An AML compliance document checklist tells you which files to collect from every client so your firm can prove it did proper due diligence if a regulator asks. Get it wrong and you face fines that start in the hundreds of thousands and go up from there.
This article gives you the complete checklist: the base documents that apply to every regulated business, the three risk tiers (simplified, standard, enhanced), and the industry-specific add-ons for banks, real estate, crypto, accountants, insurance, and law firms.
The base AML compliance document checklist
Whether you fall under FinCEN in the US, the FCA in the UK, AMF and Tracfin in France, AUSTRAC in Australia, or MAS in Singapore, the underlying document set is the same. You need to verify who the client is, where they live, where the money comes from, and whether they appear on any sanctions or PEP list.
| # | Document | Purpose | Refresh cadence |
|---|---|---|---|
| 1 | Government-issued photo ID (passport, national ID, driver’s license) | Identity verification | On expiration |
| 2 | Proof of address issued in the last 3 months (utility bill, bank statement, lease) | Residence verification | Every 12-24 months |
| 3 | Tax identification number (SSN, NIN, NIF, TIN) | Tax reporting reference | Lifetime |
| 4 | Selfie or live video matched to the ID | Liveness and anti-spoofing check | At onboarding |
| 5 | Source of funds declaration | AML compliance | Annually for high-risk clients |
| 6 | Source of wealth statement | Explains the origin of assets, not just this deposit | Annually for high-risk clients |
| 7 | Bank account proof (statement, voided check, RIB) | Links transactions to a verified account | At onboarding, then on change |
| 8 | Sanctions, PEP, and adverse media screening result | Risk scoring | Every 6-12 months |
| 9 | AML risk assessment form completed by your firm | Documents your rating logic | Every 12 months |
| 10 | Signed AML declaration and terms of engagement | Confirms the client’s cooperation duty | At onboarding |
If the client is a corporate entity rather than an individual, you also need the KYB pack. The KYB checklist covers every document needed to verify a business, its ownership, and its beneficial owners.
Documents by risk level: SDD, CDD, EDD
AML regulations do not treat every client the same. They expect you to apply a risk-based approach: less documentation for low-risk clients, more for higher-risk profiles.
Simplified Due Diligence (SDD) â low risk
Applies to publicly listed companies, regulated financial institutions, and public authorities. You can rely on public records instead of collecting full identity documents.
- Company name, registration number, and country
- Confirmation of listing or regulated status
- Sanctions screening on the entity
Customer Due Diligence (CDD) â standard risk
The default level for most retail and business clients. This is where the base checklist above applies in full.
- Full identity verification of the client
- Full identity verification of beneficial owners above the 25% threshold
- Nature and intended purpose of the business relationship
- Sanctions and PEP screening
- Source of funds declaration
Enhanced Due Diligence (EDD) â high risk
Required for politically exposed persons, clients in high-risk jurisdictions on the FATF grey or black list, complex ownership structures, and any relationship your risk assessment flags.
- Everything in CDD
- Source of wealth documentation (last two years of tax returns, sale contracts, inheritance papers, business valuations)
- Certified copies of ID and proof of address
- Senior management sign-off on the relationship
- Ongoing monitoring with tighter transaction thresholds
- More frequent refresh cycles (every 6 months rather than yearly)
- Bank and professional references
- On-site or video verification meeting
Applying SDD when EDD was warranted is one of the most common causes of AML fines. Document the reasoning behind every classification.
Industry-specific AML document checklists
The base list covers the framework, but each regulated sector adds its own required documents on top.
Banks and lending
- Full CDD on individuals, KYB on entities
- Source of wealth statement for private banking and high-net-worth clients
- Last two years of tax returns
- Pay stubs or proof of income for the last 3 months
- Credit report authorization
- W-9 or W-8BEN for US tax classification
- FATCA and CRS self-certification forms
- Beneficial ownership certification for legal entity accounts (FinCEN CTA)
Fintech and neobanks
- Digital ID verification with liveness check
- Verified phone number and email
- Device fingerprint and IP geolocation log
- Source of funds and intended use of account
- Sanctions, PEP, and adverse media screening refreshed every 6 months
- EDD pack triggered by transaction volume, cross-border flows, or high-risk MCCs
Crypto exchanges and Web3 platforms
- Tiered KYC based on withdrawal and deposit limits
- Wallet address attestation (signed message from the private key)
- Source of crypto funds (prior exchange withdrawal proof, mining records, staking income)
- Travel Rule compliance data for transfers above the local threshold (currently $3,000 in the US, âŹ1,000 in the EU)
- Blockchain analytics report showing counterparty risk
- EDD for users in FATF-flagged jurisdictions
Real estate and property agencies
- Government ID and proof of address on every buyer, tenant, and beneficial owner
- Proof of funds for the deposit and the balance
- Source of funds evidence (mortgage offer, savings statement, sale of previous property, inheritance)
- Bank reference letter for cash buyers
- Full KYB and UBO pack for corporate buyers
- AML declaration where the transaction exceeds âŹ10,000 in the EU or $10,000 in the US
Property firms often trip up on undocumented cash purchases. See real estate document collection for a workflow view of how to collect this at scale.
Accounting and tax firms
- Government ID and proof of address on every client and partner
- Tax identification number
- Signed engagement letter with an AML clause
- Beneficial ownership declaration for incorporated clients
- Authorization to access tax filings (Form 8821 in the US, procuration in France)
- Last filed tax return and prior-year financial statements
- Source of funds explanation when an unusual transaction appears in the books
Firms handling a large book of clients usually manage this through a dedicated workflow. Our financial advisor document collection guide walks through a similar setup for wealth firms.
Insurance companies
- Full CDD on the policyholder and any premium payer
- ID and address on beneficiaries at claim time
- Source of funds for large single-premium policies
- Sanctions screening on assignees
- Adverse media check on high-value life policies
- EDD for products used to store or transfer value (single-premium life, whole life with high surrender value)
Law firms and notaries
- Full CDD on every client, including introducers
- Beneficial ownership pack for entity clients
- Source of funds and source of wealth for real estate purchases, trust setup, and company formation
- Client account authorization for holding funds
- Sanctions and PEP screening
- Suspicious activity report (SAR) log kept internally
Casinos, gaming, and precious metals dealers
- Full CDD triggered at the local threshold ($3,000 in the US for casinos)
- Transaction log tied to the verified identity
- Source of funds for large buy-ins and payouts
- Cash transaction report where required by law
- Sanctions and PEP screening
How long to keep AML documents
Retention rules vary by jurisdiction but usually cluster around 5 to 7 years after the end of the business relationship. FinCEN and the EU AML Directive both require 5 years. Some countries (UK, Australia) require 7. HMRC can extend the period further for open investigations.
Store the documents in a way that lets you produce a full audit trail on request: who uploaded what, when it was reviewed, who approved it, and when it expires. A document collection app with built-in document expiration tracking turns this from a manual spreadsheet exercise into a system you can hand to an auditor in minutes.
How to collect AML documents efficiently
Chasing clients by email for missing files, then reminding them again when their ID expires, is where compliance teams lose the most time. A structured workflow replaces most of it.
Set up a single onboarding path with the base CDD pack, add conditional steps that appear only when the risk score triggers EDD, and let the platform handle reminders and expiration tracking automatically.
Superdocu is built for exactly this. You create one AML workflow, brand the portal with your logo, and send a magic link. Clients upload their ID, proof of address, source of funds, and any EDD documents through a step-by-step interface. Expired documents trigger automated reminders months before they lapse. Every action is logged for the auditor.
If your firm handles a mix of individuals and entities, the same workflow can branch into the full KYC or KYB path without duplicating templates.
Frequently asked questions
What is the difference between KYC and AML documents?
KYC (Know Your Customer) is the identity-verification piece: you confirm who the client is with an ID, proof of address, and a tax number. AML is the broader framework that also covers source of funds, source of wealth, sanctions screening, PEP checks, and ongoing monitoring. KYC documents are a subset of the AML documentation set.
Who needs an AML compliance checklist?
Any business regulated under an AML law, which usually includes banks, lenders, fintechs, crypto exchanges, insurance companies, real estate agencies, notaries, law firms handling client funds, accountants, tax advisors, casinos, and precious metals dealers. Firms operating across borders often follow the strictest applicable regime.
How often should AML documents be refreshed?
Standard-risk clients: every 24 months, plus on trigger events such as a change of address, ownership, or unusual transaction. High-risk clients: every 6 to 12 months. Sanctions and PEP screening: continuously if your tooling supports it, otherwise at least every 6 months.
What happens if AML documents are incomplete?
Regulators can fine you, suspend your license, and hold senior managers personally liable. Beyond the fine, an incomplete file typically means you cannot rely on the transaction for legal purposes: courts have voided real estate deals and unwound crypto payouts where AML files were missing key documents.
Can AML document collection be automated?
Yes for the collection, storage, tracking, and reminders. The risk assessment and SAR filing still require human judgment. Platforms like Superdocu handle the automation layer: branded portal, structured workflow, expiration tracking, magic-link access, and full audit trail.
Collect your AML documents in one workflow
Rather than pasting document lists into emails, run every client through a structured AML workflow with automatic reminders and expiration tracking. Try Superdocu free for 7 days â no credit card required.
