Everything FCA-regulated firms need to know about MLR 2017, POCA 2002, the Terrorism Act 2000, and SAMLA 2018 — the four pillars of UK AML law. Updated for 2026 including the July 2025 FCA PEP guidance and HM Treasury MLR reforms.
The United Kingdom's anti-money laundering framework rests on four primary legislative pillars, each serving a distinct but interlocking function. Together, they create one of the most comprehensive AML regimes in the world — and, since 2025, one of the most actively enforced.
£186M+
FCA fines issued 2024/25
74%
of FCA investigations involve financial crime
37
Final Notices issued by FCA 2024/25
14 yrs
Maximum prison sentence for ML
🆕
2025–2026 updates
This guide incorporates the FCA's July 2025 PEP guidance (FG25/3), HM Treasury's July 2025 MLR reform response, the Failure to Prevent Fraud offence (in force September 2025), the FCA Financial Crime Guide amendments (PS24/17, November 2024), and the FCA's confirmation as Single Professional Services Supervisor (announced October 2025).
The four pillars are:
Money Laundering Regulations 2017 (MLR 2017) — the primary rulebook for AML compliance obligations
Proceeds of Crime Act 2002 (POCA) — establishes criminal offences and the SAR regime
Sanctions and Anti-Money Laundering Act 2018 (SAMLA) — the post-Brexit UK sanctions framework
Layered on top of these are the FCA's Financial Crime Guide (FCG), FCA rules in SYSC 3.2.6R and SYSC 6.1.1R, the Senior Managers and Certification Regime (SM&CR), and a growing body of FCA guidance including the July 2025 PEP guidance (FG25/3).
"Financial crime is one of our four strategic priorities for 2025–2030. Firms that fail to meet our expectations will face the full range of our supervisory and enforcement tools." — FCA, 2025
Pillar 01
Money Laundering Regulations 2017
Primary Law
Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
SI 2017/692 · In force 26 June 2017 · Multiple amendments to 2025
The MLR 2017 replaced the Money Laundering Regulations 2007 and transposed the EU's Fourth Money Laundering Directive (4MLD) into UK law. Following Brexit, the UK retained and now independently amends the MLRs. They set out the detailed operational obligations for all firms in the regulated sector.
Who is in scope?
The MLR 2017 applies to a wide range of "relevant persons" carrying on business in the UK:
Sector
Examples
Risk Level
Credit institutions
Banks, building societies
High
Financial institutions
Payment firms, EMIs, insurers, investment firms
High
Auditors & accountants
Audit firms, tax advisers, accountants
Medium
Legal professionals
Solicitors, barristers (certain activities)
Medium
Estate agents
Residential and commercial property agents
Medium
High-value dealers
Dealers in goods receiving ≥€10,000 cash
Medium
Casinos
Land-based and online casinos
High
Cryptoasset businesses
Exchanges, wallet providers (from Jan 2020)
High
Core obligations under MLR 2017
The MLR 2017 imposes six core obligations on relevant persons. These are explored in depth in Part 2 of this series, but in summary:
Firm-wide risk assessment — identify and assess your ML/TF risks
Policies, controls and procedures — implement proportionate controls
Customer due diligence (CDD) — identify and verify customers and beneficial owners
Ongoing monitoring — keep CDD up to date and monitor transactions
Record keeping — retain records for 5 years (delete after 5 years under UK GDPR)
Staff training — ensure relevant staff are trained
Chapter 29 · In force 24 February 2003 · Amended by numerous instruments
POCA is the backbone of UK criminal AML law. It creates the money laundering offences, the asset recovery regime, and — critically — the legal obligation to submit Suspicious Activity Reports (SARs). Failure to report is itself a criminal offence. POCA applies to everyone, not just the regulated sector, though Part 7 (money laundering offences) has specific "regulated sector" provisions.
The three principal money laundering offences (Part 7)
Section 327 — Concealing
Concealing, disguising, converting, transferring or removing criminal property from the UK.
Max: 14 years / unlimited fine
Section 328 — Arranging
Entering into or becoming concerned in an arrangement which facilitates acquisition, retention, use or control of criminal property.
Max: 14 years / unlimited fine
Section 329 — Acquisition
Acquiring, using or possessing criminal property.
Max: 14 years / unlimited fine
⚠️
What is "criminal property"?
Criminal property is any property that constitutes a person's benefit from criminal conduct — and the alleged offender knows or suspects it does. This is a broad definition. It includes the proceeds of tax evasion, fraud, corruption, drug trafficking, and any other criminal conduct — not just traditional money laundering.
The SAR regime — Section 330
Section 330 POCA creates the legal obligation to submit Suspicious Activity Reports for persons in the regulated sector. The offence of "failure to disclose" is committed when a person:
Knows or suspects — or has reasonable grounds to know or suspect — that another person is engaged in money laundering
The information comes to them in the course of business in the regulated sector
They do not disclose to the NCA as soon as practicable
🚨
Tipping off — Section 333A
It is a criminal offence under S333A POCA to disclose to a third party that a SAR has been submitted, or that an investigation is underway, if that disclosure is likely to prejudice the investigation. Maximum penalty: 2 years imprisonment and/or unlimited fine. This means firms must be extremely careful about how they handle customer requests for information once a SAR has been filed.
Defence Against Money Laundering (DAML)
The "consent" or DAML regime allows firms to seek permission from the NCA before proceeding with a suspicious transaction. If the NCA grants consent (or does not respond within 7 working days), the firm has a statutory defence against the money laundering offences in sections 327–329 POCA. This is a vital tool — it allows firms to proceed with transactions they suspect may be suspicious without committing a criminal offence.
Asset recovery powers
POCA also grants law enforcement extensive asset recovery powers including: confiscation orders (post-conviction), civil recovery orders (no criminal conviction required), cash forfeiture, account freezing orders (AFOs), and unexplained wealth orders (UWOs). These powers have been significantly expanded by the Economic Crime (Transparency and Enforcement) Act 2022 and the Economic Crime and Corporate Transparency Act 2023.
🧠 Knowledge check
Under POCA Section 330, what is the maximum prison sentence for failure to disclose (failing to file a SAR when required)?
Pillar 03
Terrorism Act 2000
CTF Law
Terrorism Act 2000
Chapter 11 · In force 19 February 2001 · Amended by Counter-Terrorism Act 2008 and others
The Terrorism Act 2000 (TA 2000) addresses counter-terrorism financing (CTF) — the financial crime of funding terrorist activities. While POCA addresses the proceeds of crime (money going into the system), the TA 2000 addresses terrorist financing (money going out to fund attacks and organisations).
Key CTF offences
Section 15 — Fundraising
Inviting or receiving money or property intended for use in terrorism, or knowing it will be used.
Max: 14 years / unlimited fine
Section 16 — Use/possession
Using money or other property for terrorism, or possessing property intending it to be used.
Max: 14 years / unlimited fine
Section 17 — Funding arrangements
Entering into an arrangement where money or property is to be used for terrorism.
Max: 14 years / unlimited fine
Section 18 — Money laundering
Entering into arrangements to facilitate retention or control of terrorist property.
Max: 14 years / unlimited fine
The CTF disclosure obligation — Section 21A
Section 21A TA 2000 (inserted by the Anti-terrorism, Crime and Security Act 2001) creates the obligation for persons in the regulated sector to disclose information about suspected terrorist financing to the police or NCA. This mirrors the POCA s.330 obligation for money laundering.
💡
AML vs CTF — a key difference
Money laundering involves "dirty money" — the proceeds of crime being cleaned. Terrorist financing can involve entirely "clean money" — legitimately earned funds being diverted to terrorism. This makes CTF screening harder: a terrorist financier may have no criminal record, no suspicious transaction history, and may appear entirely legitimate. Screening against terrorist designation lists is therefore even more critical for CTF than it is for AML.
🛡️ Screen for terrorism financing risk
UN and OFAC lists include terrorist designation data
FinCrimeRadar screens against UN Security Council sanctions (which include terrorist designations) and OFAC's SDGT list — key tools for CTF compliance.
Sanctions and Anti-Money Laundering Act 2018 (SAMLA)
Sanctions Law
Sanctions and Anti-Money Laundering Act 2018
Chapter 13 · In force 23 May 2018 · UK's post-Brexit sanctions framework
SAMLA gives the UK government the power to impose, maintain, and lift sanctions regimes independently following Brexit — without reliance on EU mechanisms. Prior to SAMLA, the UK could only impose sanctions through EU law or UN Security Council resolutions. SAMLA created the autonomous UK sanctions regime administered by the Office of Financial Sanctions Implementation (OFSI) under HM Treasury.
The UK sanctions architecture
OFSI — implements and enforces UK financial sanctions, issues licences, and publishes the UK Consolidated List
FCDO — Foreign, Commonwealth & Development Office: leads on sanctions policy
HM Treasury — ministerial accountability for OFSI and financial sanctions
FCA — supervises compliance with sanctions obligations by regulated firms (via SYSC rules)
Civil monetary penalties under SAMLA
SAMLA introduced civil monetary penalties (CMPs) for sanctions breaches — meaning OFSI can fine firms without requiring criminal prosecution. CMPs can be up to the greater of:
£1 million, or
50% of the value of the breach
The Economic Crime (Transparency and Enforcement) Act 2022 lowered the evidentiary threshold for CMPs — OFSI no longer needs to prove the firm knew they were breaching sanctions, only that a breach occurred.
⚠️
Russia sanctions — the biggest test of SAMLA
Following Russia's invasion of Ukraine in February 2022, the UK imposed some of the most extensive sanctions in its history — designating hundreds of Russian individuals, entities, and vessels. The pace and complexity of designations placed significant strain on firms' sanctions screening systems. The FCA's 2024/25 enforcement activity focused heavily on sanctions compliance failures at this period.
🛡️ UK sanctions screening
Search the OFSI Consolidated List in real time
FinCrimeRadar includes OFSI (UK) sanctions data via OpenSanctions — try screening individuals or entities to see their UK sanctions status.
Above the legislative framework sits the FCA's own regulatory architecture for financial crime. For FCA-regulated firms, this layer is where the rubber meets the road — it translates the law into specific supervisory expectations.
SYSC rules — the foundation
Two rules in the FCA's Senior Management Arrangements, Systems and Controls (SYSC) sourcebook are central:
SYSC 3.2.6R — requires firms to take reasonable care to establish and maintain effective systems and controls for compliance and financial crime
SYSC 6.1.1R — requires firms to have robust governance arrangements, effective processes, and adequate internal control mechanisms to manage money laundering risk
The Financial Crime Guide (FCG)
The FCA's Financial Crime Guide (FCG) is not technically binding law — but in practice, it defines the FCA's supervisory expectations. The FCG covers:
FCG Chapter
Topic
FCG 1
Financial crime systems and controls — overview
FCG 2
Financial crime governance
FCG 3
Money laundering and terrorist financing
FCG 4
Fraud
FCG 5
Bribery and corruption
FCG 6
Market abuse
FCG 7
Sanctions
SM&CR — personal accountability for MLROs
Under the Senior Managers and Certification Regime (SM&CR), the Money Laundering Reporting Officer (MLRO) is a designated Senior Management Function: SMF17. This means:
The MLRO must be approved by the FCA before taking up the role
The FCA assesses qualifications, experience, reputation, and time availability
The MLRO has personal accountability under Conduct Rule 4 (obligation to disclose appropriately)
Failure to perform the MLRO role adequately can result in personal enforcement action by the FCA
👤
The MLRO's dual role
The MLRO wears two hats simultaneously: (1) as the firm's nominated officer under the MLRs — responsible for the firm's AML framework; and (2) as the person with statutory responsibility under POCA to decide whether to submit SARs to the NCA. The combination of these two roles creates significant personal legal exposure. The FCA expects MLROs to have sufficient seniority, resources, and independence to perform both functions effectively.
What's changing
2025–2026 regulatory changes: What you need to know now
🆕
FCA PEP Guidance FG25/3 — July 2025
The FCA's updated PEP guidance confirms that UK PEPs are generally lower risk than foreign PEPs. Non-executive board members of UK government departments and junior civil servants and military officials are NOT classified as PEPs. MLRO sign-off is no longer required automatically for every PEP relationship — firms must document reasons when applying EDD to former PEPs.
🆕
HM Treasury MLR Reform — July 2025
EDD requirements narrowed to "unusually complex" transactions (not all complex transactions). For high-risk third countries, EDD now limited to FATF "Call for Action" (blacklist) countries only. Cryptoasset firms aligned with FSMA regime — no dual registration required. Statutory instrument expected early 2026.
🆕
Failure to Prevent Fraud — September 2025
The Failure to Prevent Fraud (FTPF) offence (Economic Crime and Corporate Transparency Act 2023) came into force 1 September 2025. Large organisations must have "reasonable procedures" to prevent fraud. Applies to firms with turnover >£36m, assets >£18m, or >250 employees (meeting two of three).
🆕
FCA as Single Professional Services Supervisor — from 2027
The FCA will consolidate AML supervision of professional services firms (currently supervised by 23 separate bodies including the SRA, ICAEW, and ACCA) under a single FCA regime. Legislation introduced to Parliament; implementation expected late 2027 at earliest.
🔍 See the PEP changes in practice
Under FG25/3, UK PEPs are generally lower risk — test the difference
Search for UK politicians, ministers or civil servants on FinCrimeRadar and see how they appear in PEP screening data.
The consequences of AML compliance failures in the UK are severe, operating across three dimensions:
💰
Civil / regulatory
Unlimited
FCA fines with no cap. OFSI CMPs up to £1m or 50% of breach value. Senior manager bans.
⚖️
Criminal
14 years
Maximum imprisonment for POCA / TA 2000 offences. Unlimited fines. Confiscation of assets.
📉
Reputational
Existential
FCA Final Notices are public. Loss of authorisation. De-risking by correspondent banks.
Recent FCA enforcement cases — the pattern
Firm type
Failure
Consequence
Challenger bank
Inadequate transaction monitoring, weak CDD
Multi-million pound fine, enhanced supervision
Payment institution
Sanctions screening gaps, failure to file SARs
Licence restriction, skilled person review (s166)
Traditional bank
Systematic AML control failures over multiple years
£100m+ fine, executive personal censure
Cryptoasset firm
Failure to register under MLRs
Cessation of business, FCA public warning
🚨
The FCA's five-step penalty calculation
The FCA uses a five-step methodology to calculate fines: (1) revenue figure, (2) seriousness adjustment (1–5 scale), (3) mitigating/aggravating factors, (4) deterrence uplift, (5) settlement discount (up to 30%). There is no cap. For senior individuals, step 1 uses a "benefit received" figure. The absence of a cap means financial penalties can reach hundreds of millions of pounds for systematic failures.
FAQ
Frequently asked questions
What is the difference between MLR 2017 obligations and POCA offences? +
MLR 2017 sets out the compliance framework obligations — what systems and controls firms must have. POCA sets out criminal offences — what conduct is illegal. A firm can breach the MLRs (e.g. have inadequate CDD procedures) without committing a POCA offence, and can commit a POCA offence (e.g. fail to file a required SAR) even if their MLR compliance framework is otherwise adequate. Both can apply simultaneously in serious cases.
Does MLR 2017 apply to my fintech / EMI? +
Yes. Electronic money institutions (EMIs) and payment institutions are explicitly within scope of MLR 2017 as "financial institutions." This includes e-money issuers like Revolut, Wise, and similar businesses. The FCA is also their AML supervisor. From 2020, cryptoasset exchange providers and custodian wallet providers are also in scope. If you hold an FCA authorisation or registration, you are almost certainly within MLR scope.
What changed under the July 2025 PEP guidance? +
The FCA's FG25/3 (July 2025) clarifies that UK PEPs are generally lower risk than foreign PEPs. Specifically: non-executive board members of UK government departments are not PEPs; junior civil servants and military officials are not PEPs; MLRO sign-off is no longer required for every PEP relationship (though MLRO oversight of all PEP relationships remains required); firms must document reasons when applying EDD to former PEPs. This guidance addresses the industry concern that domestic PEPs (including MPs and civil servants) were being over-screened relative to their actual risk.
What is a Section 166 review? +
A Section 166 review (under FSMA 2000) is a "skilled person review" — where the FCA requires a firm to commission an independent expert (approved by the FCA) to review and report on specific aspects of the firm's activities. In financial crime, s166 reviews typically look at AML controls, transaction monitoring, CDD quality, and sanctions screening. They are expensive (six-figure fees are common), disruptive, and often precede formal enforcement action. Receiving a s166 is a significant red flag that the FCA has material concerns about a firm's controls.
What is the UKFIU and how does it relate to SARs? +
The UK Financial Intelligence Unit (UKFIU) is a unit within the National Crime Agency (NCA) that receives, processes, and disseminates Suspicious Activity Reports (SARs). All SARs submitted by regulated firms go to the UKFIU via the NCA's SAR Online system. The UKFIU analyses SARs for financial intelligence and shares relevant information with law enforcement. In 2023/24, over 900,000 SARs were submitted to the UKFIU — the vast majority from banks and other financial institutions. Quality over quantity is the FCA's message: a well-reasoned SAR with good financial intelligence is far more valuable than a defensive SAR filed to avoid prosecution.