Once AMLA applicability is confirmed, the business needs a permanent compliance process. It must organise responsibilities, client due diligence, risk decisions, documentation, updates and independent controls so that every decision can later be reconstructed.
1. Establish internal governance
Senior management remains responsible for compliance. It should appoint a suitably qualified AML responsible person and deputy and define their authority, escalation routes and reporting duties in writing.
- Issue an AML policy and operational procedures.
- Define four-eyes controls and approval levels.
- Provide effective cover during absences.
- Train staff before they perform relevant work.
- Manage conflicts of interest and control independence.
- Report regularly to management.
Small businesses may combine roles pragmatically, but critical decisions still require effective challenge and control.
2. Clarify SRO membership
Professional financial intermediaries generally have to join an SRO recognised by FINMA. The SRO monitors compliance and applies its own regulations within the statutory framework.
Businesses should compare sector focus, language, admission criteria, fees, training and audit model. The guidance on gwg-info.ch identifies possible contacts but does not make a binding admission decision.
Contact the SRO early
Admission applications require information on the business model, responsible persons, policies and controls. The process should not be left until immediately before operations begin.
3. Identify the contracting party
Identification must use reliable documents. For individuals this normally means official identity documents. For legal entities, register extracts, constitutional documents, registered office, officers and representation rights are relevant.
- Record the contracting party and legal form.
- Verify identification documents.
- Establish representatives and signing authority.
- Understand the purpose and expected scope of the relationship.
- Resolve discrepancies before approval.
Systems should prevent services from starting before required checks are complete.
4. Identify beneficial owners and controlling persons
Identifying a company is not enough. The natural persons who ultimately control it or economically own contributed assets must be determined. Ownership, votes, contractual control, trusts and beneficiary rights may all matter.
Client declarations should be checked against organisational charts, registers, agreements and other evidence. Complex structures need a clear explanation in the file.
5. Risk assessment and enhanced due diligence
Each relationship needs a documented risk rating. Criteria may include countries, business activity, products, transaction volume, ownership complexity, political exposure and unusual payment routes.
| Risk level | Typical response |
|---|---|
| Standard | Standard identification, plausibility checks and regular updates |
| Higher | Additional evidence, enhanced source checks and senior approval |
| Unacceptable | Decline or terminate; assess reporting obligations where necessary |
Risk ratings must change when ownership, activity, transactions or negative information change.
6. Sanctions and other screening
Relevant persons and entities should be checked against applicable sanctions lists. Depending on the business model, PEP, adverse media and internal exclusion checks may also be appropriate.
- Record the date, source and search parameters.
- Investigate name similarities rather than dismissing them automatically.
- Escalate potential matches before performing the service.
- Repeat screening periodically or on defined events.
- Monitor legal and list changes.
7. Maintain a complete AML file
The file should permit independent review. It contains not only documents but also reasons, decisions and timing.
- Client master data and identity evidence.
- Representation and powers of attorney.
- Beneficial owners and control structure.
- Purpose and background of the relationship.
- Risk rating, screening and enhanced checks.
- Approvals, exceptions, escalations and decisions.
- Updates, self-declarations and correspondence.
Standard fields and deadlines reduce the risk of incomplete or disconnected information.
8. Ongoing monitoring and annual duties
The largest operational change is often repeatability. Information must be reviewed when changes occur and at defined intervals. Depending on the SRO and business model, annual risk reviews, self-declarations, submissions and audits may be required.
- Annual update of client and control data.
- Renewed risk assessment.
- Repeat relevant screening.
- Track expiring identity documents.
- Submit required information to the SRO.
- Prepare for and complete the annual audit.
Deadlines should be managed centrally rather than in personal calendars or isolated spreadsheets.
9. Suspicion and the MROS process
A reasonable suspicion of money laundering or terrorist financing can trigger a report to the Money Laundering Reporting Office Switzerland. Staff need a clear route for internal escalation and instructions on what must not be done while the case is assessed.
The procedure should cover fact collection, decision authority, legal review, confidentiality, documentation and follow-up measures.
10. Internal control and audit
Regular checks verify that procedures are followed in practice. Samples should cover onboarding, deadlines, risk ratings, sanctions screening and decision records.
Deficiencies need an owner, deadline and documented follow-up. Audit findings should drive improvements in processes, training and technology.
Frequently asked questions
Who can act as AML responsible person?
The person needs suitable expertise, sufficient authority and organisational access. The chosen SRO’s requirements must also be met.
Can the AML function be outsourced?
External support is possible for certain tasks, but responsibility and effective decision-making must remain with the business.
How often should client data be updated?
Immediately when relevant changes occur and additionally in the prescribed periodic cycle, often at least annually.
What does the annual audit cover?
The exact scope depends on law, SRO rules and risk, but normally includes organisation, files, risk, screening, deadlines and reporting procedures.