Skip to main content
Category: Laws and Regulations

Money Laundering Regulations (MLRs)

Also known as: MLRs, The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, MLR 2017
Simply put

The Money Laundering Regulations (MLRs) are UK rules that require certain businesses, such as banks, brokers, and insurers, to put in place measures to detect and deter money laundering and terrorist financing. They set out what firms must do, including carrying out risk assessments and maintaining systems and controls. They are a key part of the UK's broader framework of laws aimed at preventing financial crime.

Formal definition

In the UK, "Money Laundering Regulations" (MLRs) generally refers to The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, secondary legislation that imposes administrative and preventive obligations on obliged entities within scope. These obligations typically include conducting business-wide risk assessments and maintaining appropriate systems and controls, as reflected in guidance from supervisors such as the FCA covering who the MLRs apply to and what firms need to do. The MLRs sit alongside, and are distinct from, the substantive criminal money laundering offences (which are addressed in separate primary legislation) and from broader AML frameworks in other jurisdictions; scope, applicability to particular sectors, and specific requirements should be confirmed against the current text of the Regulations and applicable supervisory guidance. As a regulatory instrument, the MLRs establish preventive and reporting duties designed to detect and deter financial crime rather than to determine criminal liability, and their precise application varies by the type of obliged entity concerned.

Why it matters

The Money Laundering Regulations (MLRs) are central to the UK's preventive AML framework because they translate high-level policy objectives into concrete, enforceable obligations for the firms best positioned to detect and deter financial crime. Rather than punishing money laundering after the fact, the MLRs impose forward-looking duties, such as conducting business-wide risk assessments and maintaining appropriate systems and controls, on obliged entities within scope. For compliance teams, understanding whether and how the MLRs apply to their firm is a threshold question that shapes the design of the entire AML programme.

It is important to distinguish the MLRs from the substantive criminal money laundering offences, which are addressed in separate primary legislation. The MLRs are secondary legislation that establishes administrative and preventive duties; a failure to meet those duties can expose a firm to supervisory or regulatory consequences, but the Regulations are not the instrument that determines criminal liability for laundering itself. This distinction matters operationally: a control weakness under the MLRs is a compliance and supervisory matter, whereas proof of an underlying offence is a separate legal question governed by different rules.

Because scope, sector applicability, and specific requirements vary and are periodically updated, firms should confirm their obligations against the current text of the Regulations and against guidance from their supervisor, such as the FCA. The MLRs are designed to help detect and deter money laundering and terrorist financing, but no set of regulatory requirements can guarantee prevention; they establish measures to manage and mitigate risk rather than eliminate it. Practitioners should also be careful not to treat the MLRs as equivalent to AML frameworks in other jurisdictions, which diverge in both structure and detail.

Who it's relevant to

Compliance officers and MLROs at obliged entities
For those responsible for a firm's AML programme, the MLRs define many of the preventive obligations that shape their day-to-day work, including business-wide risk assessments and systems and controls. Whether a firm is an obliged entity within scope, and precisely which requirements apply, depends on the type of business and should be confirmed against the current Regulations and supervisory guidance.
Banks, brokers, and insurers
Firms in sectors such as banking, broking, and insurance may fall within the scope of the MLRs and, where they do, are expected to implement measures including risk assessment and appropriate systems and controls. Applicability is not universal across all businesses, so firms should verify their specific position rather than assume coverage.
Supervisory and regulatory teams
Supervisors such as the FCA publish guidance on who the MLRs apply to and what firms need to do, and assess whether obliged entities are meeting their preventive obligations. This supervisory dimension is distinct from the determination of criminal liability, which is governed by separate primary legislation.
Legal and risk professionals advising on scope
Advisers assessing how the MLRs apply must distinguish these administrative and preventive obligations from the substantive criminal money laundering offences in separate legislation, and from AML frameworks in other jurisdictions. Given periodic changes and sector-specific nuances, scope and requirements should be confirmed against the current text of the Regulations and applicable guidance.

Inside MLRs

Customer Due Diligence (CDD) Requirements
The MLRs generally require obliged entities to identify and verify the identity of customers, and to apply the appropriate level of due diligence (standard, simplified, or enhanced) on a risk-sensitive basis. The specific triggers and standards should be confirmed against the current text of the regulations.
Risk Assessment Obligations
Firms within scope are typically required to conduct and document risk assessments, both at the business-wide level and in relation to individual customers and transactions, reflecting the risk-based approach that underpins the regime.
Policies, Controls and Procedures
The MLRs generally require obliged entities to establish and maintain internal policies, controls, and procedures to mitigate and manage money laundering and terrorist financing risks, proportionate to the size and nature of the business.
Enhanced Due Diligence (EDD) Situations
Certain higher-risk scenarios, such as dealings involving politically exposed persons (PEPs) or higher-risk third countries, typically trigger enhanced due diligence measures beyond standard CDD. The precise list of triggers is set out in the applicable regulation.
Scope of Obliged Entities
The MLRs apply to defined categories of regulated businesses (for example, financial institutions and certain designated non-financial businesses and professions). Whether a particular firm or activity is in scope should be checked against the definitions in the regulations, as some activities and entities fall outside them.
Record-Keeping Requirements
Obliged entities are generally required to retain records relating to customer due diligence and transactions for a specified retention period. Exact retention timeframes should be confirmed against the applicable regulation.
Governance and Compliance Function
The regulations typically require firms to have appropriate governance arrangements, which may include the appointment of a compliance officer and/or a nominated officer, together with staff training and internal controls, depending on the firm's size and activities.

Common questions

Answers to the questions practitioners most commonly ask about MLRs.

Are the Money Laundering Regulations the same thing as the Proceeds of Crime Act?
No. The two are distinct instruments that operate together but serve different functions. The Money Laundering Regulations (in the UK, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations) set out the preventive, administrative obligations that obliged entities must build into their systems and controls, such as customer due diligence, risk assessment, record-keeping and the appointment of a nominated officer. The Proceeds of Crime Act, by contrast, contains the substantive criminal money laundering offences and the suspicious activity reporting regime tied to those offences. Compliance failures under the Regulations are generally addressed through supervisory and civil enforcement, whereas the Proceeds of Crime Act deals with criminal liability. Practitioners should treat them as complementary rather than interchangeable and confirm the precise scope of each against the current text.
Do the Money Laundering Regulations apply to every business that handles money?
No. The Regulations apply only to defined categories of obliged entities, typically including credit and financial institutions, certain designated non-financial businesses and professions such as accountants, legal professionals in specified circumstances, trust and company service providers, estate agents, high-value dealers above applicable cash thresholds, and others named in the text. A business that handles money but does not fall within a listed sector or activity is generally outside the scope of the Regulations, even though it may remain subject to the substantive criminal offences under separate legislation. Because the covered sectors, thresholds and activity triggers can change and vary by jurisdiction, the exact scope should always be confirmed against the applicable regulation.
What core controls do the Money Laundering Regulations typically require an obliged entity to have in place?
In many jurisdictions the Regulations generally require obliged entities to maintain a documented, risk-based AML/CFT programme. This typically includes conducting a business-wide risk assessment, applying customer due diligence measures (with enhanced measures in higher-risk situations and simplified measures where permitted), ongoing monitoring of business relationships, record-keeping for prescribed periods, internal policies, controls and procedures, staff training and awareness, and the appointment of individuals responsible for compliance and for handling internal reports. These are measures to detect, deter and manage financial crime risk rather than guarantees of prevention. The precise list of required controls should be verified against the specific text applicable to the entity's sector and jurisdiction.
How do the Regulations interact with the requirement to file suspicious activity reports?
The Regulations and the reporting regime operate on different but connected tracks. The Regulations generally require obliged entities to establish internal reporting procedures and to appoint a nominated officer who receives internal disclosures. The obligation to make an external suspicious activity report, and the point at which suspicion arises, typically derives from the separate criminal-law framework governing money laundering offences rather than from the Regulations themselves. In practice, the controls mandated by the Regulations are what enable staff to identify and escalate concerns, but filing a report reflects a suspicion to be assessed by authorities and does not itself establish that any wrongdoing has occurred. Entities should map both frameworks together when designing escalation procedures.
Who supervises compliance with the Money Laundering Regulations, and what happens on a breach?
Supervision is typically allocated to designated supervisory authorities that vary by sector, for example, a financial services regulator for credit and financial institutions and professional bodies or dedicated supervisors for certain designated non-financial businesses and professions. These supervisors may conduct inspections, request information and take enforcement action for non-compliance, which can range from remediation directions and civil penalties to referral for other proceedings, depending on the regime and the seriousness of the failing. A breach of the Regulations is an administrative or civil compliance matter and is distinct from the commission of a substantive money laundering offence. Exact supervisory allocation and the available sanctions should be confirmed against the applicable regime.
How should an obliged entity keep its programme aligned when the Regulations are amended?
Because the Regulations are periodically amended to reflect changing standards, evolving typologies and updates to related frameworks, entities generally treat AML compliance as an ongoing rather than a one-off exercise. Common practices include monitoring for legislative and supervisory updates, refreshing the business-wide risk assessment when material changes occur, updating internal policies, controls and procedures accordingly, retraining staff on new obligations, and documenting the rationale for changes to demonstrate a defensible, risk-based approach. Entities operating across multiple jurisdictions should also account for divergence between regimes rather than assuming a single global rule. Any specific amendment's requirements and effective dates should be verified against the current published text.

Common misconceptions

The MLRs are the same as the FATF Recommendations, so complying with FATF standards means complying with the MLRs.
The FATF Recommendations are international standards, not binding law. The MLRs are a distinct regulatory instrument that implements AML/CTF obligations within its jurisdiction, and its specific requirements may differ from, or go beyond, the FATF standards. Compliance must be assessed against the actual text of the applicable regulations.
The MLRs impose a single, uniform set of AML rules identical to those in other jurisdictions.
AML regimes diverge across jurisdictions. The MLRs are one jurisdiction's regulatory framework and should not be treated as interchangeable with, for example, the US Bank Secrecy Act and FinCEN rules or the EU AML Directives and AML Regulation. Thresholds, scope, and obligations may differ, and exact values and requirements should be confirmed against the relevant regime.
Applying customer due diligence under the MLRs guarantees that a firm will not be used for money laundering.
CDD and other controls under the MLRs are measures to detect, deter, and manage financial crime risk on a risk-based basis; they do not eliminate that risk or guarantee prevention. The regulations set expectations for reasonable, proportionate measures rather than absolute outcomes.

Best practices

Confirm whether your firm and its specific activities fall within the scope of the MLRs before relying on any obligation or exemption, and document the basis for that determination.
Maintain a documented, up-to-date business-wide risk assessment and align customer- and transaction-level due diligence to it, applying standard, simplified, or enhanced measures on a risk-sensitive basis.
Verify exact thresholds, retention periods, and EDD triggers against the current text of the applicable regulations rather than relying on remembered figures, as these values may change or vary.
Establish and periodically review internal policies, controls, and procedures proportionate to the size and nature of the business, and evidence that they are operating in practice.
Where the MLRs operate alongside other instruments in the same jurisdiction (such as related proceeds-of-crime legislation), map obligations to their correct source so that compliance and criminal-law requirements are not conflated.
Treat CDD outcomes, alerts, and screening matches as risk indicators to be assessed, not as determinations of wrongdoing, and ensure staff training reflects this distinction.