Anti Money Laundering Compliance FAQs

These FAQs help you understand anti money laundering compliance requirements, how checks and processes work, and the responsibilities firms must meet under UK law.

What is anti money laundering?

Anti money laundering (AML) refers to the laws and frameworks designed to stop criminals from making illegal funds appear legitimate. It includes the wider regulatory system that aims to detect, deter, and disrupt money laundering across financial and non-financial sectors.

What are the 3 stages of anti money laundering?

The three stages of anti money laundering are placement, layering, and integration.

Placement is the initial stage where illicit money is introduced into the financial system. Layering involves moving or disguising the funds through complex transactions to make them harder to trace. Integration is the final stage, where the laundered money is returned to the economy as apparently legitimate funds.

What is Anti Money Laundering Act?

The Anti Money Laundering Act is a legal framework, mainly made up of:

  • The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), which set out detailed AML requirements such as customer due diligence, record-keeping, and suspicious activity reporting.
  • The Sanctions and Anti-Money Laundering Act 2018 (SAMLA 2018), which gives the UK government powers to create, update, and enforce AML and sanctions regulations.
    Together, these laws form the basis of the UK’s anti-money laundering regime.

When was the Anti Money Laundering Act passed?

The Anti-Money Laundering Act, also called the Sanctions and Anti-Money Laundering Act 2018 (SAMLA 2018), received Royal Assent on 23 May 2018.

What are the anti money laundering regulations?

The anti money laundering regulations are the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017). They set out the legal requirements for firms to prevent money laundering, including customer due diligence, ongoing monitoring, reporting suspicious activity, and keeping records.

These regulations are made under the Sanctions and Anti-Money Laundering Act 2018, which gives the UK government the power to create and update AML rules.

How does the Economic Crime and Corporate Transparency Act affect AML?

The Economic Crime and Corporate Transparency Act 2023 (ECCTA) strengthens the UK’s AML framework by improving transparency, enforcement, and corporate accountability.

Key AML impacts include:

  • Stronger Companies House controls – identity verification for directors and persons with significant control (PSCs), and greater powers for Companies House to query, reject, and share suspicious information.
  • Improved information sharing – easier data sharing between regulated firms and law enforcement to prevent and detect economic crime.
  • Tougher enforcement – enhanced investigatory and sanctioning powers to tackle misuse of corporate structures.
  • Higher compliance expectations – firms must place greater emphasis on risk assessments, due diligence, and accurate ownership information.

What is anti money laundering compliance?

Anti money laundering compliance covers the specific policies, controls, and procedures an organisation must implement to meet its legal obligations. It focuses on practical actions such as customer due diligence, transaction monitoring, suspicious activity reporting, record-keeping, and staff training.

Who assumes responsibility for anti money laundering supervision?

Anti money laundering supervision is carried out by designated supervisors, including the Financial Conduct Authority (FCA) for financial institutions, HMRC for certain non-financial businesses, and professional body supervisors (such as the ICAEW, Law Society, or SRA) for accountants, lawyers, and other regulated professionals.

Firms must identify and comply with the supervisor relevant to their sector.

Who must firms register with for anti money laundering purposes?

Firms that are subject to anti money laundering requirements must register with the appropriate supervisory authority for their sector.

For most businesses this is HM Revenue & Customs (HMRC), which supervises sectors such as accountancy service providers, estate agents, high-value dealers, and money service businesses.

Other sectors are supervised by professional bodies (e.g., FCA-regulated financial institutions, law firms supervised by the SRA, accountants supervised by ICAEW, etc.).

What is the difference between an MLRO and an MLCO?

The MLRO (Money Laundering Reporting Officer) focuses on reporting suspicions, while the MLCO (Money Laundering Compliance Officer) focuses on preventing non-compliance.

MLRO (Money Laundering Reporting Officer):
Responsible for detecting and reporting suspected money laundering. They receive internal suspicious activity reports, decide whether they’re reportable, and submit SARs to the authorities.

MLCO (Money Laundering Compliance Officer):
Responsible for the overall AML framework. They design, implement, and monitor AML policies, procedures, training, and controls to ensure ongoing compliance.

Does a sole practitioner need to appoint a Nominated Officer?

No, a sole practitioner does not need to appoint a separate Nominated Officer.

Where an individual operates as a sole practitioner, they act as the Nominated Officer by default and are personally responsible for identifying and reporting suspicious activity in line with money laundering legislation.

What is a firm-wide risk assessment?

A firm-wide risk assessment is a documented assessment of the money laundering and terrorist financing risks faced by an organisation.

It identifies and evaluates risks linked to the firm’s customers, services, transactions, delivery channels, and geographic exposure, and sets out the controls in place to mitigate those risks. The assessment must be kept up to date and used to shape the firm’s AML policies, procedures, and training.

How does a firm determine a customer’s risk rating?

A firm determines a customer’s risk rating by carrying out a risk-based assessment at onboarding and throughout the relationship.

This usually considers:

  • Customer risk – who the customer is (for example, individual or corporate, ownership structure, PEP status).
  • Geographic risk – countries involved and their AML risk profile.
  • Product or service risk – the nature, complexity, and value of the services provided.
  • Transaction risk – size, frequency, and unusual or complex activity.
  • Delivery channel risk – how the customer is onboarded (for example, face-to-face or remote).

These factors are weighted using the firm’s firm-wide risk assessment to assign a low, standard, or high-risk rating, which then determines the level of due diligence and ongoing monitoring required.

What is a Politically Exposed Person?

A Politically Exposed Person (PEP) is an individual who holds, or has held, a prominent public function, either in the UK or overseas, and is therefore considered to present a higher risk of money laundering or corruption.

This includes, for example, senior politicians, judges, military officers, ambassadors, and senior executives of state-owned enterprises, as well as their immediate family members and known close associates.

PEPs are not presumed to be involved in wrongdoing, but they are subject to enhanced due diligence because their position may make them more vulnerable to bribery or misuse of funds.

What is anti money laundering process?

The anti money laundering process is the series of steps organisations follow to identify and prevent attempts to move or conceal illicit funds. It includes customer due diligence, verifying identities, assessing risk, monitoring transactions, investigating unusual activity, and reporting suspicions to the appropriate authorities as required by AML regulations.

What is an anti money laundering check?

An anti money laundering check is a verification process used to confirm a customer’s identity and assess the risk that they may be involved in money laundering or terrorist financing. It includes identity verification, screening against sanctions and watchlists, and assessing the source of funds to ensure transactions are legitimate.

What is the difference between standard and enhanced due diligence?

SDD (Standard Due Diligence) is the baseline requirement, while EDD (Enhanced Due Diligence) adds deeper checks and closer monitoring when risk is higher.

Standard Due Diligence (SDD):
Applied to lower or normal-risk customers. It involves verifying a customer’s identity, understanding the nature of the business relationship, and carrying out ongoing monitoring to ensure activity is consistent with expectations.

Enhanced Due Diligence (EDD):
Required where there is a higher risk of money laundering or terrorist financing (for example, politically exposed persons or complex or high-value transactions). It involves additional checks, such as obtaining more detailed information on the customer and source of funds or wealth, closer scrutiny, and more frequent monitoring.

What is source of wealth and source of funds?

Source of wealth (SoW) explains how someone became wealthy, while source of funds (SoF) explains where the money for this transaction comes from.

Source of Wealth (SoW):
Refers to how a person has acquired their overall wealth. This looks at the origin of their total assets (for example, salary over time, business ownership, inheritance, or investments).

Source of Funds (SoF):
Refers to where the specific money for a particular transaction comes from. This focuses on the immediate origin of the funds being used (for example, savings, sale of a property, or a loan).

Can I rely on electronic verification alone?

Yes, electronic verification can be relied on, provided it is robust and appropriate to the level of risk.

Under money laundering law, electronic identity verification may be used on its own if it draws on reliable, independent sources, uses multiple data points, and provides a sufficient level of assurance.

However, where the customer or transaction presents a higher risk, electronic checks may need to be supplemented with additional evidence or enhanced due diligence.

In short: electronic verification is acceptable, but it must be fit for purpose and risk based.

How long do anti money laundering checks take?

Anti money laundering checks usually take a few minutes to a few days, depending on the complexity of the customer and the level of verification required. Straightforward checks, such as identity verification and basic due diligence, are often completed almost instantly using electronic systems.

Delays occur when information cannot be verified electronically, when additional documentation is needed, or when enhanced due diligence is required for higher-risk customers, which can extend the process to several days.

Who can certify anti money laundering documents?

Anti money laundering documents can be certified by a suitably authorised person such as a solicitor, chartered accountant, notary, bank official, or another recognised professional who can verify identity documents in line with regulatory and organisational requirements.

What is an Ultimate Beneficial Owner?

An Ultimate Beneficial Owner (UBO) is the individual who ultimately owns or controls a customer or legal entity, even if ownership is held indirectly.

In money laundering law, this typically means a person who:

  • owns or controls more than 25% of the shares or voting rights, or
  • otherwise exercises significant control over the entity.

UBOs must be identified and verified as part of customer due diligence.

What is the duty to report discrepancies to Companies House?

The duty to report discrepancies requires regulated businesses to report certain inconsistencies they identify between the beneficial ownership information they obtain during due diligence and the details held by Companies House.

If a material discrepancy is identified (for example, different beneficial owners or ownership percentages), it must be reported promptly. The duty supports transparency and helps prevent the misuse of companies for money laundering or terrorist financing.

What is a Suspicious Activity Report and where is it filed?

A Suspicious Activity Report (SAR) is a formal report made when someone knows or suspects money laundering or terrorist financing.

In the UK, SARs are filed with the UK Financial Intelligence Unit, which sits within the National Crime Agency, via the SAR Online system.

SARs enable law enforcement to identify, analyse, and investigate suspected criminal activity.

What is tipping off?

In money laundering law, tipping off means informing someone that a suspicious activity report (SAR) has been made, or that an investigation is underway, where that information could prejudice an investigation.

It is a criminal offence to tip off a customer or any other person (for example by warning them, altering normal processes, or suggesting they are under suspicion) once a SAR has been submitted or is being considered.

What is a defence against money laundering?

A defence against money laundering (DAML) is a legal protection available when someone suspects money laundering but still needs to proceed with a transaction.

It applies where a Suspicious Activity Report (SAR) is submitted to the authorities before carrying out the suspicious activity, and either:

  • consent is given, or
  • the required statutory waiting period passes without refusal.

This provides a defence under UK law if the transaction is later found to involve criminal property.

How long must anti money laundering records be kept?

Under the Money Laundering Regulations 2017, anti money laundering records (including customer due diligence documents and transaction records) must be kept for five years from the end of the business relationship or the date of the transaction. They must then be securely deleted unless another legal requirement permits or requires further retention.

What is anti money laundering training?

Anti money laundering training provides employees with the knowledge and skills to recognise, prevent, and report suspicious activity, helping organisations comply with key legislation such as the Proceeds of Crime Act 2002 and the Money Laundering Regulations 2017.

Our CPD-accredited Anti Money Laundering Training provides practical, sector-relevant guidance to help staff meet their responsibilities and protect your organisation from misuse.

How often is anti money laundering training required?

There is no fixed legal interval, but the Money Laundering Regulations require firms to provide regular, ongoing training to ensure staff remain competent. Training should be refreshed whenever risks, regulations, or job roles change, or when a need for updated knowledge is identified.

What are the penalties for non-compliance?

Penalties for non-compliance with money laundering law can be severe and include:

  • Criminal penalties – unlimited fines and/or imprisonment (up to 14 years for some offences).
  • Civil and regulatory fines – imposed by supervisors such as the Financial Conduct Authority or HM Revenue & Customs.
  • Regulatory action – including public censure, removal of approvals, or loss of registration.
  • Reputational damage – which can significantly affect a firm’s ability to operate.

Penalties may apply to organisations and individuals, particularly where there is failure to carry out due diligence, report suspicious activity, or maintain effective AML controls.

What is anti money laundering in banking?

In banking, anti money laundering involves applying robust checks and monitoring systems to identify high-risk customers, spot unusual or suspicious transactions, and block attempts to channel criminal funds through the financial system.

Banks must follow detailed regulatory requirements, verify customer identities, assess risk, and report concerns to prevent illicit money flowing through their services.