Compliance · Learning pathway
AML: recognise risk and respond professionally
A practical foundation for accountants covering risk assessment, customer due diligence, enhanced measures, monitoring and confidential escalation.
By the end, you should be able to:
- Apply a risk-based approach to onboarding and monitoring
- Recognise incomplete or unreliable beneficial-ownership evidence
- Identify red flags without treating them as proof of crime
- Escalate suspicion without tipping off the customer
1. Start with risk, not a standard checklist
A risk-based approach considers the customer, ownership, geography, services, delivery channel and transaction pattern. The assessment determines the depth of due diligence and ongoing monitoring.
- Record why the relationship is low, standard or high risk.
- Consider whether the requested service makes commercial sense for the customer.
- Refresh the risk assessment when ownership, activity or behaviour changes.
Apply it
Practice: list the customer, geographic, service and delivery-channel risks present in your last onboarding case.
2. Know the customer and beneficial owner
CDD requires identification and verification using reliable evidence, alongside an understanding of who ultimately owns or controls the customer and the intended nature of the relationship.
- Do not confuse a company contact or nominee with the beneficial owner.
- Resolve inconsistencies between documents, registries and explanations.
- Understand the source of funds or wealth when the risk profile requires it.
Apply it
Practice: draw the ownership chain until every natural person with relevant ownership or control is visible.
3. Increase scrutiny when risk increases
Complex structures, unexplained urgency, unusual payment routes, higher-risk jurisdictions, politically exposed persons and reluctance to provide evidence may require enhanced measures.
- Obtain additional evidence and senior approval where required.
- Test the commercial rationale rather than accepting a plausible phrase.
- Use ongoing monitoring to compare actual activity with the expected profile.
Apply it
Practice: separate each red flag into evidence required, person responsible and the decision needed before proceeding.
4. Escalate suspicion and protect confidentiality
A red flag prompts investigation; suspicion prompts controlled internal reporting. Staff should follow the organisation’s procedure and avoid disclosures that could prejudice an investigation.
- Record facts, sources and reasoning rather than unsupported labels.
- Report promptly through the nominated internal route or MLRO process.
- Do not tell the customer whether a suspicious activity report is being considered or made.
Apply it
Practice: rewrite a vague concern as a factual chronology that an MLRO can assess.
Worked example: the resistant overseas client
A new client has a multi-layer overseas ownership structure, requests an urgent high-value transaction and repeatedly delays beneficial-owner evidence.
- Pause activity that depends on completed due diligence.
- Map the ownership and control chain and verify reliable evidence.
- Reassess customer, geographic, service and transaction risks.
- Apply enhanced measures and obtain approvals required by policy.
- Escalate any suspicion confidentially and avoid tipping off.
Key lesson
No individual indicator proves money laundering. The correct response is a documented, proportionate process that resolves evidence gaps and escalates suspicion safely.
Ready to assess the foundation?
Take the short scored diagnostic for immediate explanations and a recommended next step.
Take the diagnostic →Educational material only. Always apply current requirements, organisational policy and jurisdiction-specific professional advice.