Knowing about sanctions, KYC and KYT is not enough — it all has to live in a single document that the team works by every day. An AML policy turns scattered knowledge into a reproducible process: any employee on any day makes decisions the same way, and under a regulator's inspection you have written proof of good faith. In this lesson we assemble a minimal but workable AML policy for a small crypto business: rules for accepting funds, inbound screening, a decision log, an accountable person and escalation — with a ready-made template you can adapt.
Many small exchange desks and services operate "on the founder's intuition." This is dangerous for three reasons: intuition does not scale to new employees, leaves no trail for the regulator, and falls apart under pressure (a lucrative client, a rush, fatigue). A written policy solves all three.
The core of the policy is a clear algorithm by which every incoming operation is accepted or rejected. Formalise it as a sequence of steps.

Inbound screening: the sending address is checked before crediting; the decision is made by predefined risk bands.
To make the decision reproducible, tie it to ranges of the risk score, not to gut feeling.
Sanctions exposure stands outside the scale: even a small share of funds tracing back to an SDN address means an unconditional refusal, regardless of the "cleanliness" of the rest. This is the rule from Lesson 9.1 — strict liability.
The log is the business's defence. Every operation where an AML check was applied is recorded uniformly and kept for at least 5 years (the standard retention period for AML data in most jurisdictions).
| Date | Client/ID | Address/TXID | Amount | Risk score | Decision | Basis | Accountable |
|---|---|---|---|---|---|---|---|
| 24.08.26 | C-0417 | 0x…/TXID | 2,000 USDT | Low (12) | Accepted | Clean source | I.I. |
This minimal set of fields answers the regulator's question of "who, when, what did they check and why did they make such a decision."
The policy must designate a person responsible for AML (in large companies — the MLRO, Money Laundering Reporting Officer; in a small business — a specific employee or the founder themselves). They approve contentious decisions and run escalation.
A policy is not a "write it and forget it" document. Sanctions lists are updated constantly, new laundering typologies appear, thresholds and regulators' requirements change. That is why two recurring processes are built into the policy. The first is a regular review of the document itself and of the list databases in use (at least once a quarter, and immediately upon major changes to sanctions regimes). The second is staff training: everyone who makes decisions about accepting funds must understand the logic of the risk bands, be able to read the result of an AML check, and know that sanctions are an unconditional stop, not something to "negotiate over."
Behaviour under pressure deserves a separate note. The most dangerous mistakes happen not from ignorance but from temptation: a big client is rushing, the rate is favourable, "just this once." That is exactly why decisions must rest on a written algorithm and the accountable person's signature, not on the operator's mood. A good policy makes "the right thing" the path of least resistance, and "going around the procedure" a conspicuous exception that stays in the log.
AML policy of [Business name] — revision of [date]
This policy is deliberately minimal: it can be rolled out in a small exchange desk in a day, not a quarter. But it is exactly what separates a bona fide business from a "reluctant laundromat." Start with it, document decisions from day one — and you will avoid most of the freeze scenarios we examined in Section 8, now from the side of the one who prevents them.
This concludes the sections on freezes and corporate AML. You have travelled the path from understanding the mechanics of blocks to building your own process for preventing them — and that is the level of a professional in AML checking.
This material is educational and does not constitute legal advice.