Free Resource

EU KYC Onboarding Checklist

A practical, printable checklist for EU fintech compliance teams. Covers CDD, EDD, PEP/sanctions screening, risk scoring, ongoing monitoring, and GDPR data-handling controls.

Download Free ChecklistHTML · Print to PDF · No sign-up required
AMLD-alignedGDPR-compliantCDD + EDDEU-focusedPrintable
Preview — full content in the download

Operational aid only. Adapt to your licence, products, member-state law, risk assessment, and legal advice.

Case Header

Customer name / legal nameCustomer type
Product requestedJurisdiction
Onboarding ownerCompliance reviewer
Initial risk ratingFinal decision
1

Scope & Customer Profile

  • Confirm AML/KYC scope, onboarding trigger, product, and customer acceptance policy.
  • Identify standard CDD, simplified due diligence, or enhanced due diligence route.
  • Collect natural-person minimum profile: name, date of birth, address, residence, intended use.
  • Collect legal-entity minimum profile: registry data, directors, signatories, ownership, control.
  • Identify beneficial owners and controlling persons under policy and local rules.
  • Record expected activity, transaction countries, source of funds, and product rationale.
2

Evidence Collection & Verification

  • Confirm each document or field has a defined AML, fraud, security, or legal purpose.
  • Prefer verified attributes or extracted fields over retaining full document images where allowed.
  • Use secure upload or vendor capture; avoid ordinary email for identity documents.
  • Verify identity documents for validity, authenticity, expiry, liveness, and mismatch signals.
  • Verify entity existence, authority to act, beneficial ownership, and ownership/control chain.
  • Record evidence source, timestamp, analyst notes, exceptions, and decision rationale.
3

PEP, Sanctions & Adverse Media Screening

  • Run sanctions screening before activation for customers and relevant connected parties.
  • Run PEP screening for customers, beneficial owners, directors, and authorised representatives.
  • Review adverse media by reliability, relevance, recency, and severity.
  • Document false positives, true matches, escalation owner, and final disposition.
  • Escalate sanctions true matches immediately; do not activate unresolved cases.
  • Configure sanctions and PEP rescreening cadence after onboarding.
4

Risk Score & EDD Triggers

  • Trigger EDD for PEPs, high-risk countries, complex ownership, adverse media, or unexplained funds.
  • Obtain source of funds/source of wealth evidence where required.
  • Obtain senior management approval where policy requires it (mandatory for PEPs).
  • Apply limits, restrictions, enhanced monitoring, or shorter review cycles when approving with controls.
  • Document EDD rationale clearly enough for audit or supervisory review.
5

Decision, Monitoring & GDPR Controls

  • Approve only when mandatory checks are complete or an approved exception exists.
  • Reject or exit where evidence is false, identity cannot be verified, or risk exceeds appetite.
  • Escalate suspicious activity concerns before customer communication; avoid tipping off.
  • Set review cadence: low 24–36 months, medium 12–24 months, high 6–12 months.
  • Map every KYC field to purpose, lawful basis, retention period, access role, and system owner.
  • Delete duplicates and expire retained records when AML retention period ends, unless legal hold applies.

Risk Factor Quick Reference

FactorKey questionNotes
CustomerSimple, transparent, and consistent with risk appetite?
GeographyAny high-risk, sanctioned, conflict, or corruption exposure?
ProductDoes the product enable cross-border, crypto, or rapid movement of funds?
ChannelAre non-face-to-face controls strong enough?
ScreeningAny PEP, sanctions, adverse media, or law-enforcement signal?
FundsIs source of funds/source of wealth plausible and evidenced?

QA Sign-off

ControlEvidence reviewedResultReviewer / date
Identity / KYB evidencePass / Fail / N/A
Beneficial ownershipPass / Fail / N/A
Sanctions, PEP, adverse mediaPass / Fail / N/A
Risk score and EDD rationalePass / Fail / N/A
GDPR minimisation and retentionPass / Fail / N/A
Final approvalPass / Fail / N/A

Prepared by KYC Bridge — privacy-first KYC workflows for EU teams. kycbridge.eu

Need more than a checklist?

The €49 Starter Kit adds a ready-to-edit CDD policy, GDPR data-handling guide, vendor scorecard, and reusable KYC explainer — everything to get your compliance programme live.

Get the full Starter Kit — €49