Skip to content
EBA · EU-wide

Policies, procedures and controls — two approval levels

Fintech Passport
August 20, 2026 · 4-min read
Policies, procedures and controls — two approval levels

Most firms have one AML manual. Article 9 of Regulation (EU) 2024/1624 is built around a distinction that one manual cannot express. It separates policies from procedures and controls, and the AMLR governance architecture approves them at different levels — policies by the management body, procedures and controls at least at compliance-manager level. A single document approved once by the board satisfies the form of neither requirement.

1. What they must achieve

Article 9(1) requires internal policies, procedures and controls to ensure compliance with the Regulation, with Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, and with any administrative act issued by any supervisor — and in particular to:

  • mitigate and manage effectively the ML/TF risks identified at the level of the Union, the Member State and the obliged entity; and
  • in addition to the obligation to apply targeted financial sanctions, mitigate and manage the risks of non-implementation and evasion of those sanctions.

The framework must be proportionate to the nature of the business, including its risks and complexity, and the size of the entity, and must cover all the activities of the entity falling within the Regulation’s scope. Proportionality governs depth; coverage is absolute.

2. What must be inside

Article 9(2) lists what the framework must include, and the internal-policies limb alone names several documents in their own right:

ComponentWhat it covers
Business-wide risk assessmentIts carrying out and updating
Risk management frameworkThe entity’s own
Customer due diligenceImplementation of Chapter III, including procedures to determine whether the customer, beneficial owner or person on whose behalf or for whose benefit a transaction is conducted falls into the relevant categories
SanctionsMeasures addressing non-implementation and evasion of targeted financial sanctions

The customer due diligence limb repays close reading, because it requires procedures to determine status — not merely a rule that applies once status is known. A framework that says what to do for a politically exposed person, without saying how the firm establishes that someone is one, addresses the second half of the obligation and not the first.

3. The two approval altitudes

This is the structural change most firms have to make. Under the AMLR compliance-function architecture:

  • Policies are approved by the management body;
  • Procedures and controls are approved at least at compliance-manager level — the compliance manager being a member of the management body in its management function under Article 11.

The practical consequence is a document architecture rather than a governance formality. A short policy layer, board-approved and stable, sitting above a procedural layer that can be changed at compliance-manager level, lets the firm update a control without a board paper — which is what makes the framework maintainable at all. Firms that keep everything in one board-approved manual face a choice between stale procedures and constant board approvals.

4. What cannot be delegated

Article 18(3) places the approval of internal policies, procedures and controls on the list of tasks that may never be outsourced under any circumstances, alongside the proposal and approval of the business-wide risk assessment and the approval of the criteria for detecting suspicious or unusual transactions.

Drafting can be supported externally. Approval cannot, and the approval record is what a supervisor will ask to see — with the date, the approver, and the version approved.

FAQ

Can we keep one AML manual?

Only if it is structured so that the policy layer and the procedural layer are distinguishable and separately approved. The Regulation approves them at different levels, so a single undifferentiated document cannot evidence either approval correctly.

Does the framework have to cover sanctions?

Yes — Article 9(1)(b) requires it to mitigate and manage the risks of non-implementation and evasion of targeted financial sanctions, in addition to the obligation to apply them.

Can a consultant approve our procedures?

No. Approval of internal policies, procedures and controls is on the never-outsource list in Article 18(3). External support for drafting is unaffected.


Related: The business-wide risk assessment · AMLR governance · AMLR outsourcing

Related reads.