Customer profile and risk classification
Check whether the recorded customer profile reflects the actual relationship, ownership, activity and relevant risk factors. Risk ratings should be supported by a stated methodology rather than selected mechanically.
Due-diligence completeness
Review identity, address, beneficial ownership and purpose-of-relationship records as applicable. Missing, expired or inconsistent information should be visible in an exception process.
Ongoing monitoring
Consider whether actual activity remains consistent with the recorded profile and whether material changes trigger refreshed due diligence. The review should cover how alerts and unusual items are documented and resolved.
Recordkeeping and access
Test whether records are retrievable, protected from inappropriate access and retained in accordance with the applicable framework. Sensitive information should not be dispersed through uncontrolled channels.
Exceptions and remediation
Sample open exceptions and assess their age, ownership, escalation and closure evidence. A policy is effective only when unresolved issues are visible and acted upon.
