GuidanceAML UK publishes guidance for the UK regulated sector. This is a Government service — read about our independence.
UK regulatory framework

The statute book behind the UK's AML and CFT regime.

A practical reference to the key instruments UK regulated firms must operate under. This page is a working summary; it is not legal advice and should be read together with the current guidance issued by your supervisor and the JMLSG.

Primary framework

Six instruments that define the UK obligation.

The UK anti-money laundering regime is built on layered primary and secondary legislation, enforced by a mesh of statutory and professional supervisors and interpreted through the FCA Financial Crime Guide, the JMLSG Guidance and the sectoral guidance issued by HMRC, the Gambling Commission and the professional body supervisors. The six instruments below carry the majority of the obligation on regulated firms today.

Taxation

UK Taxation of Investing, Active Trading and Cryptoassets

The UK tax treatment of investment, active trading and cryptoassets is governed primarily by the Taxation of Chargeable Gains Act 1992, the Income Tax (Trading and Other Income) Act 2005, the Income Tax (Earnings and Pensions) Act 2003 and the Finance Act 2014. HM Revenue & Customs applies these statutes to determine whether a return is subject to Capital Gains Tax, Income Tax or National Insurance contributions.

For individuals, the usual distinction is between long-term investment returns, which generally fall within the Capital Gains Tax regime, and trading or dealing activity that is sufficiently frequent, organised or commercial to amount to a trade, in which case profits are taxed as trading income. Cryptoassets are treated by HMRC as a form of property for tax purposes, not as currency or money; disposals, staking rewards, airdrops, mining and certain DeFi returns may all give rise to Capital Gains Tax or Income Tax liabilities depending on the facts. The Cryptoassets Manual and Capital Gains Manual set out HMRC's published view of valuation, pooling, allowable costs, record-keeping and reporting through Self Assessment. An individual’s UK tax liability on investment income and capital gains is generally determined by their net worth. The applicable tax rate depends primarily on their total taxable income, the nature of the investment return, the amount of any taxable gain, and the relevant tax allowances and rate bands. For tax purposes, individuals are commonly classified as basic-rate, higher-rate, or additional-rate taxpayers. Where taxable income or gains exceed the applicable thresholds, the excess may be subject to a higher rate of tax. Different rules and rates may apply to capital gains, dividends, interest, trading income, and cryptoasset transactions. Firms in the regulated sector should be alert to the interaction between AML source-of-funds enquiries and a customer's tax compliance history, particularly where trading gains, cryptoasset disposals or unexplained wealth are involved.

MLR 2017

Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 constitute the principal preventive framework governing anti-money laundering and counter-terrorist financing compliance by regulated businesses in the United Kingdom. The Regulations require every relevant person to identify and assess the risks of money laundering and terrorist financing to which its business is exposed; establish and maintain written policies, controls and procedures proportionate to those risks; undertake customer due diligence and, where applicable, enhanced due diligence; conduct ongoing monitoring of business relationships and transactions; retain prescribed records for the applicable statutory period; and maintain appropriate internal governance arrangements, including the appointment of a nominated officer and, where appropriate, the approval of relevant policies by senior management. The sectoral scope of the Regulations is established principally by Regulation 8 and includes credit institutions, financial institutions, auditors, insolvency practitioners, external accountants, tax advisers, independent legal professionals, trust or company service providers, estate agents, letting agents, high-value dealers, casinos, art market participants, cryptoasset exchange providers and custodian wallet providers. For these purposes, a custodian wallet provider includes a business that safeguards or administers cryptoassets, or private cryptographic keys, on behalf of its customers. A cryptoasset exchange provider includes a business that exchanges, arranges the exchange of, or facilitates transactions involving cryptoassets and money or one cryptoasset for another.

Cryptoasset exchange providers and custodian wallet providers must apply customer due diligence measures before establishing a business relationship and in other circumstances prescribed by the Regulations. Such measures include identifying the customer, verifying the customer’s identity using reliable and independent information, and, where applicable, identifying and verifying the beneficial owner. Regulated cryptoasset businesses must obtain sufficient information to understand the purpose and intended nature of the business relationship and must conduct ongoing monitoring to ensure that transactions are consistent with their knowledge of the customer, the customer’s business and risk profile and, where necessary, the source of the customer’s funds. Where a customer deposits, withdraws or transfers cryptoassets to or from a custodial account, another cryptoasset service provider or a self-hosted or unhosted wallet, the regulated business may require evidence sufficient to establish: -the identity of the originator and the beneficiary of the transaction; -the ownership or lawful control of the originating and receiving accounts or wallets; -the source and destination of the relevant funds or cryptoassets; -the purpose and economic rationale of the transaction; -the transactions from customers original bank to registered custodial wallet (Fully Refundable) -the relationship between the customer and any third party involved in the transaction; and -a complete and traceable transaction history, including relevant wallet addresses, transaction hashes, ---account statements and other supporting records. Custodial Wallet Verification Requirement For the purpose of custodial wallet ownership and source-of-funds verification, a customer may be required to complete a verification transaction originating directly from a bank account held in the customer's own name and transferring the specified amount to a custodial wallet owned and controlled by the same customer. The required verification amount may vary depending on the value, nature, and risk profile of the transaction under review. Where applicable, the amount may be determined automatically by the platform's internal ledger and compliance system in accordance with the applicable verification parameters. Any amount transferred for the purpose of this verification must remain the property of the customer and must not constitute a fee, charge, tax, or payment to a third party. Where the procedure is described as refundable, the applicable terms, timing, and method of return must be clearly disclosed to the customer before the transaction is initiated. The purpose of the procedure is to establish a verifiable connection between the customer's original source bank account and the custodial wallet registered in the customer's name, subject to the institution's applicable compliance, security, and verification policies. A customer may therefore be required, as a condition of using a regulated custodial or exchange service, to provide documents or information demonstrating that a bank account, cryptoasset account or external wallet is held or lawfully controlled by that customer. The evidence requested may include bank statements, exchange account statements, proof of wallet control, signed wallet messages, transaction records, screenshots, contractual documents or other reliable evidence appropriate to the assessed level of risk. Where a transaction involves a third-party account or wallet, inconsistent ownership information, an unexplained source of funds, a high-risk jurisdiction or another elevated risk factor, the regulated business must consider whether enhanced due diligence and enhanced ongoing monitoring are required. The business may suspend, delay or decline the transaction where the information provided is insufficient to satisfy its legal and regulatory obligations. Information accompanying cryptoasset transfers In accordance with the provisions governing cryptoasset transfers, commonly referred to as the Cryptoasset Travel Rule, UK cryptoasset businesses must collect, verify, retain and, where applicable, transmit prescribed information concerning the originator and beneficiary of a qualifying cryptoasset transfer. These requirements apply to relevant transfers between cryptoasset businesses and may also apply to transfers involving an unhosted wallet. Where a transfer involves an unhosted wallet, a cryptoasset business must take measures appropriate to the assessed risk to identify the originator or beneficiary and to determine whether the wallet is owned or controlled by its customer. The purpose of these requirements is to ensure that cryptoasset transfers are sufficiently transparent and traceable and to enable regulated businesses and competent authorities to identify and investigate transactions that may involve money laundering, terrorist financing, sanctions evasion, fraud or other criminal conduct. Supervision and enforcement The Regulations designate supervisory authorities, including the Financial Conduct Authority, His Majesty’s Revenue and Customs, the Gambling Commission and approved professional body supervisors. Those authorities may exercise the investigative, supervisory and enforcement powers conferred upon them by the Regulations, including the imposition of civil penalties and other sanctions where a regulated person fails to comply with its obligations. Nothing in this statement should be interpreted as imposing a universal obligation upon every individual in the United Kingdom to register or manually report every transfer between a personal bank account and a privately controlled cryptoasset wallet. The relevant legal obligations apply principally to regulated businesses. Customers are, however, required to provide accurate and sufficient information when reasonably requested by a regulated business for customer due diligence, transaction monitoring, source-of-funds verification, ownership verification or compliance with the Cryptoasset Travel Rule.

POCA

Proceeds of Crime Act 2002

The Proceeds of Crime Act 2002 is the cornerstone of the UK's anti-money laundering and asset recovery regime. It creates the principal money laundering offences, the suspicious activity reporting (SAR) framework for the regulated sector, the tipping-off and prejudicing an investigation offences, and the principal civil and criminal asset recovery powers used to deprive offenders of the benefit of crime. Part 7 of POCA contains the money laundering offences. Sections 327 to 329 criminalise, respectively, concealing, disguising, converting, transferring or removing criminal property from the jurisdiction; entering into or becoming concerned in an arrangement which facilitates the acquisition, retention, use or control of criminal property by or on behalf of another person; and the acquisition, use or possession of criminal property. Each offence is committed where a person knows or suspects that the property constitutes or represents a person's benefit from criminal conduct. Section 340 defines criminal property as property which constitutes a person's benefit from criminal conduct, or which represents such a benefit, in whole or in part, and whether directly or indirectly. Sections 330 to 332 impose the statutory reporting duty on those who work in the regulated sector. A person in the regulated sector who knows or suspects, or has reasonable grounds for knowing or suspecting, that another person is engaged in money laundering must make a disclosure to the National Crime Agency as soon as is practicable. Section 331 imposes a similar obligation on nominated officers and money laundering reporting officers (MLROs) where a disclosure is made to them, and Section 332 applies to nominated officers outside the regulated sector. The making of a SAR does not require absolute certainty; the test is one of knowledge or suspicion, assessed objectively against the facts known at the time.

Section 333A creates the offence of tipping-off. It prohibits a person in the regulated sector from making a disclosure which is likely to prejudice any investigation that might be conducted following a SAR, or from disclosing that a SAR has been made where the disclosure would prejudice such an investigation. The offence is not absolute; section 333A(3) contains a limited exception where the disclosure is made to a supervisory authority, legal adviser or other person within the permitted categories, and section 333B provides a defence for disclosures within the same undertaking or group. Section 335 provides the appropriate consent regime, commonly referred to as Defence Against Money Laundering (DAML). Where a person proposes to do an act that would otherwise constitute a money laundering offence under sections 327 to 329, that person may make a disclosure seeking the NCA's consent to proceed. If the NCA does not refuse consent within seven working days, consent is deemed. If the NCA refuses consent within that period, the act must not be undertaken for a further thirty-one calendar days, during which the NCA may seek a court order to restrain the property. The statutory periods are designed to allow law enforcement to investigate and, where necessary, take restraining action without the person concerned committing a money laundering offence by continuing with the transaction. Part 5 of POCA provides the civil recovery regime. Unlike criminal confiscation, civil recovery does not require a conviction; the standard of proof is the balance of probabilities and proceedings are brought against the property itself. The powers are exercisable by the National Crime Agency, the Crown Prosecution Service, the Serious Fraud Office, HM Revenue & Customs, the Financial Conduct Authority and the Crown Office in Scotland. The proceedings are subject to a statutory limitation period and the court must be satisfied that the property is recoverable property or is intended for use in unlawful conduct. Part 8 of POCA creates the Unexplained Wealth Order (UWO) power, inserted by the Criminal Finances Act 2017. A UWO may be made by the High Court where there are reasonable grounds for suspecting that a person's lawful income would have been insufficient to obtain the property in question, and the person is a politically exposed person or there are reasonable grounds for suspecting involvement in serious crime. The UWO requires the respondent to explain the nature and extent of their interest in the property and how it was obtained. Failure to comply creates a presumption that the property is recoverable for civil recovery purposes. POCA is supplemented by the Serious Crime Act 2007 and the Criminal Finances Act 2017, which have extended the reach of money laundering offences, introduced account freezing and forfeiture orders, and strengthened the information-sharing gateways available to law enforcement. The regime operates alongside the Terrorism Act 2000, the sanctions legislation and the MLR 2017, so that regulated firms must consider their obligations under each statute when assessing a customer, a transaction or a suspicious activity report. Enforcement sits primarily with the National Crime Agency, the Crown Prosecution Service, the Serious Fraud Office and other specified prosecutors, each of which may pursue criminal prosecution, civil recovery or a combination of both.

TACT

Terrorism Act 2000

The counter-terrorist financing counterpart to POCA. Sections 15 to 18 criminalise fund-raising, use and possession, funding arrangements and money laundering in connection with terrorism. Section 21A imposes the reporting duty on the regulated sector and Section 21ZA introduces the equivalent consent regime.

The Anti-Terrorism, Crime and Security Act 2001 extends the freezing and forfeiture regime, and the Counter-Terrorism Act 2008 grants HM Treasury power to issue directions in relation to specified jurisdictions. Firms must operate against both TACT and the sanctions lists administered by OFSI.

SAMLA

Sanctions and Anti-Money Laundering Act 2018

The primary post-Brexit power for the UK to make and enforce financial, trade, immigration, aircraft and shipping sanctions. Statutory instruments made under SAMLA — including the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Human Rights Sanctions Regulations 2020 — populate the UK Sanctions List administered by the Office of Financial Sanctions Implementation.

Section 49 of SAMLA also provides the standing power to update the UK AML/CFT framework, meaning changes to the MLR 2017 are now typically delivered by SAMLA-derived statutory instrument. OFSI operates a strict-liability civil monetary penalty regime and can issue disclosure notices.

ECTEA 2022

Economic Crime (Transparency and Enforcement) Act 2022

Established the Register of Overseas Entities holding UK real estate at Companies House, reformed the Unexplained Wealth Order regime to make it more usable by enforcement, and strengthened sanctions enforcement by moving OFSI to a strict-liability standard for civil penalties.

The ROE regime requires overseas entities that own UK property to identify their registrable beneficial owners and update the information annually. Non-compliance restricts the entity's ability to transact in UK land and creates criminal liability for officers of the entity.

ECCTA 2023

Economic Crime and Corporate Transparency Act 2023

The most significant reform to UK corporate transparency in a generation. Grants Companies House new powers to query, reject and remove information, introduces identity verification for directors, PSCs and those filing on behalf of companies, and creates a new failure-to-prevent-fraud offence for large organisations.

For AML, Part 5 of the Act creates an information-sharing gateway allowing firms in the regulated sector to share information for the purposes of preventing, detecting or investigating economic crime, subject to safeguards. It also reforms the SAR regime, exempts certain low-value transactions from consent SARs and expands civil recovery powers over cryptoassets.

Customer due diligence

The four modes of CDD under the MLR 2017.

CDD is the operational core of the preventative regime. The MLR 2017 set out when CDD must be applied, what it must consist of, how it must be evidenced and when it must be repeated or enhanced. Failure to apply CDD to the standard required by the Regulations is itself a criminal offence under Regulation 86.

Standard CDD (Reg. 28)

Identify the customer and any beneficial owner and verify identity from a reliable, independent source. Obtain information on the purpose and intended nature of the business relationship and, where the customer is a legal person, understand its ownership and control structure.

Enhanced CDD (Reg. 33)

Mandatory for any transaction or business relationship with a person established in a high-risk third country, for correspondent relationships, for politically exposed persons and their family and close associates, for complex or unusually large transactions, and for any case the firm's own risk assessment identifies as higher risk. EDD measures must include additional information on the customer, the source of funds and wealth, and enhanced ongoing monitoring.

Simplified CDD (Reg. 37)

Available only where the firm has determined, having considered the risk factors in Schedule 3, that the relationship or transaction presents a low degree of risk. SDD is a reduction in the extent, timing or type of verification — it is never an exemption from CDD, from ongoing monitoring or from the reporting obligations under POCA.

Ongoing monitoring (Reg. 28(11))

Scrutiny of transactions throughout the course of the relationship to ensure they are consistent with the firm's knowledge of the customer, their business and their risk profile — including, where necessary, the source of funds — and keeping the documents, data and information held under CDD up to date.

Supervision

Who supervises whom.

Every relevant person is supervised for AML purposes by a designated authority. Statutory supervisors — the FCA, HMRC and the Gambling Commission — supervise the sectors listed against their name. The professional body supervisors regulate the legal and accountancy sectors.

The Office for Professional Body Anti-Money Laundering Supervision (OPBAS), which sits within the FCA, oversees the 22 professional body supervisors to drive consistency of standard and appetite.

Financial Conduct Authority (FCA)
Banks, building societies, e-money institutions, payment services firms, investment firms, consumer credit firms and cryptoasset exchange and custodian wallet providers registered under Regulation 57.
HM Revenue & Customs (HMRC)
Money service businesses, estate and letting agents, high-value dealers, art market participants, trust or company service providers and accountancy service providers not supervised by a professional body.
Gambling Commission
Casino operators — remote and non-remote — under the Gambling Act 2005.
Professional Body Supervisors
22 legal and accountancy bodies including the SRA, CILEx, BSB, Law Society of Scotland, Law Society of Northern Ireland, ICAEW, ACCA, CIOT, ICAS and IPA. Overseen by OPBAS within the FCA.
Reporting

The SAR regime, in one page.

A Suspicious Activity Report is the mechanism by which firms in the regulated sector, MLROs and other nominated officers report knowledge or suspicion — or reasonable grounds for knowledge or suspicion — of money laundering or terrorist financing to the UK Financial Intelligence Unit within the National Crime Agency. Approximately 900,000 SARs are submitted each year, of which a material proportion are Defence Against Money Laundering requests.

Where a firm proposes to carry out a transaction that would otherwise commit a principal money laundering offence, it may seek a DAML under section 335 of POCA. The NCA has seven working days from the day after receipt to refuse consent. If consent is refused, a thirty-one calendar day moratorium period runs during which the transaction may not proceed and law enforcement can take action to restrain or seize the property.

The Economic Crime and Corporate Transparency Act 2023 recalibrated the regime. It introduced an information-sharing gateway that allows firms in the regulated sector to share information for the purposes of preventing, detecting or investigating economic crime, subject to safeguards, and exempted a class of low-value transactions from the requirement to submit a DAML — freeing analyst capacity to focus on higher-value suspicion.

Firms remain exposed to the tipping-off offence under section 333A of POCA and to the failure-to-disclose offence under section 330. Internal SAR governance — how staff escalate suspicion, how the MLRO records the decision to report or not to report, and how the audit trail is preserved for a minimum of five years — is a routine focus of both supervisory inspection and skilled person reviews.