Verify Online News
Regulatory Compliance Updates: FCA, AML, Right to Work & GDPR
30 Sept 2026 · 7 Min. To Read · By Verify Online

The regulatory landscape for identity verification and employment checks in the UK is evolving rapidly. Firms must balance Financial Conduct Authority (FCA) expectations, anti-money laundering (AML) obligations, right to work checks and GDPR data protection requirements. This update summarises recent developments and gives practical steps HR and compliance teams can apply immediately.
Key regulatory developments to note
FCA compliance: The FCA continues to emphasise robust customer due diligence (CDD), transaction monitoring and strong governance for firms in regulated sectors. Expect ongoing scrutiny of onboarding processes, supplier oversight and the use of technology such as biometric verification. High-risk sectors — including crypto-related services and certain payment firms — remain under particular focus.
AML updates: The UK’s Money Laundering Regulations and supervisory expectations have tightened, with firms required to maintain risk-based controls, enhanced due diligence for higher-risk customers and clear audit trails for identity checks. Firms should review AML policies annually and ensure staff recognise red flags in both onboarding and ongoing monitoring.
Right to Work: Digital right to work checks are widely adopted, but employers must follow Home Office guidance and retain evidence. The government continues to update guidance documents and practical identity-proofing standards — including approaches aligned with GPG45. Employers who rely on digital checks should document procedures and confirm they meet statutory defence requirements.
GDPR and data protection: The ICO has renewed focus on data minimisation, lawful basis and retention. Identity verification processes generate sensitive personal ensure you have a lawful basis (often legitimate interests, contract or legal obligation), that you conduct Data Protection Impact Assessments (DPIAs) where appropriate, and that retention schedules are documented.
Practical advice for HR and compliance teams
Keeping up with multiple regulators can feel daunting. The following steps will help create a defensible, efficient compliance programme.
- Review and document policies: Update AML, right to work and data protection policies. Make clear who is responsible for decision-making, escalation and record-keeping.
- Adopt a risk-based approach: Apply enhanced checks for higher-risk roles or customers (e.g. senior finance positions, PEPs, or high-value transactions). Proportionate controls reduce both risk and operational friction.
- Follow Government identity-proofing guidance: Use established standards for robust identity verification and supplier assessments — for practical steps consult our guidance on GPG45 identity proofing for UK businesses.
- Standardise right to work procedures: Ensure all recruiters and hiring managers use consistent checks, keep evidence for the statutory retention period and train staff on acceptable documents. Our employer-facing guidance on right to work checks highlights common pitfalls for UK employers.
- Embed GDPR into operational design: Limit the personal data collected to what is necessary, define retention periods, and implement secure transmission and storage. Where you use third-party ID verification providers, check Data Processing Agreements and international transfer mechanisms if applicable.
- Train frontline staff: Practical, scenario-based training helps staff recognise forged documents, inconsistent evidence and social engineering attempts. Maintain a log of trained personnel and refresh annually.
- Test suppliers and tech: Perform due diligence on identity vendors (accuracy, fraud detection rates, resilience). Conduct periodic audits of automated systems and maintain human oversight where algorithmic decisions influence eligibility or sanction screening.
Real-world examples
Example 1 — Fintech onboarding: A challenger payment firm updated its CDD to include enhanced documentary checks and a short video passphrase step after the FCA raised concerns about synthetic identity fraud. Result: fewer false positives, stronger audit trails and a demonstrable risk-based approach during FCA review.
Example 2 — Recruitment agency: A mid-sized recruitment agency relied on photo-copies of documents for right to work checks and did not retain consistent records. After a compliance inspection, gaps were identified and penalties applied. Following the inspection the agency introduced standardised digital checks, staff training and centralised record retention — significantly improving compliance and reducing operational risk.
Checklist for immediate action
- Map all identity and right to work processes and the data flows they create.
- Confirm the lawful basis for processing identity data and document DPIAs where necessary.
- Update AML and CDD policies to reflect recent supervisory expectations and maintain an annual review schedule.
- Train hiring managers on acceptable documents, digital checks and record retention requirements.
- Audit third-party ID verification providers for performance, data protection and contractual safeguards.
- Maintain an incident response plan for data breaches and identity fraud cases, including notification triggers for the ICO and relevant regulators.
Conclusion
Regulatory expectations across FCA compliance, AML, right to work and GDPR increasingly intersect. Effective compliance requires joined-up processes, clear governance and careful vendor selection. By adopting a risk-based approach, applying practical identity-proofing measures and keeping robust records, HR and compliance teams can reduce risk while maintaining a smooth candidate and customer experience. If you need a starting point, align your identity-proofing practices with recognised guidance and ensure right to work procedures are consistent across your organisation.
For further reading on operational best practice, see our detailed guidance on identity-proofing and employer right to work checks linked above.