UK Payroll Providers: HMRC Registration Is Only the Start
UK payroll providers face AML supervision requirements before HMRC registration deadline. Discover what control frameworks are needed now.

UK Payroll Providers: HMRC Registration Is Only the Start
The most important date for a UK payroll bureau is not 18 February 2027. It is the day the business applies for anti-money laundering supervision and discovers that HMRC expects the control framework to exist already.
Mandatory tax adviser registration is bringing that reality into focus. Payroll-only providers without an Agent Services Account have a registration window from 18 November 2026 to 18 February 2027. To register, a firm must be able to evidence AML supervision. If it is not already supervised by a recognised professional body, it may need to obtain supervision from HMRC first.
That makes the regulatory change much more than an online-account exercise. The registration form is the gate. Behind it sit customer due diligence, beneficial-ownership checks, risk assessment, training, suspicious-activity reporting, ongoing monitoring and a record that shows why each decision was made.
Which Payroll Providers Are in Scope?
The rule follows activity, not job title. Under HMRC's mandatory registration guidance, a business must register where it is paid to interact with HMRC in relation to another person's tax affairs, unless a specific exception applies.
For payroll providers, in-scope activity includes submitting Real Time Information returns such as Full Payment Submissions and Employer Payment Summaries, submitting year-end PAYE returns, and making PAYE or National Insurance payments to HMRC for clients. A bureau does not escape the requirement because it describes itself as a payroll processor rather than a tax adviser.
Activities such as gross-to-net calculations, payslip production, data entry, HR guidance, employee payments through BACS and the provision of payroll software do not by themselves trigger mandatory tax adviser registration. An in-house payroll team acting only for its employer is also outside this registration requirement. The boundary changes as soon as a paid external provider begins interacting with HMRC for a client.
Mixed-service firms need particular care. The payroll-only window applies only to providers that solely interact with HMRC in relation to payroll. If the same legal entity also provides accountancy or other tax services, it may fall into an earlier registration tranche. Subcontracting can create another perimeter question because a subcontractor may itself meet the definition of a tax adviser.
Firms that already have an Agent Services Account do not need to register again. HMRC has said it will contact them for further information and will check whether the business and its relevant individuals meet the new conditions. For firms with five officers or fewer, all officers are treated as relevant individuals. Larger firms must identify those who play a significant role in managing the tax-adviser activity and nominate at least five where fewer than five initially meet the definition.
The AML Obligation Is Not Created by the Form
There is an important distinction in the regulatory story. Payroll services were not suddenly invented as an AML risk in 2026. HMRC's Economic Crime Supervision Handbook already includes payroll services and payroll agents within the accountancy service provider perimeter under the Money Laundering Regulations 2017.
What changes is the practical gatekeeping. A payroll provider that needs an Agent Services Account must now evidence that it is already supervised for AML. Having merely applied for supervision is not enough to complete tax adviser registration. HMRC says a new AML-supervision application can take up to 45 days and may take longer if information, payment or account updates are outstanding.
Before applying for HMRC supervision, the business should have completed a written assessment of its money laundering, terrorist financing and proliferation financing risks. It should also have policies, controls and procedures designed to manage those risks, identify its beneficial owners, officers and managers, and list every premises where supervised activity takes place. HMRC may reject or refuse an application if those foundations are missing.
This is why a certificate alone proves very little. An AML-supervised payroll business needs to be able to show how the framework works across its actual client base. That includes:
Business-wide risk assessment. The firm must understand how client type, service, delivery channel, geography and ownership affect its exposure.
Customer and beneficial-owner verification. Corporate clients cannot be treated as a company name and registration number. The firm needs to identify who ultimately owns or controls the entity and preserve the evidence. As our guide to why KYB is not simply KYC for a company explains, company verification follows ownership and control through every relevant layer.
Risk-based due diligence. Higher-risk relationships require more evidence, clearer source-of-funds or source-of-wealth analysis where relevant, and enhanced ongoing monitoring. PEP, sanctions and adverse-media screening should support a documented risk decision, not exist as an isolated search result.
Governance and escalation. Responsibility for AML compliance, suspicious-activity reporting, staff training and approval of higher-risk relationships must be clear.
Record-keeping and ongoing monitoring. Customer information, beneficial ownership and risk assessments must stay current throughout the relationship, not only on the day of onboarding.
The change belongs to a wider shift in UK regulation. Professional-services businesses are increasingly expected to demonstrate not just that they have policies, but that those policies operate consistently. That same direction is visible in the AML supervisory changes facing professional-services firms.
A Practical Readiness Plan Before November 2026
The first task is a service map. Each legal entity should document which teams communicate with HMRC, what they submit, whose credentials they use, whether they make payments, and which activities sit with subcontractors. This determines the registration perimeter and prevents a software-only business from being confused with a managed payroll service, or vice versa.
The second is a supervision check. Firms should confirm which body supervises them, whether the registration covers the correct legal entity and activities, and when it renews. A business applying directly to HMRC should work backwards from the tax-adviser registration window and leave time for questions or missing evidence.
The third is a client-file inventory. Existing clients need to be matched against required evidence: legal identity, beneficial owners, risk rating, screening results, purpose of the relationship, expected activity and any enhanced due diligence. Gaps should be risk-prioritised, assigned and tracked to closure. Moving an incomplete file into a new folder does not make it compliant.
The fourth is a live control test. Select representative cases, including complex groups, overseas owners and higher-risk relationships, then trace the full journey from intake to approval and ongoing monitoring. Check whether expired documents, ownership changes, new adverse information or unusual activity create a review task with a named owner. A strong KYC periodic-review process combines scheduled reviews with event-driven reassessment when material facts change.
The fifth is evidence. HMRC supervision turns policy statements into testable controls. A firm should be able to reconstruct who reviewed a client, what information they saw, why they reached the decision, which exceptions remained open and when those exceptions were closed. Shared inboxes and spreadsheets make that reconstruction difficult precisely when it matters.
How Steward Helps Make AML Readiness Operational
This is where an AI-first, purpose-built workflow can help, provided human oversight remains explicit. AI can extract corporate information, map layered ownership, identify missing documents and assemble screening context. Human reviewers still own risk acceptance, enhanced due diligence and escalation decisions. The value comes from keeping both parts in one end-to-end record.
Steward helps firms replace disconnected email chains, spreadsheets and isolated checks with a single AML/KYC case history. Client documents and company information can be collected and reviewed in the same workflow; beneficial owners can be mapped through layered structures; sanctions, PEP and adverse-media screening is included in the platform; and missing or inconsistent evidence can be routed to a named reviewer. The resulting risk assessment records what was checked, what required human review and why the client was approved, escalated or declined.
The same record continues after onboarding. Document expiry, ownership changes, new screening information and other material events can trigger reassessment instead of waiting for a diary date. Periodic reviews, remediation tasks and reviewer decisions remain attached to the client, while Steward's append-only, timestamped audit trail preserves the evidence behind each action. This helps a payroll provider turn its written AML policy into a repeatable control that management can oversee, and a supervisor can test.
Steward does not decide a firm's regulatory perimeter or remove its responsibility to set risk appetite, appoint accountable officers and make suspicious-activity decisions. It helps make those responsibilities operable and provable: the firm can see open gaps, assign ownership, apply proportionate workflows and demonstrate how each client moved from evidence to risk decision.
Missing the registration window can eventually prevent a provider from interacting with HMRC for clients. Continuing after a formal compliance notice can also lead to financial penalties and bans. But the more immediate risk is operational: a firm reaches the deadline with an account application ready and an AML framework that cannot survive scrutiny.
Registration is a date. AML supervision is an operating model.
Book a demo to see it in action.
Related Insights
KYC Platform Migration: A Practical Best-Practice Guide
Plan a safer KYC platform migration with evidence preservation, data mapping, gap analysis, risk-based waves and clear acceptance controls.
A Practical Guide to Agentic AI in KYC and AML
Learn how agentic AI works across KYC and AML, from document review and ownership mapping to screening analysis and ongoing monitoring.
The Commercial Cost of Bad KYC
Investor onboarding delays cost funds real money - stalled subscriptions, frustrated LPs, lost allocations. Why KYC speed is a commercial weapon, not a compliance detail.