What Should a Forex Broker AML/KYC Policy Include?

Quick answer: A forex broker AML/KYC policy should be much more than a checklist for collecting a passport and proof of address. It should form an operating framework that identifies the broker’s money laundering, terrorist financing and proliferation financing risks; defines customer acceptance and prohibited business; identifies and verifies customers, beneficial owners and controllers; applies risk-based CDD and EDD; manages PEP, sanctions, adverse-information, source-of-funds and source-of-wealth issues; monitors deposits, trading behaviour and withdrawals; escalates concerns; supports legally required reporting; and produces evidence for governance and testing. During licensing, a regulator can compare the document with the proposed customers, countries, products, payment routes, people and systems. After launch, the question becomes whether the broker actually follows it.

Information last verified on 2 September 2026. This article provides a general risk-based design framework and is not legal or regulatory advice. Definitions, beneficial-ownership tests, sanctions duties, reporting rules, record-retention periods and review cycles must be confirmed under the law and licence permissions of the relevant jurisdiction. A complete policy does not guarantee authorisation.

Policy, procedure, risk assessment and workflow are not the same thing

A common licensing weakness is to mix every control into one generic manual. A business-wide risk assessment explains which financial-crime risks the broker faces and where they arise. A policy establishes principles, responsibility, risk appetite and non-negotiable boundaries. A procedure tells staff what to do in a defined situation. A workflow configures those steps in onboarding, CRM, screening, payments, trading and case-management systems. Evidence shows that the workflow operated, while management information helps the board and compliance function decide whether controls remain effective.

The FATF Recommendations, amended in June 2026, continue to frame AML, counter-terrorist financing and counter-proliferation financing through a risk-based approach. The FCA Financial Crime Guide likewise says a risk assessment should consider products and services, jurisdictions, customer types, transaction complexity and volume, and distribution channels. It should be comprehensive, draw on relevant information and remain proportionate to the firm’s nature, scale and complexity. These are design principles, not a universal application template.

Control layer Question it answers Forex-broker example Expected evidence
Business-wide risk assessment Where could the business be misused? Remote onboarding, introducing brokers, third-party payments and multicurrency flows Risk factors, methodology, controls, residual risk and approval
AML/KYC policy What is accepted, prohibited or escalated, and who owns the decision? No anonymous accounts; defined approval for higher-risk relationships Board approval, ownership, version control and risk appetite
Operating procedure What must staff do in a specific case? Corporate UBO verification, PEP review and inconsistent-data handling Steps, roles, deadlines and required records
System workflow How is the control made operational? Funding disabled before verification; alerts require documented disposition Permissions, status gates, logs, cases and audit trail
Oversight and testing Is the framework working? Alert backlogs, overdue reviews, quality sampling and remediation Reports, tests, issue owners, deadlines and closure evidence

1. Start with the broker’s actual ML, TF and PF risk

The policy should not begin with a document list. A reviewer first needs to understand what products the applicant will offer, through which licensed legal entity and permissions, to which customers and countries, using which acquisition channels, and through which banks and payment providers money will move. Without that operating map, low, medium and high risk are only labels.

A forex-broker assessment commonly covers:

  • Customers: individuals, companies, trusts and other arrangements; occupation or industry; ownership complexity; PEP connections; and whether behaviour is consistent with the declared background.
  • Geography: residence, incorporation, beneficial-owner location, business substance, banks, payment routes, sanctions exposure and reliable higher-risk information.
  • Products and permissions: execution model, leveraged products, agency or white-label arrangements, payment functionality and the precise regulated perimeter.
  • Transactions and money flows: expected deposit size, currency, frequency, payer, beneficiary, refunds, withdrawals, chargebacks and use of multiple providers.
  • Distribution: remote onboarding, introducing brokers, affiliates, agents, outsourced KYC, white-label partners and manual account opening.
  • Technology and operations: identity verification, screening, customer linkage, monitoring, case management, access control, data quality and system interruption.

Each risk should lead to a control. If remote onboarding creates impersonation risk, the framework should explain the authenticity control, when additional verification is requested, who approves an exception and where evidence is retained. Saying that the firm uses a leading KYC platform does not show whether it fits the proposed customer base or licence.

2. Define customer acceptance, identification and verification

Customer acceptance must come before sales targets. The policy should define prohibited relationships, cases requiring enhanced approval, circumstances in which simplified measures are legally available, and what happens if verification cannot be completed. A valuable client, referral by a partner or completed deposit should never allow staff to bypass a core identification requirement.

Customer type Parties to understand Verification focus Typical escalation cause
Individual Customer and any legally relevant representative Identity authenticity, contact or residence data, occupation, purpose and expected activity Conflicting identity, unexplained agency, unusual geographic link or implausible funding background
Company Entity, directors, authorised persons, shareholders, UBOs and controllers Formation and existence, business substance, ownership chain, authority and control Opaque layering, unexplained nominee arrangement or mismatch between legal and actual control
Partnership Partners, managers, authorised persons and natural-person controllers Registration, agreement, profit rights and management powers Documents do not reflect practical decision-making
Trust or legal arrangement Locally required settlor, trustee, protector, beneficiaries or class and controlling persons Instrument, amendments, powers, assets, purpose and distribution rights Missing parties, vague beneficiaries, unclear asset origin or undisclosed control
Agent or introduced relationship Customer, agent and the underlying mandate or economic interest Authority, identity, business purpose and actual control Introducer controls the account, funding or withdrawals, or will not disclose the end customer

Corporate due diligence should not stop at a certificate of incorporation or the first shareholder. The process should traverse the ownership chain to the natural persons required by local law and address control through means other than ownership. There is no single UBO percentage that can safely be copied into every jurisdiction. The ownership analysis should also agree with the proposed licensed structure described in the forex broker company structure guide.

3. Make customer risk ratings explainable

A vendor-generated colour is not a risk assessment. The policy should identify the factors used, the source and quality of data, how factors affect the result, which events require manual review, who may override a system output and how an override is documented. The rating must change what happens next: information depth, approval, monitoring, event review and relationship governance should respond to risk.

  1. Capture customer, geographic, product, channel and expected-transaction risk at onboarding.
  2. Identify special factors such as sanctions, PEP exposure, credible adverse information, complex ownership and agency.
  3. Assess residual risk after controls, rather than merely adding every inherent-risk score.
  4. Connect the outcome to standard CDD, EDD, senior approval, restriction or rejection.
  5. Reassess when ownership, payment routes, customer data or behaviour materially changes.

The FCA framework distinguishes relationship-level risk from the business-wide assessment. One informs the other, but neither substitutes for the other. Both need a documented response to new products, markets, providers, systems, internal defects and material regulatory developments.

4. Connect EDD, PEPs, sanctions and adverse information

Enhanced due diligence is not simply an extra utility bill. Measures should target the reason for higher risk. Depending on local law and the facts, they may include a deeper understanding of ownership, control, business activity, relationship purpose, expected flows, source of funds or source of wealth; additional independent corroboration; higher approval; and stronger ongoing monitoring. AUSTRAC’s 2026 guidance likewise describes EDD as targeted, proportionate, effective and appropriate to the duration of the risk.

A PEP is not automatically a criminal, and sanctions screening is not a simple exact-name search. The framework should explain:

  • how PEPs, relevant family members and close associates are identified and how locally required senior approval and funding or wealth checks operate;
  • which relevant parties are screened, how aliases and false positives are investigated, and how list changes reach live customers;
  • how credible adverse information supports judgment without treating an unverified search result as fact;
  • when a case reaches the MLRO or local designated officer, and how staff avoid inappropriate disclosure to the customer.

Depth of source-of-funds and source-of-wealth work should reflect risk. For an evidence-chain approach, see our source of funds evidence guide.

5. Monitor deposits, trading behaviour and withdrawals together

KYC is not completed forever on the account-opening date. Risk-sensitive ongoing monitoring checks whether actual activity remains consistent with identity, business or occupation, account purpose, expected activity and known funding background. It also refreshes CDD when information becomes doubtful or materially changes.

A broker should avoid fragmented visibility. CRM, trading platform, client-money ledger, bank, payment provider and case system may each show only part of the journey. A reliable customer identifier and reconciliation process should let investigators connect relevant signals without weakening access controls or privacy safeguards.

Monitoring point Question Control example Evidence retained
Initial and later deposits Is the payer permitted and is the amount consistent with the profile? Account-name comparison, third-party payment rules, method and country review Payment data, discrepancy, escalation and decision
Account and trading activity Does behaviour fit the known purpose and risk? Risk-derived scenarios, linked-account analysis and human investigation Alert basis, review scope, evidence and conclusion
Refund and withdrawal Is the destination, owner and route reasonable? Return to a verified source where appropriate; reverification after material changes Instruction, ownership check and exception approval
Customer change Has ownership, occupation, control, location or risk changed? Event-triggered refresh, rescreening and risk reassessment Old and new data, trigger, completion and rating change
Cross-system case Do separate signals become significant when combined? Unified reference, case aggregation and compliance review Data sources, searches, action and closure rationale

The public policy should not expose exact thresholds or detailed detection logic that can be tested and evaded. Controlled procedures and configurations can hold sensitive parameters. The governance document should instead explain how scenarios derive from risk, who tunes them, how false positives and backlogs are managed, when escalation occurs and how quality is tested. Broader post-authorisation duties are covered in our forex licence ongoing compliance guide.

6. Build a closed loop for suspicion, escalation and reporting

The framework should take a concern from frontline staff or a system alert through investigation, internal escalation, MLRO decision and any legally required external report. It should state how staff raise a concern, how work is allocated, which internal information can be reviewed, who decides whether to restrict, continue or exit a relationship, and what monitoring follows. The legal threshold, form, timing and confidentiality rule must be set for the local jurisdiction.

Training and customer communication should never disclose how to avoid controls. Scripts used to request documents, delay a transaction or restrict an account require compliance review so staff do not improperly reveal that a suspicious report has been made or is being considered.

7. Specify governance, competence, training and independent testing

An appropriate board or senior manager should approve the framework and appoint a competent officer with enough independence, authority, resources and system access. Organisation charts, job descriptions, committee mandates, outsourcing contracts and permissions should agree with the policy. A manual that promises daily MLRO oversight is not credible if the role cannot see the bank, PSP, trading platform or case system.

Owner Core responsibility Evidence for oversight Frequent failure
Board or senior management Approve risk appetite, policy, resources and material risk decisions Management information, major issues, remediation and challenge Signs a template without understanding the business
MLRO or compliance officer Oversee the framework, escalation, reporting judgments and remediation Mandate, competence, access, independent reporting line and cover Role outsourced with no accountable internal owner
Business and operations Execute onboarding, payment, monitoring and escalation controls Training, quality checks, errors and corrective actions Sales can override compliance or alter risk ratings
Technology and data Maintain rules, interfaces, access, logs and data quality Change tests, incidents, access reviews and completeness checks A release silently disables screening or alerts
Independent reviewer Assess design and operating effectiveness Scope, samples, issue grading, owners, deadlines and retesting The control designer approves their own work as independent

Training should be role-based. Directors need risk and oversight; sales and introducing-broker managers need acceptance boundaries; onboarding staff need identity, UBO and discrepancy handling; payments staff need payer and beneficiary controls; investigators need case quality, reporting and confidentiality. Completion statistics are not enough: testing, sampling and actual errors should reveal whether people understand the material.

8. Treat outsourcing as supervised delivery, not transferred responsibility

Identity verification, screening, monitoring, support and even investigation may use vendors, but the licensed firm must still understand and supervise the control. The policy should cover selection and due diligence, data sources and coverage, service levels, false-positive and missed-result management, privacy and access, continuity, change notification, audit rights, exit and data migration.

Bank and payment arrangements must also match the stated operating flow. A PSP is not a shortcut around bank due diligence or the regulatory perimeter. Our forex broker corporate bank-account guide explains the evidence banks commonly assess. A licence without an executable settlement route may remain commercially unusable, as discussed in our licence and settlement-path analysis.

Pre-application implementation test

  1. Map the real business: legal entity, permissions, customer countries, acquisition, banks, PSPs, platform and vendors.
  2. Complete the risk assessment: record inherent risk, controls, residual risk, information sources, ownership and approval.
  3. Build a control matrix: connect each applicable obligation and risk to policy, procedure, system, role and evidence.
  4. Walk customer journeys: test an individual, complex company, higher-risk customer, data conflict, third-party deposit and unusual withdrawal.
  5. Reconcile system configuration: fields, states, permissions, alerts, logs, integrations and language versions should match the documents.
  6. Test governance: board, MLRO, operations, technology, assurance and vendors should understand ownership and escalation.
  7. Prepare inspection evidence: retain versions, approvals, training, samples, cases, changes, issues, remediation and retests.

A frequent failure is renaming an internet template without adapting it to the proposed customers, locations, payment methods and systems. Other warning signs include references to a committee that does not exist, a high-risk approver who has not been appointed, or banking and PSP flows that conflict with the business plan. Material inconsistency may also contribute to delay, additional questions or an adverse authorisation outcome.

Frequently asked questions

Can a forex broker use a generic AML/KYC template?

Not safely without substantial adaptation. A template may help establish headings, but the content must reflect local law, permissions, customer countries, products, acquisition, bank and payment routes, systems and staffing. A regulator can compare it with the business plan, organisation, contracts and technology.

Must AML and KYC be separate policies?

Not necessarily. A firm may use one integrated framework or a master policy supported by CDD, sanctions, monitoring and reporting documents. What matters is clear ownership, version control, cross-references and consistent control boundaries.

Must every customer receive the same level of due diligence?

No. Risk-based controls should be proportionate, but core identification and applicable beneficial-ownership duties cannot be skipped because a client is valuable or introduced by a partner. Simplified and enhanced measures need a lawful basis and documented rationale.

Is there a universal UBO ownership percentage?

No single percentage can be applied safely to every country and licence. The policy must use the relevant legal and regulatory definition and consider natural persons exercising control through other means, not only the first shareholder layer.

Does a third-party KYC or screening vendor take responsibility away from the broker?

Generally no. The licensed firm should understand the tool’s coverage and limits, supervise data quality and outcomes, preserve an audit trail, and maintain arrangements for human review, outages, changes and exit.

How often should an AML/KYC policy be updated?

Follow the local legal cycle and update on material triggers such as changed risks, products, markets, ownership, systems, channels, vendors, rules or control failures. A fixed frequency from one country should not be presented as a global rule.

Must transaction monitoring already be live during the licence application?

That depends on the jurisdiction and application stage. The applicant should at least explain how scenarios derive from risk, how data will flow, who investigates and escalates, how decisions are recorded, how controls are tested and how readiness will be validated before launch.

Does a complete AML/KYC policy guarantee licence approval?

No. It is one component of an application. Regulators also assess owners, management, capital, business model, governance, staffing, technology, outsourcing, bank and payment arrangements, and local substance. A strong policy improves consistency and verifiability but cannot guarantee an outcome or timeline.


Discuss Your Licensing and Business Needs

Tell us what you need and our team will contact you shortly.