Practical, operationally grounded guidance for financial crime, compliance and transformation teams working on customer due diligence.
Each resource sets out how the work is actually done: where the obligations come from, what good practice looks like, which parts of the process technology can support, and which decisions remain matters of accountable human judgement. We keep statutory requirements, supervisor guidance, published supervisory findings and our own practitioner interpretation clearly apart.
These pages summarise publicly available UK regulation and guidance and describe how Agora approaches implementation. They are general information, not legal or compliance advice, and requirements differ by sector, supervisor and firm risk profile.
Start here
UK CDD and KYC regulatory answers
Short, source-backed answers to the questions firms ask most, with the rules, the practical implications and our interpretation kept separate.
UK CDD Automation Benchmark 2026
Data collection open. UK financial-crime, compliance and transformation practitioners at regulated firms can take part in the 28-question questionnaire. No findings yet.
Guides by topic
Eleven practitioner guides grouped into five areas. Each guide covers the regulatory basis, how the control is designed in practice, the pitfalls we see most often, and where automation helps without displacing accountable judgement.
CDD and onboarding
Getting the initial assessment right: what to capture, how to rate risk, and when enhanced measures apply.
Customer Due Diligence Automation: A Practical Guide
Which CDD activities can be automated, which decisions need governance and human judgement, and the controls that keep an automated process defensible.
Read the guideCustomer Risk Assessment: A Practical CDD Framework
Designing a risk factor model, weighting and scoring, overrides, calibration, documentation and the link between the business-wide and customer-level assessment.
Read the guideEnhanced Due Diligence (EDD): Triggers, Evidence and Controls
When EDD applies, what additional measures look like in practice, how to evidence them, and how enhanced ongoing monitoring is designed and reviewed.
Read the guidePurpose and Intended Nature of the Business Relationship
What to capture, how to structure it so it is usable in monitoring, and why free-text statements repeatedly fail supervisory review.
Read the guideRemediation and ongoing KYC
Keeping files current: review models, trigger design and recovering backlogs without losing evidence.
KYC Remediation: How to Modernise Customer File Remediation
Triggers and backlogs, risk-based prioritisation, data enrichment, ownership, screening, outreach, quality control and the audit evidence a remediation programme has to leave behind.
Read the guidePeriodic KYC vs Perpetual KYC: What UK Firms Need to Know
How cycle-based review models differ from event-driven perpetual KYC, what each demands of data and controls, and how firms move between them without losing evidence.
Read the guideKYC Trigger Events: When Should Customer Due Diligence Be Reviewed?
A practical trigger taxonomy covering customer change, ownership change, screening outcomes, behaviour, geography and internal doubt, with detection and response design.
Read the guideOwnership and KYB
Resolving who ultimately owns and controls a corporate customer, and evidencing it.
Screening
Sanctions and PEP screening that catches what matters without drowning the operation in alerts.
Governance and assurance
Proving the process worked: audit trails, quality control and independent testing.
Building a Regulator-Defensible CDD Audit Trail
What a reviewer needs to reconstruct a decision: source provenance, configuration versioning, decision records, overrides and retention.
Read the guideKYC Quality Assurance: Designing Effective QC and Independent Testing
First line quality control, second line assurance and independent testing: sampling, defect taxonomies, thresholds, remediation loops and reporting.
Read the guideRegulatory answers
Concise answers for people who need the position and the source rather than a full guide. The full set is on the UK CDD and KYC regulatory answers page.
- Does UK regulation require periodic KYC reviews?
- When should existing customer due diligence be updated?
- Do firms need to record the purpose and intended nature of a business relationship?
- What should firms do when beneficial ownership changes?
Who writes this
These resources are written and reviewed by Ian Marley, Founder and Chief Operating Officer of Agora Consulting Solutions, who has around 18 years of delivery experience in financial services remediation and compliance, including financial crime transformation and remediation programmes.
Read the author profilePrimary UK sources
Where these guides describe an obligation or a supervisory expectation, the underlying source is public. We link to it rather than paraphrasing it as though it were ours:
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- FCA Financial Crime Guide, chapter 3 (customer due diligence)
- HMRC AMLG11300, customer due diligence (updated 16 July 2026)
- HMRC AMLG11411, ongoing monitoring (updated 16 July 2026)
- HMRC AMLG11600, enhanced due diligence (updated 16 July 2026)
- GOV.UK, report a discrepancy about a beneficial owner on the PSC register
- JMLSG Guidance
Where Agora fits
Agora provides technology for customer due diligence and financial crime operations. The Due Diligence Platform supports onboarding, beneficial ownership resolution, screening, identity verification, customer risk assessment, outreach, ongoing review and case reporting, with an audit trail across each step. The due diligence software overview explains the scope in more detail.