Guide

Crypto AML policy in the UK: what the MLRs 2017 actually require

Updated

The UK requirements are readable in an afternoon and they are specific about what has to exist in writing. Most enforcement turns on the gap between the document and the practice.

Who is caught, and by whom

Regulation 14A of the Money Laundering Regulations 2017 defines a cryptoasset exchange provider as a firm or sole practitioner that by way of business exchanges cryptoassets for money or money for cryptoassets, exchanges one cryptoasset for another, arranges such exchanges, or operates a cryptoasset ATM, including as creator or issuer of the assets involved. A custodian wallet provider safeguards, or safeguards and administers, cryptoassets or the private keys used to hold, store and transfer them, on behalf of customers.

Regulation 7(1)(a)(viii) and (ix) make the FCA the supervisory authority for both. Regulation 56(1)(f) and (g) prohibit acting as either without being on the register the FCA maintains under regulation 54(1A).

The documents the regulations name

Regulation 18: risk assessment
Appropriate steps to identify and assess the money laundering and terrorist financing risks of the business, taking account of information from the supervisor and of risk factors covering customers, countries or geographic areas, products or services, transactions and delivery channels. It must be kept up to date in writing unless the supervisor says otherwise, and given to the supervisor on request.
Regulation 19: policies, controls and procedures
Established, maintained, regularly reviewed and updated, recorded in writing along with any changes and the steps taken to communicate them. They must be proportionate to size and nature and approved by senior management, and must cover risk management practices, internal controls, customer due diligence, reliance and record keeping, and the monitoring of compliance.
Regulation 21: internal controls
Where appropriate to size and nature: a board or senior management officer responsible for compliance, screening of relevant employees before and during appointment for skills, knowledge, expertise, conduct and integrity, and an independent audit function that examines and evaluates the policies, makes recommendations and monitors compliance with them.
Regulation 24: training
Relevant employees, and agents whose work is of the relevant kind, made aware of the law on money laundering, terrorist financing, proliferation financing and data protection, and regularly trained to recognise and deal with suspicious transactions, with a written record of the measures and the training given.
Regulation 40: records
Copies of CDD documents and supporting transaction records kept for at least five years from the end of the business relationship or the completion of an occasional transaction, extended for cryptoasset transfers to the documents and information received under the Part 7A travel rule obligations.

What goes into a registration application

Regulation 57 lets the registering authority specify what an application must contain, and names, among other things, the nature of the business, head office and branch addresses, the full name of the nominated officer, a risk assessment satisfying regulation 18, and information on how the business meets the MLRs, Part 3 of the Terrorism Act 2000 and Parts 7 and 8 of the Proceeds of Crime Act 2002. The AML documentation is not something you produce after registration; it is part of the application.

Reporting, which sits outside the MLRs

The duty to report suspicion comes from Part 7 of the Proceeds of Crime Act 2002 and Part 3 of the Terrorism Act 2000, not from the MLRs. Reports are made as suspicious activity reports to the National Crime Agency, and a defence against money laundering request is how consent to proceed with a transaction is sought.

What is changing

The FCA has confirmed that applications for authorisation under the Financial Services and Markets Act open on 30 September 2026 and the new cryptoasset regime is expected to start on 25 October 2027. Firms may still apply for MLR registration before then, but the FCA says it is unlikely to determine applications made after 31 July 2027 before the new regime starts, and that MLR registration does not guarantee FSMA authorisation (FCA, last updated 30 June 2026).

The MLRs are amended frequently. Check the provision on legislation.gov.uk before relying on wording quoted anywhere, including here: the site records outstanding amendments not yet applied to the text.

Questions, answered directly

Who supervises crypto firms for AML in the UK?

The FCA. Regulation 7(1)(a)(viii) and (ix) of the Money Laundering Regulations 2017 make it the supervisory authority for cryptoasset exchange providers and custodian wallet providers, and regulation 56 prohibits acting as either without being on the FCA register.

Does a small crypto firm still need a written AML policy?

Yes. Regulation 19 requires policies, controls and procedures to be recorded in writing and approved by senior management, and regulation 18 requires the risk assessment to be kept in writing. Both must be proportionate to the size and nature of the business, which changes their length, not their existence.

Get the policy written by someone who has defended one

Two minutes of questions; AML specialists quote you directly. Free, no obligation.

Get AML policy quotes