FOR MLR-REGISTERED FIRMS

FCA-Supervised for AML? Prove Your Programme.

Annex 1 financial institutions and cryptoasset businesses registered under MLR 2017 run customer due diligence, sanctions, SARs and MLRO reporting from one platform — with the evidence trail the FCA’s financial-crime supervision demands.

Start free trial Book a Consultation

14-day free trial · Take the tour

150 Financial-Crime Checks

Ten dedicated B-prefix CMP chapters

36-Control FCA Checklist

Gap analysis mapped to MLR 2017 + JMLSG

Otto MLRO Report Suite

MLRO annual, REP-CRIM + readiness dry-run

CDD & EDD Monitoring
Sanctions Screening Workspace
Business-Wide Risk Assessment
SAR Controls & Records
MLRO Annual & REP-CRIM
13-Regulator Live Feed

Registered, Not Authorised — Still Fully Supervised

MLR 2017 registration puts your business under the FCA’s financial-crime supervision. When the information request or the visit comes, the question is always the same: can you prove your programme works?

The BWRA That Lives in a Spreadsheet

Regulation 18 requires a documented, current business-wide risk assessment. A file called v11_FINAL.xlsx with no methodology and no review date isn’t one — and the FCA reads it first.

CDD Files That Can't Show Their Working

When the FCA samples customer files, “we checked” isn’t evidence. Regulation 28 expects the record to show what was verified, when, by whom — and when it falls due again.

PEP Decisions Nobody Wrote Down

Enhanced due diligence under Regulations 33 and 35 needs senior-management sign-off — a decision, a name and a date. An approval that lives in an inbox thread doesn’t survive a file review.

Sanctions Screening You Can't Evidence

Which lists, what thresholds, how often — undocumented. And when a true hit lands, OFSI expects a disposition trail, not a verbal reassurance that someone dealt with it.

The MLRO Report Written from Memory

The annual report assembled in a weekend from fragments — SAR counts guessed, training records hunted down, the BWRA quoted from an old version. It reads that way to a supervisor too.

The Update That Rewrites Your Obligations

The FCA, NCA, OFSI and HMRC all move — guidance, alerts, list changes, MLR amendments. Missing the one that applies to your business is how registered firms fall behind.

MLR 2017, Covered — Control by Control.

For a firm supervised purely for financial crime, financial crime is the whole programme — ten monitoring chapters, a dedicated module and an MLRO report suite carry it.

Ten Financial-Crime Chapters

The B-prefix chapters put 150 financial-crime checks into your monitoring plan: B1 AML framework & MLRO governance, B2 CDD/KYC, B3 EDD & PEPs, B4 ongoing monitoring, B5 sanctions, B6 SARs, B7 the MLRO annual report, B8 anti-bribery & corruption, B9 fraud and B10 market abuse. All inside the 1,139-template library.

MLR 2017JMLSGUK MAR

The Financial Crime Module

A 36-control checklist of the FCA’s minimum expectations, cross-mapped to a 137-question gap analysis anchored to MLR 2017 and the JMLSG. A business-wide risk assessment with 27 pre-seeded high-risk jurisdictions, a sanctions workspace and a per-field audit trail behind every record.

MLR 2017 Reg 18Reg 28JMLSG

Otto’s MLRO Report Suite

Four report formats drafted from your live financial-crime records: the MLRO Annual, REP-CRIM (SUP 16.23), an Executive Summary and an FCA Supervisory Readiness dry-run — rehearse the FCA visit before it happens.

MLRO AnnualREP-CRIMSUP 16.23

MLR Registration, Managed

FCA Applications runs MLR 2017 registrations alongside 74 authorisation activity types — a guided requirements blueprint scoped to your application, document tracking and full lifecycle status through to “Registered”.

MLR 2017Annex 1Cryptoassets

13 Regulators, One Feed

Regulatory Intelligence monitors 13 UK regulators in one hourly feed — the NCA, OFSI and HMRC among them — and Otto reads each item against your firm’s profile and scores its relevance, so the alert that matters surfaces first.

NCAOFSIHMRC

The 10-Policy Governance Library

The Financial Crime module ships a 10-policy AML and financial-crime governance library — the documented framework Regulation 19 expects — pre-loaded, so your policies and your controls live in the same place your evidence does.

MLR 2017 Reg 19JMLSG

The Regime You’re Supervised Under, In One Module

For an MLR-registered business, the Financial Crime module is the centre of gravity — the risk assessment, the controls, the registers and the audit trail the FCA’s financial-crime supervision runs on.

36-control checklist

The FCA’s minimum expectations as a standing checklist, cross-mapped to a 137-question gap analysis anchored to MLR 2017 and the JMLSG.

Business-wide risk assessment

The BWRA regulation 18 requires, as a living record — 27 pre-seeded high-risk jurisdictions, a documented methodology and a review date that isn’t a filename.

Sanctions workspace

Your screening programme documented — lists, thresholds, cadence — with a hit log, frozen-assets and OFSI licence registers, and a breach log alongside.

Customer risk & PEP registers

Every customer risk-rated and review-tracked, with sanctions and EDD flags — and PEP decisions recorded with a name, a date and the evidence attached.

Financial Crime dashboard — Financial Crime Health score, live operations across every regime, KPIs, the MLRO calendar and review SLAs

The MLRO’s morning glance. Financial Crime Health score, live operations across every regime, KPIs, the MLRO calendar and review SLAs — the whole function on one screen, every weakness one click from the work that fixes it.

Customer Risk and PEP registers — risk-rated, review-tracked and evidence-attached with sanctions and EDD flags

Customer risk and PEP registers — each record risk-rated and review-tracked, with sanctions and EDD flags and the evidence attached. When the FCA samples your CDD files, the working is on the record, not in someone’s head.

Sanctions workspace — screening programme, hit log, frozen-assets and OFSI licence registers and a breach log

The sanctions workspace: your screening programme — lists, thresholds, cadence — documented in one place, a hit log with dispositions, frozen-assets and OFSI licence registers, and a breach log with the reporting route named from the start.

Financial crime control checklist and 137-question gap analysis, mapped to JMLSG and MLR 2017

The 36-control checklist and the 137-question gap analysis, cross-mapped and anchored to MLR 2017 and the JMLSG — work through it, and what emerges is a documented, current assessment of your framework with every gap tracked to remediation.

Explore Financial Crime →

Ten B-Prefix Chapters, 150 Checks, Ready on Day One

Your AML monitoring plan lands complete — from the framework itself (B1) through CDD, EDD, monitoring, sanctions and SARs to the MLRO annual report (B7) — with owners, cadences and regulatory references on every check.

150 financial-crime checks

Ten dedicated chapters, B1 to B10 — AML framework, CDD/KYC, EDD & PEPs, monitoring, sanctions, SARs, the MLRO annual, ABC, fraud and market abuse.

1,139 expert templates

74 regulation-anchored categories across 8 regulators — scope your plan to the chapters your registration actually engages, nothing rebuilt from a blank page.

Maker-checker approval

One person completes a check, a second approves it — every close-out timestamped, so the monitoring record itself stands up to inspection.

Registers alongside

Breaches, complaints, gifts & entertainment and conflicts recorded in the same tracker — status chips, named owners and due dates throughout.

Compliance Monitoring Hub dashboard — KPI tiles, health score, RAG summary and distribution, status breakdown and monthly trends

The nominated officer’s landing surface. Live KPI tiles for open, closed and overdue checks, completion and approval rates, an overall Health Score, RAG summary and monthly trends — every tile a one-click drill-down to the records underneath.

Compliance Monitoring Task Library — 1,139 expert-built monitoring check templates across 74 categories, including the ten B-prefix financial-crime chapters

1,139 expert-built monitoring checks across 74 regulation-anchored categories — including the ten B-prefix financial-crime chapters, from AML framework and CDD through sanctions and SARs to the MLRO annual report. Each template ships with a regulatory reference chain and plain-English guidance that pre-populates in-form.

Register submissions tracker — breaches, complaints, gifts and entertainment and conflicts with owners, due dates and approval status

Every event your firm has to record, in one tracker. Breaches, complaints, gifts & entertainment and conflicts — status chips, named owners, due dates and a maker-checker approval workflow throughout.

Explore the Compliance Monitoring Hub →

MLR Registration, Run Like a Project

Whether you’re preparing an MLR 2017 registration or maintaining one, the application, its documents and every subsequent FCA filing run through a single lifecycle tracker.

MLR registrations built in

The application-type selector covers 74 regulated activity types plus MLR 2017 registrations — pick yours and the requirements blueprint is scoped to it.

Document tracking

Every document the application needs, tracked to done — the BWRA, policies and governance evidence the FCA expects to see attached, in one checklist.

Assessment-window tracking

Acknowledgement date, case officer and the assessment clock in one status view — so you always know where the application stands and what the FCA is waiting on.

Lifecycle to “Registered”

A four-stage lifecycle from preparation to determination — and for MLR applications the final stage reads “Registered”, because that’s your regime.

FCA Applications lifecycle dashboard — KPI strip, applications register and four-stage lifecycle

The lifecycle dashboard: a KPI strip, the applications register and a four-stage lifecycle for every FCA paperwork event your firm files — authorisations, registrations and variations of permission in one place.

Application type selector covering 74 regulated activity types plus MLR 2017 registrations

The application-type selector — 74 regulated activity types plus MLR 2017 registrations. Pick the one your application covers and the requirements blueprint is scoped to it, so you prepare what the FCA will actually assess.

FCA status tracker — assessment window, case officer and acknowledgement date

The FCA status view: acknowledgement date, case officer and the assessment window tracked day by day — the difference between chasing an application and managing one.

Explore FCA Applications →

Otto Reads Your Live Financial-Crime Data — Then Drafts the Report

Otto is the platform’s built-in compliance advisor, grounded in 150+ expert-authored documents. She reads your live monitoring, risk and financial-crime records — not a generic handbook summary — and drafts the four report formats an MLRO is asked for.

MLRO Annual Report

The report your board and the FCA both expect, drafted from your live records — SAR activity, CDD and EDD posture, sanctions performance and training, section by section.

REP-CRIM Return

The annual financial-crime return under SUP 16.23, pre-assembled from the same live data your registers already hold — not re-keyed from spreadsheets each year.

Supervisor Readiness Dry-Run

A rehearsal of the FCA’s financial-crime visit before it happens — where the framework is strong, where the file is thin, and what to fix first.

Ask Otto Anything

“Which EDD reviews are overdue?” “What does the BWRA say about our exposure?” Otto answers from your live records — and tells you what closes the gap.

AI drafts, humans decide — nothing is auto-submitted, and every fact traces to your live firm data.

Consultants and Spreadsheets vs RegTechPRO

Three ways to run an AML programme. Only one produces evidence the FCA can inspect — on the day they ask for it.

The Old Way
Consultant + Spreadsheets
c. £10,000/month retainer
  • The BWRA in a spreadsheet, versioned by filename
  • CDD and EDD decisions scattered across inboxes and drives
  • Sanctions screening with no documented lists, thresholds or cadence
  • The MLRO annual assembled from fragments every year
  • Nothing board-ready to show the FCA on the day
The RegTechPRO Way
RegTechPRO
Three simple plans, no long-term contract
  • 150 financial-crime checks ready on day one — 1,139 in the library
  • 36-control checklist and 137-question gap analysis, cross-mapped
  • BWRA, sanctions workspace and customer-risk registers in one module
  • 13 regulators in one feed — the NCA, OFSI and HMRC included
  • Otto drafts the MLRO annual and REP-CRIM from your live data
The Stack Way
5+ Separate RegTech Platforms
£20,000–£50,000/year across the stack
  • Monitoring, risk assessment, screening records and reporting — all separate platforms
  • 5+ vendor renewals, 5+ contracts, 5+ data silos
  • The same client data re-keyed into every system
  • No single evidence trail across the stack
  • Reconciliation overhead every board cycle
FAQs

MLR-registered firms. Questions Answered.

What the nominated officer of an Annex 1 financial institution or a cryptoasset business wants to know about platform-grade AML compliance.

We’re registered with the FCA, not authorised — is this platform still built for us?
Yes — arguably more so. An MLR-registered business is supervised for one thing: financial crime. That is exactly where the platform is deepest — ten dedicated monitoring chapters, a full Financial Crime module with the BWRA, sanctions workspace and customer-risk registers, and Otto’s MLRO report suite. You simply don’t switch on the modules built for FSMA permissions you don’t hold.
What do the B-prefix monitoring chapters cover?
Ten chapters put 150 financial-crime checks into your monitoring plan: B1 AML framework & MLRO governance, B2 CDD/KYC, B3 EDD & PEPs, B4 ongoing monitoring, B5 sanctions, B6 SARs, B7 the MLRO annual report, B8 anti-bribery & corruption, B9 fraud and B10 market abuse. All part of the 1,139-template library spanning 74 categories and 8 regulators.
How does the business-wide risk assessment work?
The BWRA lives in the Financial Crime module as a structured, versioned record rather than a spreadsheet — 27 high-risk jurisdictions come pre-seeded, the methodology is documented, and every change carries a per-field audit trail. It feeds the 137-question gap analysis, so the risk assessment and the controls that answer it stay connected — which is what Regulation 18 actually asks for.
What does the sanctions workspace hold?
Your screening programme documented in one place — which lists you screen against, at what thresholds, on what cadence — plus a hit log with dispositions, frozen-assets and OFSI licence registers, and a breach log with the reporting route named from the start. When OFSI or the FCA asks how screening works here, the answer is a page, not a meeting.
Is there a dedicated money-laundering filter in Regulatory Intelligence?
Not as a named sector toggle — and for this audience it isn’t the right tool anyway. The feed monitors 13 UK regulators, including the NCA, OFSI and HMRC, and Otto reads every item against your firm’s profile and scores its relevance. For a business whose whole regime is financial crime, that firm-level relevance scoring does the filtering a sector toggle would.
What does Otto actually draft for an MLRO?
Four report formats, all grounded in your live records: the MLRO Annual, the REP-CRIM return (SUP 16.23), an Executive Summary and an FCA Supervisory Readiness dry-run that rehearses the FCA visit before it happens. AI drafts, humans decide — nothing is auto-submitted.

Start free, or talk to us first.

See how RegTechPRO can simplify compliance for your MLR-registered business — and prove it in just a few clicks.

14-day free trial · Take the tour

Contact Us

Thank you!

We've received your enquiry and will be in touch shortly.