Workflow guide / Workflows

KYC and KYB quality review

Plan a defensible review sample, classify defects, identify root causes, and track remediation to evidence.

StatusPublished
AudienceQuality assurance, Compliance operations
OwnerUWAY Compliance Team
Reviewed2026-08-02

Define the review question

Start with a decision the review must support. Examples include validating a new vendor, measuring analyst consistency, investigating a rise in rework, or confirming remediation after a policy change.

A broad instruction to "check KYC quality" usually produces an unfocused sample and findings that cannot be acted on.

Build the sample

Document the population, period, products, jurisdictions, customer types, outcomes, and exclusions. Use a combination of representative and risk-focused sampling where appropriate.

The sample record should explain why each case was eligible and how the final sample was selected.

Review each case

  1. Reconstruct the requirements and policy version in force.
  2. Confirm the evidence available to the original decision maker.
  3. Reperform the relevant checks without using hindsight as an undisclosed standard.
  4. Record defects against a controlled taxonomy.
  5. Separate factual errors, policy gaps, system defects, and judgment differences.
  6. Escalate material cases through the institution's approved process.

Defect taxonomy

ClassExampleTypical response
Missing evidenceRequired document or verification result absentCorrect case and review control design
Incorrect executionPolicy exists but was not appliedTraining, workflow, or supervision change
Policy gapRequirement is not translated into an operating rulePolicy and control redesign
System defectRouting or field logic produces the wrong stateEngineering remediation and regression test
Documentation weaknessDecision may be reasonable but cannot be reconstructedImprove reason and evidence capture

Report and remediate

Report both the observed defect rate and the limitations of the sample. Assign remediation by root cause rather than sending every finding back to analysts.

Each action should have an owner, due date, validation method, and evidence location. Close an action only after the change is deployed and a follow-up sample supports effectiveness.