Customer due diligence (AML)
Customer due diligence is your AML portfolio. Here you create customer relationships, send a self-declaration with BankID, follow up reminders and close customer due diligence measures with a risk class — so the agreement can be signed when the customer assessment is complete. The agreement and self-declaration can be sent together in advance.
What you need
Before you start you need:
- Premium or Enterprise — the Customer due diligence menu item is only shown on these plans
- A role as member or administrator to create, start, remind and close (customer details also require member access)
- Recipient email when you start a measure
- Organisation number is recommended — used to link to the company and for a check before an engagement letter is sent
- The customer must be able to confirm identity with BankID
Customer due diligence is not in the compact side menu. Open More and find Customer due diligence under Accounting and finance, next to Company. The address is /kundetiltak — the old address /kunder redirects you there.
If the item is missing, the organisation is on Pro — upgrade to Premium or Enterprise.
Step 1: Find the portfolio
Open Customer due diligence. At the top you see counters:
| Counter | What it shows |
|---|---|
| Total | All customers in the portfolio |
| Waiting | Measure sent, waiting for BankID and self-declaration |
| Pending review | Self-declaration received, waiting for you to close the measure |
| Requires action | Self-declaration with findings that must be assessed and closed manually (for example PEP) |
| Overdue | The next review has passed |
Search by name or org. no. Click a column heading to sort. Status and risk are colour-coded — risk is shown as a small bar chart (low / normal / high). You can change Risk directly in the list. Last shows the last review, otherwise the last signing, otherwise the last send. Hover over Status to see who has signed, or who the invitation was sent to.
Step 2: Create a customer
- Click New customer
- Fill in Name (required)
- Optional: Org. no., Type, Risk, Responsible and Recipient email
- Click to create
A new customer gets status Missing measure. Fill in Recipient email at once — then you can start a measure from the list without entering the email again.
Type: AS, BA, ENK, NUF, Person or Other.
Risk: Not set, Low, Normal or High. You set the final class when you close the measure.
Step 3: Import from CSV (optional)
- Click Import CSV
- The file must have the columns (order and letter case do not matter):
name, orgNumber, legalType, responsibleUserId, lastReviewedAt, riskClass, recipientEmail
- Duplicate org. no. in the same organisation is skipped.
recipientEmailis optional. - Max 1000 rows per import
Without lastReviewedAt, imported customers get status Missing measure. With a valid date, status and next review are set from the risk class.
Step 4: Start customer due diligence
From the list: click Start measure on the row, or tick several and use Start measure for N. Customers waiting for BankID, or who have a measure pending review (self-declaration in, not closed), cannot be started again here — then Close measure is shown instead.
You can also open the customer and click Start measure.
Set recipient email once:
- when you create the customer
- by clicking Set email under the name in the list
- on the customer card under Identity
- or as the
recipientEmailcolumn in CSV
The next measure uses the stored address automatically. Email in the start dialog overrides and is saved for next time.
| Field | Options |
|---|---|
| Trigger | Onboarding, Periodic or Event |
| Declaration type | Company or ENK. The first choice is remembered; you can change it later |
| Recipient email | Prefills from the customer. Saved if you enter a new one |
| Send invitation by email | On by default |
When the measure is started:
- The customer receives an email with a link to the self-declaration (valid 30 days)
- Status becomes Waiting for BankID
- A smart task Customer due diligence — [customer name] is created in Tasks
Fill in the email in the start dialog. Without a recipient the invitation cannot be sent.
Step 5: What the customer does
The customer opens the link (no sign-in in Revizo):
- Reads the privacy text (no consent box — the measure is legally required)
- Confirms identity with BankID
- Completes the self-declaration (the questions follow Finanstilsynet’s guidance to the Norwegian Money Laundering Act, 2022):
- Beneficial owners — ownership and control, not only a 25 % ownership share
- Politically exposed person (PEP): the customer, the person acting on behalf of the customer, power of disposal and beneficial owner, plus close associates
- Purpose of the customer relationship, intended nature and origin of funds
- Name and position / role of the person acting on behalf of the customer
- Confirmation that the information is correct
- Submits and can download a PDF copy
After submission the measure goes to Pending review on your side. The task in Tasks is updated.
That the customer has submitted the declaration is not the same as the customer due diligence being completed. The agreement can be sent together with the declaration, but signing waits until the case handler completes the customer assessment. No extra approver is required to close the measure.
Step 6: Close the measure
When the self-declaration is in, click Close measure on the list — or open the customer and close there. The same fields apply. Above the form a hint from the self-declaration is shown (PEP, incomplete answers) and a short summary of the customer’s answers. The hint is guidance, not an automatic risk class.
| Field | Rule |
|---|---|
| Risk class | Required — cannot be «Not set» |
| Risk justification | Required for all risk classes |
| Origin of funds | Required for PEP (text) |
| Documentation | Optional in Revizo: attachment or archive reference where you store supporting documents (for example approval from a superior) for PEP/high risk |
| Customer assessment | Role/authority, ownership control with source, PEP check and internal routines |
| PEP attestation | Required for PEP — the case handler must confirm that the firm’s documented approval from a superior has been obtained. Revizo does not obtain or verify that approval |
| Enhanced measures | Required for PEP or High risk — one tick |
For PEP the risk class must be High. You fill in the origin of funds, tick that enhanced measures have been carried out and documented in the archive, and press Close measure. The tick applies to the current self-declaration — a new send requires a new confirmation. Supporting documents (for example key figure analysis) can be stored in the document archive; that is optional storage, not the same as the PEP attestation. Enhanced measures also apply at high risk without PEP.
Next review is calculated from the close date:
| Risk class | Interval |
|---|---|
| Low | 36 months |
| Normal | 24 months |
| High | 6 months |
Use Save assessment draft when you need to continue later. Each finding gets its own clarification. You can choose an earlier control deadline than the standard interval.
After closing, status becomes Customer due diligence approved. The smart task is completed.
If you change the risk class directly in the list, the same rules apply as in the close dialog: Low requires a justification, and you cannot set the class back to «Not set» on a customer with a completed measure (then the customer would have no next review). The change is logged. A changed risk class on a fully assessed customer requires a new customer assessment.
Step 7: Reminder
While status is Waiting for BankID:
- Send reminder on the customer card sends the same invitation again
- Revizo automatically sends a reminder 7 and 14 days after sending (max two automatic)
- The same customer never receives a reminder twice within 20 hours, regardless of whether it is you, the automatic reminder or a job that sends. A manual reminder early in the process does not turn off the automatic ones.
If the link has expired (30 days), start a new measure so the customer gets a new link.
Automatic job via AI chat
In the AI agent you can ask for a one-off run or a recurring job:
- «Send a reminder to everyone who is waiting»
- «Start measures for all customers who have an email»
- «Set up a weekly job that starts measures and sends reminders»
The agent first shows how many emails will go out, and waits for yes before anything is sent. A recurring job is shown in Tasks. The first round runs immediately. Cancel the task to stop the job.
The job only starts customers who have a recipient email, are not waiting for BankID, do not have a measure pending review, and where the measure is actually overdue or missing. Customers with a valid measure are never touched. Max 100 emails per round in total (start and reminder share the budget).
The job stops if you cancel the task. If you complete it, it continues in the next cycle.
Notifications
You get a notification in the bell (and push if it is turned on under Settings → Notifications → Customer due diligence):
- When the customer has submitted the self-declaration — open the customer and close the measure to set the risk class
- When an automatic job has started a measure or sent a reminder — go to Customer due diligence and follow the statuses
A notification about a submitted self-declaration goes to the person who started the measure and to the responsible person on the customer.
Step 8: Engagement letter
The agreement and self-declaration can be sent together in one link. The customer completes the declaration first. Signing opens after the case handler’s customer assessment, and work can start when the agreement is also signed.
The agreement overview shows what remains. New packages sent by email notify the customer when signing is ready. The customer uses the same link. An expired or replaced declaration requires an updated package.
Periodic AML review does not automatically require a new agreement signing. For an event-triggered review you describe what has changed.
Under Show ended there is a retention overview. The normal deadline is five years after ending, ten years for enhanced measures at ending. Older customers without a registered deadline are shown for manual assessment. The overview does not perform any deletion.
Statuses
| Status | Meaning |
|---|---|
| Missing measure | No completed measure |
| Waiting for BankID | Invitation sent, waiting for the customer |
| Pending review | Self-declaration received — close the measure to set the risk class |
| Customer due diligence approved | Valid measure, within the next review |
| Requires action | Findings in the self-declaration that must be assessed and closed manually (for example PEP) |
| Overdue | The next review has passed |
On the active measure internally: Waiting for BankID → Pending review → Completed. A new measure cancels the previous one — but if the customer has already submitted the self-declaration, you must confirm that you want to discard it before a new measure can be started.
End a customer relationship
On the customer card: End customer relationship. The customer is hidden from the list. Measure history and self-declarations are retained (documentation under the Norwegian Money Laundering Act). Open measures and pending links are cancelled.
Restore from the customer card if the relationship should continue. On the list: Show ended to find archived customers. The same org. no. cannot be created again while the customer is archived — restore instead.
Troubleshooting
I do not see Customer due diligence in the menu
The organisation is not on Premium or Enterprise.
«No recipient set on the customer»
Fill in Recipient email on the customer (the list or the customer card), or in the start dialog.
«BankID is not enabled in this environment»
BankID is not set up for this environment. Contact Revizo.
«The link has expired»
The self-declaration is valid for 30 days. Start a new measure and send a new link. A reminder is not sent on an expired link.
The customer has submitted the declaration, but the agreement cannot be signed
Check whether status is Pending review — then the customer has signed, but the measure is not closed. Close it and set a risk class. Also check that the org. no. on the agreement matches the customer.
Cannot send an engagement letter to the customer
Complete customer due diligence first, or log an exception with a justification. Check that the org. no. on the agreement matches the customer.
Something else?
Contact support with the error message you see, and we will help you further.