AML: Anti-Money Laundering

Comply with AML/CFT regulations without slowing down your operations: we design a system your team can actually run (KYC/UBO, monitoring, manual, training, internal control body and audits).

Are you an obliged entity? Free AML/CFT assessment

Tell us your situation and we'll tell you what you need to implement.

  • +50 entities advised
  • 24h response
  • No obligation

Real controls for each risk profile

Complex structures, cross-border transactions, enhanced KYC or simply complying well: each sector has its own approach.

Investment sector

UBO + transaction monitoring

"Complex structures and cross-border transactions: the AML/CFT system must demonstrate due diligence and ongoing monitoring backed by evidence."

Financial sector

Enhanced KYC and risk management

"We design controls and detection tools for unusual or suspicious transactions, with consistent criteria and traceability."

AML/CFT

Source of funds and sensitive transactions

"Internal protocols to identify, assess risk and document decisions before a transaction turns into a problem."

Professionals

Control without pointless bureaucracy

"The key is operational effectiveness: applicable procedures, role-based training and periodic audits of the AML system."

Why does AML compliance matter?

Non-compliance does more than trigger penalties: it can block operations, banking relationships and reputation.

The cost of not complying can be very high: beyond reputation, non-compliance translates into serious financial penalties.

De-risking risk: banks and providers may restrict or close the relationship if they detect gaps in KYC/UBO, monitoring or traceability.

Operations at risk: accounts, providers, onboarding and closings can be blocked if there are no controls and evidence of anti-money laundering measures.

Minor penalties up to €60,000

Minor breaches or those with no appreciable impact on the prevention system.

Serious penalties €60k – €5,000,000

Or 10% of the company's total resources.

Very serious penalties €150k – €10,000,000

Or 10% of the entity's own funds.

Ready to stop worrying about AML/CFT?

We prepare your anti-money laundering programme for you: manual, risk assessment, KYC/UBO, controls, training and periodic audits.

AML: common questions

What is AML?

AML/CFT is the set of measures and controls aimed at preventing the financial system or certain sectors from being used to launder money or finance illicit activities.

The key idea is to demonstrate a risk-based approach: identify clients, know the beneficial owner (UBO), monitor transactions and document decisions with evidence.

Who is required to comply with AML?

It depends on the activity. The Molina Law Boutique AML page highlights especially sensitive sectors such as investment/asset managers, financial, legal, luxury, real estate, foundations/associations, gambling and insurance.

If you manage funds, intermediate in significant transactions or work with complex structures, it's best to validate your status as soon as possible.

What do I have to do if I'm an obliged entity?

Implement an applicable AML/CFT system: KYC/UBO, AML manual, risk self-assessment, monitoring, training, internal control body and periodic audits.

The difference between "complying" and "complying well" is the evidence: records, traceability and consistent criteria.

Penalties: what can happen if I fail to comply?

Non-compliance can lead to financial penalties and reputational damage.

  • Minor: up to €60,000.
  • Serious: from €60,000 up to €5,000,000 or 10% of total resources.
  • Very serious: from €150,000 up to €10,000,000 or 10% of own funds.
Which AML documentation adds the most value in audits?

AML documentation that adds the most value in audits

  • AML/CFT manual and operating procedures (onboarding, due diligence, escalations, retention).
  • Risk assessment and evidence of its updating (changes in business/market).
  • Complete KYC files: verification, purpose, transaction profile and reviews.
  • UBO support: organizational charts, declarations, verifications and reasoning in complex cases.
  • Alert log: analysis, decisions, justification and follow-up.
  • Training: content, attendance, assessment and department-specific training.
  • Internal control body: appointments, minutes, reporting and annual control plan.
What are the typical AML mistakes that create risk?

Typical AML mistakes that create risk (and can be avoided)

  • "Onboarding-only" KYC with no periodic review or risk update.
  • UBO without reasonable verification in structures with multiple corporate layers or jurisdictions.
  • Monitoring without traceability: alerts with no conclusion, no evidence or no consistent criteria.
  • A generic manual that isn't applied in real operations (bureaucracy without execution).
  • One-off training instead of ongoing role-based training (onboarding + refreshers).
How is AML applied by sector?

AML/CFT lands differently depending on each sector's risk. Examples:

AML in the investment sector

  • Identify participants and UBOs in complex structures.
  • Monitor transactions and subscriptions/redemptions with consistent criteria.
  • AML manual + risk self-assessment by product, country and channel.
  • Training, internal control body and periodic audits.

AML in the financial sector

  • Enhanced due diligence and verification of the source/origin of funds where appropriate.
  • Ongoing review of the business relationship and transaction profile.
  • Detection tools, alert management and traceability of decisions.

AML in the real estate sector

  • Identification and verification in high-value transactions and complex payments.
  • Analysis of the source of funds and document retention.
  • Internal protocols, team training and escalation criteria.

AML in law firms

  • Analysis of the engagement and the client: purpose, structure and risk.
  • Identification of the client and UBO in corporate and transactional matters.
  • Control of payments/third parties and documentation of the criteria applied.

AML in crypto-assets and related providers

  • Robust KYC, identity verification and control of accounts/beneficiaries.
  • Activity monitoring: patterns, wallets, internal traceability and escalations.
  • Risk policies by product, jurisdiction and typology (sensitive transactions).
What is the internal control body and why does it matter?

The Internal Control Body (OCI) coordinates, supervises and follows up the anti-money laundering system, ensuring that policies are executed and gaps are corrected.

Without an active internal control body, the "governance" of the system usually fails: decisions, escalations, follow-up and evidence.

Practical AML/CFT guide

An AML system isn't "paperwork": it's a set of applicable controls your team can run and that leave evidence behind. The key is the risk-based approach: identify, assess, mitigate and document decisions (KYC/UBO, monitoring, escalations and document retention).

AML/CFT

What an AML system aims for

To reduce the risk of money laundering and terrorist financing through clear internal policies, consistent criteria and traceability. A good AML/CFT system helps protect operations, reputation and banking relationships.

AML/CTF

"Minimum" controls usually required

Due diligence (KYC), beneficial owner identification (UBO), risk classification, screening (PEPs/sanctions where applicable), ongoing monitoring and an internal escalation channel.

Evidence

What makes the difference

Having a manual isn't enough: you must be able to prove execution. Records, alerts, periodic reviews, internal control body minutes and justified decisions are usually the first thing reviewed in AML audits.

AML/CFT checklist in 10 steps (for obliged entities)

  1. Scope and applicability: confirm whether you are an obliged entity and define the activities/subsidiaries/channels included.
  2. Risk map: clients, products/services, channels, countries, third parties and typologies.
  3. KYC policy: identification/verification, purpose of the relationship, and periodic updating.
  4. UBO: obtaining and reasonably verifying ownership and control (including complex structures).
  5. Client risk: scoring and enhanced measures where appropriate (high risk/sensitive transactions).
  6. Screening: PEPs, sanctions and adverse/negative news where it applies to your sector and exposure.
  7. Monitoring: rules/thresholds, review of unusual transactions and alert management.
  8. Escalation and reporting: internal channels (including, where appropriate, reporting suspicious transactions to SEPBLAC).
  9. Governance: internal control body, owners, minutes, reporting and supervision of the AML/CFT system.
  10. Training + audit: role-based training and periodic reviews to measure effectiveness and close gaps.

If you want to implement AML operationally (without slowing the business), check our AML/CFT services or, if you need an independent review, the external expert report.

Free resource · PDF

Download the 10-step AML/CFT Checklist

The 10 controls every entity obliged by Law 10/2010 must meet, with the evidence you need for each one. Keep it handy and share it with your team.

  • The 10 steps of an auditable AML/CFT system
  • What evidence is expected for each control
  • References to Law 10/2010 and RD 304/2014
  • Professional PDF · 5 pages · 13 KB

No spam. Your email is only used to send you this checklist and, occasionally, relevant AML/CFT regulatory updates.

Your download has started

The checklist is downloading right now. If it doesn't start automatically, click here.

Once you've read it, do you need help implementing any of the steps? Message us directly:

AML in operational mode

AML: from "ticking boxes" to controlling risk with evidence

An effective AML/CFT system isn't a document: it's a set of repeatable decisions (KYC, UBO, risk, monitoring and escalations) with traceability. Here's a visual "dashboard" to understand how anti-money laundering lands in practice.

KYC scheme in AML: identification, verification and purpose of the relationship1) Onboarding

KYC done right: less friction, more control

The goal of AML isn't "to ask for paperwork": it's to understand the client's profile, the purpose of the relationship and to document a decision consistent with the risk.

  • Identification and verification
  • Purpose and activity
  • Risk and proportionate measures
Beneficial owner (UBO) identification in complex structures2) Beneficial owner

UBO: when the structure is the risk

In AML/CFT, the UBO isn't a formality: it's the basis for detecting real control, conflicts and opacity in complex structures.

  • Beneficial ownership and control
  • Layered structures
  • Evidence and reasoning
AML monitoring: alerts, analysis and traceability of decisions3) Ongoing

Monitoring: what generates the most evidence

Rules, thresholds and consistent criteria. Alerts with analysis, closure and traceability: that's "auditable" AML.

  • Detection of unusual transactions
  • Log of alerts and decisions
  • Ongoing monitoring
AML decision map: proportionate controls based on risk levelQuick decision

Practical AML map: what to do based on risk?

Low risk

Standard KYC + basic UBO + reasonable periodic review.

Medium risk

Enhanced controls + rule-based monitoring + evidence of decisions.

High risk

Enhanced due diligence + source of funds + internal escalation + intensive monitoring.

View AML services External expert report
AML Playbook

AML in practice

AML control
What's expected
Typical evidence

KYC (identification)

Verification consistent with the risk, purpose of the relationship and periodic updating.

KYC file, risk profile, review date and justification of exceptions.

UBO (beneficial owner)

Identify real control, especially in complex or cross-border structures.

Organizational charts, declarations, verifications and the reasoning of the "path" to the UBO.

Monitoring

Detection of unusual patterns, consistent analysis and closure of alerts.

Alert log, analysis, decisions, escalations and reviews of rules/thresholds.

Source of funds

Apply enhanced measures when the risk requires it and document the conclusion.

Supporting documentation, verification logic and traceability of the review.

Internal control body + audit

Governance of the AML/CFT system: follow-up, reporting and corrective measures.

Minutes, annual plan, KPIs, audit reports and remediation plan.

Typical signals that raise AML risk

Use them to adjust measures and justify enhanced due diligence where appropriate.

  • Inconsistency between declared activity and actual operations.
  • Reluctance to provide KYC/UBO information or inconsistent documentation.
  • Complex transactions with no clear economic rationale.
  • Frequent changes of beneficiaries, attorneys or structure.
  • High-risk countries/jurisdictions according to your internal assessment.
Operational glossary

Key AML concepts

If you're implementing AML, these terms appear in manuals, audits and in daily operations. Understanding them well helps you design applicable controls and generate evidence.

AML/CFTBasics

Anti-money laundering & counter-terrorist financing

Framework of controls to identify, assess and mitigate risks with consistent criteria and traceability.

Useful for: system design, audit, training.
KYCOnboarding

Know Your Customer

Identification and verification of the client, purpose of the relationship and periodic updating based on risk.

Typical evidence: file, reviews, justifications.
UBOBeneficial owner

Ultimate Beneficial Owner

The person(s) who actually control the entity or benefit from the transaction. Critical in complex structures.

Typical evidence: org chart + reasonable verification.
Risk-based approachCore

Risk-Based Approach

Assign controls proportionate to the risk: not every client/transaction requires the same, but everything must be justified.

Key: criteria + consistency + evidence.
MonitoringOngoing

Transaction monitoring

Detection of unusual patterns, analysis, escalation and closure of alerts with traceability.

Typical evidence: log of alerts and decisions.
Enhanced due diligenceHigh risk

EDD

Additional measures when the risk requires it: more verification, more support and more intensive monitoring.

E.g.: source of funds, intensive review, escalations.
Source of fundsSensitive

SoF / SoW

Reasonably document where the money (and, where appropriate, the wealth) comes from in sensitive transactions.

Avoid: "loose documents" with no conclusion.
ICBGovernance

Internal Control Body (OCI)

Supervises the AML/CFT system: follow-up, reporting, escalations and corrections to keep it "alive".

Typical evidence: minutes, KPIs, annual plan.
AML auditReview

Effectiveness check

Periodic reviews to verify that controls work, detect gaps and apply corrective measures.

Result: report + remediation plan.

COMPLIANCE CONTROL CENTER · AML/CFT

AML operational dashboard: control, traceability and evidence

For obliged entities, a good AML system is demonstrated through execution: KYC, UBO, monitoring, internal control body and audit. This dashboard sums up what a "living" and defensible AML/CFT looks like.

Visual risk matrix (AML)

A risk-based approach assigns proportionate and justified measures.

Impact
Low
Medium
High
Low prob.
Standard DDBasic KYC
Reviewevent-based
Controlsenhanced
Medium prob.
Monitoringlight
Screening+ rules
EDDSoF/SoW
High prob.
Follow-upongoing
Escalationinternal
Intensive+ evidence

Which companies and professionals must comply with AML/CFT?

Anti-money laundering and counter-terrorist financing (AML/CFT) doesn't only affect banks. Many obliged entities must also implement AML compliance measures, such as law firms, real estate agencies, financial operators, investment firms and providers related to crypto-assets. The key is not having "paperwork", but an applicable system: AML manual, risk assessment, KYC/UBO, training, monitoring and evidence.

If you need to implement a complete system, you can review our AML/CFT services, the AML manual, the risk assessment, the AML/CFT audit or the external expert report.

Book a call

Tell us your situation and we'll explain how we can help you comply with AML/CFT in an operational way.

AML/CFT legal framework in Spain: Law 10/2010 and RD 304/2014

Anti-money laundering and counter-terrorist financing in Spain is mainly governed by Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing, and its implementing regulation, Royal Decree 304/2014 of 5 May. Both transpose the EU AML directives (currently within the framework of the fourth and fifth AML Directives) and establish a risk-based approach system for obliged entities.

Who are the obliged entities?

Law 10/2010 sets out the list of obliged entities: credit institutions, insurers, fund managers, investment firms, notaries, lawyers, auditors, real estate agents, casinos and gambling operators, dealers in high-value goods (jewellery, art, luxury vehicles) and, since the transposition of the 5th AMLD, crypto-asset service providers (CASPs). Each category has specific obligations proportionate to the inherent risk of its activity.

The role of SEPBLAC

SEPBLAC (the Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences) is the Spanish Financial Intelligence Unit (FIU) and the main AML/CFT supervisor. It issues reference guidance, sector guidelines and carries out inspections of obliged entities. Its recommendations on risk assessment, KYC and documentary traceability are essential for any AML system that aims to pass a review.

Core obligations: KYC, UBO, monitoring and the internal control body

The prevention system requires, as a minimum: customer due diligence (KYC), identification and verification of the beneficial owner (UBO) according to the legal thresholds (25% in the general case), ongoing monitoring of the business relationship and transactions, reporting of suspicious transactions to SEPBLAC where appropriate, and an internal control body (OCI) that supervises the system and ensures it is kept up to date. Breaching these obligations is subject to a specific penalty regime, with fines that can reach 10 million euros or 10% of own funds.

MiCA and new obligations for crypto-assets

The entry into force of the MiCA Regulation (Markets in Crypto-Assets) and the evolution of the AMLD framework impose new obligations on crypto-asset service providers: registration with the CNMV, robust KYC, monitoring of wallets and transactions, and adaptation to the Travel Rule. If your activity includes crypto-assets, the AML/CFT system must be expressly adapted to this framework.

Law 10/2010 RD 304/2014 SEPBLAC 4th & 5th AMLD FATF MiCA Travel Rule