Prepare a TCSP AML working pack

Create a business-wide risk assessment, procedures, customer and arrangement records, due-diligence checks and governance evidence from the TCSP facts entered.

UKFinancial crime
Free to useRun the complete browser-local toolAbout 15 minutes9 working filesStart this tool

Tool available. Run the complete browser-local workflow and inspect the result. Paid export is not active. Entries and files stay in this browser. Sources reviewed 31 July 2026.

Inspect a real output

Built from fictional sample information using the same exporter as the tool.

TCSP risk-assessment sample

What’s included

Set governance and risk

Orient the owner, document the business-wide risk assessment and prepare the operating procedures.

  • Start Here PDF
  • Business-wide risk assessment DOCX
  • AML procedures DOCX

Work customer decisions

Keep customer or matter risk, due diligence checks and suspicion decisions in structured records.

  • Customer and matter risk register XLSX
  • CDD and EDD checklist PDF
  • Suspicion decision log XLSX

Manage evidence and actions

Retain appointments, training, remediation actions and the dated source basis behind the pack.

  • Governance and training register XLSX
  • Action plan CSV
  • Sources and assumptions record
View every output and format
  • Start Here PDF
  • Business-wide risk assessment DOCX
  • AML procedures DOCX
  • Customer and matter risk register XLSX
  • CDD and EDD checklist PDF
  • Governance and training register XLSX
  • Suspicion decision log XLSX
  • Action plan CSV
  • Sources and assumptions record

Who this tool is for

UK trust or company service provider owners, AML leads and operations teams. Prepare a consistent first working set of AML records for the services, structures, customers, jurisdictions and delivery model of the business.

Supported use

  • A UK trust or company service provider using the supported sector route
  • Recorded formation, registered-office, nominee or trust-related services and their operating context
  • Six TCSP risk prompts with human ratings, evidence and controls

Have ready

  • Organisation, supervisor, responsible roles, approver and review date
  • The regulated activities and operating facts for the trust or company service provider business
  • Locations, customer types, geographic exposure, delivery channels and scope assumptions
  • A responsible person’s rating, evidence and reasoning for every sector risk prompt

Needs separate review

  • Whether a service or arrangement falls within scope
  • Customer, beneficial-owner or arrangement acceptance decisions
  • Suspicion, reporting and final approval decisions

How it works

  1. Record the business routeEnter the organisation, supervisor, responsible roles, activities and approval details.
  2. Describe the operating contextRecord the actual footprint, customers, services, channels and trust or company service provider facts.
  3. Rate and evidence each riskA responsible person selects each rating and records the business evidence, controls, gaps and reasoning.
  4. Download the working packReview unresolved fields, then create the nine editable and evidence files in the browser.

Where does this task apply?

Choose the guidance set this tool should use. The interface and outputs stay in English.

Available guidance sets

Using United Kingdom guidance.

Build a source-bounded AML working pack for the actual business.

Enter the operating facts once. The pack creates editable records for assessment, controls, customer work, governance, training, suspicion decisions and remediation.

Browser-localBusiness facts and risk notes stay on this device.
1

Record the business and governance route

Record HMRC or the applicable professional body supervisor and every TCSP activity confirmed by the business.

2

Describe the operating context

These facts feed the risk-assessment draft. Use specific business language rather than generic statements.

Activities in this pack required

Choose every regulated activity covered by this working pack.

Trust or company services operating facts

These answers make the assessment and procedures specific to this business. Record “Not yet confirmed” where the owner still needs to investigate.

3

Make each sector risk explicit

The level is chosen by the responsible person. A rating without supporting business evidence remains incomplete.

6risk prompts
0rated
0with evidence
Opaque ownership structures

Could layers, nominees, trusts or multiple jurisdictions obscure control or purpose?

  • Map ownership and control
  • Identify settlors, trustees, protectors and beneficiaries where relevant
  • Escalate unexplained complexity
Off-the-shelf firms

Does the business sell firms that meet the definition inserted by the 2026 amendment?

  • Record the exact service and scope decision
  • Apply onboarding before sale where required
  • Review changes to officers, owners and intended activity
Nominee and officer services

Could an appointment obscure who directs or benefits from an entity?

  • Record authority and instructions
  • Assess purpose and expected activity
  • Monitor unexplained changes or third-party control
Address and virtual-office services

Could the address be used without a genuine operating connection or for multiple opaque entities?

  • Verify the customer and purpose
  • Monitor mail, activity and connected entities
  • Escalate false or inconsistent business information
Cross-border structures

Do formation, ownership, assets or controllers involve higher-risk or sanctioned jurisdictions?

  • Use dated country-risk sources
  • Record the business rationale
  • Apply additional measures where the risk requires them
Rapid structural change

Are ownership, directors, addresses or activities changing without a clear reason?

  • Set event-driven review triggers
  • Record requested and completed changes
  • Reassess customer and service risk
4

Download the working pack

Every document carries the rule-pack version or source register. The editable files remain drafts until authorised people tailor and approve them.

01
Start HereHow to tailor, approve and store the pack
02
Business-wide risk assessmentDOCX with business context and sector risks
03
AML policies, controls and proceduresDOCX with governance and operating procedures
04
Customer and matter risk registerXLSX working register and sector prompts
05
CDD and EDD checklistCited PDF decision-support checklist
06
Governance and training registerXLSX appointments and learning record
07
Suspicion decision logRestricted-access XLSX template
08
Action planCSV remediation queue with owner and target date
09
Sources and assumptionsDated JSON manifest with rule-pack version
Nine-file trust or company services packDraft with 6 unrated risks, 6 evidence gaps and no senior approver recorded.

Human decisions remain visible. The pack never assigns risk, confirms scope, approves a customer, determines suspicion or submits a report.

What this tool checks

The scope stays narrow so the result is clear and reproducible.

  • Uses the entered business facts, selected services, governance roles and risk decisions once across the pack.
  • Includes six trust or company service provider risk prompts with editable evidence and control records.
  • Keeps scope, customer acceptance, suspicion decisions and final approval as named human responsibilities.

From official material to a working record

Official material sets the basis

Official UK material describes the AML obligations and sector context relevant to trust or company service provider businesses.

The tool prepares the operational record

The starter pack applies the recorded business facts consistently across the risk assessment, procedures, registers, checklists and action record.

Official sources stay visible

Each supported check shows its jurisdiction, source title, source version and review date beside the result. Unsupported cases are rejected rather than estimated.

View this product's official sources

Questions before you use the tool

Scope, files, evidence and browser-local handling.

Does the pack decide whether a TCSP service is in scope?

No. The provider records the services, structures and scope assumptions. A responsible person must resolve whether a particular service or arrangement falls within scope.

Does the tool assign the risk ratings?

No. A responsible person chooses each rating and records the business evidence and reasoning behind it.

Are business and customer details uploaded?

No. Entered business facts, risk notes and generated working files remain in this browser.

Are the documents ready to adopt without review?

No. They are working drafts. Authorised people must resolve unfinished fields, tailor the content and approve it before use.

Prepare the trust or company service provider working pack

Record the actual business, make each risk decision explicit and review every unfinished field before export.

Open the TCSP AML pack