UK accountants and solicitors are "relevant persons" under the Money Laundering Regulations 2017 and must perform Customer Due Diligence (CDD) on every client before starting work. This means identifying the client, verifying that identity with reliable evidence, and identifying beneficial owners for corporate clients.
This guide covers the practical mechanics — what documents to collect, how to verify them, when Enhanced Due Diligence is needed, and what supervisors look for on inspection.
The three depths of due diligence
Simplified Due Diligence (SDD)
For low-risk clients only. Reduced verification — but not no verification. The risk assessment must explicitly justify SDD for each client.
Typical SDD clients: UK-listed companies, UK public authorities, certain regulated financial firms.
Standard Customer Due Diligence (CDD)
The default for most clients. Required for:
- Establishing a business relationship.
- Occasional transactions over €15,000 (or below if linked).
- Suspicion of money laundering or terrorist financing.
- Doubts about previously obtained identity evidence.
Enhanced Due Diligence (EDD)
Mandatory in higher-risk situations:
- Politically Exposed Persons (PEPs) and their family / associates.
- Clients established in high-risk third countries.
- Any client where standard CDD reveals concerns.
- Complex or unusually large transactions with no clear economic purpose.
What standard CDD requires
For an individual client:
- Identification: full legal name, residential address, date of birth.
- Verification: independent source confirming identity. Acceptable sources include passport / driving licence / national ID card AND a separate proof of address (utility bill, bank statement, council tax bill, all dated within the last 3 months).
- Source of funds (where relevant): for transactions or services involving significant value, understand where the money is coming from. Particularly important for property transactions, large company purchases, asset transfers.
For a corporate client:
- Identification: legal name, registered office, registration number, registered jurisdiction, principal place of business.
- Verification: Companies House register check, certified copy of Certificate of Incorporation if held overseas.
- Beneficial owners: identify every individual ultimately owning >25% (or with significant control). For each beneficial owner, full CDD as for an individual client.
- Officers: identify directors and senior management.
- Purpose: understand the nature and purpose of the business relationship.
For trusts:
- The settlor, trustees, named beneficiaries, classes of beneficiaries, and any person with control over the trust.
Verification standards — what counts as reliable
Documentary verification:
- Original documents examined in person, with a copy taken and certified.
- Certified copies from a regulated professional (accountant, solicitor, notary) where original cannot be examined.
- Electronic Identity Verification (IDV) — increasingly accepted using regulated providers (Onfido, GBG, Yoti, Veriff). Must use a regulated EIDV provider that meets the prescribed standards.
- Source data from independent sources — Companies House, electoral roll, credit reference agencies.
Best practice: layered approach. Use one primary document (e.g. passport) plus one corroborating piece of independent data (e.g. bank statement). Single-document verification is weak.
Beneficial ownership — going deeper
For corporate clients, the beneficial owner is the ultimate natural person, not just the immediate shareholder.
Example: Client = AlphaCo Ltd. AlphaCo''s shareholder = BravoHolding Ltd. BravoHolding''s shareholder = CharlieTrust. CharlieTrust''s settlor and primary beneficiary = an individual, Alice. Alice is the beneficial owner — and CDD must run all the way to her, not stop at BravoHolding.
The thread can be long, especially with overseas structures. PSC register data on Companies House gives the UK leg; for overseas legs, get documentary evidence (notarised certificates of incumbency, certificates of good standing, trust deeds).
When to apply Enhanced Due Diligence
EDD is required when standard CDD isn''t enough. Specific triggers:
- PEPs: any client or beneficial owner is a Politically Exposed Person, their family member, or close associate. Senior management approval required before onboarding.
- High-risk jurisdictions: clients based in countries on the FATF or UK high-risk lists (or with significant connections to those countries).
- Unusual transactions: complex, unusually large, or without clear economic / lawful purpose.
- Risk-assessment trigger: your firm-wide risk assessment flags this client category for EDD.
EDD measures typically include:
- Additional information on the source of wealth (where total assets came from, over a long period).
- Additional information on the source of funds (for the specific transaction).
- Senior management approval to onboard.
- Enhanced ongoing monitoring frequency.
- Independent verification of information provided (e.g. corroborate stated employer via LinkedIn / public records).
Ongoing monitoring
CDD is not a one-time event. Once a client is onboarded:
- Refresh CDD periodically — typical refresh cycles by risk: high risk every 12 months, medium every 2 years, low every 3-5 years.
- Monitor transactions for activity inconsistent with the known client profile.
- Refresh identification documents before they expire.
- Update CDD on trigger events — change of ownership, change of director, new line of business, change of jurisdiction.
What supervisors check on inspection
A typical AML supervisor visit (ICAEW, SRA, HMRC, etc.) examines a sample of client files for:
- CDD completed before work started.
- Identification documents on file and clearly dated.
- Risk-assessment per client, documented.
- EDD applied where required.
- Beneficial ownership thread followed to natural persons.
- Senior management approval for high-risk clients (where applicable).
- Evidence of ongoing monitoring — not just file-it-and-forget.
Findings typically include: gaps in documents, generic risk assessments not tailored to the specific client, missing refresh checks, undocumented EDD where it should apply.
Common pitfalls
- Onboarding ahead of CDD: starting work before CDD is complete. CDD must be done before, not after.
- Generic risk assessments: every client gets a "medium" rating with no thinking — supervisors flag this immediately.
- Beneficial owner stopping at the first shareholder: not going through the chain to natural persons.
- CDD records that are just document copies: no record of who verified, when, against what. The verification step is what matters.
- No refresh process: CDD done at onboarding then never updated. After 3-5 years, the file is stale.
What to do this month
- Audit your client onboarding workflow: does CDD happen before any work is done? Is the verification step recorded?
- Review your firm-wide risk assessment — is it specific to your firm, or is it a template? When was it last reviewed?
- Build a refresh schedule for existing clients. Most firms have years-old files that should have been refreshed.