Menu Close

Blog

AML & Financial Crime in 2026: Why a “Lighter” Rulebook Has Made Your Risk Assessment the Most Dangerous Document in the Firm

Infographic with orange compliance icons -- AML, financial crime, KYC, sanctions, and monitoring on a dark background.

AML & Financial Crime in 2026: Why a “Lighter” Rulebook Has Made Your Risk Assessment the Most Dangerous Document in the Firm

Making Compliance Work | Compliance Consultant


The short answer

The UK’s AML regime changed on 30 June 2026. The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621) narrowed several mandatory triggers — most notably enhanced due diligence — and converted euro thresholds to sterling. That is not deregulation. It is a transfer of judgement from the rulebook to your Business-Wide Risk Assessment. Firms that treated the old prescriptive triggers as their AML framework now have nothing holding the framework up, and the FCA’s 2025–26 enforcement record shows exactly what happens next.


1. What actually changed on 30 June 2026

HM Treasury laid the amending regulations before Parliament on 25 March 2026. They were made on 9 June and the bulk of the provisions took effect on 30 June 2026, with a residual tranche following in 2027.

The headline changes:

  • Enhanced due diligence narrowed. EDD under regulation 33 is no longer triggered by every “complex” transaction. It now bites on the unusually complex. Treasury’s stated reason: the old wording drove risk-averse, box-ticking behaviour in sectors where complexity is simply the business model.
  • High-risk third country EDD narrowed. The automatic EDD obligation is aligned to jurisdictions subject to a FATF Call to Action — at present Iran, North Korea and Myanmar — rather than the wider grey list.
  • Euro thresholds converted to sterling. The €1,000 occasional transaction threshold becomes £800, and equivalent conversions run through the rest of the Regulations. Every system, procedure and staff aide-memoire carrying a euro figure is now out of date.
  • Definitional tightening. Clearer treatment of where a body corporate is “established”, pooled client accounts, and CDD obligations for TCSPs selling off-the-shelf companies.
  • Cryptoasset alignment. A substituted Schedule 6B aligns the MLRs with the new cryptoasset regulatory perimeter created under the Financial Services and Markets Act 2000 (Cryptoassets) Order 2026.
  • Trust Registration Service expansion. Non-UK trusts holding UK land acquired before 6 October 2020 are pulled into scope, with a de minimis exemption for certain low-value, low-risk trusts.
  • A new notification duty. Certain material breaches must be notified to the FCA within 30 days.

The point most commentary has missed: every one of those relaxations is conditional on you being able to evidence why the lower-intensity treatment was appropriate. The regulator has removed the crutch, not the obligation.


2. The trap: narrower rules, wider judgement

Under the old regime, a mortgage intermediary or payments firm could defend its approach by pointing at the rulebook: the Regulations said EDD, we did EDD.

From 30 June 2026, the defence has to be: our risk assessment identified this arrangement as not unusually complex, applying criteria we set, tested and documented, and our controls were calibrated accordingly.

That is a materially higher evidential bar for a small firm — and it lands squarely on three documents most firms have not refreshed in eighteen months:

  1. The Business-Wide Risk Assessment (BWRA) — which must now be capable of carrying the weight of every judgement call the Regulations no longer make for you.
  2. The Customer Risk Assessment methodology — including how “unusually complex” is defined in your business, with worked examples.
  3. The AML/CTF Policy and Procedures manual — which almost certainly still contains euro thresholds, the old grey-list EDD logic, and pre-2026 regulation references.

If a skilled person or a supervisory visit asks you to explain a de-escalation decision and the only answer is “the rules changed”, that is a finding.

Related: an AML and Governance Review is the fastest way to test whether your risk assessment can actually bear this weight. Book a discovery call: https://bit.ly/CCDiscovr


3. What the FCA is actually punishing

The 2025 enforcement year was the clearest signal the regulator has sent in a decade. AML and financial crime failings were the single most common theme among final notices, and the numbers moved from tens of millions into the high hundreds.

The pattern across the major cases is remarkably consistent:

FirmPenaltyCore failing
Nationwide Building Society£44.1mPrinciple 3 — customer risk assessment, transaction monitoring, governance and oversight
Barclays Bank plcc.£39.3m (plus c.£3m in a second notice)Failure to identify, assess and mitigate ML risk in a long-standing relationship
Monzo Bank Ltd£21.1mFinancial crime controls that failed to scale with rapid customer growth
London Metal Exchange£9.24mGovernance and systems failings, insufficient senior oversight
Mako Financial Markets£1.66mAML control deficiencies around complex trading strategies

Three lessons every regulated SME should take from that table:

Lesson one — the FCA did not need to find actual money laundering. In the Nationwide case, as in most, there was no finding that laundering occurred. The breach was the control environment itself. You do not get to argue “no harm resulted”.

Lesson two — growth is an aggravating factor. Monzo’s customer base grew roughly tenfold while its controls stood still. If you are a fintech, payments firm or broker scaling volumes, onboarding capacity and monitoring capability must scale in the same budget cycle, not the next one.

Lesson three — governance failure is treated as seriously as systems failure. The recurring finding is not “you had no policy”. It is “your board could not demonstrate that the policy operated effectively in practice”. That is a second-line assurance and monitoring gap, and it is the single most common weakness we find in firms of under 50 staff.

The FCA has been explicit that financial crime remains a priority for 2026, and has signalled greater use of data analytics to identify fraud, scams and AML weakness earlier — which means the first you hear of a problem may well be a data request rather than a visit.


4. The supervisory map is being redrawn

In October 2025 the Government confirmed that the FCA will become the Single Professional Services Supervisor (SPSS) for AML/CTF — taking over legal, accountancy and trust and company service provider supervision from 22 professional body supervisors, with OPBAS eventually ceasing to exist in its current form.

HM Treasury published its consultation response in June 2026, and the enabling clauses sit within the Financial Services and Markets Bill introduced in May 2026. Practically:

  • The FCA’s AML-supervised population rises from roughly 17,000 firms to over 60,000.
  • Primary legislation is unlikely to complete before late 2026, so the transfer itself is not expected to begin before 2028 — a phased transition over two to three years.
  • The proposals include an FCA register for professional services firms, fit and proper assessment of firms and owners, and extension of existing tools such as skilled person reviews.

Why this matters even if you are already FCA-regulated: supervisory bandwidth and methodology are about to be standardised across a much larger population. Expect greater use of data-led, thematic and desk-based supervision, and less tolerance for firms whose evidence exists only in the MLRO’s head. If you rely on professional service providers — conveyancers, accountants, TCSPs — expect their own AML posture, and their appetite for your business, to shift during the transition.


5. Fraud is now a governance problem, not a fraud-team problem

2026 is the first full year in which the failure to prevent fraud offence under section 199 of the Economic Crime and Corporate Transparency Act 2023 is enforceable, having come into force on 1 September 2025.

The mechanics matter for any firm with a group structure, appointed representatives, introducers or commission-earning sales staff:

  • Liability attaches where an associated person — employee, agent, subsidiary, or other person performing services for the organisation — commits a fraud intended to benefit the organisation or its clients.
  • No senior management knowledge or intent is required. The prosecution does not need to show the board knew.
  • The only defence is having had reasonable fraud prevention procedures in place — or that it was reasonable not to have any.
  • Penalties are unlimited fines.

The Home Office guidance published in November 2024 sets the expected standard, and the SFO issued its own guidance in 2025. The Government’s Anti-Corruption Strategy (December 2025) and the Fraud Strategy 2026–2029 both reinforce a prevention-first posture.

The compliance implication is uncomfortable but simple: a decision that additional anti-fraud measures are unnecessary is itself a decision that must be documented, reasoned and owned by a named individual. A silent risk assessment is not a defence — it is evidence of the absence of one.

For SMCR firms, this maps directly onto the Senior Manager Conduct Rules and the reasonable steps expectation. If you cannot show the paper trail from fraud risk assessment, through controls, to board challenge, you have an SMCR exposure sitting alongside the criminal one.


6. The clock behind all of this: FATF, August 2027

The UK is due its next FATF mutual evaluation in August 2027. Every strand above — MLR reform, supervisory consolidation, SARs quality, asset recovery outcomes — is being driven toward that assessment.

FATF’s methodology now weighs effectiveness far more heavily than technical compliance. Translated into supervisory behaviour, that means firms will increasingly be asked to demonstrate outcomes rather than artefacts:

  • Does your BWRA map explicitly to the National Risk Assessment and to NCA/FCA threat priorities — money mules, cash-based laundering, overseas fraud, crypto-enabled crime, sanctions evasion?
  • Can you trace each identified threat through to a named control, a monitoring rule and an assurance test?
  • What is the quality of your SARs, not just the count? The UKFIU receives over 850,000 SARs a year; volume no longer impresses anyone.
  • What happened to your false positive rate, your alert backlog and your de-risking decisions over the last twelve months?

If your answers are anecdotal, you are describing the exact gap that FATF criticised, that OPBAS reporting exposed, and that the FCA is now resourced to find.


7. Ten questions your board should be able to answer before year end

Use these as a board agenda item. If more than three attract a shrug, you have a remediation project rather than a review.

  1. When was the BWRA last refreshed — and does it reference SI 2026/621?
  2. Where in our documentation is “unusually complex” defined for our products, with worked examples?
  3. Have all euro thresholds been converted to sterling in policies, procedures, systems and training?
  4. Have we re-based our high-risk jurisdiction logic against the FATF Call to Action list, and documented what we retained voluntarily and why?
  5. Who owns the new 30-day material breach notification, and what is the trigger definition?
  6. What second-line monitoring has tested — not reviewed, tested — our CDD and transaction monitoring in the last twelve months?
  7. Can we evidence that control capacity has scaled with business volumes?
  8. Do we have a documented fraud risk assessment under ECCTA section 199, with a named owner and board approval?
  9. How do we assure ourselves of the AML posture of our introducers, ARs and outsourced providers?
  10. If a skilled person arrived on Monday, which three files would we least want them to pull?

8. A practical 90-day plan

Days 1–30 — Establish the gap. Run a documented gap analysis of your AML/CTF framework against SI 2026/621. Produce a single change log: every clause, threshold and trigger affected. Identify system fields carrying euro values. Confirm your MLRO has capacity to own the remediation, or appoint support.

Days 31–60 — Rebuild the judgement layer. Refresh the BWRA and customer risk assessment methodology so that they, rather than the Regulations, carry the reasoning. Define “unusually complex” with examples from your own book. Rewrite the policy manual, and record board approval with minuted challenge — not a nodded-through agenda item. Complete or refresh the ECCTA fraud risk assessment in parallel; the two documents should cross-reference.

Days 61–90 — Prove it works. Refresh training on the new thresholds and triggers, with a competence check rather than an attendance register. Run a targeted file review sample across your highest-risk segment. Build the findings, root causes and remediation into an updated Compliance Monitoring Programme with named owners and dates. Report the whole exercise to the board as a single AML effectiveness paper.

That final paper is the artefact that answers a supervisory letter, a skilled person, or an FCA authorisation caseworker’s financial crime questions in one document.


Frequently asked questions

Did the 2026 changes make AML compliance easier? No. They made it narrower in prescription and wider in judgement. The volume of mandatory EDD may fall, but the burden of justifying your calibration rises. Firms with weak risk assessments are materially worse off than before.

Do the MLR 2026 amendments apply to small firms? Yes. The Money Laundering Regulations apply by activity, not by size. A two-person mortgage brokerage or a small payments firm is subject to the same amended thresholds and definitions as a clearing bank, proportionate to its risk profile.

Does failure to prevent fraud apply to my firm? The offence targets “large organisations” against the statutory threshold, but three points matter for smaller firms: group aggregation can bring you into scope; large clients and lenders are pushing the standard down the supply chain contractually; and the FCA expects proportionate fraud controls under its own rules regardless of the ECCTA threshold.

When will the FCA take over AML supervision of law and accountancy firms? Legislation is progressing through the Financial Services and Markets Bill, with transfer not expected to begin before 2028 and a phased transition thereafter. Firms should prepare for FCA-style supervision now rather than waiting for a commencement date.

What does the FCA actually look for in an AML review? Consistently: a live and specific risk assessment; customer risk ratings that are applied, not just defined; transaction monitoring calibrated to the risks identified; second-line assurance that tests effectiveness; and board-level evidence of challenge. Documentation without operation is the failure mode in nearly every final notice.


Where Compliance Consultant fits

We have spent 25 years doing precisely this work for FCA-regulated firms across mortgage broking, payment services, investment management, claims management, fintech and cryptoasset businesses.

  • AML & Governance Reviews — independent assessment of your BWRA, CDD framework, monitoring and MLRO function against the 2026 Regulations.
  • Compliance Audits and File Reviews — evidence-based testing that produces the assurance trail a supervisor expects to see.
  • FCA Authorisation Support — including the financial crime and governance elements that most commonly stall an application.
  • Regulatory Risk Management — Compliance Monitoring Programmes, board reporting and SMCR reasonable steps documentation that stands up to scrutiny.

Book a Discovery Call: https://bit.ly/CCDiscovr

Prefer to answer a few preliminary questions first? Use our voice agents:

regulatory support specialists
Compliance Support specialist
previous arrowprevious arrow
next arrownext arrow
Shadow

Sources and further reading

  • The Money Laundering and Terrorist Financing (Amendment) Regulations 2026, SI 2026/621 — legislation.gov.uk
  • HM Treasury, Explanatory Memorandum to SI 2026/621
  • HM Treasury, Improving the Effectiveness of the Money Laundering Regulations — consultation response
  • HM Treasury, AML/CTF supervision reform: duties, powers and accountability — consultation response, June 2026
  • FCA Final Notices: Nationwide Building Society, Barclays Bank plc, Monzo Bank Ltd, London Metal Exchange, Mako Financial Markets (2025)
  • FCA Annual Report and Enforcement Data 2024/25
  • Home Office, Guidance to organisations on the offence of failure to prevent fraud (November 2024); Economic Crime and Corporate Transparency Act 2023, s.199
  • Serious Fraud Office, Guidance on failure to prevent fraud (2025)
  • HM Government, Anti-Corruption Strategy (December 2025) and Fraud Strategy 2026–2029
  • National Crime Agency / UKFIU, Suspicious Activity Reports guidance and annual reporting
  • FATF, Methodology for Assessing Technical Compliance and Effectiveness

Follow us: Facebook | Twitter | Instagram | LinkedIn | Pinterest

Compliance Consultant | https://complianceconsultant.org | UK 0800 689 0190 | Int’l 020 8243 8620 | Discovery call: https://bit.ly/CCDiscovr

Compliance Consultant and Compliance Doctor are trading styles of UK Compliance Consultant Limited, Companies House number 14805896.

This article is general guidance current at the date of publication and does not constitute legal or regulatory advice for any specific firm.

author avatar
Lee Werrell