Ticking the box is not the same as managing the risk. This guide covers what a defensible AML programme actually requires — and where most compliance failures occur in practice.
Anti-money laundering compliance is one of those areas where the paper trail can look complete while the substance is missing. Regulators have been saying this for fifteen years — and still find the same failures in almost every enforcement action. The gap is rarely in the policy document. It is in the judgment: who counts as high risk, what constitutes adequate source-of-funds evidence, when enhanced diligence is genuinely triggered rather than formally avoided.
This guide covers the components of a defensible AML programme, the failure modes regulators consistently find, and where OSINT-grade intelligence fills the gaps that automated screening leaves open.
The primary legislation in the UK is the Proceeds of Crime Act 2002 (POCA) and the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), as amended by the 2019 and 2022 Regulations. The MLR 2017 implement the EU's Fourth and Fifth Anti-Money Laundering Directives into UK law.
Firms within scope must register with their supervisory authority (FCA for financial services, HMRC for accountants, estate agents, high-value dealers and others), maintain a risk assessment, apply CDD and EDD procedures, screen for sanctions and PEPs, appoint a nominated officer (MLRO), train staff, and file Suspicious Activity Reports (SARs) with the National Crime Agency where required.
POCA creates three principal offences: arranging or facilitating money laundering, acquiring criminal property, and failing to disclose knowledge or suspicion of money laundering where there is a duty to do so. Tipping off a subject that a SAR has been filed is a separate offence.
The foundation of any AML programme is a business-wide risk assessment that identifies the specific money laundering risks arising from the firm's products, client base, delivery channels and geographies. The assessment must be documented, reviewed regularly, and calibrated to the actual business — not copied from a template that describes a different one.
A risk assessment that rates all customers as medium risk without supporting analysis is not a risk-based approach. It is an avoidance of one. Regulators treat it accordingly.
Factors that typically elevate risk: clients from high-risk jurisdictions (FATF grey or black list, or jurisdictions with weak AML frameworks), complex or opaque corporate structures, politically exposed persons or their associates, high-value or cash-intensive transactions, and industries with elevated exposure to financial crime — real estate, luxury goods, professional services, crypto.
CDD is the baseline process for every new client relationship. It requires:
The standard of CDD is not fixed — it is proportionate to the risk. Simplified due diligence may apply for certain low-risk customers; enhanced due diligence is mandatory for those presenting higher risk.
EDD is mandatory for politically exposed persons (PEPs), customers from high-risk third countries (as designated by the FCA or EU), and any relationship or transaction that presents higher money laundering risk by nature. It is also good practice — and increasingly expected — for any customer where the standard CDD leaves material questions unanswered.
EDD requires:
Source of funds is not the same as source of wealth. Source of funds means: where did the specific money in this transaction come from? Source of wealth means: how did this person accumulate their overall assets? Both questions need answers in an EDD context, and database checks rarely provide them.
Sanctions compliance is a separate legal requirement from AML — and increasingly a more acute one, given the volume of new designations since 2022. Sanctions screening must cover:
List screening alone is insufficient. Sophisticated structures use nominees, trusts, and offshore vehicles to place sanctioned individuals at a distance from named accounts. OSINT-grade sanctions diligence maps the ownership and control chain, not just the named parties.
Enforcement actions and supervisory reviews consistently identify the same deficiencies. Knowing them is the first step to avoiding them.
Automated AML screening — database checks, list matching, adverse media alerts — is a floor, not a ceiling. It catches what is already recorded; it misses what is not yet formalised, what is in local-language sources, what is obscured by structure.
OSINT-based due diligence extends the picture: mapping the full beneficial ownership chain through corporate registries across multiple jurisdictions, identifying adverse reporting in press that did not reach global news wires, finding the court proceedings that predate the current entity name, and establishing whether the source-of-wealth narrative is consistent with what the open record shows.
For higher-risk onboarding decisions — a significant investor, a counterparty in a complex transaction, a client from a jurisdiction where the registry is opaque — OSINT-grade intelligence is not a supplement to automated screening. It is the substantive work that automated screening cannot do.
AML compliance is the set of policies, controls and procedures a business maintains to detect and prevent money laundering and terrorist financing. Core components are a risk assessment, customer due diligence, enhanced due diligence for higher-risk relationships, sanctions screening, ongoing monitoring and suspicious activity reporting.
A business-wide risk assessment identifying your specific risks; CDD procedures calibrated to those risks; EDD for PEPs, high-risk jurisdictions and complex structures; sanctions screening at onboarding and ongoing; a nominated MLRO; staff training; and a SAR filing process. Risk-based means effort is proportionate to risk — but low-risk classification must be supportable, not assumed.
CDD is the baseline: verify identity, understand the purpose of the relationship. Enhanced due diligence applies where risk is higher — PEPs, high-risk jurisdictions, opaque structures. EDD requires deeper verification of source of funds and wealth, senior management approval, and more frequent review.
The Money Laundering Regulations 2017 apply to credit and financial institutions, accountants, tax advisers, auditors, insolvency practitioners, legal professionals handling certain work, estate agents, high-value dealers (over €10,000 cash), casino operators and trust or company service providers. Beyond legal obligation, any business with significant counterparty exposure needs a defensible process.
Regulators consistently find: generic risk assessments; CDD that verifies identity but not source of funds; EDD triggered too narrowly; sanctions screening that is list-only and misses derivative exposure; monitoring that is periodic rather than event-driven; and MLRO roles without real authority or resource.
OSINT-based due diligence extends AML beyond what databases contain: mapping beneficial ownership across multiple registries, identifying adverse media in local-language sources, finding court proceedings under prior entity names, and testing whether source-of-wealth narratives are consistent with the open record.
One confidential message is enough. Tell us only what you are comfortable sharing — we take it from there.
Make a confidential enquiry