Core requirements under the UK Money Laundering Regulations
The MLRs apply to defined “relevant persons” across financial services and other sectors exposed to illicit-finance risk. Covered businesses must identify and assess the money-laundering and terrorist-financing risks affecting their operations, document that assessment, and maintain proportionate policies, controls and procedures. Later amendments added parallel duties concerning proliferation-financing risk.
Customer due diligence is central to the regime. When the statutory triggers apply, a relevant person must identify and verify the customer, identify and take reasonable measures to verify beneficial owners, understand the purpose and intended nature of the relationship, and conduct ongoing monitoring. Enhanced due diligence and enhanced monitoring apply in specified higher-risk circumstances, while simplified measures may be available where the regulations and risk assessment support them.
- Internal controls can include senior-management responsibility, screening and training, depending on the size and nature of the business.
- Records supporting due diligence and transactions generally must be retained for the prescribed period, commonly five years, subject to the detailed rules and lawful exceptions.
- Part 7 supports supervision and enforcement of payer and payee information requirements for traditional transfers of funds.
- Supervisors have information-gathering, inspection, registration and enforcement powers. The regulations provide for civil penalties, public statements, management prohibitions and criminal liability for specified contraventions.