Onboarding form redaction is the removal of personal data from an intake packet. The packet does three regulatory jobs at once: it gathers the due-diligence evidence required by MLR 2017 regs. 27 and 28, it records the client categorisation the firm must make under FCA COBS 3 — retail client, professional client or eligible counterparty, with the elective professional tests in COBS 3.5 — and it feeds the financial-crime systems FCA SYSC 6.3 requires. UK GDPR Art. 13 governs the notice given when all of that was collected. anonym.plus marks each field on your device, so the layout stays while the data goes.
When this applies
An intake packet collects identity, banking, tax residence and categorisation consents at sign-up. A back-office vendor, an onboarding process audit or a migration test needs the workflow, not the client. You trim the packet before it moves, and the verified original stays inside the firm.
How anonym.plus handles it
- Open the packet in anonym.plus on your device.
- Local OCR reads the scanned, signed pages.
- The tool flags name, NI number, sort code and account fields.
- Confirm each flag and keep the categorisation and section codes.
- Swap or black out the marked items.
- Save the clean copy locally.
What you need to provide
- The intake packet (PDF, DOCX, or scan).
- An operator: Replace, Redact, or Mask.
- Optional batch for a stack of new sign-ups, up to 20 per run.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Priya Nair → [NEW_CLIENT] |
| Identifiers | UK_NINO | QQ 45 21 77 C → [NINO] |
| Financial | UK_SORT_CODE | link 30-00-00 8830 → [SORT_CODE] |
| Dates | DATE_TIME | DOB 1991 → [DOB] |
| Location | LOCATION | 12 Pine Road, Leeds → [ADDRESS] |
| Contact | PHONE_NUMBER | +44 113 496 9081 → [PHONE] |
Compliance achieved
- The identity evidence in the packet exists because of MLR 2017 regs. 27-28, and reg. 40 requires it for five years after the relationship ends — so the shared copy is redacted, never the verified original.
- FCA COBS 3 requires the firm to categorise the client as retail, professional or an eligible counterparty, with the qualitative and quantitative elective-professional tests in COBS 3.5; the categorisation evidence can stay while the identity goes.
- FCA SYSC 6.3 requires systems and controls that counter the risk of the firm being used to further financial crime; local, auditable redaction is part of how a packet moves safely between teams.
- UK GDPR Art. 13 governs what the client was told at collection, and Art. 5(1)(c) limits the onward copy to what the recipient actually needs.
Anonymise onboarding forms offline — see plans & start free →
Limitations & cautions
An intake packet groups many identifiers on a single page, so one missed field stands out badly. Faint scans lean on OCR, where a sort code digit can drop. The tool does not decide the client's COBS 3 category. Check image pages before you release the packet.
Frequently asked questions
What does client categorisation have to do with redaction?
COBS 3 requires the firm to categorise every client, and the packet holds the evidence — including the COBS 3.5 elective professional tests. A reviewer usually needs to see that the test was applied, not who applied it, so the categorisation answers can stay while the identity goes.
Can I process a stack of sign-ups together?
Yes. Batch mode handles up to 20 files per local run, with OCR for scanned pages and a shared alias map so the same person maps to the same label across the set.
Is the packet uploaded?
No. The desktop tool is fully offline, so onboarding data stays on your device — which supports the financial-crime systems expected by SYSC 6.3.