NLA-AML-01-2025 — AML/CFT Programme Minimum Expectations (Risk-Based)
Circulars & Notices / NLA-AML-01-2025
NLA CIRCULAR

AML/CFT Programme Minimum Expectations (Risk-Based)

This circular sets minimum AML/CFT programme expectations for licensees and applicants. Programmes should be risk-based, documented, and capable of producing accurate records without delay.

Circular no.
NLA-AML-01-2025
Category
AML / Financial Crime
Issue date
14 February 2025
Effective from
14 February 2025

1. Purpose

risk-based

The purpose of this circular is to provide minimum AML/CFT programme expectations for entities seeking or holding an NLA-issued license. The programme should be proportionate to the nature, scale, and risk profile of the business.

2. Programme components (minimum)

baseline
  • Risk assessment: documented assessment of customer, product, geography, delivery channel, and transaction risks.
  • Customer due diligence (CDD): onboarding checks, identity verification, and beneficial ownership identification where applicable.
  • Ongoing monitoring: transaction monitoring calibrated to risk and service model.
  • Sanctions screening: screening at onboarding and at appropriate intervals thereafter.
  • Recordkeeping: retrievable records and audit trails, including decision rationale for risk ratings and exceptions.
  • Escalation & reporting: internal escalation triggers and documentation of decisions and actions taken.
  • Training: role-based AML training for staff and relevant outsourced functions.
  • Independent review: periodic independent testing proportionate to risk and complexity.
Minimum standard: Controls must be real and enforceable (not checkbox-only). Evidence must be accurate, current, and retrievable without delay.

3. Customer onboarding expectations

CDD
  • Define customer types and onboarding routes (retail, professional, institutional, intermediated).
  • Apply enhanced due diligence for higher-risk customers and contexts (high-risk jurisdictions, complex ownership, high-volume activity).
  • Maintain clear rules for acceptance, rejection, and exception approvals.
Minimum onboarding evidence (examples)

Identity document verification (where relevant), proof of address (where relevant), source of funds/source of wealth rationale for higher-risk profiles, beneficial ownership mapping for corporate structures, screening logs, and onboarding approval records.

4. Ongoing monitoring & triggers

monitoring
  • Define monitoring rules suitable for the product model (brokerage flows, payments, wallets, custody, exchange activity, etc.).
  • Document triggers for review (rapid in/out flows, unusual volumes, repeated failed deposits, anomalous geographies, pattern breaks).
  • Keep investigation notes and decision outcomes, including rationale for “no action” decisions.

5. Outsourcing & reliance

third parties

Where a licensee relies on third parties (e.g., onboarding vendors, screening tools, payment processors, KYC providers), the licensee remains responsible for ensuring controls are effective and auditable.

  • Maintain contracts, SLAs, and evidence of vendor due diligence.
  • Ensure access to logs, screening results, alerts, and case history.
  • Define how data is retained and produced during reviews.

6. Cross-references

related