Top 500 Essential KYC Interview Questions & Answers
Practise 500 KYC interview questions and answers — written the way strong candidates actually speak, not textbook definitions. Every question includes a model answer across KYC fundamentals, identity verification, CDD and risk rating, EDD and PEPs, beneficial ownership, screening, ongoing monitoring, corporate KYC, crypto & fintech KYC, and judgement scenarios — the ten areas KYC interviews are actually built from, for analyst, onboarding, EDD, and compliance roles.
Filter by category, search any topic, and — most importantly — practise saying your answers out loud. Reading builds knowledge; speaking builds interview performance. When you're ready, AGZIT's AI mock interview asks you these kinds of questions by voice and scores your answers — your first session is free.
500 questions · 10 categories · model answers included · free, no signup needed to read
KYC Fundamentals & Concepts
Q1What is KYC and why do financial institutions need it?▾
KYC — Know Your Customer — is the process of establishing who a customer is, what they do, and what activity to expect from them. Institutions need it because every downstream control — risk rating, monitoring, reporting — depends on knowing what normal looks like for each customer; without KYC, suspicious activity has no baseline to stand out against.
Q2What is the difference between KYC and AML?▾
AML is the whole framework for preventing and detecting money laundering — laws, monitoring, reporting, governance. KYC is the foundation layer inside it: identifying customers and understanding their expected behaviour. In practice, KYC answers 'who are you', while the rest of AML answers 'is what you're doing consistent with who you are'.
Q3What are the core components of a KYC programme?▾
Customer identification and verification; understanding the purpose and intended nature of the relationship; identifying beneficial owners; screening against sanctions, PEP, and adverse-media data; risk rating; and keeping information current through ongoing and event-driven reviews. Together these produce a profile that monitoring can act on.
Q4What is a customer identification programme (CIP)?▾
The formal, documented process for collecting and verifying identity at onboarding — typically name, date of birth, address, and an identification number — using reliable, independent sources. It is a legal minimum in most regimes; the institution must also keep verification records and check customers against required lists.
Q5What is the difference between a customer and a beneficial owner?▾
The customer is the party in whose name the account or relationship exists — a person or an entity. The beneficial owner is the natural person who ultimately owns or controls that customer or benefits from the relationship. For personal accounts they usually coincide; for entities, KYC must look through the structure to find the humans.
Q6Why is KYC described as a lifecycle rather than an event?▾
Because the profile decays: ownership changes, businesses pivot, risk factors emerge, documents expire. Onboarding creates the profile; periodic reviews, event-driven refreshes, screening updates, and behaviour reconciliation keep it true. A file accurate in 2020 and untouched since is not compliance — it's history.
Q7What is expected activity and why is it central to KYC?▾
A specific statement of how the customer will use the relationship — transaction types, volumes, values, counterparties, and geographies. It converts identity into a behavioural baseline. Monitoring compares reality against it, so vague expected activity produces blind monitoring, while precise expectations make anomalies visible.
Q8What is a risk-based approach in KYC?▾
Scaling due-diligence depth to the risk each customer presents: light verification for demonstrably low-risk customers, standard CDD for most, and enhanced measures for high-risk ones. It concentrates effort where laundering risk actually lives, and it is the organising principle of FATF standards and every modern regime.
Q9Who sets KYC standards globally and locally?▾
Globally, the FATF Recommendations define the architecture, with Basel and Wolfsberg adding supervisory and industry guidance. Locally, national law and regulators implement them — FinCEN and the banking agencies in the US, the FCA and MLRs in the UK, RBI in India, and so on. Institutions comply with local law while tracking FATF direction.
Q10What happens if a bank gets KYC wrong at scale?▾
Regulatory findings and fines, forced remediation of the customer book, restrictions on growth, personal accountability for senior managers, and reputational damage that drives away correspondent partners. Most major AML enforcement actions trace back to KYC failure — files that never established who customers really were.
Q11What is the purpose of the KYC profile beyond compliance?▾
A true profile protects the institution commercially: accurate risk pricing, fraud prevention, better product fit, and credit insight. It also protects customers — correct identity data prevents impersonation. Compliance drives the requirement, but a quality profile is simply knowing your business.
Q12What is meant by 'source of funds'?▾
Where the money in a specific transaction or account originated — salary, business revenue, a property sale, an inheritance. It is transaction-level and evidenced with documents like payslips or completion statements. KYC captures it at onboarding for context and tests it later when activity raises questions.
Q13What is meant by 'source of wealth'?▾
How the customer accumulated their overall net worth across their lifetime — career earnings, business ownership, investments, inheritance. It is broader than source of funds and matters most for high-net-worth customers and PEPs, where enhanced due diligence requires a credible, corroborated wealth narrative.
Q14What is the difference between identification and verification?▾
Identification is collecting the customer's claimed details; verification is testing those claims against reliable, independent evidence — documents, databases, registries, biometrics. A file can be fully identified and completely unverified; only both together satisfy KYC.
Q15What is a politically exposed person (PEP) in one sentence, and why does KYC care?▾
A PEP holds or has held a prominent public function — head of state, senior politician, judge, general, state-enterprise executive — and KYC cares because that position creates opportunity for corruption and access to public funds, so regulation mandates enhanced due diligence rather than ordinary onboarding.
Q16What is adverse media in KYC?▾
Negative news connecting a customer or connected party to crime, corruption, sanctions, or regulatory action. It often surfaces risk years before official lists do, so screening for it informs onboarding decisions, risk ratings, and review triggers — always with judgement about source quality and identity matching.
Q17What is a high-risk customer?▾
One whose profile elevates laundering exposure: high-risk geography connections, opaque or complex structures, cash-intensive or high-risk industries, PEP status, adverse media, or unusual product usage. The label triggers enhanced due diligence, senior approval, and closer, more frequent monitoring and review.
Q18What is customer risk rating and what typically feeds it?▾
A structured classification — usually low, medium, high — combining who the customer is (type, occupation, ownership), where they are and operate (geography), what they use (products, channels), and how they behave. The rating drives due-diligence depth, review frequency, and monitoring sensitivity.
Q19What are the three lines of defence, applied to KYC?▾
First line: onboarding teams and relationship owners who collect, verify, and own customer risk. Second line: compliance, setting KYC policy, advising, and testing quality. Third line: internal audit, independently assuring the framework works. The separation keeps commercial pressure from quietly lowering the KYC bar.
Q20What records must KYC keep and for how long?▾
Identification and verification evidence, due-diligence documents, screening results, risk assessments, and account files — retained typically five years after the relationship ends (longer in some regimes), sufficient for a regulator or investigator to reconstruct who the customer was and what the institution knew.
Q21What is tipping off, and how does it touch KYC work?▾
Disclosing that a report or investigation exists, directly or by implication — a criminal offence in most regimes. KYC teams touch it during RFIs and exits: outreach must use neutral commercial language, because a clumsy 'compliance needs to check something suspicious' can prejudice an investigation.
Q22What is de-risking and why do regulators dislike it?▾
Dropping or refusing entire customer categories — charities, money-service businesses, certain nationalities — instead of assessing individuals. Regulators dislike it because it displaces risk into opaque channels and harms financial inclusion; the expectation is case-by-case due diligence with documented decisions.
Q23What is a shell company, and is banking one ever acceptable?▾
An entity with no meaningful operations or presence — often legitimate as a holding vehicle, but also the classic concealment tool. Banking one is acceptable only when ownership, purpose, and funding are fully transparent and make commercial sense; opacity without rationale is the exit signal.
Q24What is a front company versus a shell in KYC terms?▾
A shell has no real activity; a front runs genuine visible business used to disguise illicit flows within plausible revenue. Shells fail KYC on substance questions; fronts pass superficial KYC and fail on behavioural analysis — declared turnover versus sector reality, cash patterns versus business model.
Q25What is a nominee and why does KYC probe nominee arrangements?▾
A nominee holds shares, directorships, or accounts in name only, on behalf of someone else. KYC probes them because the register then shows the wrong person; regulations require identifying the real party behind nominees, and undisclosed nominee control is a classic ownership-concealment red flag.
Q26What is a legal entity versus a legal arrangement?▾
Entities — companies, foundations — have their own legal personality. Arrangements — trusts being the main case — are relationships between parties without personality. KYC treats them differently: arrangements require identifying settlor, trustee, protector, and beneficiaries rather than shareholders and directors.
Q27What is meant by 'purpose and intended nature' of a relationship?▾
Why the customer wants this account and how they intend to use it: products, expected volumes, counterparties, geographies. It anchors both the risk assessment and the monitoring baseline — and an account used contrary to its stated purpose is one of the cleanest escalation triggers KYC produces.
Q28What is simplified due diligence (SDD)?▾
A reduced verification package permitted where risk is demonstrably low — regulated financial institutions, listed companies on recognised exchanges, some public bodies, depending on jurisdiction. It lightens evidence requirements but never eliminates them, and it is unavailable the moment suspicion appears.
Q29What is enhanced due diligence (EDD) at a headline level?▾
The deeper package for higher-risk customers: senior management approval, source of wealth and funds corroboration, more extensive verification, tighter expected-activity definition, and intensified ongoing monitoring. EDD is mandatory for certain categories — foreign PEPs, correspondent banking, high-risk jurisdictions — and policy-driven elsewhere.
Q30Why do regulators emphasise beneficial ownership so heavily?▾
Because anonymity is the laundering enabler: criminals act through entities precisely so no human appears. Beneficial-ownership rules force institutions to look through structures to the people in control, which is why registers, the 25% threshold concept, and control-based tests sit at the centre of modern KYC reform.
Q31What is the 25% threshold in beneficial ownership?▾
The common regulatory line at which ownership makes someone a beneficial owner — holding more than 25% of shares or voting rights, directly or indirectly. It is an indicator, not the whole test: control through other means counts regardless of percentage, and some regimes and risk policies use lower thresholds.
Q32What does 'control through other means' capture?▾
Power without headline shareholding: rights to appoint or remove directors, veto rights, dominant influence via agreements or family arrangements, or de facto control of decisions. KYC must ask who actually directs the entity — ownership percentages are only the first approximation.
Q33What is a UBO declaration and how much can you rely on it?▾
A customer's self-certification of its beneficial owners. It is a starting point and an accountability document, not verification: KYC corroborates it against registers, formation documents, and structure analysis, with reliance scaled inversely to risk. High-risk plus self-certification-only equals a gap.
Q34What is KYC remediation?▾
A programme to repair deficient files at scale — missing verification, unidentified owners, stale data — usually triggered by audits, regulatory findings, or acquisitions. It runs risk-first, with outreach, verification, re-rating, and exits for non-cooperation, and its quality is itself a regulatory examination topic.
Q35What is perpetual KYC (pKYC)?▾
Replacing calendar-based reviews with continuous, event-driven updating: registry feeds, screening deltas, transaction behaviour, and news trigger targeted refreshes as changes happen. Done well it keeps files permanently current and cuts review waste; done carelessly it automates errors — governance and data quality decide which.
Q36What is the relationship between KYC and fraud prevention?▾
Deep and growing: identity verification blocks impersonation and synthetic identities; expected-activity baselines expose account takeover and mule usage; ownership transparency defeats shell-based scams. The same weak file that admits a launderer admits a fraudster — many institutions now run the controls jointly.
Q37What is a synthetic identity and why is it a KYC problem?▾
An identity assembled from real and fabricated attributes — a genuine ID number with an invented name — nurtured until it looks established. It defeats element-by-element verification because pieces check out individually; detection needs cross-attribute consistency, bureau signals, and network analytics.
Q38What is digital or eKYC?▾
Electronic identity verification: document capture with authenticity checks, biometric matching with liveness detection, and validation against authoritative databases — producing an audited, often faster and more reliable onboarding than manual document review. It is now the default in fintech and increasingly in banking.
Q39What is video KYC?▾
Verification through a live, recorded video interaction — the customer shows their face and documents while an agent or system runs authenticity and liveness checks. Several regulators (notably in India) formalised it as an accepted full-KYC channel, with prescribed controls around recording, geotagging, and agent training.
Q40What is the difference between onboarding KYC and ongoing KYC?▾
Onboarding establishes identity, ownership, purpose, and risk before the relationship starts. Ongoing KYC keeps that picture true: periodic reviews, event triggers, re-screening, and reconciling actual behaviour against expectations. Regulators increasingly weight the ongoing half — files rot faster than they are built.
Q41What is an event-driven review trigger? Give examples.▾
Any change that invalidates the current profile: ownership or director changes, adverse media, sanctions-list updates touching connected parties, sudden behavioural shifts, new high-risk products, dormancy followed by activity, or law-enforcement contact. Event triggers exist because risk does not wait for the review calendar.
Q42What is customer offboarding or exit in KYC terms?▾
Ending a relationship for risk reasons: a governed decision with documented rationale, notice per contractual terms, careful handling of funds, no tipping off, and filings where suspicion exists. Exit also feeds controls — identifiers flagged against re-onboarding and lessons fed back into acceptance criteria.
Q43What is a customer risk appetite statement?▾
The board-approved definition of which customers the institution will accept, restrict, or refuse — by type, industry, geography, structure, and product. It converts risk tolerance into onboarding decisions, keeps individual judgement consistent, and forces exceptions through documented senior approval.
Q44Why does geography matter so much in KYC?▾
Jurisdictions carry different corruption levels, secrecy laws, sanctions exposure, and AML regime strength — and customers inherit that risk through nationality, residence, operations, and transaction corridors. Geography is usually the heaviest single factor in risk models, including mandatory treatment for FATF-listed jurisdictions.
Q45What is the FATF grey list's effect on a KYC file?▾
Connections to a grey-listed jurisdiction raise the customer's risk weighting and typically trigger deeper due diligence and closer monitoring — increased scrutiny rather than prohibition. Blacklist connections go further, into mandatory enhanced measures and, at the extreme, countermeasures.
Q46What is reliance on third-party CDD?▾
Using due diligence performed by another regulated party — a group affiliate, another bank, a professional introducer — where regulation permits. The relying institution must be able to obtain the underlying information immediately and retains full responsibility: reliance transfers work, never accountability.
Q47What is an omnibus or pooled account challenge for KYC?▾
An intermediary — broker, law firm, payment platform — holds one account containing many underlying clients' funds, so the bank cannot see the end parties. KYC responds by assessing the intermediary's own AML framework, contracting for due-diligence standards, and securing the right to obtain underlying client information.
Q48What is a data-quality issue's downstream effect in KYC?▾
Everything inherits it: wrong occupation misprices risk, unparsed addresses defeat screening, duplicate records split behaviour across profiles, stale ownership hides new controllers. Monitoring and screening can only be as good as profile data — which is why data lineage is now treated as a control, not IT housekeeping.
Q49What makes a KYC file 'audit-ready'?▾
A reviewer can reconstruct everything without asking you anything: current verified identity and ownership with a structure chart, documented screening and dispositions, a risk rating with rationale, specific expected activity, correct approvals, and a visible record of who decided what, when, and why.
Q50What is the single most common KYC failure you'd expect to find in a weak programme?▾
Stale files masquerading as compliance: onboarding done once, reviews rubber-stamped, expected activity vague, and ownership never re-verified. The programme looks complete on paper while the actual customer base has drifted years away from what the files describe.
Q51How would you explain KYC's value to a commercial colleague who sees it as friction?▾
KYC is the price of the licence — literally: regulators permit us to bank precisely because we know who we bank. Done well it is also commercial intelligence: accurate profiles price risk better, catch fraud earlier, and keep the correspondent relationships that let us move money at all.
Q52What is the difference between CDD as a noun and KYC as commonly used?▾
In precise usage, KYC is the identification-and-knowledge process and CDD is the regulatory due-diligence obligation built on it; in practice the industry uses them almost interchangeably. In interviews, show you know CDD is the formal obligation — identification, ownership, purpose, ongoing scrutiny — and KYC the broader discipline.
Q53What is Know Your Customer's Customer (KYCC)?▾
Understanding who your customer serves, where their funds ultimately come from and go — critical for intermediaries, payment firms, and correspondent-style relationships where your customer's customers drive the real risk. Full KYCC is rarely possible; the obligation is understanding the base and the controls over it.
Q54What are the biggest KYC trends right now?▾
Perpetual KYC replacing calendar reviews; digital identity and biometric verification as default; beneficial-ownership registries reshaping verification; AI-assisted document checks and entity resolution — against AI-enabled forgery and deepfakes; and regulators shifting from checklist compliance to demonstrable effectiveness.
Q55What does a great first 90 days look like for a new KYC analyst?▾
Weeks 1–2: learn the policy, risk model, systems, and quality bar by reading strong files. Weeks 3–6: work supervised cases across customer types, building speed without shortcuts. Weeks 7–12: own a full queue, hit quality scores, and start flagging process gaps you've noticed — analysts who feed improvement loops get noticed fast.
Identification & Verification
Q56What information does customer identification typically collect for individuals?▾
Full legal name, date of birth, residential address, nationality, and a government identification number — plus, by policy, occupation, employer, contact details, and tax identifiers. The set must be enough to distinguish this person from anyone with a similar name and to run meaningful screening.
Q57What documents are acceptable for identity verification?▾
Government-issued photo documents — passport, national identity card, driving licence — checked for validity, expiry, and consistency with the application. Address verification adds recent utility bills, bank statements, or government letters where required. Acceptability lists are policy- and jurisdiction-specific.
Q58How do you verify a document is genuine?▾
Layered checks: physical or digital security features (holograms, fonts, microprint), machine-readable zone consistency, checksum validation, issuing-authority database checks where available, and cross-field logic — does the age match the photo, do dates make sense. Digital tools automate most of this with authenticity scoring.
Q59What is the MRZ and why does it matter?▾
The machine-readable zone — the two or three lines of standardised characters on passports and IDs. Its check digits validate the document data mathematically, and mismatches between the MRZ and the visual zone are a strong forgery indicator. Automated verification reads it first.
Q60What is liveness detection?▾
Technology confirming a real, present human is behind a biometric capture — not a photo, video replay, mask, or deepfake. Active liveness asks for movements; passive liveness analyses texture, depth, and micro-signals from a single selfie. It is the control that makes remote biometric verification trustworthy.
Q61What is biometric matching in onboarding?▾
Comparing the customer's live selfie against the photo extracted from their identity document, producing a similarity score above a policy threshold. Combined with document authenticity and liveness checks, it establishes that the person presenting the document is its genuine holder.
Q62What is non-documentary verification?▾
Confirming identity through data rather than documents: credit bureau records, government databases, electoral rolls, telecom and utility data. Common where document verification is impractical, and often used alongside documents as corroboration. Regulations typically permit it if sources are reliable and independent.
Q63What is a knowledge-based authentication (KBA) check and its weakness?▾
Questions only the genuine person should answer — past addresses, loan amounts. Its weakness is that data breaches made the answers widely available, so fraudsters often pass KBA more smoothly than genuine customers. Modern flows treat it as a weak, last-resort factor.
Q64What is address verification and why is it still hard?▾
Confirming the customer lives where claimed, via utility bills, statements, database checks, or geotagged capture. It stays hard because documents are easily forged, databases lag moves, shared housing and informal addresses defeat matching, and address formats vary wildly across countries.
Q65How do you verify identity for a customer with thin documentation?▾
Escalate through alternatives proportionately: database and bureau checks, biometric channels, attestation regimes where law provides them, lower-risk product tiers with limits until the profile builds. Financial-inclusion guidance encourages tiered KYC — the answer is calibrated access, not automatic refusal.
Q66What is a certified copy and when is it required?▾
A copy endorsed by an approved certifier — notary, lawyer, banker — confirming they saw the original. Required when originals cannot be inspected, typically for non-face-to-face corporate onboarding and cross-border documents. The control matters because uncertified copies are trivially manipulated.
Q67What is an apostille?▾
An authentication certificate under the Hague Convention confirming a public document's origin — the signature and seal — so it is recognised across member countries. KYC meets it on cross-border corporate documents; it validates the document's issuance, not the truth of its contents.
Q68What red flags appear in forged documents?▾
Font and spacing inconsistencies, incorrect security features, MRZ checksum failures, photo tampering edges, impossible dates or number formats, template artefacts from known forgery kits, and data conflicting with independent sources. Any single flag warrants escalation to specialist review, not silent acceptance.
Q69What is document expiry policy in KYC?▾
Verification must rest on valid documents at the time it is performed; expired identity documents are generally unacceptable for new verification. For existing customers, expiry is a data point for refresh cycles — policies define when renewed documents must be obtained, especially at periodic review.
Q70How does digital identity verification handle different countries' documents?▾
Vendor libraries maintain templates for thousands of document types with country-specific security features, plus country-tuned data validation. Coverage and accuracy vary — good programmes test vendor performance on their actual customer geographies and route unsupported documents to manual expert review.
Q71What is an identity verification (IDV) waterfall?▾
A sequenced strategy: try the cheapest reliable method first — database match; fall to document-plus-biometric; fall to manual review. Waterfalls optimise cost and conversion while maintaining assurance, with routing rules by risk, geography, and signal quality.
Q72What is the trade-off between onboarding friction and verification assurance?▾
Every added check costs conversion; every removed check invites fraud. Mature programmes segment: low-risk customers get streamlined flows, risk signals trigger step-up verification. The design question is never 'maximum checks' but 'assurance proportionate to risk at each decision point'.
Q73What is step-up verification?▾
Escalating identity assurance when risk signals appear — an unusual device, mismatched geolocation, high-value activity, profile edits. Instead of front-loading friction on everyone, the flow asks for stronger evidence (biometric re-check, document refresh) exactly when the risk justifies it.
Q74What device and network signals support identity decisions?▾
Device fingerprint consistency, emulator and rooting indicators, IP geolocation versus claimed address, VPN and proxy detection, SIM and phone-number intelligence, and velocity of applications from the same device or network. They don't prove identity — they price its risk.
Q75What is a deepfake attack on onboarding and the defence?▾
Synthetic video or imagery defeating selfie and liveness checks to open accounts under stolen or invented identities. Defences: passive liveness analysing capture physics, injection-attack detection (blocking virtual cameras), document-photo forensics, cross-signal consistency, and vendor models retrained against current generation tools.
Q76What is an injection attack in remote verification?▾
Feeding pre-made images or video directly into the verification stream — bypassing the camera — via virtual camera software or API manipulation. It defeats naive liveness that trusts the capture channel. Defences verify capture integrity at device level and detect virtual-camera signatures.
Q77How do you verify politically sensitive or high-profile individuals discreetly?▾
Same standards, hardened handling: verification through official documents and databases as usual, need-to-know case access, no informal chatter, and communications through designated channels. Discretion changes logistics, never the evidence bar — profile fame is not a verification substitute.
Q78What is name matching's core difficulty?▾
Names are unstable data: transliteration across scripts, order conventions, initials, nicknames, maiden names, and data-entry noise. Verification and screening must match fuzzily enough to catch variants and precisely enough to avoid false identity merges — threshold tuning with secondary identifiers is the craft.
Q79What secondary identifiers resolve name ambiguity?▾
Date of birth first, then nationality, identification numbers, address history, and photographs. Two John Smiths separate instantly on DOB; a sanctions near-match resolves on nationality and ID data. Files thin on secondary identifiers produce screening noise for the account's whole life.
Q80What is identity proofing versus authentication?▾
Proofing establishes who a person is at onboarding — the KYC event. Authentication confirms a returning user is the same person — passwords, biometrics, tokens. They fail differently: proofing failure admits the wrong person once; authentication failure lets others in repeatedly.
Q81How should verification records be kept?▾
Capture what was checked, against which sources, when, by whom or which system, with results and scores — retained per record-keeping rules. The standard: reconstruct the verification years later for a regulator, including the document images and decision trail where law permits their retention.
Q82What is re-verification and when is it triggered?▾
Repeating identity verification during the relationship: document expiry at review, material profile changes, fraud or takeover signals, dormancy reactivation, or regulatory remediation. Ongoing KYC is not only data refresh — sometimes the identity itself must be proven again.
Q83A document passes checks but the photo resemblance is marginal. What do you do?▾
Escalate rather than rationalise: request a fresh biometric capture or alternative document, apply step-up verification, and record the concern with the resolution. Marginal face matches are exactly where impersonation lives; policy should route them to specialist review, not analyst discretion under time pressure.
Q84What is synthetic identity's typical construction and detection?▾
Construction: a real identification number (often a dormant or minor's) paired with a fabricated name and history, aged through small credit and account activity until it looks established. Detection: cross-attribute consistency checks, bureau file-depth analysis, shared-attribute networks, and issuing-authority validation of the number-name pairing.
Q85What is an identity document's 'security feature' hierarchy?▾
Level one: visible features — holograms, colour-shifting ink — checkable by eye. Level two: features needing tools — UV patterns, microprint. Level three: forensic features known to issuers. Remote verification substitutes algorithmic template checks and MRZ/chip validation for physical inspection.
Q86What is NFC chip verification?▾
Reading the cryptographically signed data on e-passports and modern IDs via a phone's NFC — validating the issuing authority's signature and cloning protections. It is the strongest remote document check available: forging paper is easy, forging the chip signature is not.
Q87How do you onboard a customer from a country whose documents you cannot reliably verify?▾
Risk-based response: alternative corroboration (databases, bank references, certified documents through trusted channels), tiered access with limits, enhanced monitoring, or refusal where assurance cannot reach policy minimums. Document the pathway chosen and why — improvisation is where these files fail audits.
Q88What is a politically mandated ID system's role in KYC (e.g., national eID)?▾
Where national digital identity exists — Aadhaar-style systems, EU eIDAS schemes, bank-ID federations — verification can rest on authenticated government confirmation rather than document inspection: faster, cheaper, and harder to forge. KYC programmes integrate them where regulation recognises the assurance level.
Q89What is the risk of over-relying on one verification vendor?▾
Single points of failure: coverage gaps in specific geographies, model blind spots fraudsters learn, outages halting onboarding, and no benchmark for performance. Mature programmes dual-source or at least test alternatives, and monitor vendor pass/fail patterns for drift.
Q90What conversion metrics matter in onboarding verification?▾
Pass rate by segment and geography, drop-off at each step, manual-review rate and turnaround, false-rejection of genuine customers, and downstream fraud rate by verification path. Tuning without fraud outcomes optimises for admitting everyone; tuning without conversion data optimises for admitting no one.
Q91What is a manual review queue's role in verification?▾
Handling what automation can't decide: unsupported documents, marginal scores, conflicting signals. Its quality determines edge-case outcomes — reviewers need forgery training, reference materials, escalation paths, and QA sampling. An untrained manual queue quietly becomes the fraudster's preferred entrance.
Q92What is identity data minimisation and why does it matter?▾
Collecting only what the risk decision needs and retaining it only as long as rules require. It matters because identity stores are breach magnets — over-collection multiplies harm and violates data-protection principles that coexist with KYC obligations.
Q93How do KYC and data protection interact on identity data?▾
AML provides the lawful basis for collecting and retaining identity data, but proportionality, security, access rights, and retention limits still apply — with carve-outs protecting investigation confidentiality. The practical discipline: documented purposes, controlled access, defined retention, and legal review where the frameworks tension.
Q94What is an acceptable failure rate philosophy for verification?▾
Zero fraud admitted means zero customers onboarded — the honest framing is risk appetite: what false-acceptance rate is tolerable at what customer value, backed by monitoring that catches what onboarding misses. Verification is a filter in a system, not a wall.
Q95A customer's selfie fails liveness three times. Likely causes and your handling?▾
Genuine causes dominate: poor lighting, old devices, glasses, accessibility needs — so first offer guided retry and an alternative channel (video call, branch). Persist fraud signals — injection indicators, device anomalies — then route to specialist review. Handling separates inclusive service from naive acceptance.
Q96What is the difference between verifying an individual and verifying an authorised signatory?▾
The signatory is verified as an individual and their authority is verified against the entity: board resolutions, mandates, powers of attorney. Two questions — are you who you claim, and does the entity actually empower you — each with its own evidence.
Q97How do you verify a customer you never meet, at scale, defensibly?▾
Layered digital assurance: document authenticity checks, NFC where available, biometric match with passive liveness, database corroboration, device and network intelligence, and initial funding from an account in the customer's own name — with every layer logged. Defensibility is the audit trail as much as the checks.
Q98What is a politically exposed document — powers of attorney — risk in verification?▾
PoAs let third parties act on accounts, so forged or overbroad PoAs are an account-takeover vector. Verify the instrument's authenticity, scope, and currency; verify the attorney's identity fully; and flag PoA-operated accounts for monitoring attention, especially with elderly or absent principals.
Q99What is the FATF stance on digital identity?▾
Supportive with conditions: its digital-identity guidance accepts digital ID systems for CDD where assurance levels are appropriate to risk, urging institutions to understand each system's proofing and authentication strength. Technology-neutral outcomes, not paper nostalgia — reliability is the test.
Q100What onboarding data should be captured 'as evidence' versus 'as data'?▾
Evidence: document images, biometric artefacts, verification results — immutable, timestamped, retention-managed. Data: the extracted attributes powering screening and risk models — structured, correctable, quality-controlled. Confusing the two produces either unauditable files or screening running on frozen mistakes.
Q101What would you check before approving a corporate signatory added mid-relationship?▾
Identity verification of the new individual, authority evidence (resolution or mandate), screening against sanctions and PEP data, plausibility of the change against the customer's profile, and whether the addition pattern itself signals control change — new signatories are how takeovers and mule conversions often arrive.
Q102What's your approach when verification tools disagree — document passes, database fails?▾
Treat disagreement as signal: identify what each source actually tested, seek a tie-breaker (alternative database, fresh biometric, issuer validation), and weight source reliability for this geography. Document the resolution. Picking the convenient result and moving on is how impersonation gets approved.
Q103How does verification differ for minors or vulnerable customers?▾
Documents differ (birth certificates, guardian IDs), consent and mandate rules apply, and product restrictions limit risk. The guardian is verified as an individual plus their authority over the account. Vulnerability also raises exploitation vigilance — accounts operated 'for' someone are takeover-adjacent.
Q104Sum up: what makes identity verification 'strong' in one sentence?▾
Multiple independent layers — document, biometric, database, device — each logged, tuned to the risk of the customer and moment, with expert handling of the edge cases automation can't decide.
Q105What is optical character recognition (OCR) risk in document processing?▾
OCR extracts document text into data — and its errors become the file: a misread digit corrupts the DOB that screening and matching depend on. Controls: confidence thresholds routing low-quality reads to human keying, MRZ cross-validation, and field-level sanity checks before data enters the profile.
CDD & Customer Risk Rating
Q106What does customer due diligence (CDD) formally require?▾
Four things in most regimes: identify and verify the customer; identify and take reasonable measures to verify beneficial owners; understand the purpose and intended nature of the relationship; and conduct ongoing monitoring of the relationship and its transactions against that knowledge.
Q107Walk me through standard CDD for a new individual customer.▾
Collect identity data and verify against documents or databases; screen for sanctions, PEP status, and adverse media; capture occupation, source of funds, and expected account usage; assess risk factors — geography, products, profile; assign the risk rating; and record everything with the approvals policy requires.
Q108Walk me through standard CDD for a new corporate customer.▾
Verify legal existence via registry and formation documents; map ownership to the beneficial owners and verify them; identify directors and authorised parties; understand the business model, purpose of account, and expected activity; screen all parties; assess jurisdiction, industry, and structure risk; rate, approve, and baseline for monitoring.
Q109What drives a customer risk rating — walk through the factor categories.▾
Customer factors: type, occupation or industry, PEP status, adverse media. Geographic factors: residence, nationality, operating countries, transaction corridors. Product and service factors: cash intensity, cross-border reach, private banking, trade finance. Channel factors: face-to-face versus remote, intermediated relationships. Behaviour joins after onboarding.
Q110How do risk models typically combine factors into a rating?▾
Weighted scoring: each factor contributes points by severity, summed against thresholds for low, medium, and high — with overrides forcing outcomes regardless of score (sanctions nexus, foreign PEP status, prohibited industries). The model must be documented, validated, and recalibrated as the book and typologies evolve.
Q111What is a risk-rating override and its governance?▾
A manual adjustment above or below the model outcome — justified by information the model can't see. Governance: documented rationale, senior approval, tracking of override rates by user and direction, and periodic review. Widespread downward overrides are a classic examination finding.
Q112What is the consequence of a rating being wrong in each direction?▾
Rated too low: under-monitoring, missed reviews, and real risk running unwatched — the dangerous error. Rated too high: wasted EDD effort, review burden, and friction pushing good customers away — the expensive error. Model tuning is the discipline of pricing both mistakes honestly.
Q113How often should customer risk be reassessed?▾
At every periodic review — commonly annual for high risk, every two-to-three years for medium, up to five for low — and immediately on trigger events: ownership changes, adverse media, behavioural shifts, screening hits. The rating is a living output, not an onboarding artefact.
Q114What is the purpose of expected transaction profiling in CDD?▾
It quantifies the relationship's intended shape — monthly volumes, typical values, counterparty types, corridors — creating the yardstick monitoring measures against. Good profiles are specific and evidenced (contracts, financials); 'general business transactions' as an expected profile is a monitoring blindfold.
Q115What sources verify a business's declared activity?▾
Registry filings and financial statements, tax records, website and digital footprint, licences for regulated activities, supplier and customer references, site visits for higher risk, and sector benchmarks testing whether declared turnover is plausible for the size and model described.
Q116A company declares consulting revenue of $5M with two employees. CDD response?▾
Test plausibility: what consulting, for whom, at what rates? Request contracts and invoices, check the principals' background supports the expertise claimed, and compare sector norms. High revenue-per-head isn't impossible — but unevidenced, it's the classic front-company shape and warrants EDD or decline.
Q117What is industry risk and how is it applied?▾
Sectors carry inherent exposure: money services, gambling, crypto, precious metals, cash-intensive retail, defence, adult entertainment. Policy maps industries to risk weights and appetite outcomes — standard, enhanced, restricted, prohibited — applied at onboarding and revisited when customers pivot activities.
Q118What is channel or delivery risk?▾
How the relationship is acquired and operated: non-face-to-face onboarding, intermediated or introduced business, and third-party-operated accounts all reduce direct knowledge and raise impersonation or layering risk. Channel risk feeds the rating and dictates compensating controls like enhanced verification.
Q119What is product risk in CDD?▾
Products differ in abuse potential: cash services, international wires, correspondent accounts, trade finance, private banking, and crypto on-ramps outrank basic savings. The customer's product mix feeds the rating, and adding high-risk products mid-relationship is an event trigger, not a formality.
Q120How does CDD treat occasional transactions versus relationships?▾
Thresholds pull one-off transactions into CDD — classically around USD/EUR 15,000, lower for wires and designated sectors — requiring identification, verification, and purpose understanding even without an account. Suspicion triggers CDD regardless of amount. Records are kept as for customers.
Q121What is the difference between static and behavioural risk factors?▾
Static factors are declared attributes — industry, geography, structure — known at onboarding. Behavioural factors emerge from actual usage: velocity, corridors, cash intensity, counterparties. Mature models blend both, letting observed behaviour confirm or contradict the declared profile continuously.
Q122What is a customer risk assessment versus the enterprise risk assessment?▾
Customer risk assessment rates one relationship; the enterprise-wide assessment aggregates exposure across the whole institution — customer segments, products, geographies, channels — driving programme design and resourcing. The customer model should visibly derive from the enterprise view, not float independently.
Q123What does 'reasonable measures' mean for verifying beneficial owners?▾
Effort proportionate to risk: registry and document verification as standard, escalating to independent corroboration, structure analysis, and direct evidence for higher risk. The phrase acknowledges perfect verification isn't always possible — but requires documented, genuine attempts, not a checkbox that ownership was 'asked about'.
Q124When can you open an account before completing verification?▾
Some regimes permit limited account opening with verification completed 'as soon as reasonably practicable' — with controls: no or restricted transactions until complete, hard deadlines, and closure if verification fails. Policy defines the window; letting incomplete files transact normally is a standard enforcement finding.
Q125What is CDD's role in the fight against terrorist financing specifically?▾
TF funds can be clean-sourced, so CDD's contribution is network and destination knowledge: who the customer is connected to, where money flows, and whether patterns fit declared purposes. Screening against designated persons and attention to high-risk corridors and NPO contexts carry the TF weight.
Q126What triggers mandatory CDD refresh in most policies?▾
Periodic review dates by risk tier; trigger events — ownership, control, or activity changes, adverse media, screening deltas; product escalations; dormancy reactivation; and regulatory or law-enforcement contact. The principle: any change that could invalidate the current risk understanding.
Q127What is a risk-rating model validation?▾
Independent testing that the model works: factor weights against outcome data, distribution analysis (is everything conveniently 'medium'?), override patterns, benchmark against peer approaches, and back-testing whether high-rated customers actually generated more confirmed risk. Models are controls — validated like any other.
Q128What distribution across low/medium/high should a healthy book show?▾
No universal number — but red flags exist: 95% low-risk suggests factor weights dodging work; a tiny high-risk bucket at a firm banking crypto and MSBs suggests the model ignores reality. The distribution must be explainable from the business model, and examiners will ask.
Q129How do you handle a customer who refuses to provide CDD information?▾
Regulations are direct: if CDD cannot be completed, do not open the account, do not perform the transaction, terminate the relationship where it exists — and consider whether the refusal itself is suspicious enough to report. Refusal handling is documented, not negotiated indefinitely.
Q130What is the interaction between CDD and credit or fraud checks?▾
They share data and increasingly signals: bureau checks corroborate identity, credit behaviour informs plausibility, fraud markers feed risk ratings. But purposes differ legally — consent and use limitations apply — so programmes integrate carefully, sharing what law permits through governed channels.
Q131What is a customer's 'economic profile' and its CDD use?▾
The financial shape of the customer: income or revenue, wealth, obligations, and realistic transactional capacity. It grounds plausibility testing — can a declared salary support these flows, can this business generate this turnover — turning CDD from document collection into sense-making.
Q132What is name-value in CDD — why do exact legal names matter?▾
Screening, registry checks, and legal enforceability all key on exact legal names; trading names and abbreviations break matching and hide connections. CDD captures the legal name precisely, maps trading names as aliases, and keeps them distinct fields — casual naming is a data-quality failure with screening consequences.
Q133How do you conduct CDD on a start-up with no track record?▾
Shift weight to the people and the plan: founders' backgrounds and source of wealth, funding evidence (investment agreements), business model plausibility, and licences where relevant. Set conservative expected activity with early review dates, letting the profile mature on evidence rather than optimism.
Q134What is a bank reference or professional reference worth in CDD?▾
Corroboration, not verification: a reference confirms a relationship existed and behaved acceptably — useful context, especially cross-border — but transfers no accountability and proves no identity. Weight it as one independent-ish signal, verified for authenticity itself.
Q135What CDD applies when a customer is acquired through a merger?▾
Acquired customers are your customers: risk-assess the inherited book, prioritise remediation by risk, apply your standards on review cycles, and interim-control the unremediated tail. 'The previous bank did KYC' has never satisfied an examiner — due diligence obligations transfer with the relationship.
Q136What is the CDD treatment of clubs, associations, and unincorporated bodies?▾
Identify the body through its constitution or rules, verify the individuals who control it — officers, committee members, signatories — understand funding sources and purpose, and screen the controllers. Informal structure raises documentation judgement, not a due-diligence exemption.
Q137What does 'ongoing monitoring' mean inside the CDD obligation?▾
Two duties: scrutinising transactions against the customer's profile and expected activity, and keeping CDD information current. It converts onboarding knowledge into a living control — the regulatory language makes monitoring part of due diligence itself, not a separate optional system.
Q138What is a trigger review's minimum content?▾
Confirm what changed and its reliability; refresh affected data — ownership, activity, screening; reassess the risk rating with rationale; decide consequences — EDD, restrictions, exit, or filing; and record the decision trail. A trigger review that only notes 'reviewed, no change' after a material event is a finding.
Q139How should CDD treat customers operating in multiple jurisdictions?▾
Aggregate the geographic exposure: every operating country contributes risk, weighted by activity share and corridor patterns. Verify licences per jurisdiction where relevant, expect multi-country counterparties in the profile, and rate on the composite — a Dubai-Singapore-Lagos trading footprint is one risk picture, not three.
Q140What is the difference between KYC data and KYC documents?▾
Data: structured attributes — names, dates, identifiers — powering screening, matching, and models. Documents: the evidence behind the data. Both are required and governed differently: data needs quality controls and correction workflows; documents need authenticity, retention, and retrieval. Programmes fail when they collect documents but never structure data.
Q141What is periodic review 'right-sizing'?▾
Matching review depth to risk and change signals: full re-papering for high-risk or changed customers, attestation-plus-verification for stable medium, data-confirmation for clean low-risk. Uniform maximal reviews waste capacity; uniform minimal reviews rot the book — right-sizing is documented proportionality.
Q142What questions does a reviewer ask of your completed CDD file?▾
Can I see who this customer is and prove it? Do I know who owns and controls them? Does the declared purpose match the products and observed activity? Was screening done and dispositioned? Does the rating follow from the facts? And can I trace every decision to a person, date, and rationale?
Q143What is customer outreach etiquette during CDD refresh?▾
Neutral, professional, deadline-clear: explain updates are standard regulatory practice, request specific items with formats, offer channels, and escalate through relationship owners before restrictions. Never hint at investigations. Outreach tone determines completion rates — and careless wording risks tipping off where cases exist.
Q144How does CDD handle a customer with legitimate privacy concerns?▾
Acknowledge and hold the line: explain the legal basis, data-protection safeguards, and confidentiality of files; offer secure submission channels; distinguish negotiable format issues from non-negotiable requirements. Respectful firmness — the obligation isn't waivable, but the experience can be professional.
Q145What metrics indicate a healthy CDD operation?▾
Onboarding cycle times by segment, first-pass completion rates, review currency (percentage overdue), trigger-review responsiveness, QA quality scores, override rates, exit follow-through, and downstream indicators — how often monitoring finds the profile wrong. Volume metrics alone say nothing about truth.
Q146What is the relationship between CDD quality and SAR quality?▾
Direct: SAR narratives contrast activity against the expected profile — a vague profile produces a vague suspicion. Investigators inherit CDD's work: verified identities, mapped ownership, and specific expected activity turn alerts into cases; empty files turn alerts into guesswork.
Q147A profitable customer's CDD refresh is overdue and they're unresponsive. Pressure says renew quietly. You?▾
Policy governs: escalate through the outreach ladder, apply the restriction stages policy defines, and document the commercial pressure separately. Quiet renewal without refreshed CDD is falsifying the control — the finding that turns an overdue review into misconduct.
Q148What is 'know your employee' and its CDD adjacency?▾
Screening and vetting staff — identity, background, sanctions, conflicts — because insiders enable the worst failures: file falsification, override abuse, tipping off. It parallels CDD logic applied inward and is increasingly a regulatory expectation within financial-crime frameworks.
Q149How would you design CDD for a digital-only bank from scratch?▾
Digital identity verification with biometrics and NFC document checks; database corroboration; risk-tiered onboarding with limits scaling to assurance; structured data capture from the start; behavioural profiling feeding perpetual KYC; and staffed exception handling for edge cases. Born-digital means audit trails by default — design them in.
Q150What is the single most underrated CDD data point in your view?▾
Occupation and business description, captured specifically. It anchors plausibility for everything downstream — expected activity, monitoring context, alert dispositions — yet books are full of 'business owner' and 'consultant'. Specific occupations turn monitoring from mathematics into meaning.
Q151What is the CDD lesson from major recent enforcement actions?▾
Files existed; knowledge didn't. Institutions held documents while missing ownership realities, tolerated vague profiles for profitable clients, and let reviews rubber-stamp. The consistent lesson: regulators now test whether CDD produced genuine understanding that controls acted on — paper compliance is discoverable and punished.
Q152How do you keep CDD proportionate for small, obviously low-risk customers?▾
Use the simplifications regulation permits: streamlined verification, longer review cycles, data-confirmation reviews — documented as risk-based decisions. Proportionality is a feature of mature programmes; drowning low-risk customers in EDD-grade demands signals a model problem, not diligence.
Q153What is 'customer lifecycle management' as the modern framing of CDD?▾
Treating onboarding, monitoring, reviews, screening, and exit as one continuous data-driven process rather than siloed events — one profile, updated by triggers and behaviour, with controls consuming it in real time. Perpetual KYC is this framing operationalised.
Q154Sum up CDD in two sentences for an interviewer.▾
CDD is establishing who the customer is, who ultimately owns them, and what their normal looks like — then keeping that knowledge true for the life of the relationship. Everything else in AML stands on it: monitoring, ratings, reporting, and exits are only as good as the due diligence beneath them.
Q155What is a prohibited customer list and how does it differ from risk appetite restrictions?▾
Prohibited means never, regardless of controls — shell banks, sanctioned parties, anonymous instruments, sectors the board bans outright. Restricted means acceptable with conditions: EDD, senior approval, exposure caps. Onboarding systems should hard-stop prohibitions and route restrictions to approval — conflating the two creates both illegal accounts and needless declines.
EDD, PEPs & High-Risk Customers
Q156What is enhanced due diligence and when does it apply?▾
EDD is the deeper due-diligence package for elevated risk: senior approval, source of wealth and funds corroboration, extended verification, tighter activity definition, and intensified monitoring. It applies mandatorily to foreign PEPs, correspondent banking, and FATF high-risk jurisdictions, and by policy wherever the risk model or judgement demands.
Q157List concrete EDD measures beyond standard CDD.▾
Independent corroboration of source of wealth and funds; deeper beneficial-ownership verification with structure analysis; adverse-media deep-dives beyond automated screening; senior or committee approval; site visits or management meetings; more specific expected-activity profiling; shortened review cycles; and elevated monitoring thresholds or dedicated scenarios.
Q158Who qualifies as a PEP?▾
Individuals entrusted with prominent public functions: heads of state and government, senior politicians and party officials, senior judiciary and military, central bankers, ambassadors, and senior executives of state-owned enterprises — plus, under most regimes, their family members and close associates who carry equivalent risk.
Q159What is the difference between foreign, domestic, and international-organisation PEPs?▾
Foreign PEPs hold prominent functions in another country — mandatory EDD under FATF. Domestic PEPs hold them in your own country; international-organisation PEPs hold senior roles at bodies like the UN or IMF — both require risk-based treatment, with EDD where risk is higher. Many institutions apply EDD to all three.
Q160Why do family members and close associates of PEPs matter?▾
They are the classic conduits: corrupt proceeds rarely sit in the official's own name — they sit with spouses, children, siblings, and business partners. Regimes extend PEP treatment to relatives and close associates precisely because the risk travels through them.
Q161How do you determine someone is a 'close associate' of a PEP?▾
Indicators: joint beneficial ownership of entities with the PEP, sole ownership of vehicles known to benefit the PEP, prominent shared business dealings, or public association at a level implying access. It's a judgement call on evidence — screening databases flag candidates; the file documents the reasoning.
Q162A new customer screens as a PEP. Walk through your process.▾
Confirm the match on identifiers — is this actually the same person; classify the PEP type and seniority; apply EDD: source of wealth and funds with corroboration, adverse-media deep-dive, purpose scrutiny; obtain senior management approval; set enhanced monitoring and shortened review; document everything. PEP status means enhanced process, not automatic refusal.
Q163How long does someone remain a PEP after leaving office?▾
No fixed FATF rule — the test is continuing risk: informal influence, the seniority held, corruption indicators, and links to current officials. Many policies set a minimum period (12–24 months) with risk-based extension; senior foreign PEPs are often treated as PEPs indefinitely under 'once a PEP' policies.
Q164What is source of wealth corroboration for a PEP in practice?▾
Building an evidenced narrative of how their wealth arose: declared official salaries versus lifestyle and assets, business interests with documentation, inheritance records, asset declarations where public. The test is proportionality and plausibility — public salary alone rarely explains substantial wealth, and the gap is the risk.
Q165A PEP's declared salary is $80K but they're placing $5M. Handling?▾
The gap demands explanation: legitimate wealth may pre-date office, come from family, or documented business — evidence each claim independently. Unexplained or implausibly explained wealth of a serving official is the textbook laundering-of-corruption profile: escalate, likely decline, and consider reporting obligations.
Q166What are the highest-risk PEP scenarios you'd flag to management?▾
Serving officials from high-corruption jurisdictions with unexplained wealth; PEPs using complex offshore structures without commercial rationale; family members fronting accounts with the official directing; PEPs in extractive-industry approval chains; and any PEP requesting secrecy or third-party intermediation of the relationship.
Q167What makes high-net-worth individuals (HNWIs) a distinct KYC challenge?▾
Wealth complexity: multi-jurisdictional assets, layered holding structures, trusts and foundations, privacy expectations, and intermediaries conducting the relationship. Verification standards stay the same while evidence gets more sophisticated — and commercial pressure to accommodate is strongest exactly where scrutiny matters most.
Q168How do you verify source of wealth for an HNWI whose fortune spans decades?▾
Reconstruct proportionately: career and business history with corroborating records, major liquidity events (sales, IPOs, inheritances) documented, public sources cross-checked. Every dollar won't have a receipt — the standard is a coherent, evidenced narrative where major components are independently supported and red flags are absent.
Q169What is a family office and its due-diligence approach?▾
An entity managing a wealthy family's investments and affairs. Due diligence identifies the family principals as beneficial owners, verifies the office's authority and controllers, maps the structures it operates, and applies HNWI-grade source-of-wealth work on the family — the office is the intermediary, the family is the risk.
Q170What high-risk industries most commonly trigger EDD, and why?▾
Money service businesses (velocity and cash), casinos and gambling (cash conversion), crypto firms (emerging controls), precious metals and stones (portable value), defence (corruption exposure), extractives (PEP adjacency), and cash-intensive retail (commingling). Each pairs a legitimate economy with a laundering-friendly mechanic.
Q171How does EDD differ for a high-risk industry versus a high-risk individual?▾
Industry EDD interrogates the business model and controls: licences, AML programme quality, flow-of-funds mechanics, customer base. Individual EDD interrogates the person: wealth origins, associations, media. Both raise approval levels and monitoring — the evidence targets differ with the risk source.
Q172What is a correspondent banking EDD package?▾
Understanding the respondent's business, customer base, and geographic reach; assessing its AML controls (often via Wolfsberg questionnaires); confirming licensing and regulatory standing; screening ownership and management; prohibiting shell-bank access; clarifying nested and payable-through usage; and senior approval with periodic reassessment.
Q173What is EDD for customers from FATF blacklisted jurisdictions?▾
Mandatory enhanced measures at minimum, escalating to countermeasures as national law implements: deeper verification, source-of-funds evidence per transaction where required, senior approvals, intensive monitoring — and frequently appetite-level restrictions or prohibition, since commercial rationale rarely survives the compliance cost.
Q174What does senior management approval mean in EDD — who and how?▾
Approval by someone with authority over risk acceptance — senior manager, MLRO, or risk committee per policy — given on a documented summary of the risk and mitigants, recorded with name, date, and rationale. Rubber-stamp approvals without visible engagement are a standard examination criticism.
Q175What ongoing monitoring changes for EDD customers?▾
Lower alerting thresholds or dedicated scenarios, more frequent screening refresh, shortened periodic reviews (often annual or better), transaction sampling or pre-approval for the highest tiers, and named ownership — a specific officer accountable for the relationship's risk posture.
Q176What is a high-risk customer register?▾
A live inventory of the institution's elevated-risk relationships — PEPs, correspondents, high-risk industries and jurisdictions — with ratings, approvals, review dates, and owners. It gives governance a portfolio view and examiners a starting sample; institutions that can't produce one reveal they don't manage the tier.
Q177A long-standing customer becomes a PEP (elected to office). What happens?▾
An event trigger, immediately: reclassify, apply EDD retroactively — source of wealth review, enhanced screening, senior approval for continuation — reset monitoring and review cycles, and document the transition. Existing-relationship comfort doesn't survive the status change; the file must be rebuilt to PEP standard.
Q178What is de-marketing versus exiting a high-risk customer?▾
De-marketing restricts: no new products, tightened limits, heightened oversight — managing risk while the relationship continues. Exit terminates. The choice weighs risk severity, mitigant effectiveness, and appetite; both are governed decisions with documentation, and neither substitutes for reporting where suspicion exists.
Q179What is reputational risk in high-risk relationships, distinct from regulatory risk?▾
The institution can be fully compliant and still front-page news: banking a controversial-but-legal industry, a sanctioned oligarch's cousin, a scandal-adjacent PEP. Appetite statements should address reputational tolerance explicitly, because 'we followed the rules' does not answer 'why did you bank them'.
Q180How do you approach adverse media on a high-risk prospect — allegations, not convictions?▾
Weigh source quality, specificity, recency, corroboration, and relevance to financial crime; distinguish investigation from accusation from politically motivated noise; seek the customer's account where appropriate. Allegations can justify decline on risk appetite even where they'd never justify a filing — document the reasoning.
Q181What is a special-category customer needing bespoke EDD you'd highlight?▾
Arms and defence intermediaries: legitimate trade exists, but the sector concentrates corruption, sanctions, end-user deception, and PEP proximity. Bespoke EDD covers licences, end-user certificates, broker registrations, and transaction-level scrutiny — a category where standard EDD templates genuinely aren't enough.
Q182What are red flags specific to private banking relationships?▾
Requests for secrecy or hold-mail; structures whose only function is opacity; reluctance to meet or verify wealth; intermediaries shielding the principal; rapid asset movements between booking centres; and pressure to shortcut onboarding for 'important' clients. Private banking concentrates both wealth and the incentives to look away.
Q183What is the role of a site visit in EDD?▾
Ground truth: does the declared business physically exist at the scale claimed — premises, staff, activity? Visits (or credible virtual equivalents) expose front companies that paper perfectly. Findings are documented with photos and observations; a visit that contradicts the file is decisive evidence.
Q184How does EDD interact with the customer's experience — managing intrusive requests?▾
Frame professionally: enhanced requirements are regulatory standards for the relationship type, not personal accusations; sequence requests, explain purposes, offer secure channels, and keep senior relationship involvement. The craft is obtaining decisive evidence while preserving a bankable relationship — where the customer is legitimate, both are achievable.
Q185What is 'once a PEP, always a PEP' and do you agree with it?▾
A conservative policy treating former officials as PEPs indefinitely. As blanket policy it over-treats minor domestic figures; as applied to senior foreign PEPs it reflects reality — influence and corruption exposure outlast office. My position: risk-based declassification with a strong presumption of retention for senior figures.
Q186What screening cadence applies to PEP and high-risk customers?▾
Continuous or daily list-based re-screening as databases update, adverse-media monitoring at elevated frequency, and full re-screening at each review and trigger. The gap between a status change and your awareness of it is unmanaged risk — cadence is the control that shrinks it.
Q187How do you document a decision to onboard despite elevated risk?▾
A risk-acceptance record: the risks identified specifically, the EDD performed, mitigants applied (limits, monitoring, review cadence), the business rationale, and the named senior approver with date. Written so a regulator reading it concludes the institution understood and consciously accepted — not overlooked — the risk.
Q188What is the difference between EDD depth and EDD theatre?▾
Depth changes decisions: corroborated wealth narratives, verified structures, monitoring that actually tightens. Theatre accumulates paper: longer forms, repeated documents, approvals without reading. Examiners distinguish them by outcomes — did EDD ever change a rating, restrict a relationship, or trigger an exit?
Q189What high-risk customer type do institutions most commonly mis-handle, in your view?▾
Domestic PEPs: treated as low-risk by default because they're familiar, while local corruption exposure is precisely where the institution has the most to lose. Risk-based treatment should reflect actual corruption indicators and seniority, not the comfort of proximity.
Q190What is a PEP declassification process?▾
A documented review concluding PEP risk has lapsed: time out of office, seniority held, continuing influence, jurisdiction corruption context, and any adverse indicators — with senior approval and rationale recorded. Automatic expiry without analysis is the weak version; silent indefinite retention without review is the wasteful one.
Q191How do trusts and foundations complicate EDD on wealthy individuals?▾
They separate legal control from benefit: the wealth sits in structures where the individual may be settlor, protector, or discretionary beneficiary — visible only through deeds and letters of wishes. EDD maps every role, obtains the instruments, and identifies who actually directs and benefits, whatever the paperwork's surface says.
Q192What is an intermediated HNWI relationship's core risk?▾
You know the adviser, not the principal: lawyers, wealth managers, and family offices conduct the relationship while the beneficial owner stays distant. Controls: direct verification of the principal regardless of intermediation, clarity on whose instructions bind, and scepticism where intermediaries resist principal contact.
Q193What EDD applies to luxury-asset-heavy wealth (art, yachts, property)?▾
Asset-level corroboration: provenance and purchase records, valuations, ownership structures per asset, and consistency with the wealth narrative. Luxury assets are integration vehicles — EDD tests whether they were bought with evidenced wealth or constitute the laundering itself.
Q194What monitoring scenario would you design specifically for PEP accounts?▾
Government-adjacent flow detection: payments to or from state entities, contractors, or licensing bodies; round-amount transfers to family-linked accounts; offshore structure funding; and lifestyle-inconsistent activity spikes around political events (elections, budget cycles). PEP risk is corruption-shaped — the scenarios should be too.
Q195A PEP relationship is approved, then the PEP is charged with corruption. Sequence your response.▾
Immediate trigger review: freeze consideration per legal advice, screening and media assessment, transaction lookback for related flows, filing evaluation on what the institution processed, senior governance decision on restriction or exit, and regulator liaison where required. Speed, documentation, and legal involvement define whether the institution is a witness or a subject.
Q196What is the interaction between PEP controls and financial inclusion concerns?▾
Blanket PEP fear excludes legitimate officials, their families, and whole political classes in developing markets from banking. FATF is explicit: PEP measures are preventive, not prohibitive. The mature posture is genuine EDD with genuine acceptance where evidence supports it — controls as filters, not walls.
Q197What would make you recommend declining a high-risk relationship despite complete EDD paperwork?▾
When the economics don't cohere: wealth narratives that technically document but don't convince, structures whose only function is opacity, activity purposes that make no commercial sense, or a pattern of near-miss red flags. Complete paper with incoherent substance is the profile of professional concealment — appetite exists to decline it.
Q198How do you keep EDD files for high-profile customers confidential internally?▾
Restricted system access on named-case basis, no discussion outside case channels, sanitized references in workflow tools, secure document storage, and audit trails on file access. High-profile files attract curiosity — access logs protect both the customer and the institution's integrity.
Q199What is the cost-benefit reality of high-risk customers institutions should be honest about?▾
EDD, monitoring, reviews, and capital of senior attention are real costs; revenue must justify them after risk-adjusting for the enforcement and reputational tail. Books carry high-risk relationships whose economics never made sense — honest portfolio review exits them before an examiner asks why they exist.
Q200What EDD lesson do the big laundromat cases teach?▾
Volume plus vagueness: non-resident high-risk customers with template wealth stories, structures nobody mapped, and EDD that existed as forms while billions flowed. The lesson — EDD must scale scrutiny with exposure, and a high-risk book growing faster than its due-diligence capacity is the alarm itself.
Q201What is your personal test for whether EDD is 'done' on a file?▾
Could I defend this relationship to a sceptical regulator in one meeting: who they are, where the wealth came from with evidence, why the structure exists, what we watch for, and who approved it — without a single 'we assumed'. If any answer starts with an assumption, EDD isn't done.
Q202How should EDD evolve with perpetual KYC?▾
From periodic deep-dives to continuous elevated attention: real-time screening deltas, media monitoring, behavioural drift detection, and micro-reviews on triggers — with the annual deep review validating the stream rather than discovering a year's surprises. High-risk is exactly where event-driven beats calendar-driven.
Q203What's the difference between high-risk appetite at a global bank versus a fintech?▾
Global banks carry correspondent exposure, dollar-clearing nexus, and examiner history — conservative appetites with heavy EDD machinery. Fintechs trade agility for thinner second lines: appetite should be narrower, not wider, because capacity to manage high-risk depth is smaller. Appetite must match machinery, not ambition.
Q204Give a 30-second model answer: 'How would you handle a PEP wanting rapid onboarding?'▾
I'd explain enhanced requirements apply and expedite the process, not the standard: parallel-track verification, prioritised screening and wealth corroboration, and fast senior approval scheduling. What I won't compress is the evidence itself. Most legitimate PEPs accept professional urgency; resistance to the standard — rather than the speed — is itself a signal.
Q205What single control most protects an institution in the high-risk tier?▾
Named senior ownership per relationship: one accountable officer who approved it, reviews it, and answers for it. Diffused responsibility is how high-risk books rot; a name on the file changes behaviour more reliably than any system.
Q206What is a state-owned enterprise (SOE) executive's PEP status?▾
Senior SOE executives are PEPs under FATF's definition — they control public assets and procurement. Due diligence maps the enterprise's governance, the executive's authority, and payment flows between the SOE, the individual, and connected parties; SOE-adjacent corruption is a dominant grand-corruption typology.
Q207What EDD applies to crowdfunding platforms or high-risk fintech customers?▾
Programme-level diligence: their onboarding and monitoring controls, flow-of-funds mechanics, customer-base composition, licensing, and fraud rates — plus standard ownership and principal checks. You are effectively assessing a mini financial institution; their control quality is your risk.
Q208How do gatekeeper professionals (lawyers, TCSPs) feature in high-risk KYC?▾
Both as customers and as risk multipliers: client-account structures obscure end parties, and trust-and-company service providers manufacture the vehicles concealment uses. Diligence covers their AML obligations and supervision, client-account mechanics, and willingness to identify underlying clients on request.
Q209What is 'lifestyle inconsistency' as an EDD signal?▾
Observable spending and assets outpacing documented wealth: property, vehicles, travel patterns visible in transactions or media that the file's wealth narrative cannot fund. It is the practical trigger behind many corruption investigations — and a legitimate EDD question when the gap is material.
Q210What approval and review cadence would you set for the highest-risk tier?▾
Committee-level approval with documented risk acceptance; annual full review as a ceiling, semi-annual where warranted; continuous screening and media monitoring; quarterly relationship-owner attestations; and defined behavioural triggers for immediate re-review. The cadence itself should be board-visible for the top tier.
Beneficial Ownership & Structures
Q211Define beneficial owner precisely.▾
The natural person who ultimately owns or controls a customer — through shareholding or voting rights (commonly above 25%), through control by other means, or on whose behalf a transaction or relationship is conducted. Always a human: the definition exists to look through every layer of legal structure.
Q212Why is beneficial ownership the centre of modern KYC reform?▾
Because anonymity through entities is the enabling technology of financial crime: shells, nominees, and layered structures let criminals act while no human appears on any record. Registries, ownership thresholds, and control tests all attack the same problem — reconnecting entities to the people behind them.
Q213Walk through identifying UBOs in a three-layer corporate structure.▾
Start at the customer: obtain its shareholder register; for each corporate shareholder above threshold, obtain their register; repeat upward until reaching natural persons or a listed/regulated terminus. Multiply percentages through the chain, evidence each layer with registry or certified documents, chart it, and screen every UBO identified.
Q214How do you calculate indirect ownership percentages?▾
Multiply through the chain: a person owning 60% of Company A, which owns 50% of the customer, holds 30% indirectly — a UBO at a 25% threshold. Aggregate multiple paths: parallel routes summing past the threshold qualify even where each alone would not.
Q215What if no individual meets the 25% threshold?▾
First test control by other means: appointment rights, veto powers, agreements, family blocs acting in concert. If genuinely no one qualifies, regulations typically default to identifying senior managing officials — documenting the analysis that led there. The default is a conclusion you evidence, not a shortcut you take.
Q216What is 'control through other means' — give concrete examples.▾
Power without threshold shareholding: the right to appoint or remove a majority of the board; veto over major decisions; shareholder agreements concentrating decisions; economic arrangements like convertible instruments or dominant creditor positions; family members' combined holdings directed by one person; or plain de facto direction everyone follows.
Q217What documents evidence an ownership layer?▾
Shareholder registers, share certificates, registry extracts, formation documents, and audited accounts noting ownership — plus trust deeds and partnership agreements for non-corporate layers. Each layer needs its own evidence; a customer-signed structure chart asserts, registry documents verify.
Q218What is a structure chart and what makes a good one?▾
A diagram of the ownership and control chain from customer to UBOs: every entity with jurisdiction and ownership percentage, every natural person with role, and control mechanisms noted. A good one lets a reviewer grasp the structure in seconds and spot gaps, circularity, or high-risk jurisdictions instantly.
Q219What structural features raise immediate concern?▾
Layers without commercial purpose; secrecy-jurisdiction chains (each layer in a different opaque locale); circular ownership; bearer-share history; nominee directors and shareholders recurring across entities; recent restructuring before onboarding; and complexity wildly disproportionate to the business's size or nature.
Q220What is a nominee shareholder arrangement and its KYC treatment?▾
Shares held in one name for another's benefit, under declaration of trust or agreement. Treatment: identify the nominator as the true owner, obtain the nominee agreement, and ask why the arrangement exists — legitimate uses exist (administrative convenience, listing mechanics), but undisclosed nomineeship is concealment by definition.
Q221What is a bearer share and the modern regulatory response?▾
A share owned by whoever physically holds the certificate — ownership transferable invisibly, the perfect anonymity instrument. Most jurisdictions have abolished or immobilised them; KYC response to entities with bearer capability: evidence of immobilisation or conversion, or decline. There is rarely an acceptable rationale.
Q222How do you verify beneficial ownership against registries — and their limits?▾
Cross-check declared UBOs against government registers where they exist. Limits: self-reported data, patchy verification by registrars, stale records, and jurisdictions without registers. Registries corroborate; they don't conclude — high-risk files need document-level verification regardless of a register match.
Q223What is a trust's ownership analysis — who do you identify?▾
No shareholders to trace; instead identify the parties in control and benefit: settlor (who provided assets), trustees (who legally control), protector (who oversees trustees), beneficiaries or classes (who benefit), and anyone else exercising effective control — evidenced through the trust deed and related instruments.
Q224What is a discretionary trust's specific challenge?▾
Beneficiaries hold no fixed entitlement — the trustee decides distributions, often guided by a private letter of wishes. The named class may hide the true intended beneficiary. KYC obtains the deed and letter of wishes where possible, identifies the class, and monitors distributions against it.
Q225What is a protector and why do they matter?▾
A person appointed to oversee trustees — often holding removal and veto powers. Protectors matter because control frequently lives there: a settlor 'giving away' assets while remaining protector may retain effective command. Identify, verify, and screen protectors as controllers.
Q226What is a foundation and how does its ownership work?▾
A civil-law vehicle with legal personality but no shareholders — governed by a council under its charter for stated purposes or beneficiaries. Ownership analysis identifies founders, council members, guardians, and beneficiaries: functionally trust-like questions asked of an entity-shaped structure.
Q227How do partnerships map to beneficial ownership?▾
Identify partners with significant capital or profit shares (thresholds mirror corporate rules) and those controlling management — general partners in limited partnerships regardless of percentage. Limited partnerships layering funds require looking through the GP structure to its own controllers.
Q228What is a general partner (GP) / limited partner (LP) structure's KYC shape?▾
LPs provide capital with limited rights; the GP controls everything. KYC identifies the GP's own ownership chain to natural persons (the effective controllers), assesses major LPs per policy thresholds, and understands the fund's strategy and investor base — control and capital analysed separately.
Q229What is an orphan structure (e.g., charitable-trust-owned SPV)?▾
An entity deliberately owned by no one — shares held by a purpose trust or foundation so no UBO exists on paper. Legitimate in securitisation, but also a concealment pattern. KYC identifies controllers instead: directors, deed powers, and whoever economically benefits from the structure's operation.
Q230How do listed companies simplify — and complicate — ownership analysis?▾
Listing on a recognised exchange with disclosure standards usually exempts tracing beyond the listed level — simplified treatment. Complications: subsidiaries claiming a parent's listing (verify the chain to the listed entity), minor exchanges without real disclosure, and majority-controlled listcos where a dominant owner still warrants identification.
Q231What is a 'regulated institution' terminus in ownership tracing?▾
Chains ending at a bank or regulated financial institution in an equivalent jurisdiction can often stop there — its own regulator supervises its ownership. Verify the regulated status genuinely exists and the jurisdiction qualifies; 'regulated' in a nameplate jurisdiction terminates nothing.
Q232What ownership questions apply to state-owned enterprises?▾
The state is the owner — the analysis shifts to control and extraction risk: which ministry or body exercises rights, who are the appointed executives (PEPs by definition at senior level), what autonomy exists, and where revenues flow. SOE opacity plus PEP control is a corruption-typology intersection.
Q233What is circular ownership and why is it a red flag?▾
Entities owning each other — A holds B, B holds C, C holds A — making ownership mathematically terminate nowhere. It has almost no legitimate rationale and functions to defeat tracing. Response: identify who controls the loop in practice, and treat the structure itself as a concealment indicator.
Q234What is the difference between legal ownership and beneficial ownership?▾
Legal ownership is whose name is on the register; beneficial ownership is who truly enjoys and controls. Nominees, trustees, and custodians hold legally for others' benefit. KYC's entire ownership discipline exists because the two diverge — and crime lives in the gap.
Q235What is a declaration of trust's significance in ownership files?▾
The instrument converting apparent ownership into nomineeship: X declares they hold shares for Y. Finding one reverses the register's story — Y is the owner. KYC obtains and verifies declarations where nominee arrangements are disclosed, and treats undisclosed ones discovered later as serious red flags.
Q236How do you handle ownership data conflicting between sources?▾
Weight by reliability and recency: certified registers and filings over customer assertions, recent over stale; seek a tie-breaker (fresh registry extract, auditor confirmation); and require the customer to explain discrepancies. Conflicts are findings to resolve on record — unresolved material conflict blocks approval.
Q237What triggers re-verification of ownership mid-relationship?▾
Registry-filed changes, announced transactions, screening or media hits on new names, periodic review cycles, behavioural shifts suggesting new control (new signatories, changed patterns), and law-enforcement or counterparty inquiries. Ownership is the profile element most likely to change silently — triggers substitute for the notification customers forget.
Q238What is the Corporate Transparency Act's practical effect on US KYC?▾
A FinCEN registry of company beneficial owners, giving institutions a verification reference for legal-entity customers — attacking the anonymous-LLC problem at formation. Practical caveats: scope adjustments and litigation have narrowed coverage, and registry data supplements rather than replaces institutional verification.
Q239How do EU beneficial ownership registers differ, and the access controversy?▾
Member states maintain registers under the AML directives; court rulings restricted fully public access on privacy grounds, moving toward legitimate-interest access including obliged entities. For KYC the operational point stands: institutions retain access for CDD, and register data remains corroborative, not conclusive.
Q240What is a shelf company and its ownership risk?▾
A pre-formed aged entity sold ready-made: its incorporation date suggests history it never had, lending false credibility. Ownership risk: the register shows formation agents until sale, and the transfer moment is where the real (possibly concealed) owner enters. Verify current ownership, not corporate age.
Q241What are formation agents / TCSPs in the ownership ecosystem?▾
Trust and company service providers manufacture and administer entities: registered offices, nominee officers, ready structures. Legitimate infrastructure — and the industrial supplier of concealment vehicles, as leak investigations showed. KYC notes TCSP fingerprints (shared addresses, recurring nominees) as structure-risk context.
Q242What does a 'senior managing official' fallback actually require?▾
When no UBO exists by ownership or control, identify and verify the individuals directing the entity — typically the CEO or executive directors — to the same verification standard. Plus documenting why the fallback applies: the analysis of ownership and control that concluded in genuine dispersal.
Q243How do you screen beneficial owners effectively?▾
As structured data, not chart annotations: every UBO's full name, DOB, and nationality entered as screenable records, run against sanctions, PEP, and adverse-media sources at onboarding and continuously. The 50% sanctions rule makes ownership screening a legal necessity — designated owners contaminate unlisted entities.
Q244What is the sanctions 50% rule's ownership analysis burden?▾
Entities majority-owned (individually or aggregate) by designated persons are blocked even when unlisted — so ownership mapping isn't only KYC hygiene, it's sanctions compliance. New designations trigger re-analysis of the book: whose structures does yesterday's designation now contaminate?
Q245A customer restructures ownership two weeks before onboarding. Read?▾
Timing is the signal: restructuring on the eve of due diligence suggests engineering the picture presented — dropping a problematic owner below thresholds, inserting nominees, moving jurisdictions. Obtain the before-and-after, the rationale, and the exiting parties' identities; recent-restructure files warrant EDD-grade scrutiny.
Q246What is fragmentation-below-threshold as an evasion technique?▾
Splitting ownership so no individual crosses the UBO line — five family members at 19% each, controlled by one. Counters: aggregation of connected parties, control-by-other-means analysis, and policy thresholds below the statutory line for high-risk cases. The threshold is a floor for inquiry, not a ceiling.
Q247How do you document an ownership analysis that relied on judgement?▾
Show the reasoning: sources obtained, what each established, where evidence ended and inference began, the conclusion, and the approver. Judgement is legitimate in complex structures — undocumented judgement is indistinguishable from guesswork when the file is examined years later.
Q248What jurisdictional features make ownership tracing hardest?▾
No public registries or access restrictions; nominee cultures with legal protection; bearer instruments' legacy; non-cooperation with information exchange; and layering-friendly formation industries. Chains routing through several such features are designed for opacity — the design itself informs the risk decision.
Q249What is the Panama/Pandora Papers' lesson for ownership KYC?▾
The leaks mapped what files never did: industrial-scale nominee and shell architecture serving PEPs, criminals, and evaders — administered by professional intermediaries banks trusted. Lessons: intermediary assurances aren't verification, structure complexity is itself a risk factor, and adverse-media screening must include leak databases.
Q250How does ownership analysis differ for funds versus operating companies?▾
Funds separate control (GP/manager — trace to its people) from capital (investors — assess per thresholds and look-through policy); strategy and investor-base composition replace business-model analysis. Operating companies concentrate on the ownership chain and controllers of the trading entity itself.
Q251What is investor look-through in fund KYC?▾
Identifying underlying investors above policy thresholds rather than stopping at the fund: required for higher risk or where the fund's own controls are unverified. Balanced against practicality via reliance on the fund's administrator — with the reliance conditions documented and testable.
Q252What ownership assurance can an administrator or auditor letter provide?▾
Corroboration from a professional with actual sight of registers: useful supporting evidence, especially cross-border — never a substitute for primary documents in high-risk files, and always verified as genuinely issued. Weight scales with the professional's independence and regulatory standing.
Q253What is your escalation threshold on ownership opacity?▾
When reasonable measures exhaust without reaching natural persons — or the structure's only coherent purpose is concealment — the file escalates for decline or exit, with suspicion assessment. The regulatory position is blunt: if you cannot establish who you are dealing with, you do not deal.
Q254Chart this: individual holds 30% directly, plus 40% of HoldCo which owns 60% of the customer. UBO?▾
Direct 30% alone already qualifies at a 25% threshold. The indirect path adds 40% × 60% = 24%, totalling 54% — a dominant owner. The exercise shows why aggregation matters: paths individually below threshold combine into control.
Q255What ongoing register-monitoring is now possible and expected?▾
Registry-change feeds and vendor monitoring flag filings — director changes, ownership transfers, address moves — in near real time, feeding perpetual KYC triggers. Where available for your jurisdictions, examiners increasingly expect subscription rather than waiting for periodic review to discover year-old changes.
Q256What single question cuts fastest through a complex structure presentation?▾
'Who decides — and show me the document that gives them that power.' Structures are stories about control; the appointment rights, vetoes, and instruments answer factually what ownership percentages only gesture at. Follow the decision rights and the UBO usually appears.
Q257Why might a legitimate business genuinely need a complex structure?▾
Real reasons exist: tax treaties, joint-venture governance, regulatory ring-fencing, succession planning, liability isolation per asset. The KYC test isn't complexity itself but coherence — does each layer have an articulable function a professional would recognise? Legitimate complexity explains itself readily.
Q258What is the future of beneficial-ownership verification?▾
Interconnected registries with verification duties on registrars, digital identity binding owners to filings, structured data replacing PDF charts, and analytics flagging fragmentation and nominee patterns automatically. Direction of travel: from institutions reconstructing ownership to authorities maintaining it — with institutions verifying against it.
Q259Sum up ownership analysis in one interview-ready sentence.▾
Trace every layer to the humans, evidence every link, test control beyond percentages, screen everyone you find — and when a structure resists explanation, treat the resistance itself as the finding.
Q260What is 'ownership drift' between reviews and its control?▾
Silent change: transfers, dilutions, and control shifts occurring after onboarding that customers rarely volunteer. Controls: registry monitoring feeds, review-cycle re-verification, transaction signals (new dividend destinations, changed signatories), and contractual obligations to notify — with breaches of the notification duty treated as risk events themselves.
Screening: Sanctions, PEP & Media
Q261What are the three screening types in KYC and their different consequences?▾
Sanctions screening: legal prohibitions — true matches mean freezing and reporting, no discretion. PEP screening: risk data — true matches trigger EDD and approval, not refusal. Adverse-media screening: intelligence — matches inform judgement on ratings and appetite. One workflow platform, three entirely different decision logics.
Q262When does screening happen across the customer lifecycle?▾
At onboarding before approval; continuously or daily as lists and databases update; at every periodic and trigger review; when new connected parties join (owners, directors, signatories); and in-flight on payments. Screening is a stream, not an event — the gaps between screenings are unmanaged exposure.
Q263Who gets screened on a corporate relationship?▾
The entity, its beneficial owners, directors and officers, authorised signatories, and often key intermediaries and major counterparties per policy. Screening only the account name is the classic failure — designated persons hide precisely in the connected-party layer.
Q264What is fuzzy matching and why is it necessary?▾
Matching that tolerates variation — spelling, transliteration, word order, initials, phonetics — because names are unstable data and lists can't enumerate every variant. Necessary to catch aliases; costly in false positives. The calibration between miss-risk and noise is screening's core engineering problem.
Q265How do you disposition a potential sanctions match properly?▾
Compare every identifier the listing offers — DOB, nationality, ID numbers, addresses, aliases — against your party data; pull additional data where inconclusive; document the reasoning for a false-positive disposition; escalate anything unresolved or matching for immediate blocking assessment. Name dissimilarity alone never clears a hit with matching identifiers.
Q266What is a false positive versus a false negative in screening, and which is worse?▾
False positive: an alert on a non-match — costs analyst time. False negative: a designated party passing undetected — a strict-liability violation processed. Negatives are catastrophically worse legally; but chronic positive floods cause the fatigue that produces negatives. Managing both is the same tuning discipline.
Q267What identifiers make screening dramatically more accurate?▾
Date of birth above all, then nationality, government ID numbers, and place of birth. A name-only file generates noise forever; capturing secondary identifiers at onboarding is the cheapest screening improvement any institution can make.
Q268What is transliteration risk in screening?▾
Names crossing scripts — Arabic, Cyrillic, Chinese — render into Latin many ways, and lists capture some variants, not all. Engines must apply transliteration algorithms and alias libraries; exact-match screening against one romanisation is structurally blind.
Q269What is delta screening versus full re-screening?▾
Delta: screening the customer base against list changes as they publish — daily additions and amendments. Full: re-running the entire base against entire lists, typically after engine or data changes. Delta is the operational rhythm; full re-screens validate the machinery periodically.
Q270What governance applies to screening list management?▾
Documented list selection tied to your nexus (jurisdictions, currencies, obligations); automated feeds with load verification; version and timestamp logs; testing that updates apply; and clear ownership. 'The vendor manages lists' fails examination — institutions own which lists, how current, and the proof.
Q271What is threshold tuning in a screening engine?▾
Setting the similarity score at which alerts generate: higher thresholds cut noise but risk misses; lower ones flood analysts. Tuning uses test data — seeded true matches, known aliases — segment-specific settings, and documented validation. An untuned engine is either a noise machine or a sieve.
Q272What is screening model validation?▾
Independent effectiveness testing: seeding known designated names and variants to confirm detection, transliteration and alias coverage tests, threshold sensitivity analysis, field-coverage checks (are all name fields screened?), and list-currency verification — documented for governance. Screening is a model; regulators expect model-grade proof.
Q273What is a suppression or good-guy list and its risks?▾
Rules auto-clearing recurring false positives — the same customer matching the same listing repeatedly. Necessary for sanity; dangerous without governance: suppressions must be specific, reviewed periodically, and invalidated when either party's data changes. Unmanaged suppression lists quietly become permanent blind spots.
Q274How does PEP screening data actually get compiled?▾
Vendors aggregate public sources — government sites, gazettes, media — into profiles with positions, dates, and relatives. Coverage and freshness vary by country; classifications differ between vendors. Treat PEP data as fallible intelligence: verify significant matches against primary sources before consequential decisions.
Q275What is a PEP false positive's typical shape and resolution?▾
Common names in populous countries matching senior officials — resolved on DOB, photographs, position timelines, and geography. Resolution documents why this customer is not that person. High PEP noise usually signals thin customer identifiers rather than vendor failure.
Q276What makes adverse-media screening harder than list screening?▾
Unstructured data: articles, not records — identity ambiguity, source quality ranging from investigative journalism to defamation blogs, allegation-versus-conviction distinctions, and recycled syndication inflating apparent volume. Engines pre-filter; the judgement about materiality remains irreducibly human.
Q277How do you assess an adverse-media hit's materiality?▾
Identity certainty first — is it actually your customer; then relevance (financial crime versus unrelated controversy), source credibility and independence, specificity (charges, amounts, dates), corroboration across genuinely separate outlets, recency, and outcome. A conviction in the financial press outweighs twenty scraped allegation reposts.
Q278What is negative-news categorisation in vendor tools?▾
Tagging by risk topic — fraud, laundering, corruption, sanctions, trafficking — letting policies weight categories differently and route alerts appropriately. Useful triage; imperfect classification. Policy should define which categories block, which escalate, and which merely annotate the file.
Q279What screening applies at the payment level versus the customer level?▾
Customer screening runs parties against lists as data changes. Payment screening runs live messages — originators, beneficiaries, banks, free text — pre-execution, catching what customer screening can't: your clean customer paying a designated beneficiary. Both mandatory; different engines, SLAs, and stakes.
Q280What is free-text screening in payments and why does it matter?▾
Scanning unstructured message fields — references, address lines, instructions — where sanctioned names, vessels, and ports hide. Evasion lives in free text precisely because it defeats field-based logic; enforcement history features payments cleared because only structured fields were screened.
Q281What SLA applies to screening alert handling?▾
Sanctions alerts: immediate — payments held until dispositioned, blockings executed same-day, regulatory reports within deadline (commonly ten business days). PEP and media alerts: risk-based but bounded — days, not months. Aging sanction alerts are aging legal violations in waiting.
Q282What is the escalation path for a confirmed sanctions match?▾
Instant hold on transactions and account activity; sanctions team verification; blocking or rejection per the regime; regulatory report within deadline; legal engagement; restricted communications to avoid tipping; and case documentation. The freeze precedes the paperwork — exposure runs by the hour.
Q283How do you screen against the sanctions 50% rule — lists don't contain those entities?▾
Ownership analytics: map customer and counterparty ownership, aggregate designated holdings across chains, and use vendor datasets flagging majority-owned entities. Trigger re-analysis on each new designation. This is where screening becomes investigation — list-matching alone structurally cannot comply.
Q284What is continuous screening's data dependency?▾
It re-screens stored customer data — so stale or thin profiles re-screen their own errors forever. Perpetual screening without profile maintenance is false comfort: the control's ceiling is the data layer's quality, which is why screening programmes now own data-quality metrics.
Q285A customer's director appears on a new sanctions designation overnight. Morning sequence?▾
Delta screening flags it; verify the match on identifiers; assess the entity's exposure — does the director's role or ownership trigger blocking or heightened measures; freeze what law requires; report within deadline; review recent transactions for pre-designation patterns; and document the case with legal input on the entity treatment.
Q286What is over-screening or over-blocking and its costs?▾
Crude rules — geography blankets, hair-trigger thresholds — rejecting lawful business: humanitarian payments refused, common-name customers punished, remittance corridors severed. Costs: customer harm, inclusion damage, and in some regimes legal exposure for wrongful blocking. Precision obligations run both directions.
Q287What are the operational metrics of a healthy screening function?▾
Alert volumes and true-match rates by type; disposition timeliness against SLA; false-positive rates trending with tuning; suppression-list size and review currency; list-update latency; validation test results; and QA scores on disposition quality. The pattern: proof of both detection and discipline.
Q288What is batch versus real-time screening architecture?▾
Batch: scheduled runs over stored records — suits customer-base delta screening. Real-time: in-line message and onboarding checks with millisecond budgets — mandatory for payments and instant decisions. Institutions run both; confusing their guarantees (assuming batch coverage protects live payments) is an architecture failure.
Q289How does screening handle non-Latin-script customer names natively?▾
Best practice: store native-script and romanised names, screen both, and use engines with script-aware matching rather than romanising everything lossily at entry. Institutions serving Chinese, Arabic, or Cyrillic-name populations with Latin-only screening carry systematic false-negative risk.
Q290What is vessel and goods screening's place in KYC-adjacent work?▾
Trade finance extends screening beyond parties: vessels (IMO numbers, sanctions lists, AIS behaviour), ports, and goods against embargo and dual-use controls. KYC teams supporting trade clients need the vocabulary — the customer may be clean while the voyage is prohibited.
Q291What is a designated crypto-address screen?▾
Sanctions lists now include wallet addresses; VASPs screen deposit sources and withdrawal destinations against them, extended by analytics to associated clusters. A match is a sanctions match — blocking and reporting logic applies on-chain exactly as it does to named parties.
Q292What screening lesson do the big enforcement cases teach?▾
Wilful gaps get punished as intent: stripped payment fields, branches routing around filters, alerts closed en masse, list updates delayed. But careless gaps score too — unscreened name fields, dormant engines, unvalidated tuning. The examinations test whether screening works, not whether it exists.
Q293What is alert fatigue and its screening-specific remedy?▾
Quality decay from repetitive noise: analysts pattern-clear alerts that always cleared before — until the true match rides through. Remedies: threshold and suppression tuning with governance, identifier enrichment to kill recurring noise at source, workload management, and QA sampling that catches drift early.
Q294How should screening treat historical (delisted) designations?▾
Delisting ends the legal prohibition, not necessarily the risk: successor entities, ownership networks, and re-designation probability persist. Policy: unblock per authority guidance, retain history on the file, and weight the past designation in risk ratings — cleared is not the same as clean.
Q295What is the interaction between screening and data privacy?▾
Screening processes personal data at scale under AML's legal basis — but proportionality applies: data minimisation in vendor transfers, access controls on hit histories, retention limits, and careful handling of adverse-media content (allegations are sensitive data). Privacy-by-design and screening coexist through governance, not exemption.
Q296What is a name-screening 'field coverage' failure?▾
Screening some name-bearing fields while others flow unchecked — trading names, counterparty fields, signatories, payment references. Designations hide in the unscreened columns. Validation must inventory every field carrying names and prove each passes through the engine.
Q297How do you screen a customer with a single name or non-standard name format?▾
Configure for reality: mononyms, patronymics, and format variants are normal across cultures — engines and data models must accept them without forcing fake structures that break matching. Capture the name as legally documented, add known variants as aliases, and test the engine handles the format.
Q298What is the role of machine learning in modern screening?▾
Secondary scoring that ranks hit likelihood using context — identifiers, geography, history — prioritising analyst attention and auto-clearing the noisiest tails under governance. Adopted with validation, explainability, and miss-testing; regulators accept ML triage, not unexplained auto-clearance of sanctions risk.
Q299What would you audit first in an unfamiliar screening setup?▾
List coverage against nexus and update latency; field coverage inventory; threshold settings with last validation date; suppression list size and review status; alert aging; and a seeded-name detection test. Those six checks expose most screening programmes' real condition within a day.
Q300What is 'screening at the perimeter' versus 'screening the book'?▾
Perimeter: onboarding and payment gates stopping risk entering or transacting. Book: continuous re-screening of existing customers as the world changes. Programmes over-invest in perimeters and under-invest in the book — yet designations mostly land on people who are already customers.
Q301A regulator asks how you know screening catches what it must. Your evidence?▾
The validation pack: seeded-name and alias detection results, transliteration tests, threshold sensitivity analysis, field-coverage inventory, list-load verification logs, and disposition QA scores — refreshed on a documented cycle. Assertion isn't evidence; testing is.
Q302What is the difference between a PEP flag and a PEP risk decision?▾
The flag is data — a vendor says this person may hold a function. The decision is yours: match confirmation, seniority and jurisdiction weighting, EDD execution, and documented approval. Programmes fail by importing vendor flags as decisions or by burying flags without documented dispositions.
Q303How do sanctions regimes' differences complicate multi-jurisdiction screening?▾
US, EU, UK, and UN lists diverge — parties designated by one, not others; licences differing; secondary-sanctions reach varying. A payment lawful in euros may violate dollar rules. Screening architecture maps obligations by entity, currency, and territory rather than assuming one merged list fits all.
Q304What is your triage order when a screening backlog forms?▾
Sanctions alerts first without exception — each may be a live prohibition; then PEP hits on pending onboarding (decisions waiting); then adverse media by category severity; then review-cycle refreshes. Backlog handling is documented and risk-ranked — clearing oldest-first is chronology, not risk management.
Q305What single data improvement most reduces screening noise?▾
Dates of birth on every individual record. DOB resolves the majority of name-collision false positives instantly, at both onboarding and remediation cost far below the perpetual analyst hours it saves. It is the highest-ROI fix in screening operations.
Q306What is adverse media's role in proactive risk detection versus reactive?▾
Reactive: dispositioning hits as they alert. Proactive: thematic monitoring — watching your book against emerging cases, leak databases, and enforcement actions before vendor tagging catches up. Mature teams read financial-crime news as a screening activity, not background awareness.
Q307How do you evidence a 'no-hit' screening result years later?▾
System logs binding the party to the list versions screened, timestamps, parameters, and result — retrievable per record-keeping rules. A no-hit you can't evidence is, for audit purposes, a screen that never ran; logging is the control that makes absence provable.
Q308Sum up screening's three disciplines in one line each.▾
Sanctions: legal precision — catch everything, freeze fast, report on time. PEP: risk judgement — identify, enhance, approve, monitor. Adverse media: intelligence craft — verify identity, weigh sources, decide with documented reasoning.
Q309What is watchlist screening for internal lists?▾
Institutions maintain their own lists — exited customers, confirmed fraud identifiers, declined applicants, law-enforcement subjects — screened alongside official lists at onboarding and ongoing. Internal lists prevent silent re-entry of known risk; governance covers additions, review, and removal like any list.
Q310What happens when two vendors classify the same person differently (PEP at one, not the other)?▾
Vendor divergence is routine — coverage and definitions differ. Resolve against primary sources: does a prominent function verifiably exist? Your policy's PEP definition decides, not the vendor's tag. Document the determination; and treat systematic divergence patterns as vendor-quality intelligence worth escalating.
Ongoing Monitoring & Reviews
Q311What does 'ongoing monitoring' mean within KYC obligations?▾
Two continuing duties: scrutinising transactions against the customer's profile and expected activity, and keeping CDD information current. It converts onboarding knowledge into a living control — the profile is the yardstick, monitoring is the measurement, and reviews are the maintenance.
Q312How does the KYC profile power transaction monitoring?▾
Segmentation assigns customers to peer groups with fitted thresholds; expected activity defines each customer's normal; occupation and business context inform alert dispositions. Weak profiles produce generic monitoring; specific profiles let systems and analysts see deviation instantly.
Q313What is a periodic review and its typical cadence?▾
A scheduled full refresh of the customer file — identity data, ownership, activity, screening, risk rating — at risk-based intervals: commonly annual for high risk, two-to-three years for medium, up to five for low. Cadence is policy; currency is the obligation.
Q314What does a quality periodic review actually contain?▾
Confirmation or refresh of identity and ownership with evidence where changed; reconciliation of actual behaviour against expected activity; fresh screening with dispositions; risk-rating reassessment with rationale; document currency checks; and a reviewer's documented conclusion — not a checkbox that the calendar was obeyed.
Q315What is behaviour-versus-expectation reconciliation in reviews?▾
Comparing what the account actually did against what onboarding said it would: volumes, values, counterparties, corridors. Matches confirm the profile; divergences demand explanation and either profile updates (evidenced) or escalation. It is the review step that most often finds real risk.
Q316What is an event-driven (trigger) review?▾
A refresh initiated by change rather than calendar: ownership or control changes, screening deltas, adverse media, behavioural anomalies, product escalations, dormancy reactivation, or external inquiries. Triggers keep files true between cycles — regulators treat missing trigger frameworks as a design defect.
Q317List the trigger events every programme should wire.▾
Registry-filed ownership and director changes; sanctions and PEP list deltas touching connected parties; material adverse media; monitoring alerts revealing profile mismatch; new signatories or authority changes; high-risk product adoption; dormancy-then-activity; failed outreach; and law-enforcement or counterparty bank inquiries.
Q318What is dormancy risk and its monitoring treatment?▾
Inactive accounts are stored identity waiting for misuse: takeover, sale, or activation as mule infrastructure. Treatment: dormancy classification with reactivation controls — identity re-verification proportionate to risk, first-activity scrutiny, and monitoring scenarios weighting post-dormancy behaviour heavily.
Q319How should reviews be right-sized by risk tier?▾
High risk: full re-papering with evidence refresh and senior sign-off. Medium: targeted verification of changed elements plus attestation. Low: data confirmation and screening refresh, escalating only on signals. Proportionality documented as policy — uniform maximal reviews drown capacity; uniform minimal ones rot the book.
Q320What is review backlog risk and its management?▾
Overdue reviews mean the institution is operating on expired knowledge — a standard examination finding. Management: risk-ranked catch-up (high-risk first), interim controls on overdue relationships (monitoring intensity, restrictions), root-cause fixes on capacity or process, and honest governance reporting of the curve.
Q321What restrictions apply to customers who ignore review outreach?▾
A documented escalation ladder: reminders through channels, relationship-owner engagement, then graduated restrictions — transaction limits, channel blocks, payment holds — and ultimately exit for sustained non-cooperation, with suspicion assessment. The ladder's existence in policy is what makes restrictions defensible.
Q322What is perpetual KYC operationally?▾
Event streams replacing calendars: registry feeds, screening deltas, transaction analytics, and media monitoring trigger targeted micro-refreshes as changes occur, with periodic reviews shrinking to validation. Requires data integration, automation governance, and exception handling — pKYC automates truth maintenance, or it automates neglect.
Q323What data feeds enable perpetual KYC?▾
Corporate-registry change subscriptions; sanctions/PEP delta feeds; adverse-media monitoring; internal behavioural analytics; document-expiry calendars; bureau and identity-data updates; and product/channel event streams. Each feed maps to defined triggers with routing, SLAs, and audit trails.
Q324What is the risk of automating reviews badly?▾
Automated rubber-stamping: systems confirming stale data against itself, attestations replacing verification, and exceptions auto-closing. Automation without designed scepticism scales the neglect it was meant to fix — governance must test that automated reviews change outcomes when reality changes.
Q325How do monitoring alerts feed back into KYC files?▾
Dispositions produce profile intelligence: verified explanations update expected activity; pattern changes reprice risk ratings; RFI responses become file evidence. Programmes where alert findings never touch the KYC file run two disconnected pictures of the same customer — and both decay.
Q326What is a customer attestation and its evidentiary weight?▾
The customer confirming their details remain accurate. Weight: an accountability document and a low-risk review tool — never verification. Attestations suit stable low-risk relationships; using them to 'complete' high-risk reviews is the classic remediation shortcut examiners unwind.
Q327What monitoring applies specifically to expected-activity breaches?▾
Scenarios comparing actuals to the profiled baseline: volume and value bands, counterparty geography, cash intensity, product usage. Breaches route to review: explanation sought, profile updated on evidence, or escalation where the divergence resists innocent explanation. The baseline's specificity determines the scenario's power.
Q328What is re-screening's place in ongoing monitoring?▾
Continuous or delta-based re-screening of all parties as lists and databases update, plus full refresh at reviews and triggers. The interval between a designation and your detection is pure exposure — re-screening cadence is the control that compresses it.
Q329How do you review a customer whose business has genuinely pivoted?▾
Treat it as re-onboarding the changed elements: understand the new model, refresh licences and expected activity, reassess industry and geography risk, re-verify ownership if changed, and re-rate with rationale. Genuine pivots are normal commerce — undocumented pivots discovered late are monitoring failures.
Q330What documentation makes a review defensible?▾
What was checked, against what sources, what changed, what was concluded, and who decided — dated and attributable. The test is reconstruction: a reviewer years later should see not just that a review happened but what it actually established.
Q331What is a review 'quality assurance' function?▾
Independent sampling of completed reviews for evidence sufficiency, reconciliation rigor, rating logic, and documentation — with feedback loops to reviewers and metrics to governance. QA converts individual habits into an institutional standard and catches rubber-stamping before examiners do.
Q332What KPIs describe a healthy review operation?▾
Review currency (percentage completed on schedule), overdue aging by risk tier, trigger-review responsiveness time, outcome distribution (ratings changed, escalations, exits — reviews that never change anything aren't reviewing), QA scores, and outreach completion rates.
Q333What is the connection between reviews and exits?▾
Reviews are where exit decisions crystallise: refreshed facts revealing risk beyond appetite, non-cooperation exhausting the ladder, or behaviour contradicting the relationship's premise. A review function that never produces exits is either blessed with a perfect book or not really reviewing.
Q334How do you handle a review discovering the original onboarding was deficient?▾
Fix forward and record honestly: complete the missing due diligence now, reassess risk on the full picture, check whether the gap enabled anything reportable, and log the deficiency for root-cause analysis. Backdating or papering over discovered gaps converts an error into misconduct.
Q335What monitoring intensity changes should follow a risk-rating increase?▾
Concrete deltas, not labels: lower alert thresholds or added scenarios, shortened review cycle, screening frequency uplift, possible transaction pre-approval or limits, and named-owner oversight. A rating change that alters no control is decoration — examiners trace ratings to their operational consequences.
Q336What is 'profile drift' and its detection?▾
Gradual divergence between the file and reality — small behavioural shifts, unreported changes — none individually alarming. Detection: trend analytics against the baseline (rolling comparisons, not single-transaction rules), periodic reconciliation, and registry feeds catching the paperwork reality moved without telling you.
Q337How does ongoing monitoring differ for intermediated relationships?▾
You watch the intermediary's aggregate behaviour, not end customers: settlement patterns versus programme profile, concentration shifts, refund and chargeback anomalies, and the intermediary's own control attestations. Reviews test the intermediary's programme quality — their KYC is your visibility.
Q338What review approach suits a book of thousands of small SME customers?▾
Segmented automation: data-confirmation cycles with registry and bureau feeds, behavioural analytics prioritising outliers for human review, attestation for the stable tail, and sampling QA. Scale demands triage — full manual reviews of everything guarantees a backlog, not diligence.
Q339What is an overdue high-risk review's correct interim treatment?▾
Immediate compensating controls: heightened monitoring, transaction limits or approvals per policy, prioritised outreach with deadlines, and a documented plan. Continuing full services on expired high-risk knowledge — silently — is the specific pattern enforcement actions quote.
Q340What is the role of relationship managers in ongoing KYC?▾
First-line eyes: they hear about ownership changes, pivots, and problems before any system does — and their incentive is retention. Programmes harness the knowledge (mandatory event reporting, review participation) while insulating decisions from the incentive: RMs inform reviews; compliance concludes them.
Q341A review finds activity matching the profile but media reporting a fraud investigation. Handling?▾
The media is the event: verify identity and source credibility, assess relevance and severity, consider account restrictions pending clarity, evaluate filing obligations on what the institution processed, and conclude with a documented decision — continue with enhancements, restrict, or exit. Profile-consistent transactions don't neutralise external risk intelligence.
Q342What is 'monitoring the monitors' — oversight of the review function itself?▾
Governance metrics on the function: throughput versus inflow, currency curves, QA trends, outcome distributions, overdue concentrations by segment, and independent testing. Reviews are a control; controls get controlled — a review function reporting only its own completeness is grading its own homework.
Q343How should document expiry be handled across a book?▾
Expiry calendars driving proactive outreach before documents lapse, grace policies distinguishing identity-critical documents from supporting ones, restrictions where refresh fails, and metrics on expiry currency. Waiting for periodic review to discover long-expired identity documents is calendar-shaped negligence.
Q344What is the interaction between transaction monitoring alerts and review scheduling?▾
Alerts should accelerate reviews: multiple alerts or a confirmed unusual pattern is a trigger, pulling the review forward rather than waiting the cycle. Conversely, review findings recalibrate monitoring. The two functions sharing signals is what 'ongoing scrutiny' actually means.
Q345What is your approach to reviewing a customer mid-investigation?▾
Coordinate, don't collide: check case status before outreach (tipping-off risk), route the review through the investigation team's guidance, complete what internal data allows, and document the constraint. A routine RFI landing during a live case can compromise it — sequencing is the control.
Q346What does 'ongoing' mean for expected activity specifically — static or living?▾
Living: expectations update on evidenced change — business growth, new markets, seasonal patterns — through reviews and verified RFI responses. But updates require evidence and authority; analysts casually widening baselines to close alerts is how monitoring gets quietly disabled.
Q347What is a thematic review across the book?▾
Reviewing a slice of the portfolio against one theme — a jurisdiction after events, a product after typology alerts, customers touched by a leak or enforcement case. Thematic reviews operationalise external intelligence and demonstrate the responsive scrutiny regulators increasingly test for.
Q348What technology trends are reshaping ongoing KYC?▾
Registry and data APIs enabling true perpetual refresh; entity resolution unifying fragmented records; ML anomaly detection on behavioural drift; workflow automation with audit-native design; and generative AI drafting review summaries — under governance that keeps humans owning conclusions.
Q349What is the failure mode of review-by-checklist?▾
Completeness without comprehension: every box ticked while the customer's story stopped making sense — the business that 'grew' tenfold, the ownership that rotated, the activity that migrated. Checklists structure evidence; the review's product is a human conclusion that the relationship still coheres.
Q350How do you prioritise when triggers, periodic reviews, and remediation all compete?▾
Risk first, always: sanctions-adjacent triggers immediately; high-risk overdue reviews and material triggers next; remediation by its own risk ranking; low-risk cycles last, with automation absorbing what it safely can. Publish the hierarchy — ad-hoc prioritisation under pressure defaults to whatever shouts loudest.
Q351What single practice most improves review quality in your experience?▾
Reconciling behaviour to expectation as the review's first step, not an afterthought. It forces engagement with what the customer actually did — and most findings, from profile drift to laundering patterns, surface in that comparison before any document check would catch them.
Q352How would you explain the review function's value to a cost-cutting executive?▾
Reviews are how we keep knowing who we bank — the licence condition — and they're the control that catches drift before it becomes an enforcement narrative. The comparison isn't review cost versus zero; it's review cost versus remediation programmes, monitors, and fines priced by recent precedent.
Q353What is the endgame of ongoing monitoring — what does 'good' finally look like?▾
A book where files describe present reality: changes detected within days through feeds and analytics, reviews validating rather than discovering, ratings driving live control differences, and an audit trail proving all of it. Not perfection — currency, with evidence.
Q354Give a 30-second answer: 'How do you keep 10,000 customer files current?'▾
Segment and automate: data feeds and screening deltas maintain the stable majority; behavioural analytics surface the drifting minority for human review; risk tiers set cycle depth; triggers interrupt calendars when reality changes; and QA plus currency metrics prove the system works. People handle judgement; machinery handles refresh.
Q355What review-related question should candidates ask interviewers — showing maturity?▾
'What percentage of reviews change a rating, restriction, or relationship?' It signals you understand reviews as decisions rather than paperwork — and the answer tells you whether their function reviews truth or maintains appearances.
Corporate & Institutional KYC
Q356How does corporate KYC fundamentally differ from retail?▾
Retail verifies a person; corporate verifies an organism: legal existence, ownership chains to humans, authority structures, business substance, and financial plausibility. The evidence set multiplies — registries, constitutional documents, resolutions — and the core risk shifts from impersonation to concealment behind the entity.
Q357What establishes a company's legal existence?▾
Registry confirmation in its jurisdiction of incorporation — certificate of incorporation, current registry extract showing status, registered address, and officers — plus constitutional documents (articles, memorandum). Existence, good standing, and identity of the exact legal entity: name precision matters because near-identical names are a fraud pattern.
Q358What is a certificate of good standing / incumbency and when do you ask?▾
Good standing: registry confirmation the entity is current on obligations and not struck off. Incumbency: certified statement (often registered agent) of current directors and officers. Requested for cross-border entities where live registry access is limited — dated recently, because both decay fast.
Q359How do you KYC a company within a large group structure?▾
Establish the specific entity first — its own existence, directors, and activity — then map its position in the group to the ultimate parent and UBOs, using group structure charts verified at key layers. Group membership informs risk (listed parent, regulated affiliates) but the customer is the entity, not the logo.
Q360What is the KYC approach to a subsidiary of a listed company?▾
Verify the chain to the listed parent — each layer, not the claim — and confirm the listing is on a recognised exchange with real disclosure standards. If verified, ownership tracing can stop at the listed level; directors, activity, and purpose of this subsidiary still require standard treatment.
Q361How do you assess business substance for a corporate customer?▾
Evidence the business is real at claimed scale: financial statements, tax filings, operational footprint (premises, staff, web presence), licences, supplier and customer relationships, and sector-plausible economics. Substance testing is what separates operating companies from shells wearing operating clothes.
Q362What financial documents support corporate CDD and what do you read in them?▾
Audited accounts ideally: revenue scale versus declared activity, cash intensity, related-party transactions, auditor identity and opinions, and balance-sheet coherence. Unaudited management accounts carry less weight; a multi-million-revenue company that 'doesn't have accounts' is answering a different question than the one asked.
Q363What is authorised signatory verification on corporate accounts?▾
Two-part: verify each signatory's identity as an individual, and verify the entity granted the authority — board resolutions, mandates, or constitutional powers. Screening covers signatories too; authority documents are checked for currency, scope, and proper execution.
Q364What is a board resolution's role in onboarding?▾
The entity's formal decision to open the account and empower named individuals — evidence that the relationship is authorised by the company, not improvised by whoever showed up. Verified for proper form, quorum plausibility, and consistency with the constitutional documents.
Q365How do you KYC a trust as a customer?▾
Obtain and read the deed: identify settlor, trustees, protector, and beneficiaries or classes; verify the trustees (who legally act) and other parties per risk; understand purpose, assets, and funding source; assess jurisdiction and structure risk; screen everyone; and profile expected activity from the trust's actual function.
Q366What differs when the trustee is a corporate/professional trustee?▾
The trustee is itself an entity: verify it, its regulation or licensing as a trust company, and its own ownership — then still identify the trust's human parties. Professional trusteeship adds a control layer but also distance; regulated-trustee status informs, never replaces, party identification.
Q367How do you KYC an investment fund?▾
Verify the fund vehicle and its regulatory status; identify and verify the control side — manager/GP through its ownership chain; assess the administrator and its CDD standards (reliance basis); understand strategy, domicile, and investor-base composition; apply look-through to major investors per policy; screen all parties.
Q368What is fund administrator reliance and its conditions?▾
Relying on the administrator's investor due diligence instead of direct look-through: permitted where regulation allows, conditioned on the administrator's regulated status, contractual access to underlying CDD on demand, periodic assurance of its standards — and your retained responsibility if the reliance proves misplaced.
Q369How do you KYC a correspondent banking respondent?▾
Full EDD: the respondent's licence and regulatory standing, ownership and management screening, business and customer-base understanding, AML programme assessment (Wolfsberg CBDDQ as the industry instrument), products to be used, nested and payable-through policies, shell-bank prohibitions — and senior approval with scheduled reassessment.
Q370What is the Wolfsberg CBDDQ?▾
The Correspondent Banking Due Diligence Questionnaire — the industry-standard instrument respondents complete covering ownership, licensing, AML controls, sanctions compliance, and products. It structures correspondent EDD; answers are assessed, corroborated where material, and refreshed on cycle — a completed form is input, not conclusion.
Q371How do you KYC a money service business (MSB) customer?▾
Programme-level diligence: registration/licensing per jurisdiction, agent network scale and oversight, corridors and customer types served, AML programme quality (policies, monitoring, filings history), principals' backgrounds — plus flow-of-funds mechanics. You are underwriting their controls; corridor analytics then monitor the aggregate.
Q372What is nested correspondent risk in institutional KYC terms?▾
Your respondent's own bank customers transacting through your correspondent account — institutions you never assessed riding a relationship you did. Controls: explicit nested-activity policies with the respondent, disclosure of downstream users, transaction patterns monitored for undisclosed nesting, and appetite limits.
Q373How do you KYC a fintech or payment company customer?▾
As a mini financial institution: licensing and regulatory perimeter analysis (what do they actually do versus what their licence covers), safeguarding arrangements, onboarding and monitoring control quality, merchant or user base composition, principals and investors — and the flow-of-funds map showing exactly where your bank sits in their stack.
Q374What is a flow-of-funds map and why demand it from institutional clients?▾
A diagram of how money actually moves: who pays whom, through which accounts, when value is held and by whom, for whose benefit. It exposes the real risk surface — pooling, settlement lags, third-party rights — that product names hide. No institutional relationship should be approved without one.
Q375How do you KYC an NPO or charity?▾
Constitution and registration verification; controllers identified — trustees, board, key officers; funding sources and disbursement destinations understood; programmes matched to declared purpose; screening including conflict-region exposure. FATF's proportionality standard applies: risk-based scrutiny of this charity, not category punishment.
Q376What is embassy or sovereign-entity banking's KYC shape?▾
Verification through official channels — appointment credentials, diplomatic notes; authority structures for signatories; purpose scoped to operational banking; PEP treatment for senior officials; and monitoring calibrated to declared functions. Sovereign status changes the documents, not the discipline — and adds political sensitivity to every decision.
Q377How do you verify a company in a jurisdiction with no reliable registry?▾
Layer alternatives: certified constitutional documents through trusted channels, local legal opinions, licensed-agent confirmations, audited financials, site verification, and bank references — weighted honestly for what each proves. Where assurance cannot reach policy minimums, the answer is restriction or decline, documented.
Q378What is a professional intermediary client account (law firm, accountant) in KYC terms?▾
A pooled account holding many underlying clients' funds under the professional's control. KYC assesses the professional: regulation, AML obligations, account purpose and mechanics — with agreements securing underlying-client information on request. The visibility gap is the risk; the intermediary's own compliance is the mitigation.
Q379What red flags appear specifically in corporate onboarding?▾
Structures disproportionate to the business; recent formation or ownership changes preceding application; nominee officers and shared registered addresses; reluctance on financials or UBOs; activity descriptions that stay vague under questioning; jurisdictions chosen for opacity; and urgency pressure around approval.
Q380What is trade-finance client KYC beyond standard corporate work?▾
Understanding the trade: goods, counterparties, corridors, and typical instruments — because monitoring will assess documents against this baseline. Plus sanctions-sensitive elements: dual-use goods exposure, vessel and port patterns, and counterparty jurisdictions. The KYC file becomes the reference the trade desk checks documents against.
Q381How does KYC treat holding companies with no operations?▾
Legitimate holdcos explain themselves: what they hold, why the layer exists (liability, tax treaty, JV governance), funded how, controlled by whom. KYC verifies the holdings and the chain above. A holdco that can't articulate its function — or holds nothing visible — is a shell with better stationery.
Q382What is joint-venture entity KYC?▾
Both parents traced: ownership chains and UBOs on each side, the JV agreement establishing control (which may not follow shareholding — casting votes, reserved matters), management appointments, and purpose. JV control mechanics are exactly where 'other means' control analysis earns its keep.
Q383What is a SPV/SPE and its due-diligence approach?▾
Special-purpose vehicles exist for one function — securitisation, asset holding, project finance. Diligence verifies the purpose documentation (transaction documents, offering materials), the sponsor and controllers, orphan-structure mechanics where used, and cash-flow rights. Purpose coherence is the test: SPVs without articulable transactions are concealment candidates.
Q384How do you assess an institutional client's own AML programme?▾
Structured review: policies and governance, MLRO independence and resourcing, onboarding and monitoring capability, filing history where shareable, regulatory findings and remediation, training, and testing. Method: questionnaires corroborated by documents, meetings, and where warranted onsite review — attestation alone is hope, not assessment.
Q385What ongoing monitoring differs for institutional relationships?▾
Programme-level signals: volume and corridor drift against the declared profile, concentration changes, downstream-client indicators (nesting, merchant anomalies), regulatory news on the client, and periodic control re-assessment. You monitor the institution's behaviour as a system — individual transactions matter mainly as pattern evidence.
Q386What is payable-through account risk?▾
Respondent customers transacting directly on your correspondent account — third parties with effective access you never onboarded. Rules require identifying who has access and assuring the respondent's CDD on them; appetite often simply prohibits the product. It is the sharpest version of banking someone else's customers.
Q387What is a shell bank and the absolute rule?▾
A bank with no physical presence in any jurisdiction and no regulated group affiliation. The rule is prohibition: no correspondent relationships with shell banks, and assurance respondents don't nest them. It is one of the few bright lines in a risk-based world.
Q388How do sanctions considerations weave through institutional KYC?▾
Ownership chains screened for designated interests (50% rule); jurisdiction and currency nexus mapped; the client's own sanctions programme assessed (their gap becomes your exposure); products scoped for embargo-sensitive trade; and designation-risk contingency for clients adjacent to designated sectors.
Q389What is 'know your customer's customer' realistically for institutions?▾
Not identifying every end user — understanding the base and the controls over it: composition, geographies, risk segments, and the client's onboarding standards, with rights to drill down on request. KYCC is programme assurance plus targeted visibility, not impossible universal identification.
Q390What approval governance suits institutional onboarding?▾
Committee-grade: documented risk assessment, control-assessment findings, flow-of-funds map, appetite check, and named senior or committee approval with conditions (limits, review cadence, information undertakings). Institutional relationships concentrate exposure — governance should look like credit committee, not account opening.
Q391What periodic reassessment applies to correspondent/institutional clients?▾
Annual as the norm for higher risk: refreshed CBDDQ or equivalent, updated ownership and screening, control re-assessment against findings and news, activity reconciliation versus profile, and renewal approval. Between cycles: event triggers on regulatory actions, ownership changes, and volume anomalies.
Q392A respondent bank's monthly volumes triple without notice. Institutional response?▾
RFI through relationship channels for the business explanation; corridor and counterparty analysis of the growth; nested-activity assessment; comparison against their declared strategy; and escalation if explanations don't cohere — volume surges through correspondents are how laundromats historically moved, and 'growth' was always the cover story.
Q393What is de-risking pressure in correspondent banking and the balanced posture?▾
Cost and fear drive wholesale regional exits, severing legitimate economies from clearing. The balanced posture: risk-based decisions per respondent with documented assessments, pricing that reflects control costs, and restrictions before exits — regulators explicitly discourage category abandonment as risk management.
Q394What is a payment aggregator's specific KYC risk?▾
Merchants hidden beneath the aggregator: your visibility ends at their settlement while their onboarding quality determines what flows through. Controls: merchant-programme assessment, transparency requirements (merchant identifiers in transaction data), monitoring for laundering signatures, and prohibited-merchant category enforcement.
Q395How do you document institutional KYC for examination?▾
The full decision architecture: risk assessment, control-assessment evidence and findings, flow-of-funds map, ownership verification, screening dispositions, approval records with conditions, and monitoring calibration — organised so an examiner reconstructs why the institution believed this relationship was manageable.
Q396What single question exposes a weak institutional client fastest?▾
'Walk me through exactly how a transaction moves from your customer to our account.' Strong clients answer precisely; weak ones reveal they don't fully know their own flows — and a client who can't map their money is asking you to bank what neither of you understands.
Q397What differentiates corporate KYC excellence from adequacy?▾
Adequacy collects documents; excellence reaches conclusions: the business coheres, the structure has purpose, the numbers are plausible, the controllers are known — stated as findings a reviewer can test. The file reads like an analyst understood a business, not like a checklist survived one.
Q398What corporate KYC trend matters most right now?▾
Registry and data-API integration: ownership verification, status monitoring, and filing alerts moving from periodic document requests to live feeds — making corporate perpetual KYC genuinely possible and raising examiner expectations of currency accordingly.
Q399Give a 30-second answer: 'How would you onboard a mid-size import/export company?'▾
Verify the entity and map ownership to UBOs with registry evidence; understand the trade — goods, corridors, counterparties, licences; test substance through financials and footprint; screen every party including against trade-sanctions exposure; profile expected activity specifically enough to monitor; rate the composite risk; and approve with documentation that shows I understood the business, not just filed it.
Q400What is 'purpose of account' scrutiny for institutional clients specifically?▾
Institutions rarely need one account — they need functions: clearing, settlement, safeguarding, FX. Scrutiny maps each requested product to a stated function and tests coherence: a payments firm requesting cash services, or a respondent wanting products misaligned with its declared business, is describing a different relationship than the one applied for.
Crypto, Fintech & Digital KYC
Q401How does KYC at a crypto exchange differ from a bank?▾
Core duties match — identify, verify, rate, monitor — but context shifts: global-by-default customers onboarded remotely, wallet addresses joining the profile as behavioural data, blockchain analytics running beside fiat monitoring, and travel-rule counterparty diligence replacing correspondent-style knowledge. Speed expectations compress everything.
Q402What is a VASP and why does the definition matter for KYC?▾
A virtual asset service provider — exchanging, transferring, custodying, or issuing virtual assets as a business. The definition matters because it draws the regulatory perimeter: falling inside means full AML/KYC obligations; business-model analysis against the definition decides who must know their customers at all.
Q403What does the crypto travel rule require of KYC data?▾
Originator and beneficiary information transmitted with virtual-asset transfers above thresholds between VASPs — mirroring wire rules. KYC supplies the payload: verified names and identifiers ready to travel, plus counterparty-VASP due diligence to know whom you're transmitting to and whether they protect the data.
Q404What is counterparty VASP due diligence?▾
Correspondent-style assessment of the VASPs you exchange travel-rule data and value with: licensing and jurisdiction, ownership and principals, control quality, analytics reputation of their clusters, and data-protection capability. The 'sunrise' problem — uneven global implementation — makes this diligence the interim control.
Q405How do wallet addresses fit into a KYC profile?▾
As linked behavioural identity: deposit sources and withdrawal destinations attach to the customer, screened against designated and high-risk addresses, scored for illicit exposure, and monitored for pattern change. The wallet graph is the crypto customer's transaction history — richer than any bank statement, if you read it.
Q406What is blockchain analytics' role in KYC decisions?▾
Attribution and exposure: clustering addresses into entities, labelling services, and scoring funds' proximity to illicit sources. It powers onboarding source-of-funds checks, deposit screening, and investigations — as probabilistic evidence requiring governance: confidence levels, vendor validation, and human ownership of consequential decisions.
Q407What is source-of-funds verification for crypto wealth?▾
On-chain corroboration of the wealth story: acquisition era and method (early purchase, mining, income) visible in wallet history, disposal events matching claimed proceeds, exchange records and tax filings aligning. 'Early Bitcoin adopter' is a testable claim — the ledger remembers; test it.
Q408A customer's deposit shows 12% indirect mixer exposure. Decision framework?▾
Policy thresholds by category and directness: quantify proportion, hops, and the mixer's status (designated changes everything); weigh customer profile and history; request explanation with evidence for material exposure; disposition — accept with documentation, hold, refuse, or file — with the analytics evidence attached.
Q409What is dusting and how should KYC systems treat it?▾
Unsolicited tiny transfers from tainted or lookalike addresses — an attack or tracking technique, not customer behaviour. Systems should recognise dust patterns, weight exposure scoring accordingly, and never penalise customers for value they neither solicited nor moved. Non-consensual taint is noise, not risk.
Q410What geo-controls apply at crypto and digital-first firms?▾
IP and geolocation screening against prohibited jurisdictions, KYC-nationality and residency checks, VPN and proxy detection, and device intelligence — layered because each is evadable alone. Sanctioned-jurisdiction access through VPNs is an enforcement staple; the layering is the defence narrative.
Q411What is tiered KYC in fintech and its logic?▾
Access scaled to assurance: minimal verification unlocks limited functionality (low balances, domestic only); fuller verification unlocks scale. Logic: financial inclusion plus conversion, with risk contained by limits until identity assurance justifies more. The tiers must be genuine controls, not marketing with thresholds.
Q412What is the onboarding conversion-versus-control tension at fintechs, honestly stated?▾
Every verification step costs signups, and growth teams measure that hourly; every removed step admits fraud that compliance measures quarterly. Mature firms resolve it with risk-based flows, step-up triggers, and shared metrics — immature ones resolve it by whoever shouts louder, and enforcement actions read like that org chart.
Q413What device and behavioural signals matter in digital onboarding?▾
Device fingerprint consistency and emulator flags; IP-versus-claimed-location logic; velocity across applications (same device, many identities); session behaviour (form-filling patterns of fraud farms); and network linkage to known-bad clusters. Identity documents say who; signals say whether to believe the channel.
Q414What is synthetic identity risk in digital banks specifically?▾
Remote onboarding at scale is the synthetic's habitat: fabricated identities pass element-wise checks, age through small activity, then monetise via credit or mule service. Defences: cross-attribute consistency, bureau depth analysis, issuing-authority validation of ID-number pairings, and network analytics linking synthetics by shared artefacts.
Q415What is a deepfake/injection attack and the current defence posture?▾
Generated video or replayed media fed into verification — increasingly through virtual cameras bypassing capture. Defences: capture-integrity verification at device level, passive liveness on physics (texture, depth), injection signatures, document-photo forensics, and continuous vendor retraining. Assume the attack improves quarterly; test likewise.
Q416How does monitoring differ at a crypto firm — what's on the dashboard?▾
Dual-rail: fiat scenarios (structuring, velocity, mule patterns) plus on-chain analytics — exposure-change alerts on customer wallets, structuring across addresses, peel-chain and rapid-conversion signatures, and deposit-source category trends. Cases pair chain traces with KYC files: one investigation surface, two ledgers.
Q417What crypto-specific red flags should KYC teams recognise?▾
Immediate conversion and withdrawal after deposits (flow-through, crypto edition); mixer or high-risk-exchange sourcing; chain-hopping patterns; profiles inconsistent with volumes — students moving institutional size; kiosk-heavy funding; and urgency around withdrawals when questions arise.
Q418What is the fiat on/off-ramp's significance for KYC strategy?▾
Ramps are where crypto meets banking — and where detection concentrates: strong KYC at conversion points chokes illicit monetisation regardless of on-chain layering. It's why regulators prioritise exchanges and why banks scrutinise ramp counterparties: control the doors and the maze matters less.
Q419How should a bank KYC a crypto-exchange corporate client?▾
As a high-risk institutional client: licensing per operating jurisdiction, ownership and principals, AML programme quality including analytics usage, segregation and safeguarding of client funds, flow-of-funds mapping (which accounts do what), and monitoring calibrated to exchange settlement patterns. Appetite honesty first: bank it properly or not at all.
Q420What is proof-of-reserves' relevance to a KYC/due-diligence file?▾
Solvency transparency for custodians — attestations that assets match liabilities. In diligence it evidences custody integrity and governance seriousness; collapses driven by commingled client funds showed custody failure and financial crime travelling together. Weight it as one control signal, not a solvency guarantee.
Q421What is DeFi's KYC problem in one paragraph?▾
Protocols execute financial services without an intermediary to obligate — no natural point where a customer is known. Regulatory response targets points of control: front-end operators, developers and DAOs with governance power, and the CeFi ramps users still need. For KYC practitioners: the perimeter question is where control lives, not what the marketing says.
Q422What is an unhosted wallet transfer policy at a VASP?▾
Risk-based tiers for transfers with self-custody wallets: thresholds triggering enhanced data collection, ownership attestation or verification (signing tests), analytics screening of the wallet, and limits or refusal at the highest risk. Blanket prohibition punishes legitimate self-custody; blanket permission ignores the traceability gap — documented tiers are the defensible middle.
Q423How do stablecoins change transaction-monitoring assumptions?▾
Fiat-denominated value at crypto speed: corridors behave like payment infrastructure, volumes concentrate, and issuer freeze capability becomes an enforcement lever. Monitoring treats major stablecoin flows as payments (corridor analytics, velocity baselines) while tracking issuer and chain risk differentials.
Q424What licensing landscape should a crypto KYC professional know?▾
FATF standards implemented unevenly: registration/licensing regimes (MiCA in the EU as the comprehensive model, state and federal layers in the US, VARA-style specialist regulators), travel-rule enforcement variance, and aggressive action against unregistered operators. Perimeter literacy is job-relevant — obligations follow classification.
Q425What is a P2P platform's KYC challenge?▾
Trades settle user-to-user with the platform as matchmaker: counterparty verification may be thin and payments route through personal bank accounts, generating mule-like patterns both sides. Platform controls: user verification depth, trade monitoring, payment-method restrictions — and bank-side, P2P references in personal-account flows are a recognisable signature.
Q426What KYC applies to NFT marketplaces?▾
Increasingly standard obligations at thresholds: identity verification for significant traders, source-of-funds on high-value settlement, wash-trade detection between linked wallets, and sanctions screening. The art-market playbook digitised — subjective pricing plus instant settlement demanded the controls follow.
Q427What is crypto ATM/kiosk KYC and its direction of travel?▾
Historically minimal — cash to crypto with a phone number — making kiosks scam cash-out infrastructure. Direction: registration mandates, genuine identity verification, transaction limits, and analytics on kiosk-linked clusters. Several jurisdictions have moved from tolerance to restriction; compliance careers there are remediation-shaped.
Q428How do you investigate a crypto customer end-to-end?▾
Pair the ledgers: KYC profile and fiat history beside wallet graph and exposure analysis; trace flows across hops and chains with analytics; test the customer's explanations against on-chain fact (claims are verifiable here); quantify tainted proportions; and conclude with evidence that cites both rails.
Q429What is the single biggest crypto-KYC misconception to correct in an interview?▾
That crypto is anonymous and untraceable. Public ledgers made tracing industrial — attribution, clustering, cross-chain analytics — often yielding better evidence than banking produces. The accurate statement: pseudonymous rails with permanent records, where identity attaches at ramps and through analytics.
Q430What digital-bank KYC failure patterns have enforcement actions exposed?▾
Growth outrunning controls: onboarding tuned for conversion admitting mule armies, monitoring backlogs at scale, generic profiles defeating detection, and compliance staffing lagging user curves by years. The pattern-lesson: control capacity must scale with the growth plan, not after it.
Q431What is perpetual KYC's natural fit with digital-first firms?▾
Born-digital data makes it native: behavioural streams, device signals, and API-connected verification enable continuous truth maintenance without paper cycles. The obligation is governance — automated triggers with audit trails and human ownership of consequential outcomes, or pKYC becomes automated neglect at digital speed.
Q432How does customer risk rating differ for crypto-native customers?▾
New factors join the model: wallet-exposure history, funding-source categories, on-chain behaviour patterns, product usage (derivatives, cross-chain), and jurisdiction signals from access patterns. Traditional factors persist — occupation, geography — but the behavioural rail carries more weight than in banking.
Q433What is a crypto firm's sanctions screening stack?▾
Name screening on customers and parties as standard, plus address screening against designated wallets, analytics exposure scoring for indirect designated-source risk, protocol restrictions (designated mixers), geo-controls for embargoed jurisdictions, and travel-rule data screening. On-chain transparency enables controls banks can't replicate — regulators expect their use.
Q434What should a traditional KYC analyst learn first when moving to crypto?▾
Mechanics before typologies: how transactions, wallets, and exchanges actually work; reading a block explorer confidently; analytics concepts — clustering, exposure, labels and their confidence limits; then the typologies (mixers, peel chains, chain-hopping) and the travel rule. A week of fundamentals converts banking instincts into crypto competence.
Q435What is embedded finance's KYC accountability question?▾
When a brand offers accounts powered by a licensed partner, who knows the customer? Legally the licence-holder; practically the brand runs the funnel. Programme answer: contractual CDD standards, oversight and audit rights, data flows ensuring the obligated party can actually see its customers — accountability cannot be API'd away.
Q436What is BaaS (banking-as-a-service) risk from the sponsor bank's seat?▾
Fintech programmes onboarding customers under your licence at their pace: your obligations, their funnel. Controls: programme due diligence and approval, CDD standard enforcement with testing, transaction visibility (not just settlement), concentration limits — and the willingness to suspend programmes, which recent enforcement shows arrives late where revenue leads.
Q437How do refund, chargeback, and dispute patterns serve KYC-adjacent monitoring?▾
They expose merchant and user quality: collusive refund loops, chargeback rates flagging deceptive merchants, dispute clustering revealing scam victims. In fintech books these signals often precede laundering confirmation — monitoring that ignores them reads half the behavioural record.
Q438What is 'compliance debt' at high-growth firms and its KYC symptom?▾
Deferred control investment accumulating like technical debt: thin files from conversion-tuned onboarding, backlogs, manual workarounds. KYC symptom: remediation programmes as permanent features — always re-verifying yesterday's growth. The interview-ready take: debt is manageable if measured and scheduled; invisible debt is the enforcement pipeline.
Q439What crypto regulation should candidates cite as shaping the field now?▾
MiCA's full application in the EU (licensing and conduct baseline), travel-rule enforcement maturing across jurisdictions, US perimeter actions on unregistered operators, and sanctions extending to protocols and services. The through-line: convergence toward bank-grade expectations wherever control and value concentrate.
Q440What is your framework for assessing any new fintech product's KYC implications?▾
Four questions: who is the customer and at what moment do we know them; where does value move and who controls it at each step; what can go wrong — fraud, laundering, sanctions — through this exact mechanic; and which existing controls see it, or what must be built. Products change; the frame doesn't.
Q441A growth team proposes removing address verification to lift conversion 8%. Your response?▾
Quantify both sides: what does address data feed — screening precision, fraud models, jurisdictional controls — and what's the risk delta if it goes; propose alternatives achieving the conversion (deferred collection, database verification, step-up on signals); and put the decision through risk governance with the trade-off explicit. 'No' isn't the job; priced decisions are.
Q442What does good KYC look like at a crypto firm in one sentence?▾
Identity assurance at the ramps, analytics reading the chain, travel-rule data flowing with counterparty diligence behind it, and behavioural monitoring that treats wallets as the customer's story — all governed like the financial institution the firm actually is.
Q443Where is digital KYC heading in the next few years?▾
Reusable digital identity and eIDAS-style wallets shrinking onboarding to consent; NFC and cryptographic documents displacing image checks; AI on both sides of the verification arms race; perpetual KYC as the default architecture; and crypto-bank convergence making chain-literacy a core, not specialist, KYC skill.
Q444Give a 30-second answer: 'Why do you want to work in crypto compliance?'▾
It's where the discipline is being rebuilt in real time: transparency tools banks never had, typologies evolving monthly, and regulation converging fast — so judgement matters more than routine. I want the version of KYC where reading a block explorer and reading a regulation are the same job.
Q445What is account takeover (ATO) versus onboarding fraud in digital KYC terms?▾
Onboarding fraud defeats identity proofing — the wrong person gets in at the door. ATO defeats authentication — someone hijacks a genuine customer later. Controls differ: proofing rigor versus session security, device binding, and behavioural biometrics. KYC teams increasingly own signals for both, because a taken-over account behaves like a mule account within hours.
Scenarios & Judgement
Q446A customer's declared occupation is 'teacher' but the account receives $60,000 monthly from various companies. Walk through your thinking.▾
Profile mismatch at scale: teaching income doesn't produce this pattern. I'd check for legitimate explanations first — business ownership, consulting, family transfers — in the file and history; identify the remitting companies and their connection to the customer; and issue a neutral RFI if nothing coheres. Unexplained corporate inflows to a salaried profile is mule or undeclared-business territory: escalate with the pattern documented.
Q447At onboarding, a company's UBO chart ends at a foundation in a secrecy jurisdiction. Next steps?▾
The foundation isn't an answer — it's a question: obtain its charter, identify founders, council members, guardians, and beneficiaries, and establish who directs it in practice. If the structure exists to make that unanswerable, reasonable measures will exhaust — and the regulatory position is clear: can't identify, can't onboard. Document the attempts either way.
Q448A prospective customer offers extra fees for 'faster onboarding with fewer documents.' Response?▾
Decline the premise explicitly and record it: verification standards aren't purchasable, and the offer itself is a red flag — legitimate urgency asks for speed, not reduced scrutiny. I'd continue standard (perhaps expedited-in-parallel) due diligence with heightened attention, and treat the inducement as risk information in the file and, per policy, an internal report.
Q449Mid-review, you discover a customer's passport used at onboarding was reported stolen before the account opened. Actions?▾
Treat as identity failure, immediately: restrict the account pending investigation, verify current control through independent channels, review all activity since opening for fraud and laundering indicators, file where suspicion stands, and root-cause how verification missed a stolen-document flag. The relationship's entire history is now unverified — the response scales accordingly.
Q450A director calls asking why their company's payments are delayed during your KYC refresh. What do you say?▾
Neutral and procedural: the account is undergoing standard periodic verification required by regulation, specific items are outstanding — I'd name them — and payments resume on completion. No mention of concerns, alerts, or reviews beyond routine. If a case exists, wording is pre-agreed with the investigation team; customer contact during live cases follows their guidance, not my improvisation.
Q451You find your own colleague onboarded a customer waiving mandatory documents. Handling?▾
Escalate through compliance or the designated channel with specifics — customer, gaps, dates — and let the review run: the file gets remediated, the activity gets checked, and the pattern gets examined (one favour or a habit?). Not a corridor conversation: undocumented waivers are how insider-enabled laundering starts, and reporting protects the colleague too if there's an innocent explanation.
Q452A high-value prospect refuses source-of-wealth evidence, citing privacy — but offers bank references. Decision?▾
References corroborate conduct, not wealth origin: for the risk tier demanding source-of-wealth, they don't substitute. I'd explain the regulatory basis, offer confidentiality assurances and secure handling, and narrow requests to what's decisive. Sustained refusal ends it: the requirement isn't negotiable, and refusal patterns at exactly the decisive evidence are themselves informative.
Q453Post-onboarding, monitoring shows a corporate account behaving exactly like the profile — but all counterparties share one registered address. Read?▾
Coherent-but-clustered: profile-consistent activity with a network fingerprint. Shared addresses across counterparties suggest connected entities — possible circular flows, invoice schemes, or a controlled ecosystem. I'd map the network (ownership, directors, formation agents), test whether the 'trade' is real economic activity or value rotating within one control group, and escalate on the network evidence.
Q454A politically connected customer's file is complete, but a journalist contacts the bank about them. What changes?▾
Nothing about standards; everything about handling: no comment externally per media policy, immediate internal notification (compliance, communications, senior management), a trigger review of the relationship against whatever the inquiry signals, and preparation for scrutiny. Press interest is adverse-media-in-progress — the file should be examination-ready before the story runs.
Q455Your risk model rates a customer low, but everything about the file makes you uneasy. What do you do with that?▾
Convert unease into analysis: what specifically doesn't cohere — occupation versus products, structure versus size, story versus documents? If articulable, document it and override upward with rationale or escalate for a second view. If it truly resists articulation after honest effort, I defer to the model but note the review. Judgement above scores — but judgement means reasons, not vibes.
Q456A remediation deadline looms and 200 files lack one non-critical document each. Team suggests marking them complete with follow-ups. Your call?▾
No — completeness is a factual claim regulators test. Instead: risk-rank the gap's materiality, report the true position with a completion plan, apply interim controls where the missing item matters, and negotiate the deadline on honesty. Marking incomplete files complete converts a resourcing problem into falsification — the finding that ends careers.
Q457An introduced customer arrives via a lucrative partner; the introducer resists your direct contact with the customer. Assessment?▾
Intermediation that blocks principal access is a control inversion: I can't verify who I can't reach. I'd insist on direct verification regardless of introducer relationships — reliance frameworks require it for exactly this reason — and read sustained resistance as concealment risk worth escalating. Revenue partners who gate identity are selling opacity.
Q458You inherit a portfolio where expected-activity fields all read 'general business transactions.' Priority response?▾
A monitoring blindfold at scale: baseline-less profiles make deviation invisible. Priority: risk-rank the book, refresh high-risk profiles first with specific expected activity, mine actual behaviour to draft baselines for verification, and fix the onboarding template so the debt stops growing. Report it as a control gap — because it is one.
Q459A customer asks which transactions 'trigger reviews' so they can 'avoid the hassle.' Response?▾
Politely absolute: internal controls aren't disclosable — and I'd note the question. Explaining thresholds is drawing a map around detection; the request itself, depending on context and persistence, is risk information. Service-level framing outward ('checks are routine and minimally intrusive'), documentation inward.
Q460Two applications arrive the same week: identical device fingerprint, different identities, both documents verifying cleanly. Analysis?▾
Verification says the documents are real; the device says the applicants aren't independent. Hypotheses: shared household (innocent), broker-assisted applications (grey), synthetic or mule factory (dark). I'd expand device and network linkage, compare application artefacts (typing patterns, photos' backgrounds), apply step-up verification, and route to fraud review. Clean documents on linked devices is exactly how organised onboarding attacks look.
Q461A sanctions delta adds a name matching your customer's UBO — name and country match, DOB absent from the listing. Sequence?▾
Treat as unresolved, act protectively: escalate to sanctions team immediately, hold material transactions pending disposition, and hunt discriminating identifiers — patronymics, positions, associates, photographs — across sources. Absent-identifier listings force judgement: document the analysis thoroughly, and where genuine ambiguity persists, the conservative path (block and report) is the defensible one.
Q462Your MLRO declines your exit recommendation for a customer you consider high-risk. How do you proceed?▾
Their call to make — my record to complete: rationale documented on both sides, enhanced monitoring and conditions if the relationship continues, and a scheduled re-review. If new evidence arrives, I re-escalate. If I believed the decline was improper rather than a judgement difference, whistleblowing channels exist. Disagreement inside governance is healthy; silent disowning of my own analysis isn't.
Q463A fintech partner's onboarding quality is slipping — your sampling finds 15% verification failures. Institutional response?▾
Contractual machinery, activated: formal findings notification, remediation plan with deadlines, enhanced sampling meanwhile, volume caps or onboarding suspension per the agreement's triggers, and internal reporting of the exposure. The partnership continues on demonstrated fix or ends on demonstrated failure — sponsored customers are your obligation regardless of whose funnel admitted them.
Q464You're asked to approve a PEP relationship an hour before a board dinner where the PEP is guest of honour. Pressure and process?▾
The dinner is irrelevant to the file and highly relevant to the record: approval happens when EDD is complete — wealth corroborated, screening dispositioned, monitoring set — not when hospitality schedules suggest. If the work is genuinely done, timing is fine; if it isn't, I say precisely what remains and when. Social pressure around approvals goes in the documentation.
Q465A customer's crypto exchange deposits are profile-consistent, but analytics show 30% sourced from a newly designated mixer. Framework?▾
Designation changes the category: this is sanctions-adjacent, not just risk appetite. Quantify directness and timing (pre- versus post-designation flows), freeze or hold per legal guidance, evaluate blocking and reporting obligations, RFI the customer on source with evidence expectations, and document the analytics trail. Post-designation mixer sourcing is close to strict-liability territory — legal in the room, fast.
Q466Onboarding a charity operating in a conflict zone: your risk model screams, FATF guidance cautions against de-risking. Reconcile.▾
Assess this charity, not the category: governance quality, funding sources, delivery partners' identities, controls over last-mile disbursement, track record and audits. Structure the relationship to the risk — corridor-specific monitoring, payment purpose documentation, review cadence. Decline only on evidence this organisation can't manage its exposure — 'conflict zone' alone is geography, not a finding.
Q467A review reveals a customer's business changed completely two years ago — nobody noticed. Beyond fixing the file, what does this tell you?▾
The trigger framework failed: no registry feed, no behavioural drift detection, no RM reporting caught a total transformation. Fix the file, then autopsy the system — which signals existed and where they died; check the interim activity against the real business (two years monitored against a fiction); and test whether this is one file or a pattern. One silent pivot found usually means many unfound.
Q468An examiner asks: 'Show me a file where your KYC changed a decision.' Why is this question dangerous, and what answers it?▾
It tests whether the programme is a control or a records system — theatre can't answer it. Answers: onboarding declines with documented rationale, EDD findings that restricted products, reviews that downgraded and exited, profiles whose specificity caught a laundering pattern. A programme with no decision-changing files has been collecting paper, and the examiner now knows.
Q469You're offered a KYC role at a firm whose enforcement history you know is ugly. Interview-savvy assessment of the opportunity?▾
Post-enforcement firms are honest markets: funded remediation, board attention, and careers made fixing what predecessors hid — if the commitment is real. My diligence: is leadership new, is the monitor's scope resourced, do compliance hires have authority or just headcount? The dangerous employer isn't the one that failed publicly; it's the one still failing quietly.
Q470A colleague dispositions alerts twice as fast as the team with identical QA scores. Manager asks you to study their method. What would you look for — and suspect?▾
Look for legitimate craft: better query habits, template discipline, typology pattern recognition, decisive evidence-first sequencing. Suspect shortcuts QA sampling might miss: shallow counterparty checks, copy-paste rationales fitting the sample rubric, risk-tolerant closures on judgement calls. The study's real output is either training material or a calibration problem — both worth finding.
Q471Your firm enters a new market with a document ecosystem you can't verify (no registry access, unfamiliar IDs). Programme build?▾
Layered assurance designed before launch: vendor coverage testing on the actual document types, database and bureau alternatives mapped, certified-channel workflows for corporates, tiered product access scaling with assurance, enhanced monitoring compensating at the back end, and honest appetite limits where assurance ceilings are low. Market entry without a verification strategy is growth borrowing from enforcement.
Q472The business wants to reduce periodic reviews by 40% using 'perpetual KYC.' What makes this legitimate versus dangerous?▾
Legitimate: real event feeds (registry, screening, behavioural) with tested trigger coverage, micro-reviews that actually fire, and validation that the stream catches what cycles caught. Dangerous: the same proposal without the feeds — review reduction wearing pKYC vocabulary. My test: show me the trigger catalogue, its firing rates, and a back-test against last year's review findings. Evidence converts the proposal; its absence exposes it.
Q473A customer under RFI responds with perfect documents suspiciously fast — inside an hour, for records that usually take days. Weight?▾
Speed cuts both ways: organised legitimate businesses retrieve fast; fabricators also pre-build evidence for expected questions. I'd examine the documents forensically (metadata, formats, issuer verification), test contents against independent sources, and note whether the package answers slightly-wrong questions — pre-fabricated evidence often fits the anticipated ask, not the actual one. Speed is context, verification is the answer.
Q474You discover the bank's screening missed a designated party for six weeks due to a feed failure. First 48 hours?▾
Contain, quantify, disclose: fix and verify the feed; re-screen the full base against the missed deltas; identify any transactions with newly-flagged parties — freeze and assess blocking/reporting obligations retroactively; brief legal and senior management; and prepare regulator notification per obligations. Documentation of the timeline starts immediately — the failure is survivable, the cover-up wouldn't be.
Q475How would you design KYC for a product serving refugees without standard documents?▾
Purpose-built inclusion tier: alternative evidence regimes regulators permit (UNHCR documents, attestation frameworks), biometric anchoring for uniqueness, restricted functionality with genuine limits, enhanced monitoring compensating at the transaction layer, and staged access as history builds. Financial inclusion is a FATF objective — the craft is designing the risk down instead of designing the people out.
Q476What's your honest answer to 'Have you ever missed something important in a file?'▾
Yes — everyone working real volume has, and the honest version names one: what I missed, how it surfaced, and what changed in my method because of it (a checklist line, a sequencing habit, a second-look rule). Interviewers aren't hunting perfection; they're testing whether your errors become systems. Claimed infallibility is the failing answer.
Q477Describe a time you had to push back on a senior stakeholder — framed for KYC work.▾
Structure it: the stake (a control being bent), the pushback (facts and policy, in writing, respectfully), the escalation path used, and the outcome — including relationships preserved. The interviewer is testing whether your compliance survives hierarchy. The strongest close: the senior party later relied on the documentation that pushback created.
Q478Why KYC as a career — the answer beyond 'compliance is important'?▾
Because it's investigative work where judgement compounds: every file is a small verification puzzle — does this story cohere? — and the craft of testing stories against evidence transfers everywhere. Plus the stakes are real: the files I get right keep stolen and trafficked money out of the system. It rewards curiosity with consequence, daily.
Q479What are your first 30 days in this KYC role?▾
Learn the risk model, policy, and appetite; read strong and weak files to calibrate the quality bar; sit with onboarding, screening, and review systems; map escalation paths and meet the second line; take a supervised caseload by week two and a full queue by week four — while keeping a list of process frictions worth raising once I've earned the context.
Q480A file is technically complete but you'd bet money the business is fake. The clock says approve. What's the professional move?▾
Name the bet's basis: which specific elements don't cohere — margins impossible for the sector, principals without footprints, counterparties that circle back. Documented articulation converts instinct into grounds for EDD or decline. If honest effort can't articulate anything, I approve with a monitoring note and early review date. The clock never decides — but neither does unexamined suspicion.
Q481Your QA reviewer disputes your alert closure. Walk through how you handle it.▾
Reread my file through their comment before defending: if the gap is real — evidence thin, reasoning implicit — I remediate and thank them; calibration is the job. If I still disagree, I make the case on the record and accept the calibration outcome. QA friction is the cheap version of examiner friction — treating reviewers as adversaries wastes the discount.
Q482What would you do differently from most KYC teams if you ran one?▾
Publish decision rates: what percentage of onboarding declines, reviews changing ratings, EDD altering terms — making the function's judgement visible instead of its throughput. Teams optimise what's measured; measuring completed files builds archives, measuring changed decisions builds a control. Second: reconciliation-first reviews, behaviour before documents.
Q483How do you stay current in KYC — concretely?▾
FATF publications and mutual evaluations as they release; enforcement actions read in full (they're free case studies); regulator guidance in my jurisdictions; two or three industry sources (Wolfsberg papers, quality newsletters); leak-investigation reporting; and internal case debriefs. One hour weekly, protected — currency in this field is a scheduled habit, not osmosis.
Q484An interviewer asks you to critique their public KYC failure (enforcement action). Approach?▾
Respect plus specificity: summarise the documented failure pattern accurately — say, profiles too generic to power monitoring — then what I'd have flagged earlier and which controls prevent recurrence, ending on evidence their remediation addresses it. It demonstrates I read enforcement as curriculum and can discuss failure without either flattery or grandstanding.
Q485What's the difference between a good KYC analyst and a great one?▾
Good analysts complete files accurately; great ones reach conclusions that change outcomes — they notice the incoherent margin, the recycled address, the story that fits the documents but not the world. Technically: great analysts write findings a stranger can test, feed patterns back into controls, and know exactly when judgement should override process — with reasons attached.
Q486Sell me KYC experience as preparation for broader financial-crime leadership.▾
KYC is where every control begins: I've seen how profiles power monitoring, how ownership work enables sanctions compliance, how file quality decides investigation outcomes — the system view leaders need. Add the stakeholder craft (pushing back with documentation, translating regulation into operations) and KYC produces exactly the judgement-plus-evidence habit that financial-crime leadership runs on.
Q487A magic wand gives you one industry-wide KYC fix. What do you choose and why?▾
Verified, interoperable beneficial-ownership registries with registrar-level verification duties. Ownership opacity is the root enabler — every shell scheme, sanctions evasion structure, and laundromat runs through it. Fix the ownership layer and monitoring, screening, and investigations all inherit the improvement. Everything else is compensating for that gap.
Q488Interviewer: 'Our KYC backlog is 4,000 files. You start Monday.' Your first week?▾
Triage before touching files: risk-rank the backlog (high-risk and sanctions-adjacent first), quantify the true aging curve, identify the inflow driver (is the hole still filling?), stand up interim controls on the riskiest overdue relationships, and give governance an honest number with a resourced plan. Week one buys truth and priorities — heroic file-clearing without them just reshuffles risk.
Q489What question should you ask us, the interviewers — and why that one?▾
'When your KYC findings conflict with revenue, tell me about the last time — and who won?' The answer reveals escalation reality, compliance authority, and whether documentation is respected or resented. Everything else about the role — tools, volumes, hybrid policy — matters less than whether the function's conclusions survive contact with commercial pressure.
Q490Rapid-fire: define KYC in exactly one sentence, interview-grade.▾
KYC is establishing and continuously verifying who a customer is, who ultimately controls them, and what their legitimate activity looks like — so every downstream financial-crime control has truth to work with.
Q491Rapid-fire: CDD versus EDD in one sentence.▾
CDD is the standard duty of identifying, verifying, and understanding every customer; EDD is the deeper evidence, approval, and monitoring package applied where risk — PEPs, high-risk jurisdictions, complex structures — demands more than standard.
Q492Rapid-fire: why does beneficial ownership matter, one sentence.▾
Because crime acts through entities to keep humans invisible, and beneficial-ownership work is the discipline of making the humans visible again.
Q493Rapid-fire: what makes a KYC file defensible, one sentence.▾
Evidence for every claim, reasoning for every judgement, and a record showing who decided what, when, and why — reconstructable by a stranger years later.
Q494Rapid-fire: the biggest KYC risk in the next five years, one sentence.▾
AI-generated identity — deepfakes and synthetic documents at industrial scale — forcing verification to rebuild around cryptographic and behavioural evidence faster than fraud rebuilds around whatever we deploy.
Q495Final: give your 30-second pitch for a KYC role.▾
I verify stories for a living: identity against documents, ownership against registries, business claims against economic sense — and I write conclusions a reviewer can test. I know the frameworks (FATF through local rules), respect the legal edges (tipping off, sanctions strict liability), and I practise the judgement out loud, not just on paper. Files I close stay closed under examination.
Q496A customer emails documents from a different name's email address. Minor or material?▾
Material until explained: document delivery channels are identity signals. Innocent explanations exist — spouses, assistants, advisers — but so does the takeover/third-party-control pattern. I'd verify through an established channel, ask who the sender is and their authority, and record it. Small anomalies at identity touchpoints deserve disproportionate attention.
Q497How do you handle interview nerves on scenario questions — your actual method?▾
Structure absorbs nerves: every scenario gets the same skeleton — clarify what's known, investigate the gap, decide at the applicable standard, document and escalate. Saying the skeleton out loud buys thinking time and shows method. Practising aloud beforehand — ideally under simulated pressure — is what converts knowledge into delivery.
Q498An onboarding case has everything except one sanction-list disposition pending. The customer's first payment is queued. Approve the payment?▾
No — that pending disposition is precisely the check that exists to stop prohibited payments. Sanctions ambiguity has no risk-based override: the payment holds until the hit is dispositioned, however commercially awkward. Approving around an open sanctions alert is the one shortcut with strict-liability consequences.
Q499What's a red flag most analysts overlook, in your view?▾
Perfection: files where every document arrives instantly, every answer anticipates the question, every number lands just under thresholds. Real customers are messy — delays, clarifications, imperfect paperwork. Frictionless files at high risk tiers deserve a second look precisely because professional concealment rehearses.
Q500You have offers from a big bank's KYC team and a crypto startup's. How do you reason about it — out loud, as an interview answer?▾
The bank teaches depth: mature frameworks, examiner exposure, complex structures at scale. The startup teaches breadth: building controls, chain analytics, regulatory ambiguity navigated in real time. My choice keys on learning slope and mentorship reality — and whichever I pick, I'd say so with reasons, because reasoned career judgement is itself the competency being interviewed.
How to prepare for a KYC interview with these questions
KYC interviews follow a predictable arc: concepts → process → judgement. Interviewers open with fundamentals (KYC vs AML, CDD vs EDD, what a UBO is), move into your process (how you verify identity, trace ownership, disposition a screening hit, run a review), and finish with scenarios that test decision-making under ambiguity. The 500 questions above are organised to match that arc — and the scenarios category at the end is where offers are won or lost.
A preparation plan that actually works
Week 1: Fundamentals, Identification & Verification, and CDD — these carry most entry and mid-level interviews. Week 2: EDD & PEPs, Beneficial Ownership, and Screening — where candidates separate themselves; interviewers love UBO tracing logic and the sanctions-vs-PEP distinction. Week 3: Monitoring, Corporate KYC, Crypto, and Scenarios — then rehearse answers aloud, timed to 45–60 seconds each. Structure every scenario answer the same way: investigate → decide → document.
By role: what to emphasise
KYC/Onboarding Analyst: identification and verification, document red flags, CDD walk-throughs, screening dispositions, file documentation. EDD/High-Risk Analyst: PEP handling, source of wealth, UBO tracing through layered structures, high-risk industries. Corporate/Institutional KYC: entity verification, fund and trust structures, correspondent-style diligence, flow-of-funds mapping. Crypto/Fintech KYC: travel rule, blockchain analytics, tiered onboarding, digital identity and deepfake risk.
KYC interview questions: FAQs
How should I use these 500 questions?
Category by category, weak areas first. Read the model answer, then practise your own version out loud in 30–60 seconds — spoken fluency is what interviews measure.
Is this suitable for freshers?
Yes — Fundamentals, Verification, and CDD cover entry-level interviews, while EDD/PEP, ownership, corporate, and crypto categories serve experienced candidates. Behavioural questions are included in Scenarios.
What do KYC interviews focus on most?
CDD vs EDD, UBO identification, PEP handling, the three screening types — and at least one judgement scenario, like an ownership chain ending at an offshore foundation.
How is an AI mock interview different from reading Q&As?
Reading builds knowledge; speaking under pressure builds performance. The AI interview asks by voice, scores your spoken structure and content, and shows where delivery loses marks — before a real interviewer sees it.
Do I need a KYC certification first?
Not always, but it strengthens shortlisting. See our guide to globally recognised KYC certifications to choose a role-aligned option.
Now practise these answers out loud — with an AI interviewer
AGZIT's AI voice interview asks you real KYC questions, listens to your answers, and scores your structure, content, and clarity — so you find your weak spots here, not in the real interview. Your first AI mock interview is free.
Start your free AI mock interview →No card needed for your first session · 20-minute voice interview · instant scorecard
