Internal AML Policies: The Compliance Programme Every Professional Must Have
L.4557/2018 requires every obliged entity to have written internal AML policies — regardless of firm size. This guide explains exactly what your programme must contain.
Why You Need Written AML Policies
L.4557/2018 (Article 16) explicitly requires every obliged entity to have internal procedures, policies and controls for the prevention of money laundering. This applies to: • Self-employed accountants with 3 clients • Small law firms with a single partner • Independent consultants Why it matters: 1. In a supervisory audit, the first question is "Where is your AML policy?" 2. The existence of written policies demonstrates good faith — it reduces penalties 3. Writing policies today costs far less than paying a fine tomorrow
The 8 Mandatory Elements of an AML Programme
The internal programme must cover: 1. Customer Acceptance Policy: Which clients you accept and which you decline. Risk-based criteria. 2. CDD Procedures: Step by step — which documents, when, how they are verified. 3. Risk scale and risk scoring: How you categorise clients (Low/Medium/High) and what you do for each category. 4. EDD procedure: When Enhanced Due Diligence is triggered and which additional steps are followed. 5. STR reporting procedure: Who decides, how it is submitted, which records are kept. 6. Record keeping: What is retained, where, for how long, who has access. 7. Training: How often, who is trained, how it is documented. 8. Compliance Officer: Named — even if you are the sole practitioner.
AML Programme Structure for a Small Firm
For small firms (1–5 people), the programme can be concise but complete: Chapter 1: Purpose & Scope — Which law applies, to which services of the firm Chapter 2: Compliance Officer — Full name, responsibilities, contact details Chapter 3: Acceptance of New Clients — Required documents by client type, rejection criteria Chapter 4: Risk Scoring & Categorisation — Criteria table, 0–100 scale, corresponding measures Chapter 5: KYC Renewal — Frequency by risk category Chapter 6: Suspicious Transaction Reporting — Internal reporting process, STR submission Chapter 7: Record Keeping — What, where, how long Chapter 8: Training — Annual training schedule
Common Errors in Internal AML Policies
The most common findings by supervisory authorities: Generic "copy-paste" policy: Policies that do not refer to the specific nature of the business. E.g. an accounting firm with a policy written for a bank. Policy without revision date: Must be revised at least annually and whenever legislation changes. No Compliance Officer named: Even in a sole-practitioner firm, the practitioner themselves must be designated. Policy not applied in practice: The policy exists in a drawer but is not followed. Supervisory authorities notice this immediately from the client files.