المملكة المتحدة KYC, KYB & AML compliance checklist
قائمة عملية وموثقة بالمصادر لتنفيذ متطلبات KYC وKYB وAML في المملكة المتحدة.
- تاريخ آخر مراجعة
- تاريخ آخر مراجعة:
- الإصدار
- الإصدار 1.4

إجابة مباشرة
ما الذي تغطيه قائمة الامتثال الخاصة بـ المملكة المتحدة؟
تحوّل قائمة المملكة المتحدة قواعد KYC وKYB وAML الأساسية إلى 11 مجالات رقابية و49 فحوص تنفيذ، وتشمل الجهات المختصة وواجبات الإبلاغ والأدلة الواجب الاحتفاظ بها.
حقائق تنظيمية أساسية
- Primary AML rule
- Money Laundering Regulations 2017, as amended including SI 2026/621 effective 30 June 2026
- Financial intelligence unit
- UK Financial Intelligence Unit within the National Crime Agency (UKFIU/NCA)
- Suspicious activity report
- No monetary threshold; make a required disclosure as soon as practicable through the applicable internal or UKFIU route
- General occasional CDD
- GBP 12,000 or more from 30 June 2026; sector-specific triggers differ
- Funds-transfer CDD
- A transfer of funds exceeding GBP 800 triggers CDD; prescribed information rules also apply
- High-value dealers
- GBP 10,000 or more in cash is a scope and CDD trigger, not a universal threshold report
- AML beneficial ownership
- More than 25% shares or voting rights, ultimate management control or other control; tailored partnership and trust tests
- Companies House PSC
- More than 25% shares or votes, board-control rights, or significant influence or control under separate statutory conditions
- Core AML retention
- Five years from the record-specific transaction or relationship trigger, subject to limited longer retention and deletion rules
- Current sanctions list
- The UK Sanctions List has been the sole source for UK designations since 28 January 2026
- Cryptoasset businesses
- In-scope UK exchange and custodian-wallet providers must register with the FCA before starting
- FATF public lists
- The United Kingdom was not named on the FATF public lists reviewed 31 July 2026
تفاصيل التنفيذ
متطلبات وإجراءات الامتثال في المملكة المتحدة
افتح كل مجال لمراجعة المتطلب وإجراء التنفيذ المقترح والأدلة الواجب الاحتفاظ بها والمصدر الأساسي.
01Scope, authorities and licensing perimeterResolve every entity, activity, customer and UK nexus first. MLR supervision or registration does not replace FCA authorization, Companies House duties, sanctions compliance or another professional or devolved requirement.5 عناصر+
The MLRs apply to the relevant persons in regulation 8 acting in the course of UK business, subject to detailed sector definitions and exclusions.
- إجراء التنفيذ
- Map each entity, product and service to regulations 8-15 and identify the FCA, HMRC, Gambling Commission or professional-body supervisor before launch.
- الأدلة الواجب الاحتفاظ بها
- Perimeter memorandum, legal-entity map, activity analysis, supervisor decision, exclusions and accountable owner.
- المصدر الأساسي
- MLRs, regs. 8-15 and 46
The 2026 MLR amendments generally took effect on 30 June 2026, while crypto correspondent rule 34A does not start until 1 February 2027.
- إجراء التنفيذ
- Configure operative sterling thresholds and pooled-account controls now; place future crypto correspondent and 2027 control reforms on a dated change calendar.
- الأدلة الواجب الاحتفاظ بها
- Amendment assessment, effective-date register, configuration tests, future-change tickets and legal approval.
- المصدر الأساسي
- Money Laundering and Terrorist Financing (Amendment) Regulations 2026, reg. 1
Payment services and e-money issuance require the correct FCA authorization or registration unless another status or exclusion applies.
- إجراء التنفيذ
- Classify each payment and e-money function, apply before regulated launch, and reconcile the permission with MLR supervisory status.
- الأدلة الواجب الاحتفاظ بها
- PSR and EMR analysis, application, FCA register extract, permissions matrix and launch gate.
- المصدر الأساسي
- PSRs 2017, regs. 4, 6 and Sch. 1; EMRs 2011, regs. 9 and 13; FCA payments guidance
An in-scope cryptoasset exchange provider or custodian wallet provider carrying on UK business must be registered with the FCA before starting.
- إجراء التنفيذ
- Apply regulations 14A, 54 and 56 to the service and UK nexus; obtain registration before launch and separately assess financial promotions and the future FSMA regime.
- الأدلة الواجب الاحتفاظ بها
- Crypto perimeter memo, FCA application, registration decision, promotions review and 2027 transition plan.
- المصدر الأساسي
- MLRs, regs. 14A, 54 and 56; FCA, Cryptoassets AML/CTF regime
Where appropriate for size and nature, appoint a responsible board or senior manager, screen relevant employees and maintain independent audit; every relevant person also needs a nominated officer unless the sole-person exception applies.
- إجراء التنفيذ
- Document appointments, notify the supervisor within 14 days where required, screen staff and operate risk-based independent assurance.
- الأدلة الواجب الاحتفاظ بها
- Appointment letters, supervisor notice, screening files, audit plan, reports and remediation evidence.
- المصدر الأساسي
- MLRs, regs. 21 and 24
02Governance, risk assessment and control frameworkA relevant person's programme must be demonstrably proportionate to its actual UK risks and current MLR obligations, including proliferation financing.4 عناصر+
A relevant person must identify, assess and keep current written records of its money-laundering and terrorist-financing risks.
- إجراء التنفيذ
- Assess customers, countries, products, transactions, delivery channels, size and nature; obtain approval and update for material change.
- الأدلة الواجب الاحتفاظ بها
- Business-wide risk assessment, source register, methodology, approvals, change log and control mapping.
- المصدر الأساسي
- MLRs, reg. 18
For a pooled account newly provided from 30 June 2026, understand purpose and use, test consistency with customer knowledge and risk, update CDD if needed, assess and mitigate ML/TF risk and consider account controls.
- إجراء التنفيذ
- Document the measures and demonstrate to the supervisor that their extent is appropriate to the account's ML/TF risk.
- الأدلة الواجب الاحتفاظ بها
- Purpose and use assessment, consistency test, updated CDD, risk decision, controls, approval and supervisor evidence pack.
- المصدر الأساسي
- MLRs, reg. 29(10)-(13); SI 2026/621, reg. 15
A relevant person must separately assess proliferation-financing risk and maintain proportionate senior-approved policies, controls and procedures.
- إجراء التنفيذ
- Map sanctions-evasion and proliferation exposure across ownership, trade, payments, geography and technology; connect risks to preventive controls.
- الأدلة الواجب الاحتفاظ بها
- PF risk assessment, senior approval, scenario inventory, sanctions mapping, tests and remediation log.
- المصدر الأساسي
- MLRs, regs. 18A and 19A
AML/CFT policies must cover risk management, internal controls, CDD, reliance, records, compliance monitoring, unusual activity and new technology.
- إجراء التنفيذ
- Maintain a control inventory mapped to regulations 19-20, assign owners, test design and operation, and communicate changes across relevant branches.
- الأدلة الواجب الاحتفاظ بها
- Policy set, control matrix, board minutes, testing results, issues, training and branch attestations.
- المصدر الأساسي
- MLRs, regs. 19-20
03Natural-person identification and verificationCDD triggers and evidence strength depend on the relationship, transaction and risk. The 30 June 2026 sterling thresholds must not be confused with universal onboarding rules.5 عناصر+
CDD applies when establishing a business relationship, on suspicion, when prior evidence is doubtful and at the prescribed occasional-transaction triggers.
- إجراء التنفيذ
- Build a trigger matrix covering the general GBP 12,000 threshold, funds transfers above GBP 800 and sector-specific cash, casino, art, letting and crypto triggers.
- الأدلة الواجب الاحتفاظ بها
- Trigger matrix, workflow rules, linked-transaction logic, suspicion override, tests and exceptions.
- المصدر الأساسي
- MLRs, reg. 27 as amended by SI 2026/621, reg. 14
A relevant person must identify the customer, verify identity from reliable independent documents or information and assess the relationship's purpose and intended nature.
- إجراء التنفيذ
- Define risk-based evidence standards, validate authenticity and independence, and record purpose, expected activity and decision before activation.
- الأدلة الواجب الاحتفاظ بها
- Identity evidence, source validation, customer profile, purpose record, timestamps and approval.
- المصدر الأساسي
- MLRs, reg. 28(2), (12)-(13) and (18)
Secure electronic identification can be a reliable independent source where it resists fraud and misuse and gives the assurance needed for the risk.
- إجراء التنفيذ
- Assess digital identity assurance, fraud controls, accessibility, exception handling and evidence retention; do not treat vendor output as automatically sufficient.
- الأدلة الواجب الاحتفاظ بها
- Vendor assessment, certification or assurance evidence, test results, decision logs, exceptions and monitoring.
- المصدر الأساسي
- MLRs, reg. 28(19); HM Treasury, Using digital identities with the MLRs
A person purporting to act for a customer must be authorized, identified and independently verified.
- إجراء التنفيذ
- Validate the mandate and signatory powers, identify and verify the representative, and connect every instruction to current authority.
- الأدلة الواجب الاحتفاظ بها
- Mandate, board authority, power of attorney, representative KYC, validation log and instruction record.
- المصدر الأساسي
- MLRs, reg. 28(10)
If required CDD cannot be completed, do not open the relationship or transact, terminate an existing relationship and consider a POCA or Terrorism Act disclosure, subject to regulation 31's express exceptions.
- إجراء التنفيذ
- Block activation and transactions, escalate termination and repayment, document any privilege or insolvency exception and record the SAR and consent assessment.
- الأدلة الواجب الاحتفاظ بها
- CDD failure, restrictions, termination or repayment record, exception analysis, SAR decision and approvals.
- المصدر الأساسي
- MLRs, reg. 31
04KYB, beneficial ownership and Companies HouseKeep MLR beneficial-owner CDD, register-discrepancy reporting and the company's own PSC and identity-verification duties distinct. A Companies House record is not sufficient by itself for MLR beneficial-owner verification.4 عناصر+
Corporate CDD requires verified registered details and reasonable measures on governing law, constitution, directors or senior managers, ownership and control.
- إجراء التنفيذ
- Obtain current registry and constitutional material, verify status and address, map directors and senior operators, and understand every ownership layer.
- الأدلة الواجب الاحتفاظ بها
- Companies House extract, constitutional documents, status check, director list, ownership chart and verification log.
- المصدر الأساسي
- MLRs, reg. 28(3)-(5)
A body corporate's beneficial owners include individuals with ultimate management control, more than 25% of shares or voting rights, or other control; partnerships and trusts use separate tests.
- إجراء التنفيذ
- Trace direct and indirect interests, voting arrangements and control to natural persons; apply regulations 5 and 6 by entity type.
- الأدلة الواجب الاحتفاظ بها
- Ownership calculations, control analysis, trust or partnership parties, source documents and reviewer approval.
- المصدر الأساسي
- MLRs, regs. 5-6
Only after exhausting all possible means may a relevant person treat the responsible senior manager as the body corporate's beneficial owner, with written records of actions and difficulties.
- إجراء التنفيذ
- Escalate unresolved ownership, document every search and inconsistency, verify the senior manager and decide whether risk or failed-CDD rules prevent onboarding.
- الأدلة الواجب الاحتفاظ بها
- Exhaustion log, source searches, escalation, senior-manager verification, risk decision and approval.
- المصدر الأساسي
- MLRs, reg. 28(6)-(9) and 31
Before onboarding and at relevant later CDD or monitoring for a regulation 30A customer, collect the prescribed register excerpt and report any Schedule 3AZA material discrepancy through the specified registrar or HMRC route.
- إجراء التنفيذ
- Compare register and CDD evidence, classify materiality, resolve false positives, submit through the correct route and retain the report.
- الأدلة الواجب الاحتفاظ بها
- Register excerpt, comparison, discrepancy analysis, submission, acknowledgement and resolution.
- المصدر الأساسي
- MLRs, reg. 30A and Sch. 3AZA
05PEPs, EDD, source of wealth and remote onboardingEDD applies to prescribed cases and other high-risk situations. Domestic PEP status is treated as lower risk absent other enhanced risk factors, but it still requires the regulation 35 process.4 عناصر+
EDD and enhanced monitoring are required in regulation 33 cases, including a FATF call-for-action-country relationship or transaction and any other situation presenting higher ML or TF risk.
- إجراء التنفيذ
- Configure mandatory triggers and a documented high-risk methodology; do not automatically equate the FATF increased-monitoring list with the regulation 33 country trigger.
- الأدلة الواجب الاحتفاظ بها
- EDD rules, FATF list version, risk decision, enhanced checks, approvals and monitoring plan.
- المصدر الأساسي
- MLRs, reg. 33 as amended by SI 2026/621, reg. 19
When establishing or continuing a relationship with a PEP, family member or close associate, including an entity beneficially owned by the PEP, obtain senior approval, establish source of wealth and funds, and conduct enhanced monitoring.
- إجراء التنفيذ
- Screen customers and beneficial owners, adjudicate matches, corroborate wealth and funds, approve the relationship and apply separate risk and EDD rules to other PEP transactions.
- الأدلة الواجب الاحتفاظ بها
- Screening result, relationship analysis, wealth narrative, funds evidence, senior approval, alerts and reviews.
- المصدر الأساسي
- MLRs, regs. 33 and 35(1)-(5), (13)
Domestic PEPs, their family members and known close associates are presumed lower risk than non-domestic PEPs unless other enhanced risk factors exist.
- إجراء التنفيذ
- Apply the PEP controls proportionately, document additional risk factors and avoid either automatic rejection or unjustified simplified treatment.
- الأدلة الواجب الاحتفاظ بها
- Domestic-status proof, risk assessment, factor analysis, measures, approval and review schedule.
- المصدر الأساسي
- MLRs, reg. 35(3A) and (12)
Remote onboarding, anonymity-favouring products and new technology require risk assessment and, where higher risk exists, enhanced measures.
- إجراء التنفيذ
- Test document and person match, fraud and impersonation risk, device and network signals, accessibility, manual escalation and vendor performance.
- الأدلة الواجب الاحتفاظ بها
- Remote-risk assessment, liveness or match tests, device data, exception files, vendor assurance and sampled outcomes.
- المصدر الأساسي
- MLRs, regs. 19(4), 28(19), 33 and 35; HM Treasury digital-identity guidance
06Monitoring, suspicious activity and confidentialityThe MLRs create monitoring and internal-control duties; POCA and the Terrorism Act create role-specific disclosure offences. Case records must show when the statutory knowledge or suspicion test arose and why disclosure was timely.4 عناصر+
Ongoing monitoring includes scrutiny of transactions, source of funds where necessary, and reviews that keep CDD documents and information current.
- إجراء التنفيذ
- Calibrate monitoring to expected activity and risk, investigate linked behaviour, refresh CDD on change and record filing and non-filing decisions.
- الأدلة الواجب الاحتفاظ بها
- Scenario inventory, expected-activity profile, alerts, investigation notes, refresh history and dispositions.
- المصدر الأساسي
- MLRs, reg. 28(11)-(13)
A regulated-sector employee or nominated officer must make the applicable disclosure when role-specific conditions are met and information concerns a person engaged in, or attempting, money laundering or terrorist financing.
- إجراء التنفيذ
- Escalate completed and attempted activity through the nominated officer and UKFIU/NCA routes, preserving privilege and reasonable-excuse analysis.
- الأدلة الواجب الاحتفاظ بها
- Attempted or completed activity, internal report, nominated-officer assessment, legal analysis, SAR reference and acknowledgement.
- المصدر الأساسي
- POCA, ss. 330-332 and 338; Terrorism Act 2000, ss. 19 and 21A; NCA SAR guidance
A required disclosure is made as soon as practicable; there is no general monetary threshold or universal fixed-day SAR deadline.
- إجراء التنفيذ
- Timestamp receipt, investigation, threshold formation, internal escalation and UKFIU submission; use the current SAR Portal and document unavoidable delay.
- الأدلة الواجب الاحتفاظ بها
- Case chronology, evidence reviewed, suspicion rationale, portal submission, receipt and delay explanation.
- المصدر الأساسي
- POCA, ss. 330-332; NCA, Suspicious Activity Reports
Tipping-off and prejudicing-investigation offences apply when their statutory conditions are met, subject to defined disclosures and other exceptions.
- إجراء التنفيذ
- Restrict case information, train staff, review customer communications and CDD continuation, and obtain legal approval for sensitive disclosures.
- الأدلة الواجب الاحتفاظ بها
- Access logs, communication review, training, legal decision, exception analysis and incident record.
- المصدر الأساسي
- POCA, ss. 333A-333D and 342; Terrorism Act 2000, ss. 21D-21G and 39; MLRs, reg. 28(14)-(15)
07Payments, cash triggers and transfer informationThe UK does not impose one universal transaction report. CDD thresholds, payment-transfer information and cryptoasset travel-rule duties must be configured separately.4 عناصر+
From 30 June 2026, general occasional transactions of GBP 12,000 or more and funds transfers exceeding GBP 800 trigger CDD, subject to sector-specific rules and linked operations.
- إجراء التنفيذ
- Configure each threshold, currency conversion, linked-transaction detection, sector exception and suspicion override without treating it as a reporting threshold.
- الأدلة الواجب الاحتفاظ بها
- Rules specification, effective-date control, conversion source, test cases, alerts and CDD files.
- المصدر الأساسي
- MLRs, reg. 27(1)-(2); SI 2026/621, reg. 14
A high-value dealer's GBP 10,000 cash transaction is an MLR scope and CDD trigger, including linked operations; it is not a standalone universal cash report.
- إجراء التنفيذ
- Identify qualifying goods activity and cash paid directly, indirectly or into an account for the seller's benefit; apply CDD before proceeding.
- الأدلة الواجب الاحتفاظ بها
- HVD perimeter analysis, cash aggregation, payer and beneficiary records, CDD and transaction decision.
- المصدر الأساسي
- MLRs, regs. 14 and 27(3)-(4)
Payment service providers must carry prescribed payer and payee information, detect missing data and respond to competent-authority enquiries under the retained funds-transfer framework.
- إجراء التنفيذ
- Map originator, beneficiary and intermediary roles, mandatory fields, rejection or follow-up rules, sanctions screening and rapid retrieval.
- الأدلة الواجب الاحتفاظ بها
- Message-field mapping, validation tests, exception queue, follow-up records, screening and retrieval exercise.
- المصدر الأساسي
- MLRs, Part 7; retained Regulation (EU) 2015/847
Cryptoasset businesses must apply the UK travel rule, including prescribed originator and beneficiary information and the GBP 800 threshold for additional information in specified transfers.
- إجراء التنفيذ
- Classify inter-business and unhosted-wallet transfers, collect and verify required data, manage missing information and report repeated failures to the FCA where required.
- الأدلة الواجب الاحتفاظ بها
- Travel-rule design, counterparty assessment, transfer messages, requests, decisions, FCA reports and records.
- المصدر الأساسي
- MLRs, regs. 64B-64G as amended by SI 2026/621, regs. 32-33
08Targeted financial sanctions and asset freezesUK sanctions are programme-specific. The UK Sanctions List supports detection, while the operative regulation determines designation effect, ownership and control, prohibitions, freezes, exceptions, licences and reports.4 عناصر+
UK persons worldwide and persons within UK territory must comply with applicable sanctions prohibitions under programme regulations made under SAMLA.
- إجراء التنفيذ
- Map persons, ownership and control, products, counterparties, vessels, geography and conduct to every applicable programme before execution.
- الأدلة الواجب الاحتفاظ بها
- Sanctions perimeter, programme inventory, legal analysis, screening logs, ownership review and decision.
- المصدر الأساسي
- SAMLA 2018; OFSI, Financial sanctions general guidance
Since 28 January 2026 the UK Sanctions List is the only current source for all UK sanctions designations; the former OFSI Consolidated List is closed.
- إجراء التنفيذ
- Screen against current UK Sanctions List data, monitor updates and remove any production dependency on the closed consolidated list.
- الأدلة الواجب الاحتفاظ بها
- List source, version and timestamp, update alerts, screening tests, migration record and quality checks.
- المصدر الأساسي
- FCDO, The UK Sanctions List; OFSI general guidance
Asset-freeze prohibitions can extend to entities owned or controlled by a designated person even if the entity is not separately named.
- إجراء التنفيذ
- Investigate direct and indirect ownership and control, joint arrangements and practical control; freeze or reject as the operative rule requires.
- الأدلة الواجب الاحتفاظ بها
- Ownership chart, control evidence, legal conclusion, freeze or rejection, approvals and audit trail.
- المصدر الأساسي
- OFSI, Financial sanctions general guidance, ownership and control
A relevant firm must inform OFSI as soon as practicable when the applicable programme's knowledge or reasonable-cause reporting trigger is met and must report frozen assets as required.
- إجراء التنفيذ
- Escalate potential breaches and designated-person assets immediately, preserve funds, use the current OFSI route and assess separate UKFIU disclosure duties.
- الأدلة الواجب الاحتفاظ بها
- Case chronology, asset record, freeze, OFSI report, licence or exception analysis, SAR assessment and acknowledgements.
- المصدر الأساسي
- Applicable sanctions programme regulations; OFSI, Financial sanctions general guidance, reporting obligations
09Records, reliance and regulator accessFive years is the core MLR period, but its starting event and limited longer-retention rules differ. Outsourcing and reliance do not transfer legal accountability.5 عناصر+
CDD, discrepancy, transfer-information and transaction-reconstruction records must generally be kept five years from the relevant transaction completion or end of business relationship.
- إجراء التنفيذ
- Map every record class to its exact trigger, retain reconstructable evidence and prevent early deletion across primary and backup systems.
- الأدلة الواجب الاحتفاظ بها
- Retention schedule, trigger dates, system configuration, legal holds, samples and deletion certificates.
- المصدر الأساسي
- MLRs, reg. 40(1)-(4)
A pooled-account customer must provide underlying-person and beneficial-owner identities on request and keep accurate, up-to-date written records of all monies paid in and out for five years from when each payment is known or reasonably believed complete.
- إجراء التنفيذ
- Require the customer to provide law-enforcement information about itself and account management and use on request; preserve regulation 29 privilege and confidentiality treatment.
- الأدلة الواجب الاحتفاظ بها
- Information requests, ownership data, payment ledger, per-payment retention clocks, authority responses and privilege record.
- المصدر الأساسي
- MLRs, reg. 29(14)-(18); SI 2026/621, reg. 15
After the applicable period, MLR personal data must be deleted unless another enactment, court proceedings, data-subject consent or reasonable legal-proceeding need supports retention.
- إجراء التنفيذ
- Run defensible deletion and exception review, record the legal basis for any extension and prevent indefinite AML-purpose retention.
- الأدلة الواجب الاحتفاظ بها
- Deletion workflow, exception register, consent or legal basis, approvals, logs and verification tests.
- المصدر الأساسي
- MLRs, reg. 40(5)
Reliance on a qualifying third party does not remove the relevant person's liability and requires immediate information plus arrangements for prompt document copies.
- إجراء التنفيذ
- Confirm third-party eligibility, obtain the required CDD data immediately, test document retrieval and prohibit reliance in a FATF call-for-action country unless the group exception applies.
- الأدلة الواجب الاحتفاظ بها
- Reliance assessment, agreement, data receipt, retrieval test, country check, monitoring and exit plan.
- المصدر الأساسي
- MLRs, reg. 39
Using an agent or outsourcing provider does not transfer liability for CDD or register-discrepancy measures.
- إجراء التنفيذ
- Contract for duties, access, security, audit, incident escalation and exit; test identity, screening, monitoring, reporting and retrieval end to end.
- الأدلة الواجب الاحتفاظ بها
- Responsibility matrix, contract, vendor diligence, control tests, incidents, remediation and exit package.
- المصدر الأساسي
- MLRs, reg. 39(7)-(8)
10Privacy, biometrics, breaches and transfersKYC necessity does not displace UK data-protection duties. Resolve controller and processor roles, lawful basis, special-category conditions, transparency, minimization and retention for each data use.5 عناصر+
UK GDPR principles and lawful-basis requirements apply to in-scope KYC data; from 19 June 2026 controllers must also facilitate complaints, acknowledge them within 30 days and respond without undue delay.
- إجراء التنفيذ
- Map each data purpose, lawful basis, notice, recipient, access and retention; operate the DUAA complaint channel, investigation and outcome process.
- الأدلة الواجب الاحتفاظ بها
- Record of processing, lawful-basis register, privacy notice, data map, complaint log, acknowledgements and outcomes.
- المصدر الأساسي
- UK GDPR, arts. 5-6; DPA 2018; DUAA 2025, s. 103; ICO DUAA summary
Biometric data used to uniquely identify a person is special-category data and requires both an Article 6 lawful basis and an Article 9 condition.
- إجراء التنفيذ
- Document necessity, proportionality and the special-category condition; minimize templates, separate uses, test accuracy and bias, and provide a non-biometric route where appropriate.
- الأدلة الواجب الاحتفاظ بها
- Lawful-basis analysis, Article 9 condition, biometric design, accuracy and bias tests, vendor terms and deletion proof.
- المصدر الأساسي
- UK GDPR, arts. 4(14), 6 and 9; DPA 2018; ICO biometric guidance
A DPIA is required before processing likely to result in high risk, including specified large-scale sensitive processing and biometric combinations.
- إجراء التنفيذ
- Screen every identity and monitoring design early, complete and approve the DPIA where required, mitigate risks and consult the ICO if high residual risk remains.
- الأدلة الواجب الاحتفاظ بها
- Screening record, DPIA, necessity test, mitigations, DPO advice, approval and consultation record.
- المصدر الأساسي
- UK GDPR, art. 35; ICO, Data protection impact assessments
Notify a reportable personal-data breach to the ICO without undue delay and, where feasible, within 72 hours; notify affected people without undue delay when high risk exists and document every breach.
- إجراء التنفيذ
- Start the clock on awareness, contain and assess risk, submit available facts within 72 hours, supplement promptly and preserve the full decision record.
- الأدلة الواجب الاحتفاظ بها
- Incident chronology, risk assessment, ICO report, affected-person notice, follow-up and breach register.
- المصدر الأساسي
- UK GDPR, arts. 33-34; ICO, Personal data breaches guide
A restricted international transfer requires an applicable UK adequacy regulation, safeguard or Article 49 exception in addition to ordinary UK GDPR compliance.
- إجراء التنفيذ
- Map destinations and onward transfers, select and document the route, complete transfer-risk work where required, and contract for security, rights and exit.
- الأدلة الواجب الاحتفاظ بها
- Transfer map, adequacy or safeguard record, risk assessment, contract, supplementary measures and review.
- المصدر الأساسي
- UK GDPR, arts. 44-49; ICO, Guide to international transfers
11Payments, agents and practical evidence packsTurn the perimeter and legal controls into testable launch gates. Payment, e-money, cryptoasset, Companies House and MLR statuses overlap but are not substitutes for one another.5 عناصر+
Covered payment and e-money firms must safeguard relevant funds under the PSRs or EMRs and the FCA supplementary regime effective 7 May 2026.
- إجراء التنفيذ
- Apply CASS 10A and 15 and SUP 3A and 16 as relevant, identify and segregate funds, reconcile, maintain the resolution pack and submit required returns.
- الأدلة الواجب الاحتفاظ بها
- Safeguarding analysis, account documents, reconciliations, discrepancy log, resolution pack, audit and returns.
- المصدر الأساسي
- PSRs 2017, reg. 23; EMRs 2011, reg. 20; FCA PS25/12 and safeguarding guidance
A payment institution remains responsible for acts and omissions of agents and must register agents before they provide services; e-money distributors and agents have separate rules.
- إجراء التنفيذ
- Perform due diligence, submit required FCA information, verify register status, contract for controls and supervise conduct, AML, complaints and safeguarding.
- الأدلة الواجب الاحتفاظ بها
- Agent assessment, FCA submission, register extract, contract, monitoring, complaints and termination plan.
- المصدر الأساسي
- PSRs 2017, regs. 34-36; EMRs 2011, regs. 33-36
An ACSP verifying identity for Companies House must be supervised for UK AML compliance, meet the verification standard and keep verification records for seven years.
- إجراء التنفيذ
- Keep ACSP verification separate from MLR CDD, capture the evidence and prescribed statement, protect the personal code and calendar seven-year retention.
- الأدلة الواجب الاحتفاظ بها
- ACSP registration, supervision proof, verification record, Companies House submission, access controls and retention schedule.
- المصدر الأساسي
- Companies House, Tell Companies House you have verified someone's identity
Companies must identify and report PSCs, and mandatory identity verification applies to new directors and PSCs from 18 November 2025 with role-specific transition deadlines for existing persons.
- إجراء التنفيذ
- Apply all five PSC conditions, file changes, capture each personal-code deadline, and distinguish Companies House verification from the business's own MLR CDD.
- الأدلة الواجب الاحتفاظ بها
- PSC analysis, filings, confirmation statement, personal-code evidence, deadline calendar and reconciliation to CDD.
- المصدر الأساسي
- Companies Act 2006, Part 21A and Sch. 1A; Companies House PSC and identity-verification guidance
Each checklist row requires a documented applicability decision, current source, control owner and reconstructable operating evidence before launch.
- إجراء التنفيذ
- Mark every row applicable, not applicable or pending counsel confirmation; close blockers and obtain compliance, legal, privacy, security and product approval.
- الأدلة الواجب الاحتفاظ بها
- Completed checklist, rationale, source snapshot, owner sign-off, test result, gap ticket and launch approval.
- المصدر الأساسي
- MLRs, regs. 18-21, 24 and 28
سجل المصادر الأساسية
39 مصدرًا مستخدمًا في هذه القائمة
استخدم هذه الروابط للتحقق من التشريعات وإرشادات الجهات الرقابية وإجراءات الإبلاغ والبيانات الدولية.
- Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017UK Legislation · Primary regulation
- Money Laundering and Terrorist Financing Amendment Regulations 2026UK Legislation · Primary regulation
- June 2026 money laundering advisory noticeHM Treasury · Official government notice
- HMRC anti-money laundering guidance for supervised businessesHM Revenue & Customs · Official supervisor guidance
- Using digital identities with the Money Laundering RegulationsHM Treasury and DSIT · Official government guidance
- Proceeds of Crime Act 2002UK Legislation · Primary legislation
- Terrorism Act 2000UK Legislation · Primary legislation
- Suspicious Activity ReportsNational Crime Agency · Official FIU guidance
- Companies Act 2006UK Legislation · Primary legislation
- Economic Crime and Corporate Transparency Act 2023UK Legislation · Primary legislation
- People with significant controlCompanies House · Official registry guidance
- 2026 statutory guidance on significant influence or controlCompanies House · Statutory guidance
- Identity verification for Companies HouseCompanies House · Official registry guidance
- Tell Companies House you have verified someone's identityCompanies House · Official registry guidance
- Changes to reporting material discrepancies to Companies HouseCompanies House · Official registry guidance
- Sanctions and Anti-Money Laundering Act 2018UK Legislation · Primary legislation
- The UK Sanctions ListForeign, Commonwealth & Development Office · Official sanctions list
- Current UK sanctions regimesForeign, Commonwealth & Development Office · Official government guidance
- Financial sanctions general guidanceOffice of Financial Sanctions Implementation · Official regulator guidance
- Report a suspected breach of financial sanctionsOffice of Financial Sanctions Implementation · Official reporting guidance
- Data Protection Act 2018UK Legislation · Primary legislation
- UK General Data Protection RegulationUK Legislation · Retained law
- Data Use and Access Act 2025UK Legislation · Primary legislation
- DUAA summary of data-protection changesInformation Commissioner's Office · Official regulator guidance
- Biometric recognition guidanceInformation Commissioner's Office · Official regulator guidance
- When a data protection impact assessment is requiredInformation Commissioner's Office · Official regulator guidance
- Personal data breaches guideInformation Commissioner's Office · Official regulator guidance
- New data-protection complaints lawInformation Commissioner's Office · Official regulator guidance
- Guide to international transfersInformation Commissioner's Office · Official regulator guidance
- Payment Services Regulations 2017UK Legislation · Primary regulation
- Information accompanying transfers of fundsUK Legislation · Retained law
- Electronic Money Regulations 2011UK Legislation · Primary regulation
- Payment services and electronic money regulationFinancial Conduct Authority · Official regulator guidance
- Safeguarding requirements for payment and e-money institutionsFinancial Conduct Authority · Official regulator guidance
- PS25/12 changes to the safeguarding regimeFinancial Conduct Authority · Official regulator policy
- Cryptoassets AML and CTF regimeFinancial Conduct Authority · Official regulator guidance
- Cryptoasset registration ahead of the new FSMA regimeFinancial Conduct Authority · Official regulator guidance
- FATF United Kingdom country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
إجابات مباشرة
أسئلة KYC وKYB وAML في المملكة المتحدة
Does every UK business have to follow the Money Laundering Regulations?+
No. Regulation 8 and the detailed sector definitions and exclusions determine relevant-person status. Resolve each entity and activity and its supervisor before applying a control as mandatory.
When must a UK suspicious activity report be made?+
Where a POCA or Terrorism Act disclosure duty applies, make the disclosure as soon as practicable after the relevant knowledge, suspicion or reasonable grounds arise. There is no general monetary threshold or universal fixed-day deadline.
Does the UK have a universal cash transaction report?+
No. For high-value dealers, GBP 10,000 or more in cash is an MLR scope and CDD trigger, including linked transactions. It is not a universal threshold report for all businesses.
What is the UK AML beneficial-ownership threshold?+
For a body corporate, the MLR definition includes more than 25% of shares or voting rights, ultimate control over management or other control. Partnerships and trusts have tailored tests, and ownership and control structure must be understood.
Can Companies House data alone verify a beneficial owner?+
No. MLR regulation 28 says relevant persons do not satisfy beneficial-owner duties by relying solely on information delivered to the registrar. Use current registry data as one input and corroborate it.
Who must verify identity for Companies House?+
Mandatory verification began on 18 November 2025 for new directors and PSCs. Existing directors and PSCs are in a 12-month transition with deadlines depending on confirmation-statement timing, role and registered birth month.
What is the core MLR record-retention period?+
Generally five years from completion of the occasional transaction or end of the business relationship, depending on the record. Some relationship transaction records can be retained up to ten years, and personal data must then be deleted unless an exception applies.
Which UK sanctions list should a business use?+
Use the UK Sanctions List. Since 28 January 2026 it is the only current source for all UK sanctions designations; the former OFSI Consolidated List is closed and no longer updated.
Must a UK cryptoasset business register with the FCA?+
An in-scope cryptoasset exchange provider or custodian wallet provider carrying on business in the UK must register under the MLRs before starting. That registration is not an FCA endorsement or full FSMA authorization.
Is the United Kingdom on a FATF public list?+
The United Kingdom was not named on FATF's current public lists reviewed on 31 July 2026. It remains a FATF member with published mutual-evaluation and follow-up history.
منهجية البحث والمراجعة
تحدد VOVE ID Compliance Research النطاق التنظيمي، وتحول الالتزامات إلى ضوابط تشغيلية، وتربط الادعاءات الجوهرية بالمصادر، وتسجل تاريخ وإصدار كل مراجعة.
This checklist is general regulatory information, not legal advice, an authorization decision or a statement that every row applies to every UK business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity, activity, customer, transaction, legal form, UK nation, MLR supervisor, FCA permission, Companies House transition date, sanctions programme, privacy role, live reporting channel and later legal developments with qualified UK counsel and the competent authorities before launch.