What is Anti-Money Laundering (AML): A Strategic Guide for Founders

This guide breaks down Anti-Money Laundering (AML) compliance for crypto, FinTech, and digital asset founders; covering core regulations, key global authorities, the five essential compliance pillars, and practical strategies to meet jurisdictional standards.

What is Anti-Money Laundering (AML): A Strategic Guide for Founders image
Anastasia Marchenko photo
Anastasia Marchenko Legal Researcher at LegalBison
Sep, 10 2026 11 minutes

Anti-money laundering (AML) refers to the laws, regulations, and internal controls that prevent criminals from disguising illegally obtained money as legitimate income. The global AML framework is coordinated by the Financial Action Task Force (FATF), an intergovernmental body whose 40 Recommendations serve as the international standard for more than 190 jurisdictions.

For founders building a crypto, FinTech, or digital asset business, AML is not an abstract compliance topic. It determines which jurisdiction makes sense to register in, which banks will open an account, and how smoothly a licensing application moves through a regulator. Businesses that need a regulated structure should also review LegalBison’s guide to company formation and AML compliance services.

The scale of the problem is significant. The United Nations Office on Drugs and Crime (UNODC) estimates 2% to 5% of global GDP ($800B to $2T USD), is laundered each year (UNODC). AML regulations exist to disrupt that flow.

How money laundering works

The pattern behind money laundering stays consistent even though the underlying crime varies. Regulators have identified three stages, and AML programs target controls at each one.

  • Placement is the first step: getting illicit funds into the financial system. Someone might deposit cash into a bank account, buy cryptocurrency through a peer-to-peer platform, or move money through a shell company’s business account. Placement is the point where the money is most exposed and most likely to raise a flag.
  • Layering comes next, as the launderer runs the funds through a series of transactions meant to break the trail back to the original crime. In traditional finance, that might mean wiring money between accounts in different countries. With digital assets, it can mean swapping between tokens, routing through mixing services, or bridging assets across chains to obscure the transaction history.
  • Integration is the last stage, when the laundered funds re-enter the economy looking clean. The money might go toward real estate, a business investment, or ordinary spending. Once integration is complete, tracing the funds back to their criminal source becomes much harder.

A concrete example: a drug trafficking organization deposits USD 50,000 in cash across three bank accounts (placement). The money gets wired through two shell companies in different countries and converted to cryptocurrency (layering). A real estate purchase is then made with a partially legitimized down payment (integration). Each stage leaves traces, but AML programs exist to detect those traces before the cycle completes.

What AML laws require: the five pillars

Every AML program regulators recognize rests on five core obligations. A business that skips any one of them will struggle to pass regulatory review or open a bank account.

1. Compliance officer designation

A designated individual must oversee the AML program. This person, sometimes called a Money Laundering Reporting Officer (MLRO) or Chief Compliance Officer (CCO), is responsible for ensuring the program meets regulatory requirements and for escalating suspicious activity to management and regulators.

2. Internal policies and procedures

Written policies must document how the business identifies, assesses, and mitigates money laundering risk. These documents must reflect the company’s actual risk profile, not a generic template.

3. Customer due diligence (KYC)

Know Your Customer (KYC) means verifying who a customer actually is before establishing a relationship. In practice, that involves collecting identification documents, confirming beneficial ownership for corporate customers, and screening against sanctions and politically exposed persons (PEP) lists. Higher-risk customers get enhanced due diligence: deeper verification and closer ongoing monitoring.

Under FinCEN’s Customer Due Diligence (CDD) Rule in the United States, CDD has four core requirements: identifying and verifying the customer’s personally identifiable information, identifying beneficial owners with a 25% or more stake, understanding the nature and purpose of the customer relationship, and monitoring for suspicious transactions.

4. Transaction monitoring and reporting

Ongoing monitoring watches for activity that does not fit a customer’s expected profile: unusually large transfers, rapid movement of funds, or patterns that look like structuring (breaking transactions into smaller amounts to dodge reporting thresholds).

When a transaction looks suspicious, the business files a Suspicious Activity Report (SAR) with the relevant regulator. In the United States, SARs must be filed within 30 days of detection. Many jurisdictions also require Currency Transaction Reports (CTRs) once transactions cross a set threshold, whether or not anything looks suspicious.

5. Independent review

An independent third party must periodically test the AML program to confirm it is working as designed and meeting regulatory expectations. This is not optional: regulators treat the absence of independent testing as a program failure.

Who enforces AML rules

AML enforcement works on two levels: a global standard-setter, and national regulators who each implement that standard in their own way.

Global: FATF

The Financial Action Task Force (FATF) sets the global benchmark through its 40 Recommendations, last updated in June 2026 (FATF Recommendations). FATF has no direct enforcement power, but it maintains grey and black lists of non-compliant jurisdictions. Landing on either list makes it much harder for a country’s financial institutions to access international banking relationships.

In June 2025, FATF finalized significant changes to Recommendation 16 on Payment Transparency, strengthening requirements for cross-border payment traceability. In February 2025, FATF strengthened its standards on the risk-based approach under Recommendation 1.

United States: FinCEN and the BSA

The Financial Crimes Enforcement Network (FinCEN) administers the Bank Secrecy Act (BSA), the foundational US AML law requiring financial institutions to run AML programs and file SARs and CTRs.

The Anti-Money Laundering Act of 2020 (AMLA) is the biggest overhaul of US AML law in decades. It expanded beneficial ownership reporting through the Corporate Transparency Act, strengthened whistleblower protections, and required FinCEN to establish national AML/CFT priorities.

In April 2026, FinCEN proposed a rule to fundamentally reform financial institution AML/CFT programs, refocusing compliance on risk-based, reasonably designed programs rather than checkbox compliance (FinCEN NPRM, April 7, 2026). The proposed rule would distinguish between program design deficiencies and implementation deficiencies, and affirm FinCEN’s central role in AML/CFT supervision.

European Union: the AMLR package

The EU is in the middle of a major structural shift. The Anti-Money Laundering Regulation (AMLR, Regulation 2024/1624), adopted on May 31, 2024, replaces the old directive-based approach with a single rulebook that applies directly across member states (EUR-Lex). The AMLR applies from July 10, 2027.

A new Anti-Money Laundering Authority (AMLA), based in Frankfurt, will directly supervise the highest-risk financial entities. Under the AMLR, AMLA was required to submit various draft regulatory technical standards to the Commission by July 10, 2026, including RTS on customer due diligence and group-wide requirements. AMLA has published several for consultation, though not all met the original deadline.

Businesses operating across several EU jurisdictions should track this transition closely, since compliance obligations will tighten as the framework phases in.

United Kingdom

The UK applies the Money Laundering Regulations 2017 (MLR 2017), enforced by the Financial Conduct Authority (FCA). The UK framework stayed close to EU standards after Brexit, though the two regimes are starting to diverge as the EU’s AMLR takes effect.

Singapore

The Monetary Authority of Singapore (MAS) enforces AML obligations under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act (CDSA), with additional requirements for payment and digital token service providers under the Payment Services Act.

Each of these regimes reads the FATF standard differently, which is why the same crypto business can find AML compliance straightforward in one jurisdiction and difficult in another. For a deeper look at how the EU framework applies to crypto businesses, see LegalBison’s MiCA license list and CASP license adaptation guides.

AML for crypto and digital asset businesses

Crypto AML compliance is where most founders get caught off guard, since the obligations look similar to traditional finance on paper but play out very differently in practice.

The Travel Rule

The Travel Rule, set out globally under FATF Recommendation 16 and updated in June 2025, requires originator and beneficiary information to travel alongside a transaction. In the EU, this obligation extends through the Transfer of Funds Regulation (Regulation 2023/1113) to transfers involving self-hosted wallets above a EUR 1,000 threshold, a lower bar than most founders expect.

VASP vs. CASP

Under FATF’s framework, crypto businesses are classified as Virtual Asset Service Providers (VASPs). In the EU, the equivalent designation is Crypto-Asset Service Provider (CASP) under the Markets in Crypto-Assets Regulation (MiCA). Whether a project needs CASP authorization or a VASP registration elsewhere depends on the specific activity involved: custody, exchange, transfer, or some combination. Explore the distinctions between VASP, CASP, and DASP in this coverage.

Blockchain analytics and KYT

Crypto AML also depends on tools traditional finance rarely needs. Blockchain analytics platforms trace the flow of funds across public ledgers, flagging wallets linked to sanctioned addresses, mixing services, or known illicit activity. This practice, often called Know Your Transaction (KYT), works alongside standard KYC and gives crypto businesses visibility that traditional monitoring tools cannot match.

The ongoing monitoring mistake

The most common mistake among crypto founders is treating AML as a one-time onboarding check instead of an ongoing program. A wallet that passes KYC on day one can still receive funds from a sanctioned address on day two, and regulators expect continuous monitoring to catch exactly that.

Why AML compliance matters for your business

AML compliance determines whether a business can operate at all.

Legal and financial penalties

Get it wrong, and the consequences range from significant fines to criminal liability for individual executives. TD Bank was fined USD 3 billion in 2024 for inadequate guards against money laundering linked to drug cartels and other criminals. From 2008 through 2020, AML and Know Your Customer violations accounted for roughly USD 26 billion in global fines, according to industry research.

Banking access

Banks will not open or maintain an account for a business without a documented AML program. Banking access is a prerequisite for basic operations, not an advanced compliance milestone.

Investor due diligence

Venture capital firms increasingly check a target’s AML posture during due diligence, especially for crypto and payments deals. A weak AML program signals regulatory risk that investors price into their terms.

Jurisdictional risk

A jurisdiction’s spot on the FATF grey list can restrict which markets a business can serve, since correspondent banks grow wary of counterparties tied to grey-listed countries.

How LegalBison helps

LegalBison builds AML compliance programs for crypto, FinTech, and digital asset businesses from scratch.

  • That starts with jurisdiction selection: working out which AML regime applies to a given business model and structuring the entity to meet those requirements from day one.
  • From there, LegalBison’s advisory team puts together the compliance program itself: KYC and due diligence procedures, transaction monitoring, and reporting workflows built around the client’s actual risk profile.
  • For businesses that need ongoing oversight but do not want to hire a full-time officer, LegalBison also offers fractional compliance officer support.

Founders still deciding where to register their business should also look at LegalBison’s guidance on company formation, since jurisdiction and AML obligations get decided together, not one after the other.

To talk through an AML program for a specific business model, get in touch with LegalBison.

FAQ about AML

What is the difference between AML and KYC?

AML is the broad framework of laws and controls used to prevent money laundering and terrorist financing. KYC (Know Your Customer) is one piece of that framework: the process of verifying a customer’s identity before and during the business relationship.

What are the penalties for AML violations?

Penalties vary by jurisdiction but typically include significant fines, loss of an operating license, and possible criminal liability for the people responsible. In the United States, FinCEN and the Department of Justice have imposed penalties reaching into the hundreds of millions and billions of dollars for serious institutional failures. TD Bank’s USD 3 billion fine in 2024 is one of the largest AML penalties to date.

Do crypto exchanges need AML compliance?

Yes. Crypto exchanges count as Virtual Asset Service Providers under FATF standards and as Crypto-Asset Service Providers under the EU’s MiCA framework. Both classifications carry the same core AML obligations as traditional financial institutions: KYC, transaction monitoring, and Travel Rule compliance. For exchange-specific guidance, see LegalBison’s crypto exchange license overview.

What is the FATF Travel Rule?

The Travel Rule, set out in FATF Recommendation 16 and updated in June 2025, requires financial institutions and VASPs to pass originator and beneficiary information along with a fund transfer. For crypto transactions in the EU, that applies to transfers involving self-hosted wallets above EUR 1,000.

What is the Corporate Transparency Act?

The Corporate Transparency Act (CTA), enacted as part of the Anti-Money Laundering Act of 2020, requires certain companies to report beneficial ownership information to FinCEN. The goal is to prevent the use of anonymous shell companies to launder money or evade sanctions. The CTA’s beneficial ownership information reporting requirements became effective on January 1, 2024.

How often do AML rules change?

Often, and the pace has picked up as digital assets have grown. FATF updated its 40 Recommendations in June 2026, finalized changes to Recommendation 16 on Payment Transparency in June 2025, and the EU’s AML framework is shifting from a directive-based system to a directly applicable regulation between 2025 and 2027. In the United States, FinCEN proposed a major reform of AML/CFT program requirements in April 2026. Businesses operating across multiple jurisdictions should review their compliance program at least once a year, or whenever a regulator in an active market announces a change.

Share this article on