Published · Agora Consulting Solutions
The Joint Money Laundering Steering Group's 2026 guidance update is the most significant refresh in several cycles. It folds in lessons from the post-ECCTA Companies House regime, the FCA's recent thematic findings on financial crime controls, and the operational realities firms have surfaced since the 2022 round. For most UK regulated firms the direction is familiar; the bar has simply moved.
This is a practical checklist of what we recommend MLROs, Heads of Financial Crime, and programme owners do over the next two quarters. It assumes you already have an established AML programme and is intentionally focused on the deltas, not first principles.
1. Refresh the enterprise-wide risk assessment
JMLSG continues to push firms towards documented, evidenced risk assessment that ties directly to controls. If your last EWRA is more than 12 months old, or pre-dates the Companies House identity verification rollout, refresh it now. Pay particular attention to the customer-risk dimension for legal entities - the 2026 guidance expects firms to articulate how they handle layered ownership structures, foreign-owned UK entities, and entities that fall outside ECCTA's verification regime.
2. Re-baseline beneficial ownership verification
Post-ECCTA, "we checked Companies House" is no longer a defensible verification standard on its own. The guidance reinforces a two-tier expectation: confirm the registered information, then independently verify the natural persons behind it. The Ownership and Identity Verification modules of the Due Diligence Platform are built to that standard - recursive ownership resolution from Companies House, with UBOs verified through document forensics, liveness and biometric match. The capability is described in detail on the customer due diligence software page, and for existing files on the KYC remediation software page.
3. Tune transaction monitoring to typology, not threshold
The 2026 update is more explicit that rule-based monitoring without typology mapping is insufficient. Firms should be able to demonstrate, for each scenario, which typology it targets, why the threshold is set where it is, and what the false-positive and true-positive rates look like in production. If you cannot evidence that mapping, prioritise a tuning cycle now rather than at the next supervisory visit.
4. SAR quality and timeliness
The NCA's UKFIU has been clear about the quality issues it sees in submitted SARs. JMLSG 2026 mirrors that emphasis. Run a sample-based quality review of the last 12 months of submissions against the UKFIU glossary codes and the standard quality criteria. Where reviewer interpretation drives variability, document the decision framework and retrain.
5. Periodic review cadence and trigger events
The expectation that periodic reviews are risk-based, not calendar-based, is now firm. If you still run a flat annual cadence across the book, document why and start the move to trigger-event-driven review for medium and high risk customers. Backlogs in this area are the single most common finding we see in remediation engagements.
6. Governance evidence and management information
Finally, the guidance continues to push on the evidence of governance - board and committee packs that show the financial crime programme is genuinely overseen, not just reported on. Refresh your MI suite so it answers three questions for each meeting: what is the residual risk picture, what has changed since last time, and what are we doing about it.
How Agora helps
Agora builds and operates the Due Diligence Platform - a fourteen-module Customer Due Diligence engine that addresses every item in this checklist by design: versioned risk assessment, post-ECCTA ownership resolution, typology-tuned transaction review, AI-drafted outreach, an immutable audit log, and an in-platform AI SME trained on MLR 2017, the FCA Handbook and JMLSG. Live in five working days; SaaS subscription only.
To scope a JMLSG 2026 readiness review, email enquiries@agoraconsulting.ai or use the enquiry form.