Updated: anti-money laundering guidance.

CCAB updates its guidance for accountants

IP-nov-25

The anti-money laundering (AML) framework applying to businesses within the regulated accountancy sector has been updated following the introduction of the Money Laundering and Terrorist Financing (Amendment) Regulations 2026.

The amending regulations came into force on 30 June 2026 and make a number of focused amendments to the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the MLRs). The changes have also been reflected in the updated anti-money laundering guidance for the accountancy sector (AMLGAS).

Although many of the amendments are intended to clarify the existing requirements rather than introduce fundamentally new obligations, firms should review their AML policies and procedures to ensure that they remain aligned with the updated legislation and guidance.

A more targeted approach to enhanced due diligence

One of the important clarifications concerns when enhanced customer due diligence (EDD) should be applied to transactions.

Previously, the MLRs referred to transactions that were ‘complex or unusually large’. This wording could potentially result in firms treating transactions as requiring EDD merely because they were complex or involved a significant amount of money.

The amended legislation now refers to transactions that are ‘unusually complex or unusually large’ in the context of the relevant sector or type of transaction.

The change is intended to enable firms to take a more proportionate, risk-based approach. The fact that a transaction is complex or has a high monetary value will not, by itself, necessarily mean that EDD is required. Firms should consider whether the transaction is unusual when viewed against the circumstances of the particular customer, business activity and type of transaction.

This should help firms distinguish between legitimate transactions that are part of a customer's normal activities and transactions that present characteristics warranting additional scrutiny.

What counts as a high-risk third country?

The amended regulations also provide greater clarity around the circumstances in which additional measures are required because of a connection with a high-risk third country.

For the purposes of the specific enhanced measures under the MLRs, the relevant countries are those identified by the Financial Action Task Force (FATF) as requiring a call for action, commonly described as the FATF ‘blacklist’.

This clarification is not expected to result in significant changes to the way accountancy firms assess geographical risk. A firm's overall risk assessment should continue to consider the particular circumstances of the client and the jurisdictions involved.

The accountancy sector AML guidance recommends that firms also consider the information contained in the Accountancy AML Supervisors Group (AASG) Risk Outlook when assessing geographical and jurisdictional risk.

It is therefore important that firms do not treat the FATF list as the only source of information when determining whether a particular jurisdiction presents a heightened risk.

Monetary limits are now expressed in pounds

The 2026 amendments convert a number of monetary thresholds in the MLRs from euros into sterling.

The sterling amounts have been set with the intention of maintaining the existing effect of the requirements while ensuring that the thresholds do not undermine the de minimis levels established by FATF standards.

For firms, the practical effect is that relevant internal AML procedures and reference materials should be checked to ensure that any monetary thresholds quoted in policies, checklists or compliance procedures are stated correctly in sterling.

New requirements for providers selling ready-made companies

The regulations also expand the scope of regulated trust or company service provider (TCSP) activities.

The sale of so-called off-the-shelf companies is now brought within the regulated TCSP activities covered by the MLRs.

Consequently, a TCSP involved in selling such companies must comply with the applicable AML requirements. These include carrying out appropriate customer due diligence, applying ongoing monitoring and complying with the firm's wider obligations under the MLRs.

Firms providing company formation or related services should therefore consider whether their activities fall within the expanded definition and review their AML procedures accordingly.

EDD remains a risk-based decision

The updated sector guidance also provides greater clarity about the circumstances in which EDD may be appropriate.

The guidance contains a number of general indicators that may suggest a need for EDD. However, these should not be regarded as a mandatory checklist.

The factors are intended to assist firms in identifying circumstances that may indicate increased risk. They are neither exhaustive nor prescriptive.

Accordingly, a firm should not automatically apply EDD whenever one particular factor is present. Equally, the absence of a listed factor does not mean that EDD can never be appropriate.

The firm's decision should be based on its assessment of the customer's money laundering and terrorist financing risk, taking into account the customer's circumstances, activities, ownership and control structure, geographical exposure and the nature of the services being provided.

This reinforces the importance of documenting the firm's reasoning where EDD is or is not considered necessary.

When should source of funds be established?

The updated guidance also clarifies the circumstances in which firms should undertake source of funds checks.

The requirement is particularly relevant where a transaction appears inconsistent with what the firm knows about the customer, their business or their risk profile. This does not mean that firms must routinely establish the source of funds for every transaction or every customer simply because money is changing hands.

Instead, firms should consider whether the circumstances give rise to a need for further investigation. For example, an unexpected transaction that is inconsistent with the customer's established business activities or known financial circumstances may warrant additional enquiries.

The examples provided in the guidance are illustrative rather than exhaustive. Firms should therefore avoid turning them into rigid rules and should continue to apply a proportionate, risk-based approach.

Where source of funds enquiries are undertaken, firms should also ensure that the information obtained is appropriately documented and that any concerns identified are considered as part of the firm's wider ongoing monitoring and risk assessment.

Strengthening the evidence used to verify identity

A new section of the accountancy sector guidance deals specifically with the evidence that firms can use when verifying the identity of beneficial owners.

The guidance draws on the approach in the Joint Money Laundering Steering Group (JMLSG) guidance and provides a clearer indication of the types of evidence that may be regarded as reliable and independent.

A hierarchy of documentary evidence is provided, with a passport identified as the preferred form of evidence, while other acceptable forms of identification may also be used where appropriate.

The important point for firms is that they should consider the reliability and independence of the evidence obtained rather than simply collecting a particular document as a matter of routine.

Greater clarity around electronic identity verification

The updated guidance also addresses the use of electronic identity verification systems.

Digital verification can provide an efficient way of establishing and verifying a customer's identity. However, firms should consider whether the particular service they are relying upon meets the relevant requirements.

Where a firm uses a digital verification service for identity verification, the guidance explains that the service should be certified and registered under the UK Digital Verification Services (DVS) trust framework.

A digital verification provider that is not certified, and therefore does not appear on the DVS register, should not be relied upon on its own to satisfy the identity verification requirements under the MLRs.

Where the service does not meet these requirements, the firm will need to obtain alternative evidence of identity.

This does not introduce a fundamentally new identity verification obligation. Rather, it gives firms greater clarity over the circumstances in which electronic verification can be relied upon as evidence of compliance.

ACCA and industry guidance recognises that firms may use electronic identification processes, either independently or alongside other evidence. However, firms must consider whether the particular service provides adequate assurance that the individual is who they claim to be and must retain sufficient evidence to demonstrate the checks undertaken and the basis on which the individual’s identity was verified. It is the responsibility of the MLRO to ensure that the firm’s electronic verification processes are appropriate and provide sufficient assurance.

For example, firms should consider whether paper-based evidence, such as a passport or photographic driving licence, is obtained and reviewed before the details are input into an electronic verification service, or whether the electronic verification service itself incorporates appropriate controls, such as biometric checks and requiring identification documents to be uploaded. Where an electronic verification service does not incorporate such controls, and the firm does not retain a copy of the identification document reviewed, the electronic check alone may not provide sufficient assurance that the individual was the person they claimed to be.

Conclusion

The changes introduced in 2026 are relatively targeted, but they provide useful clarification in several areas where firms may previously have taken an overly cautious or inconsistent approach.

The key message is that compliance should remain proportionate and risk-based. Firms should neither apply enhanced measures automatically whenever a particular trigger appears nor assume that no further action is required simply because a circumstance is not expressly listed in the guidance.

The updated accountancy sector AML guidance should therefore be reviewed in full by firms and incorporated into their existing AML policies, procedures and staff training.

Regular review remains particularly important because AML requirements, FATF assessments and supervisory expectations can change. Firms should ensure that their compliance framework reflects the legislation and guidance currently in force rather than relying on historic procedures or outdated internal checklists.