What UK firms must actually check before onboarding a customer
The Money Laundering Regulations 2017 require regulated firms to know who a new customer is and prove it with evidence. That duty is customer due diligence: identifying the customer and verifying their identity using information from a reliable source that is independent of the person being checked. Electronic verification can meet that test.
For a growth team, the practical question is how quickly a genuine customer clears that check. A slow or failed identity step is where good customers abandon an application. So the commercial value of understanding these Regulations is direct: they define the minimum a firm must confirm, and they leave it free to confirm that in seconds rather than through a document upload customers give up on.
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, SI 2017/692, are the UK regulations that require regulated firms to run anti-money-laundering checks. They set out who must comply, the due diligence firms owe on their customers, and how records are kept. They apply as amended, so firms should work from the consolidated in-force version rather than the original 2017 text.
The Regulations carry the day-to-day obligations a compliance team works to, and they connect to the wider anti-money-laundering programme a regulated firm runs.
The Regulations apply to "relevant persons": businesses acting in the course of certain activities in the UK, listed under Regulation 8. The categories include credit institutions and financial institutions, auditors, insolvency practitioners, external accountants and tax advisers, independent legal professionals, trust or company service providers, estate agents and letting agents, high value dealers, casinos, art market participants, and cryptoasset exchange and custodian wallet providers.
If a business falls into one of those categories, the Regulations require it to apply customer due diligence and to register with, or be supervised by, the relevant body for its sector. A firm outside these categories has no obligation under the Regulations, though it may face equivalent duties elsewhere.
Regulation 28 sets the core customer due diligence duty. It requires a firm to identify the customer, to verify the customer's identity, and to assess the purpose and intended nature of the relationship. Where the customer is not an individual, it also requires the firm to identify beneficial owners and understand the ownership and control structure.
"Verify" has a specific meaning here. Identity has to be confirmed on the basis of documents or information obtained from a reliable source that is independent of the person whose identity is being verified. Self-declared details are not enough on their own. The evidence has to come from somewhere the customer cannot simply assert or fabricate.
A reliable independent source is data or documentation that originates outside the customer's own account of themselves and can be trusted. A passport read and validated at source qualifies. So do records held by organisations that already know the customer through a separate relationship, such as a bank, a mobile network, or a public authority.
The Regulations do not prescribe a single list of acceptable sources. They set a standard the source must reach: reliable, and independent of the individual being verified. That is what lets a firm choose evidence appropriate to its risk assessment, and it is the test any identity check has to satisfy.
Yes. The Regulations expressly recognise electronic verification. Information counts as coming from a reliable, independent source where it is obtained through an electronic identification process, provided that process is secure from fraud and misuse and gives an appropriate level of assurance that the person is who they claim to be.
HMRC guidance adds practical detail. A check drawing on a single source, or taken at a single point in time, is not normally enough on its own; a satisfactory electronic check usually draws on multiple sources. A narrow exception applies to a single government-issued source with strong cryptographic security features.
Certified digital verification carries additional weight. Government guidance published in February 2026 by HM Treasury and the Department for Science, Innovation and Technology confirms that a provider certified against the UK's Digital Verification Services Trust Framework, and listed on the government register, can be treated as a reliable and independent source for the identity step. It supplements the Regulations rather than replacing them, and the firm keeps responsibility for the rest of its programme.
For the customer, this is the difference between an application that stalls and one that clears. There is no bill to dig out and photograph. A tap, a few seconds, and the check is done.
"2+2" is an industry convention, not a statutory term. It describes matching at least two identity attributes, such as name and address, against at least two independent, reliable data sources. The phrase does not appear in the Regulations. What the Regulations require is verification from a reliable source independent of the customer, and JMLSG and HMRC guidance is the benchmark for how firms meet that in practice.
Framed correctly, 2+2 is one common way to satisfy Regulation 28 electronically. It is a guide to good practice, not a legal rule, and a firm's risk assessment may call for more.
Due diligence is not a one-off. Regulation 28 requires ongoing monitoring of the business relationship, including scrutiny of transactions for consistency with what the firm knows about the customer, and keeping customer due diligence information up to date. Perpetual KYC is the industry approach to that duty, refreshing records when something changes rather than on a fixed cycle.
On records, the Regulations require firms to retain customer due diligence records for five years, running from the end of the business relationship or the completion of an occasional transaction. That period is capped at ten years, after which personal data should be deleted unless another legal ground applies. The five-year figure is often confused with the six-year period used for tax records; for anti-money-laundering purposes it is five.
Supervision depends on the sector. The table below shows the typical supervisor for each type of relevant person.
|
Sector (relevant person, Reg 8(2)) |
Typical AML supervisor |
|
Credit institutions (banks, building societies) |
FCA |
|
Financial institutions (e-money, payments, investment) |
FCA |
|
Cryptoasset exchange / custodian wallet providers |
FCA (AML registration) |
|
Casinos |
Gambling Commission |
|
Estate agents and letting agents |
HMRC |
|
High value dealers; art market participants |
HMRC |
|
Trust or company service providers |
HMRC or a professional body |
|
Auditors, insolvency practitioners, external accountants, tax advisers |
HMRC or a professional body |
|
Independent legal professionals |
A legal professional body supervisor |
Supervision depends on sector and professional memberships, set by Regulation 7 and Schedule 1. Professional body supervisors are themselves overseen by the Office for Professional Body Anti-Money Laundering Supervision, which sits within the FCA. Casinos are supervised by the Gambling Commission, not HMRC, a distinction firms sometimes get wrong.
Identity matching handles one part of Regulation 28: confirming the customer is who they say they are, against reliable independent sources. Done well, it clears genuine customers fast and routes only real exceptions to manual review. It does not, on its own, discharge the firm's whole due diligence duty.
This is where OneID's KYC Match fits. It performs the identity-matching step, checking name, address and date of birth across independent data sources beyond credit reference agency data, and returning a configurable count of matches. Run electronically, it meets and exceeds the 2+2 convention. The tool does not carry out sanctions or politically exposed person screening, transaction monitoring, or affordability checks. Risk assessment, screening, source of funds where required, and ongoing monitoring stay with the firm.
For thin-file customers who a single credit reference source has no record of, multi-source matching often finds evidence a narrower check misses. In one Tier-1 gaming operator's data, a second pass over customers who had failed a credit-reference-only check recovered evidence on a majority of them, lifting new-customer onboarding by around 15%.
You can test that on your own book. Run 1,000 records through KYC Match for free and compare the results against your existing provider by contacting OneID.
The Money Laundering Regulations 2017 set out the preventive duties regulated firms owe, such as customer due diligence and record-keeping. The Proceeds of Crime Act 2002 sets the underlying money-laundering offences and the duty to report suspicion. The Regulations tell firms what to do; the Act defines the crimes those duties help prevent.
For regulated firms, yes. The Money Laundering Regulations 2017 require relevant persons to identify and verify customers before or during onboarding. Know-your-customer checks are how firms meet that identity duty. Businesses outside the regulated sectors are not bound by the Regulations, though other identity or fraud obligations may still apply.
Regulation 28 is the core customer due diligence provision. It requires firms to identify the customer, verify their identity from a reliable source independent of the person being verified, identify any beneficial owners, and assess the purpose of the relationship. It also requires ongoing monitoring throughout the relationship.
Five years. Regulation 40 requires firms to keep customer due diligence records for five years from the end of the business relationship or the completion of an occasional transaction. The period is capped at ten years. It is not six years, which is a separate tax-records convention.
Yes. Regulation 28(19) recognises information obtained through a secure electronic identification process as coming from a reliable, independent source. Government guidance from February 2026 confirms that a provider certified against the UK's Digital Verification Services Trust Framework can be treated as a reliable and independent source for the identity step.
Supervisors can take action ranging from civil penalties to, in serious cases, criminal sanctions, alongside directions to fix the failing. The applicable supervisor depends on the sector. Firms should treat their own supervisor's published guidance as the authority on enforcement.