AML

The framework against money laundering. What components a program has, what name it goes by in each country in the region, and why KYC is only one of its parts.

In short

AML stands for anti-money laundering. It designates the set of obligations, policies and controls an organization has to sustain to keep its operations from being used to give a lawful appearance to funds of illicit origin.

In the region it is almost never called AML. It is called prevención de lavado de activos y financiación del terrorismo in Argentina and Colombia, prevención de lavado de dinero in Mexico, and PLD/FT in Brazil. They are the same thing.

And it is a program, not a single control. Verifying each customer well at signup is one of its pieces, not its whole compliance.

What components an AML program has

The rules across the region differ in the detail and agree on the architecture. A complete program has six pieces, and none replaces another.

  • Risk assessment — determining what money-laundering risk the organization is exposed to through its customers, its products, its channels and the jurisdictions where it operates. It is the starting point, because it sets the intensity of everything else.
  • Policies and governance — manuals approved by the governing body, a designated compliance officer and written responsibilities.
  • Customer due diligence — identification and profiling, which is where KYC and due diligence graded by risk live.
  • Transaction monitoring — the ongoing tracking of activity against the declared profile, to detect deviations.
  • Reporting to the authority — suspicious transactions and, depending on the regime, those that exceed objective thresholds.
  • Recordkeeping, training and audit — the documentary trail, staff training, and the independent review that the system works.

All six are assessed together. A program with excellent customer identification and no follow-up monitoring is not a strong program with one weakness: it is an incomplete program, and that is how it is viewed in an inspection.

Where the rules come from and who enforces them

The content of the program is not invented independently by each country. It comes from the international standard issued by FATF, which every state translates into its own regulation and assigns to a supervisor.

That produces a pattern that repeats across the region: very similar obligations, with different names, different supervisors and different thresholds.

  • [Colombia](/regulacion/colombia) — SARLAFT for entities overseen by the Superintendencia Financiera, and SAGRILAFT for real-sector companies under the Superintendencia de Sociedades.
  • [Mexico](/regulacion/mexico) — the anti-money-laundering law, with the Servicio de Administración Tributaria receiving reports from those carrying out vulnerable activities and the Comisión Nacional Bancaria y de Valores supervising the financial system.
  • [Brazil](/pt/regulacao/brasil) — prevention duties over regulated institutions, with the financial intelligence unit receiving the reports.

Who is covered by each regime is explained in obliged entity, which is where the same concept appears under four different names.

KYC is a part of AML, not its equivalent

The two terms get used as synonyms in project conversations, and they are not. The difference has concrete operational consequences.

KYC answers a one-time question: who is this person, and how do I prove it. It happens mainly at signup and gets updated when something changes.

AML answers an ongoing question: what is this person doing with their account, and is that consistent with what they said they were.

The common mistake is treating the second as covered by the first. An organization can verify all of its customers impeccably at signup and still not detect anything happening in their transactions six months later. Identification is the condition of possibility for monitoring, not its replacement: without knowing who the customer is there is no profile to compare against, but having the profile is not the same as watching it.

AML and fraud protection pursue different goals

They rely on similar data and get confused often, mostly because in many organizations the two teams watch separate screens about the same people.

  • Fraud protection — seeks to stop someone from taking money that is not theirs, typically from the organization or from its customers. The victim is inside. The goal is to avoid a loss.
  • AML — seeks to stop the financial system from being used to launder funds of illicit origin. The victim is not inside. The goal is a legal duty toward the state, and the money involved is usually the customer's own.

From that comes the most counterintuitive difference: in a laundering case the customer is not being deceived, they are cooperating. A model trained to detect someone suffering fraud does not detect someone carrying out their own with apparent normality.

The signals, on the other hand, do cross over. A device that shows up across many accounts, a pattern of correlated signups, or an identity built to order matter on both fronts. That is why it helps for both teams to see the same identity, even while pursuing different things.

Frequently asked questions

It is the acronym for anti-money laundering. It designates the set of obligations, policies and controls an organization must sustain to keep its operations from being used to give a lawful appearance to funds of illicit origin. In Spanish the same concept appears as prevención de lavado de activos y financiación del terrorismo, prevención de lavado de dinero, or PLD/FT, depending on the country.

KYC is customer identification: identifying who someone is and keeping evidence of that check. AML is the full prevention program, of which KYC is one component, and which also includes risk assessment, ongoing transaction monitoring, reporting suspicious activity to the authority, and system audit. Every KYC is part of an AML program; no KYC on its own equals an AML program.

It is the person designated by the organization as responsible for making sure the prevention system works and for channeling reports to the authority. In several regimes their appointment requires approval from the governing body, meets fitness and independence conditions, and exposes them to personal liability in case of non-compliance. Delegating operational tasks does not transfer that responsibility.

No. It reaches every sector each country's regulation defines as exposed, and most of them are outside the financial system: notaries, real estate agencies, currency exchanges, betting platforms, precious-metal dealers and virtual-asset service providers, among others. What changes between a bank and a covered real estate agency is not whether the obligation exists, but its intensity and its supervisor.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo