Module 21 | Global Financial Crimes, Risk, and RegTech Library
Research verification date: 2026-08-09
Primary jurisdictions: United Kingdom.
Important notice: Educational material only; not legal advice. It does not determine obligations in any jurisdiction or replace legal counsel, regulator engagement, institution-specific risk assessment, or a documented customer, transaction, product, or account decision.
Source Quality and Currency Note
Primary sources include UK legislation, FCA and NCA/UKFIU materials, OFSI and Companies House resources, PSR information, and FCA enforcement materials. This is an educational overview, not legal advice. SAR, DAML, sanctions, fraud, customer-action and data decisions require entity- and fact-specific legal and regulatory analysis.
How to Use This Module
Read this module in three passes if useful:
- Enterprise leader pass: executive thesis, decision map, Global Core / Local Edge model, maturity profile, failure cascade and executive discussion questions.
- Operator pass: workflows, decision rights, metrics, delivery dependencies, quality controls, jurisdictional configuration and execution checklists.
- Specialist pass: legal and supervisory architecture, technical terminology, reporting, data, evidence, test design, enforcement/supervisory cases and glossary.
Learning Objectives
- Map the UK architecture across MLRs, POCA, Terrorism Act, sanctions, FCA oversight, UKFIU/SARs, corporate transparency, fraud and payment regulation.
- Design differentiated but coordinated procedures for CDD, SARs, DAML, sanctions, account action, APP fraud and law-enforcement engagement.
- Understand UK supervisory expectations around systems and controls, PEP treatment, financial-crime risk assessment, governance and evidence.
- Apply corporate-transparency changes and registry information carefully without treating Companies House data as a complete KYC conclusion.
- Interpret official enforcement notices as operating-model evidence rather than as generic policy instructions.
- Frame UK operations within a global control model while preserving the UK legal, market, consumer and intelligence edge.
Primary-Source Spine
The source strategy for this module is: UK legislation, FCA, NCA/UKFIU, OFSI, Companies House, PSR and official enforcement materials. Representative source anchors include S01: UK Legislation; S02: UK Legislation; S03: UK Legislation; S04: UK Legislation; S05: Financial Conduct Authority; S06: Financial Conduct Authority; S07: National Crime Agency; S08: National Crime Agency. Material legal, supervisory, enforcement and operating claims are identified in the companion claim/evidence ledger. [S01][S02][S03]
Executive Thesis
The United Kingdom’s financial-crimes regime is a dense operating environment because it connects anti-money-laundering law, terrorist-financing offences, suspicious-activity reporting, sanctions, corporate transparency, fraud and scam controls, prudential and conduct supervision, professional-sector supervision, and law-enforcement intelligence. The central mistake is to treat it as a narrow “MLR compliance” program. A bank, payment institution, asset manager, insurer, fintech, professional-services firm, or trust and company service provider needs a control system that can distinguish the legal source and operational effect of each decision while sharing the data and intelligence that the decisions need.
The Money Laundering Regulations 2017 set a large part of the preventive framework. POCA and the Terrorism Act create core criminal-law, disclosure and reporting context; the UKFIU receives SARs within the NCA; DAML is a specific route that must not be confused with an ordinary account decision; OFSI administers financial sanctions implementation; the FCA supervises relevant firms’ systems and controls; Companies House reforms affect corporate transparency; and the payments/fraud environment introduces consumer-harm and reimbursement considerations. [S01][S02][S03][S04][S05][S07][S08][S09][S10] The program has to coordinate those functions without flattening them.
The UK also illustrates a decisive global design insight: strong financial-crime controls must be customer-aware. A risk-based approach means neither blanket de-risking nor a frictionless growth strategy. It means knowing the customer, product, payment, intermediary, geography, delivery channel and threat; using evidence proportionately; escalating ambiguity; and being able to show the reasoned decision. This is especially important where fraud, APP scams, mule activity and AML signals overlap but create different customer, reporting, reimbursement and law-enforcement consequences.
Executive decision rule. Before accepting, changing, centralising, outsourcing, automating, restricting, reporting, or closing a material financial-crime control, require a clear statement of the applicable question, the in-scope population, the accountable owner, the decision evidence, the local legal configuration, the quality test and the residual-risk authority.
The Questions This Module Answers
- Which UK legal or supervisory path governs a particular customer, transaction, suspicious-activity, sanctions or scam decision?
- How should an institution distinguish a SAR, DAML request, account restriction, fraud intervention, and customer-reimbursement decision?
- What is the respective role of FCA, NCA/UKFIU, OFSI, Companies House, PSR, HM Treasury and other relevant bodies?
- How do fraud and APP-scam patterns feed into AML intelligence without creating unsafe or unfair account action?
- Which corporate-transparency changes alter data availability, verification or internal KYB design?
- What evidence would show that a UK control is operating effectively after an enforcement finding or program change?
1. Executive Layer
The strategic stakes
Financial-crimes capability becomes strategically material when it affects what customers can be served, which products can be launched, how fast payments can move, whether a market can be entered, which relationships can be retained, what data can be used, and whether regulators or partners consider the institution trustworthy. The leadership task is to avoid two bad abstractions: viewing financial crime as an isolated compliance overhead, or treating every operational difficulty as a legal prohibition. The discipline is to identify the actual source of risk and then design an evidence-led decision path that is proportionate, timely, fair and sustainable.
Every executive should ask four linked questions. First, exposure: what customers, products, transactions, geographies, delivery channels, intermediaries, technologies and networks create the risk? Second, control: which preventive, detective, investigative, reporting, action and assurance mechanisms should respond? Third, proof: what data, documents, logs, reviewer rationale, quality results, model evidence and authority records prove the mechanism works? Fourth, adaptation: how will the institution detect that the risk, rule, product, data or capacity assumption has changed? The answer must be visible by legal entity and market, not merely at head office.
Executive decision map
| Decision path | Core UK lens | Control evidence |
|---|---|---|
| CDD / EDD | MLRs, FCA financial-crime guidance, risk assessment | Customer purpose, ownership/control, risk rating, source evidence, refresh, approval and exceptions. |
| SAR / DAML | POCA, Terrorism Act, UKFIU procedures | Suspicion rationale, narrative, timing, confidentiality, consent path, asset/account action and law-enforcement record. |
| Sanctions | SAMLA, regulations, OFSI guidance | List and ownership analysis, freeze/reporting/licensing decision, communications and audit trail. |
| Fraud / APP scam | FCA/PSR conduct and payments ecosystem, AML intelligence | Intervention rationale, customer contact, reimbursement process, mule-network signal, reporting and outcome record. |
| Corporate transparency | Companies House/ECCTA reforms and firm CDD duties | Registry provenance, ID-validation status, conflict analysis, independent evidence, re-verification and escalation. |
The decision map is deliberately outcome-based. It prevents a program from announcing a new standard, a vendor deployment, a training campaign or a reduced backlog as a success without showing whether the actual decision quality, coverage and resilience improved. It also gives boards and transformation sponsors a more useful way to allocate capital: fund the evidence and operating capability that changes the decision, not simply the activity that surrounds it.
Read the cascade as a management diagnostic rather than an inevitability. A visible failure at the right side of the diagram—late reporting, unsafe customer action, a supervisory finding, or a costly remediation—usually began earlier with an unstated assumption about population, data, capacity, decision rights, or change control. The control response should move upstream until it identifies the first point at which evidence, ownership, or resilience was insufficient. That approach avoids treating rework, contractors, a larger backlog team, or a new dashboard as a substitute for fixing the decision path itself.
2. Operator Layer
The execution discipline
The operator layer turns legal and risk requirements into repeatable work. It begins with a controlled inventory, not a technology implementation. For each process, record the population, trigger, required evidence, key data, legal/policy basis, routing, reviewer authority, system, action, report, time standard, exception, quality test and feedback channel. If any of those elements are missing, the program is likely relying on individual memory or an undocumented work-around.
2. Build a UK evidence record
Keep the facts, source documents, registry and third-party data, reasoning, legal/policy basis, decision owner, action, report, notifications, timeline and quality review. Protect SAR confidentiality and sensitive law-enforcement information.
3. Integrate fraud-to-AML intelligence
Create controlled sharing between fraud, AML, sanctions and customer-support teams. Define what can be shared, how a scam or mule signal is corroborated, who makes the account decision, and how customer harm is considered.
4. Operate a sanctions case spine
Separate matching, ownership/control, legal assessment, freeze or rejection, reporting, licensing, customer communications and post-action monitoring. Do not let a generic alert outcome obscure a potential statutory action.
5. Use Companies House as one evidence layer
Capture source and access date, compare it with customer declarations and other information, identify discrepancies and decide whether risk or legal requirements require further verification or reporting.
6. Test outcomes, not written policy
Use QA, independent testing, thematic reviews, complaint and reimbursement data, SAR quality, enforcement lessons, and management information to identify control failure before it becomes a supervisory outcome.
Operating metrics that resist false assurance
Measure the entire decision path. Track demand and throughput, but pair them with aged risk, incomplete evidence, decision reversal, downstream escalation, report quality, customer-impact signal, QA error, model/data exceptions, vendor or system interruption, issue recurrence and time to root-cause closure. Require a management explanation for favorable metrics that move abruptly. A sharp improvement often reflects a useful control change, but it can also reveal data loss, a policy change, a case-type exclusion, a new vendor routing rule or an unrecorded suppression.
3. Specialist and Jurisdictional Layer
21.1 Preventive AML/CFT: MLRs, risk-based design and FCA expectations
The Money Laundering Regulations 2017 form an important part of the UK preventive AML/CFT framework. They interact with sectoral supervision, the FCA Financial Crime Guide, JMLSG materials for relevant financial-sector contexts, and entity-specific authorizations. The operational task is to establish the scope of the firm and activity, apply customer due diligence and enhanced due diligence as required, conduct and document risk assessment, monitor the relationship, retain evidence, train staff, establish internal controls, and provide the appropriate management and independent oversight. [S01][S05][S06]
FCA materials repeatedly emphasize systems and controls that work in practice. A compliance policy is only a starting point. The program needs accurate risk classification, clear escalation, credible due diligence, monitoring that is aligned to products and threats, timely remediation, senior-management oversight, and reliable management information. The 2024-25 FCA final guidance on PEPs is an example of the need to distinguish a legal risk category from a simplistic “high risk by label” operational response. [S15]
Enforcement and Supervisory Lens: NatWest AML enforcement
Official record. The FCA announced a financial penalty against NatWest for AML failings. [S12]
Operating lesson. Cash-intensive or anomalous activity must be understood against customer behavior, risk appetite, escalation and reliable evidence; policy presence is not control operation.
Limit of inference. The announcement is not a rule that any specified cash pattern must result in the same outcome.
21.1A UK risk assessment, CDD, PEPs, and monitoring evidence
The UK enterprise risk assessment should connect the firm’s actual business model to the controls it says are risk based. Record entities, products, customers, intermediaries, payment and delivery channels, jurisdictions, currencies, transaction patterns, fraud/scam exposure, cash or asset features, corporate structures, third parties, data limitations, and known threat intelligence. State the methodology, sources, assumptions, scoring, material risks, control coverage, residual risk, and escalation/refresh triggers. If a product launches, a payments flow changes, a high-risk sector is added, a merger occurs, a new fraud typology emerges, or testing finds a gap, update the assessment and prove that it influenced configuration, staffing, monitoring, quality, and governance.
CDD evidence should distinguish customer assertion, registry information, independent source evidence, unavailable information, analyst inference, and provider output. The file should support a clear view of identity, ownership/control, purpose/nature of relationship, expected activity, source-of-funds or wealth evidence where proportionate, risk rating, enhanced measures, approvals, review and event triggers, exceptions, and linked monitoring. A record with many documents can still be weak if source provenance, conflicts, dates, reviewer judgment, or the reason for the risk conclusion are not visible. Conversely, an appropriately streamlined low-risk process can be defensible if its scope and risk reasoning are documented and tested.
PEP treatment needs particular care. A PEP status should lead to an appropriate risk-based assessment and required governance, not a presumption that every PEP relationship must be rejected or treated as identical. Use current relevant guidance and the applicable legal framework, identify the PEP/family/known-close-associate issue as relevant, record the source and date, distinguish domestic and foreign facts where relevant, document senior-management or other approvals when required, and apply proportionate source-of-wealth/funds, monitoring, and review measures. Quality testing should look for both weak escalation and unjustified over-treatment that creates inconsistent or unfair outcomes. [S15]
Monitoring needs a UK population and threat proof. For each scenario or analytic, identify the customer, account, transaction, product, payment, geography, currency, channel, data fields, rules/model version, exclusions, alert routing, reviewer authority, SAR/fraud/sanctions interfaces, action, QA, and change governance. Pair alert output with coverage and quality testing. A falling alert number may signal calibrated control, or it may signal a new payment flow, data gap, suppression, customer migration, rule change, or capacity constraint. UK product speed and fraud/scam patterns make this distinction operationally important.
Enforcement and Supervisory Lens: Starling Bank financial-crime enforcement
Official record. The FCA announced a penalty for financial-crime failings and described a period involving rapid growth and earlier remediation commitments. [S13]
Operating lesson. Growth, automation and customer experience need explicit control gates, quality evidence, independent challenge and senior ownership.
Limit of inference. The action does not establish that digital banking or fast growth is inherently non-compliant.
21.2 POCA, SARs, DAML and law-enforcement interface
POCA and the Terrorism Act provide critical criminal-law and disclosure context. UK SARs are submitted to the UKFIU, housed in the NCA. A SAR process should preserve the suspicion rationale, facts, account and transaction context, linked persons and entities, narrative quality, action taken, confidentiality and record retention. The report should help the UKFIU understand what happened and why the institution is suspicious; it should not be written as an internal alert log. [S02][S03][S07]
DAML is not an automatic “safe harbor” or generic escalation label. It is a specific process for asking for a defence in relation to particular activity where the relevant legal threshold and process apply. Institutions need tight legal, financial-crime, operations, customer and law-enforcement governance around DAML: when to raise it, what activity is in scope, what to do while a request is pending, how to protect confidentiality, and how to document any subsequent action. [S08]
Enforcement and Supervisory Lens: Barclays Bank UK final notice
Official record. The FCA published a final notice concerning Barclays Bank UK plc. [S14]
Operating lesson. Final notices should be used as control-evidence case studies: establish facts, affected systems/decisions, root causes, remediation proof and limits of inference.
Limit of inference. The specific notice must be read directly; this module does not extend its conclusions beyond the stated facts.
21.2A SAR and DAML decision lifecycle
The SAR case file should be designed so a later reviewer can understand the reasoning without exposing information beyond the permitted audience. Capture the source signal; customers, accounts, entities, counterparties, transactions and devices or other relevant identifiers; facts reviewed and unavailable; linked activity and prior reports; analyst assessment; suspicion rationale; narrative support; approval and filing timing; confidentiality handling; related fraud, sanctions, customer or account actions; and post-report monitoring. The unit of quality is the defensible decision and contextual report, not the number of filings or alerts cleared.
DAML governance should start with a precise question: what activity is being considered, what facts create the relevant concern, what legal and operational route is available, which decisions need to be paused or escalated, and what customer/confidentiality constraints apply? Define the legal authority, senior escalation, operations owner, case manager, time and activity scope, evidence-preservation steps, communication controls, review of any response, and action after the decision. A request should not become a substitute for an account-exit, sanctions, fraud, or customer-service decision; those decisions may be connected, but their standards and authorities differ.
Law-enforcement, regulator, court, and internal-investigation requests require a controlled intake. Authenticate the source and authority; identify scope and deadline; preserve potentially relevant records and data; coordinate legal, privacy, SAR confidentiality, sanctions, fraud, and cross-border restrictions; control access; keep a production log; and record what was provided, to whom, why, and with which approval. Retain a single chronology of the matter while preserving distinct case records where confidentiality or legal purpose requires it. An urgent operational request should not bypass the record of disclosure authority or evidence preservation.
Account action must remain a separate, customer-aware decision. A financial-crime concern might lead to more information, monitoring, an intervention, a temporary restriction, a report, an exit, or no immediate customer action. Record the legal/policy basis, facts, customer-impact assessment, decision authority, communications restrictions, complaint/escalation route, and review date. This prevents a SAR/DAML pathway from becoming a vague or opaque rationale for customer treatment and helps the firm show that it acted proportionately during uncertainty.
21.3A Sanctions decisions, licensing, and quality controls
A UK sanctions alert is not resolved by a name score alone. The case record should show the input data and system version; list/source date; identifiers, aliases, addresses, nationality, ownership/control, payment, trade, asset, product, and geographic facts reviewed; potentially applicable sanctions regulation; match/entity-resolution rationale; legal and policy escalation; whether a freeze, rejection, reporting, licensing, or other action is being considered; decision owner; timing; customer/counterparty communication controls; and post-action monitoring. A “false positive” or “clear” conclusion without a sufficient comparison of material identifiers and facts is not a defensible evidence record.
Ownership/control analysis deserves specialist governance. The relevant UK sanctions legal framework, applicable regulations and OFSI guidance must be checked for the fact pattern; a generic AML beneficial-owner percentage or a customer’s declaration should not be substituted for the required legal analysis. Layered ownership, trusts, nominees, rapidly changing corporate records, high-risk jurisdictions, opaque structures, and conflicting source evidence should trigger a defined escalation route. Preserve the sources, dates, assumptions, legal analysis, and conclusion so a future reviewer can identify why the firm acted as it did.
Licensing and authorization questions should be routed from the same factual record. Identify the relevant prohibition, parties/ownership, asset/activity, timing, nexus, source/version of relevant permission or guidance, conditions, legal review, operational safeguards, reporting, and retained evidence. Do not let a generic “license may apply” status linger in a queue without ownership and decision timing. If a temporary hold or restriction is used while facts are established, document its basis, owner, customer impact, review/expiry, and the next decision.
Sanctions assurance should include list-update and data coverage tests, match quality, ownership/control cases, overrides, false clears, actions/reports, licensing handling, provider/shared-service handoffs, and customer communications. Test actual products and payment/trade/customer populations, not just the screening engine’s aggregate performance. When an incident occurs, reconcile the potentially affected population and duration, preserve evidence, decide containment and notification/reporting implications, and track correction/lookback and root cause. Sanctions controls can share data with AML and fraud, but their action and evidence standard must remain visible.
21.4 Corporate transparency and KYB
Companies House reforms under the Economic Crime and Corporate Transparency Act create important changes to identity verification and corporate information. For financial institutions and other obliged entities, the strategic lesson is not “the registry now performs KYC.” The firm still must satisfy its own legal and risk-based CDD duties. A registry record may be valuable evidence for legal existence, directors, persons with significant control, filings, identifiers and changes; its scope, access, timing and verification status must be understood. [S10][S11]
The stronger KYB design records the registry source, date, access condition, relevant fields, customer declaration, conflicts, independent corroboration, reviewer, decision and refresh trigger. It tests structural signals such as nominee indicators, shared contact data, unexplained complexity, recent changes, opaque ownership, disconnected operating footprint and transaction patterns. It does not treat any one field or threshold as a complete conclusion.
21.4A Corporate transparency, ECCTA transition, and KYB control
Corporate-transparency change should be managed as a data and evidence transition, not a one-time registry integration. Maintain an inventory of the Companies House information and services used by each entity/process; what the record establishes and does not establish; access and verification conditions; source/date; data-quality limitations; update/event triggers; mapping to the customer’s declaration and other independent evidence; conflict/escalation route; and retention/audit use. Link the inventory to the ECCTA and Companies House transition information, but do not infer a particular firm obligation solely from a public implementation statement. [S10][S11]
KYB should be built from a business-purpose and ownership/control picture. For legal entities, trusts, partnerships, charities, funds, complex group structures, and international customers, identify the legal existence and capacity, controllers/owners and their evidentiary basis, directors/management, purpose and expected activity, source and destination of funds/wealth where appropriate, geographic and sector risk, relationship between parties, and transaction behavior. Where a registry or customer statement is incomplete, contradictory, or stale, the control needs a risk-led path: obtain more information, use an independent source, refer to a specialist, alter risk rating/monitoring, limit activity, make a report decision, or escalate residual risk.
Registry changes are risk events. Monitor changes in directors, PSC data, registered office, filings, identity verification, ownership, insolvency, legal form, or address/contact patterns where relevant to the firm’s risk model. A small data change may be routine, but a cluster of changes or a conflict with customer information can affect KYC, fraud/mule, sanctions, or suspicious-activity analysis. The entity needs controlled data ingestion, evidence of source date, data-quality flags, a case/action path, and QA. Technology that automatically overwrites historic registry facts without preserving prior versions can make later investigation and reporting explanations much weaker.
The UK corporate transparency environment is also a customer-experience issue. Requests for additional evidence, customer restrictions, or business rejection should be proportionate and explainable within legal/confidentiality limits. Product, onboarding, compliance, fraud, legal, and customer-support teams should share a controlled understanding of what the firm needs, why the registry did or did not resolve the issue, who can approve exceptions, and how complaints or urgent commercial impacts are escalated. This is how a stronger KYB process avoids both superficial verification and unjustified friction.
21.5 Fraud, APP scams and FRAML
UK payments and fraud risks make the relationship between fraud and AML unusually operationally important. APP scams can create immediate customer-harm, payment-intervention, reimbursement, mule-account, suspicious-activity and law-enforcement questions. The Payment Systems Regulator’s APP-scam work illustrates that payment firms must consider consumer outcomes as well as crime disruption. [S16]
A mature FRAML operating model differentiates prevention, authentication, scam intervention, customer communication, recovery, reimbursement, mule-network analysis, suspicious-activity investigation, SAR decision, account restrictions and feedback. It should not assume every victim is a suspect or every mule pattern is a reason for immediate irreversible action. It needs calibrated intervention, evidence, escalation, appeal/complaint awareness, intelligence sharing and post-event analysis. The safest model connects fraud signals to AML insight while keeping legal triggers, customer-protection duties and decision authorities visible.
21.5A APP scams, mule networks, customer harm, and intelligence routing
An APP-scam or suspected-mule event should enter a coordinated but differentiated operating model. First establish the immediate payment and customer-safety facts: who initiated/authorized the payment, what authentication and warning/intervention evidence exists, whether a recipient relationship/account may be involved, what recovery or payment-system action is possible, and what information can be shared. Then determine the financial-crime intelligence path: whether behavior, network relationships, devices, accounts, customer information, or transaction patterns require fraud investigation, AML investigation, a SAR consideration, sanctions escalation, customer-risk review, or a law-enforcement interface. A single “fraud case” outcome hides too much.
Mule-network analysis needs controlled corroboration. Signals can include fast receipt-and-dispersal, unusual account opening or identity patterns, linked devices or contact data, scam victim reports, beneficiary behavior, cash-out patterns, repeated account changes, or intelligence from other teams/partners where lawfully available. These signals should be assessed with data provenance, confidence, potential alternative explanation, urgency, and customer impact. An institution should not assume that every customer receiving suspicious funds is knowingly involved, or that the absence of a single signal proves safety. Escalate complex relationships and preserve the evidence that led to intervention, reporting, or no action.
Customer action and reimbursement/recovery processes should synchronize without determining each other automatically. A timely intervention may be necessary to protect a customer while AML or fraud analysis continues; an account restriction could create financial hardship or alter customer communications; a reimbursement decision may require facts and a route that differ from a suspicious-activity decision. Define authority, permitted case-data sharing, sensitive-information controls, customer communication, complaint/review path, review dates, and post-event learning. This helps the firm avoid a situation where a customer-impact team promises an outcome that a financial-crime escalation has made legally or operationally impossible.
Metrics should show both harm prevention and control quality: scam interventions, funds prevented/recovered, customer-contact timing, reimbursement/recovery status, mule-network escalations, SAR quality/timeliness, false or reversed restrictions, complaints, vulnerable-customer considerations where relevant, data/model failures, and learning actions. Use thematic review to determine whether payment speed, onboarding, product design, warnings, transaction monitoring, or shared intelligence need adjustment. The point is not to merge fraud and AML into one policy; it is to make their intersections safe, timely, fair, and evidentially sound.
21.6 Enforcement lenses: control implementation under growth and complexity
NatWest, Starling and Barclays materials demonstrate the value of reading enforcement as operating evidence. The facts, timing and remedies differ, but recurring themes include customer understanding, risk assessment, transaction monitoring, data and systems, escalation, growth, management oversight and remediation. [S12][S13][S14] No case should be reverse-engineered into a universal rule. However, every institution should ask whether it can reproduce the relevant decision path and show that its controls work for its own scale, products and customer behaviors.
The test is practical: can the board see risk concentration and customer harm; can the first line identify a broken control; can financial crime stop or condition growth; can the second line challenge evidence and claims; can internal audit test the end-to-end outcome; and can the institution show a regulator that remediation has become BAU?
21.6A FCA/OFSI/NCA-facing remediation and governance
A UK remediation program should preserve distinct authority and outcome paths. An FCA systems-and-controls concern, an NCA/UKFIU reporting or intelligence issue, an OFSI sanctions issue, a Companies House/KYB data defect, and a PSR/customer-harm concern may share data or root causes, but they can have different legal deadlines, evidence, customer communications, and regulator engagement. The issue record should identify the legal entity, requirement/control objective, affected population and period, factual record, authority/forum, customer and financial-crime consequence, immediate safeguard, reporting/notification decision, root cause, remediation, dependencies, accountable owner, validation, residual risk, and closure authority.
Read official FCA enforcement material as a test of operating evidence, not a questionnaire. For each relevant case theme—rapid growth, customer/risk assessment, monitoring, data, governance, remediation, or control ownership—ask whether the firm can identify its own in-scope population, decision path, evidence, management information, controls, quality, exceptions, and escalation. If an answer is weak, open a targeted assessment. Do not copy an enforcement remedy without verifying the institution’s legal perimeter, facts, products, customer behavior, and current official source.
Closure needs BAU proof. The entity should demonstrate that an approved target design exists; the affected population and legal/UK configuration are live; staff and shared services have the procedure/access/training; data and reports reconcile; QA and independent testing have tested actual cases, including high-risk and edge conditions; the owner has capacity and metrics; root causes have been addressed; and residual risks/limitations are formally accepted with review dates. A new rule, a policy publication, a backlog reduction, or a system go-live is an implementation event, not sufficient evidence of sustainable remediation.
Senior governance should receive explicit decision choices. Report what is known and unknown, the relevant authority or legal advice, population/period, customer and financial-crime impact, actions taken, information restrictions, interim safeguards, dependencies, resource need, validation results, residual risk, and recommended decision. This protects the board from being told that an issue is “on track” when the control evidence or legal risk remains unresolved, and gives UK accountable leaders a record of proportionate decision making.
21.7 UK operating cadence, governance, and assurance
A UK financial-crimes cadence should make law, supervisor, customer, and intelligence outcomes visible at once. Periodically review legal/regulatory change; business/entity perimeter; risk assessment; CDD/EDD and PEP quality; monitoring and payment coverage; SAR/DAML health; sanctions cases and data; fraud/APP scam/customer outcomes; corporate-transparency/KYB developments; data/model and shared-service dependencies; staffing/capacity; QA and independent testing; authority engagement; issues and remediation. The agenda should distinguish operational metrics from formal legal duties and record who can make or escalate each decision.
Management information needs local fidelity. Track in-scope customer, account, transaction, payment, product, agent/intermediary and high-risk segment populations; alert/case arrivals, aging and outcomes; SAR/DAML timing and quality; sanctions match/action/reporting; fraud interventions, customer contacts, recovery and complaint measures; CDD refresh and evidence gaps; data feed completeness; QA errors/rework; exception/override; testing findings; provider/service performance; and remediation progress. For material changes, require a causal explanation: a decline in alerts, reports or customer contacts may reflect successful prevention, but it may also reflect a population exclusion, data defect, rule change, staffing issue, or unrecorded suppression.
Assurance should use multiple lenses. First-line quality should test real work against procedures and evidence. Second-line testing should challenge risk assessment, data, coverage, decision logic, escalation, and management claims. Internal audit should independently assess design and operation. Thematic reviews should follow UK risks such as APP scams, mule networks, high-risk corporate structures, PEP treatment, payment speed, sanctions ownership/control, and growth of new digital channels. Use complaints, reversals, fraud losses/recovery, customer outcomes, authority requests, and external intelligence as signals, not as isolated conduct metrics.
Scenario exercises should test whether the organization can act under pressure: a suspected sanctions property issue, a DAML question involving a time-sensitive activity, a significant APP scam/mule network, a Companies House/identity data defect, a material SAR quality issue, a provider failure, or a regulator/UKFIU request. The test should show who owns the case, what data and evidence are available, what can be shared, what action is permitted, how customer impact is managed, how reports and confidentiality are protected, and what happens if a critical dependency fails. This is a more meaningful proof of resilience than a policy attestation.
21.8 Cross-border UK cases and global service design
Cross-border UK cases need a coordinated case plan rather than a generic global escalation. Record the UK legal entity and role, customer/account/payment facts, foreign entities and legal systems, UKFIU/SAR or DAML relevance, UK sanctions/OFSI question, fraud/customer-harm implications, foreign FIU or regulatory reports, data-access/transfer and confidentiality constraints, records location, decision authorities, and time-critical actions. Separate the facts from the legal conclusions and preserve local legal advice and the exact evidence available at the time of each decision.
Global shared services must not erase the UK edge. A central screening, case-management, data-science, operations, fraud, or customer-support team should have an explicit service specification that identifies UK procedure/configuration, lawful access, SAR/DAML confidentiality, OFSI action/reporting interface, UK fraud/customer process, language and legal support, QA, incident response, audit/regulator access, continuity, and exit. The UK entity must retain accountable decision makers and the ability to retrieve evidence. The global team must know when a UK rule or authority commitment changes the work.
Data and intelligence sharing should be purpose-specific. A central team may need a risk conclusion, controlled case record, metrics, or redacted quality sample rather than unrestricted access to raw SAR/DAML or customer information. Conversely, a UK investigator may need group information to understand a linked network. Design the permitted data and escalation path, recipients, security, retention, source provenance, and review. This lets the group use scale without assuming that a global operational convenience overrides UK confidentiality, privacy, sanctions, reporting, or customer-protection constraints.
The same principle applies to outgoing UK information. Before sharing a UK case or intelligence output to an affiliate, authority, provider, partner, or group function, identify the recipient, purpose, legal/policy basis, permitted scope, confidentiality restriction, approval, record, and downstream use. Train teams to distinguish a request for operational assistance from an authorized information-sharing decision. That discipline protects investigations and customers while preserving a useful global financial-crime intelligence network.
21.9 Product change, payment speed, and controlled growth
UK product and growth governance should identify the financial-crimes control consequences before scale changes the risk. For a new payment, account, digital channel, credit/wealth feature, intermediary/agent, corporate onboarding path, or customer segment, document the legal entities and roles; customer and transaction populations; money/information flows; MLR, sanctions, SAR/DAML, fraud/APP, corporate-transparency, consumer, and data considerations; controls; data sources; reports/actions; staffing and specialist capacity; third-party dependencies; customer communication; testing; and accountable owners. Treat an “integration complete” milestone as a technical fact, not proof that the legal/control design works in production.
Use staged release and growth gates. Start with a defined population and permitted activity; validate CDD/KYB, PEP, sanctions, monitoring, fraud/scam, payment, reporting, and customer-support data; run quality and exception review; monitor outcomes; and make the next expansion conditional on evidence. Define stop conditions such as material data loss, unmanageable high-risk aging, SAR/DAML or sanctions escalation failure, fraud/customer-harm threshold, missing evidence, provider outage, or inability to meet a legal/reporting time standard. A UK growth decision should record the business benefit, customer consequence, residual risk, authority, and review date rather than leaving a risk appetite decision implicit.
Payment speed needs particular challenge. Faster payments can improve customer outcomes, but they reduce time for intervention, evidence collection, sanctions/fraud/AML escalation, customer contact, recovery, and provider coordination. Map the decision points before initiation, during authentication/warning, after payment instruction, after recipient screening, during suspected scam/mule intervention, and after a report or customer complaint. Determine which steps are automated, which need human authority, what evidence is retained, and how failures are detected. A process that is fast but cannot explain why it intervened or failed to intervene is not an effective financial-crime control.
Product review should continue after launch. Compare approved assumptions with actual customer, transaction, alert, SAR, sanctions, fraud, complaint, reimbursement, data-quality, exception, and capacity outcomes. Investigate unexpected movements and refresh risk/control design. This creates a feedback loop between innovation, customer experience, financial-crime intelligence, and supervisory evidence rather than waiting for a fraud event or FCA action to reveal that the launch model was incomplete.
21.10 Records, data lineage, and reproducible decisions
A UK program needs a record architecture that lets it reconstruct consequential decisions without overexposing sensitive information. For customer and entity decisions, preserve source, date, provenance, document/version, translation where relevant, analyst inference, risk rating/rationale, approval, refresh and action. For monitoring and fraud/sanctions decisions, preserve input data, rules/model versions, alerts, enrichment, investigator steps, overrides, action/report rationale, communications restrictions, and quality outcome. For SAR/DAML, apply heightened access, confidentiality, retention, and disclosure controls. The exact legal requirements are fact-specific, but the operating principle is consistent: the evidence should be identifiable, retrievable, secure, and linked to the decision it supports.
Data lineage should identify source systems and transformations, missing fields, entity resolution, record linkage, user access, provider/service contribution, and temporal context. A decision made today may later be reviewed against the data and rules available then, not merely current records. Preserve configuration and release history for material screening, monitoring, fraud, or risk-rating logic. If a source is corrected, retain the correction path and assess whether historic decisions need review. This is essential where a Companies House record, payment data field, sanctions list, fraud signal, or customer declaration changed after a case was closed.
Access control is an operational and customer-protection control. Define which roles can access raw data, sensitive case records, SAR/DAML material, sanctions/legal advice, fraud customer contacts, and quality samples; review access periodically; control exports and provider access; preserve audit logs; and establish secure routes for legal, regulatory, audit, and law-enforcement requests. A global case platform should not default to unlimited group visibility simply because that is technically convenient. Conversely, UK decision owners must have access to the information they lawfully need to discharge their obligations.
Test reproducibility through real cases. Select a high-risk CDD/KYB case, a SAR/DAML case, a sanctions case, an APP-scam/mule case, and a product/change release. Ask whether an independent reviewer can trace source facts, rule/configuration, owner, escalation, decision, action/report, quality result, and subsequent learning. Where reconstruction fails, identify whether the root cause is data, retention, access, procedure, system, vendor, training, or governance, then treat it as a control issue rather than an administrative inconvenience.
21.11 Third parties, agents, and retained accountability
External providers, agents, cloud services, data suppliers, program managers, payment partners, investigators, screening platforms, and shared group services can add capability but also create UK control risk. Before relying on a service, map the activity, legal entity, customer/transaction population, decision rights, data and access, UK legal/supervisory implications, service locations, subcontractors, quality method, incident escalation, record retention, audit/regulator access, continuity, concentration, and exit. The regulated entity needs a retained control owner able to understand the service, challenge performance, inspect evidence, and condition or stop activity.
Service-level reporting should include control outcomes, not only volume and turnaround. Track data completeness, coverage, match/alert quality, investigation quality, report/action timing, customer impact, exceptions, override, staff training/turnover, incidents, subcontractor changes, access, and root-cause actions. Sample high-risk work and changes; test whether UK procedure, confidential information, OFSI/SAR/DAML pathways, fraud/customer communications, and records are handled correctly. A provider certificate or dashboard can inform oversight, but it does not replace the entity’s assurance conclusion.
Exit readiness is a test of accountability. For a critical provider or group service, identify how to retrieve open work and evidence, prioritise time-sensitive decisions, maintain access to required systems/data, transition users and procedures, protect SAR/DAML and sanctions confidentiality, communicate with customers/authorities as required, restore QA, and validate the handover. Rehearse scenarios such as a data-access failure, quality collapse, provider financial distress, cyber incident, sanctions concern, or regulatory restriction. A contractual termination clause is not an operating exit plan.
Internal centralisation should be tested using the same logic. A group team may not be a legal third party, but if it performs critical UK data, screening, investigation, or decision activity, the UK entity still needs explicit authority, evidence access, local configuration, escalation, assurance, and continuity. “In-house” does not automatically mean the UK control is observable or accountable.
21.12 Benefits realization and sustainable UK remediation
A UK financial-crimes remediation or transformation should state the target control outcome, legal/supervisory or risk basis, affected entity/population, current-state limitation, data/process/system/staffing dependencies, interim safeguard, target design, responsible BAU owner, testing/validation, customer impact, residual risk, and evidence required for closure. Do not record only projects, milestones, or policy updates. A successful release must demonstrate that UK legal and operational configuration actually reached the intended customer, transaction, product, or case population.
Benefits should be recognized only after an observation period. A reduction in alerts, backlog, cost, customer contacts, fraud loss, or manual work may be valuable, but management must test whether coverage, decision quality, SAR/sanctions/fraud outcomes, customer harm, data integrity, and resilience held or improved. Preserve baseline, population, calculation method, assumptions, exceptions, QA, adverse-event trigger, independent review, and booking decision. Otherwise a claimed efficiency can be an unrecorded transfer of risk into a less visible queue or customer outcome.
Closure evidence should distinguish implemented, operating, effective, and sustainable. Sustainable means procedure, trained people, funding/capacity, data/support, management information, QA, independent testing, issue process, authority engagement, and periodic reassessment are in BAU. For material findings, map each commitment to the control, evidence, validation, limitation, residual-risk acceptance, and final closure authority. This turns a high-pressure UK remediation into durable capability rather than a temporary programme layer.
21.13 Risk appetite, de-risking, and customer communications
A risk-based UK program needs an explicit view of risk appetite and customer consequence. Identify which customer, product, geographic, payment, intermediary, ownership, data, fraud/scam, sanctions, and operational conditions are within appetite; which require enhanced review or controls; which may be accepted only with senior approval or restrictive conditions; and which are prohibited or require exit under law, policy, or risk appetite. Make the decision rights visible. A frontline team should not have to infer from a risk score whether it can onboard, restrict, or retain a relationship, and a commercial team should not be able to override a financial-crime condition without recorded authority and evidence.
De-risking should not be treated as proof of safety. Broad exits can reduce a metric while moving financial-crime risk into less transparent channels, creating harm for lawful customers, or concealing a failure to understand the population. Conversely, maintaining a relationship without adequate evidence, monitoring, sanctions/fraud controls, capacity, or escalation can be unsafe. Before a material customer or segment action, define the risk reason, legal/policy basis, facts, alternatives, expected customer impact, data and evidence gaps, conditions, decision authority, communication constraints, complaint/review route, and monitoring/refresh. Test outcomes by customer type and risk, including whether a decision becomes an operational proxy for a protected or vulnerable characteristic without a legitimate control basis.
Customer communication is part of the control design. Fraud and APP-scam intervention may require a clear, empathetic, time-sensitive explanation; a sanctions or SAR/DAML-related matter may impose legal or confidentiality constraints; a CDD/KYB request may be routine but can cause significant friction if it is repetitive or incoherent. Train customer-facing teams on what they may say, when to escalate, how to avoid tipping-off or prejudicing an investigation, how to preserve a complaint/review path, and how to record the interaction. The case system should distinguish a confidential financial-crime rationale from the operational instruction that customer support needs to execute lawfully and fairly.
Use outcome evidence to govern the appetite. Track relationship decisions, additional-information requests, restrictions, exits, reversals, complaints, vulnerability or hardship indicators where lawfully appropriate, fraud/scam interventions, recovery/reimbursement outcomes, SAR and sanctions escalation, QA errors, and capacity/data constraints. Review patterns by product, customer segment, geography, service channel, and decision owner. When trends show rising friction, repeated reversals, unexplained exits, or disproportionate treatment, determine whether the cause is risk, data, policy, training, system design, provider behavior, or a flawed incentive. The goal is a program that can protect the system and customers without confusing risk management with a reflex to deny access.
4. Cross-Border Operating Model
The UK should be treated as a distinct regulatory and operating market, not an EU “regional variation.” UK legal, FIU, sanctions, corporate transparency, payments, fraud and consumer frameworks have their own architecture even where concepts share a FATF ancestry. A global group should standardize risk taxonomy, data model, evidence lineage, model governance, QA standards and core case-management logic. It should configure the UK legal and supervisory edge: UKFIU reporting, DAML protocol, OFSI action/reporting, FCA governance, Companies House evidence, PEP treatment, APP scam/customer-harm process and UK data-access rules.
Cross-border cases require careful sequencing. A global investigation may need UK SAR, foreign FIU report, sanctions escalation, fraud action and data-transfer assessment. The correct answer is not a one-size-fits-all “global case.” It is a coordinated case plan that identifies each legal entity, authority, report, action, data path, confidentiality requirement, owner and decision timestamp.
5. Practical Frameworks and Assurance
Framework 01: The System Proof Test
Use the following ten questions before declaring a capability effective. This is a library operating framework, not a regulatory checklist.
- Is the applicable legal, regulatory, supervisory and policy question explicitly classified?
- Is the in-scope population known, reconciled and versioned?
- Is the required customer, entity, transaction, data or evidence object complete enough for the decision?
- Is the accountable owner clear, including the local legal-entity owner where relevant?
- Does the workflow distinguish prevention, detection, investigation, reporting, action and assurance?
- Are there measurable quality, timeliness, coverage and customer-impact guardrails?
- Can a reviewer reconstruct the rule, source, data, reasoning, override, action and report?
- Can the system absorb a surge, data failure, vendor failure, legal change or material risk event?
- Has independent challenge tested real decisions and not only written procedures?
- Does the learning loop make a controlled change, retain the evidence and test whether it worked?
Framework 02: Outcome Dashboard
| Outcome | Leading / lagging indicators | Evidence source |
|---|---|---|
| Decision quality | Accuracy, completeness, timeliness, consistency, explained overrides | QA, independent testing, case review and regulatory challenge |
| Coverage | Population, product, channel, data and legal-entity inclusion | Coverage map, reconciliations, negative testing and change control |
| Customer / counterparty outcome | Friction, hold/release timing, complaints, remediation and fairness | Journey evidence, service data, root-cause analysis and governance |
| Resilience | Surge capacity, data dependency, vendor concentration, recovery and key-person exposure | Scenario test, service review, continuity exercise and exit plan |
| Learning | Issue recurrence, typology feedback, model/process change and post-implementation result | Root-cause log, risk acceptance, validation and BAU monitoring |
The dashboard should be read as a pattern, not a scorecard contest. A sharp reduction in alert volume may be good, bad, or meaningless depending on the covered population, detection precision, missed-risk testing, quality, account/action outcomes and source data. A backlog decline may signal stronger process design, or it may result from relaxed review, unrecorded exceptions, data loss or customer exits. The governance record should require the owner to explain the causal story and the independent challenger to test it.
Framework 03: Decision-Rights Map
| Role | Minimum decision rights and evidence |
|---|---|
| Global owner | Common standard, data/evidence grammar, control taxonomy, model/vendor/QA framework, thematic risk and escalation. |
| Local entity owner | Local legal translation, reportability, data access, customer action, supervisory engagement, local source and procedure. |
| Independent challenge | Second-line challenge, quality, validation/audit, issue severity, evidence review and residual-risk escalation. |
| Executive forum | Risk appetite, funding, material exceptions, product/growth conditions, remediation closure and authority engagement. |
6. What Good Looks Like / What Failure Looks Like
What mature, defensible, sustainable capability looks like
- Mature / defensible: A UK obligation map that separates MLR, POCA/SAR, DAML, sanctions, fraud/APP, corporate-transparency and conduct pathways while sharing evidence appropriately.
- Mature / defensible: A UKFIU reporting process that produces clear, timely, contextual SARs and protects confidentiality.
- Mature / defensible: A fraud-to-AML feedback loop with defined customer-harm, reimbursement, mule-network and account-action governance.
- Mature / defensible: Companies House information used as a dated, attributable evidence source within a broader KYB and conflict-resolution process.
- Mature / defensible: Board and management information that connects control performance, financial crime, customer impact, growth and remediation.
What weak, misleading, fragile, or non-defensible implementation looks like
- Fragile / non-defensible: A UK program that confuses reporting a SAR with receiving a legal defence, closing an account, or reporting sanctions.
- Fragile / non-defensible: A sanctions alert process that lacks program-specific legal analysis, ownership/control evidence, action and OFSI reporting trail.
- Fragile / non-defensible: A FRAML model that treats victims as suspects, fails to route mule intelligence, or lets reimbursement and AML teams make uncoordinated decisions.
- Fragile / non-defensible: A Companies House record treated as complete proof of identity, ownership, control or legitimacy.
- Fragile / non-defensible: A global process that suppresses UK local accountability, reportability and regulator engagement in favor of a generic regional dashboard.
7. Common Misconceptions and Contrarian Insights
“A SAR lets us proceed with the activity.”
A SAR and a DAML request have different legal functions; account and activity decisions need their own legal and policy analysis.
“OFSI screening is just another AML control.”
Sanctions require their own legal trigger, action, reporting and licensing analysis, even when they share data with AML.
“APP fraud is only a conduct issue.”
Scams, mule networks and payment patterns can be financial-crime intelligence, customer-harm and reporting issues at once.
“Companies House verification replaces KYB.”
It can improve evidence quality but does not remove a firm’s CDD, risk-assessment or escalation duties.
“The FCA Financial Crime Guide is statute.”
It is supervisory guidance; regulated obligations must be sourced to the applicable legal and regulatory framework.
8. Executive Discussion Questions
- Can senior management distinguish the UK legal and operational paths for CDD, SAR, DAML, sanctions, APP fraud and customer action?
- Does our SAR process provide enough context for the UKFIU and preserve the confidentiality required by law?
- What fraud signals should be routed to AML, and which customer-protection controls must remain independent?
- How do we make a reversible, defensible account-action decision during an APP scam or mule investigation?
- Which Companies House facts do we accept as evidence, which do we corroborate, and how do we record conflict?
- Do we retain enough sanctions evidence to show the applicable program, ownership/control analysis, action and report?
- What control indicators should condition product growth, payment speed or customer onboarding in the UK?
- How do UK local governance and group policy interact when a local supervisor expects a different escalation or evidence route?
- Are FCA enforcement lessons translated into targeted testing, not generic policy rewrites?
- Can we show how our PEP process is risk-sensitive, fair and operationally consistent?
- Which UK data, language, legal or market elements cannot be centralised without an explicit design and approval?
- Who owns post-remediation proof that a UK control is sustainable in BAU?
9. Practitioner and Specialist Checklists
Executive checklist
- Can we name the legal / policy question, accountable executive, local legal entity and decision authority?
- Can we see current evidence on coverage, quality, timeliness, customer impact, resilience and residual risk?
- Can we distinguish regulatory requirement, supervisory expectation, operating recommendation and untested assumption?
- Can we condition growth, product scope, outsourcing, data use or customer action when a guardrail is breached?
- Can we prove that a completed remediation is operating in BAU rather than merely deployed?
Operator checklist
- Map each decision to an in-scope population, trigger, data/evidence, procedure, system, owner, escalation, action and record.
- Reconcile source, case, report, action and quality data; do not allow unresolved data loss to become a business-as-usual assumption.
- Version rule, process, model, vendor, translation and report changes; retain test evidence and rollback/contingency decisions.
- Route complex, ambiguous, high-risk, cross-border, language or legal issues to named specialists with documented outcomes.
- Run recurring QA and root-cause analysis that reaches upstream policy, data, product, training and technology causes.
Specialist validation checklist
- Verify the applicable legal source, current effective date, scope, entity, product and authority before applying a control conclusion.
- Preserve primary source, locator, original language where relevant, translation/version, collection date, confidence and decision use.
- Test negative cases, population coverage, false positives, false negatives, overrides, edge conditions, timing and evidence reproducibility.
- Separate legal requirement, supervisory expectation, market practice and library operating inference in analysis and documentation.
- Record local variations, data restrictions, report interfaces, translation debt, legal advice and residual-risk decisions explicitly.
10. Module Glossary
| Term | Definition |
|---|---|
| DAML | Defence Against Money Laundering, a UKFIU/NCA process that requires careful fact- and law-specific use. |
| MLRs | The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. |
| OFSI | Office of Financial Sanctions Implementation, within HM Treasury. |
| POCA | Proceeds of Crime Act 2002. |
| SAR | Suspicious Activity Report submitted to the UKFIU under applicable UK law; distinct from a criminal finding. |
| UKFIU | United Kingdom Financial Intelligence Unit, housed in the National Crime Agency. |
| APP scam | Authorised push payment scam, where a payer is deceived into authorising a payment. |
| PSC | Person with Significant Control, a Companies House corporate-transparency concept distinct from every firm’s own CDD conclusion. |
11. MLA 9 Works Cited
[S01] United Kingdom. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. SI 2017/692, https://www.legislation.gov.uk/uksi/2017/692/contents. Accessed 9 Aug. 2026.
[S02] United Kingdom. Proceeds of Crime Act 2002. https://www.legislation.gov.uk/ukpga/2002/29/contents. Accessed 9 Aug. 2026.
[S03] United Kingdom. Terrorism Act 2000. https://www.legislation.gov.uk/ukpga/2000/11/contents. Accessed 9 Aug. 2026.
[S04] United Kingdom. Sanctions and Anti-Money Laundering Act 2018. https://www.legislation.gov.uk/ukpga/2018/13/contents. Accessed 9 Aug. 2026.
[S05] Financial Conduct Authority. Financial Crime Guide. https://api-handbook.fca.org.uk/files/sourcebook/FCG.pdf. Accessed 9 Aug. 2026.
[S06] Financial Conduct Authority. Money Laundering and Terrorist Financing. updated 11 Feb. 2026, https://www.fca.org.uk/firms/financial-crime/money-laundering-terrorist-financing. Accessed 9 Aug. 2026.
[S07] National Crime Agency. Suspicious Activity Reports (SARs). https://www.nationalcrimeagency.gov.uk/what-we-do/crime-threats/money-laundering-and-illicit-finance/suspicious-activity-reports-sars. Accessed 9 Aug. 2026.
[S08] National Crime Agency. Defence Against Money Laundering (DAML). https://www.nationalcrimeagency.gov.uk/what-we-do/crime-threats/money-laundering-and-illicit-finance/daml. Accessed 9 Aug. 2026.
[S09] Office of Financial Sanctions Implementation. OFSI Annual Review 2024-25. HM Treasury, https://www.gov.uk/government/publications/ofsi-annual-review-2024-to-2025. Accessed 9 Aug. 2026.
[S10] Companies House. Verifying Your Identity for Companies House. GOV.UK, https://www.gov.uk/guidance/verifying-your-identity-for-companies-house. Accessed 9 Aug. 2026.
[S11] Companies House. Economic Crime and Corporate Transparency Act: Outline Transition Plan for Companies House. GOV.UK, https://www.gov.uk/government/publications/economic-crime-and-corporate-transparency-act-outline-transition-plan-for-companies-house/economic-crime-and-corporate-transparency-act-outline-transition-plan-for-companies-house. Accessed 9 Aug. 2026.
[S12] Financial Conduct Authority. FCA Fines NatWest £264.8m for Anti-Money Laundering Failings. 13 Dec. 2021, https://www.fca.org.uk/news/press-releases/fca-fines-natwest-aml-failings. Accessed 9 Aug. 2026.
[S13] Financial Conduct Authority. FCA Fines Starling Bank £28,959,426 for Financial Crime Failings. 2 Oct. 2024, https://www.fca.org.uk/news/press-releases/fca-fines-starling-bank-financial-crime-failings. Accessed 9 Aug. 2026.
[S14] Financial Conduct Authority. Final Notice 2025: Barclays Bank UK plc. 14 July 2025, https://www.fca.org.uk/publication/final-notices/barclays-bank-uk-plc-2025.pdf. Accessed 9 Aug. 2026.
[S15] Financial Conduct Authority. FG25/3: Treatment of Politically Exposed Persons. 18 July 2024, https://www.fca.org.uk/publications/finalised-guidance/fg25-3-treatment-politically-exposed-persons. Accessed 9 Aug. 2026.
[S16] Payment Systems Regulator. Authorised Push Payment Fraud Reimbursement Requirement. https://www.psr.org.uk/our-work/app-scams/. Accessed 9 Aug. 2026.