Staff training, transaction monitoring, governance structures, MLRO responsibilities, FCA enforcement patterns, and what the 2026–2028 regulatory horizon means for your firm.
Parts 1 and 2 of this series established the legal framework and core obligations. Part 3 focuses on what good looks like in practice — the internal controls, governance structures, and monitoring systems that translate legal obligations into effective financial crime prevention.
The FCA is explicit: having the right policies on paper is not enough. The FCA assesses the effectiveness of your controls — not just their existence. Firms that have compliant documentation but inadequate implementation are as likely to face enforcement action as firms with no controls at all.
"We are not just checking that firms have policies. We are assessing whether those policies actually work to prevent financial crime — and whether senior management genuinely understands and owns the risks." — FCA Supervisory focus, 2025
Control 01
Staff training
Regulation 24 MLR 2017 requires firms to take appropriate measures to ensure that relevant employees are made aware of AML law and regularly trained to recognise suspicious activity. Training is not a tick-box — it is a live control that must be actively maintained and evidenced.
Who must be trained?
"Relevant employees" is broadly defined: any person whose work is relevant to AML compliance, or who is likely to encounter ML/TF activity in their role. In practice, this means:
All customer-facing staff (onboarding, relationship management, customer service)
Operations and payments teams
Compliance and legal teams
Senior management and board members
IT and data teams handling AML systems
Third-party agents acting on behalf of the firm
What training must cover
📋 All staff
AML fundamentals
What is money laundering? What are the legal obligations? What are the criminal offences? How to make an internal SAR report.
Annually minimum
👥 Customer-facing
CDD and red flags
CDD procedures, how to identify suspicious behaviour, when to escalate, specific red flags relevant to their product/customer type.
Annually + role-specific
👔 Senior management
Governance and oversight
The firm's risk profile, adequacy of controls, senior management responsibilities under SM&CR, FCA expectations for their role.
The FCA expects more than recording attendance. Firms must demonstrate training is effective through:
Post-training assessments — quizzes with defined pass marks (typically 80%)
Scenario-based exercises — case studies reflecting the firm's actual risk profile
Remedial training — for staff who fail assessments
Monitoring outcomes — are SAR quality and CDD completion rates improving?
⚠️
Common FCA finding — generic training
The FCA's thematic reviews consistently identify generic, one-size-fits-all AML training as a control weakness. A customer service agent at a payments firm needs different training to a relationship manager at a private bank. Training that does not reflect the firm's specific products, customers, and risk profile is unlikely to satisfy FCA expectations — even if it covers the right topics in theory.
Training records — retention
Training records must be retained for 5 years (consistent with MLR record-keeping requirements) and must be available for FCA inspection. Records should include: training plans, content covered, dates delivered, attendees, assessment results, and evidence of remediation for failures.
🎓 Make training real
Use FinCrimeRadar as a training tool for your team
Scenario-based exercises using a live screening tool are far more effective than theory alone. Try screening case study names with your team.
Transaction monitoring (TM) is the ongoing surveillance of customer transactions to identify patterns, anomalies, and red flags that may indicate money laundering or terrorist financing. It is a core ongoing monitoring obligation under MLR 2017 and one of the FCA's most active supervisory focus areas.
The transaction monitoring process
📊
Data input
Transaction data feeds into the TM system in real time or batch
→
⚙️
Rules & models
Rules and/or ML models flag anomalous patterns
→
🔔
Alert generated
Alert created for analyst review
→
🔍
Investigation
Analyst reviews, researches, and makes decision
→
📝
Outcome
Clear alert, escalate to MLRO, or file SAR
Common TM red flags
Pattern
Potential indicator
Risk
Structuring (smurfing)
Multiple cash deposits just below reporting thresholds
🔴 High
Rapid in/out movement
Large funds received and immediately moved
🔴 High
Inconsistent with profile
Transactions inconsistent with stated business purpose
🔴 High
High-risk jurisdiction flows
Frequent transfers to/from FATF high-risk countries
🔴 High
Round number transactions
Repeated use of round figures (e.g. £9,900, £4,999)
🟡 Medium
Dormant account activation
Long-inactive account suddenly receives large deposits
🟡 Medium
Unusual geographic patterns
Activity from locations inconsistent with customer profile
🟡 Medium
Multiple beneficiaries
Funds immediately split to numerous payees
🟡 Medium
The FCA's TM supervisory focus
Transaction monitoring has been one of the FCA's primary enforcement targets in 2024/25. Common failings identified:
Poorly calibrated rules — rules that generate excessive false positives (drowning analysts) or miss real risks
Lack of tuning — TM systems that have not been reviewed or updated for years
Inadequate alert backlogs — firms unable to work through alert volumes, leading to stale investigations
Poor documentation — alert disposals without adequate rationale recorded
No management information — senior management not receiving meaningful TM MI
💡
The false positive problem in TM
Large financial institutions can generate hundreds of thousands of TM alerts daily. False positive rates of 95–99% are common — meaning that for every 100 alerts, only 1–5 represent genuine suspicious activity. This creates enormous operational pressure. The solution is not to reduce monitoring sensitivity but to intelligently calibrate rules, layer ML models on top of rule-based systems, and ensure analysts have the context (customer risk profiles, peer group comparisons) to make fast, well-informed decisions.
Control 03
Governance, MLRO, and the three lines of defence
The three lines of defence model
Line
Function
AML role
1st line
Business operations
Own the AML risk — CDD, transaction monitoring, alert investigation, customer exits
2nd line
Risk and compliance (MLRO)
Set the framework, provide oversight, review SAR decisions, report to board, engage with FCA
3rd line
Internal audit
Independent testing of AML controls — audit the 1st and 2nd lines
The MLRO — personal accountability
The Money Laundering Reporting Officer (MLRO) holds the SMF17 Senior Management Function under SM&CR. This creates personal legal accountability that distinguishes the MLRO role from most other compliance functions. The MLRO must:
Be FCA-approved to hold SMF17 before taking up the role
Have sufficient seniority, resource, and independence to challenge business decisions
Oversee all PEP relationships within the firm (FG25/3)
Review all internal SAR reports and decide whether to disclose to NCA
Produce an annual MLRO report to the board covering ML/TF risk profile, control effectiveness, and SAR activity
Engage proactively with FCA supervisors
🚨
MLRO personal liability — a real risk
The FCA has taken personal enforcement action against MLROs who failed to perform their statutory functions adequately. In one notable case, an MLRO was fined and banned for failing to implement adequate AML controls despite repeated warnings from compliance staff — the FCA found that the MLRO prioritised business revenue over compliance obligations. The SM&CR regime means that "I was just following business instructions" is not an adequate defence for an MLRO who fails their statutory duty.
Board and senior management responsibilities
Under MLR 2017, a member of the board or senior management must be appointed to be responsible for compliance with the MLRs. Their responsibilities include:
Approving the firm-wide risk assessment
Reviewing and approving AML policies
Receiving and challenging the MLRO's annual report
Financial crime screening — sanctions, PEP, and adverse media — is not just a regulatory obligation. It is an operational control that sits within your broader AML framework and must be actively managed, evidenced, and audited.
The screening control framework
1
Data coverage
Which lists are you screening against? Are they current? How frequently are they updated? OFAC updates the SDN list multiple times per day. Your screening system must keep pace.
2
Matching configuration
What threshold are you using? Too high → miss matches. Too low → drown in false positives. Fuzzy matching algorithms (like RapidFuzz) should be calibrated to your risk appetite and customer name universe.
3
Alert management
How are screening hits managed? Who reviews them? What documentation is required to clear a false positive? What happens when a true match is identified?
4
Ongoing rescreening
Screening at onboarding is not enough. You must rescreen existing customers when lists update — particularly for sanctions, where new designations can appear overnight.
5
Audit trail
Every screening check must be documented: what was searched, when, against which lists, what results were returned, and what action was taken. This is your evidence of compliance.
✅
Good practice — screening governance
Best practice firms maintain a dedicated Screening Policy that covers: which lists are screened, the matching threshold rationale, alert triage procedures, false positive documentation, true match escalation process, rescreening frequency, and system vendor oversight. The policy should be reviewed annually and following any significant list update or new designation that affects the firm's customer base.
🛡️ Experience real screening
FinCrimeRadar shows you exactly how sanctions, PEP and adverse media screening works
Try adjusting the threshold from 60% to 95% on a search — and see how it changes what matches appear. This is the calibration decision every compliance team faces.
The FCA issued over £186 million in financial crime fines in 2024/25, with 37 Final Notices. Financial crime — particularly AML and sanctions — accounted for 74% of FCA investigations opened in 2024/25. Understanding the patterns of enforcement is critical to prioritising your compliance investments.
Recent enforcement cases — key lessons
Major UK bank — AML systems failure£100m+ fine
Failures: Inadequate transaction monitoring rules that had not been updated for years; failure to file SARs on multiple red-flag customers; CDD files that lacked basic source of funds documentation; MLRO unable to demonstrate oversight of the AML programme.
Key lesson: AML systems must be actively maintained and tested — a system that worked five years ago may not work today as criminal methodologies evolve.
Fintech / challenger bank — sanctions screening gap£50m+ fine + restrictions
Failures: Sanctions screening not applied to all payment types; gaps in real-time screening for faster payments; failure to identify beneficial ownership of legal entity customers; inadequate governance — CEO not aware of sanctions compliance gaps.
Key lesson: Fintechs are held to the same standard as traditional banks. Rapid growth does not excuse compliance deficiencies — the FCA expects controls to scale with the business.
Payment service provider — PEP screening failure£20m+ fine
Failures: PEP screening database not updated; multiple PEP customers onboarded without EDD; source of wealth not obtained despite clear PEP triggers; no senior management approval for PEP relationships.
Key lesson: PEP screening is not a one-time event at onboarding. Existing customers must be rescreened when they become PEPs (e.g. following an election), and EDD must be applied immediately.
The FCA's enforcement toolkit
Tool
Trigger
Impact
Section 166 (skilled person)
FCA has concerns but wants independent review
Expensive, disruptive, precursor to enforcement
Supervisory notice
Immediate risk requiring urgent action
Restrictions on business activities
Final Notice (fine)
Breaches proven after investigation
Unlimited fine, public censure
Prohibition order
Individual unfit for senior role
Individual banned from regulated industry
Variation of permission
Serious ongoing concerns
Restriction or removal of regulated activities
Criminal prosecution
Deliberate or reckless breaches
Up to 14 years imprisonment
🧠 Final knowledge check
The FCA is conducting a supervisory visit. Which of the following would be the strongest evidence that your AML training programme is effective?
What's coming
The 2026–2028 regulatory horizon
The UK's AML regulatory landscape is undergoing significant transformation. Firms that start preparing now will be in a far stronger position than those that wait for implementation deadlines.
🆕
MLR statutory instrument — early 2026
HM Treasury is expected to lay a revised MLR statutory instrument before Parliament in early 2026, implementing the July 2025 reform decisions. Key changes: narrowed EDD scope, FATF blacklist-only for high-risk third countries, cryptoasset alignment. Firms should be planning their gap analysis now.
🆕
FCA as single AML supervisor for professional services — from ~2027
The FCA will absorb AML supervision of legal and accountancy firms currently supervised by 23 different professional body supervisors. Law firms, accountants, and tax advisers will face FCA-level supervisory scrutiny for the first time. The FCA's data-led, risk-based supervisory approach is materially more intensive than most professional body supervision.
🆕
FATF Mutual Evaluation of the UK — 2028
The UK's next FATF mutual evaluation is scheduled for 2028. This will be the most significant external assessment of the UK's AML regime in a decade — covering legislative reforms, the new supervisory structure, and FCA enforcement effectiveness. The UK's rating will affect its international standing and the de-risking decisions of global correspondent banks.
What firms should do now
Gap analysis — assess your current EDD practices against the narrowed scope in the July 2025 MLR reforms. Where are you applying EDD that will no longer be required? Where do you have gaps?
PEP framework review — implement the FG25/3 domestic PEP guidance. Document your updated PEP risk methodology and update your policies.
TM system audit — commission an independent review of transaction monitoring rule calibration. FCA supervisory focus on TM is intensifying.
Training refresh — ensure training covers the 2025 regulatory changes, including PEP guidance and Failure to Prevent Fraud offence.
MLRO report quality — the MLRO's annual board report should be specific to your firm, not generic. If it could apply to any regulated firm, rewrite it.
🛡️ Stay ahead of regulatory change
FinCrimeRadar tracks the latest sanctions designations and PEP data
Use FinCrimeRadar to understand the current state of sanctions lists — including post-July 2025 FATF blacklist designations that now trigger mandatory EDD.
How often must we rescreen existing customers against sanctions lists? +
The MLRs require ongoing monitoring, which includes rescreening. For sanctions, best practice (and FCA expectation) is real-time or near-real-time rescreening against live sanctions lists — particularly for OFAC (which updates multiple times daily) and OFSI. At a minimum, batch rescreening of your full customer base must occur whenever a significant new designation is made. Relying solely on annual periodic reviews for sanctions rescreening is likely to be inadequate given the pace of designation activity since 2022. For PEP status, periodic rescreening is typically acceptable — the FCA expects systems to flag when existing customers acquire PEP status (e.g. following an election).
What is the difference between a Section 166 review and an FCA investigation? +
A Section 166 (FSMA 2000) "skilled person review" is commissioned by the firm at the FCA's requirement — the firm pays for an independent expert (agreed with the FCA) to review specified aspects of the business. It is a supervisory tool, not enforcement. An FCA investigation, by contrast, is conducted under the FCA's enforcement powers and can lead to a Final Notice (fine), prohibition order, or criminal prosecution. The two can overlap: a s166 that finds serious failings often precedes or runs in parallel with an enforcement investigation. Receiving a s166 requirement is a serious signal that the FCA has material concerns — firms should treat it as a significant regulatory event requiring immediate senior management attention.
Does the Failure to Prevent Fraud offence affect my AML obligations? +
The Failure to Prevent Fraud (FTPF) offence (in force 1 September 2025) creates a new corporate criminal offence for large organisations that fail to prevent fraud by associated persons. It is separate from AML obligations but closely related. Firms that already have strong AML controls (risk assessment, training, monitoring, governance) will find many of the "reasonable procedures" required under FTPF are already in place. The key difference: FTPF focuses on fraud prevention specifically, while AML focuses on detecting and reporting money laundering. Firms should conduct a FTPF gap analysis alongside their AML programme review.
What qualifications should an MLRO have? +
The FCA does not prescribe specific qualifications for MLROs but assesses fitness and propriety against criteria including: relevant knowledge and experience of AML/CTF regulation and practice; sufficient seniority and authority within the firm; adequate time allocation to perform the role; no conflicts of interest; clean regulatory and criminal history. In practice, most MLROs at regulated firms hold qualifications such as ICA Certificate or Diploma in AML, CAMS (ACAMS), or legal qualifications with AML specialisation. For FCA authorisation as SMF17, the FCA will assess whether the individual's qualifications and experience are commensurate with the complexity of the firm's business.
Can our AML screening be fully automated, or do we need human review? +
Screening tools can automate the matching process — but human review of screening hits above a certain threshold remains essential for most firms. The FCA expects a risk-based approach: very low-risk matches can be auto-cleared by system rules if those rules are well-calibrated and documented. Potential matches above a risk threshold must be reviewed by a trained analyst, and true matches (confirmed hits against sanctions lists in particular) must be escalated to the MLRO immediately. Fully automated disposition of all screening alerts, without any human review, is unlikely to satisfy FCA expectations — particularly for sanctions hits, where the consequences of an error are severe.
✓ Series complete
You've completed the UK AML Compliance Guide
You now have a comprehensive understanding of the UK's AML legal framework, core obligations, and the controls that make compliance effective. Put your knowledge into practice.