AML screening requirements by region: US, EU, UK and beyond
AML screening is a legal obligation in every major financial jurisdiction, but no single law defines it. Each region places the requirement on regulated firms through its own framework, its own supervisor, and its own sanctions authority, built on a shared international standard. This guide maps who requires screening, and how the obligation is expressed, across the United States, the European Union, the United Kingdom, Canada, and the wider world, so a firm operating across borders can see the whole picture at once.
AML screening requirements are the legal obligations, set by each jurisdiction, to check customers and payments against sanctions, politically exposed persons and adverse-media data. No global statute defines screening; instead, an international standard sets the expectation and each country writes it into its own law, enforced by its own supervisor. For a firm that operates in one market this is straightforward. For a firm serving customers across borders, the obligations stack, and the program has to satisfy every regime it touches rather than only its home one.
Is AML screening legally required?
Yes. In every major financial market, regulated firms are legally required to screen customers against sanctions lists and, as part of a risk-based program, against politically exposed persons and adverse media. The obligation is not optional and not a best practice; it is a supervised requirement backed by penalties. What varies between jurisdictions is the wording of the law, the supervisor that enforces it, and the exact list of authorities whose sanctions must be honoured. The underlying expectation, that a firm must know whether it is dealing with a prohibited party before and during a relationship, is consistent worldwide.
What is the global baseline (FATF)?
The Financial Action Task Force sets the international AML and counter-terrorist-financing standard through its Recommendations, which most countries implement in national law. FATF does not regulate firms directly; it evaluates countries, and countries in turn impose the obligations on regulated entities. This is why AML screening requirements look similar across borders: they descend from a common source. It is also why FATF's mutual-evaluation findings matter to a firm, because a jurisdiction under pressure from a poor evaluation tends to tighten supervision and enforcement of the firms within it.
What does the United States require (FinCEN and OFAC)?
The United States splits the obligation across two bodies. FinCEN administers the Bank Secrecy Act, the core AML framework that requires customer due diligence and monitoring. OFAC administers sanctions, maintaining the Specially Designated Nationals list and program-specific measures, and its reach is wide because so much global activity clears in US dollars. A firm exposed to US-dollar clearing generally has to screen against OFAC regardless of where it is based. The two obligations run in parallel: the BSA program and the sanctions program are distinct, and a compliant firm satisfies both.
What does the European Union require (AMLD and AMLA)?
The European Union has historically imposed AML obligations through successive Anti-Money Laundering Directives, transposed into each member state's law. The EU's AML package added a single rulebook and created the Anti-Money Laundering Authority (AMLA), an EU-level supervisor intended to harmonise how the rules are applied across the bloc. EU sanctions are set by the Council of the European Union and apply across member states. For a firm serving EU customers, this means screening against EU-listed measures and meeting the customer due diligence and monitoring expectations the directives and the new rulebook set out.
What does the United Kingdom require?
Since leaving the European Union, the United Kingdom maintains its own regime. The Money Laundering Regulations set the AML obligations for regulated firms, supervised for most financial firms by the FCA. Financial sanctions are administered separately by OFSI, part of HM Treasury, which maintains the UK Consolidated List of sanctions targets. As with the US, the AML and sanctions obligations are distinct authorities, and a firm serving UK customers screens against the UK list while meeting the due diligence and monitoring expectations the regulations impose.
How does Canada compare (FINTRAC)?
Canada places AML obligations on reporting entities through the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, supervised by FINTRAC, with sanctions administered by Global Affairs Canada under several statutes. The recent Bill C-12 changes raised the standard so that a compliance program must be reasonably designed, risk-based and effective. Canada is one regime among peers here rather than the whole story, and a firm serving Canadian customers screens against Canadian listings and ministerial directives while meeting FINTRAC's program expectations, in the same pattern the other jurisdictions follow.
| Region | AML supervisor | Sanctions authority | Core framework |
|---|---|---|---|
| Global standard | FATF (evaluates countries) | UN Security Council baseline | FATF Recommendations |
| United States | FinCEN | OFAC | Bank Secrecy Act |
| European Union | AMLA and national FIUs | Council of the EU | AML rulebook and Directives |
| United Kingdom | FCA | OFSI (HM Treasury) | Money Laundering Regulations |
| Canada | FINTRAC | Global Affairs Canada | PCMLTFA |
| Australia | AUSTRAC | DFAT | AML/CTF Act |
How do you run one program across regions?
A firm operating across borders does not run a separate screening program per market; it runs one program that satisfies the union of the regimes it touches. That means screening against the combined set of applicable sanctions lists, applying due diligence and monitoring to the standard of the strictest relevant regime, and rating each relationship by its jurisdictional exposure. The practical challenge is that broader coverage generates more false positives, so scaling across regions without drowning the team depends on entity resolution rather than simply adding more lists. The full discipline is set out in our complete guide to AML screening, and the sanctions regimes themselves in sanctions lists explained.
FAQ
Is AML screening legally required?
Yes, in every major financial jurisdiction. Regulated firms are legally required to screen customers against sanctions lists, and as part of a risk-based program against politically exposed persons and adverse media. It is a supervised obligation backed by penalties, not an optional best practice. What differs between countries is the wording of the law, the supervisor that enforces it, and the specific sanctions authorities whose lists must be honoured, but the underlying expectation is consistent worldwide: a firm must know whether it is dealing with a prohibited party before it opens a relationship and for as long as that relationship lasts. Because the obligation descends from a shared international standard, it looks similar across borders even though no single global statute defines it. A firm operating in more than one market has to satisfy each regime it touches, not only the one in its home country.
What is FATF and why does it matter for screening?
The Financial Action Task Force is the body that sets the international AML and counter-terrorist-financing standard through its Recommendations. It does not regulate firms directly; it evaluates countries, and countries implement the standard in national law that then binds regulated entities. This is why AML screening requirements across the United States, the EU, the UK, Canada and elsewhere resemble each other rather than being written from scratch in each place: they descend from a common source. FATF's mutual evaluations also matter to firms indirectly, because a country that receives a poor evaluation tends to tighten supervision and enforcement of the firms operating within it. Understanding FATF helps a compliance team see why the obligations rhyme across the jurisdictions it operates in, and why a screening program built to the FATF-derived standard travels reasonably well from one market to the next rather than needing a full rebuild per country.
How are AML and sanctions obligations different?
In most jurisdictions they are separate obligations, governed by separate authorities, that a firm has to satisfy at the same time. The AML obligation, administered by a financial-intelligence or conduct supervisor such as FinCEN, the FCA or FINTRAC, covers customer due diligence, ongoing monitoring and suspicious-activity reporting. The sanctions obligation, administered by a distinct authority such as OFAC, OFSI or the EU Council, prohibits dealings with designated parties and is typically strict-liability, meaning intent does not excuse a breach. Screening sits at the intersection: sanctions screening enforces the prohibition, while PEP and adverse-media screening feed the risk-based AML program. Treating the two as one and the same is a common mistake, because the response to a confirmed sanctions match, refusal, is different from the response to a PEP match, enhanced due diligence. A complete program runs both and routes each type of hit to the correct action.
Which countries' sanctions do we have to screen against?
The ones that apply to your business, which is usually determined by where your customers are, what currencies you handle, and which correspondents and payment corridors you rely on, rather than solely by where you are incorporated. A firm clearing US dollars is exposed to OFAC regardless of its location; a firm serving EU or UK customers needs those regimes; and the UN baseline underpins most national programs. Screening only your domestic list while serving an international customer base leaves a real gap, because a party clean at home can be listed abroad. The practical approach is to map your actual exposure across customers, currencies and corridors, cover the regimes that follow from it, and treat trade restriction lists separately if you deal in dual-use goods or trade finance. Broader coverage raises false-positive volume, which is why entity resolution becomes more important as the number of regimes grows.
Can one screening program cover multiple jurisdictions?
Yes, and for a cross-border firm it is the only workable approach. Rather than running a separate program per market, a firm runs one program that satisfies the union of the regimes it touches: screening against the combined set of applicable sanctions lists, applying due diligence and monitoring to the standard of the strictest relevant regime, and rating each relationship by its jurisdictional exposure. The obstacle is not coverage but noise, because adding lists multiplies false positives, so a multi-jurisdiction program depends on entity resolution to keep the alert queue workable as coverage grows. Done this way, expanding into a new market becomes a matter of adding the relevant lists and adjusting risk ratings rather than standing up a whole new compliance operation. The same underlying screening engine and data layer serve every jurisdiction, so the false-positive reduction and the audit trail are consistent across markets.
Sources
One screening program, every regime you answer to.
Book a demo and we will show you sanctions, PEP and adverse-media screening across OFAC, EU, UK, Canada, Australia and APAC coverage on one engine, risk-rated per jurisdiction. No retainers. No hourly rates.
Book a demo
