The UK AML rules accountancy firms need to follow

Accountant reviewing financial records as part of UK anti-money laundering compliance

Last updated: August 6, 2026

UK accountancy firms that carry out regulated work must organise their AML responsibilities around the services they provide, the clients they accept, and the risks they encounter in practice. 

The principal obligations sit under the Money Laundering Regulations 2017 (MLR 2017) and the Proceeds of Crime Act 2002 (POCA), supported by HM Treasury-approved guidance for the accountancy sector.

These requirements perform different but connected functions; MLR 2017 establishes the preventive framework, while POCA governs the reporting consequences when money laundering is known or suspected. 

Crucially, the AML risks created by the firm’s services and client relationships should determine the controls it applies and the evidence it retains for supervisory review.

Key takeaways

  • Whether the AML regime applies depends on the accountancy work undertaken for clients.
  • AML controls must be proportionate to the firm’s actual exposure.
  • The firm-wide risk assessment (FWRA) should explain how the practice’s service profile could expose it to money laundering or terrorist financing.
  • Client records need to show why the due diligence completed matched the assessed risk.
  • Concerns must follow a clear escalation route to the nominated officer.

Which accountancy firms are covered by the AML rules?

A firm is in scope when it provides regulated accountancy services by way of business. 

The category extends beyond statutory accounts and audit work and can include bookkeeping, accounts preparation, payroll, and client-specific tax work if the service handles or reports the client’s financial information.

Routine accounts, tax, or bookkeeping work undertaken for individual clients can therefore be sufficient to bring a firm within the UK’s money laundering framework.

Supervision is normally provided by HMRC or an approved professional body, such as ICAEW or ACCA. HMRC registration is generally required only when the firm is not already supervised for AML by one of those bodies.

Practical takeaway: Certain activities fall outside the AML registration requirement, including non-commercial in-house work, generic tax information, and narrowly defined support services. However, firms should assess the substance of the work carefully before treating it as excluded.

The main sources of UK AML obligations

MLR 2017 requires regulated firms to:

  • Maintain a FWRA
  • Conduct customer due diligence and ongoing monitoring 
  • Retain records
  • Train relevant staff
  • Establish proportionate internal controls

These AML measures should be proportionate to the size and complexity of the business and the risks it faces.

The firm’s records should show how those duties were applied to each client relationship, and in particular, explain the basis for client acceptance and how ownership or unusual activity affected the firm’s response.

POCA and suspicious activity reporting

Under POCA, a person in the regulated sector can commit an offence by failing to disclose knowledge or suspicion of money laundering involving criminal property. Sections 330 and 331 set out the relevant duties for individuals and nominated officers, also referred to as the Money Laundering Reporting Officer (MLRO). 

Suspicious activity reports are submitted to the UK Financial Intelligence Unit, which is part of the National Crime Agency

Accountancy sector guidance

CCAB guidance explains how the AML regime applies to the UK accountancy sector and provides a common reference point for supervisors.

The guidance translates legal duties into practical expectations for accountancy providers while remaining subordinate to the legislation itself. 

Its status is significant because courts must take the approved sector guidance into account when considering relevant AML breaches or POCA reporting offences.

AML compliance expectations for small accountancy firms

AML systems should be proportionate to the nature and scale of the firm’s work. Controls should then reflect how the firm operates and the risks arising from its client relationships.

The FWRA identifies exposure across the business and provides the foundation for the risk-based approach, so its findings should then determine the controls and records required.

That analysis should be grounded in the firm’s actual service and delivery model. 

Remote tax work, for example, can create different identification and verification challenges from work delivered through regular direct contact. 

The resulting differences should inform the verification measures and other controls used.

The client risk assessment and customer due diligence then translate the FWRA into decisions for each relationship. If ownership or funding is less transparent, the firm should explain how that affected the checks performed and why the resulting due diligence was sufficient.

The client-level assessment should also address activity that no longer matches the firm’s understanding of the client at onboarding. 

For instance, if a bookkeeping client’s transactions become unusual or harder to explain, the firm might need to make further enquiries and reassess the client’s risk.

The internal escalation route to the nominated officer or MLRO should also be clear. Regulated businesses must appoint someone to perform this function, although a sole trader with no employees assumes the responsibility personally. The role includes assessing internal concerns and deciding whether an external report is required.

Practical takeaway: The AML regime also requires firms to assess proliferation financing risk and to take HMRC’s accountancy sector risk assessment into account when preparing their own FWRA.

AML supervisory expectations and client file evidence

Supervisors expect evidence that the firm applies its AML controls consistently

As such, a written policy should be supported by documented decisions showing how the procedures operated in individual cases. Compliance visits and office-based reviews can then test whether that evidence is consistent with the policy.

This is particularly relevant because published supervisory findings identify weaknesses in due diligence and risk documentation.

When a firm falls short, supervisory action can range from required improvements to enforcement. Serious failures can also carry criminal consequences, while any financial penalty will reflect the severity of the breach and the firm’s circumstances. 

This scrutiny is likely to become stricter as the accountancy sector moves towards FCA supervision, with firms expected to justify how their AML controls are applied.

In summary

AML procedures should connect firm-level risk conclusions to decisions made for individual clients, while the recorded reasoning needs to explain why the relationship was accepted and how ownership and risk affected the checks undertaken.

The quality of the firm’s AML framework becomes clearest when client activity changes. At that point, the firm should be able to show how its controls led to a reasoned response and why that response was justified.

Kane Pepi, Founder of Evidentia Compliance
Kane Pepi Founder, Evidentia Compliance

Kane Pepi is the founder of Evidentia Compliance, with a strong academic background in accounting, finance, and financial crime, and peer-reviewed research in money laundering and terrorist financing.

His work focuses on making AML compliance more practical for small regulated firms that face rising supervisory expectations and limited compliance capacity.

AMLWATCH BY EVIDENTIA
AML compliance updates and regulatory guidance for the accountancy sector

Stay informed on AML supervision, FCA developments, enforcement trends, and common compliance weaknesses affecting UK accountancy firms. AMLWATCH by Evidentia is written for small practices that need AML insight without the regulatory jargon.

    FAQs

    Do AML rules apply to sole practitioners and micro accountancy firms?

    Yes. An accountancy firm’s size or legal structure does not remove it from the AML regime when it undertakes regulated work.

    Do I need HMRC AML registration if my firm belongs to a professional body?

    In most cases, no. Separate HMRC registration is generally unnecessary if the firm already receives AML supervision through its professional body. However, the firm should confirm that all its regulated work falls within that coverage.

    What does proportionate AML compliance look like for a small accountancy practice?

    Proportionate AML compliance means adjusting the depth and formality of the control environment to the identified risk. A more straightforward approach can be justified when the AML exposure is lower and less complex, provided the firm records why its checks remain sufficient.

    When should a client’s AML risk be reviewed after onboarding?

    A client’s risk should be reviewed when new information or activity changes the firm’s understanding of the relationship. A change in ownership, for example, can reduce the transparency of the ownership structure or introduce a new controlling party. The firm should then reconsider whether its existing due diligence and AML risk rating remain appropriate.

    Who handles suspicious activity concerns in a sole practice or small firm?

    Concerns about possible money laundering should follow a defined process explaining how they are recorded, escalated, and assessed. In a sole practice with no employees, that responsibility rests with the practitioner.

    What should client files show during an AML supervisor check?

    During an AML supervisory check, client records should demonstrate how the firm applied its controls to individual relationships. The supervisor should be able to trace how the client risk assessment informed the due diligence undertaken and any response to unusual activity.

    References and Source Material

    Leave a Reply

    Your email address will not be published. Required fields are marked *