Two things changed the UK financial crime landscape recently, and neither is an amendment to the money laundering regulations. The Economic Crime and Corporate Transparency Act 2023 introduced mandatory identity verification at Companies House and a corporate offence of failing to prevent fraud. Both are now live. Neither replaces your customer due diligence obligations, and treating either as if it does is the most common mistake we see.
This is a practical guide for compliance officers at UK wealth managers, private banks and their advisers. It sets out what the Money Laundering Regulations still require, what ECCTA added, and where the FCA is currently looking.
1. Who supervises what
The Money Laundering Regulations 2017 (MLR 2017) remain the primary AML legislation. Supervision is split: the FCA supervises authorised financial services firms, HMRC supervises certain other sectors, and professional bodies supervise accountants and lawyers.
For a wealth manager, that means the FCA is your AML supervisor as well as your conduct regulator — and it assesses financial crime systems and controls as part of how it judges the firm overall, not as a separate compliance silo.
2. What MLR 2017 requires
The core duties are stable and well understood:
- Customer due diligence at onboarding — identify and verify the client and, for legal entities, the beneficial owners.
- Enhanced due diligence where risk is higher, including politically exposed persons, high-risk third countries and unusual arrangements.
- Source of funds and source of wealth enquiries proportionate to risk — an area where practice varies widely and supervisory patience does not. We cover the method in source of wealth and source of funds verification.
- Ongoing monitoring of the relationship and the transactions within it.
- A documented, firm-wide risk assessment that actually drives the above rather than sitting alongside it.
HM Treasury's consultation response of July 2025 clarified several of these, particularly enhanced due diligence triggers and source of funds expectations. The direction is toward more explicit articulation of when a firm must escalate, and less tolerance for a risk-based approach that is risk-based only in name.
3. ECCTA and Companies House identity verification
Identity verification for company directors and people with significant control (PSCs) became mandatory in November 2025. Existing directors and PSCs were given twelve months to complete it, typically alongside their next confirmation statement — which means that window closes during late 2026.
This matters for wealth managers in two distinct ways, and they should not be confused.
As a firm, you have your own filings. Your directors and PSCs must verify. So must those of any UK corporate entity you administer or control.
As a compliance function, Companies House verification is not customer due diligence. This is the important part. Companies House verifies that a named individual exists and is who they claim to be, for the integrity of the register. Your CDD obligation is broader and different in purpose: you must understand ownership and control, assess risk, establish source of wealth, and monitor the relationship over time. A client who tells you their directors are "Companies House verified" has told you something about the register, not something that discharges your obligation under MLR 2017.
The practical upside is real but narrow: register data should become more reliable, which improves the quality of one input into KYB and corporate due diligence. It does not reduce the number of steps you owe.
4. Failure to prevent fraud
Since September 2025, a large organisation can be criminally liable where an associated person commits a fraud intended to benefit the organisation, and the organisation did not have reasonable fraud prevention procedures in place.
The defence is reasonable procedures. That phrasing should be familiar — it mirrors the structure of the Bribery Act's adequate procedures defence, and it has the same consequence: your protection is documentary. A firm that has controls but cannot evidence their design, communication and operation is in a materially worse position than one that can.
For a wealth manager the overlap with AML controls is substantial — client verification, transaction monitoring, escalation routes — but the offence is about fraud committed for the organisation's benefit, which is a different risk lens from money laundering. Mapping existing AML controls onto fraud risk, and documenting where they do and do not cover it, is the work.
5. Where the FCA is looking
The FCA has been explicit that private wealth management is unusually exposed to fraud, money laundering and sanctions risk, and it has communicated this to the sector directly through Dear CEO correspondence. The practical expectation is that firms with higher-risk client bases hold correspondingly stronger systems and controls — and can demonstrate the link between the risk they have accepted and the controls they operate.
That link is what supervisory review tends to probe. Not whether you have a policy, but whether your file evidence shows the policy being applied consistently, by different people, over time.
6. A practical checklist for 2026
- Confirm your own directors and PSCs are verified at Companies House, and that entities you administer are too, before the twelve-month window closes.
- Re-read your EDD triggers against HM Treasury's July 2025 clarifications and record where you have changed practice.
- Write down how your source of wealth enquiries scale with risk, with worked examples rather than principles.
- Map AML controls onto fraud risk and document the gaps — that mapping is the beginning of your reasonable procedures defence.
- Sample your own files as a supervisor would. If two officers reached different depths on comparable clients, that is your finding, not theirs.
7. Frequently asked questions
Does Companies House identity verification satisfy KYC obligations?
No. Companies House verification confirms an individual's identity for the integrity of the companies register. Customer due diligence under MLR 2017 additionally requires understanding ownership and control, assessing risk, establishing source of wealth where relevant, and monitoring the relationship. The two overlap on identity and diverge everywhere else.
When did identity verification become mandatory?
For new directors and PSCs, November 2025. Existing directors and PSCs have twelve months to comply, generally at their next confirmation statement, which places most deadlines in late 2026.
What is the failure to prevent fraud offence?
A corporate criminal offence, in force since September 2025, under which a large organisation may be liable where an associated person commits fraud intended to benefit it. The defence is having had reasonable fraud prevention procedures in place — which in practice means procedures you can evidence.
Is the UK still aligned with EU AML rules?
Not automatically. The UK retained the MLR 2017 framework after leaving the EU and now develops it independently — HM Treasury's 2025 consultation response is an example. Firms operating across both need to track two divergent regimes rather than assume one covers the other; see our guide to the EU AML package.
Who is the AML supervisor for a UK wealth manager?
The FCA, which supervises AML systems and controls alongside conduct for authorised firms.
8. How Wecan fits
Wecan Comply addresses the part of this that scales badly by hand: maintaining a current, structured, auditable due-diligence record for every client, with ownership and control mapped rather than described, and screening running continuously instead of at review time.
Two features matter specifically for the UK position described above. First, evidence: every document, decision and override carries a timestamp and an author, which is what both a supervisory file review and a reasonable-procedures defence ultimately rest on. Second, consistency: the same workflow applies to every client and every officer, which removes the variation that file sampling is designed to find.
For the wider method rather than the jurisdiction, see KYC and AML compliance for banks.
