Five core compliance obligations, FinCrimeRadar's practical grouping
The Money Laundering Regulations 2017 impose numerous specific legal requirements. For working purposes, we group them here into five core operational obligations every firm in scope needs to get right, this is FinCrimeRadar's own editorial grouping for practical clarity, not a fixed statutory list of five items. Each requirement within it, however grouped, is a genuine legal requirement, breaches of which can result in FCA enforcement action, criminal prosecution of the MLRO, and unlimited fines.
Firm-wide risk assessment
Identify and document your organisation's exposure to ML/TF risk across products, customers, geographies, and channels.
Customer Due Diligence (CDD)
Identify and verify your customers and beneficial owners. Apply SDD, standard CDD, or EDD proportionate to risk.
Suspicious Activity Reports (SARs)
Report suspected money laundering or terrorist financing to the NCA via UKFIU as soon as practicable.
Record keeping
Retain CDD documents and transaction records for 5 years. Delete after 5 years under UK GDPR (with limited exceptions).
Staff training
Ensure all relevant employees understand AML law, the firm's risk assessment, CDD procedures, and how to report suspicions.
Firm-wide risk assessment
The firm-wide risk assessment (FWRA) is the foundation of your entire AML programme. Under Regulation 18(1) MLR 2017, every relevant person must take appropriate steps to identify and assess the risks of money laundering and terrorist financing to which their business is subject, considering the factors listed in Regulation 18(2). Regulation 18(4) requires the firm to keep an up-to-date written record of those steps, unless its supervisory authority has notified it in writing that a written record isn't required, a firm-specific exemption, not a default option. Separately, Regulation 18A requires an equivalent risk assessment for proliferation financing, considering the same categories of risk factor, it is not covered by the ML/TF assessment under Regulation 18.
What the FWRA must cover
The MLR 2017 specifies that the FWRA must take into account at least the following risk factors:
- Nature and complexity of products
- Cash handling volumes
- Cross-border payment capabilities
- Anonymity features (e.g. e-money)
- Virtual asset services
- High-risk third countries (FATF lists)
- Countries with weak AML regimes
- Offshore financial centres
- Conflict zones and sanctioned countries
- PEPs and their associates
- Cash-intensive businesses
- Non-face-to-face customers
- Complex ownership structures
- High-net-worth individuals
- Online/digital onboarding
- Third-party intermediaries
- Correspondent relationships
- Mobile payment channels
The risk assessment process
Identify inherent risks
What ML/TF risks exist in your business before controls are applied? Consider each risk factor category above.
Assess risk level
Rate each inherent risk: High / Medium / Low. Document your methodology and rationale.
Identify mitigating controls
What controls does the firm have in place to reduce each identified risk?
Assess residual risk
After applying controls, what risk remains? This is your residual risk: the basis for your ongoing monitoring.
Approve and document
The FWRA must be approved by senior management and reviewed regularly (typically annually, or when risks change materially).
Customer Due Diligence (CDD)
Customer Due Diligence is the process of identifying and verifying your customers, and, for legal entities, their beneficial owners. It is the cornerstone of AML compliance: if you do not know who you are dealing with, you cannot assess the risk they present.
The three tiers of CDD
Simplified Due Diligence (SDD)
Applied on a risk-based determination where risk is demonstrably low, not automatically because a customer falls into a category. Basic identity verification is still required.
- Being a public authority, publicly owned enterprise, listed company on a regulated market, or regulated financial institution is a lower-risk factor to weigh under Reg 37(3), not an automatic SDD class on its own
- Low-value e-money is a separate, conditional full CDD exemption under Reg 38, not SDD: non-reloadable, used only for goods/services, no anonymous funding, capped at โฌ150 stored value with a โฌ100 cash redemption limit
Standard CDD
The default level. Identify the customer, verify identity, understand the relationship, and conduct ongoing monitoring.
- Verify name, address, DOB (individuals)
- Identify UBO (Reg 5: over 25% shares/voting rights, or a separate management/control test, either limb qualifies)
- Understand purpose of relationship
- Ongoing monitoring of transactions
Enhanced Due Diligence (EDD)
Mandatory for PEPs, high-risk third countries, and other elevated risk situations. More intrusive checks required.
- Source of funds verification
- Source of wealth documentation
- Senior management approval
- Enhanced ongoing monitoring
Standard CDD: what must you collect?
For individuals:
- Full name
- Date of birth
- Residential address
- Verification documents (passport, driving licence, utility bill: reliable, independent sources)
For legal entities (companies, partnerships, trusts):
- Name, legal form, registered address
- Constitutional documents (articles of association, trust deed)
- Names of senior persons responsible for operations
- Identification of ultimate beneficial owners (UBOs): Reg 5 sets two separate limbs, an individual owning or controlling more than 25% of shares or voting rights, or an individual exercising ultimate control over management, meeting either limb is enough
- Verification of UBO identity
When must CDD be conducted?
| Trigger | CDD required? | Notes |
|---|---|---|
| Establishing a business relationship | โ Yes, before or during | Must complete before proceeding in most cases |
| Occasional transaction โฅโฌ15,000 | โ Yes | Single or linked transactions |
| Suspicion of ML/TF | โ Yes, regardless of thresholds | Even if relationship pre-dates suspicion |
| Doubt about previous verification | โ Yes | Refresh CDD when reliability doubted |
| Periodic review (existing customers) | โ Yes, risk-based | Illustrative cycle, not a statutory requirement: firms commonly use annual for high risk, 2-3yr medium, 3-5yr low, set your own per your risk assessment |
| Change in customer circumstances | โ Yes, trigger-based | Change of ownership, new product, higher risk activity |
Enhanced Due Diligence (EDD)
Enhanced Due Diligence is mandatory, not discretionary, in certain circumstances defined by MLR 2017. Which specific measures are actually required depends on why EDD is triggered, though: Regulation 33(3A) sets a fixed package for FATF "Call for Action" countries specifically, other high-risk cases instead use Regulation 33(5)'s proportionate, risk-based measures, not that same fixed package as a default.
When is EDD mandatory?
- Politically Exposed Persons (PEPs): and their family members and known close associates
- Correspondent banking relationships: between credit or financial institutions
- High-risk third countries: from July 2025 reforms, limited to FATF "Call for Action" (blacklist) countries
- Unusually complex transactions: from July 2025 MLR reforms, narrowed from "all complex transactions"
- Any other situation assessed as high risk: under the firm's risk-based approach
What does EDD actually require?
For customers connected to a FATF "Call for Action" country, Regulation 33(3A) sets a fixed six-part package: additional information on the customer and beneficial owner, on the intended nature of the relationship, on source of funds and source of wealth, on the reasons for the transactions, senior management approval, and enhanced ongoing monitoring. For other high-risk cases, Regulation 33(5) instead lists measures a firm "may" apply, proportionate to the risk actually identified, not a fixed checklist, seeking additional independent sources to verify information, and better understanding the customer's background, ownership, and financial situation, among others. In practice, the measures below are commonly applied across both routes, but they are a fixed legal requirement only in the Regulation 33(3A) case:
- Source of funds (SoF): documentary evidence of where the specific funds being used originate (e.g. sale proceeds, salary, inheritance)
- Source of wealth (SoW): broader evidence of how the customer accumulated their overall wealth (e.g. business ownership, investment history, inheritance)
- Senior management approval: the business relationship must be approved by senior management before proceeding
- Enhanced ongoing monitoring: more frequent transaction reviews, lower thresholds for alert generation
- Purpose of the relationship: detailed understanding of why the customer needs the product/service
PEP screening and due diligence
PEP screening is a mandatory component of CDD for all regulated firms. The key question is not just "is this person a PEP?": it is "what EDD measures are proportionate to the risk this particular PEP presents?"
Identifying PEPs: the screening obligation
Firms must screen customers against PEP databases at onboarding and on an ongoing basis. This is where automated screening tools (like FinCrimeRadar) play a critical role: manual screening against the full universe of domestic and international PEPs is not practical at scale.
The FG25/3 approach: domestic vs foreign PEPs
| PEP type | Default risk under FG25/3 | EDD required? | MLRO approval? |
|---|---|---|---|
| Foreign PEP | High | Always | Required (or delegated oversight) |
| UK domestic PEP | Lower (generally) | Risk-based | No longer automatic, MLRO oversight required |
| International org PEP | Medium | Risk-based | Risk-based |
| RCA (family/close associate) | Medium-High | Risk-based | Risk-based |
| Former PEP (<12 months) | Medium-High | Risk-based, document reasons | Risk-based |
Suspicious Activity Reports (SARs)
The SAR regime is one of the most important, and most legally exposed, aspects of AML compliance. Getting it wrong in either direction carries serious risk: fail to file and face criminal prosecution; file incorrectly and risk tipping off customers.
The SAR decision flowchart
Step 1: Identify the suspicion
You know, suspect, or have reasonable grounds to suspect that a person is engaged in money laundering or terrorist financing. This can arise from CDD, transaction monitoring, adverse media, or staff reports.
Step 2: Internal report to MLRO
The employee submits an internal suspicious activity report (ISAR) to the MLRO. Do NOT discuss with the customer: tipping off risk. The MLRO must investigate promptly.
Step 3: MLRO assessment
The MLRO reviews the ISAR and any supporting information. They must decide whether there are reasonable grounds to know or suspect ML/TF. This is an objective test: "would a reasonable person suspect?"
Step 4: Submit SAR to NCA (if grounds exist)
If the MLRO concludes there are grounds, a SAR must be submitted to the NCA's UKFIU via the SAR Portal. Where the transaction has not yet occurred, submit a DAML (consent request) SAR.
Step 5: Await consent / proceed
For DAML SARs: the NCA has 7 working days (the statutory notice period) to respond. Consent granted, or no response within that period (deemed consent), means you may proceed. Consent refused starts a 31-day statutory moratorium period during which you must not proceed; this can be extended by court order in further 31-day increments up to 186 days total (Criminal Finances Act 2017 s.10, inserting POCA s.336A), after which, absent a restraint or forfeiture order, the transaction may proceed. The MLRO must document all decisions including reasons for NOT filing a SAR.
What makes a good SAR?
The NCA and FCA have been explicit: quality matters more than quantity. A well-written SAR should include:
- Who: full details of the subject (name, DOB, address, account numbers)
- What: the specific suspicious activity, with amounts and dates
- Why: why the activity is suspicious (not just a description of what happened)
- When: dates and timeline of the suspicious activity
- Where: jurisdictions, accounts, and institutions involved
- How: the method used (cash, wire transfer, cryptocurrency, etc.)
SAR statistics: the scale of the regime
| Metric | 2024/25 | 2023/24 |
|---|---|---|
| Total SARs submitted to UKFIU | 866,616 | 872,048 |
| Percentage from banking sector | ~85.5% | ~78.5% |
| DAML (consent) requests | 57,666 | 57,081 |
| DAML requests refused by NCA | 3,276 (~6%) | 2,881 (~5%) |
| Value of assets denied under DAML | ยฃ382.6 million | ยฃ240.1 million |
Source: NCA UKFIU SARs Annual Report 2024/25 (the most recent published), with the prior year shown for trend.
Record keeping
Record keeping is the audit trail that proves compliance. Under Regulation 40(3) MLR 2017, firms must retain specific records for a five-year statutory period (up to 10 years in some cases for transaction records, Regulation 40(4)), and, critically, must delete personal data after the retention period under UK GDPR, subject to Regulation 40(5)'s own statutory exceptions.
What records must be kept?
| Record type | Content | Retention period |
|---|---|---|
| CDD documents | Identity documents, verification data, beneficial ownership records | 5 years from end of relationship |
| Transaction records | Records sufficient to reconstruct each transaction: amounts, dates, counterparties, accounts | 5 years from end of relationship |
| SAR records | Internal reports, investigation notes, external SAR submissions, reasons for not filing | 5 years |
| Training records | Training plans, attendance records, assessment results, content delivered | No fixed period under Regulation 24, a written record is required but its retention duration isn't specified; many firms align it to 5 years as a matter of policy, not a Reg 40 requirement |
| Firm-wide risk assessment | Current and all prior versions with approval records | 5 years |
| Policies and procedures | Current and all prior versions | 5 years |
| Transaction monitoring | Alerts generated, investigations conducted, outcomes and rationale | 10 years in some cases to enable reconstruction |
What "sufficient to reconstruct" means
For transaction records, the test is whether the records enable the transaction to be fully reconstructed by law enforcement. This means you need to retain:
- The amount and currency of each transaction
- The date and time of the transaction
- The originating and receiving accounts/parties
- The payment reference and any narrative
- The channel through which the transaction was made
- Any screening alerts triggered and their resolution