Agentic AI/Featured

KYC evidence review beyond name screening

KYC is not complete when the names clear. A defensible review must establish identity, authority, ownership, purpose, expected activity, evidence quality, and human accountability.

18.08.2026·Agentic AI··12 min read·
Abstract cover art: a dashed boundary line between a field of scattered dots and a connected structure of nodes, with one focal node on the boundary. No text.

The names clear. The documents are present. The onboarding file is still not ready for approval.

This is the KYC failure that a checklist rarely exposes. Every requested file can appear in the folder while the underlying questions remain unanswered. The company extract may be stale. The person who signed may not have authority to bind the company. A beneficial-owner declaration may stop at a fund or nominee. The stated purpose may not explain the volume, countries, or counterparties shown in the supporting contracts. A missing document may have been marked "not available" without anyone deciding whether that gap is acceptable.

A name screen cannot resolve any of those questions. It can show that a particular identity, searched under particular terms and against particular lists at a particular time, produced no unresolved direct match. That result can be correct, but insufficient.

KYC is not a folder of documents and it is not a sequence of green checks. It is a set of claims that the institution is prepared to rely on:

  • this legal person exists and has been correctly identified;
  • these people may act for it;
  • these natural persons ultimately own or control it;
  • this is the purpose and intended nature of the relationship;
  • this activity is plausible for the customer and will form the baseline for ongoing review;
  • the remaining risk and any evidence gaps have been accepted by someone with authority.

The work of KYC evidence review is to test those claims against sources, expose conflicts, obtain what is missing, and give a human reviewer a decision that can be defended.

KYC review path from identity and authority through beneficial ownership, expected activity, RFIs, maker-checker review, escalation, and accountable human approval.
KYC becomes decision-ready when evidence claims, gaps, RFIs, and reviewer authority remain visible.

Begin with a case that appears complete

The following scenario is synthetic. It is not customer evidence, a performance claim, or legal advice.

Aster Vale Medical Systems AG, a Swiss medical-imaging supplier, applies for a business relationship with a regulated financial institution. The intake file contains a commercial-register extract, articles of association, a passport for the chief financial officer, a signed account-opening form, a beneficial-owner declaration, a business description, an ownership chart, and clear sanctions and PEP results for the parties named in the submission.

The business team sees a complete file. The compliance reviewer should see a series of propositions that still need to be established.

Identity review starts with legal existence, but it does not end there. The legal name, registration number, jurisdiction, legal form, registered address, status, formation date, and governing documents should resolve to one entity. Material aliases or former names should be connected to the same identity. The record should show which source established each fact and when it was retrieved.

In Aster Vale's file, the extract is eight months old. A current official record confirms that the company remains active, but it also records a recent address change and a change in signing authority. The old extract is not discarded. It remains part of the evidence history, labelled as superseded for the facts that changed.

That distinction matters. Replacing the old document without preserving the change would make the file look current while erasing the fact that the submitted evidence was stale. The stale document is not merely an inconvenience. It explains why the authority claim in the original submission was wrong.

Source authority and freshness are separate judgments. An official record may carry high authority but be too old for the decision at hand. A newly signed customer declaration may be fresh but self-asserted. A commercial database may be useful for discovery yet secondary to the underlying registry. Good evidence review records both dimensions instead of compressing them into one confidence score.

The current FATF Recommendations frame customer due diligence around reliable, independent source documents, data, or information. They are international standards directed to countries and implemented through national rules, not a substitute for the institution's exact legal obligations. Operationally, however, the point is clear: the reviewer must know what evidence the identity rests on.

2. Can the person at the keyboard bind the company?

Authority is often treated as an administrative detail after KYC. It belongs inside the KYC decision.

The current registry says Aster Vale's chief financial officer has collective signing authority with one other authorised person. The account-opening form carries only the CFO's signature. An attached board resolution appears to authorise individual execution, but it expired three months before the application.

The person is real. The signature is real. The authority claim is not established.

This is a different failure from identity fraud, and the remedy should reflect that. The case should not be labelled "screening failed." It should state that the customer identity is established but the authority to enter the relationship is unresolved. The RFI should ask for a current resolution or a valid second signature, not another passport.

That precision keeps remediation proportionate. It also prevents a familiar control gap in which an officer approves the customer but no one proves that the individual who accepted the terms could do so.

In the synthetic case, Aster Vale returns a current board resolution and the chief executive countersigns. The authority claim moves from unresolved to established. The original expired resolution remains linked to the RFI so a later reviewer can see why the additional evidence was requested.

3. Who ultimately owns or controls the customer?

The submitted chart shows a founder with 32 percent, an investment fund with 38 percent, and employees holding the remaining 30 percent. The declaration names the founder as the beneficial owner and treats the fund as an institutional shareholder requiring no further work.

That conclusion is too quick.

Beneficial ownership is not solved by locating the first percentage above a policy threshold. The reviewer must understand the ownership and control structure, including natural persons who exercise ultimate effective control through other means. FATF Recommendation 10 expressly connects beneficial-owner verification with understanding the ownership and control structure of legal persons. The FATF's 2023 guidance on beneficial ownership of legal persons also distinguishes legal ownership from ultimate ownership or control and supports a multi-source approach.

The fund's 38 percent interest may or may not create control. The answer depends on the fund structure, general partner, voting arrangement, board rights, vetoes, and other agreements. The absence of a named natural person in the customer chart is a gap, not evidence that no natural person needs to be considered.

The RFI asks for the fund's current registry information, the identity and ownership of its general partner or management entity, and the shareholder or side agreements that create control rights over Aster Vale.

The returned evidence identifies Mara Ionescu as the 60 percent owner of the fund's general partner. It also shows that the fund may appoint two of Aster Vale's five directors and veto new debt above an agreed threshold. Those rights are recorded as control facts for review, not converted by the system into an automatic declaration that Ionescu controls Aster Vale. The newly identified natural person is added to the relevant party set and screened. Her direct screening result is clear.

The human reviewer decides how the rights fit the institution's beneficial-ownership and control policy. The reviewer records the founder as an owner and Ionescu as a natural person relevant through the fund's control structure, with the exact reasoning attached. The important improvement is not the label. It is that the file no longer hides a corporate controller behind the word "fund."

The preceding article, Sanctions exposure through ownership and control chains, shows why the same source discipline becomes critical when those relationships intersect with sanctions rules.

4. Does the purpose explain the expected activity?

The intake form describes the relationship as receiving payments for medical-imaging components sold in Switzerland and Germany. Expected annual turnover through the account is CHF 3 million.

The attached distribution agreement tells a different story. It projects CHF 11.5 million and includes distributors in the United Arab Emirates and Türkiye. Neither corridor is inherently improper. The problem is that the evidence does not support the purpose and activity recorded in the form.

Purpose and intended nature are not marketing prose. They form the explanation for why the relationship exists and the baseline against which later activity can be understood. FATF Recommendation 10 covers understanding the purpose and intended nature of the relationship and conducting ongoing due diligence so transactions remain consistent with the institution's knowledge of the customer, its business, and risk profile.

If the baseline is generic or knowingly understated, later monitoring inherits a weak expectation. A CHF 9 million increase may look anomalous against the intake form even though it was visible in the contract from day one. Alternatively, the institution may suppress alerts because the relationship was labelled a medical supplier without documenting its actual distributors, products, and payment routes.

The evidence review therefore tests plausibility:

  • Do projected volumes reconcile across the application, business plan, contracts, and recent financial information?
  • Are the countries, currencies, products, customer types, and payment routes described with enough specificity to be useful?
  • Does the source of initial funding fit the ownership and financing records?
  • Are distributors or major counterparties missing from the party set?
  • Does a material media report relate to the same legal person, or only to a similar name?

Aster Vale explains that the CHF 3 million figure covered only the first Swiss distributor and submits a revised activity profile, signed contracts, recent financial statements, and evidence of the investor funding supporting expansion. The institution can now understand the higher volume and wider corridor set. The explanation does not make the risk disappear. It makes the risk assessable.

An adverse-media result concerning a similarly named distributor is also resolved by registration number and address. The match is disposed as a different legal person, with the identifiers and source preserved. A bare "false positive" would be weaker because it would not show how the conclusion was reached.

5. Does the risk level change the evidence standard?

Evidence sufficiency is risk-based. It should not become arbitrary.

The wider cross-border activity, layered fund ownership, and control rights cause the case to enter enhanced review under the synthetic institution's policy. That produces specific work: more detail on ownership and control, source of funds, key counterparties, expected corridors, and senior or MLRO review as required by policy. It does not justify asking for every document the customer possesses.

This is the difference between risk-based diligence and document accumulation. Enhanced due diligence should address the factor that created the higher risk. Each additional request should have a reason. Each returned item should close, narrow, or reframe a recorded gap.

Switzerland's FINMA overview of anti-money-laundering supervision states, among other duties, that financial intermediaries verify contracting partners, identify beneficial owners, clarify the background and purpose of unusual relationships or transactions, and clarify heightened-risk relationships in greater detail. The exact duties depend on the institution, applicable law, self-regulation, and facts. The operational lesson is that higher risk changes what must be understood, not simply how many PDFs are collected.

6. What happens when one gap cannot be closed?

At the end of the RFI cycle, Aster Vale cannot obtain a newly certified translation of an older fund charter before the onboarding deadline. The original charter and an uncertified translation are available. More recent official registry information and an executed bilingual shareholder agreement establish the current general-partner identity and the control rights material to the decision.

A weak workflow offers two bad choices: mark the file incomplete forever, or quietly tick the translation requirement as satisfied.

A controlled workflow makes the exception visible. The reviewer must decide whether the missing certification is material to the current ownership and control conclusion, whether alternative evidence covers the point, and whether policy permits acceptance. If the gap is accepted, the record must identify the missing item, the evidence used instead, the residual risk, any condition or expiry, and the person with authority to approve the exception.

Accepted evidence gaps require rationale and accountable approval.

In this case, the maker proposes accepting the bounded gap because the current controlling facts are supported by stronger and more recent sources. The checker returns the case once, asking the maker to identify which charter provisions remain relevant and why the bilingual agreement supersedes them for the decision. The maker adds the analysis. A checker who is different from the maker then accepts the exception under policy.

This is not administrative friction. It is human judgment becoming visible.

7. What is the final disposition, and what changes it later?

The final decision is not "KYC passed."

The maker proposes approval at a higher risk level with enhanced controls. The checker reviews the corrected authority, the fund-control analysis, the activity reconciliation, the adverse-media disposition, and the accepted translation gap. The accountable reviewer approves the relationship with these recorded conditions:

  • the expected activity baseline is CHF 11.5 million with the named corridors and distributor model;
  • the fund and general-partner control structure is part of the reviewed party set;
  • ownership, board-right, signatory, and material corridor changes trigger reassessment;
  • a six-month refresh applies under the synthetic policy;
  • activity that materially exceeds the documented profile is escalated for review;
  • the translation exception expires if the legal documents or control rights change.

The evidence moved the case from apparently standard to higher-risk but approvable. The human challenge changed the decision conditions. No one had to pretend that every uncertainty disappeared.

Ongoing review should preserve that history instead of overwriting it. A new shareholder register should not erase the one relied on at onboarding. A changed signatory should produce a dated change event. A new control right, sanctions hit, adverse-media finding, or material activity deviation should reopen the relevant claims and show why the assessment was refreshed.

This makes the KYC file a living decision record rather than a static folder that becomes obsolete the day after approval.

Human-in-the-loop is an authority design

Many systems say a human remains in the loop. That phrase means very little unless the human can do something consequential.

A meaningful reviewer must be able to inspect the source behind a fact, see contradictions and degraded evidence, return a case for a targeted RFI, change a proposed risk treatment, reject an unsupported disposition, accept a bounded gap with rationale, escalate to the required authority, and sign the final decision. The record must identify who acted and what changed because of the intervention.

If the reviewer can only click approve on a completed machine recommendation, the human is present but not in control.

cmpliance is assembling this KYC operating model around current components for source records and source-linked facts, screening context and dispositions, evidence-quality checks, contradictions, RFIs, and reviewer-state controls. Those components are designed to prepare decision context while preserving maker, checker, and escalation roles, open blockers, accepted residual risk, and rationale attached to state changes. The claim here is the operating model and its verified components—not a fully connected production sequence from acquisition and document extraction through screening, review, audit capture, and evidence-pack assembly.

The human decides whether the legal identity is sufficiently established, whether authority is valid, who counts under the applicable ownership and control policy, whether purpose and expected activity are plausible, whether EDD is sufficient, and whether an exception can be accepted.

That is the practical meaning of the agentic workforce for compliance. The agents do not make KYC less rigorous by removing work. They make the work legible enough for human judgment to focus on the claims that determine the outcome.

The next question is what the system must preserve so another officer can reconstruct that outcome without relying on the original reviewer's memory.

Next: Audit-ready evidence packs for compliance decisions

Agents do the work. Humans make the call.

Talk to cmpliance

Key Takeaways

A cleared name establishes only that a recorded screening query did not produce an unresolved direct match.

KYC should be reviewed as a set of source-backed claims about identity, authority, ownership, purpose, expected activity, and risk.

Human review is meaningful only when the reviewer can challenge the work, return it for evidence, accept a bounded gap with rationale, and own the final disposition.

Frequently asked questions

What must KYC establish beyond a clean name screen?

It must establish the customer's identity and legal existence, authority to act, beneficial ownership and control, purpose and intended nature, expected activity, and whether the evidence is sufficient for the assessed risk.

Can a KYC file be approved with an evidence gap?

Only where the applicable policy and law allow it, the gap is explicit, the residual risk is understood, the rationale is recorded, and an accountable person with the required authority approves it.

What makes human-in-the-loop KYC review meaningful?

The reviewer must see the evidence and uncertainty, have authority to stop or return the case, record a reasoned override or acceptance, and be identifiable in the decision record.

agentic complianceKYC/AML compliancecustomer due diligence (CDD)beneficial ownership (UBO)human-in-the-loop reviewenhanced due diligence (EDD)

Related Articles

Editorial signal

More evidence-led writing is coming.

We publish only when the argument can stand up to compliance review: source discipline, clear assumptions, and a defensible operating model.

Contact us