AML compliance is a legal requirement for accounting firms. It applies to all accountants and bookkeepers offering tax, payroll, accounts preparation, or company formation services. It is not optional and it is not discretionary, and a supervisory inspection that finds inconsistent compliance records can result in fines, public censure, or suspension.
Most small practices know they should be doing it consistently. Most small practices don't.
What AML compliance actually requires
- Customer Due Diligence before taking on any new client. Identity verification: name, address, date of birth, plus an understanding of the nature of the business and identification of any Person with Significant Control holding more than 25% of shares or voting rights.
- Risk rating every client as low, standard, or high with the rationale documented. High-risk clients trigger Enhanced Due Diligence, which requires more investigation, more documentation, and ongoing monitoring.
- An appointed Money Laundering Reporting Officer for firms with staff, notified to the supervisory body.
- Records kept for five years after the client relationship ends, under Regulation 40 of the Money Laundering Regulations 2017. This applies to CDD documents and transaction records, not just the client file.
- Training records for all relevant staff, under Regulation 24. Supervisory inspections specifically check for evidence that training was completed and documented.
Where it breaks down
AML compliance fails in small practices not because partners don't understand the requirements but because nobody owns the process consistently. ID documents get chased informally and filed inconsistently. Risk ratings are applied once at onboarding and never reviewed. Training gets done but records aren't kept in a form that would survive inspection. The client risk register exists in principle but hasn't been updated in months.
When a supervisory body visits, it checks for exactly these gaps. The question isn't whether you know AML applies. It's whether you can demonstrate consistent, documented compliance across your whole client base.
What we do
We chase ID documents at onboarding, log risk ratings and the rationale behind them, track Enhanced Due Diligence requirements for high-risk clients, maintain the five-year records schedule, and keep the client risk register updated as relationships evolve. The professional judgement on risk ratings and suspicious activity stays with you. The admin of making sure the records exist and are current stays with us.