AML compliance is the set of policies, procedures, and controls that financial institutions and regulated businesses must maintain to detect, prevent, and report money laundering and terrorist financing.
The Financial Action Task Force (FATF) — the global standard-setter — evaluates AML frameworks across 205 jurisdictions, and even major economies consistently fall short on effectiveness.
In 2025, the U.S. Securities and Exchange Commission fined Merrill Lynch $7.5 million for failing to file suspicious activity reports over a four-year period — a penalty triggered not by missing policies, but by a flawed automated monitoring system that suppressed alerts scoring below an internal threshold of 20.
The gap between having an AML program and having one that works is where most compliance failures occur. Let's dive in and go through:
- The 3 stages of money laundering and why they shape AML program design
- Real enforcement cases from 2024-2026 and what they reveal
- How KYC, CDD, and EDD differ (and when each applies)
- Why graph analytics and AI are changing detection
- The five pillars of an AML compliance program
How does money laundering work?
Money laundering follows three stages — and AML programs are designed to detect activity at each one.
Placement
Illicit funds enter the financial system. Cash deposits, currency exchanges, and purchases of monetary instruments (money orders, prepaid cards) are common methods.
Structuring — splitting large amounts into smaller deposits to avoid reporting thresholds — is one of the oldest and most frequently detected placement techniques.
Layering
The money moves through a series of transactions designed to obscure its origin.
Wire transfers between accounts, shell company transactions, trade-based invoice manipulation, and cross-border movements create distance between the funds and their source.
This stage is where international remittances and cross-border payments become compliance flashpoints — not because remittances are inherently suspicious, but because the volume and speed of cross-border flows create opportunities for layering to go undetected.
Integration
Cleaned funds re-enter the legitimate economy through real estate purchases, business investments, luxury goods, or other assets.
By this point, the money appears legitimate — which is why detection at the placement and layering stages is far more effective than trying to trace integrated funds.
What are the five pillars of an AML compliance program?
Regulators in Canada, the U.S., and most FATF member jurisdictions require financial institutions to maintain programs built on five pillars.
| Pillar | What it requires |
|---|---|
| Compliance officer | A designated individual with authority and access to report directly to senior management |
| Internal controls | Written policies covering customer onboarding, transaction monitoring, screening, and reporting |
| Risk assessment | A documented evaluation of money laundering and terrorist financing risks specific to the institution |
| Independent testing | Regular audits (internal or external) to validate that controls are working |
| Training | Ongoing employee education on AML obligations, red flags, and reporting procedures |
The five-pillar model is not aspirational — it is the minimum regulatory expectation. Enforcement actions (including Merrill Lynch's $7.5 million SEC penalty in 2025) typically cite failures in one or more of these pillars as the root cause.
How do KYC, CDD, and EDD differ?
These three terms are related but serve different functions within an AML program.
Know your customer
KYC is the process of identifying and verifying a customer's identity at onboarding.
It answers the baseline question: who is this person or entity? For businesses, KYC includes verifying legal names, addresses, identification documents, and (where applicable) beneficial ownership structures.
Customer due diligence
CDD goes deeper. It assesses the customer's risk profile — the nature of their business, expected transaction patterns, source of funds, and geographic exposure. CDD determines how closely the institution should monitor the relationship going forward.
For Canadians navigating financial literacy as newcomers, understanding that banks assess customer risk is important context for why onboarding paperwork can feel extensive.
Enhanced due diligence
EDD applies to higher-risk customers — politically exposed persons (PEPs), customers in high-risk jurisdictions, complex corporate structures, or accounts flagged by transaction monitoring. EDD involves deeper investigation into the source of wealth, more frequent reviews, and senior management approval.
| Level | When it applies | Depth |
|---|---|---|
| KYC | All customers at onboarding | Identity verification |
| CDD | All customers (ongoing) | Risk profiling and expected activity |
| EDD | High-risk customers only | Source of wealth, senior review, enhanced monitoring |
What does transaction monitoring actually detect?
Transaction monitoring is the automated surveillance of customer activity against predefined rules, thresholds, and behavioral patterns.
When a transaction triggers an alert, a compliance analyst investigates and determines whether to file a suspicious activity report (SAR) with the relevant financial intelligence unit.
Rule-based monitoring
Traditional systems flag transactions based on fixed rules — amounts exceeding thresholds, transfers to high-risk jurisdictions, rapid movement of funds, or patterns consistent with structuring.
The Merrill Lynch case illustrates the danger of rigid rule-based systems: alerts scoring below an arbitrary threshold of 20 were automatically suppressed, causing hundreds of millions of dollars in suspicious transactions to go unreported.
AI and graph analytics
A 2024 systematic review by Deprez, Vanderschueren, Baesens, Verdonck, and Verbeke analyzed 97 AML detection studies and concluded that graph neural networks — which analyze the network structure of transactions rather than individual transactions in isolation — achieved the highest predictive performance of any method tested.
A separate 2025 study using data from Alipay and E-Commerce Bank analyzed over 200 million customer accounts and 300 million transactions, finding that cross-institution collaboration dramatically improved detection of laundering networks that single-institution monitoring systems missed entirely.
For businesses managing Interac e-Transfer limits, understanding that transaction monitoring systems track patterns across transfer types — not just individual amounts — provides useful context for why transfers may occasionally be flagged for review.
What do recent enforcement cases reveal?
Enforcement actions in 2024-2026 highlight a shift from penalizing missing policies to penalizing ineffective implementation.
| Case | Year | Penalty | Root cause |
|---|---|---|---|
| Merrill Lynch | 2025 | $7.5 million | Automated system suppressed alerts below threshold of 20, causing SAR filing failures |
| UAE foreign bank branch | 2025 | AED 20 million (~$5.4M) | Inadequate monitoring systems and deficient controls post-grey-list removal |
| US AML fines (aggregate) | 2024→2025 | $4.3B → $1.7B | 61% decline in US fines as enforcement shifted geographically (Financial Times) |
The Financial Times reported that U.S. AML and sanctions fines declined 61% year over year in 2025, while enforcement activity increased in France, Switzerland, the U.K., Canada, and the UAE. The trend is clear: AML enforcement is becoming geographically distributed rather than U.S.-centric.
A 2025 econometric study by Jensen, Hansen, and Rose examined European AML data and found that increasing the volume of suspicious transaction reports does not necessarily yield proportional increases in money-laundering convictions — a finding that challenges the assumption that "more reporting = better outcomes."
Effective AML compliance increasingly depends on the quality of detection and investigation, not just the quantity of reports filed.
How is AML compliance evolving?
Three trends are reshaping AML programs worldwide.
AI-driven detection
Graph neural networks, behavioral analytics, and entity resolution are replacing (or supplementing) rigid rule-based monitoring, reducing false positives and improving detection of complex laundering schemes.
Cross-institution collaboration
The Alipay/ECB study (200M+ accounts, 300M+ transactions) demonstrated that sharing anonymized transaction data across institutions dramatically improves network-level detection.
Beneficial ownership transparency
Even the U.S. (which scored 9 Compliant, 23 Largely Compliant, 5 Partially Compliant, and 3 Non-Compliant on FATF ratings) continues to struggle with identifying the true owners behind corporate structures.
The FATF's 2025 terrorist financing risk assessment confirmed that informal value transfer systems (including hawala), virtual assets, and trade-based laundering remain the highest-risk channels — areas where traditional rule-based monitoring is least effective and where AI-driven network analysis shows the most promise.
Frequently asked questions
Here are some commonly asked questions about AML compliance:
What are the three stages of money laundering?
The three stages are placement (introducing illicit funds into the financial system), layering (moving funds through complex transactions to obscure their origin), and integration (re-entering cleaned funds into the legitimate economy through investments, real estate, or business activities). AML programs are designed to detect suspicious activity at each stage, though detection is most effective during placement and layering, before the funds have been fully integrated into legal commerce.
What is the difference between AML and KYC?
AML is the entire compliance framework — policies, risk assessments, monitoring systems, reporting obligations, training, and governance. KYC is one component within that framework, specifically the process of verifying a customer's identity at onboarding and ongoing due diligence. Every KYC process is part of AML compliance, but AML compliance includes much more than KYC alone, including transaction monitoring, sanctions screening, suspicious activity reporting, and independent auditing.
Who needs AML compliance?
Any business that handles financial transactions and operates in a FATF member jurisdiction is potentially subject to AML requirements. In Canada, this includes banks, credit unions, money service businesses, securities dealers, real estate brokers (in some provinces), accountants, casinos, and dealers in precious metals. The specific obligations depend on the institution type and the jurisdiction's regulations. FINTRAC (Financial Transactions and Reports Analysis Centre of Canada) administers AML compliance for Canadian entities.
What happens if an AML program fails?
Consequences range from regulatory fines and consent orders to criminal prosecution of responsible individuals. The Merrill Lynch case resulted in a $7.5 million penalty for SAR filing failures. Larger cases — such as Danske Bank's estimated €200 billion laundering scandal — have resulted in billions in fines, executive criminal charges, and permanent reputational damage. Regulators can also impose business restrictions, require independent monitors, or revoke operating licences.
How is AI changing AML compliance?
AI improves AML detection in three ways. Graph neural networks analyze transaction networks (rather than individual transactions) to identify complex laundering patterns that rule-based systems miss. Behavioral analytics detect deviations from a customer's normal activity rather than relying on fixed thresholds. Entity resolution connects fragmented identity data across systems to identify related accounts and beneficial owners. A 2024 review of 97 AML studies (Deprez et al.) found that graph neural networks produced the strongest detection performance of any method evaluated.



