Standard purpose

ISO 37013 Guidelines for managing money laundering and terrorist financing risks offers a principles-based framework for organizations to identify and manage their exposure to financial crime risks stemming from predicate offenses, including environmental, social and governance violations.
The standard helps organizations protect themselves from exploitation by illicit financial flows while building trusted relationships with obliged and non-obliged entities through transparent, and risk-based practices.
This is a guidelines document (Type B standard) designed for voluntary adoption with flexible, scalable implementation proportionate to organizational size, sector and risk profile.

What is ISO 37013?

The ISO 37013 project provides guidelines for managing money laundering and terrorist financing (AML/CTF) risks in any organization, particularly those that are not subject to mandatory AML/CTF obligations and may be exposed to or exploited by illicit financial flows.

Using a principles-based, risk-based approach, the standard helps organizations understand their exposure to financial crime risks, including those linked to ESG-related predicate offenses such as environmental crimes (illegal wildlife trade, ecocide), social crimes (human trafficking), and governance crimes (corruption, tax fraud).

While primarily designed for non-obliged entities, ISO 37013 can also be applied by obliged entities (regulated financial institutions) as a benchmark tool to assess their own AML/CTF frameworks and evaluate counterpartie’s risk management practices across any jurisdiction—creating a common baseline for global business development.

ISO 37013 complements existing ISO management system standards (ISO 37001–anti-bribery, ISO 37301–compliance management, ISO 37000–governance) and aligns with key landmarks such as FATF Recommendations and relevant regional or national frameworks, creating a new pillar in the ISO/TC 309 architecture for financial crime prevention.

Benefits

For non-obliged organizations

ISO 37013 provides any size organization—including SMEs, NGOs, foundations, listed or privately owned companies, state-owned companies and public institutions—with a scalable, risk-based framework that builds trust with obliged and non-obliged entities, and reduces exploitation risks.

The standard offers practical tools that integrate seamlessly with existing ISO management systems (37001, 37301, 37000), enabling proportionate implementation adapted to organizational size and complexity.

 

For obliged entities

ISO 37013 can be leveraged as a benchmarking tool to evaluate their own AML/CTF frameworks against international best practices. The standard enables consistent cross-border assessment of counterparties operating under different regulatory regimes, creating a universal baseline that streamlines due diligence processes and facilitates global business expansion through shared evaluation criteria.

FAQ

1. Is ISO 37013 mandatory for my organization?

No. ISO 37013 is a voluntary guidelines document designed primarily for organizations that are NOT subject to mandatory AML/CTF obligations under national or international law. It provides a framework for voluntary adoption of AML/CTF risk management practices proportionate to your organization's size, sector and exposure.

However, obliged entities (banks, financial institutions, regulated professionals) can also voluntarily adopt ISO 37013 as a benchmarking and assessment tool to evaluate their own practices and streamline due diligence on counterparties across different jurisdictions.

 


 

2. How does ISO 37013 differ from legal AML obligations and other ISO standards?

ISO 37013 specifically targets non-obliged entities—organizations not legally required to comply with AML/CTF regulations. While regulated entities follow strict legal obligations, ISO 37013 provides proportionate, risk-based guidance for:

  • Non-obliged entities seeking to demonstrate their integrity and vigilance
  • NGOs operating in high-risk contexts
  • Public institutions managing third-party relationships

For obliged entities, ISO 37013 serves as a complementary tool to:

  • Assess their own AML/CTF systems against international best practices
  • Evaluate counterpartie’s risk management practices regardless of jurisdiction
  • Create a common baseline for global business relationships

It complements (rather than duplicates) ISO 37001 (anti-bribery) and ISO 37301 (compliance management systems) by addressing money laundering and terrorist financing risks, creating an integrated approach to financial crime prevention.

This universal approach helps create a level playing field for global business development, regardless of differences in AML/CTF regulatory regimes.

 

WG14 Leadership

The Project is led by. Prof. Oserheimen OSUNBOR (Nigeria) as Covenor.

The Project Leaders are Duncan JEPSON (UK), Min CAI  (China) and André JACQUEMET (France)

Secretariat is held jointly by UK and Nigeria. Please contact either David Adamson or John Bature - [email protected] and [email protected]