KYC Onboarding Checklist
EU fintech CDD, EDD, screening, risk scoring, monitoring, and GDPR data-handling controls.
Operational aid only. Adapt to your licence, products, member-state law, risk assessment, and legal advice.
Case Header
| Customer name / legal name | | Customer type | |
| Product requested | | Jurisdiction | |
| Onboarding owner | | Compliance reviewer | |
| Initial risk rating | Low / Medium / High / Prohibited | Final decision | Approve / Controls / Reject / Escalate |
1. Scope and Customer Profile
- Confirm AML/KYC scope, onboarding trigger, product, and customer acceptance policy.
- Identify standard CDD, simplified due diligence, or enhanced due diligence route.
- Collect natural-person minimum profile: name, date of birth, address, residence, intended use.
- Collect legal-entity minimum profile: registry data, directors, signatories, ownership, control.
- Identify beneficial owners and controlling persons under policy and local rules.
- Record expected activity, transaction countries, source of funds, and product rationale.
2. Evidence Collection and Verification
- Confirm each document or field has a defined AML, fraud, security, or legal purpose.
- Prefer verified attributes or extracted fields over retaining full document images where allowed.
- Use secure upload/vendor capture; avoid ordinary email for identity documents.
- Verify identity documents for validity, authenticity, expiry, liveness, and mismatch signals.
- Verify entity existence, authority to act, beneficial ownership, and ownership/control chain.
- Record evidence source, timestamp, analyst notes, exceptions, and decision rationale.
3. Screening
- Run sanctions screening before activation for customers and relevant connected parties.
- Run PEP screening for customers, beneficial owners, directors, and authorised representatives.
- Review adverse media according to reliability, relevance, recency, and severity.
- Document false positives, true matches, escalation owner, and final disposition.
- Escalate sanctions true matches immediately; do not activate unresolved cases.
- Configure sanctions and PEP rescreening cadence after onboarding.
4. Risk Score and EDD Triggers
| Factor | Key question | Notes |
| Customer | Simple, transparent, and consistent with risk appetite? | |
| Geography | Any high-risk, sanctioned, conflict, or corruption exposure? | |
| Product | Does the product enable high-value, cross-border, crypto, or rapid movement of funds? | |
| Channel | Are non-face-to-face controls strong enough? | |
| Screening | Any PEP, sanctions, adverse media, or law-enforcement signal? | |
| Funds | Is source of funds/source of wealth plausible and evidenced? | |
- Trigger EDD for PEPs, high-risk countries, complex ownership, adverse media, or unexplained funds.
- Obtain source of funds/source of wealth evidence where required.
- Obtain senior management approval where policy requires it.
- Apply limits, restrictions, enhanced monitoring, or shorter review cycles when approving with controls.
5. Decision, Monitoring, and GDPR Controls
- Approve only when mandatory checks are complete or an approved exception exists.
- Reject or exit where evidence is false, identity cannot be verified, or risk exceeds appetite.
- Escalate suspicious activity concerns before customer communication; avoid tipping off.
- Set review cadence: low 24-36 months, medium 12-24 months, high 6-12 months or policy frequency.
- Map every KYC field to purpose, lawful basis, retention period, access role, and system owner.
- Delete duplicates and expire retained records when the AML retention period ends, unless legal hold applies.
QA Sign-off
| Control | Evidence reviewed | Result | Reviewer/date |
| Identity / KYB evidence | | Pass / Fail / N/A | |
| Beneficial ownership | | Pass / Fail / N/A | |
| Sanctions, PEP, adverse media | | Pass / Fail / N/A | |
| Risk score and EDD rationale | | Pass / Fail / N/A | |
| GDPR minimisation and retention | | Pass / Fail / N/A | |
| Final approval | | Pass / Fail / N/A | |