UK AML 2026: New Rules for Crypto, Effective June 30

Parliament approved 15 UK AML reforms on June 9. Most take effect June 30. Crypto firms face the deepest changes. Here's your compliance checklist.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·10 min read
Share
UK AML 2026: New Rules for Crypto, Effective June 30
imageUse this imagedownloadDownload

HM Treasury made the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 on June 9, 2026. Most provisions take effect on June 30 under the standard 21-day rule — twelve days from today. Cryptoasset exchange providers and custodian wallet providers absorb the deepest shifts in the package, and those provisions have drawn the least coverage in the industry press.

What changed, why the crypto pieces deserve priority, and what a compliance team must have ready before the deadline: that is the ground covered here.

What the 2026 Amendment Actually Does

Fifteen targeted amendments land in the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs). The package was calibrated to cut needless administrative friction and, at the same time, tighten substantive controls where regulators judge risk highest.

EDD reform is the headline for most financial firms. Crypto firms face two separate waves of obligation. The first arrives on June 30. The second, deeper wave begins February 1, 2027.

Change Effective Date
EDD mandatory only for FATF Call-to-Action countries June 30, 2026
Euro thresholds replaced with GBP equivalents June 30, 2026
EDD trigger refined to "unusually complex or large" June 30, 2026
TCSPs: off-the-shelf company sales brought in scope June 30, 2026
Trust Registration Service expanded to pre-2020 UK property June 30, 2026
Enhanced EDD for crypto correspondent relationships (new reg 34A) February 1, 2027
Broader crypto controls aligned to FSMA cryptoassets regime October 25, 2027

The EDD Reform: Narrower Scope, Sharper Risk Basis

Narrowing mandatory Enhanced Due Diligence for high-risk jurisdictions is the largest general change. Any transaction or business relationship connected to a FATF grey list country used to trigger the EDD duty. That list moves often. In recent years it has covered major trading partners.

Amended regulation 33(b) confines mandatory EDD to countries subject to a FATF Call to Action. Iran, North Korea, and Myanmar currently sit on that list.

AML controls have not been loosened. Targeting has been sharpened. Countries on the FATF increased monitoring list (the grey list) stay relevant risk factors under regulation 33(6)(c). Grey list status still belongs in risk assessments. A blanket mandatory EDD duty no longer attaches solely because of grey list inclusion. Risk-based judgement is the expectation, not administrative box-ticking.

Policy documents therefore need to match the new trigger. Risk-scoring systems, meanwhile, must keep capturing grey list country exposure as a material risk factor. Take away the EDD checkbox and the risk flag still stays.

GBP Thresholds: A Small Change With Operational Impact

Euro-denominated thresholds throughout the MLRs give way to pound sterling equivalents. Cash transactions in many regulated sectors used the familiar €10,000 threshold. That figure becomes £10,000.

Calculating and tracking EUR/GBP conversion rates for threshold monitoring is no longer required. The pound sterling equivalent applies directly.

A split now opens for crypto firms that operate in both UK and EU jurisdictions. MiCA and the recast Transfer of Funds Regulation still use euro-denominated thresholds in the EU — and, in some cases, no threshold at all. Those parallel obligations are broken down in our analysis of the MiCA Travel Rule for CASPs.

Crypto Firms: The June 30 Obligations

Two items in the June 30 tranche matter directly to crypto compliance teams.

EDD trigger refinement. Regulation 33(1)(f)(i) used to fire where a transaction was "unusually complex or unusually large, or has an unusual pattern, or has no apparent economic or legal purpose." The amendment now fires where a transaction is "unusually complex or unusually large." Catchall language from the earlier version is gone. Transaction monitoring rules need an audit so that thresholds and complexity flags match the revised, more objective wording.

FSMA cryptoassets regime alignment. Alignment of the MLRs with the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 starts here. Those 2026 Regulations established the new UK financial services regulatory framework for cryptoassets. CASPs under the FSMA regime must point their AML procedures at the correct, updated regulatory basis and keep them coherent with the revised framework.

Crypto Firms: The February 2027 Wave

For cryptoasset businesses, the change with the greatest consequence takes effect on February 1, 2027. Distant enough to feel manageable. Close enough that project planning cannot wait.

A new regulation 34A is inserted into the MLRs by Regulation 20 of the amendment. Cryptoasset exchange providers and custodian wallet providers must apply Enhanced Due Diligence in correspondent relationships.

What Is a Correspondent Relationship in Crypto?

One institution serving the customers of another — cross-border payments, account access, currency conversion — is the banking definition of a correspondent relationship. Crypto has the same pattern: exchanges routing transfers through each other, wallet providers depending on exchange infrastructure, and platforms using third-party custody services.

Under regulation 34A:

  • EDD must be applied by CASPs before a correspondent relationship with another cryptoasset firm is established
  • The counterparty's AML/CFT controls must be assessed
  • Each party's responsibilities under the relationship must be documented
  • Senior management approval must be obtained before the relationship is established or continued
  • A correspondent relationship with a shell cryptoasset firm must not be entered into or continued

Entities with no physical presence in any jurisdiction and no affiliation with a regulated group are shell firms. Banning them tracks the correspondent banking ban on shell banks and lines up with FATF Recommendations 13 and 15 on new technologies.

Why This Matters Now, Not in 2027

The effective date is February 1, 2027. The operational runway is short all the same. Finding every correspondent relationship inside a crypto firm's infrastructure is not simple. Custody arrangements, liquidity providers, OTC desk counterparties, cross-exchange transfer pathways — any of these may count as correspondent relationships under the new definition. Mapping them, running due diligence on each counterparty, and documenting the results is months of proper compliance work.

Treat regulation 34A as a January 2027 problem and time will run out.

What Your KYC Stack Needs to Deliver

June 30 and February 2027 obligations, read together, sketch what UK-compliant cryptoasset KYC infrastructure must do.

At onboarding:

  • Structured, verified identity records must come out of verification, so risk-based decisions at transaction monitoring time have something solid to use
  • The updated EDD trigger language must appear explicitly in CDD documentation

At transaction monitoring:

  • The amended "unusually complex or large" trigger must be reflected in the rules
  • Grey list country exposure must sit in the risk model as a factor, not as an automatic mandatory EDD response

At correspondent relationship management:

  • Every correspondent relationship must sit in a complete inventory
  • Each counterparty must receive EDD, with assessments written down and senior management sign-off on file
  • Counterparty AML/CFT controls must stay under ongoing monitoring

At threshold management:

  • Threshold monitoring must run in GBP rather than EUR

Autonomous compliance infrastructure, not manual review, is what firms building toward these requirements increasingly use. How AI-driven systems handle ongoing monitoring, correspondent relationship screening, and structured identity data management in practice is covered in our analysis of agentic KYC and AI agents for compliance.

Regulatory complexity is accelerating around this. UK MLR amendments, MiCA obligations, and the incoming AMLR framework from 2027 all land on firms that operate in UK and EU jurisdictions at once. The EU-side trajectory is mapped in our piece on AMLA and EU AML supervision, which covers the parallel supervisory buildup.

This is the compliance environment Joinble's AI Agents were built for: continuous identity monitoring that keeps verified, structured customer records across the full customer lifecycle, plus automated flags for EDD triggers, threshold events, and correspondent relationship review cycles.

The Compliance Arithmetic

Targeting in the amendment is sound. Administrative burden for legitimate business falls with the EDD reform. Unnecessary friction disappears with the GBP thresholds. A gap regulators have flagged for years is closed by the crypto correspondent relationship rules.

Crypto firms still carry a significant burden. Most compliance teams currently expect the February 2027 deadline for regulation 34A to arrive later than it will. Start now and treat it as a 2026 project: the rollout stays managed. Treat it as a 2027 problem and a crisis follows.

Europe's enforcement direction is consistent. Sweden's Finansinspektionen, on 17 June 2026, fined Ikano Bank SEK 140 million for structurally identical failures: outdated ML/TF typologies, no segment-specific risk assessment for corporate clients, and EDD records missing purpose, source of funds, and beneficial ownership data. The full compliance breakdown — and the specific controls regulators are now verifying — is documented in the Ikano Bank AML fine.

Maturation of the UK's cryptoasset regulatory framework is rapid. One piece is the MLR amendments. Another is the FSMA cryptoassets regime — the FCA authorisation gateway for which opens on 30 September 2026. A third is the Travel Rule equivalent under UK law. For the full compliance checklist firms need before submitting their FSMA authorisation application, see: UK FCA Crypto Gateway: KYC Compliance Checklist 2026. US stablecoin issuers, in parallel, face their own shift: FinCEN's June 2026 proposed rule under the GENIUS Act would require bank-grade Customer Identification Programs for all US payment stablecoin issuers, treating them as financial institutions under the Bank Secrecy Act. Both regimes apply independently to US-headquartered firms operating UK-registered CASPs. See GENIUS Act KYC requirements for stablecoin issuers and our State of KYC in Crypto 2026 report.

FAQ

When do most provisions of the UK MLR Amendment 2026 take effect? June 9, 2026 is when the regulations were made. Twenty-one days later, on June 30, 2026, most provisions come into force. Regulation 34A — the cryptoasset correspondent relationship EDD requirement — takes effect on February 1, 2027. Broader crypto controls aligned to the FSMA cryptoassets regime, in certain cases, come into force on October 25, 2027.

Does the FATF grey list still trigger EDD under the new rules? Automatic triggering is gone. Mandatory EDD is narrowed to FATF Call-to-Action countries, which currently means Iran, North Korea, and Myanmar. Under regulation 33(6)(c), grey list countries remain relevant risk factors, and grey list exposure still belongs in risk assessments. Mandatory EDD solely on that basis is no longer required.

What is the new EDD trigger for complex or high-value transactions? Where a transaction is "unusually complex or unusually large," amended regulation 33(1)(f)(i) triggers EDD. Language that previously covered unusual patterns or no apparent economic purpose, the catchall, has been removed. Transaction monitoring rules should be updated so they align with the revised wording.

What is a cryptoasset correspondent relationship under regulation 34A? Arrangements between cryptoasset exchange providers and custodian wallet providers in which one institution provides services to customers of another fall under this heading — structurally equivalent to correspondent banking. CASPs must apply EDD from February 1, 2027, document responsibilities, and obtain senior management approval before entering or continuing these relationships.

Does regulation 34A ban shell cryptoasset firms? Yes. Entering into or continuing correspondent relationships with shell cryptoasset firms is explicitly prohibited for CASPs. Shell cryptoasset firms are entities with no physical presence in any jurisdiction and no affiliation with a regulated group. The existing prohibition on correspondent banking relationships with shell banks is the model.

How does the UK MLR amendment interact with EU obligations under MiCA? Parallel regimes, not identical ones. Both apply independently to UK-based CASPs serving EU customers. From July 1, 2026 the MiCA Travel Rule applies to EU-jurisdiction transfers; the UK MLR applies domestically. GBP in the UK and EUR in the EU now split the threshold structures, so compliance teams operating across both jurisdictions need separate documentation and monitoring configurations for each.

Emily CarterEmily Carter
Share

Related Articles

AMLR 2027: New KYC Rules for Real Estate, Luxury & Football
Compliance25 May, 2026

AMLR 2027: New KYC Rules for Real Estate, Luxury & Football

EU AMLR 2027 extends KYC obligations to real estate, luxury goods, and football. Fourteen months for sectors with zero compliance history to get it right.

UK FCA Crypto Gateway: KYC Compliance Checklist 2026
Compliance14 Sep, 2026

UK FCA Crypto Gateway: KYC Compliance Checklist 2026

The FCA crypto authorisation gateway opens 30 September 2026. Firms have five months to apply. Here is what KYC compliance teams must prepare now.

AMLA Is Watching: EU's New AML Authority
Compliance20 Apr, 2026

AMLA Is Watching: EU's New AML Authority

The EU's new Anti-Money Laundering Authority is now actively supervising crypto firms. Here's what CASPs must do before the July 2026 deadline.