United Kingdom (MLR 2017, FCA supervision)
│   │   └── AML/KYC Framework (this unit — UK aligns with FATF)
│   └── Multiple jurisdictions
│       └── AML/KYC Framework (this unit — use FATF baseline + jurisdiction-specific add-ons)
├── Is the entity a "financial institution" or "obliged entity"?
│   ├── YES → Apply this rule: implement 5-pillar AML program
│   └── NO → Check if entity is a DNFBP or newly designated obliged entity (EU AMLR expands scope)
├── Does the entity handle virtual assets or crypto?
│   ├── YES → Apply this rule + FATF Travel Rule (Recommendation 16) + jurisdiction-specific VASP registration
│   └── NO → Standard AML/KYC program under this rule
└── Does the entity have an existing AML program?
    ├── YES → Audit against this rule: check 5 pillars, risk assessment currency, SAR filing compliance
    └── NO → Start with risk assessment, then build program per Application Checklist below
```

## Application Checklist

### Step 1: Determine applicability and scope
- **Inputs needed**: Entity type, jurisdiction(s) of operation, customer base geography, products/services offered, transaction volumes
- **Output**: Go/no-go on AML program obligation; list of applicable regulations (BSA, AMLR, FATF Recommendations, national AML laws)
- **Constraint**: If entity is an obliged entity in any jurisdiction, the entire AML program is mandatory — partial compliance is not an option. Failure to determine scope correctly was a factor in 67% of enforcement actions in 2024-2025. [src1, src5]

### Step 2: Conduct enterprise-wide risk assessment
- **Inputs needed**: Customer risk factors (PEPs, high-risk jurisdictions, complex ownership), product risk (correspondent banking, private banking, crypto), geographic risk (FATF grey/black list countries), delivery channel risk (non-face-to-face, third-party reliance)
- **Output**: Written risk assessment document categorizing ML/TF risks as low, medium, or high; risk appetite statement approved by board/senior management
- **Constraint**: Risk assessment must be updated at least annually or when material changes occur (new products, new markets, regulatory changes). Static risk assessments are the single most common deficiency cited in FATF mutual evaluations. [src1]

### Step 3: Implement CDD/EDD procedures
- **Inputs needed**: Risk assessment output, customer onboarding data requirements, identity verification technology (document verification, biometric, database checks)
- **Output**: CDD procedures covering customer identification (CIP in US), verification, beneficial ownership identification (25%+ threshold), and ongoing monitoring; EDD procedures for high-risk categories (PEPs, correspondent banking, high-risk jurisdictions, complex structures)
- **Constraint**: CDD must be completed before or during establishment of business relationship — no exceptions for "pending verification." EDD requires source of wealth and source of funds documentation. Simplified Due Diligence (SDD) only where lower risk is demonstrated and documented. [src2, src3]

### Step 4: Build transaction monitoring and SAR/STR filing
- **Inputs needed**: Transaction data, monitoring rules/scenarios, alert investigation workflow, SAR/STR filing templates
- **Output**: Operational transaction monitoring system with documented scenarios, alert triage process, investigation procedures, and SAR/STR filing workflow
- **Constraint**: SAR must be filed within 30 calendar days of initial detection (US). No regulatory requirement for post-SAR 90-day reviews — October 2025 FinCEN FAQs clarified this is not mandatory. Institutions are not required to file SARs solely because a transaction is at or near the $10,000 CTR threshold. [src4]

### Step 5: Validate, train, and independently test
- **Inputs needed**: Completed AML program documentation, training materials, independent audit plan
- **Output**: Annual independent testing report, documented training records, board/senior management reporting on AML program effectiveness
- **Constraint**: Independent testing must be conducted by qualified personnel not involved in day-to-day AML operations. Training must cover all relevant staff and be updated for regulatory changes. Escalate to legal counsel if independent testing identifies material deficiencies or potential regulatory violations. [src1, src2]

## Decision Logic

### If a US registered investment adviser or exempt reporting adviser is rushing to stand up an AML program for a January 2026 deadline
--> Stop and re-check the deadline: FinCEN postponed the investment-adviser AML/CFT and SAR rule from January 1, 2026 to January 1, 2028 (final rule issued December 31, 2025). Advisers are not yet obligated, though FinCEN may revisit the rule's substance — continue program design but do not treat 2026 as a hard cut-over. [src9]

### If a US-formed company is being asked to file beneficial-ownership information under the Corporate Transparency Act
--> It almost certainly does not have to. FinCEN's March 26, 2025 interim final rule exempts all domestic US entities and US persons from BOI reporting; only foreign entities registered to do business in a US state/tribal jurisdiction remain reporting companies. The December 16, 2025 Eleventh Circuit ruling upheld the CTA but did not reinstate domestic obligations. [src10]

### If the entity is an obliged entity in even one jurisdiction
--> Treat the full five-pillar AML program as mandatory — partial or "best-effort" compliance is never an option. Failure to determine scope correctly was a factor in a majority of recent enforcement actions. [src1, src5]

### If the entity onboards a high-risk customer (PEP, correspondent-banking, FATF grey/black-list country, or opaque ownership)
--> Apply Enhanced Due Diligence: document source of wealth and source of funds, obtain senior-management approval, and set a heightened ongoing-monitoring cadence. Do NOT rely on Simplified Due Diligence unless lower risk is demonstrated and documented. [src1, src3]

### If a compliance team is filing SARs purely because a transaction is at or near the $10,000 CTR threshold
--> Stop. FinCEN's October 2025 FAQs confirm there is no requirement to file a SAR solely on threshold proximity, and no requirement for post-SAR 90-day reviews; file on suspicion of illicit funds, structuring, or no lawful purpose instead. [src4]

### If the entity operates in the EU and is preparing for the AMLR/6AMLD regime
--> Build to the harmonized standard now: AMLA must deliver Regulatory Technical Standards on CDD and group-wide controls by July 10, 2026, AMLR applies from July 10, 2027, and AMLA's direct supervision of the first ~40 high-risk cross-border entities begins January 2028. Until AMLR applies, existing 5AMLD national transpositions remain in force. [src3, src7]

### If the question is really about payment-services/open-banking, investment-firm conduct, or the AML-vs-privacy data-retention conflict (not AML/KYC itself)
--> Route to the correct unit: PSD2/Open Banking [compliance/financial/psd2-open-banking/2026], MiFID II [compliance/financial/mifid-ii/2026], or GDPR [compliance/privacy/gdpr-summary/2026]. [src3]

## Anti-Patterns

### Wrong: Treating KYC as a one-time onboarding check
Many institutions collect identification documents at account opening and never revisit them. This approach fails to detect changes in customer risk profile, PEP status, or beneficial ownership structure over time, and was cited as a primary deficiency in TD Bank's $3.09 billion enforcement action. [src5]

### Correct: Implement ongoing CDD with risk-based refresh cycles
CDD must be continuous. High-risk customers should be reviewed at least annually, medium-risk every 2-3 years, and low-risk every 5 years. Trigger events (large unusual transactions, adverse media, sanctions list changes, jurisdiction risk rating changes) should prompt immediate review regardless of scheduled cycle. [src1, src2]

### Wrong: Filing SARs based on transaction amount alone
Some compliance teams file SARs on every transaction near the $10,000 CTR threshold, creating massive volumes of low-value reports that overwhelm FinCEN and dilute intelligence value. [src4]

### Correct: File SARs based on suspicious activity indicators, not amount thresholds
FinCEN's October 2025 FAQs explicitly clarified that institutions are not required to file SARs solely because a transaction is at or near the $10,000 threshold. SARs should be filed when there is knowledge, suspicion, or reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA requirements, or has no lawful purpose. [src4]

### Wrong: Applying identical CDD procedures to all customers regardless of risk
A one-size-fits-all approach wastes resources on low-risk customers while under-scrutinizing high-risk relationships. This was the exact failure pattern that led to multiple enforcement actions against banks processing correspondent banking transactions from high-risk jurisdictions. [src5]

### Correct: Apply tiered CDD based on documented risk assessment
Use Simplified Due Diligence (SDD) for demonstrably low-risk customers (e.g., publicly listed companies, government entities), standard CDD for medium-risk, and Enhanced Due Diligence (EDD) for high-risk categories including PEPs, correspondent banking relationships, customers from FATF grey-list countries, and complex beneficial ownership structures. [src1, src3]

## Counter-Arguments

- The risk-based approach grants institutions significant discretion, which can lead to inconsistent application. Some regulators argue that more prescriptive rules would create a more level playing field and reduce the "de-risking" phenomenon where banks exit entire markets or customer segments rather than manage risk. [src1]
- AML/KYC costs are substantial — estimated at $214 billion globally in 2024 — yet less than 1% of illicit financial flows are successfully intercepted, leading critics to question whether the current framework delivers proportionate value relative to its compliance burden. [src8]
- Strict AML/KYC requirements contribute to financial exclusion: an estimated 1.4 billion adults globally lack access to formal financial services, partly because identity verification requirements are impossible to meet in regions with limited civil registration infrastructure. [src1]

## Common Misconceptions

- **Misconception**: AML/KYC programs only apply to banks and traditional financial institutions.
  **Reality**: FATF Recommendations and most national laws extend AML obligations to designated non-financial businesses and professions (DNFBPs) including real estate agents, dealers in precious metals and stones, lawyers, notaries, accountants, and trust/company service providers. The EU AMLR further expanded scope to crypto-asset service providers, crowdfunding platforms, and professional football clubs/agents. [src1, src3]

- **Misconception**: Filing a SAR requires documenting the decision not to file when deciding against it.
  **Reality**: FinCEN's October 2025 FAQs explicitly state there is no legal or regulatory requirement for financial institutions to document decisions not to file a SAR, though institutions may choose to do so for internal risk management purposes. [src4]

- **Misconception**: The FATF Travel Rule for virtual assets is universally implemented and enforceable.
  **Reality**: As of 2025, only 85 of 117 surveyed jurisdictions (73%) have passed Travel Rule legislation, and over 75% of jurisdictions remain only partially compliant with FATF's AML standards for virtual assets. Cross-border crypto transfers between compliant and non-compliant jurisdictions remain a significant compliance gap. [src6]

- **Misconception**: The EU's new AML Regulation (AMLR) is already in effect.
  **Reality**: Regulation 2024/1624 was published on July 9, 2024, but does not apply until July 10, 2027. Until then, the existing 5th Anti-Money Laundering Directive (5AMLD) and its national transpositions remain the applicable law. [src3]

- **Misconception**: US-formed companies must still file beneficial-ownership information under the Corporate Transparency Act.
  **Reality**: FinCEN's interim final rule of March 26, 2025 redefined "reporting company" to cover only foreign entities registered to do business in the US, exempting all domestic US entities and US persons from BOI reporting. The Eleventh Circuit upheld the CTA's constitutionality on December 16, 2025, but that ruling did not reinstate the domestic reporting obligation. [src10]

- **Misconception**: US investment advisers had to have AML programs in place by January 1, 2026.
  **Reality**: FinCEN issued a final rule on December 31, 2025 (published in the Federal Register January 2, 2026) postponing the investment-adviser AML/CFT program and SAR filing requirements to January 1, 2028, and signaled it may revisit the rule's substance before then. [src9]

## Comparison with Similar Rules

| Rule/Framework | Key Difference | When to Use |
|---|---|---|
| AML/KYC Framework (this unit) | Global overview covering FATF, US BSA, and EU AMLR — the three primary pillars | When the user needs a comprehensive understanding of AML/KYC obligations across jurisdictions |
| GDPR / Data Privacy | Data minimization and right to erasure may conflict with AML record-keeping (5-7 year retention) | When balancing AML data retention against privacy obligations |
| Sanctions Screening (OFAC/EU) | Focuses on prohibited parties/countries rather than transaction patterns | When the question is about blocked persons, SDN lists, or embargo compliance rather than anti-money laundering |
| FATCA/CRS Tax Reporting | Tax information exchange between jurisdictions — overlaps with but distinct from AML beneficial ownership | When the question is about tax transparency and cross-border account reporting |

## When This Matters

Fetch this when a user asks about AML/KYC compliance obligations, anti-money laundering program requirements, customer due diligence procedures, suspicious activity reporting, beneficial ownership requirements, or when a financial institution, fintech, or VASP needs to understand its regulatory obligations for preventing money laundering and terrorist financing.

## Related Units

- [GDPR Compliance Requirements](/compliance/privacy/gdpr-summary/2026)
- [Cross-Border Data Transfers](/compliance/privacy/cross-border-data-transfers/2026)
- [PSD2 / Open Banking](/compliance/financial/psd2-open-banking/2026)
- [Dodd-Frank](/compliance/financial/dodd-frank/2026)
- [MiFID II](/compliance/financial/mifid-ii/2026)
- [SOX Compliance Checklist](/compliance/financial/sox-compliance-checklist/2026)
