Skip to content
KEDBYTE
How Money Moves
Chapter
52

Anti-Money-Laundering

Part V · Trust, Failure and the Law|8,420 words|about 37 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

52.0 What this chapter gives you#

  1. You will be able to explain why what gets a criminal caught is almost never the money itself but the story attached to it.
  2. You will be able to work through how a cash business launders by over-reporting its takings, and say why paying income tax on money nobody earned is a cost of laundering rather than a barrier to it.
  3. You will be able to say what job each onboarding question does, so that an eleven-day account opening reads as a set of purposes rather than as obstruction.
  4. You will be able to keep sanctions and money laundering apart in your head: suspicion and reasonableness on one side, absolute prohibition and strict liability on the other.
  5. You will be able to explain why a screening run producing 120 possible matches and two real ones is working correctly, and why better software does not fix it.
  6. You will be able to say why the risk-based approach governs due diligence but never sanctions screening.
  7. You will be able to explain the “more than 25 per cent” beneficial ownership threshold and at least three structures that defeat it while leaving control untouched.
  8. You will be able to describe what happens to a customer’s money after a refused Defence Against Money Laundering request, and how long it can lawfully stay immobilised.
  9. You will be able to explain why a bank exits a whole category of customers whose individual members are fine, and why that makes the underlying problem worse rather than better.
  10. You will be able to read the SARs and enforcement figures and say what the regime actually is: a privately funded intelligence-gathering exercise measured on process rather than on outcomes.

The plain version#

Take a fifty pound note out of your pocket and look at it. There is nothing on it that says where it came from. It does not know whether it was handed over for a week’s wages, given at a birthday, or taken out of a till at knifepoint. A note is a note.

Hold on to that, because everything else follows from it. What gets a criminal caught is almost never the money itself. It is the story attached to the money.

If you turn up at a car showroom with £30,000 in a sports bag, nobody has to test the notes. They just have to ask one question: where did that come from? And you have to have an answer that survives being asked twice. Money laundering, stripped of every long word ever attached to it, is the manufacture of believable answers to that question. Anti-money-laundering is the business of asking it properly.

Here is how the manufacturing works, with real numbers, because the arithmetic is the trick. Imagine a hand car wash on a busy road: five people with sponges and a jet hose, £8 a wash, open seven days. Genuinely, they wash about ninety cars a week. That is £720 of honest takings, nearly all in cash, which is completely ordinary for a car wash.

Now suppose the owner also has £1,680 a week in cash from something illegal. They do not need to hide it. They need to explain it. So each week they write down not ninety washes but three hundred, and bank £2,400 instead of £720. The bank sees a car wash on a busy road banking £2,400 a week. That is believable. Nobody counts cars.

Over a year that is £87,360 of criminal cash with a birth certificate. It has been taxed. It appears in accounts. It can buy a flat. And this is the part people find hardest to accept: the owner will happily pay income tax on money they never earned, because a tax bill is the receipt that proves the story. Paying tax is a cost of laundering, not a barrier to it.

People who do this professionally break it into three moves. First, get the cash into the system at all, the risky part, because cash is heavy, conspicuous, and the one moment where a person and a pile of money are in the same room. Second, move it around enough that the trail becomes hard to follow: car wash to supplier, supplier to a company abroad, company to a loan, loan to a property. Third, spend it on something ordinary, so from then on the money looks like the proceeds of a house sale rather than of a crime.

Every anti-money-laundering rule you have ever been annoyed by exists to interfere with one of those three moves. Which brings us to why opening a bank account takes so long.

Anaya is starting a small import business. The bank asks her for what feels like an absurd amount. Passport. Proof of address. What the business actually does. Expected turnover. Which countries she will trade with. Who else owns shares. Where her opening deposit came from. It takes eleven days, and twice she is asked for something she has already sent.

None of that is the bank being difficult for sport. Each question does a job. Who are you is the easy one, and the least important. What does the business do gives the bank a shape to compare against later: an importer of textiles moving £40,000 a month is unremarkable, and the identical account moving £40,000 a month with no goods attached is not. Who else owns it matters because the person who signs the forms is often not the person who benefits, and the whole point of a shell company is that it puts a stranger’s name on the door. And where the money comes from matters because a plausible source is exactly what a launderer cannot produce without lying, and a lie written down is evidence.

Then the bank runs her name against a list. Not a list of criminals: a list of people and organisations governments have ordered everyone to freeze out entirely. This is a different thing from money laundering and worth separating in your head now. Money-laundering rules say be careful and tell someone if it looks wrong. Sanctions say do not, under any circumstances, move this person’s money, and there is no version of that where being careful is good enough.

The list check is where the system’s most human failure lives, and the arithmetic is unkind. Say the bank takes on 4,000 new customers a week. Its screening software does not look for exact matches, because anyone wanting to evade an exact-match check could do it by dropping a letter. So it looks for near matches: same name spelled differently, name written back to front, a name that sounds the same aloud, a name transliterated from another alphabet where there was never one correct English spelling to begin with. Set the software to be sensitive and it catches more; set it to be strict and it misses things.

Set sensibly, it produces roughly 120 possible matches out of those 4,000. Perhaps two are real. The other 118 are people who share a name, or half a name, with somebody the software has heard of.

That is not a bug you can fix by buying better software. It is a property of names. Hundreds of millions of people share a few thousand very common names, and the software is deliberately built to over-report because the cost of missing one is enormous and the cost of stopping an innocent person for ten minutes is small. So a person with a common name will be stopped, and stopped again at the next bank, and will reasonably conclude the system has something against them personally. It does not. It cannot tell them apart from someone else, and it is not allowed to guess. At eight minutes each, those 118 wrong matches cost about sixteen hours a week to find two real ones. Multiply that across every bank in the country and you have an industry.

Once Anaya’s account is open, the watching starts. Software compares what she actually does against what she said she would do, and against what businesses like hers normally do. A hundred thousand customers might generate two thousand alerts a month. The great majority are nothing: a bonus, an inheritance, a wedding, a house sale, a business that grew. Perhaps forty end up reported to the authorities. And when a bank does decide something looks wrong, it must not tell the customer, because warning someone that they have been reported is itself a criminal offence in the United Kingdom. So the customer gets a delay with no explanation, from staff legally forbidden to explain it. Almost every furious story you have heard about a bank refusing to say why has this at the bottom of it.

The last idea, and the one that governs the rest, is that you cannot do all of this equally to everybody. There is not enough time in the world. So you spend effort where the risk is: light checks on a teenager opening a savings account, heavy checks on a company with owners in four countries and a bank account in a fifth. That is the risk-based approach, and it sounds like common sense because it is. It is also the hardest thing in this chapter to do honestly, because it requires a firm to write down, in advance, which of its own customers it thinks are dangerous.

Where the plain version stops being true#

The system is not primarily a net for catching launderers, and its own numbers say so. The car wash story implies that reports lead to arrests. Some do. But the regime measures firms on process, not outcomes: a firm complies by having systems, applying them and reporting suspicion, and it can do all three impeccably while the money still gets away. The United Nations Office on Drugs and Crime has long estimated that 2 to 5 per cent of global GDP is laundered annually, roughly $800 billion to $2 trillion, with its 2011 study putting the 2009 figure at around $1.6 trillion, or 2.7 per cent. Against that, the United Kingdom Financial Intelligence Unit reported in its SARs Annual Report 2025, covering April 2024 to March 2025, that £382.6 million was denied to suspected criminals through Defence Against Money Laundering requests, a record and a 59 per cent rise on the previous year’s £240.1 million. In the United States, the Bank Policy Institute’s 2018 study Getting to Effectiveness found that surveyed institutions reviewed approximately 16 million alerts in 2017 and filed over 640,000 suspicious activity reports and more than 5.2 million currency transaction reports, and that among institutions recording the data, a median of 4 per cent of those reports drew any follow-up inquiry from law enforcement. Whatever the regime is, it is not a filter with a high hit rate. It is a very large intelligence-gathering exercise, paid for privately, from which a comparatively small number of interventions are extracted.

Identity is the easy half; ownership is the hard half, and the analogy skips it entirely. Verifying that Anaya is Anaya is close to a solved problem. Establishing who actually benefits from a company is not. At the time of writing in August 2026, regulation 5 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 defines the beneficial owner of a body corporate as an individual who exercises ultimate control over its management, or who ultimately owns or controls, directly or indirectly and including through bearer share holdings or by other means, more than 25 per cent of its shares or voting rights, or who otherwise controls it. That “more than 25 per cent” is a bright line, and bright lines are designed around. Four people at 25 per cent each disclose nobody. A chain of five companies across three jurisdictions dilutes an owner below the threshold at every layer while leaving control untouched. Nominee shareholders, discretionary trusts and companies limited by guarantee each break the arithmetic differently. This is why practitioners say ultimate beneficial ownership rather than ownership, and why the honest answer to who owns this company is often a judgement rather than a fact.

“False positive” is the wrong frame for screening, and screening is not part of the risk-based approach at all. A wrong name match is not an error. It is the intended output of a system deliberately tuned to over-report, because the two kinds of mistake are not symmetrical: missing a genuine sanctions target is a strict-liability breach, while stopping an innocent customer is an inconvenience. Every screening system therefore sits on a dial between precision and recall, and the dial is set where the penalties push it. More importantly, the risk-based approach does not apply here. A firm may decide a low-risk customer needs less due diligence. No firm may decide a low-risk customer needs less sanctions screening, because an asset freeze is an absolute prohibition. At the time of writing, section 146 of the Policing and Crime Act 2017, as amended by the Economic Crime (Transparency and Enforcement) Act 2022, allows the Office of Financial Sanctions Implementation to impose a civil monetary penalty where it is satisfied on the balance of probabilities that a breach occurred, and for breaches on or after 15 June 2022 any requirement that the person knew, suspected or believed anything is disregarded. Intention is irrelevant. That is a different legal world from money laundering, where suspicion and reasonableness are everything.

De-risking is not a failure of the risk-based approach; it is a rational response to how the penalties are shaped. A bank does weigh a customer’s risk against their value, but the two sides of that scale are measured in different units. The revenue from a small money-transfer business serving one remittance corridor is bounded and known. The downside is an enforcement action, a skilled person’s report, a criminal investigation and a number in the press: the Financial Conduct Authority stated when fining Nationwide Building Society £44,078,500 in December 2025 that since 2021 it had imposed thirteen fines totalling £300,767,526 on banks for anti-money-laundering systems and controls failings. Against an unbounded and asymmetric downside, exiting an entire customer category is the cheapest available answer even when the individual customers are fine. The consequence lands hardest on those with least ability to complain, and it is a policy problem rather than a compliance one.

The technical version#

On dating#

Every figure, threshold, list and rule below is stated as accurate at the time of writing, in August 2026, and this is the fastest-moving corner of regulation covered in this book. Three things were in motion as it was written: the United Kingdom’s Money Laundering and Terrorist Financing (Amendment) Regulations 2026 came into force on 30 June 2026 with two later commencement dates still ahead of it, the European Union’s single rulebook does not apply until 10 July 2027, and OFSI had announced an intention to double its maximum civil penalty without the statutory cap yet changing. Check the primary sources before relying on any number here.

The offences that drive the machine#

In the United Kingdom the regulatory architecture rests on criminal law, and the criminal law came first. Part 7 of the Proceeds of Crime Act 2002 creates the principal offences: concealing, disguising, converting, transferring or removing criminal property under section 327; entering into or becoming concerned in an arrangement facilitating another’s acquisition, retention, use or control of criminal property under section 328; and acquiring, using or possessing criminal property under section 329. Criminal property is defined by reference to a person’s benefit from criminal conduct, with no minimum amount and no separate list of predicate offences: if the underlying conduct would be an offence in the United Kingdom, its proceeds are criminal property, however small.

Two further offences shape day-to-day behaviour more than the principal ones. Sections 330 and 331 create the offence of failing to disclose knowledge or suspicion arising in the course of regulated-sector business, with equivalents at sections 19 and 21A of the Terrorism Act 2000. Section 333A creates the tipping-off offence and section 342 the offence of prejudicing an investigation, with equivalents at sections 21D and 39 of that Act. The National Crime Agency states, at the time of writing, that the penalties on conviction on indictment for failing to disclose are up to five years’ imprisonment, a fine, or both. This is why “we are unable to discuss the reason for this decision” is a legal formula rather than rudeness.

The defence matters as much as the offence. A person who would otherwise commit a principal offence can obtain a defence by making an authorised disclosure and obtaining appropriate consent: in practice, the Defence Against Money Laundering request, or DAML. Under section 335 the National Crime Agency has seven working days beginning with the first working day after disclosure in which to refuse consent. If it refuses, a moratorium period of 31 days runs, during which the prohibited act must not be done. Section 336A allows a court, on application by a senior officer, to extend that moratorium by up to 31 days at a time where an investigation is being conducted diligently and expeditiously, but subsection (7) caps further extensions so the total cannot exceed 186 days beginning with the day after the end of the initial 31-day period. A customer’s funds can therefore be lawfully immobilised for over half a year on suspicion, with no obligation on anyone to explain why.

Section 339A sets a threshold below which deposit-taking bodies, electronic money institutions and payment institutions may operate an account without seeking a DAML. That threshold was raised from £250 to £1,000 by legislation introduced in January 2023, and the UKFIU attributes the subsequent flattening of DAML volumes partly to that change.

The regulations that make it a system#

The criminal law tells a firm what it must not do. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, now maintained under sections 49 and 54(2) of, and Schedule 2 to, the Sanctions and Anti-Money Laundering Act 2018, tell it what it must build.

At the time of writing, the most recent substantial change is the Money Laundering and Terrorist Financing (Amendment) Regulations 2026, S.I. 2026/621, made on 9 June 2026, most of it in force 21 days later on 30 June 2026. Two parts commence later: regulation 20, inserting a new regulation 34A on enhanced due diligence for cryptoasset exchange providers and custodian wallet providers in correspondent relationships, on 1 February 2027; and regulation 37, substituting Schedule 6B on changes in control of registered cryptoasset businesses, for most purposes on 25 October 2027. The instrument implements the Government’s response to HM Treasury’s 2024 consultation Improving the effectiveness of the Money Laundering Regulations, published on 17 July 2025, and its direction is broadly deregulatory.

Its most visible change is arithmetical: every euro-denominated threshold on the face of the Regulations was converted to sterling, and not always at par.

Provision Subject Before After
Reg. 27(1)(b) Occasional transaction, currency exchange or money transmission €1,000 £800
Reg. 27(2) Occasional transaction, general threshold €15,000 £12,000
Reg. 27(3) Occasional transaction, high value dealers and others €10,000 £10,000
Reg. 27(5), (7) Casino and related transactions €2,000 £2,000
Reg. 14 High value dealers, casinos, auction platforms, art market participants €10,000 £10,000
Reg. 38(1), (2) Electronic money, simplified due diligence and redemption limits €150, €50 £150, £50
Regs. 64C(4), 64G(1)(b) Transfers of funds, information requirements €1,000 £800

Three other changes matter more than they look. The phrase “complex or unusually large” in regulations 19 and 33 became “unusually complex or unusually large in each case given the nature of the transaction”, a deliberate narrowing: a transaction is no longer high risk merely because it is structurally complicated. A new regulation 30ZA lets a credit institution open an account for a customer of a failed bank, and allow transactions from it, before completing due diligence, provided the customer is identified under regulation 28(2)(a) and the relationship begins within 30 days of the bank insolvency order. And a new block at regulation 29(10) to (18) governs pooled client accounts, requiring the firm to understand the account’s purpose and proposed use, be satisfied this is consistent with what it knows of the customer, assess and mitigate the resulting risk, and demonstrate all of it to its supervisor. It also binds the customer, who must on request identify the persons whose money is held and their beneficial owners, keep written records of every payment in and out for five years, and provide information to law enforcement, subject to legal professional privilege.

Customer due diligence and beneficial ownership#

Regulation 27 sets the triggers: establishing a business relationship, an occasional transaction above the applicable threshold, suspicion of money laundering or terrorist financing, and doubts about documents or information previously obtained. Regulation 28 sets the content: identify the customer and verify their identity from a reliable source independent of the customer; identify any beneficial owner and take reasonable measures to verify their identity so the firm is satisfied it knows who they are; where the customer is a legal person, understand its ownership and control structure; and assess the purpose and intended nature of the relationship. Regulation 28(11) requires ongoing monitoring, including scrutiny of transactions for consistency with knowledge of the customer and keeping information up to date.

Two misreadings deserve naming. Verification is not document collection: a passport photocopy verifies nothing unless the firm has satisfied itself the document is genuine and belongs to the person presenting it. And know your customer is not a one-off event at onboarding; regulation 28(11)'s ongoing obligation is what enforcement actions most often find missing, because the burden of periodic review across a large book is enormous and the incentive to defer it constant. Record-keeping runs under regulation 40: five years from the date the firm knows or has reasonable grounds to believe the relationship ended, after which regulation 40(5) requires deletion of the personal data unless another legal basis applies.

On ownership, regulation 5 covers bodies corporate and regulation 6 partnerships and trusts. The 25 per cent threshold in regulation 5(1)(b) is the number practitioners quote, but the limbs either side of it matter as much: an individual exercising ultimate control over management, and an individual who otherwise controls the body, are beneficial owners regardless of shareholding. Where none can be identified after all reasonable measures, the senior person responsible for managing the body may be treated as such, a fallback that should be rare and is not.

The public registers are the second leg. The United Kingdom’s register of people with significant control, at Companies House, uses a threshold aligned to 25 per cent, and regulation 30A requires relevant persons to report discrepancies between what a customer tells them and what the register says. Register quality was for years the weak point, and the Economic Crime and Corporate Transparency Act 2023 is the response: at the time of writing, identity verification became a legal requirement for directors and people with significant control from 18 November 2025, with new people with significant control required to verify within 14 days of their appointment being notified. This does not solve the ownership problem, but it changes the cost of lying about it from nothing to something.

Enhanced due diligence#

Regulation 33 sets out when enhanced customer due diligence and enhanced ongoing monitoring are mandatory, and the 2026 amendment made one materially important change. Previously regulation 33(1)(b) bit on relationships and transactions involving a “high-risk third country” as separately defined. From 30 June 2026 it bites on a “FATF call for action country”, defined by reference to the Financial Action Task Force’s list of High-Risk Jurisdictions subject to a Call for Action as it has effect from time to time. At the FATF plenary of 19 June 2026 that list comprised the Democratic People’s Republic of Korea, Iran and Myanmar. The separate list of Jurisdictions under Increased Monitoring, informally the grey list, no longer triggers mandatory enhanced due diligence in the United Kingdom, though FATF mutual evaluations remain a geographical risk factor under regulation 33(6)(c) and a firm must still apply enhanced measures wherever it identifies high risk. HM Treasury’s Money Laundering Advisory Notice of June 2026 sets out the position.

Politically exposed persons sit at regulation 35. The definition at regulation 35(12)(a) is an individual entrusted with prominent public functions other than as a middle-ranking or more junior official, with a non-exhaustive list at regulation 35(14) running from heads of state and government, ministers and legislators through senior judiciary, central bank boards, ambassadors and high-ranking armed forces officers to the boards of state-owned enterprises and international organisations. Family members include spouses and civil partners, children and their spouses or civil partners, and parents. Known close associates covers joint beneficial ownership or other close business relations, and sole beneficial ownership of an entity known to have been set up for the PEP’s benefit, with regulation 35(15) limiting the enquiry to information in the firm’s possession or credible publicly available information.

Where a PEP relationship is proposed or continued, regulation 35(5) requires senior management approval, adequate measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. The two sources are not synonyms, and conflating them is a common finding: source of wealth explains how the person’s total assets were accumulated, source of funds where the money in this transaction came from. Regulation 35(9) requires the enhanced measures to continue for at least 12 months after the person ceases to be entrusted with the function, or longer if the firm considers it appropriate; regulation 35(11) provides that they fall away for family members and close associates when the PEP ceases to hold the function, whether or not that period has run.

Domestic PEPs are treated distinctly. Section 77 of the Financial Services and Markets Act 2023 required the Treasury to amend Part 3 of the Money Laundering Regulations so that where the customer is a domestic PEP, or a family member or known close associate of one, the starting point for the regulation 35(3) assessment is that they present a lower level of risk than a non-domestic PEP, and where no enhanced risk factors are present the extent of enhanced measures is less. That is now regulation 35(3A), with enhanced risk factors defined at regulation 35(12)(f) as risk factors other than the domestic PEP status itself. Section 78 required the FCA to review its PEP guidance and publish conclusions within twelve months. Its multi-firm review of 18 July 2024 found firms using definitions of relatives and close associates wider than the Regulations allow, ineffective arrangements for reassessing status after a person leaves office, risk ratings without clear rationale, and poor communication with affected customers. Finalised guidance FG25/3 followed on 7 July 2025, revised on 15 July 2025 to clarify that non-executive board members of United Kingdom civil service departments should not be treated as PEPs.

Simplified due diligence sits at regulation 37 and is permitted only where the firm has determined the relationship or transaction presents a low degree of risk, having taken account of the risk factors in Schedule 3. The 2026 amendment extended regulation 37(2)(a) to cover the new pooled account provisions at regulation 29(11) to (13), which was the point of that reform: making clear when simplified measures may be applied to accounts holding many clients’ money.

Sanctions screening#

Sanctions compliance is legally separate from anti-money-laundering compliance, and the vocabulary should stay separate too. In the United Kingdom, designations are made under regulations issued pursuant to the Sanctions and Anti-Money Laundering Act 2018. At the time of writing, and this is a recent change that will catch out any process built before it, the UK Sanctions List maintained by the Foreign, Commonwealth and Development Office is the single authoritative list of designations: the OFSI Consolidated List of Asset Freeze Targets closed on 28 January 2026 and is no longer updated. Any screening system still pointed at the old file is reading a frozen snapshot.

The Office of Financial Sanctions Implementation enforces financial sanctions. Under section 146 of the Policing and Crime Act 2017 as amended, and as set out in OFSI’s Financial sanctions enforcement and monetary penalties guidance last updated on 9 February 2026, the maximum civil monetary penalty is the greater of £1,000,000 or 50 per cent of the estimated value of the funds or economic resources involved, or £1,000,000 where no value can be estimated. OFSI has stated an intention to seek to double this to the greater of £2,000,000 or 100 per cent of the breach value; at the time of writing that had been announced but the statutory cap was unchanged. Relevant firms must also notify HM Treasury where they know or have reasonable cause to suspect that a person is designated or has breached a prohibition, and where they hold frozen assets.

The United States position reaches further. The Office of Foreign Assets Control maintains the Specially Designated Nationals and Blocked Persons list and applies its 50 Percent Rule, under which an entity owned in the aggregate, directly or indirectly, 50 per cent or more by one or more blocked persons is itself blocked whether or not it appears on any list. That is why ownership analysis and sanctions screening cannot be separate workflows: an entity can be blocked without ever being named.

The screening itself is a name-matching problem with unusual properties. Names arriving from customer records are not canonical: the same person may appear with given and family names reversed, with or without patronymics, with diacritics stripped, transliterated from Arabic, Cyrillic, Chinese or Korean by any of several competing conventions, abbreviated, or misspelled. Matching engines therefore combine exact matching with phonetic algorithms, edit-distance measures and token-based comparison, each returning a score, with a configurable threshold above which an alert is raised. Lower the threshold and recall rises while precision falls; raise it and the reverse. No setting gives both, and the threshold is a risk decision a supervisor will ask to see justified.

What reduces alert volumes without reducing detection is secondary identifiers and good data. Date of birth, place of birth, nationality, passport or national identity number and full address, held in structured fields rather than free text, let an engine discount a name match that is impossible on other grounds; list entries carry these to varying degrees, and the poorest-quality entries generate the most noise. Commonly cited industry estimates put the share of alerts closed with no report at between 85 and 95 per cent, but those figures come from vendors and industry bodies rather than regulators and should be treated as indicative. The cost also falls unevenly: common names in large populations, and naming conventions producing many identical full names, concentrate screening burdens on particular ethnic and national groups without anyone having designed that outcome. A firm that does not measure alert rates by customer segment will not know it is happening.

Transaction monitoring and suspicious activity reporting#

Regulation 28(11) requires ongoing monitoring; how it is done is left to the firm. In practice there are two families of approach and mature firms run both.

Rules-based monitoring encodes typologies as deterministic tests: cash deposits aggregating above a value in a rolling window, rapid movement in and out leaving a near-zero balance, transactions structured just below a reporting threshold, activity inconsistent with the stated business, payments to jurisdictions the firm has rated high risk, or sudden dormancy reversal. Rules are explainable, testable and auditable, which regulators like, and trivially avoidable by anyone who learns the thresholds, which is their weakness. Model-based monitoring scores behaviour against learned baselines, per customer or per peer group, and surfaces the anomalous. It catches patterns nobody wrote a rule for, at the cost of two problems: the firm must explain to a supervisor why a model produced a given output, and a model trained on historically labelled data learns the biases in that labelling. Above-the-line and below-the-line testing and documented calibration are standard supervisory expectations rather than sophistication.

When suspicion arises, the firm’s nominated officer, appointed under regulation 21(3) and known in FCA-regulated firms as the money laundering reporting officer, decides whether to report. In the Senior Managers and Certification Regime this is senior management function SMF17, a named individual with personal accountability. The report goes to the UK Financial Intelligence Unit at the National Crime Agency through the SAR Portal. From the SARs Annual Report 2025, covering April 2024 to March 2025:

Measure 2023-24 2024-25
SARs received 872,048 866,616
DAML requests received 57,081 57,666
Funds denied through DAML requests £240.1m £382.6m
Account freezing orders, forfeitures and restraints obtained through DAMLs 1,785 2,048
Terrorism Act SARs received 1,132 1,101
Defence Against Terrorist Financing requests 406 397
Reported SAR confidentiality breaches 8 7

Two further figures bear on how the system behaves. The average turnaround for a DAML decision was 2.8 days against the statutory seven working day period; and 151 refused cases required one or more moratorium extensions under section 336A, involving 18 law enforcement agencies and denying £120.6 million, of which £103 million came from a single DAML. The headline totals are heavily influenced by a few large cases, which is why the UKFIU publishes a three-year rolling average alongside them: £298.4 million for the period ending 2024-25.

The distribution by sector is equally telling. Of SARs submitted through the SAR Portal in 2024-25, banking accounted for 85.54 per cent and financial services a further 10.34 per cent, with virtual assets at 1.67 per cent, gambling 0.88 per cent, accountancy 0.71 per cent, legal 0.40 per cent and property 0.10 per cent. The UKFIU is careful to say it is for each sector and its supervisor to judge whether that volume is proportionate to risk. It is nonetheless clear that the overwhelming majority of the United Kingdom’s financial intelligence comes from banks, which means anything a bank cannot see is largely invisible to the system.

The United States regime under the Bank Secrecy Act is more mechanical. Under 31 CFR 1020.320 a bank must file a suspicious activity report no later than 30 calendar days after initial detection of facts that may constitute a basis for filing, with an additional 30 where no suspect has been identified, and may not disclose the report or anything revealing its existence. Alongside it sits the currency transaction report for cash above $10,000, a threshold report rather than a suspicion report, with a corresponding offence of structuring to evade it.

The risk-based approach#

The risk-based approach is FATF Recommendation 1, and it is not permission to do less. It is an instruction to allocate effort in proportion to assessed risk, which requires a firm to have assessed risk in writing. In the United Kingdom that is regulation 18, requiring a written risk assessment that takes account of information from supervisors and considers risk factors relating to customers, countries, products, services, transactions and delivery channels, and regulation 19, requiring policies, controls and procedures proportionate to that assessment and approved by senior management.

The national layer sits above it. HM Treasury and the Home Office published the National Risk Assessment of Money Laundering and Terrorist Financing 2025 on 17 July 2025, the fourth comprehensive United Kingdom assessment. It rates retail banking, money service businesses, and payment and electronic money institutions as high risk for both money laundering and terrorist financing, and cryptoasset service providers as high for money laundering and medium for terrorist financing. It assesses that trade-based schemes move over £10 billion, and describes a realistic possibility that up to £10 billion could be laundered through the United Kingdom property market annually. A firm’s regulation 18 assessment is expected to engage with those findings, not restate them.

Internationally the emphasis has shifted. In February 2025 the FATF revised Recommendation 1 and its Interpretive Note to strengthen the requirement that controls be proportionate and to encourage countries to promote financial inclusion, and later published Guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures. The FATF is explicit, including in the standing text accompanying its increased-monitoring list, that its standards do not envisage de-risking or cutting off entire classes of customer, and that flows for humanitarian assistance, legitimate non-profit activity and remittances should be neither disrupted nor discouraged. That followed its February 2021 project on the unintended consequences of the standards, which led in 2023 to amendments to Recommendation 8 curbing disproportionate measures against non-profit organisations.

Correspondent banking and de-risking#

A correspondent relationship is one bank providing services, typically an account and payment execution, to another bank in another jurisdiction. It is the mechanism by which a bank in a small economy reaches the dollar, the euro or sterling at all.

The due diligence is heavier than for an ordinary customer because the correspondent takes on not just the respondent but, indirectly, the respondent’s entire customer base. Regulation 34 requires a firm entering a correspondent relationship with a respondent from outside the United Kingdom to gather sufficient information to understand its business fully, determine its reputation and the quality of its supervision from credible public sources, assess its financial crime controls, obtain senior management approval, and document the respective responsibilities. Relationships with shell banks are prohibited outright, as is continuing one with an institution known to allow its accounts to be used by a shell bank. From 1 February 2027 the new regulation 34A extends materially the same requirements to cryptoasset exchange providers and custodian wallet providers dealing with third-country providers of similar services. The standard instrument for gathering this information is the Wolfsberg Group’s Correspondent Banking Due Diligence Questionnaire, at the time of writing at version 1.4, with the Group’s FAQs recommending a refresh cycle of 12 to 18 months.

The pattern in the data is a long, uneven contraction. The Committee on Payments and Market Infrastructures at the Bank for International Settlements publishes a quantitative review of correspondent banking data; its August 2020 commentary reported that the number of active correspondents worldwide had declined by about 22 per cent between 2011 and 2019 and by about 3 per cent in 2019 alone, with country-level declines ranging from 23 per cent in advanced economies to 41 per cent in small island developing states and dependent territories, and regional declines over the same period from 13 per cent in Northern America to 34 per cent in Latin America. Meanwhile the value and volume of payments running through those networks kept growing, by roughly 5 and 4 per cent respectively in the final year measured. Fewer relationships carrying more traffic is concentration, not shrinkage, and concentration means a single correspondent’s exit can disconnect a jurisdiction.

The consequences for smaller markets are structural. Where a country loses its last correspondent for a currency, payments must route through an additional intermediary, raising cost, lengthening settlement and reducing transparency. The National Risk Assessment 2025 records a rise in nesting, where correspondent banks hold accounts for other correspondent banks so the chain becomes longer and more opaque, and attributes this partly to de-risking. That is how de-risking makes the underlying problem worse: the flows do not stop, they move somewhere with less visibility. The same report notes that de-risking of non-profit organisations, combined with the absence of formal banking where they operate, pushes them towards cash and less well-regulated channels. The Financial Stability Board launched a four-point action plan in November 2015 to address the decline, and correspondent banking remains part of the G20 cross-border payments roadmap, but none of it changes the arithmetic facing a bank weighing bounded revenue against unbounded liability.

Supervision, enforcement and what will date this chapter#

The United Kingdom’s supervisory architecture is fragmented. The FCA supervises banks, payment institutions, electronic money institutions and registered cryptoasset businesses. His Majesty’s Revenue and Customs supervises money service businesses, trust or company service providers, high value dealers, art market participants, and estate agency and accountancy businesses not otherwise supervised. Professional body supervisors cover the legal and accountancy sectors, overseen by the Office for Professional Body Anti-Money Laundering Supervision within the FCA. The Gambling Commission supervises casinos.

Enforcement inside the FCA’s perimeter is generally brought under the Principles for Businesses rather than the Regulations, most often Principle 3 on management and control systems. The Nationwide Building Society case of December 2025 is representative of both mechanics and amounts: £44,078,500, reduced by 30 per cent from £62,969,297 for early resolution, for inadequate anti-financial-crime systems and controls between October 2016 and July 2021, specifically ineffective arrangements for keeping due diligence and risk assessments current across personal current account customers and for monitoring their transactions. The pattern across such cases is instructive: the failings are almost never an absence of policy. They are failures to apply it at scale, to keep customer information current, to tune monitoring to the actual business, and to close the loop between an alert and a decision.

The European Union is moving the opposite way. Regulation (EU) 2024/1624, the single rulebook, applies directly in all Member States from 10 July 2027, with Directive (EU) 2024/1640 to be transposed by the same date and Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, based in Frankfurt and operational since 1 July 2025, expected to begin directly supervising a small group of the highest-risk cross-border institutions from 2028.

Four things here will date, and a reader in 2029 should verify all of them. The United Kingdom’s Regulations are mid-reform: the 2026 amendment has commencement dates still ahead of it, on 1 February 2027 and 25 October 2027, and HM Treasury committed in July 2025 to further guidance on the meaning of establishing a business relationship, when source of funds checks are required, and when enhanced due diligence is mandatory. The lists move by design: FATF updates its at each plenary, roughly three times a year, and the United Kingdom’s mandatory trigger now tracks the call for action list as it has effect from time to time, while the UK Sanctions List became the single authoritative designation list on 28 January 2026. OFSI’s announced doubling of its civil penalty maximum had not taken effect as this was written, and the FCA enforcement figure was current at December 2025. And the European regime has not yet started, so the comparison drawn here between a deregulating United Kingdom and a harmonising European Union is a hypothesis that will by then have been tested.

52.98 Common wrong ideas#

Wrong: Laundering is about hiding money. Right: It is about explaining it; the car wash owner does not conceal the criminal cash but manufactures a believable answer to where it came from, and pays tax on it because the tax bill is the receipt that proves the story.

Wrong: The anti-money-laundering regime is a net for catching launderers. Right: Firms are measured on process rather than outcomes and can comply impeccably while the money still gets away; the published numbers describe a very large privately funded intelligence-gathering exercise from which comparatively few interventions are extracted.

Wrong: A wrong name match is an error to be engineered away. Right: It is the intended output of a system deliberately tuned to over-report, because missing a genuine sanctions target is a strict-liability breach while stopping an innocent customer for ten minutes is an inconvenience.

Wrong: A low-risk customer can be given lighter sanctions screening. Right: The risk-based approach governs due diligence only; an asset freeze is an absolute prohibition, and for breaches on or after 15 June 2022 any requirement that the person knew, suspected or believed anything is disregarded.

Wrong: Knowing who the customer is settles the identity question. Right: Identity is the easy half; the “more than 25 per cent” bright line is designed around by four holders at 25 per cent each, by chains of companies across jurisdictions, and by nominees, trusts and companies limited by guarantee.

Wrong: Collecting a passport copy verifies identity. Right: Verification requires the firm to satisfy itself from a source independent of the customer that the document is genuine and belongs to the person presenting it.

Wrong: Know your customer is something you complete at onboarding. Right: Regulation 28(11) makes scrutiny of transactions and keeping information up to date a continuing obligation, and it is the limb enforcement actions most often find missing.

Wrong: Source of wealth and source of funds are two phrases for the same check. Right: Source of wealth explains how the person’s total assets were accumulated and source of funds where the money in this transaction came from, and conflating them is a common finding.

Wrong: The bank is being obstructive when it refuses to explain a delay. Right: Tipping off is a criminal offence in the United Kingdom, so the staff facing the customer are legally forbidden to explain, which is at the bottom of almost every furious story of this kind.

Wrong: De-risking shows a firm has failed to apply the risk-based approach. Right: It is a rational answer to bounded revenue weighed against an unbounded and asymmetric downside, and its effect is that flows move somewhere with less visibility rather than stopping.

52.99 Chapter summary in 20 lines#

  1. A banknote carries nothing to say where it came from, so what catches a criminal is the story attached to the money rather than the money itself.
  2. Money laundering is the manufacture of believable answers to the question “where did that come from”, and anti-money-laundering is the business of asking it properly.
  3. A cash business launders by writing down more takings than it had, and its owner will happily pay tax on money never earned, because the tax bill is the receipt.
  4. The three moves are getting the cash in, moving it around until the trail is hard to follow, and spending it on something ordinary.
  5. Every rule you have been annoyed by exists to interfere with one of those three moves, which is why opening a business account takes eleven days.
  6. Each onboarding question does a job: who you are, what the business does, who else benefits, and where the opening money came from.
  7. Identity is the easiest of those and the least important; establishing who ultimately benefits is a judgement rather than a fact.
  8. Sanctions screening is a legally separate world from money laundering, with absolute prohibition and strict liability where the other has suspicion and reasonableness.
  9. Screening deliberately looks for near matches, so a bank taking on four thousand customers a week may see roughly 120 possible matches of which perhaps two are real.
  10. That is a property of names rather than a defect in software, and its cost falls unevenly on people whose naming conventions produce many identical full names.
  11. Once the account is open, monitoring compares behaviour against what the customer said and against what similar businesses do, and the great majority of alerts are ordinary life.
  12. When a firm reports, it must not tell the customer, because tipping off is itself an offence, which explains the unexplained delay.
  13. The architecture rests on Part 7 of the Proceeds of Crime Act 2002, whose principal offences sit at sections 327 to 329 and whose day-to-day grip comes from the failure to disclose and tipping-off provisions.
  14. The Defence Against Money Laundering process gives the National Crime Agency seven working days to refuse, after which moratorium extensions can lawfully immobilise funds for over half a year on suspicion alone.
  15. The Money Laundering Regulations 2017, as amended in 2026, set out what a firm must build: written risk assessment, due diligence, enhanced measures, ongoing monitoring, record-keeping and reporting.
  16. The 2026 amendment converted euro thresholds to sterling, narrowed “complex or unusually large”, added rules for pooled client accounts and moved the mandatory enhanced due diligence trigger onto the FATF call for action list.
  17. Transaction monitoring runs on rules, which are explainable and avoidable once the thresholds are known, and on models, which find what nobody wrote a rule for and must still be explained to a supervisor.
  18. Banking supplies about 85 per cent of the United Kingdom’s suspicious activity reports, so anything a bank cannot see is largely invisible to the system.
  19. Enforcement finds failures to apply policy at scale rather than absent policy, and against penalties measured in tens of millions banks exit whole customer categories.
  20. De-risking does not stop the flows; it lengthens the chain through nesting and pushes activity towards cash and less regulated channels, which is a policy problem rather than a compliance one.

Sources, all consulted in August 2026: the Proceeds of Crime Act 2002, sections 327 to 333A, 335, 336A, 339A and 342; the Terrorism Act 2000; the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 as amended by S.I. 2026/621; the Sanctions and Anti-Money Laundering Act 2018; sections 77 and 78 of the Financial Services and Markets Act 2023; section 146 of the Policing and Crime Act 2017 as amended; the Economic Crime and Corporate Transparency Act 2023 and Companies House identity verification guidance; 31 CFR 1020.320; the UKFIU SARs Annual Report 2025; the National Risk Assessment of Money Laundering and Terrorist Financing 2025; HM Treasury’s Money Laundering Advisory Notice of June 2026; the FCA, including FG25/3, the 2024 multi-firm review on politically exposed persons and the Nationwide announcement of December 2025; OFSI’s financial sanctions enforcement and monetary penalties guidance; the FCDO UK Sanctions List; the Financial Action Task Force, including the June 2026 plenary lists, the February 2025 revision to Recommendation 1 and the financial inclusion guidance; BIS CPMI correspondent banking commentaries; the Financial Stability Board; the Wolfsberg Group CBDDQ v1.4; Regulations (EU) 2024/1620 and 2024/1624 and Directive (EU) 2024/1640; the United Nations Office on Drugs and Crime; and the Bank Policy Institute, Getting to Effectiveness, 2018.