In this guide
Customer due diligence automation means performing the mechanical parts of CDD, such as data capture, verification checks, registry retrieval, screening execution, scoring and evidence assembly, through configured systems rather than manual effort.
The regulatory obligations do not change when work is automated; what changes is how the firm evidences that they were met.
This guide describes which activities automate well, which do not, and the controls that keep an automated process defensible. It is general information, not legal or compliance advice.
The obligations automation has to serve
The Money Laundering Regulations 2017, the FCA Financial Crime Guide chapter 3 and GOV.UK guidance describe a consistent core: identify and verify the customer, and beneficial owners; understand the purpose and nature of the relationship; and carry out ongoing monitoring.
What automates well
- Collection and validation of customer data
- Document handling and identity verification checks
- Registry retrieval and ownership chain construction
- Screening execution against sanctions and PEP lists
- Risk factor scoring against an approved methodology
- Workflow routing and service level tracking
- Evidence assembly and management reporting
What needs governance and human judgement
- Whether the evidence obtained is sufficient in the circumstances.
- How to treat discrepancies between sources and customer statements.
- Final risk rating where the case falls outside the standard pattern.
- Whether enhanced due diligence measures have been satisfied.
- Escalation, suspicion reporting, and relationship exit.
Automation supports these decisions by presenting complete, sourced information. It does not transfer accountability, and a defensible design makes the human step explicit.
Identification and verification
Capture identity attributes in structured form, validate them at entry, and verify them against independent sources. Automation should record which method was used, which source responded, when, and what the result was.
Screening
Screening is a strong automation candidate. The configuration, however, is a governed control: matching approach, thresholds, list scope, refresh frequency and discounting rules should all have documented rationale. See how to reduce false positives for more.
Implementation controls
- Document the target process and map each step to the obligation it serves.
- Treat rules and thresholds as controlled configuration with change approval.
- Test before deployment against representative cases and retain results.
- Monitor performance continuously: throughput, defect rates, and alert volumes.
How Agora approaches it
The Agora Due Diligence Platform automates capture, enrichment, ownership resolution, screening, and risk assessment, with configuration under the firm's control. Where a rule or model contributes to an outcome, that contribution is visible and can be overridden with a recorded reason.
Frequently asked questions
Which parts of customer due diligence can be automated?
Data capture and validation, document handling, registry retrieval and ownership chain construction, screening execution, risk factor scoring against a defined methodology, workflow routing, evidence assembly and management reporting are all well suited to automation because they are high volume and rule-describable.
Which CDD decisions should not be fully automated?
Decisions that carry regulatory accountability: whether evidence is sufficient, how to treat discrepancies, final customer risk rating in non-standard cases, whether enhanced due diligence has been properly satisfied, escalation, suspicion reporting and relationship exit. Automation can prepare and support these decisions but should not replace the accountable person.
Does automation change what the Money Laundering Regulations require?
No. The obligations are the same however the work is performed. Automation changes how a firm evidences that the obligations were met, which makes the audit trail, configuration governance and testing more important rather than less.
How should a firm govern automated CDD?
Treat rules, thresholds, models and data sources as controlled configuration: documented rationale, change approval, pre-deployment testing, version history, ongoing performance monitoring and independent review. Record where automation contributed to an outcome and preserve the ability to override with a reason.
What does good evidence look like in an automated process?
For each customer, a retrievable record of what was checked, against which source, when, under which configuration version, what the outcome was, and where a person intervened. Configuration history and testing evidence sit alongside the customer record so a reviewer can reconstruct why a given result occurred.
Where the technology fits
Agora is a technology provider: the platform automates the steps described above, and your own teams operate it and hold the accountable decisions. See KYC workflow software, customer risk assessment software and KYC quality assurance software. Where the requirement is the whole lifecycle rather than one control, the customer due diligence software page sets out onboarding, enhanced due diligence, screening, evidence and stack fit in one place.
Next step
Ready to automate?
Review an automated CDD flow against your own policy with a guided demonstration.