Preloader

Loading

100 KYC Scenario Based Interview Questions and Answers

100 KYC Scenario Based Interview Questions and Answers

Scenario questions separate people who have memorised definitions from people who can actually work a file. You are given an incomplete situation and asked what you would do — and the follow-up usually matters more than the first answer.

These KYC scenario based interview questions come with full model answers you can adapt: what you would check, what would make it innocent, what would make it suspicious, and where the decision sits.

How to structure a scenario answer

Start with your initial read, separate the innocent explanation from the suspicious one, name the specific evidence you would seek, say what would change your mind, and end with a decision. Jumping straight to "I'd reject them" or "I'd file a SAR" scores badly — those are conclusions, not analysis.

Individual onboarding (Q1–14)

1A customer opens an account stating they are a student, but declares expected monthly deposits far above a typical student income. What do you do?

I wouldn't treat this as suspicious on its own. Students commonly receive family support, scholarship payments, or income from a part-time business, so the amount alone isn't the issue — the issue is whether it can be explained and evidenced.

I'd ask the customer what the deposits relate to and, importantly, who is sending them. If it's family support, I'd expect a small number of identifiable senders, usually a parent, with reasonably regular amounts. I'd ask for something supporting it — a letter from the parent, evidence of their occupation or income, or the remitting account details.

What would concern me is a different pattern: deposits from multiple unrelated senders, irregular amounts, or a customer who can't say who's sending the money. That isn't family support, that looks like mule activity, and I'd escalate rather than resolve it myself.

If the explanation holds, I'd record it with the supporting evidence, set the expected activity profile to match, and make sure monitoring is calibrated to it so divergence later generates an alert.

2An applicant provides an address in one country, a passport from a second, and states employment in a third. Is this a problem?

Not inherently. Internationally mobile people are completely normal — someone might be a French national living in Dubai working for a Singapore company. The combination isn't the concern; whether each element is verifiable is.

I'd verify each independently: the passport through document checks or electronic verification, the address through an acceptable proof, and the employment through a letter, contract or payslip. I'd also ask why they want an account in our jurisdiction specifically, because that answer tells me a lot about expected activity.

What would raise my concern is if elements don't reconcile — an address they can't evidence, an employer that doesn't appear to exist, or an explanation that shifts when questioned. Unverifiable is different from unusual.

Assuming everything verifies, this affects the risk rating rather than the decision. Multiple jurisdictions increase geographic risk, particularly if any are higher-risk, so I'd rate accordingly and set monitoring to match.

3A customer refuses to explain the purpose of the account, saying it is private. How do you respond?

First I'd reframe it, because people often react this way when they think they're being singled out. I'd explain that understanding the purpose of the relationship is a regulatory requirement that applies to every customer, it isn't a personal enquiry, and the information is held confidentially.

Often that resolves it. Many customers simply don't realise it's a legal obligation rather than curiosity.

If they still refuse, I can't proceed. Without knowing the intended purpose, I have no baseline for expected activity, which means monitoring can't function — I'd have no way of telling normal from abnormal. That's a material gap, not a nice-to-have.

I wouldn't reject them myself. I'd document what was asked, the exact response, and the fact that the file cannot be completed, then escalate. Refusal on a core requirement is itself a risk indicator worth recording, particularly if the customer is cooperative on everything else.

4An applicant is very knowledgeable about your onboarding thresholds and asks which amounts trigger reporting. What does that suggest?

This is a recognised red flag and I'd take it seriously. Legitimate customers occasionally ask about limits for practical reasons — they want to know if a large transfer will be delayed. But asking specifically where reporting or detection thresholds sit is different, because the only real use for that information is staying below them.

I wouldn't confirm any thresholds. I'd answer generally, saying that checks apply across all activity and vary case by case, and move on without being obviously evasive.

Then I'd document it precisely — the exact questions asked, in what order, and how they were phrased. That detail matters, because it's evidence of intent rather than a vague impression.

I'd flag it for review alongside the rest of the application. On its own it may not stop onboarding, but combined with any other indicator it becomes significant, and if the account later shows structuring, this record is exactly what an investigator would need.

5A customer wants to open an account on behalf of a relative who cannot attend. What is your approach?

The first question is what legal authority they hold. If there's a power of attorney, court-appointed deputyship, or equivalent, this is a normal arrangement — elderly or unwell customers are represented all the time.

I'd verify both parties. The account holder needs full identification and verification in their own right, and the authorised person needs identifying too, plus the authority document verified as genuine and current.

What I wouldn't accept is informal representation — someone simply saying "my father asked me to do this." Without documented authority, I can't establish that the account holder knows about or controls the account, and third-party control without a legal basis is a serious indicator, including for financial abuse of vulnerable people.

I'd also want to establish the purpose and expected activity from the account holder's circumstances, not the representative's. If I couldn't get any direct confirmation from the account holder and the authority documentation was weak, I'd escalate rather than proceed.

6An applicant's stated occupation is inconsistent with their apparent age. How do you handle it?

I'd query it neutrally rather than assume deception. A 22-year-old company director is unusual but entirely possible — they may have founded a startup, inherited a family business, or been appointed to a family company. Equally, an applicant in their seventies describing themselves as a full-time trader is plausible.

What I'd ask for is evidence of the role: company registration showing their appointment, a contract, or business documentation. That's straightforward for someone genuinely in the position.

The concern would be if the evidence doesn't exist, or if the customer can't describe the role in any detail. A real director can explain what the company does and their part in it; someone whose name is being used cannot.

If it verifies, it's simply an unusual profile and I'd note it. If it doesn't, I'd treat it as a possible nominee or identity misuse indicator and escalate, particularly if the account is expected to receive significant funds.

7A customer opens an account and immediately requests a very high transaction limit before any activity history exists. Concern?

It's worth understanding rather than refusing outright. A business with a genuine contract in place may legitimately need a high limit from day one, and refusing would lose a real customer for no reason.

So I'd ask what activity the limit is for and seek evidence — signed contracts, purchase orders, invoices, or accounts from a predecessor business. A customer with real activity behind the request produces that easily.

What would concern me is a request with no evidenced basis, or a vague answer like "we expect to grow quickly." Limits should reflect evidenced expected activity, not stated ambition, because the limit is what our monitoring calibrates against. Setting it high with no basis effectively disables detection.

My recommendation would be to set the limit to what's evidenced now and review it as genuine activity develops. That's a normal commercial answer that also protects the control, and most legitimate customers accept it readily.

8An applicant is a foreign national with no local address history and limited documentation. How do you proceed?

This is a common and legitimate situation — new arrivals need bank accounts, and excluding them would be both unfair and a de-risking problem. The task is finding an acceptable verification route, not finding a reason to decline.

I'd use whatever alternatives our policy permits: passport plus verification of an overseas address, electronic verification against international data sources, an employer letter, a tenancy agreement, or certified documents from their home jurisdiction. Many firms also accept documentation from a recognised overseas financial institution.

I'd be careful to verify the overseas elements properly rather than accepting them at face value because they're harder to check. If the home jurisdiction is higher risk, that raises the rating.

The one thing I wouldn't do is waive requirements because verification is inconvenient. If no acceptable route exists, I'd escalate for a decision rather than proceed on a thin file — but I'd exhaust the legitimate options first.

9A customer's application is completed by a third-party agent who answers all questions on their behalf. What do you think?

This concerns me more than most scenarios, because it's a recognised pattern in both mule recruitment and coercion, including trafficking-related cases.

There can be innocent explanations — a language barrier, or a professional adviser assisting a corporate client. But the distinction matters: an interpreter translates the customer's answers, whereas here the agent is supplying them.

I'd insist on direct contact with the customer, separately if possible. I'd want to confirm in their own words that they understand what account is being opened, that they control it, where the funds will come from, and what it's for. Someone genuinely opening their own account can answer that; someone whose identity is being used typically cannot.

If the agent resisted that, or the customer's answers didn't match what was submitted, I'd stop and escalate immediately. I would not complete onboarding on a file where I've never established that the named holder actually controls the account.

10An applicant declares they are self-employed but cannot describe their business clearly. How do you handle it?

I'd probe with open questions before drawing any conclusion — what they sell or provide, who their customers are, how they invoice and get paid, how long they've been trading. Genuine business owners answer these easily and usually at length, because it's their livelihood.

Some allowance is fair: people can be nervous, or working in a niche they find hard to summarise. So I'd give them room and ask in different ways.

What concerns me is vagueness on basics — someone who can't say who pays them or what they actually deliver. That pattern suggests either the business doesn't exist, or the account is intended for something other than what's declared.

I'd ask for documentary evidence: registration, invoices, contracts, a website, or tax filings. If that's produced and stacks up, the earlier vagueness is probably just poor communication. If nothing exists and the description stays unclear, I'd escalate rather than onboard on an unevidenced business.

11Two unrelated applicants provide the same residential address on the same day. Significant?

Possibly innocent. Shared housing, family members, house shares and serviced accommodation all produce this legitimately, and in dense urban areas it's common.

What makes it significant is whether other links exist. I'd check for shared phone numbers, email domains, devices or IP addresses, the same referrer, sequential application times, similar declared occupations or income, and whether either has already named the other in any capacity.

A single shared address is weak evidence. A shared address plus a shared phone number, applications minutes apart, and similar profiles is a recognised coordinated mule recruitment pattern.

I'd also check whether more applications have used that address historically — two might be a house share, twelve is not.

I'd flag it as a linked pattern rather than assessing each file in isolation, because that's the mistake that lets networks through: each application looks fine alone. If the wider indicators aren't there, I'd note the link and proceed normally.

12A customer opens an account and states the purpose is "investments" with no further detail. Is that acceptable?

No, and I'd push back on it. "Investments" isn't a purpose statement — it's a category. It establishes no baseline, so monitoring has nothing to compare activity against, which is the whole point of collecting it.

I'd ask for specifics: what type of investments, roughly what scale, how frequently they expect to transact, where the funds will come from, and where they'll be sent. Someone with a genuine investment plan answers that readily.

The difference matters practically. "Monthly transfers of around ten thousand to a named brokerage, funded from salary" gives me something to monitor against. "Investments" gives me nothing, and every transaction is equally unremarkable.

If the customer can't be more specific, that's informative in itself — it may mean they don't have a clear plan, or that the stated purpose isn't the real one. I'd record what was asked and either get usable detail or escalate rather than complete the file with a placeholder.

13An applicant becomes evasive when asked about source of funds but is otherwise cooperative. What do you do?

The selectivity is what makes this notable. A customer who's difficult about everything is usually just irritated by the process. A customer who answers freely on identity, address and occupation but becomes evasive on one specific point is telling me something about that point.

I'd explain plainly why source of funds is asked — that it's a regulatory requirement applying to everyone, and that we need to understand where money entering the account originates. Sometimes evasiveness is embarrassment: an inheritance after a bereavement, a divorce settlement, or a gift they'd rather not discuss.

So I'd give a clear opportunity to respond, and be willing to accept a sensitive but plausible explanation with appropriate evidence.

If the avoidance persists on that specific point while cooperation continues elsewhere, I'd treat it as a material indicator, document the pattern precisely rather than characterising it, and escalate. Source of funds isn't optional, and I wouldn't complete the file with it unresolved.

14A high-net-worth individual is introduced by a relationship manager who says diligence has "already been done informally". How do you respond?

I'd be polite but clear: informal diligence isn't diligence. Nothing that isn't documented exists as far as a regulator, an auditor or a future investigator is concerned.

That said, I wouldn't dismiss what the RM knows. Their relationship knowledge is genuinely useful — it can point me to the right sources, explain the background, and speed up gathering evidence. I'd use it as a starting point rather than a substitute.

So I'd ask what they know, then set out exactly what's needed to evidence it: identification, verification, ownership where relevant, source of wealth given the client's profile, and screening. High-net-worth individuals typically attract enhanced measures, so the standard is higher, not lower.

If the RM pushed back on grounds of the client's importance, I'd hold the requirement and escalate if necessary. Files approved on relationship assurance rather than evidence are exactly what enforcement actions describe.

Practise reasoning out loud

Scenario answers are delivered live, with follow-up questions. Reading them is not the same as saying them under pressure. Practise a live AI voice and video interview on AGZIT:

  • A real spoken interview that follows up on your reasoning
  • A 10-competency scorecard showing where your answers fall short
  • A free ATS-friendly resume builder once you register
  • Your first AI interview is free

Start your free AI interview How it works

Documents and verification (Q15–30)

15A passport photo page shows slightly misaligned text and inconsistent font spacing. What do you do?

I'd treat it as a possible forgery and stop. Misalignment and inconsistent spacing are classic alteration indicators, because forged documents are often assembled from a genuine template with details substituted.

I'd check the other security features I have access to — the machine-readable zone consistency, whether the photograph shows signs of substitution, whether fonts match the issuer's standard, and whether the document number format is correct for that country and issue year.

What I would not do is challenge the customer directly. If it is a forgery, confronting them tips them off and may prompt them to withdraw before anything is recorded.

I'd document the specific anomalies factually — "text on the surname line is misaligned relative to the field boundary" rather than "document looks fake" — and escalate immediately. A suspected forged document may itself require a suspicious activity report, which isn't my decision. I'd also not return the document until instructed.

16A utility bill is dated 14 months ago and policy requires documents within three months. The customer says nothing has changed. Accept it?

No. The three-month rule exists to evidence a current address, and a 14-month-old document simply doesn't do that regardless of what's changed. The customer's assurance isn't verification — that's the whole point of asking for a document.

I'd explain that plainly, and then be helpful about alternatives rather than just refusing. Most people can produce something recent: a bank statement, council tax or tax correspondence, a mortgage or tenancy statement, or a recent government letter. Many firms also accept electronic address verification, which avoids the problem entirely.

If the customer genuinely can't produce anything recent, that's worth understanding — it may indicate they don't actually live at the stated address, or that bills are in someone else's name, which raises its own questions about who controls the property.

If no acceptable evidence exists, I'd escalate for a decision rather than waive the requirement myself. Making exceptions to documentation standards isn't an analyst-level call.

17A customer's ID shows a different surname from their bank records. How do you resolve it?

This is usually innocent, so I'd start by asking. Marriage, divorce, legal name change and transliteration differences all produce it routinely, and in some cultures naming conventions mean documents legitimately differ.

What I'd want is evidence linking the two identities — a marriage certificate, deed poll, decree absolute, or an official document showing both names. That's the key point: I need a documented link, not just an explanation.

What I wouldn't do is update one record to match the other so the discrepancy disappears. That's tempting operationally but it destroys the audit trail and could conceal genuine identity misuse.

The concern would be if no linking document exists, or if the explanation doesn't fit — for example a name change shortly before a large transaction, or a customer unable to say when or why the change occurred. Name changes are sometimes used to distance someone from adverse history, so I'd also re-screen under both names before concluding.

18A certified copy is signed by a certifier whose credentials you cannot verify. What now?

The certification is only worth as much as the certifier, so an unverifiable certifier means the document is effectively uncertified.

I'd first try to verify properly — professional registers for lawyers, notaries or accountants are usually searchable, and many jurisdictions publish them. Sometimes it's simply an unfamiliar overseas professional body rather than a problem.

If I can't confirm they exist or hold the stated position, I'd request re-certification by someone on our approved list. That's a normal, non-accusatory request.

The concern would be a certifier who can't be found at all, or one certifying an implausible volume of documents across unrelated customers — that pattern suggests a facilitator rather than a professional.

I'd document what verification I attempted and the outcome, because "certified copy received" in a file means nothing if nobody checked the certifier. If the pattern looked systematic rather than a one-off, I'd raise it beyond the individual file.

19An electronic verification check returns a partial match on date of birth. How do you handle it?

I'd investigate rather than let the system decide. Partial matches very often come from data entry errors in either our record or the source database — transposed digits, or day and month reversed between date formats.

So I'd first check what we captured against the document itself. If our record says 03/04 and the document says 04/03, that's almost certainly a format issue rather than a discrepancy.

If our data is right and the external source differs, I'd corroborate with a second independent source or a documentary check. One mismatch against one database isn't conclusive; two independent sources agreeing with the customer's document usually is.

What I'd be alert to is a date of birth that differs by years rather than a transposition, or one that shifts the customer across a meaningful threshold. That's less likely to be clerical.

Either way I'd record how the discrepancy was resolved and what evidence supported it, rather than just marking the check passed.

20A customer submits documents that appear to be photographs of a screen rather than the original. Acceptable?

No. Screen photographs defeat most authenticity checks — you lose the security features, the resolution to detect alteration, and any metadata that would help. It's also a well-known route for submitting stolen or edited documents, because the original never has to exist physically.

I'd request proper submission through our approved channel, whether that's original documents, a certified copy, or capture through our verification app, which typically checks liveness and document authenticity together.

Most customers do this innocently — they have a scan on their phone and photograph it because it's quicker. So I'd explain the requirement without implying suspicion.

What would escalate my concern is repeated failure to provide anything else, or documents that only ever exist as screen images. If someone can never produce the original or use the verification tool, I'd start questioning whether they hold the document at all, and I'd escalate rather than keep requesting.

21Document metadata suggests the file was edited in image software before submission. Concern?

It's a flag but not conclusive, and I'd be careful not to overstate it. A great deal of innocent editing happens — scanning apps process images, people crop and rotate, some compress files to meet upload limits. Metadata showing an image editor doesn't prove alteration of content.

So I'd focus on the document itself rather than the metadata alone. I'd examine it closely for the things editing would produce: inconsistent fonts or spacing, mismatched background texture around key fields, misalignment, or resolution differences between sections of the same image.

I'd also cross-check the content against other sources — does the address match the utility bill, does the name match the registry, does the number format look right.

If the content checks out and the anomalies are consistent with routine processing, I'd note it and proceed. If I find substantive inconsistencies alongside the metadata, that combination is much stronger, and I'd request an alternative document and escalate.

22A liveness check fails twice but the customer insists they are present. What do you do?

I wouldn't override it. Manually passing a failed control is exactly the kind of workaround that appears in enforcement findings, and the control exists specifically to stop someone using a photograph, a recording, or a deepfake.

That said, repeated failures are often technical — poor lighting, an old device, a cracked camera, or a poor connection. So I'd treat it as a support issue first: suggest better lighting, a different device, or trying again through a different channel.

If it still fails, I'd offer an alternative verification route that our policy permits — in-branch verification, a certified document route, or an approved video call with a trained colleague. The aim is to verify the person properly, not to find a way around the check.

What would concern me is refusal to attempt any alternative, or an insistence that we simply accept the documents. Someone genuinely present usually cooperates with another attempt. Persistent avoidance of any live verification is an impersonation indicator, and I'd escalate.

23A corporate customer's certificate of incorporation does not match the registry record for company number. How do you proceed?

A mismatch on a unique identifier is serious, because the company number is the one field that shouldn't vary. A name might be recorded differently or an address might be out of date, but the number either matches the registry or the document is wrong.

I'd go directly to the registry as the authoritative source and pull the record myself rather than relying on what was provided. I'd check whether the number belongs to a different company entirely, whether it doesn't exist, and whether the company as named exists under a different number.

There are innocent possibilities — a redomiciliation, a re-registration, or a typo on a covering document. So I'd ask the customer to explain and provide the original certificate.

But a certificate showing a number that belongs to another entity, or none at all, points strongly to a falsified document. I'd escalate before proceeding, and I would not onboard while the identity of the legal entity itself is unresolved.

24A customer provides all documents instantly and they are unusually clean and consistent. Should that reassure you?

Not automatically, and this is a subtle point. We're conditioned to see chasing documents as the difficult path, so a perfect submission feels like a good outcome. But professionally prepared fraud looks exactly like this — complete, consistent and immediate — whereas genuine customers often send the wrong thing first.

I wouldn't treat it as suspicious either, because organised customers exist, and corporate clients with a compliance function routinely submit complete packs.

What I'd do is apply exactly the same verification rigour I would to a messy file — verify against independent sources rather than checking internal consistency. A fabricated set is internally consistent by design; what it usually can't survive is checking against a registry, an electronic verification source, or the issuing authority.

So the answer is that presentation quality shouldn't influence verification depth at all. I'd note the observation only if other indicators emerged alongside it.

25A translated document differs materially from what you can read in the original. What do you do?

I'd stop relying on the provided translation and obtain an independent certified one. If I can see a material divergence with limited language ability, there may well be more I can't see.

I'd be specific about what differs — a different name, a different date, different amounts, or a clause missing entirely — because the nature of the difference matters. A stylistic difference is unremarkable; a different figure or party is not.

There are innocent explanations: a poor machine translation, or a translator summarising rather than translating precisely. So I wouldn't assume deception immediately.

But a translation that materially misstates the content is a significant concern, particularly if the divergence happens to favour the customer — for example understating a shareholding or omitting a party. That pattern suggests it wasn't accidental.

I'd document the specific differences, obtain the independent translation, and escalate if the certified version confirms the original said something materially different from what was submitted.

26The registry shows the company was incorporated three weeks ago, but the customer claims ten years of trading. How do you reconcile?

I'd ask directly, because there are common legitimate explanations. Businesses restructure, redomicile, form new holding entities, or incorporate a previously unincorporated partnership or sole trade. Ten years of trading through a predecessor entity is entirely normal.

What I'd want is evidence of the link: the predecessor's registration and accounts, evidence of the transfer of business, continuity of directors or owners, and ideally trading records spanning both. If the ten years is real, that documentation exists.

The concern is the alternative — a newly created shell being presented with a borrowed history to justify expected transaction volumes it has no basis for. That's why the claim matters practically: it's usually made to support high expected activity.

So I'd also test the claim against the numbers. If they're projecting turnover consistent with a decade-old business, I'd want accounts evidencing that, not just an assertion. Without a documented link to a genuine predecessor, I'd treat it as a new entity and escalate the inconsistency.

27A customer's proof of address is a bank statement from a bank you cannot identify. What now?

I'd verify the institution before considering the document. If the bank doesn't exist or isn't licensed, the statement is worthless regardless of how convincing it looks.

Most regulators publish registers of licensed institutions, so I'd check the relevant jurisdiction's register. It may simply be a small regional or overseas bank I don't recognise, which is entirely legitimate.

What concerns me is an institution that doesn't appear on any register, or one that appears only on its own website with no regulatory footprint. Unlicensed or fictitious institutions on documents are a known indicator, and statements from them are trivially fabricated.

If the bank verifies as genuine and licensed, I'd assess the statement normally — is it within date, does the name and address match, does it look consistent with that bank's format.

If it can't be verified, I'd request an alternative document from a source I can confirm, and escalate if the customer can only ever produce documents from unverifiable institutions.

28You notice the same certifier has certified documents for a large number of unrelated customers. Significant?

Potentially, and it's the kind of thing only visible when you look across files rather than within one. A single file gives no signal at all.

There are innocent explanations. A high-volume notary or a firm serving a particular community will certify many documents legitimately, and if we have a large customer base from one region, seeing the same names is unsurprising.

What would make it concerning is the pattern around it — customers who are otherwise unconnected but share the certifier, similar application profiles, applications clustered in time, or the certifier appearing on files that later showed problems. That combination suggests a facilitator introducing customers, potentially with fabricated documentation.

I wouldn't reach a conclusion from my own files alone. I'd raise it so it can be reviewed across the customer base properly, since that's the only level at which the question can be answered.

If the certifier turned out to be unverifiable as well, that would move it from a pattern worth noting to a clear escalation.

29An expired ID is the only document a long-standing customer can provide during periodic review. Accept it?

No — an expired document doesn't evidence current identity, and length of relationship doesn't change that. If anything, a customer we've held for years is one where refreshed identification matters, because a lot can change over that period.

But I'd handle it as a service problem rather than a compliance confrontation. Most people simply haven't renewed a passport they don't currently use. I'd explain the requirement, set out the acceptable alternatives — driving licence, national ID, or electronic verification where policy allows — and give reasonable time.

Electronic verification often solves this cleanly for established customers with a strong data footprint.

If they genuinely can't produce anything valid, I'd follow the firm's process for that situation, which typically involves escalation and may lead to restrictions rather than immediate exit.

What I wouldn't do is roll the review forward on the expired document to avoid the friction. That's how firms end up with large populations of unverified long-standing customers.

30A director's ID appears genuine but the photograph does not resemble the person on the video call. What do you do?

I'd stop the process and escalate. This is a possible impersonation, which is more serious than a document problem, and it's not something I should try to resolve conversationally.

I specifically would not say "you don't look like your photo" and invite an explanation. If it's impersonation, that alerts them, and they'll likely disconnect and try elsewhere with a better-matched person.

Instead I'd bring the call to a natural close — saying I need to complete some checks and will follow up — and document precisely what I observed. Factual description matters here: differences in apparent age, facial structure, or distinguishing features, rather than "didn't look like him."

I'd preserve any recording if our process permits, since that's evidence.

Then escalate immediately. Photographs do age and image quality varies, so this may be innocent — but that assessment should be made by someone with the authority and tools to check properly, not by me deciding on a video call.

Corporate onboarding (Q31–44)

31A newly incorporated company applies for an account and expects very high turnover immediately. What do you check?

New companies are legitimate customers and I wouldn't treat incorporation date alone as a problem. What I'd focus on is whether there's substance behind the projected turnover, because the projection is what our limits and monitoring will be built on.

I'd look for evidence the business is real and capable of that volume: signed contracts or purchase orders, premises, staff or payroll arrangements, a supply chain, and the founders' background. A genuine business scaling quickly usually has a predecessor entity, an established parent, or founders with a track record in the sector — and can evidence it.

I'd also ask where the working capital is coming from, since a new company transacting heavily needs funding from somewhere.

The concern is a company with no contracts, no premises, no staff and no funding source, projecting substantial turnover. That's the profile of an entity created to move funds rather than trade. In that case I'd set limits to what's evidenced and escalate rather than accommodate the projection.

32A company's registered address is shared with 400 other companies. Problem?

Not on its own, and I'd be careful not to treat it as one. Corporate service providers, accountants and virtual office providers legitimately serve as registered addresses for hundreds of companies. It's normal practice, particularly for small businesses and holding entities.

What I'd want to establish is where the business actually operates from — its trading address, premises, or where its people work. A registered address is an administrative service; an operating address tells me whether the business exists physically.

So I'd ask, and look for corroboration: a lease, utility arrangements, a website with contact details, or staff locations.

It becomes meaningful in combination. A shared registered address, plus no identifiable operating premises, plus nominee-looking directors, plus a recently incorporated entity, is a shell company profile. Any one of those alone is unremarkable.

So I'd record it as one input to the risk assessment and focus my attention on substance rather than on the address itself.

33A company's stated business is consultancy, but its expected transactions are large international goods payments. How do you handle it?

This mismatch is one of the clearer red flags, because a consultancy sells time and expertise — it shouldn't be paying for shipments of goods.

I'd raise it directly and ask them to explain. There are possible answers: they may procure on behalf of clients, act as an agent, or have a trading arm operating through the same entity. Group structures sometimes route payments oddly for legitimate reasons.

What I'd want is documentation matching the explanation — agency agreements, client contracts authorising procurement, invoices showing the arrangement, or evidence of the trading activity.

The concern is that this pattern is characteristic of trade-based laundering and of shells used to justify international payments. A consultancy label is convenient precisely because it's vague and low-documentation.

If the explanation isn't evidenced, or the customer adjusts their description of the business once questioned, I'd escalate. I wouldn't simply update the stated business activity to match the expected payments, which is the easy operational fix and exactly the wrong one.

34A corporate applicant's directors are all resident in a jurisdiction unrelated to its operations or market. Concern?

Worth understanding rather than assuming. There are legitimate reasons — investor requirements, group management structures, tax residence planning, or a founder who has relocated. International businesses often have geographically dispersed boards.

What I'd probe is whether the directors actually direct. I'd ask about their role, their involvement in decisions, and their connection to the business. A genuine director can describe the company's operations and their part in governance; a nominee typically cannot go beyond formalities.

I'd also check whether they hold directorships across a large number of unrelated companies, which would point strongly to a professional nominee service.

The concern is a board with no connection to the business, no evident involvement, and no explanation — because then the real controlling mind sits outside the documented structure, and I haven't identified who actually runs the company.

If it looks like a nominee arrangement, I'd look behind it to identify who instructs them, and escalate if that can't be established.

35The company has had three changes of ownership in the last year. What does that suggest?

It's unusual enough to warrant proper explanation. Companies do change hands legitimately — investment activity, restructuring, founder exits, or a business being built up for sale — but three times in a year is a lot for a genuine trading entity.

I'd establish who owns and controls it now, then trace what happened. Specifically: who the previous owners were, whether consideration was actually paid, whether the price reflected value, and whether the business itself changed alongside the ownership.

Transfers at nominal value between apparently unrelated parties would concern me most, because that suggests the ownership on paper isn't the real position.

The pattern to watch for is a corporate shell being passed between holders to break the connection between the current entity and its history — sometimes to distance it from adverse findings, sometimes to obscure who actually controls it.

I'd also re-screen all parties in the chain, not just the current owner, and escalate if the transfers can't be explained commercially.

36A charity applies for an account and expects frequent transfers to a high-risk region. How do you approach it?

Carefully and without prejudging, because this is exactly where de-risking causes real harm. Legitimate humanitarian organisations work in conflict zones and high-risk regions by definition, and excluding them from banking has genuine consequences.

I'd verify the organisation properly: registration with the relevant charity regulator, governance structure, trustees, published accounts, and its stated programmes.

Then I'd focus on how funds are actually controlled at the far end — who the local partners are, how distributions are authorised and accounted for, whether funds go to named organisations or individuals, and what oversight exists over spending in-country.

The genuine risk with charities isn't usually the charity itself; it's diversion at the delivery stage, which is why terrorist financing controls focus there.

So my recommendation would be enhanced due diligence with clear expectations on beneficiary transparency and reporting, rather than declining. I'd also screen trustees and known local partners, and set monitoring around destination and pattern rather than value alone.

37A money service business applies for a corporate account. What additional diligence applies?

MSBs are treated as higher risk because you're effectively providing infrastructure to their customers, whom you can't see. Their controls become your exposure.

First I'd verify licensing and registration with the relevant regulator, and confirm it's current — operating unlicensed is both a regulatory and a risk problem.

Then I'd assess their AML programme in real terms: do they have a compliance function, what screening and monitoring do they run, who is their MLRO, and have they had regulatory findings. Many firms use a structured questionnaire for this.

I'd want to understand their business specifically — customer base, corridors served, average and maximum transaction sizes, and whether they serve other MSBs, because nesting compounds the invisibility.

Cash-intensive corridors and remittance to high-risk regions raise it further.

This would be a senior-approval relationship with enhanced monitoring, periodic reassessment of their controls, and clear expectations. If their programme was weak or unverifiable, I'd recommend against onboarding regardless of the commercial opportunity.

38A company provides audited accounts showing revenue far below the expected account activity. What do you do?

I'd query the gap rather than accept either figure. There are legitimate explanations — the accounts may be a year or more old and the business has grown, or this entity may process group revenue while booking only its own margin, or the activity may include financing flows rather than trading revenue.

I'd ask which it is and seek evidence: management accounts or interim figures, contracts supporting the growth, or an explanation of the group flows with supporting structure information.

The distinction matters. Revenue of two million with expected throughput of two million is consistent; revenue of two million with expected throughput of fifty million needs a clear reason.

An unexplained gap of that scale is a classic indicator that the account is intended to move funds unrelated to the stated business.

If the explanation is evidenced, I'd set limits accordingly and monitor against the explained pattern. If it isn't, I'd escalate rather than set limits to accommodate a projection that the financials don't support.

39A corporate customer wants multiple accounts in different currencies with no clear business reason. Acceptable?

Multi-currency arrangements are routine for international businesses, so the request itself is unremarkable. What matters is whether the currencies correspond to the customer's actual trading.

I'd ask which markets they buy from and sell to, and match that against the currencies requested. A UK importer sourcing from Europe and Asia needing euro and dollar accounts makes complete sense.

What would prompt questions is currencies with no connection to their stated business — an account in a currency for a market they don't operate in, or a spread of currencies far wider than their trading footprint.

That can indicate the accounts are intended for third-party flows, or for layering across currencies to break the trail.

So my answer would be that I'd approve what the business explains and evidences, and question the rest. I'd rather open three accounts that match documented trading than six on a general statement about international expansion, and I'd revisit if genuine activity develops.

40The company's website has no substance — stock images, no contact details, recently registered domain. Significant?

It supports a picture rather than proving anything. Plenty of legitimate small businesses have poor websites, or none at all, and judging a company by its web presence would exclude many genuine customers.

What makes it relevant is the combination with other substance indicators. I'd look for evidence the business physically exists and trades: premises or a lease, staff or payroll, suppliers and customers, contracts, filed accounts, VAT or tax registration, and a trading history.

A thin website alongside all of those is just a business that hasn't invested in marketing. A thin website alongside no premises, no staff, no accounts and a recently incorporated entity is a shell profile.

I'd note the domain registration date specifically, because a domain created days before the application, presenting a business claiming to be established, is a meaningful inconsistency.

So I'd treat it as one data point, focus on verifiable substance, and escalate only if the wider picture shows a company with no evidence of real operations.

41A company applies whose parent is in a jurisdiction on the FATF grey list. How does that affect your approach?

It raises geographic risk and will typically trigger enhanced due diligence, but it doesn't prohibit the relationship. Grey-listed jurisdictions have committed to addressing deficiencies — it isn't the same as a prohibition, and treating it that way is de-risking.

Practically, I'd strengthen the ownership work. Registry quality and transparency are often weaker in those jurisdictions, so I'd rely less on registry output alone and seek corroboration through certified documents, legal confirmations or audited group accounts.

I'd want to understand what the group actually does there — is it operational, a holding entity, or a financing vehicle — and whether funds will flow to or from that jurisdiction.

I'd screen the parent, its owners and directors thoroughly, and check for adverse media in local sources as well as English.

The outcome would be a higher risk rating, enhanced measures including source of funds work, senior approval, and a shorter review cycle — with the reasoning documented so the decision to accept is defensible.

42A customer requests that account correspondence be sent to a third-party address. What do you do?

I'd establish who the third party is and why. There are legitimate reasons — an accountant or company secretary handling administration, a registered office service, or a customer who travels and uses a family address.

What I'd want is the relationship explained and, where it's a professional, evidence of the engagement.

The concern is that correspondence redirection can indicate the account is controlled by someone other than the named holder. If statements and security correspondence go to a third party, the account holder may never see the activity — which is characteristic of both mule accounts and financial abuse of vulnerable customers.

So I'd want confirmation from the account holder themselves that this is their instruction, not the third party's.

I'd also consider what's being redirected. Sending statements to an accountant is different from redirecting security credentials or card correspondence, which I'd question much harder. If the explanation is thin or the customer seems unaware, I'd escalate.

43A corporate applicant is reluctant to provide details on its ultimate parent, saying the information is commercially sensitive. How do you respond?

I'd acknowledge the concern and then be clear that it isn't an exemption. Ownership information is a regulatory requirement, it's held confidentially, and it isn't shared commercially — most sophisticated customers accept that once it's explained.

I'd also offer practical reassurance about how the information is handled and who can access it, since genuine sensitivity usually stems from worry about disclosure rather than an objection in principle.

If reluctance continues, I'd note that this is a common objection but a weak one, because publicly filed structures are usually already disclosed somewhere. A customer resisting disclosure of ownership that's already partly public is a different signal from one protecting genuinely private arrangements.

The bottom line is that I can't complete a file without identifying beneficial ownership. It isn't a field I can leave blank or fill with the immediate parent.

Persistent refusal on ownership is a material risk indicator in its own right, and I'd document it precisely and escalate rather than proceed.

44The applicant is a subsidiary of a listed company, and the RM says no ownership work is needed. Correct?

Not as stated, and this is a common misunderstanding worth handling carefully.

Reduced ownership diligence generally applies to companies listed on recognised regulated exchanges with disclosure obligations, on the basis that ownership is already public and supervised. That exemption attaches to the listed entity itself.

An unlisted subsidiary isn't automatically covered. Our policy will specify whether it extends to majority-owned subsidiaries and on what conditions, and I'd apply the policy as written rather than the RM's summary.

Practically I'd verify three things: that the parent is genuinely listed on a recognised exchange, that the exchange qualifies under our policy, and that the group relationship is evidenced rather than asserted — through filings, annual reports or group structure documentation.

I'd still identify and screen the subsidiary's directors and controllers, since the exemption concerns ownership tracing, not the whole file.

I'd explain that to the RM constructively — it's usually a short piece of work, not an obstacle.

Ownership and structures (Q45–50)

45Ownership traces through four companies across three jurisdictions and ends at a foundation with no public register. What now?

When ownership tracing hits a wall, I'd shift from ownership to control, because the regulatory question is who ultimately owns or controls the customer.

For a foundation that means identifying the founder, the council or board members, anyone with power to appoint or remove them, and who can direct distributions. Foundations separate legal ownership from benefit deliberately, so the control questions are where the answer lies.

I'd request the constitutional documents — charter, by-laws, and any regulations governing distributions — plus confirmation from the registered agent or a legal opinion from local counsel.

I'd document precisely which elements were independently verified and which rest on customer-provided documents, because that distinction matters to anyone reviewing the file later.

Then I'd assess whether the overall structure has a coherent purpose. A wealth-holding foundation for a family is normal; the same structure holding an operating trading business is harder to explain.

If control genuinely can't be established, I'd escalate — that's a substantive finding, not a gap to waive.

46Three individuals each hold 20 percent and the remaining 40 percent is held by a company with unknown owners. What do you do?

The unknown 40 percent is the priority, and I'd resist the temptation to record the three identified individuals and treat the file as substantially complete.

The reason is that the 40 percent block could contain a single controlling owner above threshold, or one of the three known individuals holding additional shares indirectly — which would aggregate them above the threshold and change their status entirely.

So I'd trace that entity's ownership through registries, request its structure from the customer, and aggregate holdings across all chains rather than treating each line separately.

I'd also look at control alongside ownership — whether the corporate shareholder has board appointment rights or veto powers disproportionate to its 40 percent.

If the corporate shareholder's ownership can't be established, that's the finding to escalate, and I'd be explicit that 40 percent of the customer's ownership is unidentified. That's materially different from saying three beneficial owners were identified.

47No individual exceeds the ownership threshold and the customer offers the CEO as the beneficial owner. Accept?

Only after I've genuinely exhausted the prior steps, and I'd want the file to show that clearly.

The senior managing official route is a legitimate last resort, but it's frequently misused as a shortcut when ownership tracing is difficult. Regulators look specifically at whether the earlier tests were actually applied.

So first I'd confirm that no individual reaches the threshold, including through aggregated indirect holdings — which requires calculating through the chain, not just reading the shareholder register.

Then I'd apply control tests: voting rights that differ from shareholding, rights to appoint or remove directors, veto rights, shareholder agreements, or funding dependence that confers influence. Dispersed ownership with concentrated control is common, and the control test catches it.

Only if both fail would I record the senior managing official, and I'd document each step and its outcome.

I'd also note that this position increases risk — we haven't identified a beneficial owner, we've substituted an officer — so it should be reflected in the rating.

48A shareholder holds 45 percent but has veto rights over all major decisions. How do you treat them?

As a beneficial owner through control, not as a shareholder below threshold. Veto rights over all major decisions are effective control in substance — nothing significant happens without their agreement, which is a stronger position than many majority holders enjoy.

Most frameworks define beneficial ownership as ownership or control precisely to capture this, so treating them as out of scope on the 45 percent figure would be a straightforward error.

I'd identify the source of those rights — shareholder agreement, articles, or a class of shares with enhanced voting — and get that documentation rather than relying on a verbal description, since the scope of the veto matters.

I'd then treat them fully as a beneficial owner: identification, verification, screening, and inclusion in the risk assessment.

I'd also look at whether the arrangement itself makes sense. Sometimes a sub-threshold holding paired with control rights is deliberately structured to stay below reporting thresholds, and that intent is worth noting.

49A trust customer names a wide discretionary beneficiary class with no individuals identified. What is your approach?

Discretionary trusts with a defined class rather than named beneficiaries are entirely normal, particularly for family succession planning, so I wouldn't treat it as inherently evasive.

I'd document the class as it's defined in the trust deed — for example the settlor's descendants — and then focus diligence where control actually sits: the settlor, the trustees, and the protector if there is one. Those are the parties who can influence what happens to the assets.

I'd also establish how distributions are decided in practice, whether any have been made, and to whom. A trust with a broad class that has only ever distributed to one person is functionally narrower than it appears.

I'd request the trust deed and any letter of wishes, since the letter often reveals the real intent.

The concern would be a class drawn so widely that it's meaningless, or a structure that appears designed specifically to prevent anyone being identified as benefiting. That I'd escalate.

50The trustee is a professional firm and the protector is a family member with power to remove trustees. Who matters most?

Both need to be identified and screened, but I'd focus attention on the protector, because that's where real control sits.

A professional trustee administers the trust and has fiduciary duties, but if a protector can remove and replace them, the trustee's independence is constrained in practice. Trustees who can be dismissed tend not to refuse the person who can dismiss them.

So I'd treat the protector as a controlling party: full identification, verification, screening for sanctions, PEP status and adverse media, and inclusion in the risk assessment.

I'd also want to see the specific powers in the trust deed rather than a summary, because protector powers vary widely — some are limited to consent on specific matters, others amount to effective control over the whole arrangement.

And I'd note the relationship: a family member protector with removal powers over a professional trustee often means the family retains control while the structure presents as independently administered.

51A company's shares were transferred to a new owner for a nominal sum. Concern?

Yes, this is one I'd want explained properly. Shares in a trading business have value, so a transfer for a nominal amount means either the business is worthless, or the transfer isn't a genuine sale.

There are legitimate explanations. Transfers within a family, between group entities, to or from a nominee under a declared arrangement, or as part of a restructure often happen at nominal value. Loss-making businesses genuinely change hands for a pound.

So I'd ask what the commercial basis was, and whether the parties are connected. A family transfer at nominal value is unremarkable; the same transfer between apparently unrelated parties is not.

What concerns me is a nominal transfer between strangers, particularly of a business with real assets or revenue. That usually means the registered owner isn't the real owner — a nominee arrangement without the disclosure.

I'd also re-screen both parties and check whether the previous owner still appears involved operationally, since that would confirm the transfer was cosmetic.

52A director appears as an officer of 180 unrelated companies. What does that tell you?

Almost certainly that they're a professional nominee or a corporate service provider director rather than someone genuinely directing 180 businesses. Nobody can meaningfully govern that many companies.

That doesn't make it unlawful — nominee directorships are legal in many jurisdictions and corporate service providers operate openly. But it changes what the appointment tells me: this person is not the controlling mind.

So the practical consequence is that identifying them doesn't answer the question of who runs the company. I'd need to look behind the appointment and establish who instructs them — usually the beneficial owner, or an intermediary acting for them.

I'd ask the customer directly who gives the director instructions and how decisions are actually made, and look for a services agreement or nominee declaration.

What would escalate it is a customer presenting this director as the genuine controlling party, or being unable to say who actually directs the business. At that point I haven't identified control at all, and I'd escalate rather than record the nominee as the answer.

53The customer's structure chart differs from the registry in two jurisdictions. How do you handle it?

I'd reconcile rather than pick one as correct, because both can be wrong in different ways. Registries lag — filings take time and some jurisdictions update slowly. Customer charts are often prepared for internal or tax purposes and may show intended rather than current structure.

So I'd identify exactly what differs. A missing intermediate entity is a different problem from a different ultimate owner. The materiality of the discrepancy determines how hard I push.

I'd ask the customer to explain each difference and provide evidence — share transfer documents, board resolutions, filing receipts showing a change submitted but not yet reflected.

Filing receipts are useful because they demonstrate the customer's version is in process rather than aspirational.

What I'd document is how each discrepancy was resolved and on what evidence, not just the final position. And I'd be wary if the customer's chart consistently understates ownership concentration compared with the registry, since that pattern suggests the differences aren't accidental.

54A UBO is identified but refuses to provide identification documents. What now?

The relationship can't be completed. Identifying a beneficial owner is only half the requirement — we also have to verify them, and a name without verification doesn't satisfy anything.

I'd work through the customer rather than approaching the UBO directly, since our relationship is with the entity. I'd explain that this is a regulatory requirement, that it applies to every beneficial owner, and that the documents are handled confidentially.

Sometimes the objection is practical rather than principled — the UBO is overseas, elderly, or hard to reach. In that case I'd offer alternatives: certified copies, electronic verification, or verification through a regulated intermediary where policy allows.

If the refusal is genuinely a refusal, that's a significant indicator. Legitimate owners of legitimate businesses provide identification routinely; someone who won't usually has a reason.

I'd document exactly what was requested, when, and the response given, then escalate. I wouldn't complete the file with the UBO identified but unverified, which is a common way incomplete files pass through.

55Two customers, apparently unrelated, share the same beneficial owner. Does that matter?

Yes, materially, and it's the kind of thing that only surfaces if someone looks across files rather than within them.

The first issue is aggregate exposure. Each relationship may look modest alone, but the true exposure to that individual is the combined position — which matters for risk rating, limits, and if they're ever sanctioned or become a PEP.

The second issue is why the businesses are separate. There are good reasons — different sectors, different investors, liability separation. But deliberate fragmentation across entities to keep each below thresholds is a recognised technique.

So I'd link the relationships in our systems, review the combined activity, and check whether funds move between them. Circular flows between commonly owned entities with no commercial purpose would concern me significantly.

I'd also make sure the risk assessment reflects the connected position rather than treating each as standalone, and flag it so both files carry the linkage rather than one analyst knowing and the other not.

56The structure involves bearer shares in a jurisdiction that still permits them. How do you proceed?

Bearer shares are a serious problem because ownership transfers by physically handing over the certificate — there's no register, and ownership can change without any record at all.

Most jurisdictions have abolished or immobilised them precisely for that reason, so where they persist they attract high scrutiny.

I'd require evidence of immobilisation: certificates held by an approved custodian, a registered agent, or converted to registered form, with documentation identifying the current holder. Some jurisdictions mandate this, and evidence of compliance is what I'd want to see.

Without that, I can't establish ownership in any meaningful sense — and importantly, I can't establish it will remain the same tomorrow.

I'd also ask why bearer shares are being used at all, since legitimate businesses have largely moved away from them. The absence of a good answer is itself informative.

If immobilisation can't be evidenced, I'd escalate with a clear recommendation not to proceed, rather than recording an owner I know may change unrecorded.

57A structure is far more complex than the business appears to justify. What do you do?

I'd ask the customer to explain the rationale, and listen carefully to whether the answer holds together.

Complexity often has good reasons — tax treaty access, investor requirements, ring-fencing liability, succession planning, regulatory licensing in different markets, or historical acquisitions never tidied up. Businesses accumulate structure over time.

What I'd test is whether the explanation matches the structure. If they cite investor requirements, are there investors? If tax planning, does the structure route through jurisdictions with relevant treaties? A genuine rationale is specific and checkable.

The concern is complexity the customer can't explain, or an explanation that doesn't fit — entities in jurisdictions with no treaty benefit, no operations, and no connection to their markets. Layers whose only apparent function is distance between the business and its owner.

I'd also weigh proportionality. A multinational with fifteen entities is normal; a single-site business with the same structure is not.

If it can't be explained, I'd escalate — unexplained complexity is a finding, not just an inconvenience.

58After extensive work you still cannot identify the UBO. What is your recommendation?

I'd escalate with a clear recommendation not to proceed, and a full record of what was attempted.

The record matters as much as the conclusion. I'd set out which registries were searched, what documents were requested and received, what the customer provided or refused, where the chain broke, and which control tests were applied and failed. Someone reviewing it should see the work, not just the outcome.

I'd be explicit that this is a substantive risk finding rather than an administrative gap. Not knowing who ultimately owns or controls a customer is precisely the condition AML rules exist to prevent, and proceeding means accepting a relationship where we cannot say who benefits.

I'd also note whether the obstacle was structural — an opaque jurisdiction with no register — or behavioural, meaning the customer wouldn't provide it. Those carry different weight, and customer refusal is the more concerning.

The decision to accept or decline sits above me. But I wouldn't sign the file as complete, and I'd make sure my recommendation is documented.

Screening situations (Q59–72)

59A customer matches a sanctions entry on name only, with no other identifiers available on either side. What do you do?

I'd escalate to the sanctions team and hold everything pending resolution. In sanctions, insufficient data to discount is not the same as a false positive — an unresolved match stays unresolved, and the default is to hold.

Before escalating I'd exhaust what I can gather. On our side: is there a date of birth, nationality, address, occupation or identification number we hold but didn't feed into screening? Often the data exists in the file but not in the screening record. On the list side: does the entry carry aliases, place of birth, or associated entities that might help.

If I can build a discriminator from that, the match may resolve properly.

What I would not do is discount it on the basis that the name is common, or that the customer seems unlikely to be a designated person. That reasoning has appeared in enforcement cases.

I'd document precisely what identifiers were and weren't available, so the sanctions team can see the gap rather than re-doing the search.

60A payment is urgent, the client is threatening to leave, and the sanctions hit is unresolved. What is your position?

The payment stays held. That's not negotiable, and I'd say so plainly.

Sanctions breaches carry strict liability in most regimes — intent doesn't help, and commercial pressure certainly doesn't. Releasing an unresolved match could expose the firm to severe penalties and me personally in some jurisdictions.

What I would do is treat the urgency seriously in the right way: escalate immediately and flag it as time-critical so the sanctions team can prioritise resolution. Speed of decision is something I can help with; the decision itself isn't mine to shortcut.

On the client relationship, that's for the relationship manager to handle, and I'd support them with a clear explanation of what's happening and what's needed. Often the fastest route is obtaining identifying documents from the client that allow the match to be discounted properly.

If pressure continued or someone attempted to release it outside process, I'd escalate that separately — the attempt itself is a compliance concern worth recording.

61An entity is 45 percent owned by a designated person. Can you proceed?

Not on the percentage alone, and I'd refer it to the sanctions team rather than decide.

Under the 50 percent rule the entity isn't automatically blocked at 45 percent. But two things need checking before that conclusion holds.

First, aggregation. If other designated parties hold stakes, they combine — 45 percent plus another designated party's 10 percent puts the entity above the threshold and it becomes blocked even though neither individually exceeds it. I'd map the full ownership for designated parties, not just the one flagged.

Second, control. Some regimes, including the UK, capture control in fact regardless of percentage. A 45 percent holder with veto rights or the power to appoint the board may bring the entity within scope.

I'd also consider whether the structure was arranged specifically to sit below the threshold, which is a known evasion technique.

Given the consequences of getting this wrong, it's a sanctions team decision with legal input, not an analyst call.

62An existing customer appears on a sanctions list published this morning. What happens?

This is time-critical, so the sequence matters. Freeze first, analyse second.

I'd ensure no further transactions are processed on any account held by that customer, and escalate to the sanctions team immediately rather than completing my own verification first. Delay here has direct consequences.

In parallel I'd identify the full exposure: all accounts held by that customer, any entities where they're a beneficial owner or controller, joint accounts, and any pending or in-flight payments that might settle.

The pending payments matter most, because those are the ones that can leave while the analysis is happening.

I'd also check for connected parties — family members or associated entities that may fall within scope through ownership or control.

Then support the reporting obligation, since most regimes require notification to the competent authority within a short defined period.

On customer contact: nothing without guidance. What can be said about a freeze is legally constrained and varies by regime.

63A PEP match shows a date of birth ten years different from your customer, but the source is unverified. Discount it?

Not on that alone. PEP databases are compiled from public sources and their identifiers are frequently incomplete, approximate or simply wrong — a date of birth from an unverified source isn't a reliable discriminator.

I'd look for stronger evidence. Nationality, current occupation, employer and country of residence are usually more decisive. If my customer is a software engineer in Manchester and the entry is a serving minister in another country, that's a clear distinction regardless of dates.

I'd also check the database entry itself — does it cite a source, is the date marked as approximate, are there aliases or alternative dates listed. Well-maintained entries flag their own uncertainty.

Where the ten-year gap is the only differentiator and the source is unverified, I'd treat the match as unresolved and escalate rather than discount.

And I'd document the reasoning either way, because "discounted — date of birth differs" with no note on source reliability is exactly the thin documentation that fails review.

64A customer denies being a PEP but public records show they hold a senior government role. How do you handle it?

I'd verify independently and classify on the evidence, not the declaration.

What I wouldn't do is treat the denial as deception. Many people genuinely don't know the term, or don't think it applies to them — someone on a regulatory board or a state-owned enterprise executive often doesn't consider themselves politically exposed. Self-declaration forms are poorly understood.

So I'd confirm the role through official sources — a government register, the organisation's own site, or credible reporting — and check it's current.

Then I'd go back to the customer and explain what the classification means and why it applies, framing it as a regulatory category rather than an accusation. Most people accept it once they understand it isn't a judgement about them.

If they still disputed a verified role, that's more concerning and I'd document it precisely.

Either way the file records that PEP status was identified through screening despite the declaration — that gap is itself relevant to the risk assessment.

65Screening flags a customer as a PEP, but their role is a junior position at a state-owned enterprise. Correct classification?

Possibly not, and this is where analyst judgement genuinely matters. PEP databases over-capture — they often flag anyone employed by a state entity regardless of seniority.

The regulatory definition turns on prominence: senior executives and those with influence over public resources or decisions. A mid-level engineer at a state utility doesn't meet that, whereas a board member does.

So I'd assess the actual role against our policy definition, which should set out where the threshold sits. If it doesn't, that's a policy gap worth raising, because otherwise treatment varies by analyst.

I'd record a reasoned declassification — the role, why it falls below the prominence threshold, and the source confirming it. That documentation is essential; an undocumented declassification looks like someone waving away a hit.

Applying EDD by default to every database flag isn't the safe option either — it wastes resource, creates friction for ordinary customers, and dilutes attention from genuine PEPs.

66Adverse media alleges fraud against your customer, but the only source is an anonymous blog. How much weight?

Limited on its own, but not zero, and I wouldn't simply dismiss it.

An anonymous blog has no editorial standards, no accountability, and can be fabricated by a competitor or someone with a grievance. Acting on it alone would be unfair and could be a data accuracy problem.

So my first step is corroboration. I'd search credible outlets, court and regulatory records, and official sources for anything supporting the allegation. If the claim is real, there's usually a trace somewhere — a filing, a case reference, a mainstream mention.

If corroboration exists, the blog becomes a pointer to something substantive and I'd assess the credible source instead.

If nothing corroborates it, I'd record the finding with a clear note on its unverified single-source status, factor it into the risk assessment as a minor input, and monitor for further reporting.

What I wouldn't do is either escalate on it alone, or delete it as noise — both lose information the file may need later.

67Credible reporting shows your customer was charged with fraud but later acquitted. How do you record it?

I'd record the complete picture — the charge and the acquittal — and make sure the outcome is as prominent as the allegation.

The acquittal substantially reduces the weight. Someone tried and acquitted has been through the process and not been found guilty, and treating that as equivalent to an open investigation would be both unfair and analytically wrong.

That said, I wouldn't erase it. The surrounding circumstances can remain relevant context — what the allegation concerned, whether it related to their current business, whether other parties were convicted. An acquittal on a technicality in a case where associates were convicted reads differently from a clear exoneration.

So I'd note the nature of the acquittal where that's available.

Practically this probably doesn't drive a rating increase on its own, though it may support enhanced attention if other factors exist.

The documentation point matters most: a file recording "adverse media — fraud charge" without the acquittal is misleading, and would prejudice every future reviewer.

68Adverse media exists only in a language nobody on the team reads. What do you do?

I wouldn't close it as unreviewable, which is the tempting shortcut and a genuine control failure.

Significant reporting often exists only in local-language media, particularly for customers in markets where English coverage is thin. Recording "no adverse media found" when material exists but wasn't read is worse than not searching at all, because it creates false assurance.

Practically I'd use machine translation first to establish whether the content is material — that's usually enough to tell whether an article concerns financial crime or is entirely unrelated.

If it looks material, I'd escalate for proper translation: a colleague who reads the language, the firm's research function, or an external translation service.

I'd document what was found, how it was translated, and the limitations of that translation.

If this recurs for a particular market, I'd raise it as a coverage gap rather than solving it case by case — that's a resourcing and tooling issue for the programme.

69Your screening returns 300 results for a very common name. How do you work it?

Systematically rather than exhaustively, and I'd document the method as much as the conclusion.

Reading 300 articles individually isn't feasible or necessary. I'd filter first — by risk category, so I'm looking at financial crime, corruption and regulatory matters rather than all negative coverage, and by jurisdiction and date to focus where my customer actually has a footprint.

Then I'd use identifiers to eliminate in bulk. If my customer is 34 and based in one country, results concerning a 70-year-old in another can be discounted as a group rather than individually.

Next I'd prioritise the highest-severity categories, since a single money laundering investigation matters more than fifty minor mentions.

Crucially, I'd record how I narrowed it: what filters were applied, what was eliminated and why, and what was reviewed in detail. A note saying "300 results reviewed, no concerns" is not credible; a note showing the method is.

If the volume made it genuinely unworkable, I'd flag the data quality issue driving it.

70You find adverse media on a beneficial owner rather than the account holder. Does it matter?

Materially, yes — arguably more than if it concerned a director or signatory.

The beneficial owner controls the entity and benefits from its funds. If they're under investigation for fraud or corruption, that risk attaches directly to money flowing through our account, regardless of whose name is on it.

So I'd assess it exactly as I would for a direct customer — credibility of the source, nature and stage of the matter, materiality, and recency.

Then I'd consider what it means for the relationship specifically. Is the alleged conduct connected to this business or entirely separate? Could proceeds plausibly flow through this account? Does it change what the entity's funds might represent?

I'd raise the risk rating on the entity, since risk assessment should reflect the people behind it and not just the corporate profile.

And I'd make sure the finding is recorded on the entity's file, not only against the individual — otherwise the next reviewer of the corporate relationship won't see it.

71A whitelisted false positive from last year now returns against new reporting. How should the system have handled it?

This is a governance failure rather than a screening failure, and it's a good illustration of why whitelists are risky.

A whitelist records that a specific match was assessed and discounted. The flaw is that it suppresses future matches on that name — including genuinely new material about a genuinely different situation.

The system should have had expiry and revalidation built in, so entries lapse after a defined period and are reassessed rather than persisting indefinitely. Better still, whitelisting should be scoped to the specific matched record rather than the name broadly, so new reporting still surfaces.

On the case itself, I'd assess the new material entirely on its merits, ignoring the previous discount — last year's assessment addressed last year's article.

Then I'd raise the governance gap, because if it happened here it's suppressing hits elsewhere. That's a control weakness affecting the whole population, and it's worth far more than resolving one case.

72A relationship manager insists a screening hit is a false positive because he knows the client personally. Sufficient?

No. Personal assurance isn't evidence, and a file recording "discounted — RM confirmed not the same person" would fail any review.

I'd explain that constructively rather than as a refusal. The RM's knowledge is genuinely useful — they may know the client's date of birth, nationality, career history or the fact they've never worked in the relevant sector. That's exactly what I need.

So I'd turn the assurance into evidence: ask what specifically distinguishes the client from the listed person, then obtain documentation supporting it. Often the RM can get identifying documents from the client quickly, which resolves it properly in a day.

What I'd document is the identifiers compared and the source — not the RM's opinion.

If the RM pushed back on principle, I'd hold the line and escalate. And if the hit were a sanctions match rather than PEP or adverse media, I'd be firmer still, because there the consequences of an unevidenced discount are severe.

EDD and source of wealth (Q73–84)

73A PEP states their wealth comes from a family business. What evidence would satisfy you?

"Family business" is a narrative, not evidence, and accepting it as stated is the single most cited weakness in PEP files. What I need is corroboration that the business existed, that they held a stake, and that it generated wealth at the scale claimed.

Specifically: company registration and shareholding records showing their interest and how long they held it; audited accounts or filings demonstrating profitability at the relevant scale; dividend records, or sale and purchase documentation if they exited; and tax filings where available.

I'd also test consistency. If they claim wealth from a business, does the timeline fit their public career, and does the scale match? A business turning over a modest amount doesn't explain substantial assets.

For a PEP I'd cross-check against public asset declarations where the jurisdiction requires them, since a discrepancy there is highly significant.

What I'd avoid is accepting a thick file of documents that don't actually evidence the wealth. Volume isn't corroboration — I'd want to be able to point at which document supports which component.

74A customer's declared assets substantially exceed what their known career could plausibly generate. What do you do?

The gap becomes the central question of the file, and I'd frame it that way rather than treating it as one factor among many.

I'd first make sure my assumption is sound. Career income isn't the only legitimate source — inheritance, marriage, business ownership alongside employment, early investment, property appreciation, or a successful exit all explain wealth beyond salary. So I'd ask what accounts for the difference before concluding anything.

Then I'd seek evidence for whatever's claimed, proportionate to the size of the gap. A modest difference explained by property might need little; a very large unexplained sum needs substantive documentation.

What concerns me is an explanation that's vague, shifts under questioning, or can't be evidenced at all — particularly for a PEP or someone in a position with corruption exposure, where unexplained wealth is the classic indicator.

If the gap remains unexplained after reasonable enquiry, I'd escalate toward a suspicious activity report rather than accepting a plausible-sounding story, and document precisely what remained unevidenced.

75Source of wealth is stated as inheritance but no documentation is available. How do you proceed?

I'd look for what does exist rather than accepting that nothing is available, because inheritance usually leaves a documentary trail somewhere.

Options include probate records, which are public in many jurisdictions; a grant of representation; extracts from the will; correspondence from the executor or estate solicitor; evidence of the deceased's assets such as property records; and the bank transfer itself showing funds arriving from an estate account.

Even where the estate was administered privately, something usually exists.

I'd also assess plausibility. Does the timing fit, was the deceased's wealth consistent with the amount, is the relationship to the deceased evidenced?

If genuinely nothing can be obtained — an old inheritance in a jurisdiction with no records — I'd document exactly what was sought and why it's unavailable, assess whether the unevidenced portion is material to the overall picture, and escalate rather than record the file as satisfied.

The distinction matters: "inheritance, evidence unavailable, escalated" is defensible. "Source of wealth: inheritance" is not.

76A customer provides a large volume of documents that do not actually evidence the wealth claimed. What is your assessment?

Volume isn't corroboration, and I'd say so directly in my assessment rather than letting a thick file imply completeness.

This is a common pattern — customers or intermediaries submit everything they have, and the file looks substantial. But if the wealth is claimed to come from a business sale and the documents are utility bills, bank statements and old payslips, none of them evidence the sale.

So I'd work component by component. I'd list what the customer claims their wealth comes from, then identify which document evidences each one. Anything unmatched is unevidenced regardless of how much paper surrounds it.

Then I'd go back with a specific request naming exactly what's needed — "share sale agreement and completion statement" rather than "further evidence of source of wealth." Specific requests get better results and are fairer to the customer.

What I'd record is which components are evidenced and which aren't, so the gap is visible. A reviewer should be able to see the reasoning, not a document count.

77An RM says the EDD requests are excessive and losing the client. How do you respond?

I'd take the feedback seriously first, because sometimes the friction genuinely is ours.

I'd review what's been requested and how. Common failures are asking piecemeal so the customer is approached repeatedly, requesting documents we don't actually need, not explaining why something is required, or setting unrealistic deadlines. If any of that applies, I'd fix it — consolidate the requests, drop anything not genuinely required, and explain the rationale.

Where the requests are proportionate, I'd hold them and explain the regulatory basis clearly to the RM, including what the consequence of an incomplete file is for the firm.

I'd also offer to help. Joining a call with the client, or explaining directly why source of wealth is needed, often resolves resistance faster than the RM relaying it second-hand.

What I wouldn't do is reduce the standard because of revenue. If the RM escalated, I'd support that going to the right level for a documented decision — but the decision to accept a weaker file isn't mine to make quietly.

78A PEP's account receives a large payment from a company that recently won a government contract in their ministry. Your assessment?

This is one of the clearest corruption indicators in the file — a payment from a contract beneficiary to an official with influence over the award. The pattern is exactly what PEP controls exist to detect.

I'd establish the facts precisely: the timing relative to the contract award, the amount, what the payment reference states, and the PEP's role in that ministry and in the procurement process specifically.

Then I'd seek explanation and documentary basis. There are conceivable innocent answers — a pre-existing commercial relationship, a legitimate consultancy engagement predating the contract, a family connection unrelated to the award. Each would need evidence.

What I'd scrutinise hard is any "consultancy" explanation with no evidence of services delivered, which is the standard cover for these payments.

Given the seriousness, I'd escalate early rather than complete a full investigation first. And I'd be careful about customer contact — depending on the assessment, questioning them could tip off, so I'd take guidance before making enquiries.

79A high-risk customer's source of funds for a single large transfer is evidenced, but overall wealth is not. Enough?

No, and this is an important distinction that files often blur.

Source of funds explains one transaction — where this specific money came from. Source of wealth explains the whole picture — how the customer accumulated their assets. They're different questions, and evidencing one doesn't answer the other.

A customer can have a perfectly clean source of funds for a single transfer, say a documented property sale, while their overall position remains unexplained. In fact laundering often involves entirely legitimate individual transactions layered on top of illicit accumulated wealth.

For a high-risk customer, and certainly for a PEP, both are required. That's the core of enhanced due diligence.

So I'd treat the transfer evidence as satisfying one requirement and continue on the other. I'd be specific with the customer that I'm asking a different question, since people often assume they've already answered it.

And I'd make sure the file distinguishes the two clearly, rather than recording the transfer evidence under a general "source of wealth" heading.

80A customer's business is legitimate but operates in a sector with high cash and weak record-keeping. How do you evidence source of funds?

Proportionately, using what genuinely exists, while being honest in the file about the limitations.

Small cash businesses often have limited formal records, and demanding audited accounts from a market trader would exclude legitimate customers. So I'd work with what's realistic: tax filings and returns, historic deposit patterns showing consistent takings, supplier invoices, rent or lease documents, payroll records, and licences or permits.

Sector benchmarking helps too — comparing declared takings against typical revenue for that trade, size and location. A café taking three times the sector norm for its footprint warrants questions.

Card versus cash ratios are useful where applicable, since most legitimate businesses show both.

Where evidence is inherently weaker, the compensating control is monitoring — a tighter expected activity profile and closer attention to deviation, rather than accepting weaker evidence and monitoring loosely.

I'd document explicitly what could and couldn't be evidenced, so the file doesn't imply more certainty than exists.

81Senior management approves a PEP relationship you recommended against. What do you do?

I'd accept the decision and make sure the record is complete.

Senior management has the authority to accept risk — that's precisely why PEP relationships require their approval. My role is to ensure the decision is informed, not to make it.

So I'd check that my assessment, my recommendation and the specific concerns are documented clearly in the file, and that the approval records what was known at the time. If the approval is verbal or thin, I'd ask for it in writing with the rationale, which is a reasonable request and protects everyone.

I wouldn't treat being overruled as a problem in itself. Reasonable people weigh risk differently, and they may have context I don't.

What I would do is make sure the accepted risk is actively managed — enhanced monitoring, a shorter review cycle, and clear triggers for reassessment. Accepting risk should come with conditions.

If I believed the decision was not just different but improper, I'd use the escalation route. But disagreement alone isn't that.

82A former PEP left office 18 months ago. Should you step down the treatment?

I'd assess rather than apply a fixed period, though I'd note what our policy sets as a minimum.

The relevant factors are seniority — a former head of state or finance minister retains influence far longer than a junior official; the nature of the role, particularly whether it involved control over public funds or procurement; whether they retain influence informally, through party positions, board seats or family in office; the jurisdiction's corruption risk; and whether any adverse media exists.

Time out of office matters, but it's one input rather than the test.

I'd also consider the account itself. If activity during their tenure raised questions, or wealth accumulated in office remains unexplained, stepping down would be premature regardless of elapsed time.

Practically, I'd document the assessment and reasoning, and route it for the appropriate approval rather than declassifying at analyst level.

Where the profile is high-seniority or high-risk jurisdiction, I'd recommend maintaining enhanced treatment and revisiting later.

83An EDD file is complete but you are not comfortable with the overall picture, though nothing specific is wrong. What do you do?

I'd do the work of turning the discomfort into something specific, because that's actually the job — vague unease isn't actionable and can't be escalated meaningfully.

In my experience that feeling usually reflects something identifiable that I haven't articulated yet. So I'd go back through the file asking what exactly is bothering me. Common answers: structural complexity that's technically explained but doesn't feel commercially coherent; a narrative that's internally consistent but doesn't match the numbers; documents that satisfy the checklist without answering the underlying question; or several minor items that individually pass but collectively form a pattern.

Often writing out the concerns exposes the issue clearly.

If I can name it, I'd investigate that point and either resolve it or escalate with specifics.

If after that effort I still can't articulate it, I'd raise it with a colleague or supervisor and talk it through rather than either approving to close it out or blocking on instinct. A second perspective usually resolves it one way or the other, and the discussion itself is worth documenting.

84A customer offers to provide additional information only if you agree not to record it. How do you respond?

I'd decline clearly and treat the request itself as significant.

I'd explain that everything relevant to the assessment has to be recorded, that I can't accept information on that basis, and that our records are held confidentially and accessed only by those who need them. Sometimes the concern is genuinely about confidentiality rather than concealment, and that reassurance resolves it.

But I wouldn't negotiate on the principle. An unrecorded file isn't a file, and accepting off-record information would mean my assessment rests on something no reviewer can see.

The request is informative regardless of what follows. A customer who wants to tell me something they don't want documented is signalling that the information is problematic — otherwise there's no reason to condition it.

So I'd document the request itself precisely: what was offered, what condition was attached, and my response. Then escalate. That conversation may be more revealing than whatever they were going to disclose.

Periodic review and triggers (Q85–92)

85During periodic review you find the UBO changed 18 months ago and was never disclosed. What now?

Two separate issues here, and I'd address both rather than just updating the record.

First, the substantive one: complete full due diligence on the new beneficial owner — identification, verification, screening for sanctions, PEP status and adverse media, and source of wealth if the risk profile warrants it. Effectively they're a new party to the relationship.

Second, and often overlooked: why wasn't it disclosed? Customers are typically required to notify material changes. Eighteen months of non-disclosure could be administrative oversight in a small business, or deliberate concealment.

I'd ask, and weigh the answer against the circumstances. If the new UBO turns out to be sanctioned, a PEP, or someone with adverse media, non-disclosure looks very different from an unremarkable change nobody thought to report.

I'd also review activity over the intervening period, since a change in control often coincides with a change in how the account is used.

And I'd document the non-disclosure explicitly as a risk factor, not just correct the record silently.

86A low-risk customer's transaction volumes have increased tenfold since onboarding. What do you do?

I'd treat the profile as stale rather than the activity as automatically suspicious. Businesses grow, and a tenfold increase over several years can be entirely legitimate.

The problem is that the baseline no longer reflects reality, which means monitoring is calibrated to a business that no longer exists. That's a control failure independent of whether the activity is suspicious.

So I'd establish what changed — new contracts, a new market, an acquisition, a change in business model — and seek supporting evidence. Genuine growth is usually easy to document.

I'd also look at the shape of the change, not just the size. Growth in the same pattern with the same counterparties reads very differently from a tenfold increase involving new counterparties in new jurisdictions.

Then I'd update the expected activity profile, reassess the risk rating — since scale and geography may have shifted it — and recalibrate monitoring.

If the increase couldn't be explained or evidenced, that changes it from a stale profile to a live concern, and I'd escalate.

87A long-standing customer is appointed to a senior government position. What happens?

The relationship gets reclassified as PEP and moves onto enhanced treatment, and ongoing screening should surface this automatically rather than us learning it incidentally.

Practically: complete enhanced due diligence including source of wealth, which for an existing customer means establishing how they accumulated assets before taking office. That baseline is genuinely valuable, because it's the reference point against which any future unexplained accumulation is assessed.

Then obtain senior management approval to continue the relationship, adjust monitoring to PEP-appropriate thresholds with attention to payments from state entities, contractors or unexplained third parties, and shorten the review cycle.

I'd approach the customer straightforwardly — PEP status isn't confidential and isn't an accusation, and long-standing customers generally accept it once explained.

I'd also screen their close family and known associates, since RCAs fall in scope.

What I'd avoid is treating a good history as a reason to apply the classification lightly. The risk arises from the new position, not their past conduct.

88A customer has been unreachable for a scheduled review for six months. What is your approach?

I'd follow the defined process rather than letting it drift, because an indefinitely overdue review is a control failure and these are exactly what audits find in volume.

First I'd confirm genuine attempts have been made across all channels we hold — phone, email, post, secure message — and that they're documented with dates. Sometimes "unreachable" means one email went unanswered.

I'd also check whether contact details are simply out of date, and whether the account is still active. An account transacting normally while the holder is unreachable is more concerning than a dormant one.

Then I'd escalate through the firm's process, which typically means restrictions — blocking outgoing transactions or new services — before any consideration of exit, with notice to the customer where permitted.

Restrictions often resolve it: customers who ignore review requests respond quickly when a payment is blocked.

What I wouldn't do is roll the review forward or close it as attempted. That's how firms end up with large unverified populations.

89Review shows the customer's business has changed entirely from what was onboarded. How do you treat it?

Effectively as a new relationship for risk purposes, rather than editing a field and rolling the review forward.

If a company onboarded as a local retailer is now an import-export business, almost everything we assessed has changed — the risk profile, expected activity, counterparties, jurisdictions, and potentially the documentation required. The original assessment no longer applies to anything.

So I'd redo the substantive work: understand the new business, verify it with appropriate documentation, reassess geographic and product risk, establish the new expected activity, and rescreen the entity and its controllers given the changed footprint.

I'd also check whether ownership or control changed alongside the business, since the two often move together.

And I'd look at when the change happened and whether it was disclosed. An undisclosed shift into a higher-risk activity is a meaningful indicator in itself.

The output should be a fresh risk rating and refreshed monitoring, with the file showing the change was properly assessed rather than absorbed.

90An account has been dormant for three years and suddenly receives a very large credit. What do you do?

I'd treat it as a trigger event and act before the funds move on, because dormant account reactivation with a large credit is a well-established laundering pattern — the account has no recent activity to compare against, and criminals use exactly this.

First I'd establish the source: where the funds came from, who sent them, what the reference says, and whether the sender has any evident connection to the customer.

Then I'd look at what's happening next. Funds arriving and being immediately moved on or withdrawn is the pattern that concerns me most; funds sitting in the account is less urgent.

I'd also verify the customer still controls the account. Dormant accounts are targets for takeover, so I'd want confirmation the activity is genuinely theirs before assuming it is.

Then refresh the customer file, since three years of dormancy means our information is stale, and reassess expected activity.

If the credit can't be explained satisfactorily, I'd escalate rather than let onward movement proceed.

91You discover a customer file was approved without required screening being run. What now?

I'd run the screening immediately, because the priority is establishing whether there's live exposure right now — a sanctioned customer transacting is a materially different problem from a procedural gap.

If screening returns a hit, that becomes the urgent issue and I'd escalate on that basis. If it's clear, the exposure was hypothetical but the control failure is still real.

Either way I'd escalate it as a control failure rather than quietly fixing the file. Screening was required, wasn't performed, and the file was approved anyway — that means a control was bypassed and approval given without it.

I'd also check whether it's isolated. A single missed step might be human error; several suggests a process or system gap, perhaps a workflow that allows approval without the check completing. That's the more important finding.

I'd document what was missed, when, what I found on running it, and what remediation followed. And I'd raise it constructively — the aim is fixing the process, not attributing blame.

92Adverse media appears on an existing customer between scheduled reviews. What is your response?

Treat it as an event-driven review and act now rather than holding it to the scheduled date. Waiting is how firms end up explaining to a regulator why they knew about an investigation for eight months and did nothing.

First I'd assess the finding properly — is it genuinely our customer, is the source credible, what stage is the matter at, and is it material to financial crime risk.

If it's material, I'd reassess the risk rating, review recent account activity in light of what's alleged, and consider whether enhanced measures or a source of funds refresh is warranted. Activity that looked unremarkable can read differently once you know what the customer is accused of.

Depending on severity, this may warrant escalation toward a suspicious activity report, particularly if account activity aligns with the alleged conduct.

I'd be careful about customer contact where a report might follow, and take guidance before making enquiries.

And I'd bring forward the next scheduled review rather than leaving the cycle unchanged.

Pressure, ethics and escalation (Q93–100)

93A senior executive asks you to approve a file that does not meet policy, saying they will take responsibility. What do you do?

I'd decline to approve it myself, and I'd be clear that this isn't obstruction — it's about the record showing who actually made the decision.

If I approve it, the file shows an analyst signed off a non-compliant file. A verbal assurance that someone else takes responsibility protects nobody, least of all me, and won't appear anywhere a reviewer looks.

What I'd propose instead is the proper route: if someone with the authority to accept the risk wants to accept it, that should be recorded as their documented decision, with the policy gap identified, the rationale stated, and their approval in writing.

That's a legitimate outcome. Firms do accept exceptions — what matters is that they're visible, reasoned and owned at the right level.

I'd set out my concerns in writing regardless, so my position is on record.

If they refused to document it and pressed me to approve anyway, that's a serious compliance concern in itself and I'd escalate to compliance leadership.

94You discover a colleague has been closing EDD files without obtaining source of wealth evidence. What do you do?

I'd escalate to a supervisor promptly rather than raise it informally, because this isn't a personal disagreement — it's a systemic control failure with a population of affected files behind it.

I'd be factual about what I found: which files, what was missing, and how I came across it. I wouldn't characterise motive, because I don't know it.

The reason it needs formal escalation is that the consequences extend well beyond one person. Those files may need remediation, the customers may be higher risk than recorded, and if EDD files are being closed without source of wealth, our reporting on EDD completion is wrong.

I'd also flag that this often reflects pressure or training rather than misconduct — unrealistic targets, unclear standards, or an analyst who was never properly taught what corroboration means. That framing usually leads to a better fix.

What I wouldn't do is mention it quietly and let it continue, or confront the colleague and rely on them to correct it. The firm's risk position is affected either way.

95You realise you approved a file six months ago that you now believe was wrong. What do you do?

Report it immediately. Concealing it converts a correctable error into an integrity failure, and integrity failures end careers in compliance in a way that mistakes generally don't.

I'd go to my supervisor with the specifics: which file, what I got wrong, why I now think so, and what the potential exposure is. Having thought it through before raising it is more useful than flagging a vague worry.

I'd also consider whether the same error might affect other files I worked around that time — if I misunderstood a requirement, it probably wasn't a one-off.

Then support whatever remediation follows: re-reviewing the file, obtaining what was missed, reassessing the risk rating, or escalating if the customer turns out to present real risk.

Compliance teams are judged on how errors are handled, not on never making them. Self-reporting is treated far better than discovery through QA or audit, and a colleague who surfaces their own mistakes is more trusted, not less.

96A customer offers you a gift after you helped resolve a documentation issue. How do you respond?

I'd decline politely and report it under the gifts and inducements policy, regardless of value.

I'd decline in a way that doesn't embarrass them, since it's usually genuine gratitude and refusing bluntly can seem ungracious. Something like explaining that we're not permitted to accept gifts from customers, but that the thanks are appreciated.

The reason it's declined even when small is the position I hold. I make decisions affecting whether their account is approved and what conditions apply. Any gift creates an appearance problem, and appearance matters in a control function — a reviewer looking at a file later shouldn't be able to ask whether a gift influenced it.

I'd report it because the policy requires it and because reporting protects me. If it ever came up, a recorded and declined gift is a non-issue; an unrecorded one is not.

If the offer were repeated after refusal, or came while a decision was pending, I'd treat that as a more serious concern and escalate.

97You recognise a customer as a close friend while reviewing their file. What do you do?

Declare it immediately and hand the file to a colleague. I wouldn't complete the review, even if I were confident I could be objective.

The point isn't whether I'd actually be biased — it's that the decision couldn't be relied upon. If the relationship emerged later, every judgement I made would be questioned, including ones that were entirely correct. That's unfair to the firm and to me.

There's also a confidentiality dimension. Reviewing a friend's file gives me access to their financial affairs in a way they haven't consented to and probably wouldn't want.

So I'd tell my supervisor, explain the relationship, and stop working the file. I'd also make sure the reassignment and reason are recorded, so the file shows the conflict was identified and managed.

And I wouldn't mention to my friend that I'd seen their file, since that would breach confidentiality in the other direction.

Declaring conflicts early is straightforward; discovering them afterwards is not.

98A colleague asks to use your system login because theirs is locked. What do you do?

Refuse, and direct them to IT. This is straightforward and I wouldn't treat it as a difficult judgement call.

Sharing credentials breaches security policy in every firm I've worked in, and in most it's a disciplinary matter for both people. But the more important reason is the audit trail: every decision recorded under my login is attributed to me. If work is done under my credentials, I'm accountable for it whether I did it or not.

In a control function that matters enormously. The record of who approved what is the evidence a regulator relies on, and credential sharing destroys it.

I'd say no without making it confrontational — most people ask out of time pressure rather than bad intent, and IT usually resolves a lockout quickly.

If they persisted, or I discovered it was happening routinely in the team, I'd raise it with a supervisor. Casual credential sharing is a security control failure regardless of intent.

99Your team is under pressure to clear a backlog and you are told to "speed up" reviews. How do you handle it?

I'd distinguish between working faster and working to a lower standard, because they're often conflated in that instruction.

There's usually genuine scope for efficiency — batching similar files, better prioritisation, fixing repeated bottlenecks, or removing steps that add no risk value. I'd look for that first and propose it constructively.

What I'd flag is that throughput can't come from reducing depth of review. Files closed without proper checks don't reduce the backlog, they convert it into a remediation exercise later at far greater cost — and that's precisely the pattern enforcement actions describe.

So I'd propose alternatives: risk-based triage so low-risk files move quickly and high-risk ones get full attention, temporary resource, or a phased plan with the backlog transparently reported.

Transparency is key — a reported backlog with a plan is manageable; a hidden one that emerges in audit is not.

If pressure continued to reduce standards, I'd escalate and ensure the instruction and my concerns are documented.

100You suspect a customer is involved in financial crime but your manager disagrees and closes the case. What do you do?

First I'd make sure I've made my case properly, because sometimes disagreement comes from my not having explained the reasoning clearly. I'd set out the specific evidence, the pattern, and why the innocent explanation doesn't hold, in writing rather than verbally.

If my manager still disagrees after seeing that, I'd accept the decision — they may have context I lack, and reasonable people weigh evidence differently.

But I'd ensure my assessment is documented in the file, not just in a conversation. That matters both for the firm's record and for me personally.

Where I'd go further is if I believed a genuine reporting obligation was being missed. The obligation to report sits with the institution, and in some jurisdictions individuals carry personal exposure. In that situation I'd use the escalation route — to the MLRO directly if the process allows, or through whistleblowing procedures.

That's not something to do lightly or over ordinary disagreement. But suspicion being suppressed rather than assessed is exactly what those routes exist for.

Rehearse your reasoning out loud

Scenario answers are judged on how you reason under follow-up questioning. Practise a live AI voice and video interview on AGZIT, get a 10-competency scorecard, and build a free ATS-friendly resume when you register.

Start your free AI interview See how it works

Work real cases before the interview

The strongest scenario answers come from having actually worked files. eStraLux training covers end-to-end KYC with real tool access and entity-based case studies, so your examples are genuine rather than hypothetical.

Explore eCEEK Explore eCADS Browse All Courses

Browse KYC jobs on eStraLux →

leave your comment


Uploading