Introduction

Five core compliance obligations, FinCrimeRadar's practical grouping

The Money Laundering Regulations 2017 impose numerous specific legal requirements. For working purposes, we group them here into five core operational obligations every firm in scope needs to get right, this is FinCrimeRadar's own editorial grouping for practical clarity, not a fixed statutory list of five items. Each requirement within it, however grouped, is a genuine legal requirement, breaches of which can result in FCA enforcement action, criminal prosecution of the MLRO, and unlimited fines.

1

Firm-wide risk assessment

Identify and document your organisation's exposure to ML/TF risk across products, customers, geographies, and channels.

2

Customer Due Diligence (CDD)

Identify and verify your customers and beneficial owners. Apply SDD, standard CDD, or EDD proportionate to risk.

3

Suspicious Activity Reports (SARs)

Report suspected money laundering or terrorist financing to the NCA via UKFIU as soon as practicable.

4

Record keeping

Retain CDD documents and transaction records for 5 years. Delete after 5 years under UK GDPR (with limited exceptions).

5

Staff training

Ensure all relevant employees understand AML law, the firm's risk assessment, CDD procedures, and how to report suspicions.

MLR 2017 is not a compliance checklist, in our view. It is a risk-based framework, and the FCA assesses whether your controls are proportionate to the risks your firm actually faces, not whether you have ticked boxes.
Obligation 01

Firm-wide risk assessment

The firm-wide risk assessment (FWRA) is the foundation of your entire AML programme. Under Regulation 18(1) MLR 2017, every relevant person must take appropriate steps to identify and assess the risks of money laundering and terrorist financing to which their business is subject, considering the factors listed in Regulation 18(2). Regulation 18(4) requires the firm to keep an up-to-date written record of those steps, unless its supervisory authority has notified it in writing that a written record isn't required, a firm-specific exemption, not a default option. Separately, Regulation 18A requires an equivalent risk assessment for proliferation financing, considering the same categories of risk factor, it is not covered by the ML/TF assessment under Regulation 18.

What the FWRA must cover

The MLR 2017 specifies that the FWRA must take into account at least the following risk factors:

๐Ÿข Products & services
  • Nature and complexity of products
  • Cash handling volumes
  • Cross-border payment capabilities
  • Anonymity features (e.g. e-money)
  • Virtual asset services
๐ŸŒ Geographic risk
  • High-risk third countries (FATF lists)
  • Countries with weak AML regimes
  • Offshore financial centres
  • Conflict zones and sanctioned countries
๐Ÿ‘ฅ Customer risk
  • PEPs and their associates
  • Cash-intensive businesses
  • Non-face-to-face customers
  • Complex ownership structures
  • High-net-worth individuals
๐Ÿ“ก Delivery channels
  • Online/digital onboarding
  • Third-party intermediaries
  • Correspondent relationships
  • Mobile payment channels

The risk assessment process

1

Identify inherent risks

What ML/TF risks exist in your business before controls are applied? Consider each risk factor category above.

2

Assess risk level

Rate each inherent risk: High / Medium / Low. Document your methodology and rationale.

3

Identify mitigating controls

What controls does the firm have in place to reduce each identified risk?

4

Assess residual risk

After applying controls, what risk remains? This is your residual risk: the basis for your ongoing monitoring.

5

Approve and document

The FWRA must be approved by senior management and reviewed regularly (typically annually, or when risks change materially).

โš ๏ธ
Common FCA finding: generic risk assessments
The FCA's multi-firm review of risk assessment processes and controls (published 11 November 2025) found that while most firms had a business-wide risk assessment on paper, many were too generic or not tailored to the specific business, some oversimplified their risks and failed to explain how each one actually affected the firm. A risk assessment that could apply to any payment firm in the sector is unlikely to satisfy the FCA. Your FWRA should reflect your specific products, your specific customers, your specific geographies, not a template.
๐Ÿ” Risk assessment in practice
Customer screening is part of your risk assessment controls
Sanctions, PEP, and adverse media screening are key risk assessment tools. Try FinCrimeRadar to understand what a screening control delivers.
Try the tool โ†’
Obligation 02

Customer Due Diligence (CDD)

Customer Due Diligence is the process of identifying and verifying your customers, and, for legal entities, their beneficial owners. It is the cornerstone of AML compliance: if you do not know who you are dealing with, you cannot assess the risk they present.

The three tiers of CDD

๐ŸŸข Lower risk

Simplified Due Diligence (SDD)

Applied on a risk-based determination where risk is demonstrably low, not automatically because a customer falls into a category. Basic identity verification is still required.

  • Being a public authority, publicly owned enterprise, listed company on a regulated market, or regulated financial institution is a lower-risk factor to weigh under Reg 37(3), not an automatic SDD class on its own
  • Low-value e-money is a separate, conditional full CDD exemption under Reg 38, not SDD: non-reloadable, used only for goods/services, no anonymous funding, capped at โ‚ฌ150 stored value with a โ‚ฌ100 cash redemption limit
๐Ÿ”ต Standard risk

Standard CDD

The default level. Identify the customer, verify identity, understand the relationship, and conduct ongoing monitoring.

  • Verify name, address, DOB (individuals)
  • Identify UBO (Reg 5: over 25% shares/voting rights, or a separate management/control test, either limb qualifies)
  • Understand purpose of relationship
  • Ongoing monitoring of transactions
๐Ÿ”ด Higher risk

Enhanced Due Diligence (EDD)

Mandatory for PEPs, high-risk third countries, and other elevated risk situations. More intrusive checks required.

  • Source of funds verification
  • Source of wealth documentation
  • Senior management approval
  • Enhanced ongoing monitoring

Standard CDD: what must you collect?

For individuals:

  • Full name
  • Date of birth
  • Residential address
  • Verification documents (passport, driving licence, utility bill: reliable, independent sources)

For legal entities (companies, partnerships, trusts):

  • Name, legal form, registered address
  • Constitutional documents (articles of association, trust deed)
  • Names of senior persons responsible for operations
  • Identification of ultimate beneficial owners (UBOs): Reg 5 sets two separate limbs, an individual owning or controlling more than 25% of shares or voting rights, or an individual exercising ultimate control over management, meeting either limb is enough
  • Verification of UBO identity

When must CDD be conducted?

TriggerCDD required?Notes
Establishing a business relationshipโœ… Yes, before or duringMust complete before proceeding in most cases
Occasional transaction โ‰ฅโ‚ฌ15,000โœ… YesSingle or linked transactions
Suspicion of ML/TFโœ… Yes, regardless of thresholdsEven if relationship pre-dates suspicion
Doubt about previous verificationโœ… YesRefresh CDD when reliability doubted
Periodic review (existing customers)โœ… Yes, risk-basedIllustrative cycle, not a statutory requirement: firms commonly use annual for high risk, 2-3yr medium, 3-5yr low, set your own per your risk assessment
Change in customer circumstancesโœ… Yes, trigger-basedChange of ownership, new product, higher risk activity
๐Ÿ’ก
Beneficial ownership: ownership OR control, not one blended test
Under MLR 2017 Regulation 5, you must identify any individual who owns or controls more than 25% of shares or voting rights in a legal entity, or, on a separate limb, any individual who exercises ultimate control over its management, either limb qualifies on its own. This threshold is a minimum, not a ceiling: where risks are higher, you should look through lower ownership levels. Only once you have exhausted all possible means of identifying a beneficial owner under Regulation 28(6)-(7), and recorded in writing the actions taken and the difficulties encountered, may you treat the senior managing official as the beneficial owner instead (Reg 28(8)), both conditions have to be met, this is a documented last resort, not a shortcut for whenever no one obviously clears 25%.
๐Ÿง  Knowledge check
Under MLR 2017 Regulation 5, what is the ownership/voting-rights threshold on the ownership limb of the beneficial-owner test (the separate control limb has no percentage threshold)?
๐Ÿ” CDD in practice
Screening is a core component of CDD: try it here
Sanctions and PEP screening are required as part of CDD for regulated firms. Enter a customer name to see what a compliant screening check reveals.
Run a CDD screen โ†’
Obligation 02b

Enhanced Due Diligence (EDD)

Enhanced Due Diligence is mandatory, not discretionary, in certain circumstances defined by MLR 2017. Which specific measures are actually required depends on why EDD is triggered, though: Regulation 33(3A) sets a fixed package for FATF "Call for Action" countries specifically, other high-risk cases instead use Regulation 33(5)'s proportionate, risk-based measures, not that same fixed package as a default.

When is EDD mandatory?

  • Politically Exposed Persons (PEPs): and their family members and known close associates
  • Correspondent banking relationships: between credit or financial institutions
  • High-risk third countries: from July 2025 reforms, limited to FATF "Call for Action" (blacklist) countries
  • Unusually complex transactions: from July 2025 MLR reforms, narrowed from "all complex transactions"
  • Any other situation assessed as high risk: under the firm's risk-based approach

What does EDD actually require?

For customers connected to a FATF "Call for Action" country, Regulation 33(3A) sets a fixed six-part package: additional information on the customer and beneficial owner, on the intended nature of the relationship, on source of funds and source of wealth, on the reasons for the transactions, senior management approval, and enhanced ongoing monitoring. For other high-risk cases, Regulation 33(5) instead lists measures a firm "may" apply, proportionate to the risk actually identified, not a fixed checklist, seeking additional independent sources to verify information, and better understanding the customer's background, ownership, and financial situation, among others. In practice, the measures below are commonly applied across both routes, but they are a fixed legal requirement only in the Regulation 33(3A) case:

  • Source of funds (SoF): documentary evidence of where the specific funds being used originate (e.g. sale proceeds, salary, inheritance)
  • Source of wealth (SoW): broader evidence of how the customer accumulated their overall wealth (e.g. business ownership, investment history, inheritance)
  • Senior management approval: the business relationship must be approved by senior management before proceeding
  • Enhanced ongoing monitoring: more frequent transaction reviews, lower thresholds for alert generation
  • Purpose of the relationship: detailed understanding of why the customer needs the product/service
๐Ÿ†•
July 2025 reform: EDD scope narrowed
HM Treasury's July 2025 MLR reform response confirms that EDD obligations will be narrowed: (1) EDD for "complex" transactions will be limited to "unusually complex" transactions, reducing burden on firms dealing with routine cross-border payments; (2) For high-risk third countries, EDD will now only be required for jurisdictions on the FATF "Call for Action" list (the FATF blacklist), rather than all countries on the FATF monitoring list. This is a significant reduction in EDD scope for many payment firms.
Obligation 02c

PEP screening and due diligence

PEP screening is a mandatory component of CDD for all regulated firms. The key question is not just "is this person a PEP?": it is "what EDD measures are proportionate to the risk this particular PEP presents?"

Identifying PEPs: the screening obligation

Firms must screen customers against PEP databases at onboarding and on an ongoing basis. This is where automated screening tools (like FinCrimeRadar) play a critical role: manual screening against the full universe of domestic and international PEPs is not practical at scale.

The FG25/3 approach: domestic vs foreign PEPs

PEP typeDefault risk under FG25/3EDD required?MLRO approval?
Foreign PEPHighAlwaysRequired (or delegated oversight)
UK domestic PEPLower (generally)Risk-basedNo longer automatic, MLRO oversight required
International org PEPMediumRisk-basedRisk-based
RCA (family/close associate)Medium-HighRisk-basedRisk-based
Former PEP (<12 months)Medium-HighRisk-based, document reasonsRisk-based
๐Ÿ’ก
Who is NOT a PEP under FG25/3?
The FCA's July 2025 guidance (FG25/3) confirms: non-executive board members of UK government departments are NOT PEPs; junior civil servants below senior grade are NOT PEPs; junior military officials are NOT PEPs. This addressed industry concerns that MPs' staffers, junior HMRC officials, and similar individuals were being treated as PEPs when their positions did not create meaningful corruption risk.
๐Ÿ” PEP screening in practice
See what PEP data looks like on a real screening tool
Try screening UK ministers, foreign heads of state, or central bank governors, and see how FinCrimeRadar displays PEP category, position, and country data.
Screen a PEP โ†’
Obligation 03

Suspicious Activity Reports (SARs)

The SAR regime is one of the most important, and most legally exposed, aspects of AML compliance. Getting it wrong in either direction carries serious risk: fail to file and face criminal prosecution; file incorrectly and risk tipping off customers.

"The SAR is not a bureaucratic form. It is the mechanism by which the regulated sector shares financial intelligence with law enforcement, and filing one correctly can make the difference between catching and missing a criminal."

The SAR decision flowchart

๐Ÿ”

Step 1: Identify the suspicion

You know, suspect, or have reasonable grounds to suspect that a person is engaged in money laundering or terrorist financing. This can arise from CDD, transaction monitoring, adverse media, or staff reports.

โ†“
๐Ÿ“

Step 2: Internal report to MLRO

The employee submits an internal suspicious activity report (ISAR) to the MLRO. Do NOT discuss with the customer: tipping off risk. The MLRO must investigate promptly.

Immediately, do not delay
โ†“
๐Ÿค”

Step 3: MLRO assessment

The MLRO reviews the ISAR and any supporting information. They must decide whether there are reasonable grounds to know or suspect ML/TF. This is an objective test: "would a reasonable person suspect?"

โ†“
๐Ÿ“ค

Step 4: Submit SAR to NCA (if grounds exist)

If the MLRO concludes there are grounds, a SAR must be submitted to the NCA's UKFIU via the SAR Portal. Where the transaction has not yet occurred, submit a DAML (consent request) SAR.

As soon as practicable / before transaction where possible
โ†“
โœ…

Step 5: Await consent / proceed

For DAML SARs: the NCA has 7 working days (the statutory notice period) to respond. Consent granted, or no response within that period (deemed consent), means you may proceed. Consent refused starts a 31-day statutory moratorium period during which you must not proceed; this can be extended by court order in further 31-day increments up to 186 days total (Criminal Finances Act 2017 s.10, inserting POCA s.336A), after which, absent a restraint or forfeiture order, the transaction may proceed. The MLRO must document all decisions including reasons for NOT filing a SAR.

What makes a good SAR?

The NCA and FCA have been explicit: quality matters more than quantity. A well-written SAR should include:

  • Who: full details of the subject (name, DOB, address, account numbers)
  • What: the specific suspicious activity, with amounts and dates
  • Why: why the activity is suspicious (not just a description of what happened)
  • When: dates and timeline of the suspicious activity
  • Where: jurisdictions, accounts, and institutions involved
  • How: the method used (cash, wire transfer, cryptocurrency, etc.)
๐Ÿšจ
Tipping off: the most common compliance error
Once a SAR has been filed (or is being considered), you must not disclose this to the customer or any third party in a way that could prejudice an investigation. Common tipping-off scenarios: closing an account without explanation immediately after filing a SAR; telling the customer their account is "under review for compliance reasons"; discussing the SAR with colleagues who don't need to know. The safest approach: maintain normal business conduct while the SAR is under investigation unless instructed otherwise by law enforcement.

SAR statistics: the scale of the regime

Metric2024/252023/24
Total SARs submitted to UKFIU866,616872,048
Percentage from banking sector~85.5%~78.5%
DAML (consent) requests57,66657,081
DAML requests refused by NCA3,276 (~6%)2,881 (~5%)
Value of assets denied under DAMLยฃ382.6 millionยฃ240.1 million

Source: NCA UKFIU SARs Annual Report 2024/25 (the most recent published), with the prior year shown for trend.

๐Ÿง  Knowledge check
If you submit a DAML (consent) SAR to the NCA and receive no response, how long must you wait before proceeding with the transaction?
Obligation 04

Record keeping

Record keeping is the audit trail that proves compliance. Under Regulation 40(3) MLR 2017, firms must retain specific records for a five-year statutory period (up to 10 years in some cases for transaction records, Regulation 40(4)), and, critically, must delete personal data after the retention period under UK GDPR, subject to Regulation 40(5)'s own statutory exceptions.

What records must be kept?

Record typeContentRetention period
CDD documentsIdentity documents, verification data, beneficial ownership records5 years from end of relationship
Transaction recordsRecords sufficient to reconstruct each transaction: amounts, dates, counterparties, accounts5 years from end of relationship
SAR recordsInternal reports, investigation notes, external SAR submissions, reasons for not filing5 years
Training recordsTraining plans, attendance records, assessment results, content deliveredNo fixed period under Regulation 24, a written record is required but its retention duration isn't specified; many firms align it to 5 years as a matter of policy, not a Reg 40 requirement
Firm-wide risk assessmentCurrent and all prior versions with approval records5 years
Policies and proceduresCurrent and all prior versions5 years
Transaction monitoringAlerts generated, investigations conducted, outcomes and rationale10 years in some cases to enable reconstruction
โš ๏ธ
The deletion obligation: MLR 2017 meets UK GDPR
MLR 2017 Regulation 40(3) requires retention for 5 years. UK GDPR requires deletion when data is no longer needed. These obligations interact directly: after the retention period, you must delete personal data collected for AML purposes unless a Regulation 40(5) exception applies (retention required by another enactment, needed for court proceedings, retained with the data subject's consent, or reasonably anticipated to be needed for legal proceedings). Failure to delete without one of those exceptions is a UK GDPR breach. In our view, automated deletion functionality is a sensible operational control given the scale involved, but it is not itself a statutory requirement, Regulation 40 sets the retention period and its exceptions, not how you implement deletion. Note: the retention period itself is not subject to the risk-based approach: there is no discretion on whether or how long to retain.

What "sufficient to reconstruct" means

For transaction records, the test is whether the records enable the transaction to be fully reconstructed by law enforcement. This means you need to retain:

  • The amount and currency of each transaction
  • The date and time of the transaction
  • The originating and receiving accounts/parties
  • The payment reference and any narrative
  • The channel through which the transaction was made
  • Any screening alerts triggered and their resolution
๐Ÿ“‹ Screening audit trails
Every screening result should be part of your CDD record
FinCrimeRadar's results show you exactly what data was checked: use this to understand what a screening audit trail should contain.
Run a screen โ†’
FAQ

Frequently asked questions

What is the difference between SDD, CDD, and EDD? +
All three are customer due diligence measures, they differ in intensity. Simplified Due Diligence (SDD) can be applied on a risk-based determination to demonstrably lower-risk customers, being a regulated financial institution or listed company is a lower-risk factor under Reg 37(3), not an automatic entitlement to SDD, and requires less intensive checks. Standard CDD is the default: full identity verification, beneficial ownership identification, and ongoing monitoring. Enhanced Due Diligence (EDD) is mandatory for PEPs, certain correspondent relationships, high-risk third countries, and unusually complex transactions, but what it actually requires depends on why it's triggered: Reg 33(3A)'s fixed package (source of funds/wealth, senior management approval, enhanced monitoring, and more) applies specifically to FATF "Call for Action" countries, other high-risk cases use Reg 33(5)'s proportionate measures instead. The firm's risk assessment determines which tier applies to each customer.
Can we rely on a third party to conduct CDD on our behalf? +
Yes. Regulation 39 MLR 2017 allows firms to rely on third parties to conduct CDD, provided: (1) the third party is itself a relevant person under MLR 2017 or is subject to equivalent requirements; (2) under Regulation 39(2), you immediately obtain the required CDD information from the third party, and have arrangements enabling you to obtain copies of identification and verification data immediately on request, not within a set number of working days; (3) the third party retains records in accordance with MLR 2017. Critically: you cannot delegate liability. If the third party's CDD is inadequate, the relying firm remains responsible. The FCA has been clear that "we relied on our outsource partner" is not an adequate defence.
What is the "reasonable grounds" test for filing a SAR? +
Section 330 POCA covers money laundering specifically, the parallel obligation for terrorist financing sits in section 21A of the Terrorism Act 2000, they're separate offences under separate Acts, not one combined "ML/TF" section. Section 330 requires all four conditions together: you know, suspect, or have reasonable grounds to know or suspect that another person is engaged in money laundering; the information came to you in the course of business in the regulated sector; you can identify the other person or the laundered property, or believe (or it's reasonable to expect you'd believe) the information will help identify them; and you fail to disclose to a nominated officer or the NCA as soon as practicable. "Reasonable grounds" is an objective test: would a reasonable person with the same information and training have suspected money laundering? This is lower than the civil standard of balance of probabilities. You do not need to be certain, or even more likely than not, that money laundering is occurring. If a reasonable compliance professional would have suspected it, the obligation to disclose is triggered, regardless of whether you personally believed it was suspicious, provided the other three conditions are also met.
How do we handle CDD when a customer refuses to provide information? +
Under Regulation 31 MLR 2017, where a firm cannot complete CDD measures, it must: not carry out the transaction or establish the business relationship; terminate any existing business relationship; consider whether to file a SAR. A customer's refusal to provide CDD information is itself a potential red flag that should be documented and assessed. The FCA has been clear that "we could not obtain the documents" is not a reason to proceed with a relationship: if you cannot complete CDD, you should not have the customer. Note: the exit must be handled carefully to avoid tipping-off obligations if a SAR has been or is being considered.
Do the 5-year record retention periods run from the transaction date or the end of the relationship? +
For CDD documents and transaction records: the 5-year period runs from the end of the business relationship (or, for occasional transactions, from the date of the transaction). This means you retain all CDD and transaction records for the entire duration of the relationship PLUS 5 years after it ends. For SAR records: 5 years from the date the SAR was submitted. The practical implication: a 10-year customer relationship means records must be retained for 15 years total (10 years of relationship + 5 years after end), then deleted. Your data architecture must support this lifecycle management.