AML Essentials for Professional Services Staff
A practical guide to anti-money laundering basics for accountants, financial advisers, estate agents and other MLR 2017 regulated professional services staff -- who's covered, client due diligence, red flags and your personal reporting duty.
If your organisation is an accountancy practice, a firm of financial advisers, an estate agency or a company formation agent, anti-money laundering law almost certainly applies to you personally, not just to a compliance department somewhere upstairs. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017) put direct, individual obligations on staff working in a wide range of professional services — and getting the basics wrong can mean a criminal record, not just a difficult conversation with a manager. This guide sets out who is covered, how client due diligence and the risk-based approach actually work day to day, the red flags worth knowing, and what the law expects of you personally if something looks wrong. Building this knowledge properly — rather than picking it up piecemeal — is exactly what structured CPD courses are designed for, and AML is one of the areas regulators most consistently check firms have covered.
Who counts as a "relevant person" under MLR 2017
MLR 2017 uses the term "relevant person" for any business caught by the regulations, and regulation 8 sets out the regulated sector in detail. It is a much wider net than most people outside compliance realise. Alongside banks and other credit and financial institutions, it explicitly includes:
- External accountants and tax advisers — anyone providing accountancy, bookkeeping or tax advice services to clients, whether or not they hold a professional qualification.
- Auditors and insolvency practitioners.
- Independent legal professionals when carrying out specified activities (this is the category that generates the law-firm-specific AML rules — see below).
- Trust or company service providers — including company formation agents, and anyone who forms companies, acts as a director, secretary or nominee shareholder, or provides a registered office for clients.
- Estate agents and letting agents (letting agency work was brought fully into scope for lettings of €10,000 a month or more).
- High value dealers, art market participants, casinos, and cryptoasset or custodian wallet providers.
The practical test is not your job title — it is whether your firm carries out one of these activities "in the course of business" in the UK. A bookkeeper working for a small accountancy practice, a paraplanner supporting a financial adviser, or a negotiator at an estate agency are all working inside the regulated sector, with the same personal reporting duties as the partner who signs the engagement letter.
Client due diligence: the basics
Client due diligence (CDD) is the process of finding out who you are really dealing with before — and for the life of — a business relationship. Under MLR 2017 you generally need to:
- Identify the client and verify their identity using documents, data or information from a reliable, independent source.
- Identify any beneficial owner — for a company or trust, the individual(s) who ultimately own or control it — and take reasonable measures to verify who they are, including checking a company's entry on the People with Significant Control register where relevant.
- Understand the purpose and intended nature of the business relationship — why is this client instructing your firm, and does the work requested make sense for them?
- Keep CDD up to date throughout the relationship, and carry out ongoing monitoring of transactions to check they are consistent with what you know about the client.
CDD is not a single tier. Firms apply simplified due diligence where the risk is assessed as low (for example, some listed companies or UK public authorities), standard due diligence for the ordinary run of clients, and enhanced due diligence wherever the risk is higher — including for any Politically Exposed Person (PEP), their family members and known close associates, for high-risk third countries, and in any case where a transaction is complex, unusually large, or follows an unusual pattern with no apparent economic or lawful purpose. Enhanced due diligence means digging further: more evidence, senior sign-off before taking the client on, and closer ongoing monitoring.
The risk-based approach in practice
MLR 2017 does not expect every client to be treated identically — it expects firms (and the people working in them) to apply a risk-based approach. That means your firm should hold a written practice-wide risk assessment covering the money laundering and terrorist financing risks it faces, and every client file should reflect a risk assessment specific to that client and matter. Factors that typically push risk up include: cash-intensive client businesses, ownership structures that are unusually complex or opaque for no obvious commercial reason, clients or funds connected to higher-risk jurisdictions, unexplained urgency, and instructions that do not match the client's known profile or stated purpose.
For frontline staff, the risk-based approach mostly comes down to one habit: never treat CDD as a box-ticking exercise to get through before the "real" work starts. The quality of the questions you ask at onboarding — and how carefully you follow up on anything that does not add up — is the actual control. If you are ever unsure whether a client or transaction needs a closer look, escalate rather than guess; that instinct is worth far more than any checklist.
Common red flags
No single sign proves money laundering, but certain patterns should prompt you to pause and ask more questions, or raise it internally. Common red flags across professional services include:
- A client who is reluctant to provide identification, ownership or source-of-funds information, or who provides documents that look altered or inconsistent.
- Payments from, or instructions involving, unrelated third parties with no clear connection to the client or the transaction.
- Requests to structure a transaction in an unusually complex way, or to route funds through multiple accounts or jurisdictions, for no clear commercial reason.
- A transaction, purchase or investment that is inconsistent with the client's known income, business activity or wealth.
- Unusual urgency or pressure to complete a matter quickly, especially where it discourages normal due diligence checks.
- Use of cash for transactions that would normally be settled electronically, or repeated transactions just under a reporting or verification threshold.
- Company structures involving multiple jurisdictions, nominee directors or shareholders, or beneficial owners who are difficult to identify.
These same underlying patterns — opaque structures, unexplained urgency, third-party funds — turn up across financial crime more broadly, not only money laundering. If your role also touches international payments or client lists, it is worth pairing this with a look at how sanctions screening works in day-to-day client and payment checks, since the two obligations often overlap on the same file.
Your personal reporting obligation
This is the part of AML law that catches people out, because it is a duty on the individual, not just the firm. Under section 330 of the Proceeds of Crime Act 2002 (POCA), if you work in the regulated sector and you know, suspect, or have reasonable grounds to know or suspect that another person is engaged in money laundering, based on information that came to you in the course of your work, you must disclose it — normally to your firm's Money Laundering Reporting Officer (MLRO), who will decide whether to file a Suspicious Activity Report (SAR) with the UK Financial Intelligence Unit (UKFIU) at the National Crime Agency (NCA). Disclosure must be made as soon as practicable. Failing to do so, without reasonable excuse, is a criminal offence carrying a maximum of five years' imprisonment and/or an unlimited fine.
Two related points matter just as much as the headline duty:
- You cannot "tip off." Once a disclosure has been made (or you know or suspect an investigation is being contemplated or carried out), telling the client or anyone else in a way that is likely to prejudice that investigation is a separate offence under section 333A of POCA, also carrying up to five years' imprisonment.
- The threshold is low. You do not need proof. "Reasonable grounds to suspect" is enough to trigger the duty, and that is a deliberately low bar — the law is designed to get information to the authorities early, not to make individual staff act as investigators or judges of guilt.
To put the scale of this in context: the NCA's UKFIU received 872,048 SARs in the 2024–25 reporting year. The large majority came from banking and financial services, but accountancy, legal and property firms all submit meaningfully into that total every year — this is a live, active reporting regime, not a theoretical one. Firms whose work touches complex ownership structures or cross-border arrangements should also be alert to a distinct but related obligation covered in our guide to preventing the facilitation of tax evasion, since the same client behaviour can raise both money laundering and tax evasion concerns on a single file.
If you work in a law firm specifically, note that solicitors sit under an additional, more detailed layer of regulation — including the firm-wide risk assessment duty under Regulation 18 and the governance requirements under Regulation 21, which we cover separately in our guide to firm-wide AML risk assessments for law firms. That post is written for the legal sector's own supervisory regime; the guidance above applies across the wider MLR 2017 regulated sector, including accountancy, financial advice, estate agency and company formation work.
FAQs
Do I need to report a suspicion even if I am not certain?
Yes. The legal threshold under section 330 of POCA is "know or suspect, or have reasonable grounds to know or suspect" — you are not expected to prove anything, and you should not try to investigate it yourself. Raise it through your firm's internal reporting line to the MLRO as soon as practicable.
What is the difference between my firm's obligations and my personal obligations?
Your firm must have policies, controls and procedures in place, carry out a practice-wide risk assessment, and appoint an MLRO. You, as an individual working in the regulated sector, have a separate personal duty to disclose what you know or suspect — you cannot rely on "the firm will handle it" as a defence if you sat on information.
Does client due diligence apply to existing clients, or only new ones?
Both. MLR 2017 requires CDD to be kept up to date on a risk-sensitive basis throughout the relationship, and firms must carry out ongoing monitoring — not just a one-off check when a client first comes on board.
What happens if I raise a suspicion that turns out to be nothing?
Nothing adverse to you. Making a report in good faith is protected, and the entire point of a low reporting threshold is to encourage staff to escalate uncertainty rather than second-guess themselves. The risk sits firmly on the side of under-reporting, not over-reporting.
AML obligations are not a one-off induction topic — the regulations, red flags and case law move, and every relevant person is expected to keep their knowledge current. Learnsignal's CPD courses cover anti-money laundering alongside the wider compliance topics professional services staff need, in a format built for busy practices to complete properly rather than tick off. If AML training has not been refreshed on your team this year, that is a good place to start.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


