United Kingdom KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in United Kingdom.

Direct answer
What does the United Kingdom compliance checklist cover?
The United Kingdom checklist translates primary KYC, KYB and AML rules into 11 control areas and 49 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML rule
- Money Laundering Regulations 2017, as amended including SI 2026/621 effective 30 June 2026
- Financial intelligence unit
- UK Financial Intelligence Unit within the National Crime Agency (UKFIU/NCA)
- Suspicious activity report
- No monetary threshold; make a required disclosure as soon as practicable through the applicable internal or UKFIU route
- General occasional CDD
- GBP 12,000 or more from 30 June 2026; sector-specific triggers differ
- Funds-transfer CDD
- A transfer of funds exceeding GBP 800 triggers CDD; prescribed information rules also apply
- High-value dealers
- GBP 10,000 or more in cash is a scope and CDD trigger, not a universal threshold report
- AML beneficial ownership
- More than 25% shares or voting rights, ultimate management control or other control; tailored partnership and trust tests
- Companies House PSC
- More than 25% shares or votes, board-control rights, or significant influence or control under separate statutory conditions
- Core AML retention
- Five years from the record-specific transaction or relationship trigger, subject to limited longer retention and deletion rules
- Current sanctions list
- The UK Sanctions List has been the sole source for UK designations since 28 January 2026
- Cryptoasset businesses
- In-scope UK exchange and custodian-wallet providers must register with the FCA before starting
- FATF public lists
- The United Kingdom was not named on the FATF public lists reviewed 31 July 2026
Implementation detail
United Kingdom compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensing perimeterResolve every entity, activity, customer and UK nexus first. MLR supervision or registration does not replace FCA authorization, Companies House duties, sanctions compliance or another professional or devolved requirement.5 items+
The MLRs apply to the relevant persons in regulation 8 acting in the course of UK business, subject to detailed sector definitions and exclusions.
- Implementation action
- Map each entity, product and service to regulations 8-15 and identify the FCA, HMRC, Gambling Commission or professional-body supervisor before launch.
- Evidence to retain
- Perimeter memorandum, legal-entity map, activity analysis, supervisor decision, exclusions and accountable owner.
- Primary citation
- MLRs, regs. 8-15 and 46
The 2026 MLR amendments generally took effect on 30 June 2026, while crypto correspondent rule 34A does not start until 1 February 2027.
- Implementation action
- Configure operative sterling thresholds and pooled-account controls now; place future crypto correspondent and 2027 control reforms on a dated change calendar.
- Evidence to retain
- Amendment assessment, effective-date register, configuration tests, future-change tickets and legal approval.
- Primary citation
- Money Laundering and Terrorist Financing (Amendment) Regulations 2026, reg. 1
Payment services and e-money issuance require the correct FCA authorization or registration unless another status or exclusion applies.
- Implementation action
- Classify each payment and e-money function, apply before regulated launch, and reconcile the permission with MLR supervisory status.
- Evidence to retain
- PSR and EMR analysis, application, FCA register extract, permissions matrix and launch gate.
- Primary citation
- PSRs 2017, regs. 4, 6 and Sch. 1; EMRs 2011, regs. 9 and 13; FCA payments guidance
An in-scope cryptoasset exchange provider or custodian wallet provider carrying on UK business must be registered with the FCA before starting.
- Implementation action
- Apply regulations 14A, 54 and 56 to the service and UK nexus; obtain registration before launch and separately assess financial promotions and the future FSMA regime.
- Evidence to retain
- Crypto perimeter memo, FCA application, registration decision, promotions review and 2027 transition plan.
- Primary citation
- MLRs, regs. 14A, 54 and 56; FCA, Cryptoassets AML/CTF regime
Where appropriate for size and nature, appoint a responsible board or senior manager, screen relevant employees and maintain independent audit; every relevant person also needs a nominated officer unless the sole-person exception applies.
- Implementation action
- Document appointments, notify the supervisor within 14 days where required, screen staff and operate risk-based independent assurance.
- Evidence to retain
- Appointment letters, supervisor notice, screening files, audit plan, reports and remediation evidence.
- Primary citation
- MLRs, regs. 21 and 24
02Governance, risk assessment and control frameworkA relevant person's programme must be demonstrably proportionate to its actual UK risks and current MLR obligations, including proliferation financing.4 items+
A relevant person must identify, assess and keep current written records of its money-laundering and terrorist-financing risks.
- Implementation action
- Assess customers, countries, products, transactions, delivery channels, size and nature; obtain approval and update for material change.
- Evidence to retain
- Business-wide risk assessment, source register, methodology, approvals, change log and control mapping.
- Primary citation
- MLRs, reg. 18
For a pooled account newly provided from 30 June 2026, understand purpose and use, test consistency with customer knowledge and risk, update CDD if needed, assess and mitigate ML/TF risk and consider account controls.
- Implementation action
- Document the measures and demonstrate to the supervisor that their extent is appropriate to the account's ML/TF risk.
- Evidence to retain
- Purpose and use assessment, consistency test, updated CDD, risk decision, controls, approval and supervisor evidence pack.
- Primary citation
- MLRs, reg. 29(10)-(13); SI 2026/621, reg. 15
A relevant person must separately assess proliferation-financing risk and maintain proportionate senior-approved policies, controls and procedures.
- Implementation action
- Map sanctions-evasion and proliferation exposure across ownership, trade, payments, geography and technology; connect risks to preventive controls.
- Evidence to retain
- PF risk assessment, senior approval, scenario inventory, sanctions mapping, tests and remediation log.
- Primary citation
- MLRs, regs. 18A and 19A
AML/CFT policies must cover risk management, internal controls, CDD, reliance, records, compliance monitoring, unusual activity and new technology.
- Implementation action
- Maintain a control inventory mapped to regulations 19-20, assign owners, test design and operation, and communicate changes across relevant branches.
- Evidence to retain
- Policy set, control matrix, board minutes, testing results, issues, training and branch attestations.
- Primary citation
- MLRs, regs. 19-20
03Natural-person identification and verificationCDD triggers and evidence strength depend on the relationship, transaction and risk. The 30 June 2026 sterling thresholds must not be confused with universal onboarding rules.5 items+
CDD applies when establishing a business relationship, on suspicion, when prior evidence is doubtful and at the prescribed occasional-transaction triggers.
- Implementation action
- Build a trigger matrix covering the general GBP 12,000 threshold, funds transfers above GBP 800 and sector-specific cash, casino, art, letting and crypto triggers.
- Evidence to retain
- Trigger matrix, workflow rules, linked-transaction logic, suspicion override, tests and exceptions.
- Primary citation
- MLRs, reg. 27 as amended by SI 2026/621, reg. 14
A relevant person must identify the customer, verify identity from reliable independent documents or information and assess the relationship's purpose and intended nature.
- Implementation action
- Define risk-based evidence standards, validate authenticity and independence, and record purpose, expected activity and decision before activation.
- Evidence to retain
- Identity evidence, source validation, customer profile, purpose record, timestamps and approval.
- Primary citation
- MLRs, reg. 28(2), (12)-(13) and (18)
Secure electronic identification can be a reliable independent source where it resists fraud and misuse and gives the assurance needed for the risk.
- Implementation action
- Assess digital identity assurance, fraud controls, accessibility, exception handling and evidence retention; do not treat vendor output as automatically sufficient.
- Evidence to retain
- Vendor assessment, certification or assurance evidence, test results, decision logs, exceptions and monitoring.
- Primary citation
- MLRs, reg. 28(19); HM Treasury, Using digital identities with the MLRs
A person purporting to act for a customer must be authorized, identified and independently verified.
- Implementation action
- Validate the mandate and signatory powers, identify and verify the representative, and connect every instruction to current authority.
- Evidence to retain
- Mandate, board authority, power of attorney, representative KYC, validation log and instruction record.
- Primary citation
- MLRs, reg. 28(10)
If required CDD cannot be completed, do not open the relationship or transact, terminate an existing relationship and consider a POCA or Terrorism Act disclosure, subject to regulation 31's express exceptions.
- Implementation action
- Block activation and transactions, escalate termination and repayment, document any privilege or insolvency exception and record the SAR and consent assessment.
- Evidence to retain
- CDD failure, restrictions, termination or repayment record, exception analysis, SAR decision and approvals.
- Primary citation
- MLRs, reg. 31
04KYB, beneficial ownership and Companies HouseKeep MLR beneficial-owner CDD, register-discrepancy reporting and the company's own PSC and identity-verification duties distinct. A Companies House record is not sufficient by itself for MLR beneficial-owner verification.4 items+
Corporate CDD requires verified registered details and reasonable measures on governing law, constitution, directors or senior managers, ownership and control.
- Implementation action
- Obtain current registry and constitutional material, verify status and address, map directors and senior operators, and understand every ownership layer.
- Evidence to retain
- Companies House extract, constitutional documents, status check, director list, ownership chart and verification log.
- Primary citation
- MLRs, reg. 28(3)-(5)
A body corporate's beneficial owners include individuals with ultimate management control, more than 25% of shares or voting rights, or other control; partnerships and trusts use separate tests.
- Implementation action
- Trace direct and indirect interests, voting arrangements and control to natural persons; apply regulations 5 and 6 by entity type.
- Evidence to retain
- Ownership calculations, control analysis, trust or partnership parties, source documents and reviewer approval.
- Primary citation
- MLRs, regs. 5-6
Only after exhausting all possible means may a relevant person treat the responsible senior manager as the body corporate's beneficial owner, with written records of actions and difficulties.
- Implementation action
- Escalate unresolved ownership, document every search and inconsistency, verify the senior manager and decide whether risk or failed-CDD rules prevent onboarding.
- Evidence to retain
- Exhaustion log, source searches, escalation, senior-manager verification, risk decision and approval.
- Primary citation
- MLRs, reg. 28(6)-(9) and 31
Before onboarding and at relevant later CDD or monitoring for a regulation 30A customer, collect the prescribed register excerpt and report any Schedule 3AZA material discrepancy through the specified registrar or HMRC route.
- Implementation action
- Compare register and CDD evidence, classify materiality, resolve false positives, submit through the correct route and retain the report.
- Evidence to retain
- Register excerpt, comparison, discrepancy analysis, submission, acknowledgement and resolution.
- Primary citation
- MLRs, reg. 30A and Sch. 3AZA
05PEPs, EDD, source of wealth and remote onboardingEDD applies to prescribed cases and other high-risk situations. Domestic PEP status is treated as lower risk absent other enhanced risk factors, but it still requires the regulation 35 process.4 items+
EDD and enhanced monitoring are required in regulation 33 cases, including a FATF call-for-action-country relationship or transaction and any other situation presenting higher ML or TF risk.
- Implementation action
- Configure mandatory triggers and a documented high-risk methodology; do not automatically equate the FATF increased-monitoring list with the regulation 33 country trigger.
- Evidence to retain
- EDD rules, FATF list version, risk decision, enhanced checks, approvals and monitoring plan.
- Primary citation
- MLRs, reg. 33 as amended by SI 2026/621, reg. 19
When establishing or continuing a relationship with a PEP, family member or close associate, including an entity beneficially owned by the PEP, obtain senior approval, establish source of wealth and funds, and conduct enhanced monitoring.
- Implementation action
- Screen customers and beneficial owners, adjudicate matches, corroborate wealth and funds, approve the relationship and apply separate risk and EDD rules to other PEP transactions.
- Evidence to retain
- Screening result, relationship analysis, wealth narrative, funds evidence, senior approval, alerts and reviews.
- Primary citation
- MLRs, regs. 33 and 35(1)-(5), (13)
Domestic PEPs, their family members and known close associates are presumed lower risk than non-domestic PEPs unless other enhanced risk factors exist.
- Implementation action
- Apply the PEP controls proportionately, document additional risk factors and avoid either automatic rejection or unjustified simplified treatment.
- Evidence to retain
- Domestic-status proof, risk assessment, factor analysis, measures, approval and review schedule.
- Primary citation
- MLRs, reg. 35(3A) and (12)
Remote onboarding, anonymity-favouring products and new technology require risk assessment and, where higher risk exists, enhanced measures.
- Implementation action
- Test document and person match, fraud and impersonation risk, device and network signals, accessibility, manual escalation and vendor performance.
- Evidence to retain
- Remote-risk assessment, liveness or match tests, device data, exception files, vendor assurance and sampled outcomes.
- Primary citation
- MLRs, regs. 19(4), 28(19), 33 and 35; HM Treasury digital-identity guidance
06Monitoring, suspicious activity and confidentialityThe MLRs create monitoring and internal-control duties; POCA and the Terrorism Act create role-specific disclosure offences. Case records must show when the statutory knowledge or suspicion test arose and why disclosure was timely.4 items+
Ongoing monitoring includes scrutiny of transactions, source of funds where necessary, and reviews that keep CDD documents and information current.
- Implementation action
- Calibrate monitoring to expected activity and risk, investigate linked behaviour, refresh CDD on change and record filing and non-filing decisions.
- Evidence to retain
- Scenario inventory, expected-activity profile, alerts, investigation notes, refresh history and dispositions.
- Primary citation
- MLRs, reg. 28(11)-(13)
A regulated-sector employee or nominated officer must make the applicable disclosure when role-specific conditions are met and information concerns a person engaged in, or attempting, money laundering or terrorist financing.
- Implementation action
- Escalate completed and attempted activity through the nominated officer and UKFIU/NCA routes, preserving privilege and reasonable-excuse analysis.
- Evidence to retain
- Attempted or completed activity, internal report, nominated-officer assessment, legal analysis, SAR reference and acknowledgement.
- Primary citation
- POCA, ss. 330-332 and 338; Terrorism Act 2000, ss. 19 and 21A; NCA SAR guidance
A required disclosure is made as soon as practicable; there is no general monetary threshold or universal fixed-day SAR deadline.
- Implementation action
- Timestamp receipt, investigation, threshold formation, internal escalation and UKFIU submission; use the current SAR Portal and document unavoidable delay.
- Evidence to retain
- Case chronology, evidence reviewed, suspicion rationale, portal submission, receipt and delay explanation.
- Primary citation
- POCA, ss. 330-332; NCA, Suspicious Activity Reports
Tipping-off and prejudicing-investigation offences apply when their statutory conditions are met, subject to defined disclosures and other exceptions.
- Implementation action
- Restrict case information, train staff, review customer communications and CDD continuation, and obtain legal approval for sensitive disclosures.
- Evidence to retain
- Access logs, communication review, training, legal decision, exception analysis and incident record.
- Primary citation
- POCA, ss. 333A-333D and 342; Terrorism Act 2000, ss. 21D-21G and 39; MLRs, reg. 28(14)-(15)
07Payments, cash triggers and transfer informationThe UK does not impose one universal transaction report. CDD thresholds, payment-transfer information and cryptoasset travel-rule duties must be configured separately.4 items+
From 30 June 2026, general occasional transactions of GBP 12,000 or more and funds transfers exceeding GBP 800 trigger CDD, subject to sector-specific rules and linked operations.
- Implementation action
- Configure each threshold, currency conversion, linked-transaction detection, sector exception and suspicion override without treating it as a reporting threshold.
- Evidence to retain
- Rules specification, effective-date control, conversion source, test cases, alerts and CDD files.
- Primary citation
- MLRs, reg. 27(1)-(2); SI 2026/621, reg. 14
A high-value dealer's GBP 10,000 cash transaction is an MLR scope and CDD trigger, including linked operations; it is not a standalone universal cash report.
- Implementation action
- Identify qualifying goods activity and cash paid directly, indirectly or into an account for the seller's benefit; apply CDD before proceeding.
- Evidence to retain
- HVD perimeter analysis, cash aggregation, payer and beneficiary records, CDD and transaction decision.
- Primary citation
- MLRs, regs. 14 and 27(3)-(4)
Payment service providers must carry prescribed payer and payee information, detect missing data and respond to competent-authority enquiries under the retained funds-transfer framework.
- Implementation action
- Map originator, beneficiary and intermediary roles, mandatory fields, rejection or follow-up rules, sanctions screening and rapid retrieval.
- Evidence to retain
- Message-field mapping, validation tests, exception queue, follow-up records, screening and retrieval exercise.
- Primary citation
- MLRs, Part 7; retained Regulation (EU) 2015/847
Cryptoasset businesses must apply the UK travel rule, including prescribed originator and beneficiary information and the GBP 800 threshold for additional information in specified transfers.
- Implementation action
- Classify inter-business and unhosted-wallet transfers, collect and verify required data, manage missing information and report repeated failures to the FCA where required.
- Evidence to retain
- Travel-rule design, counterparty assessment, transfer messages, requests, decisions, FCA reports and records.
- Primary citation
- MLRs, regs. 64B-64G as amended by SI 2026/621, regs. 32-33
08Targeted financial sanctions and asset freezesUK sanctions are programme-specific. The UK Sanctions List supports detection, while the operative regulation determines designation effect, ownership and control, prohibitions, freezes, exceptions, licences and reports.4 items+
UK persons worldwide and persons within UK territory must comply with applicable sanctions prohibitions under programme regulations made under SAMLA.
- Implementation action
- Map persons, ownership and control, products, counterparties, vessels, geography and conduct to every applicable programme before execution.
- Evidence to retain
- Sanctions perimeter, programme inventory, legal analysis, screening logs, ownership review and decision.
- Primary citation
- SAMLA 2018; OFSI, Financial sanctions general guidance
Since 28 January 2026 the UK Sanctions List is the only current source for all UK sanctions designations; the former OFSI Consolidated List is closed.
- Implementation action
- Screen against current UK Sanctions List data, monitor updates and remove any production dependency on the closed consolidated list.
- Evidence to retain
- List source, version and timestamp, update alerts, screening tests, migration record and quality checks.
- Primary citation
- FCDO, The UK Sanctions List; OFSI general guidance
Asset-freeze prohibitions can extend to entities owned or controlled by a designated person even if the entity is not separately named.
- Implementation action
- Investigate direct and indirect ownership and control, joint arrangements and practical control; freeze or reject as the operative rule requires.
- Evidence to retain
- Ownership chart, control evidence, legal conclusion, freeze or rejection, approvals and audit trail.
- Primary citation
- OFSI, Financial sanctions general guidance, ownership and control
A relevant firm must inform OFSI as soon as practicable when the applicable programme's knowledge or reasonable-cause reporting trigger is met and must report frozen assets as required.
- Implementation action
- Escalate potential breaches and designated-person assets immediately, preserve funds, use the current OFSI route and assess separate UKFIU disclosure duties.
- Evidence to retain
- Case chronology, asset record, freeze, OFSI report, licence or exception analysis, SAR assessment and acknowledgements.
- Primary citation
- Applicable sanctions programme regulations; OFSI, Financial sanctions general guidance, reporting obligations
09Records, reliance and regulator accessFive years is the core MLR period, but its starting event and limited longer-retention rules differ. Outsourcing and reliance do not transfer legal accountability.5 items+
CDD, discrepancy, transfer-information and transaction-reconstruction records must generally be kept five years from the relevant transaction completion or end of business relationship.
- Implementation action
- Map every record class to its exact trigger, retain reconstructable evidence and prevent early deletion across primary and backup systems.
- Evidence to retain
- Retention schedule, trigger dates, system configuration, legal holds, samples and deletion certificates.
- Primary citation
- MLRs, reg. 40(1)-(4)
A pooled-account customer must provide underlying-person and beneficial-owner identities on request and keep accurate, up-to-date written records of all monies paid in and out for five years from when each payment is known or reasonably believed complete.
- Implementation action
- Require the customer to provide law-enforcement information about itself and account management and use on request; preserve regulation 29 privilege and confidentiality treatment.
- Evidence to retain
- Information requests, ownership data, payment ledger, per-payment retention clocks, authority responses and privilege record.
- Primary citation
- MLRs, reg. 29(14)-(18); SI 2026/621, reg. 15
After the applicable period, MLR personal data must be deleted unless another enactment, court proceedings, data-subject consent or reasonable legal-proceeding need supports retention.
- Implementation action
- Run defensible deletion and exception review, record the legal basis for any extension and prevent indefinite AML-purpose retention.
- Evidence to retain
- Deletion workflow, exception register, consent or legal basis, approvals, logs and verification tests.
- Primary citation
- MLRs, reg. 40(5)
Reliance on a qualifying third party does not remove the relevant person's liability and requires immediate information plus arrangements for prompt document copies.
- Implementation action
- Confirm third-party eligibility, obtain the required CDD data immediately, test document retrieval and prohibit reliance in a FATF call-for-action country unless the group exception applies.
- Evidence to retain
- Reliance assessment, agreement, data receipt, retrieval test, country check, monitoring and exit plan.
- Primary citation
- MLRs, reg. 39
Using an agent or outsourcing provider does not transfer liability for CDD or register-discrepancy measures.
- Implementation action
- Contract for duties, access, security, audit, incident escalation and exit; test identity, screening, monitoring, reporting and retrieval end to end.
- Evidence to retain
- Responsibility matrix, contract, vendor diligence, control tests, incidents, remediation and exit package.
- Primary citation
- MLRs, reg. 39(7)-(8)
10Privacy, biometrics, breaches and transfersKYC necessity does not displace UK data-protection duties. Resolve controller and processor roles, lawful basis, special-category conditions, transparency, minimization and retention for each data use.5 items+
UK GDPR principles and lawful-basis requirements apply to in-scope KYC data; from 19 June 2026 controllers must also facilitate complaints, acknowledge them within 30 days and respond without undue delay.
- Implementation action
- Map each data purpose, lawful basis, notice, recipient, access and retention; operate the DUAA complaint channel, investigation and outcome process.
- Evidence to retain
- Record of processing, lawful-basis register, privacy notice, data map, complaint log, acknowledgements and outcomes.
- Primary citation
- UK GDPR, arts. 5-6; DPA 2018; DUAA 2025, s. 103; ICO DUAA summary
Biometric data used to uniquely identify a person is special-category data and requires both an Article 6 lawful basis and an Article 9 condition.
- Implementation action
- Document necessity, proportionality and the special-category condition; minimize templates, separate uses, test accuracy and bias, and provide a non-biometric route where appropriate.
- Evidence to retain
- Lawful-basis analysis, Article 9 condition, biometric design, accuracy and bias tests, vendor terms and deletion proof.
- Primary citation
- UK GDPR, arts. 4(14), 6 and 9; DPA 2018; ICO biometric guidance
A DPIA is required before processing likely to result in high risk, including specified large-scale sensitive processing and biometric combinations.
- Implementation action
- Screen every identity and monitoring design early, complete and approve the DPIA where required, mitigate risks and consult the ICO if high residual risk remains.
- Evidence to retain
- Screening record, DPIA, necessity test, mitigations, DPO advice, approval and consultation record.
- Primary citation
- UK GDPR, art. 35; ICO, Data protection impact assessments
Notify a reportable personal-data breach to the ICO without undue delay and, where feasible, within 72 hours; notify affected people without undue delay when high risk exists and document every breach.
- Implementation action
- Start the clock on awareness, contain and assess risk, submit available facts within 72 hours, supplement promptly and preserve the full decision record.
- Evidence to retain
- Incident chronology, risk assessment, ICO report, affected-person notice, follow-up and breach register.
- Primary citation
- UK GDPR, arts. 33-34; ICO, Personal data breaches guide
A restricted international transfer requires an applicable UK adequacy regulation, safeguard or Article 49 exception in addition to ordinary UK GDPR compliance.
- Implementation action
- Map destinations and onward transfers, select and document the route, complete transfer-risk work where required, and contract for security, rights and exit.
- Evidence to retain
- Transfer map, adequacy or safeguard record, risk assessment, contract, supplementary measures and review.
- Primary citation
- UK GDPR, arts. 44-49; ICO, Guide to international transfers
11Payments, agents and practical evidence packsTurn the perimeter and legal controls into testable launch gates. Payment, e-money, cryptoasset, Companies House and MLR statuses overlap but are not substitutes for one another.5 items+
Covered payment and e-money firms must safeguard relevant funds under the PSRs or EMRs and the FCA supplementary regime effective 7 May 2026.
- Implementation action
- Apply CASS 10A and 15 and SUP 3A and 16 as relevant, identify and segregate funds, reconcile, maintain the resolution pack and submit required returns.
- Evidence to retain
- Safeguarding analysis, account documents, reconciliations, discrepancy log, resolution pack, audit and returns.
- Primary citation
- PSRs 2017, reg. 23; EMRs 2011, reg. 20; FCA PS25/12 and safeguarding guidance
A payment institution remains responsible for acts and omissions of agents and must register agents before they provide services; e-money distributors and agents have separate rules.
- Implementation action
- Perform due diligence, submit required FCA information, verify register status, contract for controls and supervise conduct, AML, complaints and safeguarding.
- Evidence to retain
- Agent assessment, FCA submission, register extract, contract, monitoring, complaints and termination plan.
- Primary citation
- PSRs 2017, regs. 34-36; EMRs 2011, regs. 33-36
An ACSP verifying identity for Companies House must be supervised for UK AML compliance, meet the verification standard and keep verification records for seven years.
- Implementation action
- Keep ACSP verification separate from MLR CDD, capture the evidence and prescribed statement, protect the personal code and calendar seven-year retention.
- Evidence to retain
- ACSP registration, supervision proof, verification record, Companies House submission, access controls and retention schedule.
- Primary citation
- Companies House, Tell Companies House you have verified someone's identity
Companies must identify and report PSCs, and mandatory identity verification applies to new directors and PSCs from 18 November 2025 with role-specific transition deadlines for existing persons.
- Implementation action
- Apply all five PSC conditions, file changes, capture each personal-code deadline, and distinguish Companies House verification from the business's own MLR CDD.
- Evidence to retain
- PSC analysis, filings, confirmation statement, personal-code evidence, deadline calendar and reconciliation to CDD.
- Primary citation
- Companies Act 2006, Part 21A and Sch. 1A; Companies House PSC and identity-verification guidance
Each checklist row requires a documented applicability decision, current source, control owner and reconstructable operating evidence before launch.
- Implementation action
- Mark every row applicable, not applicable or pending counsel confirmation; close blockers and obtain compliance, legal, privacy, security and product approval.
- Evidence to retain
- Completed checklist, rationale, source snapshot, owner sign-off, test result, gap ticket and launch approval.
- Primary citation
- MLRs, regs. 18-21, 24 and 28
Primary-source register
39 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017UK Legislation · Primary regulation
- Money Laundering and Terrorist Financing Amendment Regulations 2026UK Legislation · Primary regulation
- June 2026 money laundering advisory noticeHM Treasury · Official government notice
- HMRC anti-money laundering guidance for supervised businessesHM Revenue & Customs · Official supervisor guidance
- Using digital identities with the Money Laundering RegulationsHM Treasury and DSIT · Official government guidance
- Proceeds of Crime Act 2002UK Legislation · Primary legislation
- Terrorism Act 2000UK Legislation · Primary legislation
- Suspicious Activity ReportsNational Crime Agency · Official FIU guidance
- Companies Act 2006UK Legislation · Primary legislation
- Economic Crime and Corporate Transparency Act 2023UK Legislation · Primary legislation
- People with significant controlCompanies House · Official registry guidance
- 2026 statutory guidance on significant influence or controlCompanies House · Statutory guidance
- Identity verification for Companies HouseCompanies House · Official registry guidance
- Tell Companies House you have verified someone's identityCompanies House · Official registry guidance
- Changes to reporting material discrepancies to Companies HouseCompanies House · Official registry guidance
- Sanctions and Anti-Money Laundering Act 2018UK Legislation · Primary legislation
- The UK Sanctions ListForeign, Commonwealth & Development Office · Official sanctions list
- Current UK sanctions regimesForeign, Commonwealth & Development Office · Official government guidance
- Financial sanctions general guidanceOffice of Financial Sanctions Implementation · Official regulator guidance
- Report a suspected breach of financial sanctionsOffice of Financial Sanctions Implementation · Official reporting guidance
- Data Protection Act 2018UK Legislation · Primary legislation
- UK General Data Protection RegulationUK Legislation · Retained law
- Data Use and Access Act 2025UK Legislation · Primary legislation
- DUAA summary of data-protection changesInformation Commissioner's Office · Official regulator guidance
- Biometric recognition guidanceInformation Commissioner's Office · Official regulator guidance
- When a data protection impact assessment is requiredInformation Commissioner's Office · Official regulator guidance
- Personal data breaches guideInformation Commissioner's Office · Official regulator guidance
- New data-protection complaints lawInformation Commissioner's Office · Official regulator guidance
- Guide to international transfersInformation Commissioner's Office · Official regulator guidance
- Payment Services Regulations 2017UK Legislation · Primary regulation
- Information accompanying transfers of fundsUK Legislation · Retained law
- Electronic Money Regulations 2011UK Legislation · Primary regulation
- Payment services and electronic money regulationFinancial Conduct Authority · Official regulator guidance
- Safeguarding requirements for payment and e-money institutionsFinancial Conduct Authority · Official regulator guidance
- PS25/12 changes to the safeguarding regimeFinancial Conduct Authority · Official regulator policy
- Cryptoassets AML and CTF regimeFinancial Conduct Authority · Official regulator guidance
- Cryptoasset registration ahead of the new FSMA regimeFinancial Conduct Authority · Official regulator guidance
- FATF United Kingdom country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
Direct answers
United Kingdom KYC, KYB and AML questions
Does every UK business have to follow the Money Laundering Regulations?+
No. Regulation 8 and the detailed sector definitions and exclusions determine relevant-person status. Resolve each entity and activity and its supervisor before applying a control as mandatory.
When must a UK suspicious activity report be made?+
Where a POCA or Terrorism Act disclosure duty applies, make the disclosure as soon as practicable after the relevant knowledge, suspicion or reasonable grounds arise. There is no general monetary threshold or universal fixed-day deadline.
Does the UK have a universal cash transaction report?+
No. For high-value dealers, GBP 10,000 or more in cash is an MLR scope and CDD trigger, including linked transactions. It is not a universal threshold report for all businesses.
What is the UK AML beneficial-ownership threshold?+
For a body corporate, the MLR definition includes more than 25% of shares or voting rights, ultimate control over management or other control. Partnerships and trusts have tailored tests, and ownership and control structure must be understood.
Can Companies House data alone verify a beneficial owner?+
No. MLR regulation 28 says relevant persons do not satisfy beneficial-owner duties by relying solely on information delivered to the registrar. Use current registry data as one input and corroborate it.
Who must verify identity for Companies House?+
Mandatory verification began on 18 November 2025 for new directors and PSCs. Existing directors and PSCs are in a 12-month transition with deadlines depending on confirmation-statement timing, role and registered birth month.
What is the core MLR record-retention period?+
Generally five years from completion of the occasional transaction or end of the business relationship, depending on the record. Some relationship transaction records can be retained up to ten years, and personal data must then be deleted unless an exception applies.
Which UK sanctions list should a business use?+
Use the UK Sanctions List. Since 28 January 2026 it is the only current source for all UK sanctions designations; the former OFSI Consolidated List is closed and no longer updated.
Must a UK cryptoasset business register with the FCA?+
An in-scope cryptoasset exchange provider or custodian wallet provider carrying on business in the UK must register under the MLRs before starting. That registration is not an FCA endorsement or full FSMA authorization.
Is the United Kingdom on a FATF public list?+
The United Kingdom was not named on FATF's current public lists reviewed on 31 July 2026. It remains a FATF member with published mutual-evaluation and follow-up history.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
This checklist is general regulatory information, not legal advice, an authorization decision or a statement that every row applies to every UK business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity, activity, customer, transaction, legal form, UK nation, MLR supervisor, FCA permission, Companies House transition date, sanctions programme, privacy role, live reporting channel and later legal developments with qualified UK counsel and the competent authorities before launch.