Skip to content

Practice area 04

AML & Financial Crime Compliance

Financial crime compliance that matches your actual risk profile — documented for regulators, banks and auditors, and practical enough for your operations team to run.

Discuss your matter
A brass magnifying glass over a transaction review ledger with escalated entries marked.

Typical deliverables

  • AML/CFT programme and governance map
  • Enterprise-wide risk assessment
  • AML/CFT and sanctions policy set
  • KYC/KYB, CDD and EDD standards
  • Monitoring scenario specification
  • Audit report and remediation plan
A cross-jurisdiction capability, supported across the jurisdictions in our directory. See jurisdictions

Overview

Why it matters

Regulators increasingly test whether a compliance framework works, not whether it exists. Policies copied from another business, risk assessments that do not reflect the customer base and monitoring rules no one tunes are among the most common findings in inspections.

We design AML/CFT and sanctions programmes from your own enterprise-wide risk assessment upward, provide MLRO capacity where the rules allow the role to be outsourced or supported, and carry out independent AML/CFT audits that show where you stand before a regulator, bank or payment partner does.

Banks, acquirers and payment partners examine the same framework during onboarding and periodic reviews. A programme that holds up to regulatory scrutiny is also one of the strongest supports for keeping banking and payment access.

Scope

What we do

  1. 1.

    AML/CFT Compliance Programme

    Design or rebuild of the whole programme: governance, risk assessment, policies, customer due diligence, monitoring, reporting, record-keeping and training.

  2. 2.

    MLRO-as-a-Service

    An experienced MLRO, a deputy MLRO or structured support to the MLRO you appoint, delivered within the local requirements that apply to your firm.

  3. 3.

    Independent AML/CFT Audit

    Independent testing of the design and effectiveness of your AML/CFT framework, with rated findings and a prioritised remediation plan.

  4. 4.

    Enterprise-Wide Risk Assessment

    A documented assessment of customer, product, delivery channel and geographic risk that drives the controls in every other part of the programme.

  5. 5.

    KYC / KYB / CDD / EDD Frameworks

    Onboarding, verification and due diligence standards for individuals and businesses, including beneficial ownership, source of funds and source of wealth.

  6. 6.

    Transaction Monitoring Frameworks

    Scenarios and thresholds calibrated to your products, alert handling and escalation workflows, and support with selecting monitoring vendors.

  7. 7.

    Sanctions & PEP Compliance

    Screening scope, list management, match handling and escalation for sanctions and politically exposed persons.

  8. 8.

    AML Policies & Procedures

    Policies, procedures and controls written for your products, customers and jurisdictions — and for the people who have to apply them.

  9. 9.

    AML Remediation

    Structured remediation of audit, inspection or bank findings: root-cause analysis, look-backs, file remediation and evidence of closure.

  10. 10.

    Regulatory Inspection / Examination Support

    Preparing for inspections and examinations, supporting management during the visit and responding to findings.

Questions

Frequently asked

Can you act as our MLRO?

Where the regulator permits the role to be outsourced, we can provide it through our MLRO-as-a-Service arrangement. Where the MLRO must be an employee or resident in the jurisdiction, we support the MLRO you appoint instead. We confirm what is permitted before designing anything.

We have an inspection coming up. Can you help us prepare?

Yes. A pre-inspection review focuses on the areas regulators typically test — risk assessment, customer files, monitoring outcomes and governance — and gives you time to remediate before the visit.

Our bank has asked about our AML framework. What should we send?

Usually a summary of the programme, the latest risk assessment, key policies and, increasingly, the most recent independent audit and the status of its findings. We prepare a consistent pack so that the answers match what the bank has already seen.

Related

  • Regulatory, business model, perimeter, payment, gaming, crypto-asset and cross-border opinions for banks, partners and investors.

  • Bank account opening, merchant account and acquiring setup, payment flows and safeguarding for businesses banks consider high-risk.

  • Privacy compliance and GDPR programmes, notices and DPAs, DPIAs, data mapping and ROPA, transfers, audits and breach response.

  • Licence strategy, applications and regulator engagement for gaming, payments, e-money, investment and crypto-asset businesses.

All 11 practice areas

Discuss your matter with a senior advisor.

Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.