Skip to main content
Download free report
Softblues
Softblues
Back to Blog
Business Process Automation
July 13, 20269 min read

Automating Client and Matter Intake with AML and KYC Checks

UK corporate onboarding averages more than six weeks, and 70% of firms lost clients to slow intake last year. Here is how AI automates client and matter intake without weakening AML compliance.

Automating Client and Matter Intake with AML and KYC Checks

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude and Gemini implementations for finance, legal and healthcare teams across the UK and Ireland.

To automate client onboarding with AML AI, you let the system read incoming documents, extract the client and matter data, run screening against sanctions and PEP lists, draft the client and matter risk assessment, and route anything unusual to a human reviewer. UK firms typically cut intake from weeks to days without weakening compliance.

Here is the number that explains why this is worth fixing. UK financial services firms now spend £38.3 billion a year on financial crime compliance, and 95% of firms reported their costs rising (Oxford Economics with LexisNexis Risk Solutions, 2024). Most of that money buys manual work: chasing documents, re-keying data, filling in risk assessment forms. At SoftBlues, an AI consulting firm working with regulated mid-market companies across the UK and Ireland, intake is one of the first workflows we automate because the same checks repeat on every new client.

Six-stage automated client intake pipeline: documents arrive, AI extracts data, screening runs against sanctions and PEP lists, the risk assessment is drafted, a human reviews and signs off, the matter opens in the practice system.

Key facts

  • UK financial services firms spend £38.3 billion a year on financial crime compliance (market: Oxford Economics / LexisNexis Risk Solutions, 2024)
  • UK corporate banks report the slowest client onboarding globally, averaging more than six weeks (market: Fenergo, 2025)
  • 70% of financial institutions lost clients in the past year because onboarding was too slow, up from 48% in 2023 (market: Fenergo, 2025)
  • The SRA issued more than 35 AML fines totalling over £565,000 in 2025, with client and matter risk assessments the most common weak spot (market: First AML, 2025)
  • Reported use of advanced AI in KYC and AML work jumped from 42% in 2024 to 82% in 2025 (market: Fenergo, 2025)
  • Automation handles the document-heavy first pass; a named human still signs off every risk decision
  • Who this is for, and who it isn't

    This guide is for COOs, MLROs and compliance leads at UK accountancy practices, law firms, financial advisers and insurance brokers with roughly 50 to 500 staff, where new clients arrive weekly and every one needs AML and KYC checks before work starts.

    It is not for firms taking on a handful of clients a year (a good checklist is cheaper), and not for anyone hoping to remove human judgement from AML decisions. The regulations do not allow that, and neither would we.

    Why is client intake still so slow in regulated firms?

    Because the process was designed around documents, and documents arrive messy. A new corporate client might mean a certificate of incorporation, a shareholder register, passports for every beneficial owner, proof of address, source of funds evidence and an engagement letter. Someone has to read all of it, key it into the practice management system, run the screening checks, and complete a client and matter risk assessment.

    UK corporate banks, which have entire departments for this, still average more than six weeks to onboard a corporate client (Fenergo, 2025). Mid-market professional firms usually run the same checks with a fraction of the staff. The result is a queue, and clients notice: 70% of institutions surveyed lost clients in the past year because onboarding was too slow.

    The compliance risk runs alongside the commercial one. In its 2025 enforcement round the SRA found client and matter risk assessments were either missing or reduced to tick-box forms detached from the actual client, and up to 39% of reviewed files did not effectively assess AML risk (First AML, 2025). Slow and non-compliant is a bad combination.

    Important
    The goal of automation here is not fewer checks. It is the same checks, done consistently on every file, with the evidence trail written as you go.

    What does an automated intake workflow look like?

    The pattern we deploy has six stages. AI does the reading and drafting; people make the decisions.

    1. Capture. The prospective client uploads documents through a portal or emails them in. Nothing is re-typed. The system logs what arrived and what is still missing, and chases the gaps automatically.

    2. Extraction. An AI model reads each document and pulls the structured data: entity names, registration numbers, directors, beneficial owners with their ownership percentages, addresses, dates. It flags low-confidence reads instead of guessing.

    3. Screening. The extracted names run against sanctions lists, PEP databases and adverse media through your existing screening provider. The AI does not replace the screening database; it makes sure every relevant name actually gets screened, including the beneficial owners buried on page four of the shareholder register.

    4. Risk assessment drafting. The system drafts the client and matter risk assessment using your firm's own methodology: client type, jurisdiction, service, delivery channel, source of funds. Every field cites the source document it came from. This directly targets the weakness the SRA keeps fining firms for.

    5. Human review. A compliance reviewer sees the draft assessment, the screening results and the flagged exceptions in one place, and approves, escalates or rejects. High-risk matters go to the MLRO. The reviewer's decision and reasoning are recorded.

    6. Matter opening. On approval, the client and matter records are created in the practice management system, and the evidence bundle is filed for the audit trail.

    The honest version of the timeline: a standard low-risk client can move from documents-received to matter-open inside a day. Complex structures with overseas beneficial owners still take longer, because the delay is the human judgement, and that is the part you keep.

    Which checks can AI run, and which stay human?

    TaskAI handlesHuman keeps
    Document reading and data extractionYes, with confidence flagsReviews low-confidence items
    Identity document checksFirst pass (validity, consistency)Final acceptance on flagged items
    Sanctions, PEP and adverse media screeningRuns the checks, collates resultsReviews every hit and near-match
    Client and matter risk assessmentDrafts it, evidence-linkedApproves, adjusts, signs off
    Source of funds analysisSummarises evidence, flags gapsJudges whether it is satisfactory
    Enhanced due diligence decisionRecommends based on risk factorsDecides. Always.
    Ongoing monitoring triggersWatches for changes, re-screensActs on the alerts

    The regulatory logic behind this split is simple: the Money Laundering Regulations 2017 and the SRA's guidance require your firm to assess and own the risk. Software can prepare the assessment; it cannot own it.

    Two-column comparison: what AI takes over in client intake (reading documents, extracting data, running screening, drafting assessments, chasing missing items) versus what humans keep (approving risk assessments, judging source of funds, EDD decisions, signing off every file).

    How long does deployment take, and what does it involve?

    From our own UK engagements (indicative, July 2026), a working intake automation follows this shape:

    PhaseDurationWhat happens
    Discovery1 to 2 weeksMap your current intake, risk methodology and systems; agree scope
    Proof of concept2 to 4 weeksThe extraction and drafting pipeline running on your real (anonymised) files
    Production build4 to 8 weeksIntegration with your practice management and screening tools, review workflow, audit trail
    Parallel running2 to 4 weeksAutomated and manual intake side by side until the numbers hold

    We put systems like this into production in 90 days at a fixed price, with a money-back guarantee if it fails. The parallel-running phase matters more than any demo: you compare the AI-drafted assessments against what your team would have written, file by file, before anything relies on it.

    💡Tip
    Ask any vendor to run their extraction on ten of your real historic files before you sign. The gap between demo documents and your actual inbox is where these projects succeed or fail.

    How does this work under UK rules?

    Three regulators shape the design. For AML, the Money Laundering Regulations 2017 and your supervisor's guidance (the SRA for solicitors in England and Wales, the FCA for financial firms, HMRC or a professional body for accountants) require documented client due diligence and risk assessment. Automation strengthens this when every AI-drafted field carries its evidence source, and weakens it when it becomes a new tick-box.

    For data protection, UK GDPR and the ICO apply because you are processing identity documents at scale. The practical requirements: a lawful basis, a data protection impact assessment for the new processing, retention rules the system enforces, and clarity on where the AI provider processes and stores data. Ask your vendor the questions in our AI vendor security questionnaire before signing.

    And for accountability, whichever supervisor you answer to will want to see that a human made each risk decision. Design the audit trail first, not last.

    We have proposed exactly this evidence-first pattern for a regulated financial advice firm's monthly compliance file reviews; the approach is documented in our compliance file review automation case study.

    What are the red flags when buying intake automation?

    1. "Fully automated compliance." Anyone promising to remove the human review does not understand the regulations you answer to. Walk away.

    2. No confidence scores. If the extraction cannot say "I am unsure about this field", every output needs full manual re-checking and you have saved nothing.

    3. A generic risk model. Your client and matter risk assessment methodology is yours. A tool that imposes its own scoring will fail an SRA or FCA review of your firm's approach.

    4. Vague data-handling answers. Where do the documents go, who can see them, when are they deleted, is anything used for model training? Precise answers exist. Accept nothing less.

    5. No integration path. If it cannot write into your practice management system (Clio, LEAP, IRIS, Xero and their peers all have APIs), you are buying a second place to do the same work.


    Frequently asked questions

    Does the MLRO still have to sign off every client?

    Your firm's policies decide who approves what, exactly as today. What changes is what the approver sees: a drafted, evidence-linked assessment instead of a blank form and a folder of PDFs. High-risk matters should always route to the MLRO.

    Which documents can the AI actually read?

    Certificates of incorporation, shareholder registers, passports and driving licences, utility bills, bank statements, trust deeds and engagement letters are all standard. Handwritten or poorly scanned documents get flagged for a human rather than guessed at.

    Does our client data train the AI model?

    It must not, and with enterprise AI agreements it does not. Anthropic's commercial terms, for example, exclude customer data from model training by default. Confirm this in writing with any vendor, ours included.

    What happens to screening false positives?

    The same thing as today: a human reviews them. The difference is volume and presentation. Because the AI extracts complete, correctly spelled names with dates of birth, match quality improves, and the reviewer sees each hit with its context in one screen.

    Can we start with just one part of the process?

    Yes, and we recommend it. Document extraction plus risk assessment drafting is the highest-value first slice for most firms. Screening integration and matter opening can follow once trust is established.

    How do we measure whether it worked?

    Three numbers: days from first contact to matter open, compliance hours per new client, and the share of files that pass your own internal audit first time. Baseline them before the project starts.


    SoftBlues is a registered Anthropic Partner Network member and a registered Google Cloud and Microsoft partner. We build automation for regulated UK and Ireland firms, we run our own operations on Claude, and we deploy in 90 days at a fixed price with a money-back guarantee. If you want to see what your intake process would look like automated, book a discovery call or read more about business process automation. For the wider regulatory picture, see our guide to AI in financial services.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles