Skip to main content
UK Strategy Shows What Happens When AML Becomes PaperworkAnti-Corruption & AML
4 min readFor Compliance Training Managers

UK Strategy Shows What Happens When AML Becomes Paperwork

Recognizing the Problem

The UK government recently published its Anti-money laundering and asset recovery strategy 2026-2029, highlighting a significant issue: despite heavy investment in AML, many compliance efforts remain focused on low-value "tick-box" activities. Tools and training haven't kept up with evolving threats.

This isn't about regulatory failure. It's about the system generating vast amounts of activity with limited intelligence value. In 2024-25, firms submitted 866,616 suspicious activity reports to the UK Financial Intelligence Unit. The government questions whether this volume includes too much reporting that doesn't effectively prevent money laundering.

Key Developments

February 2026: Guidance on using digital identity providers for customer due diligence is published, indicating a shift toward technology-enabled compliance.

September 2026: The new strategy launches, stating that the system relies too heavily on low-value compliance activity.

Current status: The Financial Services and Markets Bill is moving through Parliament to transfer AML supervision of legal, accountancy, and trust and company service providers to the FCA. HM Treasury plans consultations on further changes to the Money Laundering Regulations, the SARs regime, and supervisory enforcement powers during 2026-27.

2027-28: A decision is expected on whether to raise the statutory suspicion threshold under the Proceeds of Crime Act, with "reasonable grounds to suspect" as a possible alternative.

2028-29: The strategy envisions firms beginning to move to FCA supervision.

Identifying the Issues

The problem isn't failed controls, but that controls became the goal.

Risk assessment became formulaic: Firms applied blanket controls rather than assessing which customers, transactions, and activities presented the highest risks. Enhanced due diligence was often triggered by jurisdiction lists instead of actual risk indicators.

Training focused on rules, not recognition: AML courses often covered definitions and requirements without building employees' ability to recognize risk indicators or understand what makes a SAR worth filing.

Reporting volume replaced reporting quality: The suspicion threshold under the Proceeds of Crime Act led to many SARs with limited intelligence value. Firms reported defensively, more concerned about regulatory exposure than helping law enforcement.

Supervision rewarded documentation over outcomes: Reviews checked for policies, procedures, and training records but spent less time examining whether controls focused on high-risk activity.

Technology lagged behind threats: While criminals used AI and fintech platforms, many compliance programs still relied on document collection.

What Standards Require

The Money Laundering Regulations require a risk-based approach. Regulation 18 requires firms to identify and assess money laundering risks. Regulation 19 requires policies, controls, and procedures that are proportionate to the business's nature and size.

ISO 37301 Compliance Management Systems requires compliance obligations to be determined and risks assessed, with controls proportionate to those risks. Section 8.2.2 emphasizes evaluating compliance performance based on outcomes.

The Federal Sentencing Guidelines for Organizations stress that an effective compliance program must detect and prevent criminal conduct. Commentary to §8B2.1 notes that a program should be assessed on its effectiveness, not just its existence.

None of these standards endorse tick-box compliance. They require risk-based, proportionate, and effective controls. The UK government isn't changing the obligation but acknowledging that many firms' interpretations have drifted toward low-value activity.

Action Items for Your Team

Audit your training for judgment, not just coverage. Review your AML training. Does it teach employees to recognize risk indicators and make decisions, or just walk them through requirements? If it's the latter, you're training people to complete boxes, not assess risk.

Consider adding scenario-based exercises where employees decide if a situation warrants enhanced due diligence or a SAR. Use realistic examples that require judgment, not obvious red flags.

Map your EDD triggers to actual risk. List every circumstance that triggers enhanced due diligence. Ask if each reflects a genuine money laundering risk or is a defensive response to regulation. The 2026 changes dropped mandatory EDD for FATF grey-listed jurisdictions, allowing more risk-based EDD. If your program still treats jurisdiction as an automatic trigger, you're not operating risk-based controls.

Review your SAR quality, not just your SAR count. Sample SARs filed in the past year. How many described genuine suspicion based on specific facts? How many were filed because they met a technical threshold? If you can't distinguish, your team may be reporting defensively.

The government may raise the suspicion threshold to "reasonable grounds to suspect." Even if it doesn't, ensure each SAR reflects meaningful suspicion.

Prepare for technology to play a larger role. The FCA will publish examples of good and poor AI use for AML during 2026-27. If your program hasn't evaluated digital identity providers or AI-assisted risk assessment, you're falling behind expectations.

Start by reviewing the February 2026 guidance on digital identity providers. Identify where your program relies on manual document collection when digital identity could provide more reliable information.

Track where your team spends time. For one month, have your AML team log their activities. If most hours go toward documentation rather than identifying or mitigating risk, you've built a tick-box program.

The UK government's strategy signals a shift toward intelligence-led, outcomes-focused supervision. Your program should already meet that standard.

You Might Also Like