An AML programme may look complete on paper and still fail when reviewed in practice. The UK Financial Conduct Authority’s 2025 report found that most reviewed firms had a business-wide risk assessment, but very few had properly adapted it to their actual risks. The review found that some firms were unable to clearly explain how they were managing the risks they had identified. And these results indicate a bigger problem. AML weaknesses are more about poor implementation than lack of policies. Keep reading to explore the common AML compliance gaps.
Why AML Gaps Appear During Reviews
Many businesses treat AML compliance as a document exercise. They write policies, collect IDs, perform training, but they don’t test those controls to see how they’re working in the real world on a day-to-day basis.
Compliance review includes review of customer files, risk ratings, screening results, alerts, internal reports, training records and management oversight.
A thorough review will show that AML controls are risk-based, applied consistently and supported by evidence. Reviewers must see a clear trail from the identified risk to the action taken, the person responsible and the final decision. Clear the train when there is a change of staff, systems or responsibilities.
What are the Common AML Compliance Gaps Found During Reviews?
1. Generic or Old Risk Assessments
What Reviewers Find
The business risk assessment could be a copy of a template or based on old information. This assessment may not reflect current customers, products, locations, channels or transaction patterns. Some of the assessments list risks but do not explain how the risks were scored or controlled.
How to Repair
Review it from time to time and update the assessment as the business changes. Keep clear records of inherent risk, control effectiveness and residual risk. Each major risk must have a control, owner and review date.
2. Low-risk Customer Ratings
What Reviewers Find
Customers are often labelled low, medium or high risk with no clear rationale. Staff may rely on personal judgment instead of approved risk factors. A change in ownership, activity or transaction behaviour may also leave ratings unchanged.
How to Repair
Use documentable factors such as customer type, geography, ownership, products and expected activity. Determine when a high-risk rating is required. Look for big changes, strange activity or new screener results.
3. Incomplete Customer Due Diligence
What Reviewers Find
Files may have expired IDs, unavailable addresses, or unclear relationship information. Ownership documents or beneficial-owner evidence may not be in company files. Getting papers is not enough. The staff must check that the information is complete, consistent and reliable.
How to Repair
Use a checklist appropriate to the customer’s legal form and level of risk. Verify the information through a reliable person who ultimately owns or controls the entity. Use a chart for complex structures.
4. Poor Beneficial Ownership Checks
What Reviewers Find
Some firms accept the shareholder named on the first company document and do not follow the chain of ownership. The file may not represent the ultimate owner or controller of the customer. Screening checks can also fail to detect beneficial owners.
How to Repair
Trace the chain of ownership to the natural person who ultimately owns or controls the entity. A chart may be useful for complex structures. Verify facts with reliable sources and keep it simple.
5. Inconsistent Enhanced Due Diligence
What Reviewers Find
A high-risk customer may receive the same checks as a low-risk customer. There may be no source of the funds, or senior approval, or more robust monitoring. You can collect more documents without checking the coherence of the information.
How to Repair
Carry out stronger identity checks, verify the source of funds or wealth, obtain senior approval and review the customer more often. Document why the business relationship is acceptable despite the higher risk.
6. Sanction and PEP Screening Gaps
What Reviewers Find
Screening is only available at onboarding. Ownership details or political exposure are subject to change, and customers are not always re-checked. Extra documents may be collected without deciding whether the information makes sense.
How to Repair
Screen customers, beneficial owners and related parties at onboarding and throughout the relationship. Save the date, result, lists checked and decision. Define clear escalation rules and train staff to review aliases, ownership links and possible matches.
7. Ineffective Transaction Monitoring
What Reviewers Find
Rules for monitoring are frequently too broad, too narrow, or irrelevant to the business. This situation leads to many weak alerts and serious activity. Many weak alerts arise from this situation, resulting in the loss of serious activity. It can also make it challenging to spot unusual transactions when there is an absence of expected customer activity.
How to Repair
Monitor real products, customers, channels and risks. Review thresholds as behaviour, services and threats change. Find out why there is each rule and see if it works.
8. Weak Suspicious Activity Escalation
What Reviewers Find
Employees can see suspicious activity but cannot report it. They may assume automated monitoring, or the compliance team will identify the issue. Investigations may remain open without deadlines, evidence or clear decisions.
How to Repair
Establish a transparent internal reporting channel for employees and emphasise role-specific warning signs. Any concerns should be reported promptly to the MLRO or the compliance officer. Use a standard investigation record covering the activity, decision, evidence and reasoning.
9. Policies That Don’t Match Practice
What Reviewers Find
Policies may refer to systems, approval levels, review periods or roles that no longer exist. Employees may do something different than what is written. They do this by comparing policies with files and interviewing staff.
How to Repair
Map every policy requirement to an actual task, owner and record. Update documents when systems, services or responsibilities change. Ask employees to explain the process. There is no room for any gap between policy and practice.
10. Generic Training & Lack of Oversight
What Reviewers Find
Annual training may cover basic AML terminology but may ignore the risks employees face. The staff can get a quiz right and still miss a real red flag. Management reports could omit overdue reviews, high-risk customers, open alerts and unresolved findings.
How to Repair
Provide role-based training with examples from the business. Track attendance, test understanding, and refresh training as risks change. Provide management with clear reports of trends, exceptions and overdue actions. The MLRO should have sufficient authority, information and support.
How to Prepare for an AML Compliance Audit?
Conduct an internal gap assessment using samples of real customer files, alert and transaction samples. Ensure that the written policies align with actual practices.
Interviewing employees reviewing management information and checking that previous findings had been acted upon. Focus on weaknesses that might prevent the business from identifying high-risk customers or suspicious activity.
Close AML Gaps Before They Become Findings
Gaps in AML controls typically occur where risk assessments, customer checks, monitoring, reporting, training and oversight all fail. You can’t fix a bigger control problem by fixing one document.
Vertex Compliance offer services such as finding gaps in AML/CFT, conducting independent evaluations, assessing risks, helping with sanctions compliance, creating policies, performing internal audits, managing KYC services, and providing AML training tailored to specific roles. We can identify weaknesses, develop remedial actions, and prepare your AML programme for independent or regulatory review.
Contact us today to discuss your AML requirements and improve your controls before your next compliance review.
Frequently Asked Questions
What should we do after AML gaps are found?
Start by creating a clear action plan. Write down what needs to be fixed, who will handle it, and when it should be completed. Keep records of every change so you can show that the business has acted on the review findings.
Which AML gaps should be fixed first?
Deal with the issues that create the greatest risk first. For example, a serious weakness in customer checks or suspicious activity reporting should not be treated the same as a minor filing error. Prioritising the work helps prevent important problems from being delayed.
Who is responsible for fixing AML compliance gaps?
The compliance officer usually coordinates the work, but fixing the gaps may involve several teams. Senior management should also follow the progress and make sure the right people, time, and resources are available. AML compliance cannot be left to one employee alone.
How can we prevent the same gaps from appearing again?
Do not treat the review as a one-time exercise. Check that the new process is actually being followed, provide refresher training, and review the corrected areas again. Regular checks help confirm that the problem has been properly fixed rather than temporarily covered up.
How can Vertex Compliance help close AML gaps?
Vertex Compliance can review your existing AML framework, identify areas that need attention, and provide a practical roadmap for improvement. The support is tailored to your business, helping your team understand what to fix and how to strengthen its compliance process.