Guide
Crypto AML policy in the UK: what the MLRs 2017 actually require
Updated
The UK requirements are readable in an afternoon and they are specific about what has to exist in writing. Most enforcement turns on the gap between the document and the practice.
Who is caught, and by whom
Regulation 14A of the Money Laundering Regulations 2017 defines a cryptoasset exchange provider as a firm or sole practitioner that by way of business exchanges cryptoassets for money or money for cryptoassets, exchanges one cryptoasset for another, arranges such exchanges, or operates a cryptoasset ATM, including as creator or issuer of the assets involved. A custodian wallet provider safeguards, or safeguards and administers, cryptoassets or the private keys used to hold, store and transfer them, on behalf of customers.
Regulation 7(1)(a)(viii) and (ix) make the FCA the supervisory authority for both. Regulation 56(1)(f) and (g) prohibit acting as either without being on the register the FCA maintains under regulation 54(1A).
The documents the regulations name
- Regulation 18: risk assessment
- Appropriate steps to identify and assess the money laundering and terrorist financing risks of the business, taking account of information from the supervisor and of risk factors covering customers, countries or geographic areas, products or services, transactions and delivery channels. It must be kept up to date in writing unless the supervisor says otherwise, and given to the supervisor on request.
- Regulation 19: policies, controls and procedures
- Established, maintained, regularly reviewed and updated, recorded in writing along with any changes and the steps taken to communicate them. They must be proportionate to size and nature and approved by senior management, and must cover risk management practices, internal controls, customer due diligence, reliance and record keeping, and the monitoring of compliance.
- Regulation 21: internal controls
- Where appropriate to size and nature: a board or senior management officer responsible for compliance, screening of relevant employees before and during appointment for skills, knowledge, expertise, conduct and integrity, and an independent audit function that examines and evaluates the policies, makes recommendations and monitors compliance with them.
- Regulation 24: training
- Relevant employees, and agents whose work is of the relevant kind, made aware of the law on money laundering, terrorist financing, proliferation financing and data protection, and regularly trained to recognise and deal with suspicious transactions, with a written record of the measures and the training given.
- Regulation 40: records
- Copies of CDD documents and supporting transaction records kept for at least five years from the end of the business relationship or the completion of an occasional transaction, extended for cryptoasset transfers to the documents and information received under the Part 7A travel rule obligations.
What goes into a registration application
Regulation 57 lets the registering authority specify what an application must contain, and names, among other things, the nature of the business, head office and branch addresses, the full name of the nominated officer, a risk assessment satisfying regulation 18, and information on how the business meets the MLRs, Part 3 of the Terrorism Act 2000 and Parts 7 and 8 of the Proceeds of Crime Act 2002. The AML documentation is not something you produce after registration; it is part of the application.
Reporting, which sits outside the MLRs
The duty to report suspicion comes from Part 7 of the Proceeds of Crime Act 2002 and Part 3 of the Terrorism Act 2000, not from the MLRs. Reports are made as suspicious activity reports to the National Crime Agency, and a defence against money laundering request is how consent to proceed with a transaction is sought.
What is changing
The FCA has confirmed that applications for authorisation under the Financial Services and Markets Act open on 30 September 2026 and the new cryptoasset regime is expected to start on 25 October 2027. Firms may still apply for MLR registration before then, but the FCA says it is unlikely to determine applications made after 31 July 2027 before the new regime starts, and that MLR registration does not guarantee FSMA authorisation (FCA, last updated 30 June 2026).
The MLRs are amended frequently. Check the provision on legislation.gov.uk before relying on wording quoted anywhere, including here: the site records outstanding amendments not yet applied to the text.