An account-opening form does two jobs at once. It records the contract, and it carries the customer due diligence MLR 2017 reg. 27(1)(a) requires whenever a business relationship begins. Reg. 28 sets what that means: identify the customer, then verify from a source that is reliable and independent of them. FCA SYSC 3.1.1R makes the firm organise and control that work responsibly, and SYSC 9.1.1R makes it keep orderly records of it. UK GDPR Art. 6(1)(c) is the lawful basis for the diligence part, Art. 6(1)(b) for the contract part. anonym.plus marks each field on your machine, so the form stays usable while the applicant details go.
When this applies
A branch sends a signed application to a training team building a worked example. The trainers need the layout and the product codes. They do not need the applicant's National Insurance number, address or funding account, so those come out first.
How anonym.plus handles it
- Open the application in anonym.plus on your device.
- Local OCR reads a scanned, signed page.
- It flags the applicant, NINO, and funding source.
- Confirm each flag and keep the product and branch codes.
- Swap or black out the confirmed fields.
- Save the clean version locally.
What you need to provide
- The application (PDF, DOCX, or scan).
- An operator (Replace keeps the form readable).
- Optional allow-list for product and branch codes.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Marcus Hale → [APPLICANT] |
| Identifiers | UK_NINO | QQ 50 98 22 B → [NINO] |
| Financial | UK_BANK_NUMBER | funding 40-12-19 11904456 → [SOURCE] |
| Contact | EMAIL_ADDRESS | hale@example.co.uk → [EMAIL] |
| Location | LOCATION | 12 Pine Road, Leeds → [ADDRESS] |
| Dates | DATE_TIME | DOB 1984 → [DOB] |
Compliance achieved
- Supports the identify-and-verify duty in MLR 2017 reg. 28, triggered at onboarding by reg. 27(1)(a).
- Backs the responsible-organisation duty in FCA SYSC 3.1.1R and the orderly-records rule in SYSC 9.1.1R.
- Separates contract processing under UK GDPR Art. 6(1)(b) from diligence processing under Art. 6(1)(c).
- Leaves the fee and account wording an applicant must receive under the Payment Accounts Regulations 2015.
- AES-256-GCM guards the working copies at rest; batch up to 20 forms per intake run.
Anonymise account-opening forms offline — see plans & start free →
Limitations & cautions
An application joins several identifiers on one page, so a single missed field can re-link the rest. A tax self-certification collected under the International Tax Compliance Regulations 2015 often sits on the same sheet — check that block too, not just the flagged boxes.
Frequently asked questions
Which fields does the tool target on an application?
The applicant name, National Insurance number, address, contact lines and any funding account. Those are the values MLR 2017 reg. 28 has you verify and FCA SYSC 3.1.1R has you control, which is exactly why a shared copy should not carry them.
Can I keep the product and branch codes?
Yes. Allow-list them so they survive the pass. The fee and account information the Payment Accounts Regulations 2015 require an applicant to receive is not personal data either, so it can stay and keep the form intelligible.
Is the signed page sent to a server?
No. The desktop app runs locally, so the application never leaves your machine and the record stays inside the firm's own systems, which is what FCA SYSC 9.1.1R assumes.