UK AML Regime Review – Key Takeaways for Accountants, Lawyers, TCSPs
What's Included
Last year, the UK government carried out an exercise to collect feedback on the effectiveness of the county’s Anti-Money Laundering (AML) regime. This Call for Evidence sought opinions from the industry, law enforcement, supervisors, broader public and civic society. The responses have helped shape the recently published review of the UK’s AML/CFT regulatory and supervisory regime. The report provides a snapshot of the current AML landscape within the UK but more importantly it sheds light on what’s in store in the near future. What changes to the UK’s AML regime should we expect in the near future? And what will remain as is?
This is the first of two articles that lists the key takeaways that are highly relevant for individuals working in industries such as accountancy, audit, legal, tax advisory, trusts and company service provides (TCSPs). This article focuses on general concepts whilst the second article will deal with the government’s position in terms of specific regulations.
The UK is committed to fight money laundering, and you should too
In his forward, John Glen, Economic Secretary to the Treasury at the time, puts a very strong and clear message about the commitment of the UK government to fight economic crime and for the country to retain high and robust standards in maintaining this objective. All threats to the integrity of the UK economy will be fully speedily dealt with.
There is an understandable sense of pride that the UK is a global leader in the fight against money laundering. Reference is made to the fact that AML efforts managed to stop £172 million being funnelled into accounts owned by suspected criminals in the twelve months preceding March 2020.
On the other hand, the government acknowledges that the country’s attractive economy attracts criminals from around the world and that there is always room for improvement. The report points out the various reforms targeted at addressing money laundering and economic crimes such as the Economic Crime (Transparency and Enforcement) Act 2022, introducing the Register of Oversees Entities, which was fast-tracked by the government in response to Russia’s invasion of Ukraine.
One last piece of evidence on the UK’s commitment to combat money laundering is the report itself, which analysis the current AML landscape, identifies potential gaps in regulation and supervision and suggests ways of addressing shortcomings.
#1 Key takeaway for your organisation:
Given, the amount of effort the government is putting into AML, there is an expectation that firms and individuals at the frontline of this fight (accountants, auditors, law firms, TCSPs, etc…) give it their utmost importance.
Effectiveness is the name of the game
The report references the UK’s most recent evaluation by the FATF, an international organisation that sets the global standards for anti-money laundering. The evaluation makes a distinction between the technical compliance (i.e. how well the laws and regulations align with the standards the FATF recommends) and the effectiveness in implementing them to reduce money laundering. On the technical front the UK is a world-leader. There is, however, room for improvement on the effectiveness front.
In fact, the report makes minimal proposals in terms of changes to legislation itself. The word “effectiveness” is however mentioned constantly and it is clear that the government’s focus is ensuring that the AML regulations and guidelines put in place are adhered to and deliver results.
A key element that is of interest to the accountancy and legal sectors is that the UK acknowledges the FATF’s evaluation of significant weaknesses in legal and accountancy supervision and reporting of suspicious transactions.
#2 Key takeaway for your organisation:
With the focus of the government firmly grounded in effectiveness rather than legislation, we should not expect drastic changes to the rulebook itself. However, as per the conclusion for the previous point, firms will be expected to step up their AML game and become more effective.
A slight divergence from EU regulations
The feedback received via the Call for Evidence included requests to relax some anti-money laundering regulations. The criteria used by the government in determining whether such changes to the regulation are acceptable is based on two key points.
The first point is around whether the proposed alterations increase the risk of criminal activity going undetected. Since most clients are genuine, some AML checks may sometimes be deemed excessive. However, these checks are there to make sure nothing slips through the cracks. Even if a regulation addresses a scenario that is rarely likely to lead to a suspicion of money laundering, it nevertheless needs to be kept in place to prevent the introduction of weak links in AML processes.
The second point deals with whether the regulation is derived directly from FATF guidelines. The report notes that the UK is a founding member of the FATF and is committed to abide by the international standards it sets. As a result, the government will not compromise on any regulation that can be directly traced back to the FATF guidelines. There are scenarios, however, where the EU’s Anti-Money Laundering Directives (AMLD), especially the fourth and fifth AMLD, are considered to have gone beyond FATF requirements. In such cases the government has shown willingness to relax some regulations which were put in place as part of the transposition of the EU’s 4th and 5th AMLD into UK laws in 2017 and 2020. One such example is the treatment of domestic PEPs, which we will discuss in our next article.
#3 Key takeaway for your organisation:
There might be a few changes to regulations, but most of the rules are going to remain the same.
Small/Newer Firms need to apply a Risk-Based Approach (RBA)
A couple of paragraphs in the report are dedicated to small firms or those that have only recently become subject to AML regulations. Responses to the Call for Evidence highlight the unique challenges such firms may have. For starters, such organisations may have limited knowledge of AML concepts and regulations. Moreover, they may not have the right set up and resources to take on the onerous obligations that such regulations entail. Some respondents requested the government to make exempt such organisations from implementing a Risk-Based Approach (RBA) and provide them with a list of mandatory requirements to follow.
This idea was shot down by the government for two reasons. The first is that it is not viable to have two sets of requirements that apply to the same sector based on whether the firm is new or not. Secondly, creating an exception to follow a risk-based approach is not compatible with FATF recommendations. The RBA is in fact the foundation of most FATF requirements and empowers any entity that deals with AML, including firms, to allocate more resources to high-risk scenarios as opposed to those posing a lower risk. It is no surprise therefore that while the government is keen to identify ways to support small and new firms with their AML obligations, it cannot make such an exception and all firms are expected to apply an RBA, irrespective of size or maturity.
#4 Key takeaway for your organisation:
Small and new firms are obliged to understand regulations and allocate enough resources to enable them to follow a risk-based approach to AML.
Major reforms to supervisory structure may be round the corner
One of the three main sections of the report deals with supervision. Within the UK’s AML regime, supervisors are organisations that are responsible for ensuring that firms that fall within their remit are adhering to AML regulations, engage in ongoing monitoring of such firms and issue sector-specific guidance.
The large number of AML supervisory bodies in the UK may be of concern. Supervision of the legal and accountancy sector, for example, is spread across 22 Professional Body Supervisors (PBS). In theory, having a large number of supervisors could be positive since it allows these bodies to specialise and adapt to the various nuances of a sector or geography. For example, the Institute of Chartered Accountants of Scotland would be expected to be more in tune with accountants in Scotland as opposed to a generic supervisory board.
This does create a few issues though. For starters, the report references recent studies that show that not all supervisors are as effective as they should be. Other issues include the fact that standards across different supervisors will vary and there are cases of “supervisory gaps” – for example legal practitioners may be offering a service that falls under the scope of AML regulations even though they are not members of a PBS.
The above may be one of the reasons why the financial services sector has lamented about the discrepancy between the AML standards within its industry when compared to those within other sectors such as accountancy and legal. This is corroborated by the criticism made by the FATF when assessing the UK in 2018 and also reiterated in the latest National Risk Assessment (NRA).
The government has acknowledged that these issues need to be addressed and is studying various ways in which the supervisory regime is overhauled. One option is to empower OPBAS (the body responsible for supervising the PBSs) to be more effective. Other options include establishing a single AML supervisor or reducing the number of supervisors by either consolidating multiple PBSs or establishing a Single Professional Services Supervisor.
#5 Key takeaway for your organisation:
The report reiterates the government’s reluctance to make much regulatory changes in the near future. This stands in stark contrast to the section of the report considering major supervisory reform. While changes will not happen overnight, it is important to note that reforms may be on the way. A few years from now, you may have the same AML obligations, but the supervisory structure may be totally different.
A Risk-Based Approach?
The Risk-Based Approach (RBA) is the cornerstone of FATF guidelines. This concept was born out of the need to move away from a prescriptive checklist approach and empower entities (including regulators, supervisors and firms) with the ability to put more resources on higher risk scenarios as opposed to those that are deemed to be lower risk. One major criticism of current regulations is that mandatory requirements are not compatible with the risk-based approach, and some advocated for the complete removal of such prescriptive provisions.
After all, how can firms truly implement an RBA if a connection to a list of high-risk jurisdictions as published by the UK government automatically triggers enhanced due diligence (EDD)? Shouldn’t firms be allowed to decide whether this jurisdiction is high risk for them? What if a client they know is low risk deals with such a jurisdiction – why does that automatically trigger EDD?
The government’s report unequivocally states that it is not considering making major changes to existing regulations, and it is not minded to do an overhaul of mandatory requirements. The rationale here is that the FATF does agree with the inclusion of prescriptive requirements and that given the country’s vulnerability to financial crime, the UK has a duty to be even more forceful than other countries in implementing mandatory requirements. There may be instances where some minor elements may be relaxed, as discussed in our previous article, but the government considers that current regulations provide the right balance between promoting a risk-based approach and ensuring that high-risk scenarios are dealt with effectively.
#6 Key takeaway for your organisation:
AML processes cannot be effective without implementing a risk-based approach that ensures you put more resources on clients that are deemed high risk. However, it is important to adhere to any mandatory requirement put in place within the regulations. Most of these requirements are not going to go away anytime soon.
Does the complexity or size of a transaction matter?
Notwithstanding the reluctance by the government to do away with mandatory requirements, there is one particular scenario that may be reconsidered. Firms are obliged to carry out ongoing monitoring – i.e. they should keep monitoring a client and their activities after the client has been onboarded. One of these requirements is the scrutiny of transactions. This makes sense – an unusually large or complex transaction may raise suspicion of illegal activities. The current regulations, however, go beyond this and mandate that enhanced due diligence be triggered in cases where there is a “complex or unusually large transaction”.
But what does “complex” mean? At what point does the size of the transaction become “unusually large”? And does it even matter? There may be a valid reason for a one-off transaction being an outlier. Why does this necessitate the automatic triggering of EDD?
While the report states that this concept is directly lifted from FATF recommendations, the government does acknowledge that there may be room for improvement in the wording of the regulation and that there is a need to ensure that transactions that are low-risk do not automatically trigger EDD just because they are “complex” or “unusually large”.
#7 Key takeaway for your organisation:
Current regulations do mandate EDD in cases of complex or unusually large transactions. But there may be some subtle changes in the near future.
A PEP is a PEP is a PEP – or is it?
A basic concept of anti-money laundering processes is treating politically exposed persons (PEPs) as high risk. This is because individuals that are entrusted with prominent public functions, together with their families and close associates, could abuse their position for money-laundering purposes or could get involved in corruption and bribery situations. Under current regulations a PEP automatically triggers enhanced due diligence. The FATF however makes a distinction between a foreign PEP and a domestic PEP, with the former requiring a higher level of scrutiny. This makes sense. After all, criminals who are politically exposed may attempt to engage the services of a firm in a foreign jurisdiction where their PEP status may go unnoticed, where they may be out of reach of local legislation or where allegations of bribery and corruption may not be well known.
Locally, the distinction between domestic and foreign PEPs was removed as part of the EU’s fourth Anti-Money Laundering directive, and under current regulations “a PEP is a PEP” and requires the application of EDD. The case for treating domestic and foreign PEPs differently is a strong one. To begin with, the requirement does not stem from FATF recommendations. Moreover, the UK’s National Risk Assessment (NRA) lists the risk from domestic PEPs as being low. The government acknowledges that this may be putting an unnecessary burden on local PEPs who genuinely need the services of accountants, auditors, lawyers and tax advisors. As a result, it is considering removing the automatic triggering of EDD for domestic PEPs, especially in cases where there are no other high-risk factors.
#8 Key takeaway for your organisation:
Under current regulations, EDD needs to be applied in the case of a PEPs; whether the individual resides or holds office in the UK or not. The government is however considering relaxing this prescriptive measure in cases of low-risk domestic PEPs.
High-risk third countries EDD may be too prescriptive
The UK government maintains and publishes a list of high-risk third countries (HRTC) that pose a high money laundering risk due to deficiencies within the country’s AML/CFT controls. This list is composed of countries that are placed on the FATF’s Call to Action list or Jurisdictions under Increased Monitoring list.
AML regulations require that firms carry out enhanced due diligence when dealing with clients established in a country on this list or in cases where a transaction involves a party established in one of these jurisdictions.
The government has acknowledged that not all the jurisdictions flagged as high risk by the FATF pose the same level of risk to the UK. As a result, it is considering updating the criteria used to determine the list of countries on the HRTC list.
Another point discussed in the HM Treasury’s report is that the current regulations go beyond stating that EDD needs to be applied in such cases. The regulations list a very specific set of checks that need to be carried out. This includes obtaining additional information on the customer, their beneficial owners, the nature of the business relationship, the source of funds, source of wealth and the reason for related transactions. Moreover, in such scenarios, organisations are obliged to get approval of senior management to onboard the client or continue a business relationship with the client; and commit to carry out enhanced monitoring on the client.
The government has acknowledged that this list of requirements may be too prescriptive and, in most cases, goes beyond FATF guidelines. As a result, while the government is committed to maintain a list of high-risk third countries, it is considering removing the mandatory requirements associated with these jurisdictions. This would empower organisations to take a more risk-based approach in such situations.
#9 Key takeaway for your organisation:
The list of high-risk third countries (HRTC) needs to be monitored regularly since any business established in these countries automatically triggers EDD. Given that the list is based on lists published by the FATF, organisations should be mindful that this is currently updated three times a year. This may change in the future if the government defines different criteria to determine what jurisdictions are considered high-risk. Another key takeaway is that under current regulations, the EDD checks to apply are prescriptive and very specific. This is a requirement that may change in the future though.
No changes to SDD Regulations
AML regulations stipulate that simplified due diligence (SDD) can be carried out for clients that are classified as low risk. In such scenarios, the regulations still require normal customer due (CDD) to be carried out but the “extent, timing or type” of CDD may be altered. Respondents to the Call for Evidence noted that since all elements of CDD need to be carried out, SDD still requires the same level of resources to implement as CDD; rendering SDD useless.
The government’s position in this regard remains the same, however, and no changes to guidelines are anticipated. This is because the guidelines are deemed to be in line with FATF requirements.
#10 Key takeaway for your organisation:
SDD can be applied in lower-risk scenarios, but all elements of the customer due diligence process need to be carried out. The “extent, timing or type” may allow some flexibility but there are no plans to relax these regulations further.
How much can you rely on reliance?
Reliance is a mechanism by which a firm may rely on another regulated business to carry out relevant due diligence checks. This could in theory simplify the CDD process drastically but the manner in which the regulations are worded decreases its usefulness. For starters, the legal liability for carrying out due diligence rests squarely on the firm providing the relevant service and therefore firms cannot blindly rely on the due diligence carried out by the other firm.
The relying party must ensure they are provided with the ability to immediately access CDD data and documents on request. The term “immediately” may lead to complex data-sharing agreements and may pose challenges from an IT systems perspective. Moreover, given such documents and data need to be retained for a long period of time, commercial and contractual obligations between the parties become more complex. Reliance also does not lend itself particularly useful in terms of ongoing monitoring. Another argument against reliance is the difficulty in aligning risk policies between the two parties because the relying party’s AML policies may dictate that a different set of data or documents is collected as part of the due diligence process.
Given these issues, a lot of businesses are reluctant to enter into reliance agreements. The government, however, stated that reliance should not be used to circumvent customer due diligence obligations in terms of liability, record keeping and data retention. The report states that the current regulations are in line with the FATF position and that the government is of the opinion that these regulations remain in place as is.
#11 Key takeaway for your organisation:
Using reliance to improve the efficiency of your customer due diligence process is encouraged. However, you are still responsible for all customer due diligence; and you need to make sure that your contractual agreement with the other party addresses all regulatory obligations.
Conclusion
In this article we looked at the UK government’s mindset when reviewing the current version of AML regulations. Some of these regulations are expected to remain unchanged. For example, even though businesses may find the regulations around simplified due diligence and reliance as being restrictive, the government is not foreseeing any changes in these areas.
On the other hand, there are a few mandatory requirements that trigger enhanced due diligence that may be relaxed slightly going forward. This includes the treatment of complex and unusual transactions, local PEPs and high-risk third countries. Until the current regulations are in place though, it is important to ensure that the existing legislation is followed.

The Notary AML Forum 2026: Sanctions, Regulatory Updates & Tax Insights
Join Inscope-AML and Forvis Mazars for a focused event covering sanctions updates, new regulatory developments, and tax insights for notaries and compliance professionals.

New InScope-AML REQ 2026 Features for Maltese Subject Persons
Enhancing REQ reporting for 2026 with improved documentation, expanded licence templates, and streamlined export capabilities for Maltese Subject Persons.

Enhancing Our REQ 2025 Reporting Capabilities
Ensuring Seamless AML Compliance with Timely Updates for REQ 2025 Reporting Requirements

Preparing for DORA: How we at InScope-AML are getting ready for DORA as we align with EU digital resilience standards to safeguard operations and support our clients.