The AML & KYC tracker is a structured reference covering anti-money laundering and know-your-customer obligations across major jurisdictions. Regulatory frameworks are tightening globally, and the cost of non-compliance - ranging from substantial fines to licence revocations - continues to rise. This hub maps the key rules, deadlines, competent authorities and recent shifts that international businesses must monitor.
Whether you operate a fintech platform, a corporate services firm, a bank or a real estate business, your obligations under anti-money laundering law depend heavily on where you are incorporated, where your clients are based and what activities you conduct. This tracker organises that complexity into a practical, jurisdiction-by-jurisdiction reference.
The tracker is organised around four dimensions that matter most to compliance officers and business owners operating across borders.
Each jurisdiction entry identifies the FATF mutual evaluation status, the most recent legislative changes and the practical timelines for filing and registration obligations. Where a jurisdiction has been grey-listed or placed under enhanced monitoring by the Financial Action Task Force, that status is noted prominently.
Anti-money laundering regulation operates at multiple levels simultaneously. Understanding the hierarchy helps businesses identify which rules take precedence and where gaps in local implementation exist.
The Financial Action Task Force is the intergovernmental body that sets the international standard. Its Forty Recommendations define the baseline for customer due diligence, beneficial ownership transparency, suspicious activity reporting and targeted financial sanctions compliance. FATF conducts mutual evaluations of member jurisdictions and publishes lists of high-risk and monitored countries. A jurisdiction';s FATF status directly affects the due diligence obligations that counterparties in other countries must apply to it.
At the regional level, the European Union has built the most codified supranational AML framework. The successive Anti-Money Laundering Directives - commonly referred to as AMLD - have progressively expanded the scope of obliged entities, tightened beneficial ownership registers and introduced direct supervisory powers at the EU level through the new Anti-Money Laundering Authority, known as AMLA. AMLA is expected to assume direct supervisory responsibility over the highest-risk financial institutions operating across the EU single market.
Outside the EU, regional bodies such as the Asia-Pacific Group on Money Laundering, the Caribbean Financial Action Task Force and MONEYVAL in Europe perform similar peer-review functions and issue their own guidance that supplements FATF standards.
For businesses, the practical consequence is a layered compliance obligation: FATF standards set the floor, regional rules add specificity and national legislation determines the exact filing deadlines, registration requirements and penalties.
EU member states implement AML obligations through national legislation transposing the AMLD framework. The core requirements are broadly consistent: obliged entities must conduct customer due diligence at onboarding, apply enhanced due diligence to politically exposed persons and high-risk third-country nationals, and report suspicious transactions to their national Financial Intelligence Unit.
Beneficial ownership registers are mandatory across the EU. Most member states require legal entities to file beneficial ownership information within a short window of incorporation - typically between seven and thirty days - and to update that information promptly when ownership changes. Failure to maintain accurate beneficial ownership records carries administrative penalties that vary by member state but are generally significant.
In practice, a common mistake made by foreign founders establishing EU subsidiaries is treating the beneficial ownership register as a one-time filing. The obligation is continuous. Any change in the ownership or control structure must be reported, and many member states now cross-reference register data with tax and company filings to identify discrepancies.
The EU';s risk-based approach means that obliged entities must conduct and document a business-wide risk assessment. Supervisors increasingly examine the quality of that assessment during inspections, not merely whether one exists.
The United Kingdom maintains its own AML framework following its departure from the EU. The primary legislation is the Proceeds of Crime Act and the Money Laundering, Terrorist Financing and Transfer of Funds Regulations. The Financial Conduct Authority and His Majesty';s Revenue and Customs are the principal supervisory authorities for financial services and non-financial businesses respectively.
The UK operates a register of persons with significant control, maintained at Companies House. Obliged entities must also register with their relevant supervisor before conducting regulated activity - a step that many non-UK founders overlook when establishing UK operations. Operating without supervisor registration is itself a criminal offence.
The UK has introduced the Economic Crime and Corporate Transparency Act, which strengthens identity verification requirements for company directors and persons with significant control. The reforms expand Companies House';s powers to query and reject filings it considers suspicious, marking a significant shift from the previously passive registration model.
For a fintech business onboarding UK customers from abroad, the practical scenario is this: the firm must apply UK customer due diligence standards to those customers regardless of where the firm is incorporated, if it is conducting regulated activity in the UK. Many cross-border operators underestimate the territorial reach of UK AML rules.
The United States AML framework is anchored in the Bank Secrecy Act, administered by the Financial Crimes Enforcement Network, known as FinCEN. The Corporate Transparency Act introduced a federal beneficial ownership reporting requirement, requiring most US companies to file beneficial ownership information with FinCEN. Reporting companies must disclose the identity of beneficial owners who own or control at least twenty-five percent of the entity or who exercise substantial control.
The US framework is notable for its sector-specific approach. Banks, broker-dealers, money services businesses and certain other financial institutions have detailed AML programme requirements, including written policies, designated compliance officers, independent testing and ongoing training. Non-financial businesses face a narrower set of obligations, though real estate, precious metals dealers and certain professional service providers are subject to specific rules.
Suspicious activity reports must be filed with FinCEN within thirty days of detecting a suspicious transaction, with a limited extension available in certain circumstances. Currency transaction reports are required for cash transactions above a defined threshold. A non-obvious requirement for foreign businesses with US operations is that the AML programme obligation applies to the US branch or subsidiary independently - a group-level programme does not automatically satisfy US requirements.
The UAE has made substantial legislative investment in its AML framework in recent years, driven in part by the FATF mutual evaluation process. The primary legislation includes the Federal Decree-Law on Anti-Money Laundering and Combating the Financing of Terrorism. The Financial Intelligence Unit, known as the UAE FIU, receives suspicious transaction reports through the goAML platform.
Obliged entities in the UAE include financial institutions, designated non-financial businesses and professions - a category that covers real estate agents, lawyers, accountants, corporate service providers and dealers in precious metals and stones. Registration with the relevant supervisory authority and with the goAML system is mandatory before conducting regulated activity.
The UAE';s free zone structure adds a layer of complexity. Businesses established in financial free zones such as the Dubai International Financial Centre or the Abu Dhabi Global Market are subject to the AML frameworks of those zones, which are modelled on international standards and administered by their own financial regulators. Mainland UAE businesses fall under the Central Bank of the UAE or sector-specific regulators.
A practical scenario: a corporate services provider operating in a UAE mainland free zone that onboards international clients must conduct customer due diligence, maintain records for a minimum period and file suspicious transaction reports - obligations that apply regardless of whether the underlying transaction occurs inside or outside the UAE.
Singapore';s AML framework is administered primarily by the Monetary Authority of Singapore. The key legislation includes the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act and sector-specific notices issued by MAS to financial institutions. Singapore applies a risk-based approach aligned with FATF standards.
Financial institutions in Singapore must conduct customer due diligence, maintain records for at least five years and file suspicious transaction reports with the Suspicious Transaction Reporting Office. MAS notices set out detailed requirements for customer risk assessment, enhanced due diligence for higher-risk customers and correspondent banking relationships.
Singapore';s beneficial ownership framework requires companies to maintain registers of registrable controllers, which must be filed with the Accounting and Corporate Regulatory Authority. The information must be kept current, and ACRA has powers to inspect and enforce compliance.
For asset managers and family offices operating in Singapore, a common mistake is assuming that the lighter-touch licensing regime applicable to certain exempt fund managers also reduces AML obligations. In practice, AML and KYC requirements apply to all entities conducting regulated activity, regardless of their licensing category.
The Cayman Islands is a major jurisdiction for investment funds and special purpose vehicles. Its AML framework is administered by the Cayman Islands Monetary Authority, known as CIMA, and the Anti-Money Laundering Steering Group. The primary legislation is the Proceeds of Crime Act and the Anti-Money Laundering Regulations.
All regulated entities and most investment funds must appoint a Money Laundering Reporting Officer, a Deputy MLRO and a Compliance Officer. These roles carry personal responsibility for the adequacy of the AML programme. Customer due diligence must be conducted on investors, and enhanced due diligence applies to higher-risk relationships.
The Cayman Islands has invested significantly in its regulatory infrastructure following earlier FATF scrutiny. Current requirements include economic substance obligations for certain entities, beneficial ownership registration with CIMA and annual compliance certifications. Many fund managers underestimate the operational burden of maintaining compliant investor files across a large fund structure, particularly when investors are themselves legal entities requiring look-through due diligence.
The scope of AML obligations varies significantly by business type. Understanding which category applies determines the specific rules, the competent supervisor and the penalties for breach.
Financial institutions - banks, payment institutions, e-money institutions and investment firms - face the most comprehensive obligations in virtually every jurisdiction. These include written AML programmes, transaction monitoring systems, suspicious activity reporting, staff training and independent audit.
Designated non-financial businesses and professions - a category that typically includes lawyers, accountants, notaries, real estate agents, trust and company service providers, and dealers in high-value goods - face obligations that are broadly similar in structure but often less intensively supervised in practice. This creates a risk: enforcement gaps in the non-financial sector are a known vulnerability that FATF mutual evaluations regularly identify.
Virtual asset service providers are now subject to AML obligations in most major jurisdictions following FATF';s guidance on virtual assets. The Travel Rule - which requires originating institutions to pass beneficiary information alongside virtual asset transfers - is being implemented at different speeds across jurisdictions, creating compliance complexity for cross-border virtual asset businesses.
Corporate and trust service providers face heightened scrutiny globally. Regulators have identified the misuse of corporate structures as a primary money laundering typology, and supervisors are increasingly conducting thematic reviews of the sector.
In practice, founders should consider their business type carefully when assessing AML obligations. A technology company that processes payments on behalf of merchants may be classified as a payment institution in some jurisdictions and as an unregulated technology provider in others - a distinction with significant compliance consequences.
If you are uncertain which category applies to your business or how to structure your AML programme across multiple jurisdictions, contact us at info@vlolawfirm.com. We can help structure the setup correctly the first time.
The FATF grey list - formally the list of jurisdictions under increased monitoring - has direct operational consequences for businesses. When a jurisdiction is grey-listed, counterparties in other countries are expected to apply enhanced due diligence to transactions and relationships involving that jurisdiction.
For a business incorporated in a grey-listed jurisdiction, this means that correspondent banks, payment processors and institutional counterparties will scrutinise the relationship more closely, may require additional documentation and may in some cases decline to maintain the relationship. The reputational and operational costs of grey-listing are substantial.
For a business dealing with customers or counterparties from a grey-listed jurisdiction, the obligation is to apply enhanced due diligence. This typically means obtaining additional information about the purpose of the relationship, the source of funds and the source of wealth of the customer. The enhanced due diligence file must be documented and retained.
FATF also maintains a list of high-risk jurisdictions subject to a call for action - sometimes referred to as the black list. Transactions involving these jurisdictions require the most intensive due diligence and, in some cases, are subject to countermeasures imposed by national regulators.
A common mistake is treating FATF list status as a static fact. The lists are reviewed and updated at each FATF plenary, which meets three times per year. Compliance programmes must include a process for monitoring list changes and updating customer risk ratings accordingly.
The EU publishes its own list of high-risk third countries for AML purposes, which does not always align exactly with the FATF lists. Businesses operating within the EU must apply the EU list, not only the FATF list, when determining enhanced due diligence obligations.
Beneficial ownership transparency is the most consistent direction of travel in global AML regulation. The FATF Recommendations require jurisdictions to ensure that competent authorities have timely access to accurate beneficial ownership information for legal entities and arrangements. Most major jurisdictions have now implemented or are implementing central registers.
The definition of beneficial ownership varies by jurisdiction but typically captures individuals who own or control more than a defined percentage of the entity - commonly twenty-five percent - or who exercise control through other means. Nominee arrangements do not eliminate beneficial ownership obligations; the underlying natural person must be identified.
For corporate groups with complex structures, the look-through obligation can be demanding. Where a shareholder is itself a legal entity, the due diligence obligation extends to identifying the natural persons who ultimately own or control that entity. Many underestimate the documentation burden this creates, particularly for structures involving trusts, foundations or entities in multiple jurisdictions.
Trust beneficial ownership is a distinct and more complex area. FATF Recommendation 25 addresses transparency of legal arrangements. Many jurisdictions now require trustees to maintain and disclose beneficial ownership information covering settlors, trustees, protectors, beneficiaries and any other natural persons exercising ultimate control.
Practical tip: when establishing a new entity or restructuring an existing one, map the beneficial ownership chain before filing. Errors in beneficial ownership registers are difficult to correct retrospectively and can attract regulatory attention.
What is the difference between AML compliance and KYC, and do both apply to my business?
Anti-money laundering compliance is the broader framework of policies, controls and procedures designed to prevent a business from being used to launder criminal proceeds. Know-your-customer is a component of that framework - specifically the process of identifying and verifying the identity of customers and understanding the nature of the business relationship. Both apply to any business classified as an obliged entity under applicable law. In practice, KYC is the front-end process that feeds into the ongoing AML monitoring and reporting obligations. A business that conducts thorough KYC at onboarding but fails to monitor transactions or file suspicious activity reports is still non-compliant. The two elements must work together as part of an integrated compliance programme.
How long does it take to build a compliant AML programme, and what does it cost?
The timeline depends on the complexity of the business and the number of jurisdictions involved. A single-jurisdiction financial institution building a programme from scratch typically requires several months to develop policies, implement technology, train staff and conduct an independent review. A multi-jurisdiction group may require considerably longer. Costs vary widely: technology solutions for transaction monitoring range from entry-level tools accessible to smaller businesses to enterprise platforms costing significantly more. Professional fees for policy development, legal review and independent audit add to the total. Many businesses underestimate the ongoing cost of maintaining a compliant programme - staff time, system licences, training and periodic independent review are recurring expenses, not one-time investments.
Should a business choose a single global AML policy or separate local policies for each jurisdiction?
Most international businesses adopt a hybrid approach: a group-level AML policy sets the minimum standards that apply across all entities, while local policies or supplements address jurisdiction-specific requirements that exceed the group standard. This approach ensures that the most stringent applicable rules are met everywhere, while avoiding the administrative burden of maintaining entirely separate frameworks. The group policy must be genuinely enforceable - a common mistake is producing a group policy that is aspirational rather than operational, with no mechanism for monitoring local compliance. Local management must understand their obligations under both the group policy and local law, and the group compliance function must have visibility into local implementation.
AML and KYC compliance is a continuous, jurisdiction-sensitive obligation that demands active monitoring rather than periodic review. Regulatory frameworks are evolving rapidly, enforcement is intensifying and the consequences of non-compliance - financial penalties, licence loss and reputational damage - are material. Businesses operating across borders must map their obligations carefully, maintain current knowledge of FATF and regional list changes, and ensure their programmes are genuinely operational rather than merely documented.
VLO Law Firms advises international clients on AML and KYC matters across multiple jurisdictions. We can assist with compliance programme design, beneficial ownership analysis, regulatory registration and ongoing monitoring of legislative changes. To request a consultation, contact: info@vlolawfirm.com