Free template · Updated for 2026

EU KYC Onboarding Checklist Template (2026)

Copy this practical checklist to turn EU AML, CDD, KYB, EDD, sanctions-screening, and GDPR requirements into a repeatable onboarding workflow. It is built for compliance, product, and operations teams that need a template today — not a generic explainer.

Target query

Use this when someone asks: “what does our EU KYC onboarding checklist need to include?”

A good KYC checklist is not just a document-collection list. It should tell the team which customer types are in scope, what evidence is mandatory, when enhanced due diligence is triggered, how screening hits are handled, and which personal data is retained. The EU’s newer AML framework moved toward a more harmonised rulebook, while the EBA remote-onboarding guidelines remain an important operational reference for credit and financial institutions.

This template is a practical operating aid, not legal advice. Adapt it to your licence, country, products, customer risk assessment, vendors, and supervisory expectations before using it in production.

Copy-ready template

EU KYC onboarding checklist template

Start with this table in your policy, onboarding runbook, product requirements document, or vendor QA file. For a fuller printable version, use the internal free EU KYC onboarding checklist.

Checklist fieldMinimum decision record
Customer typeIndividual / company / representative / UBO / trust / marketplace seller
Product and purposeRequested service, expected use, transaction profile, source of funds, countries
Identity or KYB evidenceDocument, eID, registry, vendor result, liveness, authority evidence
Ownership and controlUBOs, directors, control chain, exceptions, analyst rationale
ScreeningSanctions, PEP, adverse media, false positives, true-match escalation
Risk decisionSDD / CDD / EDD, score, approval level, limits, reject or exit reason
Monitoring setupReview cadence, rescreening, event triggers, transaction alerts, refresh owner
GDPR recordPurpose, lawful basis, retention, access role, processor, deletion workflow

1. Scope the customer and product risk before collecting documents

  • Confirm whether the customer is an individual, sole trader, legal entity, trust, marketplace seller, director, authorised representative, or beneficial owner.
  • Record the regulated product or service being requested, expected account purpose, funding source, transaction types, corridors, volume, and delivery channel.
  • Decide the onboarding path: simplified due diligence, standard CDD, enhanced due diligence, manual review, or reject before activation.
  • Write the minimum data set for that path so product and operations teams do not collect identity documents by habit.

2. Collect identity, KYB, and authority evidence

  • For individuals, collect enough verified attributes to identify the person: name, date of birth, address or residence, nationality where relevant, and document or electronic-ID evidence.
  • For companies, collect registry data, legal form, registered office, trading address, directors, authorised signatories, ownership chain, control structure, and business activity.
  • For representatives, verify authority to act through board resolution, power of attorney, account mandate, platform admin role, or another auditable source.
  • Keep a source log: evidence type, issuing country, vendor/source, extraction confidence, timestamp, reviewer, exception, and final decision.

3. Identify and verify beneficial ownership and control

  • Define the ownership and control threshold used by your policy, then map direct and indirect owners until a natural person or approved exception is documented.
  • Flag nominee arrangements, bearer shares, opaque trusts, layered offshore structures, unusual voting rights, or mismatches between registry data and submitted declarations.
  • Require manual review when ownership cannot be understood, when a controlling person refuses evidence, or when a corporate customer cannot explain its structure.
  • Store the ownership diagram or structured UBO record with the analyst rationale, not only a screenshot from a registry lookup.

4. Screen before activation and set rescreening rules

  • Screen customers, UBOs, directors, authorised representatives, and high-control connected parties for sanctions, PEP exposure, and relevant adverse media.
  • Separate false-positive clearance from true-match escalation, with named owners, timestamps, source lists, evidence reviewed, and outcome notes.
  • Block activation for unresolved sanctions true matches, suspected false documents, inconsistent identity evidence, or risks outside appetite.
  • Set automatic rescreening and event-driven refresh triggers for sanctions list updates, ownership changes, product changes, geography changes, unusual activity, and periodic review dates.

5. Score risk and trigger enhanced due diligence when needed

  • Score customer, geography, product, channel, delivery, funds, ownership, screening, and behavioural risk separately before combining them into an overall rating.
  • Trigger EDD for PEPs, high-risk countries, complex or opaque ownership, credible adverse media, unusual source of funds or wealth, rapid cross-border movement, or weak non-face-to-face safeguards.
  • Require senior approval, additional evidence, limits, shorter review cycles, or exit decisions according to the documented risk band.
  • Make the risk explanation audit-ready: a reviewer should understand why the customer was approved, rejected, restricted, or escalated without asking the original analyst.

6. Add GDPR controls before the checklist goes live

  • Map each data field to purpose, lawful basis, retention period, system owner, access role, processor, transfer safeguard, and deletion workflow.
  • Prefer verified attributes, registry references, and vendor result tokens over permanent copies of documents where your legal and operational model allows it.
  • Prohibit identity documents in ordinary email, Slack, shared drives, screenshots, and analyst desktops unless there is an approved temporary exception and deletion step.
  • Define how data-subject rights requests, fraud holds, AML retention obligations, and suspicious-activity restrictions are handled without deleting records too early or keeping them forever.

Evidence file

What “done” should mean before activation

Use a definition of done that is binary enough for operations, defensible enough for compliance, and readable enough for an external reviewer. Before activating a customer, the file should show:

Identity attributes collected and verified against an approved source
Legal entity exists and matches registry, tax, website, and submitted information
Directors, signatories, representatives, and UBOs are identified where relevant
PEP, sanctions, and adverse-media hits are resolved with evidence
Risk score explains the route taken and the approval level used
EDD file contains source-of-funds/source-of-wealth evidence where required
Onboarding decision is recorded before account activation or product access
Retention and deletion rules are attached to every KYC data category

Quality check

Five mistakes that make a KYC checklist fail

  1. Collecting the same documents from every customer instead of using a risk-based path.
  2. Treating KYB as a registry lookup only, without authority, ownership, purpose, and expected-activity checks.
  3. Clearing PEP or adverse-media matches without a written rationale that another reviewer can follow.
  4. Letting product teams add new KYC fields without a matching purpose, lawful basis, and retention rule.
  5. Launching remote onboarding before documenting liveness, fraud, vendor, retry, and fallback controls.

Fastest route to implementation

Upgrade from checklist to complete Starter Kit

If you are building onboarding this week, the free checklist is the map. The €49 Starter Kit is the editable work product: policy language, GDPR data-handling rules, vendor scoring, and checklist assets packaged so your team can adapt them instead of starting from a blank page.

Included in the €49 kit

  • Editable KYC Onboarding Checklist
  • Full CDD Policy Template
  • GDPR / KYC Data-Handling Guide
  • KYC Vendor Evaluation Scorecard
  • Reusable-KYC Explainer