The 12 fundamentals of AML

Anti-money laundering compliance can feel like a long list of disconnected obligations. In practice, however, most accountancy practices, bookkeeping firms and tax advisers can think about AML compliance as twelve core elements. If those elements are properly covered, kept up to date and documented, the firm is in a much stronger position when its supervisory body comes knocking.

Number 1 is registration. Any firm in the UK providing accountancy services, tax advice, bookkeeping or trust or company services by way of business must be supervised for AML purposes, either by a professional body or by HMRC.

Accountancy services means not only the obvious audit or accounts preparation work, but also other services involving the recording, review, analysis, calculation or reporting of financial information, such as payroll processing. Tax advice is similarly broad, covering material aid, assistance or advice in connection with another person’s tax affairs.

TCSP (trust or company service provider) work can include forming companies or providing a registered office, business address, correspondence address or administrative address for clients.

Governance, risk assessment and procedures

Number 2 is appointing a money laundering reporting officer, and possibly also a separate money laundering compliance officer. These roles must be held by an individual within the firm, not an external consultant.

The person appointed needs sufficient authority, access to relevant records and the confidence to challenge colleagues where necessary. Details must be notified to the firm’s supervisory body, and beneficial owners, officers and managers may also need DBS (Disclosure and Barring Service) basic checks.

Number 3 is the written Firm-wide AML Risk Assessment. This has been mandatory since 2017 and should identify the risks the firm faces and explain how those risks are mitigated.

The FWRA needs to cover the main risk areas: clients, services, geography, transactions, delivery or communication channels, and proliferation financing. It should not be just a generic template with the firm’s name pasted on the front. It should describe the firm as it actually operates and should be reviewed at least annually.

Number 4 is the written AML Policies, Controls and Procedures document. This should translate the risk assessment into day-to-day practice.

The PC+P should cover customer due diligence, enhanced and simplified due diligence, ongoing monitoring, politically exposed persons, training, record keeping, internal reporting of suspicions and the responsibilities of the MLRO. Again, it should reflect what the firm actually does, not what a model document assumes it does.

People, clients and evidence

Number 5 is training and staff screening. Staff need to understand what money laundering is, the main types of acquisitive crime, the requirements of the Money Laundering Regulations, the firm’s own procedures, red flags, internal reporting and the offence of tipping off.

The MLRO will need additional training, including on reporting to the National Crime Agency and on internal compliance reviews. Firms also need records showing who was trained, when, and on what content. Staff screening is not only about competence; it also concerns conduct and integrity.

Number 6 is carrying out client due diligence on a risk-sensitive basis. Clients must be identified and their identity verified. For individuals, that will usually include full name, date of birth and residential address.

For companies, it includes company number, registered office and, where different, principal place of business. Firms must also identify beneficial owners of companies and take reasonable, risk-based measures to verify their identity. Directors’ names should also be determined and verified on a risk-sensitive basis. All of this needs to be properly recorded.

Number 7 is checking the PSC register when onboarding company clients and retaining evidence of that check. The register should be reviewed regularly, typically annually. If a material discrepancy or error is found, the practical first step is normally to get it corrected. If that is not possible, a report may need to be made to the Registrar of Companies.

Numbers 8 and 9 are client risk assessment and ongoing monitoring. Each client should have a documented AML risk assessment, often using structured questions and comments, leading to a low, normal or high-risk rating.

That assessment must then be kept alive. Client information, due diligence and risk ratings should be reviewed regularly, and the review should be documented even if nothing has changed.

Reporting, review and inspection readiness

Number 10 is having a procedure for reporting suspicions of money laundering, terrorist property offences or proliferation financing. Staff need to know how to make an internal report, and the MLRO should have a reporting form and decision-making record. The firm should be registered on the NCA portal, and copies of any external reports should be retained securely by the MLRO.

The final two elements are reviews. Number 11 is monitoring the firm’s own AML compliance, and an annual review by the MLRO is a sensible way to do that. This should be documented, with issues identified and followed up.

Number 12 is having regular independent reviews of the adequacy and effectiveness of the firm’s AML systems. Independent does not necessarily mean external: in a larger firm, another partner or director may be able to perform the review. In smaller firms, an external consultant may be more realistic.

One-person firms have some exemptions, including from appointing an MLRO as a separate person, staff screening, and certain compliance review requirements.

Software helps, but documentation matters most

Two wider points are worth stressing. First, AML compliance software is not compulsory. It can, however, add structure, support delegation, highlight missing information and help collate data for a supervisory visit.

Secondly, documentation is vital. Supervisors cannot inspect what is merely in someone’s head. If the firm has carried out the work but cannot evidence it, it will struggle to demonstrate compliance.

The move towards FCA supervision of accountancy sector AML compliance may change guidance, tone and supervisory expectations, but the underlying Money Laundering Regulations 2017 will still apply. These twelve fundamentals are therefore unlikely to disappear. A firm that has them adequately covered, properly tailored and fully documented should be well placed to be assessed as compliant, or at least generally compliant, on inspection.

If your firm’s AML compliance is incomplete, out of date, or has never been properly documented, get in touch now using the link below and we can work together to fix this. The hardest part is getting started.

David Winch

BOOK AN INITIAL 15 MINUTE CALL-BACK WITH DAVID WINCH (FREE)