Hatch resource banner image for How to develop your AML and KYC policies

How to develop your AML and KYC policies

Creating clear AML and KYC policies is a legal requirement for many businesses that protects you from financial crime and builds trust with your customers.

Your first step is to create written Anti-Money Laundering (AML) and Know Your Customer (KYC) policies. If your business operates in a sector regulated for money laundering purposes, this isn't just good practice—it's a legal requirement. These policies are your rulebook for verifying who your customers are and spotting any unusual financial activity, protecting your business from being used for financial crime.

First, do you even need AML and KYC policies?

Before you dive in, you need to confirm if your business falls into a 'regulated sector'. In the UK, this typically includes:

  • Financial services (banks, financial advisors)
  • Accountancy and bookkeeping services
  • Legal services
  • Estate agents and letting agents
  • High-value dealers (e.g., dealing in goods for cash payments of €10,000 or more)
  • Trust or company service providers
  • Art market participants
  • Cryptoasset businesses

If your business isn't on this list (for example, you're a freelance graphic designer or run a coffee shop), you are not legally required to have these formal policies. However, understanding the principles can still be valuable for general business security.

What’s the difference between KYC and AML?

It’s easy to get these two confused, but the distinction is quite simple. Think of it this way:

  • Know Your Customer (KYC) is the first step. It’s the process of verifying the identity of your customers. It’s about asking, "Are you who you say you are?". This is where you collect and check documents like passports, driving licences, and utility bills.
  • Anti-Money Laundering (AML) is the bigger picture. It’s your entire strategy for preventing your business from being used for illegal purposes. KYC is a crucial part of your AML policy, which also includes things like monitoring transactions and reporting suspicious activity.

How to build your AML and KYC policies

Creating your policy document might sound intimidating, but it breaks down into a few logical steps. Your goal is to create a clear, written document that you and any staff can follow consistently.

  1. Conduct a Business Risk Assessment: Start by thinking about the risks specific to your business. Consider your customers, the products or services you offer, your location, and how you transact. For example, a business that deals exclusively with online payments from overseas clients might have a different risk profile to one that deals face-to-face with local customers. Document these risks.
  2. Define Your Customer Due Diligence (CDD) Process: This is the core of your KYC procedure. You need to decide what information you will collect from customers to verify their identity. There are three main levels:
    • Simplified Due Diligence (SDD): For low-risk situations where the chance of money laundering is small.
    • Standard Due Diligence: This is the default. You must identify the customer (e.g., collect their name and address) and verify their identity using reliable, independent documents (e.g., a passport and a recent utility bill).
    • Enhanced Due Diligence (EDD): For high-risk customers or transactions. This requires you to take extra steps, such as finding out the source of their wealth or funds. High-risk factors could include politically exposed persons (PEPs) or transactions with individuals in high-risk countries.
  3. Appoint a Nominated Officer: Even if you're a one-person business, you must formally appoint a 'Nominated Officer' or Money Laundering Reporting Officer (MLRO). This is the person responsible for overseeing your AML policies and for reporting any suspicious activity to the authorities. Write down who this person is in your policy.
  4. Outline Your Transaction Monitoring Process: How will you spot red flags? Your policy should explain what constitutes suspicious activity for your business. This could be unusually large transactions, a sudden change in a customer's behaviour, or unnecessarily complex payment arrangements.
  5. Establish a Reporting Procedure: If you spot something suspicious, you have a legal duty to report it by submitting a Suspicious Activity Report (SAR) to the National Crime Agency (NCA). Your policy must state that the Nominated Officer is responsible for this.
  6. Set Your Record-Keeping Rules: You must keep records of your customer due diligence checks and transactions. Under UK law, these records must be kept for five years after your business relationship with the customer has ended. Your policy should clearly state what you will keep, where it will be stored securely, and for how long.
  7. Plan for Staff Training: If you have employees, they need to be aware of the law and your policies. Your document should outline how and when staff will be trained on their responsibilities. If it's just you, make a note to review the official guidance annually to keep yourself up to date.

Putting it all together

Once you have considered all the points above, write them down in a single document. It doesn’t need to be a 100-page legal masterpiece. It needs to be a practical guide that is relevant to your business and demonstrates that you have thought about your risks and responsibilities.

Our Top Tip: Don't just file it away! Your AML & KYC policy is a living document. Set a reminder to review and update it at least once a year, or whenever your business changes significantly. This ensures you stay compliant and protected.

Created by hatch. • Updated on April 27, 2026