Compliance

How can we onboard new clients without weeks of back and forth?

By Paul Meakin6 min read

A clipboard holding a blank sheet of paper and a pen on a plain pale orange background
Photo: DS stories on Pexels

Why does onboarding drag on for weeks?

Because it runs on email. The client says yes, and then the forms go out as attachments. Some come back filled in, some come back half done, and some come back as photos taken on a kitchen table. The ID arrives separately, from a different address. Someone saves it somewhere, or forwards it to someone who saves it somewhere else. Then the follow up emails start, and every one of them waits for a reply.

The client is keen now. In three weeks they are wondering why it is this hard to give you their business.

Meanwhile the firm has a different problem. When the time comes to show what was checked, by whom and when, the evidence is scattered across inboxes, shared drives and a download folder.

What do the checks actually involve?

If your business is covered by the Money Laundering Regulations, the checks are not optional, and it helps to know what they are before designing the process around them.

HMRC's guidance on customer due diligence describes CDD, sometimes called know your customer or KYC, as the collective term for the checks businesses must do on their customers and, where applicable, their beneficial owners. The key requirements include identifying all customers and verifying their identity through identity documents such as a passport, official corporate documents, or electronically.

The guidance on identifying and verifying customers sets the minimum information to obtain for a private individual, which you then verify: full name, date of birth and residential address. It is blunt about what happens if you cannot verify them. You must not establish the business relationship or carry out the occasional transaction. And it says you should do more than simply obtain the ID documents: each one should be checked, for things like expiry dates and whether the details match across documents.

That guidance is written for businesses HMRC supervises. If a professional body or another regulator supervises you, follow their guidance. The shape of the work is similar. The detail is theirs, not ours.

How long do the records have to be kept?

HMRC's page on your responsibilities under money laundering supervision says you must keep your records for 5 years, beginning from the date a business relationship ends or the date a transaction is completed. It lists scanned, computerised or electronic records among the acceptable formats.

So a digital process is not a compromise. In practice, done properly, it is the easier way to meet the record keeping rule, because the record is created as the check happens rather than assembled afterwards.

What does a clean onboarding flow look like?

One link, one place, one record.

The client gets a single link to a secure form. It asks for what you need and nothing else, in the order a person would naturally answer. Documents are uploaded there, not emailed. Where your process allows electronic verification, the form can pass the details to a verification service you have chosen, and the result comes back into the same record. If HMRC supervises you, its guidance says a digital verification service provider that is not on the DVS register of certified services cannot reliably be deemed suitable. Check the register before you pick one.

Behind the form, the record holds everything about that client's onboarding: what was asked, what was provided, which checks ran, what they returned, who reviewed it and when. Each client has a status the team can see at a glance. Anything stuck gets a reminder on a schedule, so nobody has to remember to chase.

Access matters as much as convenience. A folder of passports and utility bills is exactly the kind of thing that should not sit in a shared inbox or a drive anyone can browse. Limit the records to the people who need them, keep a log of who opened what, and decide in advance how long each document is kept and what happens to it afterwards. Those decisions are far easier to make once, while the system is being built, than to retrofit after a busy year of onboarding.

Onboarding by email Onboarding through one link
Collecting details Forms sent as attachments, returned in pieces One form, filled in once
Documents Emailed, forwarded, saved in several places Uploaded into the client's record
Status In someone's head Visible to the whole team
Chasing Whoever remembers Scheduled reminders
Evidence when asked Rebuilt from inboxes Already in one record, with dates

What should you ask new clients up front?

Only what you need. That is a data protection point as much as a design one. The ICO's guidance on data minimisation says you should identify the minimum amount of personal data you need to fulfil your purpose, and hold that much information but no more. Its checklist starts with collecting only the personal data you actually need for your specified purposes.

In practice, write the list before you build the form. For each question, note which obligation or business need it serves. If nobody can say, drop it. Then ask everything in one go, so the client is not drip fed a new request every few days.

The ICO notes that this guidance is under review following the Data (Use and Access) Act, so check the current version when you set your process.

Where do people get this wrong?

The first mistake is digitising the mess. A PDF form attached to an email is still onboarding by email. The client still prints it, signs it, scans it and sends it back, and the firm still files it by hand.

The second is collecting everything just in case. Extra personal data is extra risk to store and protect, and it slows the client down for no benefit.

The third is treating the software as the compliance. A system can collect, check, remind and record. It cannot decide your risk appetite, and it does not take on your obligations. Your firm remains responsible for its own checks, its own risk assessment and its own decisions.

The fourth is forgetting the review step. Automated checks return results. A named person still needs to look at anything unusual and record what they decided and why.

When is this not the answer?

When you onboard a handful of clients a year. A well organised checklist and a secure upload folder may be all you need.

When your question is about the rules themselves. Whether you are in scope, which checks apply to which clients, and when enhanced checks are needed are questions for your supervisor's guidance and, if you need it, a compliance adviser. We build the systems that carry out and record your process. We are not regulated advisers and we do not tell you what your obligations are.

When the delay is a decision, not a process. If onboarding waits on a partner who reviews every file personally, a form will not fix that. A clear rule on who can approve what might.

Where do you start?

Take the last few clients you onboarded and list every email that went back and forth before the work could begin. That list shows where the weeks went.

If you want onboarding to be one link and one record, with the evidence in place when someone asks to see it, tell us what's stuck and we'll map the quickest fix. We build this kind of flow as a web application and as process automation. Time to talk yet?

Common questions

Can we keep onboarding records digitally?

Yes. HMRC's page on responsibilities under money laundering supervision lists scanned, computerised or electronic records among the acceptable formats, and says records must be kept for 5 years from the end of the relationship or the completion of the transaction.

Can identity be verified electronically?

HMRC's customer due diligence guidance, for the businesses it supervises, says identity can be verified through documents or electronically. If HMRC supervises you, its guidance points to digital verification services on the DVS register. Which method to use is a decision for your firm, guided by your supervisor.

Does a system make us compliant?

No. It can collect, check, remind and record. Your firm remains responsible for its own risk assessment, its checks and the decisions it makes.

What if a client cannot provide standard ID?

HMRC's guidance covers customers who cannot produce standard documents. It says to exhaust the standard documents first and record why they cannot be provided. Build a route in the form for those cases, with a person reviewing them and noting the reason.

Sources

  1. AMLG11300, Customer due diligence (CDD), HMRC internal manual, GOV.UK
  2. AMLG11400, Identifying and verifying your customers, HMRC internal manual, GOV.UK
  3. Your responsibilities under money laundering supervision, GOV.UK
  4. Principle (c): Data minimisation, ICO

Paul Meakin, Founder

Twenty years of fixing businesses from the inside, eighteen of them in recruitment from consultant to national operations, before building the automation, web applications and compliance systems Staxxd runs today.

More about Paul

Time to talk yet?

Tell us what's stuck and we'll map the quickest fix. Fifteen minutes, no obligation.

Time to talk yet?