Account Opening Form Redaction with anonym.plus

Clear applicant identifiers from a new-customer form before you file or forward it.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

An account-opening form does two jobs at once. It records the contract, and it carries the customer due diligence MLR 2017 reg. 27(1)(a) requires whenever a business relationship begins. Reg. 28 sets what that means: identify the customer, then verify from a source that is reliable and independent of them. FCA SYSC 3.1.1R makes the firm organise and control that work responsibly, and SYSC 9.1.1R makes it keep orderly records of it. UK GDPR Art. 6(1)(c) is the lawful basis for the diligence part, Art. 6(1)(b) for the contract part. anonym.plus marks each field on your machine, so the form stays usable while the applicant details go.

When this applies

A branch sends a signed application to a training team building a worked example. The trainers need the layout and the product codes. They do not need the applicant's National Insurance number, address or funding account, so those come out first.

How anonym.plus handles it

  1. Open the application in anonym.plus on your device.
  2. Local OCR reads a scanned, signed page.
  3. It flags the applicant, NINO, and funding source.
  4. Confirm each flag and keep the product and branch codes.
  5. Swap or black out the confirmed fields.
  6. Save the clean version locally.

What you need to provide

PII & financial identifiers detected

Categoryanonym.plus entity typeExample
NamesPERSONMarcus Hale → [APPLICANT]
IdentifiersUK_NINOQQ 50 98 22 B → [NINO]
FinancialUK_BANK_NUMBERfunding 40-12-19 11904456 → [SOURCE]
ContactEMAIL_ADDRESShale@example.co.uk → [EMAIL]
LocationLOCATION12 Pine Road, Leeds → [ADDRESS]
DatesDATE_TIMEDOB 1984 → [DOB]

Compliance achieved

Anonymise account-opening forms offline — see plans & start free →

Limitations & cautions

An application joins several identifiers on one page, so a single missed field can re-link the rest. A tax self-certification collected under the International Tax Compliance Regulations 2015 often sits on the same sheet — check that block too, not just the flagged boxes.

Frequently asked questions

Which fields does the tool target on an application?

The applicant name, National Insurance number, address, contact lines and any funding account. Those are the values MLR 2017 reg. 28 has you verify and FCA SYSC 3.1.1R has you control, which is exactly why a shared copy should not carry them.

Can I keep the product and branch codes?

Yes. Allow-list them so they survive the pass. The fee and account information the Payment Accounts Regulations 2015 require an applicant to receive is not personal data either, so it can stay and keep the form intelligible.

Is the signed page sent to a server?

No. The desktop app runs locally, so the application never leaves your machine and the record stays inside the firm's own systems, which is what FCA SYSC 9.1.1R assumes.