Customer profile and risk classification

Check whether the recorded customer profile reflects the actual relationship, ownership, activity and relevant risk factors. Risk ratings should be supported by a stated methodology rather than selected mechanically.

Due-diligence completeness

Review identity, address, beneficial ownership and purpose-of-relationship records as applicable. Missing, expired or inconsistent information should be visible in an exception process.

Ongoing monitoring

Consider whether actual activity remains consistent with the recorded profile and whether material changes trigger refreshed due diligence. The review should cover how alerts and unusual items are documented and resolved.

Recordkeeping and access

Test whether records are retrievable, protected from inappropriate access and retained in accordance with the applicable framework. Sensitive information should not be dispersed through uncontrolled channels.

Exceptions and remediation

Sample open exceptions and assess their age, ownership, escalation and closure evidence. A policy is effective only when unresolved issues are visible and acted upon.