How Irish financial advisers can handle client ID documents securely

How small Irish advisory and brokerage firms can collect, store, share and delete client ID documents and fact-finds without relying on email attachments.

The short answer: keep client ID documents and fact-finds out of ordinary email. Instead, ask clients to upload passports, utility bills and bank statements through a secure portal or file request. Store each file once, in a client folder in Microsoft 365 that only the right people can open. Share reports with links that expire. Give every file a retention date and delete it when that date passes. Protect it all with multi-factor sign-in, encrypted laptops and tested backups.

This guide is for small advisory and brokerage firms in Meath, Cavan, Westmeath, Louth and Dublin. Specifically, it covers anti-money laundering (AML) ID checks and fact-finds. We’re an IT company, not a compliance firm, so check your obligations with your compliance adviser.

Why client ID documents need extra care in an advisory firm

Passports, utility bills, bank statements and payslips are highly sensitive. So one client file holds enough to steal someone’s identity.

Section 55 of the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 covers identity evidence. Designated persons must keep the original or a copy of each document used to verify a customer’s identity. Central Bank AML guidelines for the financial sector say firms can keep records evidencing identity on paper or electronically.

Fact-finds have their own rules. Regulation 16 of the Central Bank’s Consumer Protection Regulations 2025 covers knowing the consumer. Firms must gather and record sufficient information before recommending a financial service. On top of this, the GDPR requires security appropriate to the risk for all personal data (Article 32).

Stop collecting passports and bank statements by email

Most clients send documents by email because it’s easy. Plain email is still a poor home for client ID documents. Attachments sit in inboxes, sent folders and phones for years. As a result, anyone who gets into one of those mailboxes can read every attachment in it.

Give clients a better route, and tell them about it:

  • Secure upload links or file requests that drop documents straight into the right client folder.
  • A client portal, if your adviser software or a provider platform already offers one.
  • A note in your welcome letter saying which upload link to expect from you.
  • Scanning at the desk for clients who call in with paper copies, then handing the originals back.

Never act on changed bank details sent by email alone; confirm them by phone on a number you already hold.

Where client ID documents should live in Microsoft 365

Above all, pick one home for client files and stick to it. For most small firms that’s a SharePoint document library, with a folder per client. Avoid personal OneDrive folders, desktops and Downloads folders, which are hard to permission and easy to forget when someone leaves.

Then set access by role. The Data Protection Commission’s data security guidance says access to personal data should be on a “need to know” basis. For example:

  • Advisers open the client folders they work on.
  • Administration staff upload and file documents, but can’t change permissions.
  • A separate, tighter area holds AML risk assessments and other compliance records.
  • Leavers lose access on their last day, through a written joiners, movers and leavers process.

Keep each client’s ID and fact-find together, with clear file names and dates. Regulation 118 of the Consumer Protection Regulations calls for records that are complete, orderly, accurate and readily accessible.

Sharing fact-finds and reports with clients and providers

Outgoing files need the same care. Instead of attaching a suitability report or fact-find, share a link to the file in SharePoint. Limit the link to the named recipient and set an expiry date. If providers and lenders run their own portals, use those too. Every extra copy is another file to secure, retain and later delete.

How long to keep client ID documents, and when to delete them

Retention cuts both ways. Delete too early and you may struggle to show your checks later. Keep files forever and you hold more personal data than you need.

Section 55 sets the AML period. Designated persons must keep identity documents and CDD records for at least five years. That period runs from when the relationship ends or the last transaction, whichever is later. A 2018 amendment then requires firms to delete personal data kept solely for AML purposes once that period expires. Meanwhile, Regulation 117 of the Consumer Protection Regulations 2025 sets six-year periods for many consumer records. At the same time, the GDPR’s storage limitation principle in Article 5 limits how long you hold personal data.

Which period applies depends on the record and on how your firm is authorised. Agree a written retention schedule with your compliance adviser, then record a review date for each client folder. Microsoft 365 retention settings can also help, depending on your licences. A person should still check the list before the firm deletes anything.

Staff devices, multi-factor sign-in and backup

Turn on multi-factor authentication for every Microsoft 365 account. The NCSC’s guidance for SMEs recommends MFA on all systems and services. The DPC describes encryption as essential where personal data sits on a portable device. So encrypt every laptop, require a screen lock and make sure you can wipe a lost phone remotely.

A Microsoft 365 backup should cover email, OneDrive and SharePoint, kept separately from Microsoft. Test that you can restore a client folder. However, that backup won’t automatically cover adviser software, local files or every cloud platform.

Hypothetical example

A four-person advisory firm in Drogheda takes passports and bank statements by email. Because of that, one adviser’s inbox holds six years of client ID documents. The firm moves to one SharePoint library, with a folder per client and access by role. Clients now get a secure upload link, and every account uses multi-factor sign-in. The team encrypts each laptop and agrees a retention schedule with its compliance adviser. Finally, staff move old attachments into the right client folder or delete them on schedule.

How Sweeney Computer Services can help

Oliver Sweeney founded the company in 1985. Today we support more than 50 businesses and more than 10 schools from Hurdlestown, Kells, Co. Meath. We set up Microsoft 365 with multi-factor sign-in, role-based access and client folders that make sense. Gold adds Microsoft 365 admin, email security, phishing training and leaked-password alerts. It also includes 24/7 security monitoring through our security operations centre partner.

Both packages include Microsoft 365 backup of email, OneDrive and SharePoint, and we test restores every two weeks. Silver starts from €45 and Gold from €70 per user per month, excluding VAT. Microsoft 365 licences are billed separately. Our helpdesk runs Monday to Friday, 9am to 5:30pm, and after-hours emergency support costs extra.

See our financial services IT support, Microsoft 365, cybersecurity and backup and disaster recovery pages. Read our guide to IT security and managed support for Irish financial services SMEs. We’re an IT support company, not a compliance firm, and we don’t give legal or regulatory advice.

more insights