How to run KYC and customer due diligence onboarding under the Money Laundering Regulations 2017: when CDD applies, the three levels and monitoring.

Know Your Customer (KYC) checks and customer due diligence sit at the front door of every regulated firm. They are the point at which you decide who you are willing to do business with, on what terms, and how closely you intend to watch the relationship. Get onboarding right and you build a defensible record of who your customers are. Get it wrong and you risk letting money laundering or terrorist financing flow through your systems, with regulatory consequences to match.
In the UK, customer due diligence is not a matter of preference. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, usually shortened to the Money Laundering Regulations 2017 (MLR 2017), set out precisely when CDD must be applied and what those measures involve. The Financial Conduct Authority (FCA) supervises how firms meet those obligations, and the Joint Money Laundering Steering Group (JMLSG) publishes detailed industry guidance on how to do it in practice.
This guide walks through the onboarding lifecycle: the triggers that oblige you to carry out CDD, the core measures the regulations require, how the risk-based approach shapes the depth of your checks, and why the work does not stop once an account is opened. Every threshold and rule below is drawn from the primary sources.
Regulation 27 of the MLR 2017 sets out the trigger events. A relevant person must apply customer due diligence measures when it establishes a business relationship, when it carries out an occasional transaction that amounts to a transfer of funds exceeding 800 pounds, when it suspects money laundering or terrorist financing, and when it doubts the veracity or adequacy of documents or information previously obtained for identification or verification.
There is also a monetary threshold for occasional transactions that are not transfers of funds. For most relevant persons, an occasional transaction of 12,000 pounds or more triggers CDD, whether the transaction is carried out in a single operation or in several operations that appear to be linked. Different thresholds apply to specific sectors such as casinos, high value dealers, letting agents, art market participants and cryptoasset businesses, so check the figure that applies to your sector.
The suspicion and doubt triggers matter as much as the monetary ones. Even below any threshold, a suspicion of money laundering or a doubt about identity documents obliges you to carry out CDD. This is why onboarding controls and ongoing monitoring need to feed each other: a flag raised later can send you back to re-verify a customer you thought was settled.
| Trigger | What it means |
|---|---|
| Establishing a business relationship | You form an ongoing arrangement with a customer expected to have an element of duration. |
| Occasional transaction of 12,000 pounds or more | A one-off transaction at or above the threshold, whether single or several linked operations. |
| Transfer of funds exceeding 800 pounds | An occasional transfer of funds above this amount. |
| Suspicion of money laundering or terrorist financing | CDD applies regardless of any monetary threshold. |
| Doubts about documents or information | You doubt the veracity or adequacy of identity evidence obtained earlier. |
Regulation 28 defines what customer due diligence actually involves. There are three core measures. First, you must identify the customer and verify their identity on the basis of documents or information obtained from a reliable source that is independent of the customer, unless their identity is already known to and has been verified by your firm. Second, where the customer is beneficially owned by another person, you must identify the beneficial owner and take reasonable measures to verify their identity so that you are satisfied you know who the beneficial owner is. Third, you must assess, and where appropriate obtain information on, the purpose and intended nature of the business relationship or occasional transaction.
JMLSG guidance draws a helpful distinction between collecting basic identity information and verifying it. For a private individual, the basic identity typically comprises name, date of birth and residential address. Verification then confirms that this information is accurate, using evidence from a reliable and independent source such as a government-issued document or an electronic identity check. Separating the two steps keeps your process auditable and lets you tune the depth of verification to the risk presented.
Understanding the purpose and nature of the relationship is easy to skip but valuable. Knowing why a customer wants a product, how they expect to use it, and where their funds are expected to come from gives you the baseline against which later activity is judged. Without that baseline, ongoing monitoring has nothing to compare against.
For any customer that is a legal entity, the person in front of you is rarely the person who ultimately benefits. Regulation 28 requires you to look through the corporate structure to the beneficial owner. For a body corporate, regulation 5 of the MLR 2017 defines the beneficial owner as any individual who ultimately owns or controls, whether directly or indirectly, more than 25% of the shares or voting rights in the entity, or who otherwise exercises control over the entity or its management.
The 25% test is the anchor of entity due diligence, but it is a floor rather than a ceiling. Ownership can be layered through holding companies, trusts and nominee arrangements, and control can be exercised without holding shares at all. Reasonable measures to verify the beneficial owner mean tracing that ownership chain until you are satisfied you know who the natural persons behind the entity are, not simply accepting a name supplied by the customer.
Where you genuinely cannot identify a beneficial owner after exhausting all reasonable means, the regulations require you to identify the senior person responsible for managing the entity instead. Document the steps you took and why, because an examiner will want to see that you tried before you fell back.
CDD is not one size fits all. The MLR 2017 and the FCA both require a risk-based approach, meaning the depth of your checks should be proportionate to the money laundering and terrorist financing risk a customer presents. The FCA Financial Crime Guide treats applying identical measures across very different risk profiles as poor practice, and expects firms to apply more scrutiny where the risk is higher and to be able to evidence why a customer received a given rating.
Standard due diligence is the default. Simplified due diligence, under regulation 37, may be applied only where you have determined, following a risk assessment, that the relationship or transaction presents a low degree of risk. Even then you must still carry out monitoring sufficient to detect unusual or suspicious activity. Enhanced due diligence, under regulation 33, is mandatory in defined higher-risk situations, including business with people established in high-risk third countries, politically exposed persons and their family members or close associates, correspondent relationships, cases where false or stolen documents have surfaced, transactions that are unusually complex or unusually large, and any case that by its nature presents a higher risk.
A useful onboarding control is the Nasara Connect Control platform, which lets you tie a customer's risk rating to the CDD level applied and hold the evidence for each. That linkage is exactly what the FCA looks for when it asks a firm to justify why a particular level of diligence was chosen.
| CDD level | When it applies | What it typically involves |
|---|---|---|
| Simplified due diligence | Only where a risk assessment shows a low degree of ML/TF risk (regulation 37). | Reduced verification with monitoring still sufficient to detect unusual activity. |
| Standard due diligence | The default for a business relationship or qualifying occasional transaction (regulation 28). | Identify and verify the customer and beneficial owner and understand the relationship. |
| Enhanced due diligence | High-risk cases such as high-risk third countries, PEPs and complex or unusual transactions (regulation 33). | Additional information and verification, source of funds and wealth checks, and enhanced ongoing monitoring. |
An individual owning or controlling more than 25% of shares or voting rights in a body corporate is a beneficial owner who must be identified and verified.

Onboarding is the start, not the end, of due diligence. Regulation 28 requires ongoing monitoring of a business relationship. This includes scrutiny of transactions undertaken throughout the course of the relationship, including where necessary the source of funds, to ensure they are consistent with your knowledge of the customer, their business and their risk profile. It also requires you to keep the documents, data and information obtained for CDD up to date through periodic reviews.
In practice, this means transaction monitoring that references the baseline you established at onboarding, trigger-based reviews when a customer's circumstances change, and refresh cycles calibrated to risk so that higher-risk customers are reviewed more often. The FCA regards retaining outdated CDD information without periodic updates, and staff accepting customer explanations at face value without further enquiry, as poor practice.
Payment and transaction activity is often the richest source of monitoring signals. Systems that surface unusual patterns against a customer's expected profile feed straight back into whether you need to refresh CDD, escalate to enhanced measures, or consider a suspicious activity report.
A CDD process is only as strong as the evidence behind it. Regulation 40 of the MLR 2017 requires firms to keep copies of the documents and information obtained to satisfy CDD requirements, together with supporting records of transactions. The retention period is five years, beginning on the date the business relationship ends or the occasional transaction is completed.
Beyond meeting the letter of the regulation, a clean audit trail is what lets you demonstrate to a supervisor that your decisions were reasonable at the time you made them. Record what you collected, what you verified, the source you relied on, the risk rating you assigned and the reasoning behind the CDD level applied. If a customer relationship is ever questioned, that contemporaneous record is your primary defence.
Onboarding also needs governance around it. Clear escalation routes for higher-risk cases, senior management sign-off where appropriate, and a system that prevents a relationship going live before checks are complete are all features the FCA associates with stronger firms.
Effective KYC and customer due diligence onboarding comes down to a disciplined sequence: apply CDD at the right trigger points, identify and verify both the customer and the beneficial owner, understand why the relationship exists, and choose a level of diligence that matches the risk. The Money Laundering Regulations 2017 give you the fixed points, from the more than 25% beneficial ownership test to the five-year retention rule, while the FCA and JMLSG show what good execution looks like in practice.
The firms that handle this well treat onboarding and ongoing monitoring as one continuous process rather than a single gate. They build a defensible evidence trail, revisit customer risk as circumstances change, and can always explain why a given customer received the treatment they did. If you want to see how a single platform can link risk rating, CDD level and evidence in one place, you can request a demo and walk through it against your own onboarding flow.
Under regulation 27 of the Money Laundering Regulations 2017, CDD must be applied when you establish a business relationship, carry out an occasional transaction of 12,000 pounds or more, carry out a transfer of funds exceeding 800 pounds, suspect money laundering or terrorist financing, or doubt the veracity or adequacy of identity documents or information obtained earlier.
Regulation 28 requires you to identify and verify the customer using a reliable source independent of the customer, identify the beneficial owner and take reasonable measures to verify them, and assess the purpose and intended nature of the business relationship or transaction. Ongoing monitoring of the relationship is also required.
For a body corporate, regulation 5 defines a beneficial owner as any individual who ultimately owns or controls, directly or indirectly, more than 25% of the shares or voting rights, or who otherwise exercises control over the entity. Where no such person can be identified, you identify the senior managing official instead.
Standard due diligence is the default. Simplified due diligence under regulation 37 may be applied only where a risk assessment shows a low degree of risk. Enhanced due diligence under regulation 33 is mandatory in higher-risk situations such as high-risk third countries, politically exposed persons, and unusually complex or large transactions.
Regulation 28 requires scrutiny of transactions throughout the relationship, including where necessary the source of funds, to check they are consistent with your knowledge of the customer and their risk profile. It also requires keeping the documents and information obtained for CDD up to date through periodic reviews.
Regulation 40 requires firms to keep copies of the documents and information obtained for CDD, plus supporting transaction records, for five years beginning on the date the business relationship ends or the occasional transaction is completed.
Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.
Practical guides and updates for UK firms, straight to your inbox.