AI agent · Retail banking · Review against rules
KYC document review
Much of a KYC review is confirming that documents are present, current and consistent with each other. The agent does that part, document by document, and gives your reviewer a short list of what does not meet the policy and why.
Typical volumes for this process, not a client figure.
A file arrives, someone checks each document against a checklist.
Documents read and checked; only mismatches and expiries reach a reviewer.
Where the time goes today
A KYC file for a new client or a periodic refresh arrives as a bundle: identity documents, proof of address, company registry extracts, constitutional documents, ownership charts, beneficial owner declarations, sometimes financial statements. A reviewer opens each document, checks it against the checklist your policy sets for that client type and risk rating, and records what is present, what is missing and what has expired.
The checks are mostly mechanical. Does the name on the passport match the application, is the address proof within the permitted age, do the ownership percentages add up, is every beneficial owner above the threshold identified. They are also easy to get wrong on the fortieth file of the day. Names spelled differently across documents, dates in different formats, and ownership held through several layers of companies are where reviewers slow down or miss things.
Files then bounce back and forth. A missing document found at the end of the review restarts the clock, and the client is asked for things one at a time.
How the agent works
- Identify each documentThe agent classifies every document in the file, such as passport, utility bill, registry extract or ownership declaration, and lists any it cannot identify.
- Extract the factsIt reads names, dates of birth, addresses, issue and expiry dates, registration numbers and ownership percentages, keeping a link to where each came from.
- Check against policyEach requirement in your policy for this client type and risk rating is tested: present or absent, current or expired, consistent or not with the other documents.
- Trace ownershipFor companies, it follows the ownership chain through the documents supplied and lists the individuals above your threshold. Layers it cannot resolve from the file are marked as unresolved.
- Write up findingsThe reviewer receives findings in plain sentences, each tied to a policy requirement and the document concerned, with a draft request to the client covering everything missing at once.
What stays with a person
The reviewer decides on the file: whether the client is accepted, whether the risk rating stands, and whether an explanation from the client is sufficient. The agent does not judge whether an unusual ownership structure or a source of funds is adequately explained, and it does not clear screening matches. Those rest on judgement and on your risk appetite, and they stay with the people accountable for them.
Where the agent finds nothing to raise, the reviewer still signs off. What changes is that they check a short, sourced list of findings instead of rebuilding it from the documents.
What it reads, what it produces
| It reads | It produces |
|---|---|
| Identity documents for individuals | A findings list per file, each finding tied to a policy requirement |
| Proof of address documents | An extracted data sheet for the client record |
| Company registry extracts and constitutional documents | An ownership view with unresolved layers marked |
| Ownership charts and beneficial owner declarations | A draft request to the client listing everything missing |
| The application and existing client record in your onboarding system | An expiry calendar for documents held on file |
| Your KYC policy and checklists by client type and risk rating |
Controls that come with it
- The agent never approves a file; a named reviewer signs every decision.
- Screening matches for sanctions, politically exposed persons and adverse media are passed to the reviewer untouched, never dismissed by the agent.
- Each finding cites the policy clause and the document page it relies on.
- A regular sample of files with no findings is fully re-reviewed by a second person.
- Policy changes are loaded as new rule versions, and every check records which version it used.
How you know it works
- Agreement between the agent's findings and reviewers' findings on past files
- Reviewer time per file, before and after go-live
- Requests sent to the client per file, and time to a complete file
- Findings the agent missed that a reviewer or quality check caught later
Is your process ready?
- Written rules: your policy states, per client type and risk rating, which documents are required and how recent they must be.
- Systems: files can be read from your onboarding or document system, and your vendor licence allows automated access.
- Cheap check: a reviewer can confirm or reject each finding in seconds, because each one cites the document and the clause.
- Volume: hundreds of files a week, most complete or nearly so, repays the build; a small book of high-risk clients may not.
- Consistent process: reviewers in different teams apply the checklist the same way, or are willing to agree on one reading.
The five candidacy checks are explained, with an exam, in the free Module 01.
What goes wrong
- A policy that says 'recent' or 'satisfactory' without a number, which the agent cannot test and reviewers read differently.
- Low-quality scans and phone photographs, which need a clear rule for when the agent refuses to read rather than guesses.
- Name matching across transliterations and naming conventions, which needs explicit rules, not a similarity score alone.
- Expecting the agent to shorten files whose delay is the client's reply time; it can ask for everything at once, but it cannot make the client answer.
Questions we get
Does the agent verify that documents are genuine?
It checks consistency: names, dates and numbers that agree or disagree across documents, and whether each document is still valid. It does not replace document authentication tools or a trained person examining a high-risk document. If you already use a verification service, the agent reads its result, includes it in the findings, and flags files where the service returned nothing.
Does it work for periodic reviews as well as onboarding?
Yes, and periodic reviews are often the better place to start, because the existing record gives the agent something to compare against. It checks what has expired, what has changed since the last review and what the policy now requires that it did not before, then drafts one request to the client for everything needed.
How are policy changes handled?
The policy is held as a set of written rules that your compliance team owns. When it changes, the new version is loaded, run against past files to see which results change, and then applied. Every finding records the policy version it was checked against, so a file reviewed last year can still be explained by last year's rules.
What does a reviewer actually see?
A short list in plain sentences, such as 'Address proof is five months old; the limit is three', each linked to the document and the policy clause. Below it sit the extracted data and the ownership view. The reviewer confirms, overrides with a reason, or asks for more, and each of those actions is recorded against the file.
Want this agent on your process?
Tell us about your version of this process — volumes, systems, what goes wrong. A person answers with an approach and a price, usually within two working days, or tells you it is the wrong project.