The way we think about know-your-customer (KYC) has evolved rapidly over the last 10 years. We believe that an evolution of a similar magnitude will take place over the next two years driven by our evolving understanding, regulatory changes, and the rise of new processes made possible by artificial intelligence (AI).

This will allow firms to achieve ‘formless’ KYC updating, reviewing, and handling significant changes all automatically from their interactions with clients, but supported by a full and robust set of auditing, controls, and tracking.

At its core, KYC in private banking was historically something that was, at best, held in a patchwork of documents, or in a little ‘black book’ in the drawer next to a desk. As KYC regulations evolved, driven by both suitability and anti-money laundering (AML) requirements globally, we saw the rise of structured systems to gather and manage this data.

At Wealth Dynamix, we built this into our CLM (Client Lifecycle Management) tools, helping gather KYC from the first meeting to ongoing reviews.

Implemented correctly, this provides firms with:

  • A single ‘golden record’ of client KYC
  • A true audit trail of all changes to KYC across the lifecycle of a client, what was changed and by whom
  • Clear cycles to review and evidence changes within the KYC process

For many firms this still represents a distant goal with KYC spread across several systems, and with manual re-typing and poor-quality data.

But it is also not a panacea for all problems. It places a key emphasis on the rigour of staff to maintain KYC translating updates from their regular engagements with clients into systematic updates on the platforms used to maintain this data.

While the top quartiles of a firm’s front office staff will often apply rigour in using these systems, some staff may use them intermittently or not at all. This means that the quality of the data can be mixed, in some cases ‘peaking’ at the point of a client review and then slowly degrading until the next review is completed.

This is because data can be considered to have a ‘half-life’, rapidly degrading over time since the last review, with the rate of degradation increasing the longer the data is left unchecked.

KYC data qualuty degradation between review cycles

Solving this challenge

Wealth Dynamix has explored a number of different approaches to increase the frequency of updates across the entire client lifecycle and for all employees. One of the key focus areas is reducing friction for front office staff in making these updates to the tool, with ‘single page’ reviews, intelligent KYC forms, collaborative digital tools, and automated rules.

However, we believed that more was possible and, over the years, have looked both internally and with partners at how we might be able to automate the updating of KYC. This was always limited by technology constraints, but with the rise of LLMs (Large Language Models), we are now able to deliver a solution based on this concept: a perpetual KYC engine that updates KYC in real-time, based on client updates.

The core principles

  • KYC changes should be automatically identified from client interactions, not re-typed by staff.
  • Staff should not have to determine what rules apply to different data changes; the system should do it automatically.
  • Second- and third-line compliance checks for errors, coherence, and plausibility should automatically be built into change processes and become part of your first line of defence.

“We are now able to deliver a solution based on this concept: a perpetual KYC engine that updates KYC in real-time, based on client updates.”

The core constraints

All changes must be fully audited, with a clear trail on who approved, why, when, and what they changed. As it is regulatory data, KYC must be kept in a structured format to enable deterministic calculations and reporting – this is where traditional approaches are used, which can provide 100 percent certainty and consistency of answers.

Security is paramount. Robust guardrails are deployed to detect and prevent any attempts to compromise data, while granular access controls ensure that staff can only view and update the information relevant to their role.

With these in mind, our core engine is capable of ingesting unstructured and structured data from any source, identifying the potential parties impacted by the changes, and then processing this through a clear approval process.

Once a change is approved, this can be routed through deterministic change of-circumstances processes which are supported by clear audit trails along with robust checking and approval mechanisms. In so doing, changes that impact regulatory compliance rules are detected and routed to the correct team.

This combination of LLM approaches to detect changes connected to more traditional deterministic approaches to then calculate risk, suitability, FATCA, and more – provides the best of both worlds: significant automation of low-value tasks, combined with 100 percent certainty on rules and calculations.

After all, you can’t present a chat conversation to a regulator as the reason you onboarded a high-risk client!

Sources of data

  • Internal data from staff interactions, from call notes, to meeting transcripts, handwritten notes, emails, or secure messages
  • Documents from clients, from updated passports to Proof of Address documentation, or Source of Wealth (SOW) corroboration
  • Public data, from professional sources such as LinkedIn to public news stories
  • Private data, from B2B proprietary sources and aggregators to specialist high net worth (HNW) research databases and third-part providers

When considering public data sources, it is key to avoid crossing the line from insight into intrusion by ensuring transparency with clients on how you collect and source data a key element of global data protection rules and only utilising this in a respectful manner with the client.

This is where human judgement remains irreplaceable: the kind of nuanced decision-making that AI can inform, but never fully replicate.
 

So, what is the impact on you?

When implemented, Perpetual KYC has three core impacts:

  • An immediate reduction in the effort needed to maintain KYC
  • A secondary improvement on the quality of data
  • A continuous effect where lower effort and higher data quality leads to a virtuous loop of data improvement

This increased data quality encourages greater use of the data, which in turn drives further improvements in the quality of that data.

Prospecting

KYC files are automatically updated via fact-finding and initial engagements, supplemented by public data sources. Enhanced quality allows new angles to be identified such as mutual connections across a firm and an overall increase in conversion ratios.

Onboarding

Onboarding files are automatically populated via collected documents, alongside the enhanced data collected at the prospect stage. Agents automatically run coherence and plausibility checks, detecting potential issues earlier in the process, significantly reducing onboarding times and effort.

Ongoing Maintenance

Significant reduction in the front office and middle office effort required to maintain KYC Files and complete reviews, and KYC files are kept consistently up to date during the year.

Conclusion

The rise of AI is enabling a new approach to managing KYC and the associated prospecting, onboarding, and review processes. When done right, this leads to a virtuous circle, where improved quality drives usage, and usage drives further quality improvements.

However, in a regulated industry, this is only possible where it is underpinned by a deterministic layer, calculating risk, managing audit and security, and structuring data with 100 percent certainty.

Sign up to our Newsletter

Would you like to visit our French website?

GET THE BROCHURE
Client Onboarding