3.1 ML + TF fundamentals
▼The 3 stages of money laundering syllabus 1.1
- PLACEMENT — inserting illicit cash into the financial system (highest detection risk)
- LAYERING — moving it through complex transactions to disguise origin
- INTEGRATION — returning cleaned funds as apparently legitimate wealth
Not every scheme is neatly 3-stage — modern schemes may skip placement (already-electronic funds like frauds/hacks).
ML vs TF — key distinction syllabus 1.2
ML = disguising the PROCEEDS OF CRIME (funds are DIRTY).
TF = funds can be from LEGITIMATE origin (salary, charity donations, state sponsorship) but intended USE is criminal. Often SMALL amounts.
Detection: ML → suspicious ORIGIN. TF → suspicious USE / DESTINATION.
3.2 FATF + AML directives
▼FATF — the standard-setter syllabus 1.3
Financial Action Task Force — Paris-based, founded 1989 at G7 Summit. Inter-governmental. Sets 40 Recommendations. Countries implement them into domestic law. FATF conducts mutual evaluations, publishes grey list (increased monitoring) and black list (high-risk / call for action — currently North Korea, Iran, Myanmar).
Post-2019 movements: UAE greylisted 2022 → removed 2024. South Africa greylisted 2023.
EU AML Directives — 4MLD → 6MLD → AMLA syllabus 1.4
- 4MLD (2017) — risk-based approach, beneficial ownership registers
- 5MLD (2020) — added crypto, prepaid cards, art dealers
- 6MLD (2020) — harmonised predicate offences (22), criminal liability for LEGAL persons, minimum 4-year prison for laundering
- AMLA (post-2019) — new EU-level Anti-Money Laundering Authority, Frankfurt-based, operational 2025. Direct EU supervision of highest-risk FIs.
3.3 Risk-based approach + CDD
▼RBA — the foundation syllabus 2.1
Firms must IDENTIFY, ASSESS, and UNDERSTAND their ML/TF risks (customer · product · geographic · delivery channel) and apply controls PROPORTIONATE to those risks:
- High-risk → Enhanced Due Diligence (EDD)
- Low-risk → Simplified Due Diligence (SDD)
- Standard risk → Standard Customer Due Diligence (CDD)
Standard CDD — 4 components syllabus 3.1
- IDENTIFY the customer and VERIFY identity from reliable independent sources
- IDENTIFY and take reasonable measures to VERIFY the BENEFICIAL OWNER
- UNDERSTAND (and obtain info on) the PURPOSE and INTENDED NATURE of the relationship
- Conduct ONGOING MONITORING
Beneficial owner — the 25% threshold syllabus 3.2
Beneficial owner = natural person who ultimately OWNS or CONTROLS the customer.
For corporates: FATF benchmark is MORE than 25% of shares or voting rights — BUT anyone exercising ULTIMATE CONTROL through other means (contractual arrangements, senior management position) is ALSO a BO even if below the 25% threshold.
Complex ownership chains must be traced up until a natural person is identified. If no BO can be identified, the senior managing official is treated as the BO.
SDD — LIGHTER, not NONE syllabus 3.3
Simplified due diligence applies where risk is LOW — regulated FIs from equivalent-jurisdiction, listed companies with disclosure requirements, government / supra-national bodies.
SDD does NOT mean NO due diligence. Identity should still be established; the intensity is REDUCED, not eliminated.
3.4 EDD, PEPs, SoF vs SoW
▼When EDD is required syllabus 3.4
EDD triggers — memorise these:
- PEPs and their close associates / family members
- Customers from high-risk third countries (FATF grey/black list)
- Non-face-to-face relationships (unless mitigated)
- Complex ownership structures
- Cash-intensive businesses
- Correspondent banking (especially with respondents in high-risk jurisdictions)
- Private banking
EDD adds: senior management approval · enhanced info on SoF and SoW · enhanced ongoing monitoring · deeper understanding of purpose. All DOCUMENTED.
PEPs syllabus 3.4.1
Politically Exposed Person = person entrusted with a PROMINENT PUBLIC FUNCTION:
- Head of state, government minister, senior politician
- Senior judge, senior military officer
- Senior state-owned-enterprise executive
- Senior political-party official
- Ambassador, senior international-organisation official
Plus their IMMEDIATE FAMILY MEMBERS and CLOSE ASSOCIATES / business partners.
Domestic vs foreign PEPs may qualify for lighter EDD in some jurisdictions.
Source of Funds vs Source of Wealth syllabus 3.6
SoF — origin of the PARTICULAR funds in this transaction / deposit
SoW — origin of the CUSTOMER'S OVERALL wealth / net worth
For high-risk customers (especially PEPs) you need BOTH — SoF proves this transaction is legitimate; SoW proves the underlying wealth is legitimate.
3.5 Transaction monitoring + SARs
▼SAR / STR filing syllabus 4.2
Suspicious Activity / Transaction Report — filed to the national FIU (UK NCA, US FinCEN, etc.) when a firm KNOWS, SUSPECTS, or has REASONABLE GROUNDS to SUSPECT that funds involve proceeds of crime or the account is being used for ML/TF.
UK NCA receives 900k+ SARs/year. Failure to file when threshold met = criminal offence for MLRO and firm.
MLRO / nominated officer syllabus 4.3
Designated INDIVIDUAL (SMCR Senior Manager or equivalent) responsible for:
- Receiving internal reports of suspicion from staff
- Considering them
- Filing SAR to FIU where appropriate
- Overseeing the firm's AML/CFT framework
UK: SMF17 senior management function. Personal criminal liability for failure to disclose or tipping off.
Tipping off syllabus 4.4
Separate criminal offence: disclosing to the CUSTOMER (or third party) that a SAR has been filed / is being considered, OR that a law-enforcement investigation is underway, where such disclosure is LIKELY TO PREJUDICE the investigation.
UK: POCA s.333A. Why firms can't say "your account is being reviewed by our AML team".
3.6 Sanctions (incl. post-2022)
▼Sanctions types syllabus 5.1
- Asset freezes (individual / entity level)
- Prohibitions on providing funds / economic resources to designated persons
- Sectoral sanctions (targeting industries — Russian energy, tech, defence)
- Country embargoes (comprehensive prohibitions — e.g. North Korea)
- Trade controls (export licences, dual-use goods)
US OFAC extraterritorial reach syllabus 5.2
US OFAC sanctions apply to any non-US person using USD (via US correspondent clearing), US-origin goods/tech, or US-linked persons. Non-US persons have paid multi-billion-dollar penalties (BNP Paribas $8.9bn 2014).
UK OFSI — strict liability (June 2022+) post-workbook
Major post-2019 shift: UK OFSI (Office of Financial Sanctions Implementation) now has strict liability monetary penalty powers — no need to prove firm knew or had reasonable cause to know of the breach.
Also since 2022: naming firms even where no fine imposed. Dramatically increases firm exposure.
3.7 Bribery + corruption
▼UK Bribery Act 2010 — 4 offences syllabus 6.1
- Bribing (active)
- Being bribed (passive)
- Bribing a FOREIGN PUBLIC OFFICIAL
- Failure of a commercial organisation to PREVENT BRIBERY (s.7) — defence: firm had "adequate procedures"
Extraterritorial: any commercial organisation doing business in the UK, wherever the bribery occurred.
"Adequate procedures" — 6 principles syllabus 6.2
- PROPORTIONATE procedures
- TOP-LEVEL COMMITMENT
- RISK ASSESSMENT
- DUE DILIGENCE on associated persons
- COMMUNICATION and TRAINING
- MONITORING and REVIEW
Together give a defence to the s.7 corporate offence.
Facilitation payments — UKBA vs FCPA syllabus 6.4
Small payments to secure/expedite routine government acts:
- UK Bribery Act — PROHIBITED (no exemption)
- US FCPA — narrow "grease payment" exemption exists but PRACTICALLY unused (creates problems for firms with global operations)
- Prohibited under most modern regimes
3.8 Fraud + tax evasion
▼Fraud categories syllabus 7.1
- External fraud — payment fraud, ID theft, cheque fraud, invoice fraud
- Internal fraud — theft, expense fraud, unauthorised trading (Kerviel/Rusnak), insider dealing
- Customer-victim fraud enabled through firm platforms — APP scams, romance/investment scams
UK APP scam mandatory reimbursement rule from PSR effective Oct 2024.
UK ECCT Act 2023 — failure to prevent fraud post-workbook
New corporate offence for LARGE organisations (in force 1 September 2025):
Large org can be criminally liable where an ASSOCIATED PERSON commits specified fraud INTENDING to benefit the organisation — defence: "reasonable fraud prevention procedures".
"Large" = 2 of: >250 employees, >£36m turnover, >£18m balance sheet.
UK Criminal Finances Act 2017 — CCO tax offence syllabus 8.1
Corporate Criminal Offence: failure to prevent the facilitation of tax evasion (UK and foreign taxes) by an associated person — defence: "reasonable procedures".
Applies to ALL relevant bodies (companies, partnerships) regardless of size.
CRS vs FATCA syllabus 8.2-8.3
| CRS | FATCA | |
|---|---|---|
| Origin | OECD | US |
| Scope | 110+ jurisdictions, multilateral | US persons' accounts globally |
| Teeth | Peer pressure, mutual evaluations | 30% withholding on non-compliant FFIs |
| Does US participate? | NO | YES (it's their rule) |
Firms must run BOTH FATCA and CRS classification / reporting.
3.9 Crypto + emerging risks
▼Crypto travel rule syllabus 9.1
FATF Recommendation 16 extended to crypto: Virtual Asset Service Providers (VASPs) — exchanges, custodians, some wallets — must obtain and share ORIGINATOR + BENEFICIARY info for crypto transfers above thresholds.
UK travel rule in force September 2023. EU TFR extension to crypto in force December 2024.
Crypto ML typologies syllabus 9.2
- Mixers / tumblers (obscuring trails)
- Cross-chain bridges
- Privacy coins (Monero, Zcash)
- Decentralised exchanges without KYC
- NFT wash-trading
- Peer-to-peer exchanges in high-risk jurisdictions
- Ransomware payments
- Cash-out via cooperative or lax off-ramps
Blockchain analytics (Chainalysis, Elliptic, TRM Labs) make investigation feasible.
Culture — the ultimate defence syllabus 9.3
Every major FC enforcement case (Danske Bank Estonia, Wells Fargo, Wirecard, HSBC Mexico, BSI Singapore / 1MDB) had culture failure at its heart — not absence of policies.
Systems and controls fail without human judgement. Human judgement without controls also fails. Both needed.
3.10 All the numbers (cheat sheet)
▼Ch 3 quick-reference
| Item | Answer |
|---|---|
| ML stages | Placement · Layering · Integration |
| FATF Recommendations count | 40 |
| FATF founded | 1989 (G7 Summit, Paris-based) |
| BO threshold | >25% + control |
| SDD applies to | Low-risk (regulated FI, listed company, government body) |
| EDD triggers | PEP · high-risk country · non-F2F · complex ownership · cash-intensive · correspondent banking · private banking |
| SAR threshold | Know / suspect / reasonable grounds to suspect |
| Tipping off | SEPARATE offence — POCA s.333A (UK) |
| UKBA year | 2010 |
| UKBA offences | 4 (bribing, being bribed, foreign public official, corporate failure to prevent) |
| Adequate procedures | 6 principles |
| Facilitation payments UK | Prohibited |
| Facilitation payments US | Narrow FCPA exemption, largely unused |
| UK CFA 2017 | Failure to prevent facilitation of tax evasion (all sizes) |
| UK ECCT 2023 fraud offence | In force Sept 2025, large orgs only |
| FATCA withholding | 30% |
| CRS participating jurisdictions | 110+ · US does NOT participate |
| OFSI strict liability | June 2022+ |
| UK crypto travel rule | September 2023 |
| EU 6MLD predicate offences | 22 harmonised |
| EU AMLA operational | 2025 (Frankfurt) |