Skip to main content

How do accounting practices handle anti-money laundering compliance? HMRC’s Anti-Money Laundering Supervision Report 2024-25 is a useful reality check for any practice that thinks AML compliance is something only larger firms worry about. Between October 2024 and March 2025 alone, 91 accountancy service providers received a combined £538,916 in AML penalties.

The scale of non-compliance: ICAEW’s Quality Assurance monitoring found 19.3% of supervised accounting practices non-compliant with basic AML requirements. HMRC issued 1,860 AML fines to accountancy service providers between 2021/22 and 2024/25, a 102% increase over the period.

What are the AML obligations for accounting practices in the UK?

Every accounting practice in the UK that provides tax advice, accountancy services, audit, or trust and company service provider (TCSP) functions is regulated under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended. The core obligations are:

  • Registration: Register with your supervisory body (HMRC, ICAEW, ACCA, CIOT, or AAT depending on your qualifications)
  • Business-wide risk assessment: A written document assessing the money laundering risk of your practice as a whole, kept up to date and capable of withstanding supervisory scrutiny
  • Client due diligence: Identity verification and risk assessment for every new client, and ongoing monitoring for the duration of the relationship
  • Policies, controls, and procedures: Written AML policies covering how your practice handles each obligation, reviewed regularly and communicated to all relevant staff
  • Suspicious Activity Reporting: A nominated officer responsible for receiving internal reports and submitting Suspicious Activity Reports (SARs) to the National Crime Agency (NCA) where required
  • Record retention: Customer due diligence (CDD) documents and risk assessment records retained for at least five years after the business relationship ends

What does customer due diligence actually require from your practice?

CDD sits at the heart of AML compliance. The regulations require your practice to:

  • Identify the client
  • Verify that identity using reliable independent sources
  • Understand the nature and purpose of the business relationship
  • Assess the money laundering risk that client presents

Here’s what that looks like by entity type:

Entity type Standard CDD required Additional checks
Sole trader Photo ID + proof of address Source of income if high-turnover or unusual trading pattern
Limited company Photo ID for all beneficial owners (25%+ stake); Companies House verification UBO structure; EDD if complex ownership or overseas PSC
LLP or partnership Photo ID for all partners with management or profit interest UBO where a corporate partner is involved
Trust or foundation Trustee and beneficiary ID; trust deed review EDD almost always required due to opacity of structure

The distinction between standard CDD and enhanced due diligence (EDD) is risk-driven.

EDD applies where your risk assessment identifies elevated risk factors:

  • Clients in high-risk third countries
  • Politically exposed persons (PEPs)
  • Complex corporate structures with opaque ownership
  • Transactions with no obvious lawful explanation

EDD requires more detailed verification, deeper source of funds investigation, and more frequent ongoing monitoring.

CDD isn’t a one-time task. The regulations require you to monitor client relationships on an ongoing basis. If a client’s circumstances change materially, like new shareholders, change of trading activity, unusually large transactions, the CDD file should be updated to reflect the new risk assessment.

What is a business-wide risk assessment and why is it the foundation of AML compliance?

The business-wide risk assessment (BWRA) is a written document that sets out your practice’s overall assessment of the money laundering risk it faces as a business. It covers the types of clients your practice serves, the services you provide, the geographies you operate in, and the delivery channels you use. It’s the document that underpins everything else: your CDD tiers, your PCP (policies, controls, and procedures), and your staff training.

HMRC and the professional supervisory bodies are increasingly scrutinising the quality of BWRAs during monitoring visits. A BWRA that was written three years ago and hasn’t been updated isn’t compliant. Supervisors want to see a proportionate, evidence-based assessment that reflects your actual client base and that has been reviewed within the last 12 months.

Many practices either have no written BWRA at all, or have one that was completed at registration and never updated. This is the single most common finding in HMRC AML monitoring visits for accountancy firms.

How do accounting practices build AML compliance into their onboarding workflow?

The practices that handle AML most effectively are those that have embedded it into their standard onboarding process rather than treating it as a separate compliance task.

Here’s the workflow structure that works:

  1. Initial enquiry: Conduct a pre-engagement risk check before taking on any new client. Consider the entity type, the services requested, and any red flags (urgency, unusual payment requests, reluctance to provide information)
  2. Identity verification: Collect the required CDD documents based on entity type. Electronic verification tools can automate this step and return a verified result in minutes, removing the need to handle physical documents
  3. Risk assessment: Complete a client-level risk assessment documenting the basis for your risk rating (standard, enhanced, or simplified). This should reference your BWRA and be saved to the client file
  4. Engagement letter: Issue and obtain a signed engagement letter before any billable work begins. The letter should reference your AML obligations and the client’s agreement to provide the required information on an ongoing basis
  5. Ongoing monitoring: Set a review trigger for each client based on their risk rating. High-risk clients should be reviewed annually. Standard-risk clients should be reviewed when circumstances change or at least every two to three years
  6. Record retention: Store all CDD documents and risk assessments in a retrievable format for the required five-year retention period after the relationship ends

What do AML supervisors look for when reviewing an accounting practice?

Based on HMRC’s published supervision reports and ICAEW’s Quality Assurance monitoring findings, here are the most common failures and what inspectors are looking for in each area:

Common failure What inspectors find
No written business-wide risk assessment Supervisors treat this as a fundamental breach, regardless of how good the firm’s actual CDD is
Incomplete CDD for long-standing clients Practices that onboarded clients before AML obligations tightened and never updated the file
Missing beneficial ownership information ID collected for the company director but not for shareholders with 25%+ stake
No evidence of ongoing monitoring CDD completed at onboarding but no review triggered when client circumstances change
Poor record retention CDD documents collected but not retrievable or not retained for the full five-year period after relationship ends
Failure to register under MLRs Firms providing relevant services without registering with their supervisory body

Most practices that receive AML penalties aren’t facilitating money laundering. They’re running a practice without the documented controls and records that the regulations require. The distinction matters because it means most compliance failures are preventable with the right workflow.

How does BrightManager by Bright help accounting practices manage AML compliance?

AML compliance is fundamentally a workflow and document management challenge. You need to know, at any point in time, which clients have complete CDD on file, which are due for a review, and which are flagged as higher risk. Managing that across a portfolio of hundreds of clients in a spreadsheet or a shared drive doesn’t scale and creates exactly the kind of documentation gaps that supervisors find during monitoring visits.

BrightManager by Bright gives practices a centralised client management platform where AML status, CDD completion, and review dates can be tracked across the entire client portfolio. When a client’s CDD review is due, BrightManager by Bright surfaces that in the same workflow as the client’s filing deadlines and outstanding tasks, so it doesn’t fall through the cracks between busy periods. The client file holds the CDD documentation, risk assessment, and engagement history in a single retrievable location, which is precisely what a supervisor expects to see during a monitoring visit.

For the engagement letter step, BrightPropose by Bright connects the proposal and engagement letter workflow to the onboarding process. Practices using BrightPropose by Bright issue a professionally branded engagement letter with e-signature capability as part of the same sequence as identity verification and risk assessment, rather than as a separate task that relies on someone remembering to chase. The signed letter is returned digitally and stored in the client record, giving you the audit trail that both your supervisory body and your professional indemnity insurer want to see.

How does BrightManager by Bright compare to alternatives for managing AML compliance workflow?

Dedicated AML compliance tools for accountants include NorthRow, Thirdfort, and SmartSearch. These are strong identity verification and electronic CDD platforms that automate the evidence-gathering process and return verified results in seconds. They work well as standalone ID verification tools and can integrate with some practice management platforms.

The difference with BrightManager by Bright is that it handles the AML workflow as part of practice management rather than as a standalone compliance step. It’s ID checks are conducted through a trusted third party called Veriphy. Your client’s AML status, CDD completion, review dates, and compliance documents sit in the same platform as their filing deadlines, tasks, and billing records.

BrightManager by Bright helps accounting practices track AML status, CDD completion, and review dates across every client in the portfolio, so nothing falls through the cracks during a busy period. BrightPropose by Bright connects engagement letters and e-signatures to the same onboarding workflow.