An AML customer risk assessment methodology explains how an organisation turns customer and relationship information into a controlled risk classification. It defines which factors matter, how data is interpreted, whether scores or rules are used, what each category changes, who may exercise judgement, when the assessment must be reopened and what evidence must remain available.
The difficult part is not selecting a neat set of points. It is creating a method that reflects the organisation's actual money-laundering and terrorist-financing exposure, applicable requirements and operating model. FATF provides an international risk-based baseline across customer, geography, product or service, transaction and delivery-channel factors, but it does not prescribe one customer-scoring formula.1 UK industry guidance says the relative weight of factors can vary between firms, products and customers, while FinCEN says a formal risk rating or category is not categorically required under the US Customer Due Diligence Rule.23
The practical objective is therefore:
Relevant information → controlled factor treatment → mandatory escalation where applicable → score or rule result → risk band → authorised review and treatment → retained evidence → reassessment when facts change.
What an AML customer risk assessment is
An AML customer risk assessment is a structured assessment of the money-laundering and terrorist-financing risk presented by an individual customer, prospective customer or business relationship. AUSTRAC describes customer risk rating as a case-by-case exercise and distinguishes it from the broader assessment of the reporting entity's own ML/TF risks. FINTRAC similarly distinguishes business-based risk assessment from relationship-based risk assessment.45
The terms around the assessment should be defined precisely in policy:
| Term | Working meaning | Important boundary |
|---|---|---|
| Assessment | The process of evaluating relevant information about a customer or relationship. | It is broader than a mathematical calculation. |
| Methodology | The approved framework of scope, factors, data definitions, rules, weights, thresholds, review and governance. | It is owned by the organisation, not supplied universally by a regulator or vendor. |
| Risk score | A numerical or rule-derived representation produced by the methodology, if one is used. | It is not a legal finding or final relationship decision. |
| Risk band or category | A classification mapped from scores, rules and judgement, such as lower, standard or higher risk. | Its names and boundaries are organisation-specific unless applicable rules say otherwise. |
| Reviewer decision | An authorised conclusion after considering the calculated result, evidence, requirements and permitted judgement. | Human review should not silently erase the original result. |
This vocabulary prevents false precision. A customer can have a system score, a system-derived band and a final reviewed classification. Those values may be related, but they are not interchangeable.
Customer risk assessment versus business-wide risk assessment
A business-wide or enterprise-wide AML risk assessment asks: what ML/TF risks does the organisation face through its customers, geographies, products, services, transactions and delivery channels? A customer risk assessment asks: what risk does this particular customer or relationship present within that environment?
| Business-wide assessment | Customer or relationship assessment |
|---|---|
| Evaluates exposure across the organisation or relevant business. | Evaluates one customer, prospective customer or relationship. |
| Helps design policies, controls, risk appetite and customer methodology. | Helps determine proportionate CDD, EDD, monitoring, review and approval treatment. |
| Uses portfolio, product, market, channel and threat information. | Uses customer-specific and relationship-specific information. |
| Changes when the business, products, threat environment or rules materially change. | Changes when customer facts, activity, products, ownership or other relevant signals change. |
UK Regulation 18 is a binding UK rule for relevant persons and addresses the risks to the business. Regulation 28 separately makes the extent of CDD in a particular case risk-sensitive.67 The FCA's UK supervisory findings show how firms can connect business-wide and customer-risk assessments without confusing them.8
The business-wide assessment should inform the customer methodology. It should not be copied mechanically. For example, a product identified as higher exposure at portfolio level may justify customer-level questions or stronger factor treatment, but the methodology still needs to reflect which product the customer actually uses and the controls that apply.
Keep CRA distinct from KYC, CDD, EDD, screening and monitoring
These controls exchange information, but each answers a different question.
| Control | Question answered | Typical output |
|---|---|---|
| KYC or KYB | Who is the person or entity, who owns or controls it, and what evidence supports that understanding? | Identity, entity, ownership, control and authority information. |
| CDD | What must the organisation understand, verify and scrutinise for this relationship? | A risk-sensitive due-diligence record. |
| Customer risk assessment | What ML/TF risk does the customer or relationship present under the approved methodology? | Factors, rule or score result, risk band and rationale. |
| EDD | What additional measures are required or appropriate for prescribed or higher-risk circumstances? | Additional information, verification, approval or scrutiny. |
| Screening | Does supplied party or context information produce a possible sanctions, PEP, watchlist or adverse-media finding? | No match, potential match, false positive, confirmed or unresolved result. |
| Behavioural transaction monitoring | Is actual activity unusual or inconsistent with the organisation's understanding of the customer? | Alert, investigation, disposition and possible escalation. |
| Relationship decision | Should the relationship be established, continued, restricted, escalated, declined or exited? | An authorised legal, compliance and risk-appetite decision. |
For the wider lifecycle, see KYC, KYB and customer due diligence and how CDD and EDD differ. For the activity-control boundary, see transaction screening versus transaction monitoring.
Define the methodology before selecting a score
Start with the decisions the methodology must support, not with points. Document:
- Legal and policy perimeter: which entities, sectors, jurisdictions, customer populations and products are in scope.
- Risk universe: which customer, geography, product, service, transaction and channel exposures are material to the business.
- Downstream treatment: what changes when a customer moves between categories, including CDD, EDD, monitoring, approval and review.
- Data and evidence: which sources support each factor and how missing, stale or contradictory information is represented.
- Decision architecture: whether the method uses qualitative categories, numerical scores, rules or a hybrid.
- Governance: who owns, approves, operates, overrides, tests and changes the methodology.
FATF is an international standard that jurisdictions implement. The EBA ML/TF Risk Factors Guidelines are EU supervisory guidelines for institutions within their scope, not law applying identically to every business. FCA findings are UK supervisory observations, not a universal scoring mandate. JMLSG is UK financial-sector industry guidance, not law. The cited August 2025 text predates UK amendments effective 30 June 2026, so users should check JMLSG's current guidance before relying on it.1982
Likewise, Regulation (EU) 2024/1624 is binding EU legislation, but its general application is principally from 10 July 2027. It must not be treated as a current EU-wide duty in 2026.10
Choose relevant customer-risk factors
Common official frameworks support broad factor categories, but relevance and treatment depend on the organisation and relationship. A factor belongs in the methodology because it helps assess the organisation's ML/TF exposure—not merely because it appears on a generic template.
| Factor category | Questions the methodology may need to answer | Design caution |
|---|---|---|
| Customer type and activity | What is the legal form, occupation, sector or business activity? Does it make sense for the relationship? | Do not declare an entire customer type high risk without context. |
| Ownership and control | Who ultimately owns or controls the entity? Is the structure proportionate and commercially intelligible? | Complexity is a risk indicator, not proof of wrongdoing. Use supplied UBO and related-party context with source provenance. |
| Products and services | Which services will this customer actually use, and what relevant exposure do they create? | Do not score the customer for every product the organisation offers. |
| Delivery channel and intermediaries | Is the relationship direct, remote, agent-led or introduced? What controls operate in that channel? | Remote delivery is not automatically high risk in every context. |
| Geography | Which countries matter through residence, incorporation, operations, beneficial owners, funds or counterparties? | Avoid one undifferentiated country field that hides why the location is relevant. |
| Purpose and intended nature | Why does the relationship exist, and is its proposed use economically or commercially coherent? | A completed form field is not the same as a plausible explanation. |
| Expected activity | What products, volumes, corridors, counterparties or funding routes are relevant and reasonably expected? | FinCEN does not categorically require expected-activity information for every covered US customer.3 |
| Actual behaviour and change | Does later activity remain consistent with the known profile? Has the customer materially changed? | This is a reassessment input; it does not turn CRA into the behavioural monitoring engine. |
| PEP exposure | Has a potential match been resolved, and what PEP measures apply in the relevant jurisdiction? | Confirmed PEP status is not a universal rejection rule. |
| Sanctions exposure | Is there a potential or confirmed legal restriction involving the customer, owners or controllers? | A sanctions prohibition must not be reduced to points that safer factors can offset. |
| Adverse information | Is the information attributable, credible, relevant, serious and current enough to affect ML/TF risk? | An adverse-media indicator is not guilt or an automatic high-risk verdict. |
| Source of funds or wealth | Is further understanding or corroboration required for the relationship or trigger? | Neither should be presented as a universal onboarding requirement for every customer. |
| Missing or conflicting information | Is a required fact absent, inconsistent, stale or unresolved? | Never silently translate missing information into zero or low risk. |
FATF supports customer, country or geography, product, service, transaction and delivery-channel considerations and provides illustrative—not universally mandatory—risk examples.1 AUSTRAC's official Australian guidance and FINTRAC's official Canadian guidance both tell relevant entities to develop methods appropriate to their own circumstances.45
Use a methodology register, not a generic point sheet
The following structure makes factor design reviewable without pretending the entries are universal:
| Factor | Source data | Inherent-risk treatment | Recognised mitigating control | Scoring or rule logic | Escalation trigger | Accountable owner | Evidence | Review trigger |
|---|---|---|---|---|---|---|---|---|
| Ownership complexity | Supplied ownership chain, control information and corroborating sources | Define which structural features materially change exposure | Credit only controls whose relevance and effectiveness are defined | Categorical, ordinal or rule-based treatment approved for the customer population | Required ownership/control fact cannot be established | Methodology owner and CDD owner | Source, retrieval date, structure, limitation and rationale | Ownership or control changes |
| PEP information | Resolved screening result and supporting source | Apply the relevant PEP risk analysis | Recognise prescribed or policy controls only as the methodology defines | Keep applicable PEP obligations visible rather than hiding them in aggregate points | Confirmed status engages applicable approval or EDD requirements | PEP policy owner | Original alert, resolution, status, rationale and approval | New role, changed status or new related-party information |
| Expected activity | Customer information and relationship context | Assess exposure relevant to the product | Recognise controls only where the architecture is explicit | Compare categorical ranges or defined states; avoid false precision | Information is implausible, materially incomplete or inconsistent | Product and CDD owners | Values, source, validation and reviewer note | Material activity, product or geographic change |
The rows are examples of structure, not prescribed scoring. A methodology should explain why each factor exists, who owns its data and what action follows from it.
Decide whether to model inherent and residual risk
Inherent customer risk can mean exposure before the methodology credits defined mitigating controls. Residual customer risk can mean the remaining exposure after those controls are recognised. FCA findings discuss inherent risk, control effectiveness and residual risk in financial-crime frameworks, but the reviewed sources do not establish one globally required individual-customer formula.8
Two architectures can be defensible:
- Direct classification: relevant factors lead to a customer category, and that category determines control intensity.
- Inherent-to-residual: factors establish inherent customer risk, defined controls are evaluated, and the method calculates or determines residual risk.
If the second architecture is used, name the controls that may reduce a factor, explain how effectiveness is assessed and prevent double counting. Ordinary completion of CDD should not automatically lower every customer's inherent risk. The methodology must make clear whether a control changes the classification, manages the classified risk, or both.
Select scoring, weighting and threshold mechanics
A practical method can use:
- qualitative categories for contextual factors;
- ordinal states, such as 1–3, where ordering is meaningful;
- quantitative scores where data and rules support consistent calculation;
- weighted factor groups where relative importance is documented;
- binary rules for conditions that should produce a defined treatment;
- a hybrid of rules, scoring and authorised judgement.
The design order should be:
Policy universe → factors → data definitions → factor states → mandatory triggers → weighting → aggregation → thresholds → review rules → override authority → evidence → testing.
Do not begin with “how many points should a PEP receive?” JMLSG's UK industry guidance expressly recognises that weights may vary by firm, product and customer.2 FinCEN's official US FAQ goes further: for covered institutions under its CDD Rule, a customer risk profile may include a formal rating or category, but it does not have to.3
Keep hard triggers outside weighted arithmetic
Some circumstances require separate legal analysis or a prescribed control response. Where applicable, a sanctions prohibition, required EDD circumstance, PEP approval requirement, inability to complete required CDD or organisation-defined prohibited condition should not be averaged away by unrelated lower-risk factors.
That does not mean every risk indicator is a hard stop. The methodology should distinguish:
- legal trigger: action required under an applicable rule;
- policy trigger: action required by the organisation's approved risk appetite or control standard;
- risk indicator: information that changes the assessment but requires context;
- workflow trigger: an event that sends the case to a reviewer without deciding the outcome.
Set thresholds by treatment
For each boundary, ask what changes when it is crossed. A band is useful only if it leads to a defined level of due diligence, approval, monitoring or review. Test whether the highest category can actually be reached, whether one factor dominates intentionally, and whether thresholds were chosen to describe risk rather than to reduce operational workload.
Represent data states explicitly: known, not applicable, missing, conflicting, unresolved, and verified where relevant. Blank must not mean low risk. Material contradictions should preserve both values and their provenance until resolved.
Connect screening without treating alerts as verdicts
A screening result can change the information available to the customer risk assessment, but the alert itself is not the customer's final risk category.
| Screening state | Appropriate CRA treatment | It should not mean automatically |
|---|---|---|
| No match returned | Record that the configured check found no candidate at that time. | The customer is low risk or CDD is complete. |
| Potential match | Resolve identity, source and relevance under the screening process. | Confirmed status, rejection or high-risk classification. |
| False positive | Preserve the resolution and exclude the unrelated source record from adverse treatment. | A continuing negative factor simply because an alert existed. |
| Confirmed PEP | Apply the relevant PEP measures and assess the effect on customer risk. | Automatic refusal or exit. |
| Potential sanctions match | Conduct identity, ownership/control and legal-context analysis promptly. | A final sanctions conclusion. |
| Confirmed sanctions exposure | Apply the separate legal obligations and restrictions that govern the case. | Ordinary extra points that can be offset in an aggregate score. |
| Adverse-media indicator | Assess identity, source credibility, relevance, seriousness and recency. | Guilt, suspicion, rejection or automatic high risk. |
| Unresolved result | Show the uncertainty and route it for resolution or authorised action. | Silent clearance. |
FinCEN's official US FAQ says its CDD Rule does not categorically require media searches on every customer or related party.3 FATF PEP standards establish additional measures in relevant cases, while domestic implementation determines enforceable detail.1 For focused workflows, see PEP screening and enhanced due diligence and sanctions ownership and control.
Connect the risk category to CDD, EDD and monitoring
The correct operating flow is not score → automatic rejection. A defensible flow is:
Customer information and factors → assessed risk → CDD, EDD, monitoring and approval treatment → qualified review → relationship decision.
FATF expects enhanced measures for higher-risk situations and permits simplified measures where lower risk has been appropriately established. UK Regulations 28 and 33 contain binding UK risk-sensitive CDD and specified EDD provisions for entities within scope.1711
High customer risk is not universally synonymous with exit. The applicable rules, ability to manage the risk, completion of required measures and approved risk appetite determine whether the organisation establishes, continues, restricts, declines or exits the relationship. AUSTRAC's official Australian EDD guidance expressly contemplates continuing a higher-risk relationship where the risk can be appropriately managed under that framework.12
Customer risk can inform behavioural monitoring segmentation, alert prioritisation or investigation depth where the organisation's design supports it. Monitoring findings can in turn trigger reassessment when they change the known customer context. The controls remain distinct: CRA classifies customer risk; behavioural transaction monitoring assesses activity. Checklynx configured ongoing re-screening should not be described as an autonomous behavioural transaction-monitoring engine.
Define reassessment triggers
Avoid a universal statement that every customer must be reassessed annually. FATF uses risk and materiality concepts, while AUSTRAC and FINTRAC connect ongoing information and activity changes to customer-risk review.145
| Trigger | Why reopen the assessment | Expected control response |
|---|---|---|
| Onboarding or relationship creation | Establish the initial classification from reasonably available information. | Complete the initial assessment and required review. |
| Scheduled risk-based review | Confirm the data and classification remain appropriate. | Apply the frequency required by applicable rules and internal policy. |
| Ownership or control change | The parties and exposure behind an entity may have changed. | Re-establish relevant ownership/control information and risk. |
| Business activity or purpose change | The original relationship rationale may no longer be accurate. | Update factors and expected activity. |
| New product, service or delivery channel | The customer is exposed to a different risk environment. | Assess the new product or channel before or when enabled. |
| Material geographic change | Residence, operations, counterparties or funds corridors have changed. | Recalculate the relevant geographic factors. |
| New PEP, sanctions or relevant adverse information | A new or changed external signal may affect requirements or risk. | Resolve the signal first and apply any separate urgent legal process. |
| Unusual activity or monitoring finding | Actual behaviour may conflict with the known profile. | Feed the investigation's relevant established facts into CRA. |
| Material source-of-funds or wealth concern | Financial context may require stronger understanding or EDD. | Obtain and assess proportionate evidence where applicable. |
| Missing, stale or contradictory information | The current category may no longer have an adequate basis. | Mark the limitation and resolve or escalate it. |
| Regulatory, policy or business change | Factor definitions or required treatments may have changed. | Identify the affected population and decide recalculation or remediation. |
| Methodology version change | Revised logic may materially change classifications. | Define migration, comparison and approval before release. |
From 10 July 2027, AMLR Article 26 will generally combine event-driven updates with maximum intervals of one year for customers subject to higher-risk measures and five years for other customers. These are future EU rules, not current 2026 or global duties.10
Govern reviewer decisions, overrides and exceptions
Define these separately:
- A reviewer decision is the authorised disposition reached after applying the methodology to the evidence.
- An override changes a system-derived score or band.
- An exception is an authorised departure from the normal method or process, often for a limited condition or period.
These are operating-model terms, not universally standardised AML statutory definitions. FCA supervisory findings support documented methodology, approvals, change control, rationale, management information and review or testing. JMLSG industry guidance also emphasises documentation of risk assessments and case rationale.82
A controlled override record should retain:
| Control | Evidence to retain |
|---|---|
| Original result | Factor values, raw score if used and system-derived band. |
| Final result | Reviewed classification and resulting treatment. |
| Rationale | Specific reason linked to the evidence and policy provision. |
| Authority | Reviewer, role, permission and any required approver. |
| Timing | Decision time, effective time and expiry or reassessment condition. |
| Direction | Whether risk moved upward or downward. |
| Quality review | Later QA, testing outcome and remediation where needed. |
Downward overrides deserve particularly clear challenge because they reduce the treatment produced by the methodology. Four-eyes approval can be a defensible internal control for material overrides or exceptions, but it should not be called universally mandatory unless an applicable rule requires it.
Retain a reconstructable customer-risk record
Another qualified reviewer should be able to reconstruct:
What was known → which methodology applied → which factors and rules ran → what result was produced → what judgement changed → why and by whom → what treatment followed → what changed later.
Retain, as applicable:
- customer and assessment identifiers and effective timestamps;
- source data, provenance, retrieval date and known limitations;
- methodology profile and version;
- factor definitions, values and states;
- rules, weights and thresholds then in force;
- raw score and system-derived band, if used;
- screening alert and resolved status, not only the final label;
- supplied UBO and related-party context used in the assessment;
- missing, conflicting or unresolved information;
- reviewer notes, override or exception rationale and approvals;
- final category, treatment and reassessment trigger;
- prior and new assessment versions.
Record-retention duration is jurisdiction-specific. FATF Recommendation 11 provides an international five-year baseline for specified records, and UK Regulation 40 contains UK requirements within its scope; neither creates one universal global CRA retention period.113
Test and change the methodology
Testing should be proportionate to complexity. A rules-based three-band method still requires assurance, but it is not automatically a statistically estimated model requiring bank-style quantitative validation.
Test:
- whether each factor remains relevant to the business risk;
- data completeness, accuracy, timeliness and source mapping;
- null, boundary and conflicting-value behaviour;
- whether factor logic implements the approved policy;
- whether weights can be explained and produce intended influence;
- population distribution and cases around each threshold;
- samples from every band, including known higher-risk and borderline cases;
- false-high and false-low outcomes;
- repeated overrides that may reveal poor calibration;
- screening-state mapping and reassessment-trigger operation;
- historical or current populations before material methodology changes;
- old-to-new version comparison, migration and remediation;
- independent challenge appropriate to the organisation's size and complexity.
FCA's UK supervisory findings identify stronger practices around methodology documentation, regular review, testing following automation or enhancements, controlled change and useful management information.8 These findings are valuable supervisory evidence, not a global statistical-validation rule.
Use management information to challenge outcomes
Management information should help owners decide whether the method is plausible and operating as intended. Useful measures can include:
| Metric | Governance question |
|---|---|
| Customers by risk band and movement between bands | Does the distribution reflect the risk universe, and what caused material change? |
| New and former high-risk customers | Are upward and downward movements supported by evidence? |
| Missing or invalid factor data | Is data quality undermining classification? |
| Overdue reviews and unresolved states | Does the operating model have enough capacity and clear ownership? |
| Overrides by direction, reason, reviewer and team | Are reviewers repeatedly correcting the same rule or threshold? |
| Exceptions and ageing | Are temporary workarounds becoming permanent? |
| Screening- and monitoring-triggered reassessments | Are material lifecycle signals reaching CRA? |
| Methodology version distribution | Has approved migration completed? |
| Pre- and post-change classification | Did a release create unintended reclassification? |
| Sampled false-high and false-low findings | Is calibration credible across customer populations? |
An unusually small high-risk population, concentrated downward overrides or a sudden version-driven migration is a reason to investigate. It is not automatically evidence of breach.
AML customer risk methodology implementation checklist
How Checklynx supports the operating model
Checklynx can help teams configure, operate, review and evidence their approved customer-risk methodology. Checklynx Customer Risk Assessment supports configurable factors, weights, thresholds and risk bands, together with retained assessment evidence and snapshots of the methodology version, inputs, score, band, notes and review history.
Connect customer, company, UBO and related-party context to screening, case review, audit evidence and integrations. Configured re-screening can return new sanctions, PEP, adverse-media and watchlist signals for review and reassessment.
Your organisation retains control of the methodology, legal interpretation and final relationship decision.
CONTROLLED CUSTOMER RISK ASSESSMENT
Configure and evidence your customer-risk methodology in Checklynx
Apply your organisation's factors, weights, thresholds and risk bands, connect screening and reviewer evidence, and retain the history behind customer-risk decisions.
Frequently asked questions
Do regulators require an AML customer risk score?
No universal rule requires a numerical score. FinCEN also says a formal rating or category is not categorically required under the US CDD Rule; apply the regime relevant to your organisation.3
Does a PEP automatically make a customer high risk or require rejection?
No. Resolve the match, then apply the PEP measures and risk analysis required by the relevant regime; PEP status is not a universal rejection rule.
Does a sanctions alert automatically make a customer high risk?
No. Resolve the alert first. Confirmed exposure may create separate legal obligations or restrictions that must not be diluted within an ordinary weighted score.
How often should customer risk be reassessed?
Follow applicable law and risk-based policy, and reopen the assessment when material facts change. There is no universal annual rule.
Can a high-risk customer still be onboarded or retained?
Potentially, if law permits, required measures are completed, the risk can be managed and approved risk appetite allows it.
Can software make the final customer-risk decision?
Software can calculate, route and preserve evidence. The organisation remains responsible for the methodology, legal obligations and final relationship decision.
Closing perspective
The strongest CRA methodology is not the most mathematical. It is the one your team can explain, govern, reproduce and update when customer facts change.
Official sources
Footnotes
-
FATF, The FATF Recommendations, international standards amended June 2026. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Joint Money Laundering Steering Group, Prevention of money laundering/combating terrorist financing: Guidance for the UK Financial Sector, Part I, UK financial-sector industry guidance, not law; August 2025 version. ↩ ↩2 ↩3 ↩4
-
FinCEN, Customer Due Diligence Rule FAQs, official US regulatory guidance for covered financial institutions, updated 6 May 2026. ↩ ↩2 ↩3 ↩4 ↩5
-
AUSTRAC, Assigning customer risk ratings, official Australian regulatory guidance, updated 27 March 2026; the page notes limits for more complex reporting entities. ↩ ↩2 ↩3
-
FINTRAC, Risk assessment guidance, official Canadian regulatory guidance for reporting entities within scope. ↩ ↩2 ↩3
-
UK legislation, Money Laundering Regulations 2017, Regulation 18, binding UK business-risk-assessment requirements for relevant persons within scope. ↩
-
UK legislation, Money Laundering Regulations 2017, Regulation 28, binding UK CDD requirements for relevant persons within scope. ↩ ↩2
-
Financial Conduct Authority, Risk assessment processes and controls in firms: our findings, UK supervisory good and poor practice, 11 November 2025. ↩ ↩2 ↩3 ↩4 ↩5
-
European Banking Authority, Guidelines on ML/TF risk factors, EBA/GL/2021/02, consolidated version, EU supervisory guidelines for institutions within scope. ↩
-
EUR-Lex, Regulation (EU) 2024/1624, EU legislation generally applicable principally from 10 July 2027, not a current 2026 EU-wide duty. ↩ ↩2
-
UK legislation, Money Laundering Regulations 2017, Regulation 33, binding UK EDD and enhanced-monitoring requirements within scope. ↩
-
AUSTRAC, Enhanced customer due diligence, official Australian regulatory guidance, updated 15 July 2026. ↩
-
UK legislation, Money Laundering Regulations 2017, Regulation 40, binding UK record-keeping requirements within scope. ↩