Module 04 | Global Financial Crimes, Risk, and RegTech Library
Research verification date: 9 August 2026
Important notice: Educational material only; not legal advice. It does not determine obligations in any jurisdiction or replace counsel, regulatory engagement, or an institution-specific risk assessment.
Source Quality and Currency Note
This module uses primary sources first: the FATF Recommendations and FATF guidance; statutes and regulations; regulator and supervisor handbooks; official supervisory publications; and public enforcement actions. It distinguishes legal requirements from supervisory expectations and from the operating recommendations developed for this library. Time-sensitive material was verified on 9 August 2026. The legal treatment of customer due diligence, beneficial ownership, politically exposed persons, screening, data retention, and customer restrictions differs by entity type and jurisdiction. The United States is considering further AML/CFT-program reforms, while the EU Anti-Money Laundering Regulation (AMLR) will generally apply from 10 July 2027. Neither proposed rules nor future application dates are treated in this module as current universal obligations. [S01][S06][S09]
How to Use This Module
This module concerns the lifetime of a relationship: deciding whether to enter it, establishing what is known and how well it is known, assigning a risk view, changing that view as facts change, applying proportionate diligence, and deciding whether to continue, limit, escalate, or exit. It does not replace the dedicated business-verification and beneficial-ownership analysis in Module 5, sanctions mechanics in Module 6, monitoring design in Module 7, or country deep dives in Modules 19-24. It provides the common relationship-control model that those later modules will extend.
Read in three passes where useful:
- Enterprise leader pass: Executive Thesis; Sections 1, 3, 6, 10, and 12; the maturity profile; and executive discussion questions.
- Operator pass: Sections 2 through 9; the decision architectures; lifecycle metrics; process ownership; case lenses; and the practitioner checklist.
- Specialist pass: Sections 4, 7, 8, 9, and 13; evidence objects; identity uncertainty; data lineage; test design; jurisdictional comparison; and the glossary.
Learning Objectives
By the end of this module, the reader should be able to:
- Explain the difference between CIP, KYC, CDD, EDD, continuous CDD, and customer-life-cycle management without treating those terms as interchangeable legal labels.
- Design a risk-based customer lifecycle from identity collection through restriction, reporting, remediation, and exit.
- Distinguish an identity assertion, an identity verification result, an ownership fact, a risk factor, an investigative allegation, and a decision record.
- Build a customer-risk-rating system that changes due-diligence depth, approval authority, refresh cadence, transaction expectations, and testing - rather than merely producing a score.
- Design proportionate EDD for PEPs, relatives and close associates, complex structures, high-risk geographies, negative information, inconsistent wealth or funds, and material behavioral changes.
- Assess remote onboarding, vendor data, alternate identity evidence, risk signals, adverse media, and source-of-funds/source-of-wealth evidence without turning any one source into an automatic decision.
- Define the global core and local edge for group-wide KYC and customer-risk controls.
- Test whether a relationship-control program can prove completeness, timeliness, judgment quality, data lineage, and defensible customer outcomes.
Key Terms Used Deliberately
Know your customer (KYC) is an industry term for the operational discipline of identifying, verifying, understanding, risk-assessing, and keeping current the knowledge needed to manage a customer relationship. It is not a single universal legal requirement.
Customer identification program (CIP) is a specific U.S. regulatory construct for certain financial institutions. For banks, it requires a written, risk-based program to verify identity to the extent reasonable and practicable, enabling the bank to form a reasonable belief that it knows the true identity of each customer. [S04]
Customer due diligence (CDD) is the broader set of risk-based measures used to identify and verify customers and beneficial owners, understand relationship purpose and expected activity, identify relevant risk factors, and conduct ongoing monitoring and updates. The precise legal scope differs by jurisdiction and sector. [S01][S05][S09]
Enhanced due diligence (EDD) means additional, targeted measures when a relationship or event is higher risk or a rule requires them. It is not a longer document list. Good EDD tests the concern that made the relationship higher risk and changes monitoring, approval, restrictions, or a decision where necessary.
Ongoing CDD is the continuous obligation to keep customer knowledge adequate for the risk: monitor activity and behavior, update KYC data as appropriate, reassess risk, and trigger additional evidence or action when facts change. [S05][S09]
Customer lifecycle means the full system of decisions from prospecting and onboarding to product change, periodic review, event-driven review, restriction, report, remediation, and exit. A lifecycle design is stronger than a static onboarding file because it makes change explicit.
Executive Thesis
KYC and CDD are commonly described as onboarding controls. That framing is too narrow. A relationship becomes risky when what the institution believes about the customer, their owners, their purpose, their expected activity, or their authority to use the relationship ceases to be adequate. That can happen before account opening, immediately after it, years later through a change of ownership or behavior, or at the moment a transaction exposes a fact that prior diligence did not explain. The control objective is therefore not to collect documents. It is to maintain a defensible, proportionate, decision-useful understanding of a relationship as it evolves.
That objective changes the executive question. The question is not: What documents do we require? It is: What must be sufficiently true, sufficiently evidenced, sufficiently current, and sufficiently connected to activity for us to enter, retain, expand, restrict, or exit this relationship? The answer requires choices about risk appetite, customer strategy, product design, identity technology, data sources, information security, operations capacity, legal interpretation, exception authority, and customer treatment. It also requires distinguishing uncertainty from suspicion, and a risk factor from a conclusion.
The international baseline is clear about the core work. FATF Recommendation 10 requires financial institutions to conduct CDD when establishing business relationships, in specified occasional transactions, when there is suspicion, or when there are doubts about previously obtained identification data. Its measures include identifying and verifying the customer, identifying the beneficial owner and taking reasonable measures to verify that person, understanding the purpose and intended nature of the relationship, and conducting ongoing due diligence. [S01] National rules translate that baseline differently. U.S. bank CIP requirements are specific and prescriptive in places; EU rules are moving toward a directly applicable single rulebook from 2027; the UK combines the Money Laundering Regulations with supervisory guidance; and AUSTRAC’s current guidance describes initial, ongoing, and enhanced CDD as connected risk-management activities. [S04][S06][S08][S09]
The mature organization treats every customer file as a living evidence-and-decision record. It knows which facts were asserted by the customer, verified through what source, challenged because of what conflict, accepted by whom, and due for revalidation when. It can show why a risk rating is what it is, which controls it changes, and what event will cause the rating or relationship decision to be reconsidered. It can answer whether a customer was screened, but also whether the result was resolved properly; whether source-of-funds evidence was collected, but also whether it was coherent with the customer’s purpose and activity; and whether a review was completed, but also whether the review addressed the actual change that triggered it.
Poor lifecycle design creates both compliance and customer harm. It creates false confidence when a high-volume file has little analytical value. It creates inconsistency when one business accepts an alternative identity path and another rejects the same customer without an evidence-based distinction. It produces expensive operations when low-risk relationships are over-collected while high-risk relationships are under-explained. It encourages de-risking when ambiguity is handled by wholesale exit rather than by tiered products, deliberate limits, or a risk-based information strategy. FATF’s 2025 financial-inclusion guidance expressly links a risk-sensitive approach with consideration of exclusion risk and the benefits of bringing people into the regulated financial system. [S12]
The control must also survive speed. Remote onboarding, real-time payments, embedded finance, marketplace models, and distributed data mean that decision time is short and the original evidence may sit with a third party. Technology can improve evidence quality and customer experience, but it does not remove the obligation to know what a result means. A facial match, device signal, registry search, vendor match, or adverse-media alert is a signal from a particular source with limitations. It is not the person, ownership fact, risk conclusion, or legal determination itself. FATF’s digital-identity guidance emphasizes assessing assurance, reliability, independence, and fit for the risk; the EBA’s remote-onboarding guidelines similarly require financial institutions to manage risks arising from technology-enabled onboarding. [S13][S14]
Executive decision rule. A relationship-control program is defensible only if it can connect: the person or entity; the relationship purpose; the risk view; the evidence for material claims; the customer’s actual behavior; the decisions made; the accountable owner; and the next condition that will cause reconsideration.
The Questions This Module Answers
- What is the practical difference between CIP, KYC, CDD, EDD, and ongoing CDD?
- How should an enterprise define the customer lifecycle as a connected decision-and-evidence system?
- Which customer facts must be globally consistent, locally configured, or locally decided?
- How should a risk rating change action rather than merely label a customer?
- When does EDD add useful understanding, and when is it empty document collection?
- How should an organization deal with incomplete evidence, remote identity, customer-provided information, vendor data, and conflict between sources?
- How should PEP, RCA, adverse-media, source-of-funds, source-of-wealth, sanctions, and fraud signals be connected without conflating them?
- What triggers periodic review, event-driven review, temporary restriction, exit, reporting, or remediation?
- How can an institution improve customer access and speed without lowering its ability to understand or evidence risk?
- What evidence proves that lifecycle controls are complete, timely, proportionate, and effective?
1. The Customer Lifecycle Is a Decision System
1.1 The Core Design Error: Treating Onboarding as a Finished State
A customer profile starts as a hypothesis. The institution has an identity claim, a purpose claim, an ownership or authority claim where relevant, a declared activity pattern, and an initial risk assessment. Some claims are verified immediately; some are inferred from a product or relationship type; some must be reconsidered as the relationship grows. The profile becomes reliable only when the enterprise continuously compares what it believed with what it observes.
The lifecycle must be designed around three questions:
- Entry: Are the identity, authority, purpose, and risk conditions sufficient to establish the relationship, and on what limits?
- Continuance: Does evidence and behavior remain consistent with the relationship understanding and risk appetite?
- Change: What evidence, trigger, or decision changes the relationship’s risk view, products, limits, monitoring, escalation, or eligibility?
The United States makes the unresolved-identity point explicit in the bank CIP rule. If a bank cannot form a reasonable belief that it knows a customer’s true identity, its program must specify when it will not open an account, the terms of any interim account use, when it will close an account after verification fails, and when it will file a SAR as applicable. [S04] That is a useful general operating principle even where the exact legal standard differs: uncertainty must have a designed route, not an analyst improvisation.
1.2 Seven Connected Relationship Decisions
| Decision | The question that must be answered | Outputs that downstream controls need | Common failure |
|---|---|---|---|
| 1. Establish identity and authority | Who is the customer, who acts for them, and how confident are we? | identity record, method, source, confidence, unresolved discrepancies | copying a document without establishing authenticity or authority |
| 2. Understand ownership and control | Who owns, controls, benefits from, or directs the relationship? | ownership graph, evidence lineage, confidence, refresh triggers | treating a declared ownership percentage as a verified fact |
| 3. Understand purpose and expected activity | Why is this relationship needed and how should it behave? | purpose statement, product use, expected corridors/volumes/counterparties | generic purpose codes that never inform monitoring |
| 4. Decide risk and eligibility | What risk is presented and which products, limits, approvals, and controls apply? | risk rating, risk drivers, decision authority, restrictions, review cadence | a score that produces no differentiated action |
| 5. Monitor, refresh, and learn | Has identity, ownership, purpose, or behavior changed? | event triggers, periodic review, data refresh, monitoring feedback | periodic reviews that ignore material behavior or trigger events |
| 6. Escalate, restrict, report, or exit | Does the enterprise need to pause, limit, investigate, report, remediate, or end the relationship? | reason code, legal/risk basis, decision record, customer treatment plan | confusing a control action with a final adverse conclusion |
| 7. Assure and redesign | Is the lifecycle working for the intended population and risk? | QA, testing, outcomes, backlogs, rework, issue management | measuring completion volume instead of decision quality |
1.3 A Customer Profile Is an Evidence Graph, Not a PDF File
The customer file needs a structured representation of facts, sources, uncertainty, and decisions. A PDF packet is sometimes required as an evidence artifact, but it is not an operating model. The enterprise should be able to represent, retrieve, and test at least these objects:
- Party: natural person, entity, trust, authorized person, beneficial owner, director, signer, controller, related customer, counterparty.
- Claim: legal name, date of birth, address, identifier, employment, business activity, ownership percentage, prominent public function, source of wealth, source of funds, expected payment pattern.
- Evidence: document, registry record, validated digital identity, public database result, customer declaration, vendor result, financial statement, transaction record, analyst observation, law-enforcement request.
- Assessment: identity confidence, risk factor, screening disposition, ownership confidence, adverse-media assessment, source-of-funds reasonableness, source-of-wealth plausibility, quality issue.
- Decision: approve, approve with conditions, restrict, defer, request information, reject, escalate, investigate, report, exit, remediate.
- Control state: pending, complete, overdue, overridden, expired, failed, re-opened, not applicable with rationale.
This model matters because it prevents two familiar errors. First, a system can carry a field called “verified” without recording what was verified, when, by what method, at what confidence, and against which claimed fact. Second, an organization can keep a record of a decision without retaining the reasons, evidence, policy version, approver, and effect on customer permissions. Neither can be tested credibly.
1.4 The Relationship Contract: Customer Experience Is Part of Control Design
KYC creates a reciprocal contract. The organization asks for information, takes a risk-based decision, and makes promises about access, privacy, service, time, and how it will handle changes. That contract is often implicit. It should be designed.
For a lower-risk relationship, a streamlined pathway may be appropriate if the institution can identify the customer adequately, understand the product risk, set fitting limits, and retain the ability to detect inconsistencies. For a higher-risk relationship, the customer should understand the purpose of additional requests, the authority needed to approve exceptions, and the likely impact of non-response. Avoiding opaque and inconsistent requests is a control objective: it reduces customer abandonment, prevents front-line workarounds, improves evidence quality, and makes outreach more defensible.
The EU AMLR illustrates the point in a future legal framework. Its simplified-due-diligence provisions allow defined simplifications for lower risk, including delayed verification in a defined circumstance, but require sufficient monitoring, risk-management conditions, documentation, and withdrawal of simplification if information is doubtful or the lower-risk basis no longer exists. [S06] The operating lesson is not that every organization may use the same mechanism now; it is that simplification is a controlled design with conditions, not an absence of diligence.
2. The Regulatory Baseline: Same Objectives, Different Legal Interfaces
2.1 The Baseline Controls Converge More Than the Labels
FATF Recommendation 10 provides the international control spine: CDD on relationship formation and specified trigger events; customer identification and verification; beneficial-owner identification and reasonable verification; understanding purpose and intended nature; and ongoing due diligence, including scrutiny of transactions and keeping documents, data, or information up to date. Recommendation 12 adds measures for PEPs, including reasonable measures to establish source of wealth and funds and enhanced ongoing monitoring. [S01]
The common objective does not produce one global legal answer. Different regimes define covered entities, customer, business relationship, beneficial owner, PEP, verification timing, permissible reliance, recordkeeping, and safe or prohibited interim activity differently. A group therefore needs a precise legal-obligation inventory. It should not use an internal phrase such as “global KYC standard” as though it substitutes for national law.
| Lens | Legal or supervisory baseline | Practical implication for a global enterprise | Status as of 9 Aug. 2026 |
|---|---|---|---|
| FATF | Recommendation 10 sets the CDD baseline; Recommendation 12 adds PEP measures; Recommendation 1 requires risk-based implementation. | Global minimum vocabulary, control objectives, and risk-based logic. | International standard; implemented through domestic regimes. [S01] |
| United States | A bank CIP must form a reasonable belief that it knows each customer’s true identity; AML-program rules integrate risk profile and ongoing monitoring. | Do not equate a global KYC policy with U.S. CIP; map sector-specific rules and exceptions. | Current regulation; FinCEN AML/CFT program proposals must be separated from final obligations. [S04][S17] |
| European Union | AMLR 2024/1624 contains CDD, simplified CDD, EDD, PEP, and reliance provisions; it generally applies from 10 July 2027. | Maintain a transition register: national law and current supervisory practice remain material until application and implementation milestones. | In force; general application date in 2027. [S06] |
| United Kingdom | MLRs govern CDD/EDD; FCA publishes supervisory views and tested CDD controls in 2026. | Capture explicit local requirements, but use FCA good/poor practice to sharpen procedures and testing. | Current law and supervisory material. [S08][S11] |
| Australia | AUSTRAC describes connected initial, ongoing, and enhanced CDD, including risk ratings and PEP obligations. | Useful operational model: refresh KYC, monitor behavior, update risk, and collect additional information as needed. | Current guidance updated in 2026. [S09] |
| Singapore | MAS Notice 626 requires risk assessment, CDD, recordkeeping, and controls for banks. | Use jurisdiction-specific source, fields, and evidence rules; do not rely on generic Asia-Pacific policy text. | Current notice page and 2025 amendments verified. [S15] |
2.2 What Must Not Be Collapsed Into a Single Field
There are several decisions that should be connected but not collapsed:
- Identity versus eligibility. A person can be identified with high confidence and still be outside appetite because of product, geography, PEP, sanctions, fraud, conduct, or other risk factors.
- Identity confidence versus customer risk. Weak identity evidence can increase risk, but it is not the same thing as suspected misconduct. A customer may need an alternative evidence path rather than an adverse decision.
- PEP status versus suspicion. A PEP is not an allegation of wrongdoing. The control responds to exposure to misuse of public position, bribery, or corruption risk with proportionate measures.
- Adverse media versus verified fact. A screening result is a lead. Its relevance, reliability, recency, jurisdiction, and relation to the person or entity need a documented resolution.
- Source of funds versus source of wealth. Source of funds explains the origin of a particular amount or transaction. Source of wealth explains how a person accumulated overall wealth. One may be relevant without the other.
- Customer restriction versus account closure. A temporary limit, pause, product restriction, transaction block, account exit, regulatory report, and escalation to legal or law enforcement serve different purposes and may have different decision authorities.
2.3 Laws, Guidance, and Operating Recommendations
The terms must, should, and recommended need disciplined use. This module uses:
- Legal or regulatory requirement for a cited obligation in an applicable rule or statute.
- Supervisory expectation for a regulator’s published view, examination approach, or good/poor-practice material.
- Operating recommendation for a library framework that translates these sources into an enterprise design choice.
This distinction is especially important for adverse media, specific refresh intervals, risk-score thresholds, document types, vendor selection, and global control configurations. These matters are often governed by a combination of law, local expectations, contractual commitments, risk appetite, and operational feasibility. A mature program documents the basis for each design choice.
3. Executive Layer: The Decisions That Determine Lifecycle Quality
3.1 The Four Executive Allocations
Leaders determine lifecycle quality through four allocations. They cannot delegate these choices away by purchasing an onboarding platform or approving a global policy.
| Allocation | The executive choice | A defensible position | Fragile position |
|---|---|---|---|
| Risk appetite | Which customer types, structures, geographies, products, and uncertainties are accepted, conditionally accepted, or outside appetite? | Specific segments, conditions, limits, approvals, and exit routes are documented. | Appetite says “high risk requires EDD” but has no definition, capacity, or escalation path. |
| Customer proposition | How much friction, information, and time are appropriate for each journey? | Product design, eligibility, limits, and evidence requirements are co-designed. | Sales promises instant access while controls are forced to recover facts after funds move. |
| Capability and funding | What evidence and review work needs automation, specialist judgment, and control capacity? | Funding follows the highest-risk and highest-volume decision points, including remediation and QA. | Budget is set through headcount cuts and average case time without population or risk analysis. |
| Accountability | Who decides, challenges, overrides, restricts, and exits - and who owns rework? | Decision rights are explicit across business, operations, compliance, sanctions, fraud, legal, and risk. | Analysts are asked to make de facto legal or appetite decisions with no authority or appeal path. |
3.2 Customer-Risk Strategy Is Product Strategy
The choice to offer a product cannot be separated from the ability to know the customer through that product. A cross-border business account can require different ownership, purpose, and payment understanding than a domestic retail savings product. An instant-payment capability leaves less time to clarify source of funds. A marketplace creates identity and financial-crime risk around the seller or merchant as well as the platform. Embedded-finance models can create uncertainty about who owns the relationship and who completes which diligence step.
Each material product or channel should therefore have a lifecycle design statement before launch or material change. At minimum, it should explain: customer population; required identity and authority evidence; expected behavior; source and ownership data; risk segmentation; decision time; interim use; event triggers; customer communications; escalation and restriction logic; data retention; third-party dependencies; and testing population. This document sits alongside product approval, not behind it.
3.3 Customer Friction Is a Risk Metric, Not Merely a Service Metric
Low friction is not always a good outcome. A journey can be frictionless because it silently accepts low-quality data, defers impossible reviews, or suppresses challenges to reach a conversion target. Conversely, high friction can be a sign that controls lack risk differentiation, source reuse, and clear evidence standards. The goal is appropriate friction: the minimum interaction that yields sufficient evidence and enables appropriate controls for the risk.
Measure friction alongside risk outcomes:
- abandonment and approval rates by risk tier, journey, geography, customer type, and evidence path;
- first-pass completion rate and rework rate for low-, medium-, and high-risk cases;
- request count, cycle time, and customer-contact frequency;
- evidence reuse rate with validation controls;
- false-positive/false-negative challenge patterns in identity, PEP, and adverse-media processing;
- post-onboarding exception rate, account restriction rate, SAR/STR escalation rate, fraud-loss incidence, and early-life behavior variance;
- complaints, accessibility outcomes, and rejection/exit reasons where permitted and meaningful.
The point is not to optimize every metric downward. A reduction in onboarding time that increases early-life restrictions or monitoring gaps may be a poor trade. A rise in EDD time can be justified if it materially improves the decision quality for a segment that the enterprise has deliberately chosen to serve.
3.4 Financial Inclusion Requires Control Design, Not a Waiver Culture
FATF’s 2025 guidance positions financial inclusion and financial integrity as mutually supportive when a risk-based approach considers both the risk of exclusion and the benefits of bringing customers into regulated channels. [S12] This has practical consequences. Institutions should avoid making standard-photo-ID possession the only route to a lower-risk product where law and risk allow credible alternatives. They should distinguish a customer who lacks conventional documentation from a customer whose identity evidence is contradictory or deceptive. They should consider tiered capabilities, limits, progressive evidence, supervised manual review, community or government reference pathways where permitted, and alternate verification methods.
These are not universal safe harbors. They must be lawful, risk-based, accessible, privacy-conscious, and tested. A group should document its alternative-evidence catalogue, qualifying conditions, review authority, use limits, and fraud controls. AUSTRAC’s 2026 guidance specifically addresses alternative identification for customers without standard ID, while the FCA’s 2026 CDD review found that some firms’ policies did not explain what alternative evidence staff could use. [S09][S11]
3.5 Executive Enforcement Lens: Growth Does Not Excuse Control Misalignment
In October 2024, the FCA fined Starling Bank Limited GBP 28,959,426 for financial-crime systems and controls failings related to sanctions screening. The FCA also stated that Starling repeatedly breached a requirement not to open accounts for high-risk customers; it reported that the bank opened more than 54,000 accounts for 49,000 high-risk customers during the restriction period. [S20] The lesson is wider than sanctions. If a growth strategy allows customer acquisition, product configuration, and control capacity to separate, a restriction designed to contain risk can become only a policy statement. Lifecycle control must be embedded in the actual account-opening and change-management path.
5. Operator Layer II: Risk Rating That Changes Action
5.1 Risk Rating Is a Decision Framework, Not a Score
Customer risk ratings should make real differences. If a rating does not alter evidence depth, eligibility, products, limits, review cadence, monitoring, approval authority, or QA intensity, it is informational decoration. If it is not comprehensible enough to challenge, it is a model risk. If it cannot be reconciled to the customer population, it is a completeness risk.
An effective framework combines two elements:
- Segment logic: predefined customer, product, geography, channel, entity, ownership, and activity characteristics that make a customer eligible for a standard path, EDD path, or specialist path.
- Customer-specific judgment: facts that alter the expected risk within a segment, including inconsistency, complexity, PEP/RCA exposure, source-of-funds or source-of-wealth questions, adverse information, behavioral change, ownership opacity, or fraud signals.
The rating needs three records: the factors considered, the rationale and evidence for material drivers, and the actions the rating triggered. A point total without those records is difficult to validate and almost impossible to improve after a failure.
5.2 A Practical Risk-Rating Architecture
| Risk domain | Examples of factors | Decision use | Bad design pattern |
|---|---|---|---|
| Customer and ownership | legal form, ownership complexity, authority, PEP/RCA, prior relationship, occupation/business | EDD, approval level, ownership refresh, linked-party review | arbitrary numeric weighting that obscures why a risk factor matters |
| Product and service | cash access, speed, cross-border reach, crypto exposure, credit, merchant acquiring, trade, correspondent features | eligibility, limits, product restrictions, monitoring coverage | assigning product risk once and ignoring configuration changes |
| Geography and corridor | residence, incorporation, operations, payment origin/destination, sanctions and high-risk-country exposure | evidence depth, screening frequency, payment controls | treating nationality as a proxy for risk without a relevant exposure basis |
| Channel and identity | in-person/remote, device, introduction route, agent/partner, document type, digital-ID assurance | verification path, early-life monitoring, fraud controls | using a remote flag as a permanent adverse label |
| Behavior and events | activity vs stated purpose, unusual patterns, fraud indicators, data changes, screening hits, external information | event-driven review, EDD, restriction, investigation | not feeding behavior back into the customer profile |
5.3 Rating Governance and Overrides
Each risk-rating framework needs a documented methodology owner, change authority, validation plan, performance monitoring, and exception policy. Overrides are neither automatically bad nor automatically safe. They are signals. A high override rate may show a poor model, fragmented risk appetite, operational pressure, missing data, or inadequate policy design. A very low override rate can indicate that users are avoiding escalation or that the score is mechanically accepted.
Track at least:
- percentage of customers with missing critical risk fields;
- distribution of ratings by product, market, channel, customer segment, and onboarding route;
- overrides by reason, approver, source system, and customer outcome;
- changes from initial to post-onboarding rating and time to change;
- review due dates, overdue rate, repeat rework, and event-trigger coverage;
- relationship restrictions, exits, SAR/STR escalation, fraud events, sanctions matches, and QA defects by rating tier;
- false-negative signals, including material cases that had low or standard ratings before escalation.
The intention is not to promise that high-risk customers will generate more reports or exits. It is to test whether the rating framework is coherent with the actual risk and control outcomes it was designed to manage.
5.4 Periodic Review Is a Backstop, Not the Main Control
Periodic review is useful because not every change will create a detectable event. But it is a blunt instrument. A two-year refresh of a relationship with a material change in ownership, PEP status, payments, device, beneficiary, legal action, or source-of-funds story may be too late. Conversely, a frequent full document refresh of a stable lower-risk customer can add cost with little risk reduction.
Design periodic review as a risk-based backstop and event-driven review as the main learning loop. The review cadence should reflect risk, product speed, information decay, availability of reliable source refresh, and the quality of observed activity. The trigger catalogue should be clear enough to configure and test, and flexible enough to capture human escalation.
The FCA’s April 2026 review found that some firms had insufficient detail on periodic review frequency and what to do following an event-driven review; it also found examples of firms failing to conduct periodic reviews in line with their own policy. [S11] This is a recurring supervisory pattern: policies say “ongoing,” systems need a date or event, but no one owns the action when the timer or trigger fires.
6. Operator Layer III: EDD, PEPs, Funds, Wealth, and Adverse Information
6.1 EDD Must Answer a Specific Risk Question
EDD should be designed as a risk hypothesis test. It starts by naming the concern and ends by identifying the evidence, analytic judgment, monitoring, approval, and customer action needed to resolve or manage that concern. It should not begin with a generic request for “more documents.”
| Trigger or concern | The question EDD should answer | Potential evidence and analysis | Possible outcome |
|---|---|---|---|
| PEP/RCA exposure | Is there a corruption, influence, or misuse-of-office risk that changes relationship controls? | role, country exposure, public records, source of wealth/funds, relationship purpose, senior approval | approve with enhanced monitoring; condition; decline; investigate |
| Opaque or complex ownership | Can the enterprise identify and understand the relevant owners/controllers and their rationale? | ownership graph, registries, trust instruments, corporate records, linked entities, independent sources | obtain more evidence; restrict product; specialist review; reject |
| High-risk geography/corridor | Does the relationship have an exposure that requires enhanced understanding or controls? | business operations, payment purpose, counterparties, sanctions/TF/PF indicators, risk assessment | enhanced monitoring; limits; EDD; escalation |
| Inconsistent funds or wealth | Is the transaction or relationship economically plausible and sufficiently explained? | transaction trail, sale agreement, payroll/dividend evidence, financial statements, tax/asset records where proportionate | accept; request clarity; monitor; restrict; investigate |
| Adverse information | Is the result correctly matched, credible, relevant, current, and material? | source provenance, court/regulatory record, response where appropriate, date, jurisdiction, relation to role | clear false positive; update risk; EDD; restrict; escalate |
| Behavior inconsistent with purpose | Has observed activity changed what was understood at onboarding? | transaction history, expected activity, payment counterparties, device/behavioral signals, customer explanation | refresh; EDD; monitoring change; SAR/STR pathway; exit decision |
6.2 Source of Funds and Source of Wealth Are Different Tests
Source of funds (SOF) asks where the specific funds involved in a transaction, account balance, or relationship came from. It often requires a traceable path: salary payment, sale proceeds, dividend, loan, inheritance, business revenue, redemption, or transfer from an identified account.
Source of wealth (SOW) asks how the individual accumulated their overall wealth. It is a broader plausibility assessment: business ownership, long-term employment, investment gains, inheritance, or other legitimate economic activity. SOW does not always need a complete lifetime audit. It needs to be sufficient for the risk and relationship purpose, and it must be capable of explaining the scale and pattern of the relationship.
The key is coherence. A single bank statement might show that money arrived from another account but not explain the economic source. A customer’s occupation might be plausible in isolation but inconsistent with a very large cross-border transaction. Conversely, an organization should not demand intrusive wealth evidence when it has no risk basis for it. The enterprise should define evidence packages by trigger and amount, but preserve specialist judgment and clear escalation for inconsistency.
6.3 PEPs, Relatives, and Close Associates: Exposure Is Not Guilt
PEP controls exist because prominent public function can create an elevated exposure to bribery, corruption, or misuse of public assets. They are not a moral classification and must not be used as a proxy for nationality, political opinion, or adverse conduct. FATF Recommendation 12 calls for appropriate risk-management systems to determine whether a customer or beneficial owner is a PEP, senior-management approval to establish or continue relationships with foreign PEPs, reasonable measures to establish source of wealth and funds, and enhanced ongoing monitoring. Domestic PEP requirements are risk-based under the Recommendation. [S01]
The local overlay matters. The UK’s MLRs contain specific PEP EDD provisions and the FCA’s 2025 finalised guidance focuses on a proportionate, risk-based approach to UK PEPs, their relatives, and close associates. [S08][S10] The EU AMLR contains specific PEP requirements, including senior approval, source-of-wealth and source-of-funds measures, and enhanced ongoing monitoring. [S06] These are not interchangeable rulebooks.
A good PEP/RCA process records: the qualifying function or relationship; source and match resolution; country and organization; start/end dates where available; direct versus indirect exposure; other risk factors; approved EDD plan; senior decision; review cadence; and any change in status. It avoids two errors: automatically accepting a PEP because a senior person wants the relationship, or automatically rejecting a PEP because the system cannot make a nuanced decision.
6.4 Adverse Media: A Lead, Not a Verdict
Adverse-media controls are frequently underdesigned. They are powerful because they can reveal allegations, legal actions, regulatory decisions, sanctions-evasion indicators, corruption links, fraud, and identity relationships that are not otherwise captured. They are dangerous because names collide, sources vary in reliability, reporting can be sensational or outdated, translated items can lose context, and a subject may be referenced without being accused.
An adverse-media disposition should distinguish:
- potential match from confirmed identity match;
- allegation from adjudicated fact or official action;
- current relevance from stale or superseded reporting;
- customer conduct from connected-party conduct;
- material financial-crime relevance from unrelated reputational content;
- source quality and provenance from aggregate vendor risk labels.
The output should be a documented risk assessment with an action. It should not be a screenshot uploaded to a case file, nor an algorithmic red flag that silently becomes a customer exit decision. Data-protection, fairness, consumer, labor, and local-defamation considerations may also apply and should be routed through the relevant local governance.
6.5 Case Lens: EDD Must Connect to Transaction Behavior
In September 2020, AUSTRAC stated that Westpac’s proposed A$1.3 billion civil penalty addressed, among other matters, failures to carry out appropriate customer due diligence in relation to suspicious transactions associated with possible child exploitation, failures in transaction monitoring, and failures to assess and monitor risks in correspondent banking relationships. [S22] The lifecycle lesson is important: EDD is not a once-only onboarding package. Material suspicious behavior can require enhanced customer understanding, monitoring, and escalation after a relationship is already established.
7. Operator Layer IV: Ongoing CDD, Event Triggers, Restrictions, and Exit
7.1 Ongoing CDD Has Three Inputs
Ongoing CDD should integrate:
- Scheduled review: risk-based reassessment at a defined interval.
- Event-driven review: a material change in data, ownership, behavior, external information, product, or risk signal.
- Continuous observation: monitoring and business activity that may update the customer profile or require investigation.
AUSTRAC’s current overview describes ongoing CDD as keeping KYC information up to date and re-verifying it where appropriate; monitoring unusual transactions, behaviors, and criminal activity; updating ML/TF risk as more is known; and collecting or verifying additional information where appropriate. [S09] This is a useful operational formulation: continuous review is not merely a clock, and it is not merely transaction monitoring.
7.2 A Trigger Catalogue Should Be a Controlled Asset
Each trigger needs a source, logic, severity, owner, target completion time, required action, ability to combine with other triggers, suppression/override controls, and test cases. The catalogue should include data-quality triggers as well as risk triggers. It should be reconciled to product and market changes.
| Trigger family | Examples | Possible lifecycle response |
|---|---|---|
| Identity and authority | document expiration, death indicator, address conflict, device/credential anomaly, signatory change | re-verify, step-up authentication, limit or pause access, fraud review |
| Ownership and control | ownership change, director change, beneficial-owner mismatch, trust event, registry discrepancy | ownership refresh, EDD, specialist review, restriction until resolved |
| Purpose and activity | large unexplained activity, new corridor, cash pattern, counterparty changes, activity inconsistent with stated business | refresh purpose, SOF/SOW, monitoring change, investigation/suspicion assessment |
| External information | sanctions/PEP/RCA match, adverse media, law-enforcement request, regulatory action, negative public filing | screening resolution, EDD, legal/sanctions review, restriction as applicable |
| Product and relationship | product upgrade, credit expansion, merchant onboarding, new country, new legal entity, embedded-finance partner | new-product CDD, risk rerating, conditions, approvals |
| Control quality | vendor outage, unprocessed backlog, data feed failure, configuration change, missing mandatory fields | population remediation, compensating control, customer-impact review, issue management |
7.3 Restriction Is a Portfolio of Actions
“Restrict” is not one action. It can mean no account opening; no use pending verification; lower transaction limit; no cross-border payments; no cash access; no new product; beneficiary block; manual review; delayed settlement; temporary account freeze where law permits or requires; exit; or an internal monitoring adjustment. The legal basis, customer communication, timeliness, reporting consequences, privacy boundaries, and appeal process vary materially.
The enterprise needs a restriction taxonomy linked to authority and systems. A control cannot tell a customer relationship team to “apply enhanced monitoring” without a system field, monitoring configuration, target date, and owner. It cannot tell operations to “restrict the customer” without defining what operational permission changes. It cannot tell a case manager to “close” a relationship without a reason, decision maker, legal review where applicable, safeguards around tipping-off, and a controlled exit plan.
7.4 Deciding to Exit: Risk Management, Not Data Deletion
Exiting a relationship does not end the institution’s need to preserve records, assess suspicious activity where appropriate, complete applicable reports, manage residual claims or obligations, and prevent immediate re-entry through a different business or channel if that is a relevant risk. It also does not prove that the risk has been reduced in the system as a whole. The customer may move to a less transparent channel or return through an affiliate or correspondent.
The decision should therefore be recorded with: trigger, facts, risk/appetite and legal basis, authority, alternatives considered, required restrictions pending exit, communications plan, timing, data and record obligations, investigation/reporting route, linked-party scope, re-entry rules, and QA requirements. This is a control design recommendation, not a statement of any universal legal duty.
7.5 Case Lens: A Restriction Must Exist in the Operating Path
The Starling case demonstrates a common failure pattern. The FCA stated that Starling agreed to a requirement not to open new accounts for high-risk customers until its controls improved, but then opened more than 54,000 accounts for high-risk customers. [S20] An enterprise cannot treat restriction language as adequate if customer-acquisition systems, risk classification, approvals, and monitoring do not reliably execute it. The evidence should be a population-level proof: every customer in the restricted cohort, every account-opening attempt, every override, every approver, and every outcome.
8. Specialist Layer I: Evidence, Data, and Decision Traceability
8.1 The Five Evidence States
For each material customer fact, use a controlled state. The exact labels can vary, but the distinction matters.
| State | Meaning | Example | What it can support |
|---|---|---|---|
| Asserted | Provided by the customer or representative | “This is the ultimate owner.” | initial workflow; not necessarily final confidence |
| Corroborated | Consistent with a source, but not fully independently verified | registry record aligns with declaration | risk assessment; may require further validation |
| Verified | Verified through a defined method that met the applicable standard | valid document plus non-documentary check | required identity/owner step, subject to freshness |
| Conflicted | A material inconsistency exists | address, ownership, or identity source conflict | review, remediation, hold, EDD, or escalation |
| Expired / stale | Prior evidence no longer supports the decision without refresh | document expiration, ownership change, outdated activity | trigger for review and potential restrictions |
The status should be attribute-level, not merely customer-level. A customer can have verified legal identity, asserted source of wealth, stale address, unresolved adverse-media match, and confirmed PEP status at the same time. A single green or red customer flag destroys this detail.
8.2 Decision Traceability Is the Audit Trail of Judgment
Every material decision should be reconstructable. At minimum, capture:
- identity of the subject and related parties;
- decision type and decision time;
- policy, procedure, and rule/model version used;
- inputs and data-source versions;
- risk factors and material evidence;
- decision maker, reviewer, approver, and authority basis;
- decision outcome and operational effect;
- exceptions, overrides, expiry, and re-review condition;
- links to case, transaction, reporting, complaint, or remediation records where appropriate.
This is not unnecessary bureaucracy. Without it, an organization cannot show whether decisions were timely, consistent, explainable, and within authority. It cannot tell a customer what changed without exposing protected investigation information. It cannot reproduce why a model made a recommendation. It cannot separate a poor decision from a poor data source. And it cannot prove a remediation had actually changed the underlying decision logic.
8.3 Data Quality Must Be Tested as a Risk Control
Data quality is often reviewed as a technology or operations issue. In lifecycle control, it is a risk control. Examples include:
- customer-population records missing a relationship identifier or mapped to the wrong legal entity;
- owner, controller, or signer records not linked to all relevant customer relationships;
- an old customer-risk tier persisting after ownership or product changes;
- screening results unable to reconnect to the specific data input and list version used;
- event triggers not firing because a source field is null, stale, or not mapped;
- customer data held in a country or system where the review team cannot lawfully access enough detail to make a decision;
- evidence images available but the metadata needed to prove source, time, reviewer, or validity absent.
Test data quality against the decision, not only against a technical specification. A field can be 99 percent populated and still fail if the missing 1 percent is concentrated in a high-risk customer segment. A registry feed can be technically on time but economically stale. A vendor can return a clean result because it had no coverage for the relevant jurisdiction. The control owner needs both data-quality metrics and decision-impact metrics.
8.4 Retention, Privacy, and Purpose Limitation
CDD evidence carries sensitive personal and corporate data. The institution needs to retain sufficient records to demonstrate compliance, respond to legitimate investigations, and support lifecycle continuity, while complying with local privacy, secrecy, retention, and cross-border-transfer rules. A global control should define its minimum evidence model and then apply local retention, access, localization, and deletion overlays. It should not assume that “compliance purpose” permits unrestricted group-wide access to all customer evidence.
The core design question is: what minimum information must a central service, regional team, or local entity have to make the decision, assure its quality, investigate risk, and demonstrate compliance - and what can remain local or be shared through a controlled derived fact, evidence summary, or request process? Module 13 develops this issue in depth. Here, the key point is that an inability to transfer evidence is a design constraint that needs a deliberate fallback, not a reason to lower the decision standard silently.
9. Specialist Layer II: Test Design and Quality Assurance
9.1 Test the Population Before Testing the File
File testing alone can miss the most serious lifecycle failure: customers who never entered the process, were wrongly exempted, were routed to the wrong path, or changed without a trigger. Start with the population.
| Test question | Evidence needed | Example failure detected |
|---|---|---|
| Is the in-scope population complete? | authoritative customer, account, product, and third-party feeds; reconciliation rules | accounts opened through a partner not in the CDD inventory |
| Are relationship types classified correctly? | legal-entity, product, channel, and ownership mapping | customer treated as individual rather than legal entity or trust |
| Did every required step occur? | timestamps, workflow states, source records, override logs | KYC task marked complete without a verification result |
| Was the evidence sufficient and current? | evidence metadata, source method, risk tier, freshness rule | expired documents accepted for high-risk remote onboarding |
| Did risk rating change action? | rating, EDD package, approvals, limits, monitoring, review dates | high-risk customer receives standard review and no senior approval |
| Did events create timely outcomes? | trigger source, queue timestamp, analyst action, restriction and closure logs | ownership-change event never prompted an EDD review |
| Did decisions stay within authority? | decision-rights map, approver role, exception records | front-line override used for a prohibited customer type |
9.2 QA, QC, Compliance Testing, Validation, and Audit Have Different Jobs
- Quality control (QC): embedded, near-real-time checks that prevent or correct operational errors before completion.
- Quality assurance (QA): independent sampling or review of completed work to assess accuracy, consistency, and adherence.
- Compliance testing: risk-based assessment of whether controls and processes meet legal, policy, and supervisory expectations.
- Model or methodology validation: independent challenge of risk-rating, matching, or analytic methods where they function as models or material decision systems.
- Internal audit: independent assurance on design and operating effectiveness, governance, and issue closure.
Weak programs make all of these teams count the same thing. Strong programs give them distinct mandates and share results through a common issue taxonomy. The issue taxonomy should distinguish at least: population gap, data defect, evidence insufficiency, policy ambiguity, procedure breach, authority breach, system configuration defect, vendor defect, training/capacity problem, and risk-methodology deficiency.
9.3 Quality Measures That Matter
| Measure | Why it matters | Guardrail against misuse |
|---|---|---|
| First-pass right rate | indicates clarity and process quality | segment by complexity; do not penalize legitimate EDD rigor |
| Material defect rate | focuses on failures that change a decision or regulatory outcome | define materiality independently and review calibration |
| Evidence sufficiency rate | tests whether evidence supports the stated claim | avoid counting documents rather than claim coverage |
| Event-to-action time | measures whether risk signals change the relationship in time | stratify by severity and system outage periods |
| Overdue high-risk reviews | shows aging exposure | reconcile to population and exclusion logic |
| Override rate and outcome | exposes pressure, model weakness, or missing policy | inspect reason quality, approvals, and later outcomes |
| Repeat-defect rate | tests whether remediation reached root cause | track by product, market, vendor, and system release |
| Customer rework and complaint rate | indicates friction, fairness, and unclear requests | do not treat complaints as proof that controls are unnecessary |
9.4 Enforcement and Supervisory Lens: Policies Must Tell People What to Do
The FCA’s April 2026 review is instructive because it examined policies, customer files, and interviews rather than merely a written program. It reported that most firms had procedures for identity verification but few had enough practical detail; some lacked alternative-evidence guidance for customers without standard identification; some had unclear periodic and event-driven review practices; and stronger firms documented EDD steps, senior approval, and oversight. [S11] The lesson for control testing is to test the distance between policy language and operational execution.
10. Global Core / Local Edge for Customer Lifecycle Controls
10.1 Standardize Control Objectives, Not Every Customer Interaction
A global group needs consistency in the identity of the control: every material relationship should have a traceable customer, relevant associated parties, a purpose and expected activity view, a risk assessment, a defined evidence standard, a review condition, and a decision authority. It also needs one way to record key evidence attributes, actions, exceptions, and outcomes.
It should not assume that every jurisdiction permits identical sources, identity proofs, PEP definitions, data movement, public-registry access, customer notices, record retention, reliance on third parties, electronic signatures, or interim account use. The goal is one control language with controlled local configuration, not forced uniformity.
| Control element | Global core | Local edge | Evidence that the boundary is governed |
|---|---|---|---|
| Customer and party taxonomy | canonical party roles, identifiers, relationships, status definitions | legal-form specifics, language, local identifiers | data dictionary; mapping; local legal sign-off |
| Identity verification | minimum claim/evidence/decision model; confidence states | permitted documents, source accessibility, local proofing standards | country evidence matrix; configuration version |
| Risk rating | global risk domains, methodology governance, rating actions | local risk factors, high-risk-country lists, thresholds, product features | local overlay register; approval; validation results |
| EDD | common hypothesis-and-evidence structure; senior decision standards | mandatory local triggers, SOF/SOW scope, PEP/RCA treatment | EDD playbook; local procedure; decision logs |
| Ongoing CDD | event catalogue structure, review-state model, escalation taxonomy | legal deadline, data availability, customer notification, report interface | trigger mapping; queue SLA; local QA |
| Restriction and exit | global taxonomy and decision traceability | legal basis, customer rights, restrictions, data retention, tipping-off | authority map; reason codes; legal review path |
| QA and reporting | global defect taxonomy and minimum metrics | local sampling rules, regulator reporting, data restrictions | consolidated dashboard with local exception note |
11. What Good Looks Like / What Failure Looks Like
| Capability | Mature, defensible, sustainable | Weak, misleading, fragile |
|---|---|---|
| Identity | claim-level evidence, multiple paths, confidence and discrepancy states, designed unresolved-identity route | document copies marked “verified,” no alternative path, no response to unresolved uncertainty |
| Customer understanding | purpose, expected activity, ownership, authority, and risk views are usable by monitoring and investigations | generic purpose codes and free text that no downstream control can use |
| Risk rating | drivers, actions, approvals, refresh logic, outcomes, and validation are connected | one score, unclear inputs, no linkage to EDD or monitoring |
| EDD | question-led evidence plan, documented judgment, senior approval, enhanced monitoring and review | longer document list without a stated risk concern or control change |
| PEP / adverse information | accurate matching, proportionality, reasoned source assessment, controlled decisions | PEP treated as guilt; media alert treated as verified misconduct |
| Ongoing CDD | scheduled backstop plus event catalogue, clear owners, quality metrics, population reconciliation | annual-review queue, overdue items, event signals routed nowhere |
| Restrictions and exits | specific operational effects, authority, evidence, legal/risk basis, linked-party and re-entry logic | vague “restrict” or “close” tasks that cannot be executed or audited |
| Data and evidence | lineage, freshness, access controls, retention, versioned sources and decision traceability | static PDFs, missing timestamps, untraceable vendor scores, ungoverned local spreadsheets |
| Global model | common objectives with tested local overlays and translation-debt management | universal policy wording that conflicts with local execution or data rules |
12. Common Misconceptions and Contrarian Insights
- “KYC is complete when the account opens.” It is complete only for the facts and decision at that point. The relationship must be continuously re-understood.
- “More documents means stronger due diligence.” More evidence can create a larger but weaker file if it does not test the material risk hypothesis.
- “A PEP is a high-risk customer.” PEP status is a risk factor requiring mandated or proportionate measures; it is not a verdict or universal risk rating.
- “Adverse media is an independent fact.” It is a sourced signal whose relevance, reliability, match quality, and legal implications need analysis.
- “A vendor verification result shifts responsibility.” A vendor can perform a service. It cannot remove the institution’s need to understand the method, evidence, quality, and customer outcome.
- “Low friction and strong controls are opposites.” Poor differentiation creates both high friction and poor control. Appropriate evidence paths and tiered products can improve both.
- “A standard refresh interval proves ongoing CDD.” A calendar cannot substitute for event-driven understanding of change.
- “Customer exit solves the risk.” Exit can be necessary, but it does not erase reporting, recordkeeping, re-entry, consumer, data, or system-learning obligations.
- “A clean screening result proves a clean customer.” It proves only that a particular list or data source produced a particular result at a particular time.
- “Global consistency means identical workflows.” Consistency is a common control objective, evidence model, and accountability standard - not necessarily a universal document list or data flow.
13. Executive Discussion Questions
- Which customer segments, products, and markets create the greatest gap between onboarding speed and the quality of knowledge needed to manage risk?
- Can the organization show, for every material customer segment, what changes when a customer is rated higher risk?
- Where do we accept customer assertions without independent corroboration, and why is that appropriate for the risk?
- Which evidence sources have become implicit single points of failure: a registry, vendor, broker, program manager, or internal platform?
- Are alternative identity pathways controlled well enough to improve inclusion without creating unmanaged fraud or AML risk?
- Which event-driven triggers are most likely to identify that our initial customer understanding has become stale?
- Can we prove that product, growth, and third-party teams cannot bypass a restriction designed for high-risk customers?
- What percentage of EDD files can explain the specific risk question tested, rather than merely list additional documents?
- Where do our PEP, RCA, adverse-media, and sanctions-screening processes make inconsistent or opaque customer decisions?
- What is the customer and risk consequence of our review backlog, by risk tier and product?
- Which local legal or data constraints prevent a global team from seeing enough evidence to make or assure a decision, and what is the fallback?
- What root causes drive repeat QA defects: unclear policy, missing data, poor technology, capacity, incentives, vendor quality, or decision-rights confusion?
- Which control metrics could look better while actual risk becomes worse, and how will we guard against that?
- If a regulator asked for a population proof of a restriction, an EDD trigger, or a customer-exit decision, could we produce it promptly?
14. Practitioner Checklist
14.1 Executive Checklist
14.2 Operator Checklist
14.3 Specialist Validation Checklist
Module Glossary
Adverse media: Publicly available information that may indicate financial-crime, integrity, or related risk and requires source-aware, identity-aware assessment.
Beneficial owner: The natural person(s) who ultimately owns or controls a customer, or on whose behalf a transaction is conducted. Definitions and thresholds vary by regime.
Binding: The degree to which a person presenting evidence or operating a session is linked to the claimed identity.
CIP: Customer Identification Program; a specific U.S. regulatory term for certain financial institutions, including banks.
CDD: Customer due diligence; risk-based measures to understand and manage a customer relationship.
Close associate / RCA: A person known to have a close relationship with a PEP, as defined under an applicable regime; terminology varies.
Customer risk profile: A documented understanding of risk factors, purpose, expected activity, and control needs relevant to a customer relationship.
EDD: Enhanced due diligence; additional risk-based or required measures for higher-risk relationships or events.
Event-driven review: A review triggered by a material change or signal, rather than solely by a scheduled date.
Identity confidence: An evidence-based assessment of how well the enterprise can rely on an identity claim for a specific decision.
KYC: Know your customer; a practical operational label, not a single universal legal construct.
PEP: Politically exposed person; a person entrusted with a prominent public function, with definitions and measures set by applicable regimes.
Source of funds (SOF): The origin and traceable path of specific funds involved in a transaction or relationship.
Source of wealth (SOW): How a person accumulated overall wealth sufficient to make the relationship or activity plausible.
Translation debt: The accumulated gap between global policy, local law, systems configuration, operational procedure, training, and retained evidence.
Verification: A controlled process that tests an identity or other claim through defined methods and produces a recorded result with limitations.
MLA 9 Works Cited
Anti-Money Laundering Authority. Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the Prevention of the Use of the Financial System for the Purposes of Money Laundering or Terrorist Financing. Official Journal of the European Union, 19 June 2024, https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng. Accessed 9 Aug. 2026.
Australian Transaction Reports and Analysis Centre. “AUSTRAC and Westpac Agree to Proposed $1.3bn Penalty.” AUSTRAC, 24 Sept. 2020, https://www.austrac.gov.au/news-and-media/media-release/austrac-and-westpac-agree-penalty. Accessed 9 Aug. 2026.
Australian Transaction Reports and Analysis Centre. “Overview of Customer Due Diligence.” AUSTRAC, 27 Mar. 2026, https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/overview-customer-due-diligence. Accessed 9 Aug. 2026.
Australian Transaction Reports and Analysis Centre. “Source of Funds and Source of Wealth.” AUSTRAC, 2026, https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/source-funds-and-source-wealth. Accessed 9 Aug. 2026.
Australian Transaction Reports and Analysis Centre. “Identifying Individuals Who Don’t Have Standard ID.” AUSTRAC, 27 Mar. 2026, https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/initial-customer-due-diligence/identifying-individuals-who-dont-have-standard-id. Accessed 9 Aug. 2026.
European Banking Authority. Guidelines on the Use of Remote Customer Onboarding Solutions. EBA/GL/2022/15, 22 Nov. 2022, https://www.eba.europa.eu/sites/default/files/document_library/Publications/Guidelines/2022/EBA-GL-2022-15%20GL%20on%20remote%20customer%20onboarding/1043884/Guidelines%20on%20the%20use%20of%20Remote%20Customer%20Onboarding%20Solutions.pdf. Accessed 9 Aug. 2026.
Federal Deposit Insurance Corporation. Consent Order: Metropolitan Commercial Bank. FDIC-23-0110b, 2023, https://orders.fdic.gov/sfc/servlet.shepherd/document/download/0693d00000CTBl4AAH. Accessed 9 Aug. 2026.
Federal Financial Institutions Examination Council. “BSA/AML Examination Manual.” BSA/AML InfoBase, 2026, https://bsaaml.ffiec.gov/manual. Accessed 9 Aug. 2026.
Financial Conduct Authority. “FCA Fines Starling Bank GBP29m for Failings in Their Financial Crime Systems and Controls.” FCA, 2 Oct. 2024, updated 5 Dec. 2025, https://www.fca.org.uk/news/press-releases/fca-fines-starling-bank-failings-financial-crime-systems-and-controls. Accessed 9 Aug. 2026.
Financial Conduct Authority. “Firms’ Customer Due Diligence Processes and Controls: Our Findings.” FCA, 8 Apr. 2026, https://www.fca.org.uk/publications/good-and-poor-practice/firms-customer-due-diligence-processes-and-controls-our-findings. Accessed 9 Aug. 2026.
Financial Conduct Authority. FG25/3: Treatment of Politically Exposed Persons. 7 July 2025, https://www.fca.org.uk/publications/finalised-guidance/fg25-3-treatment-politically-exposed-persons. Accessed 9 Aug. 2026.
Financial Crimes Enforcement Network. “CDD Final Rule.” FinCEN, 2016, https://www.fincen.gov/resources/statutes-and-regulations/cdd-final-rule. Accessed 9 Aug. 2026.
Financial Crimes Enforcement Network. “In the Matter of Bittrex, Inc.” FinCEN, 11 Oct. 2022, https://www.fincen.gov/news/enforcement-actions/matter-bittrex-inc. Accessed 9 Aug. 2026.
Financial Crimes Enforcement Network. “FinCEN Issues Exceptive Relief to Streamline Customer Due Diligence Requirements.” FinCEN, 13 Feb. 2026, https://www.fincen.gov/news/news-releases/fincen-issues-exceptive-relief-streamline-customer-due-diligence-requirements. Accessed 9 Aug. 2026.
Financial Stability Board. Guidance on Correspondent Banking Services. 2016, https://www.fsb.org/2016/10/guidance-on-correspondent-banking-services/. Accessed 9 Aug. 2026.
Financial Action Task Force. The FATF Recommendations. 29 Oct. 2025 edition, https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/FATF%20Recommendations%202012.pdf.coredownload.inline.pdf. Accessed 9 Aug. 2026.
Financial Action Task Force. Guidance on Digital Identity. 6 Mar. 2020, https://www.fatf-gafi.org/en/publications/Financialinclusionandnpoissues/Digital-identity-guidance.html. Accessed 9 Aug. 2026.
Financial Action Task Force. “FATF Publishes New Guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures.” FATF, 23 June 2025, https://www.fatf-gafi.org/en/publications/Financialinclusionandnpoissues/guidance-financial-inclusion-aml-tf-measures.html. Accessed 9 Aug. 2026.
Financial Action Task Force. Guidance on Beneficial Ownership of Legal Persons. 10 Mar. 2023, https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-Beneficial-Ownership-Legal-Persons.html. Accessed 9 Aug. 2026.
Monetary Authority of Singapore. “Notice 626: Prevention of Money Laundering and Countering the Financing of Terrorism - Banks.” MAS, 2025, https://www.mas.gov.sg/regulation/notices/notice-626. Accessed 9 Aug. 2026.
United Kingdom. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. regulation 35, https://www.legislation.gov.uk/uksi/2017/692/regulation/35. Accessed 9 Aug. 2026.
United States, Financial Crimes Enforcement Network. “Anti-Money Laundering and Countering the Financing of Terrorism Programs.” Federal Register, 10 Apr. 2026, https://www.federalregister.gov/documents/2026/04/10/2026-07033/anti-money-laundering-and-countering-the-financing-of-terrorism-programs. Accessed 9 Aug. 2026.
United States, Financial Crimes Enforcement Network. “Customer Due Diligence Requirements for Financial Institutions.” Federal Register, 11 May 2016, https://www.federalregister.gov/documents/2016/05/11/2016-10567/customer-due-diligence-requirements-for-financial-institutions. Accessed 9 Aug. 2026.
United States, Office of the Federal Register. “31 CFR 1010.230 - Beneficial Ownership Requirements for Legal Entity Customers.” eCFR, current edition, https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230. Accessed 9 Aug. 2026.
United States, Office of the Federal Register. “31 CFR 1020.210 - Anti-Money Laundering Program Requirements for Banks.” eCFR, current edition, https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.210. Accessed 9 Aug. 2026.
United States, Office of the Federal Register. “31 CFR 1020.220 - Customer Identification Program Requirements for Banks.” eCFR, current edition, https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-B/section-1020.220. Accessed 9 Aug. 2026.
Notes on Sources Used in Prose
[S01] FATF Recommendations (29 Oct. 2025 edition), including Recommendations 1, 10, 11, 12, 17, 18, 24, and 25.
[S02] FATF Guidance on Beneficial Ownership of Legal Persons (10 Mar. 2023).
[S03] FATF Guidance on Beneficial Ownership and Transparency of Legal Arrangements (11 Mar. 2024).
[S04] 31 CFR 1020.220, current eCFR edition, verified 9 Aug. 2026.
[S05] 31 CFR 1020.210 and FinCEN CDD Final Rule.
[S06] Regulation (EU) 2024/1624 (AMLR), Articles 20, 33, 42 and Article 92 application provision.
[S07] Commission / EUR-Lex AMLR summary, application from 10 July 2027.
[S08] UK Money Laundering Regulations 2017, Regulation 35; FCA Financial Crime Guide and PEP guidance.
[S09] AUSTRAC CDD guidance, updated 27 Mar. 2026.
[S10] FCA FG25/3, finalised 7 July 2025.
[S11] FCA, “Firms’ Customer Due Diligence Processes and Controls: Our Findings,” 8 Apr. 2026.
[S12] FATF, “Guidance on Financial Inclusion and AML/TF Measures,” 23 June 2025.
[S13] FATF, Guidance on Digital Identity, 6 Mar. 2020.
[S14] EBA/GL/2022/15, Guidelines on Remote Customer Onboarding.
[S15] MAS Notice 626, verified 9 Aug. 2026.
[S16] FFIEC BSA/AML Examination Manual.
[S17] FinCEN AML/CFT program proposal, 10 Apr. 2026 - proposal only.
[S18] FinCEN exceptive relief on CDD requirements, 13 Feb. 2026.
[S19] FinCEN Bittrex consent order, 11 Oct. 2022.
[S20] FCA Starling Bank enforcement announcement, 2 Oct. 2024.
[S21] FDIC Consent Order, Metropolitan Commercial Bank, 2023.
[S22] AUSTRAC Westpac proposed penalty announcement, 24 Sept. 2020.