KYC redaction is the removal of personal data from a customer due-diligence file. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692) set the duty: reg. 27 says when due diligence applies, reg. 28 requires the customer to be identified and the identity verified from a reliable, independent source, reg. 33 adds enhanced measures for higher-risk cases, and reg. 40 requires the record to be kept for five years after the relationship ends. Proceeds of Crime Act 2002 s.330 makes non-disclosure in the regulated sector an offence, and s.333A makes tipping off one. anonym.plus marks each identity field on your device, so the file's structure stays while the data goes.
When this applies
A due-diligence file holds a passport image, a proof of address and a tax identification number. An external AML auditor, a correspondent institution or a remediation team needs the shape of the evidence, not the customer's identity in full. You trim the shared copy while the verified original stays on file for the five years reg. 40 requires.
How anonym.plus handles it
- Open the file in anonym.plus on your device.
- Local OCR reads the scanned passport or utility bill image.
- The tool flags name, document number, address and date of birth.
- Confirm each flag on the image pages — OCR is where errors hide.
- Swap or black out the marked items.
- Save the clean copy locally; the retained record is untouched.
What you need to provide
- The identity file (PDF, image scan, DOCX).
- An operator (Redact suits image evidence).
- Optional batch of up to 20 files per local run.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Daniel Okoye → [CUSTOMER] |
| National ID | NATIONAL_ID | passport scan → [NATIONAL_ID] |
| Identifiers | UK_NINO | QQ 33 07 71 C → [NINO] |
| Location | LOCATION | residence → [ADDRESS] |
| Dates | DATE_TIME | DOB 1975 → [DOB] |
| Contact | PHONE_NUMBER | +44 20 7946 0920 → [PHONE] |
Compliance achieved
- MLR 2017 reg. 27 sets when due diligence applies and reg. 28 requires identity to be verified from a reliable, independent source — the verified original must survive, so only a shared copy is redacted.
- MLR 2017 reg. 33 adds enhanced measures for a high-risk third country, a complex or unusually large transaction, or any case the firm rates as higher risk; those files hold more data and gain most from redaction before review.
- MLR 2017 reg. 40 requires the record to be kept for five years from the end of the business relationship or the occasional transaction — redaction never shortens that period.
- POCA 2002 s.330 makes failure to disclose in the regulated sector an offence and s.333A makes tipping off one; keeping the work offline means a due-diligence file is not exposed to anyone who should not see it.
Anonymise KYC documents offline — see plans & start free →
Limitations & cautions
OCR on a faint, skewed or laminated identity scan can miss a digit, and a machine-readable zone repeats the number in a second place. The tool does not decide whether reg. 33 enhanced measures apply. Check every image page before you release the copy.
Frequently asked questions
What do the MLR 2017 require for customer due diligence?
Regulation 27 sets the trigger and reg. 28 requires the firm to identify the customer and verify that identity from a reliable, independent source, including any beneficial owner. Regulation 40 then requires the record for five years. Redaction applies to a copy you need to share, never to the retained record.
Can it redact a scanned passport?
Yes. Local OCR reads the image first, including the machine-readable zone, then flags the document number, name and dates so you can black them out before the copy travels.
Does the file leave my machine?
No. The application works entirely offline, so identity evidence never reaches a cloud service — which matters when POCA 2002 s.333A makes tipping off an offence.