Introduction

From obligations to controls

Parts 1 and 2 of this series established the legal framework and core obligations. Part 3 focuses on what good looks like in practice: the internal controls, governance structures, and monitoring systems that translate legal obligations into effective financial crime prevention.

The FCA is explicit: having the right policies on paper is not enough. The FCA assesses the effectiveness of your controls, not just their existence. Firms that have compliant documentation but inadequate implementation are as likely to face enforcement action as firms with no controls at all.

The FCA's own guidance is consistent on this point: having AML policies on paper is not the test. Whether those policies actually work to prevent financial crime, and whether senior management genuinely understands and owns the risks, is. (FinCrimeRadar's paraphrase of the FCA's stated supervisory approach in FCG 1.1, not a direct FCA quotation.)
Control 01

Staff training

Regulation 24 MLR 2017 requires firms to take appropriate measures to ensure that relevant employees are made aware of AML law and regularly trained to recognise suspicious activity. Training is not a tick-box: it is a live control that must be actively maintained and evidenced.

Who must be trained?

"Relevant employee" has a specific functional definition under Regulation 21(2): an employee whose work is either relevant to the firm's compliance with the MLRs, or otherwise capable of contributing to identifying or mitigating money laundering, terrorist financing, or proliferation financing risk. It is not a blanket category covering every job title by seniority alone. In practice, this typically includes:

  • All customer-facing staff (onboarding, relationship management, customer service)
  • Operations and payments teams
  • Compliance and legal teams
  • IT and data teams handling AML systems

Regulation 24 separately extends the training duty to agents acting on the firm's behalf, a distinct limb from the "relevant employee" definition, not agents being reclassified as employees. Senior management and board members are relevant employees only where their actual role meets the functional test above, for example, a board member with hands-on AML oversight responsibilities. Many firms choose to train the wider board regardless, as good governance practice, but Regulation 24 does not itself make every board member a relevant employee by virtue of seniority alone.

Regulation 24 requires training to be given "regularly" and calibrated to the firm's size, nature, and risk, it does not itself set a fixed minimum cycle such as annual. Most firms do train annually as a reasonable, defensible cadence, but that is a firm choice, not a statutory mandate.

What training must cover

๐Ÿ“‹ All staff
AML fundamentals
What is money laundering? What are the legal obligations? What are the criminal offences? How to make an internal SAR report.
Regularly (risk-based)
๐Ÿ‘ฅ Customer-facing
CDD and red flags
CDD procedures, how to identify suspicious behaviour, when to escalate, specific red flags relevant to their product/customer type.
Regularly + role-specific
๐Ÿ‘” Senior management
Governance and oversight
The firm's risk profile, adequacy of controls, senior management responsibilities under SM&CR, FCA expectations for their role.
Regularly, board-level
๐Ÿ›ก๏ธ Compliance / MLRO
Technical and regulatory
Detailed MLR obligations, SAR quality, FCA supervisory expectations, emerging typologies, regulatory developments.
Ongoing, CPD

Assessing training effectiveness

The FCA expects more than recording attendance. Firms must demonstrate training is effective through:

  • Post-training assessments: quizzes with a defined pass mark, 80% is a common industry convention, not an FCA or MLR mandated figure, set at whatever level the firm can defend as meaningful
  • Scenario-based exercises: case studies reflecting the firm's actual risk profile
  • Remedial training: for staff who fail assessments
  • Monitoring outcomes: are SAR quality and CDD completion rates improving?
โš ๏ธ
Common FCA finding: generic training
The FCA's thematic reviews consistently identify generic, one-size-fits-all AML training as a control weakness. A customer service agent at a payments firm needs different training to a relationship manager at a private bank. Training that does not reflect the firm's specific products, customers, and risk profile is unlikely to satisfy FCA expectations, even if it covers the right topics in theory.

Training records: retention

Regulation 24 requires a written record of the training measures taken, but specifies no fixed retention period for that record. The MLRs' explicit 5 year retention period applies to Regulation 40's CDD evidence and transaction records, not training records specifically. Many firms retain training records for 5 years to align with their wider record-keeping policy, a sensible firm choice, but not itself a Regulation 24 requirement. Records must be available for FCA inspection and should include: training plans, content covered, dates delivered, attendees, assessment results, and evidence of remediation for failures.

๐ŸŽ“ Make training real
Use FinCrimeRadar as a training tool for your team
Scenario-based exercises using a live screening tool are far more effective than theory alone. Try screening case study names with your team.
Open screening tool โ†’
Control 02

Transaction monitoring

Transaction monitoring (TM) is the ongoing surveillance of customer transactions to identify patterns, anomalies, and red flags that may indicate money laundering or terrorist financing. It is a core ongoing monitoring obligation under MLR 2017 and one of the FCA's most active supervisory focus areas.

The transaction monitoring process

๐Ÿ“Š
Data input
Transaction data feeds into the TM system in real time or batch
โ†’
โš™๏ธ
Rules & models
Rules and/or ML models flag anomalous patterns
โ†’
๐Ÿ””
Alert generated
Alert created for analyst review
โ†’
๐Ÿ”
Investigation
Analyst reviews, researches, and makes decision
โ†’
๐Ÿ“
Outcome
Clear alert, escalate to MLRO, or file SAR

Common TM red flags

PatternPotential indicatorRisk
Structuring (smurfing)Multiple cash deposits just below reporting thresholds๐Ÿ”ด High
Rapid in/out movementLarge funds received and immediately moved๐Ÿ”ด High
Inconsistent with profileTransactions inconsistent with stated business purpose๐Ÿ”ด High
High-risk jurisdiction flowsFrequent transfers to/from FATF high-risk countries๐Ÿ”ด High
Round number transactionsRepeated use of round figures (e.g. ยฃ9,900, ยฃ4,999)๐ŸŸก Medium
Dormant account activationLong-inactive account suddenly receives large deposits๐ŸŸก Medium
Unusual geographic patternsActivity from locations inconsistent with customer profile๐ŸŸก Medium
Multiple beneficiariesFunds immediately split to numerous payees๐ŸŸก Medium

The FCA's TM supervisory focus

Transaction monitoring failings feature prominently across the FCA's published 2024/25 enforcement cases, this is FinCrimeRadar's own reading of that pattern rather than an FCA-stated enforcement priority ranking. Common failings identified:

  • Poorly calibrated rules: rules that generate excessive false positives (drowning analysts) or miss real risks
  • Lack of tuning: TM systems that have not been reviewed or updated for years
  • Inadequate alert backlogs: firms unable to work through alert volumes, leading to stale investigations
  • Poor documentation: alert disposals without adequate rationale recorded
  • No management information: senior management not receiving meaningful TM MI
๐Ÿ’ก
The false positive problem in TM
Large financial institutions can generate hundreds of thousands of TM alerts daily. Industry estimates commonly cite false positive rates in the 95-99% range, meaning that for every 100 alerts, only 1-5 would represent genuine suspicious activity, though this isn't an FCA or NCA-published benchmark and actual rates vary by institution, rule calibration, and risk appetite. Even at the lower end, this creates enormous operational pressure. The solution is not to reduce monitoring sensitivity but to intelligently calibrate rules, layer ML models on top of rule-based systems, and ensure analysts have the context (customer risk profiles, peer group comparisons) to make fast, well-informed decisions.
Control 03

Governance, MLRO, and the three lines of defence

The three lines of defence model

LineFunctionAML role
1st lineBusiness operationsOwn the AML risk: CDD, transaction monitoring, alert investigation, customer exits
2nd lineRisk and compliance (MLRO)Set the framework, provide oversight, review SAR decisions, report to board, engage with FCA
3rd lineInternal auditIndependent testing of AML controls: audit the 1st and 2nd lines

The MLRO: personal accountability

For firms within the FCA's Senior Managers and Certification Regime, the Money Laundering Reporting Officer typically holds the SMF17 Senior Management Function, creating personal legal accountability that distinguishes the role from most other compliance functions. SMF17 is a specific FCA/SM&CR implementation, though, not something every MLR-regulated firm has, firms outside SM&CR scope (supervised by HMRC or a professional body, for example) still need a named compliance officer under MLR 2017 Regulation 21 without that person ever holding an SMF17 designation. Where SMF17 applies, the MLRO must:

  • Be FCA-approved to hold SMF17 before taking up the role
  • Have sufficient seniority, resource, and independence to challenge business decisions
  • Retain oversight of the firm's overall PEP process; FG25/3 does not require the MLRO to personally approve every individual PEP relationship where another suitably senior person does so
  • Where also appointed as the firm's nominated officer under POCA s.331, a distinct statutory role most firms designate their MLRO to hold, review internal SAR reports referred to that role and decide whether to disclose onward to the NCA
  • Report to the board on the firm's ML/TF risk profile, control effectiveness, and SAR activity, at a frequency the firm's own governance sets rather than a fixed statutory cycle
  • Engage proactively with FCA supervisors
๐Ÿšจ
MLRO personal liability: a real risk
The FCA has taken personal enforcement action against MLROs who failed to perform their statutory functions adequately. In one notable case, an MLRO was fined and banned for failing to implement adequate AML controls despite repeated warnings from compliance staff, the FCA found that the MLRO prioritised business revenue over compliance obligations. The SM&CR regime means that "I was just following business instructions" is not an adequate defence for an MLRO who fails their statutory duty.

Board and senior management responsibilities

MLR 2017 Regulation 21(1)(a) requires a firm to appoint a member of the board (or of senior management, where there is no board) as the officer responsible for compliance with the MLRs, but only where appropriate with regard to the size and nature of the firm's business, it is not an unconditional appointment mandate for every relevant person. Where the appointment is required, that officer's responsibilities include:

  • Approving the firm-wide risk assessment
  • Reviewing and approving AML policies
  • Receiving and challenging the MLRO's board report
  • Approving high-risk customer relationships (including PEPs)
  • Ensuring adequate resources are allocated to AML compliance
  • Understanding the firm's ML/TF risk profile, not just delegating it
๐Ÿ” MLRO tool
Demonstrate your screening controls to the board
FinCrimeRadar is useful for board-level demonstrations of what screening controls do, and what happens when they work correctly.
Open the tool โ†’
Control 04

Screening as a compliance control

Financial crime screening, sanctions, PEP, and adverse media, sits at the intersection of several distinct legal bases, not one single "regulatory obligation." Sanctions screening and rescreening are driven by the applicable sanctions regime, not the MLRs. PEP identification supports the MLRs' EDD triggers under Regulation 33/35. Adverse media screening is not itself an express universal MLR obligation, most firms use it as a risk-management tool because it helps surface PEP status, sanctions exposure and other risk factors, not because a specific regulation names it. Whatever its legal basis, screening is an operational control that sits within your broader AML framework and must be actively managed, evidenced, and audited.

The screening control framework

1

Data coverage

Which lists are you screening against? Are they current? How frequently are they updated? OFAC updates the SDN list on an ongoing, unscheduled basis, sometimes more than once in a day. Your screening system must keep pace.

2

Matching configuration

What threshold are you using? Too high โ†’ miss matches. Too low โ†’ drown in false positives. Fuzzy matching algorithms (like RapidFuzz) should be calibrated to your risk appetite and customer name universe.

3

Alert management

How are screening hits managed? Who reviews them? What documentation is required to clear a false positive? What happens when a true match is identified?

4

Ongoing rescreening

Screening at onboarding is not enough. Existing customers should be rescreened as lists and risk profiles change. For sanctions, this flows from the sanctions regime's own prohibitions, not a specific MLR rescreening rule, MLR 2017 Regulation 28's ongoing-monitoring duty concerns scrutinising transactions and keeping CDD information current, it does not itself prescribe a screening cadence.

5

Audit trail

Every screening check must be documented: what was searched, when, against which lists, what results were returned, and what action was taken. This is your evidence of compliance.

โœ…
Good practice: screening governance
Best practice firms maintain a dedicated Screening Policy that covers: which lists are screened, the matching threshold rationale, alert triage procedures, false positive documentation, true match escalation process, rescreening frequency, and system vendor oversight. The policy should be reviewed annually and following any significant list update or new designation that affects the firm's customer base.
๐Ÿ›ก๏ธ Experience real screening
FinCrimeRadar shows you exactly how sanctions, PEP and adverse media screening works
Try adjusting the threshold from 60% to 95% on a search, and see how it changes what matches appear. This is the calibration decision every compliance team faces.
Try the tool โ†’
Enforcement

FCA enforcement: patterns and lessons

The FCA issued more than ยฃ186 million in fines across 37 Final Notices in 2024/25, its overall enforcement total for the year, not a financial-crime-specific figure. Financial crime nonetheless accounted for a substantial share of new enforcement activity: 17 of the FCA's 23 new investigation operations opened in 2024/25 related to financial crime. The FCA's financial-crime-specific supervisory data separately records 546 AML assessments and 965 financial crime supervision cases opened in 2024/25, alongside named penalties including Starling Bank (ยฃ28,959,426, sanctions-screening failings) and Metro Bank (ยฃ16,675,200, Principle 3 breaches). Understanding the patterns of enforcement is critical to prioritising your compliance investments.

Recent enforcement cases: key lessons

The three cards below are composite, illustrative scenarios built from recurring FCA enforcement patterns, not named cases with an identifiable Final Notice, they teach the pattern, not a specific firm's history.

Major UK bank: AML systems failure ยฃ100m+ fine
Failures: Inadequate transaction monitoring rules that had not been updated for years; failure to file SARs on multiple red-flag customers; CDD files that lacked basic source of funds documentation; MLRO unable to demonstrate oversight of the AML programme.
Key lesson: AML systems must be actively maintained and tested: a system that worked five years ago may not work today as criminal methodologies evolve.
Fintech / challenger bank: sanctions screening gap ยฃ50m+ fine + restrictions
Failures: Sanctions screening not applied to all payment types; gaps in real-time screening for faster payments; failure to identify beneficial ownership of legal entity customers; inadequate governance, CEO not aware of sanctions compliance gaps.
Key lesson: Fintechs are held to the same standard as traditional banks. Rapid growth does not excuse compliance deficiencies: the FCA expects controls to scale with the business.
Payment service provider: PEP screening failure ยฃ20m+ fine
Failures: PEP screening database not updated; multiple PEP customers onboarded without EDD; source of wealth not obtained despite clear PEP triggers; no senior management approval for PEP relationships.
Key lesson: PEP screening is not a one-time event at onboarding. Existing customers must be rescreened when they become PEPs (e.g. following an election), and EDD must be applied immediately.

The FCA's enforcement toolkit

ToolTriggerImpact
Section 166 (skilled person)FCA has concerns but wants independent reviewExpensive, disruptive, precursor to enforcement
Supervisory noticeImmediate risk requiring urgent actionRestrictions on business activities
Final Notice (fine)Breaches proven after investigationUnlimited fine, public censure
Prohibition orderIndividual unfit for senior roleIndividual banned from regulated industry
Variation of permissionSerious ongoing concernsRestriction or removal of regulated activities
Criminal prosecutionDeliberate or reckless breachesMLR 2017 Regulation 86: up to 2 years on indictment for an MLR breach itself. Fourteen years applies to the separate principal money laundering offences under POCA, not to a breach of the MLRs.
๐Ÿง  Final knowledge check
The FCA is conducting a supervisory visit. Which of the following would be the strongest evidence that your AML training programme is effective?
What's coming

The 2026-2028 regulatory horizon

The UK's AML regulatory landscape is undergoing significant transformation. Firms that start preparing now will be in a far stronger position than those that wait for implementation deadlines.

๐Ÿ†•
MLR statutory instrument: in force from 30 June 2026
S.I. 2026/621 has already taken effect, from 30 June 2026, this is no longer a prospective change. Key changes now live: mandatory country-based EDD under Regulation 33 tied to FATF "Call for Action" (blacklist) countries rather than the broader high-risk third country list, and cryptoasset alignment. Firms should be confirming their gap analysis is complete, not still planning it.
๐Ÿ†•
FCA as single AML supervisor for professional services: decision confirmed, timing still to be set
HM Treasury has confirmed the FCA will absorb AML supervision of legal and accountancy firms currently supervised by 23 different professional body supervisors. Implementation depends on primary legislation and parliamentary timing, so a firm date, including any estimate around 2027, should be treated as indicative rather than fixed until that legislation is introduced. Law firms, accountants, and tax advisers will face FCA-level supervisory scrutiny for the first time once it takes effect. The FCA's data-led, risk-based supervisory approach is materially more intensive than most professional body supervision.
๐Ÿ†•
FATF Mutual Evaluation of the UK: 2028
The UK's next FATF mutual evaluation is scheduled for 2028. This will be the most significant external assessment of the UK's AML regime in a decade, covering legislative reforms, the new supervisory structure, and FCA enforcement effectiveness. The UK's rating will affect its international standing and the de-risking decisions of global correspondent banks.

What firms should do now

  • Gap analysis: assess your current EDD practices against S.I. 2026/621's Call for Action country trigger, in force since 30 June 2026. Where are you still applying country-based EDD that is no longer required? Where do you have gaps?
  • PEP framework review: implement the FG25/3 domestic PEP guidance. Document your updated PEP risk methodology and update your policies.
  • TM system audit: commission an independent review of transaction monitoring rule calibration. FCA supervisory focus on TM is intensifying.
  • Training refresh: ensure training covers the 2025 regulatory changes, including PEP guidance and Failure to Prevent Fraud offence.
  • MLRO report quality: the MLRO's board report, whatever cadence your governance sets, should be specific to your firm, not generic. If it could apply to any regulated firm, rewrite it.
๐Ÿ›ก๏ธ Stay ahead of regulatory change
FinCrimeRadar tracks the latest sanctions designations and PEP data
Use FinCrimeRadar to understand the current state of sanctions lists, including FATF blacklist designations, which since 30 June 2026 trigger mandatory country-based EDD under Regulation 33.
Screen now โ†’
FAQ

Frequently asked questions

How often must we rescreen existing customers against sanctions lists? +
MLR 2017 Regulation 28 requires ongoing monitoring of the business relationship, scrutinising transactions and keeping CDD information current, it does not itself create a specific sanctions rescreening rule. That rescreening obligation instead flows from the sanctions regime itself: you must not deal with a designated person, so a control that catches new designations promptly is what keeps you compliant with that separate prohibition. For sanctions, best practice (and FCA expectation) is real-time or near-real-time rescreening against live sanctions lists: OFAC updates the SDN list on an ongoing, unscheduled basis, sometimes more than once in a day, and the FCDO's UK Sanctions List (which OFSI implements and enforces) updates on its own schedule. At a minimum, batch rescreening of your full customer base should occur whenever a significant new designation is made. Relying solely on annual periodic reviews for sanctions rescreening is likely to leave gaps given the pace of designation activity since 2022. For PEP status, periodic rescreening is typically acceptable: the FCA expects systems to flag when existing customers acquire PEP status (e.g. following an election).
What is the difference between a Section 166 review and an FCA investigation? +
A Section 166 (FSMA 2000) "skilled person review" usually has the firm commission the review at the FCA's requirement, paying for an independent expert agreed with the FCA to review specified aspects of the business. Under s166(3), the FCA can instead appoint the skilled person itself, still at the firm's expense, where it considers that appropriate. It is a supervisory tool, not itself an enforcement action, though a s166 that finds serious failings often precedes or runs in parallel with an enforcement investigation. An FCA investigation, by contrast, is conducted under the FCA's enforcement powers and can lead to a Final Notice (fine), prohibition order, or criminal prosecution. Receiving a s166 requirement is a serious signal that the FCA has material concerns: firms should treat it as a significant regulatory event requiring immediate senior management attention.
Does the Failure to Prevent Fraud offence affect my AML obligations? +
The Failure to Prevent Fraud (FTPF) offence (in force 1 September 2025) creates a new corporate criminal offence for large organisations that fail to prevent fraud by associated persons. It is separate from AML obligations but closely related. Firms that already have strong AML controls (risk assessment, training, monitoring, governance) will find many of the "reasonable procedures" required under FTPF are already in place. The key difference: FTPF focuses on fraud prevention specifically, while AML focuses on detecting and reporting money laundering. Firms should conduct a FTPF gap analysis alongside their AML programme review.
What qualifications should an MLRO have? +
The FCA does not prescribe specific qualifications for MLROs but assesses fitness and propriety against criteria including: relevant knowledge and experience of AML/CTF regulation and practice; sufficient seniority and authority within the firm; adequate time allocation to perform the role; no conflicts of interest; clean regulatory and criminal history. Relevant qualifications, such as an ICA Certificate or Diploma in AML, ACAMS' CAMS designation, or a legal qualification with AML specialisation, can support a fitness and propriety case, but the FCA does not mandate any specific qualification, and no independently benchmarked data establishes how common these credentials actually are among practising MLROs. For FCA authorisation as SMF17, the FCA will assess whether the individual's qualifications and experience are commensurate with the complexity of the firm's business.
Can our AML screening be fully automated, or do we need human review? +
Screening tools can automate the matching process, but human review of screening hits above a certain threshold remains essential for most firms. In FinCrimeRadar's operational view, a risk-based approach works best: very low-risk matches can be auto-cleared by system rules if those rules are well-calibrated, tested, and documented. Potential matches above a risk threshold should be reviewed by a trained analyst, and true matches (confirmed hits against sanctions lists in particular) should be escalated to the MLRO or the firm's designated senior function immediately. This is our own operational recommendation rather than a cited FCA rule, but fully automated disposition of all screening alerts, with no human review at all, is unlikely to satisfy FCA expectations of an effective, demonstrable control, particularly for sanctions hits, where the consequences of an error are severe.
โœ“ Series complete
You've completed the UK AML Compliance Guide
You now have a comprehensive understanding of the UK's AML legal framework, core obligations, and the controls that make compliance effective. Put your knowledge into practice.