100 KYC Interview Questions for Experienced Professionals
100 KYC Interview Questions for Experienced Professionals
Interviews for experienced KYC roles work differently from entry level. Nobody will ask you to define CDD. They will hand you a complex ownership structure, ask how you reached a decision, and probe whether you can defend it — to a quality reviewer, to a relationship manager pushing back, or to a regulator.
These KYC interview questions for experienced professionals cover complex structures, EDD judgement, quality and escalation, regulatory expectations, and the leadership questions that separate senior analysts from team leads.
- Your experience and track record (Q1–12)
- Complex structures and beneficial ownership (Q13–30)
- EDD, source of wealth and judgement (Q31–48)
- Screening depth and resolution (Q49–62)
- Quality, escalation and stakeholders (Q63–76)
- Regulatory expectations and programme (Q77–88)
- Scenario questions (Q89–95)
- Leadership and closing (Q96–100)
What separates experienced candidates
The ability to say why you decided something, not just what you decided. Interviewers at this level probe for reasoning, trade-offs and what you would do differently. Answers that describe a process without a judgement call in them sound like someone who has followed procedures rather than owned decisions.
Your experience and track record (Q1–12)
1Walk me through your KYC experience.
Structure it by scope rather than chronology — customer types handled, jurisdictions, entity complexity, whether you did onboarding, periodic review, remediation or EDD, and what you owned versus what you escalated. Volume alone is less persuasive than complexity.
2What is the most complex case you have worked?
Pick one with genuine difficulty — a multi-jurisdiction structure, an unresolvable UBO, conflicting documentation. Explain the complication, what you did, what you concluded and why. This is the question that most differentiates candidates, so prepare it properly.
3What customer types have you handled?
Be specific — individuals, SMEs, listed companies, trusts, funds, SPVs, partnerships, charities, correspondent relationships. Each carries distinct documentation and ownership challenges, and naming them signals real exposure.
4Which jurisdictions have you worked with?
Name them and mention any that were operationally difficult — opaque registries, limited public records, unusual corporate forms. Awareness of where verification gets hard is a mark of experience.
5What systems have you used?
Name the case management, screening and registry tools you have genuinely used, and what you did in them. Do not overstate — follow-up questions on system functionality expose exaggeration quickly.
6What is your average file completion time and quality score?
Give real figures if you have them, with context — complex EDD files legitimately take far longer than standard onboarding. If you do not track them, say how your work was measured instead.
7Have you worked on a remediation project?
Describe the scope, the population, why it was triggered and your role. Remediation experience is valued because it demonstrates working to a defined standard at volume under deadline pressure.
8Have you dealt with regulators or auditors?
Say honestly whether you have had direct exposure or supported preparation. Having had your files sampled in an audit or regulatory review is relevant experience worth mentioning.
9Have you trained or mentored others?
Even informal coaching counts. It matters for senior roles because it signals you understand the work well enough to explain it and can raise the standard of a team rather than just your own output.
10What made you decide to leave your current role?
Give a forward-looking reason — greater complexity, ownership, specialisation. Criticising your current employer, however justified, reads badly and invites doubt about your discretion.
11What is a decision you got wrong?
Have a genuine example. Describe what happened, how it was identified, what you did and what changed in your approach. Claiming you have never made a mistake is not credible at this level.
12What do you want from your next role?
Be specific — more complex entity types, EDD ownership, a specialism such as trusts or funds, or a step toward team leadership. Vague ambition suggests you have not thought about direction.
Practise the delivery, not just the content
Experienced interviews probe reasoning under follow-up questioning — where prepared answers usually break down. Practise a live AI voice and video interview on AGZIT tailored to your target role:
- A real spoken interview that follows up on your answers
- A 10-competency scorecard showing where your reasoning is thin
- A free ATS-friendly resume builder once you register
- Your first AI interview is free
Complex structures and beneficial ownership (Q13–30)
13How do you identify the UBO in a multi-layered structure?
Trace ownership upward layer by layer, calculating effective holdings through each level rather than treating each layer separately. Where no one meets the threshold, look for control by other means — voting rights, board appointment powers, veto rights, or contractual influence.
14What is indirect ownership and how do you calculate it?
Ownership held through intermediate entities. You multiply through the chain — a person owning 60 percent of a company that owns 50 percent of your customer holds 30 percent effectively. Aggregate across all chains to the same person.
15What if no individual meets the ownership threshold?
Move to control tests, then to the senior managing official as a last resort. Recording the senior manager should follow a documented failure to identify ownership or control — not be used as a shortcut to close the file.
16How do you handle a trust?
Identify the settlor, trustees, protector if any, beneficiaries or class of beneficiaries, and anyone else with effective control. Trusts require a different mental model from companies because control and benefit are deliberately separated.
17How do you handle a discretionary trust with an unnamed beneficiary class?
Document the class rather than individuals, focus diligence on the settlor, trustees and protector who exercise control, and record how distributions are determined. Escalate where the arrangement obscures who genuinely benefits.
18What is a protector and why does it matter?
A person with powers over the trustees — often to remove or appoint them or veto decisions. It matters because real control can sit with the protector rather than the trustee named on the documents.
19How do you approach a fund structure?
Distinguish the fund, the manager, the general partner and the investors. Diligence usually focuses on the manager and controlling entities, with a risk-based approach to investors depending on the fund type and regulatory status.
20What is an SPV and what makes it higher risk?
A special purpose vehicle created for a defined transaction. Risk arises when the purpose is unclear, the structure is disproportionate to the activity, or it sits in a jurisdiction with no connection to the underlying business.
21How do you treat a listed company?
Companies listed on recognised regulated exchanges typically attract reduced ownership diligence because of disclosure obligations. Verify the listing and exchange rather than assuming — and note that the exemption usually does not extend to unlisted subsidiaries.
22What are nominee shareholders and directors?
Parties holding shares or office on behalf of someone else. They conceal the real controller, so identifying nominee arrangements and looking behind them is central to correct UBO identification.
23What indicators suggest a nominee arrangement?
A director holding office in an implausible number of unrelated companies, corporate service provider addresses, shareholders with no commercial connection to the business, and recently transferred shares with no consideration evident.
24How do you assess whether a structure has legitimate purpose?
Compare the complexity against the business rationale. Tax, regulatory, investor and succession reasons are legitimate. What concerns me is complexity with no explanation, jurisdictions with no operational connection, or a structure the customer cannot describe clearly.
25What if the corporate registry conflicts with customer-provided documents?
Investigate rather than pick one. Registries can lag recent filings, and customer documents can be outdated or wrong. Request evidence of any change, reconcile the difference and document how it was resolved.
26How do you handle jurisdictions without public registries?
Rely on certified constitutional documents, registered agent confirmations, audited accounts, legal opinions and customer attestations — while recording that independent verification was limited. That limitation should feed the risk rating rather than be ignored.
27What is a bearer share and why is it a problem?
A share owned by whoever physically holds the certificate, making ownership untraceable. Most jurisdictions have abolished or immobilised them; where they persist, they are treated as high risk requiring immobilisation evidence.
28How do you verify a beneficial owner you never meet?
Through certified identification documents, electronic verification, registry confirmation and independent data sources. The verification standard should reflect the risk — higher-risk UBOs warrant stronger evidence than a certified copy alone.
29When would you refuse to proceed on ownership grounds?
When the UBO cannot be identified after reasonable effort, when the customer refuses to explain the structure, or when the documentation is inconsistent and unresolved. An unidentifiable owner is itself a risk finding, not a gap to be waived.
30How do you keep ownership information current?
Through periodic review, trigger-event review on ownership changes, registry monitoring where available, and customer attestation. Structures change quietly, so a file accurate at onboarding may be wrong within a year.
EDD, source of wealth and judgement (Q31–48)
31What triggers EDD in your experience?
PEP involvement, high-risk jurisdictions, complex or opaque ownership, cash-intensive or high-risk sectors, adverse media, unusual transaction patterns, and any relationship rated high risk. Triggers should follow policy rather than individual discretion.
32What does good EDD actually involve?
Corroborated source of wealth and source of funds, deeper understanding of the business and its counterparties, expanded screening, senior approval, and a documented rationale for accepting the risk. Volume of documents is not the measure — corroboration is.
33How do you verify source of wealth?
Establish the narrative, then corroborate each material component with independent evidence — audited accounts and shareholding records for business wealth, contracts and tax records for employment, probate for inheritance, transaction records for asset sales. The test is whether total wealth is plausibly explained.
34What is the most common weakness in source of wealth files?
Recording assertion as though it were evidence. "Family business" or "successful entrepreneur" with no supporting documents is the single most cited regulatory criticism in this area.
35How much corroboration is enough?
Proportionate to risk and to the amounts involved. For a high-risk PEP with substantial assets, I would expect documentary evidence covering the material sources. For a moderate-risk customer, a credible narrative with partial corroboration may suffice — the reasoning must be documented either way.
36What if source of wealth cannot be fully evidenced?
Document what was obtained, what could not be verified and why, assess whether the unexplained portion is material, and escalate. Partial evidence with a reasoned assessment is defensible; a gap recorded as satisfied is not.
37How do you assess wealth that appears disproportionate to known income?
Treat it as a significant red flag, particularly for PEPs. Seek explanation and evidence for the gap, and where it cannot be credibly explained, escalate toward a suspicious activity report rather than accepting a plausible-sounding narrative.
38What is the difference between source of wealth and source of funds in practice?
Source of wealth explains the whole picture and takes longer to establish; source of funds explains a specific transaction. A customer can have a clean source of funds for one payment while their overall wealth remains unexplained — both matter.
39How do you handle a PEP relationship?
Confirm the classification and category, complete EDD with source of wealth corroboration, obtain senior management approval, set enhanced monitoring and a shorter review cycle. Never treat PEP status as a reason to decline outright.
40How do you handle a former PEP?
Reassess rather than automatically declassify — seniority held, time elapsed, residual influence, jurisdiction risk and adverse media. Document the reasoning for stepping down treatment.
41How do you assess a cash-intensive business?
Benchmark expected cash against the sector, size and location, compare cash against card and electronic receipts, review supplier and payroll patterns, and look for seasonality consistent with the trade. Deviation from the sector norm is what matters.
42How do you approach a correspondent banking relationship?
Assess the respondent's AML programme, ownership, regulatory standing and jurisdiction, establish whether nesting is permitted, and understand the products offered. The exposure is to customers you cannot see, so the respondent's controls are the control.
43How do you handle a customer in a sanctioned or near-sanctioned jurisdiction?
Determine precisely what is prohibited versus permitted, involve the sanctions team early, and treat proximity to a sanctioned state as a diversion risk requiring evidence of genuine local business rather than blanket refusal.
44What is your approach to a customer who refuses to provide information?
Establish whether the refusal is a misunderstanding or genuine resistance, explain the regulatory basis, and set a clear deadline. Persistent refusal on material points is itself a risk indicator and should be escalated, not negotiated away.
45How do you decide a risk rating when factors conflict?
Weight the factors most predictive of financial crime risk — ownership opacity, jurisdiction, PEP exposure, adverse media — over softer ones. Where genuinely balanced, rate higher and document why, since under-rating is the harder failure to defend.
46When have you overridden a system-generated risk rating?
Give a real example. Overrides are legitimate where the model misses context, but they must be documented with reasoning and usually require approval. Frequent undocumented overrides are a control weakness.
47What is your approach to de-risking?
Exit should follow unmanageable risk or non-cooperation, not customer category. Blanket de-risking is criticised by regulators and excludes legitimate customers, so the decision needs a documented, case-specific rationale.
48How do you balance thoroughness against turnaround pressure?
By front-loading the risk assessment so effort is concentrated where it matters, and by raising resourcing rather than quietly reducing depth. Consistently missing deadlines is a problem; silently lowering the standard is a worse one.
Screening depth and resolution (Q49–62)
49How do you resolve a complex sanctions hit?
Compare all identifiers against the list entry, consider ownership and control including aggregation across designated parties, and escalate rather than discount where data is insufficient. In sanctions, unresolved means held, not released.
50How does the 50 percent rule affect your ownership analysis?
An entity owned 50 percent or more by designated parties, individually or in aggregate, is treated as blocked even if unlisted. It means sanctions analysis must run through the ownership chain, not stop at the name.
51How do you handle control-based sanctions exposure below 50 percent?
Some regimes capture control in fact regardless of percentage. I would assess board influence, veto rights and funding dependence, and escalate to the sanctions team rather than clearing on the numeric test alone.
52What is your approach to PEP hit resolution?
Verify identity against multiple identifiers, confirm the role and its currency, classify the PEP type, and assess whether the database entry is reliable. Databases both over- and under-capture, so the classification decision is mine to reason and record.
53How do you assess adverse media credibility?
Source independence and reputation, corroboration, recency, and the stage of any legal process — allegation, charge, conviction or dismissal carry very different weight. A single anonymous source is recorded but not acted on alone.
54How do you handle adverse media in a jurisdiction with a controlled press?
Cautiously in both directions — reporting may be politically motivated, and absence of reporting may reflect suppression. I weight source independence heavily and seek international corroboration.
55What if adverse media relates to a company the UBO left years ago?
Establish the timeline. Presence during the conduct is materially different from association before or after it. Relevance depends on role, tenure and whether the individual was implicated.
56How do you handle screening for non-Latin script names?
Search known transliteration variants and native script where possible, and be aware that a single individual may appear under several spellings. Missing a variant is a common cause of false negatives.
57How would you reduce false positives without weakening detection?
Improve customer identifier quality first, segment matching by risk, refine category filters, and govern whitelists with periodic revalidation. Loosening thresholds indiscriminately trades detection for comfort.
58What are the risks of whitelisting?
Staleness. A match correctly discounted previously may relate to new reporting or a new designation now. Whitelists need expiry and revalidation, otherwise they suppress genuine hits.
59How do you document a discounted match defensibly?
Record which identifiers were compared, what differed, the sources used and the conclusion. Another reviewer should be able to follow it without repeating the search.
60How do you know screening coverage is adequate?
By testing — injecting known names and variants to confirm they return, and checking that all required parties and lists are actually in scope. Alert volume tells you nothing about what is being missed.
61How do you screen related parties on a complex entity?
Beneficial owners, directors, authorised signatories, and in higher-risk cases key counterparties and connected entities. Screening only the customer name leaves the most common exposure route open.
62What do you do when screening data quality is the underlying problem?
Raise it as a control issue rather than working around it case by case. Missing dates of birth or truncated names cause both false positives and false negatives, and that is a systemic fix, not an analyst workaround.
Quality, escalation and stakeholders (Q63–76)
63What makes a defensible KYC file?
Complete information and verification evidence, a reasoned risk assessment, screening results and their resolution, source of wealth corroboration where required, approvals at the right level, and reasoning another reviewer can follow.
64What do quality reviewers most commonly find wrong?
Conclusions without reasoning, unverified information recorded as verified, incomplete ownership tracing, weak source of wealth corroboration, and screening hits closed without documented rationale.
65How do you respond to QA feedback you disagree with?
Set out my reasoning and the evidence, and ask them to reconsider. If they maintain their position, accept it and ensure my view is recorded. Being right matters less than the decision being properly considered and documented.
66How do you handle pressure from a relationship manager?
Explain the requirement and the regulatory basis, offer to help gather what is needed, and hold the standard. If pressure continues, escalate and document it — the pressure itself is a compliance concern.
67How do you push back without damaging the relationship?
By being specific about what is required and why, giving realistic timelines, and separating the requirement from the person. Most friction comes from vague or repeated requests rather than the requirement itself.
68When do you escalate rather than decide?
When the decision exceeds my authority, when risk factors conflict materially, when the customer is uncooperative on a material point, or when I suspect financial crime. Escalating appropriately is judgement, not indecision.
69How do you handle a case where you suspect financial crime?
Document the concerns factually, escalate to the MLRO through the internal route, avoid tipping off, and continue handling the customer normally where required. The reporting decision is not mine.
70How do you ensure consistency across a team?
Written standards and worked examples, calibration sessions on borderline cases, QA sampling with feedback loops, and a clear escalation path. Consistency comes from shared criteria, not from individual diligence.
71How would you improve a KYC process you inherited?
Find where files fail QA and where turnaround stalls, since those reveal the real bottlenecks. Then fix root causes — unclear standards, poor data, unnecessary steps — rather than adding controls on top of a broken process.
72How do you manage a backlog?
Triage by risk rather than age alone, deploy resource to the highest-risk population first, report the position transparently, and address the cause. A hidden backlog is a regulatory finding waiting to happen.
73What management information would you use?
File volumes and ageing, QA pass rates by analyst and file type, EDD completion rates, overdue reviews, screening hit and discount rates, and escalation outcomes. Outcome data matters more than throughput.
74How do you handle a colleague producing poor-quality work?
Raise it constructively and directly first, offer support if it is a knowledge gap, and escalate to a supervisor if it persists. Quality failures affect the firm's risk position, so it cannot be left unaddressed.
75How do you onboard a new analyst effectively?
Start with the reasoning behind the controls rather than the click-path, pair them on real files, review early work closely with specific feedback, and build up complexity gradually.
76What would you do if asked to approve a file you were not comfortable with?
Decline to approve and state the specific concerns in writing. If overruled by someone with the authority to do so, ensure my position is documented. Signing off a file I do not believe in transfers the risk to me personally.
Regulatory expectations and programme (Q77–88)
77What do regulators focus on in KYC reviews?
Whether files evidence the reasoning, whether risk ratings are justified and applied consistently, whether EDD was genuinely enhanced, whether reviews are current, and whether the firm acts on known deficiencies.
78What are common findings in enforcement actions?
Incomplete ownership identification, source of wealth accepted without corroboration, overdue periodic reviews, inconsistent risk rating, screening gaps, and failure to remediate issues already identified internally.
79How does the risk-based approach apply to periodic review cycles?
Review frequency scales with risk — high-risk annually or more often, lower risk on longer cycles — with trigger-event reviews overriding the schedule. The cycles must be documented and actually met.
80What is perpetual or event-driven KYC?
Continuously refreshing customer information as data changes rather than waiting for a fixed review date. It reduces the window of stale information but requires reliable data feeds and clear trigger definitions.
81What are the practical challenges of moving to perpetual KYC?
Data quality, defining triggers narrowly enough to avoid constant reviews, integrating external sources, and demonstrating to regulators that continuous refresh genuinely replaces periodic review rather than diluting it.
82How does KYC feed the enterprise risk assessment?
Through aggregated exposure — customer types, jurisdictions, PEP counts, high-risk populations. That shapes control design, resourcing and board reporting.
83What is the second line's role relative to yours?
Setting policy and standards, challenging risk decisions, testing quality, and holding authority to override acceptance. If I sit in the first line, they are my challenge function, not my approval queue.
84How do you keep up with regulatory change?
Regulator publications and enforcement notices, FATF guidance and mutual evaluation reports, industry bodies and internal policy updates. Enforcement actions are the most useful because they show what is actually being penalised.
85How would you implement a change in regulatory requirements?
Assess the gap against current practice, update policy and procedures, define whether existing customers need remediation, train the team, and evidence the change through QA. The remediation question is usually the expensive part.
86How do data protection obligations interact with KYC?
KYC processes personal data under a legal obligation basis, but accuracy, proportionality and access restriction still apply. Recording someone incorrectly as a PEP or linked to crime carries real consequences.
87What role does technology play in KYC now?
Electronic verification, automated registry retrieval, entity resolution, perpetual monitoring and workflow automation. It removes manual effort but does not remove judgement — and automated decisions must remain explainable.
88What are the limits of automation in KYC?
It cannot assess whether a structure has genuine commercial purpose, judge whether a source of wealth narrative is credible, or weigh conflicting evidence. Those are the decisions the role actually exists for.
Scenario questions (Q89–95)
89A customer's structure spans four jurisdictions and ownership stops at a foundation with no public register. How do you proceed?
I would map what is verifiable, then focus on control rather than ownership — who founded it, who the council members are, who can direct distributions. I would request the constitutional documents and a legal opinion or registered agent confirmation, and record precisely what could not be independently verified. If control remains unidentifiable, that is a finding to escalate, not a gap to waive.
90A PEP client's source of wealth is stated as a family business. What evidence would satisfy you?
Company registration and shareholding evidence showing their stake and its duration, audited accounts or filings demonstrating the business generated wealth on that scale, dividend or sale records, and consistency with public asset disclosures. A narrative alone is exactly the weakness regulators cite most.
91A relationship manager escalates that your EDD request is losing them a major client. How do you handle it?
I would review whether my requests are proportionate and clearly explained — sometimes the friction is ours. If they are, I would hold the requirement, explain the regulatory basis to the RM and, if needed, join a call with the client. What I would not do is reduce the standard because of revenue.
92During periodic review you find the UBO changed 18 months ago and was never disclosed. What now?
Establish the current ownership and complete diligence on the new UBO, then assess why it was not disclosed — administrative oversight or deliberate concealment. Non-disclosure of a material ownership change is itself a risk indicator, and I would document it and escalate accordingly.
93A file you approved is criticised in an internal audit. How do you respond?
Understand the specific finding, review my reasoning honestly, and accept it if valid. If I still believe the decision was sound, I would explain the basis and let it be considered on the evidence. Either way I would look at whether the standard needs clarifying for the team.
94You discover a colleague has been closing EDD files without obtaining source of wealth evidence. What do you do?
Escalate to a supervisor promptly. This is a systemic control failure, not a personal disagreement — those files may need remediation, and it likely indicates a pressure or training issue that needs addressing at team level.
95A long-standing corporate customer becomes majority-owned by an entity in a sanctioned jurisdiction. What is your first action?
Escalate to the sanctions team immediately before anything else, and ensure no further transactions are processed pending assessment. Ownership can bring the customer within sanctions restrictions regardless of their own status, so speed matters more than completing my own analysis first.
Leadership and closing (Q96–100)
96How would you describe your risk appetite?
Frame it as proportionate rather than cautious or commercial. Good answers show you can distinguish manageable risk with adequate controls from risk that cannot be evidenced or explained.
97Tell me about a time you changed your mind on a decision.
Use a real example where new evidence shifted your view. It demonstrates you follow evidence rather than defending an initial position, which is exactly what senior reviewers look for.
98How do you develop others in your team?
Explain the reasoning behind decisions rather than just the answer, give specific feedback on files, and let people work through complexity with support rather than taking over. Describe something you have actually done.
99Where do you want to specialise?
Be concrete — complex structures, EDD and source of wealth, sanctions, financial crime advisory, or team leadership. A clear direction reads as considered; "open to anything" reads as drift.
100What questions do you have for us?
Ask about the customer mix and complexity, how quality is measured, the escalation path and how often it is used, whether the firm is moving to perpetual KYC, and how compliance and the business resolve disagreements. These reveal what the job is really like.
Test your answers under pressure
Senior interviews probe follow-up questions, which is where rehearsed answers break down. Practise a live AI voice and video interview on AGZIT, get a 10-competency scorecard, and build a free ATS-friendly resume when you register.
Deepen your technical edge
Senior KYC roles reward demonstrable depth in complex structures, EDD and due diligence practice. eStraLux training covers end-to-end workflows with real tool access and entity-based case studies.
leave your comment