Back to Blog

What Is Anti-Money Laundering (AML)? The Five-Pillar Framework Explained

Phalcon Compliance
July 24, 2026
6 min read

A flagged deposit lands at 02:00. It moved through three hops before it reached the platform wallet. Identity checks at onboarding already passed. The question is no longer who the customer claims to be. It is whether the institution has a system built to catch this flow, document it, and report it. That system is anti-money laundering. AML is the program, not the crime.

What Is Anti-Money Laundering (AML)?

Compliance officers new to the field often blur two terms that sound alike. Money laundering is the crime. It moves illicit funds through placement, layering, and integration until the source is disguised. Anti-money laundering is the response. It is the set of policies, controls, people, and reporting duties an institution builds to detect, block, and report that crime.

AML is not a single tool. It is a risk-based program that ties identity checks, transaction screening, record-keeping, and audit into one obligation. A regulator does not ask whether a firm bought software. It asks whether the program works. The risk-based approach is the spine of that program. It directs more scrutiny to customers, products, and flows that carry higher risk, so a firm spends its compliance budget where exposure is real rather than evenly across every account. For the behavior side of the definition, see what money laundering itself means (our What Is Money Laundering guide). This piece covers the system that fights it.

The Five Pillars of an AML Program

An AML program rests on five pillars set by the FinCEN Bank Secrecy Act rule: internal policies and controls, a designated compliance officer, ongoing training, independent audit, and risk-based customer due diligence. Each pillar names a function, not a tool. The five together define the minimum program a covered institution must run.

Diagram of the five pillars of an AML program
Diagram of the five pillars of an AML program

The four core pillars trace to FinCEN's BSA AML program rules for covered institutions—for example, 31 CFR 1022.210 for money services businesses and 31 CFR 1020.210 for banks. The fifth pillar—risk-based customer due diligence—was added by FinCEN's 2018 CDD Rule under 31 CFR 1010.230. Each names a function the institution must operate, not a product it must buy.

  1. Internal policies, procedures, and controls. The firm writes the rules that govern how it screens, escalates, and records. In crypto, the control layer lands on-chain as address screening and transaction monitoring, where wallets and transfers are the objects under policy.

  2. A designated compliance officer. One accountable owner runs the program, files reports, and faces the regulator. The title is a role, not a hire.

  3. Ongoing employee training. Staff learn the firm's risk posture, typologies, and escalation paths. Training is continuous because the threat moves.

  4. Independent audit or testing. A party that does not report to the audited function tests whether the program works. Independence is the safeguard against self-marking.

  5. Risk-based customer due diligence. The firm verifies the customer, applies enhanced diligence where risk is high, and monitors the relationship over time. This pillar has two sublayers. The identity layer is the institution's own KYC. The ongoing monitoring layer watches for risk that emerges after onboarding.

Pillar five is where the framework meets the chain. The identity check runs once. The monitoring runs for the life of the relationship. Drop any pillar and the program breaks: without audit, no one checks the controls; without training, staff miss the signals; without a compliance officer, no one owns the finding. The pillars are interdependent, not optional. For the international standard that maps these duties onto virtual asset service providers, see FATF guidance on virtual assets. For the U.S. rule that fixes the five pillars, see FinCEN on money laundering.

Pillar Function Crypto Deployment BlockSec Role
1 Internal policies, procedures, controls Lands on-chain as address screening + transaction monitoring Screening & monitoring layer
2 Designated compliance officer Accountable owner; unchanged Institution
3 Ongoing training Continuous; threat moves Institution
4 Independent audit Tests whether on-chain controls work Institution
5 Risk-based CDD Splits into identity (one-time) + ongoing monitoring (continuous) Institution owns identity; Phalcon Compliance runs ongoing monitoring (KYA + KYT)

Why Crypto AML Is Harder, and Where Monitoring Fits

Three structural gaps make the five pillars harder to run on-chain than in traditional finance.

First is time. A chain settles in seconds. A control that runs after finality has no window. Pillar one's controls and pillar five's monitoring must run at the moment of transfer, not in a nightly batch.

Second is reach. Funds hop across chains, bridges, and mixers. A graph that stops at the first hop misses the layering. Pillar one's controls need a tracer that follows value across chains, not within one ledger.

Phalcon Compliance interface for tracing crypto AML risk
Phalcon Compliance interface for tracing crypto AML risk

Third is identity. One entity holds many addresses. One address serves many entities. The identity layer and the on-chain layer are decoupled. A control that only reads the identity file cannot see the flow.

Phalcon Compliance covers the monitoring and screening pillars in this stack. KYA, or Know Your Address, screens wallet risk against a database of more than 600 million labeled addresses and seventeen risk indicators, including Sanctioned, Mixing, and FATF high-risk jurisdiction. KYT, or Know Your Transaction, monitors each transfer in real time, traces funds across chains with unlimited hops, and flags layering patterns through behavioral rules aligned to the FATF default engine. When a transfer is confirmed suspicious, the platform exports a suspicious transaction report aligned with major regulatory jurisdictions, using region-specific templates for direct filing.

What Phalcon Compliance does not do is just as defined. It does not perform the identity verification that sits inside pillar five's customer due diligence. It does not run the independent audit in pillar four. It does not deliver the training in pillar three. Those remain the institution's own duties. Phalcon Compliance is the screening and monitoring layer that feeds the rest of the program. For the full platform read, see the AML compliance platform for crypto.

Phalcon Compliance monitoring workflow for AML controls
Phalcon Compliance monitoring workflow for AML controls

Putting the Five Pillars to Work

Naming the five pillars is the entry point. Running them is the work. The institution owns policy, officer, training, and audit. The on-chain monitoring and screening layer is where a crypto compliance team most often needs a purpose-built tool, because pillar one and pillar five meet the chain at the transfer.

→ Book a Phalcon Compliance demo and run the monitoring pillar that meets the chain at the transfer: Book a demo

Frequently Asked Questions

Is AML the same as money laundering?

No. Money laundering is the crime of disguising illicit funds. AML is the compliance program institutions build to detect, block, and report that crime.

Do the five pillars apply only to banks?

No. The BSA AML program rule applies to a range of covered financial institutions. Under FATF Recommendation 15, a VASP carries equivalent duties. The five pillars are the program skeleton.

How does pillar five CDD relate to KYT?

CDD has two sublayers: identity verification and ongoing monitoring. KYT is the on-chain implementation of the ongoing monitoring sublayer. It screens transfers and addresses, not identities.

How often should the independent audit run?

Frequency is risk-based. There is no fixed statutory interval. The binding rule is independence: the auditor must not report to the function under review.

For readers who want to see the monitoring pillar deployed on a real workflow, our blockchain legal compliance guide walks from this framework into the operational picture. Enter an address on the platform landing page to see how a KYA risk score is produced.

Start Real-Time AML with Phalcon Compliance

Turn Phalcon Network alerts into actions with Phalcon Compliance. Use verified blockchain intelligence to screen wallets, monitor transactions and investigate risks. This helps you respond quickly and stay compliant in the digital assets ecosystem.

Phalcon Compliance