AML/CFT  ·  Governance & Operating Framework

AML/CFT Policies & Procedures Development

Risk-based AML/CFT policies and operational procedures for CASPs, fintech, payment institutions and other regulated businesses — designed around the actual business model, regulatory perimeter, customer journey, transaction flows and control environment.

Risk-Based
Aligned to the
business model
Operational
Built around real
workflows & controls
Cross-Border
Jurisdiction-specific
regulatory mapping
AML/CFT documentation that works in practice

Not a generic AML manual.

AML/CFT policies should define the organisation’s risk-based framework, governance, responsibilities and control standards. Procedures should explain how those requirements are applied in day-to-day operations, who makes decisions, when matters are escalated and what evidence is retained.

Documentation that does not reflect the actual customer journey, products, transaction flows, systems, outsourcing arrangements and decision rights creates a gap between written controls and operational reality.

LEX ARTA supports the design, review and enhancement of AML/CFT policy suites and operating procedures for regulated and higher-risk businesses, with scope tailored to the applicable jurisdiction, regulatory status and business model.

Policy
Sets the framework.
Governance, principles, risk approach, roles, responsibilities, control requirements, oversight and management expectations.
Procedure
Explains how the framework operates.
Operational steps, decision points, review standards, escalation routes, approvals, evidence, records and ownership.
Scope of support

Policies and procedures across the AML/CFT control framework.

The exact documentation set depends on the client’s regulatory perimeter, products, customer base, delivery channels, geographic exposure, technology and outsourcing model.

AML/CFT Framework & Governance
AML/CFT programme architecture, management responsibilities, MLRO or equivalent oversight, escalation lines, reporting arrangements and control ownership.
Business-Wide Risk Assessment
Methodology and governance for identifying, assessing, documenting and updating ML/TF risks across customers, products, services, delivery channels and geographic exposure.
CDD / KYC & Beneficial Ownership
Customer identification and verification, beneficial ownership, purpose and nature of the relationship, onboarding evidence, ongoing due diligence and refresh requirements.
Customer Risk Rating & EDD
Risk classification methodology, higher-risk triggers, PEP controls, source of funds / source of wealth measures, enhanced review and approval requirements.
Transaction Monitoring & Investigations
Alert review, investigation standards, escalation criteria, case documentation, decision-making and governance of monitoring rules and thresholds.
Suspicious Transaction Reporting
Internal escalation, MLRO review, decision documentation, external reporting processes and confidentiality controls, adapted to the applicable reporting regime.
Sanctions & Targeted Financial Sanctions
Screening governance, alert handling, escalation, restrictions, freezing or other legally required actions, record keeping and regulatory reporting where applicable.
Record Keeping & Information Governance
Retention responsibilities, evidence standards, access controls and interaction with applicable data-protection requirements.
Outsourcing, Reliance & Third Parties
Responsibilities, oversight and control standards where AML/CFT processes, technology or customer due diligence activities involve external providers or permitted reliance arrangements.
Training & Staff Responsibilities
Role-based training requirements, responsibilities of relevant staff, escalation expectations and evidence of training completion.
Crypto / CASP Controls
Where relevant: crypto-asset customer risk, blockchain analytics governance, wallet-risk controls, unhosted wallet procedures, Travel Rule / TFR workflows and crypto-specific escalation criteria.
Quality Assurance & Issue Management
Control testing, review of deficiencies, corrective actions, version control, change management and evidence that policies and procedures remain current.
When this service is useful

Build, refresh or repair the AML/CFT operating framework.

New Licence or Registration
A new regulated business needs AML/CFT documentation that reflects the proposed services, customer journey, governance and control environment.
Existing Framework Is Outdated
Policies no longer match current products, systems, customer types, jurisdictions, organisational structure or regulatory requirements.
Audit or Gap Findings
Internal review, independent audit, supervisory feedback or due diligence has identified documentation or control weaknesses requiring remediation.
Business Model Change
New products, customer segments, payment flows, crypto services, outsourcing arrangements or technology materially change the firm’s risk and control environment.
Cross-Border Expansion
A business enters a new jurisdiction and needs its group framework mapped and adapted to local legal and supervisory requirements.
Operationalisation
A policy framework exists, but operational teams need procedures, decision rules, escalation routes and evidence standards that can actually be followed.
How the work is structured

From regulatory requirements to operational controls.

01 — Scope & Perimeter
Confirm regulated activities, applicable jurisdiction, customer types, products, delivery channels, transaction flows, outsourcing and the existing documentation set.
02 — Risk & Control Mapping
Map legal and regulatory obligations to the business-wide risk assessment, customer journey, systems, control owners and decision points.
03 — Draft or Review
Develop new policies and procedures or revise existing documentation, removing generic provisions that do not match the operating model.
04 — Operational Validation
Check that responsibilities, approvals, escalation routes, workflow steps and required evidence correspond to how the business is intended to operate.
05 — Implementation & Handover
Finalise the documentation set, identify implementation actions and, where included in scope, support rollout, training and implementation tracking. Broader remediation remains a separate workstream.
Typical deliverables

A usable AML/CFT documentation set.

Framework
Core AML/CFT Policy Suite
Policies and governance documents tailored to the agreed regulatory perimeter and risk profile.
Operations
Operational Procedures
Step-by-step workflows, decision points, approvals, escalation routes and evidence requirements.
Governance
Roles & Responsibilities
Allocation of responsibility across management, MLRO / compliance, operations, first-line teams and relevant service providers.
Controls
Control & Escalation Matrix
Key control points, ownership, triggers, escalation thresholds and review responsibilities where required by scope.
Implementation
Implementation Action List
Prioritised implementation actions where documentation changes require process, system, governance or training updates. Broader remediation programmes are separately scoped.
Maintenance
Review & Change Framework
Version control, ownership and review triggers so the documentation can be maintained as the business and regulatory environment change.
Deliverables are defined in the engagement scope. Not every project requires every document or control artifact.
Related but different

Policies & Procedures are one part of the AML/CFT lifecycle.

The right service depends on whether the business needs to build controls, identify gaps, independently test effectiveness or implement corrective actions.

01
Policies & Procedures
Build or update the operating framework.
Design and documentation of governance, controls and operational procedures.
02
AML Regulatory Gap Analysis
Identify what is missing.
Structured comparison of the existing framework against applicable requirements and supervisory expectations.
03
AML Audit & Compliance Review
Independently test effectiveness.
Independent assessment of controls, governance, implementation and evidence.
04
Remediation
Turn findings into corrective action.
Support to address identified deficiencies and strengthen the operating framework.
Regulatory basis

Built against the rules that actually apply to the business.

AML/CFT policy requirements are not identical across jurisdictions or sectors. The applicable framework depends on the legal status of the business, regulated activities, location, customer and product risk, and sector-specific requirements.

For EU businesses, projects can be mapped to currently applicable national AML/CFT law and EU requirements, with sector-specific rules such as the Transfer of Funds Regulation included where relevant.

Future-state alignment with Regulation (EU) 2024/1624 (AMLR) can also be incorporated where appropriate. The AMLR applies from 10 July 2027 for most obliged entities.

Risk-based and proportionate
The documentation set should reflect the nature, size, risk and complexity of the business rather than reproduce a generic catalogue of controls.
Implementation matters
Written policies and procedures do not by themselves establish effective compliance. Responsibilities, systems, controls, records, training, oversight and testing must support the written framework.
Common questions

AML/CFT Policies & Procedures — FAQ.

Do you provide standard AML policy templates?
+
The service is designed around the client’s jurisdiction, regulated status, business model, risk profile and operating processes. Existing templates can be reviewed, but documentation should be adapted to the actual control environment rather than used as a generic substitute for implementation.
Can you review and update an existing AML/CFT manual?
+
Yes. Existing policies and procedures can be reviewed against applicable requirements, the current business model and operational practice, with revisions prioritised according to risk and regulatory relevance.
Are AML/CFT policies the same as operational procedures?
+
No. Policies set the governance framework, principles, responsibilities and control expectations. Procedures translate those requirements into operational steps, decision points, escalation rules, evidence and ownership.
Can the framework cover crypto and CASP-specific controls?
+
Yes. Where relevant, the scope can include crypto-asset customer risk, blockchain analytics governance, unhosted wallet controls, sanctions screening and Travel Rule / TFR procedures.
Does having written policies make a business AML compliant?
+
No. Written documentation is only one part of an effective AML/CFT framework. Controls must also be implemented, assigned to responsible persons, supported by systems and records, tested, monitored and updated when requirements, risks or operations change.
How is the project priced?
+
Scope and pricing depend on the jurisdiction, regulated status, business model, number and maturity of existing documents and the level of implementation support required. A defined scope and fee can be provided after an initial scoping discussion.
Need to build or update your AML/CFT framework?
Scope the required policy suite, operating procedures and implementation work around your business model and regulatory perimeter.
Why LEX ARTA

Why LEX ARTA for AML Policies & Procedures.

AML documentation is drafted around the actual risk model and operating process rather than treated as a standalone policy pack.

Business-Model AlignedPolicies reflect products, customers, jurisdictions, delivery channels, transaction flows and the actual allocation of responsibilities.
Risk-Based DraftingCDD, EDD, sanctions, monitoring, reporting and governance are calibrated to the risk framework and applicable obligations.
Operational DetailProcedures are written to support implementation, evidence and staff use rather than high-level statements alone.
Connected ControlsDocumentation can be aligned with EWRA, training, MLRO oversight, audit findings and regulatory-readiness work.