AML checks for accountants can be run in-house or handed to an outsourced team, but the legal duty never moves: under the Money Laundering Regulations 2017 your practice stays liable for any failure in customer due diligence, even when someone else does the legwork. What you can outsource is the preparation: collecting documents, running identity and sanctions screening, and building the file. The risk decision, the sign-off and any suspicion report stay with you.
UK accountants may use an agent or outsourcing provider to carry out customer due diligence, provided the contract keeps the practice liable for any failure (MLR 2017, regulation 39(7)). Keep the risk assessment, the decision to accept the client and the nominated officer role in-house, and delegate the repeatable verification work.
Key points
- Identity must be verified before the business relationship starts, with a narrow exception for low-risk cases (regulation 30).
- Outsourcing CDD is expressly allowed, but liability stays with the practice (regulation 39).
- Agents doing AML work for you must be trained in money laundering law and data protection (regulation 24).
- CDD records are kept for five years after the relationship ends (regulation 40).
- The real cost of in-house checks is senior time, not software.
Terms used in this guide
- CDD (customer due diligence): identifying and verifying the client, any beneficial owner and anyone acting for them, and understanding the purpose of the relationship (regulation 28).
- EDD (enhanced due diligence): extra checks for higher-risk clients, such as politically exposed persons or clients linked to high-risk countries (regulation 33).
- Nominated officer (MLRO): the individual your firm appoints to receive internal suspicion reports and decide whether to report to the National Crime Agency (regulation 21(3)).
- Outsourcing service provider: a third party carrying out CDD steps on your behalf under a contract, as distinct from reliance on another regulated firm’s checks.
What AML checks for accountants involve
Regulation 28 sets the core of AML checks for accountants: identify the client and verify that identity, identify the beneficial owners and take reasonable measures to understand the ownership and control structure, and assess the purpose and intended nature of the work. For a company client you must also obtain its name, registration number, registered office, the names of the board and the senior persons responsible for its operations.
On top of the client-level checks, every supervised practice needs a firm-wide risk assessment, written policies, staff screening and training, and ongoing monitoring of existing clients. Our separate guide to AML requirements for accountants covers those duties and a CDD evidence list by client type. This post focuses on one practical question: who in your practice, or outside it, should do the work.
Who stays liable when you outsource
Regulation 39(7) says nothing in the regulations prevents a firm applying CDD measures “by means of an agent or an outsourcing service provider”, as long as the arrangement leaves the firm liable for any failure. In plain terms, outsourcing changes who opens the documents, not who answers to your supervisor.
That has three consequences for the engagement. First, the contract with the provider should state that the practice retains responsibility and sets the procedure. Second, the provider’s staff are your agents for training purposes under regulation 24, so they need training on UK money laundering law and data protection, with records kept. Third, any suspicion goes straight to your nominated officer. A provider should never decide whether something is reportable, and must never discuss a suspicion with the client.
The supervisor’s view is set out in HMRC’s guidance on your responsibilities under the Money Laundering Regulations. If you are supervised by a professional body, its own guidance applies in the same way.
In-house vs outsourced AML checks: a side-by-side comparison
Most practices start running AML checks for accountants in-house because the work appears free. The table compares the two models on the points a supervisor or a partner would ask about.
| Factor | In-house | Outsourced |
|---|---|---|
| Legal liability | Practice | Practice (regulation 39(7)) |
| Who collects ID and documents | Admin staff, managers or partners | Provider, using your procedure and tools |
| Risk rating and client acceptance | Practice | Practice |
| Suspicion reporting | Nominated officer | Nominated officer; the provider flags concerns only |
| Training records | Your staff | Your staff and the provider’s team |
| Main cost | Senior hours, interruptions, delayed starts | Provider fee plus your review time |
| Consistency | Varies with workload | Same checklist every time, if the provider is managed well |
| Peak capacity | Limited by headcount | Can absorb onboarding spikes |
The hidden cost of in-house checks
When a manager runs ID checks, chases proof of address and screens names against the UK sanctions list, that time comes out of review and advisory work. A thorough check on a limited company with several directors and a layered shareholding can take well over an hour once the chasing is counted. Squeezed between deadlines, shortcuts creep in, and the file your supervisor eventually asks for is thinner than it should be.
Common gaps in in-house AML checks for accountants
When AML checks for accountants are done between other jobs, the same weaknesses tend to show up in file reviews. None of them needs a qualified accountant to fix; they need a consistent process and someone with time to run it.
- No recorded purpose. The file holds a passport and a utility bill but nothing explaining what the client wants from the practice, which regulation 28 requires.
- Beneficial owners missing. The director is verified, but the shareholder behind a holding company is not.
- Undated screening. Sanctions and PEP results are not saved, so there is no proof the check happened before work began.
- No refresh date. Existing clients are never revisited, so changes in ownership go unnoticed.
Outsourced AML checks for accountants fix these gaps only if the provider works to a written checklist and your reviewer sees every file before acceptance.
Six steps to run AML checks for accountants with outsourced support
This is the split that keeps judgement in the practice while moving the repetitive work out.
- Practice sets the procedure. Document which evidence you accept for each client type, which screening tool you use and what triggers EDD.
- Provider requests documents. The support team sends the request, chases gaps and logs every response with a date.
- Provider runs verification and screening. Electronic ID, sanctions and PEP screening, and a Companies House check of officers and PSCs, all inside your systems.
- Provider prepares the file. A completed CDD record with discrepancies and red flags listed at the top.
- Practice decides. A partner or the MLRO rates the risk, applies EDD where needed and approves or declines the client.
- Provider tracks refresh dates. Ongoing monitoring reminders are logged so higher-risk clients are reviewed on time.
Who does what at each stage of your AML checks for accountants is easier to defend when it is written down. A short responsibility matrix in your AML policy, naming the provider’s role, does that.
What to check before you choose a provider for AML checks for accountants
Not every outsourcing arrangement is equal. Before you hand over any part of your AML checks for accountants, ask these questions and keep the answers on file.
- Will the team work inside your own systems, with logins you issue and can revoke?
- How is client data protected, and where is it processed? Our guide to outsourcing and GDPR compliance covers the transfer questions.
- Has the team been trained on the UK regulations specifically, and will they take your firm’s AML training too?
- Can they show a sample file and audit trail?
- How fast can they turn round a check in a busy onboarding month, and how are urgent cases flagged?
- What happens to a red flag? The answer should always be “it goes to your MLRO, unanswered”.
Where AML checks fit in onboarding
AML checks for accountants are the first gate in onboarding. No engagement letter, clearance request or agent authorisation should go out until CDD is complete, unless your procedure allows the regulation 30(3) exception for low-risk cases. Our client onboarding checklist for accountants shows where the AML gate sits among the other steps, and the outsourced client onboarding service runs the steps around it.
Cost matters too. If you are weighing outsourced AML support against a new hire, our guide to outsourcing costs for accountants sets out the 2026/27 employer on-costs to compare against.
FAQs
Can you outsource AML compliance?
You can outsource the work but not the responsibility. Regulation 39(7) of the Money Laundering Regulations 2017 allows CDD to be applied through an agent or outsourcing provider, provided the arrangement keeps your practice liable for any failure. The firm-wide risk assessment, client risk decisions and the nominated officer role should stay in the practice.
What do AML checks for accountants include?
They include identifying and verifying the client, identifying beneficial owners and understanding the ownership structure, assessing the purpose of the relationship, screening for sanctions and politically exposed persons, and ongoing monitoring. Higher-risk clients need enhanced due diligence. The steps come from regulations 28 and 33 of the Money Laundering Regulations 2017.
Do AML checks have to be done before work starts?
Generally yes. Regulation 30 requires identity to be verified before the business relationship is established. Verification can be completed during the relationship only where that is needed to avoid interrupting normal business and the money laundering risk is low, and it must then be finished as soon as practicable.
Can an offshore team do AML checks for a UK practice?
Yes, if the arrangement meets the regulations and data protection law. The team should be trained on UK money laundering law, work to your written procedure inside your systems, and pass every concern to your nominated officer. Your practice remains liable, so review their files as you would a junior’s.
How long must AML records be kept?
Five years from the date the business relationship ends, or from completion of an occasional transaction, under regulation 40. After that, personal data should be deleted unless another legal reason to keep it applies. An outsourced team should save everything into your systems so the records stay under your control.
Hand over the legwork, keep the judgement
Virtual Service Assists prepares CDD files for UK practices: document requests, chasing, electronic ID and sanctions screening and refresh tracking, all inside your systems and under your procedure. Your partners and MLRO keep every risk decision. See how our outsourced AML checks for accountants work, or book a consultation to map it against your current onboarding.



