Regmindr
Guides

How often should you review your AML risk assessment, policies and training?

Updated

The Money Laundering Regulations rarely set a fixed interval. They require your risk assessment to be kept up to date (reg. 18(4)), policies to be reviewed regularly (reg. 19(1)(b)), staff to be trained regularly (reg. 24) and customer due diligence to be kept up to date (reg. 28(11)). Only the MLRO's report to senior management has a set minimum: at least once a year. A yearly review on a fixed date, with an earlier one whenever something changes, is the simplest cycle to evidence.

Table of AML reviews and what the rules say about frequency: business-wide risk assessment, keep an up-to-date record (MLR reg. 18(4)); proliferation financing risk assessment, same (reg. 18A(4)); policies, controls and procedures, review and update regularly (reg. 19(1)(b)); staff training, regularly (reg. 24(1)); customer due diligence, keep up to date (reg. 28(11)(b)); staff screening, before and during appointment (reg. 21(1)(b)); independent audit, where size and nature call for it (reg. 21(1)(c)); MLRO report to the board, at least once a year (SYSC 6.3.7G).
What each rule says about timing. Where it says regularly, the interval is yours to set and justify.

Business-wide risk assessment

You must keep an up-to-date written record of the steps you took to assess your money laundering and terrorist financing risks (reg. 18(4)), and the same applies to your proliferation financing risk assessment (reg. 18A(4)). The FCA says firms must regularly review their risk assessment to make sure it stays current (FCG 3.2.3).

Review it at least once a year, and again before you launch a new product, business practice or technology, which the regulations require you to assess in advance (reg. 19(4)(c)).

Policies, controls and procedures

Review and update them regularly, have senior management approve them, and keep a written record of each change and how you told staff about it (reg. 19). Schedule the review after the risk assessment, so the policies reflect its findings.

Staff training

Relevant employees, and agents doing similar work, must be made aware of the law and regularly trained to recognise and deal with suspicious activity. Keep a written record of the training given (reg. 24). Train new joiners before they start relevant work, and everyone else on a yearly cycle.

Customer due diligence

Ongoing monitoring includes reviewing existing records and keeping CDD information up to date (reg. 28(11)). How far you go must reflect the risk (reg. 28(12)), so set review cycles by risk rating, for example yearly for high-risk customers and less often for low-risk ones, and record why.

Screening, audit and the MLRO report

  • Screen relevant employees before they're appointed and during their appointment, where your size and nature make it appropriate (reg. 21(1)(b)).
  • Have an independent audit function examine your AML controls, where your size and nature make it appropriate (reg. 21(1)(c)). The interval comes from your audit plan.
  • The MLRO reports to the board at least once a year. See what to include in an MLRO annual report.

Make the cycle visible

Where the rules say regularly, you set the interval and should be able to justify it. Put each review on a fixed date with an owner and keep the evidence when it's done. The AML compliance checklist adds each of these as a yearly reminder on your own dates.

Get reminded before each deadline

Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related