The Transfer of Funds Regulations 2017 (the Regulations) are a key part of the United Kingdoms antimoney laundering (AML) and counterterrorist financing (CTF) framework. They transpose the EUs Fourth Money Laundering Directive into UK law and set out detailed obligations for a wide range of businesses, from banks to virtualcurrency providers. The Regulations apply to obliged entities, which include: Any person who carries out a regulated activity, alone or on behalf of another, must comply with the Regulations. Obliged entities must identify and verify the identity of their customers before establishing a business relationship or conducting a transaction above the thresholds set out in the Regulations (generally 10,000). CDD includes: Monitoring must be continuous, covering transaction patterns, changes in risk profile and any suspicious activity. Entities are required to keep records of all CDD information and transaction data for a minimum of five years. When a transaction or pattern raises suspicion of money laundering or terrorist financing, the entity must submit a SAR to the National Crime Agency (NCA) without informing the client. Failure to report can result in criminal liability. Each obliged entity must maintain a documented riskassessment process that evaluates: The assessment must be reviewed regularly and updated whenever there is a material change in risk exposure. Money laundering is the process of disguising the origins of illegally obtained money, typically through three stages: placement, layering and integration. The aim is to make illicit proceeds appear legitimate. Terrorist financing involves providing or collecting funds, either from legitimate or illegitimate sources, with the intention of supporting terrorist activities. Unlike money laundering, the source of the money may be lawful, but its use is criminal. Both crimes threaten the integrity of the financial system and can undermine public confidence, national security and economic stability. Companies and other legal persons must maintain a register of their UBOs and submit this information to Companies House. The register must be accessible to competent authorities and persons with a legitimate interest. Entities must apply enhanced scrutiny to PEPs, their families and close associates. The regulations require a riskbased approach and, where appropriate, the use of thirdparty data sources to verify the source of funds. All records related to CDD, transactions and SARs must be stored in a form that permits retrieval within a reasonable time. The fiveyear retention period applies regardless of whether the business relationship has ended. Obliged entities must provide regular AML/CTF training to staff at all levels. Training must be proportionate to the employees role and risk exposure and must be documented. Noncompliance may lead to civil penalties, criminal prosecution, unlimited fines and imprisonment. The Financial Conduct Authority (FCA) and the NCA have the power to issue enforcement notices, conduct investigations and levy fines. Since 2017, the regulatory landscape has evolved to address new threats: Organizations must stay abreast of guidance from the FCA, the Treasury and the European Union (where applicable) to ensure ongoing compliance.Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
1. Scope and Covered Entities
2. Core Obligations
2.1 Customer Due Diligence (CDD)
2.2 Ongoing Monitoring
2.3 Suspicious Activity Reporting (SAR)
2.4 Risk Assessment
3. Money Laundering and Terrorist Financing Explained
4. Key Provisions of the 2017 Regulations
4.1 Beneficial Ownership Registers
4.2 Politically Exposed Persons (PEPs)
4.3 RecordKeeping
4.4 Training
4.5 Sanctions and Enforcement
5. Recent Developments and Emerging Risks
6. Practical Steps for Compliance
7. Resources and Further Reading
