Profession-specific playbook Current

GDPR and AML operating playbook for EU accounting and audit firms

Two EU regimes apply to the same client file at once; here's how they work together.

An EU accounting or audit firm is usually both a GDPR data controller and an AML obliged entity for the same client relationship. This playbook sets out how the core obligations from each fit together. It is general information, not legal or compliance advice.

Action plan

1 Recognise your firm's dual status: AML obliged entity and GDPR data controller These are two separate legal statuses, with two separate sets of obligations, on the same client relationship.

The EU's Anti-Money Laundering Regulation names auditors, external accountants, and tax advisors as obliged entities in their own right. Separately, GDPR treats your firm as the data controller for the personal data of clients, beneficial owners, and related individuals you collect and hold. Build your compliance process around both statuses applying at once, rather than treating AML and privacy as two unrelated workstreams.

  • Confirm your firm's AML obliged-entity status against the Regulation's own list
  • Confirm your firm's GDPR data-controller status for each category of personal data it holds
  • Design due diligence and privacy processes to run together, not as separate, disconnected tracks

Done when: The firm's dual AML obliged-entity and GDPR data-controller status is documented and reflected in its process design

See which professional-services firms are obliged entities under EU AML rules
2 Confirm your specific national AML supervisor and registration requirement This is set by your member state, not by the EU rulebook directly, and it varies by profession too.

Because the EU's AML directive layer leaves supervision and registration detail to each member state, confirm which specific national authority supervises your firm's profession, and what registration or notification that authority expects. Don't assume the same supervisor, or the same registration process, applies to a different profession or a different member state, even within your own firm's group.

  • Identify the specific national authority that supervises your firm's profession for AML purposes
  • Confirm any registration or notification that authority requires
  • Re-check this separately for each member state your firm actually operates in

Done when: The firm's specific national AML supervisor and registration status are confirmed for each member state it operates in

See what's EU-wide and what your member state sets independently
3 Build evidence, retention, and security into one connected workflow AML retention, GDPR security, and GDPR minimisation are three requirements on the same underlying records.

Due diligence evidence collected for AML purposes is also personal data subject to GDPR's security-of-processing obligation and storage-limitation principle. Run collection, security, and scheduled deletion as one connected workflow against the same client record, so evidence gathered for AML due diligence is also stored securely under Article 32 and deleted on schedule once its retention floor expires, rather than lingering indefinitely under a different, unstated purpose.

  • Apply Article 32 security measures to due diligence evidence as a matter of course
  • Track each record's applicable AML retention floor from the point it's collected
  • Delete records on schedule once that floor expires, rather than retaining them by default

Done when: Due diligence evidence collection, security, and scheduled deletion run as one connected workflow, not three disconnected processes

See setting a record-retention schedule for AML and GDPR evidence

Designated services

Customer due diligence

Capturing customer due diligence evidence at the right trigger point

Capturing identity and due diligence evidence at the EU's defined trigger points, business relationship, threshold transaction, entity creation involvement, or suspicion, is worth building as a standard step rather than a one-off task per engagement.

  • cdd
  • designated-trigger-check

Beneficial ownership

Identifying and cross-checking beneficial owners for corporate and trust clients

Identifying beneficial owners against the EU's 25% and control-based standard, then cross-checking that against the client's home member state's own central register, is a recurring service worth standardising rather than repeating from scratch for each client.

  • beneficial-ownership
  • register-check

GDPR

Handling client data subject access requests within the one-month clock

Recognising and responding to a client's GDPR access request within the one-month clock, with a genuine reason recorded for any extension, is worth a standard intake and response process rather than an ad hoc reply each time.

  • gdpr
  • access-request

Retention and security

Retaining and then securely deleting due diligence evidence on schedule

Applying the applicable AML retention floor, keeping the evidence secure under GDPR Article 32 while it's held, and then actually deleting it on schedule is a service worth running as one lifecycle rather than three separate, disconnected steps.

  • retention
  • deletion
  • security