Brief
What are AML Trigger events your team needs to be aware of?
Trigger Events highlight instances where there may be a change in customers’ circumstances.
Michaela Clarke
Operations & Compliance Coordinator

Trigger Events highlight instances where there may be a change in customers’ circumstances.
Your firm must have systems and controls and policies and procedures in place to enable it to identify, assess, monitor, and manage the risks that defined trigger events may identify or present.
- Each trigger event may have a different level of risk associated with it.
- You must train staff to ensure they understand how to identify trigger events along with when a trigger event will result in either a refresh of due diligence information, enhanced due diligence requirements, or a suspicious activity report, and the steps required to prevent ‘tipping off’ the customer if suspicions exist.
- Records regarding the decisions and approaches taken must be maintained.
- Where there is knowledge of suspicion or reasonable grounds for knowledge or suspicion a report must be made by the MLRO or a deputy to the NCA
- All decisions and communications regarding suspicious activity reports must be clearly documented and maintained on file.
Such changes require the financial institution to revisit the due diligence undertaken on the client, understand whether the client’s risk profile has changed, and obtain further information where necessary to update the CDD:
- Trigger events can be grouped into three categories:
- Internal knowledge
- External knowledge
- Client driven
Provided below is an example table on trigger events your team should consider. This covers information received on a client, your internal knowledge, and detail from external sources.
Reach out or download our financial crime guide for more detail on understanding what are trigger events and the steps you can take to ensure you have the correct controls in place.
Need expert regulatory guidance?
Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.
Book a Free Scoping CallRelated insights
View all insights →
CACEIS and WealthTek: testing the control chain behind client-asset protection
The FCA censured CACEIS UK and recorded a £31.7m voluntary payment after failures to act on information that exposed WealthTek clients to financial-crime risk.

CP26/16 has closed: what firms should prepare for next
CP26/16 closed on 9 July 2026. Its proposals concern safekeeping delegation and the authorised fund registration function, not a new FCA data return.

In-house, outsourced or co-sourced compliance: a governance comparison
A comparison of compliance resourcing models through accountability, capability, information access, provider oversight, continuity and exit planning.