Royaume-Uni KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Royaume-Uni.
- Dernière revue
- Dernière revue:
- Version
- Version 1.4

Réponse directe
Que couvre la checklist de conformité pour Royaume-Uni ?
La checklist pour Royaume-Uni traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 49 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML rule
- Money Laundering Regulations 2017, as amended including SI 2026/621 effective 30 June 2026
- Financial intelligence unit
- UK Financial Intelligence Unit within the National Crime Agency (UKFIU/NCA)
- Suspicious activity report
- No monetary threshold; make a required disclosure as soon as practicable through the applicable internal or UKFIU route
- General occasional CDD
- GBP 12,000 or more from 30 June 2026; sector-specific triggers differ
- Funds-transfer CDD
- A transfer of funds exceeding GBP 800 triggers CDD; prescribed information rules also apply
- High-value dealers
- GBP 10,000 or more in cash is a scope and CDD trigger, not a universal threshold report
- AML beneficial ownership
- More than 25% shares or voting rights, ultimate management control or other control; tailored partnership and trust tests
- Companies House PSC
- More than 25% shares or votes, board-control rights, or significant influence or control under separate statutory conditions
- Core AML retention
- Five years from the record-specific transaction or relationship trigger, subject to limited longer retention and deletion rules
- Current sanctions list
- The UK Sanctions List has been the sole source for UK designations since 28 January 2026
- Cryptoasset businesses
- In-scope UK exchange and custodian-wallet providers must register with the FCA before starting
- FATF public lists
- The United Kingdom was not named on the FATF public lists reviewed 31 July 2026
Détail d’implémentation
Exigences et actions de conformité pour Royaume-Uni
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensing perimeterResolve every entity, activity, customer and UK nexus first. MLR supervision or registration does not replace FCA authorization, Companies House duties, sanctions compliance or another professional or devolved requirement.5 éléments+
The MLRs apply to the relevant persons in regulation 8 acting in the course of UK business, subject to detailed sector definitions and exclusions.
- Action d’implémentation
- Map each entity, product and service to regulations 8-15 and identify the FCA, HMRC, Gambling Commission or professional-body supervisor before launch.
- Preuves à conserver
- Perimeter memorandum, legal-entity map, activity analysis, supervisor decision, exclusions and accountable owner.
- Source primaire
- MLRs, regs. 8-15 and 46
The 2026 MLR amendments generally took effect on 30 June 2026, while crypto correspondent rule 34A does not start until 1 February 2027.
- Action d’implémentation
- Configure operative sterling thresholds and pooled-account controls now; place future crypto correspondent and 2027 control reforms on a dated change calendar.
- Preuves à conserver
- Amendment assessment, effective-date register, configuration tests, future-change tickets and legal approval.
- Source primaire
- Money Laundering and Terrorist Financing (Amendment) Regulations 2026, reg. 1
Payment services and e-money issuance require the correct FCA authorization or registration unless another status or exclusion applies.
- Action d’implémentation
- Classify each payment and e-money function, apply before regulated launch, and reconcile the permission with MLR supervisory status.
- Preuves à conserver
- PSR and EMR analysis, application, FCA register extract, permissions matrix and launch gate.
- Source primaire
- PSRs 2017, regs. 4, 6 and Sch. 1; EMRs 2011, regs. 9 and 13; FCA payments guidance
An in-scope cryptoasset exchange provider or custodian wallet provider carrying on UK business must be registered with the FCA before starting.
- Action d’implémentation
- Apply regulations 14A, 54 and 56 to the service and UK nexus; obtain registration before launch and separately assess financial promotions and the future FSMA regime.
- Preuves à conserver
- Crypto perimeter memo, FCA application, registration decision, promotions review and 2027 transition plan.
- Source primaire
- MLRs, regs. 14A, 54 and 56; FCA, Cryptoassets AML/CTF regime
Where appropriate for size and nature, appoint a responsible board or senior manager, screen relevant employees and maintain independent audit; every relevant person also needs a nominated officer unless the sole-person exception applies.
- Action d’implémentation
- Document appointments, notify the supervisor within 14 days where required, screen staff and operate risk-based independent assurance.
- Preuves à conserver
- Appointment letters, supervisor notice, screening files, audit plan, reports and remediation evidence.
- Source primaire
- MLRs, regs. 21 and 24
02Governance, risk assessment and control frameworkA relevant person's programme must be demonstrably proportionate to its actual UK risks and current MLR obligations, including proliferation financing.4 éléments+
A relevant person must identify, assess and keep current written records of its money-laundering and terrorist-financing risks.
- Action d’implémentation
- Assess customers, countries, products, transactions, delivery channels, size and nature; obtain approval and update for material change.
- Preuves à conserver
- Business-wide risk assessment, source register, methodology, approvals, change log and control mapping.
- Source primaire
- MLRs, reg. 18
For a pooled account newly provided from 30 June 2026, understand purpose and use, test consistency with customer knowledge and risk, update CDD if needed, assess and mitigate ML/TF risk and consider account controls.
- Action d’implémentation
- Document the measures and demonstrate to the supervisor that their extent is appropriate to the account's ML/TF risk.
- Preuves à conserver
- Purpose and use assessment, consistency test, updated CDD, risk decision, controls, approval and supervisor evidence pack.
- Source primaire
- MLRs, reg. 29(10)-(13); SI 2026/621, reg. 15
A relevant person must separately assess proliferation-financing risk and maintain proportionate senior-approved policies, controls and procedures.
- Action d’implémentation
- Map sanctions-evasion and proliferation exposure across ownership, trade, payments, geography and technology; connect risks to preventive controls.
- Preuves à conserver
- PF risk assessment, senior approval, scenario inventory, sanctions mapping, tests and remediation log.
- Source primaire
- MLRs, regs. 18A and 19A
AML/CFT policies must cover risk management, internal controls, CDD, reliance, records, compliance monitoring, unusual activity and new technology.
- Action d’implémentation
- Maintain a control inventory mapped to regulations 19-20, assign owners, test design and operation, and communicate changes across relevant branches.
- Preuves à conserver
- Policy set, control matrix, board minutes, testing results, issues, training and branch attestations.
- Source primaire
- MLRs, regs. 19-20
03Natural-person identification and verificationCDD triggers and evidence strength depend on the relationship, transaction and risk. The 30 June 2026 sterling thresholds must not be confused with universal onboarding rules.5 éléments+
CDD applies when establishing a business relationship, on suspicion, when prior evidence is doubtful and at the prescribed occasional-transaction triggers.
- Action d’implémentation
- Build a trigger matrix covering the general GBP 12,000 threshold, funds transfers above GBP 800 and sector-specific cash, casino, art, letting and crypto triggers.
- Preuves à conserver
- Trigger matrix, workflow rules, linked-transaction logic, suspicion override, tests and exceptions.
- Source primaire
- MLRs, reg. 27 as amended by SI 2026/621, reg. 14
A relevant person must identify the customer, verify identity from reliable independent documents or information and assess the relationship's purpose and intended nature.
- Action d’implémentation
- Define risk-based evidence standards, validate authenticity and independence, and record purpose, expected activity and decision before activation.
- Preuves à conserver
- Identity evidence, source validation, customer profile, purpose record, timestamps and approval.
- Source primaire
- MLRs, reg. 28(2), (12)-(13) and (18)
Secure electronic identification can be a reliable independent source where it resists fraud and misuse and gives the assurance needed for the risk.
- Action d’implémentation
- Assess digital identity assurance, fraud controls, accessibility, exception handling and evidence retention; do not treat vendor output as automatically sufficient.
- Preuves à conserver
- Vendor assessment, certification or assurance evidence, test results, decision logs, exceptions and monitoring.
- Source primaire
- MLRs, reg. 28(19); HM Treasury, Using digital identities with the MLRs
A person purporting to act for a customer must be authorized, identified and independently verified.
- Action d’implémentation
- Validate the mandate and signatory powers, identify and verify the representative, and connect every instruction to current authority.
- Preuves à conserver
- Mandate, board authority, power of attorney, representative KYC, validation log and instruction record.
- Source primaire
- MLRs, reg. 28(10)
If required CDD cannot be completed, do not open the relationship or transact, terminate an existing relationship and consider a POCA or Terrorism Act disclosure, subject to regulation 31's express exceptions.
- Action d’implémentation
- Block activation and transactions, escalate termination and repayment, document any privilege or insolvency exception and record the SAR and consent assessment.
- Preuves à conserver
- CDD failure, restrictions, termination or repayment record, exception analysis, SAR decision and approvals.
- Source primaire
- MLRs, reg. 31
04KYB, beneficial ownership and Companies HouseKeep MLR beneficial-owner CDD, register-discrepancy reporting and the company's own PSC and identity-verification duties distinct. A Companies House record is not sufficient by itself for MLR beneficial-owner verification.4 éléments+
Corporate CDD requires verified registered details and reasonable measures on governing law, constitution, directors or senior managers, ownership and control.
- Action d’implémentation
- Obtain current registry and constitutional material, verify status and address, map directors and senior operators, and understand every ownership layer.
- Preuves à conserver
- Companies House extract, constitutional documents, status check, director list, ownership chart and verification log.
- Source primaire
- MLRs, reg. 28(3)-(5)
A body corporate's beneficial owners include individuals with ultimate management control, more than 25% of shares or voting rights, or other control; partnerships and trusts use separate tests.
- Action d’implémentation
- Trace direct and indirect interests, voting arrangements and control to natural persons; apply regulations 5 and 6 by entity type.
- Preuves à conserver
- Ownership calculations, control analysis, trust or partnership parties, source documents and reviewer approval.
- Source primaire
- MLRs, regs. 5-6
Only after exhausting all possible means may a relevant person treat the responsible senior manager as the body corporate's beneficial owner, with written records of actions and difficulties.
- Action d’implémentation
- Escalate unresolved ownership, document every search and inconsistency, verify the senior manager and decide whether risk or failed-CDD rules prevent onboarding.
- Preuves à conserver
- Exhaustion log, source searches, escalation, senior-manager verification, risk decision and approval.
- Source primaire
- MLRs, reg. 28(6)-(9) and 31
Before onboarding and at relevant later CDD or monitoring for a regulation 30A customer, collect the prescribed register excerpt and report any Schedule 3AZA material discrepancy through the specified registrar or HMRC route.
- Action d’implémentation
- Compare register and CDD evidence, classify materiality, resolve false positives, submit through the correct route and retain the report.
- Preuves à conserver
- Register excerpt, comparison, discrepancy analysis, submission, acknowledgement and resolution.
- Source primaire
- MLRs, reg. 30A and Sch. 3AZA
05PEPs, EDD, source of wealth and remote onboardingEDD applies to prescribed cases and other high-risk situations. Domestic PEP status is treated as lower risk absent other enhanced risk factors, but it still requires the regulation 35 process.4 éléments+
EDD and enhanced monitoring are required in regulation 33 cases, including a FATF call-for-action-country relationship or transaction and any other situation presenting higher ML or TF risk.
- Action d’implémentation
- Configure mandatory triggers and a documented high-risk methodology; do not automatically equate the FATF increased-monitoring list with the regulation 33 country trigger.
- Preuves à conserver
- EDD rules, FATF list version, risk decision, enhanced checks, approvals and monitoring plan.
- Source primaire
- MLRs, reg. 33 as amended by SI 2026/621, reg. 19
When establishing or continuing a relationship with a PEP, family member or close associate, including an entity beneficially owned by the PEP, obtain senior approval, establish source of wealth and funds, and conduct enhanced monitoring.
- Action d’implémentation
- Screen customers and beneficial owners, adjudicate matches, corroborate wealth and funds, approve the relationship and apply separate risk and EDD rules to other PEP transactions.
- Preuves à conserver
- Screening result, relationship analysis, wealth narrative, funds evidence, senior approval, alerts and reviews.
- Source primaire
- MLRs, regs. 33 and 35(1)-(5), (13)
Domestic PEPs, their family members and known close associates are presumed lower risk than non-domestic PEPs unless other enhanced risk factors exist.
- Action d’implémentation
- Apply the PEP controls proportionately, document additional risk factors and avoid either automatic rejection or unjustified simplified treatment.
- Preuves à conserver
- Domestic-status proof, risk assessment, factor analysis, measures, approval and review schedule.
- Source primaire
- MLRs, reg. 35(3A) and (12)
Remote onboarding, anonymity-favouring products and new technology require risk assessment and, where higher risk exists, enhanced measures.
- Action d’implémentation
- Test document and person match, fraud and impersonation risk, device and network signals, accessibility, manual escalation and vendor performance.
- Preuves à conserver
- Remote-risk assessment, liveness or match tests, device data, exception files, vendor assurance and sampled outcomes.
- Source primaire
- MLRs, regs. 19(4), 28(19), 33 and 35; HM Treasury digital-identity guidance
06Monitoring, suspicious activity and confidentialityThe MLRs create monitoring and internal-control duties; POCA and the Terrorism Act create role-specific disclosure offences. Case records must show when the statutory knowledge or suspicion test arose and why disclosure was timely.4 éléments+
Ongoing monitoring includes scrutiny of transactions, source of funds where necessary, and reviews that keep CDD documents and information current.
- Action d’implémentation
- Calibrate monitoring to expected activity and risk, investigate linked behaviour, refresh CDD on change and record filing and non-filing decisions.
- Preuves à conserver
- Scenario inventory, expected-activity profile, alerts, investigation notes, refresh history and dispositions.
- Source primaire
- MLRs, reg. 28(11)-(13)
A regulated-sector employee or nominated officer must make the applicable disclosure when role-specific conditions are met and information concerns a person engaged in, or attempting, money laundering or terrorist financing.
- Action d’implémentation
- Escalate completed and attempted activity through the nominated officer and UKFIU/NCA routes, preserving privilege and reasonable-excuse analysis.
- Preuves à conserver
- Attempted or completed activity, internal report, nominated-officer assessment, legal analysis, SAR reference and acknowledgement.
- Source primaire
- POCA, ss. 330-332 and 338; Terrorism Act 2000, ss. 19 and 21A; NCA SAR guidance
A required disclosure is made as soon as practicable; there is no general monetary threshold or universal fixed-day SAR deadline.
- Action d’implémentation
- Timestamp receipt, investigation, threshold formation, internal escalation and UKFIU submission; use the current SAR Portal and document unavoidable delay.
- Preuves à conserver
- Case chronology, evidence reviewed, suspicion rationale, portal submission, receipt and delay explanation.
- Source primaire
- POCA, ss. 330-332; NCA, Suspicious Activity Reports
Tipping-off and prejudicing-investigation offences apply when their statutory conditions are met, subject to defined disclosures and other exceptions.
- Action d’implémentation
- Restrict case information, train staff, review customer communications and CDD continuation, and obtain legal approval for sensitive disclosures.
- Preuves à conserver
- Access logs, communication review, training, legal decision, exception analysis and incident record.
- Source primaire
- POCA, ss. 333A-333D and 342; Terrorism Act 2000, ss. 21D-21G and 39; MLRs, reg. 28(14)-(15)
07Payments, cash triggers and transfer informationThe UK does not impose one universal transaction report. CDD thresholds, payment-transfer information and cryptoasset travel-rule duties must be configured separately.4 éléments+
From 30 June 2026, general occasional transactions of GBP 12,000 or more and funds transfers exceeding GBP 800 trigger CDD, subject to sector-specific rules and linked operations.
- Action d’implémentation
- Configure each threshold, currency conversion, linked-transaction detection, sector exception and suspicion override without treating it as a reporting threshold.
- Preuves à conserver
- Rules specification, effective-date control, conversion source, test cases, alerts and CDD files.
- Source primaire
- MLRs, reg. 27(1)-(2); SI 2026/621, reg. 14
A high-value dealer's GBP 10,000 cash transaction is an MLR scope and CDD trigger, including linked operations; it is not a standalone universal cash report.
- Action d’implémentation
- Identify qualifying goods activity and cash paid directly, indirectly or into an account for the seller's benefit; apply CDD before proceeding.
- Preuves à conserver
- HVD perimeter analysis, cash aggregation, payer and beneficiary records, CDD and transaction decision.
- Source primaire
- MLRs, regs. 14 and 27(3)-(4)
Payment service providers must carry prescribed payer and payee information, detect missing data and respond to competent-authority enquiries under the retained funds-transfer framework.
- Action d’implémentation
- Map originator, beneficiary and intermediary roles, mandatory fields, rejection or follow-up rules, sanctions screening and rapid retrieval.
- Preuves à conserver
- Message-field mapping, validation tests, exception queue, follow-up records, screening and retrieval exercise.
- Source primaire
- MLRs, Part 7; retained Regulation (EU) 2015/847
Cryptoasset businesses must apply the UK travel rule, including prescribed originator and beneficiary information and the GBP 800 threshold for additional information in specified transfers.
- Action d’implémentation
- Classify inter-business and unhosted-wallet transfers, collect and verify required data, manage missing information and report repeated failures to the FCA where required.
- Preuves à conserver
- Travel-rule design, counterparty assessment, transfer messages, requests, decisions, FCA reports and records.
- Source primaire
- MLRs, regs. 64B-64G as amended by SI 2026/621, regs. 32-33
08Targeted financial sanctions and asset freezesUK sanctions are programme-specific. The UK Sanctions List supports detection, while the operative regulation determines designation effect, ownership and control, prohibitions, freezes, exceptions, licences and reports.4 éléments+
UK persons worldwide and persons within UK territory must comply with applicable sanctions prohibitions under programme regulations made under SAMLA.
- Action d’implémentation
- Map persons, ownership and control, products, counterparties, vessels, geography and conduct to every applicable programme before execution.
- Preuves à conserver
- Sanctions perimeter, programme inventory, legal analysis, screening logs, ownership review and decision.
- Source primaire
- SAMLA 2018; OFSI, Financial sanctions general guidance
Since 28 January 2026 the UK Sanctions List is the only current source for all UK sanctions designations; the former OFSI Consolidated List is closed.
- Action d’implémentation
- Screen against current UK Sanctions List data, monitor updates and remove any production dependency on the closed consolidated list.
- Preuves à conserver
- List source, version and timestamp, update alerts, screening tests, migration record and quality checks.
- Source primaire
- FCDO, The UK Sanctions List; OFSI general guidance
Asset-freeze prohibitions can extend to entities owned or controlled by a designated person even if the entity is not separately named.
- Action d’implémentation
- Investigate direct and indirect ownership and control, joint arrangements and practical control; freeze or reject as the operative rule requires.
- Preuves à conserver
- Ownership chart, control evidence, legal conclusion, freeze or rejection, approvals and audit trail.
- Source primaire
- OFSI, Financial sanctions general guidance, ownership and control
A relevant firm must inform OFSI as soon as practicable when the applicable programme's knowledge or reasonable-cause reporting trigger is met and must report frozen assets as required.
- Action d’implémentation
- Escalate potential breaches and designated-person assets immediately, preserve funds, use the current OFSI route and assess separate UKFIU disclosure duties.
- Preuves à conserver
- Case chronology, asset record, freeze, OFSI report, licence or exception analysis, SAR assessment and acknowledgements.
- Source primaire
- Applicable sanctions programme regulations; OFSI, Financial sanctions general guidance, reporting obligations
09Records, reliance and regulator accessFive years is the core MLR period, but its starting event and limited longer-retention rules differ. Outsourcing and reliance do not transfer legal accountability.5 éléments+
CDD, discrepancy, transfer-information and transaction-reconstruction records must generally be kept five years from the relevant transaction completion or end of business relationship.
- Action d’implémentation
- Map every record class to its exact trigger, retain reconstructable evidence and prevent early deletion across primary and backup systems.
- Preuves à conserver
- Retention schedule, trigger dates, system configuration, legal holds, samples and deletion certificates.
- Source primaire
- MLRs, reg. 40(1)-(4)
A pooled-account customer must provide underlying-person and beneficial-owner identities on request and keep accurate, up-to-date written records of all monies paid in and out for five years from when each payment is known or reasonably believed complete.
- Action d’implémentation
- Require the customer to provide law-enforcement information about itself and account management and use on request; preserve regulation 29 privilege and confidentiality treatment.
- Preuves à conserver
- Information requests, ownership data, payment ledger, per-payment retention clocks, authority responses and privilege record.
- Source primaire
- MLRs, reg. 29(14)-(18); SI 2026/621, reg. 15
After the applicable period, MLR personal data must be deleted unless another enactment, court proceedings, data-subject consent or reasonable legal-proceeding need supports retention.
- Action d’implémentation
- Run defensible deletion and exception review, record the legal basis for any extension and prevent indefinite AML-purpose retention.
- Preuves à conserver
- Deletion workflow, exception register, consent or legal basis, approvals, logs and verification tests.
- Source primaire
- MLRs, reg. 40(5)
Reliance on a qualifying third party does not remove the relevant person's liability and requires immediate information plus arrangements for prompt document copies.
- Action d’implémentation
- Confirm third-party eligibility, obtain the required CDD data immediately, test document retrieval and prohibit reliance in a FATF call-for-action country unless the group exception applies.
- Preuves à conserver
- Reliance assessment, agreement, data receipt, retrieval test, country check, monitoring and exit plan.
- Source primaire
- MLRs, reg. 39
Using an agent or outsourcing provider does not transfer liability for CDD or register-discrepancy measures.
- Action d’implémentation
- Contract for duties, access, security, audit, incident escalation and exit; test identity, screening, monitoring, reporting and retrieval end to end.
- Preuves à conserver
- Responsibility matrix, contract, vendor diligence, control tests, incidents, remediation and exit package.
- Source primaire
- MLRs, reg. 39(7)-(8)
10Privacy, biometrics, breaches and transfersKYC necessity does not displace UK data-protection duties. Resolve controller and processor roles, lawful basis, special-category conditions, transparency, minimization and retention for each data use.5 éléments+
UK GDPR principles and lawful-basis requirements apply to in-scope KYC data; from 19 June 2026 controllers must also facilitate complaints, acknowledge them within 30 days and respond without undue delay.
- Action d’implémentation
- Map each data purpose, lawful basis, notice, recipient, access and retention; operate the DUAA complaint channel, investigation and outcome process.
- Preuves à conserver
- Record of processing, lawful-basis register, privacy notice, data map, complaint log, acknowledgements and outcomes.
- Source primaire
- UK GDPR, arts. 5-6; DPA 2018; DUAA 2025, s. 103; ICO DUAA summary
Biometric data used to uniquely identify a person is special-category data and requires both an Article 6 lawful basis and an Article 9 condition.
- Action d’implémentation
- Document necessity, proportionality and the special-category condition; minimize templates, separate uses, test accuracy and bias, and provide a non-biometric route where appropriate.
- Preuves à conserver
- Lawful-basis analysis, Article 9 condition, biometric design, accuracy and bias tests, vendor terms and deletion proof.
- Source primaire
- UK GDPR, arts. 4(14), 6 and 9; DPA 2018; ICO biometric guidance
A DPIA is required before processing likely to result in high risk, including specified large-scale sensitive processing and biometric combinations.
- Action d’implémentation
- Screen every identity and monitoring design early, complete and approve the DPIA where required, mitigate risks and consult the ICO if high residual risk remains.
- Preuves à conserver
- Screening record, DPIA, necessity test, mitigations, DPO advice, approval and consultation record.
- Source primaire
- UK GDPR, art. 35; ICO, Data protection impact assessments
Notify a reportable personal-data breach to the ICO without undue delay and, where feasible, within 72 hours; notify affected people without undue delay when high risk exists and document every breach.
- Action d’implémentation
- Start the clock on awareness, contain and assess risk, submit available facts within 72 hours, supplement promptly and preserve the full decision record.
- Preuves à conserver
- Incident chronology, risk assessment, ICO report, affected-person notice, follow-up and breach register.
- Source primaire
- UK GDPR, arts. 33-34; ICO, Personal data breaches guide
A restricted international transfer requires an applicable UK adequacy regulation, safeguard or Article 49 exception in addition to ordinary UK GDPR compliance.
- Action d’implémentation
- Map destinations and onward transfers, select and document the route, complete transfer-risk work where required, and contract for security, rights and exit.
- Preuves à conserver
- Transfer map, adequacy or safeguard record, risk assessment, contract, supplementary measures and review.
- Source primaire
- UK GDPR, arts. 44-49; ICO, Guide to international transfers
11Payments, agents and practical evidence packsTurn the perimeter and legal controls into testable launch gates. Payment, e-money, cryptoasset, Companies House and MLR statuses overlap but are not substitutes for one another.5 éléments+
Covered payment and e-money firms must safeguard relevant funds under the PSRs or EMRs and the FCA supplementary regime effective 7 May 2026.
- Action d’implémentation
- Apply CASS 10A and 15 and SUP 3A and 16 as relevant, identify and segregate funds, reconcile, maintain the resolution pack and submit required returns.
- Preuves à conserver
- Safeguarding analysis, account documents, reconciliations, discrepancy log, resolution pack, audit and returns.
- Source primaire
- PSRs 2017, reg. 23; EMRs 2011, reg. 20; FCA PS25/12 and safeguarding guidance
A payment institution remains responsible for acts and omissions of agents and must register agents before they provide services; e-money distributors and agents have separate rules.
- Action d’implémentation
- Perform due diligence, submit required FCA information, verify register status, contract for controls and supervise conduct, AML, complaints and safeguarding.
- Preuves à conserver
- Agent assessment, FCA submission, register extract, contract, monitoring, complaints and termination plan.
- Source primaire
- PSRs 2017, regs. 34-36; EMRs 2011, regs. 33-36
An ACSP verifying identity for Companies House must be supervised for UK AML compliance, meet the verification standard and keep verification records for seven years.
- Action d’implémentation
- Keep ACSP verification separate from MLR CDD, capture the evidence and prescribed statement, protect the personal code and calendar seven-year retention.
- Preuves à conserver
- ACSP registration, supervision proof, verification record, Companies House submission, access controls and retention schedule.
- Source primaire
- Companies House, Tell Companies House you have verified someone's identity
Companies must identify and report PSCs, and mandatory identity verification applies to new directors and PSCs from 18 November 2025 with role-specific transition deadlines for existing persons.
- Action d’implémentation
- Apply all five PSC conditions, file changes, capture each personal-code deadline, and distinguish Companies House verification from the business's own MLR CDD.
- Preuves à conserver
- PSC analysis, filings, confirmation statement, personal-code evidence, deadline calendar and reconciliation to CDD.
- Source primaire
- Companies Act 2006, Part 21A and Sch. 1A; Companies House PSC and identity-verification guidance
Each checklist row requires a documented applicability decision, current source, control owner and reconstructable operating evidence before launch.
- Action d’implémentation
- Mark every row applicable, not applicable or pending counsel confirmation; close blockers and obtain compliance, legal, privacy, security and product approval.
- Preuves à conserver
- Completed checklist, rationale, source snapshot, owner sign-off, test result, gap ticket and launch approval.
- Source primaire
- MLRs, regs. 18-21, 24 and 28
Registre des sources primaires
39 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017UK Legislation · Primary regulation
- Money Laundering and Terrorist Financing Amendment Regulations 2026UK Legislation · Primary regulation
- June 2026 money laundering advisory noticeHM Treasury · Official government notice
- HMRC anti-money laundering guidance for supervised businessesHM Revenue & Customs · Official supervisor guidance
- Using digital identities with the Money Laundering RegulationsHM Treasury and DSIT · Official government guidance
- Proceeds of Crime Act 2002UK Legislation · Primary legislation
- Terrorism Act 2000UK Legislation · Primary legislation
- Suspicious Activity ReportsNational Crime Agency · Official FIU guidance
- Companies Act 2006UK Legislation · Primary legislation
- Economic Crime and Corporate Transparency Act 2023UK Legislation · Primary legislation
- People with significant controlCompanies House · Official registry guidance
- 2026 statutory guidance on significant influence or controlCompanies House · Statutory guidance
- Identity verification for Companies HouseCompanies House · Official registry guidance
- Tell Companies House you have verified someone's identityCompanies House · Official registry guidance
- Changes to reporting material discrepancies to Companies HouseCompanies House · Official registry guidance
- Sanctions and Anti-Money Laundering Act 2018UK Legislation · Primary legislation
- The UK Sanctions ListForeign, Commonwealth & Development Office · Official sanctions list
- Current UK sanctions regimesForeign, Commonwealth & Development Office · Official government guidance
- Financial sanctions general guidanceOffice of Financial Sanctions Implementation · Official regulator guidance
- Report a suspected breach of financial sanctionsOffice of Financial Sanctions Implementation · Official reporting guidance
- Data Protection Act 2018UK Legislation · Primary legislation
- UK General Data Protection RegulationUK Legislation · Retained law
- Data Use and Access Act 2025UK Legislation · Primary legislation
- DUAA summary of data-protection changesInformation Commissioner's Office · Official regulator guidance
- Biometric recognition guidanceInformation Commissioner's Office · Official regulator guidance
- When a data protection impact assessment is requiredInformation Commissioner's Office · Official regulator guidance
- Personal data breaches guideInformation Commissioner's Office · Official regulator guidance
- New data-protection complaints lawInformation Commissioner's Office · Official regulator guidance
- Guide to international transfersInformation Commissioner's Office · Official regulator guidance
- Payment Services Regulations 2017UK Legislation · Primary regulation
- Information accompanying transfers of fundsUK Legislation · Retained law
- Electronic Money Regulations 2011UK Legislation · Primary regulation
- Payment services and electronic money regulationFinancial Conduct Authority · Official regulator guidance
- Safeguarding requirements for payment and e-money institutionsFinancial Conduct Authority · Official regulator guidance
- PS25/12 changes to the safeguarding regimeFinancial Conduct Authority · Official regulator policy
- Cryptoassets AML and CTF regimeFinancial Conduct Authority · Official regulator guidance
- Cryptoasset registration ahead of the new FSMA regimeFinancial Conduct Authority · Official regulator guidance
- FATF United Kingdom country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
Réponses directes
Questions KYC, KYB et AML pour Royaume-Uni
Does every UK business have to follow the Money Laundering Regulations?+
No. Regulation 8 and the detailed sector definitions and exclusions determine relevant-person status. Resolve each entity and activity and its supervisor before applying a control as mandatory.
When must a UK suspicious activity report be made?+
Where a POCA or Terrorism Act disclosure duty applies, make the disclosure as soon as practicable after the relevant knowledge, suspicion or reasonable grounds arise. There is no general monetary threshold or universal fixed-day deadline.
Does the UK have a universal cash transaction report?+
No. For high-value dealers, GBP 10,000 or more in cash is an MLR scope and CDD trigger, including linked transactions. It is not a universal threshold report for all businesses.
What is the UK AML beneficial-ownership threshold?+
For a body corporate, the MLR definition includes more than 25% of shares or voting rights, ultimate control over management or other control. Partnerships and trusts have tailored tests, and ownership and control structure must be understood.
Can Companies House data alone verify a beneficial owner?+
No. MLR regulation 28 says relevant persons do not satisfy beneficial-owner duties by relying solely on information delivered to the registrar. Use current registry data as one input and corroborate it.
Who must verify identity for Companies House?+
Mandatory verification began on 18 November 2025 for new directors and PSCs. Existing directors and PSCs are in a 12-month transition with deadlines depending on confirmation-statement timing, role and registered birth month.
What is the core MLR record-retention period?+
Generally five years from completion of the occasional transaction or end of the business relationship, depending on the record. Some relationship transaction records can be retained up to ten years, and personal data must then be deleted unless an exception applies.
Which UK sanctions list should a business use?+
Use the UK Sanctions List. Since 28 January 2026 it is the only current source for all UK sanctions designations; the former OFSI Consolidated List is closed and no longer updated.
Must a UK cryptoasset business register with the FCA?+
An in-scope cryptoasset exchange provider or custodian wallet provider carrying on business in the UK must register under the MLRs before starting. That registration is not an FCA endorsement or full FSMA authorization.
Is the United Kingdom on a FATF public list?+
The United Kingdom was not named on FATF's current public lists reviewed on 31 July 2026. It remains a FATF member with published mutual-evaluation and follow-up history.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice, an authorization decision or a statement that every row applies to every UK business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity, activity, customer, transaction, legal form, UK nation, MLR supervisor, FCA permission, Companies House transition date, sanctions programme, privacy role, live reporting channel and later legal developments with qualified UK counsel and the competent authorities before launch.