The UK regimeFoundation

The Money Laundering Regulations 2017, explained

The Money Laundering Regulations 2017 (the "MLRs") are the rulebook that turns the UK's anti-money-laundering principles into concrete obligations for businesses. Where the Proceeds of Crime Act criminalises laundering after the fact, the MLRs are preventative: they require regulated firms to know their customers, assess risk, and report suspicion — so the money is stopped before it is cleaned.

Who the regulations apply to

The MLRs apply to businesses in the "regulated sector" — those most exposed to being used for laundering. Per GOV.UK, this includes:

Who
SectorExamples
FinancialBanks, payment and e-money firms, investment firms
LegalSolicitors and other legal professionals (in scope activities)
AccountancyAccountants, tax advisers, auditors, insolvency practitioners
PropertyEstate and letting agents (above rent thresholds)
Trust & companyTrust or company service providers (TCSPs)
High valueHigh-value dealers, art market participants, casinos
CryptoCryptoasset exchange and custodian wallet providers

Each in-scope firm must be supervised (by the FCA, HMRC, or a professional body) and, where required, registered.

The risk-based approach

The MLRs do not ask every customer to be treated identically. They require a risk-based approach: effort is proportionate to risk.

The
  • Lower-risk customerSimplified due diligence may apply
  • Standard customerStandard customer due diligence
  • Higher-risk customer (PEP, high-risk country, unusual structure)Enhanced due diligence

This runs on two levels: a business-wide risk assessment (what risks does the firm face overall?) and a customer risk assessment (what risk does this specific customer present?).

When customer due diligence is triggered

Regulation 27 sets out when CDD must be applied. Match each trigger to what it means.

Match the pairsWhen must you apply CDD?0 / 5

The MLRs name specific moments that trigger customer due diligence. Match each trigger to its meaning.

What customer due diligence involves

At its core, CDD under the MLRs means:

The
  1. Identify the customer
    Establish who they are.
  2. Verify their identity
    Confirm it from a reliable, independent source.
  3. Identify beneficial owners
    For entities, find and verify who ultimately owns or controls them (see beneficial ownership).
  4. Understand the relationship
    Establish the purpose and intended nature of the business relationship.
  5. Monitor on an ongoing basis
    Keep the relationship under review and keep information up to date.

The depth of this scales with risk — the three tiers (simplified, standard, enhanced) are covered in KYC vs CDD.

The wider duties

CDD is the most visible obligation, but the MLRs require a whole control framework:

Beyond
DutyWhat it means
Risk assessmentA documented business-wide assessment of ML/TF risk
Policies & controlsWritten policies, controls and procedures to manage that risk
Nominated officer (MLRO)Appoint someone responsible for AML, who receives internal reports
TrainingStaff trained to recognise and handle ML/TF risk
Record-keepingKeep CDD and transaction records (generally five years)
ReportingReport suspicion via SARs to the NCA

See the role of the MLRO and SARs and the NCA for two of these in depth.

Where Probitas fits

Probitas supports the CDD and ongoing-monitoring parts of the MLR framework: it screens names and companies against sanctions, PEP and adverse media sources and surfaces beneficial-ownership signals from the public record, with every finding anchored to its source. It is a tool for the evidence-gathering the MLRs expect; the risk decisions, policies and reporting remain the firm's own responsibility.

Knowledge checkMLR 2017: quick check1 / 5

Five questions on the regulations.

What is the core principle of the MLRs?

The

What are the Money Laundering Regulations 2017?

They are the UK rules that require regulated businesses to take preventative anti-money-laundering measures — customer due diligence, risk assessment, record-keeping, training and reporting. They implement the UK's AML obligations in practical, enforceable form.

Who has to comply with the MLRs?

Businesses in the regulated sector: banks and financial firms, legal and accountancy professionals, estate and letting agents, trust or company service providers, high-value dealers, art market participants, casinos and cryptoasset firms, among others. Each must be supervised and, where required, registered.

When is customer due diligence required?

When establishing a new business relationship, on occasional transactions at or above the thresholds, on certain funds transfers, whenever you suspect money laundering or terrorist financing, and when you doubt previously obtained identification information.

What is the difference between the MLRs and POCA?

POCA (the Proceeds of Crime Act 2002) criminalises money laundering itself. The MLRs are preventative — they require regulated firms to put controls in place so laundering is detected and deterred before it happens. They work together.

What happens if a firm breaches the MLRs?

Supervisors can take enforcement action including fines and restrictions, and serious breaches can have criminal consequences. Beyond penalties, weak MLR compliance exposes a firm to being used for laundering and to severe reputational damage.

Sources

This guide is written from primary sources. Each is linked below; claims in the text link to the specific reference they rely on.

  1. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (legislation.gov.uk)
  2. MLR 2017 reg. 27 — when CDD must be applied (legislation.gov.uk)
  3. GOV.UK — Money laundering supervision: your responsibilities
  4. GOV.UK — Who needs to register for money laundering supervision