Introduction

The four pillars of UK AML law

The United Kingdom's anti-money laundering framework rests on four primary legislative pillars, each serving a distinct but interlocking function. Together, they create one of the most comprehensive AML regimes in the world — and, since 2025, one of the most actively enforced.

£186M+
FCA fines issued 2024/25
74%
of FCA investigations involve financial crime
37
Final Notices issued by FCA 2024/25
14 yrs
Maximum prison sentence for ML
🆕
2025–2026 updates
This guide incorporates the FCA's July 2025 PEP guidance (FG25/3), HM Treasury's July 2025 MLR reform response, the Failure to Prevent Fraud offence (in force September 2025), the FCA Financial Crime Guide amendments (PS24/17, November 2024), and the FCA's confirmation as Single Professional Services Supervisor (announced October 2025).

The four pillars are:

  1. Money Laundering Regulations 2017 (MLR 2017) — the primary rulebook for AML compliance obligations
  2. Proceeds of Crime Act 2002 (POCA) — establishes criminal offences and the SAR regime
  3. Terrorism Act 2000 — addresses terrorist financing obligations
  4. Sanctions and Anti-Money Laundering Act 2018 (SAMLA) — the post-Brexit UK sanctions framework

Layered on top of these are the FCA's Financial Crime Guide (FCG), FCA rules in SYSC 3.2.6R and SYSC 6.1.1R, the Senior Managers and Certification Regime (SM&CR), and a growing body of FCA guidance including the July 2025 PEP guidance (FG25/3).

"Financial crime is one of our four strategic priorities for 2025–2030. Firms that fail to meet our expectations will face the full range of our supervisory and enforcement tools." — FCA, 2025
Pillar 01

Money Laundering Regulations 2017

Primary Law

Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017

SI 2017/692 · In force 26 June 2017 · Multiple amendments to 2025

The MLR 2017 replaced the Money Laundering Regulations 2007 and transposed the EU's Fourth Money Laundering Directive (4MLD) into UK law. Following Brexit, the UK retained and now independently amends the MLRs. They set out the detailed operational obligations for all firms in the regulated sector.

Who is in scope?

The MLR 2017 applies to a wide range of "relevant persons" carrying on business in the UK:

SectorExamplesRisk Level
Credit institutionsBanks, building societiesHigh
Financial institutionsPayment firms, EMIs, insurers, investment firmsHigh
Auditors & accountantsAudit firms, tax advisers, accountantsMedium
Legal professionalsSolicitors, barristers (certain activities)Medium
Estate agentsResidential and commercial property agentsMedium
High-value dealersDealers in goods receiving ≥€10,000 cashMedium
CasinosLand-based and online casinosHigh
Cryptoasset businessesExchanges, wallet providers (from Jan 2020)High

Core obligations under MLR 2017

The MLR 2017 imposes six core obligations on relevant persons. These are explored in depth in Part 2 of this series, but in summary:

  • Firm-wide risk assessment — identify and assess your ML/TF risks
  • Policies, controls and procedures — implement proportionate controls
  • Customer due diligence (CDD) — identify and verify customers and beneficial owners
  • Ongoing monitoring — keep CDD up to date and monitor transactions
  • Record keeping — retain records for 5 years (delete after 5 years under UK GDPR)
  • Staff training — ensure relevant staff are trained

Key amendments since 2017

June 2017
MLR 2017 in force
Replaced MLR 2007. Introduced risk-based approach, enhanced beneficial ownership requirements, domestic PEP obligations.
January 2020
Cryptoassets brought into scope
FCA becomes supervisor for cryptoasset businesses. Exchange providers and custodian wallet providers must register.
March 2022
Russia sanctions — emergency amendments
Significant wave of MLR amendments following Russia's invasion of Ukraine. Expanded sanctions obligations for regulated firms.
November 2023
Domestic PEP clarification
Amendments introduce clearer distinction between domestic and foreign PEPs — domestic PEPs not automatically subject to EDD.
November 2024
FCA Financial Crime Guide updated (PS24/17)
FCA updates its Financial Crime Guide — enhanced sanctions guidance, updated AML systems and controls expectations.
July 2025
HM Treasury MLR reform response
HM Treasury confirms MLR amendments: narrowing EDD to "unusually complex" transactions, FATF blacklist-only for high-risk third countries, cryptoasset alignment with FSMA.
2026 (expected)
MLR statutory instrument
HM Treasury expected to lay revised MLRs before Parliament in early 2026, implementing the July 2025 reform decisions.
🛡️ MLR in action
See how MLR screening obligations work in practice
The FinCrimeRadar screening tool demonstrates the sanctions, PEP and adverse media checks that regulated firms must conduct under MLR 2017.
Try the tool →
Pillar 02

Proceeds of Crime Act 2002 (POCA)

Criminal Law

Proceeds of Crime Act 2002

Chapter 29 · In force 24 February 2003 · Amended by numerous instruments

POCA is the backbone of UK criminal AML law. It creates the money laundering offences, the asset recovery regime, and — critically — the legal obligation to submit Suspicious Activity Reports (SARs). Failure to report is itself a criminal offence. POCA applies to everyone, not just the regulated sector, though Part 7 (money laundering offences) has specific "regulated sector" provisions.

The three principal money laundering offences (Part 7)

Section 327 — Concealing
Concealing, disguising, converting, transferring or removing criminal property from the UK.
Max: 14 years / unlimited fine
Section 328 — Arranging
Entering into or becoming concerned in an arrangement which facilitates acquisition, retention, use or control of criminal property.
Max: 14 years / unlimited fine
Section 329 — Acquisition
Acquiring, using or possessing criminal property.
Max: 14 years / unlimited fine
⚠️
What is "criminal property"?
Criminal property is any property that constitutes a person's benefit from criminal conduct — and the alleged offender knows or suspects it does. This is a broad definition. It includes the proceeds of tax evasion, fraud, corruption, drug trafficking, and any other criminal conduct — not just traditional money laundering.

The SAR regime — Section 330

Section 330 POCA creates the legal obligation to submit Suspicious Activity Reports for persons in the regulated sector. The offence of "failure to disclose" is committed when a person:

  • Knows or suspects — or has reasonable grounds to know or suspect — that another person is engaged in money laundering
  • The information comes to them in the course of business in the regulated sector
  • They do not disclose to the NCA as soon as practicable
🚨
Tipping off — Section 333A
It is a criminal offence under S333A POCA to disclose to a third party that a SAR has been submitted, or that an investigation is underway, if that disclosure is likely to prejudice the investigation. Maximum penalty: 2 years imprisonment and/or unlimited fine. This means firms must be extremely careful about how they handle customer requests for information once a SAR has been filed.

Defence Against Money Laundering (DAML)

The "consent" or DAML regime allows firms to seek permission from the NCA before proceeding with a suspicious transaction. If the NCA grants consent (or does not respond within 7 working days), the firm has a statutory defence against the money laundering offences in sections 327–329 POCA. This is a vital tool — it allows firms to proceed with transactions they suspect may be suspicious without committing a criminal offence.

Asset recovery powers

POCA also grants law enforcement extensive asset recovery powers including: confiscation orders (post-conviction), civil recovery orders (no criminal conviction required), cash forfeiture, account freezing orders (AFOs), and unexplained wealth orders (UWOs). These powers have been significantly expanded by the Economic Crime (Transparency and Enforcement) Act 2022 and the Economic Crime and Corporate Transparency Act 2023.

🧠 Knowledge check
Under POCA Section 330, what is the maximum prison sentence for failure to disclose (failing to file a SAR when required)?
Pillar 03

Terrorism Act 2000

CTF Law

Terrorism Act 2000

Chapter 11 · In force 19 February 2001 · Amended by Counter-Terrorism Act 2008 and others

The Terrorism Act 2000 (TA 2000) addresses counter-terrorism financing (CTF) — the financial crime of funding terrorist activities. While POCA addresses the proceeds of crime (money going into the system), the TA 2000 addresses terrorist financing (money going out to fund attacks and organisations).

Key CTF offences

Section 15 — Fundraising
Inviting or receiving money or property intended for use in terrorism, or knowing it will be used.
Max: 14 years / unlimited fine
Section 16 — Use/possession
Using money or other property for terrorism, or possessing property intending it to be used.
Max: 14 years / unlimited fine
Section 17 — Funding arrangements
Entering into an arrangement where money or property is to be used for terrorism.
Max: 14 years / unlimited fine
Section 18 — Money laundering
Entering into arrangements to facilitate retention or control of terrorist property.
Max: 14 years / unlimited fine

The CTF disclosure obligation — Section 21A

Section 21A TA 2000 (inserted by the Anti-terrorism, Crime and Security Act 2001) creates the obligation for persons in the regulated sector to disclose information about suspected terrorist financing to the police or NCA. This mirrors the POCA s.330 obligation for money laundering.

💡
AML vs CTF — a key difference
Money laundering involves "dirty money" — the proceeds of crime being cleaned. Terrorist financing can involve entirely "clean money" — legitimately earned funds being diverted to terrorism. This makes CTF screening harder: a terrorist financier may have no criminal record, no suspicious transaction history, and may appear entirely legitimate. Screening against terrorist designation lists is therefore even more critical for CTF than it is for AML.
🛡️ Screen for terrorism financing risk
UN and OFAC lists include terrorist designation data
FinCrimeRadar screens against UN Security Council sanctions (which include terrorist designations) and OFAC's SDGT list — key tools for CTF compliance.
Screen now →
Pillar 04

Sanctions and Anti-Money Laundering Act 2018 (SAMLA)

Sanctions Law

Sanctions and Anti-Money Laundering Act 2018

Chapter 13 · In force 23 May 2018 · UK's post-Brexit sanctions framework

SAMLA gives the UK government the power to impose, maintain, and lift sanctions regimes independently following Brexit — without reliance on EU mechanisms. Prior to SAMLA, the UK could only impose sanctions through EU law or UN Security Council resolutions. SAMLA created the autonomous UK sanctions regime administered by the Office of Financial Sanctions Implementation (OFSI) under HM Treasury.

The UK sanctions architecture

  • OFSI — implements and enforces UK financial sanctions, issues licences, and publishes the UK Consolidated List
  • FCDO — Foreign, Commonwealth & Development Office: leads on sanctions policy
  • HM Treasury — ministerial accountability for OFSI and financial sanctions
  • FCA — supervises compliance with sanctions obligations by regulated firms (via SYSC rules)

Civil monetary penalties under SAMLA

SAMLA introduced civil monetary penalties (CMPs) for sanctions breaches — meaning OFSI can fine firms without requiring criminal prosecution. CMPs can be up to the greater of:

  • £1 million, or
  • 50% of the value of the breach

The Economic Crime (Transparency and Enforcement) Act 2022 lowered the evidentiary threshold for CMPs — OFSI no longer needs to prove the firm knew they were breaching sanctions, only that a breach occurred.

⚠️
Russia sanctions — the biggest test of SAMLA
Following Russia's invasion of Ukraine in February 2022, the UK imposed some of the most extensive sanctions in its history — designating hundreds of Russian individuals, entities, and vessels. The pace and complexity of designations placed significant strain on firms' sanctions screening systems. The FCA's 2024/25 enforcement activity focused heavily on sanctions compliance failures at this period.
🛡️ UK sanctions screening
Search the OFSI Consolidated List in real time
FinCrimeRadar includes OFSI (UK) sanctions data via OpenSanctions — try screening individuals or entities to see their UK sanctions status.
Screen for UK sanctions →
Regulatory Layer

The FCA's financial crime framework

Above the legislative framework sits the FCA's own regulatory architecture for financial crime. For FCA-regulated firms, this layer is where the rubber meets the road — it translates the law into specific supervisory expectations.

SYSC rules — the foundation

Two rules in the FCA's Senior Management Arrangements, Systems and Controls (SYSC) sourcebook are central:

  • SYSC 3.2.6R — requires firms to take reasonable care to establish and maintain effective systems and controls for compliance and financial crime
  • SYSC 6.1.1R — requires firms to have robust governance arrangements, effective processes, and adequate internal control mechanisms to manage money laundering risk

The Financial Crime Guide (FCG)

The FCA's Financial Crime Guide (FCG) is not technically binding law — but in practice, it defines the FCA's supervisory expectations. The FCG covers:

FCG ChapterTopic
FCG 1Financial crime systems and controls — overview
FCG 2Financial crime governance
FCG 3Money laundering and terrorist financing
FCG 4Fraud
FCG 5Bribery and corruption
FCG 6Market abuse
FCG 7Sanctions

SM&CR — personal accountability for MLROs

Under the Senior Managers and Certification Regime (SM&CR), the Money Laundering Reporting Officer (MLRO) is a designated Senior Management Function: SMF17. This means:

  • The MLRO must be approved by the FCA before taking up the role
  • The FCA assesses qualifications, experience, reputation, and time availability
  • The MLRO has personal accountability under Conduct Rule 4 (obligation to disclose appropriately)
  • Failure to perform the MLRO role adequately can result in personal enforcement action by the FCA
👤
The MLRO's dual role
The MLRO wears two hats simultaneously: (1) as the firm's nominated officer under the MLRs — responsible for the firm's AML framework; and (2) as the person with statutory responsibility under POCA to decide whether to submit SARs to the NCA. The combination of these two roles creates significant personal legal exposure. The FCA expects MLROs to have sufficient seniority, resources, and independence to perform both functions effectively.
What's changing

2025–2026 regulatory changes: What you need to know now

🆕
FCA PEP Guidance FG25/3 — July 2025
The FCA's updated PEP guidance confirms that UK PEPs are generally lower risk than foreign PEPs. Non-executive board members of UK government departments and junior civil servants and military officials are NOT classified as PEPs. MLRO sign-off is no longer required automatically for every PEP relationship — firms must document reasons when applying EDD to former PEPs.
🆕
HM Treasury MLR Reform — July 2025
EDD requirements narrowed to "unusually complex" transactions (not all complex transactions). For high-risk third countries, EDD now limited to FATF "Call for Action" (blacklist) countries only. Cryptoasset firms aligned with FSMA regime — no dual registration required. Statutory instrument expected early 2026.
🆕
Failure to Prevent Fraud — September 2025
The Failure to Prevent Fraud (FTPF) offence (Economic Crime and Corporate Transparency Act 2023) came into force 1 September 2025. Large organisations must have "reasonable procedures" to prevent fraud. Applies to firms with turnover >£36m, assets >£18m, or >250 employees (meeting two of three).
🆕
FCA as Single Professional Services Supervisor — from 2027
The FCA will consolidate AML supervision of professional services firms (currently supervised by 23 separate bodies including the SRA, ICAEW, and ACCA) under a single FCA regime. Legislation introduced to Parliament; implementation expected late 2027 at earliest.
🔍 See the PEP changes in practice
Under FG25/3, UK PEPs are generally lower risk — test the difference
Search for UK politicians, ministers or civil servants on FinCrimeRadar and see how they appear in PEP screening data.
Try PEP screening →
Consequences

Penalties for non-compliance

The consequences of AML compliance failures in the UK are severe, operating across three dimensions:

💰
Civil / regulatory
Unlimited
FCA fines with no cap. OFSI CMPs up to £1m or 50% of breach value. Senior manager bans.
⚖️
Criminal
14 years
Maximum imprisonment for POCA / TA 2000 offences. Unlimited fines. Confiscation of assets.
📉
Reputational
Existential
FCA Final Notices are public. Loss of authorisation. De-risking by correspondent banks.

Recent FCA enforcement cases — the pattern

Firm typeFailureConsequence
Challenger bankInadequate transaction monitoring, weak CDDMulti-million pound fine, enhanced supervision
Payment institutionSanctions screening gaps, failure to file SARsLicence restriction, skilled person review (s166)
Traditional bankSystematic AML control failures over multiple years£100m+ fine, executive personal censure
Cryptoasset firmFailure to register under MLRsCessation of business, FCA public warning
🚨
The FCA's five-step penalty calculation
The FCA uses a five-step methodology to calculate fines: (1) revenue figure, (2) seriousness adjustment (1–5 scale), (3) mitigating/aggravating factors, (4) deterrence uplift, (5) settlement discount (up to 30%). There is no cap. For senior individuals, step 1 uses a "benefit received" figure. The absence of a cap means financial penalties can reach hundreds of millions of pounds for systematic failures.
FAQ

Frequently asked questions

What is the difference between MLR 2017 obligations and POCA offences? +
MLR 2017 sets out the compliance framework obligations — what systems and controls firms must have. POCA sets out criminal offences — what conduct is illegal. A firm can breach the MLRs (e.g. have inadequate CDD procedures) without committing a POCA offence, and can commit a POCA offence (e.g. fail to file a required SAR) even if their MLR compliance framework is otherwise adequate. Both can apply simultaneously in serious cases.
Does MLR 2017 apply to my fintech / EMI? +
Yes. Electronic money institutions (EMIs) and payment institutions are explicitly within scope of MLR 2017 as "financial institutions." This includes e-money issuers like Revolut, Wise, and similar businesses. The FCA is also their AML supervisor. From 2020, cryptoasset exchange providers and custodian wallet providers are also in scope. If you hold an FCA authorisation or registration, you are almost certainly within MLR scope.
What changed under the July 2025 PEP guidance? +
The FCA's FG25/3 (July 2025) clarifies that UK PEPs are generally lower risk than foreign PEPs. Specifically: non-executive board members of UK government departments are not PEPs; junior civil servants and military officials are not PEPs; MLRO sign-off is no longer required for every PEP relationship (though MLRO oversight of all PEP relationships remains required); firms must document reasons when applying EDD to former PEPs. This guidance addresses the industry concern that domestic PEPs (including MPs and civil servants) were being over-screened relative to their actual risk.
What is a Section 166 review? +
A Section 166 review (under FSMA 2000) is a "skilled person review" — where the FCA requires a firm to commission an independent expert (approved by the FCA) to review and report on specific aspects of the firm's activities. In financial crime, s166 reviews typically look at AML controls, transaction monitoring, CDD quality, and sanctions screening. They are expensive (six-figure fees are common), disruptive, and often precede formal enforcement action. Receiving a s166 is a significant red flag that the FCA has material concerns about a firm's controls.
What is the UKFIU and how does it relate to SARs? +
The UK Financial Intelligence Unit (UKFIU) is a unit within the National Crime Agency (NCA) that receives, processes, and disseminates Suspicious Activity Reports (SARs). All SARs submitted by regulated firms go to the UKFIU via the NCA's SAR Online system. The UKFIU analyses SARs for financial intelligence and shares relevant information with law enforcement. In 2023/24, over 900,000 SARs were submitted to the UKFIU — the vast majority from banks and other financial institutions. Quality over quantity is the FCA's message: a well-reasoned SAR with good financial intelligence is far more valuable than a defensive SAR filed to avoid prosecution.