Insights / Research note

Published

6 September 2026

By

Scrutinex Research Desk

Anti-Money Laundering: What Business Must Actually Do

Some businesses are legally required to run a formal AML program. Most aren't, but still deal with the same risks. Here's the actual distinction, and what to do on each side of it.

Cover image for “Anti-Money Laundering: What Business Must Actually Do”

Anti-money laundering rules create a real, formal, legally enforced obligation, but only for specific categories of business: banks, payment processors, money service businesses, and certain other regulated sectors named in legislation like the UK's Money Laundering Regulations or equivalent frameworks elsewhere. If you're not in one of those categories, you don't have a legal AML program requirement. You can still end up doing business with a sanctioned party, a shell company laundering funds, or a fraudulent counterparty, none of which requires you to be a regulated entity to go wrong.

The two-part distinction that actually matters

Formal, regulated AML obligations apply to a defined list of business types and require a documented risk-based program, a designated compliance officer, ongoing customer monitoring, and suspicious activity reporting to the relevant authority. This is a real legal compliance function, not something a general business without a regulatory obligation should attempt to replicate wholesale.

Practical risk management applies to everyone else, and covers the much more common situation: you're not legally required to have an AML program, but you're still exposed if you send money to a sanctioned entity, accept funding from an undisclosed source, or sign a contract with a shell company. Sanctions violations in particular don't require regulatory status to create liability, strict liability sanctions rules can apply regardless of whether you're in a regulated industry.

What an unregulated business should actually do

  • Screen counterparties before money moves, not after. A sanctions or fraud problem discovered after a wire transfer is far harder to unwind than one caught before it.
  • Verify identity and registration for anyone receiving a significant payment, especially a new vendor, investor, or partner, see our KYB guide for what that actually involves.
  • Check sanctions exposure on both the entity and the individuals behind it, since sanctions can attach to a person even when the company they're using looks clean.
  • Keep records of what you checked and when. If a relationship is ever questioned, having done and documented reasonable checks is a materially different position than having done nothing.

What a regulated business should do beyond this

If you are in a formally regulated category, the above is the floor, not the program. You need a documented, risk-based AML policy, a designated compliance officer, ongoing monitoring, not just point-in-time checks, and a process for filing suspicious activity reports. See our piece on FCA rules specifically for what that looks like under UK regulation.

Where a one-off report fits either way

Whether or not you have a formal obligation, the actual verification step, is this counterparty who they claim, are they sanctioned, is there adverse history, is the same underlying check. Scrutinex delivers that check as a single report rather than a compliance program, useful whether you're building toward a full regulated AML function or simply making sure one specific relationship is sound. See a sample report or order one.

Reports from $99

No contract, no subscription

Order a report