Your AML compliance program needs a written policy that works across borders without requiring separate documents for each regulator. This template provides a structure that satisfies Bank Secrecy Act requirements, addresses Fourth and Fifth Anti-Money Laundering Directives expectations, and meets Financial Transactions and Reports Analysis Centre standards, all in one document.
Purpose of This Template
This policy template establishes the foundation your compliance team needs to document customer due diligence procedures, transaction monitoring protocols, and reporting obligations across U.S., EU, and Canadian operations. It's designed for financial institutions that need to maintain consistent controls while addressing jurisdiction-specific requirements.
Use this when:
- Building your first AML policy for a new entity
- Consolidating separate policies after a merger
- Updating a legacy policy that doesn't address current regulatory expectations
- Preparing for an independent audit
This isn't a compliance program. It's the written policy that documents your program's existence and structure.
Prerequisites
Before customizing this template, ensure you have:
Regulatory registrations: Active registration with FinCEN (if U.S.-based), relevant EU member state financial intelligence unit, or FINTRAC (if Canadian operations exist).
Risk assessment: A completed institutional risk assessment that identifies your customer segments, product risks, and geographic exposure.
Governance structure: A designated AML compliance officer with authority and resources.
Systems access: Transaction monitoring tools capable of generating alerts and audit trails.
Training records: A system for tracking who received training and when.
Without these elements, your policy will document procedures you can't execute. Fix the infrastructure first.
The Template
Section 1: Policy Statement and Scope
[INSTITUTION NAME] maintains this Anti-Money Laundering Policy to prevent the use of our financial services for money laundering, terrorist financing, or other illicit purposes. This policy applies to all employees, contractors, and agents across [LIST JURISDICTIONS].
We comply with:
- Bank Secrecy Act and FinCEN regulations (U.S. operations)
- Fourth and Fifth Anti-Money Laundering Directives (EU operations)
- Proceeds of Crime (Money Laundering) and Terrorist Financing Act (Canadian operations)
Section 2: Customer Due Diligence
Standard CDD Requirements: All customer relationships require:
- Identity verification using [SPECIFY DOCUMENTS/METHODS]
- Beneficial ownership identification for entities (25% ownership threshold for U.S.; 25% for EU; control-based for Canada)
- Purpose and nature of relationship documentation
- Risk rating assignment: Low, Medium, High, Prohibited
Enhanced Due Diligence: High-risk relationships require:
- Senior management approval before onboarding
- Source of funds verification
- Politically Exposed Person screening
- Ongoing monitoring frequency: [SPECIFY INTERVAL]
High-risk indicators include [LIST YOUR INSTITUTION'S RISK FACTORS].
Section 3: Transaction Monitoring
We monitor transactions for patterns consistent with money laundering typologies, including structuring, layering, and integration schemes.
Reporting thresholds:
- U.S. operations: Currency Transaction Reports for cash exceeding $10,000 per day
- All jurisdictions: Suspicious Activity Reports when transaction patterns meet internal alert criteria
Alert investigation: Compliance staff investigate alerts within [SPECIFY TIMEFRAME]. Investigations document:
- Transaction pattern analysis
- Customer explanation (if contact is appropriate)
- Disposition: Clear, escalate, or file SAR
Section 4: Watchlist Screening
We screen customers and transactions against:
- Office of Foreign Assets Control sanctions lists (U.S.)
- EU consolidated financial sanctions list
- Canadian sanctions lists
- Politically Exposed Person databases
- [ADD INSTITUTION-SPECIFIC LISTS]
Screening occurs at onboarding and [SPECIFY ONGOING FREQUENCY].
Section 5: Independent Testing
We conduct independent audits every 12-18 months. Audits in high-risk areas occur more frequently.
Audit scope includes:
- Policy and procedure adequacy
- Risk assessment accuracy
- Transaction monitoring effectiveness
- Training completion rates
- SAR quality and timeliness
Section 6: Training
Initial training: All employees complete AML training within [SPECIFY TIMEFRAME] of hire.
Ongoing training: Annual refresher training for all staff; semi-annual for compliance officers and relationship managers.
Role-specific training: [SPECIFY ROLES] receive targeted training on [SPECIFY TOPICS].
Section 7: Recordkeeping
We retain:
- Customer identification records: 5 years after relationship termination
- Transaction records: 5 years after transaction date
- SARs and supporting documentation: 5 years after filing
- Training records: Duration of employment plus 5 years
Customization Instructions
Replace bracketed placeholders with your institution's specifics. Don't leave "[SPECIFY]" in your final document.
Adjust risk factors in Section 2 to match your institutional risk assessment. If you don't serve cash-intensive businesses, don't list cash structuring as a primary risk. If you operate correspondent banking relationships, add those risks.
Set monitoring thresholds in Section 3 based on your transaction monitoring system's capabilities and your risk appetite. Document why you chose these thresholds in your risk assessment.
Define "high-risk areas" for audit frequency based on your operations. High-risk typically means jurisdictions with weak AML controls, products with anonymity features, or customer segments with elevated typology exposure.
Add jurisdiction-specific sections if you operate in additional countries. Each jurisdiction gets its own regulatory reference and reporting requirement.
Link to procedures: This policy should reference detailed procedures maintained separately. Example: "Customer due diligence procedures are documented in [PROCEDURE MANUAL NAME]."
Validation Steps
Before finalizing this policy:
Legal review: Have counsel in each operating jurisdiction confirm the policy addresses local requirements. The Bank Secrecy Act, Anti-Money Laundering Directives, and FINTRAC regulations each have nuances this template can't fully capture.
Board approval: Your board or equivalent governing body must approve this policy. Document that approval with meeting minutes.
System alignment: Verify your transaction monitoring system can execute what the policy promises. If your policy says you screen transactions in real-time but your system batches overnight, you've documented a control you don't have.
Staff accessibility: Publish this policy where relationship managers and compliance staff can access it. A policy that lives only in the compliance officer's files doesn't guide behavior.
Annual review: Schedule a recurring review every 12 months. Regulations change; your policy should reflect current requirements, not last year's framework.
This template documents your commitment to AML compliance. The real work happens in the procedures, systems, and training that bring these words to life.



