Skip to main content

Client onboarding checklist for UK accountants

By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 10 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

A UK accountancy practice’s onboarding checklist covers acceptance checks, the engagement letter, customer due diligence, a client risk rating and privacy information. Due diligence is required when the business relationship is established (regulation 27), identity is normally verified before it starts (regulation 30), and due diligence records are kept for at least five years after it ends (regulation 40).

This page is for accountancy practices writing or refreshing their client take-on process. Two things changed in 2026: the Institute of Chartered Accountants in England and Wales (ICAEW) announced updated engagement letter templates on 13 March 2026, with schedules for identity verification and Making Tax Digital, and the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 changed the money thresholds in regulation 27 from 30 June 2026. Building Filyst, our case management product, we enforced four-eyes sign-off on the server so no one approves their own work; the named-person steps below use the same separation. The sections cover scope, timing, due diligence, risk, the engagement letter, privacy, records, automation and a copyable checklist.

Client onboarding steps for a UK accounting practiceSeven steps: acceptance checks and professional enquiry; the engagement letter is issued; customer due diligence identifies and verifies the client and any beneficial owners; a named person sets the client risk rating; privacy information is given; the client is set up in the practice systems from the same data; ongoing monitoring continues through the relationship.AcceptanceCompetence,conflicts,previousadviserEngagementScope andclientobligationsCDDIdentify andverifyRiskA namedperson ratesitPrivacyArticle 13informationSet upSystemsfilled fromthe same dataMonitorOngoing,through therelationship
Customer due diligence sits before the work starts: regulation 30 requires verification before the relationship is established, with one narrow exception.

What is client onboarding for an accounting practice?

Client onboarding, also called client acceptance, turns an enquiry into a client the practice can act for: agreed terms, completed due diligence, a risk rating and the client set up in the practice’s systems. Some steps are set by law and some by professional-body guidance, and the checklist below marks which is which.

Customer due diligence (CDD) is the legal core. CDD means identifying the client, verifying that identity from a reliable independent source and understanding the purpose of the relationship. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the MLR 2017) set the CDD rules. The practice must be able to show its anti-money laundering (AML) supervisor, the supervisory authority that oversees its compliance with the MLR 2017, that the extent of its measures is appropriate to the risks (regulation 28(16)).

Who do the onboarding rules apply to?

The MLR 2017 apply to “relevant persons” acting in the course of business carried on in the UK, and the list includes auditors, insolvency practitioners, external accountants and tax advisers (regulation 8(1) and 8(2)(c)).

An external accountant is a firm or sole practitioner who by way of business provides accountancy services to other persons, when providing those services. A tax adviser is a firm or sole practitioner who by way of business provides material aid, assistance or advice in connection with the tax affairs of other persons, directly or through a third party (regulation 11(c) and (d)). ICAEW’s engagement letter guidance is addressed to its member firms and is professional guidance, not law.

When must due diligence be done?

A relevant person must apply CDD when it establishes a business relationship, and in three further cases under regulation 27(1): an occasional transaction that is a transfer of funds exceeding £800, a suspicion of money laundering or terrorist financing, and doubts about the veracity or adequacy of documents or information obtained earlier for identification.

Regulation 27(2) adds occasional transactions of £12,000 or more, whether in one operation or several linked ones. For existing clients, regulation 27(8) requires CDD again in four situations:

  • when the practice has a legal duty in the calendar year to contact the client to review information relevant to its risk assessment that relates to beneficial ownership;
  • when the practice has to contact the client to fulfil a duty under the International Tax Compliance Regulations 2015;
  • at other appropriate times, on a risk-based approach;
  • when the practice becomes aware that the client’s circumstances relevant to its risk assessment have changed.

Regulation 27(9) lists what the practice must take into account in deciding when to repeat CDD, among other things: signs that the identity of the client or its beneficial owner has changed, transactions inconsistent with what the practice knows of the client, a change in the purpose or nature of the relationship, and any other matter that may affect the risk assessment.

Timing is set by regulation 30. Under 30(2), identity must be verified before the business relationship is established. Under 30(3), verification may be completed during the establishment of the relationship only if both conditions hold: it is necessary not to interrupt the normal conduct of business, and there is little risk of money laundering and terrorist financing. Verification must then be completed as soon as practicable after contact is first established.

What must due diligence cover?

Regulation 28sets what CDD covers, and the measures differ by client type. “Verify” means on the basis of documents or information from a reliable source independent of the person (28(18)); a beneficial owner is the individual who ultimately owns or controls the client.

Client typeWhat to obtainStandardRegulation
Every clientIdentity of the clientIdentify and verify28(2)(a), (b)
Every clientPurpose and intended nature of the relationshipAssess, and obtain information where appropriate28(2)(c)
Company (body corporate)Name, company number, registered office and, if different, principal place of businessObtain and verify28(3)(a)
Company, unless listed on a regulated marketGoverning law and constitution (articles or other governing documents); full names of the board and the senior persons responsible for operationsReasonable measures to determine and verify28(3)(b), 28(5)
Legal person, trust or similar, unless a listed companyOwnership and control structureReasonable measures to understand28(3A), 28(5)
Client with a beneficial owner, unless a listed companyThe beneficial owner, not relying solely on the Companies House registerIdentify; reasonable measures to verify28(4), 28(5), 28(9)
Anyone acting for the clientAuthority to act, and identityVerify authority; identify and verify28(10)

Where a practice has exhausted all possible means of identifying a company’s beneficial owner and failed, or is not satisfied it has the right person, it may treat the senior person responsible for managing the company as the beneficial owner. It must then keep written records of every action taken and any difficulties met (28(6) to (8)). An electronic identification process counts as a reliable independent source if it is secure from fraud and misuse and gives the assurance needed to manage the risk (28(19)).

How is a client’s risk rated?

The extent of CDD must reflect two things: the practice’s firm-wide risk assessment under regulation 18(1), and its assessment of the risk in the particular case (regulation 28(12)). In rating a case, the practice must take account of factors including the purpose of the relationship, the size of the transactions and the regularity and duration of the relationship (28(13)).

Each client rating draws on the practice’s own AML firm-wide risk assessment, which assesses risk factors relating to its customers, countries, products or services, transactions and delivery channels (regulation 18(2)(b)). Enhanced due diligence (EDD) means extra measures and closer ongoing monitoring on top of standard CDD. EDD applies in cases listed in regulation 33(1), including high-risk cases identified in the firm-wide assessment, clients established in a country on the Financial Action Task Force (FATF) list of high-risk jurisdictions subject to a call for action, politically exposed persons (PEPs) and their family members and close associates, clients who provided false or stolen identity documents, and unusually complex or large transactions.

After onboarding, regulation 28(11) requires ongoing monitoring: scrutiny of transactions for consistency with what the practice knows of the client, and reviews that keep CDD documents and information up to date.

What should the engagement letter settle?

ICAEW’s guidance says that before commencing any services, an engagement letter should be issued that sets out the agreed scope of work, specifies the client’s obligations, including providing information and completing any identity verification requirements, and incorporates all relevant schedules from the outset (ICAEW engagement letter updates, 13 March 2026).

The same page sets out acceptance steps for new clients: due diligence on the client’s identity and integrity, understanding the proposed engagement, confirming the firm has the competence and capacity to do the work, and identifying conflicts of interest. Where a previous adviser is involved, ICAEW says firms must also follow professional enquiry procedures, sometimes called professional clearance.

ICAEW’s March 2026 templates added schedules for identity verification, filing company accounts on behalf of clients, Making Tax Digital services and agreed upon procedures. The terms of business now refer to AI, with guidance on whether AI or other software tools will be used, their limitations and responsibilities for data protection, confidentiality and due diligence on technology providers. ICAEW warns against leaving scope ambiguous, using unmodified templates and assuming terms are agreed because a letter was sent.

Which privacy information must the client get?

UK GDPR Article 13 requires the practice, as controller, to give privacy information at the time personal data are collected from the person they relate to (Article 13(1)).

The information includes the practice’s identity and contact details, the purposes and legal basis of the processing, the recipients, the retention period or the criteria for it, the person’s rights, the right to complain to the practice and to the regulator, and whether providing the data is a statutory or contractual requirement. Article 13 lists every item in paragraphs 1 and 2.

Article 13(2)(f) requires information on automated decision-making only where the decision is subject to the safeguards in Article 22C. Telling clients whether AI is used, and that a person reviews its output, goes beyond that legal minimum and matches the AI wording in ICAEW’s updated terms of business.

What if due diligence cannot be completed?

A practice unable to apply CDD as regulation 28 requires must not establish the business relationship or carry out a transaction, must terminate an existing relationship, and must consider whether a disclosure is required under the Terrorism Act 2000 or the Proceeds of Crime Act 2002 (regulation 31(1)).

Regulation 31 has narrow exceptions, including one in 31(3) for an auditor, external accountant or tax adviser who belongs to a qualifying professional body and is ascertaining a client’s legal position or acting in legal proceedings. Read regulation 31(2) to (5) before relying on any of them.

How long are onboarding records kept?

CDD documents and information, and supporting records of transactions subject to CDD or ongoing monitoring, are kept for at least five years from the date the practice knows, or has reasonable grounds to believe, that the business relationship has ended (regulation 40(1) to (3)).

Regulation 40 covers those records only; it sets no period for engagement letters or other client files. After the five years, the practice must delete personal data obtained for the MLR 2017 unless one of three exceptions applies under 40(5): another enactment or court proceedings require it, the person has consented, or the practice has reasonable grounds to believe the records are needed for legal proceedings.

Onboarding creates the due diligence records that the five-year rule governs, and AML record keeping requirements for UK accountants sets out that rule, its start date and what to keep.

How can onboarding be automated safely?

Onboarding can be automated around the people who sign it off: software collects and checks, and a named person decides.

  • One form captures the client’s details once and feeds the engagement letter, the CDD record and the practice systems.
  • An electronic identity check verifies documents; a named person reviews the result.
  • The risk rating is suggested from the facts but set and signed by a person, who is not the person who prepared the file.
  • Each CDD record gets a review date five years after the relationship ends, when personal data are deleted unless regulation 40(5) requires keeping them.
  • A change to the client’s owners or circumstances flags the file for fresh CDD under regulation 27(8).

These checks are part of a wider question about where AI fits in a practice. The guide to AI for accountants in the UK covers which tasks suit AI and where a person signs off, and software for accounting practices describes how we build a client file, its risk rating and the review steps around it.

Client onboarding checklist (template)

This checklist is a starting point to adapt to your practice, your supervisor’s guidance and your own procedures. Copy it into your practice manual, delete what does not apply and add your own steps. Items marked (MLR) come from the regulations; items marked (ICAEW) come from ICAEW guidance.

Before acceptance

  • [ ] Record the enquiry: client name, type (individual, company, partnership, trust), services requested, who referred them.
  • [ ] Confirm the practice has the competence and capacity for the work. (ICAEW)
  • [ ] Check for conflicts of interest and record the result. (ICAEW)
  • [ ] If there is a previous adviser, send the professional enquiry and file the reply. (ICAEW)

Customer due diligence

  • [ ] Identify the client and verify identity from a reliable independent source. (MLR 28(2))
  • [ ] Record the purpose and intended nature of the relationship. (MLR 28(2)(c))
  • [ ] Company: obtain and verify name, company number, registered office and principal place of business. (MLR 28(3)(a))
  • [ ] Company not listed on a regulated market: take reasonable measures on governing law, constitution, directors and senior persons. (MLR 28(3)(b))
  • [ ] Record the ownership and control structure. (MLR 28(3A))
  • [ ] Identify each beneficial owner and take reasonable measures to verify; do not rely only on the Companies House register. (MLR 28(4), 28(9))
  • [ ] Anyone acting for the client: verify their authority and identity. (MLR 28(10))
  • [ ] Verification complete before work starts, or record why regulation 30(3) applies and the date it was completed. (MLR 30)

Risk

  • [ ] Rate the client’s risk against the firm-wide risk assessment and the case factors. (MLR 28(12), 28(13))
  • [ ] Check for EDD triggers, including PEPs, high-risk countries and false documents; apply EDD where triggered. (MLR 33(1))
  • [ ] Rating set and signed by a named person: [name], [date].
  • [ ] If CDD cannot be completed: do not act, and consider a disclosure. (MLR 31(1))

Terms and privacy

  • [ ] Issue the engagement letter before any service: scope, what is outside scope, client obligations including information and identity verification, relevant schedules. (ICAEW)
  • [ ] Receive the signed letter and file the version agreed. (ICAEW)
  • [ ] Give the privacy information when collecting personal data. (UK GDPR Article 13)

Set-up and after

  • [ ] Set the client up in the practice systems from the same record, without re-typing.
  • [ ] Set a CDD review date and the triggers for fresh CDD. (MLR 27(8), 28(11))
  • [ ] When the relationship ends, record the end date; keep CDD records at least five years from it. (MLR 40)

Frequently asked questions

When must an accountant carry out customer due diligence?

When establishing a business relationship; on suspicion of money laundering or doubts about earlier documents; for occasional transactions over the thresholds; and again for existing clients when their circumstances change or at other times on a risk-based approach (regulation 27).

What due diligence is needed for a company client?

Obtain and verify its name, company number, registered office and principal place of business. Unless it is listed on a regulated market, take reasonable measures on its governing law, constitution, directors and senior persons, and identify its beneficial owners without relying only on the Companies House register (regulation 28).

Can identity checks finish after the work has started?

Only if finishing them during set-up is necessary not to interrupt the normal conduct of business and there is little risk of money laundering, and they are completed as soon as practicable (regulation 30(3)).

How long are onboarding records kept?

Customer due diligence records are kept for at least five years from the end of the business relationship, then personal data are deleted unless an exception in regulation 40(5) applies.

Can client onboarding be automated?

Yes: one form can feed the engagement letter, due diligence and the practice systems, with a named person reviewing identity checks and setting the risk rating.

Sources

  1. Money Laundering Regulations 2017, regulation 8 (application)
  2. Money Laundering Regulations 2017, regulation 11 (external accountants and tax advisers)
  3. Money Laundering Regulations 2017, regulation 18 (firm-wide risk assessment)
  4. Money Laundering Regulations 2017, regulation 27
  5. Money Laundering Regulations 2017, regulation 28
  6. Money Laundering Regulations 2017, regulation 30 (timing of verification)
  7. Money Laundering Regulations 2017, regulation 31
  8. Money Laundering Regulations 2017, regulation 33 (enhanced due diligence)
  9. Money Laundering Regulations 2017, regulation 40
  10. UK GDPR Article 13 (information to be provided), legislation.gov.uk
  11. ICAEW, Engagement Letter updates: key changes and guidance for firms (13 March 2026)

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.