Policies, procedures and controls — two approval levels
Most firms have one AML manual. Article 9 of Regulation (EU) 2024/1624 is built around a distinction that one manual cannot express. It separates policies from procedures and controls, and the AMLR governance architecture approves them at different levels — policies by the management body, procedures and controls at least at compliance-manager level. A single document approved once by the board satisfies the form of neither requirement.
1. What they must achieve
Article 9(1) requires internal policies, procedures and controls to ensure compliance with the Regulation, with Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, and with any administrative act issued by any supervisor — and in particular to:
- mitigate and manage effectively the ML/TF risks identified at the level of the Union, the Member State and the obliged entity; and
- in addition to the obligation to apply targeted financial sanctions, mitigate and manage the risks of non-implementation and evasion of those sanctions.
The framework must be proportionate to the nature of the business, including its risks and complexity, and the size of the entity, and must cover all the activities of the entity falling within the Regulation’s scope. Proportionality governs depth; coverage is absolute.
2. What must be inside
Article 9(2) lists what the framework must include, and the internal-policies limb alone names several documents in their own right:
| Component | What it covers |
|---|---|
| Business-wide risk assessment | Its carrying out and updating |
| Risk management framework | The entity’s own |
| Customer due diligence | Implementation of Chapter III, including procedures to determine whether the customer, beneficial owner or person on whose behalf or for whose benefit a transaction is conducted falls into the relevant categories |
| Sanctions | Measures addressing non-implementation and evasion of targeted financial sanctions |
The customer due diligence limb repays close reading, because it requires procedures to determine status — not merely a rule that applies once status is known. A framework that says what to do for a politically exposed person, without saying how the firm establishes that someone is one, addresses the second half of the obligation and not the first.
3. The two approval altitudes
This is the structural change most firms have to make. Under the AMLR compliance-function architecture:
- Policies are approved by the management body;
- Procedures and controls are approved at least at compliance-manager level — the compliance manager being a member of the management body in its management function under Article 11.
The practical consequence is a document architecture rather than a governance formality. A short policy layer, board-approved and stable, sitting above a procedural layer that can be changed at compliance-manager level, lets the firm update a control without a board paper — which is what makes the framework maintainable at all. Firms that keep everything in one board-approved manual face a choice between stale procedures and constant board approvals.
4. What cannot be delegated
Article 18(3) places the approval of internal policies, procedures and controls on the list of tasks that may never be outsourced under any circumstances, alongside the proposal and approval of the business-wide risk assessment and the approval of the criteria for detecting suspicious or unusual transactions.
Drafting can be supported externally. Approval cannot, and the approval record is what a supervisor will ask to see — with the date, the approver, and the version approved.
FAQ
Can we keep one AML manual?
Only if it is structured so that the policy layer and the procedural layer are distinguishable and separately approved. The Regulation approves them at different levels, so a single undifferentiated document cannot evidence either approval correctly.
Does the framework have to cover sanctions?
Yes — Article 9(1)(b) requires it to mitigate and manage the risks of non-implementation and evasion of targeted financial sanctions, in addition to the obligation to apply them.
Can a consultant approve our procedures?
No. Approval of internal policies, procedures and controls is on the never-outsource list in Article 18(3). External support for drafting is unaffected.
Related: The business-wide risk assessment · AMLR governance · AMLR outsourcing


