An anti-money laundering programme needs regular upkeep: the business-wide risk assessment, policies and procedures, staff training, the MLRO's report to the board, an independent audit and a refresh of high-risk customers. This template adds each one to Regmindr as a yearly task on your own date.
The deadlines in this template
- Annual business-wide AML risk assessmentInternal · Once a year, on your own date
Assess the money laundering, terrorist financing and sanctions risks your business is exposed to, and record how your controls address them. Update it sooner if your products, customers or markets change.
- Annual AML policy and procedures reviewInternal · Once a year, on your own date
Review your AML and sanctions policies and procedures against the latest risk assessment and any rule changes, and record who approved them.
- Annual AML and sanctions staff trainingInternal · Once a year, on your own date
Train everyone in a relevant role to spot and report suspicious activity, and keep a record of who completed it and when.
- Annual MLRO report to the boardInternal · Once a year, on your own date
The money laundering reporting officer reports to senior management or the board on how well the AML controls worked over the year, with the main risks and planned improvements.
- Independent AML auditInternal · Once a year, on your own date
Have the AML controls tested by someone independent of the team that runs them, internal audit or an outside firm, and follow up the findings. Set the date to suit your audit cycle.
- Annual high-risk customer due diligence refreshInternal · Once a year, on your own date
Refresh the due diligence and risk rating of customers rated high risk, and check whether the business relationship should continue.
Download this checklist
Get these tasks as a spreadsheet, with columns for your own dates, owners and evidence, free.
6 deadlines
Where the duties come from
In the UK, the Money Laundering Regulations 2017 require a written risk assessment kept up to date (reg. 18), policies and controls (reg. 19), an independent audit function where your size and nature call for one (reg. 21) and staff training (reg. 24). FCA firms appoint an MLRO, who reports to the governing body at least once a year (SYSC 6.3.7G). EU firms have equivalent duties under the national laws that implement the AML directives.
On your own dates
Apart from the MLRO report, the regulations don't fix an interval. Once a year is common practice, so each task starts on a date you choose, such as your board cycle or audit plan, and repeats yearly from there.
Start with this template
Pick this template when you set up Regmindr, tick the deadlines that apply and check each date. Your team gets an email before each one is due.
Sources
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
- FCA Handbook: SYSC 6.3 Financial crime
This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.