Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.
All insights

AML KYC Requirements UK: Compliance Guide

AML KYC requirements in the UK explained for financial services compliance officers, covering CDD, SARs, PEPs, records and FCA readiness.

17 September 2026

AML KYC Requirements UK: Compliance Guide

For a UK-regulated financial services firm, AML and KYC are not simply onboarding checks. They are an integrated control framework covering business risk assessment, customer due diligence, beneficial ownership, ongoing monitoring, escalation, reporting, governance and evidence. This guide explains the core AML KYC requirements UK compliance officers should be able to demonstrate in policy, process and customer files.

Book a call about your AML and KYC framework

What AML and KYC mean for UK-regulated firms

Short answer: AML is the wider framework used to prevent money laundering and terrorist financing. KYC is the customer-identification and risk-assessment process within that framework. For a UK-regulated firm, effective controls connect customer identity, beneficial ownership, purpose, risk rating, monitoring, escalation and record keeping rather than treating KYC as a one-off document collection exercise.

Anti-money laundering controls address the risk that a firm, product or channel could be used to move or disguise criminal property. Know Your Customer controls help the firm understand who it is dealing with, who ultimately owns or controls the customer, why the relationship is being established and whether the activity is consistent with the stated profile.

The exact obligations depend on the firm's activities, sector, customer base and regulator. FCA-supervised firms should read the FCA guidance on money laundering and terrorist financing alongside the Money Laundering Regulations 2017, applicable FCA rules and relevant industry guidance.

For boards and senior managers, the practical test is whether the firm can show that its controls are proportionate to its risks and operate in practice. A policy that describes an ideal process is not enough if customer files, monitoring alerts, approvals and management information do not evidence that process.

The Money Laundering Regulations 2017: core obligations

Short answer: The Money Laundering Regulations 2017 require relevant firms to assess risk, maintain policies and controls, conduct customer due diligence, apply enhanced measures where risk is higher, monitor relationships, keep records and appoint appropriate responsibility for the AML framework. FCA-supervised firms must also meet complementary FCA requirements and be able to evidence effective governance.

The Regulations are risk based. A firm should begin with a documented business-wide risk assessment that reflects its customers, products, services, delivery channels and geographic exposure. That assessment should inform the design of controls, not sit separately from them.

Core areas for a UK financial services compliance framework include:

  • Governance: clearly assign responsibility for AML systems and controls to appropriate senior management, with an MLRO or nominated officer where required.
  • Business-wide risk assessment: identify and assess money laundering and terrorist financing risks, then document the rationale for control design.
  • Customer due diligence: identify and verify the customer, beneficial owners and anyone acting on the customer's behalf.
  • Purpose and intended nature: understand why the relationship exists and what activity should reasonably be expected.
  • Ongoing monitoring: review transactions and customer information so unusual or inconsistent activity can be investigated.
  • Policies, controls and procedures: give staff practical instructions, escalation routes and approval requirements.
  • Training and awareness: ensure relevant staff understand their responsibilities and how to escalate concerns.
  • Independent testing and remediation: assess whether controls work, record weaknesses and track corrective action.

The Regulations also contain specific requirements on record keeping. Regulation 40 requires relevant records, including CDD information and supporting transaction records, to be retained for at least five years from the relevant end date, subject to the detailed provisions and any applicable longer period. Firms should confirm the retention approach with their legal and compliance advisers rather than relying on a generic schedule.

Regulation 28 sets out customer due diligence measures, while Regulation 40 addresses record keeping. These links are useful starting points, but the current consolidated legislation and relevant sector guidance should be checked when a policy is updated. Regulation 33 covers enhanced customer due diligence, with Regulation 35 addressing politically exposed persons.

How should firms apply standard, simplified and enhanced CDD?

Short answer: Standard CDD is the baseline process for identifying and verifying a customer, identifying beneficial ownership and understanding the relationship. Simplified due diligence is available only where a documented risk assessment supports it. Enhanced due diligence applies where a relationship presents higher risk, including relevant PEP, geographic, product or transaction risk.

Customer due diligence should be designed around the firm's risk appetite and customer journey. A useful file should allow an independent reviewer to understand what was checked, what was learned, how the risk rating was reached and what monitoring will follow.

CDD approach

When it may apply

Evidence compliance officers should expect

Standard CDD

Ordinary relationships within the firm's assessed risk profile

Identity and verification, ownership and control, purpose, risk rating and approval

Simplified due diligence

Lower-risk situations where the firm's assessment supports reduced measures

Recorded rationale, scope of reduced measures and ongoing review

Enhanced due diligence

Higher-risk relationships, unusual activity, higher-risk jurisdictions, complex structures or relevant PEP exposure

Additional information, source of wealth or funds where appropriate, senior approval and enhanced monitoring

For corporate customers, the file should explain the ownership and control chain rather than simply attach a company extract. For trusts, partnerships and similar structures, the firm should identify the relevant parties and understand how control operates. If information is incomplete or inconsistent, the issue should be resolved or escalated before the relationship proceeds.

Ongoing due diligence is equally important. A relationship should be reviewed when circumstances change, when activity is inconsistent with the expected profile, or when a periodic review is due. FCA findings published in 2026 identified recurring weaknesses in practical procedures, event-driven reviews, documentation of EDD and evidence of how controls differ between lower and higher-risk customers. These are useful prompts for a targeted file review.

Review your regulatory compliance controls with Aureliant Global

What are the obligations when a firm suspects money laundering?

Short answer: A suspicion should follow the firm's internal escalation process to the nominated officer or MLRO. Where a report is required, the regulated-sector reporter should submit a Suspicious Activity Report to the UK Financial Intelligence Unit through the NCA SAR Portal as soon as practicable. Staff must also avoid tipping off the customer.

A KYC discrepancy is not automatically a SAR. However, unexplained ownership, inconsistent source of funds, unusual transaction patterns, evasive responses or other indicators may require escalation. The firm's procedures should define how staff record the facts, protect confidentiality, preserve evidence and refer the matter to the person responsible for the reporting decision.

The National Crime Agency guidance on Suspicious Activity Reports explains that SARs are submitted to the UKFIU, which receives, analyses and disseminates them in the United Kingdom. A SAR does not replace a police or fraud report where another reporting route is also required.

The practical control questions are:

  • Can staff recognise and escalate a concern without trying to investigate beyond their role?
  • Does the MLRO or nominated officer have a clear decision record?
  • Are SAR decisions, including decisions not to report, documented with reasons?
  • Are consent or defence requests handled through the correct process where relevant?
  • Does the firm control communications so it does not tip off a customer?

Reporting duties can involve criminal offences and regulatory consequences. This is an area where a firm should obtain specific legal or regulatory advice if the facts are uncertain.

Why do PEPs require enhanced scrutiny?

Short answer: A politically exposed person, or PEP, holds or has held a prominent public function. UK rules require risk-management systems to identify PEPs, their family members and known close associates, and to apply proportionate enhanced measures. A PEP should not be treated as automatically suspicious or automatically high risk.

The firm's process should assess the individual relationship, not apply a blanket response that creates unnecessary friction for every PEP. Relevant factors can include the public function, country and sector risk, products used, ownership structure, source of wealth, source of funds and transaction behaviour.

The FCA's FG25/3 guidance on the treatment of PEPs states that firms should apply a proportionate and risk-based approach. The current UK framework also recognises that UK PEPs and their family members or close associates should generally start from a lower-risk position where no other enhanced risk factors are present.

For a higher-risk relationship, enhanced measures may include obtaining additional information about source of wealth and source of funds, increasing monitoring and obtaining senior management approval to establish or continue the relationship. The reasons for the risk assessment and the approval should be documented. Policies should also explain how the firm reviews PEP status over time and how it handles a customer who is no longer in a prominent public function.

How can a firm prepare for an FCA AML supervisory visit?

Short answer: Preparation should show that the AML framework works from risk assessment through customer files, monitoring, escalation, reporting, training, management information and independent testing. Compliance officers should reconcile policy with practice, identify gaps before the visit and prepare an evidence pack that is easy for supervisors to navigate.

An FCA review may involve questionnaires, desk-based document requests, customer file sampling, staff interviews and testing of control effectiveness. Firms should be ready to explain not only what their policies say, but how decisions are made and evidenced in day-to-day operations.

A practical readiness review should cover:

  1. Business model and risk: confirm that the business-wide risk assessment reflects current products, customers, jurisdictions, distribution channels and growth.
  2. Governance: map board and senior management oversight, MLRO responsibilities, committee reporting and escalation decisions.
  3. Customer files: sample new, high-risk, PEP, declined and long-standing relationships. Check identity, beneficial ownership, purpose, risk rating, approvals and review dates.
  4. Monitoring and alerts: test whether scenarios, thresholds, investigations and closures are documented and proportionate to risk.
  5. SAR governance: review escalation records, decision logs, reporting quality, confidentiality and staff awareness of tipping-off risk.
  6. Training: confirm that training is role specific, current and linked to the firm's actual products and risk profile.
  7. Independent assurance: evidence second-line monitoring, internal audit or other independent testing, findings, owners and remediation dates.
  8. Management information: give senior management meaningful information about volumes, overdue reviews, high-risk customers, alerts, SARs, testing findings and open actions.

The FCA's 2026 review of CDD, EDD and ongoing due diligence found that stronger firms documented each stage of EDD, used clear approval requirements and maintained independent oversight. That points to an important distinction: having a control is not the same as being able to demonstrate that it operated, was reviewed and improved when weaknesses were found.

AML and KYC readiness checklist for compliance officers

Short answer: A defensible AML and KYC framework connects risk assessment to operating controls and evidence. Before a supervisory review, compliance officers should be able to trace a sample customer from onboarding through risk rating, monitoring, review, escalation and closure, with clear ownership at each stage.

  • Business-wide risk assessment approved, current and linked to the control framework.
  • Customer risk-rating methodology documented, tested and consistently applied.
  • Beneficial ownership and control checks completed for relevant legal entities.
  • Standard, simplified and enhanced CDD criteria defined with approval routes.
  • Purpose and intended nature of the relationship recorded in usable terms.
  • Event-driven and periodic review triggers identified and monitored.
  • PEP, sanctions, adverse media and geographic-risk processes proportionate to risk.
  • MLRO or nominated officer escalation, SAR and tipping-off procedures understood by staff.
  • CDD, monitoring, training, policy and testing records retained for the required period.
  • Independent assurance findings tracked to closure and reported to senior management.

For regulated businesses, the most valuable review is usually a focused test of how the framework operates, not a longer policy document. Sampling customer files, tracing decisions to evidence and checking whether management information supports action can reveal weaknesses before a regulator does.

Request a consultation on AML and KYC readiness

Frequently asked questions

What is the difference between AML and KYC in the UK?

AML is the wider system of policies, controls and reporting used to prevent money laundering and terrorist financing. KYC is the customer-focused part of that system, including identity verification, beneficial ownership, risk assessment, understanding the relationship and ongoing due diligence.

Are AML and KYC checks required for every customer?

Firms must apply customer due diligence in the circumstances set out in the Money Laundering Regulations, including when establishing a business relationship, where there is suspicion, where identity information is doubtful and when existing-customer circumstances require it. The depth of checks should reflect risk.

Do all PEPs automatically require the same level of enhanced due diligence?

No. PEPs, family members and known close associates must be identified and managed through appropriate risk systems, but the measures should be proportionate to the individual risk. UK PEPs are not automatically high risk where no other enhanced risk factors are present.

How long should AML and KYC records be kept?

Regulation 40 of the Money Laundering Regulations 2017 generally requires relevant CDD and transaction records to be kept for at least five years from the applicable end date, subject to detailed provisions and any longer retention period that may apply.

Who submits a Suspicious Activity Report?

The firm's nominated officer or MLRO normally makes the reporting decision and submits a SAR where required. Staff should escalate concerns through the firm's procedure and should not alert the customer to a report or investigation where doing so could amount to tipping off.

Important: This article is general information for UK financial services compliance professionals. It is not legal advice and does not replace the firm's obligations to obtain current regulatory, legal or professional guidance for its specific business model, customers and jurisdictions.

Aureliant Global is an ICAEW-regulated chartered accountancy firm supporting UK and international businesses with regulatory compliance, financial services advisory and partner-led implementation support. +44 20 7967 1177 | Contact Aureliant Global.

For a tailored review, contact Aureliant Global.