Customer due diligence

Customer Onboarding, CDD, UBO, PEP and EDD Forms for TCSPs

Build a risk-based TCSP onboarding pack that records customer identity, beneficial ownership, authority, PEP screening, EDD, approvals and reviews.

Key answer

A practical TCSP onboarding pack should do more than collect passport and company documents. It should create a traceable decision record: customer and beneficial-owner identity, ownership and control, authorised persons, purpose and intended nature, service requested, customer risk, PEP and sanctions screening, any EDD, approvals, outstanding items and the schedule for ongoing review. Forms should drive a real workflow and adapt to natural persons, legal persons and trusts.

The difference between collecting documents and performing CDD

Document collection is an input. CDD is the process of identifying the relevant persons, verifying them using reliable and independent information, understanding the relationship and assessing its ML/TF risk. A file can contain many documents and still fail to explain who ultimately controls the customer or why the proposed structure makes sense.

The Companies Registry Guideline identifies four central CDD measures: identify and verify the customer; identify and take reasonable measures to verify the beneficial owner and understand ownership and control; obtain information on purpose and intended nature; and identify, reasonably verify and confirm the authority of a person purporting to act for the customer.

A modular onboarding pack

ModuleWhat it should capture
Customer profileLegal name, type, registration or identity details, contact, business and requested services
Ownership and controlStructure chart, intermediate entities, natural-person UBOs, control route and verification
Authorised personsIdentity, verification, role, authority evidence and permitted instructions
Purpose and expected activityReason for the relationship, services, expected jurisdictions, counterparties, funds or activity
ScreeningPEP, sanctions and relevant searches, date, inputs, source, results and match disposition
Customer risk assessmentCustomer, country, service/transaction and delivery-channel factors, overall rating and rationale
EDDHigher-risk enquiries, source of wealth/funds, supporting evidence, enhanced monitoring and approvals
Approval and exceptionsReviewer, approver, outstanding conditions, exception rationale and deadline
Ongoing reviewReview frequency, trigger events, next date, record refresh and rescreening

Beneficial ownership is a reasoning exercise

The form should lead staff through ownership layers to the natural person or persons who ultimately own or control the customer. Under the AMLO framework described in the Guideline, a corporation’s beneficial owner includes an individual with more than 25% ownership or voting control, an individual who exercises ultimate control over management, or the person on whose behalf the corporation acts. Where no natural person meets the applicable test, the relevant senior managing official should be identified and reasonably verified.

A declaration can support identification, but staff should apply reasonable verification measures proportionate to risk. Complex chains, nominees, trusts and unexplained control arrangements need more than copying the immediate shareholder register. Record the sources reviewed and how inconsistencies were resolved.

PEP and sanctions screening records

A defensible screening record shows who and what was searched, the names and identifiers used, the system or source, date and time, results, potential-match analysis, decision maker and any follow-up. A “clear” screenshot without search inputs may not show whether all customers, UBOs, authorised persons or relevant connected parties were screened.

Potential matches should be resolved using relevant identifiers and escalated where uncertainty remains. The outcome should feed the customer risk assessment and EDD decision. The process also needs rescreening and trigger events; onboarding is a point in time, while PEP status, sanctions exposure and ownership can change.

EDD and source-of-wealth/source-of-funds evidence

EDD should respond to the reason the relationship is higher risk. Possible measures include obtaining more information on the customer, beneficial owner, purpose, expected activity, source of wealth or source of funds; using additional independent verification; obtaining required senior-management approval; and applying enhanced ongoing monitoring.

The form should separate a statement from supporting evidence. “Business income” is a source description, not necessarily sufficient evidence. The appropriate documents and depth depend on the risk, plausibility, amount and context. The file should show what was obtained, how it was evaluated, inconsistencies, residual concerns and the approval conclusion—not merely whether a box was ticked.

Workflow controls that prevent incomplete onboarding

  1. Maker completion: the relationship manager or preparer records the customer, ownership, purpose and risk facts.
  2. Independent or supervisory check: a second person reviews required fields, verification and inconsistencies where the firm’s structure permits.
  3. Compliance escalation: higher-risk, PEP, potential-match or exception cases go to the authorised decision maker.
  4. Conditional approval: outstanding conditions have a named owner, restriction and expiry; they are not left as indefinite notes.
  5. Activation control: systems prevent or flag service commencement before required approval.
  6. Review scheduling: the approved risk drives ongoing monitoring and the next review date.

Electronic forms can improve completeness, but mandatory fields do not replace judgement. Free-text rationale, evidence attachments and an audit trail of changes remain important.

Ongoing CDD, privacy and record retention

The onboarding pack should become a living customer record. Changes in ownership, directors, authorised persons, services, activity, jurisdiction, adverse information or screening results should trigger reassessment. The Guideline expects customer information to remain up to date and relevant through ongoing monitoring.

Collect only information needed for the regulatory and risk purpose, restrict access, use secure transfer and preserve the record trail. The Companies Registry Guideline generally requires CDD and related records throughout the relationship and for at least five years after it ends. Retention does not justify uncontrolled duplication or sending identity documents through insecure channels.

Connect the forms to the customer risk method, the AML/CFT policy, the review evidence checklist and the remediation process.

Frequently asked questions

Is a UBO declaration enough?
It can support identification, but the TCSP should take reasonable measures, proportionate to ML/TF risk, to verify the beneficial owner and understand the ownership and control structure.
Does every higher-risk customer need the same EDD documents?
No. EDD should respond to the identified risk. The file should document why particular measures and evidence were appropriate and who approved the relationship where required.
Can onboarding be completed after services start?
The general rule is to complete applicable identification and verification before or during establishment of the relationship. The Guideline describes limited circumstances for delayed verification, subject to conditions, risk controls and prompt completion; it should not become routine.

Primary sources

Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
  3. Companies Registry — Highlights of disciplinary cases
  4. FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.