In fact, many businesses have internal regulations on anti-money laundering. However, when the management agency checks, what they are interested in is not only whether the enterprise has a set of regulations but whether that regulation is really applied in daily business activities or only exists in archived records. The gap between "regulated" and "regulated operation" is the reason why many businesses are still being dealt with despite significant investment in compliance.

Such an internal regulation is difficult to promote.
A good rule is one for employees to implement
When asked to develop internal regulations on anti-money laundering, the first reaction of many businesses is to find an existing form of regulation or use the documents of the overseas parent company. This approach helps businesses quickly complete the dossier, but it also creates a major limitation: regulations are developed to meet legal requirements rather than to serve administrative activities.
It is not difficult to come across tens or even hundreds of pages of regulations, fully citing international laws and recommendations but not reflecting the actual business process of the enterprise. The person who directly deals with the customer does not know which terms to apply, the sales department cannot determine when additional due diligence is needed, and the compliance department is only mentioned when there is an inspection team.
Such an internal regulation is difficult to promote. Because, the goal of the law is not to force businesses to own a complete set of documents, but to require businesses to establish a mechanism capable of identifying, controlling and handling money laundering risks in the process of operation.
This also explains why the current trend of inspection no longer stops at checking the existence of internal regulations. Regulators are paying more and more attention to how businesses operate that system in practice. Whether employees are trained, how suspicious transactions are handled, whether customer identification is adequately implemented, and whether the business retains evidence of control activities are the deciding factors.
From a management perspective, an internal regulation only makes sense when it becomes the way the business handles its daily work. If employees do not understand the regulations, do not know how to apply them to each specific situation, or often try to ignore the control steps because they are too complicated, no matter how elaborate the regulations are, it is difficult to consider an effective anti-corruption program.
In other words, the quality of an internal regulation is not measured by the number of clauses or the thickness of the document, but by its ability to turn legal requirements into simple, clear and actionable processes in business operations.
An effective anti-money laundering system must start from the risk, not the process
Another common mistake is that businesses start building anti-money laundering systems by designing forms, customer identification processes, or suspicious transaction reporting processes. These are all important components of a compliance program, but not a starting point.
The 2022 Anti-money Laundering Law as well as the Recommendations of the Financial Action Task Force (FATF) are based on a risk-based approach. That means that before deciding how to control, businesses need to answer a more important question: Where is the risk of laundering your own money?
The answer will not be the same from business to business. A law firm specializing in M&A advice faces different risks than a gold business. A real estate broker will have a different risk profile than a business that provides accounting services. Even in the same industry, businesses serving domestic customers may also face a different level of risk than businesses that regularly carry out cross-border transactions or work with complex ownership structures.
Therefore, risk assessment needs to be placed at the center of the entire anti-corruption program. Businesses need to determine which customer groups have a higher level of risk, which types of transactions need to be monitored more closely, which products or services are easily exploited to hide the origin of assets, and which factors can increase the likelihood of suspicious transactions. Only when you understand those risks will you have a basis to design a customer identification process, build an internal approval mechanism, identify cases where it is necessary to strengthen due diligence, or decide on the appropriate level of control for each transaction group.
Conversely, if the business replicates an existing process and applies the same to all customers, the control system will quickly reveal its limitations. On the one hand, businesses have to devote too many resources to low-risk transactions. On the other hand, transactions that really need to be scrutinized are at risk of being missed because they weren't properly categorized in the first place.
It's also the difference between a formal compliance program and a true risk management system. The first program is built from existing forms and processes. The second program is designed from the business characteristics of the enterprise, then transformed into appropriate control processes.
An effective anti-money laundering system therefore does not start with the question "what processes do businesses need to promulgate", but starts with the question "what risks are businesses having to manage". Only when the first question is answered correctly can businesses build internal regulations that both meet the requirements of the law and are flexible enough to accompany business activities.
An anti-money laundering program is only effective when it becomes a "living system"
If risk assessment is the foundation, then the operation determines the quality of the entire anti-corruption program. This is also a point where many Vietnamese businesses are still weak.
Many businesses consider the issuance of internal regulations as the end point of the compliance process. In fact, that's just the beginning. A regulation, no matter how elaborately formulated, will quickly become obsolete if it is not regularly operated, checked and updated.
The most noticeable sign of an ineffective anti-money laundering program is that employees don't know what to do when an unusual situation arises. Who is responsible for deciding on suspicious transactions? When is enhanced due diligence needed? Which department is responsible for reporting? If these questions do not have clear answers, it is very difficult for businesses to prove that their control system is actually working.
Therefore, training should not be considered a procedural activity after the promulgation of regulations. This must be part of the governance system itself. What employees need is not to remember the provisions of the Anti-money Laundering Law 2022, but to understand the risks that may arise in their daily work and know how to handle those situations.
Along with people, technology is becoming an important tool to help businesses improve compliance efficiency. Solutions such as electronic identification, customer screening, beneficial owner identification, or transaction monitoring can help businesses detect risks faster and significantly reduce manual operations.
However, technology cannot replace administration. A system can detect hundreds of alerts a day and still fail if the business doesn't clearly define who evaluates the alerts, who has the power to make decisions, and what the next action process is. In contrast, many small and medium-sized enterprises can still build an effective anti-money laundering program even without investing in specialized software, as long as the process is reasonably designed and implemented consistently.
Another requirement that is often overlooked is the review and update of internal regulations. Many businesses only amend their regulations when the law changes, while the risk of money laundering fluctuates much faster. Businesses can open more industries, develop new products, expand to other markets or reach new customer groups. Each of those changes can significantly alter the risk profile and render previous controls irrelevant.
Therefore, an effective anti-corruption program must be considered as a "living system", constantly adjusted according to changes in business activities instead of only being updated according to the cycle of amendments of the law.

From a business perspective, this approach also brings more benefits.
Compliance is measured by effectiveness, not the number of documents
A notable change in state management activities is the way of evaluating the anti-money laundering work of enterprises. In the past, the inspection often focused on the question of whether the enterprise has issued internal regulations or not. Currently, the focus has shifted to assessing whether the system is operating effectively or not. This is also in line with international trends. FATF standards do not encourage businesses to develop increasingly complex sets of regulations but emphasize the effectiveness of the control system. An anti-corruption program is considered effective when the business can demonstrate that it has correctly identified risks, applied appropriate control measures, trained appropriate personnel, and promptly handled transactions with abnormal signs.
From a business perspective, this approach also brings more benefits. A risk-based system will help businesses use compliance resources appropriately, avoiding spreading controls over every customer and every transaction. At the same time, it is also easier for businesses to adapt when expanding operations, approaching foreign investors or participating in transactions with high compliance requirements.
More importantly, today's anti-money laundering program no longer exists independently. It is increasingly associated with corporate governance, personal data protection, risk management, internal control, and technology governance. For many international corporations, this has become a component of the overall governance system rather than an individual legal obligation.
Conclusion
For businesses subject to reporting under the Law on Anti-money Laundering 2022, the value of a compliance program does not lie in the thickness of the regulation or the number of forms issued. What is more important is that the program reflects the characteristics of the business's operations, is built on the basis of risk assessment, is understood and applied by employees in each transaction, and is regularly reviewed to adapt to changes in the business environment.
In the context of transparency and compliance requirements becoming increasingly important criteria in relations with regulatory agencies, banks, investment funds and international partners, internal regulations on anti-corruption are no longer a document to be kept in inspection records. It is a measure of the risk management capacity of the business. A properly designed, efficiently operated and continuously improved system will not only help businesses reduce the risk of sanctions, but also contribute to strengthening credibility, increasing access to capital and improving competitiveness in an increasingly compliance-oriented business environment.
