UK AML Regulations: The Money Laundering Regulations 2017 Explained

UK AML Regulations: The Money Laundering Regulations 2017 Explained

The United Kingdom implements its anti-money-laundering and counter-terrorist-financing obligations through The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), commonly known as the MLR 2017. Since Brexit the UK has kept a largely equivalent framework, so the core concepts will be familiar to anyone who knows the EU rules.

The purpose is the same: prevent the financial system from being used for money laundering and terrorist financing by placing duties on financial institutions and on a wide set of other businesses.

A financial compliance team reviewing AML documentation in a UK office
A financial compliance team reviewing AML documentation in a UK office

Who is in scope

The MLR 2017 apply to a broad list of sectors, including:

  • banks, building societies and other credit institutions
  • financial institutions, money remittance and currency exchange businesses
  • auditors, insolvency practitioners, external accountants and tax advisers
  • independent legal professionals
  • trust or company service providers
  • estate agents and letting agents
  • high value dealers
  • casinos and gambling operators
  • crypto-asset businesses
  • art market participants

The regulated activities include lending and credit, financial leasing, payment services, issuing and administering means of payment, guarantees, trading in money market instruments and foreign exchange, securities services, portfolio management, safekeeping, and issuing electronic money.

A regulator's office building, symbolising FCA and HMRC supervision
A regulator’s office building, symbolising FCA and HMRC supervision

Core obligations

Firms in scope must:

Supervision and enforcement

Supervision is split across several bodies: the Financial Conduct Authority, HMRC, the Gambling Commission, and, for the legal and accountancy professions, self-regulatory bodies overseen by OPBAS. Enforcement can be criminal or civil, with unlimited fines for the most serious breaches.

Sanctions are separate

Economic sanctions are not part of the MLR 2017. In the UK they are implemented by OFSI under the sanctions legislation, and firms must screen against the UK sanctions list, which recently moved to a single consolidated list.

AML and data protection overlap

Where AML processing involves personal data, the UK GDPR and the Data Protection Act 2018 apply, supervised by the Information Commissioner’s Office. Screening must therefore respect purpose limitation, minimisation and accountability.

Screening in practice

Keeping customer data current, re-screening against sanctions and PEP lists, and producing an audit trail are the day-to-day tasks. A platform such as Hyperflow provides screening and company monitoring through an API, which makes these checks repeatable and auditable.

Related reading