The United Kingdom maintains one of the most developed and actively enforced anti-money laundering frameworks in the world. Businesses operating in regulated sectors face detailed obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations, commonly called the MLRs, as well as the Proceeds of Crime Act 2002. Understanding AML and KYC in United Kingdom is essential for any firm that handles client funds, provides professional services or operates in financial markets. This guide covers the legal framework, who it applies to, what compliance requires in practice, recent regulatory updates, and the consequences of getting it wrong.
The legal framework governing AML and KYC in United Kingdom
The UK';s AML regime rests on several interlocking pieces of legislation. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations, as amended, are the primary instrument for regulated firms. They implement the Financial Action Task Force recommendations and successive EU directives that the UK chose to retain and develop after its departure from the European Union. The Proceeds of Crime Act 2002 creates the underlying criminal offences, including the offences of money laundering, failure to disclose and tipping off. The Terrorism Act 2000 adds a parallel layer for terrorist financing.
The Financial Conduct Authority is the principal supervisor for financial services firms, including banks, payment institutions, e-money firms, investment managers and consumer credit providers. HM Revenue and Customs supervises a wide range of non-financial businesses, including money service businesses, high-value dealers, accountants, estate agents and trust or company service providers. The Solicitors Regulation Authority and other professional body supervisors oversee legal professionals. The Office for Professional Body Anti-Money Laundering Supervision, known as OPBAS, sits within the FCA and monitors the professional body supervisors to ensure consistency.
Each supervisor has the power to inspect firms, require information, impose civil penalties and refer cases for criminal prosecution. The FCA publishes its enforcement decisions and has issued substantial fines in recent years. HMRC has similarly increased its inspection activity across the sectors it supervises.
Who must comply: the scope of regulated activity
The MLRs apply to a defined list of regulated sectors. Any business that falls within these categories must register with or be authorised by the relevant supervisor before conducting regulated activity. Operating without registration is itself a criminal offence.
The main categories of regulated persons include:
- Credit institutions and financial institutions, including banks, building societies, payment service providers and e-money issuers.
- Auditors, insolvency practitioners, external accountants and tax advisers.
- Independent legal professionals when they engage in certain financial or real estate transactions.
- Trust or company service providers, including registered agents and company formation agents.
- Estate agents and letting agents meeting a rental threshold.
- High-value dealers accepting cash payments above a specified threshold.
- Cryptoasset exchange providers and custodian wallet providers registered with the FCA under the MLRs.
A common mistake made by foreign founders setting up UK operations is assuming that because their parent entity is regulated abroad, the UK subsidiary is automatically covered. Each UK entity must independently assess whether it falls within scope and, if so, register with the correct supervisor. The de facto position is that UK nexus triggers UK obligations regardless of where the group is headquartered.
Core KYC and customer due diligence requirements
Know Your Customer obligations under the MLRs require regulated firms to identify and verify their customers before establishing a business relationship or carrying out an occasional transaction above the relevant threshold. Customer due diligence, or CDD, is the practical mechanism through which this is achieved.
Standard CDD requires firms to identify the customer and verify their identity using reliable, independent source documents. For legal entities, this means obtaining the company name, registered number, registered address and understanding the nature of the business. Firms must also identify the beneficial owners of the entity - those who ultimately own or control more than twenty-five percent of the shares or voting rights, or who otherwise exercise control. Verification of beneficial ownership must go beyond simply accepting a company';s self-declaration; firms should cross-reference against Companies House records, which are publicly accessible, and apply judgment where discrepancies arise.
Enhanced due diligence applies in higher-risk situations. These include business relationships with politically exposed persons, transactions involving high-risk third countries as designated by the UK government, and any situation where the firm';s own risk assessment identifies elevated risk. Enhanced due diligence requires additional information gathering, senior management approval for the relationship, and more frequent ongoing monitoring.
Simplified due diligence is permitted in genuinely low-risk situations, such as relationships with other UK-regulated firms or certain listed companies. However, simplified does not mean no due diligence; firms must still satisfy themselves that the lower-risk classification is justified.
Ongoing monitoring is a continuous obligation. Firms must scrutinise transactions to ensure they are consistent with the firm';s knowledge of the customer and their business. They must also keep documents and information up to date. A non-obvious requirement is that the ongoing monitoring obligation applies throughout the life of the relationship, not just at onboarding. Many firms invest heavily in onboarding controls but allow customer files to become stale, which creates significant regulatory exposure.
Risk-based approach and internal controls
The MLRs require regulated firms to adopt a risk-based approach to AML and KYC. This means that the intensity of controls must be proportionate to the level of money laundering and terrorist financing risk the firm faces. A firm cannot simply apply identical procedures to every customer; it must assess risk at the firm level, the customer level and the transaction level.
At the firm level, the MLRs require a written firm-wide risk assessment. This document must identify the risks to which the firm is exposed given its customer base, products, delivery channels, geography and any other relevant factors. The risk assessment must be kept up to date and must be reviewed when there are material changes to the business or the external risk environment.
Internal controls must include the appointment of a nominated officer, who is the person responsible for receiving internal suspicious activity reports and deciding whether to make an external report to the National Crime Agency. For larger firms, a Money Laundering Reporting Officer, or MLRO, typically holds this role. The MLRO must have sufficient seniority, resources and independence to carry out the function effectively. Regulators have criticised firms where the MLRO role was treated as a compliance formality rather than a substantive function.
Staff training is a mandatory element of the internal controls framework. All relevant employees must receive training on how to recognise suspicious activity, what their obligations are, and how to make an internal report. Training must be repeated at appropriate intervals and must be tailored to the employee';s role. A common mistake is delivering generic online training that does not reflect the specific risks of the firm';s business.
In practice, founders and senior managers should consider the internal controls framework as a living system rather than a one-time exercise. The FCA and HMRC both assess whether controls are genuinely embedded in day-to-day operations, not merely documented in a policy manual.
If you are establishing a regulated business in the UK and need to design a compliant AML and KYC framework from the outset, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Suspicious activity reporting and the role of the National Crime Agency
The obligation to report suspicious activity is one of the most operationally significant elements of the UK';s AML framework. Under the Proceeds of Crime Act 2002, a nominated officer who knows or suspects that a person is engaged in money laundering must submit a Suspicious Activity Report, or SAR, to the National Crime Agency. Failure to report where there are grounds to do so is a criminal offence.
The SAR regime operates through the UK Financial Intelligence Unit, which sits within the National Crime Agency. Firms submit SARs through an online portal. Where a firm wants to proceed with a transaction that it suspects may involve criminal property, it must submit a Defence Against Money Laundering report, known as a DAML, and wait for consent from the NCA before proceeding. The NCA has seven days to refuse consent, with a further extension available in complex cases.
The tipping off offence under the Proceeds of Crime Act 2002 prohibits firms from disclosing to a customer or a third party that a SAR has been made or that an investigation is underway. This creates a practical tension: firms must continue to deal with the customer in a normal manner while the SAR is under consideration, without revealing the existence of the report. Staff must be trained to handle this situation carefully.
The volume of SARs submitted to the NCA has grown substantially in recent years, reflecting both increased regulatory pressure and improved detection systems. Regulators have noted that quality matters as much as quantity: a SAR that contains insufficient information to support an investigation has limited value. Firms should invest in training their nominated officers to write clear, factual and actionable reports.
Recent regulatory updates and upcoming changes
The UK';s AML and KYC landscape has evolved significantly in recent periods. Several developments are particularly relevant for businesses operating in or entering the UK market.
The Economic Crime and Corporate Transparency Act introduced important reforms to Companies House. The register now requires identity verification for company directors and persons with significant control. This change directly affects the KYC process for regulated firms, since Companies House data is a key source for beneficial ownership verification. Firms should update their CDD procedures to account for the enhanced reliability of Companies House records while remaining alert to the transitional period during which historical records may not yet be verified.
The FCA has continued to develop its approach to cryptoasset businesses. Firms providing cryptoasset exchange or custodian wallet services must be registered with the FCA under the MLRs. The FCA has refused registration to a significant proportion of applicants and has placed requirements on those that have been registered. Cryptoasset businesses face the same CDD, ongoing monitoring and SAR obligations as traditional financial firms, and the FCA has made clear that it expects the same standard of compliance.
The UK government has published its national risk assessment of money laundering and terrorist financing, which identifies the sectors and typologies considered to present the highest risk. Regulated firms are expected to use the national risk assessment as an input into their own firm-wide risk assessments. Ignoring the national risk assessment when designing controls is a mistake that regulators have highlighted in enforcement actions.
The FCA';s financial crime guide, known as FCG, provides detailed guidance on what the regulator expects in practice. While not legally binding, the FCG is treated by the FCA as a benchmark against which it assesses firms'; systems and controls. Firms that cannot demonstrate alignment with the FCG are likely to face scrutiny.
Enforcement, penalties and practical consequences
Enforcement of AML and KYC obligations in the UK is active and consequential. The FCA has the power to impose unlimited financial penalties on regulated firms and to take action against senior individuals, including prohibition from working in financial services. HMRC can impose civil penalties on the businesses it supervises and can revoke registration, which effectively prevents the firm from operating in its regulated capacity.
Criminal prosecution remains available for the most serious cases. Individuals can be prosecuted for money laundering offences under the Proceeds of Crime Act 2002, for failure to disclose, and for tipping off. Corporate criminal liability for failure to prevent money laundering has been a developing area, and the Economic Crime and Corporate Transparency Act has expanded the circumstances in which organisations can be held criminally liable for economic crimes committed by associated persons.
Reputational consequences can be as damaging as financial penalties. The FCA publishes its final notices, which set out the facts of enforcement cases in detail. Being named in a final notice affects relationships with correspondent banks, payment processors and institutional counterparties.
In practice, firms should treat AML compliance as a core business function rather than a regulatory overhead. The cost of building robust controls at the outset is substantially lower than the cost of remediation, enforcement and reputational damage after a failure.
A practical scenario illustrates the stakes: a payment institution onboards a corporate customer without adequately verifying the beneficial ownership structure. The customer subsequently processes transactions linked to fraud. The firm faces an FCA investigation, a substantial fine, and a requirement to appoint a skilled person under section 166 of the Financial Services and Markets Act 2000 to review its systems. The skilled person review takes many months and costs the firm significant sums in professional fees, in addition to the penalty itself.
A second scenario involves a professional services firm - an accountancy practice - that fails to register with HMRC as a trust or company service provider before offering company formation services. HMRC identifies the failure during a routine inspection. The firm faces a civil penalty and must immediately cease the unregistered activity while its application is processed. Clients are disrupted and the firm';s reputation with referral partners is damaged.
---
Frequently asked questions
What happens if a UK-regulated firm fails to carry out adequate customer due diligence?
Failure to carry out adequate CDD is a breach of the MLRs and can result in civil penalties from the relevant supervisor, whether the FCA, HMRC or a professional body supervisor. In serious cases, the supervisor may suspend or revoke the firm';s registration or authorisation, preventing it from conducting regulated activity. Where the failure is connected to actual money laundering, criminal prosecution of individuals and the firm itself becomes possible. Beyond formal sanctions, inadequate CDD creates operational risk: the firm may unknowingly facilitate financial crime and face reputational and commercial consequences when this comes to light.
How long does it take to register with the FCA or HMRC for AML purposes, and what does it cost?
Timelines vary significantly by supervisor and by the complexity of the application. FCA authorisation for financial services firms is a detailed process that can take several months, particularly for firms with complex structures or novel business models. HMRC registration for businesses such as money service businesses or trust and company service providers is generally faster but still requires the submission of detailed information about the business, its owners and its controllers. Professional fees for preparing a registration application vary depending on the firm';s structure and the level of support required, but can run from the low thousands to the mid-tens of thousands of pounds for more complex cases. State registration fees are set by the relevant authority and vary by entity type.
Does a UK branch of a foreign bank or financial institution need to comply with UK AML rules separately from its parent?
Yes. A UK branch of a foreign firm is subject to UK AML obligations in respect of its UK activities. The branch must comply with the MLRs, maintain its own risk assessment and internal controls appropriate to its UK operations, and appoint a nominated officer for UK purposes. While the branch can draw on group-level policies and procedures, it cannot simply rely on the parent';s compliance programme as a substitute for its own. The FCA expects UK branches to demonstrate that their controls are calibrated to the specific risks of their UK business and that senior management in the UK has genuine oversight of AML matters.
---
Conclusion
AML and KYC compliance in the United Kingdom is a substantive, ongoing obligation that requires investment in systems, people and governance. The regulatory framework is detailed, actively supervised and subject to regular development. Firms that treat compliance as a genuine business priority - rather than a box-ticking exercise - are better positioned to avoid enforcement action and to build sustainable relationships with counterparties and regulators.
VLO Law Firms advises international clients on AML and KYC matters in the United Kingdom. We can assist with regulatory registration, designing and reviewing compliance frameworks, preparing firm-wide risk assessments, and advising on specific CDD and SAR obligations. To request a consultation, contact: info@vlolawfirm.com