Bank Statutory Audit
Statutory central and branch audit for public sector, private and co-operative banks.
Learn more
Banking & Financial Services
Customer due diligence, risk categorisation, record-keeping and transaction monitoring, tested against the applicable KYC and anti-money-laundering directions.
Overview
KYC failures are rarely dramatic. They are missing re-verifications, customers never re-risk-rated, alerts closed without a reason recorded, and beneficial ownership taken on trust. Each is minor alone; together they are exactly what an inspection finds and what a penalty attaches to. A KYC audit tests the file population rather than the policy document.
What this covers
Testing of onboarding CDD and enhanced due diligence against the applicable directions.
Whether customers are risk-rated, and periodically re-rated, on a defensible basis.
Coverage and timeliness of re-KYC across the customer base.
Identification and verification of beneficial owners for non-individual customers.
Alert generation, disposition quality and the audit trail behind closures.
Completeness and timeliness of prescribed regulatory reporting.
Retention and retrievability of identification and transaction records.
Common questions
The population, not the policy. We sample real customer files and real alerts and test whether due diligence was performed, evidenced and repeated as required, whether risk categorisation is applied and refreshed, and whether alert closures carry a documented rationale. A compliant policy with non-compliant files is the most common finding.
Related
Statutory central and branch audit for public sector, private and co-operative banks.
Learn more
Continuous branch-level audit that catches an exception in the month it happens, not in the year it is reported.
Learn more
Revenue leakage, branch inspection, currency chest and treasury operations audit.
Learn more
A short conversation is usually enough to establish whether this is the right route, and what it would involve.