These FAQs help you understand anti money laundering compliance requirements, how checks and processes work, and the responsibilities firms must meet under UK law.
Anti money laundering (AML) refers to the laws and frameworks designed to stop criminals from making illegal funds appear legitimate. It includes the wider regulatory system that aims to detect, deter, and disrupt money laundering across financial and non-financial sectors.
The three stages of anti money laundering are placement, layering, and integration.
Placement is the initial stage where illicit money is introduced into the financial system. Layering involves moving or disguising the funds through complex transactions to make them harder to trace. Integration is the final stage, where the laundered money is returned to the economy as apparently legitimate funds.
The Anti Money Laundering Act is a legal framework, mainly made up of:
The Anti-Money Laundering Act, also called the Sanctions and Anti-Money Laundering Act 2018 (SAMLA 2018), received Royal Assent on 23 May 2018.
The anti money laundering regulations are the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017). They set out the legal requirements for firms to prevent money laundering, including customer due diligence, ongoing monitoring, reporting suspicious activity, and keeping records.
These regulations are made under the Sanctions and Anti-Money Laundering Act 2018, which gives the UK government the power to create and update AML rules.
The Economic Crime and Corporate Transparency Act 2023 (ECCTA) strengthens the UK’s AML framework by improving transparency, enforcement, and corporate accountability.
Key AML impacts include:
Anti money laundering compliance covers the specific policies, controls, and procedures an organisation must implement to meet its legal obligations. It focuses on practical actions such as customer due diligence, transaction monitoring, suspicious activity reporting, record-keeping, and staff training.
Anti money laundering supervision is carried out by designated supervisors, including the Financial Conduct Authority (FCA) for financial institutions, HMRC for certain non-financial businesses, and professional body supervisors (such as the ICAEW, Law Society, or SRA) for accountants, lawyers, and other regulated professionals.
Firms must identify and comply with the supervisor relevant to their sector.
Firms that are subject to anti money laundering requirements must register with the appropriate supervisory authority for their sector.
For most businesses this is HM Revenue & Customs (HMRC), which supervises sectors such as accountancy service providers, estate agents, high-value dealers, and money service businesses.
Other sectors are supervised by professional bodies (e.g., FCA-regulated financial institutions, law firms supervised by the SRA, accountants supervised by ICAEW, etc.).
The MLRO (Money Laundering Reporting Officer) focuses on reporting suspicions, while the MLCO (Money Laundering Compliance Officer) focuses on preventing non-compliance.
MLRO (Money Laundering Reporting Officer):
Responsible for detecting and reporting suspected money laundering. They receive internal suspicious activity reports, decide whether they’re reportable, and submit SARs to the authorities.
MLCO (Money Laundering Compliance Officer):
Responsible for the overall AML framework. They design, implement, and monitor AML policies, procedures, training, and controls to ensure ongoing compliance.
No, a sole practitioner does not need to appoint a separate Nominated Officer.
Where an individual operates as a sole practitioner, they act as the Nominated Officer by default and are personally responsible for identifying and reporting suspicious activity in line with money laundering legislation.
A firm-wide risk assessment is a documented assessment of the money laundering and terrorist financing risks faced by an organisation.
It identifies and evaluates risks linked to the firm’s customers, services, transactions, delivery channels, and geographic exposure, and sets out the controls in place to mitigate those risks. The assessment must be kept up to date and used to shape the firm’s AML policies, procedures, and training.
A firm determines a customer’s risk rating by carrying out a risk-based assessment at onboarding and throughout the relationship.
This usually considers:
These factors are weighted using the firm’s firm-wide risk assessment to assign a low, standard, or high-risk rating, which then determines the level of due diligence and ongoing monitoring required.
A Politically Exposed Person (PEP) is an individual who holds, or has held, a prominent public function, either in the UK or overseas, and is therefore considered to present a higher risk of money laundering or corruption.
This includes, for example, senior politicians, judges, military officers, ambassadors, and senior executives of state-owned enterprises, as well as their immediate family members and known close associates.
PEPs are not presumed to be involved in wrongdoing, but they are subject to enhanced due diligence because their position may make them more vulnerable to bribery or misuse of funds.
The anti money laundering process is the series of steps organisations follow to identify and prevent attempts to move or conceal illicit funds. It includes customer due diligence, verifying identities, assessing risk, monitoring transactions, investigating unusual activity, and reporting suspicions to the appropriate authorities as required by AML regulations.
An anti money laundering check is a verification process used to confirm a customer’s identity and assess the risk that they may be involved in money laundering or terrorist financing. It includes identity verification, screening against sanctions and watchlists, and assessing the source of funds to ensure transactions are legitimate.
SDD (Standard Due Diligence) is the baseline requirement, while EDD (Enhanced Due Diligence) adds deeper checks and closer monitoring when risk is higher.
Standard Due Diligence (SDD):
Applied to lower or normal-risk customers. It involves verifying a customer’s identity, understanding the nature of the business relationship, and carrying out ongoing monitoring to ensure activity is consistent with expectations.
Enhanced Due Diligence (EDD):
Required where there is a higher risk of money laundering or terrorist financing (for example, politically exposed persons or complex or high-value transactions). It involves additional checks, such as obtaining more detailed information on the customer and source of funds or wealth, closer scrutiny, and more frequent monitoring.
Source of wealth (SoW) explains how someone became wealthy, while source of funds (SoF) explains where the money for this transaction comes from.
Source of Wealth (SoW):
Refers to how a person has acquired their overall wealth. This looks at the origin of their total assets (for example, salary over time, business ownership, inheritance, or investments).
Source of Funds (SoF):
Refers to where the specific money for a particular transaction comes from. This focuses on the immediate origin of the funds being used (for example, savings, sale of a property, or a loan).
Yes, electronic verification can be relied on, provided it is robust and appropriate to the level of risk.
Under money laundering law, electronic identity verification may be used on its own if it draws on reliable, independent sources, uses multiple data points, and provides a sufficient level of assurance.
However, where the customer or transaction presents a higher risk, electronic checks may need to be supplemented with additional evidence or enhanced due diligence.
In short: electronic verification is acceptable, but it must be fit for purpose and risk based.
Anti money laundering checks usually take a few minutes to a few days, depending on the complexity of the customer and the level of verification required. Straightforward checks, such as identity verification and basic due diligence, are often completed almost instantly using electronic systems.
Delays occur when information cannot be verified electronically, when additional documentation is needed, or when enhanced due diligence is required for higher-risk customers, which can extend the process to several days.
Anti money laundering documents can be certified by a suitably authorised person such as a solicitor, chartered accountant, notary, bank official, or another recognised professional who can verify identity documents in line with regulatory and organisational requirements.
An Ultimate Beneficial Owner (UBO) is the individual who ultimately owns or controls a customer or legal entity, even if ownership is held indirectly.
In money laundering law, this typically means a person who:
UBOs must be identified and verified as part of customer due diligence.
The duty to report discrepancies requires regulated businesses to report certain inconsistencies they identify between the beneficial ownership information they obtain during due diligence and the details held by Companies House.
If a material discrepancy is identified (for example, different beneficial owners or ownership percentages), it must be reported promptly. The duty supports transparency and helps prevent the misuse of companies for money laundering or terrorist financing.
A Suspicious Activity Report (SAR) is a formal report made when someone knows or suspects money laundering or terrorist financing.
In the UK, SARs are filed with the UK Financial Intelligence Unit, which sits within the National Crime Agency, via the SAR Online system.
SARs enable law enforcement to identify, analyse, and investigate suspected criminal activity.
In money laundering law, tipping off means informing someone that a suspicious activity report (SAR) has been made, or that an investigation is underway, where that information could prejudice an investigation.
It is a criminal offence to tip off a customer or any other person (for example by warning them, altering normal processes, or suggesting they are under suspicion) once a SAR has been submitted or is being considered.
A defence against money laundering (DAML) is a legal protection available when someone suspects money laundering but still needs to proceed with a transaction.
It applies where a Suspicious Activity Report (SAR) is submitted to the authorities before carrying out the suspicious activity, and either:
This provides a defence under UK law if the transaction is later found to involve criminal property.
Under the Money Laundering Regulations 2017, anti money laundering records (including customer due diligence documents and transaction records) must be kept for five years from the end of the business relationship or the date of the transaction. They must then be securely deleted unless another legal requirement permits or requires further retention.
Anti money laundering training provides employees with the knowledge and skills to recognise, prevent, and report suspicious activity, helping organisations comply with key legislation such as the Proceeds of Crime Act 2002 and the Money Laundering Regulations 2017.
Our CPD-accredited Anti Money Laundering Training provides practical, sector-relevant guidance to help staff meet their responsibilities and protect your organisation from misuse.
There is no fixed legal interval, but the Money Laundering Regulations require firms to provide regular, ongoing training to ensure staff remain competent. Training should be refreshed whenever risks, regulations, or job roles change, or when a need for updated knowledge is identified.
Penalties for non-compliance with money laundering law can be severe and include:
Penalties may apply to organisations and individuals, particularly where there is failure to carry out due diligence, report suspicious activity, or maintain effective AML controls.
In banking, anti money laundering involves applying robust checks and monitoring systems to identify high-risk customers, spot unusual or suspicious transactions, and block attempts to channel criminal funds through the financial system.
Banks must follow detailed regulatory requirements, verify customer identities, assess risk, and report concerns to prevent illicit money flowing through their services.