You've updated your AML policy three times this year. You've incorporated the latest regulatory guidance. Your procedures reference the right frameworks. Your team knows the high-risk jurisdictions by heart.
But when did you last ask whether your red flags are actually catching the criminals operating right now?
Recent analysis of Companies House data identified 3,097 dissolved companies between 2016 and 2026, with average lifespans of just 170 to 194 days. These weren't offshore shell companies or complex international structures. They were hairdressers, convenience stores, and beauty salons clustered around the same postcodes and registered addresses. Conservative estimates suggest £310 million to £464 million moved through these seemingly ordinary businesses.
The problem isn't that your AML program ignores red flags. It's that you're still looking for yesterday's patterns while criminals exploit today's gaps.
Myth 1: "High-risk businesses are the ones in our policy"
Reality: Your list of high-risk business types probably hasn't changed in years.
Most AML policies flag offshore companies, complex ownership structures, and businesses in high-risk jurisdictions. All valid. But where on your list is the corner shop? The nail salon? The car wash?
Among the suspect convenience businesses in the Companies House analysis, 92% were incorporated in the first or second quarter of the year, with more than half dissolved in the fourth quarter. For hairdressing-related companies, 83% were incorporated during the first two quarters. One Cardiff postcode alone contained 119 suspected companies across these two sectors.
These businesses didn't look suspicious individually. The pattern made them suspicious.
Your red flags should capture not just what a business is, but how it behaves. A convenience store isn't inherently high-risk. A convenience store that shares a registered address with 40 other recently dissolved companies is worth a second look.
Myth 2: "Companies House registration validates legitimacy"
Reality: Registration confirms that paperwork was filed, not that a genuine business exists.
When you search Companies House during client onboarding, what are you actually checking? That the company exists on the register? Or that the information on the register makes commercial sense?
If your due diligence stops at "company is registered," you're missing the story the data tells. Look at the company's lifespan. Check how many other businesses share its registered address. Review the directors' history. Count how many companies they've been involved with that dissolved within months.
The SRA's June 2026 guidance on client and matter risk assessments specifically noted examples where firms missed specific AML risks or adopted a tick-box approach rather than genuinely considering the risks involved.
Registration is the starting point for due diligence, not the conclusion.
Myth 3: "Individual red flags trigger enhanced due diligence"
Reality: Individual red flags in isolation may mean nothing. Patterns reveal the risk.
A short corporate history might indicate a startup. A shared registered address might reflect a serviced office. A generic business description might just be lazy drafting.
But what if you see all three? What if the client's stated turnover doesn't match typical businesses of that type? What if the beneficial owner has been involved with five other companies that dissolved within six months?
The issue isn't any single indicator. It's the combination.
Your AML procedures should train your team to recognize when multiple low-level indicators cluster together. That requires documenting not just whether a red flag is present, but what story emerges when you consider them collectively.
Myth 4: "Our risk assessment reflects current threats"
Reality: Your risk assessment probably reflects last year's regulatory update, not this year's criminal tactics.
When did you last revise your firm-wide risk assessment? More importantly, when did you last challenge the assumptions underneath it?
The SRA's current guidance requires that a firm's risk assessment identify the money laundering risks the firm is exposed to and inform its policies, controls, and client and matter risk assessments. The SRA also says its sectoral risk assessment should be taken into account when firms produce their own firm-wide risk assessment.
With the SRA's latest sectoral risk assessment published in August 2026, you have a timely opportunity to revisit whether your red flags still capture emerging risks.
Criminals don't wait for the next regulatory cycle before changing tactics. Your risk assessment shouldn't either.
Myth 5: "We'd spot a suspicious client during onboarding"
Reality: The clients who should concern you most probably look completely ordinary.
Picture this client: a UK limited company operating a convenience store. One director. One beneficial owner. Registered address in a major city. Modest stated turnover. No offshore connections. No complex ownership structure. Nothing on your high-risk checklist.
Would your onboarding process flag it?
Now add context: The company was incorporated eight months ago. Its registered address is shared by 30 other recently dissolved companies. The beneficial owner was director of three other businesses that existed for less than a year. The stated annual turnover is £200,000, but the client wants to complete a property transaction worth £800,000.
Same company. Different risk profile.
The most dangerous assumption in AML compliance is that suspicious clients look suspicious. Effective money laundering looks legitimate until you examine the details.
What to do instead
Stop treating red flags as a static checklist. Start treating them as hypotheses you're constantly testing against real-world patterns.
Review your high-risk business categories. Are they based on where financial crime is actually happening, or where it was happening five years ago? Add questions about corporate lifespan, address clustering, and director histories to your risk assessment.
Train your team to look for patterns, not just flags. Individual indicators should prompt questions, not automatic decisions. Multiple indicators should prompt deeper investigation.
Use Companies House data actively, not passively. Don't just confirm a company exists. Look at its history, its connections, and whether its stated activity aligns with its financial behavior.
Document your reasoning. When you identify a pattern of indicators, record what you found and why it did or didn't concern you. This protects you if questions arise later and helps you refine your red flags over time.
Test your assumptions regularly. Every six months, pull a sample of recent client onboardings and ask: would our current procedures catch the patterns identified in recent enforcement actions or industry research?
The most dangerous AML policy isn't one that's out of date. It's one that's perfectly updated on paper but still looking for criminals who've already moved on.
Your red flags should evolve as fast as the threats you're trying to catch. If they don't, you're compliant in theory and exposed in practice.



