Corporate KYC Review Cost in UK Banks: A Diagnostic Guide
In short
DATS is the AI consulting system from DILR.AI that helps UK banks diagnose where the cost of a corporate KYC review actually sits before buying a build. This guide separates Money Laundering Regulations duties from bank practice, explains why most refresh timing is the bank's own policy, and shows where AI helps and where people decide.
DE
Dilr.ai EngineeringEngineering team
Published Oct 5, 2026Read 18 min
A corporate KYC review at a UK bank is one of the few compliance tasks that every relationship eventually triggers, and one of the least examined as a cost line. In Fenergo's KYC in 2023 survey, the most recent UK-specific figures we could verify, British banks were spending an average of $2,613 to complete a KYC review for a corporate client, up 19% year on year, and 39% of banks operating in the UK said they had lost clients to slow or inefficient onboarding (Fenergo). Those numbers are now three years old, which is itself part of the problem: most banks know their review cost only as a headline, not as a breakdown they could act on.
This guide is written for the Chief Risk Officer, who is measured on cost to income and on avoiding anti-money-laundering findings, and for the operations and technology leads who sit beside that role. Its scope is deliberately narrow. It takes one corporate review apart into its components, separating the duties the Money Laundering Regulations 2017 set from the practices banks use to evidence them, explains why the refresh schedule is the bank's own commitment rather than a regulator's, and sets out how to diagnose where review effort goes before anyone buys a build. It does not map every DILR line onto banking, which our AI in UK banking map already does, and it leaves the document-extraction and agent-desk questions to that map and to the line pages it links.
This guide is shipped by the team behind DATS, the five-stage AI consulting system that runs from Discover and Diagnose through to Scale and Run. Or see our AI operating model work, which covers governance, RACI and lifecycle, audit-ready by design.
What goes into a corporate KYC review at a UK bank?
A corporate KYC review at a UK bank combines customer due diligence duties from the Money Laundering Regulations 2017, namely verifying the entity, understanding its ownership and control, verifying beneficial owners and anyone acting for it, with the practices banks use to evidence those duties: screening the parties, a risk rating with written reasoning, and sign-off by a second reviewer.
The statutory core sits in regulation 28 of the Money Laundering Regulations 2017. For a body corporate, the bank must obtain and verify the name, company number and registered office address, and take reasonable measures to determine and verify the law the company is subject to, its constitution, and the full names of the board and the senior persons responsible for its operations. Regulation 28(3A) adds a duty to understand the ownership and control structure, and regulation 28(4) requires the bank to identify the beneficial owner and take reasonable measures to verify that person's identity. Regulation 28(10) then covers anyone purporting to act for the customer: the bank must verify that the person is authorised, identify them, and verify their identity from a reliable, independent source.
Two details change the shape of the work. First, regulation 28(5) disapplies the governing-law, constitution and board limbs, the ownership-structure limb and the beneficial-owner limb where the customer is a company listed on a regulated market, so a listed counterparty and a privately held trading group with offshore holding layers are not the same job. Second, regulation 28(12) says the extent of the measures must reflect the bank's own risk assessment and its view of risk in the particular case, and may differ from case to case. The law sets the components; the bank sets the depth.
The components of a corporate KYC reviewThe first three stages map to duties in regulation 28 of the Money Laundering Regulations 2017; screening, the risk rating and narrative, and sign-off are how banks apply and evidence those duties in practice.
Seen this way, a review is not one task but six, and they fail in different places. Entity identity for a UK company is comparatively mechanical, because the core data sits on a public register. Ownership and control is where the time goes on any group with more than one layer, because the analyst is rebuilding a structure chart from registry extracts, shareholder documents and the client's own answers. The risk narrative is where inconsistency creeps in, because two analysts given the same file can write different explanations of the same rating. That is the first useful finding for a cost diagnosis: the expensive stages are the ones where judgement and assembly are tangled together, and it is the stage-level view the team behind Dilr.ai starts from.
Why does the KYC refresh clock belong to the bank, not the regulator?
The KYC refresh clock belongs to the bank because the Money Laundering Regulations 2017 do not fix a review interval for most existing customers. Regulation 27(8) requires due diligence at other appropriate times on a risk-based approach, and whenever the bank becomes aware that circumstances relevant to its risk assessment have changed. The bank's own risk-rated review policy is what turns that duty into dates.
The text of regulation 27 is worth reading closely, because it is often summarised as a fixed regulatory deadline. Paragraph (8) lists the occasions on which a bank must apply customer due diligence to an existing customer: when it has a legal duty in the calendar year to contact the customer to review beneficial ownership information, when it must contact the customer for international tax compliance purposes, at other appropriate times on a risk-based approach, and when it becomes aware that circumstances relevant to its risk assessment have changed. Paragraph (9) then lists what the bank must weigh in deciding when, including any change in the identity of the customer or its beneficial owner, transactions not reasonably consistent with what the bank knows, and a change in the purpose or nature of the relationship.
The calendar-year beneficial-ownership contact in paragraph (za) and the tax-compliance contact in (zb) are genuine fixed triggers, but they arise from other legal duties to contact the customer; the routine refresh cycle is otherwise set by the bank. Regulation 28(11) completes the picture: ongoing monitoring includes undertaking reviews of existing records and keeping due diligence documents and information up to date. The duty binds the relevant person, which here is the bank. It does not bind a technology vendor, a consultant or the customer. Making that ownership explicit, stage by stage, is part of any AI operating model for a regulated process.
This matters commercially. When a bank writes a policy saying high-risk corporates are reviewed annually and others every two or three years, that policy becomes the bank's own commitment, because it is how the bank evidences a risk-based approach, and falling behind it is a gap measured against the bank's own standard. A backlog therefore compounds for a reason of the bank's own making: each review missed this year lands on top of next year's cohort, and the event-driven reviews triggered under regulation 27(8)(b) arrive on no schedule at all. A refresh programme that is permanently behind is not a staffing anomaly. It is a sign that the cycle lengths in the policy and the cost per review in operations were never reconciled. Our enterprise AI consulting guide covers the broader question of how to decide where a build belongs before choosing one.
Where does the cost of a corporate KYC review actually go?
The cost of a corporate KYC review has to be read as elapsed time as well as money. Fenergo's KYC in 2023 survey found UK review costs up 19% year on year, with UK firms taking 17 more days per review than in 2022 while UK KYC staff numbers rose 1%. The public figures give totals, so where those days go inside a bank is something it must measure itself.
In money terms, the same Fenergo survey put the average UK corporate review at $2,613. The trend in elapsed time is the clearer signal. Globally, it found banks took an average of 95 days to complete a KYC review in 2023, up from 84 days in 2022. A review that takes around three months of elapsed time is not necessarily three months of work, which is why elapsed days and analyst hours have to be measured separately.
Average days to complete a KYC review, globalGlobal average elapsed time to complete a KYC review rose from 84 days in 2022 to 95 days in 2023, both figures from the same Fenergo KYC in 2023 survey. Source: Fenergo, KYC in 2023 survey (press release)
Fenergo's published summary does not give a stage-by-stage split of where those days go, and no honest guide should invent one. What a bank can do is measure its own. A diagnostic can test four candidate cost drivers, each of which can be timed on real files:
Cost driver
What it looks like on the floor
What to measure
Outreach and chasing
Requests for documents the bank already holds, or holds in another system
Days between first request and complete file
Structure rebuilding
Analysts redrawing ownership charts from scratch on each refresh
Analyst hours on ownership and control per file
Narrative inconsistency
Different reasoning for the same risk factors across analysts
Rate at which four-eyes review returns files
Rework after QA
Files reopened because evidence is missing or stale
Share of files reopened, and hours per reopen
The measurement point is important because it changes what the bank buys. If most of the elapsed time is in outreach, the fix is communication and data reuse. If most of the analyst hours are in structure rebuilding, the fix is persistence of the ownership picture between cycles. If most of the cost is rework, the fix is a consistent narrative standard and better first-pass evidence. Each of those leads to a different build, and buying the wrong one is how a bank ends up with a tool that makes one stage faster while the review takes just as long. The same before-and-after discipline appears in our guide to pre-pilot baseline measurement, written for voice deployments but directly transferable.
Once the stages are measured, the build itself is the work of our AI execution office, embedded delivery with production placements the client owns.
How did Companies House identity verification change corporate KYC inputs?
Companies House identity verification changed corporate KYC inputs by making directors and people with significant control verify their identity with the registrar. From 18 November 2025, new directors and PSCs must verify, while existing directors and PSCs verify within a twelve-month transition. A bank gains better register data, but the Money Laundering Regulations still require its own beneficial-ownership verification.
Companies House announced the rollout on 5 August 2025 and estimated that 6 to 7 million individuals would need to verify their identity by mid-November 2026. Verification runs through GOV.UK One Login or through an Authorised Corporate Service Provider. For a bank reviewing a UK private company, the practical effect is that the people named on the register are increasingly people whose identity someone has checked, which Companies House expects to improve the quality and reliability of its register data.
It does not remove the bank's own duty, and the regulations say so in terms. Regulation 28(9) of the Money Laundering Regulations 2017 states:
"Relevant persons do not satisfy their requirements under paragraph (4) by relying solely on information delivered to the registrar under any enactment that requires information to be delivered to the registrar about registrable persons, registrable relevant legal entities or registrable beneficial owners."
That sentence, from regulation 28(9), is the boundary a KYC build has to respect. A register lookup is an input to beneficial-ownership verification, not a substitute for it. A design that treats a verified Companies House record as the end of the ownership stage would be faster and non-compliant at the same time. A design that treats it as a strong first input, then focuses analyst effort on the cases where the register is silent, foreign or inconsistent, is where the time saving is real. Our banking AI map shows where this review sits among the other places AI pays in UK banking.
What does the FCA's enforcement record say about KYC quality?
The FCA's enforcement record says that financial crime controls must keep pace with a bank's growth. In July 2025 the FCA fined Monzo for inadequate financial crime systems and controls, including onboarding and customer risk assessment, and described it as the tenth fine on a bank for financial crime control failings in four years. Any KYC saving has to leave those controls intact.
The FCA's press release is specific about what went wrong, and sets the fine at £21,091,300. Between October 2018 and August 2020, the bank failed to design, implement and maintain adequate customer onboarding, customer risk assessment and transaction monitoring systems, and between August 2020 and June 2022 it signed up over 34,000 high-risk customers in breach of a requirement not to. The case is primarily an onboarding case rather than a corporate refresh case, so it should not be read as a direct parallel. Its lesson for a corporate KYC programme is about sequencing: controls that do not keep pace with volume eventually become a supervisory problem, and the press release records what followed: a fine, an independent review of the financial crime framework and a change programme.
For a CRO, this sets the frame for any automation conversation. The objective is not a cheaper review. It is a review whose cost per file holds steady as the book grows, without any loss of the evidence a supervisor would ask to see. A build that lowers cost by dropping steps fails that test immediately. A build that lowers cost by removing duplicated assembly, so analysts spend their hours on the judgement the file actually needs, passes it. Our guide to AI governance for the FCA and the ICO covers how firms keep an inventory of the AI tools that touch regulated processes like this one, which is where a supervisor's first questions usually start.
Where can AI cut the cost of a KYC review, and where must it not?
AI can cut the cost of a corporate KYC review in the assembly work: pulling existing records into a draft file, keeping the ownership picture current between cycles, flagging changes that trigger an event-driven review, and drafting a consistent first narrative for an analyst to test. It must not make the risk decision or the sign-off, which stay with accountable people at the bank.
That division matches how UK firms already use AI. The Bank of England and FCA survey published in November 2024 found that 75% of financial services firms were already using AI, but only 2% of use cases involved fully autonomous decision-making. The same survey found that just 34% of respondent firms said they had complete understanding of the AI technologies they use, against 46% reporting only partial understanding, largely because of third-party models. For a KYC build, that second finding is the design constraint: a bank must be able to explain why a draft narrative said what it said, and to show that a person tested it.
Four placements usually carry most of the value, and each maps back to one of the cost drivers above:
Pre-population from records the bank already holds. A refresh begins with what the bank knew last time, so outreach asks only for what is missing or changed.
A persistent ownership picture. The structure chart is kept between cycles and updated on change, rather than rebuilt from scratch at each refresh.
Change detection for event-driven reviews. Signals that regulation 27(9) lists, such as a change in beneficial owner or in the purpose of the relationship, are surfaced when they happen rather than found at the next scheduled cycle.
A drafted first narrative. The analyst starts from a consistent draft against the bank's own risk factors and edits it, which reduces variation between reviewers and makes four-eyes review faster.
Where the model runs is a separate decision. Customer due diligence files contain personal data about directors and beneficial owners, so whether a build runs inside the bank's own environment, on a cloud tenancy the bank controls such as Azure, AWS or Google Cloud, or through a third-party service is a question of data protection, model risk and operational resilience together. A bank's model risk function will also want to know which model produced which draft. That choice belongs in the diagnostic, weighed against the bank's own risk appetite, not settled by whichever vendor arrives first. The adjacent explainability questions are worked through in our guide to AI auditability and explainability.
Two of the four placements also connect to work other DILR lines do. Outbound document chasing is the kind of campaign Dilr Voice runs from an uploaded contact list with a full audit trail on every call, which our voice collections guide for fintech explores for a neighbouring use. Case preparation shared between people and agents is where Cognibl, from DILR.AI, applies its rule that a task reaches done only once a proof version is attached. Both sit downstream of the diagnosis this guide describes.
How should a bank diagnose its KYC cost before buying a build?
A bank should diagnose its KYC cost by timing its own reviews stage by stage before choosing any tool. That means sampling recent corporate files, measuring elapsed days and analyst hours per stage, recording reopen rates after four-eyes review, and reconciling policy cycle lengths with actual capacity. The diagnosis produces a ranked list of placements, and only then a build decision.
DATS runs this as its first stage, Discover and Diagnose, followed by Prioritise and Place. The output of the placement work is a ranked roadmap of where AI belongs in the KYC process and, just as usefully, where it does not. A diagnostic may well find that some stages do not justify a build: entity identity for a UK company, for example, is comparatively mechanical, and adding a model to it may add cost and risk without saving much time.
A workable diagnostic sequence for a corporate KYC function looks like this:
Sample the book by risk tier. Pull recent completed reviews across high, medium and low risk, listed and private, UK and foreign-owned, so the measurement reflects the real mix.
Time each stage. Record elapsed days and analyst hours against the six components, including the waits between them.
Count the reopens. Measure how often four-eyes review returns a file and why, which shows where narrative and evidence quality break.
Reconcile policy with capacity. Compare the review volume the policy cycles generate each year with the volume the team can actually complete at its measured cost per file.
Rank the placements. Score each candidate build on hours saved, evidence quality and model risk, and choose a small number to ship.
That last step is where discipline pays. DATS works to a stated delivery discipline of three shippable placements a year, with a named owner for each. For a KYC function, that might mean a persistent ownership picture in the first placement and a drafted narrative in the second, each measured against the baseline from step two. Our DATS methodology page sets out the five stages in full, and the six named enterprise AI solutions cover other functions where the same placement discipline applies.
The policy reconciliation in step four often produces the most uncomfortable finding. If a bank's cycles generate more reviews each year than the team can complete, no amount of automation in one stage will close the gap unless it is large enough to change the arithmetic. Sometimes the right first move is to revisit how risk tiers are assigned, so that high-risk cycles fall on files that are genuinely high risk. HM Treasury's July 2025 consultation response on the Money Laundering Regulations describes changes intended to ensure customer due diligence is targeted at high-risk activity, with other issues to be addressed through guidance, which is the same principle a tiering review applies.
What is the best way for a UK bank to cut KYC review cost in 2026?
The best way for a UK bank to cut corporate KYC review cost in 2026 depends on where its cost sits. If most cost is workflow friction across systems, a client lifecycle management platform may be the better first purchase. If cost sits in assembly and narrative judgement, a measured, placement-first build pays more. In either case, the bank should diagnose first and keep accountable people on every risk decision.
The criteria that separate good options from bad ones are consistent. A credible approach measures a baseline before it changes anything, keeps a person accountable for every risk rating, can explain its outputs to the bank's model risk function, respects regulation 28(9) on the limits of register data, and shows its effect as a cost per file that holds as the book grows.
Against those criteria, the honest concession is that DATS is not always the right first call. A bank whose reviews are slow mainly because files move between disconnected systems may get more from a dedicated client lifecycle management platform such as Fenergo, which describes itself as a provider of client lifecycle management solutions. A bank facing a large, deadline-driven remediation after a supervisory finding may prefer a large firm such as Deloitte, PwC, EY or KPMG for a deadline-driven remediation. Where DATS fits is the space between: a bank that knows its review cost is rising, does not yet know which stage is driving it, and wants senior practitioners who ship code, not decks, to find out and then build the few placements that change the number, which starts with a short scoping conversation. The AI pilot purgatory guide explains why pilots that skip that diagnosis tend to stall.
Does Companies House identity verification mean a bank can skip beneficial-ownership checks?
Companies House identity verification does not let a bank skip beneficial-ownership checks. Regulation 28(9) of the Money Laundering Regulations 2017 says a bank does not satisfy its beneficial-owner duties by relying solely on information delivered to the registrar. Verified register data is a stronger input from 18 November 2025 onwards, but the bank must still identify beneficial owners and take reasonable measures to verify them itself.
Can AI make the final risk decision on a corporate KYC file?
AI should not make the final risk decision on a corporate KYC file at a UK bank. The Money Laundering Regulations 2017 place customer due diligence duties on the bank as the relevant person, and supervisors expect accountable people to own risk ratings. AI can assemble evidence, flag changes and draft a narrative, while an analyst tests the draft and a second reviewer signs the file off.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
AI consulting UK banking KYC costbankingKYC review cost UK bankscorporate KYC review UKcustomer due diligence corporate clientsai consulting redditbest ai consultancy uk 2026dats
Questions this article answers
What goes into a corporate KYC review at a UK bank?
A corporate KYC review at a UK bank combines customer due diligence duties from the Money Laundering Regulations 2017, namely verifying the entity, understanding its ownership and control, verifying beneficial owners and anyone acting for it, with the practices banks use to evidence those duties: screening the parties, a risk rating with written reasoning, and sign-off by a second reviewer.
Why does the KYC refresh clock belong to the bank, not the regulator?
The KYC refresh clock belongs to the bank because the Money Laundering Regulations 2017 do not fix a review interval for most existing customers. Regulation 27(8) requires due diligence at other appropriate times on a risk-based approach, and whenever the bank becomes aware that circumstances relevant to its risk assessment have changed. The bank's own risk-rated review policy is what turns that duty into dates.
Where does the cost of a corporate KYC review actually go?
The cost of a corporate KYC review has to be read as elapsed time as well as money. Fenergo's KYC in 2023 survey found UK review costs up 19% year on year, with UK firms taking 17 more days per review than in 2022 while UK KYC staff numbers rose 1%. The public figures give totals, so where those days go inside a bank is something it must measure itself.
How did Companies House identity verification change corporate KYC inputs?
Companies House identity verification changed corporate KYC inputs by making directors and people with significant control verify their identity with the registrar. From 18 November 2025, new directors and PSCs must verify, while existing directors and PSCs verify within a twelve-month transition. A bank gains better register data, but the Money Laundering Regulations still require its own beneficial-ownership verification.
What does the FCA's enforcement record say about KYC quality?
The FCA's enforcement record says that financial crime controls must keep pace with a bank's growth. In July 2025 the FCA fined Monzo for inadequate financial crime systems and controls, including onboarding and customer risk assessment, and described it as the tenth fine on a bank for financial crime control failings in four years. Any KYC saving has to leave those controls intact.
Where can AI cut the cost of a KYC review, and where must it not?
AI can cut the cost of a corporate KYC review in the assembly work: pulling existing records into a draft file, keeping the ownership picture current between cycles, flagging changes that trigger an event-driven review, and drafting a consistent first narrative for an analyst to test. It must not make the risk decision or the sign-off, which stay with accountable people at the bank.
How should a bank diagnose its KYC cost before buying a build?
A bank should diagnose its KYC cost by timing its own reviews stage by stage before choosing any tool. That means sampling recent corporate files, measuring elapsed days and analyst hours per stage, recording reopen rates after four-eyes review, and reconciling policy cycle lengths with actual capacity. The diagnosis produces a ranked list of placements, and only then a build decision.
What is the best way for a UK bank to cut KYC review cost in 2026?
The best way for a UK bank to cut corporate KYC review cost in 2026 depends on where its cost sits. If most cost is workflow friction across systems, a client lifecycle management platform may be the better first purchase. If cost sits in assembly and narrative judgement, a measured, placement-first build pays more. In either case, the bank should diagnose first and keep accountable people on every risk decision.
DE
Dilr.ai Engineering
Engineering team
Dilr Voice
Voice AI built for your sector
Dilr Voice answers and places calls 24/7 with compliance rules for regulated industries, from clinics and estate agents to financial services.