When onboarding raises suspicion: How accountants should proceed
Last updated: July 24, 2026
Accountants must know how to respond when information gathered before accepting a client points to possible money laundering or terrorist financing.
While routine onboarding questions can resolve an inconsistency, if the available facts support suspicion, the practice must stop the engagement from progressing and use its formal reporting process.
The person who identifies the AML concern should make a clear internal report, while the money laundering reporting officer (MLRO) decides whether an external suspicious activity report (SAR) is required.
Submitting, or deciding not to submit, an external SAR does not settle onboarding. The practice still needs to determine whether customer due diligence (CDD) can be completed and whether the prospective client should be accepted.
Key takeaways
- A warning sign becomes suspicion only when there is sound factual support for it.
- Client approval and substantive work should not proceed while a founded concern is under internal review.
- The internal report should distinguish confirmed information from assumptions and be shared only with the appropriate people.
- CDD, external reporting, and engagement approval should be treated as different decision tracks.
- Communication with the prospective client should remain accurate and neutral while reporting is being considered.
- The onboarding case record must show the reasoning, authority, and outcome for each decision, with SAR material stored separately from the ordinary client file.
When onboarding concerns become AML suspicion
Suspicion needs a factual foundation, although the MLRO does not need proof before treating the concern as reportable.
During onboarding, CCAB guidance places suspicion between mere speculation and evidence-based knowledge, so the AML case note should explain the facts that moved the concern beyond a routine inconsistency.
Pressure to accept questionable records or bypass normal checks can strengthen the basis for suspicion. This concern is consistent with HMRC’s accountancy sector risk guidance, which highlights misleading client information and commercially inexplicable arrangements.
Repeated onboarding concerns can also be relevant to the firm-wide risk assessment, particularly if they point to recurring risks in the firm’s client base or service mix.
Nonetheless, normal onboarding questions can still clarify an ownership discrepancy or the purpose of a service. Yet, they must stay within the usual client-acceptance process, as an open-ended investigation can increase tipping-off risk.
Internal escalation after client onboarding suspicion
Once a concern amounts to suspicion, client approval and substantive action should not proceed until the MLRO or nominated officer has reviewed the position.
The case note should identify any onboarding steps that have been paused and who may approve resumption.
Anyone who forms the suspicion must report it promptly through the practice’s formal internal SAR procedure; an informal conversation is not enough.
Practical takeaway: The written report should set out the basis for the concern and clearly separate facts from assumptions, and access must be limited to those who need the information.
CDD and client acceptance as separate decisions
An electronic identity check alone is insufficient to resolve broader CDD concerns. The same principle applies when a firm relies on old ID documents or CDD material, as that evidence might not resolve questions about control, purpose, or risk.
On the contrary, accountancy firms need reliable information establishing who is behind the client and whether the relationship has a legitimate purpose. This includes completing initial beneficial ownership checks where the client is a company, to establish the relevant ownership and control position.
When required CDD measures cannot be applied, Regulation 31 bars the practice from proceeding with the relationship or transaction and requires it to consider a suspicious activity report.
Client acceptance after AML suspicion
The client-acceptance review should sit alongside, but remain separate from, the CDD outcome and any external reporting duty.
Reporting alone neither compels acceptance nor requires refusal. Any decision to proceed should explain how the suspicion affects the engagement and whether work could continue lawfully without revealing the concern.
Importantly, submitting an external SAR does not decide whether the prospect can be accepted. The practice still needs to assess client acceptance separately, by reference to the level of risk it is willing and able to manage, CDD position, and tipping-off constraints.
External SAR reporting threshold
The internal report to the practice’s MLRO differs from the external SAR sent to the UK Financial Intelligence Unit (UKFIU).
Once the concern has been escalated internally, the MLRO must determine whether the statutory threshold for reporting suspected money laundering or terrorist financing has been met.
Risk concerns or doubts about accepting the prospect can inform that assessment, but they do not create an automatic reporting duty. Equally, declining the engagement does not remove the need to submit an external SAR if the threshold is met.
Sections 330 and 331 of the Proceeds of Crime Act 2002 set the regulated-sector duties for staff and nominated officers.
If an external suspicious activity report is required, it should be submitted through the UKFIU’s SAR Portal. The submission needs to explain the basis for the suspicion and identify the people and property involved.
As an external SAR reports suspected money laundering to the UKFIU, it does not replace a separate duty to report the same facts to a supervisor or another relevant authority.
The practice should also ensure that the submission and related decision records are handled in line with SAR confidentiality and record-keeping requirements.
Defence against money laundering (DAML) and prohibited acts:
A DAML request is relevant only when the practice is being asked to carry out a specific act that could involve suspected criminal property, such as filing a return, submitting accounts, or completing another defined instruction.
The defense does not provide general clearance to accept or continue a client relationship, and the UKFIU will not treat a broad request to keep acting for the client as a sufficient prohibited act.
Client communications and AML record keeping
Communications must not reveal that a report has been made or suggest that suspicion is behind a delay, refusal, or possible investigation.
That said, ordinary commercial enquiries and neutral updates are not automatically tipping off. Once the MLRO is considering an external SAR, related client communications should be controlled through the reporting process.
The practice can refer accurately to its onboarding procedure or explain that the engagement will not go ahead, without inventing a false explanation.
The case record should show how the concern was assessed and why each resulting decision or communication was made. This also helps show a reviewer how the firm controlled the AML issue rather than allowing it to remain as an unresolved onboarding concern.
Moreover, the MLRO’s reasoning should still be recorded even when no external SAR is submitted, with SAR-related material stored securely outside the routine client record.
A founded suspicion during onboarding should therefore move the case out of ordinary client acceptance and into formal AML decision-making.
The engagement should pause while the concern is referred to the MLRO, after which the due diligence outcome and the client-acceptance decision should be reached and recorded as separate conclusions.
In summary
Accountancy firms should deploy a controlled handover from client onboarding to formal AML decision-making. In doing so, the transition preserves the evidence available at the time and makes clear who can authorise further work.
Staff then have a consistent route to follow without allowing routine checks to expand beyond their proper scope. Practices can also show supervisory bodies how they moved from the initial AML concern to their reporting position and final client-acceptance decision.
FAQs
A red flag often requires targeted checking without automatically leading to a SAR. If the evidence gathered creates a genuine suspicion, further onboarding should be halted, and the concern reported through the firm’s internal procedure. It is then for the MLRO to determine whether an external suspicious activity report must be made.
The firm can ask focused questions as part of its normal onboarding checks. If the explanation does not resolve the AML concern, or raises further doubts, client approval and substantive work should pause while the matter is referred internally. Routine enquiries should not develop into a wider investigation of the prospect.
Communication should be neutral in tone and factually accurate. The firm can say that its onboarding review is continuing or that it cannot take on the engagement. It should not disclose the existence of a report, suggest that an investigation may follow, or attribute any delay or refusal to suspicion.
An electronic identity check addresses only a small part of customer due diligence. Further evidence is needed to establish who exercises control and why the relationship is being formed. If those wider concerns remain unresolved, the firm cannot proceed with the engagement.
A firm can decline an engagement under its own acceptance criteria even when the reporting threshold has not been reached. An external SAR might still be necessary after the firm declines the client if the MLRO concludes that the reporting threshold has been met. Each of these decisions requires its own analysis.
Responsibility for deciding on an external report rests with the MLRO. The firm must separately assess whether CDD is complete and if the risk can be controlled in practice. An external SAR does not determine if the engagement should continue.
References and Source Material
- HMRC, Risks common to accountancy service providers
- Money Laundering Regulations 2017
- Proceeds of Crime Act 2002, Part 7
- CCAB, Anti-Money Laundering, Counter-Terrorist and Counter-Proliferation Financing Guidance for the Accountancy Sector
- National Crime Agency, Suspicious Activity Reports
- UKFIU, SARs Best Practice Guidance, Chapter 2: Submitting a SAR
- UKFIU, SARs Best Practice Guidance, Chapter 3: Understanding DAMLs and DATFs

