Introduction

The five core compliance obligations

The Money Laundering Regulations 2017 impose five core operational obligations on every firm in scope. These are not optional best practices — they are legal requirements, breaches of which can result in FCA enforcement action, criminal prosecution of the MLRO, and unlimited fines.

1

Firm-wide risk assessment

Identify and document your organisation's exposure to ML/TF risk across products, customers, geographies, and channels.

2

Customer Due Diligence (CDD)

Identify and verify your customers and beneficial owners. Apply SDD, standard CDD, or EDD proportionate to risk.

3

Suspicious Activity Reports (SARs)

Report suspected money laundering or terrorist financing to the NCA via UKFIU as soon as practicable.

4

Record keeping

Retain CDD documents and transaction records for 5 years. Delete after 5 years under UK GDPR (with limited exceptions).

5

Staff training

Ensure all relevant employees understand AML law, the firm's risk assessment, CDD procedures, and how to report suspicions.

"MLR 2017 is not a compliance checklist. It is a risk-based framework — and the FCA will assess whether your controls are proportionate to the risks your firm actually faces, not whether you have ticked boxes."
Obligation 01

Firm-wide risk assessment

The firm-wide risk assessment (FWRA) is the foundation of your entire AML programme. Under Regulation 18 MLR 2017, every relevant person must identify and assess the risks of money laundering and terrorist financing to which their business is subject — and must document this assessment in writing.

What the FWRA must cover

The MLR 2017 specifies that the FWRA must take into account at least the following risk factors:

🏢 Products & services
  • Nature and complexity of products
  • Cash handling volumes
  • Cross-border payment capabilities
  • Anonymity features (e.g. e-money)
  • Virtual asset services
🌍 Geographic risk
  • High-risk third countries (FATF lists)
  • Countries with weak AML regimes
  • Offshore financial centres
  • Conflict zones and sanctioned countries
👥 Customer risk
  • PEPs and their associates
  • Cash-intensive businesses
  • Non-face-to-face customers
  • Complex ownership structures
  • High-net-worth individuals
📡 Delivery channels
  • Online/digital onboarding
  • Third-party intermediaries
  • Correspondent relationships
  • Mobile payment channels

The risk assessment process

1

Identify inherent risks

What ML/TF risks exist in your business before controls are applied? Consider each risk factor category above.

2

Assess risk level

Rate each inherent risk: High / Medium / Low. Document your methodology and rationale.

3

Identify mitigating controls

What controls does the firm have in place to reduce each identified risk?

4

Assess residual risk

After applying controls, what risk remains? This is your residual risk — the basis for your ongoing monitoring.

5

Approve and document

The FWRA must be approved by senior management and reviewed regularly (typically annually, or when risks change materially).

⚠️
Common FCA finding — generic risk assessments
The FCA's risk assessment thematic review (2024) found that many firms produce risk assessments that are too generic — describing industry risks rather than the firm's specific risk profile. A risk assessment that could apply to any payment firm in the sector is unlikely to satisfy the FCA. Your FWRA should reflect your specific products, your specific customers, your specific geographies — not a template.
🔍 Risk assessment in practice
Customer screening is part of your risk assessment controls
Sanctions, PEP, and adverse media screening are key risk assessment tools. Try FinCrimeRadar to understand what a screening control delivers.
Try the tool →
Obligation 02

Customer Due Diligence (CDD)

Customer Due Diligence is the process of identifying and verifying your customers — and, for legal entities, their beneficial owners. It is the cornerstone of AML compliance: if you do not know who you are dealing with, you cannot assess the risk they present.

The three tiers of CDD

🟢 Lower risk

Simplified Due Diligence (SDD)

Applied where risk is demonstrably low. Less intensive checks — though basic identity verification is still required.

  • Listed companies on regulated markets
  • UK public authorities
  • Low-value e-money products (≤€150)
  • Regulated financial institutions
🔵 Standard risk

Standard CDD

The default level. Identify the customer, verify identity, understand the relationship, and conduct ongoing monitoring.

  • Verify name, address, DOB (individuals)
  • Identify UBO (>25% ownership threshold)
  • Understand purpose of relationship
  • Ongoing monitoring of transactions
🔴 Higher risk

Enhanced Due Diligence (EDD)

Mandatory for PEPs, high-risk third countries, and other elevated risk situations. More intrusive checks required.

  • Source of funds verification
  • Source of wealth documentation
  • Senior management approval
  • Enhanced ongoing monitoring

Standard CDD — what must you collect?

For individuals:

  • Full name
  • Date of birth
  • Residential address
  • Verification documents (passport, driving licence, utility bill — reliable, independent sources)

For legal entities (companies, partnerships, trusts):

  • Name, legal form, registered address
  • Constitutional documents (articles of association, trust deed)
  • Names of senior persons responsible for operations
  • Identification of ultimate beneficial owners (UBOs) — individuals owning >25% shares or voting rights, or exercising significant control
  • Verification of UBO identity

When must CDD be conducted?

TriggerCDD required?Notes
Establishing a business relationship✅ Yes — before or duringMust complete before proceeding in most cases
Occasional transaction ≥€15,000✅ YesSingle or linked transactions
Suspicion of ML/TF✅ Yes — regardless of thresholdsEven if relationship pre-dates suspicion
Doubt about previous verification✅ YesRefresh CDD when reliability doubted
Periodic review (existing customers)✅ Yes — risk-basedHigh risk: annually; Medium: 2–3yr; Low: 3–5yr
Change in customer circumstances✅ Yes — trigger-basedChange of ownership, new product, higher risk activity
💡
Beneficial ownership — the 25% threshold
Under MLR 2017, you must identify any individual who owns more than 25% of shares or voting rights in a legal entity, or who otherwise exercises significant control. This threshold is a minimum, not a ceiling — where risks are higher, you should look through lower ownership levels. If no individual meets the 25% threshold, you should identify the most senior person responsible for managing the entity as the beneficial owner.
🧠 Knowledge check
Under MLR 2017, what is the beneficial ownership threshold that triggers the requirement to identify and verify an individual's ownership of a company?
🔍 CDD in practice
Screening is a core component of CDD — try it here
Sanctions and PEP screening are required as part of CDD for regulated firms. Enter a customer name to see what a compliant screening check reveals.
Run a CDD screen →
Obligation 02b

Enhanced Due Diligence (EDD)

Enhanced Due Diligence is mandatory — not discretionary — in certain circumstances defined by MLR 2017. It requires additional measures beyond standard CDD to manage elevated risks.

When is EDD mandatory?

  • Politically Exposed Persons (PEPs) — and their family members and known close associates
  • Correspondent banking relationships — between credit or financial institutions
  • High-risk third countries — from July 2025 reforms, limited to FATF "Call for Action" (blacklist) countries
  • Unusually complex transactions — from July 2025 MLR reforms, narrowed from "all complex transactions"
  • Any other situation assessed as high risk — under the firm's risk-based approach

What does EDD involve?

  • Source of funds (SoF) — documentary evidence of where the specific funds being used originate (e.g. sale proceeds, salary, inheritance)
  • Source of wealth (SoW) — broader evidence of how the customer accumulated their overall wealth (e.g. business ownership, investment history, inheritance)
  • Senior management approval — the business relationship must be approved by senior management before proceeding
  • Enhanced ongoing monitoring — more frequent transaction reviews, lower thresholds for alert generation
  • Purpose of the relationship — detailed understanding of why the customer needs the product/service
🆕
July 2025 reform — EDD scope narrowed
HM Treasury's July 2025 MLR reform response confirms that EDD obligations will be narrowed: (1) EDD for "complex" transactions will be limited to "unusually complex" transactions — reducing burden on firms dealing with routine cross-border payments; (2) For high-risk third countries, EDD will now only be required for jurisdictions on the FATF "Call for Action" list (the FATF blacklist), rather than all countries on the FATF monitoring list. This is a significant reduction in EDD scope for many payment firms.
Obligation 02c

PEP screening and due diligence

PEP screening is a mandatory component of CDD for all regulated firms. The key question is not just "is this person a PEP?" — it is "what EDD measures are proportionate to the risk this particular PEP presents?"

Identifying PEPs — the screening obligation

Firms must screen customers against PEP databases at onboarding and on an ongoing basis. This is where automated screening tools (like FinCrimeRadar) play a critical role — manual screening against the full universe of domestic and international PEPs is not practical at scale.

The FG25/3 approach — domestic vs foreign PEPs

PEP typeDefault risk under FG25/3EDD required?MLRO approval?
Foreign PEPHighAlwaysRequired (or delegated oversight)
UK domestic PEPLower (generally)Risk-basedNo longer automatic — MLRO oversight required
International org PEPMediumRisk-basedRisk-based
RCA (family/close associate)Medium-HighRisk-basedRisk-based
Former PEP (<12 months)Medium-HighRisk-based — document reasonsRisk-based
💡
Who is NOT a PEP under FG25/3?
The FCA's July 2025 guidance (FG25/3) confirms: non-executive board members of UK government departments are NOT PEPs; junior civil servants below senior grade are NOT PEPs; junior military officials are NOT PEPs. This addressed industry concerns that MPs' staffers, junior HMRC officials, and similar individuals were being treated as PEPs when their positions did not create meaningful corruption risk.
🔍 PEP screening in practice
See what PEP data looks like on a real screening tool
Try screening UK ministers, foreign heads of state, or central bank governors — and see how FinCrimeRadar displays PEP category, position, and country data.
Screen a PEP →
Obligation 03

Suspicious Activity Reports (SARs)

The SAR regime is one of the most important — and most legally exposed — aspects of AML compliance. Getting it wrong in either direction carries serious risk: fail to file and face criminal prosecution; file incorrectly and risk tipping off customers.

"The SAR is not a bureaucratic form. It is the mechanism by which the regulated sector shares financial intelligence with law enforcement — and filing one correctly can make the difference between catching and missing a criminal."

The SAR decision flowchart

🔍

Step 1 — Identify the suspicion

You know, suspect, or have reasonable grounds to suspect that a person is engaged in money laundering or terrorist financing. This can arise from CDD, transaction monitoring, adverse media, or staff reports.

📝

Step 2 — Internal report to MLRO

The employee submits an internal suspicious activity report (ISAR) to the MLRO. Do NOT discuss with the customer — tipping off risk. The MLRO must investigate promptly.

Immediately — do not delay
🤔

Step 3 — MLRO assessment

The MLRO reviews the ISAR and any supporting information. They must decide whether there are reasonable grounds to know or suspect ML/TF. This is an objective test — "would a reasonable person suspect?"

📤

Step 4 — Submit SAR to NCA (if grounds exist)

If the MLRO concludes there are grounds, a SAR must be submitted to the NCA's UKFIU via SAR Online. Where the transaction has not yet occurred, submit a DAML (consent request) SAR.

As soon as practicable / before transaction where possible

Step 5 — Await consent / proceed

For DAML SARs: the NCA has 7 working days to respond. Consent granted (or no response) = proceed. Consent refused = do NOT proceed. The MLRO must document all decisions including reasons for NOT filing a SAR.

What makes a good SAR?

The NCA and FCA have been explicit: quality matters more than quantity. A well-written SAR should include:

  • Who — full details of the subject (name, DOB, address, account numbers)
  • What — the specific suspicious activity, with amounts and dates
  • Why — why the activity is suspicious (not just a description of what happened)
  • When — dates and timeline of the suspicious activity
  • Where — jurisdictions, accounts, and institutions involved
  • How — the method used (cash, wire transfer, cryptocurrency, etc.)
🚨
Tipping off — the most common compliance error
Once a SAR has been filed (or is being considered), you must not disclose this to the customer or any third party in a way that could prejudice an investigation. Common tipping-off scenarios: closing an account without explanation immediately after filing a SAR; telling the customer their account is "under review for compliance reasons"; discussing the SAR with colleagues who don't need to know. The safest approach: maintain normal business conduct while the SAR is under investigation unless instructed otherwise by law enforcement.

SAR statistics — the scale of the regime

Metric2023/24
Total SARs submitted to UKFIU~900,000+
Percentage from banking sector~65%
DAML (consent) requests~35,000
Consent refused by NCA<1% of DAML requests
Value of assets refused under DAML£258 million+
🧠 Knowledge check
If you submit a DAML (consent) SAR to the NCA and receive no response, how long must you wait before proceeding with the transaction?
Obligation 04

Record keeping

Record keeping is the audit trail that proves compliance. Under Regulation 40 MLR 2017, firms must retain specific records for defined periods — and, critically, must delete personal data after the retention period under UK GDPR (with limited exceptions).

What records must be kept?

Record typeContentRetention period
CDD documentsIdentity documents, verification data, beneficial ownership records5 years from end of relationship
Transaction recordsRecords sufficient to reconstruct each transaction — amounts, dates, counterparties, accounts5 years from end of relationship
SAR recordsInternal reports, investigation notes, external SAR submissions, reasons for not filing5 years
Training recordsTraining plans, attendance records, assessment results, content delivered5 years
Firm-wide risk assessmentCurrent and all prior versions with approval records5 years
Policies and proceduresCurrent and all prior versions5 years
Transaction monitoringAlerts generated, investigations conducted, outcomes and rationale10 years in some cases to enable reconstruction
⚠️
The deletion obligation — MLR 2017 meets UK GDPR
MLR 2017 requires retention for 5 years. UK GDPR requires deletion when data is no longer needed. These obligations interact directly: after the 5-year retention period, you must delete personal data collected for AML purposes unless a specific exemption applies (e.g. ongoing legal proceedings, law enforcement request). Failure to delete is a UK GDPR breach. This means your AML record-keeping system must have automated deletion functionality — a manual process is unlikely to be reliable or auditable at scale. Note: record keeping requirements are not subject to the risk-based approach — there is no discretion on whether or how to comply.

What "sufficient to reconstruct" means

For transaction records, the test is whether the records enable the transaction to be fully reconstructed by law enforcement. This means you need to retain:

  • The amount and currency of each transaction
  • The date and time of the transaction
  • The originating and receiving accounts/parties
  • The payment reference and any narrative
  • The channel through which the transaction was made
  • Any screening alerts triggered and their resolution
📋 Screening audit trails
Every screening result should be part of your CDD record
FinCrimeRadar's results show you exactly what data was checked — use this to understand what a screening audit trail should contain.
Run a screen →
FAQ

Frequently asked questions

What is the difference between SDD, CDD, and EDD? +
All three are customer due diligence measures — they differ in intensity. Simplified Due Diligence (SDD) can be applied to demonstrably lower-risk customers (e.g. regulated financial institutions, listed companies) and requires less intensive checks. Standard CDD is the default — full identity verification, beneficial ownership identification, and ongoing monitoring. Enhanced Due Diligence (EDD) is mandatory for PEPs, certain correspondent relationships, high-risk third countries, and unusually complex transactions — it requires additional measures including source of funds/wealth, senior management approval, and enhanced monitoring. The firm's risk assessment determines which tier applies to each customer.
Can we rely on a third party to conduct CDD on our behalf? +
Yes — Regulation 39 MLR 2017 allows firms to rely on third parties to conduct CDD, provided: (1) the third party is itself a relevant person under MLR 2017 or is subject to equivalent requirements; (2) you have a written agreement requiring the third party to provide CDD data within 2 working days on request; (3) the third party retains records in accordance with MLR 2017. Critically: you cannot delegate liability. If the third party's CDD is inadequate, the relying firm remains responsible. The FCA has been clear that "we relied on our outsource partner" is not an adequate defence.
What is the "reasonable grounds" test for filing a SAR? +
The Section 330 POCA obligation to file a SAR is triggered when a person knows or suspects — or has reasonable grounds to know or suspect — that another person is engaged in ML/TF. "Reasonable grounds" is an objective test: would a reasonable person with the same information and training have suspected money laundering? This is lower than the civil standard of balance of probabilities. You do not need to be certain, or even more likely than not, that ML/TF is occurring. If a reasonable compliance professional would have suspected it, the obligation to file is triggered — regardless of whether you personally believed it was suspicious.
How do we handle CDD when a customer refuses to provide information? +
Under Regulation 31 MLR 2017, where a firm cannot complete CDD measures, it must: not carry out the transaction or establish the business relationship; terminate any existing business relationship; consider whether to file a SAR. A customer's refusal to provide CDD information is itself a potential red flag that should be documented and assessed. The FCA has been clear that "we could not obtain the documents" is not a reason to proceed with a relationship — if you cannot complete CDD, you should not have the customer. Note: the exit must be handled carefully to avoid tipping-off obligations if a SAR has been or is being considered.
Do the 5-year record retention periods run from the transaction date or the end of the relationship? +
For CDD documents and transaction records: the 5-year period runs from the end of the business relationship (or, for occasional transactions, from the date of the transaction). This means you retain all CDD and transaction records for the entire duration of the relationship PLUS 5 years after it ends. For SAR records: 5 years from the date the SAR was submitted. The practical implication: a 10-year customer relationship means records must be retained for 15 years total (10 years of relationship + 5 years after end), then deleted. Your data architecture must support this lifecycle management.