HMRC’s New AML Manual: What It Means for CDD, Source of Wealth and Adverse Media Monitoring

HMRC has, for the first time, brought its scattered AML sector guidance into a single manual. It sets out the clearest recent statement of what a UK supervisor expects across the whole due diligence pipeline, from identity verification through to the ongoing monitoring that adverse media screening exists to support.

A new manual, and a clearer baseline across the whole pipeline

On 8 July 2026, HMRC published a new internal manual, “Anti-money laundering guidance for supervised businesses,” with a further update following on 16 July. It’s the first time HMRC has brought its previously scattered sector guidance into a single document, and it reflects changes introduced by the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621), in force since 30 June 2026.

It’s worth reading in full rather than skipping to the source of wealth section. Part 1, general guidance for all sectors, sets out HMRC’s clearest recent statement of what it expects across the whole due diligence pipeline: how to establish who a customer is, when to go further, what evidence a source of wealth or source of funds judgement needs, and what ongoing scrutiny, including the kind adverse media screening exists to support, should look like once the relationship is live.

Who this manual actually covers

Worth being precise about scope before going further. HMRC’s manual governs the businesses it directly supervises for AML purposes: money service businesses, trust or company service providers, art market participants, high value dealers, estate and letting agents, and bill payment or telecoms payment providers. Banks and wealth managers are FCA-regulated and sit outside this manual’s direct remit.

That doesn’t make it irrelevant to bank and wealth manager compliance teams. It’s a rare piece of primary-source UK regulatory drafting that spells out, in plain terms, what a supervisor expects a due diligence file to contain and how it expects that file to be reasoned through, useful as a benchmark whatever your own supervisor happens to be, and directly relevant if your due diligence ever touches a TCSP or other HMRC-supervised counterparty.

Customer due diligence: the baseline HMRC expects

Part 1 opens with CDD in fairly unambiguous terms. HMRC frames it as the collective set of checks a business runs on a customer and, where applicable, a beneficial owner, what most of the industry still calls KYC, with the depth of those checks scaled to the risk presented by the customer, product, or transaction. Standard due diligence applies by default; simplified due diligence is available in genuinely lower-risk situations; enhanced due diligence is mandatory in higher-risk ones.

Three points in this section carry more operational weight than they might first appear to:

  • Identity must be verified before a business relationship or transaction is established. HMRC allows a narrow exception, beginning to set up a relationship before verification so as not to interrupt normal business, but only where the money laundering risk is genuinely low.
  • If CDD can’t be completed, HMRC’s position is unequivocal: the business relationship or transaction must not go ahead.
  • CDD is not a one-off exercise. HMRC expects it to be revisited whenever a customer’s circumstances change materially, which may mean stepping up from standard to enhanced due diligence for a relationship that was onboarded at a lower risk grade.

Firms also need to be able to demonstrate to HMRC, not simply assert, that the extent of CDD applied was appropriate to the risk. That evidentiary framing carries through everything else in the manual, including the sections on enhanced due diligence and source of wealth below.

Where the bar moves: enhanced due diligence

HMRC sets out three circumstances in which EDD is mandatory, not discretionary:

  • The relationship or transaction has been assessed as high risk, either in your own risk assessment, or based on information HMRC itself has provided, including this guidance.
  • Either party to the relationship or transaction is established in, or operating from, a FATF Call for Action country.
  • You discover a customer has provided false information or false or stolen identity documents, and you propose to continue dealing with them. HMRC adds a pointed aside here: regardless of whether you continue the relationship, this should be considered for a Suspicious Activity Report to the NCA.

Where EDD applies, HMRC expects more than a heavier version of standard CDD. The measures should include seeking additional independent, reliable sources to verify what the customer has told you; building a deeper understanding of their background, ownership and financial situation; and applying enhanced ongoing monitoring for the life of the relationship. That last element is where source of wealth verification and, further down, adverse media screening both sit.

Source of funds vs source of wealth, in HMRC’s own terms

Buried in this same Part 1 is a source of funds and source of wealth section that’s one of the more explicit statements a UK authority has put in writing about what “good” analysis actually looks like, and it keeps the two concepts distinct in a way that maps closely onto how the industry already separates them.

Source of Funds

The provenance of the specific funds involved in a transaction or business relationship. HMRC is explicit that this goes beyond identifying which account the money arrived from: it means understanding how and where the client obtained the money for that transaction, whether that’s employment savings, an inheritance, or something else.

Source of Wealth

The origin of a client’s entire body of wealth: the economic, business or commercial activity that generated their overall net worth, potentially built up from more than one source over time. The evidence base is broader by necessity: audited accounts, share registers, property portfolios, and crypto wallets all get an explicit mention as acceptable supporting documentation, alongside the bank statements collected for source of funds.

Source of FundsSource of Wealth
Question askedHow and from where did the client get the money for this specific transaction?Why and how does the client have the overall assets they have?
Typical evidenceBank statements showing regular/sufficient credits; evidence of gifted funds matching the stated amount; remitter details cross-checked against the clientAudited accounts, share registers, property portfolios, crypto wallets, plus the underlying source of funds evidence
Higher-risk responseDeeper investigation of gifted funds and employment evidenceWider corroboration across every material wealth-generating activity identified

The plausibility test, straight from a UK regulator

The most quotable line in the section isn’t really about documents at all. HMRC frames the core judgement as whether a client’s wealth is commensurate with what you’d expect of them: does it make sense that the person in front of you obtained their wealth the way they’ve described? That’s a narrative plausibility test, not a document checklist, and it’s a welcome piece of regulatory endorsement for an approach compliance teams have often had to justify without a clean primary-source reference to point to.

What HMRC Actually Says

Ongoing monitoring — and where adverse media screening fits

EDD’s requirement for “enhanced ongoing monitoring” connects directly to a wider duty that runs through the Money Laundering Regulations more broadly: monitoring a business relationship means scrutinising transactions against what you know about the customer, and keeping the CDD information you hold on them current for as long as the relationship lasts.

That duty is precisely the gap adverse media screening is built to close. Transaction monitoring is good at catching activity that looks wrong; it’s poorly suited to catching a customer who looks exactly as they did on day one but is now the subject of a fraud indictment, a sanctions designation, or a credible investigative report. A source of wealth narrative that was entirely plausible at onboarding can stop being plausible six months later for reasons that never touch the account. That’s why robust monitoring programmes for PEPs and other higher-risk relationships pair transaction scrutiny with periodic negative-news and watchlist rescreening. It’s the practical mechanism firms use to keep the picture of a customer’s risk current, which is exactly what the ongoing monitoring duty requires of them.

This section draws on the established ongoing monitoring obligation under the Money Laundering Regulations rather than a specific passage quoted from HMRC’s the manual.

Documentation as a defensibility test

The most operationally significant paragraph in the whole manual isn’t about what evidence to collect. It’s about what happens if you don’t collect it.

HMRC’s Warning, In Substance

That’s a defensibility standard, not just a documentation standard. It isn’t enough to hold the right paperwork on file, or the right screening hits on record. A firm needs to be able to reconstruct, after the fact, why a particular level of scrutiny was applied, why the evidence obtained was judged sufficient, and how that decision traced back to the risk assessment. Compliance teams that already document their reasoning across CDD, EDD, source of wealth and monitoring decisions, not just their checklists, are well placed here.

Benchmarking your own framework

Five questions worth putting to your own due diligence process in light of this guidance:

  • Can you evidence, for any customer, why the level of due diligence applied, simplified, standard or enhanced, was proportionate to the risk, and that it gets revisited when circumstances change?
  • Does your framework treat source of funds and source of wealth as genuinely separate evidential trails, or does one get waved through on the back of the other?
  • Is the plausibility rationale, why this wealth level makes sense for this client, written down, or does it only exist in an analyst’s head?
  • Is your ongoing monitoring pairing transaction scrutiny with periodic adverse media and watchlist rescreening, particularly for PEPs and other higher-risk relationships?
  • Could you hand a regulator your file today and show, in writing, why the due diligence applied, at onboarding and on an ongoing basis, was judged sufficient?

Where the answer to any of those is no, that’s the gap this guidance has just made more visible.

This is precisely the workflow smartKYC’s platform is built to support. Source of Wealth Verification structures source of wealth and source of funds evidence into a tiered, risk-linked audit trail, while smartEYE carries that same evidence-based discipline into ongoing adverse media and watchlist monitoring, so the rationale behind every CDD, EDD and monitoring decision is documented as it’s made rather than reconstructed under pressure later.

For a fuller walkthrough of building a defensible source of wealth framework, see smartKYC’s Source of Wealth guide. For the equivalent on ongoing screening, see smartKYC’s Adverse Media Screening guide.

Frequently Asked Questions

What is the difference between source of funds and source of wealth under HMRC’s guidance?

Source of funds is the origin of the specific money used in a transaction or relationship: how and from where the client obtained it. Source of wealth is broader: the origin of the client’s entire net worth, covering the economic or commercial activity that built it up over time.

When does HMRC require enhanced due diligence?

HMRC requires EDD in three circumstances: where a relationship or transaction is assessed as high risk, where either party is established in or operating from a FATF Call for Action country, and where a customer has provided false information or documents and the firm proposes to continue the relationship.

What does HMRC expect from ongoing monitoring, including adverse media screening?

HMRC’s guidance requires enhanced ongoing monitoring wherever EDD applies, sitting on top of the general duty to scrutinise transactions and keep customer due diligence information current throughout a relationship. Adverse media screening is the practical way most firms satisfy that duty for reputational and criminal risk that wouldn’t otherwise surface in transaction data, particularly for PEPs and other higher-risk customers.

Does HMRC’s new AML manual apply to banks and wealth managers?

Not directly. The manual governs businesses HMRC itself supervises, such as money service businesses, TCSPs, art market participants and high value dealers, not FCA-regulated firms. It’s relevant to banks and wealth managers as a clear statement of UK regulatory expectations on CDD, EDD and source of wealth, and directly relevant wherever due diligence touches an HMRC-supervised counterparty.

What evidence satisfies HMRC’s source of wealth requirements?

There’s no fixed list. HMRC points to audited accounts, share registers, property portfolios, crypto wallets and bank statements as examples, but frames the real test as whether the evidence collected supports a coherent, risk-appropriate rationale for how the client’s wealth was generated, not simply whether a set of documents has been filed.

What happens if a firm can’t evidence its due diligence for a higher-risk customer?

HMRC has said that where enhanced due diligence measures aren’t carried out, it expects a firm to provide an evidence-based explanation tied to its risk assessment. Without one, HMRC has indicated it will consider penalties and other sanctions.

See the full evidence trail, from onboarding to ongoing monitoring

Book a Demo

Share this