Pseudonymising Source of Funds Declarations for AML Compliance Review – UK GDPR-compliant anonymisation per MLR 2017
Source-of-funds declarations under Money Laundering Regulations 2017 identify purchaser or tenant, disclose fund origins, and attach evidence including bank statements, gift letters, and beneficial owner declarations. MLR 2017 requires CDD records retained for five years; estate agents in scope since 26 June 2017, letting agents since 10 January 2020. anonym.legal pseudonymises personal identifiers in these packs so AML compliance teams can review declaration adequacy without retaining personal data.
When this applies
This task applies when source-of-funds packs are reviewed internally by AML compliance officers, external compliance consultants, or quality-assurance teams assessing the firm's MLR 2017 compliance, and those reviewers require sight of the disclosure structure and evidence categories — not the individual's personal details — to complete their assessment.
How anonym.legal handles it
- Upload the source-of-funds declaration and all supporting evidence (bank statements, gift letters, beneficial owner declarations, sale proceeds certificates) to anonym.legal.
- The engine identifies the declarant's name, address, date of birth, bank account details, and any third-party donors or gift providers named in supporting documents.
- Each natural person is pseudonymised consistently across the declaration and all evidence; the fund origin description, fund amounts, and evidence categories are preserved.
- Bank statement entries naming third parties (e.g. salary payors, investment providers) are pseudonymised at the individual name level while transaction amounts and dates are retained.
- A mapping table is produced with UK/EU data residency.
- Release the pseudonymised pack for AML compliance review; restore originals before any regulatory submission or production to law enforcement.
What you provide
- Source-of-funds declaration form
- Supporting bank statements (certified copies)
- Gift letters naming donor and recipient
- Beneficial owner declaration if third-party funds are involved
- Sale proceeds certificate or mortgage redemption statement (if applicable)
Limitations & cautions
- Source-of-funds information submitted to law enforcement, the National Crime Agency, or as part of a Suspicious Activity Report must use the real identities of the declarant and any third parties — the pseudonymised version is for internal compliance review only and must never be used in regulatory submissions.
- MLR 2017 requires adequate customer due diligence with records retained for five years; pseudonymisation of the source-of-funds pack for internal review does not itself satisfy those CDD obligations.
- Bank account numbers and sort codes in bank statements are pseudonymised alongside personal names; retain the mapping key securely to cross-reference with the firm's AML records for the MLR 2017 five-year retention period.
FAQ
What is a source-of-funds declaration in conveyancing?
A source-of-funds declaration is the document — required under the Money Laundering Regulations 2017 — in which a purchaser or tenant evidences the origin of the funds used in a property transaction. It is a key component of customer due diligence and, in higher-risk cases, enhanced due diligence required under the MLR 2017.
Are bank account numbers treated as personal data in source-of-funds packs?
Bank account numbers and sort codes that can identify an individual account holder are personal data under UK GDPR when combined with a name. The engine pseudonymises them alongside the account holder's personal identifiers.
Can this workflow be used for reviewing a firm's AML file quality across multiple matters?
Yes. Upload multiple source-of-funds packs in a batch for a consistent quality-assurance review. The compliance team can assess the adequacy of the declaration structure and evidence across multiple matters without retaining client personal data.
Does the MLR 2017 require source-of-funds checks on all conveyancing transactions?
The MLR 2017 require customer due diligence and, in higher-risk scenarios, enhanced due diligence including source-of-funds verification. The specific trigger thresholds depend on the transaction's risk profile — obtain specialist AML compliance advice.
Are gift donors named in gift letters pseudonymised separately from the main purchaser?
Yes. Each named individual in the gift letter — donor and recipient — is pseudonymised with a unique pseudonym. The gift amount, the relationship description, and any declaration of non-repayment are preserved.