KYC compliance: what kyc programs a small US firm runs, the kyc onboarding compliance requirements behind them, and what kyc compliance software has to keep

Updated

KYC compliance is usually described as a set of steps at the front door and judged on something else entirely, which is whether the file survives being asked for later. A firm can identify every customer correctly on the day and still fail the only test that matters, because the evidence went into four inboxes and the review date went nowhere. This page is about the version of KYC compliance that holds up eighteen months on, and what that means for the software you keep it in.

The four things a customer file is asked for

Almost every version of this question resolves to the same four things. Who is the customer, and what evidence do you hold that they are. If the customer is a company, which individuals are behind it. What risk rating did you give them, on what basis, and who approved it. And when did somebody last look at the file again. A firm that can answer all four for a customer taken on two years ago is compliant in the way that counts. A firm that can answer the first two only has a good onboarding screen and no file.

Programs fail on the fourth question, not the first

Onboarding is the part everyone builds. It has a screen, an owner and a visible failure mode, so it gets attention and it usually works. Periodic review has none of those: nothing goes wrong on the day it is missed, the customer does not complain, and the failure only becomes visible when somebody asks for the file. That is why the honest measure of a KYC program is not how good the onboarding flow is, it is what share of the book has no recorded review date. The free checklist on this site asks for that number because most firms have never counted it.

What KYC compliance software has to do, and what it does not

The useful software here is a record with dates on it, not a workflow with a lot of screens. It has to hold one file per customer, attach the evidence to the file rather than to a message, carry the risk rating with the reason and the approver, and produce a review date that arrives on its own. Everything else in the category is a different product: screening against sanctions and watchlists, monitoring what a customer does after onboarding, and capturing identity documents are three separate purchases, and a tool that claims all of them at this size is usually good at one.

Questions people ask about kyc compliance

Does KYC compliance mean the same thing for every firm?

No, and anybody who tells you it does is selling something. What you have to collect depends on what you are, who your customers are and which rules apply to you, which is a question for your own policy and, where it matters, your own counsel. What is common across nearly every version of it is the shape: identify, rate, approve, review, and be able to produce all four. Software can hold that shape. It cannot tell you what your rules are.

Where do KYC programs usually break?

At the review, and quietly. A program that opens files well and never reopens them looks healthy on every internal dashboard until the day somebody asks how many customers have not been looked at since onboarding. The number is nearly always higher than the compliance owner expects, because nothing in a shared drive or a spreadsheet counts it.

Do we need KYC compliance software or will a spreadsheet do?

A spreadsheet is a perfectly good list of customers. It is a bad clock and a worse audit trail: it does not tell anyone that a file opened in March is due in March two years later, and it does not record that the rating was approved by a particular person on a particular day. Those two gaps are what a purpose-built record closes.

Sources

Related answers

Start Clientvo ProKeep the files, $29 a month