100 KYC Interview Questions for Experienced Professionals
100 KYC Interview Questions for Experienced Professionals
Interviews for experienced KYC roles work differently from entry level. Nobody will ask you to define CDD. They will hand you a complex ownership structure, ask how you reached a decision, and probe whether you can defend it — to a quality reviewer, to a relationship manager pushing back, or to a regulator.
These KYC interview questions for experienced professionals come with full model answers covering complex structures, EDD judgement, screening resolution, quality and escalation, and regulatory expectations.
- Your experience and track record (Q1–12)
- Complex structures and beneficial ownership (Q13–30)
- EDD, source of wealth and judgement (Q31–48)
- Screening depth and resolution (Q49–62)
- Quality, escalation and stakeholders (Q63–76)
- Regulatory expectations and programme (Q77–88)
- Scenario questions (Q89–95)
- Leadership and closing (Q96–100)
What separates experienced candidates
The ability to say why you decided something, not just what you decided. Interviewers at this level probe for reasoning, trade-offs and what you would do differently. Answers that describe a process without a judgement call in them sound like someone who has followed procedures rather than owned decisions.
Your experience and track record (Q1–12)
These questions are about you, so there is no model answer — only a structure that works and the mistakes that lose marks.
1Walk me through your KYC experience.
Cover four dimensions: the customer types you have handled, the jurisdictions involved, which parts of the lifecycle you worked — onboarding, periodic review, remediation, EDD — and what you owned versus escalated.
Complexity is more persuasive than volume. "I reviewed 40 files a week" says less than "I handled trusts, funds and multi-layered corporate structures across the Gulf and Caribbean, including EDD on PEP relationships."
Finish by connecting your experience to what this role requires, which means having read the job description properly.
2What is the most complex case you have worked?
Choose genuine analytical difficulty rather than administrative hassle. Strong choices: ownership ending at a foundation with no public register, a structure where control sat away from ownership, or conflicting documentation across jurisdictions.
Structure it as: what the customer was, where the difficulty lay, what you did to resolve it, what you could not establish, and what you concluded and why.
The detail that impresses is the point where you had to make a judgement call with incomplete information — because that is the actual job at senior level.
Expect follow-ups on why you did not do X. Interviewers push hardest on this answer.
3What customer types have you handled?
Name them precisely — individuals, SMEs, listed companies, trusts, funds, SPVs, partnerships, charities, correspondent relationships. Each carries distinct documentation and ownership challenges, and naming them tells the interviewer immediately what you have actually seen.
Where you have handled something unusual, mention what made it difficult. Trusts and funds in particular separate candidates, because the ownership model differs fundamentally from a company.
If your experience is narrower, say so honestly and explain what you would need to learn. Overstating breadth collapses under a single follow-up question.
4Which jurisdictions have you worked with?
Name the markets, then say which presented verification difficulties — opaque or paywalled registries, limited public records, unusual corporate forms, or documentation in other languages.
That awareness is what marks experience. Anyone can list countries; knowing where beneficial ownership becomes genuinely hard to establish demonstrates you have actually done the work.
If you have worked mainly in one region, frame the depth positively and show you understand what would differ elsewhere.
5What systems have you used?
Name the case management, screening and registry tools, and be precise about what you did in each: completing files, resolving screening hits, running registry searches, extracting reporting, or configuring workflow.
Where you used more than one platform, mention what differed. That shows you understand the underlying process rather than one interface.
If your exposure was as a user rather than an administrator, say so. Interviewers respect the distinction and will discover it regardless.
6What is your average file completion time and quality score?
Provide real metrics if you have them, but qualify them by file type. A complex EDD file legitimately takes days; a standard retail onboarding takes minutes. Quoting an average without that context makes you look either slow or superficial.
Quality score matters more than speed at senior level, so lead with it if it is strong.
If your firm did not track these, explain how your work was measured instead — QA sampling, supervisor review, or audit outcomes.
7Have you worked on a remediation project?
Describe the scope, what triggered it, the population size, and your specific role. Remediation is often driven by a regulatory finding, so knowing why it happened matters.
Mention what the root cause turned out to be, since that shows you understood the exercise rather than just processing files.
If you led or coordinated any part of it, say so — remediation experience combined with any coordination role is a strong signal for senior positions.
8Have you dealt with regulators or auditors?
Be honest about the level — direct engagement, supporting preparation, or having your files sampled. All three are relevant.
The valuable part is what it taught you about how files are assessed under scrutiny. Anyone whose work has been sampled by an examiner thinks about documentation differently afterwards, and saying that specifically lands well.
If you have no exposure, mention internal audit or QA experience instead — the assessment principle is the same.
9Have you trained or mentored others?
Describe what you actually did: onboarding new joiners, reviewing their early files, running training on a specific topic, or acting as the point of reference for complex structures.
Explain your approach briefly. Teaching reasoning rather than process is the answer that signals seniority, because it shows you understand the work well enough to explain why rather than what.
For team lead roles this question carries real weight, so have a concrete example ready.
10What made you decide to leave your current role?
Give a reason rooted in what you want next — more complex entity types, EDD ownership, a specialism, or a step toward leadership.
Criticising a current employer raises questions about discretion, which matters disproportionately in compliance.
If the real reason is negative, translate it. "The portfolio had become largely standard retail onboarding with limited complexity" is honest without being disloyal.
11What is a decision you got wrong?
Choose something genuine but not catastrophic — accepting a source of wealth explanation that should have been corroborated further, or missing a control relationship in a structure.
Structure it as: what you concluded, why it seemed reasonable at the time, how it surfaced, and what changed in your approach afterwards.
The last part is what they are listening for. An error that produced a lasting change in how you work is a strength; one you simply regret is not.
Avoid blaming systems, colleagues or time pressure, even where they genuinely contributed.
12What do you want from your next role?
Name what you want — more complex entity types, ownership of EDD decisions, a specialism such as trusts or funds, or a move toward team leadership and sign-off responsibility.
Connect it to what this role offers.
If you want a step up in seniority, say so directly rather than hinting. Ambiguity here usually reads as lack of ambition rather than modesty.
Practise the delivery, not just the content
Experienced interviews probe reasoning under follow-up questioning — where prepared answers usually break down. Practise a live AI voice and video interview on AGZIT:
- A real spoken interview that follows up on your answers
- A 10-competency scorecard showing where your reasoning is thin
- A free ATS-friendly resume builder once you register
- Your first AI interview is free
Complex structures and beneficial ownership (Q13–30)
13How do you identify the UBO in a multi-layered structure?
I trace ownership upward layer by layer, calculating effective holdings through the chain rather than assessing each layer in isolation. That distinction matters, because someone holding sixty percent of an entity that holds fifty percent of the customer has thirty percent effective ownership, not sixty.
I aggregate across all chains to the same individual, since ownership routed through several vehicles can combine above the threshold when no single line reaches it.
Where no individual meets the ownership test, I move to control — voting rights that differ from shareholding, rights to appoint or remove directors, veto rights, shareholder agreements, or funding dependence that confers influence.
Only if ownership and control both fail would I record the senior managing official, and the file needs to show those steps were genuinely applied rather than skipped.
Throughout, I verify against registries rather than relying solely on a customer-provided structure chart.
14What is indirect ownership and how do you calculate it?
Indirect ownership is a stake held through one or more intermediate entities rather than directly in the customer.
The calculation is multiplicative through the chain. If an individual owns eighty percent of Company A, and Company A owns sixty percent of our customer, their effective indirect holding is forty-eight percent — not eighty, and not sixty.
Where the same person holds stakes through multiple routes, those aggregate. Twenty percent through one chain and fifteen through another gives thirty-five percent effective ownership, which may cross a threshold that neither line reaches alone.
The common error is reading each layer separately and recording the shareholder of the immediate parent as the beneficial owner. That identifies an intermediate holder rather than the ultimate one.
I would also check whether voting rights track economic ownership, because they frequently do not, and control may sit differently from the percentages.
15What if no individual meets the ownership threshold?
I move to the control tests before considering the senior managing official, and I would want the file to evidence that sequence.
Control can exist without ownership. I would look for enhanced voting rights, rights to appoint or remove the board, veto rights over major decisions, shareholder or investment agreements conferring influence, and situations where a single funder effectively directs the business.
Dispersed ownership with concentrated control is common, particularly in family businesses and investor-backed companies, and the control test exists specifically to catch it.
Only where both ownership and control tests genuinely fail would I record the senior managing official — and that is a documented last resort, not a shortcut when tracing becomes difficult.
I would also note that this position increases risk. We have not identified a beneficial owner; we have substituted an officer. The risk rating should reflect that.
16How do you handle a trust?
Trusts require a different mental model from companies, because ownership and control are deliberately separated.
I identify the settlor, who created the trust and provided the assets; the trustees, who hold and administer them; the protector if there is one; the beneficiaries or the class of beneficiaries; and anyone else with effective control.
The settlor matters for source of funds — where the assets came from originally. The trustees matter operationally. The protector often matters most for control, since powers to remove trustees constrain their independence.
I would want the trust deed rather than a summary, and any letter of wishes where available, because that frequently reveals the real intent behind a discretionary arrangement.
I would also establish whether distributions have actually been made and to whom, since a trust with a broad beneficiary class that has only ever paid one person is functionally narrower than it appears.
17How do you handle a discretionary trust with an unnamed beneficiary class?
A defined class rather than named beneficiaries is entirely normal, particularly for family succession planning, so I would not treat it as evasive by default.
I document the class as it is defined in the deed — for example the settlor's children and remoter issue — and then focus diligence on the parties who exercise control: settlor, trustees and protector.
I would establish how distributions are decided in practice and whether any have been made. Actual distribution history tells you far more than the class definition.
Where the class is drawn so broadly that it is effectively meaningless, or the structure appears designed specifically so that no one can be identified as benefiting, that is a different matter and I would escalate.
The proportionality point is that a family trust and an opaque arrangement can look similar on paper — the difference emerges from the deed, the letter of wishes and the distribution record.
18What is a protector and why does it matter?
A protector is a party with powers over the trustees — commonly to remove and appoint them, to veto certain decisions, or to consent to distributions.
It matters because real control frequently sits with the protector rather than the trustee named on the documents. A professional trustee who can be dismissed by a family member is constrained in practice, whatever their fiduciary duties say.
So I treat the protector as a controlling party: full identification, verification, screening for sanctions, PEP status and adverse media, and inclusion in the risk assessment.
I would want to see the specific powers in the trust deed rather than a description, because protector powers vary enormously — some are limited to consent on narrow matters, others amount to effective control of the whole arrangement.
The pattern worth noting is a family member protector over a professional trustee, which usually means the family retains control while the structure presents as independently administered.
19How do you approach a fund structure?
I start by separating the parties, because funds have several and they carry different weight: the fund itself, the investment manager, the general partner or management company, the administrator, and the investors.
Diligence usually concentrates on the manager and the controlling entities, since they direct the fund's activity and are typically regulated.
Investor diligence is risk-based and depends heavily on the fund type. A regulated fund with institutional investors is treated differently from a private vehicle with a handful of individuals, where investors may need identifying individually.
I would verify the fund's regulatory status and where it is domiciled, since that drives what reliance is permissible.
The point I would be careful about is not treating "it's a fund" as answering the ownership question. Some structures use fund terminology while functioning as a private holding vehicle, and the substance matters more than the label.
20What is an SPV and what makes it higher risk?
A special purpose vehicle is an entity created for a defined transaction or purpose — securitisation, a property holding, a joint venture, or ring-fencing a particular asset. They are entirely routine in corporate finance.
Risk arises from three things. First, purpose that cannot be clearly articulated — a legitimate SPV has a specific reason for existing, and a customer who cannot explain it is a concern. Second, structural disproportion, where the vehicle and its jurisdiction are far more elaborate than the underlying activity warrants. Third, jurisdictional disconnection, where the SPV sits somewhere with no relationship to the assets, the parties or the transaction.
I would want to see what the SPV actually holds or does, who controls it, and why it was established in that particular jurisdiction.
The concerning version is an SPV with no identifiable transaction behind it, which is a shell with a more respectable label.
21How do you treat a listed company?
Companies listed on recognised regulated exchanges typically attract reduced ownership diligence, on the basis that ownership is publicly disclosed and the exchange imposes supervision.
But I would verify rather than assume. Three checks: that the company is genuinely listed, that the exchange qualifies as recognised under our policy, and that the listing is current rather than lapsed.
The reduced treatment applies to the listed entity itself. It does not automatically extend to unlisted subsidiaries, and our policy should specify whether and on what conditions it does.
Reduced ownership diligence also does not mean no diligence. Directors and controllers still need identifying and screening, and the relationship still needs a risk assessment.
The practical error I have seen is treating any company with a stock listing anywhere as exempt, including listings on exchanges with minimal disclosure requirements, which defeats the rationale for the exemption entirely.
22What are nominee shareholders and directors?
Parties who hold shares or office on behalf of someone else, under an arrangement where the beneficial interest or the direction sits elsewhere.
They are legal in many jurisdictions and used legitimately — for privacy, administrative convenience, or where a corporate service provider supplies directors as part of a package.
The AML significance is that the registered position does not reflect reality. Identifying a nominee tells you nothing about who owns or controls the entity, so recording them as the beneficial owner would be a substantive error.
So the task is looking behind the arrangement: who instructs the nominee, who holds the beneficial interest, and is there a declaration of trust or services agreement evidencing it.
The concerning version is a customer presenting a nominee as the genuine controller, or being unable to say who actually directs the entity. At that point control has not been established.
23What indicators suggest a nominee arrangement?
The clearest is a director or shareholder holding positions in an implausible number of unrelated companies. Nobody meaningfully governs 180 businesses, so that pattern identifies a professional nominee almost conclusively.
Corporate service provider addresses appearing as the registered office, particularly where the same address recurs across otherwise unconnected customers.
Shareholders with no apparent commercial connection to the business — no relevant background, no evident investment rationale, no involvement.
Recent share transfers for nominal consideration between apparently unrelated parties, since a genuine sale of a valuable business does not happen for a token amount.
Directors resident in a jurisdiction unconnected to the company's operations or market.
And behaviourally, a customer who cannot describe the role their own directors play, or who routes all communication through an intermediary while the named officers remain invisible.
24How do you assess whether a structure has legitimate purpose?
I test the explanation against the structure rather than assessing whether it sounds plausible, because most explanations sound plausible.
If the customer cites tax efficiency, does the structure route through jurisdictions with relevant treaties, or through places with no treaty benefit at all? If investor requirements, are there investors? If succession planning, does the arrangement actually achieve that?
A genuine rationale is specific and checkable. A vague one — "our advisers set it up this way" — is not an explanation.
I would also weigh proportionality. A multinational with fifteen entities across its operating markets is normal; a single-site business with the same structure is not.
The concerning pattern is complexity the customer cannot explain, entities in jurisdictions with no connection to the business, and layers whose only apparent function is distance between the operating company and its ultimate owner.
25What if the corporate registry conflicts with customer-provided documents?
I reconcile rather than choose, because either source can be wrong in different ways.
Registries lag — filings take time to process, and some jurisdictions update slowly. Customer documents can be outdated, prepared for another purpose, or reflect an intended rather than completed position.
So I identify precisely what differs, because materiality varies enormously. A missing intermediate entity is a different problem from a different ultimate owner.
Then I ask the customer to explain each discrepancy and provide evidence — share transfer documents, board resolutions, or filing receipts showing a change submitted but not yet reflected. Filing receipts are particularly useful because they demonstrate the customer's version is in process.
What I document is how each difference was resolved and on what evidence, not just the final position.
The pattern that would concern me is customer documentation that consistently understates ownership concentration relative to the registry.
26How do you handle jurisdictions without public registries?
I fall back to the strongest available alternatives while being explicit in the file about what could not be independently verified.
Options include certified constitutional documents, confirmations from the registered agent, legal opinions from local counsel, audited accounts, and customer attestations supported by whatever documentary evidence exists.
The ordering matters — an independent legal opinion carries more weight than a customer attestation, and I would seek the strongest source obtainable rather than the easiest.
Critically, the limitation feeds the risk rating rather than disappearing. If ownership rests on documents the customer supplied with no independent corroboration, that is a weaker position than registry-verified ownership, and the file should say so.
I would also consider whether the jurisdiction choice itself is explicable. Opacity may be incidental, or it may be the reason the structure sits there.
27What is a bearer share and why is it a problem?
A bearer share is owned by whoever physically holds the certificate. There is no register of ownership, and title transfers by handing the document over.
The AML problem is fundamental: ownership cannot be established with any confidence, and more importantly it can change tomorrow with no record. Even a correct assessment today has no durability.
Most jurisdictions have abolished or immobilised them for exactly this reason, so where they persist they attract high scrutiny.
Practically I would require evidence of immobilisation — certificates held by an approved custodian or registered agent, or conversion to registered form, with documentation identifying the current holder.
Without that, I cannot establish ownership and would escalate with a recommendation not to proceed. I would also ask why bearer shares are being used, since legitimate businesses have largely moved away from them and the absence of a good answer is itself informative.
28How do you verify a beneficial owner you never meet?
Through documentary and electronic means, with the standard scaling to the risk.
The baseline is certified identification documents, verified against the issuing standard where possible, plus address verification.
Electronic verification against independent data sources adds meaningfully, because it corroborates the identity exists independently of the documents supplied.
Registry confirmation of their role, and where available, public records connecting the individual to the entity.
For higher-risk beneficial owners I would want more — verification through a regulated intermediary, video verification with liveness checks, or independent confirmation from a professional adviser.
The point I would make is that certification quality matters. A certified copy is only as good as the certifier, so where the certifier cannot be verified, the document is effectively uncertified — and that is a common weakness in files that appear complete.
29When would you refuse to proceed on ownership grounds?
Three situations, and I would frame them as recommendations rather than decisions I make alone.
First, where the beneficial owner cannot be identified after genuine effort — I have exhausted registries, requested documentation, applied control tests, and the chain still breaks. An unidentifiable owner is a substantive finding.
Second, where the customer refuses to explain the structure or provide ownership information. That refusal is itself a risk indicator, and it is materially different from an obstacle we cannot overcome.
Third, where documentation is materially inconsistent and the inconsistencies cannot be reconciled — particularly where explanations shift when challenged.
In each case I would escalate with a full record of what was attempted rather than declining unilaterally. The decision to accept or decline sits above analyst level, but I would not sign the file as complete.
30How do you keep ownership information current?
Through a combination of scheduled and event-driven review, because structures change quietly and a file accurate at onboarding can be wrong within a year.
Periodic review on a risk-based cycle is the baseline, with higher-risk relationships reviewed more frequently.
Trigger events matter more in practice — a notified ownership change, a change in directors, adverse media, a change in transaction behaviour suggesting new control, or a corporate action.
Registry monitoring where the jurisdiction supports it, so filings generate alerts rather than being discovered at the next review.
Customer attestation as part of periodic review, though I would treat that as a prompt rather than verification.
The gap most firms have is undisclosed change. Customers are usually required to notify, and frequently do not, so relying solely on their notification means discovering changes late — which is why registry monitoring and behavioural triggers matter.
EDD, source of wealth and judgement (Q31–48)
31What triggers EDD in your experience?
The triggers should be set in policy rather than left to individual judgement, and in practice they cluster into a few categories.
PEP involvement, whether the customer, a beneficial owner, or a relative or close associate. High-risk jurisdictions, either as the customer's location or where funds and counterparties sit. Complex or opaque ownership, particularly where tracing was difficult or relies on unverified sources.
Cash-intensive and other higher-risk sectors, correspondent relationships, and adverse media findings that are credible and material.
Also any relationship the risk assessment rates high for a combination of factors none of which triggers EDD alone.
The point I would make is that triggers should be applied consistently. Where analysts decide case by case whether something feels like it warrants EDD, treatment varies and the programme becomes indefensible under review.
32What does good EDD actually involve?
Corroboration rather than more documents, which is the distinction that separates genuine EDD from a thicker file.
Concretely: source of wealth and source of funds established with independent evidence rather than assertion; deeper understanding of the business including its counterparties and how it actually generates money; expanded screening across related parties; senior management approval; and a documented rationale for accepting the risk.
The rationale matters and is often missing. A file can contain extensive evidence without ever stating why, given all of it, the relationship is acceptable.
Enhanced monitoring should follow, calibrated to what the EDD revealed rather than applied generically.
What good EDD is not is the standard file with additional documents attached. If the analysis is the same and only the volume changed, it is not enhanced — and that is exactly what regulators identify when they sample EDD files.
33How do you verify source of wealth?
I start by establishing the narrative — how the customer says they accumulated their assets — then break it into components and corroborate each one independently.
For business wealth: registration and shareholding records showing their stake and its duration, audited accounts or filings demonstrating the business generated wealth at that scale, and evidence of dividends or a sale.
For employment: contracts, payslips, tax filings.
For inheritance: probate records, grant of representation, or estate correspondence.
For asset sales: completion statements, transfer records, or registry evidence.
The test I apply is whether the total accumulated wealth is plausibly explained by the sources evidenced. Individual components can each be documented while still not adding up to the overall position, and that gap is the finding.
Depth scales with risk — a high-risk PEP warrants documentary evidence across material components; a moderate-risk customer may need less.
34What is the most common weakness in source of wealth files?
Recording assertion as though it were evidence. "Family business" or "successful entrepreneur" written into a file with no supporting documentation is the single most cited criticism in this area.
The reason it happens is that the narrative sounds complete. A file saying the customer built a manufacturing business over twenty years reads as an explanation, and it is easy to treat it as answered.
But it is a claim, not a finding. Nothing in the file demonstrates the business existed, that they owned it, or that it generated wealth at that scale.
The second common weakness is volume substituting for relevance — a file containing many documents, none of which evidence the wealth claimed.
The discipline that fixes both is component mapping: list what the customer claims, then identify which specific document evidences each. Anything unmatched is unevidenced, however thick the file.
35How much corroboration is enough?
Proportionate to the risk and to the amounts involved, and I would want the reasoning documented either way rather than applying a fixed rule.
For a high-risk PEP with substantial assets, I would expect documentary evidence covering each material component of the wealth, from independent sources.
For a moderate-risk customer with a straightforward profile, a credible narrative with partial corroboration on the principal source may be sufficient.
The judgement is about materiality. If ninety percent of the wealth is evidenced and the remainder is a modest unexplained portion, that is a different position from the reverse.
What I would not accept is uniform treatment in either direction — demanding exhaustive evidence from every customer creates friction without benefit, and accepting thin evidence from high-risk ones is the failure mode.
The file should state what was obtained, what was not, and why that was assessed as sufficient.
36What if source of wealth cannot be fully evidenced?
I document what was obtained, what could not be verified and why, assess whether the unevidenced portion is material, and escalate rather than record the file as satisfied.
The distinction that matters is between a documented gap and a concealed one. "Source of wealth: inheritance, probate unavailable as estate administered privately in 1998, customer provided will extract, remaining portion unevidenced, escalated" is a defensible file position.
"Source of wealth: inheritance" is not.
I would also test how hard we actually tried. Most sources leave some trace, and an inability to evidence anything usually reflects insufficient effort rather than genuine impossibility.
Then the materiality question: is the unevidenced portion small relative to the whole, or is it the substantial part? And is the customer high risk, where the standard is higher?
The decision to accept a partially evidenced position sits above analyst level, but the record needs to make the gap visible.
37How do you assess wealth that appears disproportionate to known income?
The gap becomes the central question of the file rather than one factor among many.
First I would test my own assumption, because career income is not the only legitimate source. Inheritance, marriage, business ownership alongside employment, early investment, property appreciation and a successful exit all explain wealth beyond salary.
So I would ask what accounts for the difference before concluding anything, and seek evidence proportionate to the size of the gap.
What concerns me is an explanation that is vague, shifts under questioning, or cannot be evidenced at all — particularly for a PEP or someone in a position with corruption exposure, where unexplained wealth is the defining indicator.
The specific pattern to watch for is wealth accumulating during a period in public office at a rate the declared salary cannot support.
Where the gap remains unexplained after reasonable enquiry, I would escalate toward a suspicious activity report rather than accepting a plausible-sounding account.
38What is the difference between source of wealth and source of funds in practice?
Source of funds explains where the specific money in a transaction or account came from. Source of wealth explains how the customer accumulated their overall assets.
They answer different questions and evidencing one does not answer the other. A customer can have an entirely clean source of funds for a particular transfer — a documented property sale — while their overall position remains unexplained.
That combination is common in laundering, where legitimate individual transactions sit on top of illicit accumulated wealth.
Practically, source of funds is easier: a single transaction with a traceable origin. Source of wealth is harder and more revealing, because it requires explaining a lifetime of accumulation.
For high-risk customers and PEPs both are required, and the file should record them separately rather than blending the transaction evidence under a general source of wealth heading — which is a common way an incomplete file appears complete.
39How do you handle a PEP relationship?
Confirm the classification and category first, since foreign, domestic and international organisation PEPs are treated differently under most frameworks, and databases both over- and under-capture.
Then complete EDD with genuine source of wealth corroboration, which is the core of PEP due diligence and where files most often fall short.
Obtain senior management approval to establish or continue the relationship, documented with the rationale rather than a signature alone.
Set enhanced monitoring calibrated to the specific risk — attention to payments from state entities, government contractors, or unexplained third parties — rather than simply tightening thresholds generically.
Shorten the review cycle and define trigger events.
And I would screen relatives and close associates, since funds are frequently routed through them rather than the PEP directly.
What I would never do is treat PEP status as a reason to decline. That is de-risking, and regulators have criticised it explicitly.
40How do you handle a former PEP?
I would assess rather than apply a fixed period, while noting whatever minimum our policy sets.
The factors that matter: the seniority of the role held, since a former head of state or finance minister retains influence far longer than a junior official; whether the role involved control over public funds or procurement; whether they retain influence informally through party positions, board seats or family in office; the corruption risk of the jurisdiction; and whether adverse media exists.
Time elapsed is one input, not the test.
I would also look at the relationship itself. If activity during their tenure raised questions, or wealth accumulated in office remains unexplained, stepping down treatment would be premature regardless of elapsed time.
Practically I would document the assessment and route it for approval rather than declassifying at analyst level, since an undocumented step-down looks like a shortcut.
41How do you assess a cash-intensive business?
By benchmarking against what the business could plausibly generate, rather than assessing the cash in isolation.
The most useful comparison is cash against card and electronic receipts. Most legitimate businesses take both, and the ratio should be broadly consistent with the sector. Cash rising while card revenue stays flat is the pattern that concerns me, because it means more cash without more customers.
Then capacity. A business can only physically serve so many customers given its size, staffing and opening hours, so deposits implying volumes beyond that are a concrete, evidenced concern rather than a general suspicion.
Costs corroborate: genuine trading volume means proportionate stock purchases, utilities and payroll. Revenue rising with costs flat is difficult to explain.
And seasonality — legitimate takings fluctuate with trade, so unnaturally consistent deposits are themselves an indicator.
Sector benchmarking data, where available, makes all of this defensible rather than impressionistic.
42How do you approach a correspondent banking relationship?
The fundamental point is that you are relying on another institution's controls for customers you will never see, so the respondent's programme is effectively your control.
So I would assess their AML framework substantively: screening and monitoring capability, governance, who their MLRO is, regulatory standing, and whether they have faced enforcement action.
Ownership and jurisdiction matter, since a respondent in a weakly supervised market carries different risk regardless of what their policies say.
I would establish whether they permit nesting — other institutions accessing services through them — because that adds a layer of customers neither of us can see.
I would understand the products offered, the corridors served, and expected volumes, since that becomes the baseline for monitoring their flows.
Wolfsberg-style questionnaires are the standard tool, but I would treat them as a starting point rather than assurance, and supplement with independent checks and periodic reassessment.
43How do you handle a customer in a sanctioned or near-sanctioned jurisdiction?
I would separate the sanctions question from the AML one immediately, because they have different consequences and timelines.
For sanctions, the question is what is actually prohibited versus permitted — comprehensive programmes differ from sectoral ones, and a jurisdiction being sanctioned does not automatically prohibit every dealing. That determination needs the sanctions team and often legal input rather than analyst judgement.
For a near-sanctioned jurisdiction, the specific risk is diversion. Trade and payments routed through countries bordering a sanctioned state is a recognised evasion pattern, so I would want evidence of genuine local business rather than treating proximity as either disqualifying or irrelevant.
Practically that means verifying counterparties exist and trade locally, understanding why the routing makes commercial sense, and checking whether goods are controlled.
Blanket refusal is the wrong answer, but so is treating it as an ordinary geographic risk factor.
44What is your approach to a customer who refuses to provide information?
First I would establish whether it is refusal or misunderstanding, because they look similar and are handled differently.
Many customers object because they think they are being singled out, or do not understand why ownership or source of wealth is relevant. Explaining that it is a regulatory requirement applying to everyone, handled confidentially, resolves a good proportion.
I would also check whether our requests were clear and proportionate. Vague or repeated requests generate resistance that is our fault rather than theirs.
If it is genuine refusal, I would set a clear deadline and explain the consequence plainly.
Persistent refusal on a material point is itself a risk indicator and I would document it precisely — what was requested, when, and the exact response. Legitimate customers of legitimate businesses generally provide this information; someone who will not usually has a reason.
Then escalate rather than complete the file with the gap unaddressed.
45How do you decide a risk rating when factors conflict?
I weight the factors most predictive of financial crime risk above the softer ones.
Ownership opacity, jurisdiction exposure, PEP status and credible adverse media carry more weight than factors like account tenure or relationship value, which feel reassuring but predict little.
Tenure in particular is over-weighted in practice. A long clean history makes a legitimate explanation more likely, but criminals use established accounts precisely because they attract less scrutiny.
Where factors genuinely balance, I would rate higher and document why. Under-rating is the harder failure to defend — explaining why a customer was rated medium when the indicators supported high is a difficult conversation with an examiner.
The critical part is documenting the reasoning rather than just the outcome. A rating with no explanation cannot be reviewed, and inconsistent ratings across similar customers is a finding in itself.
46When have you overridden a system-generated risk rating?
Overrides are legitimate where the model misses context the analyst can see, but they need documentation and usually approval.
The valid case is where the model lacks information. A customer rated high because of a jurisdiction where they have a genuine, evidenced family or business connection, or rated low because their profile data is incomplete, are both situations where analyst knowledge improves on the model.
What I would document is the specific factor the model did not capture and the evidence for it — not simply that the rating felt wrong.
Downward overrides warrant more scrutiny than upward ones, since they reduce controls.
The pattern that concerns me is frequent undocumented overrides, particularly downward, because that suggests either the model is miscalibrated or ratings are being managed to reduce workload. Either is a finding, and override rates are worth monitoring as management information.
47What is your approach to de-risking?
Exit should follow unmanageable risk or non-cooperation, not customer category.
Blanket de-risking — exiting entire segments such as money service businesses, charities operating in high-risk regions, or all PEPs — has been criticised by regulators because it excludes legitimate customers and pushes activity into less regulated channels where it becomes invisible.
So the decision needs to be case-specific and documented. Legitimate grounds include an inability to establish beneficial ownership, unexplained source of wealth, persistent refusal to provide information, or activity we cannot monitor effectively.
What I would not accept as grounds is that the customer type is inconvenient, or that EDD is resource-intensive.
There is also a commercial reality: a firm can decline business within its risk appetite, and that is legitimate. The distinction is between a reasoned appetite decision and reflexive category exclusion, and the file should show which it was.
48How do you balance thoroughness against turnaround pressure?
By front-loading the risk assessment so effort concentrates where it matters, rather than applying uniform depth and then running out of time.
A clear risk rating early tells you which files need genuine EDD and which can proceed on standard measures. Most of the volume is straightforward; the complexity sits in a minority.
Efficiency also comes from process rather than depth — consolidating information requests so the customer is approached once, using templates for recurring structures, and not re-verifying what is already evidenced.
What I would not do is quietly reduce standards to hit turnaround. Files completed inadequately do not save time; they become remediation later at far greater cost.
Where volumes genuinely exceed capacity, I would raise it with evidence — throughput data and quality trends — rather than absorbing it. Deteriorating QA scores under stable volume is the clearest signal that the standard is already slipping.
Screening depth and resolution (Q49–62)
49How do you resolve a complex sanctions hit?
I compare every available identifier against the list entry — full name, date of birth, nationality, place of birth, address, identification numbers, and for entities the registration number and place of incorporation.
Then I consider ownership and control, because sanctions exposure frequently sits behind the named party rather than with them. That means aggregating holdings across designated parties and assessing control in fact, not just ownership percentage.
Where identifiers genuinely distinguish my customer from the designation, I document the discount with the specific points of difference and the sources used.
Where the data is insufficient to discriminate, the match stays unresolved and I escalate. Insufficient data is not a false positive.
The discipline that matters in sanctions specifically is that the default is to hold. Releasing on the basis that a match seems unlikely is the reasoning that appears in enforcement cases.
50How does the 50 percent rule affect your ownership analysis?
It means sanctions analysis has to run through the ownership chain rather than stopping at the named entity.
An entity owned fifty percent or more by one or more designated parties is treated as blocked even though it is not itself listed. Screening the entity name alone would miss it entirely.
The aggregation point is the one people get wrong. It is not fifty percent held by a single designated person — it is the combined holdings of all designated parties. Two designated individuals holding thirty percent each puts the entity in scope, though neither reaches the threshold alone.
So practically, once I identify any designated party in an ownership structure, I map all designated holdings rather than assessing that one line.
I would also note that this is a US-derived rule and other regimes differ, particularly the UK's control test, so the applicable regime determines the analysis.
51How do you handle control-based sanctions exposure below 50 percent?
Some regimes, notably the UK, capture control in fact regardless of ownership percentage, so a sub-threshold holding does not settle the question.
I would assess whether the designated party can direct the entity's affairs: board appointment or removal rights, veto powers over major decisions, enhanced voting rights, or arrangements where the entity is dependent on them for funding or business.
The practical difficulty is that these arrangements often sit in shareholder agreements rather than public documents, so I would request them rather than assuming their absence.
I would also consider whether the structure appears designed to sit below the threshold, since deliberately holding forty-nine percent while retaining control is a recognised evasion technique.
Given the consequences and the legal complexity, this is a referral to the sanctions team with legal input rather than an analyst determination — but I would flag the control indicators specifically rather than simply noting the percentage.
52What is your approach to PEP hit resolution?
Verify identity first, then classify, then assess whether the classification is right — because databases both over- and under-capture.
For identity I compare identifiers, weighting occupation and country of residence heavily since those usually discriminate faster than dates for PEP matches.
Then I confirm the role and whether it is current, using official sources rather than relying on the database entry, which may be stale.
Then classification: foreign, domestic, international organisation, or relative and close associate, since treatment differs.
The judgement step is assessing prominence against our policy definition. Databases frequently flag anyone employed by a state entity, and a mid-level employee of a state utility does not meet the regulatory test.
A reasoned declassification is legitimate and should be documented with the role and why it falls below the threshold. Applying EDD to every database flag wastes resource and dilutes attention from genuine PEPs.
53How do you assess adverse media credibility?
I weigh four things: the source, corroboration, the stage of any legal process, and recency.
Source independence and editorial standards matter most. A regulatory notice or court record is verifiable fact; a mainstream outlet with editorial accountability carries real weight; an anonymous blog carries little on its own.
Corroboration is the practical test. If a claim is genuine there is usually a trace elsewhere — a filing, a case reference, a mainstream mention.
Stage of process is where files most often go wrong. Allegation, investigation, charge, conviction and acquittal carry escalating and then reducing weight, and treating an allegation as equivalent to a finding is both unfair and analytically wrong.
Recency matters but seriousness matters more — an old fraud conviction may remain material where a recent commercial dispute does not.
And I would record the outcome as prominently as the allegation, since a file noting a charge without the acquittal misleads every future reviewer.
54How do you handle adverse media in a jurisdiction with a controlled press?
Cautiously in both directions, because the usual credibility tests do not work in the same way.
Reporting may be politically motivated — allegations against opposition figures or business rivals appear in state-influenced media routinely, so a domestic report is not necessarily reliable evidence.
Equally, absence of reporting proves nothing. In a suppressed media environment, genuine wrongdoing by connected individuals may simply not be reported at all, so a clean search is weak assurance.
So I would weight source independence heavily and look for international corroboration — reporting from outside the jurisdiction, investigative journalism consortia, or foreign regulatory and enforcement records.
I would also use structural indicators rather than relying on media alone: whether the individual's wealth is explicable, whether their business benefits from state contracts, and what the jurisdiction's corruption profile is.
And I would document the limitation explicitly rather than recording "no adverse media found" as though it were meaningful.
55What if adverse media relates to a company the UBO left years ago?
The timeline is decisive, so I would establish it precisely before assessing relevance.
The key question is whether they were in position during the conduct in question. Someone who was a director while the misconduct occurred is materially different from someone who joined afterwards or left before it began.
I would check appointment and resignation dates against the period the allegations cover, using registry filings rather than the customer's account.
Then their role — a board member with oversight responsibility is different from an employee with no involvement in the relevant function.
And whether they were personally implicated, or whether the finding was against the company with no individual attribution.
Where they were present and senior during the conduct, it remains relevant to their integrity regardless of elapsed time. Where the timeline clears them, I would document that reasoning specifically, so the finding does not resurface at every review without the resolution attached.
56How do you handle screening for non-Latin script names?
Transliteration is one of the main causes of both false positives and false negatives, so it needs deliberate handling rather than relying on the system default.
A single name can be rendered many ways in Latin script, and a customer may appear under several spellings across documents. So I would search known variants rather than the one spelling we hold, and use native script where the system supports it.
Name order is a related trap — conventions differ, and a system treating the first field as a given name will mismatch where the order is reversed.
Fuzzy matching is essential here, which raises volume, so the compensating control is better identifiers rather than tighter matching.
On resolution, I would be more cautious about discounting on spelling differences alone, since a variant spelling is exactly what a genuine match may look like.
Where our data quality is the constraint, that is a systemic issue worth raising rather than a case-by-case workaround.
57How would you reduce false positives without weakening detection?
Improve customer identifier quality first, because most false positives stem from having insufficient data to discriminate rather than from matching logic. A name with a date of birth and nationality resolves quickly; a name alone does not.
Then segment matching by risk, so higher-risk relationships get tighter settings and lower-risk ones are calibrated proportionately.
Then refine category filters for adverse media, so screening returns financial crime and regulatory content rather than all negative coverage.
Whitelisting helps but needs governance — entries should expire and be revalidated, and should be scoped to the specific matched record rather than the name broadly, or they suppress genuinely new material.
What I would avoid is loosening match thresholds indiscriminately. That reduces volume and detection together, and in sanctions specifically the asymmetry of consequences means conservative settings are justified even at the cost of noise.
58What are the risks of whitelisting?
Staleness is the principal one. A whitelist records that a specific match was assessed and discounted, but if it suppresses future matches on that name, it also suppresses genuinely new material.
The situation that illustrates it: a customer sharing a name with someone who was later designated, or who becomes the subject of new adverse media. The original discount was correct; applying it to the new information is not.
So whitelists need expiry and periodic revalidation rather than persisting indefinitely, and ideally should be scoped to the specific list entry or article rather than the name.
There is also a governance risk — whitelisting can be used to clear alert volume rather than to record genuine assessments, particularly under pressure.
So I would want whitelist additions documented with the same reasoning as any discount, and the population reviewed periodically. An unreviewed whitelist is an invisible suppression layer.
59How do you document a discounted match defensibly?
By recording the comparison rather than the conclusion.
Specifically: which identifiers were available on our side and on the list entry, which ones differed and how, what sources were used to verify, and the resulting conclusion.
The test I apply is whether another reviewer could follow it without repeating the search. "Discounted — not the same person" fails that immediately. "Customer DOB 1978 and Indian nationality; list entry DOB 1961, Nigerian nationality, no alias matching; verified against passport and electronic verification" passes.
Where the discount rests on weaker evidence, the documentation should say so rather than presenting it as conclusive.
I would also record what was not available, since a reviewer needs to know whether the discount was made on rich data or on a single differentiator.
Thin documentation on discounted matches is one of the more common examination findings, precisely because it is quick to produce and impossible to defend later.
60How do you know screening coverage is adequate?
By testing it, since alert volume tells you nothing about what is being missed.
The most direct method is injecting known names — including designated parties, PEPs, and variants with transliteration and name-order differences — and confirming they return. If a known designation does not generate a hit, coverage is failing regardless of how many alerts the system produces.
Then verifying scope: are all required parties screened, including beneficial owners, directors, signatories and relevant counterparties, or only the account holder?
And list coverage: are all lists relevant to our jurisdictions, currencies and client base actually loaded, and how frequently are they updated?
Data completeness matters too — screening runs on the data supplied, so missing fields mean effective non-screening for those records.
I would also sample high-risk customers manually to check for exposure that never surfaced, since that is the only way to detect a silent gap.
61How do you screen related parties on a complex entity?
By mapping who actually matters before screening, rather than screening whatever the system defaults to.
The core set is the entity itself, its beneficial owners including those identified through control rather than ownership, directors, and authorised signatories.
For higher-risk relationships I would extend to intermediate entities in the ownership chain, since a designated party may sit at an intermediate level rather than the top, and to known key counterparties.
For trusts that means settlor, trustees, protector and beneficiaries or class. For funds, the manager and controlling entities.
Former names and trading names matter too, since entities rebrand and screening the current name alone will miss historical designations or adverse media.
The failure mode is screening the customer name and stopping. Sanctions and PEP exposure sits behind the entity far more often than in it, which is precisely why beneficial ownership identification exists.
62What do you do when screening data quality is the underlying problem?
I raise it as a systemic control issue rather than working around it file by file.
Poor data causes failures in both directions. Missing dates of birth and nationalities mean matches cannot be discriminated, generating unresolvable alerts. Truncated names in payment messages mean genuine matches are missed entirely.
Analysts compensating manually is not a control — it hides the problem, produces inconsistent outcomes, and does not scale.
So I would quantify it: what proportion of records lack key identifiers, which populations are affected, and what the resulting alert and resolution rates look like compared with well-populated records.
Then escalate with that evidence, because a data quality argument without numbers rarely gets prioritised.
In the meantime I would flag affected records rather than resolving them on inadequate data, since discounting a match without sufficient identifiers is exactly the practice that appears in enforcement findings.
Quality, escalation and stakeholders (Q63–76)
63What makes a defensible KYC file?
One where another reviewer — internal QA, audit, or a regulator — can follow the reasoning to the conclusion without redoing the work.
Concretely that means: complete customer information with evidence of verification rather than assertion; ownership traced with the calculation and sources shown; screening results with resolution reasoning, not just an outcome; source of wealth corroborated where required, with any gaps stated; a risk rating with the factors that drove it; and approvals at the level policy requires.
The element most often missing is the reasoning connecting evidence to conclusion. Files frequently contain everything except an explanation of why, given all of it, the relationship was accepted.
The test I apply is whether someone could reach a different conclusion from the same file and I would have no way of showing they were wrong. If so, the reasoning is not recorded well enough.
64What do quality reviewers most commonly find wrong?
Conclusions without reasoning is the most frequent — a rating or a discount recorded with no basis, which cannot be assessed by anyone reviewing it.
Unverified information recorded as verified. A customer statement written into the file as though it were established fact, particularly on source of wealth or ownership.
Incomplete ownership tracing, usually stopping at an intermediate holder rather than the ultimate one, or applying the senior managing official without evidencing that the prior tests failed.
Weak source of wealth corroboration — narrative accepted without documents.
Screening hits closed with thin or no rationale.
And inconsistency: similar customers rated differently, or the same analyst applying different standards under time pressure.
The common thread is that most findings are documentation failures rather than judgement failures. The analyst often did the work and did not record it, which is indistinguishable from not having done it.
65How do you respond to QA feedback you disagree with?
Understand it precisely first, because disagreement often comes from different assumptions rather than substance — a difference over what the standard requires rather than what I did.
If I believe the finding is factually wrong, I would set out the evidence: the documents in the file, the sources checked, the reasoning recorded. Evidence changes minds; argument does not.
If the point is valid, I would accept it directly. Defending an indefensible file damages credibility more than the original error.
Where it is a genuine judgement difference, I would state my position, ask for it to be recorded, and accept the outcome. Being right matters less than the decision being properly considered and documented.
And I would look at whether the disagreement points to an unclear standard. If a reasonable analyst and a reasonable reviewer differ on the same file, the criteria probably need clarifying for everyone.
66How do you handle pressure from a relationship manager?
First by checking whether the pressure is reasonable, because sometimes it is. If our requests have been vague, piecemeal or disproportionate, the friction is ours and I would fix that before defending it.
Where the requirement is sound, I would explain the regulatory basis plainly and what specifically is needed. RMs generally respond better to "we need X because Y, and without it the file cannot complete" than to a policy reference.
I would offer to help — joining a client call, or explaining directly why source of wealth is required. That often resolves resistance faster than the RM relaying it second-hand.
What I would not do is reduce the standard because of revenue or relationship value.
If pressure persisted, I would escalate and document it, because sustained pressure on an analyst to lower a standard is itself a compliance concern independent of the file.
67How do you push back without damaging the relationship?
By being specific, consistent and useful.
Specific means naming exactly what is required and why, rather than issuing general requests. "We need the share transfer agreement and the last two years of audited accounts to evidence the source of wealth" is actionable; "we need more information on source of wealth" is not.
Consistent means applying the same standard regardless of who the client is. RMs accept requirements they see applied evenly far more readily than ones that appear discretionary.
Useful means consolidating requests so the client is approached once, giving realistic timelines, and flagging early rather than at the deadline.
I would also separate the requirement from the person — the objection is to the process, not to them, and treating pushback as personal escalates it unnecessarily.
Most friction in my experience comes from how requirements are communicated rather than the requirements themselves.
68When do you escalate rather than decide?
Four situations, and I would treat escalating appropriately as judgement rather than indecision.
Where the decision exceeds my authority — accepting a relationship that policy requires senior approval for, or waiving a documentation requirement.
Where risk factors conflict materially and I cannot resolve them on the evidence available.
Where the customer is uncooperative on something material, since that is a risk indicator rather than an operational obstacle.
And where I suspect financial crime, which goes to the MLRO regardless of anything else.
What I would not escalate is every borderline case, because that transfers work rather than performing it. If I am escalating a high proportion, that suggests either my threshold is wrong or the standards are unclear, and I would want to know which.
Escalation should come with my analysis and a recommendation, not just the file.
69How do you handle a case where you suspect financial crime?
I document the concerns factually, escalate to the MLRO through the internal route, and stop making enquiries that could tip off.
The documentation needs to be specific and neutral — what I observed, what the customer said, what I verified, what remains unexplained. Not characterisation of the customer, and not conclusions I am not in a position to reach.
On customer contact, this is the point where routine enquiries become risky. Questions that would be ordinary in another context can signal that something specific is being examined, so I would take guidance before contacting them further.
I would continue handling the relationship normally where required, which is uncomfortable but necessary.
And I would keep the information restricted to those who need it. The reporting decision belongs to the MLRO, not to me, and my role is to give them a complete and accurate basis for it.
70How do you ensure consistency across a team?
Written standards are necessary but insufficient on their own, because most inconsistency comes from differing interpretations of the same standard rather than ignorance of it.
Worked examples are what actually calibrate people — a set of real files with the reasoning explained, showing what adequate looks like for each customer type.
Calibration sessions where analysts assess the same case independently and compare reasoning surface divergence quickly, and the discussion is usually more valuable than the outcome.
QA with feedback that explains the reasoning rather than just recording pass or fail.
And monitoring outcome variation — if two analysts on similar portfolios have materially different rating distributions or EDD rates, that is inconsistency rather than differing judgement, and it is better we identify it than an auditor does.
A clear escalation path for borderline calls also helps, since it prevents individuals resolving ambiguity differently in private.
71How would you improve a KYC process you inherited?
By diagnosing before changing, because the visible problem is usually a symptom.
I would start with two data sources: where files fail QA, and where turnaround stalls. Those reveal the real bottlenecks rather than the ones people complain about.
Common root causes are unclear standards producing rework, poor customer data forcing manual effort, requests to customers made piecemeal so files wait repeatedly, and steps in the process that add no risk value but consume time.
I would fix causes rather than adding controls on top. The instinct when quality is poor is to add a review layer, which slows everything and treats the symptom.
I would also ask the analysts, since they generally know exactly where the process wastes time and are rarely asked.
And I would change one thing at a time with measurement, so improvement is demonstrable rather than assumed.
72How do you manage a backlog?
Triage by risk first, so the highest-exposure files are worked while the backlog is addressed. Working chronologically means a high-risk onboarding sits behind low-risk periodic reviews.
Then diagnose the cause, because the remedy differs entirely. Capacity shortfall, process inefficiency, and an upstream problem such as poor-quality submissions all produce backlogs and none is fixed by the others.
Then report the position transparently with a remediation plan.
That last point is the one that matters most. Backlogs become regulatory findings not because they exist but because they were concealed. A reported backlog with a credible plan is a manageable issue; one discovered in audit is not.
I would also put ageing metrics in place so the position is visible continuously, and specifically track ageing of high-risk files, since those should never be the ones waiting.
73What management information would you use?
Information that surfaces problems rather than demonstrates activity.
File volumes and ageing, broken down by risk rating, since aggregate figures hide whether high-risk files are the ones waiting.
QA pass rates by analyst and by file type — the file type breakdown matters because a pattern there indicates a standards or training gap rather than individual performance.
EDD completion rates and outstanding source of wealth evidence.
Overdue periodic reviews, which is a straightforward regulatory exposure.
Screening hit and discount rates, and override rates on risk ratings.
Escalation outcomes, since escalations that consistently close suggest the threshold is wrong.
What I would avoid emphasising is throughput per analyst. It measures activity rather than effectiveness, and optimising for it degrades quality in ways the metric cannot see.
74How do you handle a colleague producing poor-quality work?
Directly and constructively first, because most quality problems are knowledge or pressure rather than carelessness.
I would raise it with them specifically — pointing at what was missing in a particular file rather than making a general criticism — and offer help if it is a gap in understanding. Complex structures and source of wealth are areas where people frequently were never properly taught.
If it persists, I would escalate to a supervisor, framed as a quality issue rather than a personal complaint.
The reason it cannot be left is that poor files affect the firm's risk position, and if they pass QA sampling by chance, nobody else may catch it.
I would also consider whether it reflects something systemic — unrealistic volume targets, unclear standards, or inadequate onboarding. If one analyst is struggling, others may be too, and that changes the appropriate response entirely.
75How do you onboard a new analyst effectively?
By teaching reasoning before process, because process can be documented but judgement has to be developed.
I would start with why the controls exist — what risk each step addresses — rather than the click-path through the system. Analysts who understand the purpose can handle a case they have not seen before; those who learned the sequence cannot.
Then pairing on real files, with them doing the work and me reviewing rather than demonstrating.
Close review of early files with specific feedback, which is time-consuming and is the part usually cut short. Errors caught in week two do not become habits.
Then building complexity gradually — standard individuals, then corporates, then trusts and multi-layered structures — rather than exposing them to everything immediately.
And making it explicitly safe to ask. New analysts who guess rather than ask are the ones who produce quiet errors.
76What would you do if asked to approve a file you were not comfortable with?
I would decline to approve it and put my specific concerns in writing.
The reason is that approval means I assessed the work and agree with the conclusion. Signing off a file I do not believe in creates a false record and transfers the exposure to me personally, since my name is on it regardless of who pressed for it.
What I would propose instead is the legitimate route: if someone with authority to accept the risk wants to accept it, that should be their documented decision, with the gap identified and the rationale stated.
That is a normal outcome. Firms do accept exceptions; what matters is that they are visible, reasoned and owned at the right level.
If I were overruled by someone with that authority, I would accept it and ensure my assessment is on the record.
If asked to approve anyway without documentation, I would escalate that separately.
Regulatory expectations and programme (Q77–88)
77What do regulators focus on in KYC reviews?
Whether files evidence the reasoning, not whether procedures exist.
In practice they sample files and reassess them independently — reading the ownership analysis, the source of wealth corroboration and the screening resolution to see whether the conclusion is supported. Files that record outcomes without reasoning fail immediately.
They test whether risk ratings are justified and applied consistently, since inconsistent ratings across similar customers indicate the criteria are not working.
They check whether EDD was genuinely enhanced or simply longer.
They look at periodic review currency, because overdue reviews are easy to evidence and hard to explain.
And they look hard at whether previously identified deficiencies were remediated, which is consistently treated as the most serious finding because it demonstrates awareness without action.
78What are common findings in enforcement actions?
Incomplete beneficial ownership identification — files recording an intermediate holder, or applying the senior managing official without evidencing that ownership and control tests failed.
Source of wealth accepted without corroboration, which appears in almost every PEP-related action.
Overdue periodic reviews, often across large populations and extending years.
Inconsistent risk rating, where similar customers are rated differently with no discernible basis.
Screening gaps — parties not screened, lists not loaded, or discounts recorded without rationale.
And failure to remediate issues the firm had already identified internally, which is the aggravating factor that turns a control weakness into something closer to recklessness.
The pattern is that enforcement follows systemic weakness rather than a single bad customer, which is why programme-level thinking matters more than individual case quality.
79How does the risk-based approach apply to periodic review cycles?
Review frequency scales with risk — high-risk relationships reviewed annually or more often, standard risk on a longer cycle, lower risk longer still.
Trigger events override the schedule. A change in ownership, adverse media, a PEP designation, or a material shift in transaction behaviour should pull a review forward rather than waiting for the cycle.
The two requirements regulators test are that the cycles are documented and that they are actually met. A policy specifying annual review for high-risk customers, with a population of overdue high-risk reviews, is worse than a longer stated cycle that is honoured — because the firm has documented its own failure.
I would also make sure the review is substantive rather than a refresh of contact details. A periodic review that does not revisit ownership, source of wealth and actual versus expected activity is not a review.
80What is perpetual or event-driven KYC?
Continuously refreshing customer information as data changes, rather than waiting for a scheduled review date.
The logic is that a fixed cycle means information can be stale for most of the period. A customer whose ownership changed a month after their annual review carries an inaccurate file for eleven months.
Perpetual KYC replaces that with triggers — registry changes, adverse media, transaction pattern shifts, sanctions or PEP designations — that prompt review when something actually happens.
In practice it depends on data feeds and integration, so the customer record updates from external sources rather than from a scheduled human exercise.
The benefit is a shorter window of stale information and better resource allocation, since effort follows change rather than the calendar.
The requirement regulators will test is that it genuinely replaces periodic review rather than diluting it.
81What are the practical challenges of moving to perpetual KYC?
Data quality is the first. Continuous refresh depends on reliable external feeds, and where registry data is poor or unavailable, the model has nothing to run on. It works far better in jurisdictions with good public registers than in opaque ones.
Trigger definition is the second. Set triggers too broadly and every minor change generates a review, which is worse than the cycle it replaced. Too narrowly and material changes pass unnoticed.
Integration is a real constraint — customer data, screening, transaction monitoring and registry feeds have to connect, which many firms' architecture does not support easily.
And demonstrating equivalence to regulators. The firm needs to show that continuous refresh covers what periodic review covered, rather than being a lighter-touch alternative.
There is also a transition problem: the existing population still needs bringing up to date before perpetual monitoring is meaningful.
82How does KYC feed the enterprise risk assessment?
Through aggregation. Individual files answer questions about individual customers; aggregated they describe the firm's actual exposure.
The useful outputs are customer type distribution, jurisdiction exposure, PEP population, high-risk customer counts and their concentration, and the prevalence of complex structures.
That shapes control design and resourcing. A firm discovering that a substantial share of its portfolio sits in higher-risk jurisdictions has a different control requirement from one that does not.
It also validates the risk assessment. If a customer segment rated low is generating escalations or adverse findings, the rating was wrong and needs revisiting.
The failure mode is the risk assessment being prepared as a document without reference to what the KYC population actually shows. That produces an assessment describing the business the firm thinks it has rather than the one it has.
83What is the second line's role relative to yours?
Setting policy and standards, challenging risk decisions, testing quality, and holding the authority to override acceptance.
If I sit in the first line, they are my challenge function rather than my approval queue. That distinction matters — a second line that simply signs off what the first line proposes is not providing independent challenge, and the model exists on paper only.
Practically I would expect them to set the standards I apply, review a sample of my decisions independently, and be willing to disagree with an acceptance the business wants.
The relationship works best when challenge is expected rather than treated as obstruction. An analyst who resents second-line questions, or a second line that only ever confirms, both indicate the model is not functioning.
I would also expect them to own the aggregate view — patterns across files that no individual analyst sees.
84How do you keep up with regulatory change?
Through structured monitoring rather than reacting to what colleagues mention.
Regulator publications and consultations for the jurisdictions we operate in, so changes are assessed before they take effect rather than after.
FATF guidance and mutual evaluation reports, since those shape national requirements downstream.
Enforcement notices, which are the most practically useful source because they show exactly which failures are being penalised, at what cost, and what the regulator expected instead.
Industry bodies and peer discussion for interpretation, since the practical application of a requirement is often unclear from the text.
Internally, policy updates and training.
What I would emphasise is reading enforcement actions specifically. They are more informative than guidance because they describe real failures in real firms rather than principles, and the pattern across them is remarkably consistent.
85How would you implement a change in regulatory requirements?
Start with a gap assessment — what the requirement demands versus what we currently do — because the scope of change determines everything that follows.
Then update policy and procedures, which is the easy part and the part firms sometimes stop at.
The expensive question is the existing population. If the requirement changes what must be collected or verified, does it apply retrospectively? A remediation exercise across an existing customer base is usually the largest cost, and it needs deciding early rather than discovering later.
Then training, so analysts apply the change consistently from the effective date.
Then evidencing it through QA — sampling files after implementation to confirm the change actually landed rather than assuming it did.
And system changes where the requirement affects data capture or workflow, which typically have the longest lead time and should be started first.
86How do data protection obligations interact with KYC?
KYC processing generally rests on a legal obligation basis, so the lawfulness of processing is not usually the issue. What still applies is accuracy, proportionality, retention and access control.
Accuracy has real consequences here. Recording someone incorrectly as a PEP, or linking them to adverse media that concerned a different person, causes genuine harm and creates a correction obligation. So discount reasoning and correction of errors matter for data protection as well as compliance.
Proportionality means collecting what is needed for the risk rather than everything available.
Access restriction — customer files contain sensitive information and should not be broadly accessible.
Retention per the applicable period rather than indefinitely.
The tension people raise is subject access, where AML confidentiality can override normal rights, particularly regarding suspicion. That is a legal question rather than an analyst one.
87What role does technology play in KYC now?
Substantial in execution, limited in judgement.
Electronic identity verification has replaced much document handling, particularly for individuals, and does it more reliably. Automated registry retrieval pulls corporate data directly rather than through manual search. Entity resolution improves screening accuracy. Workflow automation routes files and tracks status.
Perpetual monitoring depends entirely on technology, since continuous refresh is not humanly possible.
Document analysis and structure extraction are improving, and can accelerate the mechanical parts of ownership tracing.
What it has not replaced is assessment — whether a structure has genuine commercial purpose, whether a source of wealth narrative is credible, or how to weigh conflicting evidence.
The practical effect is that it removes the repetitive work and concentrates analyst time on the difficult cases, which raises the skill level the role requires rather than lowering it.
88What are the limits of automation in KYC?
It cannot assess purpose, credibility or the weight of conflicting evidence — which is most of what makes a difficult file difficult.
A system can extract an ownership structure but cannot judge whether the complexity is commercially explicable. It can retrieve a source of wealth document but cannot assess whether the narrative is plausible given everything else known.
It cannot conduct a conversation with a customer and notice that the explanation shifted.
There is also an explainability constraint. Automated decisions must be justifiable to a regulator, and "the model rated it low" is not an answer, so automated risk rating requires the same governance as any model.
And automation inherits data quality problems — a system running on incomplete customer data produces confident, wrong outputs faster than a human would.
So the sensible boundary is automating the mechanical and evidencing steps, and keeping judgement human with the reasoning documented.
Scenario questions (Q89–95)
89A customer's structure spans four jurisdictions and ownership stops at a foundation with no public register. How do you proceed?
I would shift from ownership to control, because that is where the answer lies with a foundation — the structure deliberately separates legal ownership from benefit.
Specifically: who founded it, who the council or board members are, who can appoint or remove them, and who can direct distributions. I would request the charter, by-laws and any regulations governing distributions.
Where the register is not public, I would seek confirmation from the registered agent or a legal opinion from local counsel, since those carry more weight than customer attestation.
I would document precisely which elements were independently verified and which rest on customer-provided documents, because that distinction matters to any reviewer.
I would also assess whether the structure has coherent purpose. A family wealth-holding foundation is normal; the same structure holding an operating trading business is harder to explain.
If control genuinely cannot be established, I would escalate with a recommendation not to proceed rather than recording an unverified position.
90A PEP client's source of wealth is stated as a family business. What evidence would satisfy you?
I would want the claim broken into its components and each one corroborated independently.
Company registration and shareholding records showing their interest and how long they held it — that establishes the business existed and they owned part of it.
Audited accounts or regulatory filings demonstrating the business generated profit at a scale consistent with the wealth claimed. This is the step most often missing: a business can be real without generating the assets in question.
Dividend records, or sale and purchase documentation if they exited.
Tax filings where available, since declared income should broadly reconcile.
And for a PEP specifically, consistency with any public asset declaration the jurisdiction requires — a discrepancy there is highly significant.
What would not satisfy me is a narrative supported by documents that do not evidence it. I would map each component to a specific document and flag anything unmatched.
91A relationship manager escalates that your EDD request is losing them a major client. How do you handle it?
I would review my own requests first, because sometimes the friction is genuinely ours — requests made piecemeal, poorly explained, or asking for things we do not actually need. If any of that applies, I would fix it immediately.
Where the requests are proportionate, I would hold them and explain the regulatory basis plainly, including what happens if we complete a file without adequate source of wealth evidence.
I would offer to help directly — joining a call with the client to explain why the information is needed. Clients frequently accept requirements better when they hear the rationale from compliance rather than a second-hand relay.
I would also consolidate everything outstanding into a single clear request with a realistic timeline.
What I would not do is reduce the standard because of revenue. If the RM wanted to escalate, I would support that going to the right level for a documented decision rather than resolving it between us.
92During periodic review you find the UBO changed 18 months ago and was never disclosed. What now?
Two separate issues, and I would address both rather than simply updating the record.
The substantive one: complete full due diligence on the new beneficial owner — identification, verification, screening for sanctions, PEP status and adverse media, and source of wealth where the risk profile requires it. They are effectively a new party to the relationship.
The second, often overlooked: why was it not disclosed? Customers are usually required to notify material changes. Eighteen months of silence could be administrative oversight in a small business or deliberate concealment.
The answer matters. If the new UBO turns out to be sanctioned, a PEP, or subject to adverse media, non-disclosure reads very differently from a routine change nobody thought to report.
I would also review activity over the intervening period, since a change in control often coincides with a change in how the account is used, and document the non-disclosure explicitly as a risk factor.
93A file you approved is criticised in an internal audit. How do you respond?
Understand the specific finding first — what exactly was inadequate, and against what standard.
Then review my own reasoning honestly. If the point is valid, I would accept it directly rather than defending it, because defending an indefensible file damages credibility more than the original error.
If I believe the decision was sound, I would explain the basis with reference to what is in the file and let it be assessed on the evidence. That is a legitimate position provided the reasoning was recorded at the time.
The distinction I would draw is between a judgement audit disagrees with and a documentation failure. If the reasoning was sound but unrecorded, the finding stands regardless of whether I was right — an undocumented good decision is indistinguishable from a bad one.
I would also look at whether the standard needs clarifying for the team, since a finding against one analyst often reflects an ambiguity affecting everyone.
94You discover a colleague has been closing EDD files without obtaining source of wealth evidence. What do you do?
Escalate to a supervisor promptly rather than raising it informally, because this is a systemic control failure with a population of affected files behind it.
I would be factual about what I found — which files, what was missing, and how I came across it — without characterising motive, since I do not know it.
The reason it needs formal escalation is that the consequences extend well beyond one person. Those files may need remediation, the customers may be higher risk than recorded, and our reporting on EDD completion is inaccurate.
I would also flag that this often reflects pressure or training rather than misconduct — unrealistic targets, unclear standards on what corroboration means, or an analyst who was never properly taught. That framing usually produces a better outcome than treating it as an individual failing.
What I would not do is mention it quietly and let it continue, since the firm's risk position is affected either way.
95A long-standing corporate customer becomes majority-owned by an entity in a sanctioned jurisdiction. What is your first action?
Escalate to the sanctions team immediately, before completing my own analysis, and ensure no further transactions process pending assessment.
The reason for that sequencing is that ownership can bring the customer within sanctions restrictions regardless of their own status. If the acquiring entity is designated, or is itself majority-owned by designated parties, the customer may now be blocked — and every transaction processed in the meantime is potentially a breach.
Speed matters more than completeness here, which is different from most KYC work.
In parallel I would establish the facts: who the acquirer is, their ownership, whether they or their owners are designated, and whether the jurisdiction is subject to comprehensive or sectoral measures.
I would also identify pending payments, since those are the ones that settle while analysis is underway.
Customer communication would wait for guidance, since what can be said about a freeze is legally constrained.
Leadership and closing (Q96–100)
96How would you describe your risk appetite?
Proportionate rather than cautious or commercial, and I would frame it around what can be evidenced.
The distinction I draw is between risk that is understood and managed, and risk that cannot be explained. A high-risk customer with fully evidenced source of wealth, clear ownership and appropriate monitoring is a manageable relationship. A medium-risk customer whose ownership we cannot establish is not, despite the lower rating.
So my appetite is not about customer categories but about whether we can articulate the risk and demonstrate control over it.
I would also say I am conscious of de-risking. Declining business because it is complex rather than because it is unacceptable excludes legitimate customers and has been criticised by regulators.
And where risk is accepted, it should be a documented decision at the right level rather than something that happens by default because nobody escalated.
97Tell me about a time you changed your mind on a decision.
This needs a real example, and the value is in the mechanism rather than the outcome.
The structure that works: what you initially concluded and why that was reasonable on the information available, what new evidence emerged, how it changed the picture, and what you did about it.
Strong versions involve reversing toward greater scrutiny — accepting a source of wealth explanation, then finding something that undermined it. That demonstrates you follow evidence rather than defending a position you have already committed to.
Reversals the other way work too: escalating something, then finding a legitimate explanation. That shows escalation is not a one-way ratchet for you.
What interviewers are testing is intellectual honesty. Candidates who cannot recall changing their mind are usually either inexperienced or not examining their own reasoning, and both are concerning at senior level.
98How do you develop others in your team?
By explaining reasoning rather than answers, because that is what transfers to the next case.
When someone brings me a question, I try to work through how to think about it rather than telling them the conclusion. It takes longer and produces analysts who can handle a structure they have not seen before.
Specific feedback on files rather than general encouragement — pointing at what was missing in a particular ownership analysis is worth more than a quality score.
Letting people work through complexity with support rather than taking the case off them, which is faster in the moment and develops nobody.
And giving people stretch work before they feel ready, with review, since that is how people actually progress.
I would describe something I have genuinely done here rather than a philosophy, because the specifics are what make it credible.
99Where do you want to specialise?
Be concrete, because a clear direction reads as considered and "open to anything" reads as drift.
Credible answers include complex structures — trusts, funds and multi-jurisdiction ownership; EDD and source of wealth, which is where the hardest judgement sits; sanctions, which is a distinct discipline with its own severity; financial crime advisory; or team leadership and sign-off responsibility.
Whichever you choose, explain why with reference to what you have found interesting or difficult. Specialisation reasoning grounded in real experience is far more convincing than a stated preference.
Connect it to the role you are applying for, since a specialism the firm has no need for is not a selling point.
And be honest if you are still deciding — saying you want to deepen technical expertise before choosing a direction is a reasonable answer at mid-level.
100What questions do you have for us?
Have three or four ready, and make them operational rather than generic.
Good ones for a senior KYC role: what the customer mix and complexity look like; how quality is measured and what the current pass rate is; what the periodic review position is and whether there is a backlog; how escalation disagreements between analysts and second line are resolved; whether the firm is moving toward perpetual KYC; and what the last audit or examination found.
Those do two things. They tell you what the job is actually like — a firm with a large overdue review population is a different role from one that is current. And they demonstrate you think at programme level rather than file level.
Asking about the review backlog in particular signals experience, because anyone who has worked in a stretched function knows that is where the reality of the role shows.
Test your answers under pressure
Senior interviews probe with follow-up questions, which is where rehearsed answers break down. Practise a live AI voice and video interview on AGZIT, get a 10-competency scorecard, and build a free ATS-friendly resume when you register.
Deepen your technical edge
Senior KYC roles reward demonstrable depth in complex structures, EDD and due diligence practice. eStraLux training covers end-to-end workflows with real tool access and entity-based case studies.
leave your comment