Company Brochure

AML/CFT Staff Training in the Isle of Man: What Code Para 32 Actually Requires

Compliance officer leading a small AML/CFT training session around a table in an Isle of Man office

Strengthen your compliance strategy

— with confidence. clarity. experts.

Book a
consultation

Code para 32 requires a relevant person to provide education and training, including refresher training, at least annually, to all officers, anyone in senior management, and appropriate employees and workers. It also requires ad-hoc top-up training within a reasonable timeframe whenever AML/CFT legislation or the firm's own policies and procedures change materially. A single induction session for new starters satisfies neither obligation.

In our experience, this is one of the most quietly under-resourced areas of an AML/CFT framework — not because firms disagree with the principle, but because training gets treated as a box-ticking formality rather than a control in its own right. It has a statutory rhythm, defined content, and a records requirement, and each of those three elements gets tested in a supervisory visit.

Isn't an induction session for new starters enough?

No. Para 32(1) sets a recurring obligation, not a one-time event: training, including refresher training, must be provided at least annually to everyone in scope. An induction covers a new starter's first exposure to your policies, but it does not discharge the annual refresher duty for that person the following year, and it says nothing about the rest of your existing staff, who need their own annual refresher regardless of how long they have been with the firm.

Para 32(3) adds a second, separate trigger. Where there have been significant changes to AML/CFT legislation, or to the relevant person's own policies and procedures, appropriate training must be provided within a reasonable timeframe — it does not wait for the next annual cycle. A change to your customer due diligence procedure in March does not sit quietly until the December refresher; it needs its own top-up training, delivered promptly enough that staff are working to current procedure rather than the version they were trained on last year. Firms that treat "annual training" as the whole of para 32 are missing half the requirement.

What must the training actually cover?

Para 32(2) is specific about content, and it is one of the few places in the Code where a tight list genuinely earns its place. Training given under para 32(1) must make staff aware of:

  • the provisions of the AML/CFT legislation itself, and any personal obligations arising from it;
  • the reporting procedures and controls established under Part 7, the recognition and handling of unusual and suspicious activity, and their personal liability for failing to report — including the offence of tipping off;
  • the relevant person's own policies, procedures and controls, and current techniques, methods and trends in money laundering and terrorist financing.

That last point matters more than it looks. Training that only recites the legislation, without walking staff through the firm's actual policies and procedures and how ML/FT typology is evolving, is not compliant training under para 32(2) — it is a legal-awareness briefing wearing a training label. The Handbook's guidance at §6.3 puts the underlying purpose plainly: effective application of AML/CFT/CPF policies and procedures depends on staff understanding both the requirements and the processes they are required to follow, and the risks those processes are designed to mitigate. Training that stops at "here is the law" without connecting it to "here is what you do when you see this" has not met that standard.

Compliance officer reviewing AML/CFT training records at a desk with a laptop and paper files

Who actually needs to be in scope?

Para 32(1) names three groups: all officers, anyone involved in senior management, and appropriate employees and workers. The Handbook's guidance is that firms should assess the risks posed by different roles to work out who falls into that third category — it is a risk-based judgement, not a headcount exercise, and it will vary by firm depending on which staff actually touch onboarding, transaction monitoring or client-facing decisions.

The senior management category deserves a second look too. A person can need training under para 32(1)(b) because of their involvement in senior management, regardless of what their day-to-day job title suggests — seniority in the governance sense, not the org chart sense, is what triggers the duty. And training is not meant to be delivered as a single script for everyone in scope: the Handbook's guidance is explicit that it should be risk-sensitive and tailored to role, with the MLRO and Deputy MLRO, where one is appointed, receiving more detailed training commensurate with the requirements, responsibilities and ML/FT/CPF risks that role carries. A junior administrator and the MLRO should not be sitting through an identical thirty-minute video.

Where a firm uses technology as part of its AML/CFT procedures and controls — screening tools, transaction-monitoring systems, automated CRA scoring — the Handbook's guidance under §6.3 is that staff need appropriate training on that technology specifically, including its benefits and its limitations. Rolling out a new screening tool without training staff on what it does and does not catch leaves a gap that no amount of general AML/CFT training closes.

How do you actually prove it happened?

Para 32(4) is a short paragraph carrying a lot of weight: the relevant person must maintain records which demonstrate compliance with the training obligation. In practice, that means records showing who was trained, when, on what content, and — ideally — evidence that attendees engaged with and understood the material, not just that an email invite went out. A calendar entry is not a training record. An attendance log tied to the actual content delivered, kept in a form you can retrieve months or years later, is.

This is the same evidentiary muscle we describe in the evidence behind your statistical return and BRA: what matters to a supervisor is not that you did the thing, but that you can prove you did it, in a form that survives scrutiny after the fact. Training records that live in one compliance officer's inbox, with no consistent format and no way of confirming who missed a session, will not hold up under the same pressure-test a BRA or CRA file would face.

Close-up of a training attendance record and policy document on an office desk

Common mistakes we see

The pattern we see most often is treating training as an event rather than a system: an induction pack for new joiners, no defined refresher cycle, and nothing triggered when policies change mid-year. A close second is generic content — a bought-in AML/CFT slide deck that never references the firm's own policies, procedures or risk profile, which fails the para 32(2) content requirement even if attendance is perfect. We also regularly see MLROs and Deputy MLROs sitting through the same session as general staff, with no additional depth reflecting the seniority of their obligations. And we see records kept loosely enough — a sign-in sheet, an unfiled email thread — that nobody could reconstruct, eighteen months later, exactly who was trained on exactly what.

Firms that are already reviewing their broader AML/CFT/CPF framework against the current Handbook tend to find training gaps surface at the same time — it is rarely an isolated weak point.

Frequently asked questions

Does every member of staff need the same AML/CFT training?

No. Para 32(1) covers officers, senior management and appropriate employees and workers, but the Handbook's guidance is clear that content should be tailored to role and risk. The MLRO and Deputy MLRO, where appointed, should receive more detailed training reflecting the requirements, responsibilities and risks of that role, and firms should assess which roles genuinely need to be treated as "appropriate employees and workers" rather than applying a single generic session to everyone.

What counts as a "significant change" that triggers para 32(3) training?

The Code does not define a fixed threshold, but a material amendment to AML/CFT legislation, or to the firm's own AML/CFT policies and procedures, is what triggers the obligation. The test is whether staff are now expected to work differently — a substantive change to a customer due diligence procedure or a reporting process is the kind of thing that needs a prompt top-up, delivered within a reasonable timeframe rather than folded into the next annual cycle.

Do we need to train staff on the systems and software we use for AML/CFT?

Yes, where technology forms part of your AML/CFT procedures and controls. The Handbook's guidance under §6.3 requires sufficient training on any technology used, covering both what it does well and where its limitations lie — not just how to click through the screens.

What records do we need to keep to demonstrate compliance?

Para 32(4) requires records demonstrating compliance with the training obligation as a whole. That means being able to show, for each training cycle, who attended, what content was covered, and when it took place — in a format you can retrieve and stand behind if a supervisor asks, not a scattered trail of calendar invites and unfiled emails.

Small group of colleagues in discussion during a compliance training session in an Isle of Man office

Annual and ad-hoc are not alternatives under para 32 — they are both running at once, and the records are what turn "we trained our staff" into something you can actually prove.

Knight Consultancy Limited
(Company No: 136669C)
Design House, Hills Meadow, Douglas,
Isle of Man ,IM1 5EB

© Knight Consultancy Limited {{Y}}. All Rights Reserved. Privacy Policy

Website and marketing partner: Yellowstone Accounts

Knight