Country-specific guidance Current
Storing client identity evidence securely
Record-keeping and data security sit on two different, overlapping rules.
Keeping identity evidence isn't only about not losing it, it's a specific record-keeping obligation with its own security expectations layered on top. This guide sets out a practical approach. It is general information, not legal, security, or compliance advice.
Action plan
1 Keep a copy of the documents and information obtained for due diligence Regulation 40 requires the evidence itself to be kept, not just a note that a check happened.
Regulation 40 of the Money Laundering Regulations 2017 requires a relevant person to keep a copy of the documents and information obtained to satisfy customer due diligence requirements. Keep the actual documents or copies, not only a summary note that identity was checked, since a summary alone does not meet this requirement.
- Retain a copy of every document and piece of information obtained for due diligence
- Don't rely on a summary note in place of the underlying documents
- Keep due diligence evidence together, rather than scattered across separate systems
Done when: A copy of the documents and information obtained for due diligence is retained, not just a summary
legislation.gov.uk: Money Laundering Regulations 2017, regulation 402 Limit access and apply appropriate security measures Identity documents are personal data in their own right, with the UK GDPR's own security expectations attached.
Identity evidence is personal data, so it also falls under the UK GDPR's security principle, which requires appropriate technical and organisational measures against unauthorised access, loss, or damage. ICO guidance frames this as covering the whole way personal data is processed, not only how it's stored, with the measures applied expected to be proportionate to risk. Limit who in your firm can access stored identity documents, and apply security measures proportionate to how sensitive that evidence is.
- Limit access to stored identity documents to staff who genuinely need it
- Apply security measures proportionate to the sensitivity of identity evidence
- Review access periodically, including after staff changes
Done when: Access to stored identity documents is limited and proportionate security measures are applied
ICO: a guide to data security3 Keep due diligence evidence separate from general client correspondence A document buried in an email thread is harder to retain, retrieve, and secure correctly.
Store due diligence evidence in a dedicated, access-controlled record rather than leaving it inside general email correspondence, so it can be retained for the right period, retrieved on request, and secured to a consistent standard rather than however the original message happened to be handled.
- Move identity evidence out of general email into a dedicated, access-controlled record
- Apply the same retention and security standard to every client's evidence
- Make sure evidence can be retrieved on request, not only located by chance
Done when: Due diligence evidence is stored in a dedicated, access-controlled record separate from general correspondence
See setting a record retention schedule