Hatch resource banner image for How to develop your anti-money laundering (AML) and KYC policies

How to develop your anti-money laundering (AML) and KYC policies

Creating clear AML and KYC policies is a legal requirement in many sectors that protects your business from financial crime and builds trust with your customers.

What are AML and KYC policies?

If your business operates in a sector regulated for financial crime, you are legally required to have formal Anti-Money Laundering (AML) and Know Your Customer (KYC) policies. Think of these as your company’s rulebook for preventing criminals from using your services. Your first step is to create a written document that clearly outlines how you verify who your customers are and how you monitor their financial activities for anything suspicious.

What’s the difference?
AML (Anti-Money Laundering) is the overall framework of rules and procedures you use to fight financial crime.
KYC (Know Your Customer) is a key part of AML. It’s the specific process you follow to verify a customer's identity before doing business with them.

Why you need these policies

Creating these policies isn’t just about ticking a legal box; it’s about protecting your new business. Having robust procedures in place:

  • Keeps you compliant: It’s a legal requirement in the UK for many sectors, and failing to comply can lead to significant fines or even criminal charges.
  • Protects your reputation: Being associated with financial crime can destroy customer trust and ruin your brand before it even gets off the ground.
  • Reduces your risk: It helps you identify and manage high-risk customers, preventing potential financial losses and legal headaches down the line.
  • Builds trust: It shows customers, banks, and partners that you are a legitimate and responsible business.

Does my business need AML policies?

AML regulations apply to businesses considered to be at a higher risk of being targeted for money laundering. This is known as the 'regulated sector'. Key industries include:

  • Financial and credit services (lenders, brokers)
  • Accountancy and tax advisory services
  • Legal services
  • Estate and letting agents
  • High-value dealers (dealing in goods where a single transaction is over €10,000, such as art, cars, or jewellery)
  • Trust or company service providers

If you are unsure, check the list of supervised business sectors on the UK government's website or consult with your industry’s professional body.

How to create your AML and KYC policies

Your policy document should be tailored to your business's specific risks. It doesn’t need to be overly complex, but it must be clear and comprehensive. Here are the essential sections to include.

1. Policy Statement and Risk Assessment

Start with a simple statement declaring your business's commitment to preventing financial crime. This should be followed by a business-wide risk assessment. This involves thinking about where your business is vulnerable. Consider:

  • Customer Risk: Are your customers anonymous, based overseas, or politically exposed persons (PEPs)?
  • Transactional Risk: Do you accept large cash payments? Are transactions unusually complex?
  • Geographical Risk: Do you do business with customers in high-risk countries?

2. Know Your Customer (KYC) Procedures

This is the core of your policy. Detail the exact steps you will take to verify a customer’s identity. This process is often called 'Customer Due Diligence' (CDD).

  • For Individuals: You need to collect their full name, date of birth, and residential address. You must then verify this information using reliable, independent documents like a passport, driving licence, or a recent utility bill.
  • For Companies: You need to identify the business name, company number, and registered address. You also need to identify the beneficial owners (the people who ultimately own or control it). You can use sources like Companies House to verify this information.

You should also define when you will perform Enhanced Due Diligence (EDD). This involves taking extra steps to verify identity for higher-risk customers, such as those identified in your risk assessment.

3. Transaction Monitoring

Explain how you will monitor customer activity. This doesn't mean watching every single transaction, but having a process to spot 'red flags' that could indicate suspicious behaviour. Examples include:

  • A customer making an unusually large transaction that doesn't fit their profile.
  • A series of complex, illogical transactions.
  • A customer being secretive or reluctant to provide identity documents.

4. Reporting Suspicious Activity

Your policy must state a clear procedure for reporting suspicious activity to the National Crime Agency (NCA) by submitting a Suspicious Activity Report (SAR). You must appoint a Nominated Officer or Money Laundering Reporting Officer (MLRO). In a small business, this will likely be you. This person is legally responsible for making the report.

5. Record Keeping

You are required to keep records of all customer identity checks and transactions. Your policy should state that you will keep these records for five years after your business relationship with the customer has ended.

6. Staff Training

Finally, include a commitment to training any current or future employees on your AML/KYC policies, their legal obligations, and how to spot suspicious activity.

Top Tip: Start with a Template
You don’t have to start from a blank page. Many industry bodies and regulatory supervisors (like HMRC) provide templates for AML policies. Use one of these as a starting point, but always remember to adapt it to the specific risks and realities of your own business. This is a living document that should evolve as your business grows.

Created by hatch. • Updated on April 27, 2026