The UK AML rules accountancy firms need to follow
Last updated: August 6, 2026
UK accountancy firms that carry out regulated work must organise their AML responsibilities around the services they provide, the clients they accept, and the risks they encounter in practice.
The principal obligations sit under the Money Laundering Regulations 2017 (MLR 2017) and the Proceeds of Crime Act 2002 (POCA), supported by HM Treasury-approved guidance for the accountancy sector.
These requirements perform different but connected functions; MLR 2017 establishes the preventive framework, while POCA governs the reporting consequences when money laundering is known or suspected.
Crucially, the AML risks created by the firm’s services and client relationships should determine the controls it applies and the evidence it retains for supervisory review.
Key takeaways
- Whether the AML regime applies depends on the accountancy work undertaken for clients.
- AML controls must be proportionate to the firm’s actual exposure.
- The firm-wide risk assessment (FWRA) should explain how the practice’s service profile could expose it to money laundering or terrorist financing.
- Client records need to show why the due diligence completed matched the assessed risk.
- Concerns must follow a clear escalation route to the nominated officer.
Which accountancy firms are covered by the AML rules?
A firm is in scope when it provides regulated accountancy services by way of business.
The category extends beyond statutory accounts and audit work and can include bookkeeping, accounts preparation, payroll, and client-specific tax work if the service handles or reports the client’s financial information.
Routine accounts, tax, or bookkeeping work undertaken for individual clients can therefore be sufficient to bring a firm within the UK’s money laundering framework.
Supervision is normally provided by HMRC or an approved professional body, such as ICAEW or ACCA. HMRC registration is generally required only when the firm is not already supervised for AML by one of those bodies.
Practical takeaway: Certain activities fall outside the AML registration requirement, including non-commercial in-house work, generic tax information, and narrowly defined support services. However, firms should assess the substance of the work carefully before treating it as excluded.
The main sources of UK AML obligations
MLR 2017 requires regulated firms to:
- Maintain a FWRA
- Conduct customer due diligence and ongoing monitoring
- Retain records
- Train relevant staff
- Establish proportionate internal controls
These AML measures should be proportionate to the size and complexity of the business and the risks it faces.
The firm’s records should show how those duties were applied to each client relationship, and in particular, explain the basis for client acceptance and how ownership or unusual activity affected the firm’s response.
POCA and suspicious activity reporting
Under POCA, a person in the regulated sector can commit an offence by failing to disclose knowledge or suspicion of money laundering involving criminal property. Sections 330 and 331 set out the relevant duties for individuals and nominated officers, also referred to as the Money Laundering Reporting Officer (MLRO).
Suspicious activity reports are submitted to the UK Financial Intelligence Unit, which is part of the National Crime Agency
Accountancy sector guidance
CCAB guidance explains how the AML regime applies to the UK accountancy sector and provides a common reference point for supervisors.
The guidance translates legal duties into practical expectations for accountancy providers while remaining subordinate to the legislation itself.
Its status is significant because courts must take the approved sector guidance into account when considering relevant AML breaches or POCA reporting offences.
AML compliance expectations for small accountancy firms
AML systems should be proportionate to the nature and scale of the firm’s work. Controls should then reflect how the firm operates and the risks arising from its client relationships.
The FWRA identifies exposure across the business and provides the foundation for the risk-based approach, so its findings should then determine the controls and records required.
That analysis should be grounded in the firm’s actual service and delivery model.
Remote tax work, for example, can create different identification and verification challenges from work delivered through regular direct contact.
The resulting differences should inform the verification measures and other controls used.
The client risk assessment and customer due diligence then translate the FWRA into decisions for each relationship. If ownership or funding is less transparent, the firm should explain how that affected the checks performed and why the resulting due diligence was sufficient.
The client-level assessment should also address activity that no longer matches the firm’s understanding of the client at onboarding.
For instance, if a bookkeeping client’s transactions become unusual or harder to explain, the firm might need to make further enquiries and reassess the client’s risk.
The internal escalation route to the nominated officer or MLRO should also be clear. Regulated businesses must appoint someone to perform this function, although a sole trader with no employees assumes the responsibility personally. The role includes assessing internal concerns and deciding whether an external report is required.
Practical takeaway: The AML regime also requires firms to assess proliferation financing risk and to take HMRC’s accountancy sector risk assessment into account when preparing their own FWRA.
AML supervisory expectations and client file evidence
Supervisors expect evidence that the firm applies its AML controls consistently.
As such, a written policy should be supported by documented decisions showing how the procedures operated in individual cases. Compliance visits and office-based reviews can then test whether that evidence is consistent with the policy.
This is particularly relevant because published supervisory findings identify weaknesses in due diligence and risk documentation.
When a firm falls short, supervisory action can range from required improvements to enforcement. Serious failures can also carry criminal consequences, while any financial penalty will reflect the severity of the breach and the firm’s circumstances.
This scrutiny is likely to become stricter as the accountancy sector moves towards FCA supervision, with firms expected to justify how their AML controls are applied.
In summary
AML procedures should connect firm-level risk conclusions to decisions made for individual clients, while the recorded reasoning needs to explain why the relationship was accepted and how ownership and risk affected the checks undertaken.
The quality of the firm’s AML framework becomes clearest when client activity changes. At that point, the firm should be able to show how its controls led to a reasoned response and why that response was justified.
FAQs
Yes. An accountancy firm’s size or legal structure does not remove it from the AML regime when it undertakes regulated work.
In most cases, no. Separate HMRC registration is generally unnecessary if the firm already receives AML supervision through its professional body. However, the firm should confirm that all its regulated work falls within that coverage.
Proportionate AML compliance means adjusting the depth and formality of the control environment to the identified risk. A more straightforward approach can be justified when the AML exposure is lower and less complex, provided the firm records why its checks remain sufficient.
A client’s risk should be reviewed when new information or activity changes the firm’s understanding of the relationship. A change in ownership, for example, can reduce the transparency of the ownership structure or introduce a new controlling party. The firm should then reconsider whether its existing due diligence and AML risk rating remain appropriate.
Concerns about possible money laundering should follow a defined process explaining how they are recorded, escalated, and assessed. In a sole practice with no employees, that responsibility rests with the practitioner.
During an AML supervisory check, client records should demonstrate how the firm applied its controls to individual relationships. The supervisor should be able to trace how the client risk assessment informed the due diligence undertaken and any response to unusual activity.
References and Source Material
- Money Laundering Regulations 2017
- Proceeds of Crime Act 2002
- HMRC, Risks common to accountancy service providers
- HMRC, Accountancy sector guidance for money laundering supervision
- CCAB, Anti-Money Laundering, Counter-Terrorist Financing and Counter-Proliferation Financing Guidance for the Accountancy Sector
- HMRC, Check if you need to register for money laundering supervision if you’re an accountancy service provider
- HMRC, Your responsibilities under money laundering supervision
- HMRC, Risk assess your business for money laundering supervision
- HMRC, How HMRC checks on businesses registered for money laundering supervision

