Singuard Home Blog Contact eTrader eTrader for Businesses eTrader for Traders Broker Broker CRM Live Demo Prop Firm Prop Firm CRM Live Demo
Licenses & Regulation

Writing an AML Policy for a Broker.

Most AML policies for trading firms are strong on definitions and weak on the part that matters: what happens on a Tuesday when a client's fourth card deposit is declined and a stranger wires the money instead.

Alex Onta, Executive Director, SINGUARD By August 28, 2026 8 min read

An anti money laundering policy is a set of operating instructions, and it is judged by whether the client files match it. Reviewers do not grade prose. They pull twenty accounts, check the risk rating, look for the documents the policy required at that rating, and see whether the alerts on those accounts were cleared with a reason. Everything below exists to make that sample come out clean.

Start with the business wide risk assessment

The policy sits on top of an assessment of the firm's own exposure, and the risk factors for a retail trading business are specific. Products offered on leverage settle quickly and can be closed at will, which makes an account usable as a value transfer route. Client geography can span jurisdictions with weak controls or active sanctions exposure. Delivery is non face to face by default. Payment methods vary in traceability: card, bank transfer, e wallet and crypto each carry a different profile, and crypto deposits raise attribution questions that card payments do not. Introducer and affiliate channels add a layer where the firm does not control the first contact.

The assessment should score these, and the scores should visibly drive the controls that follow. A firm that rates crypto deposits as higher risk and then applies identical checks to crypto and card clients has written two documents that contradict each other.

Customer risk rating and due diligence tiers

Every client gets a rating at onboarding, driven by stated factors: country of residence and nationality, occupation and source of wealth, political exposure, expected deposit level, payment method, and whether the relationship came through an introducer. The policy defines what each rating requires and what triggers a move between ratings.

Standard due diligence is identity and address verification against reliable sources, with liveness or document authenticity checks appropriate to remote onboarding. Enhanced due diligence adds source of funds and, for high risk cases, source of wealth, senior approval before the relationship opens, and more frequent review. Simplified measures exist in some regimes for specific low risk cases and should not be used as a default. The practical layers are described in KYC verification levels.

Be precise about deposit thresholds and review frequencies, and then set them where the firm can meet them. Reviewers compare the promise to the records, and an unmet promise is worse than a modest one that was kept.

Screening and the payment reality

Sanctions screening runs at onboarding and continuously, because lists change after a client is approved. The policy states which lists apply, given the firm's jurisdictions and its banking relationships, how matches are reviewed, who may clear a false positive, and how the decision is recorded. Adverse media screening usually sits alongside it with a defined scope. The mechanics are in sanctions screening basics.

Payment rules are where trading firms live or die on this, and they need to be explicit rather than implied. Deposits accepted only from an instrument in the client's own name. Withdrawals returned to the original funding source before any alternative is considered. Third party payments refused, with a documented exception process. Currency and route consistency checked against the client's stated residence. These rules are also what a payment provider expects to see during underwriting, which is why they belong in the policy rather than in a support team's habits.

The pattern that matters most in this sector is deposit followed by minimal trading followed by withdrawal to a different route. Monitoring has to catch low activity accounts, not only large ones, because a clean account moving money is the typical case rather than the exception.

Transaction monitoring and internal reporting

Monitoring rules should be written as scenarios the firm can actually run: deposits materially inconsistent with the client's stated profile, rapid deposit and withdrawal with little trading, structuring below a threshold, repeated failed payment attempts followed by a different instrument, and offsetting positions across linked accounts. Each scenario needs an owner, an investigation standard and a recorded outcome.

The internal reporting route has to be short and known: any employee who has a concern reports to the money laundering reporting officer, in writing, without discussing it with the client. The MLRO decides whether to file externally and records the reasoning either way, because a decision not to file is as much a record as a filing. Tipping off restrictions and how staff should respond to client questions during an investigation belong in the same section, along with the handling of any account freeze. The process is set out in suspicious activity reports.

Training, records and review

Training is required for all relevant staff at induction and periodically, and the register has to show who, when and on what. Sales staff need scenario training rather than legislation summaries, because they are the ones who hear the explanation that does not add up.

Records of identification, due diligence, monitoring decisions and internal reports must be retained for the statutory period, retrievable on request, and protected under applicable data protection law. That last combination causes real friction, since AML retention obligations and data minimisation duties pull in opposite directions, and the policy should state how the firm resolves it. The wider framework sits in AML directives explained.

Finally, state the review cycle and who approves the policy. Requirements differ by jurisdiction and change frequently. This is descriptive background rather than advice, and any firm should draft its policy against its own applicable law with qualified local counsel.

"Write the thresholds you will actually enforce. A policy that says every client is reviewed annually, in a firm that never reviews anyone, is evidence against you."

— Alex Onta, Executive Director, SINGUARD

Key Takeaways

Frequently Asked Questions

Should a broker accept a deposit from a client's spouse or company?

Third party payments are normally refused as a default, because they break the link between the account holder and the funds. Where a policy allows narrow exceptions, they should require documented evidence of the relationship and senior approval recorded on the file.

How long do AML records have to be kept?

Retention periods are set by local law and typically run for several years after the relationship ends. The practical requirement is that records are retrievable on request and handled in line with applicable data protection rules, which the policy should address explicitly.

Who decides whether to file a suspicious activity report?

The money laundering reporting officer, based on internal reports from staff. The decision has to be recorded either way, including where the MLRO concludes no report is warranted, and the client must not be told an investigation is under way.


About the Author

Alex Onta, Executive Director, SINGUARD
Alex Onta Executive Director, SINGUARD

Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.

Your Own Trading Firm, Live in 24 Hours.

SINGUARD builds the technology behind brokers and prop firms: trading platform, CRM, client portal and payment rails, one bundle, one predictable price. Book a call and see it working, or keep reading the guides.

More in Licenses & Regulation