If you are building onboarding for an EU fintech, payments platform, lending product, crypto service, wealthtech app, or embedded-finance flow, the practical question is not simply “do we need KYC?” It is: what should the onboarding journey collect, verify, screen, retain, and escalate in 2026 without creating unnecessary privacy risk?
This EU KYC onboarding requirements checklist 2026 is designed as an operating guide for compliance, product, risk, and onboarding teams. It is general guidance, not legal advice. Your exact requirements depend on your licence, member-state rules, product risk, customer types, supervisory expectations, and internal AML risk assessment. Use it as a practical baseline before tailoring your policy with counsel and your MLRO or nominated officer.
Free operational template
Download the EU KYC onboarding checklist
Want the printable control checklist instead of reading the guide? Use the free version for onboarding QA, vendor setup, and desk procedures.
What KYC onboarding must prove
A defensible KYC flow should prove six things before the customer can use the regulated product. First, the customer is in scope for your AML and customer-acceptance policy. Second, you know who the customer is. Third, you understand the purpose and intended nature of the business relationship. Fourth, you have screened the relevant people and entity against sanctions, PEP, and adverse-media sources required by policy. Fifth, you have assigned and documented a risk rating. Sixth, you have retained the right evidence in controlled systems and deleted avoidable duplicates.
The best onboarding teams translate those requirements into concrete product decisions: which fields appear for everyone, which fields appear only after a risk trigger, when automated approval is allowed, when an analyst must review the file, and what evidence is written to the system of record.
Individual customer information to collect
For a natural person, the standard starting point is a minimum customer profile. In practice, this usually includes full legal name, date of birth, residential address, country of residence, and contact details needed for onboarding and account security. Depending on the product and reporting obligations, you may also need nationality, tax residence, tax identifier, occupation or business activity, expected account use, expected transaction volume, and source of funds.
The key is proportionality. Do not ask every low-risk customer for every possible document. Define which facts are mandatory for all customers, which are conditional, and which belong only in enhanced due diligence. For identity evidence, common sources include a passport, national ID card, residence permit, reliable electronic identification, or a trusted reusable credential where your policy supports it. Record document type, issuing country, issue date, expiry date, verification outcome, mismatch handling, and the analyst or automated decision trail.
Business customer and KYB information to collect
For legal entities, onboarding is not complete when the company name is captured. A practical KYB profile should include registered legal name, trading name, registration number, legal form, incorporation or registration jurisdiction, registered office, principal place of business, nature of business, website, regulated status where relevant, expected account activity, and countries of operation.
You also need to understand who can act for the entity and who owns or controls it. That means collecting and verifying directors, authorised signatories, persons acting on behalf of the entity, the ownership and control chain, intermediate entities, and beneficial owners under your policy threshold and local legal requirements. Useful evidence can include a company registry extract, LEI, certificate of incorporation, articles, signatory list, board resolution, power of attorney, shareholder register, trust deed, ownership chart, or control declaration. Complex, nominee, opaque, or multi-layer structures should be escalated rather than pushed through a standard low-risk path.
CDD versus EDD: when to escalate
Customer due diligence is the normal control set: verify the customer, verify beneficial owners where relevant, understand the relationship, confirm expected activity, screen required parties, assign a risk rating, and record the decision. For low-risk or simple medium-risk cases, a well-designed automated or analyst-assisted flow may be enough if your policy permits it.
Enhanced due diligence should be triggered by policy-defined risk factors, not by analyst instinct alone. Common EDD triggers include PEP status, a family member or known close associate of a PEP, high-risk third-country exposure, significant sanctions proximity, complex or opaque ownership, credible adverse media, unusual or high-value source of funds, unexplained source of wealth, higher-risk products or delivery channels, weak non-face-to-face safeguards, unresolved identity mismatches, customer resistance to evidence requests, or reliance on an intermediary that limits direct evidence.
EDD actions should be specific. Ask what additional fact is needed to make a decision. That may mean additional identity evidence, source of funds documentation, source of wealth review, ownership-chain evidence, senior management approval for policy-defined high-risk relationships, transaction limits, product restrictions, shorter periodic-review cadence, or increased monitoring sensitivity.
PEP, sanctions, and adverse-media screening
Screening should happen before product activation, and it should cover the right parties. For individual customers, screen the customer and any relevant aliases or matched identifiers. For business customers, screen the legal entity, beneficial owners, directors, authorised representatives, and controlling persons. Your policy should define the sanctions lists, PEP sources, adverse-media scope, and rescreening cadence.
The operational record matters as much as the screen itself. Keep the name searched, aliases, date of birth or entity identifiers, country, source list, confidence score or match rationale, analyst disposition, evidence, and escalation decision. A true sanctions match should stop onboarding while the case is unresolved. A PEP match normally requires EDD, source of funds or source of wealth consideration, and senior approval where your policy requires it. False positives should be resolved carefully, but not retained in a way that creates unnecessary personal data sprawl.
GDPR obligations in the onboarding flow
GDPR does not prevent AML/KYC. It requires the process to be lawful, fair, transparent, proportionate, secure, documented, and time-limited. The practical mistake is treating “KYC” as one broad permission to collect anything useful. Instead, map each field and document to a purpose, likely lawful basis, system owner, access rule, and retention period.
Mandatory AML/CFT checks and recordkeeping often rely on legal obligation. Fraud prevention and platform security may rely on legitimate interests where a balancing test supports the use. Consent is usually a poor basis for mandatory KYC because the customer cannot realistically refuse and still receive the regulated service. Keep optional uses separate from compliance uses, especially marketing, analytics, AI training, and product personalisation.
Build minimisation into the form. Ask whether you can collect a verified attribute instead of a full document, a vendor attestation instead of an internal raw image, a redacted bank statement instead of every transaction, or a registry reference instead of another uploaded file. Keep KYC data out of general CRM notes, ordinary email, support tickets, shared drives, analyst desktops, and broad warehouse exports unless a documented need exists.
Record-keeping and retention checklist
Your retention schedule should separate statutory AML records from operational duplicates. EU AML rules commonly require CDD records and transaction evidence to be retained for a period after the relationship ends or an occasional transaction occurs. Under the AMLD framework this has commonly been five years, with possible member-state extensions in defined circumstances; teams should track current national obligations and the transition to the newer EU AML package.
For each record type, define the retention trigger and deletion action. Customer profile and CDD results may need to remain for the AML statutory period. Raw ID images should be retained only where needed for audit, legal, AML, or dispute reasons. Biometric and liveness artifacts should be treated as high-risk processing and kept for the shortest defensible period unless a stronger requirement applies. Screening alerts should preserve the match result, disposition, and rationale. Support copies, email attachments, vendor exports, and temporary upload files should be deleted once transferred into the controlled system of record.
Common KYC onboarding mistakes
- Collecting the same evidence from everyone. A low-risk individual, a PEP, and a multi-layer holding company should not receive the same evidence journey.
- Using consent for mandatory checks. If the check is required for regulated access, document a more appropriate lawful basis instead of pretending consent is freely optional.
- Letting support tools become KYC archives. Passport images in email, chat, CRM, and spreadsheets create avoidable breach and retention risk.
- Screening only the applicant. KYB cases also need screening for beneficial owners, directors, authorised representatives, and control persons.
- Escalating without a written trigger. EDD should tie back to defined risk factors and produce a clear decision record.
- Keeping data “just in case”. Retention should be a designed control with deletion tests, not a vague promise in the privacy notice.
A practical 2026 onboarding checklist
- Confirm the customer, product, transaction, and jurisdiction are in scope.
- Choose simplified, standard CDD, EDD, or prohibited handling under policy.
- Collect the minimum profile for the customer type and risk level.
- Verify identity, entity existence, authority to act, and beneficial ownership.
- Run sanctions, PEP, and adverse-media screening on all relevant parties.
- Assign a risk score with written rationale and escalation rules.
- Document source of funds or source of wealth where risk requires it.
- Approve, reject, restrict, or escalate with clear reason codes.
- Set ongoing monitoring, rescreening, and periodic-review cadence.
- Map every KYC field to purpose, lawful basis, retention, and deletion.
Next step: turn the guide into an operating control
A guide is useful, but a repeatable checklist is what makes onboarding auditable. Start by mapping each form field, document request, vendor check, analyst queue, and decision outcome to one row in your internal control checklist. Then test the flow with one low-risk individual, one high-risk individual, one simple company, and one complex company before you scale it across every applicant.
KYC Bridge has published a free checklist version you can adapt for this exercise, plus a paid Starter Kit with the checklist, CDD policy template, GDPR/KYC data-handling guide, vendor scorecard, and reusable KYC explainer.
Use the templates behind this guide
Download the free KYC checklist for a quick operating baseline, or buy the full €49 Starter Kit when you need editable policy, privacy, vendor, and reusable-KYC templates.
Official sources to check while tailoring
- The European Commission AML/CFT overview and 2024 AML package pages for EU-level legislative context.
- The EBA remote customer onboarding guidance for risk-sensitive initial CDD policies and remote verification controls.
- The GDPR text on EUR-Lex, especially Articles 5, 6, 25, 28, 30, 32, 35, and 44-49, plus EDPB guidance on data protection by design and by default.
- Your member-state AML law, FIU guidance, supervisory expectations, and sector-specific rules.