01 / Scope
Who United Kingdom KYC rules cover
Relevant persons within regulation 8, including specified financial institutions and professional or commercial activities. Sector guidance and supervisor rules add implementation detail.
02 / Start the check
When United Kingdom customer due diligence starts
- When establishing a business relationship.
- For a covered transfer of funds over EUR 1,000 and other occasional transactions of EUR 15,000 or more, including linked operations.
- Whenever money laundering or terrorist financing is suspected.
- When the veracity or adequacy of earlier identification information is doubted and at appropriate times for existing customers.
03 / Evidence
Identity data required for United Kingdom KYC
- Customer identity information sufficient for the person or entity in question.
- Identity of a person acting on behalf of the customer and evidence of authority.
- Beneficial-owner identity and reasonable measures to understand ownership and control.
- Information on the purpose and intended nature of the relationship or transaction.
Verification methods and evidence
- Verify customer identity using documents or information from a reliable source independent of the customer.
- Apply measures before the relationship or transaction, subject to narrow regulation 30 timing exceptions.
- Increase evidence and scrutiny for higher risk; simplified treatment still requires an evidenced lower-risk assessment.
04 / Entity customers
Beneficial-owner and representative checks
Regulation 28 requires identification of the beneficial owner and reasonable measures to verify identity so the relevant person is satisfied it knows who the beneficial owner is. For a body corporate, understand ownership and control structure.
05 / After onboarding
Ongoing KYC monitoring in United Kingdom
Scrutinize transactions throughout the relationship and keep documents, data, and information up to date. The extent and frequency must reflect risk.
Record retention
Regulation 40 requires CDD copies and supporting transaction records for five years from the end of the relationship or completion of an occasional transaction. Personal data should then be deleted unless a listed exception applies.
06 / Build notes
How to implement United Kingdom KYC requirements
- Store the independent source and the risk rationale; a document image by itself does not evidence the whole CDD decision.
- Keep authority-to-act and beneficial-owner steps separate from customer identity verification.
- Build linked-transaction aggregation into threshold logic.
- Schedule risk-based refreshes and event-driven updates for existing customers.
07 / Related answers
Questions behind international KYC implementation
08 / Source ledger
Primary sources for United Kingdom KYC rules
We use regulator and legislation publishers here, not vendor explainers. Pinpoint citations show where to begin; the linked instrument controls.
SI 2017/692, reg. 27 Events that trigger customer due diligence.
SI 2017/692, reg. 28 Required identification, verification, beneficial ownership, and monitoring measures.
SI 2017/692, reg. 40 Records, five-year period, and deletion rule.
SI 2017/692 Full text used to cross-check the individual provisions.
Source review completed 18 July 2026. This page is a structured research summary, not a legal opinion or a substitute for sector-specific advice.