An AML policy is the top-level, board-approved document that states a firm's anti-money-laundering duties, its risk appetite, who owns what, and the minimum standards every procedure must meet. It is the yardstick auditors and examiners hold you to.
What is an AML policy, in plain English?
An AML policy is the top-level rulebook for how a firm fights money laundering. Approved by the board, it sets out the firm's legal obligations, how much risk it is willing to accept, who is responsible for what, and the minimum standards that every detailed procedure underneath it has to meet. It is the statement of intent and authority that everything else flows from.
Crucially, the policy sits above the procedures. It says what the firm will do and to what standard; the procedures say exactly how. That separation matters, because the policy is the document auditors and examiners measure you against, and the procedures have to deliver on what it promises.
The recurring danger is drift. Trouble starts when the policy and how monitoring or customer checks actually run pull apart, and that gap is a frequent exam criticism. A policy is only useful if it is current, dated, and version-controlled, so it still describes the firm you actually are today.
Policy versus procedures
What changes | AML policy | Procedures |
Level | Top-level, principles | Detailed, step by step |
Approved by | The board | Operational management |
Answers | What and to what standard | Exactly how, by whom |
Changes | Rarely, on material shifts | More often, as processes evolve |
Role in exams | The yardstick you are measured against | Evidence the yardstick is met |
Who is involved?
Who | Their role |
The board | Approves the policy, sets risk appetite, and owns accountability for it. |
The compliance officer or MLRO | Drafts, maintains, and version-controls the policy and keeps it aligned to the business. |
First-line teams | Follow procedures that must deliver the standards the policy sets. |
Auditors and examiners | Measure real practice against the policy and flag any gaps between the two. |
What it looks like in practice
In practice
A firm's AML policy, last updated three years ago, describes its products, customer types, and monitoring approach as they were then. Since then it has launched cross-border payments and started onboarding higher-risk business customers, but the policy still does not mention either.
During an exam, the reviewer lines up the current business against the policy and finds the document predates two major changes. The controls may even be running reasonably in practice, but the policy no longer describes the firm, so the drift between the stale document and reality becomes a written finding. Dating and version control would have caught it.
Why it matters to operators
The policy is the standard you are judged against, so its quality and currency directly shape exam outcomes. When practice matches the policy, the firm looks controlled and deliberate. When they diverge, examiners read that gap as a governance weakness, regardless of how well individual controls happen to be working.
The operator's job is to keep it dated, version-controlled, and refreshed when the business changes, not years later. A stale policy that predates a new product or a new rule is a recurring exam criticism precisely because it signals that oversight has fallen behind reality. Treating the policy as a living document, updated alongside material changes, is what keeps it a genuine yardstick rather than a historical artifact.
What to watch for
- Policy-practice drift. Monitoring or customer checks running differently from what the policy states.
- Stale dates. A policy that predates new products, markets, or regulatory changes and no longer describes the firm.
- No version control. Missing dates, owners, or change history, so no one can tell which version is current.
- Vague standards. A policy that sounds good but sets no clear minimum standards for procedures to meet.
- No board evidence. Weak or missing proof that the board actually approved and reviewed the policy.
Quick questions
How is the policy different from the AML program?
The policy is the top-level document setting duties and standards; the program is the whole operating system that carries them out. The policy is one component of the broader program.
How is a policy different from a procedure?
The policy states what the firm will do and to what standard; the procedure states exactly how, step by step. The policy is approved by the board and changes rarely, while procedures change as processes evolve.
Who has to approve it?
The board, or the equivalent senior governing body. Board approval is what gives the policy authority and signals that risk appetite and accountability sit at the top of the firm.
How often should it be updated?
Whenever the business materially changes, such as a new product, market, or regulatory requirement, plus a periodic scheduled review. The failure mode is leaving it untouched for years until it no longer matches reality.
Why is version control such a big deal?
Because examiners need to know which version was in force and when. Missing dates, owners, or change history make it impossible to prove the policy kept pace with the business, which itself becomes a finding.
What is the most common exam criticism?
Drift between the policy and real practice, especially a stale policy that predates a new product or rule. It signals that governance has fallen behind the business, which regulators treat as a control weakness.
Go deeper
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
- FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

