Skip to main content

AML record keeping requirements for UK accountants

By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 9 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

UK accountants must keep copies of customer due diligence documents and supporting transaction records for five years from the end of the business relationship, or from completion of an occasional transaction (Money Laundering Regulations 2017, regulation 40). The practice must then delete the personal data, unless one of three exceptions applies.

This guide is for the owner of a UK accounting practice, or the person responsible for its AML compliance, who has to decide what goes on a client file and when it comes off. Two things changed in 2026. On 30 June 2026 the due diligence thresholds in regulation 27 moved from euros to pounds. On 22 September 2026 the Financial Conduct Authority (FCA) published its plans for taking over anti-money laundering (AML) supervision of accountants. We built the same close-then-count retention clock into Filyst, our case management product for immigration firms. The sections cover the records, the retention period, deletion, the due diligence triggers and supervision.

AML record retention: from onboarding to deletionCustomer due diligence is applied when the business relationship starts (regulations 27 and 28). Ongoing monitoring continues through the relationship (regulation 28(11)). The relationship ends. The records are kept for five years from the date the practice knows, or has reasonable grounds to believe, that the relationship has ended (regulation 40(3)). The practice then deletes personal data obtained for the purposes of the Regulations, unless another enactment or court proceedings require it, the data subject has consented, or the practice has reasonable grounds to believe it is needed for legal proceedings (regulation 40(5)).StartDue diligence (reg27, 28)DuringOngoing monitoring(28(11))EndRelationship ends+5 yearsRetention ends(40(3))ThenDelete personal data(40(5))
The five-year period starts when the relationship ends, not when the record was made.

What are AML records?

AML records are the documents a firm must keep under regulation 40 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, usually called the Money Laundering Regulations 2017 or MLR 2017. Regulation 40 names the records, sets the period and orders deletion at the end of it.

Most of these records come from customer due diligence (CDD), often called “know your customer” checks. CDD is the set of measures in regulation 28: identifying the customer, verifying that identity and assessing the purpose of the relationship.

Who must keep AML records?

Every “relevant person” must keep them. Regulation 8(2)(c) lists auditors, insolvency practitioners, external accountants and tax advisers acting in the course of business in the United Kingdom.

Regulation 11 defines an external accountant as a firm or sole practitioner who by way of business provides accountancy services to other persons. It defines a tax adviser as one who provides material aid, assistance or advice in connection with the tax affairs of other persons. A practice that forms companies or provides a registered office is also a trust or company service provider under regulation 12(2).

Which AML records must accountants keep?

Regulation 40(2) requires two kinds of record from an accounting practice: copies of the due diligence documents and information, and supporting records of transactions. Its other two kinds apply only to cryptoasset transfers. Other regulations require written records that sit beside them.

RecordWhat it containsRegulation
Due diligence copiesA copy of any documents and information obtained to satisfy the due diligence requirements in regulations 28, 29 and 33 to 37, and regulation 30A (discrepancies in registers)40(2)(a)
Supporting transaction recordsOriginals or copies, sufficient to reconstruct a transaction that was the subject of due diligence or ongoing monitoring40(2)(b)
Beneficial owner searchA written record of all the actions taken to identify a company's beneficial owner, where the practice has exhausted all possible means of identifying that owner28(8)
Firm-wide risk assessmentAn up-to-date written record of the steps taken to identify and assess the practice's own risks, unless the supervisor has notified the practice in writing that no record is required18(4)
TrainingA written record of the awareness and training measures taken for relevant employees and agents24(1)(b)

A “copy” means a copy that would be admissible in court proceedings as evidence of the original document (regulation 40(9)(b)). The five-year period in regulation 40 applies to the two regulation 40(2) records. The risk assessment in the fourth row is the subject of our AML firm-wide risk assessment template, and the practice must give it to its supervisor on request (regulation 18(6)).

How long must AML records be kept?

AML records must be kept for at least five years. The period begins on the date the practice knows, or has reasonable grounds to believe, that the business relationship has come to an end or the occasional transaction is complete (regulation 40(3)).

Record relates toFive years begin whenRegulation
An occasional transactionThe transaction is complete40(3)(a)
A transaction within a business relationshipThe business relationship ends40(3)(b)(i)
Due diligence measures taken in connection with a business relationshipThe business relationship ends40(3)(b)(ii)

A business relationshipis a business, professional or commercial relationship with a customer that the practice expects, when contact is established, to have an element of duration (regulation 4(1)). An occasional transaction is a transaction not carried out as part of a business relationship (regulation 3). A long-standing client’s onboarding documents therefore stay on file for the whole relationship plus five years.

The 10-year cap in regulation 40(4) is narrow. It covers only the records in regulation 40(3)(b)(i): records of a transaction that occurs as part of a business relationship. A practice is not required to keep those for more than 10 years. The cap does not cover the due diligence records in regulation 40(3)(b)(ii).

When must AML personal data be deleted?

Once the period has expired, the practice must delete any personal data obtained for the purposes of the Regulations, unless one of the three exceptions in regulation 40(5) applies:

  • the practice is required to retain records containing the personal data by or under any enactment, or for the purposes of any court proceedings (40(5)(a));
  • the data subject has given consent to the retention of that data (40(5)(b));
  • the practice has reasonable grounds for believing that records containing the personal data need to be retained for the purpose of legal proceedings (40(5)(c)).

The duty is to delete personal data, so a practice that keeps a passport copy past the period needs to name the exception it relies on. The first exception needs a requirement to retain. The third needs only reasonable grounds for the belief.

When must a practice carry out customer due diligence?

Regulation 27 gives an accounting practice nine triggers for customer due diligence. Four are in regulation 27(1), one is in regulation 27(2) and four apply to existing clients under regulation 27(8).

TriggerRegulation
The practice establishes a business relationship27(1)(a)
The practice carries out an occasional transaction that amounts to a transfer of funds, within the meaning of Article 3.9 of the funds transfer regulation, exceeding £80027(1)(b)
The practice suspects money laundering or terrorist financing27(1)(c)
The practice doubts the veracity or adequacy of documents or information previously obtained for identification or verification27(1)(d)
The practice carries out an occasional transaction that amounts to £12,000 or more, in a single operation or in several operations which appear to be linked27(2)
The practice has a legal duty in the calendar year to contact an existing client to review information that is relevant to its risk assessment of that client and relates to the client's beneficial ownership27(8)(za)
The practice has to contact an existing client to fulfil a duty under the International Tax Compliance Regulations 201527(8)(zb)
An existing client reaches another appropriate time for due diligence, decided on a risk based approach27(8)(a)
The practice becomes aware that an existing client's circumstances relevant to its risk assessment for that client have changed27(8)(b)

The £800 and £12,000 figures date from 30 June 2026. The Money Laundering and Terrorist Financing (Amendment) Regulations 2026(SI 2026/621), regulation 14, replaced “1,000 euros” and “15,000 euros”. The £800 trigger covers only a transfer of funds as the funds transfer regulation defines it. The £12,000 trigger covers any occasional transaction.

Regulation 27(9) lists what a practice must take into account when deciding the appropriate time for an existing client, among other things: any indication that the identity of the client or its beneficial owner has changed; any transactions not reasonably consistent with what the practice knows of the client; any change in the purpose or intended nature of the relationship; and any other matter affecting the risk assessment. The remaining paragraphs of regulation 27 apply to high value dealers, casinos, letting agents, art market participants and cryptoasset businesses.

A request to form a firm, sell an off-the-shelf firm, or act as or arrange a director, secretary, partner, trustee or nominee shareholder is treated as a business relationship whether or not it is expected to last (regulation 4(2)). The first trigger then applies.

What does customer due diligence involve?

Customer due diligence involves identifying the customer, verifying the identity from a reliable independent source and assessing the purpose and intended nature of the relationship (regulation 28(2)). Regulation 28 adds measures for companies, beneficial owners and people acting for the customer.

MeasureRegulation
Identify the customer and verify the customer's identity28(2)(a)–(b)
Assess, and where appropriate obtain information on, the purpose and intended nature of the relationship or transaction28(2)(c)
Company: obtain and verify its name, its company or registration number, and its registered office address (and principal place of business, if different)28(3)(a)
Company not listed on a regulated market: take reasonable measures to determine and verify its governing law and constitution, the full names of its board of directors and its senior persons28(3)(b), 28(5)
Company, trust or similar arrangement not listed on a regulated market: take reasonable measures to understand its ownership and control structure28(3A), 28(5)
Customer not listed on a regulated market and beneficially owned by another person: identify the beneficial owner and take reasonable measures to verify that identity28(4), 28(5)
Person acting on the customer's behalf: verify the authority to act, identify the person and verify that identity28(10)
Ongoing monitoring: scrutinise transactions, review existing records and keep due diligence documents up to date28(11)

A search of the company register is not enough on its own. Regulation 28(9) says a practice does not satisfy the beneficial owner requirement by relying solely on information delivered to the registrar about registrable persons, registrable relevant legal entities or registrable beneficial owners. The extent of the measures must reflect the practice’s firm-wide risk assessment and its assessment of the risk in the particular case (regulation 28(12)).

Who can ask a practice for its AML records?

The practice’s supervisor can, and so can another firm that relied on the practice’s due diligence. A practice must be able to demonstrate to its supervisory authority that the extent of its measures is appropriate to the risks (regulation 28(16)).

Regulation 39 lets one relevant person rely on another to apply due diligence measures, although the relying firm remains liable for any failure. A practice that is relied on must keep the regulation 40(2) records for the same period (regulation 40(6)). On request within that period it must immediately make the information available and forward copies of the identification and verification data (regulation 40(7)).

What happens if a practice does not keep AML records?

A practice that contravenes regulation 40(1) or 40(5) to (7) commits a criminal offence. Schedule 6, paragraph 8(b)makes those paragraphs “relevant requirements”, and regulation 86(1) makes contravening a relevant requirement an offence. The same contravention can instead be dealt with by a civil penalty or a public censure from a designated supervisory authority, which means the FCA or HMRC (regulation 76).

The maximum sentence is three months’ imprisonment, a fine or both on summary conviction, and two years’ imprisonment, a fine or both on conviction on indictment. A person is not guilty who took all reasonable steps and exercised all due diligence to avoid committing the offence (regulation 86(3)). Deleting too late is covered as well as keeping too little, because regulation 40(5) is on the list.

Who supervises accountants for AML?

An accounting practice is supervised today by its professional body or by HM Revenue and Customs (HMRC). Regulation 7(1)(b) makes each professional body listed in Schedule 1 the supervisory authority for its members. Regulation 7(1)(c)(iv) gives HMRC the auditors, external accountants and tax advisers that no listed body supervises.

The Government announced in October 2025 that the FCA will take over AML supervision of accountancy, legal, and trust and company service providers. The move is not law yet. The FCA’s page on AML supervisory reform, published on 22 September 2026, says the reform “relies on the Government passing new legislation”: the Financial Services Bill and secondary legislation, including changes to the Money Laundering Regulations.

The FCA says today:

  • “Nothing changes immediately”, and accountancy providers “do not need to take any action now”;
  • practices should continue to follow existing AML processes and speak to their current professional body supervisor with questions;
  • it does not expect to begin taking on supervision until autumn 2028, and the transition is likely to happen in phases and complete around 2030;
  • the change is expected to affect around 34,000 accountancy businesses supervised by professional bodies, and around 18,000 accountancy businesses and trust and company service providers supervised by HMRC (FCA estimates);
  • its timeline expects Government legislation in 2027, and it will consult on fees before it takes on the role.

Regulation 40 places the record-keeping duty on the practice, whichever body supervises it. Until legislation changes the regulation, it applies as written above.

How should a practice organise AML records?

A practice should store three dates on each client file: the date due diligence was last applied, the date the relationship ended and the deletion date that follows from it. Regulation 40 turns on the second date, and a spreadsheet of onboarding dates does not hold it.

We met the same problem building Filyst. Filyst sets a retention date when a case is closed, runs a daily job that reminds the firm when destruction is due and blocks destruction before that date. That is a six-year default for UK immigration files, not the AML rule, but the design carries over: the clock starts from a recorded closing event, not from the date a document was uploaded.

Onboarding creates most of the records that regulation 40 governs, so the client onboarding checklist for UK accountants is the place to fix what is collected. Where a practice uses AI to read identity documents or draft a risk rating, a person signs off the result; our guide to AI for accountants in the UK sets out those review steps. We build this kind of client file into software for accounting practices.

Frequently asked questions

What is the AML record retention period in the UK?

Five years from the date the firm knows, or has reasonable grounds to believe, that the business relationship has ended, or that an occasional transaction is complete (Money Laundering Regulations 2017, regulation 40(3)).

Must AML records be deleted after five years?

Yes. Personal data obtained for the purposes of the Regulations must be deleted unless another enactment or court proceedings require it, the data subject has consented, or the firm has reasonable grounds to believe it is needed for legal proceedings (regulation 40(5)).

Does the 10-year limit apply to all AML records?

No. Regulation 40(4) applies only to records of a transaction that occurs as part of a business relationship. A firm is not required to keep those for more than 10 years.

What is the occasional transaction threshold for accountants?

£12,000 or more, in a single operation or several that appear linked (regulation 27(2)). A separate £800 threshold applies to an occasional transfer of funds (regulation 27(1)(b)). Both replaced euro figures on 30 June 2026.

When will the FCA supervise accountants for AML?

The FCA says it does not expect to begin until autumn 2028, with a phased transition likely to complete around 2030. The move relies on the Government passing new legislation, and the FCA says nothing changes immediately.

Sources

  1. Money Laundering Regulations 2017, regulation 40 (record-keeping)
  2. Money Laundering Regulations 2017, regulation 27 (customer due diligence)
  3. Money Laundering Regulations 2017, regulation 28 (customer due diligence measures)
  4. Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621), regulation 14
  5. Money Laundering Regulations 2017, regulation 3 (interpretation: occasional transaction)
  6. Money Laundering Regulations 2017, regulation 4 (meaning of business relationship)
  7. Money Laundering Regulations 2017, regulation 7 (supervisory authorities)
  8. Money Laundering Regulations 2017, regulation 8 (application)
  9. Money Laundering Regulations 2017, regulation 11 (auditors and others)
  10. Money Laundering Regulations 2017, regulation 12 (trust or company service providers)
  11. Money Laundering Regulations 2017, regulation 18 (risk assessment by relevant persons)
  12. Money Laundering Regulations 2017, regulation 24 (training)
  13. Money Laundering Regulations 2017, regulation 39 (reliance)
  14. Money Laundering Regulations 2017, regulation 76 (power to impose civil penalties: fines and statements)
  15. Money Laundering Regulations 2017, regulation 86 (criminal offence)
  16. Money Laundering Regulations 2017, Schedule 6 (meaning of relevant requirement)
  17. FCA, AML supervisory reform (published 22 September 2026)

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.