Ask most small firm owners about AML and you get a version of the same answer: it's real work, it takes real hours, and none of it goes on a client invoice.
Client onboarding checks. Risk assessments. Re-screening existing clients. Writing the policy, then reviewing the policy. Chasing a client for a document you've asked for twice. It sits in the same category as professional indemnity insurance renewal and practising certificates: necessary, non-negotiable, and none of it shows up on a bill.
That cost is about to go up. Not because your obligations are changing, but because who checks them is.
What's actually changing
AML supervision for accountancy firms is moving to the Financial Conduct Authority (FCA).
Today, your AML compliance is supervised either by your professional body (ICAEW, ACCA, CIOT, AAT and around 19 others) or by HMRC if you're not a member of a supervised body. That model is being retired. In its place, the FCA becomes what Treasury is calling the Single Professional Services Supervisor, covering accountancy, legal and company service providers.
This is locked in, not something still up for debate. HM Treasury confirmed the decision in October 2025, published its response on the FCA's powers in June 2026, and the legal changes needed are already going through Parliament, in the Financial Services and Markets Bill. There's not yet a fixed go-live date; the sector's working expectation is full implementation by 2029, with Treasury itself describing a multi-year transition rather than a single switchover. Until then, your existing supervisor keeps supervising you.
That gap isn't downtime. It's the window your compliance record is being written in, for reasons that have nothing to do with how fast you can write a policy.
Why "prove it" is the bit that matters
Your obligations under the Money Laundering Regulations 2017 aren't being rewritten. Treasury is extending the FCA's existing powers rather than adding new duties for firms, and the official line is that a firm already compliant shouldn't need to change its controls.
The supervisory culture is a different question.
The FCA supervises on a risk basis, and it will be taking on roughly 60,000 new firms. At that scale, supervision leans on data, documentation and evidence rather than relationship. The practical difference is between having a firm-wide risk assessment and being able to show when it was last reviewed, what changed, and who signed it off. Between having a training policy and producing the attendance records. Between saying your CDD is risk-based and demonstrating why this client got enhanced due diligence and that one didn't.
Firms that already work that way will find the transition uneventful. Firms whose compliance lives in a folder that gets tidied up before an inspection will find it less so. And Treasury's own supervision data shows which of the two is more common: among professional services firms assessed in 2024/25, only 24% of accountancy firms were fully compliant. That's the record that got this job handed to the FCA.
Why waiting is the expensive option
Most regulatory changes let you prepare in the run-up. This one doesn't, because of what the FCA will be looking at when it arrives.
You cannot backdate a history. For the first time, accountancy firms will face the FCA's fit-and-proper test, covering beneficial owners, officers and managers, and assessing integrity, competence and compliance history rather than just criminal records. Compliance history is a track record, not a snapshot. Whatever you can evidence in 2029 is whatever you actually recorded between now and then. A firm that starts keeping proper records six months before handover has a file that shows a start date, and a start date invites the obvious question about everything before it.
Today's files are already in scope. The Money Laundering Regulations require you to keep CDD records for five years after a business relationship ends. A client you onboard this month is a file a supervisor can pull in 2029 and after. You are already creating the evidence the FCA will assess. The only open question is whether it will stand up.
Nothing resets at handover. Existing regulatory investigations and enforcement actions transfer across to the FCA, and in the transition it will make use of your existing supervisor's checks where appropriate. There is no clean slate, no fresh start, no amnesty for the years before the switch. And registration on the FCA's new public register becomes the condition of doing in-scope work at all.
Your current supervisor hasn't gone anywhere. Enforcement under the existing regime is escalating, not winding down. Supervisors issued 338 fines totalling over £2 million in 2024/25, more than triple the 2022 total. The years before handover are not a grace period.
What an auditable trail actually means
The gap in most small firms isn't the work. It's that the work leaves no continuous trace. The checks got done and the risk decision was sound, but the evidence sits in fragments: an ID document in a client folder, an approval in someone's sent items, a risk rating in a spreadsheet nobody's opened since. Producing a complete picture for one client takes a day of archaeology. Across 200 clients, it can't be done.
An auditable trail is the opposite. For any client, on demand: what was checked, when, by whom, what the risk decision was, what evidence supported it, and when it was last revisited. For the firm: when the risk assessment was reviewed and who approved it. For your people: what training ran and who attended.
None of that is a new obligation. It's what a risk-based approach has always implied. The difference is that a supervisor with 60,000 firms and a data-led methodology will ask you to produce it, rather than take your word for it.
Where to start
Pick one client you onboarded in the last month and reconstruct the full trail from your records alone. How long it takes you is your answer.
The work doesn't get more billable. But the record you build from here is the one you'll be judged on, and it only accumulates in one direction.
Free AML Education
Complete your annual AML requirement with our in-app education.
Risk Assessments
Risk assessments help you decide how much due diligence to apply

AML Red Flags
Submitting a Suspicious Activity Report (SAR) is a legal obligation under UK AML laws.

AML Essentials
If AML feels overly complex, this guidance is designed to help you get to grips with the essentials

Try Firmcheck
for free
Start your compliance journey for free. Try Firmcheck's beautifully designed platform and see why firms trust us with their AML compliance.

