CAAML registration after a bank closes your account: access, objection and removal

23 September 2026
Picture of Arslan Advocaten

Arslan Advocaten

Foto van Arslan Advocaten

Arslan Advocaten

Need help urgently?

Choose a location

CAAML registration after a bank closes your account: access, objection and removal

A CAAML registration is an internal registration by which a bank records that a customer relationship has ended because the customer due diligence could not be adequately completed. It is not a BKR credit registration and not automatically an accusation of fraud. Do you want the registration removed? Then look into the reason for it, the data used, the retention period and your personal interest. A registration must have a valid legal basis and must remain necessary and proportionate.

Nederlands: Lees dit artikel in het Nederlands: CAAML-registratie na bankopzegging: inzage, bezwaar en verwijdering

Türkçe: Bu makaleyi Türkçe okuyun: Banka hesabının kapatılmasından sonra CAAML kaydı: erişim, itiraz ve silme

Written by Onur Arslan, attorney at Arslan Advocaten. Registered in the specialisation register of the Netherlands Bar for employment law and personal injury. Last updated: 17 September 2026.

The abbreviation appears, among other places, in cases concerning ABN AMRO. Other banks may use different names and systems. Always ask, therefore, about the exact registration in your own file. Merely being told that you have been “registered internally” is not enough to determine which rules and consequences apply.

What does a CAAML registration mean?

In the banking practice discussed here, CAAML stands for a record of customers whose relationship was terminated because the investigation into money laundering risks could not be completed. The registration helps the bank recognise, when a new application is made, that there was an earlier problem with the customer due diligence. Its meaning derives from the system and policy of that bank, not from a general statutory register bearing this name.

Incomplete customer due diligence can have various causes. For example, you did not respond to questions, documents are missing, or the explanation of a flow of money does not match the bank statements. Legally, that is something different from proven money laundering. Your objection must therefore make clear what the bank actually alleges and which parts of it you dispute.

Even if you close the account yourself while the investigation is still ongoing, a registration may become an issue. Closing the account yourself does not automatically erase the questions raised in the investigation. If you want to switch banks, ask how the investigation will be concluded and whether the bank will include data in an internal warning system.

The difference from BKR, IVR, EVR and an incident register

The consequences and assessment rules of registrations differ. A general request to erase “all blacklists” is therefore often too unfocused. First establish which systems have actually been used and which organisation is responsible for them.

Registration Core of the assessment
CAAML or a comparable internal system Reason relating to customer due diligence, internal purposes and retention policy
IVR (Internal Reference Register) Internal warning and the specific facts and interests on which the institution bases it
EVR (External Reference Register) External reference with conditions for inclusion and a separate proportionality test
Incident register Recording and investigation of incidents in accordance with the applicable rules
BKR credit registration Data on credit and payment behaviour, with its own rules on special codes

An external registration can warn other financial institutions. An internal CAAML entry has a more limited reach, but can still carry considerable weight within the bank group concerned. If there are several registrations, also read the overview of the EVR, IVR, CIS and the incident register.

Who can see the registration?

Ask the bank which legal entities have access, whether data are shared with group companies and for what purposes this happens. “Internal” does not necessarily mean that only one employee or one branch can consult the entry. Nor does it mean that every Dutch bank can view your file.

The ruling of Kifid, the Dutch Financial Services Complaints Tribunal, discussed below concerned access within ABN AMRO and its subsidiaries. That scope may not be transposed to all banks or future systems without verification. The privacy information, the applicable policy and the actual exchange of data in your case are decisive.

If an application at another bank is rejected, ask for that bank’s own reason for the rejection. Another bank may independently ask questions about transactions, consult a different registration or take its own acceptance decision. The rejection does not in itself prove that the bank has seen your CAAML entry.

Which legal basis can the bank rely on?

The GDPR requires a legal basis for processing personal data. For an internal warning, the bank may rely on a legitimate interest, such as recognising earlier problems with customer due diligence. It must then assess whether the processing is necessary and whether your interests or fundamental rights outweigh it.

The Wwft (the Dutch Money Laundering and Terrorist Financing Prevention Act) obliges banks to carry out customer due diligence, but does not automatically make every conceivable registration lawful. The bank must be able to explain why precisely these data, this scope and this duration are necessary. Moreover, a mandatory retention of investigation documents is not automatically the same as a need to maintain an active warning.

Ask for the legal basis for each processing operation. Different parts of the file may be retained on different grounds. A request can therefore be aimed at removal of the flag, rectification of incorrect data or restriction of use, without every historical bank document having to disappear.

What does the 2026 Kifid ruling teach us?

In Kifid 2026-0024, a CAAML registration was upheld. The consumer had ended the banking relationship on their own initiative. The explanation of the origin of the money was insufficiently supported by documents, so the customer due diligence could not be completed. The committee also took the limited reach of the registration and the personal circumstances into account in its decision.

This ruling does not mean that every internal registration is justified. Above all, it shows that an objection must address the specific missing information and the consequences for the person concerned. A general statement that the money is your own savings may be insufficient when the bank is investigating precisely the original source of those savings.

The five-year period applied in that case is not a general statutory retention period for all CAAML registrations. Ask which period your bank applies, when it starts and why it is necessary in your situation. Never adopt a period from a ruling as a universal rule without further verification.

Step one: request a complete but targeted overview

Ask in writing which registrations exist in your name, on what date they were entered and which data are processed in connection with them. Request the purposes, legal basis, recipients or categories of recipients and retention periods. Also ask which specific questions from the customer due diligence have, according to the bank, remained unanswered.

A subject access request gives you a right of access to your personal data and the associated information. It is not an unlimited right to every internal document in its original form. The rights of third parties, confidential information and specific statutory restrictions may play a role. Do, however, ask for any restriction to be explained with sufficient specificity.

Send your request through an official channel. Use a file number and keep the proof of dispatch. Do not provide additional identification details via an unknown link or an unexpected phone call. If the bank asks you to verify your identity, check the route before you send sensitive documents.

Step two: supply the missing substantiation

Compare the bank’s questions with your earlier answers. Which amounts were discussed? Over what period? Which documents are missing? Then prepare an overview in which each transaction is given an explanation and, where possible, a supporting document. This prevents a pile of loose documents from raising more new questions than it answers.

For savings, a series of statements may be relevant. For the sale of a home or a business, agreements and completion statements can help. For a loan, the agreement, the identity of the counterparty and payment trails are important. Which documents are reasonably required depends on the risk and the specific questions.

If you genuinely no longer have a document, explain this and describe which alternatives you have explored. A missing old document is not the same as a refusal to cooperate. Nevertheless, the absence of verifiable information may still have consequences. Read more about organising evidence in a Wwft investigation.

Step three: identify the error or the lack of proportionality

An effective objection distinguishes between factual inaccuracy and a balancing of interests. Inaccuracy concerns, for example, the wrong person, an incorrect amount, or an entry stating that you did not respond when you demonstrably did send documents. Enclose the correspondence with its date and acknowledgement of receipt.

As regards proportionality, the original registration may have been understandable, while its continuation has since become too burdensome. New documents, a completed investigation, a changed situation and demonstrable problems with essential services may be relevant. Do not merely state that the registration is unpleasant, but describe which specific obstacle it creates.

Also state which outcome you are asking for. That may be removal, a shorter duration, correction of the description or reassessment on the basis of new evidence. Alternative requests help to prevent the file from getting stuck in an all-or-nothing discussion without any examination of a less far-reaching solution.

Which documents strengthen your personal interest?

A rejection letter for an essential account, a pending application or a specific restriction within the bank group makes your interest clear. Describe what you need, why other options are insufficient and what consequences the refusal has. Share only the data needed for that purpose.

If you now have a fully usable account elsewhere, this may affect the weight of your interest. That does not suddenly make an incorrect registration correct, but it may make a difference to the question of whether immediate removal is necessary. Be complete, therefore, about the available alternatives and their limitations.

A fictitious example: an entrepreneur only has a personal account elsewhere, while the disputed registration blocks a business application within the same bank group. The substantiation must then make clear why business use elsewhere is not possible. Simply stating that “there is no account” while a personal account does exist makes the file unnecessarily vulnerable.

How quickly must the bank respond?

GDPR requests are in principle subject to a response period of one month. For complex or multiple requests, an extension of up to two months may be possible. The bank must notify you of the extension and the reason within the first month. An acknowledgement of receipt without a substantive response is not in itself a valid, completed answer.

A privacy request and a complaint about the service are different routes. State clearly that you are disputing the registration and, where relevant, also complaining about the way in which the account relationship was handled. For both parts, ask who is responsible and which procedure will be followed.

Above all, keep a record of the date of any rejection. Certain GDPR applications to the court are subject to a short time limit after the controller’s response. Have that time limit assessed immediately; do not assume that a pending complaint with the bank, Kifid or the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) suspends every other time limit.

Kifid or the court

For a consumer, Kifid may be an option if the financial service provider concerned is affiliated and the complaint falls within its jurisdiction and time limits. As a rule, the internal complaints procedure must be completed first. Opting for a binding procedure has consequences for what can still be brought before the court later.

The court may be appropriate when urgent relief is needed, the complaint does not fit Kifid or a specific GDPR route is used. The right procedure depends on the outcome sought. Proceedings about the registration are not automatically proceedings about restoring your payment account or compensation for damage.

If you also have problems with access to a bank account, deal with them in parallel if necessary. A new means of payment can limit urgent practical damage. That does not mean you have to withdraw your objection to the old registration or accept that it was justified.

Which mistakes can you avoid?

  • Do not rely solely on the abbreviation in a letter; ask for the system and its consequences.
  • Do not confuse incomplete customer due diligence with a proven finding of fraud.
  • Send missing source documents with a clear explanation and numbering.
  • Record the specific consequences before rejection messages or application details disappear.
  • In addition to removal, ask where necessary for rectification, restriction or shortening of the registration.
  • Monitor the time limits for privacy requests, complaints and court proceedings separately.

Do not alter documents to make a flow of money fit your earlier explanation better. If an earlier statement was incorrect or incomplete, correct it transparently. A verifiable supplement is far easier to assess legally than a file in which versions and dates no longer add up afterwards.

What should you ask if the bank only gives a general answer?

A statement that you do not fit within the risk policy often leaves unclear which data the bank retains. Split up your follow-up questions. First ask whether a registration exists, then what purpose it serves and next which specific personal data and categories of recipients are involved. Also ask which start date and intended retention period the bank applies. This makes your request easier to answer than a single general demand to erase all data.

The bank cannot always share every detail of the investigation. That does not mean every part of a subject access request is thereby automatically dealt with. Where a restriction applies, ask for an explanation to the extent one can be given, and have it assessed whether the statutory exception genuinely applies to the part concerned. In doing so, distinguish between insight into your personal data and a request to receive every internal document in full.

For a reassessment, the practical consequence is also important. Keep any rejection of a new application and note with which company within the bank group that application was made. Do not assume without confirmation that every rejection is caused by the same registration. A provider may also take a separate acceptance decision based on current information.

After a promised correction, ask for confirmation of exactly what has been changed. Does it concern removal, an amended description, a shorter period or merely a note of your objection? Check whether the recipients concerned should receive the correction and how the bank handles this. A general letter stating that your complaint has been dealt with does not necessarily provide clarity on this.

Frequently asked questions about CAAML registrations

Is a CAAML registration the same as a criminal record?

No. It is an internal processing operation by a bank and not a criminal conviction. The reason and the information included must be examined separately. A registration because of insufficient customer due diligence does not in itself prove that you have laundered money.

Can all banks see the registration?

That does not follow from the concept of CAAML. Ask about the actual scope. The Kifid case discussed concerned the bank involved and its subsidiaries. An external fraud registration or another bank’s own investigation is a different matter.

Will the registration disappear if I send documents after all?

Not automatically. The documents may, however, remove the reason for continuing it or make a new balancing of interests necessary. Ask for a substantive assessment and have the bank explain why the information is or is not sufficient.

May the bank always keep a registration for five years?

No. A period mentioned in a policy or a ruling does not exempt the bank from the necessity test. The bank must be able to justify the applicable duration and the interest in continuing the registration, taking into account the circumstances of your case.

Can I obtain compensation?

That requires a separate assessment of unlawfulness, damage and a causal link. An unpleasant experience or a successful correction does not automatically lead to compensation. Keep specific rejections, additional costs and other documents that demonstrate the consequences of the registration.

Can Arslan Advocaten help with a removal request?

Arslan Advocaten can assess the reason for the registration, the customer due diligence and your evidence, and prepare a targeted request or follow-up proceedings. For an initial assessment, send us the registration letter, the relevant questions from the bank, your answers and any rejections. Costs and any options for subsidised legal aid are discussed in advance.

Sources and legal basis

Sources checked on 16 September 2026. The applicable GDPR route, time limits and bank policy must be checked again when an individual case is handled.


Related Legal Services

Share this message

Facebook
Twitter
LinkedIn

Categories

Financial Law

Recent Posts

Need help urgently?

Choose a location