The Money Laundering Regulations 2017 (the "MLRs") are the rulebook that turns the UK's anti-money-laundering principles into concrete obligations for businesses. Where the Proceeds of Crime Act criminalises laundering after the fact, the MLRs are preventative: they require regulated firms to know their customers, assess risk, and report suspicion — so the money is stopped before it is cleaned.
Who the regulations apply to
The MLRs apply to businesses in the "regulated sector" — those most exposed to being used for laundering. Per GOV.UK, this includes:
| Sector | Examples |
|---|---|
| Financial | Banks, payment and e-money firms, investment firms |
| Legal | Solicitors and other legal professionals (in scope activities) |
| Accountancy | Accountants, tax advisers, auditors, insolvency practitioners |
| Property | Estate and letting agents (above rent thresholds) |
| Trust & company | Trust or company service providers (TCSPs) |
| High value | High-value dealers, art market participants, casinos |
| Crypto | Cryptoasset exchange and custodian wallet providers |
Each in-scope firm must be supervised (by the FCA, HMRC, or a professional body) and, where required, registered.
The risk-based approach
The MLRs do not ask every customer to be treated identically. They require a risk-based approach: effort is proportionate to risk.
- Lower-risk customerSimplified due diligence may apply
- Standard customerStandard customer due diligence
- Higher-risk customer (PEP, high-risk country, unusual structure)Enhanced due diligence
This runs on two levels: a business-wide risk assessment (what risks does the firm face overall?) and a customer risk assessment (what risk does this specific customer present?).
When customer due diligence is triggered
Regulation 27 sets out when CDD must be applied. Match each trigger to what it means.
The MLRs name specific moments that trigger customer due diligence. Match each trigger to its meaning.
What customer due diligence involves
At its core, CDD under the MLRs means:
- Identify the customerEstablish who they are.
- Verify their identityConfirm it from a reliable, independent source.
- Identify beneficial ownersFor entities, find and verify who ultimately owns or controls them (see beneficial ownership).
- Understand the relationshipEstablish the purpose and intended nature of the business relationship.
- Monitor on an ongoing basisKeep the relationship under review and keep information up to date.
The depth of this scales with risk — the three tiers (simplified, standard, enhanced) are covered in KYC vs CDD.
The wider duties
CDD is the most visible obligation, but the MLRs require a whole control framework:
| Duty | What it means |
|---|---|
| Risk assessment | A documented business-wide assessment of ML/TF risk |
| Policies & controls | Written policies, controls and procedures to manage that risk |
| Nominated officer (MLRO) | Appoint someone responsible for AML, who receives internal reports |
| Training | Staff trained to recognise and handle ML/TF risk |
| Record-keeping | Keep CDD and transaction records (generally five years) |
| Reporting | Report suspicion via SARs to the NCA |
See the role of the MLRO and SARs and the NCA for two of these in depth.
Where Probitas fits
Probitas supports the CDD and ongoing-monitoring parts of the MLR framework: it screens names and companies against sanctions, PEP and adverse media sources and surfaces beneficial-ownership signals from the public record, with every finding anchored to its source. It is a tool for the evidence-gathering the MLRs expect; the risk decisions, policies and reporting remain the firm's own responsibility.
Five questions on the regulations.
The
What are the Money Laundering Regulations 2017?
They are the UK rules that require regulated businesses to take preventative anti-money-laundering measures — customer due diligence, risk assessment, record-keeping, training and reporting. They implement the UK's AML obligations in practical, enforceable form.
Who has to comply with the MLRs?
Businesses in the regulated sector: banks and financial firms, legal and accountancy professionals, estate and letting agents, trust or company service providers, high-value dealers, art market participants, casinos and cryptoasset firms, among others. Each must be supervised and, where required, registered.
When is customer due diligence required?
When establishing a new business relationship, on occasional transactions at or above the thresholds, on certain funds transfers, whenever you suspect money laundering or terrorist financing, and when you doubt previously obtained identification information.
What is the difference between the MLRs and POCA?
POCA (the Proceeds of Crime Act 2002) criminalises money laundering itself. The MLRs are preventative — they require regulated firms to put controls in place so laundering is detected and deterred before it happens. They work together.
What happens if a firm breaches the MLRs?
Supervisors can take enforcement action including fines and restrictions, and serious breaches can have criminal consequences. Beyond penalties, weak MLR compliance exposes a firm to being used for laundering and to severe reputational damage.
Sources
This guide is written from primary sources. Each is linked below; claims in the text link to the specific reference they rely on.
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (legislation.gov.uk)
- MLR 2017 reg. 27 — when CDD must be applied (legislation.gov.uk)
- GOV.UK — Money laundering supervision: your responsibilities
- GOV.UK — Who needs to register for money laundering supervision