Risk intelligence Insights

The grey-list trap: What are the new UK Money Laundering Regulation changes for enhanced due diligence

Qifei Zeng

Manager, Third-Party Risk Intelligence
  • New UK Money Laundering Regulations coming into effect on 30 June 2026 change how firms apply enhanced due diligence to higher-risk jurisdictions. 
  • FATF grey-list status will no longer automatically trigger EDD, placing greater emphasis on firm-led risk assessment and judgement. 
  • As compliance teams adapt, robust documentation, consistent decision-making and clear audit trails will become increasingly important.

From 30 June 2026, amendments to the UK Money Laundering Regulations (MLRs) changed the way firms are expected to apply enhanced due diligence (EDD) to subjects in higher-risk jurisdictions. 

The key change is that FATF grey-list exposure is no longer treated as an automatic EDD trigger. Mandatory EDD continues to apply to FATF high-risk jurisdictions subject to a Call for Action, currently the Democratic People’s Republic of Korea (DPRK/North Korea), Iran and Myanmar. Jurisdictions under Increased Monitoring, commonly referred to as the FATF grey list, still matter, but they now sit within the broader risk assessment rather than operating as an automatic escalation point.

This is the grey-list trap: assuming that removing an automatic trigger reduces the need for EDD discipline. In reality, it reflects a broader regulatory expectation that firms should be able to justify and evidence their own risk decisions. The practical challenge is therefore not simply screening against a specific list, it’s demonstrating how the country risk exposure has been interpreted alongside the customer, product, transaction, and channel risks.

From automatic escalation to risk-based EDD decisioning

The amended framework introduces a more explicitly risk-based approach to higher-risk jurisdictions. Rather than relying on list status alone, firms are expected to assess whether enhanced measures are appropriate based on the broader context of risk.

That context includes factors such as customer profile, ownership structure, source of funds / wealth, transaction behaviour and delivery channel. FATF grey list exposure remains a key input, but it is no longer sufficient on its own to determine whether EDD is required.

This is where many EDD frameworks will need to mature. A defensible decision should not simply record “grey list — no EDD required.” It should show the factors considered, the weighting applied, the conclusion reached and the monitoring response applied. In other words, the output of the process should be a defensible rationale, not just checking a box.

Why grey-list exposure still matters

The removal of an automatic trigger does not remove the underlying risk considerations associated with grey-list jurisdictions. These jurisdictions are identified because they are working with FATF to address strategic deficiencies and therefore remain relevant within a firm’s country risk methodology.

For grey-list jurisdictions, the question becomes more nuanced. Is the customer merely connected to the jurisdiction via inconsequential ties, or is the exposure central to the relationship? Are the FATF-identified deficiencies relevant to the customer’s activity? Do transaction patterns, ownership structures or source-of-funds indicators amplify the risk?

The limits of list-based approaches

FATF lists provide an important signal, but they are inherently binary. In practice, country risk exists on a spectrum, and jurisdictions vary significantly in their financial crime exposure, regulatory maturity and economic environment. While a list can identify a risk signal, it does not explain how that risk applies to a specific customer or transaction, whether the exposure is direct or indirect, and whether other controls already mitigate the risk.

What this means for compliance teams

For compliance teams, the MLR update has operational and governance implications. Firms need to ensure that policies, workflows and documentation support consistent and defensible decision-making. The approach should be:

  • Risk-based — it distinguishes between mandatory EDD for “call for action” jurisdictions and risk-based EDD decisions for grey list exposure
  • Evidence-led — It uses validated and contextualized data for risk assessment 
  • Explainable — it documents why a grey-list connection did or did not result in EDD or contribute to an EDD outcome
  • Dynamic — it responds to changes in customer behaviour, products and services, geographies, and typologies 
  • Consistent — it is consistently reflected in policies, procedures and workflows across customer onboarding, transaction monitoring, and periodic reviews accordingly 

The firms with the most effective response will not simply remove grey-list triggers, they will replace blunt escalation with clearer risk interpretation.

Supporting defensible decisions

As firms move away from automatic triggers, defensibility becomes central to effective compliance. This places greater emphasis on structured data, consistent workflows and the ability to maintain a clear audit trail.

An audit-ready escalation decisioning record ideally should capture:

  • The country-risk source and list date;
  • How the jurisdictional exposure arises;
  • The customer, ownership, product, channel and transaction risks considered;
  • EDD decisioning and rationale;
  • Any controls applied;
  • Who approved the decision;
  • When the decision will be reviewed (timeline, triggers, etc.)

Conclusion

The amended UK MLRs reinforce the importance of a risk-based approach to enhanced due diligence. Firms are expected to assess, document and justify their own decisions in a way that can withstand supervisory scrutiny.
  • 1. What are the UK Money Laundering Regulations 2026 changes?

    The changes introduce a more risk-based approach to enhanced due diligence, with less reliance on automatic triggers linked to jurisdiction lists. After the coming into force date (30 June 2026), enhanced due diligence and enhanced ongoing monitoring will only be required for business relationships with a person established in a jurisdiction listed by FATF as one of the High-Risk Jurisdictions subject to a Call for Action or in relation to relevant transactions where either of the parties to the transaction is established in a jurisdiction listed by FATF as one of the High-Risk Jurisdictions subject to a Call for Action. [note1]  

    2. Do firms still need enhanced due diligence for FATF grey-listed countries?

    Yes, but not automatically. Grey-list exposure remains a risk factor that firms must assess within their broader evaluation of risk. Grey-list exposure may still lead to EDD where the overall risk profile warrants it. Firms should evidence how the exposure was assessed and why EDD was or was not applied. 

    3. What is the FATF grey list?

    The FATF grey list refers to jurisdictions under increased monitoring due to strategic deficiencies in their AML and counter-terrorist financing frameworks.

    4. What does a risk-based approach to AML mean?

    A risk-based approach requires firms to assess the level of financial crime risk and apply proportionate due diligence measures based on that assessment.

    5. How should firms assess the FATF grey list exposure?

    The FATF grey list remains an important country-risk signal, even where it no longer serves as an automatic trigger for EDD. Firms should consider it in combination with other factors such as customer profile (e.g., residence / place of incorporation and business, beneficial ownership), transaction activity and product risk.

    6. Why is auditability important for EDD decisions?

    Auditability is especially important where EDD is no longer driven by an automatic trigger. Firms need to demonstrate to regulators what information was considered, how the risk was assessed, how and why decisions were made, what controls were applied, and who owns the decision, supporting transparency and compliance.

    7. What should compliance teams review following the MLR changes?

    Compliance teams should review risk methodologies, screening rules, policies, workflows, escalation logic, and risk decisioning documentation to ensure that grey-list exposure is treated as a risk-based indicator rather than an automatic trigger or an ignored signal.

footnotes

Legal Disclaimer

Republication or redistribution of LSE Group content is prohibited without our prior written consent. 

The content of this publication is for informational purposes only and has no legal effect, does not form part of any contract, does not, and does not seek to constitute advice of any nature and no reliance should be placed upon statements contained herein. Whilst reasonable efforts have been taken to ensure that the contents of this publication are accurate and reliable, LSE Group does not guarantee that this document is free from errors or omissions; therefore, you may not rely upon the content of this document under any circumstances and you should seek your own independent legal, investment, tax and other advice. Neither We nor our affiliates shall be liable for any errors, inaccuracies or delays in the publication or any other content, or for any actions taken by you in reliance thereon.

Copyright © 2026 London Stock Exchange Group. All rights reserved.