Verify Online News

Regulatory Compliance Updates: FCA, AML, Right to Work & GDPR

31 Aug 2026 · 6 Min. To Read · By Verify Online

Regulatory Compliance Updates: FCA, AML, Right to Work & GDPR

UK businesses and HR teams face a shifting compliance landscape. From FCA expectations on financial crime to Right to Work checks and data protection under GDPR, organisations must balance robust verification with lawful processing. This article summarises key regulatory updates, offers practical steps HR and compliance teams can apply immediately, and points to resources for deeper learning.

Why recent regulatory attention matters

Regulators in the UK have increased scrutiny across several fronts. The Financial Conduct Authority (FCA) continues to emphasise strong anti-money laundering (AML) controls and resilient customer due diligence. At the same time, immigration and employment enforcement remains active around Right to Work checks. Data protection regulators expect firms to demonstrate GDPR-compliant processing when handling identity data. These strands intersect for any business conducting identity verification during onboarding, contractor vetting or banking relationships.

Practical compliance priorities for HR and compliance teams

Focus on three core areas to reduce regulatory risk:

  • Risk-based AML and Know Your Customer (KYC) measures: Implement tiered checks that align with the customer or role risk profile. High-risk cases require enhanced verification and ongoing monitoring.
  • Right to Work certainty: Ensure robust, contemporaneous checks and retain evidence in accordance with guidance to avoid civil penalties.
  • Data minimisation and GDPR accountability: Collect only necessary identity data, document lawful bases, and maintain clear retention schedules.

Actionable steps

  • Map every identity touchpoint in your recruitment and onboarding process. Know where documents or biometric data are captured, transmitted and stored.
  • Adopt multi-layer verification: document checks, database corroboration and, where appropriate, biometric liveness checks. This layered approach is defensible to auditors and regulators.
  • Keep role-based records that show why a particular level of verification was applied and who approved exceptions.

GPG45 and identity proofing

For organisations that require high-assurance identity proofing, GPG45 sets out government-level standards. Understanding and aligning to GPG45 helps firms demonstrate rigorous identity proofing practices, especially where individuals access public services or sensitive systems. Our guide on GPG45 identity proofing explains how to integrate those standards into commercial onboarding and audit trails.

Right to Work: maintaining checks under changing circumstances

Right to Work remains an operational priority. Employers should ensure manual and digital checks are performed correctly and that evidence is retained for the statutory period. Where individuals have time-limited immigration permissions, set automated reminders for re-checks to avoid inadvertent non-compliance. For employers seeking additional guidance, see our practical summary on Right to Work compliance.

FCA compliance and AML expectations

The FCA’s approach is outcomes-focused: firms must demonstrate they understand their customer base and the associated money laundering risks. For businesses in regulated sectors (or those interacting with regulated clients), a clear AML policy, proportionate customer due diligence and effective suspicious activity reporting are essential. Real-world example: a mid-sized payments firm improved transaction monitoring and reduced false positives by introducing risk-scored onboarding tiers, enabling faster decisions for low-risk customers while allocating more resource to higher-risk cases.

GDPR: lawful processing and security

Collecting identity data triggers GDPR obligations. Practical measures include:

  • Documenting lawful bases for processing (contractual necessity, legal obligation or legitimate interests supported by balancing tests).
  • Carving out a data retention schedule tied to business need and regulatory obligations, then automating deletion where possible.
  • Ensuring secure transfer and storage, with encryption and access controls, and logging access for audit purposes.

Example: an employer moved from storing scanned passports in shared drives to an encrypted verification platform. This reduced data exposure and simplified Subject Access Request responses.

Technology, auditability and vendor management

Technology can make compliance scalable, but it must be selected and managed carefully. Conduct due diligence on identity verification vendors to confirm their AML and data protection controls, retention policies and certification standards. Maintain vendor contracts that reflect joint responsibilities under GDPR and set service levels for data deletion, breach notification and audit access.

Audit readiness checklist

  • Documented policies for AML, KYC, Right to Work and data protection.
  • Clear process maps for identity capture and retention.
  • Role-based access and an audit log for identity data.
  • Evidence of staff training and periodic policy reviews.

Final recommendations for HR and compliance leaders

Start with a gap analysis: compare current processes against FCA guidance, GPG45 where relevant, Right to Work rules and GDPR principles. Prioritise quick wins such as automating re-check reminders and centralising consent records. Invest in staff training so frontline recruiters understand what constitutes acceptable evidence and how to handle sensitive identity information. Where ambiguity exists, seek specialist legal or compliance advice rather than applying ad hoc solutions.

Regulatory change is continuous, but a structured, risk-based approach—backed by clear policies, technology that enforces controls, and documented decision-making—will keep your organisation resilient. For practical verification best practice and onboarding techniques, our broader resource on identity verification offers useful operational guidance and case studies.