How to draft an AML policy and risk assessment
Protect your business and stay compliant with UK law by documenting how you identify and manage the risks of financial crime.
To legally operate in many sectors in the UK, you must have a written Anti-Money Laundering (AML) policy and a firm-wide risk assessment to identify and mitigate the risk of your business being used for financial crime. Having these documents is not just a "nice to have"—it is a legal requirement under the Money Laundering Regulations 2017 if you fall within the "relevant persons" category (such as tax advisers, accountants, or estate agents).
Understanding the Risk Assessment
Before you write your policy, you must understand your risks. A firm-wide risk assessment is a document where you look at your business objectively and identify where it is most vulnerable to being used by criminals to hide the proceeds of crime.
To complete this, you should consider four main "risk pillars":
- Customer Risk: Do you deal with high-net-worth individuals, politically exposed persons (PEPs), or businesses with complex ownership structures?
- Geographic Risk: Do you or your clients operate in countries with high levels of corruption or inadequate AML regulations?
- Product/Service Risk: Are your services particularly attractive to money launderers? For example, helping to form companies or handling large cash transactions.
- Delivery Channel Risk: Do you meet all your clients face-to-face, or is your business entirely remote?
Drafting your AML Policy
Your AML policy is the "how-to" guide for your business. It explains the steps you and your staff will take to prevent money laundering based on the risks you identified. It should include:
- The Money Laundering Reporting Officer (MLRO): Clearly state who is responsible for AML compliance in your firm. In a one-person business, this will be you.
- Internal Controls: Outline how you will monitor transactions and identify suspicious activity.
- Reporting Procedures: Detailed steps on how to file a Suspicious Activity Report (SAR) with the National Crime Agency (NCA) if you suspect something is wrong.
- Staff Training: If you have employees, document how often they will be trained on AML and how you will keep their knowledge up to date.
- Record Keeping: State that you will keep records of your risk assessments and client checks for at least five years.
Best Practices for Your Documents
"Your AML policy should be a 'living document'. It isn't something you write once and hide in a drawer; it must reflect how your business actually operates."
To ensure your documents are effective and compliant, follow these tips:
- Avoid generic templates: While templates are a great starting point, you must tailor them to your specific business. An auditor from HMRC or your professional body will quickly spot a "copy-paste" job that doesn't reflect your actual services.
- Be specific: If you've decided you won't take on offshore clients, state that clearly in your policy.
- Review annually: Set a calendar reminder to review your risk assessment every 12 months. If you launch a new service or expand into a new market, update your assessment immediately.
- Keep it simple: Use plain English. If the policy is too complex, it becomes harder to follow, increasing the risk of a compliance breach.
| Document | Focus |
|---|---|
| Risk Assessment | Identifying where the danger is. |
| AML Policy | Outlining what you will do about it. |
Created by hatch. • Updated on May 14, 2026