UK Statutory Instrument 2017 United Kingdom

Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017

At a glance

Enforced by

HMRC, FCA, SRA, LSB, Home Office

What's here

105 compliance obligations, 16 practical guides across 4 topics · 9 journeys

Penalty landscape

17 of 105 obligations carry an unlimited fine. 16 carry different penalties and 72 have no criminal penalty — flagged in the list below.

Who this Act binds

Business-side actors with duties under this Act, ranked by how often they appear.

  • Any Person 34
  • Trader 24
  • Responsible Person 11
  • Director or Officer 5
  • Trustee 3
  • Employer 1
  • Operator 1

Plus 26 non-business duties on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

Step-by-step journeys using this legislation

Walkthroughs that take you from a real business situation to compliance.

Relevant guidance

Practical guides for businesses affected by this Act, ordered by how closely they engage with it.

Other Acts binding the same actors

For each actor bound by this Act, the other UK Acts that bind them most often. Useful for understanding the full compliance landscape facing each role.

Any Person also bound by 749 other Acts (top 5 shown)
Traders also bound by 219 other Acts (top 5 shown)
Responsible Persons also bound by 56 other Acts (top 5 shown)
Directors and Officers also bound by 224 other Acts (top 5 shown)
Trustees also bound by 8 other Acts (top 5 shown)
Employers also bound by 171 other Acts (top 5 shown)
Operators also bound by 125 other Acts (top 5 shown)

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

Part 1 — Introduction

s.007

Supervisory authorities

  • Identify which regulator supervises your anti-money laundering compliance Responsible Person
Browse 6 other sections in this Part — procedural / definitional / commencement

Part 2 — Money Laundering and Terrorist Financing

s.018

Risk assessment by relevant persons

Unlimited fine
  • Assess your business risks for money laundering and terrorist financing Responsible Person
  • Carry out and record a money‑laundering risk assessment Any Person
s.019

Policies, controls and procedures

Unlimited fine
  • Establish and maintain anti-money laundering policies and procedures Responsible Person
  • Establish, maintain and update AML policies, controls and procedures Trader
s.021

Internal controls

  • Set up internal anti-money laundering controls and appointments Responsible Person
s.024

Training

  • Train relevant staff and agents on anti-money laundering requirements Responsible Person
s.025

Supervisory action

  • Follow FCA supervisory directions Employer
Other duties (1) — Crown / regulator
  • Supervisors must review and may restrict high-risk overseas operations Statutory regulator
s.026

Prohibitions and approvals

2 years imprisonment
  • Act as manager/officer or be beneficial owner without regulator approval Any Person
  • Operating a regulated business without proper management approval Any Person
s.policies, controls and procedures in relation to p

Policies, controls and procedures in relation to proliferation financing

Unlimited fine
  • Establish and maintain proliferation financing policies and controls Responsible Person
  • Maintain policies and controls to prevent proliferation financing Trader
s.risk assessment by relevant persons in relation to

Risk assessment by relevant persons in relation to proliferation financing

Unlimited fine
  • Assess and record proliferation financing risks Any Person
  • Assess your business risk for proliferation financing Responsible Person
s.risk assessment by the treasury

Risk assessment by the Treasury

Other duties (1) — Crown / regulator
  • The Treasury must assess risks related to weapons of mass destruction financing Crown / Minister / Government department
Browse 11 other sections in this Part — procedural / definitional / commencement

Part 3 — Customer Due Diligence

s.030

Timing of verification

  • Verify customer and beneficial‑owner identity before doing business Any Person
  • Verify customer identity before starting a business relationship Responsible Person
s.requirement to report discrepancies in registers

Requirement to report discrepancies in registers

Unlimited fine
  • Check ownership registers and report discrepancies Responsible Person
  • Report material discrepancies in beneficial‑ownership registers Any Person
Browse 9 other sections in this Part — procedural / definitional / commencement

Part 4 — Reliance and Record-keeping

s.041

Data Protection

  • Provide data‑protection statement to new customers Any Person
  • Limit use of anti-money laundering data and notify customers Responsible Person
Browse 2 other sections in this Part — procedural / definitional / commencement

Part 5 — Beneficial Ownership Information

s.044

Trustee obligations

  • Maintain and disclose trust beneficial ownership records Trustee
  • Maintain and provide records of trust beneficial owners Any Person
s.045

Register of beneficial ownership

Unlimited fine
  • Register your trust and its beneficial owners with HMRC Trustee
  • Provide and keep up‑to‑date information on taxable trusts to HMRC Any Person
s.access to information on the register

Access to information on the register

Other duties (1) — Crown / regulator
  • HMRC must provide trust register information to persons with a legitimate interest Statutory regulator
s.register of beneficial ownership: additional types

Register of beneficial ownership: additional types of trust

  • Register non-taxable express trusts with HMRC Trustee
Browse 1 other section in this Part — procedural / definitional / commencement

Part 5A — Requests for information about accounts and safe-deposit boxes

s.duty to establish mechanism for requests

Duty to establish mechanism for requests

Unlimited fine
  • Cryptoasset businesses must set up a system for information requests Trader
  • Set up a system to handle information requests Trader
s.duty to respond to requests for information

Duty to respond to requests for information

Unlimited fine
  • Provide information to regulator when requested Any Person
  • Respond to information requests from cryptoasset regulators Trader
Browse 5 other sections in this Part — procedural / definitional / commencement
s.access to requests and responses, guidance and rev

Access to requests and responses, guidance and review

s.record keeping

Record keeping

s.requests for information about accounts

Requests for information about accounts

s.requests for information about safe-deposit boxes

Requests for information about safe-deposit boxes

s.requirements for making a request for information

Requirements for making a request for information

Part 6 — Money Laundering and Terrorist Financing: Supervision and Registration

s.046

Duties of supervisory authorities

Other duties (1) — Crown / regulator
  • Supervisory authorities must monitor and enforce anti-money laundering rules Statutory regulator
s.049

Duties of self-regulatory organisations

Unlimited fine
  • Put in place governance and resources for AML supervisory duties Any Person
Other duties (1) — Crown / regulator
  • Self-regulatory bodies must ensure independent and effective anti-money laundering supervision Statutory regulator
s.050

Duty to co-operate

Other duties (1) — Crown / regulator
  • Supervisory authorities must co-operate and share information Statutory regulator
s.051

Regulatory information

Other duties (1) — Crown / regulator
  • Supervisory authorities must collect and share regulatory information Statutory regulator
s.055

Power to maintain registers

Other duties (1) — Crown / regulator
  • FCA and HMRC may maintain registers of certain financial and business types Statutory regulator
s.annual reports by self-regulatory organisations

Annual reports by self-regulatory organisations

  • Publish an annual AML report Any Person
Other duties (1) — Crown / regulator
  • Self-regulatory organisations must publish annual anti-money laundering reports Statutory regulator
s.disclosure by cryptoasset businesses

Disclosure by cryptoasset businesses

  • Inform customers about lack of regulatory protection Trader
  • Inform customers when activity is not covered by FOS or FSCS Trader
s.obligation of confidentiality: offence

Obligation of confidentiality: offence

2 years imprisonment
  • Disclose confidential AML information Any Person
  • Unlawfully disclose confidential anti-money laundering information Any Person
Browse 9 other sections in this Part — procedural / definitional / commencement
s.changes in control of registered cryptoasset busin

Changes in control of registered cryptoasset businesses

s.fit and proper test: cryptoasset businesses

Fit and proper test: cryptoasset businesses

s.obligation of confidentiality

Obligation of confidentiality

s.transitional provision for existing cryptoasset bu

Transitional provision for existing cryptoasset businesses: requirement to register

Part 7 — Transfer of Funds (Information on the Payer) Regulations

s.064

Obligations of payment service providers

Unlimited fine
  • Be able to respond quickly to authorised law‑enforcement enquiries Trader
  • Respond to law enforcement enquiries about fund transfers Operator
Browse 2 other sections in this Part — procedural / definitional / commencement

Part 7A — Cryptoasset Transfers

s.information accompanying an inter-cryptoasset busi

Information accompanying an inter-cryptoasset business transfer

  • Include and verify required information for cryptoasset transfers Trader
s.missing information: intermediaries

Missing information: intermediaries

Unlimited fine
  • Check and obtain required information before transferring cryptoassets Trader
  • Verify cryptoasset transfer information as an intermediary Trader
s.missing or non-corresponding information: the cryp

Missing or non-corresponding information: the cryptoasset business of a beneficiary

  • Verify cryptoasset transfer information and manage discrepancies Trader
  • Verify and manage information for incoming cryptoasset transfers Trader
s.provision of information

Provision of information

Unlimited fine
  • Provide requested information to law enforcement promptly Trader
  • Respond to law enforcement requests for cryptoasset information Trader
s.requesting information: unhosted wallet transfers

Requesting information: unhosted wallet transfers and cryptoasset businesses

Unlimited fine
  • Request AML information for unhosted wallet transfers Trader
  • Assess risks and restrict unhosted wallet transfers Trader
s.retention of information with an inter-cryptoasset

Retention of information with an inter-cryptoasset business transfer: intermediaries

Unlimited fine
  • Pass on information during cryptoasset transfers Trader
  • Ensure required information travels with cryptoasset transfers Trader
Browse 2 other sections in this Part — procedural / definitional / commencement
s.application of this part

Application of this Part

s.interpretation

Interpretation

Part 8 — Information, Investigation and Directions

s.directions: cryptoasset businesses

Directions: cryptoasset businesses

  • Comply with FCA directions and respond to notices Trader
Other duties (1) — Crown / regulator
  • FCA may issue specific directions to cryptoasset businesses Statutory regulator
s.report by a skilled person: cryptoasset businesses

Report by a skilled person: cryptoasset businesses

Unlimited fine
  • Appoint a skilled person and cooperate with FCA report request Trader
Other duties (1) — Crown / regulator
  • FCA may require a skilled person's report on your cryptoasset business Statutory regulator
s.reporting requirements: cryptoasset businesses

Reporting requirements: cryptoasset businesses

  • Provide information to the FCA on request Trader
  • Provide information to the FCA when requested Trader
Browse 9 other sections in this Part — procedural / definitional / commencement

Part 9 — Enforcement

s.084

Publication: the FCA

  • Keep FCA warning notices confidential Any Person
Other duties (1) — Crown / regulator
  • FCA must publish details of money laundering decision and final notices Statutory regulator
s.085

Publication: the Commissioners

Other duties (1) — Crown / regulator
  • HMRC must publish details of money laundering sanctions and breaches Statutory regulator
s.086

Criminal offence

2 years imprisonment
  • Breach of money laundering or terrorist financing requirements Any Person
  • Fail to comply with money‑laundering requirements Any Person
s.088

Information offences

2 years imprisonment
  • Provide false information or disclose restricted info to regulators Any Person
  • Provide false or misleading information or unlawful disclosure Any Person
Browse 8 other sections in this Part — procedural / definitional / commencement

Part 10 — Appeals

s.095

Review by the Commissioners

  • Notify the Commissioners within 30 days if you want a review Any Person
Other duties (1) — Crown / regulator
  • HMRC must review a decision if you accept their offer of a review Statutory regulator
s.097

Review out of time

  • Request a review out of time Any Person
Other duties (1) — Crown / regulator
  • HMRC must review a decision if a late request has a reasonable excuse Statutory regulator
s.098

Nature of review etc

Other duties (1) — Crown / regulator
  • HMRC must conduct and notify the outcome of a manual review Statutory regulator
Browse 4 other sections in this Part — procedural / definitional / commencement

Part 11 — Miscellaneous Provisions

s.102

Costs of supervision

  • Pay FCA supervision charges when imposed Any Person
Other duties (1) — Crown / regulator
  • FCA and HMRC may charge fees for anti-money laundering supervision Statutory regulator
s.104

Suspicious activity disclosures

Other duties (1) — Crown / regulator
  • NCA must provide annual feedback on suspicious activity reports Statutory regulator
Browse 9 other sections in this Part — procedural / definitional / commencement

Schedules

s.sch003

Relevant Offences

2 years imprisonment
  • Make a false statement under oath (perjury) Any Person
s.sch006b

Changes in Control of Registered Cryptoasset Businesses

2 years imprisonment
  • Fail to notify FCA of acquisition or increase in control of a cryptoasset business Any Person
Browse 10 other Schedules — structural / supplementary
s.sch003a

Excluded Trusts

s.sch003aza

Material Discrepancies

s.sch003za

High-Risk Third Countries

s.sch006a

The United Kingdom’s Financial Intelligence Unit

Official guidance

Authoritative sources published by regulators or government explaining this legislation.

Enforcement and responsible bodies

The regulators that administer or enforce this legislation.

HMRC

Primary

HM Revenue & Customs

Tax collection, customs duties, national insurance, tax credits, and enforcement of the National Minimum Wage. Regulates all UK businesses for tax compliance …

FCA

Financial Conduct Authority

Regulation of financial services firms and markets. Supervises banks, insurers, investment firms, payment services, and cryptoasset businesses. Issues authorisations and enforces conduct …

SRA

Solicitors Regulation Authority

Regulates solicitors and law firms in England and Wales. Sets standards, authorises firms, investigates misconduct, and can impose sanctions including fines and …

LSB

Legal Services Board

Oversight regulator for legal services in England and Wales. Supervises approved regulators including SRA, Bar Standards Board, and CILEx. Ensures regulation serves …

Government department responsible for immigration, security, and law and order. Administers UK Visas and Immigration (UKVI), issues sponsor licences for employers hiring …

Explore more

Browse legislation

Find other UK business legislation with related guidance.

Regulators

Learn more about the bodies that enforce this legislation.