Test your skills, reveal your AML knowledge level, and grab a promo code!

Test now!
For Organizations

Corporate AML/CTF training for employees

Live AML/CTF training built around your products, your customers and your business-wide risk assessment, and cut separately for the first line, for compliance, and for internal audit.

Delivered online, on-site or hybrid. Every session closes with an evidence pack: training log, materials, assessment results and a management summary, filed within 3 working days. You won’t be reformatting any of it before it reaches your internal audit function.

Your MLRO keeps the training obligation — we supply the record that shows it was met.

Proven with teams worldwide

Role-based AML/CTF training for regulated teams, delivered under Estonian continuing-education licence 261779 and CPD Standards Office supplier number 50475. Every cohort leaves behind a training log, certificates and a management summary for the compliance file — the part most buyers care about six months later.
250+
Teams trained
Across banking, payments and EMIs, crypto and digital assets, insurance, gambling, BPO and public-sector investigations. Alumni in 79+ countries.
5,000+
Professionals trained
Since 2023, from onboarding staff and monitoring analysts through to MLROs and board members. Trained, which isn’t the same as certified. Certification is a separate, optional route.
Up to 29%
Lower annual training spend
Reported by partner organisations against comparable prior external or internal delivery, usually where one supplier replaced several. Results vary, and we don’t forecast yours.

Overall, we liked the structure and content a lot.

Mainly: there was an important terminology clarification highlighted and then repeated a few times so that it really stays with you. Moreover, there were practical examples added, a clear regulatory timeline presented and Kahoot was a great wrap up of the whole training session.

The number of real life examples was great and made the meaning of the topics very clear and relevant to bunq. Providing the latest updates on typologies and methods for financial crime was super interesting and great to see real world examples.

The bunq team

Packages

cpdOptional add-on: CPD accreditation for training sessions is available upon request. Live sessions are quoted per cohort — €3,295 covers up to 50 people — while catalogue certifications are priced per seat. Supplier onboarding forms, PO references and compliance documentation are supported on request. So a quote can go into your procurement workflow without a second round of questions.
1
One-off Training Package
3,295€
One live session for a single cohort — usually the first line, or a mixed group ahead of a supervisory inspection. Scoped against your business-wide risk assessment, delivered in up to 4 hours, and closed with the evidence pack. Fixed price, one invoice, and no seat count to reconcile afterwards.
pdfGet details
Package Featuresclose
  • Up to 4 hours of on-site, online, or hybrid training
  • Delivered by industry experts
  • Includes discussions, Q&A sessions, and practical exercises
  • Certificate of completion issued
  • Best for teams of up to 50 people
  • Evidence pack delivered within 3 working days of the session
3
Corporate Training Program
Request pricing
For groups running AML training across several entities or jurisdictions. Quarterly live sessions, catalogue seats for nominated staff, and API or SCORM integration so completion data lands in your own LMS rather than in a spreadsheet somebody maintains by hand. One supplier, one documentation standard, one line in the budget.
pdfGet details
Package Featuresclose
  • Quarterly on-site, online, or hybrid sessions
  • All features included in previous packages
  • Enrol up to 50 employees in AML Foundations (€399 per seat on the catalogue);
  • Enrol more than 10 team members in CASS, the specialist-level certification (€959 per seat);
  • Add customised e-learning modules from the content library, mapped to your own policies and procedures
  • Integrations available – through API, SCORM or other custom options
  • Best for organisations of 5000+ employees
  • Corporate Training Portal access with one-click audit export

Role, jurisdiction and evidence: the three things an inspection tests

HMRC’s supervision handbook tells its officers to ask whether a firm’s training is “one size fits all or tailored to specific roles”, and whether there is a training log showing who completed it and when. Those two questions set how every session here is built and documented. So the structure below isn’t a marketing frame; it’s the shape of the questions.
Sector and role-specific
Content is cut by role, because a customer onboarding officer and an MLRO don’t need the same session.

• Onboarding and first line: CDD, red flags, escalation routes
• Transaction monitoring: alert triage, typologies, documenting a disposition
• Sanctions and PEP screening: match assessment, false positives, escalation
• MLRO, deputy MLRO and compliance officers: SAR/STR quality, governance, supervisory expectations
• Board and senior management: oversight, risk appetite, accountability
• Internal audit: testing control design against the business-wide risk assessment

Scenarios come from your own products and customer base, not from a generic case bank.
Jurisdiction-aligned
The training obligation isn’t the same in every jurisdiction, so we map it before anyone writes a slide.

• EU: Article 12 of Regulation (EU) 2024/1624 (AMLR) requires ongoing training appropriate to the role and to the entity’s risks, and duly documented. It applies from 10 July 2027, alongside AMLD6, Directive (EU) 2024/1640
• UK: regulation 24 of the Money Laundering Regulations 2017 requires relevant employees and agents to be regularly trained, and a written record to be kept
• Sector overlays where they bite, MiCA for crypto-asset service providers being the common one
• Scope and jurisdictions are confirmed on the scoping call

And the obligation stays with you — we supply the training and the record, not the compliance.
Audit evidence pack included
One pack, delivered within 3 working days, answering the questions an inspection actually puts.

• Training log: who attended, on what date, for how long
• Agenda and the materials used, so a reviewer can see what was covered
• Assessment and knowledge-check results where you opt in
• Certificates of completion, publicly verifiable and co-brandable with your identity
• Management summary with themes observed and recommended follow-up
• CPD documentation on request, under CPD Standards Office supplier number 50475

That’s the file your internal audit function pulls, and the one you hand a supervisor. None of it has to be reformatted first.
Corporate Training Portal
Completion data lives in one place instead of in three inboxes and a spreadsheet.

• Live view of who has completed what, per cohort and per person
• One-click export of the training log, certification log and management summary, timestamped and branded
• Certificates issued automatically once attendance is confirmed, each independently verifiable
• Follow-up flags for the people who registered but haven’t finished
• API or SCORM integration where the record has to sit in your own LMS

So ask for a walkthrough before you buy. If the reporting doesn’t answer the questions your auditor asks, that’s worth knowing at the demo rather than at the review.

Coverage across all three lines of defence

Training depth is set by line, not by headcount. Structured in accordance with ISO 37301, and delivered so each line can evidence what its own people were taught rather than pointing at a single all-staff deck.
1st line
Operations. Customer onboarding, payments and service staff: red flags in the products they actually handle, when to escalate, and how to write an escalation the second line can act on.
2nd line
Compliance. The MLRO, deputy MLRO and compliance officers: transaction monitoring logic, sanctions and PEP screening decisions, SAR/STR quality, and record keeping.
3rd line
Internal audit. Testing whether the programme works as written: control design against the business-wide risk assessment, training coverage, and the gaps a supervisory inspection finds first.

How corporate training works — step by step

Six steps, each with a time attached, so procurement can put a date in a contract and compliance can put one in the training plan. Nothing here waits on a scheduling email. And where a step depends on you — nominating experts, confirming jurisdictions, approving the agenda — it says so rather than leaving it implied.
1
Scoping call
30 minutes. We confirm roles and lines of defence, operating jurisdictions, cohort size, delivery format, and what the outcome has to prove. Bring your business-wide risk assessment if you want the scenarios drawn from it.
2
Plan sign‑off
At least 2 weeks before training. Dates, nominated experts, delivery format and the final agenda are signed off in writing. That signed agenda is what goes into the evidence pack later, so it’s worth having the MLRO read it rather than only the training coordinator.
3
Materials prepared
Prepared within 10 working days of sign-off. Scenarios and exercises are written against your products, customer base and risk profile. Where you share internal policies or a redacted case, they go into the material and the session stops being generic.
4
Live delivery & assessment
2-4 hours. Instructor-led session online, on-site or hybrid, followed by the assessment where you’ve opted into one. Cohorts run to 50; larger populations split by role rather than by calendar.
5
Evidence pack & recording
Delivered within 3 working days. Training log, materials, assessment results where used, management summary and the recording link. One file, ready for internal audit or a supervisory inspection without reformatting.
6
Completion tracking & certificates
Real-time: automatic. Non-attendees are tracked through recording viewing and assessment completion, and certificates are issued once passed. So turnover between booking and delivery doesn’t leave a hole in the record.

Certification pathways for teams

Live sessions move the whole function. Catalogue certifications go deeper for the people who need it in writing: AML Foundations €399, five sector verticals at €499 each — banking, EMIs, VASPs, gambling and iGaming, funds and trading — then CASS €959 at specialist level and CAPS €1,695 at Principal Specialist level, which ships in six jurisdiction-scoped CASP versions. So buy seats when you need a named individual credentialled. Book a cohort when the whole team has to move at once.

Seven sector programmes: pick the one your licence is written against

Every sector below has its own page, its own typologies and its own set of things a supervisor asks about. Start there rather than here. The sector page tells you which roles need which content, what the programme covers, and how the training obligation reads inside that regulatory perimeter. But if you straddle two — a payments firm with a crypto arm is the usual case — take the one your licence is written against and raise the rest at scoping.
Crypto & Digital Assets
VASPs, exchanges and wallet providers. Blockchain analytics and wallet monitoring, DeFi exposure, mixing and tumbling services, and the sanctions and PEP screening that on-chain activity makes harder rather than easier. Crypto and digital assets programme.
Fintech & Payments
Payment institutions, PSPs and EMIs. Source of funds and source of wealth, third-party due diligence, PSD2 and PSD3 obligations, the Travel Rule under FATF Recommendation 16, and agent and distributor oversight under the EU AMLR. Fintech and payments programme.
Banking & Financial Institutions
Retail, corporate and private banking, plus trade finance and correspondent relationships. Trade-based money laundering, beneficial ownership in complex structures, source of funds and wealth verification, and correspondent de-risking decisions. Banking programme.
Insurance
Life and general insurers and insurance brokers. Early policy surrender as a risk indicator, policy transfer and ownership-change red flags, unusual premium payment patterns, and monitoring across the policy lifecycle. Insurance programme.
Gambling & Gaming
Online casinos, sportsbooks and land-based operators. Player risk assessment, enhanced due diligence for high-risk players, structuring of bets and suspicious betting patterns, rapid deposits and withdrawals, and cross-border exposure. Gambling and gaming programme.
BPO & Outsourcing
Outsourced KYC, onboarding and transaction monitoring teams working to a client’s policy rather than their own. Alert disposition decisions, governance over outsourced functions, and what clients and their supervisors look for in an outsourced control. BPO and outsourcing programme.
Law Enforcement & Investigations
FIUs, investigators and financial intelligence analysts. The FIAR route runs seven modules across typologies, early detection and asset freezing, seizure and asset management, investigative technique, court procedure and confiscation, and case building. FIAR certification.
Request a corporate quote
Tell us the sector, the cohort size and the jurisdictions, and you get a scoped quote back rather than a qualifying call.

Frequently
Asked
Questions

about corporate AML training, pricing and evidence

Do you tailor training to our jurisdiction and sector?

Yes, and the tailoring starts before an agenda exists. On the scoping call we take your operating jurisdictions, licence type, products and business-wide risk assessment, then build the scenarios out of them. The regulatory layer is set to the rules you actually operate under: the EU AMLR from 10 July 2027, the UK Money Laundering Regulations 2017, or your local framework. But method stays constant across cohorts, so standards don’t drift between one team and the next.

How long should a session be?

Half a day, around 4 hours, covers one cohort properly. Much below three hours and you get awareness rather than applied judgement, which isn’t what an inspection tests. We split delivery into shorter blocks where shift patterns or time zones require it, and two two-hour sessions is common for teams spread across Europe and Asia. Board and senior-management briefings run shorter, because that content is oversight rather than procedure. We agree the length at scoping.

Can you train different teams on different content?

Yes, and for most organisations it’s the right structure. Onboarding and first-line staff work through CDD, red flags and escalation. Transaction monitoring teams work alert triage, typologies and how to document a disposition. The MLRO, deputy MLRO and compliance officers get SAR/STR quality, governance and supervisory expectations. Internal audit gets control testing. Same supplier, same documentation standard, different rooms. And that is the split HMRC’s supervision handbook probes when it asks whether training is one size fits all.

Do we get a recording of the session?

Usually, though it depends on delivery format and your own policies. Some organisations don’t permit recording where live cases are discussed, and that’s a reasonable position. Where recording is agreed, the link reaches you within 3 working days of the session, and non-attendees are then tracked through recording viewing and assessment completion rather than simply marked absent. So we settle the position at scoping, and nobody discovers a restriction on the day.

What exactly is in the evidence pack?

One pack, within 3 working days. It holds the training log (who attended, on what date, for how long), the agenda and materials used, assessment and knowledge-check results where you opted in, certificates of completion, and a management summary with themes observed and recommended follow-up. CPD documentation is added on request under CPD Standards Office supplier number 50475. The Corporate Training Portal shows the same data live, with a one-click export. It’s built to be filed as received, not reformatted first.

Do you include assessments, and do the results reach us?

Knowledge checks and applied scenarios are optional, and we push for them, because a completion record without a comprehension check answers only half the question a reviewer asks. Results land in the evidence pack. Where your internal policy requires staff to sign a confirmation of understanding, the assessment can be aligned to it. And HMRC officers are told to ask whether staff sign anything confirming their obligations, so the two records end up working together.

How many people can be in one cohort?

Fifty is the ceiling for a single live session, and the discussion is better nearer 20 to 30. Larger populations run as multiple cohorts, which also lets you split by role rather than by calendar. The €3,295 one-off package covers a cohort of up to 50, so splitting cohorts affects your scheduling more than it affects your budget. We’ll recommend a split at scoping if the mix of roles in one room looks too wide to teach well.

Which languages can you deliver in?

English and Spanish are the standing delivery languages. Other languages are available subject to trainer availability, so raise the requirement in the first request rather than after plan sign-off. Language is one of the few variables that can genuinely move a delivery date, and finding that out two weeks before the session helps nobody. Materials and the evidence pack follow the language of delivery.

How does pricing work for a team, per seat or per session?

Both, depending on what you buy. Live sessions are priced per cohort rather than per seat: €3,295 for a one-off session covering up to 50 people. Flex and Corporate Training Programme pricing depends on cadence, cohort count, tailoring and jurisdictions, and is quoted after scoping. Catalogue certifications are priced per seat: AML Foundations €399, the sector verticals €499, CASS €959, CAPS €1,695. So most organisations end up with a mix of both, and that’s usually the cheaper answer.

Can you work with our procurement, purchase orders and invoicing?

We work to your process rather than ours. Supplier onboarding forms, PO references and compliance documentation are supported, so flag them in the first request and they get handled alongside scoping instead of after it. The quote is fixed before scoping work begins, which means what procurement approves is what gets invoiced.

What do participants receive at the end?

A Certificate of Completion for everyone who finishes the training. Trained, which isn’t the same as certified: certification is a separate route through the catalogue, and we’re deliberate about the difference. Certificates are publicly verifiable, so a supervisor, an auditor or a counterparty can check one independently rather than taking your word for it. They can also be co-branded with your organisation’s logo and visual identity.

Does this satisfy our supervisor’s staff-training requirement?

That call is yours, and we won’t pretend otherwise. No regulator approves, endorses or mandates this training. What we can set out is what the requirement asks for. Article 12 of the EU AMLR requires training that is ongoing, appropriate to the role and to the entity’s risks, and duly documented. UK regulation 24 requires relevant employees and agents to be regularly trained, with a written record kept. The programme is designed against those tests and the evidence pack is the record. But your MLRO signs off that it fits your risk assessment.

Which of the seven sector programmes should we start from?

Take the one your licence is written against. Banks and financial institutions, banking. Payment institutions, PSPs and EMIs, fintech and payments. VASPs and digital asset platforms, crypto and digital assets. Insurers and brokers, insurance. Operators, gambling and gaming. Outsourced KYC and monitoring providers, BPO. FIUs and investigators, FIAR. And where two apply, pick the licensed one, then raise the other at scoping.

How quickly can training start?

The binding constraint is preparation, not trainer availability. Plan sign-off happens at least two weeks before delivery, and tailored materials are built within 10 working days of that sign-off. So roughly four weeks from scoping call to a delivered tailored session. Where you need it sooner — an inspection date already in the diary, a finding to close — say so at scoping and we’ll tell you what can be compressed and what can’t. Catalogue seats, by contrast, are self-serve and don’t wait on us at all.

What happens when staff join, leave or change roles?

Turnover is the usual reason a training log fails a review. The record covers whoever was in the room in March, not the analyst who started in July. Non-attendees and late starters are tracked through recording viewing and assessment completion, so the gap closes without waiting for the next cohort. And for continuous intake, the Flex and Corporate Training Programme cadences exist precisely so a new joiner meets a scheduled session rather than an improvised one.

Can we mix corporate sessions with self-serve seats?

Yes, and for most teams it’s the cheaper structure. Live cohorts move the whole function; catalogue seats credential the individuals who need it on paper. AML Foundations is €399 per seat, the five sector verticals — banking, EMIs, VASPs, gambling and iGaming, funds and trading — are €499, CASS is €959 at specialist level, and CAPS is €1,695 at Principal Specialist level with six jurisdiction-scoped CASP versions. Completion for either route shows in the same portal view, so the audit record stays in one place.

Do you train MLROs and the board, or only frontline staff?

Both, and separately. Frontline sessions are procedural: recognise, escalate, document. MLRO and deputy MLRO sessions go to SAR/STR quality, monitoring model assumptions, sanctions and PEP screening decisions, and what a supervisory inspection tests. Board and senior-management briefings are oversight: risk appetite, programme health, and where accountability sits when a control fails. Running all three in one room is the most common mistake we see, and it produces a training log that satisfies nobody.