The short answer is: we don’t know yet!
The updated HMRC Trust or Company Service Provider (TCSP) guidance, published on 8 July 2026, doesn’t necessarily change the underlying law. However, it does significantly expand HMRC’s explanation of supply chains, intermediary arrangements and business relationships in a way that raises important questions for many virtual office, registered office and business address partnership models.
At Flex AML, we’ve contacted HMRC directly to seek clarification on how these updated examples should be interpreted in practice. Until that clarification is received, we believe there are several important questions that businesses operating partnership models should now be considering.
What has changed?
This isn’t the first time HMRC has referred to supply chains.
The previous Trust or Company Service Provider guidance for money laundering supervision (originally published on 16 October 2010 and last updated on 19 November 2025) already recognised that TCSPs may operate through service supplier chains and intermediary arrangements.
However, the updated guidance goes much further by providing practical examples explaining when an intermediary’s client may also become your customer.
One example states:
“You provide the use of a registered office address to an intermediary, for their clients to use, and you may have contact or dealings with their clients such as forwarding mail to their clients’ address or arranging for mail to be collected by their clients.
In this example, it is likely that a business relationship exists between you and the intermediary’s client(s). You have provided this service indirectly, but you have had direct dealings with the end user.”
Source: HMRC, Trust or Company Service Provider guidance for money laundering supervision (updated 8 July 2026). Crown copyright. Contains public sector information licensed under the Open Government Licence v3.0.
For many businesses operating virtual office partnership models, this is one of the clearest examples HMRC has published of how it may view intermediary arrangements.
The updated guidance also directs readers to HMRC’s guidance on Reliance (AMLG11410). HMRC reminds businesses that they remain responsible for customer due diligence even where reliance is placed on a third party, and that reliance should itself be considered a risk when assessing compliance.
Why is this important?
Importantly, the Money Laundering Regulations themselves have not been amended in relation to these arrangements. What has changed is HMRC’s published guidance and the level of practical detail it now provides.
Whilst guidance does not create new law, it explains how HMRC expects businesses to interpret and apply their existing legal obligations. For that reason alone, updates to regulatory guidance should not be overlooked.
If HMRC’s expectations regarding these arrangements have been clarified or expanded, the implications could extend beyond customer due diligence. Businesses may need to consider whether their contractual arrangements, partner responsibilities, staff training, internal procedures, Business Risk Assessment and AML supervisory position continue to reflect how services are actually delivered.
Why does this matter?
The virtual office industry has changed significantly over the last decade.
Many providers now work with serviced offices, coworking operators and other location partners who may advertise services, receive customer mail, verify identity before releasing mail, forward or scan mail, interact with customers visiting the premises and report unusual or suspicious activity back to the regulated provider.
Whilst these operating models have become increasingly common, the updated guidance raises legitimate questions about:
- Where does the business relationship begin?
- Has a location partner formed its own business relationship with the end customer?
- When does operational support become the provision of TCSP services?
- How should reliance be applied within these partnership arrangements?
- Are existing AML policies, procedures and risk assessments still appropriate?
At this stage, we do not believe businesses should assume their current operating model is no longer compliant. Equally, we do believe the additional detail included within the updated guidance provides sufficient reason for businesses to review how their partnership arrangements operate and whether their AML documentation accurately reflects those arrangements.
Questions every provider should now consider
The updated guidance doesn’t necessarily mean your operating model is incorrect. However, it does provide a useful opportunity to step back and ask some important questions.
- Who markets the service?
- Who enters into the contract with the customer?
- Who invoices the customer?
- Who undertakes customer due diligence?
- Who receives and handles customer mail?
- Who verifies identity before releasing mail?
- Who has day-to-day interaction with the customer?
- Who identifies and reports suspicious or unusual behaviour?
- Has anyone other than the regulated TCSP formed a business relationship with the customer?
- Does your Business Risk Assessment adequately consider your supply chain and intermediary arrangements?
- Do your AML policies and procedures accurately reflect how the service operates in practice?
- Are reliance arrangements clearly documented and appropriate for your operating model?
These questions won’t necessarily change the answer for every business, but they are worth considering in light of HMRC’s expanded guidance.
Don’t forget your Business Risk Assessment
One area that shouldn’t be overlooked is your Business Risk Assessment (BRA).
Where your operating model relies on intermediary arrangements, location partners or outsourced operational functions, consider whether those supply chain risks have been appropriately identified, assessed and documented within your existing BRA.
Similarly, review your AML policies and procedures to ensure they accurately describe how responsibilities are divided between each party, particularly where customer interaction extends beyond the regulated TCSP itself.
What should businesses do?
If your business operates through referral partners, affiliate arrangements, serviced office operators or other location partners, now is a sensible time to review:
- your customer journey;
- contractual arrangements;
- who markets the service;
- who contracts with the customer;
- who undertakes customer due diligence;
- the responsibilities of each party;
- reliance procedures;
- Business Risk Assessments; and
- AML policies and procedures.
Every operating model is different, and HMRC’s expectations will ultimately depend on the facts of each arrangement.
If, having reviewed your operating model, you remain unsure how the updated guidance applies to your circumstances, consider seeking independent professional advice or contacting HMRC AML Supervision with a clear explanation of your customer journey, contractual arrangements and the responsibilities of each party. HMRC is best placed to clarify how it interprets its published guidance in the context of your specific operating model.
Final thoughts
This article is intended to highlight questions raised by HMRC’s updated guidance rather than suggest that the law has changed or that existing partnership models are necessarily non-compliant.
As the virtual office industry has evolved, it is perhaps unsurprising that HMRC has expanded its guidance to address increasingly sophisticated partnership arrangements. Whether that represents a clarification of existing expectations or signals a broader shift in HMRC’s interpretation remains to be seen.
This isn’t about creating unnecessary concern.
Most partnership models may ultimately remain entirely appropriate. However, where HMRC expands its published guidance in an area that directly affects how your business operates, it is good compliance practice to understand why, review your arrangements and document the conclusions you reach.
Even if your review concludes that no changes are required, being able to demonstrate that you have actively considered updated regulatory guidance, assessed any potential impact and recorded your rationale is itself evidence of a mature and risk-based compliance framework.
Flex AML has contacted HMRC to seek clarification on several practical questions arising from the updated guidance. We’ll publish a further update once a response is received so businesses can better understand any practical implications for the sector.
In the meantime, reviewing your supply chain, partnership arrangements and AML documentation is a sensible and proportionate step.
Disclaimer: This article is intended as commentary on HMRC’s published guidance and should not be taken as legal or regulatory advice. The views expressed are our interpretation of the guidance at the time of writing. Every business arrangement is different and should be assessed on its own facts and circumstances. Flex AML has contacted HMRC to seek clarification on several practical questions arising from the updated guidance and will publish a further update should additional clarification be provided.

