Compliance guide

KYC and AML: From Onboarding Check to Ongoing Control

A buyer-oriented guide to customer due diligence, screening, risk decisions, monitoring and the evidence a defensible process needs.

KYC is a lifecycle, not a one-time identity check

Know Your Customer processes collect and assess information needed to understand a customer, establish risk and apply appropriate controls. Anti-money laundering obligations vary by business and jurisdiction, but effective programmes connect onboarding decisions to ongoing review and monitoring.

The FATF Recommendations provide an international framework for risk-based customer due diligence. Organisations must translate applicable requirements into their own policy, decision rules and evidence.

A practical control workflow

  1. Identify the customer. Collect appropriate identity and contact data.
  2. Verify identity. Establish confidence using reliable, independent evidence.
  3. Understand purpose and expected activity. Capture context needed for a risk decision.
  4. Screen relevant parties. Apply sanctions, politically exposed person and other required checks.
  5. Assess risk. Combine customer, geography, product, channel and behavioural factors.
  6. Apply due diligence. Route higher-risk or uncertain cases to enhanced checks and review.
  7. Monitor and refresh. Detect material changes and review information at appropriate intervals.
Keep policy separate from provider logic

Your organisation owns the decision policy. A provider supplies data, workflow and signals, but cannot remove your accountability for thresholds, exceptions and review.

Evaluate screening data and case operations

Screening quality depends on source coverage, update frequency, name-matching behaviour, transliteration, aliases and the context shown to reviewers. Ask how false positives are controlled without hiding genuine matches.

  • Document list sources and update schedules
  • Test common names, multiple scripts and incomplete dates of birth
  • Preserve search inputs, candidate results and reviewer rationale
  • Define re-screening triggers after list or customer changes
  • Separate alert creation from final risk decisions

What to compare across KYC and AML providers

Identity and data-source coverage
Sanctions, PEP and adverse-media sources
Matching configuration and explainability
Case management and reviewer permissions
Risk scoring and workflow orchestration
Ongoing monitoring and refresh triggers
Audit trail, retention and reporting
Integration effort and operational pricing

Evidence to request

Request sample audit records, workflow diagrams, list-source documentation, security materials and proof-of-concept results. Confirm which functions are native, supplied by third parties or require separate contracts.

IA
Important

This page is general information, not legal or compliance advice. Applicable obligations and acceptable controls must be determined for your entity, products and jurisdictions.