AML Red Flags for Payroll and Annex 1 Firm
Identify AML red flags in payroll and Annex 1 firms: understand sector-specific risks, connect anomalies to customer context, and build effective controls.

AML Red Flags for Payroll and Annex 1 Firm
A red flag is not proof of money laundering. It is a fact that does not fit the expected customer, structure or activity and therefore needs an explanation.
That distinction protects both sides of a risk-based approach. Treating every anomaly as criminal creates noise and poor decisions. Ignoring anomalies because each has an innocent explanation in isolation allows a suspicious pattern to grow unnoticed. Effective AML controls connect the warning sign to what the firm already knows, then document the investigation and outcome.
Payroll providers and Annex 1 firms share several core indicators, but their sector-specific risks are different. A fabricated employee is relevant to a payroll bureau. An unexplained repayment through an SPV matters to a commercial lender. The control framework should recognise both the common logic and the operational context.
The first shared indicator is a customer structure that is more opaque than the commercial purpose requires. Multiple companies, trusts, nominees or SPVs can be legitimate. Risk increases when the customer cannot explain why the layers exist, information conflicts across documents and registers, or the structure obscures the natural people who ultimately own or control it.
Verification must therefore go beyond copying Companies House data. A firm needs to understand ownership and control, compare independent information with the customer's account, and record how inconsistencies were resolved. Our guide to KYB and layered corporate verification explains why complex structures require an evidence trail rather than a single database result.
The second indicator is activity without a convincing economic or lawful purpose. That can mean a service request unrelated to the customer's stated business, a payment route with unnecessary intermediaries, repeated changes in instructions or transactions whose size and timing do not fit the expected relationship. The right question is not merely whether the transaction is technically possible. It is whether it makes sense for this customer.
Other shared warning signs include:
reluctance to provide supporting documents or identify beneficial owners;
information that changes when challenged or conflicts with independent records;
unexplained links to higher-risk jurisdictions;
funds sent by or returned to an unrelated third party;
sudden changes in directors, shareholders, business activity or payment accounts;
pressure to proceed before due diligence is complete;
sanctions, PEP or adverse-media information inconsistent with the declared risk profile;
a customer or intermediary carrying on relevant activity without the expected AML supervision.
No single factor creates an automatic outcome. Several weak explanations across ownership, purpose and payment flows can, however, create a materially different risk picture from any one alert.
Payroll Red Flags Sit Inside the Instructions
Payroll can make illicit funds appear to be legitimate compensation. The 2025 National Risk Assessment identifies over-reporting or under-reporting employee numbers and pay as ways to move criminal funds or avoid liabilities such as National Insurance contributions. It also notes that standalone payroll work can be particularly exposed where the provider sees only a fragment of the customer's wider activity.
HMRC's payroll risk guidance identifies several practical warning signs. These include fabricated employees, misrepresented pay or benefits, unsupported deductions, illicit funds used to pay workers and customers who resist providing information showing that payroll instructions are legitimate.
A provider should investigate when employee numbers, salary levels or working patterns do not fit the client's industry and scale. Round-sum payments across groups of employees, identical pay despite materially different hours, unusually low National Insurance contributions or a suspicious absence of employee costs can all require explanation. These indicators become more significant in labour-intensive, low-margin sectors where workers may be vulnerable to exploitation.
Changes in HMRC interaction also matter. A customer that suddenly prevents the provider from reporting directly, cannot evidence that required reports were made, or refuses to confirm National Insurance numbers and tax codes may be concealing payroll fraud or fabricated workers. Requests to change how the provider interacts with HMRC should have a clear commercial reason and an attributable decision.
Payment flows provide another layer of context. Risk can increase where the payroll provider pays workers directly from the customer's account, salary funds arrive from an unexpected entity or unusual payments and deductions appear without a connection to the customer's operations. The provider should compare instructions with the expected business relationship rather than treat each payroll run as a standalone data file.
Umbrella arrangements and labour supply chains deserve particular attention because distance can obscure the end user, worker and source of instructions. Warning signs include unnecessary intermediaries, limited visibility of the actual work performed, frequent changes of corporate entity and arrangements promising outcomes that do not fit ordinary payroll or tax treatment.
Annex 1 Red Flags Depend on the Activity
Annex 1 is not one business model. It includes commercial lenders, factoring businesses, financial leasing firms, money brokers and safe custody providers. The customer and transaction indicators must therefore be tailored to the service.
For lenders, the FCA has highlighted unregulated lending through complex structures, including SPVs. A lender should look closely at borrowers formed shortly before the application, ownership layers with no clear financing purpose, discrepancies between the stated borrower and economic beneficiary, or a loan whose purpose does not fit the borrower's business.
Source and repayment are as important as identity. Unexpected third-party funding, repayment from an unrelated entity, early repayment with no credible commercial explanation, repeated refinancing or security provided by a party outside the understood structure can change the risk assessment. In property-related bridging finance, speed, layered companies and rapid movement between funding arrangements should be understood together rather than reviewed as isolated facts.
The FCA has also reported cases where consumers were encouraged to establish limited companies to obtain unregulated bridging finance. That is not automatically an AML issue, but it is a warning that the legal form may not reflect the real customer or purpose of the relationship. The lender should understand who benefits, why the company was introduced and whether the arrangement is consistent with the parties' explanations.
For financial leasing, warning signs can include an asset that appears unnecessary for the customer's business, pricing or payment terms without commercial logic, third-party payments and rapid changes to the lessee or beneficial ownership. For money broking, the firm should understand each party, the rationale for the intermediary chain and whether the activity fits the customer's expected markets and jurisdictions.
Safe custody has a different exposure. The National Risk Assessment records the use of safety deposit boxes to store criminal property, including cash and high-value portable assets. Providers should apply risk-sensitive due diligence, monitor the relationship and keep access information current. Unexplained use by third parties, customer behaviour inconsistent with the stated purpose or attempts to prevent normal record keeping should prompt investigation.
Turn Red Flags Into Decisions
A red-flag list has little value unless it changes the workflow. Each indicator should have a defined response: request evidence, refresh customer due diligence, update the risk assessment, apply enhanced due diligence, refer the case for human review or escalate a suspicion to the nominated officer.
The case record should preserve the original alert, relevant customer context, evidence collected, reviewer, decision and any change to monitoring. Dismissed concerns matter too. If the same indicator returns later, the firm needs to know what was previously considered and whether the new facts alter that conclusion.
Screening works the same way. A sanctions, PEP or adverse-media result is useful only when the firm can establish who it relates to, resolve false positives and connect a genuine finding to the risk decision. Better context is central to reducing false positives without weakening screening.
Steward supports this operating model by keeping customer documents, ownership, screening, risk assessments, exceptions and ongoing reviews within the same end-to-end history. AI-first document and entity analysis can surface inconsistencies and missing evidence, while human reviewers retain responsibility for accepting risk and escalating suspicion. The append-only audit trail preserves what was known, what changed and why the firm acted.
Red flags are most valuable when they interrupt assumptions. The objective is not to create the longest possible list. It is to notice when the customer in front of the firm no longer matches the customer the firm believed it had accepted.
Related Insights

The AML AI Readiness Gap in North America
North American firms allocate funds to AI for AML, yet 54% use 8-10 fragmented systems. Why AI adoption isn't the same as operational readiness.

How to Set Up AML Controls for a UK Business
A practical operating model for building AML controls that work across payroll and Annex 1 businesses

FCA Increases Scrutiny of Annex 1 Firms
What the FCA's August 2026 intervention means for Annex 1 registration, governance and AML controls