The five core compliance obligations
The Money Laundering Regulations 2017 impose five core operational obligations on every firm in scope. These are not optional best practices — they are legal requirements, breaches of which can result in FCA enforcement action, criminal prosecution of the MLRO, and unlimited fines.
Firm-wide risk assessment
Identify and document your organisation's exposure to ML/TF risk across products, customers, geographies, and channels.
Customer Due Diligence (CDD)
Identify and verify your customers and beneficial owners. Apply SDD, standard CDD, or EDD proportionate to risk.
Suspicious Activity Reports (SARs)
Report suspected money laundering or terrorist financing to the NCA via UKFIU as soon as practicable.
Record keeping
Retain CDD documents and transaction records for 5 years. Delete after 5 years under UK GDPR (with limited exceptions).
Staff training
Ensure all relevant employees understand AML law, the firm's risk assessment, CDD procedures, and how to report suspicions.
Firm-wide risk assessment
The firm-wide risk assessment (FWRA) is the foundation of your entire AML programme. Under Regulation 18 MLR 2017, every relevant person must identify and assess the risks of money laundering and terrorist financing to which their business is subject — and must document this assessment in writing.
What the FWRA must cover
The MLR 2017 specifies that the FWRA must take into account at least the following risk factors:
- Nature and complexity of products
- Cash handling volumes
- Cross-border payment capabilities
- Anonymity features (e.g. e-money)
- Virtual asset services
- High-risk third countries (FATF lists)
- Countries with weak AML regimes
- Offshore financial centres
- Conflict zones and sanctioned countries
- PEPs and their associates
- Cash-intensive businesses
- Non-face-to-face customers
- Complex ownership structures
- High-net-worth individuals
- Online/digital onboarding
- Third-party intermediaries
- Correspondent relationships
- Mobile payment channels
The risk assessment process
Identify inherent risks
What ML/TF risks exist in your business before controls are applied? Consider each risk factor category above.
Assess risk level
Rate each inherent risk: High / Medium / Low. Document your methodology and rationale.
Identify mitigating controls
What controls does the firm have in place to reduce each identified risk?
Assess residual risk
After applying controls, what risk remains? This is your residual risk — the basis for your ongoing monitoring.
Approve and document
The FWRA must be approved by senior management and reviewed regularly (typically annually, or when risks change materially).
Customer Due Diligence (CDD)
Customer Due Diligence is the process of identifying and verifying your customers — and, for legal entities, their beneficial owners. It is the cornerstone of AML compliance: if you do not know who you are dealing with, you cannot assess the risk they present.
The three tiers of CDD
Simplified Due Diligence (SDD)
Applied where risk is demonstrably low. Less intensive checks — though basic identity verification is still required.
- Listed companies on regulated markets
- UK public authorities
- Low-value e-money products (≤€150)
- Regulated financial institutions
Standard CDD
The default level. Identify the customer, verify identity, understand the relationship, and conduct ongoing monitoring.
- Verify name, address, DOB (individuals)
- Identify UBO (>25% ownership threshold)
- Understand purpose of relationship
- Ongoing monitoring of transactions
Enhanced Due Diligence (EDD)
Mandatory for PEPs, high-risk third countries, and other elevated risk situations. More intrusive checks required.
- Source of funds verification
- Source of wealth documentation
- Senior management approval
- Enhanced ongoing monitoring
Standard CDD — what must you collect?
For individuals:
- Full name
- Date of birth
- Residential address
- Verification documents (passport, driving licence, utility bill — reliable, independent sources)
For legal entities (companies, partnerships, trusts):
- Name, legal form, registered address
- Constitutional documents (articles of association, trust deed)
- Names of senior persons responsible for operations
- Identification of ultimate beneficial owners (UBOs) — individuals owning >25% shares or voting rights, or exercising significant control
- Verification of UBO identity
When must CDD be conducted?
| Trigger | CDD required? | Notes |
|---|---|---|
| Establishing a business relationship | ✅ Yes — before or during | Must complete before proceeding in most cases |
| Occasional transaction ≥€15,000 | ✅ Yes | Single or linked transactions |
| Suspicion of ML/TF | ✅ Yes — regardless of thresholds | Even if relationship pre-dates suspicion |
| Doubt about previous verification | ✅ Yes | Refresh CDD when reliability doubted |
| Periodic review (existing customers) | ✅ Yes — risk-based | High risk: annually; Medium: 2–3yr; Low: 3–5yr |
| Change in customer circumstances | ✅ Yes — trigger-based | Change of ownership, new product, higher risk activity |
Enhanced Due Diligence (EDD)
Enhanced Due Diligence is mandatory — not discretionary — in certain circumstances defined by MLR 2017. It requires additional measures beyond standard CDD to manage elevated risks.
When is EDD mandatory?
- Politically Exposed Persons (PEPs) — and their family members and known close associates
- Correspondent banking relationships — between credit or financial institutions
- High-risk third countries — from July 2025 reforms, limited to FATF "Call for Action" (blacklist) countries
- Unusually complex transactions — from July 2025 MLR reforms, narrowed from "all complex transactions"
- Any other situation assessed as high risk — under the firm's risk-based approach
What does EDD involve?
- Source of funds (SoF) — documentary evidence of where the specific funds being used originate (e.g. sale proceeds, salary, inheritance)
- Source of wealth (SoW) — broader evidence of how the customer accumulated their overall wealth (e.g. business ownership, investment history, inheritance)
- Senior management approval — the business relationship must be approved by senior management before proceeding
- Enhanced ongoing monitoring — more frequent transaction reviews, lower thresholds for alert generation
- Purpose of the relationship — detailed understanding of why the customer needs the product/service
PEP screening and due diligence
PEP screening is a mandatory component of CDD for all regulated firms. The key question is not just "is this person a PEP?" — it is "what EDD measures are proportionate to the risk this particular PEP presents?"
Identifying PEPs — the screening obligation
Firms must screen customers against PEP databases at onboarding and on an ongoing basis. This is where automated screening tools (like FinCrimeRadar) play a critical role — manual screening against the full universe of domestic and international PEPs is not practical at scale.
The FG25/3 approach — domestic vs foreign PEPs
| PEP type | Default risk under FG25/3 | EDD required? | MLRO approval? |
|---|---|---|---|
| Foreign PEP | High | Always | Required (or delegated oversight) |
| UK domestic PEP | Lower (generally) | Risk-based | No longer automatic — MLRO oversight required |
| International org PEP | Medium | Risk-based | Risk-based |
| RCA (family/close associate) | Medium-High | Risk-based | Risk-based |
| Former PEP (<12 months) | Medium-High | Risk-based — document reasons | Risk-based |
Suspicious Activity Reports (SARs)
The SAR regime is one of the most important — and most legally exposed — aspects of AML compliance. Getting it wrong in either direction carries serious risk: fail to file and face criminal prosecution; file incorrectly and risk tipping off customers.
The SAR decision flowchart
Step 1 — Identify the suspicion
You know, suspect, or have reasonable grounds to suspect that a person is engaged in money laundering or terrorist financing. This can arise from CDD, transaction monitoring, adverse media, or staff reports.
Step 2 — Internal report to MLRO
The employee submits an internal suspicious activity report (ISAR) to the MLRO. Do NOT discuss with the customer — tipping off risk. The MLRO must investigate promptly.
Step 3 — MLRO assessment
The MLRO reviews the ISAR and any supporting information. They must decide whether there are reasonable grounds to know or suspect ML/TF. This is an objective test — "would a reasonable person suspect?"
Step 4 — Submit SAR to NCA (if grounds exist)
If the MLRO concludes there are grounds, a SAR must be submitted to the NCA's UKFIU via SAR Online. Where the transaction has not yet occurred, submit a DAML (consent request) SAR.
Step 5 — Await consent / proceed
For DAML SARs: the NCA has 7 working days to respond. Consent granted (or no response) = proceed. Consent refused = do NOT proceed. The MLRO must document all decisions including reasons for NOT filing a SAR.
What makes a good SAR?
The NCA and FCA have been explicit: quality matters more than quantity. A well-written SAR should include:
- Who — full details of the subject (name, DOB, address, account numbers)
- What — the specific suspicious activity, with amounts and dates
- Why — why the activity is suspicious (not just a description of what happened)
- When — dates and timeline of the suspicious activity
- Where — jurisdictions, accounts, and institutions involved
- How — the method used (cash, wire transfer, cryptocurrency, etc.)
SAR statistics — the scale of the regime
| Metric | 2023/24 |
|---|---|
| Total SARs submitted to UKFIU | ~900,000+ |
| Percentage from banking sector | ~65% |
| DAML (consent) requests | ~35,000 |
| Consent refused by NCA | <1% of DAML requests |
| Value of assets refused under DAML | £258 million+ |
Record keeping
Record keeping is the audit trail that proves compliance. Under Regulation 40 MLR 2017, firms must retain specific records for defined periods — and, critically, must delete personal data after the retention period under UK GDPR (with limited exceptions).
What records must be kept?
| Record type | Content | Retention period |
|---|---|---|
| CDD documents | Identity documents, verification data, beneficial ownership records | 5 years from end of relationship |
| Transaction records | Records sufficient to reconstruct each transaction — amounts, dates, counterparties, accounts | 5 years from end of relationship |
| SAR records | Internal reports, investigation notes, external SAR submissions, reasons for not filing | 5 years |
| Training records | Training plans, attendance records, assessment results, content delivered | 5 years |
| Firm-wide risk assessment | Current and all prior versions with approval records | 5 years |
| Policies and procedures | Current and all prior versions | 5 years |
| Transaction monitoring | Alerts generated, investigations conducted, outcomes and rationale | 10 years in some cases to enable reconstruction |
What "sufficient to reconstruct" means
For transaction records, the test is whether the records enable the transaction to be fully reconstructed by law enforcement. This means you need to retain:
- The amount and currency of each transaction
- The date and time of the transaction
- The originating and receiving accounts/parties
- The payment reference and any narrative
- The channel through which the transaction was made
- Any screening alerts triggered and their resolution