Reference🧭 Global overviewsIntermediate⏱ 28 min read

🔎 KYC and KYB around the world

Due diligence levels and account tiers, India’s Aadhaar e-KYC and V-CIP, video identification in Europe, beneficial ownership registers, KYB for platform sellers, sanctions screening, and remediation

Three levels of due diligence, one common standard

Customer due diligence covers every check an institution runs on a customer’s identity, business, and source of funds. National regimes all derive from a common framework. The 40 Recommendations of the Financial Action Task Force (FATF) set that framework, and mutual evaluations, in which countries review one another, check how it is applied. A jurisdiction found deficient is placed under increased monitoring. Recommendation 1 establishes the risk-based approach. Recommendation 10 names the four events that trigger due diligence: establishing a business relationship, an occasional transaction above a threshold, a suspicion of money laundering or terrorist financing, and doubts about data already collected. The same grid shows up in every market. Local law transposes it, and a local authority supervises how it is applied.

The due diligence level is how intensively an institution scrutinizes a given business relationship. Each customer gets its own level, which can be revised over the life of the relationship. It rests on a risk rating that the institution must be able to justify with documentation. Everywhere, that rating is built on four factors: customer, product, distribution channel, and geography.

LevelTriggerWhat it adds to the fileOperational impact
Simplified due diligence (SDD)Low risk, demonstrated and documented: capped product, limited-purpose e-money, counterparty that is itself regulated and supervisedLighter or deferred verification, fewer documents, automated consistency checksOnboarding in minutes. Low caps that cannot be raised without additional documentation
Standard due diligenceDefault case, when no aggravating factor appliesVerified identity, business activity, declared source of funds, and beneficial owners for a legal entityThe file must be complete before the first payout, not before the first sale
Enhanced due diligence (EDD)Politically exposed person, high-risk third country, correspondent banking relationship, opaque ownership structure, high integrity-risk sectorDocumented source of wealth, senior management sign-off, closer transaction monitoringOnboarding takes weeks. More frequent reviews, and the institution may exit the relationship on its own decision
The three levels of due diligence and what they change in day-to-day operations

Being on the FATF “gray list” means a jurisdiction is under increased monitoring. The listing carries no sanction in itself. Its effects come from correspondent banks worldwide, which then apply enhanced due diligence to flows from that jurisdiction. Those effects last well beyond delisting. Malta was on the list from June 2021 to June 2022, and local media reported that around 40 licenses had been surrendered by the end of 2021 (The Shift News, November 2021). Lebanon was added in October 2024, with its cash-based economy explicitly cited. Nigeria, South Africa, Mozambique, and Burkina Faso were removed at the October 24, 2025 plenary.

⚠️
Delisting does not reopen accounts
A FATF plenary can lift the designation. It cannot lift correspondent banks’ distrust, because that is a commercial choice each bank makes on its own, not a collective decision. Years after delisting, a Maltese institution still finds it easier to get a license than a correspondent account. Opening a corridor therefore runs on two separate clocks. The regulatory clock moves with the plenaries, three times a year. The commercial clock of correspondent banks moves far more slowly, and nobody publishes it.
  • Politically exposed person: FATF Recommendation 12 covers the individual, their family members, and their known close associates. The status does not lapse automatically the day after the person leaves office.
  • High-risk third country: residence, nationality, registered office, and the place where the transaction is carried out. These are four independent criteria. They do not overlap, and each is checked separately.
  • Opaque ownership structure: chains of holding companies, trusts, nominee shareholders, and bearer shares where they still exist.
  • Correspondent banking relationship: the correspondent bank must know its respondent bank’s customers without having access to them. Nested banking, where a third bank uses the second bank’s account, grows out of that blind spot.
  • High integrity-risk sector: gambling, adult content, pharmaceuticals, and digital asset brokerage. The card networks keep their own list, separate from the supervisor’s, with their own registration fees.

Account tiers turn KYC into a lever for financial inclusion

An account tier is a level of account access with regulatory caps, available with reduced due diligence. Tiers resolve a tension between financial inclusion and due diligence: requiring proof of address shuts out people who have none. The first tier opens with a minimal identifier and low caps. Higher tiers lift those caps but require full due diligence. Four continents designed the mechanism independently, with no country copying another. That they converged without a shared model shows how strong the underlying constraint is.

MarketLegal frameworkEntry tierWhat lifts the caps
IndiaMaster Direction – Know Your Customer, Reserve Bank of India, issued February 25, 2016, updated August 14, 2025Account opened via Aadhaar e-KYC with a one-time passcode. Aggregate balance capped at ₹1 lakh, total credits at ₹2 lakh per year, account unusable after one yearFull due diligence at a branch, or via V-CIP, the RBI’s standardized video identification process
ChinaThree-category bank account regime introduced by the People’s Bank of China in 2015Category II and III accounts, opened remotely, with balance and transaction capsOpening a Category I account at a branch, in person
MexicoDisposiciones de carácter general for credit institutions, issued under Article 115 of the Ley de Instituciones de Crédito (CNBV)Level 1 and 2 accounts, simplified file, monthly caps set in investment units (UDIs)Upgrade to levels 3 and 4, with a complete file and face-to-face verification
NigeriaCentral Bank of Nigeria’s three-tier regime, built on the Bank Verification Number launched with NIBSS in 2014Tier 1 account, with low balance and transaction limitsBVN and full documentation, for Tier 2 and then Tier 3
ColombiaDepósito de bajo monto, a simplified account category whose prototype is Daviplata (Banco Davivienda, 2011)Opened from a phone, with balance and transaction capsMigration to a regular deposit account, with a complete file
The entry tier in five regimes, and what lifts the caps

Tiers affect payment acceptance design in three ways. The first is product. A tier cap is a binding regulatory limit, not an internal risk setting, and customer support cannot lift it case by case. The second is cash management: funds collected for a customer stuck in the entry tier pile up and cannot be paid out. The third is conversion. A flow that demands full due diligence up front loses the customers the entry tier would have captured.

Tiers come with an obligation to monitor the caps. When an account hits its limit, it must be blocked, not just flagged. The Reserve Bank of India spells this out for OTP-based e-KYC: the account becomes unusable after 12 months unless full due diligence has been completed. A monitoring setup that only raises an alert lets the account run outside the regime, sometimes for months.

🔑
Without tiers, the choice is between excluding customers and breaking the rules
A single onboarding flow calibrated to full due diligence shuts out a large share of the addressable market in economies with a big informal sector. Calibrated to the minimum, it opens noncompliant accounts as soon as amounts grow. Both options are costly, and the second puts the license at risk. Tiers are what make mass onboarding defensible to a supervisor. They are a regulatory mechanism, not a commercial favor to the customer.

India: Aadhaar e-KYC, V-CIP, and a central KYC registry

Aadhaar is a 12-digit identifier issued by the Unique Identification Authority of India (UIDAI). It is backed by biometric and demographic data and governed by the 2016 Aadhaar Act. India has turned it into public identity infrastructure. Financial institutions use it to verify customers without a branch visit. An authorized institution queries UIDAI and gets back a digitally signed response, with no paper documents involved. UIDAI’s published counters show how far the system has scaled.

1.45B
Aadhaar numbers issued since launch
UIDAI, Aadhaar dashboard, accessed August 2026
25.7B
cumulative e-KYC transactions
UIDAI, Aadhaar dashboard, accessed August 2026
182.9B
cumulative Aadhaar authentications
UIDAI, Aadhaar dashboard, accessed August 2026
₹1 lakh
maximum aggregate balance on an account opened through OTP-based e-KYC
RBI, Master Direction on KYC, update of August 14, 2025
February 25, 2016
Reserve Bank of India Master Direction on KYC
The core text for any customer onboarding in Indian finance. It has been updated continuously ever since, most recently on August 14, 2025.
2016
Aadhaar Act
The identifier gets a legal basis, and online authentication a binding framework.
September 26, 2018
Supreme Court’s Puttaswamy ruling
The Court strikes down Section 57 of the Aadhaar Act. Private entities lose the right to require Aadhaar authentication from their customers.
2019
Aadhaar and Other Laws (Amendment) Act
Banks and telecom operators can again use Aadhaar e-KYC on a voluntary basis, subject to authorization.
January 2020
V-CIP standardized
The RBI amends its Master Direction to regulate video identification, down to penetration tests by CERT-In-empaneled auditors.
June 27, 2025
AePS operator due diligence
Directions RBI/2025-26/63 subject operators of Aadhaar Enabled Payment System touchpoints to due diligence. They have applied since January 1, 2026.

Access to Aadhaar e-KYC requires authentication user agency or e-KYC user agency status. That status is contracted with UIDAI and limited to authorized categories. A foreign provider cannot plug in with just an API key. Most nonbank firms go through a licensed partner, and that partner is who they negotiate with. Three channels remain outside online authentication. Offline Aadhaar XML is downloaded by the customer and signed by UIDAI. Masked Aadhaar shows only the last four digits. The Virtual ID (VID) is a revocable token that stands in for the number.

The Central KYC Records Registry (CKYCR), run by CERSAI, has centralized KYC records for India’s financial sector since 2016. It is the second layer of the system, after Aadhaar authentication. A customer verified once receives a 14-digit KYC identifier, which lets another institution retrieve the record instead of rebuilding it. Portable due diligence has worked in India for 10 years, while Europe is still building it one directive at a time.

⚠️
Consent is the first thing auditors look for
An e-KYC request requires the customer’s consent, timestamped and retained by the entity making the query. Missing consent, or a missing record of it, is more than a procedural lapse. The request becomes unlawful, and the resulting file is unusable. India’s architecture puts the burden of proving consent on the querying entity, never on UIDAI. An integration that logs the registry’s response but not the request or the consent leaves an empty regulatory record. Check that audit trail during acceptance testing on a real case, not six months after go-live.

Video KYC: one method, as many regimes as supervisors

Remote identification covers any method of verifying a customer’s identity without the customer being physically present. Video KYC is the variant in which the customer shows an official ID document to a camera. Europe has no single method, and won’t before 2027. Each member state authorizes its own methods, through a supervisory circular or by reference to national law. A single banking group may therefore run four or five different onboarding flows across the EU. The regimes differ less on the principle than on the evidence required and on who keeps it.

RegimeProof of identityProof of presenceTechnical requirements
V-CIP, Reserve Bank of IndiaOfficial document shown on camera, or offline Aadhaar XML, with a consistency checkLive video interview with random questions; liveness detection mandatoryInfrastructure hosted on the institution’s own premises, end-to-end encryption, GPS coordinates and timestamp in the recording, penetration tests by a CERT-In-empaneled auditor
Videoident, GermanyDocument read and its optical security features checked on screenLive video interview with a trained agentRecording retained, human agent required. The Chaos Computer Club publicly defeated a flow of this kind in August 2022, reopening the debate on the required level of assurance
Video identification, SpainDocument read, automated checks, human review after the factVideo recorded by the customer, with no live agentRecording and audit trail retained. Methods authorized since 2016 by SEPBLAC, Spain’s financial intelligence unit and AML supervisor
Reusing a bank identityThe bank that already performed due diligence vouches for the customer (BankID, itsme, iDIN, Smart-ID)Strong authentication with the vouching bankNo video capture. The relying party inherits due diligence without knowing its exact scope
Querying a government registrySigned response from the registry (Aadhaar in India, Myinfo in Singapore, BVN in Nigeria)A factor tied to the registry, often a code sent to the mobile number on fileAccess authorization, contract with the authority, consent logged for every request
What remote identification requires, by regime

Liveness detection is the check that tells a person actually in front of the camera from a reproduction of their face. Two attack vectors are routinely confused. A presentation attack holds a screen, a photo, or a mask up to the lens, and image analysis catches it. An injection attack replaces the camera feed with synthetic video upstream of the sensor. The stream that arrives is perfectly clean, so this check cannot detect it. The ISO/IEC 30107-3 standard governs how these checks are evaluated, and test levels and the attack vectors covered vary from one certification to the next. A certification that covers presentation attacks alone proves nothing about resistance to injection.

The EU’s anti-money laundering package will end this patchwork on a date that is already set. Regulation (EU) 2024/1624, adopted on May 31, 2024, applies from July 10, 2027. It replaces national transpositions with a directly applicable text, which removes the leeway in which local methods grew up. Directive (EU) 2024/1640 accompanies it. Regulation (EU) 2024/1620 creates the Anti-Money Laundering Authority (AMLA), whose seat was set in Frankfurt am Main in February 2024. AMLA will draft the technical standards for remote onboarding and, from 2028, will directly supervise a first group of cross-border institutions.

ℹ️
The EU identity wallet comes with a mandate to accept it
Regulation (EU) 2024/1183 amends eIDAS and creates the European Digital Identity Wallet. The deadlines run from the entry into force of the implementing acts on December 24, 2024. Each member state must provide at least one wallet within 24 months. Private relying parties that are legally required to use strong authentication, including financial services, must accept it within 36 months. The obligation is to accept the wallet as a means of identification, not to let it replace due diligence checks. The wallet does not remove any due diligence requirement: an institution that accepts it must still verify the source of funds, identify beneficial owners, and screen against sanctions lists.

Beneficial ownership registers

The beneficial owner is the natural person who ultimately controls a legal entity. FATF, EU law, UK law, and the US customer due diligence rule all use the same benchmark threshold: 25% of the capital or voting rights. But identifying the owner is more than applying that threshold. Control can also come through a shareholders’ agreement, the power to appoint directors, or financing, without any single stake reaching a quarter. When no beneficial owner can be identified, the regimes require the institution to name the senior managing official as a fallback.

2015
Fourth Anti-Money Laundering Directive
The EU requires each member state to keep a central register of the beneficial owners of companies incorporated in its territory.
April 6, 2016
UK PSC register
The register of persons with significant control becomes mandatory, with a threshold of more than 25% of shares or voting rights.
2018
Fifth Anti-Money Laundering Directive
The registers are opened to the general public across the EU.
March 2022
FATF revises Recommendation 24
A register alone is no longer enough. Countries must combine several sources of information on the beneficial ownership of legal persons.
August 1, 2022
Register of Overseas Entities
The UK requires foreign entities that own UK property to declare their beneficial owners.
November 22, 2022
Court of Justice of the European Union ruling
In joined cases C-37/20 and C-601/20, the Court strikes down general public access to the registers as disproportionate under fundamental rights.
January 1, 2024
US Corporate Transparency Act
Beneficial ownership reporting to FinCEN takes effect, covering US companies as well.
May 31, 2024
EU anti-money laundering package
Directive (EU) 2024/1640 restores register access for people who can show a legitimate interest, including journalists and civil society.
March 26, 2025
The US pulls back
A FinCEN interim final rule, published in the Federal Register, removes the reporting requirement for companies formed in the US. Only foreign companies registered to do business in a US state remain covered.
November 18, 2025
Identity verification at Companies House
Identity verification, available on a voluntary basis since April 8, 2025, becomes a legal requirement for directors and persons with significant control.
RegisterWho reportsWho has accessWhat it does not guarantee
EU national registersEvery company incorporated in the member stateAuthorities, obliged entities, and, since Directive (EU) 2024/1640, people with a legitimate interestAccuracy. The data is self-declared, and how thoroughly it is verified varies by country
PSC register, UKEvery company registered with Companies HouseThe public, free of chargeThe filer’s honesty. Identity verification has been mandatory only since November 18, 2025
Register of Overseas Entities, UKForeign entities that own property in the UKThe public, with restrictions on trust informationCoverage. The register covers property ownership only, not business activity
Beneficial Ownership Information, FinCEN (US)Since the March 26, 2025 interim final rule, only foreign companies registered in a US stateAuthorized agencies, and financial institutions with the reporting company’s consentUniversal coverage. Companies formed in the US no longer have to report
Four registers, and what a verifier can actually get out of them

A beneficial ownership register records what the company declares. It does not establish who actually owns it. Three mechanisms are enough to hollow it out. A nominee shareholder appears on the register without holding real power. A chain of holding companies dilutes each stake below the threshold, layer after layer, until no name surfaces. A trust separates the settlor, the trustee, and the beneficiary, often across jurisdictions whose registers do not go equally deep. That is why FATF’s March 2022 revision of Recommendation 24 requires countries to combine several sources of information rather than rely on the register alone.

⚠️
The register is a starting point, never proof
A due diligence file that rests only on a register extract will not survive a supervisory review. The expected method cross-checks at least three sources: the customer’s own declaration, the extract from the official register, and a structure chart provided by the company itself. Discrepancies between these three sources are the intended output of the check, not a sign that it failed: they show exactly where the declarations disagree. An unresolved discrepancy leads to enhanced due diligence or to declining the relationship. Noting it in the file does not close out the due diligence.

KYB for platform sellers

KYB is the verification of a legal entity entering into a business relationship. KYC applies to individuals. No business identifier is mandatory worldwide, and no cross-border register can be searched with a single query. A platform onboarding 2,000 sellers a week in 20 countries therefore deals with 20 formats, 20 registers, and 20 update cycles. Most of the cost lies in the internal reference database, not in each individual check. That database lists, for every country, which business number to ask for and which official source to check it against.

MarketIdentifierIssuing registryWhat it lets you verify
BrazilCNPJReceita FederalExistence, tax status, declared activity. A business chave Pix is tied to its holder’s CNPJ
IndiaCIN for the company, GSTIN for indirect taxMinistry of Corporate Affairs, tax authorityRegistration, legal form, tax registration status
SingaporeUEN (Unique Entity Number)Accounting and Corporate Regulatory AuthorityExistence, plus direct addressing: PayNow uses the UEN as the proxy for legal entities
MalaysiaSSM registration numberSuruhanjaya Syarikat MalaysiaExistence, plus DuitNow addressing by business registration number
ThailandCorporate tax IDThai Revenue DepartmentPromptPay uses this number to address legal entities, which ties the account to a registered entity
IndonesiaNIB and NPWPOSS system, tax authorityBusiness license and tax registration, checked separately
United KingdomCompany numberCompanies HouseExistence, directors, persons with significant control, filed accounts
NigeriaRC numberCorporate Affairs CommissionExistence and legal form. The director is verified through their BVN
Japan13-digit corporate number (法人番号)National Tax AgencyOfficial name and address, publicly available free of charge
MexicoRFCServicio de Administración TributariaTax registration, in practice a prerequisite for payouts
Which business identifier to ask for, market by market

The Legal Entity Identifier (LEI) is a 20-character code defined by ISO 17442, issued by accredited organizations and overseen by GLEIF. It is a global identifier, but it is not mandatory outside the financial sector. What sets it apart is its relationship data. The LEI shows the direct parent and the ultimate parent, which no national register does. Renewal is annual and paid, so part of the population sits in lapsed status. A lapsed LEI still identifies the entity, but its ownership hierarchy is no longer attested.

The card networks set their own KYB requirements on top of the supervisor’s. Under Visa and Mastercard rules, an aggregator that collects payments for sellers must onboard and monitor its sponsored merchants. Visa rules require a sponsored merchant to contract directly with the acquirer once its annual volume exceeds $1 million. In 2022, Visa replaced its Global Brand Protection Program with the Visa Integrity Risk Program. Mastercard runs the Mastercard Registration Program. Under both, high integrity-risk categories are registered, monitored, and billed, regardless of any legal requirement.

⚠️
Transaction laundering, the blind spot of self-declared KYB
Transaction laundering is when a properly onboarded seller is in fact processing payments for an undisclosed third party. A seller registered for phone accessories may be processing payments for a completely different business. Nothing in the onboarding file reveals it, because the declarations were true when the file was put together. Detection therefore relies on transaction analysis, not on documents. Warning signs include an average ticket out of line with the declared category, buyer addresses clustered outside the stated market, regular overnight spikes, and a dispute rate abnormally low for the sector. Mastercard’s MATCH listing reason code 03 targets exactly this situation, and a listing stays on file for five years.
  • Matching the director, the beneficial owner, and the payout account holder. These three names should line up, and in fraudulent files they almost never do.
  • Age of the registration. A company incorporated three weeks before onboarding, in a high-ticket category, warrants a manual review before the first payout.
  • The same business identifier reused across several seller accounts, often with slightly different spellings of the company name.
  • Declared category versus the actual catalog. Check the published listings, not the sign-up form.
  • A change of payout account shortly before a large payout. It signals a compromised seller account and calls for a cooling-off period.

Sanctions and screening

Financial sanctions are measures that freeze assets and prohibit making funds available to specifically designated individuals or entities. Screening is the process by which an institution checks the parties to a transaction against those designation lists. The regime differs from AML due diligence. AML tolerates a calibrated, documented residual risk; an asset freeze tolerates none. A payment made to a designated person is a violation, whatever the intent. Under US rules, civil liability is strict. Dollar clearing alone gives US authorities jurisdiction, even over a flow between two non-US banks. The nexus comes from routing through a New York correspondent bank, which the customer does not choose.

ListAuthorityReachWhat sets it apart
SDN List and non-SDN listsOffice of Foreign Assets Control, US Department of the TreasuryUS persons, and any transaction with a US nexus, including dollar clearingThe broadest and most demanding regime. Secondary sanctions risk reaches firms with no US presence at all
EU Consolidated Financial Sanctions ListEuropean Commission, based on Council decisions and regulationsEU persons and transactions carried out in the EUEach measure has its own legal basis. Obligations vary from one sanctions regime to another
UN Security Council Consolidated ListUnited NationsAll member states, once transposed into national lawThe common baseline that other lists incorporate, transposed with varying delays from country to country
UK Sanctions List and OFSI Consolidated ListForeign, Commonwealth and Development Office, HM TreasuryUK persons and transactions with a UK nexusA standalone regime since Brexit, with deliberate differences in scope
National lists (Switzerland’s SECO, Australia’s DFAT, Global Affairs Canada, Japanese authorities)National authoritiesDepends on the nexus of the transaction or the partyScreening only against US and EU lists leaves documented gaps on some corridors
The lists to screen against, and who maintains them

Two rules extend a designation to structures owned by a designated person, so the list never contains every entity covered. OFAC has applied the 50% rule since revised guidance issued on August 13, 2014. An entity owned 50% or more, directly or indirectly, individually or in the aggregate, by one or more designated persons is itself blocked, even though it is not on the list. The EU uses an ownership test of more than 50%, supplemented by a set of control indicators. Screening on names alone therefore misses these owned entities. Catching them means tracing the ownership chain as it stood on the date of the transaction.

What a cross-border transfer goes through before it is executed
Originating institution
Screens the originator and the beneficiary
Screening at onboarding, then on every transaction. The lists will have changed in between
Payment message
Carries the data required by Recommendation 16
Originator’s name, account number, and address or ID; beneficiary’s name and account. The simplified-requirements threshold is USD or EUR 1,000
Correspondent bank
Re-screens on its own behalf
It applies the rules of its own jurisdiction, not the sender’s. A message that was compliant at origin can be stopped in transit
Screening engine
Raises an alert on a fuzzy match
Transliteration, name order, namesakes, owned entities. The vast majority of alerts are false positives that still need to be dispositioned
Analyst
Dispositions, releases, or freezes
Freezes are reported to the competent authority within the national deadline. Releases are documented, because they will be audited

Screening comes down to comparing character strings. A name written in Arabic, Cyrillic, or Chinese arrives transliterated, and every transliteration produces variants. Mohammed, Muhammad, and Mohamed are the same person. Screening engines therefore use fuzzy matching with an adjustable similarity threshold. A lower threshold multiplies false positives and swamps the review team. A higher threshold produces false negatives, letting through a transaction that benefits a designated person, and the asset-freeze regime tolerates none. Threshold tuning must be documented, tested against known test sets, and rerun with every list update.

⚠️
List refresh latency is an exposure, not a technical setting
A designation takes effect when it is officially published, not when the institution next imports the file. An institution that reloads its lists once a day is accepting a 24-hour exposure window. On an instant payment rail, that window lets thousands of irreversible transactions through. Two parameters set its real size. The first is the lag between official publication and the vendor making the data available. The second is what a reload does: whether it triggers a rescreen of the existing customer base or applies only to future transactions. Get both in writing before signing the data supply contract.

Remediation and periodic review

Remediation means reworking a backlog of due diligence files that no longer meet the standard. It is rarely planned for in workload forecasts, yet it weighs heavily on budgets once it starts. Volumes run to tens or hundreds of thousands of files. The timeline is set externally and cannot be negotiated. The per-customer onboarding cost, optimized for years, says nothing about the cost of reworking an old file for a customer who no longer responds.

  • Supervisory follow-up. The authority sets the deadline, and progress is reported periodically, file by file.
  • Acquisitions. The acquired portfolio was built under a different regime, sometimes in a different country. The files cannot be converted; they have to be redone.
  • A change of standard. When Regulation (EU) 2024/1624 starts to apply on July 10, 2027, it will trigger projects like this across the EU.
  • A structural collection gap. A field never filled in, a document never requested, discovered years later across the entire backlog.
  • A country added to the gray list. Lebanon’s listing in October 2024 moved every relationship linked to that market into enhanced due diligence overnight.
The five stages of a remediation, and where it goes wrong
Scoping
Define the population in scope and the target compliance rule
This is where the costliest mistake happens. Too broad a definition inflates the volume; too narrow a definition means redoing the project two years later
Segmentation
Sort the backlog by risk level and by type of gap
A file missing proof of address is not handled like a file with no identified beneficial owner
Outreach
Ask the customer for the missing documents
The unprompted response rate drives the rest of the timeline. Measure it on a sample before sizing the team
Escalation
Restrict, then freeze, accounts that have not been brought up to date
Restrictions must be graduated and notified. An unexplained freeze invites customer litigation and a complaint to the supervisor
Closure
Document the population covered and any remaining exceptions
The supervisor reviews the method and completeness, not just the number of files fixed

Traditional periodic review schedules a reassessment at a fixed interval, with a frequency set by risk level. The model has two mirror-image flaws. It forces reviews of files that nothing has changed, and it leaves untouched, for a full cycle, files that changed the day after their review. Ongoing due diligence, often called perpetual KYC, works the other way around: events trigger the review. A change of director in the register, a change in the ownership structure, the customer’s country of residence being added to a list, or a break in the transaction profile is enough to reopen the file. The periodic cycle then remains as a safety net rather than the main trigger.

De-risking is when an institution exits entire categories of relationships rather than bear the cost of monitoring them. FATF and the World Bank have documented it for a decade. Remittance corridors to Africa and the Pacific still bear the marks, with operators cut off from banking services. Exiting is a business decision made under compliance pressure, not a compliance decision in the strict sense. How it is characterized shapes the institution’s defense. A business decision generally falls under its freedom to contract, while a compliance decision is judged against a documented risk assessment.

🔑
Remediation is won on outreach, not on tooling
The cost of a remediation is concentrated in a single line item: getting the missing document from the customer. Response rates to a first email request are low on an old backlog, where some contact details are no longer valid. Collection then continues across multiple channels, with calibrated reminders and graduated service restrictions. That response rate determines team size and project length. Standard practice is to measure it on a sample before committing the budget. Most of that budget goes to customer outreach, more than to software licenses.

What breaks in production, and what it costs

Failures seen in production stem from how compliance controls are implemented, and more rarely from how the law is interpreted. They come from operational trade-offs that nobody decided when it mattered. The same failures recur from one market to the next under different names. Each one can be caught before go-live by explicitly testing the point in question.

FailureRoot causeWhat it costsPrevention
Funds collected for a customer who was never verifiedPayment collection starts before the file is complete, with no cap attachedOrphaned balances that cannot be paid out and are hard to return. The supervisor sees funds held with no legal basisCap collections until the file is complete, from the moment the flow is designed
Sanctions alert not handled in timeFalse-positive volume sized on the average, not on list-update peaksTransactions executed without disposition. A clear-cut breach, regardless of the outcomeSize for the peak, and document the queue prioritization rule
e-KYC consent not loggedThe integration logs the registry’s response, not the request or the consentFiles unusable for the entire period affected. They cannot be reconstructed after the factTest the audit trail end to end during acceptance testing, on a real file
Beneficial owner frozen at onboardingNo review triggered by a register eventThe file is wrong from the first change in shareholding, and nothing flags itSubscribe to register change notifications for the entire legal-entity portfolio
Verification redone in every countryNo single customer database across subsidiaries or brandsHigher costs, a worse customer experience, and personal data duplicated for no reasonA single customer database, subject to each market’s data localization rules
List reloaded without rescreening the customer baseThe engine screens the transaction flow, never the existing portfolioA customer designated after onboarding stays active and keeps being servedFull portfolio rescreen on every update, with timestamped proof that it ran
Six compliance failures, their real cause, and the fix
  • Actual coverage by country, distinguishing registers queried live from copied databases. A copied database goes stale, and its age is never displayed.
  • Sanctions list latency, between official publication and availability in the vendor’s feed.
  • The liveness detection test level, with the standard applied and the attack vector actually covered.
  • Raw data returned, not just the verdict. A “rejected” with no reason can be neither challenged nor improved.
  • Where processing and storage take place, market by market. India, Indonesia, and Nigeria impose constraints that a European master agreement ignores.
  • Reversibility, with a usable export of the verified-file backlog. A due diligence file that cannot be ported locks you in for years.
🔑
The question that separates vendors
Fallback mode is how a verification system behaves when the official source it queries goes down. An outage at a government registry or a sanctions list service halts onboarding. Three behaviors are commonly chosen: deny by default, queue with automatic retry, or switch to a declared secondary source. Which one applies should be negotiated and documented before the contract is signed. This point separates a real verification provider from an interface reseller. A contract that is silent on it leaves the response entirely to the vendor’s discretion.