Financial Conduct Authority Rules for AML Compliance
The FCA's AML requirements are a full regulatory program, not a checklist a single report can satisfy. Here's what's actually required, and where screening fits within it.

A necessary clarification before anything else: this article explains what UK-regulated firms are required to do under FCA and Money Laundering Regulations rules. It is not a substitute for that program, and no single due diligence report, from Scrutinex or anyone else, satisfies these obligations on its own. A regulated firm needs its own documented, risk-based AML program regardless of what screening tools it uses within it. What follows is an honest account of what that program actually requires.
The legal framework the FCA operates within
UK AML regulation rests on three pieces of legislation working together: the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (the MLRs, amended most recently in 2026), the Proceeds of Crime Act 2002, and the Terrorism Act 2000. The FCA is the supervisor for firms it regulates, banks, payment institutions, investment firms, and since recent expansions, registered cryptoasset exchange and custodian wallet providers.
What the FCA actually requires of a regulated firm
A documented, risk-based AML program. Not a generic policy, one that reflects the firm's actual customer base, products, and geographic exposure, embedded under the FCA's Senior Management Arrangements, Systems and Controls (SYSC) sourcebook.
A named Money Laundering Reporting Officer. This role sits under the Senior Managers and Certification Regime as a designated significant-influence function (SMF17), meaning a specific, accountable individual, not a shared departmental responsibility.
Customer due diligence at onboarding, and ongoing monitoring after. A one-time check at the start of a relationship doesn't satisfy the requirement; firms must monitor for changes in risk throughout.
Enhanced due diligence for higher-risk relationships, including anyone connected to a high-risk third country or holding politically exposed person status, see our PEP screening explainer for what that category specifically requires.
Suspicious activity reporting to the National Crime Agency, with criminal penalties, up to 14 years' imprisonment and unlimited fines under the Proceeds of Crime Act, for regulated-sector professionals who suspect money laundering and fail to report it.
What's changed recently
The 2026 amendments to the MLRs expanded enhanced due diligence requirements to cryptoasset exchange providers and custodian wallet providers, tightened rules around changes of control at registered cryptoasset businesses, and closed a gap around the sale of off-the-shelf companies by trust and company service providers. The direction is consistently toward more documentation and earlier scrutiny, not less.
Where third-party screening genuinely fits
Sanctions, PEP, and adverse media screening, the kind covered in our sanctions screening guide, is one input into the customer due diligence and enhanced due diligence steps above. A regulated firm still needs its own risk assessment, its own MLRO, its own monitoring process, and its own documented policy; a screening report feeds evidence into that process, it doesn't replace it.
For a regulated firm building out that program, or for a business without a formal FCA obligation that still wants a specific counterparty properly checked, Scrutinex provides the underlying screening, sanctions, PEP, offshore exposure, and adverse media, as a sourced report. See a sample report or order one for a specific subject.