UBO + transaction monitoring
"Complex structures and cross-border transactions: the AML/CFT system must demonstrate due diligence and ongoing monitoring backed by evidence."
Comply with AML/CFT regulations without slowing down your operations: we design a system your team can actually run (KYC/UBO, monitoring, manual, training, internal control body and audits).
Are you an obliged entity? Free AML/CFT assessment
Tell us your situation and we'll tell you what you need to implement.
Six elements that make up an applicable, auditable and risk-proportionate AML/CFT system.
Risk Self-Assessment Report in line with RD 304/2014 and SEPBLAC guidelines, with controls proportionate to the actual risk profile of your activity.
Review of control effectiveness and evidence: KYC/EDD, ongoing monitoring, reporting to the internal control body and full documentary traceability of the system.
Mandatory document setting out measures, internal procedures, roles and workflows to comply with Law 10/2010 and RD 304/2014.
Practical sessions for exposed teams: spotting red flags, obligations, real cases and training evidence.
Independent annual review (Art. 28 RD 304/2014) identifying deficiencies and improvement recommendations.
Preparation of documentation and responses for SEPBLAC/CNMV/Bank of Spain: consistency, deadlines and evidence.
Complex structures, cross-border transactions, enhanced KYC or simply complying well: each sector has its own approach.
"Complex structures and cross-border transactions: the AML/CFT system must demonstrate due diligence and ongoing monitoring backed by evidence."
"We design controls and detection tools for unusual or suspicious transactions, with consistent criteria and traceability."
"Internal protocols to identify, assess risk and document decisions before a transaction turns into a problem."
"The key is operational effectiveness: applicable procedures, role-based training and periodic audits of the AML system."
Non-compliance does more than trigger penalties: it can block operations, banking relationships and reputation.
The cost of not complying can be very high: beyond reputation, non-compliance translates into serious financial penalties.
De-risking risk: banks and providers may restrict or close the relationship if they detect gaps in KYC/UBO, monitoring or traceability.
Operations at risk: accounts, providers, onboarding and closings can be blocked if there are no controls and evidence of anti-money laundering measures.
Minor breaches or those with no appreciable impact on the prevention system.
Or 10% of the company's total resources.
Or 10% of the entity's own funds.
We prepare your anti-money laundering programme for you: manual, risk assessment, KYC/UBO, controls, training and periodic audits.
AML/CFT is the set of measures and controls aimed at preventing the financial system or certain sectors from being used to launder money or finance illicit activities.
The key idea is to demonstrate a risk-based approach: identify clients, know the beneficial owner (UBO), monitor transactions and document decisions with evidence.
It depends on the activity. The Molina Law Boutique AML page highlights especially sensitive sectors such as investment/asset managers, financial, legal, luxury, real estate, foundations/associations, gambling and insurance.
If you manage funds, intermediate in significant transactions or work with complex structures, it's best to validate your status as soon as possible.
Implement an applicable AML/CFT system: KYC/UBO, AML manual, risk self-assessment, monitoring, training, internal control body and periodic audits.
The difference between "complying" and "complying well" is the evidence: records, traceability and consistent criteria.
Non-compliance can lead to financial penalties and reputational damage.
AML/CFT lands differently depending on each sector's risk. Examples:
The Internal Control Body (OCI) coordinates, supervises and follows up the anti-money laundering system, ensuring that policies are executed and gaps are corrected.
Without an active internal control body, the "governance" of the system usually fails: decisions, escalations, follow-up and evidence.
An AML system isn't "paperwork": it's a set of applicable controls your team can run and that leave evidence behind. The key is the risk-based approach: identify, assess, mitigate and document decisions (KYC/UBO, monitoring, escalations and document retention).
To reduce the risk of money laundering and terrorist financing through clear internal policies, consistent criteria and traceability. A good AML/CFT system helps protect operations, reputation and banking relationships.
Due diligence (KYC), beneficial owner identification (UBO), risk classification, screening (PEPs/sanctions where applicable), ongoing monitoring and an internal escalation channel.
Having a manual isn't enough: you must be able to prove execution. Records, alerts, periodic reviews, internal control body minutes and justified decisions are usually the first thing reviewed in AML audits.
If you want to implement AML operationally (without slowing the business), check our AML/CFT services or, if you need an independent review, the external expert report.
The 10 controls every entity obliged by Law 10/2010 must meet, with the evidence you need for each one. Keep it handy and share it with your team.
No spam. Your email is only used to send you this checklist and, occasionally, relevant AML/CFT regulatory updates.
The checklist is downloading right now. If it doesn't start automatically, click here.
Once you've read it, do you need help implementing any of the steps? Message us directly:
An effective AML/CFT system isn't a document: it's a set of repeatable decisions (KYC, UBO, risk, monitoring and escalations) with traceability. Here's a visual "dashboard" to understand how anti-money laundering lands in practice.
1) OnboardingThe goal of AML isn't "to ask for paperwork": it's to understand the client's profile, the purpose of the relationship and to document a decision consistent with the risk.
2) Beneficial ownerIn AML/CFT, the UBO isn't a formality: it's the basis for detecting real control, conflicts and opacity in complex structures.
3) OngoingRules, thresholds and consistent criteria. Alerts with analysis, closure and traceability: that's "auditable" AML.
4) GovernanceThe internal control body and periodic audits turn AML/CFT into a real system: follow-up, corrections, reporting and evidence.
Quick decisionStandard KYC + basic UBO + reasonable periodic review.
Enhanced controls + rule-based monitoring + evidence of decisions.
Enhanced due diligence + source of funds + internal escalation + intensive monitoring.
Verification consistent with the risk, purpose of the relationship and periodic updating.
KYC file, risk profile, review date and justification of exceptions.
Identify real control, especially in complex or cross-border structures.
Organizational charts, declarations, verifications and the reasoning of the "path" to the UBO.
Detection of unusual patterns, consistent analysis and closure of alerts.
Alert log, analysis, decisions, escalations and reviews of rules/thresholds.
Apply enhanced measures when the risk requires it and document the conclusion.
Supporting documentation, verification logic and traceability of the review.
Governance of the AML/CFT system: follow-up, reporting and corrective measures.
Minutes, annual plan, KPIs, audit reports and remediation plan.
Use them to adjust measures and justify enhanced due diligence where appropriate.
If you're implementing AML, these terms appear in manuals, audits and in daily operations. Understanding them well helps you design applicable controls and generate evidence.
Framework of controls to identify, assess and mitigate risks with consistent criteria and traceability.
Identification and verification of the client, purpose of the relationship and periodic updating based on risk.
The person(s) who actually control the entity or benefit from the transaction. Critical in complex structures.
Assign controls proportionate to the risk: not every client/transaction requires the same, but everything must be justified.
Detection of unusual patterns, analysis, escalation and closure of alerts with traceability.
Additional measures when the risk requires it: more verification, more support and more intensive monitoring.
Reasonably document where the money (and, where appropriate, the wealth) comes from in sensitive transactions.
Supervises the AML/CFT system: follow-up, reporting, escalations and corrections to keep it "alive".
Periodic reviews to verify that controls work, detect gaps and apply corrective measures.
COMPLIANCE CONTROL CENTER · AML/CFT
For obliged entities, a good AML system is demonstrated through execution: KYC, UBO, monitoring, internal control body and audit. This dashboard sums up what a "living" and defensible AML/CFT looks like.
A risk-based approach assigns proportionate and justified measures.
Anti-money laundering and counter-terrorist financing (AML/CFT) doesn't only affect banks. Many obliged entities must also implement AML compliance measures, such as law firms, real estate agencies, financial operators, investment firms and providers related to crypto-assets. The key is not having "paperwork", but an applicable system: AML manual, risk assessment, KYC/UBO, training, monitoring and evidence.
We analyze whether your activity qualifies as an obliged entity and which AML/CFT measures you must implement based on your risk, operations and sector.
Implementation of controls over the client, beneficial owner, engagement, third-party payments, corporate transactions and document retention.
Controls for high-value transactions, source-of-funds analysis, identification of the parties involved and escalation protocols.
Enhanced KYC, operations review, jurisdiction-based approach, traceability and adapting the AML/CFT system to crypto models.
If you need to implement a complete system, you can review our AML/CFT services, the AML manual, the risk assessment, the AML/CFT audit or the external expert report.
Anti-money laundering and counter-terrorist financing in Spain is mainly governed by Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing, and its implementing regulation, Royal Decree 304/2014 of 5 May. Both transpose the EU AML directives (currently within the framework of the fourth and fifth AML Directives) and establish a risk-based approach system for obliged entities.
Law 10/2010 sets out the list of obliged entities: credit institutions, insurers, fund managers, investment firms, notaries, lawyers, auditors, real estate agents, casinos and gambling operators, dealers in high-value goods (jewellery, art, luxury vehicles) and, since the transposition of the 5th AMLD, crypto-asset service providers (CASPs). Each category has specific obligations proportionate to the inherent risk of its activity.
SEPBLAC (the Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences) is the Spanish Financial Intelligence Unit (FIU) and the main AML/CFT supervisor. It issues reference guidance, sector guidelines and carries out inspections of obliged entities. Its recommendations on risk assessment, KYC and documentary traceability are essential for any AML system that aims to pass a review.
The prevention system requires, as a minimum: customer due diligence (KYC), identification and verification of the beneficial owner (UBO) according to the legal thresholds (25% in the general case), ongoing monitoring of the business relationship and transactions, reporting of suspicious transactions to SEPBLAC where appropriate, and an internal control body (OCI) that supervises the system and ensures it is kept up to date. Breaching these obligations is subject to a specific penalty regime, with fines that can reach 10 million euros or 10% of own funds.
The entry into force of the MiCA Regulation (Markets in Crypto-Assets) and the evolution of the AMLD framework impose new obligations on crypto-asset service providers: registration with the CNMV, robust KYC, monitoring of wallets and transactions, and adaptation to the Travel Rule. If your activity includes crypto-assets, the AML/CFT system must be expressly adapted to this framework.