← All postsHow-to

AML training for employees: what regulated firms need to cover and evidence

AML training for employees has to fit the firm's risks and each role's exposure. What to cover, how often, and the training records an inspection will ask for.

How-toA

AML training for employees is a specific obligation for firms covered by anti-money laundering rules: staff must understand the risks the firm faces, recognise suspicious activity in their own work, and know exactly what to do about it. Generic e-learning ticks a box but rarely survives a supervisor's questions. What inspectors test is whether the training matched the firm's risk assessment, whether the right people got the right depth, and whether the firm can prove it.

What AML training for employees should cover

  • The firm's own money laundering and terrorist financing risks, taken from its risk assessment rather than a textbook.
  • Customer due diligence and when enhanced due diligence is required.
  • Red flags that apply to the employee's role — unusual payments, reluctance to provide information, complex ownership.
  • How to raise an internal suspicious activity report, and to whom.
  • Tipping-off rules: what the employee must not say to the customer.
  • Record-keeping duties and why records matter to investigations.
  • Personal consequences of failing to report.

Match depth to role

  1. Map roles to exposure: client-facing and transaction staff need more depth than back-office roles with no customer contact.
  2. Give the nominated officer and senior managers training on oversight, reporting decisions and governance.
  3. Train new starters before they handle relevant work, not months later.
  4. Set a refresher cycle — commonly annual — and bring it forward when rules or the firm's risks change.
  5. Add targeted sessions after internal incidents or regulatory findings.

Use cases from your own sector. Staff remember a realistic scenario from their own type of transaction far better than a generic list of typologies.

Evidence the training

The training record is what a supervisor examines: who was trained, on what content and version, when, how understanding was tested, and what happened with people who missed or failed it. Ettex Records keeps that per-employee record with the certificate or assessment result attached, and a completion view by role shows gaps before an inspection does. Policy acknowledgements — confirming staff have read the AML policy — can be collected as signed records alongside the training.

Measuring whether it worked

  • Assessment pass rates by role, not just completion rates.
  • The number and quality of internal suspicious activity reports after training.
  • Findings from file reviews on customer due diligence quality.
  • Time taken to escalate concerns, from internal records.
  • Staff feedback on whether scenarios matched their real work.

AML training sits within the wider compliance training programme: mandatory compliance training defines the full list of required courses, employee training records hold the evidence, and client due diligence is the day-to-day process the training exists to support.

Frequently asked

How often should AML training be delivered?

At least on joining and regularly afterwards — annual refreshers are common. Additional training is expected when regulations, products or the firm's risk profile change.

Does everyone need the same AML training?

No. Training should be proportionate to the role. Staff handling customers and transactions need deeper, scenario-based training than colleagues with no exposure.

Is e-learning acceptable for AML training?

It can form the core, but supervisors increasingly expect firm-specific content and testing of understanding. Supplement generic modules with your own scenarios and procedures.

DK
Written by Daria K.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.