AML policies, controls, and procedures for accountancy firms
Last updated: August 7, 2026
AML policies, controls, and procedures (PCPs) explain how an accountancy firm puts its money laundering risk assessment into daily practice. They set out how client due diligence is applied and how AML decisions are made and recorded.
These arrangements are important to regulators because the risk assessment identifies the firm’s exposure, while the PCPs explain how it responds. As a result, PCPs connect identified risks with the AML controls used during client onboarding and throughout the relationship.
Key takeaways
- AML PCPs should follow from the firm-wide risk assessment.
- Accountancy firms need written AML arrangements that reflect their actual work.
- Client onboarding procedures should explain how due diligence is completed before new engagements begin.
- Higher-risk clients or services should have clear approval and escalation steps.
- Records must show the evidence kept, the decisions made, and the rationale for that judgment.
- Reviews should confirm that the documented process still reflects current working methods.
What AML PCPs are and why they matter
Policies, controls, and procedures are often grouped together, but each has a different role.
- Policies set out the firm’s stated approach, where they explain the practice’s AML responsibilities and the standards expected when accepting and managing client relationships.
- Controls are the safeguards used to reduce risk; they should show how higher-risk work, due diligence, and compliance checks are managed.
- Procedures describe how the firm applies its AML requirements in practice. They explain the firm’s approach to CDD, reporting, and record keeping for staff and partners.
Taken together, these policies, controls, and procedures fall within Regulation 19 of the Money Laundering Regulations, which requires relevant businesses to establish and maintain AML PCPs to mitigate and manage money laundering and terrorist financing risk.
The regulation also requires senior management to approve proportionate written measures and keep them reviewed and updated. These duties now also sit alongside proliferation financing obligations under regulation 19A.
Crucially, even when proportionality applies, a sole practitioner or micro practice still needs written AML PCPs. Where staff are present, the relevant procedures must also be communicated internally so that people understand the responsibilities that apply to their work.
Firm-wide risk assessment findings and AML control design
The firm-wide risk assessment (FWRA) provides the basis for deciding how the practice should control the money laundering risks it has identified.
For example, a firm might have assessed that most of its clients are local owner-managed businesses with routine accountancy needs. Its procedures could therefore use a simple standard onboarding route for lower-risk clients, with clear triggers for further checks when a client no longer fits the usual pattern.
By contrast, another practice might have higher-risk service lines, such as company formation or payroll services for cash-intensive businesses.
Those services can change the controls needed at intake and during the relationship, which can mean enhanced intake checks and senior oversight for certain clients, with a lower threshold for referral to the money laundering reporting officer (MLRO).
The key aspect is that the FWRA needs to lead to a clear decision about how the practice works. Consistent with this, HMRC’s Economic Crime Supervision Handbook explains that AML PCPs should be designed using the business’s risk assessment and should not be reviewed in isolation.
Practical takeaway: the written document should identify the controls that apply to clients, services, or delivery channels needing closer oversight.
Core content of AML PCPs for accountancy firms
The written content does not need to read like a large corporate manual. It should, however, cover the areas that impact AML behaviour across the practice.
In this context, CCAB guidance for the accountancy sector groups these areas around risk-based due diligence, monitoring, and compliance governance.
Client onboarding and customer due diligence controls
Client onboarding is where many AML controls first take effect, so this section should set out the checks required before the firm starts work. If CDD checks remain incomplete, the procedure should explain when the firm must stop and whether escalation is required.
At a minimum, the process needs to cover client identification and verification, beneficial ownership checks where relevant, and sufficient information to assess the relationship’s risk. By extension, the onboarding section should also explain how customer information is kept up to date when circumstances change.
The firm’s guidance should also specify the circumstances that require enhanced checks. If onboarding checks indicate higher risk, the procedure should describe the firm’s enhanced due diligence route, including any required approval before acceptance.
Ongoing monitoring, reporting, and escalation
AML controls do not end once a client is accepted, which is especially relevant because accountancy work often gives the firm repeated access to client information and transaction records.
As that information develops, the firm’s procedures should help staff recognise when a change might affect the client’s risk profile.
Ongoing monitoring can remain proportionate to the work being carried out, but it should still identify relevant indicators, such as unusual payments, repayment claims, or changes in the client’s circumstances.
The procedures should also set out the internal reporting route, what a timely referral should include, and how staff avoid discussing a potential suspicious activity report (SAR) with the client.
Any SAR decision should then be recorded, with the record connecting the concern raised with the decision and the reason for making or not making an external report.
AML record keeping, training, and responsibility allocation
Record procedures explain what evidence the firm keeps and where it is stored. This usually includes due diligence evidence, risk assessments, and the firm’s main compliance records.
HMRC’s handbook treats record keeping as an area supervisors might test during compliance interventions, reaffirming its importance in practice.
Alongside record keeping, training procedures should be role-appropriate.
For instance, a micro firm does not require a large training programme, but staff with AML responsibilities need to understand the practice’s AML risks and the reporting and record-keeping procedures that apply to their roles. Firms also need evidence that training happened and was refreshed.
While in a small practice one person can hold several senior compliance roles, the document should still state who owns key AML decisions and checks.
Finally, employee screening under the Money Laundering Regulations should be covered briefly where relevant. The firm can document the suitability checks applied to staff who carry out AML-sensitive client work.
Proportionate AML PCPs for small accountancy practices
Proportionality means documenting enough process to control real AML risks without adding unnecessary procedural burden.
Accordingly, the document should make key AML decision points easy to identify, while any templates used should support the structure rather than be treated as evidence that the firm’s PCPs are complete.
Regardless of format, the document must be sufficiently clear for staff to understand the required procedures without making assumptions. This clarity is especially important when a document appears complete but still leaves material steps or decision points open to interpretation.
AML PCP review, evidence, and governance records
AML policies, controls, and procedures need to be reviewed when material changes affect the firm or its risk profile.
Periodic review is also required even when no obvious change has occurred, as the firm still needs to confirm that its procedures remain aligned with the risk assessment and are being followed consistently.
HMRC reinforces this expectation by emphasising written procedures, effective staff communication, and records showing that the documented process is applied in practice.
Beyond the policies, controls, and procedures document itself, governance records should capture approval, implementation, and follow-up action, rather than only preserving the current PCP.
An external compliance review can be useful for some firms, especially if the practice faces greater AML exposure. That said, in a very small practice, a documented internal review by someone with enough knowledge and authority can be proportionate.
In either case, the practical outcome is that the PCPs support consistent AML decision-making in daily client work.
In summary
Effective AML PCPs help accountancy practices apply their AML process reliably in routine engagements. They provide the practitioner with enough structure for client acceptance, monitoring of changes, and responses to concerns without creating compliance steps that add little value.
Ultimately, the strongest PCP documents do more than describe the firm’s AML framework. They give staff a clear basis for applying the procedures consistently and showing how key decisions were reached.
FAQs
AML policies, controls, and procedures can be short, but they should reflect the practice’s actual clients, services, and risk profile. The document should identify how checks are completed, when closer review is required, who deals with internal concerns, and where records are kept. If one individual handles most AML decisions, that should be stated plainly.
Yes, provided the document clearly distinguishes the firm’s overall AML approach from the procedures used in practice. It should also show how those procedures respond to the risks identified in the firm-wide risk assessment.
Any elevated-risk findings should drive the firm’s AML response. For example, a higher-risk service or client type might require closer review at acceptance, clearer approval points, or earlier internal referral if concerns arise. Therefore, the written approach should reflect the firm’s own risk assessment.
The procedures need to explain how the client is reassessed when new information changes the risk picture. This might involve confirming whether the existing due diligence remains sufficient and identifying the person responsible for deciding what further action is needed. The document should also make clear how AML concerns are raised internally before any client discussion creates a reporting risk.
The review cycle should include planned intervals and any meaningful change affecting the firm’s AML risk. A change could involve new services, different client types, staff changes, or signs that the current document is no longer being followed. The review must consider whether the documented arrangements still fit the firm’s day-to-day work.
Anyone with AML responsibilities should understand the parts of the PCPs relevant to their role. Whether the practice consists of one person or a small team, the PCPs should make clear how changes are recognised and concerns are escalated.
References and Source Material
- Money Laundering Regulations 2017
- HMRC, Economic Crime Supervision Handbook (ECSH33210: ECSH33215, ECSH33520)
- HMRC, Risks common to accountancy service providers
- HMRC, Your responsibilities under money laundering supervision
- CCAB, Anti-Money Laundering and Counter-Terrorist Financing Guidance for the Accountancy Sector
- ICAEW, What is required of an ICAEW AML supervised firm
- ICAEW, Perform a regular compliance review

