Annex 1 financial institutions and cryptoasset businesses registered under MLR 2017 run customer due diligence, sanctions, SARs and MLRO reporting from one platform — with the evidence trail the FCA’s financial-crime supervision demands.
14-day free trial · Take the tour
Ten dedicated B-prefix CMP chapters
Gap analysis mapped to MLR 2017 + JMLSG
MLRO annual, REP-CRIM + readiness dry-run
MLR 2017 registration puts your business under the FCA’s financial-crime supervision. When the information request or the visit comes, the question is always the same: can you prove your programme works?
Regulation 18 requires a documented, current business-wide risk assessment. A file called v11_FINAL.xlsx with no methodology and no review date isn’t one — and the FCA reads it first.
When the FCA samples customer files, “we checked” isn’t evidence. Regulation 28 expects the record to show what was verified, when, by whom — and when it falls due again.
Enhanced due diligence under Regulations 33 and 35 needs senior-management sign-off — a decision, a name and a date. An approval that lives in an inbox thread doesn’t survive a file review.
Which lists, what thresholds, how often — undocumented. And when a true hit lands, OFSI expects a disposition trail, not a verbal reassurance that someone dealt with it.
The annual report assembled in a weekend from fragments — SAR counts guessed, training records hunted down, the BWRA quoted from an old version. It reads that way to a supervisor too.
The FCA, NCA, OFSI and HMRC all move — guidance, alerts, list changes, MLR amendments. Missing the one that applies to your business is how registered firms fall behind.
For a firm supervised purely for financial crime, financial crime is the whole programme — ten monitoring chapters, a dedicated module and an MLRO report suite carry it.
The B-prefix chapters put 150 financial-crime checks into your monitoring plan: B1 AML framework & MLRO governance, B2 CDD/KYC, B3 EDD & PEPs, B4 ongoing monitoring, B5 sanctions, B6 SARs, B7 the MLRO annual report, B8 anti-bribery & corruption, B9 fraud and B10 market abuse. All inside the 1,139-template library.
A 36-control checklist of the FCA’s minimum expectations, cross-mapped to a 137-question gap analysis anchored to MLR 2017 and the JMLSG. A business-wide risk assessment with 27 pre-seeded high-risk jurisdictions, a sanctions workspace and a per-field audit trail behind every record.
Four report formats drafted from your live financial-crime records: the MLRO Annual, REP-CRIM (SUP 16.23), an Executive Summary and an FCA Supervisory Readiness dry-run — rehearse the FCA visit before it happens.
FCA Applications runs MLR 2017 registrations alongside 74 authorisation activity types — a guided requirements blueprint scoped to your application, document tracking and full lifecycle status through to “Registered”.
Regulatory Intelligence monitors 13 UK regulators in one hourly feed — the NCA, OFSI and HMRC among them — and Otto reads each item against your firm’s profile and scores its relevance, so the alert that matters surfaces first.
The Financial Crime module ships a 10-policy AML and financial-crime governance library — the documented framework Regulation 19 expects — pre-loaded, so your policies and your controls live in the same place your evidence does.
For an MLR-registered business, the Financial Crime module is the centre of gravity — the risk assessment, the controls, the registers and the audit trail the FCA’s financial-crime supervision runs on.
The FCA’s minimum expectations as a standing checklist, cross-mapped to a 137-question gap analysis anchored to MLR 2017 and the JMLSG.
The BWRA regulation 18 requires, as a living record — 27 pre-seeded high-risk jurisdictions, a documented methodology and a review date that isn’t a filename.
Your screening programme documented — lists, thresholds, cadence — with a hit log, frozen-assets and OFSI licence registers, and a breach log alongside.
Every customer risk-rated and review-tracked, with sanctions and EDD flags — and PEP decisions recorded with a name, a date and the evidence attached.
The MLRO’s morning glance. Financial Crime Health score, live operations across every regime, KPIs, the MLRO calendar and review SLAs — the whole function on one screen, every weakness one click from the work that fixes it.
Customer risk and PEP registers — each record risk-rated and review-tracked, with sanctions and EDD flags and the evidence attached. When the FCA samples your CDD files, the working is on the record, not in someone’s head.
The sanctions workspace: your screening programme — lists, thresholds, cadence — documented in one place, a hit log with dispositions, frozen-assets and OFSI licence registers, and a breach log with the reporting route named from the start.
The 36-control checklist and the 137-question gap analysis, cross-mapped and anchored to MLR 2017 and the JMLSG — work through it, and what emerges is a documented, current assessment of your framework with every gap tracked to remediation.
Your AML monitoring plan lands complete — from the framework itself (B1) through CDD, EDD, monitoring, sanctions and SARs to the MLRO annual report (B7) — with owners, cadences and regulatory references on every check.
Ten dedicated chapters, B1 to B10 — AML framework, CDD/KYC, EDD & PEPs, monitoring, sanctions, SARs, the MLRO annual, ABC, fraud and market abuse.
74 regulation-anchored categories across 8 regulators — scope your plan to the chapters your registration actually engages, nothing rebuilt from a blank page.
One person completes a check, a second approves it — every close-out timestamped, so the monitoring record itself stands up to inspection.
Breaches, complaints, gifts & entertainment and conflicts recorded in the same tracker — status chips, named owners and due dates throughout.
The nominated officer’s landing surface. Live KPI tiles for open, closed and overdue checks, completion and approval rates, an overall Health Score, RAG summary and monthly trends — every tile a one-click drill-down to the records underneath.
1,139 expert-built monitoring checks across 74 regulation-anchored categories — including the ten B-prefix financial-crime chapters, from AML framework and CDD through sanctions and SARs to the MLRO annual report. Each template ships with a regulatory reference chain and plain-English guidance that pre-populates in-form.
Every event your firm has to record, in one tracker. Breaches, complaints, gifts & entertainment and conflicts — status chips, named owners, due dates and a maker-checker approval workflow throughout.
Whether you’re preparing an MLR 2017 registration or maintaining one, the application, its documents and every subsequent FCA filing run through a single lifecycle tracker.
The application-type selector covers 74 regulated activity types plus MLR 2017 registrations — pick yours and the requirements blueprint is scoped to it.
Every document the application needs, tracked to done — the BWRA, policies and governance evidence the FCA expects to see attached, in one checklist.
Acknowledgement date, case officer and the assessment clock in one status view — so you always know where the application stands and what the FCA is waiting on.
A four-stage lifecycle from preparation to determination — and for MLR applications the final stage reads “Registered”, because that’s your regime.
The lifecycle dashboard: a KPI strip, the applications register and a four-stage lifecycle for every FCA paperwork event your firm files — authorisations, registrations and variations of permission in one place.
The application-type selector — 74 regulated activity types plus MLR 2017 registrations. Pick the one your application covers and the requirements blueprint is scoped to it, so you prepare what the FCA will actually assess.
The FCA status view: acknowledgement date, case officer and the assessment window tracked day by day — the difference between chasing an application and managing one.
Otto is the platform’s built-in compliance advisor, grounded in 150+ expert-authored documents. She reads your live monitoring, risk and financial-crime records — not a generic handbook summary — and drafts the four report formats an MLRO is asked for.
The report your board and the FCA both expect, drafted from your live records — SAR activity, CDD and EDD posture, sanctions performance and training, section by section.
The annual financial-crime return under SUP 16.23, pre-assembled from the same live data your registers already hold — not re-keyed from spreadsheets each year.
A rehearsal of the FCA’s financial-crime visit before it happens — where the framework is strong, where the file is thin, and what to fix first.
“Which EDD reviews are overdue?” “What does the BWRA say about our exposure?” Otto answers from your live records — and tells you what closes the gap.
AI drafts, humans decide — nothing is auto-submitted, and every fact traces to your live firm data.
Three ways to run an AML programme. Only one produces evidence the FCA can inspect — on the day they ask for it.
What the nominated officer of an Annex 1 financial institution or a cryptoasset business wants to know about platform-grade AML compliance.
We use essential cookies to make the site work, and optional analytics cookies to understand how it's used. See our Cookie Policy.