L
Obiter
AML Compliance 9 min read

UK AML Obligations: Money Laundering Regulations 2017 for Solicitors

A plain-English guide to the Money Laundering Regulations 2017 for solicitors — scope, obligations, penalties, and what changed after the 2019 amendments.

C

Obiter Editorial Team

Published 15 May 2025

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 — universally referred to in the legal profession as “the Money Laundering Regulations 2017” or simply “the MLRs” — form the backbone of the UK’s anti-money laundering regime for solicitors. Yet many fee earners who work on in-scope matters every day have only a passing acquaintance with what the Regulations actually require. This guide changes that.

Why the MLRs Matter More Than Ever

The UK’s legal sector handles trillions of pounds in client money annually. The National Crime Agency estimates that hundreds of billions of pounds in criminal proceeds flow through the UK economy each year, and solicitors — particularly those handling property transactions, company formations, and trust arrangements — are persistently targeted by criminals seeking to launder illicit funds.

In 2022–23, the SRA opened 686 AML investigations and issued fines totalling more than £2 million. By 2023–24, enforcement activity had intensified further. Non-compliance is not a technical failing — it is a gateway to the proceeds of serious crime entering the legitimate economy.

The Legislative Architecture

Primary Legislation

The MLRs 2017 sit within a broader legislative architecture. They must be read alongside:

  • The Proceeds of Crime Act 2002 (POCA) — creates the principal money laundering offences and the SAR regime
  • The Terrorism Act 2000 — creates equivalent offences for terrorist financing
  • The Counter-Terrorism and Security Act 2015 — expanded terrorist financing controls
  • The Economic Crime (Transparency and Enforcement) Act 2022 — introduced the Register of Overseas Entities
  • The Economic Crime and Corporate Transparency Act 2023 — reformed Companies House verification

How the MLRs Are Structured

The MLRs run to 109 regulations and six schedules. The key parts for solicitors are:

  • Part 2 (Regs 8–23) — the risk-based approach, firm-wide risk assessment, and policies
  • Part 3 (Regs 27–38) — customer due diligence, including standard, simplified, and enhanced CDD
  • Part 4 (Regs 39–47) — reliance and record-keeping
  • Part 5 (Regs 48–52) — policies, controls, and procedures; training
  • Part 6 (Regs 53–60) — supervisory authorities and their powers

The 2019 Amendments

The Money Laundering and Terrorist Financing (Amendment) Regulations 2019 made significant changes, implementing the Fifth EU Anti-Money Laundering Directive (5AMLD) into UK law before Brexit. Key changes included:

  • Expansion of CDD triggers — certain electronic money products and virtual currency exchanges brought into scope
  • Enhanced due diligence for high-risk third countries — automatic EDD triggered by transactions involving designated high-risk third countries
  • Beneficial ownership registers — requirement to check central registers before relying on client-provided beneficial ownership information
  • PEP regime adjustments — clarification of who counts as a PEP and how firms should treat domestic PEPs versus foreign PEPs

Post-Brexit, the UK retained the 5AMLD changes and has since made further amendments through statutory instruments. The UK’s AML regime is now diverging from the EU’s developing framework, and firms with cross-border practices should track both.

Who Is a “Relevant Person”?

The obligations in the MLRs apply to “relevant persons.” For legal practices, you are a relevant person if you carry out any of the following activities:

Covered Activities

Trust or company service provider (TCSP) services — forming companies, acting as a director or secretary, providing a registered office address, or acting as a trustee.

Conveyancing — any transaction involving the buying or selling of real property (including residential and commercial). Note that acting for a lender on a mortgage is included; acting as a defendant in possession proceedings is not.

Estate agency services — included since January 2020.

Client account management — managing client money, securities, or other assets on behalf of clients, or advising on the investment thereof.

Company and business transactions — advising on the purchase or sale of a business, acting on mergers and acquisitions, or advising on business reorganisations.

Activities Outside Scope

Pure contentious work — litigation, arbitration, and tribunal proceedings — is generally excluded from the MLRs. However, many in-scope activities arise adjacent to litigation: a settlement involving the transfer of real property, for example, may trigger CDD obligations even if the underlying dispute is contentious.

The Risk-Based Approach

The MLRs are built around a risk-based approach (RBA). Rather than prescribing identical procedures for every transaction, the Regulations require firms to calibrate their controls to the actual risks they face. This has two important implications:

First, firms must genuinely assess their risks. The firm-wide risk assessment (FWRA) must be a real analysis of the money laundering and terrorist financing threats that the firm’s specific business model, client base, and service offering create. A template document downloaded and barely edited is not a compliant FWRA.

Second, not all clients require the same level of scrutiny. Simplified due diligence is permissible for genuinely low-risk clients (subject to specific conditions); enhanced due diligence is mandatory for higher-risk clients. The risk-based approach demands professional judgment — and that judgment must be documented.

Customer Due Diligence: The Regulation 27 Trigger

Regulation 27 sets out when CDD must be applied. The triggers are:

  1. Establishing a business relationship — when you first take on a client in scope
  2. Carrying out an occasional transaction — a one-off transaction of €15,000 or more (roughly £13,000), or linked transactions that together exceed that threshold
  3. Where there is a suspicion — whenever you suspect money laundering or terrorist financing, regardless of transaction value
  4. Where there is doubt about the veracity of previously obtained documents — if you have reason to believe a client’s documents may be false or the client has misrepresented their identity

Timing of CDD

CDD must ordinarily be completed before establishing a business relationship or carrying out a transaction. Regulation 30 permits a limited exception — completing CDD during the establishment of a relationship where necessary to avoid interrupting normal business — but this exception is narrow and must not become routine practice.

What Standard CDD Requires

Regulation 28 sets out the standard CDD measures:

  • Identify the customer — obtain the customer’s name and, for individuals, their date of birth and address
  • Verify the customer’s identity — check the identity against documents, data, or information obtained from a reliable and independent source
  • Identify the beneficial owner — for corporate clients and legal arrangements, identify the ultimate beneficial owner (UBO) — those with more than 25% ownership or control — and take reasonable measures to verify their identity
  • Understand the purpose and nature of the business relationship

The Regulations do not specify exactly which documents satisfy verification — this is left to professional judgment guided by LSAG guidance. In practice, a combination of photo ID and address verification is standard for individuals; Companies House documents and UBO declarations for corporate clients.

Enhanced Due Diligence Under Regulation 33

Regulation 33 makes EDD mandatory in certain circumstances, regardless of the firm’s own risk assessment:

Mandatory EDD Scenarios

Politically Exposed Persons. Any client who is a PEP (or a family member or known close associate of a PEP) requires EDD, including:

  • Obtaining additional information on the PEP’s source of wealth and source of funds
  • Approval by senior management before establishing or continuing the relationship
  • Enhanced ongoing monitoring

High-Risk Third Countries. Transactions involving individuals or entities connected to countries designated by the UK Government as high-risk automatically trigger EDD. The list is updated periodically and is available on GOV.UK.

Non-Face-to-Face Transactions. Where the business relationship or transaction is not carried out in the physical presence of the client, additional measures are required to compensate for the reduced ability to verify identity.

Discretionary EDD

Beyond the mandatory triggers, firms must apply EDD whenever their own risk assessment identifies a higher-risk situation. This is an important point: the list of mandatory EDD triggers is a floor, not a ceiling. If your client presents red flags — unusual transaction structures, unexplained wealth, complex cross-border arrangements — EDD is warranted regardless of whether any mandatory trigger is technically met.

Beneficial Ownership: The Regulation 28 Challenge

Identifying beneficial owners of corporate clients has become significantly more complex. The MLRs require firms to:

  1. Identify every individual who ultimately owns or controls more than 25% of the company
  2. Take “reasonable measures” to verify their identity
  3. Check the Companies House PSC (Persons with Significant Control) register as a matter of course

The Economic Crime and Corporate Transparency Act 2023 strengthened Companies House verification requirements. From autumn 2024, directors of UK companies must have their identity verified with Companies House, which provides an additional layer of assurance for firms verifying company clients. Firms should update their corporate CDD procedures to incorporate verified Companies House data where available.

Ongoing Monitoring

Regulation 28(11) requires firms to conduct ongoing monitoring of every business relationship. This means:

  • Scrutinising transactions to ensure they are consistent with the firm’s knowledge of the client
  • Keeping CDD documents up to date — refreshing them when they expire or when the client’s circumstances change
  • Updating the risk assessment for the relationship when new information emerges

In practice, ongoing monitoring is one of the most commonly neglected requirements. Firms complete thorough CDD at onboarding and then never revisit it, even for long-running client relationships spanning multiple transactions over several years.

Policies, Controls, and Procedures

Regulation 19 requires firms to establish and maintain written policies, controls, and procedures (PCPs) to prevent and detect money laundering and terrorist financing. The PCPs must be approved by senior management and must be communicated to all relevant staff.

The minimum content of PCPs is set out in Regulation 19(4):

  • Customer due diligence
  • Ongoing monitoring
  • Suspicious activity reporting
  • Record-keeping
  • Internal controls
  • Risk assessment and management
  • The management of compliance with relevant legislation by members of staff

Training Obligations

Regulation 24 requires firms to take appropriate measures to ensure that relevant employees are trained in AML and counter-terrorist financing. Training must cover:

  • The law relating to money laundering and terrorist financing
  • How to recognise and deal with transactions and activities that may be related to money laundering or terrorist financing
  • Data protection obligations relevant to AML

Training records must be kept and must be available for inspection by the SRA. The SRA expects training to be tailored to staff roles — generic online training that covers the basics is a starting point, not a complete solution.

Penalties for Non-Compliance

Non-compliance with the MLRs exposes firms and individuals to significant penalties:

  • Civil penalties — the SRA can impose unlimited fines under its expanded powers
  • Criminal prosecution — Regulation 86 creates criminal offences for intentional, reckless, or negligent breaches of key obligations; individuals can face up to two years’ imprisonment
  • Regulatory consequences — conditions on practising certificates, suspension, or striking off in serious cases

The direction of travel is clear: regulatory penalties are increasing, enforcement is more active, and the SRA is investing more resources in AML supervision. The question for most firms is not whether the SRA will look at their AML compliance, but when.


Keeping pace with the MLRs’ requirements across a busy practice is administratively intensive. Obiter integrates electronic identity verification, sanctions and PEP screening, and CDD record storage into the instruction workflow — so your firm meets its obligations under the Money Laundering Regulations 2017 without drowning fee earners in administrative process.

Topics:

aml money-laundering-regulations uk-law compliance

Ready to reclaim 12+ hours a week?

See how Obiter handles your legal admin so you can focus on advising clients.