Qifei Zeng
- New UK Money Laundering Regulations coming into effect on 30 June 2026 change how firms apply enhanced due diligence to higher-risk jurisdictions.
- FATF grey-list status will no longer automatically trigger EDD, placing greater emphasis on firm-led risk assessment and judgement.
- As compliance teams adapt, robust documentation, consistent decision-making and clear audit trails will become increasingly important.
From 30 June 2026, amendments to the UK Money Laundering Regulations (MLRs) changed the way firms are expected to apply enhanced due diligence (EDD) to subjects in higher-risk jurisdictions.
The key change is that FATF grey-list exposure is no longer treated as an automatic EDD trigger. Mandatory EDD continues to apply to FATF high-risk jurisdictions subject to a Call for Action, currently the Democratic People’s Republic of Korea (DPRK/North Korea), Iran and Myanmar. Jurisdictions under Increased Monitoring, commonly referred to as the FATF grey list, still matter, but they now sit within the broader risk assessment rather than operating as an automatic escalation point.
This is the grey-list trap: assuming that removing an automatic trigger reduces the need for EDD discipline. In reality, it reflects a broader regulatory expectation that firms should be able to justify and evidence their own risk decisions. The practical challenge is therefore not simply screening against a specific list, it’s demonstrating how the country risk exposure has been interpreted alongside the customer, product, transaction, and channel risks.
From automatic escalation to risk-based EDD decisioning
The amended framework introduces a more explicitly risk-based approach to higher-risk jurisdictions. Rather than relying on list status alone, firms are expected to assess whether enhanced measures are appropriate based on the broader context of risk.
That context includes factors such as customer profile, ownership structure, source of funds / wealth, transaction behaviour and delivery channel. FATF grey list exposure remains a key input, but it is no longer sufficient on its own to determine whether EDD is required.
This is where many EDD frameworks will need to mature. A defensible decision should not simply record “grey list — no EDD required.” It should show the factors considered, the weighting applied, the conclusion reached and the monitoring response applied. In other words, the output of the process should be a defensible rationale, not just checking a box.
Why grey-list exposure still matters
The removal of an automatic trigger does not remove the underlying risk considerations associated with grey-list jurisdictions. These jurisdictions are identified because they are working with FATF to address strategic deficiencies and therefore remain relevant within a firm’s country risk methodology.
For grey-list jurisdictions, the question becomes more nuanced. Is the customer merely connected to the jurisdiction via inconsequential ties, or is the exposure central to the relationship? Are the FATF-identified deficiencies relevant to the customer’s activity? Do transaction patterns, ownership structures or source-of-funds indicators amplify the risk?
The limits of list-based approaches
FATF lists provide an important signal, but they are inherently binary. In practice, country risk exists on a spectrum, and jurisdictions vary significantly in their financial crime exposure, regulatory maturity and economic environment. While a list can identify a risk signal, it does not explain how that risk applies to a specific customer or transaction, whether the exposure is direct or indirect, and whether other controls already mitigate the risk.
What this means for compliance teams
For compliance teams, the MLR update has operational and governance implications. Firms need to ensure that policies, workflows and documentation support consistent and defensible decision-making. The approach should be:
- Risk-based — it distinguishes between mandatory EDD for “call for action” jurisdictions and risk-based EDD decisions for grey list exposure
- Evidence-led — It uses validated and contextualized data for risk assessment
- Explainable — it documents why a grey-list connection did or did not result in EDD or contribute to an EDD outcome
- Dynamic — it responds to changes in customer behaviour, products and services, geographies, and typologies
- Consistent — it is consistently reflected in policies, procedures and workflows across customer onboarding, transaction monitoring, and periodic reviews accordingly
The firms with the most effective response will not simply remove grey-list triggers, they will replace blunt escalation with clearer risk interpretation.
Supporting defensible decisions
As firms move away from automatic triggers, defensibility becomes central to effective compliance. This places greater emphasis on structured data, consistent workflows and the ability to maintain a clear audit trail.
An audit-ready escalation decisioning record ideally should capture:
- The country-risk source and list date;
- How the jurisdictional exposure arises;
- The customer, ownership, product, channel and transaction risks considered;
- EDD decisioning and rationale;
- Any controls applied;
- Who approved the decision;
- When the decision will be reviewed (timeline, triggers, etc.)
Conclusion
footnotes
Legal Disclaimer
Republication or redistribution of LSE Group content is prohibited without our prior written consent.
The content of this publication is for informational purposes only and has no legal effect, does not form part of any contract, does not, and does not seek to constitute advice of any nature and no reliance should be placed upon statements contained herein. Whilst reasonable efforts have been taken to ensure that the contents of this publication are accurate and reliable, LSE Group does not guarantee that this document is free from errors or omissions; therefore, you may not rely upon the content of this document under any circumstances and you should seek your own independent legal, investment, tax and other advice. Neither We nor our affiliates shall be liable for any errors, inaccuracies or delays in the publication or any other content, or for any actions taken by you in reliance thereon.
Copyright © 2026 London Stock Exchange Group. All rights reserved.
The content of this publication is provided by London Stock Exchange Group plc, its applicable group undertakings and/or its affiliates or licensors (the “LSE Group” or “We”) exclusively.
Neither We nor our affiliates guarantee the accuracy of or endorse the views or opinions given by any third party content provider, advertiser, sponsor or other user. We may link to, reference, or promote websites, applications and/or services from third parties. You agree that We are not responsible for, and do not control such non-LSE Group websites, applications or services.
The content of this publication is for informational purposes only. All information and data contained in this publication is obtained by LSE Group from sources believed by it to be accurate and reliable. Because of the possibility of human and mechanical error as well as other factors, however, such information and data are provided "as is" without warranty of any kind. You understand and agree that this publication does not, and does not seek to, constitute advice of any nature. You may not rely upon the content of this document under any circumstances and should seek your own independent legal, tax or investment advice or opinion regarding the suitability, value or profitability of any particular security, portfolio or investment strategy. Neither We nor our affiliates shall be liable for any errors, inaccuracies or delays in the publication or any other content, or for any actions taken by you in reliance thereon. You expressly agree that your use of the publication and its content is at your sole risk.
To the fullest extent permitted by applicable law, LSE Group, expressly disclaims any representation or warranties, express or implied, including, without limitation, any representations or warranties of performance, merchantability, fitness for a particular purpose, accuracy, completeness, reliability and non-infringement. LSE Group, its subsidiaries, its affiliates and their respective shareholders, directors, officers employees, agents, advertisers, content providers and licensors (collectively referred to as the “LSE Group Parties”) disclaim all responsibility for any loss, liability or damage of any kind resulting from or related to access, use or the unavailability of the publication (or any part of it); and none of the LSE Group Parties will be liable (jointly or severally) to you for any direct, indirect, consequential, special, incidental, punitive or exemplary damages, howsoever arising, even if any member of the LSE Group Parties are advised in advance of the possibility of such damages or could have foreseen any such damages arising or resulting from the use of, or inability to use, the information contained in the publication. For the avoidance of doubt, the LSE Group Parties shall have no liability for any losses, claims, demands, actions, proceedings, damages, costs or expenses arising out of, or in any way connected with, the information contained in this document.
LSE Group is the owner of various intellectual property rights ("IPR”), including but not limited to, numerous trademarks that are used to identify, advertise, and promote LSE Group products, services and activities. Nothing contained herein should be construed as granting any licence or right to use any of the trademarks or any other LSE Group IPR for any purpose whatsoever without the written permission or applicable licence terms.