Financial crime consultancy covers anti-money laundering, fraud prevention, sanctions and tax evasion facilitation. Two offences have changed what firms actually need: failure to prevent fraud, in force since 1 September 2025 for large organisations, and the corporate criminal offences for failing to prevent facilitation of tax evasion, which have applied since 2017 and apply to organisations of every size.
The money laundering baseline
The Money Laundering Regulations 2017 set the framework, and five obligations carry most of the weight:
- Regulation 18 — risk assessment. Take appropriate steps to identify and assess the risks the business is subject to, taking account of supervisory information and the risk factors relating to customers, geography, products, transactions and delivery channels. Keep an up-to-date written record of all the steps taken, and provide it to the supervisor on request;
- Regulation 19 — policies, controls and procedures to mitigate and manage those risks, approved by senior management, proportionate to the size and nature of the business, kept under review and recorded in writing, including revisions and how they were communicated;
- Regulation 28 — customer due diligence. Identify and verify the customer from reliable independent sources, identify beneficial owners and take reasonable measures to verify them, understand the ownership and control structure, and obtain information on the purpose and intended nature of the relationship. Extent of measures reflects the risk assessment, with ongoing monitoring throughout;
- Regulation 33 — enhanced due diligence, triggered by high-risk cases, business in a FATF call-for-action country, correspondent relationships, politically exposed persons and their family members and close associates, false or stolen identification documents, and transactions that are unusually complex or large, follow an unusual pattern, or have no apparent economic or legal purpose;
- Regulation 40 — record keeping. Five years from completion of the transaction or the end of the relationship, with records relating to transactions within a relationship not kept more than ten years, and personal data deleted at the end of the period subject to stated exceptions.
Regulation 18 is the one most often done badly, and everything else depends on it. A firm-wide risk assessment that could belong to any firm of the same type will not support the controls built on top of it, and it is the first document a supervisor asks for.
Governance and the MLRO
For FCA-regulated firms, SYSC 6.3 requires systems and controls that enable the firm to identify, assess, monitor and manage money laundering risk, comprehensive and proportionate to the nature, scale and complexity of its activities, with a regular assessment of their adequacy.
Two appointments follow. SYSC 6.3.8R requires overall responsibility for effective AML systems and controls to be allocated to a director or senior manager — who may also be the MLRO. SYSC 6.3.9R requires the appointment of an MLRO with responsibility for oversight of compliance, and requires the firm to ensure they have sufficient authority, independence, resources and access to information.
Under the senior managers regime, SMF17 is the money laundering reporting function and SMF16 compliance oversight, both designated as senior management functions.
Separately, the Money Laundering Regulations' own regulation 21 requires a nominated officer, and the suspicious activity reporting obligations attach to that role.
The annual financial crime return
SUP 16.23 requires an Annual Financial Crime Report from firms subject to the Money Laundering Regulations and falling into one of three categories:
- Category A — UK banks, building societies, non-UK banks, mortgage lenders and administrators, and life and annuity insurers;
- Category B — firms with certain investment permissions that held client money or safe custody assets during the financial year;
- Category C — firms with total revenue of £5 million or more at the last accounting reference date holding permissions including advising on investments, arranging deals in investments, or a credit-related regulated activity.
Excluded are credit unions, operators of peer-to-peer platforms, authorised professional firms and firms with only limited permission. The return is annual and due within 60 business days of the accounting reference date. The Handbook calls it the Annual Financial Crime Report; the industry shorthand is REP-CRIM.
Failure to prevent fraud
This is the newest exposure and the one most large organisations are still building for. Section 199 of the Economic Crime and Corporate Transparency Act 2023 creates an offence where a person associated with a relevant body commits a fraud offence intending to benefit the body, or a person to whom the associate provides services on the body's behalf. It came into force on 1 September 2025.
It applies to large organisations, defined in section 201 as satisfying two or more of: turnover more than £36 million; balance sheet total more than £18 million; more than 250 employees, in the financial year preceding the fraud.
The defence in section 199(4) is that the body had in place such prevention procedures as it was reasonable in all the circumstances to expect, or that it was not reasonable to expect any. "Associated" is broad — employees, agents, subsidiary undertakings, and anyone otherwise performing services for or on behalf of the body.
The in-scope fraud offences in Schedule 13 include cheating the public revenue, false accounting, false statements by company directors, fraudulent trading under the Companies Act, and the Fraud Act 2006 offences. Penalty is a fine, unlimited on indictment.
Note the direction of the offence. It catches fraud committed for the organisation's benefit, not fraud against it — so the risk sits in sales, procurement, reporting and tax, not in the places most anti-fraud programmes were built to look. Our guide to the corporate criminal offences covers the tax equivalent.
Facilitation of tax evasion
Part 3 of the Criminal Finances Act 2017 has been in force since 30 September 2017 and is still under-addressed. Section 45 creates the UK tax evasion facilitation offence and section 46 the foreign equivalent, applying where the body is UK-incorporated, carries on business in the UK, or the relevant conduct occurs here.
A "relevant body" is any body corporate or partnership wherever incorporated or formed — there is no size threshold, which is the key difference from the failure to prevent fraud offence. The defence is the same reasonable prevention procedures formulation, and penalties include an unlimited fine on indictment.
What to buy, and what to look for
The useful engagements are narrow and specific. A firm-wide risk assessment that reflects your actual customer base and products rather than a template. A gap analysis against the two failure-to-prevent offences, because the defence is procedural and has to exist before an incident rather than after. Testing of CDD files against the regulation 28 and 33 requirements, which is where supervisory criticism concentrates. And the Annual Financial Crime Report where you are in scope.
What to be sceptical of: a provider quoting a fixed set of "principles" for reasonable prevention procedures as though they were statutory. The defence turns on what is reasonable in your circumstances, and a generic framework applied without reference to your risk assessment is the thing most likely to fail when tested.
Acumon supports firms on financial crime through AML audit, anti-fraud and internal audit work, with forensic accounting where an incident has already happened. If your organisation is above two of the three section 201 thresholds and has no documented fraud prevention procedures, that is the gap that matters most.