HMRC’s updated TCSP guidance published in July 2026 has provided much-needed clarity around supply chains and intermediaries.
And there’s one point I think virtual office and TCSP operators should pay particular attention to:
Using an intermediary does not automatically remove your AML responsibilities.
An intermediary could be a broker, reseller, aggregator, platform, professional adviser or another TCSP sitting between the service provider and the end user.
For example:
Address Provider → Intermediary → End Customer
There can be perfectly legitimate commercial reasons for operating this way. But HMRC now gives much clearer guidance about what businesses within that chain need to consider.
Who is actually your customer?
This is where it gets interesting.
You may contract with the intermediary, but that doesn’t necessarily mean they are your only customer for AML purposes.
HMRC says you need to consider whether your dealings with the end user mean that you’ve also established a business relationship with them.
Take a virtual office example.
An intermediary sells use of your registered office address to its customer.
But you:
• Receive the customer’s mail
• Arrange their collections
• Forward post directly to them
• Communicate with them about the service
HMRC’s guidance indicates that in this type of scenario, it is likely that a business relationship also exists between you and the end user.
And if you’ve established that relationship, you need to consider your own CDD responsibilities.
“But the intermediary has already done the AML”
That doesn’t automatically solve it either.
There are circumstances where you can formally rely on another regulated business to carry out CDD under Regulation 39.
But reliance does not mean passing over responsibility.
You need the appropriate arrangements in place, access to the required CDD information and the ability to obtain the underlying documentation.
In simple terms:
You can’t just pass the buck.
What about the intermediary?
You also need to understand who you’re working with.
Calling a business an intermediary, broker, reseller or platform doesn’t determine its AML obligations.
What matters is what it is actually doing.
HMRC’s updated guidance says that before entering a relationship with a business or intermediary carrying out relevant regulated activity, you should take appropriate steps to check that it has the appropriate AML supervision.
So don’t just due diligence the end customer.
Due diligence the supply chain too.
Sometimes referral is simpler
This is also worth considering commercially.
An accountant, workspace platform or other partner could sell your address service directly to its customers.
But that creates questions around:
Who is the customer? Who does the CDD? Who is supervised? Who monitors them? Are you relying on the intermediary? Who holds the documents?
Sometimes a simpler model is:
Intermediary → Referral → You → Customer
They make the introduction.
You onboard the customer directly.
You complete your own CDD and risk assessment.
You manage the ongoing relationship.
That’s not to say reseller, white-label or other intermediary models are wrong. They can work extremely well.
They just need to be structured properly.
Map the AML before the commercial model
If you’re building a partnership involving TCSP services, don’t agree the commercial arrangement first and work out the AML afterwards.
Map:
Service Provider → Intermediary → End User
Then establish:
Who is providing the regulated service?
Who requires AML supervision?
Who is actually the customer?
Who completes CDD?
Is reliance being used?
Who interacts with the end user?
Who performs ongoing monitoring?
If you can’t answer those questions clearly, the model probably needs more work before launch.
HMRC’s July 2026 guidance gives significantly more clarity around supply chains, but every operating model can be different.
Where you’re unsure, explain your actual structure to HMRC and get clarification before launching it.
Because putting an intermediary between you and the end customer doesn’t automatically put your AML responsibilities there too.

