Blogs
UK's AML rules have upgraded – here's what’s changing and when

The UK has overhauled its anti-money laundering regulations. This June, Parliament passed the Money Laundering and Terrorist Financing (Amendment) Regulations 2026. Many changes take effect from 30 June 2026, with a handful of crypto specific rules following in early 2027.
The intent behind the reforms is proportionality: smarter compliance focused on risk. Here's what that looks like in practice.
Sterling thresholds replace euro equivalents
One of the most practical changes: euro denominated thresholds are being replaced with pound sterling equivalents across the board. That means €10,000 becomes £10,000, occasional transaction thresholds drop to £800, and standard verification thresholds align at £12,000. Everything is now expressed in sterling, cleaner, clearer, and easier to apply consistently.
Enhanced due diligence: a narrower trigger
Currently, firms must apply Enhanced Due Diligence (EDD) to customers from countries on either FATF's blacklist or its grey list. The grey list changes regularly, which has meant MLROs tracking a moving target.
From 30 June, mandatory EDD applies to FATF blacklist countries only. Grey list countries still carry risk and should be reflected in your internal country risk framework, but the automatic mandatory trigger is gone. In its place: considered, risk-based judgement.
There's also an important tweak to the language around EDD triggers. The previous threshold, transactions that were "complex or unusually large", has been updated to "unusually complex or unusually large." One word, but the implications are meaningful. Enhanced checks should now be reserved for transactions that are genuinely atypical for the context, rather than anything that simply looks large on the surface. The goal is proportionate scrutiny, not reflexive escalation.
Off the shelf companies: no ambiguity left
Trust or Company Service Providers (TCSPs), company formation agents and similar, take note. The sale of off-the-shelf companies is now explicitly within scope of AML regulation. Customer due diligence applies. The grey area that existed before is gone.
Cryptoasset firms: more oversight
If you operate in the cryptoasset space, these updates have significant implications.
Customer due diligence requirements have been tightened and aligned with the UK's broader cryptoasset regulatory framework. Enhanced due diligence provisions have been added for unusually complex crypto transactions. From February 2027, there's a formal prohibition on crypto firms dealing with shell banks. And stricter requirements around ownership change notifications to the FCA come into effect across the timeline.
These adjustments reflect a sustained tightening of oversight in a sector that has grown significantly faster than the regulatory frameworks around it.
Pooled client accounts: time to formalise
Firms using pooled client accounts (PCAs) must now conduct full risk assessments on them and maintain structured records. If your PCA arrangements haven't been reviewed recently, now's the time.
FCA reporting: 30-day window
Material data inaccuracies or material changes must be reported to the FCA within 30 days of becoming aware of them. The clock starts when you know, not when it's convenient.
Supervision: the FCA takes the lead
Alongside the regulatory changes, AML supervision of professional services firms is moving to the FCA, from professional body supervisors such as ICAEW. The aim is more consistent oversight and a clearer line of accountability. For firms currently supervised by a professional body, the practical message is the same as it's always been: stay focused on compliance with the regulations, whoever your supervisor is.

The timeline
30 June / early July 2026: Sterling thresholds, narrower EDD triggers, the grey list change, TCSP requirements for off-the-shelf companies, and the FCA 30-day reporting rule.
February 2027: Ban on crypto firms dealing with shell banks; tighter structural controls.
October 2027: Further cryptoasset controls take full effect.

What regulated businesses need to do
- Update EDD procedures to apply mandatory EDD to FATF blacklist countries only, and revisit your internal country risk classifications
- Adjust transaction monitoring to focus on "unusually complex or unusually large", not just anything that exceeds a size threshold
- Update your systems and policies to reflect the new sterling thresholds
- If you're a TCSP, ensure CDD applies when selling off-the-shelf companies
- If you operate in the cryptoasset space, begin preparing for the February 2027 requirements now
- Review pooled client account arrangements and ensure formal risk assessments and records are in place
- Verify your FCA data is accurate and that there's a clear process for flagging material changes within 30 days
The direction is clear: less compliance overhead where it adds little value, more focus where risk is real. Proportionate doesn't mean relaxed, it means doing the right things, done properly.
If you want to make sure your AML compliance and due diligence processes are ready for what's coming, APLYiD can help. We make compliance straightforward, so you can focus on the parts of your business that actually need your attention.








