From obligations to controls
Parts 1 and 2 of this series established the legal framework and core obligations. Part 3 focuses on what good looks like in practice: the internal controls, governance structures, and monitoring systems that translate legal obligations into effective financial crime prevention.
The FCA is explicit: having the right policies on paper is not enough. The FCA assesses the effectiveness of your controls, not just their existence. Firms that have compliant documentation but inadequate implementation are as likely to face enforcement action as firms with no controls at all.
Staff training
Regulation 24 MLR 2017 requires firms to take appropriate measures to ensure that relevant employees are made aware of AML law and regularly trained to recognise suspicious activity. Training is not a tick-box: it is a live control that must be actively maintained and evidenced.
Who must be trained?
"Relevant employee" has a specific functional definition under Regulation 21(2): an employee whose work is either relevant to the firm's compliance with the MLRs, or otherwise capable of contributing to identifying or mitigating money laundering, terrorist financing, or proliferation financing risk. It is not a blanket category covering every job title by seniority alone. In practice, this typically includes:
- All customer-facing staff (onboarding, relationship management, customer service)
- Operations and payments teams
- Compliance and legal teams
- IT and data teams handling AML systems
Regulation 24 separately extends the training duty to agents acting on the firm's behalf, a distinct limb from the "relevant employee" definition, not agents being reclassified as employees. Senior management and board members are relevant employees only where their actual role meets the functional test above, for example, a board member with hands-on AML oversight responsibilities. Many firms choose to train the wider board regardless, as good governance practice, but Regulation 24 does not itself make every board member a relevant employee by virtue of seniority alone.
Regulation 24 requires training to be given "regularly" and calibrated to the firm's size, nature, and risk, it does not itself set a fixed minimum cycle such as annual. Most firms do train annually as a reasonable, defensible cadence, but that is a firm choice, not a statutory mandate.
What training must cover
Assessing training effectiveness
The FCA expects more than recording attendance. Firms must demonstrate training is effective through:
- Post-training assessments: quizzes with a defined pass mark, 80% is a common industry convention, not an FCA or MLR mandated figure, set at whatever level the firm can defend as meaningful
- Scenario-based exercises: case studies reflecting the firm's actual risk profile
- Remedial training: for staff who fail assessments
- Monitoring outcomes: are SAR quality and CDD completion rates improving?
Training records: retention
Regulation 24 requires a written record of the training measures taken, but specifies no fixed retention period for that record. The MLRs' explicit 5 year retention period applies to Regulation 40's CDD evidence and transaction records, not training records specifically. Many firms retain training records for 5 years to align with their wider record-keeping policy, a sensible firm choice, but not itself a Regulation 24 requirement. Records must be available for FCA inspection and should include: training plans, content covered, dates delivered, attendees, assessment results, and evidence of remediation for failures.
Transaction monitoring
Transaction monitoring (TM) is the ongoing surveillance of customer transactions to identify patterns, anomalies, and red flags that may indicate money laundering or terrorist financing. It is a core ongoing monitoring obligation under MLR 2017 and one of the FCA's most active supervisory focus areas.
The transaction monitoring process
Common TM red flags
| Pattern | Potential indicator | Risk |
|---|---|---|
| Structuring (smurfing) | Multiple cash deposits just below reporting thresholds | ๐ด High |
| Rapid in/out movement | Large funds received and immediately moved | ๐ด High |
| Inconsistent with profile | Transactions inconsistent with stated business purpose | ๐ด High |
| High-risk jurisdiction flows | Frequent transfers to/from FATF high-risk countries | ๐ด High |
| Round number transactions | Repeated use of round figures (e.g. ยฃ9,900, ยฃ4,999) | ๐ก Medium |
| Dormant account activation | Long-inactive account suddenly receives large deposits | ๐ก Medium |
| Unusual geographic patterns | Activity from locations inconsistent with customer profile | ๐ก Medium |
| Multiple beneficiaries | Funds immediately split to numerous payees | ๐ก Medium |
The FCA's TM supervisory focus
Transaction monitoring failings feature prominently across the FCA's published 2024/25 enforcement cases, this is FinCrimeRadar's own reading of that pattern rather than an FCA-stated enforcement priority ranking. Common failings identified:
- Poorly calibrated rules: rules that generate excessive false positives (drowning analysts) or miss real risks
- Lack of tuning: TM systems that have not been reviewed or updated for years
- Inadequate alert backlogs: firms unable to work through alert volumes, leading to stale investigations
- Poor documentation: alert disposals without adequate rationale recorded
- No management information: senior management not receiving meaningful TM MI
Governance, MLRO, and the three lines of defence
The three lines of defence model
| Line | Function | AML role |
|---|---|---|
| 1st line | Business operations | Own the AML risk: CDD, transaction monitoring, alert investigation, customer exits |
| 2nd line | Risk and compliance (MLRO) | Set the framework, provide oversight, review SAR decisions, report to board, engage with FCA |
| 3rd line | Internal audit | Independent testing of AML controls: audit the 1st and 2nd lines |
The MLRO: personal accountability
For firms within the FCA's Senior Managers and Certification Regime, the Money Laundering Reporting Officer typically holds the SMF17 Senior Management Function, creating personal legal accountability that distinguishes the role from most other compliance functions. SMF17 is a specific FCA/SM&CR implementation, though, not something every MLR-regulated firm has, firms outside SM&CR scope (supervised by HMRC or a professional body, for example) still need a named compliance officer under MLR 2017 Regulation 21 without that person ever holding an SMF17 designation. Where SMF17 applies, the MLRO must:
- Be FCA-approved to hold SMF17 before taking up the role
- Have sufficient seniority, resource, and independence to challenge business decisions
- Retain oversight of the firm's overall PEP process; FG25/3 does not require the MLRO to personally approve every individual PEP relationship where another suitably senior person does so
- Where also appointed as the firm's nominated officer under POCA s.331, a distinct statutory role most firms designate their MLRO to hold, review internal SAR reports referred to that role and decide whether to disclose onward to the NCA
- Report to the board on the firm's ML/TF risk profile, control effectiveness, and SAR activity, at a frequency the firm's own governance sets rather than a fixed statutory cycle
- Engage proactively with FCA supervisors
Board and senior management responsibilities
MLR 2017 Regulation 21(1)(a) requires a firm to appoint a member of the board (or of senior management, where there is no board) as the officer responsible for compliance with the MLRs, but only where appropriate with regard to the size and nature of the firm's business, it is not an unconditional appointment mandate for every relevant person. Where the appointment is required, that officer's responsibilities include:
- Approving the firm-wide risk assessment
- Reviewing and approving AML policies
- Receiving and challenging the MLRO's board report
- Approving high-risk customer relationships (including PEPs)
- Ensuring adequate resources are allocated to AML compliance
- Understanding the firm's ML/TF risk profile, not just delegating it
Screening as a compliance control
Financial crime screening, sanctions, PEP, and adverse media, sits at the intersection of several distinct legal bases, not one single "regulatory obligation." Sanctions screening and rescreening are driven by the applicable sanctions regime, not the MLRs. PEP identification supports the MLRs' EDD triggers under Regulation 33/35. Adverse media screening is not itself an express universal MLR obligation, most firms use it as a risk-management tool because it helps surface PEP status, sanctions exposure and other risk factors, not because a specific regulation names it. Whatever its legal basis, screening is an operational control that sits within your broader AML framework and must be actively managed, evidenced, and audited.
The screening control framework
Data coverage
Which lists are you screening against? Are they current? How frequently are they updated? OFAC updates the SDN list on an ongoing, unscheduled basis, sometimes more than once in a day. Your screening system must keep pace.
Matching configuration
What threshold are you using? Too high โ miss matches. Too low โ drown in false positives. Fuzzy matching algorithms (like RapidFuzz) should be calibrated to your risk appetite and customer name universe.
Alert management
How are screening hits managed? Who reviews them? What documentation is required to clear a false positive? What happens when a true match is identified?
Ongoing rescreening
Screening at onboarding is not enough. Existing customers should be rescreened as lists and risk profiles change. For sanctions, this flows from the sanctions regime's own prohibitions, not a specific MLR rescreening rule, MLR 2017 Regulation 28's ongoing-monitoring duty concerns scrutinising transactions and keeping CDD information current, it does not itself prescribe a screening cadence.
Audit trail
Every screening check must be documented: what was searched, when, against which lists, what results were returned, and what action was taken. This is your evidence of compliance.
FCA enforcement: patterns and lessons
The FCA issued more than ยฃ186 million in fines across 37 Final Notices in 2024/25, its overall enforcement total for the year, not a financial-crime-specific figure. Financial crime nonetheless accounted for a substantial share of new enforcement activity: 17 of the FCA's 23 new investigation operations opened in 2024/25 related to financial crime. The FCA's financial-crime-specific supervisory data separately records 546 AML assessments and 965 financial crime supervision cases opened in 2024/25, alongside named penalties including Starling Bank (ยฃ28,959,426, sanctions-screening failings) and Metro Bank (ยฃ16,675,200, Principle 3 breaches). Understanding the patterns of enforcement is critical to prioritising your compliance investments.
Recent enforcement cases: key lessons
The three cards below are composite, illustrative scenarios built from recurring FCA enforcement patterns, not named cases with an identifiable Final Notice, they teach the pattern, not a specific firm's history.
The FCA's enforcement toolkit
| Tool | Trigger | Impact |
|---|---|---|
| Section 166 (skilled person) | FCA has concerns but wants independent review | Expensive, disruptive, precursor to enforcement |
| Supervisory notice | Immediate risk requiring urgent action | Restrictions on business activities |
| Final Notice (fine) | Breaches proven after investigation | Unlimited fine, public censure |
| Prohibition order | Individual unfit for senior role | Individual banned from regulated industry |
| Variation of permission | Serious ongoing concerns | Restriction or removal of regulated activities |
| Criminal prosecution | Deliberate or reckless breaches | MLR 2017 Regulation 86: up to 2 years on indictment for an MLR breach itself. Fourteen years applies to the separate principal money laundering offences under POCA, not to a breach of the MLRs. |
The 2026-2028 regulatory horizon
The UK's AML regulatory landscape is undergoing significant transformation. Firms that start preparing now will be in a far stronger position than those that wait for implementation deadlines.
What firms should do now
- Gap analysis: assess your current EDD practices against S.I. 2026/621's Call for Action country trigger, in force since 30 June 2026. Where are you still applying country-based EDD that is no longer required? Where do you have gaps?
- PEP framework review: implement the FG25/3 domestic PEP guidance. Document your updated PEP risk methodology and update your policies.
- TM system audit: commission an independent review of transaction monitoring rule calibration. FCA supervisory focus on TM is intensifying.
- Training refresh: ensure training covers the 2025 regulatory changes, including PEP guidance and Failure to Prevent Fraud offence.
- MLRO report quality: the MLRO's board report, whatever cadence your governance sets, should be specific to your firm, not generic. If it could apply to any regulated firm, rewrite it.