Most enterprise vendor due diligence programs are built around three checks: verify the entity is real, screen its name against sanctions and watchlists, and trace who ultimately owns it. Those checks matter, and a vendor that fails any of them should never be onboarded. But passing all three tells you almost nothing about a separate and increasingly scrutinized risk: whether the payment relationship itself could be used to move or disguise illicit funds. Money laundering does not require a sanctioned party or a fraudulently registered shell company. It requires a plausible-looking commercial relationship through which value can move — and a routine vendor invoice, paid on ordinary payment terms, is exactly that.
Anti-money laundering (AML) vendor due diligence is the discipline built to close that specific gap. It asks a different question than identity verification or sanctions screening: does the structure of transactions with this vendor — the pricing, the payment pattern, the jurisdictions involved, the consistency of invoicing — create a channel that could be exploited to launder proceeds, whether the vendor itself is a willing participant or an unwitting conduit. This article is written for CFOs, financial crime and compliance teams, internal audit, procurement, and enterprise risk functions — particularly in banking and financial services, but increasingly relevant to any global enterprise whose vendor payment volume has grown faster than its financial-crime controls.
See how a unified governance approach connects entity verification, ownership tracing, sanctions screening, and transaction-level risk monitoring into one defensible program, inside Crest.Digital's end-to-end vendor risk governance framework.
See the Governance FrameworkThe AML Gap Sanctions Screening and Identity Checks Leave Open
Sanctions screening is a name-matching exercise, not a transaction-risk assessment. It checks a vendor's registered name, its directors, and its beneficial owners against government and international watchlists, and it is an essential control — Crest.Digital's guide to vendor sanctions compliance covers that discipline in depth. But a vendor with zero sanctions exposure, a fully verified legal entity, and a clean ownership structure can still present significant money-laundering risk if the payments flowing to it are structured to move value rather than to compensate for goods or services genuinely delivered.
AML due diligence is also distinct from beneficial ownership verification, which asks who controls a vendor, not how money moves through it. Crest.Digital's guide to beneficial ownership verification covers tracing ownership through layered holding structures to identify the real economic beneficiary — a critical input into AML risk-tiering, since opaque ownership is itself a laundering red flag, but not a substitute for evaluating the transaction pattern itself. A vendor can have fully disclosed, entirely legitimate ownership and still be used as a laundering conduit if nobody is watching what the invoices actually say.
This is the layer of due diligence that sits underneath the checks most programs already run. Sanctions, ownership, and entity identity verification (covered in Crest.Digital's guide to Know Your Business verification) confirm the vendor is who it claims to be and is not a prohibited party. AML vendor due diligence asks whether the ongoing financial relationship with that verified, unsanctioned, transparently owned vendor could still be exploited — a question that requires looking at transaction patterns and payment structures, not just names and registries.
Why AML Vendor Due Diligence Is a Growing Compliance Expectation
The regulatory architecture for anti-money laundering has historically focused on financial institutions screening their own customers. That focus is widening. The U.S. Financial Crimes Enforcement Network's Customer Due Diligence Rule requires covered institutions to understand the nature and purpose of customer relationships well enough to detect suspicious activity — a standard that extends naturally to any counterparty relationship carrying payment flow, including vendors positioned to move money on an institution's behalf or through its accounts payable function. In the United Kingdom, the Financial Conduct Authority has repeatedly flagged third-party and outsourced payment relationships as a channel financial crime controls must extend to, not an exception to them.
The Financial Action Task Force's standards on customer due diligence and beneficial ownership set the international baseline that national AML regimes build from, and its guidance on trade-based money laundering specifically identifies invoice manipulation and complicit or negligent trade intermediaries as a persistent enforcement gap — precisely the scenario standard vendor screening does not test for. The European Union's Anti-Money Laundering Directives, enforced through national regulators and coordinated via the European Commission, extend similar due diligence obligations to designated non-financial businesses and professions with material payment exposure to third parties.
Advisory practice reflects the same shift. Deloitte's financial crime advisory work has flagged vendor and supply-chain payment channels as an underexamined laundering vector relative to the scrutiny applied to direct customer relationships, and ISACA's assurance guidance treats transaction-pattern monitoring — not just static screening at onboarding — as a baseline expectation for any control claiming to manage financial-crime risk. For enterprise risk, internal audit, and compliance functions, the practical implication is that a vendor program built entirely on onboarding-stage sanctions and identity checks cannot claim to manage money-laundering risk, regardless of how thorough those onboarding checks are.
The 8-Capability AML Vendor Due Diligence Framework
Building a defensible AML vendor due diligence program requires more than screening names against watchlists at onboarding. These eight capabilities determine whether the resulting picture of laundering risk is complete, current, and defensible under regulatory or internal audit review.
AML Risk Tiering at Onboarding
Scoring vendors by jurisdiction risk, sector exposure, payment structure, and expected transaction volume to determine how much ongoing AML scrutiny each relationship warrants.
Sanctions, PEP & Adverse Media Screening
Treating name-based screening as one input feeding a broader AML risk profile, not a standalone check that closes the file once it clears.
Trade-Based Money Laundering Detection
Comparing invoice pricing, volumes, and billing patterns against market benchmarks and historical norms to flag over-invoicing, under-invoicing, or phantom billing.
Payment-Structuring Detection
Flagging transactions split into amounts just below regulatory reporting or internal approval thresholds, including patterns repeated across related vendors.
High-Risk Jurisdiction & Correspondent Exposure Mapping
Identifying vendors whose payment routing, banking relationships, or beneficial ownership touch jurisdictions associated with elevated laundering risk.
Beneficial Ownership Layering Checks
Feeding ownership-chain findings into AML risk scoring, since opaque or layered ownership structures are themselves a recognized laundering indicator.
Continuous Transaction Pattern Monitoring
Watching payment behavior against expected norms on an ongoing basis rather than screening once at onboarding and treating the file as closed.
Audit-Ready, Investigation-Ready Evidence Trail
Documenting every screening result, anomaly finding, and investigation outcome in a form that supports regulatory examination or suspicious activity reporting.
The third and seventh capabilities — trade-based laundering detection and continuous transaction monitoring — are where most vendor programs stop short in practice, because comparing every vendor invoice against market and historical benchmarks, and sustaining that comparison across the full payment lifecycle rather than at a single onboarding moment, is not something a periodic screening cycle can deliver. Crest.Digital runs AML-relevant screening, ownership tracing, and continuous monitoring as one connected workflow inside the same platform used for the rest of the vendor lifecycle — backed by managed-services capacity from former Big4 risk professionals for the investigative judgment a flagged anomaly alone can't resolve.
Crest.Digital connects sanctions and ownership screening, trade-based laundering detection, and continuous transaction monitoring into one auditable AML workflow — with the managed-services capacity to investigate what the system flags.
Building an AML Vendor Due Diligence Program: A Playbook
Extending vendor due diligence to cover money-laundering risk works best as a structured build layered on top of existing identity and sanctions checks, not a parallel process that duplicates them.
AML Vendor Due Diligence — Build Checklist
- Establish Risk-Tiering Criteria: Score vendors on jurisdiction, sector, payment structure, and volume to set the depth of AML review required.
- Integrate Sanctions and PEP Screening: Feed name-based screening results into a broader AML risk profile rather than closing the file once cleared.
- Build Trade-Based Laundering Detection: Compare invoice pricing and volumes against market and historical benchmarks to flag anomalies.
- Set Payment-Structuring Alerts: Flag transactions split to stay under reporting or approval thresholds, including patterns across related vendors.
- Map High-Risk Jurisdiction Exposure: Identify vendors whose payment routing or ownership touches higher-risk jurisdictions.
- Document the Evidence Trail: Retain screening, anomaly, and investigation records in a form that supports regulatory review.
This build sequence extends directly from the identity and screening foundation covered in Crest.Digital's guides to vendor sanctions compliance and beneficial ownership verification — this article's AML framework is the transaction-risk layer that should sit alongside both, not replace either. It also connects to the broader due diligence foundation in Crest.Digital's guide to what is vendor due diligence.
Where Agentic AI Fits in AML Vendor Due Diligence
Correlating sanctions results, invoice-pricing anomalies, payment-structuring patterns, and jurisdiction exposure across an entire vendor base — and doing it continuously rather than at a single onboarding checkpoint — is exactly the kind of high-volume, cross-signal analysis that scales poorly as a manual process and is well suited to AI-driven orchestration, provided the system knows where to stop and hand judgment back to a human investigator.
AI-Assisted Transaction Pattern Analysis
Rather than a compliance analyst manually sampling invoices for review, an AI-assisted workflow can continuously compare every vendor invoice against category and historical pricing benchmarks, flag payment sequences consistent with structuring, and surface each anomaly with the specific data points that triggered it — turning a check that would otherwise rely on periodic sampling into continuous, full-population coverage.
Agentic Orchestration Across Screening, Monitoring, and Escalation
The higher-value capability is orchestration across the full sequence: running sanctions and ownership screening, correlating it with transaction-pattern findings, checking jurisdiction and correspondent exposure, and re-triggering the entire assessment automatically when a vendor's payment instructions or transaction profile changes — connected as one workflow rather than disconnected manual reviews. This is the core of Crest.Digital's agentic AI layer applied to AML vendor due diligence: the system plans and executes the assessment sequence, and escalates only what warrants human investigation.
Human-in-the-Loop Governance
No defensible AML program should treat a flagged anomaly as confirmed wrongdoing without investigation — a pricing deviation might reflect a legitimate volume discount, and a payment-instruction change might reflect a routine banking update. The right design routes every credible finding to a trained investigator while letting AI handle the exhaustive, continuous cross-referencing underneath it, producing the kind of measurable impact that comes from compressing detection time without compressing the judgment applied to what detection turns up.
Frequently Asked Questions
AML (anti-money laundering) vendor due diligence is the practice of assessing a vendor relationship for the risk that it could be used, knowingly or not, to move or disguise illicit funds — through structured payments, trade-based invoicing schemes, or exposure to high-risk jurisdictions and correspondent relationships. Know Your Customer (KYC) and its business-entity counterpart, Know Your Business (KYB), verify who the vendor is — its registration, its directors, its identity. AML due diligence goes further and asks a different question: even if the vendor's identity is genuine, does the structure of payments and transactions with this vendor create a plausible path for laundering illicit proceeds. A vendor can pass identity verification cleanly and still present unaddressed AML risk if the payment relationship itself has red flags.
Sanctions screening checks a vendor's name, its directors, and its beneficial owners against government and international watchlists — a name-matching exercise that flags a very specific category of prohibited counterparty. AML vendor due diligence is broader: it evaluates the transaction and payment relationship itself for laundering risk, independent of whether any party involved appears on a sanctions list. A vendor with no sanctions exposure at all can still present AML risk through trade-based money laundering (over- or under-invoicing to move value across borders), payment structuring (splitting transactions to stay under reporting thresholds), or routing funds through high-risk jurisdictions and shell layers. Sanctions screening is one input into a complete AML due diligence program, not a substitute for it.
Trade-based money laundering (TBML) is the practice of disguising the movement of illicit funds within the pricing, quantity, or quality of a legitimate trade transaction — for example, a vendor invoice priced well above or below fair market value, phantom shipments billed with no corresponding goods, or the same goods invoiced multiple times across a chain of related entities. Because a vendor invoice is a routine, everyday document, TBML schemes can move significant value through an enterprise's own accounts payable function without ever triggering a sanctions or identity check, since none of the entities involved need to be sanctioned or fraudulently registered for the scheme to work. Detecting it requires comparing invoiced pricing and volumes against market benchmarks and historical patterns for that vendor and category, not just verifying the vendor's identity and screening its name.
Common AML red flags in vendor relationships include: invoice pricing that deviates significantly from market benchmarks for the same goods or services; payments split into multiple transactions just below a regulatory reporting or internal approval threshold; a vendor requesting payment to a bank account in a jurisdiction unrelated to its registered address or the location where services are delivered; frequent changes to payment or banking instructions with limited business justification; a vendor operating through a chain of related shell entities with no clear operational substance; and transaction volumes or values inconsistent with the vendor's apparent size, headcount, or filing history. None of these are visible from an identity check alone — they surface only when payment patterns and invoicing data are actively monitored against expected norms.
AML vendor due diligence depends on continuously correlating signals across sanctions and PEP screening, invoice and pricing pattern analysis, payment-structuring detection, and jurisdiction-risk mapping — a volume and complexity of cross-referencing that scales poorly as a manual, periodic review. Agentic AI can orchestrate this end to end: running continuous transaction pattern analysis against vendor and category baselines, flagging invoice or payment anomalies consistent with trade-based laundering or structuring, re-screening exposure whenever a vendor's payment instructions or jurisdiction profile changes, and escalating only the findings that cross a materiality threshold to a human investigator. This keeps AML vendor due diligence connected to the same orchestrated, human-in-the-loop workflow used elsewhere across onboarding, sanctions screening, and continuous monitoring, rather than treating it as an isolated, point-in-time review.