Client Onboarding Checklist for Accountants and Consultancies (UK)
UK client onboarding checklist for accountants: AML customer due diligence under the MLRs 2017, professional enquiry letters and engagement letters, in order.
Short answer: In the UK, onboarding an accountancy client means: confirm you can act, get the client's permission to contact the previous adviser, carry out customer due diligence under regulations 27 to 30 of the Money Laundering Regulations 2017 before the relationship starts, and issue an engagement letter. ICAEW strongly advises one for all work and requires it for audit.
This checklist covers England, Wales, Scotland and Northern Ireland, since the Money Laundering Regulations apply UK-wide. We checked the legislation and guidance on 7 October 2026, including the 2026 amendments. It is a practical summary, not legal advice: your anti-money laundering (AML) supervisor's guidance and your own firm-wide risk assessment come first.
Who does this checklist apply to?
Firms that provide accountancy services, tax advice, audit, insolvency or trust and company services. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the "MLRs") apply to defined types of business. Regulation 11 defines an "external accountant" as "a firm or sole practitioner who by way of business provides accountancy services to other persons, when providing such services", and covers tax advisers in similar terms (MLRs reg 11). Trust or company service providers, such as firms forming companies or providing a registered office, are covered by regulation 12.
A consultancy that only gives, say, strategy or HR advice is not in scope just by being a consultancy. If it also does bookkeeping, tax work or company secretarial services, those services are in scope. Under regulation 7, AML supervision sits with the professional body listed in Schedule 1 that the firm belongs to, or with HMRC for firms not supervised by one of those bodies (MLRs reg 7).
What changed in 2026?
- MLR amendments. The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621) took effect mostly from 30 June 2026 (SI 2026/621, reg 1). Enhanced due diligence for high-risk countries now refers to the FATF list of "High-Risk Jurisdictions subject to a Call for Action" (MLRs reg 33), and selling off-the-shelf companies now counts as trust or company service provider activity (MLRs reg 12). ICAEW reported on 10 August 2026 that the CCAB AML guidance for the accountancy sector had been updated to match (ICAEW).
- Supervision reform. HM Treasury has confirmed the FCA will become the single AML supervisor for professional services. Its June 2026 response says implementation "will inevitably take several years" (HM Treasury, June 2026). As of October 2026, your current supervisor still supervises you.
- Companies House identity verification. Since 18 November 2025, directors and people with significant control must verify their identity with Companies House, phased in over 12 months (GOV.UK, 5 August 2025). This is separate from your own CDD, but company clients will ask you about it.
The onboarding checklist at a glance
| Stage | What to do | Where the requirement comes from |
|---|---|---|
| 1. Before accepting | Check scope, competence, capacity and conflicts | ICAEW Code of Ethics, section 320 (or your body's code) |
| 2. Previous adviser | Client's written permission, then a professional enquiry letter | ICAEW change of appointment helpsheet; ACCA and others have equivalents |
| 3. Risk assessment | Assess this client against your firm-wide risk assessment | MLRs regs 18, 19 and 28(12) |
| 4. Identify and verify | Client, beneficial owners, anyone acting for them | MLRs reg 28 |
| 5. Purpose and nature | Record why they want your services and what you will do | MLRs reg 28(2)(c) |
| 6. Enhanced checks | PEPs, high-risk countries, unusual structures | MLRs regs 33 and 35 |
| 7. Timing | Verify before the relationship starts | MLRs reg 30 |
| 8. If CDD can't be done | Do not act; consider a suspicious activity report | MLRs reg 31 |
| 9. Engagement letter | Scope, fees, responsibilities, complaints | ICAEW engagement letter helpsheet |
| 10. Records and monitoring | Keep CDD records, review the relationship over time | MLRs regs 28(11) and 40 |
What should you check before accepting a client?
Whether you can do the work properly and ethically. ICAEW's Code of Ethics section 320 deals with professional appointments, and ICAEW's client engagement resources suggest a risk-based assessment before accepting, covering the engagement itself, Money Laundering Regulations compliance, professional enquiries to the existing accountant and company research (ICAEW, Client engagement).
In practice, confirm the scope, that you have the skills and capacity (including at year-end), that there is no conflict, and note any red flags, such as reluctance to explain the business or pressure to start before checks are done.
How do you handle the previous accountant?
Get the client's permission first, then send a professional enquiry letter. ICAEW's helpsheet for incoming accountants says client consent is required, "preferably in writing", to respect the fundamental principle of confidentiality, and suggests the letter asks the existing accountant for "any circumstances or information" relevant to whether you should accept (ICAEW, Change of professional appointment: incoming accountant).
Points from the same helpsheet worth building into your process:
- If the client refuses permission, ask why and record it. A client who won't let you speak to their last adviser is telling you something.
- If there is no reply, chase by other means, then write stating that you intend to accept unless you hear back within a specified, reasonable period.
- Don't ask whether they filed a suspicious activity report. The helpsheet says you shall not specifically enquire whether the existing accountant has reported suspicions of money laundering.
- Unpaid fees are not a reason for the outgoing accountant to refuse to reply to your enquiry, though they may mention them.
- Professional enquiry is not CDD. A reassuring reply does not replace your own due diligence.
Other professional bodies publish their own guidance on changes in appointment. If you are not an ICAEW member, follow your own body's; we cite ICAEW because it is the guidance we opened and checked.
What customer due diligence do the Money Laundering Regulations require?
Identify and verify the client, understand who owns and controls them, and understand why they want your services. Regulation 27 requires CDD when you establish a business relationship, and also if you suspect money laundering or terrorist financing, or doubt identification you were given earlier (MLRs reg 27). A business relationship is one expected to have "an element of duration" when contact is first made (regulation 4), which describes most accountancy clients.
For every client (regulation 28)
- Identify the client and verify their identity. Verification means using documents or information "from a reliable source which is independent" of the person (MLRs reg 28).
- Assess the purpose and intended nature of the relationship. Regulation 28(2)(c) requires you to "assess, and where appropriate obtain information on" it. Write down what the client does and what you will do for them.
- Check anyone acting on the client's behalf is authorised to do so, and identify and verify them (regulation 28(10)).
For companies and other entities
- Obtain and verify the company's name, company number, and registered office address (and principal place of business if different).
- Take reasonable measures to determine and verify the law it is subject to, its constitution, and the full names of the board and senior persons responsible for its operations.
- Identify the beneficial owners and take reasonable measures to verify their identity, and take reasonable measures to understand the ownership and control structure.
When enhanced due diligence applies (regulations 33 and 35)
Regulation 33 requires enhanced due diligence in higher-risk situations, including where a party is established in a FATF call-for-action country, where the client or beneficial owner is a politically exposed person (PEP) or a family member or known close associate of one, where false or stolen identity documents have been used, and where a transaction is "unusually complex or unusually large" (MLRs reg 33). For PEPs, regulation 35 requires senior management approval, adequate measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. Domestic PEPs start from a lower level of risk than non-domestic PEPs (MLRs reg 35).
Risk-based, not one-size-fits-all
How much you do depends on risk. Regulation 18 requires a written firm-wide risk assessment, and regulation 19 requires written policies, controls and procedures based on it (reg 18, reg 19). Your client-level checks should follow that framework, not a generic list. The CCAB anti-money laundering guidance for the accountancy sector sets out what supervisors expect in more detail.
When must verification be finished?
Before the business relationship is established. Regulation 30 allows verification to be completed during the establishment of the relationship only if that is necessary not to interrupt the normal conduct of business, there is little risk of money laundering or terrorist financing, and verification is completed as soon as practicable after contact is first established (MLRs reg 30). Don't start chargeable work on the assumption that the ID will turn up later.
What if the client won't or can't complete CDD?
Don't act. Regulation 31 says that if you cannot apply the required CDD measures, you must not establish the business relationship or carry out a transaction, must terminate any existing relationship, and must consider whether you are required to make a disclosure under Part 7 of the Proceeds of Crime Act 2002 or Part 3 of the Terrorism Act 2000 (MLRs reg 31). The regulation contains limited carve-outs for professional advisers in certain circumstances; check your supervisor's guidance before relying on one. Speak to your money laundering reporting officer and be careful not to tip the client off.
What goes in the engagement letter?
Scope, responsibilities, fees and complaints, issued before you start. ICAEW says an engagement letter is compulsory for audit work and that "whilst a letter of engagement is not compulsory for non-regulated work, the issuing of an engagement letter is strongly advised" (ICAEW, Client engagement). ICAEW's engagement letter helpsheet, last updated March 2026, provides a main letter, schedules for each service, terms of business and privacy notices (ICAEW, Engagement letters and privacy notices).
Make sure yours covers at least:
- Who the client is (the entity, not just the person you met).
- The services, one schedule per service, and what is excluded.
- What the client must provide, including identity information.
- Fees, complaints procedure and any limitation of liability.
- Data protection, a privacy notice and how either side can end the engagement.
Get it signed before work starts, and reissue it when the scope changes.
What happens after onboarding?
Ongoing monitoring and record-keeping. Regulation 28(11) requires ongoing monitoring of the business relationship, including keeping CDD documents and information up to date. Regulation 27 also requires CDD to be reapplied to existing clients at appropriate times, for example when their circumstances or ownership change. Regulation 40 requires you to keep CDD records for five years from the end of the relationship, after which personal data should generally be deleted unless an exception applies (MLRs reg 40). In practice, diary a CDD review for each client, more often for higher-risk ones, and treat a request for new services as a prompt to look again.
How can a team keep this consistent?
Write your onboarding procedure down once, and make the current version easy to find mid-task, especially for unusual cases: a trust client, an overseas director, a client who wants to start before ID arrives.
Verika can help with that. Load your AML policy, firm-wide risk assessment and onboarding procedure, and a trainee can ask "can I start the bookkeeping before we've verified the director's ID?" and get your firm's answer, with the policy document it came from named. If your documents don't cover it, Verika says so and logs the question for your MLRO to answer once. It answers only from your own sources; it does not hold the MLRs or supervisor guidance for professional services firms, so your policy needs to reflect them. More on Verika for professional services, or start a free trial.
Sources
All checked on 7 October 2026.
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), regulations 4, 7, 11, 12, 18, 19, 27, 28, 30, 31, 33, 35 and 40, legislation.gov.uk (latest revised versions). https://www.legislation.gov.uk/uksi/2017/692/contents
- The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621), regulation 1 (citation and commencement) and explanatory note. https://www.legislation.gov.uk/uksi/2026/621/contents
- HM Treasury, "Anti-Money Laundering/Counter Terrorist-Financing (AML/CTF) Supervision Reform: Duties, Powers, and Accountability Consultation Response", June 2026, chapter 10. https://assets.publishing.service.gov.uk/media/6a33d34c6422bec01b117788/Powers_Consultation_Response.pdf
- ICAEW, "2026 CCAB AML guidance for the accountancy sector", regulatory news, 10 August 2026. https://www.icaew.com/regulation/regulatory-news/regulatory-news-2026-08/2026-ccab-aml-guidance-for-the-accountancy-sector
- ICAEW Technical Advisory Service, "Change of professional appointment: incoming accountant" helpsheet (last reviewed 17 November 2023). https://www.icaew.com/technical/tas-helpsheets/practice/change-of-professional-appointment-incoming-accountant
- ICAEW, "Client engagement", practice resources. https://www.icaew.com/technical/practice-resources/supporting-your-clients/developing-client-relationships/client-engagement
- ICAEW Technical Advisory Service, "Engagement letters and privacy notices" helpsheet (last updated 10 March 2026). https://www.icaew.com/technical/tas-helpsheets/practice/engagement-letters
- Companies House / GOV.UK, "Companies House confirms identity verification rollout from 18 November 2025", 5 August 2025. https://www.gov.uk/government/news/companies-house-confirms-identity-verification-rollout-from-18-november-2025
Frequently asked questions
›When must an accountant carry out customer due diligence?
Under regulation 27 of the Money Laundering Regulations 2017, when establishing a business relationship, and also when money laundering is suspected or earlier identification is in doubt. Identity must normally be verified before the relationship starts (regulation 30).
›Is an engagement letter a legal requirement for accountants?
ICAEW says an engagement letter is compulsory for audit work and, while not compulsory for non-regulated work, is strongly advised. Check your own professional body's rules.
›Can I take on a client if the previous accountant doesn't reply?
ICAEW's helpsheet says to chase, then write stating that you intend to accept unless you hear back within a specified reasonable period. Document each step.
›How long must CDD records be kept?
Regulation 40 requires CDD records to be kept for five years after the business relationship ends, after which personal data must generally be deleted unless an exception applies.
›Does the anti-money laundering regime apply to management consultancies?
Not to consultancy as such. It applies to defined activities, including external accountancy, tax advice and trust or company services. A consultancy doing any of those is in scope for that work.