Preview — full content in the download
Operational aid only. Adapt to your licence, products, member-state law, risk assessment, and legal advice.
Case Header
| Customer name / legal name | Customer type | ||
| Product requested | Jurisdiction | ||
| Onboarding owner | Compliance reviewer | ||
| Initial risk rating | Final decision |
1
Scope & Customer Profile
- Confirm AML/KYC scope, onboarding trigger, product, and customer acceptance policy.
- Identify standard CDD, simplified due diligence, or enhanced due diligence route.
- Collect natural-person minimum profile: name, date of birth, address, residence, intended use.
- Collect legal-entity minimum profile: registry data, directors, signatories, ownership, control.
- Identify beneficial owners and controlling persons under policy and local rules.
- Record expected activity, transaction countries, source of funds, and product rationale.
2
Evidence Collection & Verification
- Confirm each document or field has a defined AML, fraud, security, or legal purpose.
- Prefer verified attributes or extracted fields over retaining full document images where allowed.
- Use secure upload or vendor capture; avoid ordinary email for identity documents.
- Verify identity documents for validity, authenticity, expiry, liveness, and mismatch signals.
- Verify entity existence, authority to act, beneficial ownership, and ownership/control chain.
- Record evidence source, timestamp, analyst notes, exceptions, and decision rationale.
3
PEP, Sanctions & Adverse Media Screening
- Run sanctions screening before activation for customers and relevant connected parties.
- Run PEP screening for customers, beneficial owners, directors, and authorised representatives.
- Review adverse media by reliability, relevance, recency, and severity.
- Document false positives, true matches, escalation owner, and final disposition.
- Escalate sanctions true matches immediately; do not activate unresolved cases.
- Configure sanctions and PEP rescreening cadence after onboarding.
4
Risk Score & EDD Triggers
- Trigger EDD for PEPs, high-risk countries, complex ownership, adverse media, or unexplained funds.
- Obtain source of funds/source of wealth evidence where required.
- Obtain senior management approval where policy requires it (mandatory for PEPs).
- Apply limits, restrictions, enhanced monitoring, or shorter review cycles when approving with controls.
- Document EDD rationale clearly enough for audit or supervisory review.
5
Decision, Monitoring & GDPR Controls
- Approve only when mandatory checks are complete or an approved exception exists.
- Reject or exit where evidence is false, identity cannot be verified, or risk exceeds appetite.
- Escalate suspicious activity concerns before customer communication; avoid tipping off.
- Set review cadence: low 24–36 months, medium 12–24 months, high 6–12 months.
- Map every KYC field to purpose, lawful basis, retention period, access role, and system owner.
- Delete duplicates and expire retained records when AML retention period ends, unless legal hold applies.
Risk Factor Quick Reference
| Factor | Key question | Notes |
|---|---|---|
| Customer | Simple, transparent, and consistent with risk appetite? | — |
| Geography | Any high-risk, sanctioned, conflict, or corruption exposure? | — |
| Product | Does the product enable cross-border, crypto, or rapid movement of funds? | — |
| Channel | Are non-face-to-face controls strong enough? | — |
| Screening | Any PEP, sanctions, adverse media, or law-enforcement signal? | — |
| Funds | Is source of funds/source of wealth plausible and evidenced? | — |
QA Sign-off
| Control | Evidence reviewed | Result | Reviewer / date |
|---|---|---|---|
| Identity / KYB evidence | — | Pass / Fail / N/A | — |
| Beneficial ownership | — | Pass / Fail / N/A | — |
| Sanctions, PEP, adverse media | — | Pass / Fail / N/A | — |
| Risk score and EDD rationale | — | Pass / Fail / N/A | — |
| GDPR minimisation and retention | — | Pass / Fail / N/A | — |
| Final approval | — | Pass / Fail / N/A | — |
Prepared by KYC Bridge — privacy-first KYC workflows for EU teams. kycbridge.eu