The client due-diligence register under MLR 2017

If you provide accountancy, bookkeeping or tax services by way of business, MLR 2017 requires documented client due diligence — and a register that proves it. Here is what goes in it and how long it must be kept.

Who is in scope

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 — usually shortened to MLR 2017 — apply to "relevant persons", and for the accountancy world that net is wide. You are in scope if you provide, by way of business:

  • Accountancy services — external accountancy, bookkeeping, payroll where it forms part of accountancy services, and audit.
  • Tax advice or tax compliance services, however incidental to the rest of the practice.
  • Trust or company services — forming companies, acting as or arranging registered offices, directorships or nominee arrangements.
  • Insolvency practice.

Size does not matter: a sole-practitioner bookkeeper doing self-assessment returns is as much in scope as a national firm. Nor does the label — if you do the work of an accountancy service provider, you are one, whether or not you hold a qualification. Being in scope means you must be supervised (see below) and registered before trading, hold a documented firm-wide risk assessment, have written policies, controls and procedures proportionate to the firm, train relevant staff, and — the subject of this guide — perform and record client due diligence.

What client due diligence requires

CDD under regulations 27 and 28 is not "get a copy of the passport and move on". For every client you must:

  1. Identify the client — name, and for entities the registered details — and verify that identity from documents or data from a reliable source independent of the client. Electronic verification is acceptable if the source is sufficiently reliable and independent.
  2. Identify the beneficial owners — for companies, generally anyone ultimately owning or controlling more than 25% of shares or voting rights, or otherwise exercising control; for trusts, the settlor, trustees, beneficiaries and anyone with control. Take reasonable measures to verify them, and understand the ownership and control structure well enough to explain it. You must not rely on the Companies House PSC register alone — and where you find a discrepancy between what you learn and the register, you have a duty to report it to Companies House.
  3. Understand the purpose and intended nature of the business relationship — what services, for whom, funded how.
  4. Assess the risk the client presents — considering client, geographic, product/service, transaction and delivery-channel risk factors — and record the rating and the reasoning, because the level of ongoing attention flows from it.

Timing matters: verification should be completed before the business relationship is established (with a narrow allowance to complete it as soon as practicable afterwards where risk is low and the work must not be delayed). Where you cannot complete CDD, you must not act — and you should consider whether a suspicious activity report is needed.

Enhanced and simplified due diligence

The depth of CDD scales with risk. Enhanced due diligence is mandatory in defined situations, including politically exposed persons (PEPs, their family members and known close associates), clients or transactions linked to high-risk third countries, unusually large or complex transactions with no apparent purpose, and anything your own risk assessment flags as high risk. EDD means more: senior-management approval to take the client on, additional evidence of source of funds or wealth, and closer ongoing scrutiny. Simplified due diligence may be applied where risk is demonstrably low — but it is a lighter touch, never a skipped step, and the justification must be recorded.

Ongoing monitoring — CDD is not a one-off

Regulation 28(11) requires ongoing monitoring of every business relationship: scrutinising transactions and activity to check they are consistent with what you know about the client, and keeping the CDD information itself up to date. In practice that means:

  • Periodic reviews on a cycle set by risk rating — high-risk clients reviewed more often than low-risk ones.
  • Trigger reviews when something changes: new ownership, a new service line, an unusual transaction, adverse information.
  • Refreshing expired identity evidence rather than letting it quietly age out.

This is where a proper CDD register earns its keep. A register that shows, for every client, the risk rating, what evidence was taken and when, who approved it, and the next review date turns "ongoing monitoring" from a vague aspiration into a working list. Firms run this in spreadsheets, practice-management suites or dedicated tools — FinanceIQ includes a client due-diligence register built for exactly this record-keeping job. Be clear about what any register tool is and is not, though: it organises your records and review dates; it is not a PEP or sanctions screening data service, it does not verify identity for you, and it does not submit suspicious activity reports — those judgements and filings remain the firm's own.

Record keeping — the five-year rule

Regulation 40 requires you to keep copies of the documents and information obtained for CDD, and sufficient supporting records of transactions, for five years from the end of the business relationship (or from the completion of an occasional transaction). Three practical points:

  • The clock runs from the end of the relationship, not from when the evidence was taken — a twenty-year client means holding current and superseded CDD for a long time, in an organised way.
  • Deletion is also a duty. After the five years, personal data gathered for CDD must be deleted unless another enactment requires retention or the individual has consented — indefinite hoarding breaches both MLR 2017 and UK GDPR.
  • Records must prove the process, not just the outcome. A passport copy with no note of who checked it, when, against what risk assessment, tells a supervisor very little. Record the decision trail.

Supervision and what inspectors look for

Every accountancy service provider must be supervised for AML. If you are a member of a professional body that is a listed supervisor — ICAEW, ACCA, CIOT, ATT, AAT, ICB and others — that body supervises you. If not, you must register with HMRC as your supervisor before providing services; trading unregistered is an offence. (The government has been reforming the supervision landscape, so check the current arrangements for your firm.) When supervisors inspect, the CDD register is usually the first thing on the table, and the recurring findings are consistent: firm-wide risk assessments that exist but do not match the client base; CDD done at onboarding and never revisited; beneficial owners taken on trust from the PSC register; no evidence of EDD decisions for PEPs; and records that cannot show who decided what, when. A register maintained as a living document — not reconstructed the week before a visit — answers most of those questions before they are asked.

This guide is general information, not legal, tax or compliance advice. Rules change — always check the current official guidance for your situation.

Put it into practice

FinanceIQ is built for exactly this — see what it does or book a free demo.

Keep your CDD register inspection-ready

FinanceIQ includes a client due-diligence register for the record-keeping side of MLR 2017 — your evidence trail, risk ratings and review dates in one place. It is not a screening data provider and does not submit SARs.

You own your dataUK-hostedUK GDPR compliant