A protocol records steps and results within its stated scope. It does not automatically prove identity, beneficial ownership, lawful funding or complete compliance. Read it with source dates, inputs, limitations and your evidence. This guide describes a demonstrable protocol; verify actual features in the version you use.
What and when
Distinguish query time from source-data time. A query today against an older list is not a current check of today’s list. Each source should disclose origin, version/snapshot, retrieval and availability. A failed retrieval must not become “no match”.
Inputs matter too: names, variants and any identifiers used. “Company checked” does not establish whether related individuals, ownership or control were assessed. Results must correspond to actual inputs.
Matches need assessment
Similar names may refer to different people. Assess birth dates, nationality, addresses and available identifiers against relevant sources. Similarity scores are not legal conclusions. Record why each candidate was confirmed, excluded or left unresolved; removing it from a screen is not evidence.
No match does not exclude all sanctions. Name searches may miss ownership, sectoral measures, goods and services. State coverage limits. PEP and sanctions are different questions; one green status must not stand for both.
Technical output and human decisions
Distinguish retrieved data, customer declarations, manually verified evidence and reasoned conclusions. Statutory identification needs a permitted process, not simply a recorded name. Section 9 covers purpose, beneficial ownership, structure, monitoring and sources as applicable. Forms or protocols alone do not complete those measures.
Unperformed steps should remain visibly missing or inapplicable with a reason. An empty owner section does not prove the customer has no beneficial owner. Assess the complete file before deciding.
Export and rechecking
Store the protocol, relevant attachments and case link in your own archive. Check readability, version and source evidence availability. Rechecking creates a new timed record rather than retrospectively correcting the old result. Keep both, state what changed and assess whether measures need to change.
Practical steps
- Check input scope.
- Compare query and source times.
- Distinguish match, no match, unavailable and unresolved.
- Complete your own identification and due diligence.
- Retain reasoning and full export.
Illustrative scenario
A protocol shows a similar name but a different birth year. Staff verify other available identifiers and record why that candidate is excluded without declaring the entire deal risk-free.
When the situation differs
A source is unavailable but the export says “verified, no sanctions”. A retrieval failure must not be treated as a negative check.
What to document
- Protocol version and input
- Source dates and availability
- Human conclusion and supporting file
Common pitfalls
- Green scores as legal approval
- Todays query using old data
- Empty fields as negative results
Frequently asked questions
Is it a legal opinion?
No. It records stated steps, evidence and decisions. Evidential value depends on their accuracy and completeness.
Does it replace my archive?
Not automatically. The obliged entity must ensure statutory retention and availability; temporary tool storage is not its complete archive.
Put this guidance into practice
Choose a record for the step you are working on. Adapt it to your profession and actual case.
Complete client information online
Where to go next
- Identification and customer due diligence are different — Identity, purpose, beneficial ownership and funds: assign the correct customer measures.
- No match found: what the result actually means — How to interpret a negative sanctions result and recognise incomplete data, incorrect queries and restrictions outside lists.
Sources and legal references
- Zákon č. 253/2008 Sb., aktuální znění od 11. 1. 2026 ↗
§ 8–9, § 16 · accessed 2026-10-04
Editorial work and source checks are not independent legal approval of your particular process. Compare the conditions and exceptions with your own circumstances.
