How to Write an Anti-Money Laundering (AML) Policy for Non-Bank Businesses
How to Write an Anti-Money Laundering (AML) Policy for Non-Bank Businesses | PolicyTrak
PolicyTrak›
How to Write an Anti-Money Laundering (AML) Policy for Non-Bank Businesses
AML Policy Guide
How to Write an Anti-Money Laundering (AML) Policy for Non-Bank Businesses
Anti-money laundering (AML) compliance has historically been associated primarily with banks, but AML obligations have expanded substantially to cover non-bank businesses — money services businesses, real estate firms, dealers in precious metals and stones, certain digital asset operations, art and antiquities dealers, and others. Non-bank businesses subject to AML obligations face requirements that look familiar to bank compliance teams but often surprise leadership at non-financial organizations. The right AML policy framework identifies the specific obligations that apply, establishes customer due diligence and beneficial ownership requirements, implements suspicious activity monitoring, and includes training. This guide covers practical AML framework for non-bank organizations.
Anti-money laundering (AML) compliance has historically been associated primarily with banks and traditional financial institutions, but AML obligations have expanded substantially to cover non-bank businesses — money services businesses, real estate firms, dealers in precious metals and stones, certain digital asset operations, art and antiquities dealers, and others. Non-bank businesses subject to AML obligations face requirements that look familiar to bank compliance teams but often surprise leadership at non-financial organizations. The right AML policy framework for a non-bank business identifies the specific obligations that apply (which vary by business type and jurisdiction), establishes the customer due diligence and beneficial ownership requirements, implements suspicious activity monitoring and reporting, addresses high-risk transaction categories, includes training requirements, and provides the documentation that examination will request. This guide covers practical AML policy framework for non-bank organizations subject to these obligations.
Why AML Reaches Beyond Banks
Anti-money laundering regulation in the United States originated with the Bank Secrecy Act in 1970, applying initially to traditional banks and depository institutions. The framework has expanded substantially over subsequent decades through various legislative additions, FinCEN regulations, and Treasury Department guidance. The expansion reflects regulatory recognition that money laundering doesn’t only flow through banks — it moves through real estate transactions, money services businesses, precious metals dealers, art markets, casino operations, and increasingly digital asset platforms. Closing AML gaps required extending regulatory frameworks beyond banks to the broader population of businesses that handle financial transactions.
The expansion continues. The Corporate Transparency Act (effective in 2024) created beneficial ownership reporting requirements applying broadly to U.S. businesses. The Anti-Money Laundering Act of 2020 expanded AML coverage to antiquities dealers. FinCEN has proposed expanded coverage to real estate transactions and investment advisers. The trend suggests continued expansion rather than stabilization, with more business categories likely to face AML obligations over time.
For non-bank businesses subject to these obligations, the requirements can be substantial. Money services businesses face customer identification programs, suspicious activity reporting, currency transaction reporting, and other obligations under the BSA. Real estate professionals in certain categories face customer due diligence requirements on cash purchases above thresholds. Dealers in precious metals, stones, and jewels face specific BSA requirements. Antiquities dealers face newly-applicable requirements. Casinos face longstanding obligations including comprehensive customer monitoring.
The challenge for non-bank businesses is often less about the complexity of AML rules than about the compliance infrastructure they require. Banks have built sophisticated AML programs over decades with dedicated staff, specialized systems, and integrated workflows. Non-bank businesses often need to develop comparable compliance capability without the resources or institutional knowledge banks have accumulated. The investment is meaningful, the timeline can be compressed (especially when new obligations apply suddenly), and the consequences of inadequate compliance can include substantial penalties and reputational damage.
AML Policy Components
Customer Identification Program (CIP)
Requirements for identifying customers, verifying identity, maintaining records of verification, and refusing transactions when identity cannot be verified. The CIP is the foundation of AML programs.
Customer Due Diligence (CDD)
Requirements for understanding customer relationships — purpose of accounts or transactions, expected activity, beneficial ownership of legal entity customers. CDD extends beyond identity verification to relationship understanding.
Enhanced Due Diligence (EDD)
Additional scrutiny for higher-risk customers — politically exposed persons, customers from high-risk jurisdictions, customers in high-risk industries. EDD includes deeper investigation and ongoing monitoring.
Beneficial Ownership Identification
Identifying the natural persons who ultimately own or control legal entity customers. Beneficial ownership requirements have expanded substantially with the Corporate Transparency Act and similar developments.
Suspicious Activity Monitoring
Ongoing monitoring of customer transactions for activity that may indicate money laundering, terrorist financing, or other illicit activity. Detection systems range from simple rule-based monitoring to sophisticated analytics depending on business size and complexity.
Suspicious Activity Reporting (SAR)
Filing SARs with FinCEN when suspicious activity is detected, within required timeframes, with appropriate detail. The SAR process is one of the most distinctive AML obligations.
Currency Transaction Reporting (CTR)
For businesses that handle cash, reporting cash transactions above $10,000 to FinCEN through CTRs. The CTR process is mechanical compliance with specific reporting thresholds.
Recordkeeping
Retention of records supporting AML compliance — customer identification documentation, transaction records, monitoring outputs, investigation files, training records. Specific retention requirements apply.
Independent Testing
Periodic independent review of the AML program — testing whether controls operate as designed, identifying gaps, supporting program improvement. Independent testing requirements apply to many AML programs.
Training
Training for staff with AML responsibilities — initial training, periodic refresh, specialized training for higher-risk roles. Training requirements apply to specific staff categories.
Who Faces These Obligations
1
Money Services Businesses
MSBs — money transmitters, currency exchangers, check cashers, prepaid card issuers, certain digital asset businesses — face comprehensive AML obligations including registration with FinCEN, full BSA programs, and substantial compliance infrastructure.
2
Casinos and Card Clubs
Casinos with gross annual gaming revenue above thresholds face comprehensive AML programs including customer identification, transaction monitoring, SAR reporting, and CTR reporting. The obligations have applied since the 1980s and are well-established.
3
Dealers in Precious Metals, Stones, and Jewels
Dealers above defined thresholds (currently $50,000 in qualifying purchases and sales annually) face specific BSA requirements including written AML programs.
4
Antiquities Dealers
Antiquities dealers face newly-applicable AML requirements following the Anti-Money Laundering Act of 2020 expansion. Specific implementation details continue to develop.
5
Real Estate Professionals
Specific real estate categories face customer identification requirements under existing geographic targeting orders, with expanded coverage proposed. Specific applicability varies by transaction type and location.
6
Digital Asset Operations
Various digital asset businesses face AML obligations as money transmitters or under specific frameworks. The application has evolved substantially as the digital asset industry has developed.
7
All U.S. Businesses Under CTA
The Corporate Transparency Act applies beneficial ownership reporting requirements broadly to U.S. businesses, with limited exceptions. Even businesses without other AML obligations face CTA reporting.
Building the Program
Risk Assessment First
AML programs are risk-based, with controls calibrated to the specific risks the business faces. The risk assessment identifies customer types, product/service categories, geographies, and transaction patterns that elevate risk. The assessment drives subsequent program design.
Written Program Documentation
The AML program is documented in writing — policy, procedures, system documentation, training materials. The written program is what examiners and auditors review; verbal or undocumented processes don’t satisfy program requirements.
Designated BSA/AML Officer
A designated individual with authority and resources to operate the program. The designation is a regulatory requirement for many AML programs, not just an organizational choice.
System Infrastructure Appropriate to Scale
Small businesses may operate AML with relatively simple infrastructure; larger businesses need more sophisticated systems for monitoring, case management, and reporting. The infrastructure should match scale rather than copy bank infrastructure that’s disproportionate to the business.
Specialized Counsel and Consulting Support
Most non-bank businesses building AML programs benefit from specialized counsel and consultant support. The expertise gap between non-bank operations and AML compliance is substantial; specialized support accelerates program development.
Continuous Improvement
AML programs evolve over time — regulatory developments, enforcement priorities, business changes, lessons from operation. The program includes periodic review and improvement rather than treating the initial build as complete.
Build AML Compliance Without the Bank-Style Overhead
PolicyTrak supports the policy framework around AML programs — the policy itself, training tracking, acknowledgment workflow, and documentation infrastructure — for non-bank businesses building proportionate AML capability.
Through careful review of the specific regulations and any thresholds. Some categories are clearly covered — money services businesses, casinos above revenue thresholds, dealers in precious metals above transaction thresholds. Others depend on specific activities — real estate professionals are covered for certain transaction types in certain locations. The Corporate Transparency Act applies broadly with specific exceptions. The analysis benefits from review by counsel familiar with AML — both the original Bank Secrecy Act framework and the various subsequent expansions. Businesses that are uncertain about coverage should seek specific legal advice rather than assume coverage doesn’t apply; the penalties for non-compliance with applicable AML requirements can be substantial.
AML compliance has specific regulatory requirements with prescribed program elements, while general financial controls are about operational risk management broadly. AML programs require specific elements — customer identification, suspicious activity monitoring, SAR filing, BSA officer designation, training, independent testing — that aren’t part of general financial controls. The penalties for AML non-compliance also differ — failure to file SARs, failure to maintain required records, or failure to operate required program elements can result in substantial civil and criminal penalties under the BSA. General financial controls can be designed flexibly to suit organizational needs; AML compliance has specific regulatory requirements that constrain program design. Both serve risk management purposes, but the regulatory specificity differs substantially.
Substantially, through the Corporate Transparency Act and similar developments. The CTA requires most U.S. companies to report beneficial owners to FinCEN, with limited exceptions (the exceptions cover entities already subject to substantial federal regulation, like banks). Most operating businesses, including non-financial businesses, are subject to the reporting. The reporting includes information about the natural persons who ultimately own or control the reporting company — typically individuals owning 25% or more, plus individuals with substantial control. Initial reports were due by January 2025 for existing companies; new companies must report within specific periods after formation. The requirements continue to evolve as FinCEN issues guidance and as courts address legal challenges. Specific compliance analysis benefits from legal counsel review.
Through programs that satisfy the most restrictive applicable requirements while operating efficiently across jurisdictions. Different countries have different AML frameworks — FATF Recommendations provide international standards, but specific implementation varies. EU member states implement EU directives. UK has its own framework. Asia-Pacific countries have varying requirements. Cross-border businesses typically design programs to meet U.S. requirements (often the most prescriptive) while accommodating specific requirements of other jurisdictions where they operate. Specific multi-jurisdictional analysis benefits from international AML counsel. The general principle is that programs satisfying the most restrictive applicable requirements typically work across jurisdictions, though specific local requirements may require additions.
Varies enormously by business size, complexity, and risk profile. Very small money services businesses may operate AML programs with modest investment — designated BSA officer (often a senior business owner), basic procedures, manual transaction monitoring, periodic training. Larger or higher-risk businesses face substantially higher costs — specialized AML staff, sophisticated transaction monitoring systems, dedicated case management, regular independent testing, ongoing training programs. Industry surveys suggest AML compliance costs for covered businesses can range from low six figures annually for smaller operations to many millions for larger or higher-risk operations. The investment should be proportionate to risk and scale; bank-level investment isn’t appropriate for many non-bank operations, but adequate investment is essential to avoid penalty exposure.
PolicyTrak supports the policy framework around AML programs — AML policy with version control as regulations evolve, acknowledgment workflow for AML-related policies, training tracking for required AML training, and documentation infrastructure. Specialized AML functionality — transaction monitoring systems, SAR case management, customer identification verification, sanctions screening — typically lives in specialized AML platforms or financial crimes compliance systems. PolicyTrak doesn’t replicate that specialized functionality. The combination produces appropriate separation: PolicyTrak owns the policy framework and training tracking; specialized AML tools handle the operational compliance work. For smaller AML programs, PolicyTrak’s general functionality may handle a substantial portion of compliance documentation alongside specialized tools for the operational elements.
⚠️
Legal & Compliance Disclaimer
The information on this page is provided for general informational purposes only and does not constitute legal, HR, or compliance advice. Regulations and standards referenced are complex and require interpretation specific to your organization’s facts, jurisdiction, and circumstances. Always consult qualified legal counsel and your industry-specific compliance professionals before making decisions. PolicyTrak is a software platform — not a law firm. AML requirements vary by business type, jurisdiction, and continue to evolve through FinCEN guidance, regulatory developments, and judicial interpretation. Specific compliance obligations should be reviewed with qualified AML counsel. PolicyTrak is a software platform — not a law firm and not a financial crimes compliance system. All examples and interpretations are illustrative only.