The 2017 Regulations implement the EUs Fourth AntiMoney Laundering Directive (AMLD4) in the United Kingdom, providing a framework for preventing the misuse of the financial system. The Regulations apply to a wide range of obliged entities, including banks, credit unions, building societies, accountinformation service providers, paymentservice providers, accountants, lawyers, estate agents and highvalue dealers. Their purpose is threefold: They are enforced by the Financial Conduct Authority (FCA), HM Revenue & Customs (HMRC) and the Office of Financial Sanctions Implementation (OFSI). Noncompliance can lead to civil penalties, criminal prosecution and reputational damage. Every obliged entity must have a documented antimoneylaundering (AML) and counterterroristfinancing (CTF) policy approved by senior management. The policy must set out the riskbased approach, internal controls, training programmes and reporting mechanisms. A periodic, documented risk assessment is required. It must consider: The outcome determines the intensity of customer duediligence (CDD) and monitoring measures. CDD is the process of identifying and verifying a customers identity, understanding the nature of the business relationship and assessing the purpose of transactions. The Regulations distinguish three levels: Compliance does not stop once a client is onboarded. Entities must continuously monitor transactions, compare them to the customers risk profile, and update CDD information as needed. Automated transactionmonitoring systems are encouraged for large volumes. A robust risk assessment includes: Documentation of the assessment demonstrates to regulators that a proportionate, riskbased approach is in place. Collect reliable, independent documents such as passports, driving licences, utility bills, or corporate registration excerpts. For legal persons, verify the identity of the beneficial owners holding at least 25% of the voting rights, or the natural person who ultimately controls the entity. Obtain information on the source of funds, intended use of the account and expected transaction patterns. Questionnaires and riskscoring questionnaires help to capture this data. For higherrisk customers, review CDD information at least annually; for lowerrisk customers, a review every three years is acceptable. All CDD information, risk assessments and transaction records must be retained for a minimum of five years after the business relationship ends or after a transaction is completed. Whenever an entity has knowledge, suspicion, or a reasonable belief that a transaction may involve proceeds of crime or terrorist financing, it must file a SAR with HMRCs National Economic Crime Centre (NECC). Key points: Prompt reporting is essential there is no minimum monetary threshold. The FCA and HMRC have extensive enforcement powers. Penalties may include: Recent case law shows that regulators penalise not only failures to detect illicit activity but also weak governance, inadequate training and poor recordkeeping. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 create a comprehensive, riskbased framework aimed at protecting the integrity of the UK financial system. Success depends on a culture of compliance, robust policies, regular risk assessments, effective CDD, timely monitoring and swift reporting of suspicious activity. By embedding these practices, obliged entities not only meet legal obligations but also reinforce public confidence in the financial sector.Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
1. Overview of the Regulations
2. Core Obligations for Covered Entities
2.1 Governance and Policies
2.2 Risk Assessment
2.3 Customer Due Diligence (CDD)
2.4 Ongoing Monitoring
3. Conducting a Risk Assessment
4. Customer Due Diligence Practical Steps
4.1 Identification & Verification
4.2 Understanding the Business Relationship
4.3 Ongoing Updating
4.4 Recordkeeping
5. Suspicious Activity Reporting (SAR)
6. Penalties and Enforcement
7. Conclusion
