UK AML compliance updates: five changes firms should be addressing now

Published: 20 Jul 2026

By Leroy Rodrigues, Compliance Consulting Analyst

Key takeaways

  • Recent anti-money laundering (AML) reforms reinforce the importance of a risk-based approach to compliance
  • New guidance on digital identity verification is helping firms modernise onboarding processes
  • Changes affecting pooled client accounts place greater emphasis on understanding risks and account purpose
  • Increased regulatory information sharing between regulators is likely to drive greater scrutiny
  • Cryptoasset firms should begin assessing how the future Financial Services and Markets Act (FSMA) regime may affect their obligations

Financial crime continues to evolve, and UK regulators are raising expectations of how firms identify, assess and manage money laundering risks.

Recent updates to the AML framework are intended to close gaps, improve transparency and strengthen the UK’s response to financial crime.

While many of the reforms reinforce existing risk-based principles, they also provide firms with an opportunity to modernise compliance processes, strengthen governance and improve operational efficiency.

Here’s five AML changes firms should be addressing now.

1. Enhanced due diligence becomes more targeted

Previous position

Enhanced due diligence (EDD) was required for all unusually large or complex transactions. It was also mandatory for customers linked to Financial Action Task Force (FATF) black‑list and grey‑list countries, regardless of the wider risk assessment.

What’s changed?

EDD is no longer automatically required for customers connected to FATF grey list jurisdictions. Firms are instead expected to apply a more proportionate, risk-based assessment while continuing to apply appropriate controls to higher-risk relationships.

What firms should do now

  • Update AML policies and procedures to reflect the revised EDD requirements
  • Reassess how country risk factors are incorporated into risk assessments
  • Continue applying robust controls to higher-risk customers and transactions
  • Train staff on the updated EDD requirements and associated risk factors

2. Digital identity verification gains regulatory clarity

Previous position

Joint Money Laundering Steering Group (JMLSG) guidance permitted firms to verify customer identities electronically, either directly using customer information or through third-party providers that met JMLSG requirements.

What’s changed?

In February 2026, the UK Government published new guidance, covering biometrics, electronic identity (eID) solutions and remote onboarding. The guidance is intended to support faster and more secure customer onboarding.

What firms should do now

  • Update onboarding policies to define when digital identity verification is acceptable
  • Identify approved and certified providers that meet regulatory expectations
  • Ensure digital verification processes support Regulation 28 identity verification requirements
  • Review where manual onboarding processes can be replaced by digital solutions

3. New expectations for pooled client accounts

Previous position

Firms were not required to conduct customer due diligence (CDD) on every underlying client within a pooled client account (PCA). Typically, CDD was applied to the account holder, with simplified due diligence used where risks were assessed as low.

What’s changed?

Firms are still not expected to conduct CDD on all underlying clients. However, they must demonstrate a clear understanding of the purpose of the pooled client account, the risks it presents and how those risks are managed. CDD continues to apply to the account holder.

What firms should do now

  • Review the use of pooled client accounts across the business
  • Clearly document account purpose and risk assessments
  • Ensure appropriate CDD is maintained on account holders
  • Be able to provide information on underlying clients if requested

4. Greater information sharing between regulators

Previous position

AML supervisors had relatively limited powers to share intelligence across regulatory bodies.

What’s changed?

AML supervisors, including the Financial Conduct Authority (FCA), the Prudential Regulation Authority (PRA), HM Revenue and Customs (HMRC) and professional bodies, can now share AML-related information with Companies House and the Financial Regulators Complaints Commissioner. The aim is to improve the detection of suspicious entities and strengthen oversight.

What firms should do now

  • Maintain clear records and audit trails
  • Ensure prescribed responsibilities remain up to date
  • Review governance and accountability arrangements
  • Be prepared for increased regulatory scrutiny and information requests

5. Cryptoasset regulation continues to evolve

Previous position

The FCA currently requires cryptoasset firms to remain registered under the Money Laundering Regulations (MLRs) for AML supervision until the new regulatory framework is introduced.

What’s changed?

When the FSMA cryptoasset regime comes into force, currently expected on 25 October 2027, firms authorised to undertake regulated cryptoasset activities will no longer require separate MLR registration because AML supervision will sit within the wider FSMA framework. Firms outside the FSMA cryptoasset perimeter may still need MLR registration.

What firms should do now

  • Assess whether activities are likely to fall within the FSMA cryptoasset regime
  • Consider readiness for FCA authorisation applications, expected to open on 30 September 2026
  • Strengthen AML controls and governance frameworks
  • Ensure record keeping, oversight and monitoring arrangements are robust ahead of implementation

Staying ahead of AML change

As regulatory expectations continue to evolve, firms need practical support to maintain effective compliance frameworks and respond to financial crime risks.

The latest reforms reinforce the importance of a risk-based approach, stronger governance and robust customer due diligence processes. For many firms, they also present an opportunity to review existing frameworks, streamline onboarding and monitoring activities, and strengthen their overall approach to financial crime compliance.

Whether you’re updating AML policies, reviewing risk assessments, enhancing customer due diligence processes or exploring digital identity verification solutions, taking proactive steps now can help reduce regulatory risk and improve operational efficiency.

Our UK regulatory compliance specialists support firms with:

  • AML framework reviews and gap assessments
  • Customer due diligence and ongoing monitoring
  • Digital identity verification and onboarding solutions
  • Regulatory compliance advisory services
  • Targeted compliance training for regulated firms

By combining practical compliance expertise with technology-enabled solutions, we help firms build compliance frameworks that are both effective and proportionate to their risk profile.

To learn more about how we can support your AML compliance programme, get in touch today.

Working with IQ-EQ has been seamless – you and your team understand our business, advise us appropriately, and handle your side of our collective partnership so that we can focus on making good investment decisions. Evan Gibson SVP, Merchants Capital

Get in touch with us today

We’re ready to listen.

Make an enquiry

Interested in joining our team?

We are always on the lookout for passionate people that possess IQ and EQ to join our growing team.

View job vacancies