Anti-Money Laundering (AML) Policy (UK) by Study Academy
Updated 29 November 2025
Anti-Money Laundering (AML) Policy sets out a zero-tolerance framework for preventing money laundering, terrorist financing and financial crime in line with UK law. It gives practical guidance on risk-based due diligence, identity verification, suspicious-activity reporting, record retention and staff accountability. Developed by the Study Academy compliance team, experts in UK regulatory training and workplace standards.
Anti-Money Laundering (AML) Policy (UK, 2025 Edition)
Purpose
This Policy sets out the organisation’s framework for preventing its products, services or business operations from being used to facilitate money laundering, terrorist financing or other financial crime.
It is intended to ensure compliance with UK anti-money laundering and counter-terrorist financing legislation and to promote a culture of financial crime risk awareness.
Scope
This Policy applies to all staff, including senior management, and to all business units involved in onboarding customers, processing payments, handling funds, managing business relationships, or providing services that may be exposed to financial crime risk.
Where the organisation falls within the regulated sector, this Policy shall apply in conjunction with the Money Laundering Regulations and guidance from supervisory bodies.
Policy Statement
The organisation will not tolerate money laundering, terrorist financing or the concealment of criminal property. It will take all reasonable steps to identify, assess, monitor and mitigate the risk of financial crime.
Conduct risk-based customer due diligence (CDD) and enhanced due diligence (EDD) where applicable.
Identify and verify the identity of customers and beneficial owners before entering into a business relationship.
Maintain appropriate records to evidence CDD, transactions and decisions.
Report suspicious activity to the firm’s Money Laundering Reporting Officer (MLRO).
Legislative and Regulatory Framework
Proceeds of Crime Act 2002 (POCA)
Terrorism Act 2000
Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended)
Criminal Finances Act 2017
Sanctions and Anti-Money Laundering Act 2018
Relevant sectoral guidance issued by UK supervisory authorities and the UK National Risk Assessment
Roles and Responsibilities
The Board shall approve this Policy and ensure adequate resources for AML compliance.
A Money Laundering Reporting Officer (MLRO) shall be appointed to receive internal suspicious activity reports (SARs), consider them and, where appropriate, submit Suspicious Activity Reports to the National Crime Agency (NCA).
All employees must complete AML training and promptly report any knowledge or suspicion of money laundering.
Risk-Based Approach
The organisation shall conduct an institutional AML risk assessment considering products, services, delivery channels, geography, and customer types.
Higher-risk circumstances (e.g. politically exposed persons, complex ownership structures, high-risk jurisdictions) shall be subject to enhanced due diligence and senior management approval.
Customer Due Diligence
CDD shall be conducted before establishing a business relationship or carrying out an occasional transaction above the applicable threshold.
CDD shall include identifying the customer, verifying identity on the basis of reliable, independent source documents or data, and understanding the purpose and intended nature of the business relationship.
Where the customer is a body corporate, beneficial ownership shall be identified and verified.
Ongoing Monitoring
Transactions and business relationships shall be monitored on a risk-sensitive basis to ensure they are consistent with the organisation’s knowledge of the customer, their business and risk profile.
Unusual or suspicious activity shall be escalated to the MLRO.
Reporting
Any employee who knows or suspects, or has reasonable grounds for knowing or suspecting, that a person is engaged in money laundering must make an internal report to the MLRO without delay.
Tipping-off is prohibited. Employees must not inform a customer that a report has been made.
Record Keeping
Records of CDD, copies of identification documents, transaction records and SARs shall be retained for a minimum of five (5) years, or longer where required by law.
Training and Awareness
All relevant staff shall receive AML training on induction and at least annually thereafter, tailored to the risks of their role.
Review
This Policy shall be reviewed annually or following material legislative or regulatory changes.
About this template
What is this template?
Anti-Money Laundering (AML) Policy (UK) by Study Academy is a free, ready-to-use Policies template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.
When should you use it?
Reach for this Policies template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. This version is drafted with England & Wales in mind, though you should always review the final wording against the laws that apply to you.
What's typically included?
A well-drafted Policies usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.