Onboarding is where AML compliance is won or lost. Everything that follows - monitoring, reviews, reporting - depends on what you established and recorded when the client first walked in. Get onboarding right and the file largely maintains itself; get it wrong and every later stage inherits the gap.
This checklist sets out the steps an Irish designated person should run for every new client, built to work under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 today and under the AMLR - Regulation (EU) 2024/1624 - from 10 July 2027. Whether your supervisor is the Law Society of Ireland, a designated accountancy body, the PSRA, the AMLCU or the Central Bank of Ireland, the shape of a defensible onboarding is the same.
Step 1: establish what you are being asked to do
Before any documents, understand the engagement: the service, the expected transactions, the approximate values, and how the client found you. This does two jobs. It tells you which CDD triggers apply - for a one-off piece of work, note that the AMLR drops the occasional-transaction threshold to 10,000 euro, with limited CDD from 3,000 euro for occasional cash transactions. And it gives you the baseline that ongoing monitoring later compares against: you cannot spot unusual activity without a record of what "usual" was supposed to be.
Step 2: identify and verify the client
For individuals: name, date of birth and address, verified against reliable, independent evidence - the classic photo-ID-plus-proof-of-address pairing, or electronic identity verification. The AMLR explicitly recognises eIDAS-aligned electronic identification, so a properly configured e-ID or verification tool is not a shortcut; it is a recognised method, and usually a faster and better-evidenced one.
For companies and other entities: confirm the entity exists and who acts for it - registered details, directors, and the authority of the person instructing you. Verify the individual you are dealing with as well as the entity itself.
Step 3: identify the beneficial owners
For any corporate or trust client, identify the natural persons who ultimately own or control it. The AMLR harmonises the test EU-wide at 25 per cent or more ownership interest, direct or indirect - and note the Commission may later set a threshold of 15 per cent or lower for high-risk sectors following a review. Map the chain until you reach human beings, and record the reasoning, especially through layers.
Then do the Irish-specific step firms most often miss in sequence: obtain an extract from the Register of Beneficial Ownership at rbo.gov.ie before entering the business relationship. Designated persons register for access using the BEN3A1 form, and each extract costs a flat 2.50 euro. Compare the extract against what your own work found. If they differ, you have a discrepancy-reporting duty to the Registrar - record the comparison either way. Remember trusts sit on a separate register (CRBOT, via Revenue), and ICAVs and certain other vehicles on the Central Bank's register.
Step 4: screen everyone you have identified
Screen the client, and for entities their beneficial owners and controllers, against sanctions lists - the EU consolidated financial sanctions list and UN designations at minimum - and for politically-exposed-person status. Date the screening and record how any potential matches were resolved. A true sanctions match stops the onboarding immediately; a PEP match routes the file into enhanced due diligence. Screening once is not enough: your programme should re-screen as lists change, but onboarding is where the baseline is set.
Step 5: risk-rate the client and choose the level of diligence
Pull the threads together into a risk rating with written reasoning - customer, service, delivery channel and geography, consistent with your business-wide risk assessment. The rating determines what happens next:
- Lower risk: simplified measures may be justified - lighter, never absent - with the justification recorded.
- Standard risk: your normal CDD, completed before the relationship proceeds.
- Higher risk: enhanced due diligence - source of funds and source of wealth evidence, senior approval, closer monitoring. Triggers include high-risk third-country connections, PEPs and, under the AMLR, high-net-worth relationships where you handle assets of 5 million euro or more for a client whose total wealth is 50 million euro or more.
A rating without reasoning is the most common inspection finding in small-firm files. One paragraph is usually enough.
Step 6: approve, record and set the clock
Close the loop: the file shows who approved the client, on what date, at what risk level, with every document and screening result attached. Record the review date the rating implies, and the retention clock - under the AMLR, records are kept for five years and then deleted, so the file should know its own lifecycle from day one. Where any step could not be completed, the relationship does not proceed - and consider whether what you learned requires a report to FIU Ireland and Revenue.
What to do now
- Write your onboarding steps down in this order and make the sequence mandatory - especially the RBO extract before the relationship begins.
- Move to electronic identity verification if document-chasing is your bottleneck; the AMLR expressly supports it.
- Check that screening covers beneficial owners, not just the named client.
- Add the AMLR thresholds - 10,000 euro occasional transactions, 3,000 euro occasional cash - to your procedures ahead of July 2027.
- Require one paragraph of risk-rating reasoning on every new file, starting this week.
- Sample your five most recent onboardings against this checklist and remediate the gaps.
Where CompliDesk fits
CompliDesk Ireland runs this exact sequence as a guided workflow - verification, beneficial-ownership mapping, RBO evidence, screening and risk-rating in one dated file. Compare your current files against the CDD file checklist to see where you stand.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.