This briefing is general guidance, current at the time of writing. It is not legal or professional advice. Whether, and how, the Money Laundering Regulations apply to your firm depends on your specific services and supervision, so verify anything load-bearing with your MLRO, your supervisory body, or ICAEW before you rely on it.
Anti-money-laundering is the compliance obligation that touches an accountancy firm’s website most directly, and the one firms are most likely to build against by accident. Onboarding a new client almost always begins on the website: an enquiry form, a “get started” flow, sometimes a “send us your ID and last year’s accounts” portal. Every one of those touches the customer-due-diligence duty the firm carries under the Money Laundering Regulations 2017, and most agency-built intake flows handle it in exactly the way the regulations are least comfortable with.
This briefing sets out when the duty bites, what it actually requires, the timing rule that catches firms out, how long the records must be kept, and what all of that means for the intake step on the site.
Who this applies to
Not every business that touches numbers is in scope, but most accountancy firms are. HMRC’s guidance defines an accountancy service provider broadly: it covers “auditors who carry out statutory audit work”, “accountants who provide accountancy services to clients”, “tax advisers and consultants who provide advice to clients about their tax affairs”, and “payroll agents that provide accountancy services or tax advice”, along with bookkeeping and accounts preparation.
Where a firm is supervised for anti-money-laundering matters, but not by whom. A firm supervised by a professional body such as ICAEW, ACCA, or the Chartered Institute of Taxation does not separately register with HMRC; a firm not covered by a professional-body supervisor generally must register with HMRC directly. Either way the substantive customer-due-diligence duties are the same, because they come from the regulations, not from the supervisor. If you are unsure which supervisor covers your firm, that is the first thing to establish, because the whole obligation hangs off it.
When customer due diligence is required
Regulation 27 of the Money Laundering Regulations 2017 sets out when a firm must apply customer due diligence. The core triggers are: when establishing a business relationship, when carrying out certain occasional transactions, when there is a suspicion of money laundering or terrorist financing, and when the firm doubts the veracity or adequacy of documents or information previously obtained. Regulation 27(8) adds an ongoing duty to apply due diligence to existing clients at appropriate times on a risk-sensitive basis.
For a normal accountancy engagement, the trigger that matters is the first one: taking on a new client is establishing a business relationship, and that is the point at which customer due diligence is required. There is a risk-based dimension throughout, so the depth of diligence varies with the risk, but the duty to carry it out is not itself optional for a standard onboarding.
What the due diligence must actually do
Regulation 28 sets out the measures. In its own words, a relevant person must:
“(a) identify the customer unless the identity of that customer is known to, and has been verified by, the relevant person; (b) verify the customer’s identity unless the customer’s identity has already been verified by the relevant person; and (c) assess, and where appropriate obtain information on, the purpose and intended nature of the business relationship or occasional transaction.”
Two further points from Regulation 28 matter for onboarding. First, where the customer is not an individual, or has a beneficial owner, the firm must identify the beneficial owner and take reasonable measures to verify their identity and understand the ownership and control structure. Second, verification must be done “on the basis of documents or information … obtained from a reliable source which is independent of the person whose identity is being verified.” A passport scan the client emails in is a document; the “reliable and independent source” test is what turns collecting it into verification.
Read as a practical sequence, onboarding a new client means: identify who they are, verify that from an independent source, work out who ultimately owns or controls them where they are not an individual, understand what the engagement is actually for, and keep monitoring the relationship as it runs. That is a fair amount of sensitive material, and the website is usually where the first pieces of it arrive.
The timing rule that catches firms out
Regulation 30 governs timing, and it is the rule most likely to trip up a firm that is trying to be helpful. The general position is that verification of the customer, and of any beneficial owner, must take place before the establishment of a business relationship. There is a narrow exception allowing verification to be completed during the establishment of the relationship where this is necessary not to interrupt normal business and there is little risk of money laundering, but it is genuinely narrow, and it is not a licence to start chargeable work first and verify later at leisure.
The practical version most firms adopt, and the safe default, is simple: do not begin the engagement, issue the engagement letter as a live instruction, or start chargeable work until identity verification is complete. That is a workflow rule, but it has a website consequence. The site’s “get started” flow should not imply that uploading a document is the last step before work begins, because for the firm the verification is a gate, not a formality, and the intake experience should reflect that ordering.
Five years, in a place you can name
Regulation 40 sets the record-keeping duty. A firm must keep the customer-due-diligence documents and information, and supporting records of transactions, for five years after the end of the business relationship or the completion of the occasional transaction. That retention runs alongside, and is distinct from, HMRC’s separate tax record-keeping expectations, so a firm can be holding client identity documents for years after the client has left.
This is where the website intake choice compounds. A “send us your ID” portal wired to a general cloud drive means the client’s passport, proof of address, and beneficial-ownership documents sit in that store for the whole retention period. By year three, a firm rarely knows with confidence which sub-processor can still reach a former client’s identity documents, when the store’s terms and routing have changed several times. The five-year clock does not care that the tool was convenient at signup.
The AML Intake Test
When a firm asks us to look at its onboarding, this is the sequence we run over the website’s part of it. A flow that cannot answer all five has an exposure to fix.
The AML Intake Test. (1) Ordering: does the intake flow treat identity verification as a gate before the engagement begins, not a formality after work has started? (2) Minimisation: does the public intake step collect only what it needs to open a conversation, with identity documents gathered through a proper verification channel rather than a general enquiry form? (3) Channel: do identity documents and beneficial-ownership information travel through a route the firm can account for, not a US-cloud drive or a general form embed? (4) Residency and retention: is the store for customer-due-diligence records in a place the firm can name, with the five-year Regulation 40 retention actually configured? (5) Records: does the intake feed the firm’s own AML records, so the trail exists if the supervisor asks for it? A “no” to any one of these is a finding, and channel and residency are the two firms most often fail.
The value of running it explicitly is the same as with any compliance question: it turns a vague sense that “onboarding is handled” into a documented position the firm can show its MLRO or its supervisor.
What good onboarding intake looks like
Onboarding that holds up does not make the client’s experience worse. It is the same “enquire, get proposed to, verify, begin” sequence, engineered so the sensitive material lands where the firm can account for it.
- The public intake step is light. The website enquiry collects enough to open a conversation: a name, a contact method, the general nature of the work sought. It does not ask for a passport scan, a date of birth, or a company’s beneficial-ownership breakdown at the public form.
- Verification runs through a proper channel. Identity verification is done through a channel built for it, whether a dedicated electronic identity-verification provider or a controlled secure-upload route, not through a general contact form or an email attachment.
- The records store is named and retained. Customer-due-diligence records live in a store the firm can locate, kept in-jurisdiction, with the Regulation 40 five-year retention configured rather than assumed, so a former client’s identity documents are neither lost early nor kept indefinitely.
- It is documented. The onboarding flow, and every sub-processor in it, is named in the firm’s records of processing and its AML records, so the trail is ready if the supervisor selects the firm for a review.
How a regulated-grade estate handles this
Custodiance runs an accountancy firm’s web and email estate as a managed, in-jurisdiction service, and the onboarding intake is part of it. The public enquiry step is kept light; identity verification is routed through a proper channel rather than a general form; the customer-due-diligence record store is pinned to a UK or EU region with the five-year retention configured; and every sub-processor in the intake and verification path is named in the records the firm can hand to its MLRO or its supervisor. The confidentiality view of the same intake, and why a US-resident form is the wrong place for it in the first place, is set out in why your UK accountancy website probably fails ICAEW confidentiality.
This is the floor of a Growth engagement (£1,495/mo). A firm that wants a fractional CTO owning the onboarding, verification, and compliance roadmap across the practice takes an Embedded engagement (from £6,000/mo, bespoke).
Frequently asked questions
Does anti-money-laundering really apply to a small bookkeeping practice?
If the practice provides accountancy or tax services within HMRC’s definition of an accountancy service provider, it is in scope for anti-money-laundering supervision, whatever its size. What varies with size and risk is the depth of due diligence, not whether the duty exists. Check which body supervises your firm, because that determines where you register and whose detailed guidance you follow.
Can we let a client start work and verify their identity afterwards?
The general rule under Regulation 30 is that verification comes before the business relationship is established. There is a narrow exception for completing verification during establishment where interrupting business would be unhelpful and the risk is low, but it is genuinely narrow. The safe default, and the one most firms adopt, is to treat verification as a gate: no engagement letter as a live instruction, no chargeable work, until identity is verified.
How long do we have to keep the identity documents we collect?
Regulation 40 requires customer-due-diligence records to be kept for five years after the business relationship ends. That is a firm number, and it is why where those records live matters so much: a document collected today has to be held, and reachable, in a place the firm can account for, for years after the client has gone.
What should the website intake form actually collect?
At the public step, only what opens a conversation: a name, a contact method, and the general nature of the work. Leave identity documents, dates of birth, and beneficial-ownership detail off the public form, and gather those through a verification channel built for the purpose once the engagement is genuinely proceeding.
Where this fits
The confidentiality frame on the same intake is why your UK accountancy website probably fails ICAEW confidentiality, and the disclosure surface, including the anti-money-laundering supervisory-authority footer, is set out clause by clause in the Section 114 website disclosures briefing. The data-protection view of the client documents you collect is client financial data protection: UK GDPR for accountants, and the residency posture that ties the whole estate together is a sovereign, compliant accountancy website. The published posture behind all of it, including the documented sub-processor list and the in-jurisdiction position, is the Custodiance framework, and the overview for practices is Custodiance for accountancy practices. When a firm’s next onboarding review or supervisory visit is approaching, the next step is to request a scoping call.
Sources & methodology
Regulatory text is quoted from the primary sources below. The “verification as a gate” position is the common safe reading of Regulation 30, not a quoted absolute, and is flagged as such above; the narrow completion-during-establishment exception is real but limited. Confirm the specifics for your firm with your MLRO or supervisor.
- Money Laundering Regulations 2017, Regulation 27 (when customer due diligence is required) - legislation.gov.uk - https://www.legislation.gov.uk/uksi/2017/692/regulation/27
- Money Laundering Regulations 2017, Regulation 28 (customer due diligence measures) - legislation.gov.uk - https://www.legislation.gov.uk/uksi/2017/692/regulation/28
- Money Laundering Regulations 2017, Regulation 30 (timing of verification) - legislation.gov.uk - https://www.legislation.gov.uk/uksi/2017/692/regulation/30
- Money Laundering Regulations 2017, Regulation 40 (record-keeping) - legislation.gov.uk - https://www.legislation.gov.uk/uksi/2017/692/regulation/40
- Money laundering supervision for accountancy service providers - HMRC, GOV.UK - https://www.gov.uk/guidance/money-laundering-regulations-accountancy-service-provider-registration
- Anti-money laundering, UK law and guidance - ICAEW - https://www.icaew.com/technical/trust-and-ethics/anti-money-laundering/uk-law-and-guidance
- Methodology: the Money Laundering Regulations 2017 read against typical accountancy onboarding flows and the website intake step specifically. General guidance, not legal or professional advice. Last updated 3 July 2026.