The RoadmapSetupWriting Contracts and Policies

Compliance with Anti-Money Laundering Policies

A complete guide to UK small business compliance with anti-money laundering (AML) laws, obligations, and best practices

9 minute read
Setup — Writing Contracts and Policies
✓ Verified against GOV.UK
Claire Henderson
Written by Claire Henderson
Finance & Tax Editor · GuideToBusiness
Back to Setup

If your small business handles money, deals with clients, or provides professional services, you may be subject to UK anti-money laundering (AML) laws. Non-compliance risks severe fines, criminal charges, and loss of business reputation. This guide demystifies AML compliance for UK small businesses, explaining who’s affected, what’s required, how to implement practical policies, and how to avoid common pitfalls. By the end, you’ll know exactly what steps to take to protect your business and stay on the right side of the law.

Understanding UK Anti-Money Laundering Laws and Who They Apply To

The UK's anti-money laundering (AML) regime is among the world’s most robust, governed by laws like the Proceeds of Crime Act 2002 (POCA), the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (as amended), and enforced by HMRC, the Financial Conduct Authority (FCA), and other regulators. These laws are designed to prevent the use of legitimate businesses to disguise criminal proceeds or fund terrorism. Small businesses must recognise that these regulations are not just for banks—many sectors are covered.

If you run an accountancy firm, estate agency, law practice, trust or company service provider, high-value dealer (handling cash transactions of €10,000 or more), or an art market participant (handling transactions of €10,000 or more), you are likely covered by AML regulations. Even some fintech, cryptocurrency, and letting agent businesses fall within the AML scope. The breadth of coverage surprises many small business owners.

UK AML obligations kick in not only for regulated sectors but also for businesses that inadvertently handle suspicious funds or fail to report suspicious activity. Even if you believe your sector is 'low risk', failing to check your obligations could leave you exposed to criminal liability and business-ending fines. Always check HMRC’s sector guidance or consult a legal adviser if unsure.

Does AML apply to my business?

Visit GOV.UK’s official AML supervision checker or consult your trade association for tailored guidance. If in doubt, err on the side of caution—failing to register or comply can have severe consequences even for small businesses.

  • Accountants, tax advisers, and bookkeepers
  • Estate agents and letting agents
  • Law firms and notaries
  • Trust or company service providers
  • High-value dealers (accepting/receiving €10,000+ cash)
  • Art market participants (dealers, galleries, auctioneers)
  • Cryptoasset exchange and custodian wallet providers

If your business falls into any of these categories, you must register with your supervising authority (often HMRC or your professional body) and implement robust AML policies. Even if you do not directly fall under these regulations, consider adopting some AML practices if you deal with high-risk clients or transactions.

Core AML Obligations for UK Small Businesses

There are several core obligations every relevant UK business must fulfil under AML regulations. These include business registration with a supervisory authority, risk assessment, customer due diligence (CDD), ongoing monitoring, record keeping, and reporting of suspicious activity. Each stage is crucial for demonstrating your compliance in the event of audit or investigation.

Registering with your sector’s supervisory authority is non-negotiable. For example, estate agents, accountants, and high-value dealers often register with HMRC, while solicitors might be supervised by the Solicitors Regulation Authority (SRA). Registration is not a one-off process; you must renew and update your details, paying annual fees and submitting to inspections.

Businesses must conduct a written risk assessment, tailored to their operations, clients, geography, and delivery channels. This risk assessment is the foundation for all further AML activity, as it helps determine the level of scrutiny applied to different clients and transactions. Failure to conduct or update this assessment is a common reason for fines.

  • Register with your AML supervisory authority (check GOV.UK for your sector)
  • Write and regularly update a risk assessment
  • Apply customer due diligence (CDD) to all clients
  • Monitor business relationships and transactions
  • Keep records of checks and decisions for at least five years
  • Report suspicious activity to the National Crime Agency (NCA)

Customer due diligence is not just an initial hurdle. You must verify identity, understand the purpose of the business relationship, and—where relevant—identify the beneficial owner. For high-risk clients (such as those from high-risk countries or with complex structures), enhanced due diligence (EDD) is required, involving deeper checks and possibly senior management approval.

Report any suspicion of money laundering or terrorist financing to the National Crime Agency (NCA) via a Suspicious Activity Report (SAR). Failing to report is a criminal offence, even if the transaction never takes place. All staff must know how and when to submit a SAR, and these procedures must be documented in your AML policies.

Common compliance failures

Many UK small businesses are fined for poor documentation, out-of-date risk assessments, or inadequate CDD. HMRC inspectors look for evidence of written policies and records—even if you 'know your clients well'.

Building and Implementing an Effective AML Policy

Your AML policy is the backbone of your compliance programme. It must be tailored to your business’s size, sector, and risk profile—not a generic template. The policy should detail procedures for client onboarding, risk assessment, customer due diligence, transaction monitoring, suspicious activity reporting, staff training, and record keeping. Regular review and board (or senior manager) approval are essential.

Start by mapping your client journey and identifying points where money laundering risks arise. Your policy should spell out exactly how staff are to verify identity (including acceptable documents), what red flags to watch for, and how to escalate concerns. Specify who is responsible for oversight—usually a nominated officer or Money Laundering Reporting Officer (MLRO).

Staff must receive regular AML training appropriate to their role and sector exposure. Training should cover your business’s specific risks, legal obligations, and real-world scenarios. Document all training activity—HMRC and other regulators will ask for evidence.

Implementing Effective AML Compliance in Your UK Business

1
Draft a sector-specific AML policy
Write your policy to address your business’s unique risks, referencing official guidance for your sector (e.g., HMRC, Law Society, ICAEW).
2
Assign responsibility for AML compliance
Designate a Money Laundering Reporting Officer (MLRO) or responsible senior manager to oversee implementation, monitoring, and reporting.
3
Set procedures for risk assessment and due diligence
Include step-by-step instructions for client onboarding, verification, ongoing monitoring, and escalation of high-risk cases.
4
Roll out staff training and awareness
Ensure all relevant staff are trained on your policy, AML law, and practical red flags. Update training at least annually.
5
Test and review your AML controls
Regularly audit your own compliance—spot-check files, simulate SAR reporting, and update your policy in response to any gaps or regulatory changes.

It’s vital that your AML policy is a living document. Review it at least annually, or after any significant change in your business, client base, or the law. Keep evidence of reviews, updates, and approvals. Regulators expect to see a clear audit trail and evidence of senior management involvement.

Use sector-specific guidance

Most UK professional bodies publish detailed AML guidance and sample policies tailored to their members. Start with these, but always personalise to your business.

  • Base your policy on your written risk assessment
  • Specify client verification procedures and acceptable documents
  • Detail enhanced checks for high-risk clients and transactions
  • Include clear SAR reporting and escalation steps
  • Document staff training and regular policy reviews

Don’t rely on outdated or overseas templates. UK AML laws and enforcement are unique. Regulators will penalise 'tick box' approaches that show no evidence of real risk-based thinking.

Customer Due Diligence: What You Must Do and How to Get It Right

Customer due diligence (CDD) is the cornerstone of AML compliance. It means verifying your client’s identity, understanding the nature and purpose of the business relationship, and identifying the ultimate beneficial owner (UBO) if the client is a company or trust. The checks you apply must be risk-based—more thorough for higher-risk clients and transactions.

CDD must be applied before establishing a business relationship or carrying out an occasional transaction worth €10,000 or more. For ongoing clients, you must monitor transactions and update CDD if circumstances change (e.g., new directors, unusual activity, or adverse media reports). Skipping or delaying CDD because you 'know the client' or are 'in a rush' is a major compliance failure.

You can verify identity with official documents: UK passport, driving licence, or government-issued ID, plus proof of address (utility bill, bank statement, council tax). For corporate clients, obtain company registration details from Companies House and identify individuals with significant control (PSCs). For trusts, identify all trustees and beneficiaries.

Enhanced Due Diligence (EDD)

EDD applies to clients from high-risk countries, PEPs (politically exposed persons), or those with complex ownership structures. This may involve source-of-funds checks, additional documentation, and senior management approval.

  • Verify individual clients with original government ID and proof of address
  • Check company clients on Companies House and identify beneficial owners
  • Apply EDD for high-risk clients or complex cases
  • Re-assess CDD if client circumstances or risk profile changes
  • Keep written records of all checks and decisions

Don’t just file copies of documents—record the steps you took, who performed the checks, and any queries or red flags. Regulators are looking for an evidence-based process, not just paperwork. Keep everything securely for at least five years after the end of the client relationship.

Common mistake: Incomplete checks for 'trusted' clients

Even longstanding clients must be subject to CDD. Many small firms are fined for not updating checks when a client’s circumstances change or for overlooking beneficial ownership in corporate structures.

Reporting Suspicious Activity and Record Keeping

If you suspect that a client or transaction involves money laundering or terrorist financing, you must file a Suspicious Activity Report (SAR) with the National Crime Agency (NCA) as soon as possible. This duty applies even if the transaction is never completed. Failing to report is a criminal offence under the Proceeds of Crime Act.

Your AML policy must include clear, practical instructions for reporting suspicions internally (to your MLRO or nominated officer) and externally (to the NCA). Staff should know how to recognise red flags—such as reluctance to provide ID, unusual transactions, or complicated payment routes—and how to escalate them without tipping off the client (which is also a criminal offence).

All AML records—risk assessments, CDD checks, policy documents, training logs, internal reports, and SARs—must be retained for at least five years. These records must be accessible and available for inspection by HMRC or your regulator. Digital filing is acceptable but must be secure and backed up.

  • Report suspicions to the NCA using the SAR Online system
  • Document the reason for suspicion and all supporting evidence
  • Do not inform the client that a SAR has been made ('tipping off' is illegal)
  • Keep SARs and related correspondence securely for five years
  • Review and update your reporting process regularly
SARs filed in the UK

Over 900,000 Suspicious Activity Reports were submitted to the NCA in 2022-23, with small firms making up a significant share. Many SARs are filed by non-financial businesses.

Make sure your staff understand the difference between a genuine suspicion and routine due diligence queries. Encourage a culture where concerns can be raised without fear of reprisal. Regulators will check that your SAR process is clear, used, and regularly tested.

Supervision, Inspections, and Penalties: What to Expect

Supervisory authorities in the UK actively monitor compliance. HMRC, the FCA, and sector regulators conduct inspections, desk-based reviews, and spot audits. Even small businesses and sole traders are subject to inspection, often at short notice. Inspectors will expect to see up-to-date registrations, written risk assessments, CDD records, SAR logs, training materials, and evidence of policy review.

Penalties for non-compliance are severe. HMRC fined over £3.2 million in 2022-23 for AML breaches, and the FCA has issued multi-million-pound fines for persistent failures. Even small businesses face fines running into tens of thousands of pounds, public naming, and potential criminal prosecution. Fines are often for poor documentation, inadequate CDD, or failing to register.

Supervisors also have the power to suspend or revoke your registration, effectively shutting down your business. Repeat offenders can be prosecuted under the Proceeds of Crime Act, risking jail time. The reputational damage can be catastrophic—clients, banks, and suppliers may sever ties with non-compliant firms.

Breach TypeTypical Penalty (2023)Common Causes
Failure to register£1,000 - £15,000+Not realising registration was required, late renewal
Inadequate CDD£2,000 - £20,000+Not verifying clients, missing beneficial owners
Poor record keeping£1,000 - £10,000+No written risk assessments or training records
Failure to file SARCriminal prosecutionNot recognising red flags, no reporting process
Tipping offCriminal prosecutionInforming client of SAR
You can be inspected at any time

HMRC and other regulators can inspect your premises, request documents, and interview staff with little or no notice. Preparation and up-to-date records are your best defence.

Preparation is key. Keep all registrations, risk assessments, policy documents, and staff training logs up to date and easily accessible. If you are inspected, be transparent and cooperative. Attempting to hide breaches or falsify documents will always make things worse.

Practical Steps to Ensure Ongoing Compliance

AML compliance is not a one-off task but an ongoing process. Your business must embed AML checks into everyday operations, review risks regularly, and adapt to new threats or regulatory changes. Assigning clear responsibility and creating a culture of compliance are just as important as ticking the legal boxes.

Schedule annual reviews of your risk assessment and AML policy, especially if your client base, services, or the law changes. Use external guidance from your professional body or HMRC’s sector guidance to benchmark your practices. Many businesses benefit from periodic third-party audits, especially ahead of a likely inspection.

Leverage technology where possible: electronic verification, secure record-keeping platforms, and automated monitoring tools can reduce risk and save time. However, technology is not a substitute for judgement—staff must be trained to interpret alerts and escalate genuine concerns.

  • Set calendar reminders for policy and risk assessment reviews
  • Use secure digital record systems for CDD and SAR logs
  • Join a trade body for sector-specific updates and support
  • Conduct mock inspections to test your readiness
  • Encourage staff feedback on AML processes and red flags

Stay informed: subscribe to regulatory updates from your supervisory authority, the NCA, and your professional body. AML law changes regularly, and ignorance is not a defence. If in doubt, seek legal advice—especially for complex or international transactions.

ACAS and FSB support

ACAS and the Federation of Small Businesses (FSB) provide practical support, training, and helplines for small firms tackling AML and other compliance issues.

Key Takeaways
  • Understand if AML laws apply to your business. Check your sector’s requirements—many small businesses are caught out by assuming AML is only for banks.
  • Register with the correct supervisory authority. HMRC, SRA, FCA, or your professional body must be notified and kept up to date.
  • Write and review a tailored AML policy. Use sector guidance and keep your risk assessment, training, and procedures specific to your business.
  • Customer due diligence is non-negotiable. Verify all clients, document checks, and apply enhanced due diligence where risks are higher.
  • Report suspicions promptly and keep records. File SARs with the NCA, maintain confidentiality, and store all records for five years.
  • Penalties for non-compliance are severe. Fines, public censure, business closure, and even criminal prosecution await those who ignore AML duties.
  • Ongoing compliance requires a proactive approach. Review, train, and test your AML processes regularly, adapting to new risks and rules.
  • Seek support and stay informed. Use resources from HMRC, FSB, and your trade body to keep on top of your obligations and avoid costly mistakes.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.