Connect risk assessment to acceptance, customer and counterparty due diligence, monitoring, reporting, records, quality assurance and management oversight.
Why this workstream matters
Controls should reflect geography, customers, channels, assets, custody, cash exposure, counterparties and transaction behaviour. Generic policy wording does not demonstrate configured screening, KYT, cases, escalation or reporting.
What this guide covers
- Enterprise and product risk assessment
- Customer acceptance, CDD and EDD
- Beneficial ownership, PEP and sanctions
- Counterparty VASP due diligence
- KYT, alerts and suspicious activity
- Records, QA, staff and management information
How it connects to the application
Outputs must be consistent with the ownership structure, product and information flows, providers, business plan, staffing assumptions, policies and system behaviour. Any inconsistency should be resolved before filing or implementation.
Client inputs and dependencies
We confirm required founders, group records, product documentation, vendor information, system access, markets, transaction assumptions and responsible client personnel during scoping. The proposal separates adviser work, client responsibilities and third-party costs.