How to Set Up AML Controls for a UK Business
A practical operating model for building AML controls that work across payroll and Annex 1 businesses

How to Set Up AML Controls for a UK Business
An AML policy downloaded from a template library is not an AML programme. It becomes a programme only when it changes how a business accepts customers, investigates risk, escalates suspicion and keeps evidence.
That distinction matters for two UK sectors facing immediate scrutiny. Payroll providers preparing for HMRC tax adviser registration must be able to evidence appropriate AML supervision. Annex 1 lenders, financial leasing firms, money brokers and safe custody providers face closer FCA examination of both applications and existing controls. The supervisory routes differ, but the foundations of an effective framework are shared.
This guide does not determine whether a particular company or activity is within the Money Laundering Regulations 2017. That perimeter should be established before implementation. Once a business is in scope, however, the work begins with the operating model rather than the application form.
Start With Scope, Ownership and Risk
Map the business by legal entity. Record the services each entity provides, where it operates, who its customers are, whether it handles money or assets, which intermediaries it uses and which supervisor covers each activity. A payroll software provider, a bureau submitting PAYE information for clients and a company moving salary funds do not necessarily have the same exposure. An Annex 1 group may similarly separate origination, servicing, funding and loan ownership across different entities.
This service map should feed a written business-wide risk assessment. Regulation 18 requires relevant businesses to identify and assess money laundering and terrorist-financing risk, while regulation 18A adds proliferation-financing risk. HMRC's risk-assessment guidance identifies the core method: understand the risks, assess the business and its customers, design controls, monitor those controls, and record what was done and why.
A useful assessment covers at least five dimensions: customers, products or services, transactions, delivery channels and geography. It should also reflect the firm's size, structure and complexity. The result is not a generic label such as “medium risk”. It should identify concrete exposure, such as standalone payroll work for unfamiliar labour-intensive businesses, commercial lending through SPVs, remote onboarding of overseas-owned companies or safe custody relationships involving high-value portable property.
Senior ownership must then be explicit. Depending on the firm's size and nature, the regulations require a board or senior-management officer responsible for compliance and a nominated officer to receive internal disclosures and consider suspicious activity reports. These roles require authority, information and time. A name in a policy does not work if operational teams do not know when or how to escalate.
Build Controls Around the Customer Journey
Customer due diligence begins before the relationship is established. The firm must identify and verify the customer, identify beneficial owners where applicable, take reasonable measures to verify them, understand the ownership and control structure, and establish the purpose and intended nature of the relationship. It must also identify anyone acting on the customer's behalf and confirm their authority.
For companies, this is more than collecting an incorporation document. A strong process compares registry information with documents and information provided by the customer, resolves discrepancies, follows relevant ownership layers and records any difficulty identifying the ultimate owners. Our explanation of why KYB is not simply KYC with a company number covers the operational difference.
The next step is to establish expected activity. Payroll providers need to understand the client's business, expected workforce, who supplies payroll instructions, whether funds are handled and how the service interacts with HMRC. Annex 1 firms need equivalent context for their activity. A lender may need to understand the commercial purpose, borrower structure, source and destination of funds, expected repayment and collateral. A safe custody provider needs to understand the purpose and expected use of the relationship.
Screening should support this assessment. Sanctions, PEP and adverse-media results should be linked to the correct customer, beneficial owners and relevant connected parties. A match is not a risk decision by itself. The process needs documented resolution, human review where required and escalation criteria. The aim is not to generate more alerts, but to ensure that relevant information changes the customer assessment. Our guide to reducing false positives in AML screening explains how better identity context improves that decision.
Customer risk classification should combine these facts rather than replace them. The score or rating must lead to an action: standard due diligence, enhanced due diligence, senior approval, tighter monitoring, remediation or refusal. Where enhanced due diligence is required, the measures should answer the reason for higher risk. That may include stronger verification, more information on ownership or business activity, source-of-funds or source-of-wealth work, senior-management approval and more intensive monitoring.
Make Monitoring and Escalation Work in Practice
AML does not stop once a customer is accepted. Regulation 28 requires ongoing monitoring so that activity can be assessed against what the firm knows about the customer, its business and its risk profile. Documents and information must also be kept up to date.
The monitoring model should combine periodic reviews with trigger events. A fixed review date is useful, but it should not delay action when a material fact changes. New beneficial owners, a change in business activity, an unexpected payment account, entry into a higher-risk jurisdiction, new adverse information or unexplained transaction patterns can all require reassessment. HMRC's inspection guidance asks firms to show whether reviews are event-driven, periodic or both. The KYC periodic-review process provides a practical model for combining the two.
The triggers should reflect the sector. For payroll, examples include unsupported changes to employee numbers, salary instructions that do not fit the client's business, blocked HMRC reporting or funds arriving from an unexpected party. For Annex 1 lending, triggers can include a new repayment source, early repayment without a commercial explanation, changes to the borrower or guarantor structure, unexpected third-party payments or collateral that no longer fits the relationship.
Staff need a clear route from concern to decision. Procedures should explain what gets investigated within the customer case, what is escalated to the nominated officer, how confidentiality is protected and when the business must stop acting. A suspicion is not resolved because an operational employee added a note to a spreadsheet.
Training must follow the same principle. Generic annual slides establish awareness, but role-specific scenarios establish capability. Payroll teams should practise responding to fabricated employees or suspicious instructions. Lending teams should work through opaque borrowers, unexplained repayment routes and pressure to complete quickly. Reviewers should know how to document a decision without disclosing a potential suspicious activity report to the customer.
Test the Evidence Before a Supervisor Does
Policies should be tested against real files. Select a sample across services and risk levels, then trace each case from initial contact to the current date. Check whether the business can show who performed each review, which evidence was considered, how discrepancies were resolved, why the risk rating was chosen, who approved exceptions and whether monitoring responded to later changes.
Record keeping is part of the control, not an administrative afterthought. The regulations generally require CDD and transaction records to be retained for five years from the end of the relationship or completion of the transaction, subject to the detailed rules and data-protection obligations. The record should preserve the decision context as well as the final document. An approval with no visible reasoning is difficult to defend.
This is where an AI-first, purpose-built system can support execution. Steward keeps document collection, company verification, beneficial-ownership mapping, risk assessment and screening within one end-to-end workflow. Exceptions can be assigned to named reviewers, while automated findings and human decisions remain attached to the customer history. Ongoing monitoring and periodic review can continue from the same record instead of restarting the investigation in a new folder.
Technology does not set the firm's regulatory perimeter, risk appetite or suspicion threshold. Those remain management responsibilities. Its value is in making the chosen controls consistent, visible and testable across a growing customer base.
The best AML programme is not the longest policy. It is the one that produces the right decision, assigns accountability and preserves enough evidence to explain what happened months or years later.
Related Insights

The AML AI Readiness Gap in North America
North American firms allocate funds to AI for AML, yet 54% use 8-10 fragmented systems. Why AI adoption isn't the same as operational readiness.

AML Red Flags for Payroll and Annex 1 Firm
Identify AML red flags in payroll and Annex 1 firms: understand sector-specific risks, connect anomalies to customer context, and build effective controls.

FCA Increases Scrutiny of Annex 1 Firms
What the FCA's August 2026 intervention means for Annex 1 registration, governance and AML controls