Compliance

AML checks for commercial finance brokers: what to run, when, and how to evidence it

Craig PetersonPublished 11 June 2026Reviewed 4 September 20268 min read

Most commercial finance brokers know they have to run anti-money laundering checks. Fewer can say, without digging through a folder, exactly what checks they ran on a given client, when, and why they were satisfied with the result. That gap is where problems start. Not because the broker did anything wrong, but because they can't prove they did anything right.

This piece sets out what AML checks a UK commercial finance broker actually needs to run, when to run them, and how to keep evidence that stands up if a lender, your PI insurer, or the FCA asks to see it.

Why AML checks apply to brokers, not just lenders

If your firm is FCA-authorised and arranges regulated credit agreements, or if you fall within scope as an estate agency business or other relevant person under the Money Laundering Regulations, you have direct obligations of your own. It isn't simply a case of helping the lender tick a box. Many brokers sit somewhere between 'obviously in scope' and 'not sure', particularly on unregulated bridging and development deals. The safe assumption is that if you're handling client funds, introducing deals, or acting as an agent in the transaction chain, you should have a documented risk-based AML approach regardless of your exact legal status. Lenders increasingly expect it as a condition of panel membership anyway.

The FCA's financial crime guidance is the reference point for what a proportionate framework looks like. It applies risk-based judgement rather than a single fixed checklist, which gives you flexibility, but it's also where firms trip up.

What customer due diligence actually means in practice

Customer due diligence, or CDD, is the process of establishing who you're dealing with and forming a view on the money laundering risk they present. For a commercial finance deal that typically means:

  • Verifying the identity of individual applicants and, separately, of anyone who owns or controls a corporate applicant.
  • Identifying beneficial owners with significant control — usually anyone holding more than 25% of shares or voting rights.
  • Understanding the purpose and intended nature of the transaction, in enough detail to spot something that doesn't add up.
  • Checking the source of funds for any deposit, equity injection or repayment, and the source of wealth for higher-risk clients.
  • Screening for sanctions, and for politically exposed person status, using a reputable provider.

None of this is complicated on its own. What trips brokers up is inconsistency: a thorough check on a large development deal and a cursory one on a small asset finance proposal, with no documented reason for the difference. A risk-based approach means the intensity of the check should map to the risk profile of the client and deal, not to how busy your ops team happens to be that week.

Simplified, standard and enhanced due diligence

The regulations recognise three tiers. Simplified due diligence applies to lower-risk situations, a well-established UK plc with a long trading history, for example, though it's rarely appropriate to skip verification entirely. Standard due diligence is the default for most commercial deals. Enhanced due diligence is required for higher-risk factors: offshore corporate structures, cash-intensive businesses, politically exposed persons, or jurisdictions flagged as higher risk. Enhanced due diligence should mean more than running the same check twice. It should mean deeper source of funds analysis and senior sign-off before proceeding.

Who counts as a beneficial owner in practice

Beneficial ownership sounds like a technical detail until a deal has three holding companies between the borrower and the person actually putting up the equity. On a straightforward trading company, the beneficial owners are usually the named shareholders and directors. On anything involving a special purpose vehicle, a family trust, or an offshore parent, the paper trail can obscure who's actually in control. It's the broker's job to trace it, not to accept the client's summary of who owns what.

This overlaps closely with KYB, verifying the business itself as distinct from verifying the individual, and it's worth reading alongside our separate piece on KYC versus KYB checks if this is an area where your current process is thin. Getting beneficial ownership wrong doesn't just create a compliance gap. It means the person you've actually verified may not be the person who matters to the deal.

When to run checks, and when to refresh them

Checks belong at the start of the relationship, before you progress an application, not retrofitted once a lender asks for them at offer stage. That timing matters for two reasons. It stops you spending time packaging a deal for a client you can't actually onboard, and it means the audit trail shows due diligence happening because of your own process rather than because a third party chased you for it.

Checks also need refreshing. A client relationship that runs for years, a broker doing repeat deals for the same developer, say, should have periodic reviews, with the frequency driven by risk. A single transaction relationship is simpler: check once, thoroughly, at the outset.

This is where a lot of the pain in the client onboarding process actually sits. A structured onboarding flow brings those checks forward. Chasing ID documents and beneficial ownership information after a client has already had a term sheet feels natural but creates exactly the kind of gap that later looks like an afterthought.

Evidencing it properly

Running the check is half the job. The other half is keeping evidence that another person, a compliance reviewer, a lender's credit team, an FCA supervisor, can pick up cold and understand. That means storing, against each client and deal:

  • The identity documents or electronic verification results used, with dates.
  • The beneficial ownership structure as understood at the time, including any Companies House PSC register extract used to corroborate it. Our guide to using Companies House data explains how to bring that evidence into the application process.
  • Sanctions and PEP screening results, including how any hits were resolved.
  • The risk rating assigned to the client and the reasoning behind it.
  • Sign-off from whoever approved onboarding, particularly for enhanced due diligence cases.

A spreadsheet can technically hold all of this, but it degrades fast once more than one person is entering data, and it makes refresh reminders someone's manual job to remember. Most brokerages we speak to that have grown past a handful of staff have already found this out the hard way. Structured compliance workflows that attach checks and evidence directly to a client record, with automatic reminders for periodic review, remove the guesswork. The answer to 'show me your AML file for this client' becomes a few clicks, not an afternoon.

The firms that struggle at audit aren't usually the ones who skipped checks. They're the ones who ran good checks and then couldn't find the evidence six months later.

Craig Peterson, Xova

Common failure points worth checking now

A few patterns come up repeatedly when brokerages review their own AML processes:

  • Corporate applicants checked at company level but the individuals behind them never properly verified — see our companion piece on KYC vs KYB checks for where this usually goes wrong.
  • No documented rationale for why a client was rated standard rather than enhanced risk.
  • Screening run once at onboarding with no process for re-screening against updated sanctions lists.
  • Evidence held in individual staff inboxes or personal drives rather than a central, auditable record.

Any one of these is fixable quickly. The harder problem is usually cultural: AML checks get treated as a gate to clear rather than a discipline to maintain, so the file looks fine at completion and thin a year later when something needs revisiting.

Building this into how the firm actually works

Firms that get this right tend to do three things consistently. They fix the risk-rating criteria before a deal comes in, not while it's on the desk, since decisions made under deadline pressure are the ones that get challenged later. They make due diligence part of onboarding rather than a side process, so a deal genuinely cannot progress past a certain stage without checks being complete and recorded. And they treat the evidence trail as a product in its own right, something built to be read by someone outside the firm, not just useful to the person who created it.

None of that requires a large compliance team. It requires a process that doesn't rely on any one person's memory, and a system that keeps the evidence attached to the deal rather than scattered across emails and desktop folders. Bodies like the NACFB and UK Finance both publish member guidance that's worth reviewing periodically, since expectations here shift as typologies change.

Get the process and the evidence trail right once, build it into onboarding rather than bolting it on afterwards, and AML checks stop being a source of anxiety before every audit. That's a better use of everyone's time than reconstructing a file from memory.

See how Xova puts this into practice across your own pipeline.

Bring a live case and we will map it from enquiry to completion.

  • 30 minutes
  • No slide deck
  • No obligation

30 minutes, around your own deals.

Book a demo