
Regulated Business AML Guide for UK Firms

A weak AML process rarely announces itself through a single obvious failure. More often, it appears in an incomplete client file, an unexplained change in ownership, or a team member who is unsure what should be escalated. This regulated business AML guide sets out the practical controls UK firms need to manage financial-crime risk with confidence, while keeping compliance proportionate to the business they run.
For owner-managed firms and growing businesses, AML is not simply a box-ticking exercise. It protects your reputation, supports sound commercial decisions and demonstrates that your business takes its regulatory responsibilities seriously. The objective is clear: understand who you deal with, assess the risk of that relationship, monitor it appropriately and act when something does not make sense.
When AML rules apply to your business
The Money Laundering Regulations 2017 apply to a defined range of regulated businesses, including accountancy service providers, tax advisers, trust or company service providers, estate and letting agency businesses, legal professionals undertaking certain work, and financial services firms. The exact obligations depend on the service provided, not just the sector named on a company website.
An e-commerce retailer, for example, is not automatically within the regulated sector simply because it receives online payments or trades internationally. However, an online business offering regulated financial, property, accountancy or company-formation services may be. That distinction matters. Applying a full regulated-firm process where it is not required can create unnecessary administration, but assuming AML rules do not apply can expose directors to serious regulatory and reputational consequences.
Your supervisory authority will depend on your activity. Accountancy businesses may be supervised by a professional body or HMRC, while other sectors have different supervisors. Registration, policies and reporting arrangements should match the relevant supervisory regime.
Build your AML framework around real risk
The starting point is a documented business-wide risk assessment. This should not be a generic document downloaded once and left untouched. It needs to consider where your own exposure sits: the clients you serve, the services you offer, the countries involved, how payments are made, delivery channels and the scale or pattern of transactions.
A UK-based bookkeeping client paying monthly fees from a named business account may present a different risk profile from a new overseas company seeking urgent company-structure advice, paying through a third party and providing limited information about its owners. Neither example proves wrongdoing. The point is to identify which circumstances require more scrutiny before you proceed.
Your assessment should lead directly to workable policies, controls and procedures. If a risk is identified but nobody knows what action to take, the document has limited value. Staff need clear instructions on when to obtain identification, when to establish beneficial ownership, who approves higher-risk clients and how a concern is escalated.
Review the assessment at regular intervals and whenever the business changes materially. New service lines, expansion into additional markets, a change in client profile or emerging fraud methods can all alter the risk position.
Customer due diligence is more than collecting ID
Customer due diligence, often called CDD, is the process of establishing who the customer is and verifying that identity using reliable, independent sources. For companies and other entities, this also means understanding the ownership and control structure and identifying the ultimate beneficial owner or owners.
The process should give you a coherent picture of the relationship. You should know why the client requires your service, how the business operates, where relevant funds are expected to come from and whether the proposed activity is consistent with the information provided.
For lower-risk relationships, proportionate checks may be appropriate. Higher-risk cases require enhanced due diligence. This can include obtaining additional evidence on source of wealth or source of funds, securing senior management approval, conducting more frequent monitoring and taking additional steps to verify information.
Politically exposed persons, their family members and known close associates require particular care. Being a PEP is not an allegation of criminality, but it can increase the risk of bribery or corruption. The right response is a documented, risk-based assessment rather than an automatic refusal to act.
Beneficial ownership needs careful attention
Complex ownership is one of the areas where businesses often lose sight of the actual risk. A company may have several corporate shareholders, overseas entities or individuals exercising control through agreements rather than a straightforward shareholding. The beneficial ownership register can be useful, but it should not always be treated as the final answer.
Where the structure is unclear, take reasonable measures to understand it. Ask for supporting documents, trace ownership through the chain and record both the evidence obtained and any limitations. If you cannot complete CDD, the regulations may require you not to establish the relationship or to cease acting, depending on the circumstances.
Make ongoing monitoring part of normal operations
AML checks are not finished once a client has been onboarded. Ongoing monitoring means reviewing the relationship and transactions so that they remain consistent with what you know about the client and their risk profile.
For an accounting or advisory firm, this may involve noticing a major shift in trading activity, frequent payments from unrelated third parties, a sudden overseas expansion with no clear commercial explanation, or directors who avoid reasonable questions about the origin of funds. A single unusual transaction is not necessarily suspicious. What matters is whether the activity can be explained plausibly in the context of the client relationship.
The most effective approach is to build monitoring into existing workflows. Teams reviewing bookkeeping records, management accounts, payroll, VAT returns or payment data are often best placed to spot anomalies. They need enough AML training to recognise potential red flags, but they should not be expected to investigate alone.
Reporting concerns without tipping off
Every regulated business should appoint a nominated officer, commonly called the Money Laundering Reporting Officer or MLRO. Staff must know how to report an internal suspicion to that person promptly and confidentially.
The MLRO considers whether there is knowledge or suspicion of money laundering, or reasonable grounds for it, and whether a Suspicious Activity Report should be made to the National Crime Agency. This decision should be documented. A SAR is not a declaration that a client is guilty. It is a protected report made where the legal threshold is met.
One rule is especially important: do not tip off the customer. Telling a client that a report has been made, or disclosing information likely to prejudice an investigation, may be a criminal offence. Communications should remain professional and carefully managed. If work must pause while consent is sought or guidance is obtained, the explanation given to the client should not reveal the underlying suspicion.
Keep records that evidence your decisions
Good records show both what you checked and why you were satisfied with the outcome. Retain copies of identification and verification evidence, beneficial ownership information, risk assessments, transaction records, internal reports, training records and decisions made by the MLRO.
Under the UK regulations, CDD and transaction records are generally retained for five years from the end of the business relationship or completion of an occasional transaction. Record retention must also be handled with data-protection obligations in mind. Keep only what is required, secure it properly and dispose of it safely once the retention period has ended, unless there is a lawful reason to retain it longer.
A clear audit trail is valuable even where no suspicious activity is found. If a supervisor asks how a higher-risk relationship was assessed, a well-maintained file demonstrates considered judgement rather than retrospective reconstruction.
Training, ownership and practical testing
AML compliance cannot sit solely with the MLRO. Directors retain responsibility for ensuring appropriate systems are in place, while everyone involved in client onboarding, service delivery and payments should understand their role.
Training should be relevant to the work staff actually perform. A colleague collecting client documents needs to recognise incomplete or inconsistent information. A manager approving a complex engagement needs to understand enhanced due diligence and escalation. Refresher training should address new risks, regulatory changes and lessons from internal cases.
It is also sensible to test the process. Sample a number of client files. Check whether risk ratings are supported by evidence, whether beneficial owners have been identified correctly and whether review dates are being met. The purpose is not to catch people out. It is to identify process weaknesses while they can still be corrected.
For regulated businesses, effective AML controls create more than compliance comfort. They provide better visibility over who the business serves, support consistent client acceptance decisions and reduce the chance that commercial growth brings unmanaged risk. Where the requirements feel complex, specialist advice can help turn them into a disciplined process that protects both the firm and its clients.




Comments