One Constellation
Regulations

UK AML Compliance: MLR 2017 and What the FCA Expects

The UK anti-money laundering regime is not a single rulebook. It is assembled from several instruments that operate together, and firms that read only one of them tend to discover the others during an enforcement action.

Published: September 2026 Category: Regulations Read time: ~4 minutes
Quick Answer
Four components matter. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 — universally "MLR 2017" — set the preventative obligations. The Proceeds of Crime Act 2002 creates the reporting duties and the criminal offences. The FCA supervises and enforces, with expectations set out principally in its Financial Crime Guide. And guidance from the Joint Money Laundering Steering Group carries particular weight, because courts and regulators must take approved JMLSG guidance into account when considering whether a firm complied.

MLR 2017: the preventative obligations

Risk assessment

Regulation 18 requires a written, regularly updated firm-wide risk assessment, and it must be made available to the supervisor on request. Regulation 19 requires policies, controls and procedures proportionate to it. This is not a documentation formality — it is the foundation the FCA tests first, and a weak assessment undermines every control decision that depends on it. See how to build one.

Customer due diligence

Regulations 27 to 38 cover CDD: when it applies, what it requires, and when enhanced or simplified measures are appropriate. Enhanced due diligence is mandatory for high-risk third countries, for politically exposed persons and their family members and known close associates, for correspondent relationships, and in any case presenting higher risk.

The UK's PEP treatment deserves attention. The FCA has been explicit that domestic PEPs should generally be treated as lower risk than foreign PEPs absent other risk factors, and has criticised firms applying blanket high-risk treatment that resulted in unjustified de-risking. Applying a uniform approach to all PEPs is now a supervisory risk in both directions.

Ongoing monitoring

Regulation 28(11) requires scrutiny of transactions for consistency with the firm's knowledge of the customer, and keeping documents and information up to date. That phrase — consistency with knowledge of the customer — is the legal basis for profile-based monitoring, and it is why a monitoring configuration disconnected from CDD data is difficult to defend. See perpetual KYC.

Systems, controls and personnel

Regulation 21 requires, where appropriate to size and nature, a board member or senior manager responsible for compliance, an appointed nominated officer, screening of relevant employees, and an independent audit function to examine and evaluate the controls. That independent audit requirement is frequently overlooked by smaller firms — see AML internal audit.

POCA: reporting and personal exposure

The Proceeds of Crime Act creates the duty to report. In the regulated sector, a person who knows or suspects — or has reasonable grounds to know or suspect — money laundering must make a disclosure. Failure to do so is a criminal offence for the individual, not merely a regulatory matter for the firm.

Two features shape UK practice. The objective test: "reasonable grounds to suspect" means a person can commit the offence without actually having suspected, if a reasonable person would have. This is why the quality of alert disposition reasoning matters so much in the UK. And the consent regime: where a firm would otherwise commit a principal money laundering offence by proceeding, a Defence Against Money Laundering request can be submitted to the UKFIU, with statutory notice and moratorium periods governing what happens next.

Tipping off is a separate offence. Firms need procedures ensuring customer-facing staff cannot inadvertently disclose that a report has been made — including through system messages or unexplained account restrictions.

SMCR: individual accountability

The Senior Managers and Certification Regime attaches personal accountability to the financial crime function. SMF17 is the Money Laundering Reporting Officer function, and the holder has a statement of responsibilities and a duty to take reasonable steps to prevent regulatory breaches in their area.

The practical consequence: an MLRO without adequate resource, authority or access to information has a personal interest in documenting that fact and escalating it. See the MLRO role and personal liability.

Where UK firms most often come unstuck

  • Risk assessments that are not firm-specific. A generic document that could describe any firm fails Regulation 18 in substance even if it exists in form.
  • Blanket PEP treatment. Both over-application and under-application now carry supervisory risk.
  • No independent audit. Regulation 21(1)(c) is frequently missed by firms that consider themselves too small for a third line, without documenting why it is not appropriate.
  • Monitoring disconnected from CDD. Rules that do not reference the customer's expected activity cannot deliver consistency with knowledge of the customer.
  • Thin disclosure reasoning. Given the objective test, a closure note that does not show the reasoning creates individual exposure.

Practical starting point

If you are establishing or reviewing a UK programme, read the JMLSG guidance for your sector alongside MLR 2017 rather than after it. The guidance is where the regulations become operational, and its approved status means following it is evidentially useful in a way that following an internal interpretation is not.

Note that this is a summary, not legal advice, and the UK regime has been amended repeatedly since 2017 — verify the current text of any provision you intend to rely on.

How the FCA Supervises in Practice

Supervision is risk-based and largely thematic. Firms encounter it in four forms, and preparation differs for each.

Thematic reviews and multi-firm work

The FCA examines a specific control across a population of firms and publishes the findings. These publications are the clearest available statement of expectation, and a firm that cannot show it read and considered a relevant review is in a weak position if the same weakness is later found on site.

"Dear CEO" letters

Sector-specific letters setting out identified harms and expected actions. They are addressed to the accountable individual deliberately. The expectation is a documented board-level response, not circulation.

Information requests and skilled person reviews

Section 166 reviews commission an independent skilled person at the firm's expense. They typically follow an identified concern, and their findings carry substantial weight.

Across all four, the recurring theme in published enforcement is not absent controls but controls that existed on paper and were not operating — monitoring not calibrated to the business, CDD files never refreshed, alerts closed without reasoning recorded.

Record-Keeping, and the Tension With Data Protection

Regulation 40 requires records of CDD and transactions to be kept for five years from the end of the business relationship or the date of the occasional transaction, after which personal data must generally be deleted unless another obligation or consent applies.

That creates a genuine tension with UK GDPR, and the resolution is a documented retention schedule that states what is kept, for how long, on what legal basis, and how deletion is executed. Firms fail this in both directions: indefinite retention "in case it is needed", and deletion that destroys the audit trail supporting a filed report.

Two practical points. A suspicious activity disclosure and its supporting material sit on a different footing from routine CDD and should be scheduled separately. And deletion has to be operable — a policy promising deletion from systems that have no deletion capability is a finding waiting to be made. See GDPR and AML for the wider framework.

Standing Up a UK Programme From Scratch

Firms entering the UK market, or newly brought into scope, face the regime in a particular order. Taking it in that order avoids most of the rework.

Establish scope before anything else

Determine precisely which regulated activities the firm will carry on and therefore which parts of MLR 2017 and which JMLSG sector guidance apply. Scope errors propagate into every later document.

Write the risk assessment first, not the policy

Regulation 18 comes before Regulation 19 for a reason. A policy written ahead of the assessment will describe generic controls and will not survive the question of why those controls suit this firm.

Appoint before you launch

The nominated officer and, where applicable, the SMF17 holder must be in place with a statement of responsibilities, adequate seniority and a reporting line that does not run through the revenue side.

Plan for independent review at the outset

Regulation 21(1)(c) applies where appropriate to size and nature. Firms that decide it is not appropriate should record that reasoning contemporaneously; the decision is defensible, the silence is not.

The most common early failure is treating the JMLSG guidance as optional reading. Its approved status makes following it evidentially useful in a way that an internal interpretation is not.

MLR 2017 Obligations, Operationalised

One Constellation covers CDD and EDD, ongoing monitoring consistent with your knowledge of the customer, and the record-keeping the FCA expects to see on inspection.

← PEP Screening Best Practices The MLRO Role All Articles
Scroll to Top