Skip to main content

    Regulatory Deadlines Aml Ico Professional

    UK regulatory deadlines: AML, ICO, professional body

    Beyond tax and Companies House, UK regulated businesses face an annual cycle of regulatory deadlines: AML risk-assessment review (annual), ICO data protection fee renewal (annual), professional body returns (annual or as required), and sector-specific filings. Missing them attracts civil penalties, supervisor action, and reputational damage.

    5 min readBy Rajoka editorial

    Beyond tax and Companies House, UK regulated businesses face an annual cycle of regulatory deadlines: AML risk-assessment review (annual), ICO data protection fee renewal (annual), professional body returns (annual or as required), and sector-specific filings. Missing them attracts civil penalties, supervisor action, and reputational damage.

    For UK accountants, solicitors, estate agents, financial advisers, regulated tech businesses, healthcare providers, and many others, the regulatory calendar runs in parallel to the tax calendar. This guide covers the main non-tax deadlines.

    AML / Money Laundering Regulations 2017

    For UK regulated firms — accountants, solicitors, estate agents, trust and company service providers, and others — the Money Laundering Regulations require annual obligations:

    Firm-wide risk assessment review

    • Required: at least annually, plus when material risk factors change.
    • Frequency: typically once per year + ad-hoc on trigger events.
    • Evidence required: dated, documented review with rationale.

    Customer risk-assessment refresh

    • For each client: refresh per risk tier (typically annually for high-risk; less for medium / low).
    • Evidence: dated risk-assessment records per client.

    Training records

    • Annual mandatory training for staff with AML responsibilities.
    • Evidence: dated training records, attendance, content covered.

    Supervisor''s annual return (where required)

    • Some supervisors (ICAEW, ACCA, HMRC for unregulated sectors) require an annual return.
    • Deadline: varies by supervisor.

    Independent audit (some sectors)

    • Larger firms may need periodic independent AML audit.
    • Frequency: typically every 1-3 years.

    Missing AML obligations: supervisor monetary penalty, B-rating downgrade, possible removal of supervisor approval (which prevents practice).

    See our AML regulations UK guide for the full framework.

    ICO Data Protection Fee

    For UK businesses processing personal data (most are in scope):

    Annual fee renewal

    • Tier 1 (micro-organisations): £40 (direct debit) / £52 (other payment).
    • Tier 2 (small/medium): £66 (DD) / £78.
    • Tier 3 (large): £2,900.
    • Renewal: annually, on the anniversary of registration.

    ICO sends reminder letters 30 days before renewal.

    Penalty for late or missing payment

    • Fixed civil penalty: up to £4,350 for non-compliance.
    • Naming on the ICO''s public register of non-compliant organisations.

    The ICO also takes formal action under the Data Protection Act 2018 for serious or repeated breaches.

    Professional body deadlines

    Specific to each supervised profession:

    ICAEW / ACCA / ICAS / CIOT (accountants)

    • Annual return: typically by 31 January or 30 June (varies by body).
    • Continuing Professional Development (CPD): annual hours requirement (varies, often 40 hours).
    • Practice licence renewal: annual.
    • Annual member fee: due varies.

    SRA / Law Society (solicitors)

    • Practising certificate renewal: by 31 October each year.
    • Compensation Fund contribution: annual.
    • CPD: by 31 October (now competency-based, not hours-based).
    • Annual returns: per firm''s registration cycle.

    FCA / PRA (financial services)

    • GABRIEL submissions: monthly or quarterly per firm.
    • Annual report: typically by 31 January.
    • Annual fees: invoiced.
    • AR (Approved Person) updates: as needed.

    CILEx, RICS, IFA, etc.

    • Each professional body has its own annual cycle. Members should diarise their specific dates.

    For all UK businesses (not just regulated):

    Breach notification to ICO

    • If a personal data breach is likely to result in a risk to individuals'' rights and freedoms.
    • Deadline: within 72 hours of becoming aware.
    • Method: online via the ICO portal.

    Data subject access requests

    • Standard response deadline: 30 days from receipt.
    • Extended to 90 days possible for complex requests, with notice within the first 30 days.
    • Refreshed when needed; review consents periodically.

    Sector-specific deadlines

    Health and Social Care (CQC)

    • Annual statement of providers'' duties.
    • Provider information return.
    • Notifications of significant changes within 28 days.

    Financial Reporting Council (FRC)

    • For audited public-interest entities and certain large companies.

    Companies House (additional to accounts and confirmation statement)

    • PSC changes within 14 days.
    • Director changes within 14 days.
    • Charge / mortgage registration within 21 days.

    Charity Commission

    • Annual return: by 10 months after financial year-end.
    • Trustee changes within 28 days.
    • Significant donor disclosures.

    MHRA, Ofcom, Ofgem, etc.

    • Each sector regulator has its own annual cycle.

    Right to Work check follow-ups

    For UK employers of workers with time-limited permission:

    • Re-check on or before the worker''s permission expiry date.
    • Diarise per worker in HR.
    • Penalty for failure: up to £45-£60K per illegal worker (strict liability).

    See our Right to Work checks guide.

    How to actually keep track

    Compliance calendar

    Build a single document (spreadsheet, Notion, or compliance software) listing every regulatory deadline with:

    • The deadline.
    • The owner (named person).
    • Reminders at 60, 30, and 7 days before.
    • Evidence required.
    • Where the evidence is filed.

    Compliance software

    For multi-deadline regulated businesses, specialist compliance software (Vanta, Drata, Tugboat, Sparta) gives shared calendars, automated reminders, evidence repositories.

    Annual all-hands

    Once a year, walk through the compliance calendar with the relevant team. Identifies anything missed, anything new, anything that needs reassignment.

    What to do this month

    • Build (or refresh) a compliance calendar covering every non-tax regulatory deadline you face.
    • Assign each deadline to a named person with backup.
    • Set 60-day reminders for the next 12 months of deadlines.
    • If you''re a regulated firm and don''t have a documented AML risk assessment in the last 12 months: that''s a finding waiting to happen on supervisor inspection. Fix it this quarter.

    Rajoka Insights

    Operating notes from a UK house of brands.

    A weekly note from Mehmood. House-of-brands strategy, UK operating, and what's working across the portfolio. No fluff.

    Delivered via Substack. Unsubscribe anytime.

    Explore Rajoka

    A family of firms. One operating standard.

    Pick a brand, pick a stage, or tell us your problem.