UK AML Regulations: The Money Laundering Regulations 2017 Explained
The United Kingdom implements its anti-money-laundering and counter-terrorist-financing obligations through The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), commonly known as the MLR 2017. Since Brexit the UK has kept a largely equivalent framework, so the core concepts will be familiar to anyone who knows the EU rules.
The purpose is the same: prevent the financial system from being used for money laundering and terrorist financing by placing duties on financial institutions and on a wide set of other businesses.

Who is in scope
The MLR 2017 apply to a broad list of sectors, including:
- banks, building societies and other credit institutions
- financial institutions, money remittance and currency exchange businesses
- auditors, insolvency practitioners, external accountants and tax advisers
- independent legal professionals
- trust or company service providers
- estate agents and letting agents
- high value dealers
- casinos and gambling operators
- crypto-asset businesses
- art market participants
The regulated activities include lending and credit, financial leasing, payment services, issuing and administering means of payment, guarantees, trading in money market instruments and foreign exchange, securities services, portfolio management, safekeeping, and issuing electronic money.

Core obligations
Firms in scope must:
- carry out a business-wide risk assessment and keep it up to date
- apply customer due diligence (CDD) before establishing a relationship, and enhanced due diligence for higher-risk cases, including politically exposed persons
- apply ongoing monitoring of the relationship
- keep records for the required period
- appoint a Money Laundering Reporting Officer and train staff
- file suspicious activity reports (SARs) to the National Crime Agency
Supervision and enforcement
Supervision is split across several bodies: the Financial Conduct Authority, HMRC, the Gambling Commission, and, for the legal and accountancy professions, self-regulatory bodies overseen by OPBAS. Enforcement can be criminal or civil, with unlimited fines for the most serious breaches.
Sanctions are separate
Economic sanctions are not part of the MLR 2017. In the UK they are implemented by OFSI under the sanctions legislation, and firms must screen against the UK sanctions list, which recently moved to a single consolidated list.
AML and data protection overlap
Where AML processing involves personal data, the UK GDPR and the Data Protection Act 2018 apply, supervised by the Information Commissioner’s Office. Screening must therefore respect purpose limitation, minimisation and accountability.
Screening in practice
Keeping customer data current, re-screening against sanctions and PEP lists, and producing an audit trail are the day-to-day tasks. A platform such as Hyperflow provides screening and company monitoring through an API, which makes these checks repeatable and auditable.