What to collect for each entity type, how to work a real file, how screening actually behaves, and how to build a career out of it. Start with Module 1, KYC Foundations if you haven't.
Entity types look like a memory test. They aren't. Every type asks the same five questions and only the documents change.
When you meet an entity type nobody trained you on, a Liechtenstein foundation, a Japanese kabushiki kaisha, a Delaware series LLC, you will not have a checklist. You will have these five questions, and they work every time.
Auditors found that €1.9bn supposedly sitting in two Philippine bank accounts had never existed. The banks said the documents carrying their letterheads were fabrications. The money was accounted for through third party acquirers and trustee arrangements that very few people had ever traced to the end.
The point: a document is only worth the independence of its source. Question one is does it exist, and the answer has to come from somewhere the customer does not control.
Pick an entity type and a risk level. This is built from what the regulations and normal practice require, so treat it as a starting point and reconcile it against your own policy.
Record which source verified each item and the date you checked it. And ask for what the entity is actually required to produce. Demanding audited accounts from a company that is audit exempt just teaches the relationship manager that you do not know the rules.
People collect documents to satisfy a list. The documents are evidence, and each one answers a specific question.
| Document | What it proves | What it does not |
|---|---|---|
| Certificate of incorporation | The entity legally exists, its number, its date and place of formation | That it trades, that the details are current, or who owns it now |
| Articles of association | How decisions get made, share classes, transfer rules | Who currently holds the shares |
| Register of members | Current shareholdings | Whether a holder is a nominee for someone else |
| Trust deed | The roles, the powers, the governing law, the purpose | Who currently benefits in practice, or where the assets came from |
| Board resolution | That the entity authorised someone to act | That the person signing the resolution had authority themselves |
| Financial statements | Scale, and whether the activity matches the story | Anything, if unaudited and prepared by the customer |
| Trade licence | Permitted activities, validity period, issuing authority | What the business actually does day to day |
A register of members showing "Northgate Nominees Ltd, 40%" has told you nothing about beneficial ownership. It has told you a layer exists. You need the declaration of trust, the nominee agreement or a written confirmation naming the person behind it, and if nobody will give you that, the answer is the file.
Four entity types that catch people out, and the specific thing that catches them.
No shares, so no percentages. You identify the settlor, the trustees, the beneficiaries or a description of the class, and anyone with control such as a protector or a power to appoint and remove trustees.
Work out who your customer actually is first. The fund, the management company, the general partner and the investors are four different things with four different risk profiles.
Ownership is the wrong lens. Nobody owns a charity. You are looking at control, at where the funding comes from, and at where the money goes, particularly cross-border.
The entity may be straightforward. The people around it may not be. Senior figures at a state owned enterprise are frequently politically exposed persons, and that brings enhanced due diligence and senior approval with it.
One file, worked end to end, with the mistakes left in. Everything here is invented.
| Field | What the pack says |
|---|---|
| Customer | Meridian Logistics FZE, a UAE free zone company |
| Product | Business current account with international payments |
| Introduced by | A relationship manager, who has flagged it as urgent twice |
| Stated activity | "Freight forwarding and logistics" |
| Expected turnover | $4m a year |
| Ownership | 70% an individual, 30% a Cyprus company |
| In the pack | Trade licence, passport for the 70% holder, a one page shareholder certificate, a bank reference |
Spend twenty seconds on what you would ask for next. Most people say "more documents". The useful answer names the specific question each missing document would answer.
Seven things in this file need a decision. Accept it, query it with the relationship manager, or escalate it. There is a right answer to each and it is not always escalate.
Escalating everything is as much a failure as escalating nothing. It clogs the second line, it trains people to ignore you, and it hides the two things that genuinely needed their attention.
The 30% Cyprus holding is where this file is decided.
Not "structure understood". Write the chain, the percentages, where each fact came from, the date, and the explanation you were given for why it is shaped that way. In two years that paragraph is the only thing standing between your colleague and a blank page.
Same file, same facts, two summaries. One survives a cold read. The other is what most files contain.
Customer is a UAE freight forwarding company introduced by the RM. Ownership structure reviewed and understood. All documents obtained and verified. Screening completed with no adverse findings. Risk rated medium. Recommend approval.
Meridian Logistics FZE, free zone licence 4471 valid to Mar 2027, freight forwarding between the UAE, Turkey and East Africa. Owned 70% by Mr A (passport verified, UAE resident) and 30% by Caldera Holdings Ltd, Cyprus, which the Cyprus registry shows is wholly owned by a BVI entity. Beneficial owners behind the BVI entity are not yet established. Mr A states the Cyprus layer dates from a 2019 investor arrangement; no documentation provided. Expected turnover $4m, around 30 to 40 payments a month, largest counterparties in Turkey and Kenya. Screening: one PEP near-match on Mr A discounted on date of birth and nationality, evidence on file. Not recommending approval until the BVI ownership is established.
Could somebody who has never seen this customer read your summary and reach the same decision you reached? If they would need to ask you a question to get there, the answer to that question belongs in the file.
Move the slider. These are the name variations that break screening in real life. The red dot marks the pairs that are genuinely the same person.
The bank admitted conspiring to breach US sanctions on Iran. In the 2007 to 2011 period it processed around 9,500 transactions worth roughly $240m. Customers had registered general trading companies in the UAE and used them as fronts for Iranian business. Total penalties came to around $1.1bn across US and UK authorities.
The point: name screening alone would never have caught this. The names on the payments were not sanctioned. The concealment was in the structure and the purpose, which is exactly what a good onboarding file is supposed to capture.
People lump these together and then treat them all the same way. They are not the same thing at all.
| Sanctions | PEP | Adverse media | |
|---|---|---|---|
| What it is | A legal prohibition | A risk factor | An open question |
| On a true hit | Stop. Freeze or reject per your policy, escalate immediately, do not tip off | Enhanced due diligence, source of wealth, senior approval | Investigate, then record what you concluded and why |
| Can you accept it? | No. Intent is irrelevant, this is strict liability | Yes, with the right process. Being a PEP is not wrongdoing | Yes, often. Much of it is old, wrong, or a different person |
| Timing | Onboarding and continuously, against list updates | Onboarding and at review, plus when someone takes office | Onboarding, review, and when something surfaces |
De-risking every PEP is not compliance, it is avoidance, and regulators have said so repeatedly. A PEP is a person with a higher corruption risk and a process attached. Refusing the whole category tells you nothing about the individuals you should actually be worried about.
Most of your screening work is closing false positives. Doing it well is a skill and doing it badly is how banks get fined.
Volume. Deadline pressure. "We cleared this one last month." A previous analyst's decision that carries no recorded reasoning. And never on the customer's own assurance that it isn't them.
An alert narrative is read by someone who was not there, possibly years later, possibly a regulator. Write for them.
Reviewed transactions. Activity appears consistent with customer profile. No further action. Closed.
Alert triggered on three inbound payments totalling $310k from a counterparty not seen before, 4 to 9 Sept. KYC records expected turnover $4m a year with counterparties in Turkey and Kenya. Counterparty is a Kenyan freight agent; invoices provided by the customer on 12 Sept match the amounts and dates and reference two container numbers consistent with the stated trade. Counterparty screened, no hits. Activity consistent with the recorded profile. Closed, no escalation. Reviewed by [name], 13 Sept.
What alerted and why. What the file said to expect. What you did to test it. What you found. What you concluded. Who and when. Five sentences, in that order, every time.
Indicative UK and US ranges, gathered in 2023 and not adjusted since. Treat them as shape rather than as current numbers, and check live postings before any conversation about money.
| Role | Level | UK | US |
|---|---|---|---|
| Junior KYC Analyst | Entry | £20k–28k | $35k–45k |
| KYC Analyst | Junior | £25k–35k | $45k–55k |
| Senior KYC Analyst | Mid | £35k–50k | $60k–75k |
| QA / QC Analyst | Mid | £40k–60k | $70k–90k |
| Team Lead | Mid | £50k–70k | $80k–110k |
| KYC Manager | Senior | £70k–90k | $110k–140k |
| Head of KYC | Senior | £90k–120k | $140k–180k |
| Director | Executive | £120k+ | $180k+ |
Day rates in remediation programmes run well above the permanent equivalent, and a lot of people build a career on them. The trade is no progression, no training, and a gap when the programme ends. A year or two of contract work mid-career is useful. Five years of it is a ceiling.
I have read a lot of these. The ones that work are specific about volume, entity types and systems, because that is what a hiring manager is actually trying to find out.
Responsible for conducting KYC reviews in line with regulatory requirements. Ensured compliance with AML policies and procedures. Liaised with stakeholders to resolve queries.
Worked a queue of 12 to 15 periodic reviews a week across UK and EU corporates, LLPs and trusts, including multi-layer structures to UBO. Cleared an average of 40 screening alerts a week on Fircosoft. Second-line QA pass rate 96% over 18 months. Trained two joiners on the entity matrix.
Work out your answer first, then open the card. What matters is not the fact, it is what the answer reveals about how you think.
They are testing whether you know trusts have roles rather than percentages.
They are testing whether you fold, and whether you are difficult about it.
The single most revealing question in the interview, and the one most people waste.
Testing whether you understand it or just know the vocabulary.
Most candidates have nothing. Having three good answers is a genuine differentiator.
File volume gets you to competent. It does not get you promoted. Four things do.
Analyst work is answering questions. Senior work is deciding which questions are worth asking. The first time you are asked whether a control is adequate rather than whether a file is complete, that is the jump, and nothing in the queue prepares you for it.