AML Requirements for Accountants in the UK: A CDD Checklist

AML Requirements for Accountants in the UK: A CDD Checklist

UK accountants who provide accountancy, bookkeeping or tax services fall under the Money Laundering Regulations 2017 (MLR 2017). In practice the AML requirements mean registering with an AML supervisor, keeping a written firm-wide risk assessment, completing customer due diligence (CDD) before taking on a client, monitoring clients on a risk-based cycle, training staff and keeping records for five years after the relationship ends.

The AML requirements for accountants in the UK come from the Money Laundering Regulations 2017. Firms must be supervised, assess their own money laundering risk in writing, identify and verify every client and its beneficial owners before work starts, apply enhanced checks to higher-risk clients, monitor clients over time, appoint a nominated officer, train staff and keep records.

AML requirements at a glance

Who supervises accountants for AML

An AML supervisor is the body that registers, monitors and can take action against a firm that breaches its AML requirements. Under regulation 7, auditors, external accountants and tax advisers are supervised by the professional body listed in Schedule 1 that they belong to, such as ICAEW, ACCA, AAT, CIOT or ATT. Those not supervised by a professional body are supervised by HMRC and must register with HMRC as an accountancy service provider. HMRC’s guidance gives bookkeeping, preparing accounts, tax advice and completing tax returns as examples of services that bring a business into scope.

Supervision is changing. HM Treasury has confirmed that the FCA will become the single AML supervisor for professional services, including accountancy service providers currently supervised by professional bodies and HMRC. Until that transfer happens, your current supervisor remains responsible, and the AML requirements below are unchanged.

Risk assessment: firm-wide and client-level

A firm-wide risk assessment is the practice’s written analysis of the money laundering and terrorist financing risks its business faces. Regulation 18 requires it to consider your customers, the countries you deal with, your services, your transactions and your delivery channels, to be kept in writing and up to date, and to be provided to your supervisor on request.

A client risk assessment applies that thinking to one client. Regulation 28(12) says the extent of CDD must reflect the firm’s risk assessment and may differ from case to case. Record for every client:

  • the services you provide and why the client needs them;
  • the client’s sector, and any cash-intensive or high-risk activity;
  • countries involved, including where the owners live;
  • ownership complexity: trusts, overseas companies, nominee arrangements;
  • whether you have met the client or onboarded entirely remotely;
  • PEP and sanctions screening results;
  • a risk rating (low, standard, high) and the reason for it.

CDD, simplified and enhanced due diligence

Customer due diligence sits at the centre of the AML requirements. It means identifying the client, verifying that identity from a reliable independent source, identifying and verifying beneficial owners, and understanding the purpose and intended nature of the relationship (regulation 28). Under regulation 27, you apply CDD when you establish a business relationship, when you suspect money laundering or terrorist financing, and when you doubt documents obtained earlier.

Level When it applies What changes Regulation
Simplified (SDD) You have assessed the relationship as low risk The extent and timing of measures can be adjusted, but you must still monitor enough to detect unusual or suspicious activity 37
Standard CDD Every new business relationship by default Identify and verify client and beneficial owners; understand purpose and nature 27, 28
Enhanced (EDD) High risk identified; a high-risk third country; a PEP or family member or close associate; false or stolen documents; unusually complex or large transactions with no apparent purpose More independent sources, more on ownership and source of funds, closer monitoring 33
PEPs Client or beneficial owner is a politically exposed person, family member or known close associate Senior management approval, establish source of wealth and funds, enhanced ongoing monitoring; domestic PEPs start from a lower risk level 35

If you cannot complete CDD, regulation 31 says you must not establish the relationship, must end any existing one, and must consider whether to make a suspicious activity report.

AML checks for accountants: a CDD evidence checklist by client type

“Verify” in the regulations means checking against documents or information from a reliable source independent of the person, which can include a secure electronic identification process (regulation 28(18) and (19)). The evidence list below is a typical practice approach; your supervisor’s guidance sets how it expects you to meet the AML requirements.

Client type Identify Verify with Also record
Individual or sole trader Full name, date of birth, residential address Photo ID such as a passport or driving licence plus proof of address, or an electronic ID check Trading name and nature of the business
Company or LLP Name, company number, registered office, directors, senior management Companies House record and constitution; regulation 28(3) Beneficial owners holding more than 25% of shares or voting rights, or otherwise controlling it (regulation 5), each verified individually
Partnership Partnership name, partners, business address Partnership agreement or equivalent, ID for relevant partners Who controls the partnership
Trust Trust name, trustees, settlor, beneficiaries or class Trust deed, ID for trustees and controlling persons Source of the trust’s funds
Anyone acting for the client The person and their authority ID for that person and evidence of authority; regulation 28(10) Why they act for the client

Companies House: two checks most guides miss

  1. Regulation 28(9) states you do not meet the beneficial owner requirement by relying only on the Companies House register. Use it as a starting point, then verify.
  2. Before establishing a relationship with a company, regulation 30A requires you to obtain an excerpt of the register (or confirmation that nothing is registered), and to report any material discrepancy between the register and what your CDD finds to Companies House.

For the separate Companies House duty on directors and PSCs to verify their own identity, see our Companies House identity verification checklist.

Ongoing monitoring and refresh cycles

Ongoing monitoring means scrutinising activity during the relationship to check it fits what you know about the client, and keeping CDD records up to date (regulation 28(11)). The AML requirements do not set a fixed refresh period. Regulation 27(8) and (9) require CDD for existing clients at appropriate times on a risk-based approach, including when relevant circumstances change. Many practices set cycles by risk rating in their policy:

Trigger Action
Scheduled review date for the client’s risk rating Re-screen for PEPs and sanctions, confirm details, review the risk rating
New director, shareholder or beneficial owner Identify and verify the new person, update the ownership record
New service, such as payroll or a property transaction Reassess purpose and risk
Activity that does not fit the client’s profile Ask questions, record answers, consider an internal report to the MLRO
Doubts about earlier documents Repeat CDD (regulation 27)

Record keeping: five years

Under regulation 40, keep copies of CDD documents and information, and records sufficient to reconstruct transactions, for five years from the date you know, or have reasonable grounds to believe, the relationship has ended or the transaction is complete. Diary the destruction date when a client leaves, so data is not kept longer than the AML requirements justify.

What can be delegated and what stays with the MLRO

Under regulation 21, a firm must, where appropriate to its size and nature, appoint a senior person responsible for compliance and a nominated officer (often called the MLRO) to receive internal reports and decide on reports to the National Crime Agency. It must tell its supervisor who they are within 14 days. Regulation 24 adds staff training on the AML requirements, with a written record of it.

Regulation 39(7) allows CDD to be carried out through an outsourcing service provider or agent, provided the firm remains liable for meeting the AML requirements. That gives a clear split:

Can be delegated Stays with the firm and MLRO
Requesting and chasing ID documents The firm-wide risk assessment and AML policies
Running electronic ID, PEP and sanctions checks in your chosen tool Each client’s risk rating and the decision to accept
Pulling Companies House records and drafting ownership charts EDD decisions and PEP approvals
Maintaining the CDD tracker and review dates Internal suspicion reports and SAR decisions
Flagging discrepancies and gaps for review Discrepancy reports and dealings with your supervisor

Our article on AML checks for accountants, in-house or outsourced looks at the cost and control trade-offs, and our client onboarding checklist shows where CDD sits in the engagement process, and our guide to the accountant’s engagement letter covers the AML clause clients sign.

FAQs

What are the AML requirements for accountants in the UK?

The AML requirements come from the Money Laundering Regulations 2017. Accountants must be supervised for AML, keep a written firm-wide risk assessment and policies, carry out customer due diligence before taking on clients, apply enhanced checks to higher-risk clients and PEPs, monitor clients over time, appoint a nominated officer, train staff and keep CDD records for five years after the relationship ends.

Who supervises accountants for anti-money laundering?

Accountants who belong to a professional body listed in Schedule 1 of the regulations, such as ICAEW, ACCA or AAT, are supervised by that body. Accountancy service providers without a professional body supervisor must register with HMRC. The government has confirmed the FCA will become the single supervisor for professional services, but current supervisors remain responsible for enforcing the AML requirements until the transfer.

How do you do AML checks for accountants?

Assess the client’s risk, identify the client and any beneficial owners, verify identity using a reliable independent source such as photo ID or an electronic check, screen for PEPs and sanctions, record the purpose of the relationship and a risk rating, and complete this before work starts. Higher-risk clients need enhanced checks, including source of funds.

Can I rely on Companies House for beneficial ownership checks?

Not on its own. Regulation 28(9) of the Money Laundering Regulations 2017 says relying solely on information delivered to Companies House does not satisfy the duty to identify and verify beneficial owners. Use the register as a starting point, verify the individuals yourself, and report any material discrepancy you find to Companies House under regulation 30A.

How often should accountants refresh client due diligence?

The regulations set no fixed period. Regulation 27 requires CDD for existing clients at appropriate times on a risk-based approach and whenever relevant circumstances change, such as a new owner or new service. Most practices set review cycles by risk rating in their AML policy and record each review.

Do the AML requirements apply to bookkeepers?

Yes. HMRC’s guidance gives bookkeeping, preparing accounts, tax advice and completing tax returns as examples of accountancy services that bring a business within the AML requirements. A bookkeeper who is not supervised by a professional body must register with HMRC as an accountancy service provider and then meets the same duties on risk assessment, CDD and records.

How long must accountants keep AML records?

Five years. Regulation 40 requires CDD documents and supporting transaction records to be kept for five years from the date the firm knows, or has reasonable grounds to believe, the business relationship has ended or the occasional transaction is complete. Records of transactions within an ongoing relationship need not be kept beyond 10 years.

Keep CDD current without tying up your seniors

Most of the day-to-day work behind the AML requirements is collecting documents, running checks and keeping review dates on track. Our AML checks support for UK practices does that work in your chosen tools and under your policies, while your MLRO keeps every risk decision. Book a consultation to talk through your CDD backlog.