Verify a new client's identity in seconds, and keep onboarding moving
Accountants, tax advisers and bookkeepers who provide services by way of business are relevant persons under the Money Laundering Regulations 2017. You owe client due diligence on every new engagement: identify and verify the client from a reliable, independent source. You are supervised by a professional body or HMRC, and you keep records for five years.
For most firms the rule is clear enough. The friction shows up at the moment a new client sits at their kitchen table trying to prove who they are before you can start work. That client might be a newly appointed director, or a sole trader who set up last month. The identity check that should take seconds stalls, the engagement letter waits, and a partner ends up chasing a passport scan by email.
Yes. Firms and sole practitioners that provide accountancy or tax services to others by way of business are relevant persons under Regulation 8 of the Money Laundering Regulations 2017. The obligation attaches to the service rather than the job title, so the regime reaches beyond chartered accountants to bookkeepers, payroll agents and tax consultants.
An external accountant is a firm or sole practitioner who, by way of business, provides accountancy services to other people, when providing those services. A tax adviser is defined the same way for aid, assistance or advice on another person's tax affairs. HMRC treats bookkeeping, accounts preparation, tax advice and tax return assistance as covered work. Delivering it through software or automation does not remove the duty.
Every relevant firm has a single AML supervisor: a professional body such as ICAEW, ACCA or AAT, or HMRC where no professional body supervises the firm. Professional body supervisors are overseen by the Office for Professional Body Anti-Money Laundering Supervision, which sits within the FCA.
One distinction is worth keeping straight. AML supervision is not the same as being FCA regulated. Most accountancy firms are supervised for money laundering by a professional body or HMRC, which is separate from FCA authorisation of a regulated financial activity.
|
Question |
Answer |
|
Are you in scope? |
Yes, if you provide accountancy or tax services to others by way of business (external accountant, tax adviser, auditor, bookkeeper, payroll agent). Relevant person under MLR 2017 Reg 8. |
|
Who supervises you? |
A professional body (ICAEW, ACCA, AAT, CIMA, CIOT among others), or HMRC where no professional body does. Professional body supervisors are overseen by OPBAS. |
|
Must you register? |
If no professional body supervises you, register with HMRC and renew every 12 months. |
|
CDD at onboarding? |
Identify and verify the client from a reliable source independent of the client, and understand the purpose and nature of the engagement (Reg 28). |
|
Ongoing? |
Ongoing monitoring and keeping CDD current throughout the relationship (Reg 28(11)). |
|
Records? |
Keep CDD and transaction records for five years after the relationship ends (Reg 40). |
Yes. When you establish a business relationship with a client, you must apply customer due diligence before or during the engagement. The identity component, knowing who the client is, is the part most firms feel at onboarding. For a limited company that means the client and the people behind it. For an individual or sole trader it means confirming they are who they say they are.
Regulation 28 requires you to identify the client, verify their identity from a reliable source that is independent of them, and assess the purpose and intended nature of the engagement. Verification can be done electronically. Confirming identity on the basis of information from a reliable, independent source is exactly what electronic matching does.
In practice, electronic identity verification works to an industry convention known as "2+2": matching at least two identity attributes, such as name, address and date of birth, against at least two independent, reliable data sources. The convention is not written into the regulations. It is the practical benchmark that HMRC and sector guidance point firms towards for meeting the reliable-independent-source test.
Five years. Regulation 40 requires you to keep the CDD documents and information, plus supporting records, for five years from the end of the business relationship or the completion of an occasional transaction. After that, personal data should be deleted unless you have another lawful basis to retain it. A clean, timestamped record of how each client was verified is part of the evidence a supervisor will expect to see.
Most new clients are straightforward, the sort you can find across several datasets on the first look. The problem cases are the thin-file ones: a company formed last month, a director new to the UK, someone with almost no footprint at a single credit reference agency. A check that relies on one data source fails them, and a genuine client gets stuck in manual review while a partner tracks down documents.
Matching a client across several independent sources at once recovers many of those people on the first pass. Bank data, mobile network records, insurance and public sector data hold a footprint that credit reference agency data alone can miss. The routine clients clear in seconds, and only the true exceptions reach a human. In one Tier-1 gaming operator's data, running previously failed customers through a wider multi-source check recovered a match on a little over half of them, an onboarding uplift of around 15%. That is a gambling result and the numbers will differ for accountancy, but the mechanism is the same wherever thin-file clients slow a small team down.
The experience for the client is the point that gets overlooked. Instead of finding a passport, photographing it and waiting, they confirm their identity in a few seconds and the engagement moves on.
KYC Match, from OneID, a digital verification services provider certified under the UK's Digital Verification Services Trust Framework, performs the identity-matching step. It returns a configurable count of matches across independent data sources, going beyond credit reference agency data, and runs as a real-time API or a batch check across a list of clients.
It does one job well, and it does not do the rest. The firm keeps its business-wide and client risk assessment, its PEP and sanctions screening, source of funds where required, ongoing monitoring, suspicious activity reporting to the National Crime Agency, and the five-year record-keeping. Identity matching supports the "know who you are dealing with" step. It does not discharge the wider programme.
You can run 1,000 client records through KYC Match for free, to compare the results against your existing provider, by contacting OneID. It is the fastest way to see how many of the clients your current check fails would actually pass on a wider, multi-source match.
Are accountants covered by the Money Laundering Regulations? Yes. Accountancy and tax service providers who work by way of business are relevant persons under Regulation 8 of the MLRs 2017, with client due diligence, ongoing monitoring and record-keeping duties.
Do accountants need to do KYC / ID checks on clients? Yes. Regulation 28 requires you to identify and verify each client from a reliable source independent of them at onboarding, and to keep that due diligence current through the relationship.
Who is my AML supervisor if I'm not a member of a professional body? HMRC. Firms not supervised by a professional body must register with HMRC for anti-money laundering supervision and renew that registration every 12 months.
Do bookkeepers and payroll providers need AML supervision? Yes, where they provide accountancy or tax services to others by way of business. The duty attaches to the service rather than the professional title, so bookkeepers and payroll agents are commonly in scope.
Can I verify a client's identity electronically instead of a passport and utility bill? Yes. Electronic verification is accepted, and for many clients it is faster and harder to fake than a document upload. Matching a client's details across independent data sources confirms identity without asking for paperwork.
Does electronic ID verification meet the MLR 2017 requirement? Regulation 28 requires verification from a reliable source that is independent of the client. Electronic matching meets this, and a certified digital verification services provider is such a source for the identity step.
What records do I need to keep, and for how long? Keep the CDD information and supporting records for five years from the end of the business relationship, under Regulation 40, then delete personal data unless you have another lawful basis to hold it.