Country-specific guidance Current

UK Money Laundering Regulations client due diligence overview

A practical overview of when customer due diligence is triggered.

The Money Laundering Regulations don't require the same depth of check for every client at every point -- they set out specific triggers. This guide sets out an overview of those triggers. It is general information, not legal or compliance advice.

Action plan

1 Know the core triggers for customer due diligence The Regulations name specific events that require CDD, not a blanket ongoing requirement.

Regulation 27 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 requires a relevant person to apply customer due diligence measures where they establish a business relationship, carry out an occasional transaction amounting to a transfer of funds above the relevant threshold, suspect money laundering or terrorist financing, or doubt the veracity or adequacy of documents or information previously obtained.

  • Apply CDD when establishing a new business relationship
  • Apply CDD for an occasional transaction above the relevant threshold
  • Apply CDD whenever you suspect money laundering or terrorist financing, or doubt previously obtained information

Done when: CDD is applied at each of the Regulations' specific trigger points, not only at initial onboarding

legislation.gov.uk: Money Laundering Regulations 2017, regulation 27
2 Apply the level of diligence proportionate to risk Not every client needs the same depth of check -- a risk-based approach is the general structure of the UK's AML framework, not a single fixed check.

Beyond regulation 27's trigger events, the wider Money Laundering Regulations framework is generally understood to allow for different levels of due diligence depending on risk. Match the depth of the check to your own risk assessment of the client rather than applying one standard approach to every relationship, and confirm the specific provisions your firm relies on for any reduced or enhanced approach.

  • Assess each client relationship's risk before deciding the level of due diligence
  • Confirm the specific provision your firm relies on before applying anything less than standard due diligence
  • Apply a more thorough check for higher-risk relationships

Done when: The level of due diligence applied matches the assessed risk of the client relationship

3 Keep reviewing existing client relationships, not just new ones The due diligence obligation continues throughout the relationship on a risk-based schedule.

Regulation 27 itself extends beyond initial onboarding: it requires reviewing existing customers' information on a risk-based approach, and separately when the circumstances of an existing customer relevant to their risk assessment change.

  • Review existing customers on a risk-based schedule, not only at onboarding
  • Review a customer sooner if you become aware of a change relevant to their risk profile
  • Keep a record of when and why each review took place

Done when: Existing client relationships are reviewed on a risk-based schedule, not only checked once at onboarding

See UK GDPR data subject access requests for client information