Skip to content
EyesClear

AML Requirements for UK Asset Managers

Asset managers, AIFMs and wealth managers authorised by the FCA are in scope of the Money Laundering Regulations 2017 today. What that actually requires.

Article

Most anti-money-laundering writing is addressed to banks. That is where the enforcement headlines are, where the transaction volumes are, and where the vendors have historically sold. It leaves a large population of regulated firms — asset managers, AIFMs, wealth managers, discretionary managers, the smaller end of the fund industry — reading guidance written for an institution ten thousand times their size and trying to work out which parts apply to them.

Nearly all of it applies to them. The obligation is not smaller because the firm is.

Who is in scope

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 apply to “relevant persons”, a definition that captures credit institutions and financial institutions carrying on business in the UK. FCA-authorised firms fall within the FCA’s supervisory scope under those regulations, and that includes alternative investment fund managers, UCITS management companies, discretionary investment managers and wealth managers.

There is no exemption for size. A four-person AIFM running a single fund is a relevant person on the same terms as a global manager, subject to the same duties, with the same supervisor. What changes with size is not the obligation but the resource available to discharge it — which is precisely the problem worth writing about.

And the sector is being looked at

It would be reasonable to assume that supervisory attention follows transaction volume, and that a small manager is therefore some way down the list. The regulator’s own statements do not support that reading.

In its February 2025 portfolio letter to asset management and alternatives firms, the FCA set out financial crime systems and controls as a supervisory priority, and made a specific point that is worth reading twice: the trend towards investment in private assets requires a commensurate increase in anti-money-laundering controls, because of the complex ownership structures that tend to sit around those assets.

That is not a general exhortation. It identifies the exact place the work is hardest — the layered, cross-border, privately held structure that does not resolve from public filings alone — and says the controls have to keep pace with the move into it.

The letter also describes a data-led supervisory approach: identifying outlier firms and funds from data, then seeking assurance about how the risk is managed. A firm is not below the radar because it is small. It is on a list or it is not, and the thing that puts it on one is a pattern in data rather than a headcount.

What the regulations actually require

Stripped of the commentary, the duties fall into six groups.

A written risk assessment. The firm must identify and assess the money-laundering and terrorist-financing risk it faces, taking account of its customers, the countries it operates in, its products, its delivery channels and its transactions. This is the document everything else hangs from, and it is the first thing a supervisor asks for.

Policies, controls and procedures, proportionate to that risk, kept up to date, and approved by senior management. Proportionate is doing real work in that sentence: it is what allows a small firm to run a simpler programme, and it is also what stops “we are small” from being an answer on its own.

Customer due diligence. Identify the customer and verify that identity on the basis of documents or information from a reliable, independent source. Where there is a beneficial owner, identify them and take reasonable measures to verify them. Where the customer is a legal person, trust or similar arrangement, take reasonable measures to understand the ownership and control structure.

Enhanced due diligence where the risk is higher — a politically exposed person, a jurisdiction identified by the Financial Action Task Force as high-risk, an unusually complex or unusually large transaction, or any relationship the firm’s own risk assessment puts in that category. The scope of this one changed in June 2026; see below.

Ongoing monitoring. Scrutiny of the relationship over its life, and keeping the underlying documents and information up to date. Due diligence is not a gate at onboarding that closes behind the investor.

Record keeping, training, and a nominated officer to receive internal reports and decide whether to make a suspicious activity report.

What changed on 30 June 2026

The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 were made on 9 June 2026 and most of their provisions came into force on 30 June, implementing the government’s response to its 2024 consultation on the effectiveness of the MLRs. Three of the changes matter to a manager rewriting its procedures.

Enhanced due diligence on high-risk jurisdictions was narrowed. The mandatory requirement is focused more tightly, with firms given greater room to apply a risk-based approach; EDD must continue to be applied where required for clients and transactions involving jurisdictions the FATF identifies as high-risk. A procedure that applies blanket EDD to a long list of countries is now doing more than the regulations require, and — more to the point — may be spending effort where the firm’s own risk assessment would not have put it.

The trigger wording was refined to “unusually complex or unusually large” transactions. The intention is to focus enhanced checks on transactions that are genuinely out of place, rather than on an over-cautious reading of complexity.

Euro-denominated thresholds became sterling. The €10,000 threshold reads £10,000.

Two provisions land later: enhanced due diligence for specified cryptoasset activities on 1 February 2027, and parts of the cryptoasset change-in-control regime later still.

The direction is worth noting, because it is easy to misread. Narrowing mandatory EDD is not a relaxation of the obligation; it moves effort from a list to a judgement. A firm applying EDD because a country appeared on a schedule had a defence that wrote itself. A firm applying it because its own risk assessment says so needs the risk assessment, and the evidence, to be good.

Where a small firm actually loses the time

Set the framework aside and look at the work. An asset manager does not onboard retail customers one at a time across a branch network. It onboards investors — and investors arrive as structures.

A subscription comes in from a Luxembourg SPV whose shares are held by a Jersey trust, and the trustee is a corporate services provider. Another comes from a family office that invests through three vehicles with overlapping directors. A feeder fund subscribes on behalf of investors the manager will never see. A corporate LP names a signatory who does not appear anywhere in its filed ownership.

Every one of those is answerable. None of them is answerable from the subscription documents alone, which is the point where the work leaves the file and becomes research: company registries in three jurisdictions, filed accounts, litigation records, regulatory registers, sanctions and PEP lists, adverse media, and the slow business of reconciling a name that is spelled two ways across four documents.

That research is the majority of the effort and almost none of the software budget. It is also the part that a two-person compliance function cannot scale, because it does not get faster with practice — each new investor is a fresh problem.

The half of the file you do not own

There is a structural reason this is hard, and it is worth naming precisely.

For your own investors you hold the evidence. The subscription, the payment instruction, the account, the correspondence, the history. You can reason about that side because you own it.

The other side — who actually stands behind the corporate subscriber, what the trustee has done elsewhere, whether the beneficial owner has an enforcement record in a jurisdiction you have never looked at — is on the public record, outside your systems. No amount of internal tooling reaches it, because the evidence was never inside the firm.

This is the same split we wrote about for banks, and it lands harder on a small manager: a bank has an operations team to absorb the research, and you do not.

What a defensible answer looks like

Three things distinguish a file that survives a supervisory visit from one that does not, and none of them is about volume.

Every finding traces to a source. A note that says “no adverse findings” is not evidence. A note that quotes the register entry, names the source and dates it can be checked two years later by someone who was not in the room.

Negative results are recorded honestly. Where nothing is found, the file should say nothing was identified in the sources searched — not that the investor is clean. The second is a claim the search never supported, and it is the one that fails on review.

A person decided. Automation can assemble the evidence; it cannot own the conclusion. The regulations put the decision with the firm, and a file where a human weighed the material and signed is the file that defends itself.

EyesClear Investigations was built against exactly that standard: it screens a company or a person against public sources and returns every finding with the quote, the source and the date it came from, and it says explicitly when nothing was identified. How a report is produced is published in full — including what it cannot tell you — because a method you cannot read is not a method you can defend. What leaves your firm is the name being screened and the search terms derived from it; the security page states that in detail rather than rounding it down to a slogan.

The EyesClear Platform is the other tool, and it is a different conversation: it runs inside a bank’s own infrastructure and consolidates alert handling at institutional volume. Nine years in production, seven banking clients. A manager onboarding two hundred investors a year does not need it. The research problem is the one worth solving first.

Where to go next

If the specific problem is the subscriber that is a company rather than a person, investor onboarding due diligence is the operational version of this article. If it is the layers above the subscriber, identifying beneficial owners through fund and trust structures deals with the point where ownership stops resolving to a natural person. And if the file keeps failing on the same question, source of wealth and source of funds is usually that question.

Sources

AMLAsset ManagementCustomer Due DiligenceMLR 2017FCAComplianceRegTechFund Management

← All articles

Try it on a name you already know

Investigations is free for financial institutions and their regulators — five screenings to start, nothing to integrate. Or book a demo and we will run the Platform on your own scenarios.