Approving a client
In brief: What must be done before a client can be approved, and what to do when something is missing.
Approving a client means your firm has finished customer due diligence and can start working for them. The regulations require that work to be done before the relationship starts (MLR 2017 reg 28 and reg 30; AMLGAS 2026 5.2.1 and 5.6.5), so Certivus checks it when you press Approve.
If something is missing, the approval is not recorded and the message tells you what to do. Nothing on the file changes. Reject, Escalate and Request additional documents are always available, whatever is missing.
The checklist
Every client needs:
- A scored risk assessment.
- Identity verified.
- An individual needs a completed identity check: an electronic check the provider approved, one you reviewed and approved yourself, or a paper document check you recorded. A check that is still in review or never finished does not count.
- If the provider declined the electronic check, approving it as an MLRO override is not enough: record a paper document check for the client. A check declined only because its built-in screening found a match is not an identity failure; the screening is reviewed instead.
- A company needs a dated copy of its Companies House record on file. If it is missing, the approval dialog offers Save the Companies House record, which is free. Running the company check also saves one.
- A company should also have a company check that confirmed it against the register. If you have not run one, you can approve as an MLRO override instead and say how you confirmed the company yourself (see below).
- An AML screening with a result. A screening that has not run, or failed to run, does not count. For a company, this is the screening of the company itself. The company check runs it, or you can run an AML screening for the company on its own.
- Enhanced due diligence when the risk assessment asks for it. If the risk assessment says enhanced due diligence is required, or rates the client High, record enhanced due diligence dated after that assessment. What the record must contain is in When enhanced due diligence is required.
- Possible matches decided and signed off. See Reviewing possible AML matches, including what a confirmed sanctions match or politically exposed person needs.
- For a company, its beneficial owners.
- Every individual who owns more than 25% or is a person with significant control must be verified.
- If an owner is a confirmed sanctions match, screen the owner, report it to OFSI and record the OFSI report reference and the licence on the owner's screening.
- If an owner is a confirmed politically exposed person, the company's enhanced due diligence must record senior management approval, the approval date, source of wealth and source of funds, dated after the owner's screening was signed off (MLR 2017 reg 35).
- If no beneficial owner can be identified after all reasonable steps, record a director as the senior managing official on the Beneficial Owners card, with the steps you took, and verify their identity (MLR 2017 reg 28(6) to (8)). Only the firm's owner, a manager or the MLRO can record one.
For any politically exposed person, the senior management approval must be given by a named person in your firm (the owner, a manager or the MLRO), chosen on the enhanced due diligence card. An older record with only a typed approver name is not enough for a new approval.
Simplified due diligence
Simplified due diligence (MLR 2017 reg 37) is offered only when the scored risk assessment says Low, it does not require enhanced due diligence, and there is no politically exposed person, high-risk country or confirmed sanctions match. Applying it never changes the risk rating. If a later risk assessment requires enhanced due diligence, simplified due diligence is revoked automatically and the reason is recorded. A risk assessment that answers Yes to the simplified due diligence question while it requires enhanced due diligence cannot be scored: answer No to that question first. 7. For a company, no open PSC discrepancy. See PSC discrepancies below.
Occasional transactions
An occasional transaction is one not carried out as part of a business relationship (AMLGAS 5.2.3). On the client profile, Change beside the relationship chip in the header lets you mark the client as an occasional transaction and record its value, including any linked transactions. Customer due diligence is required when that value is £12,000 or more (MLR 2017 reg 27(2)), and at any value if you suspect money laundering or doubt the identity information. If the client comes back for more work, consider whether this has become a business relationship.
When customer due diligence cannot be completed
MLR 2017 reg 31 and AMLGAS 5.6.14: if you cannot complete CDD, for example because the client will not provide proof of identity, do not carry out the work and end any existing relationship. Consider whether the reason gives grounds for a suspicion.
When a client is rejected, or its identity check has failed, the client profile shows Customer due diligence could not be completed with two actions:
- Consider an internal SAR opens the report to your MLRO.
- Cease to act (owner, manager or MLRO) records the date and your reason, archives the client and ends the relationship. The five-year record-keeping period starts from that date (MLR 2017 reg 40).
CDD delays
AMLGAS 5.6.2 to 5.6.13 allow CDD to be finished while work starts only in rare, urgent cases where the risk is low, for a specific reason and a fixed time, agreed by the MLRO. Commercial or filing deadlines alone are not enough. Your MLRO (or the owner, if no MLRO is appointed) records the delay using More actions → Record a CDD delay on the client profile, with its reason and deadline. It appears on the AML calendar on that date and stays until someone marks CDD complete.
PSC discrepancies
Certivus compares the beneficial owners on the client file with the persons with significant control (PSC) on the newest copy of the company's Companies House record. It does this every time a new copy is saved, when you open the company's page, and when you approve. A difference is shown on the company's page, above its people, and kept on file until it is dealt with:
- Not on this file: Companies House lists a person with significant control you have not recorded.
- Not on the PSC register: you record someone as holding 25% or more, or as a person with significant control, and Companies House does not.
- Date of birth differs or Name differs for the same person.
A material discrepancy must be reported to Companies House (MLR 2017 reg 30A; AMLGAS 2026 5.7), normally within 15 working days of finding it. Each one shows a target date, 15 working days from when it was first found. The target skips weekends but not bank holidays, so treat it as a guide.
A firm owner, a manager or the firm's MLRO can record what happened:
- Record report to Companies House: report it on the Companies House service first, then enter the reference it gives you and the date.
- Client corrected the register: if the client fixes the PSC register first, no report is needed. Say what changed.
- Not material: only where the difference could not reasonably be linked to money laundering or hide who controls the company, for example a known spelling variant. Say why.
If you correct your own client file and the difference goes away, it is marked resolved on its own, with the date. The records stay on the file and go into both compliance packs.
A company with an open discrepancy cannot be approved. You do not have to wait for Companies House to reply, and the MLRO can approve as an MLRO override, saying why in the reason. Record the report as well: an override is not a report.
Keeping the Companies House record current
The Companies House evidence row on Overview shows when the register copy was confirmed. Opening a company profile refreshes a missing copy or one older than 30 days in the background. If it fails, the row says it could not refresh and offers Retry. Report opens the full company verification. A fresh copy is also taken each time the company's risk assessment is scored, so a periodic review always compares against the current register. If Companies House cannot be reached at that moment, the assessment still scores and you are told to refresh the copy.
Company checks and MLRO overrides
The company check compares the company with the Companies House register: its status, its registered number and its registered office.
- No company check. Run one, or approve as an MLRO override: the approval dialog offers Approve as an MLRO override. Tick it and say in the reason how you confirmed the company against the register.
- Not found on the register. The company cannot be approved, and this cannot be overridden. Check the company number on the client and run the company check again.
- Differences found (for example a registered office that has just moved, or a company that is not active). Correct the company details if they are wrong. If you have checked the differences and they are acceptable, the approval dialog offers Approve as an MLRO override. Tick it and say why in the reason. The reason is saved on the client's file with the approval.
An override covers only what you tick. Each check that can be overridden has its own tick box. If a company has both differences from the register and an unreported PSC discrepancy, overriding the first does not approve past the second: the dialog shows it next, with its own tick box. The client's file records which checks you overrode, beside your reason. If you see a message asking you to reload the page, your screen is from before this change: reload it and approve again.
The client's to-do list also shows an open PSC discrepancy until it is reported, resolved or marked not material, and the company risk assessment suggests the answer to "have you reported it to Companies House?" from the discrepancy records.
Clients approved before these checks
Approvals already recorded are not changed. If an approved client is missing something on this list, complete it, or record why no further action is needed, from the client's page.
Recording the decision
While steps are outstanding, the header's primary button takes you to the next step. Authorised users can still open More actions → Record decision to record a hold or rejection. Once those steps are complete, Record decision becomes the primary button. The button in Overview's Outcome section opens the same dialog. Saving refreshes the file without reloading the page.
The relationship chip in the header shows your recorded choice, including the amount for an occasional transaction. Choose Change to record or update it. The CDD delays card appears only once a delay has been recorded and retains completed delays as history.
Didn't find what you needed?
Contact support