Skip to main content

KYC onboarding agent

A collected identity is not an approved customer.

A KYC onboarding agent organizes applicant evidence, ownership and control candidates, screening results and due-diligence questions for institutional review. The pattern Werkon would validate keeps identity resolution, evidence validation and applicant verification distinct, with missing or conflicting information visible. Qualified owners decide acceptance, rejection, enhanced due diligence, restrictions, reporting and ongoing monitoring under the applicable policy.

KYC job boundary

Prepare the evidence. Keep the customer decision human.

KYC is not one universal checklist. The agent can make a scoped case complete and reviewable, but law, risk appetite and accountable judgment determine what the evidence means.

01

Onboarding scope

Register the prospective relationship, applicant and representative; legal entity and institution; product and channel; customer type, jurisdiction and intended use; applicable rule and policy versions; risk and decision owners; notices, consent, language, accessibility, deadline and prohibited actions before collection.

Required evidence: Case and request identifiers, regulated entity and institution type, product and account purpose, applicant and representative roles, customer and entity type, jurisdictions, policy and source versions, risk owner, reviewer and delegation, notices and lawful basis, consent, language and accessibility path, effective time and expiry.

02

Identity and ownership evidence

Collect only required attributes and original evidence; resolve the person or legal entity, validate evidence and attributes against approved sources, verify the applicant under the selected method, map representatives, owners and controllers with effective dates, and preserve gaps or contradictions rather than inferring them away.

Required evidence: Person and organization identifiers, names and aliases, birth or formation data as required, addresses, evidence type, issuer, identifier and validity, original artifact and digest, authoritative validation response, verification method, registry records, ownership shares, control roles, relationship edges, source and observation times, consent and provenance.

03

Reviewable due-diligence packet

Run deterministic completeness, validity and policy checks; search only approved and current sanctions and risk sources; preserve query fields, normalization, list and data versions; present potential matches, alternatives, counterevidence, ownership gaps, expected activity and risk indicators without converting them into legal findings.

Required evidence: Policy and rule results, identity-assurance record, source and list identifiers and publication times, exact search inputs, transliteration and matching settings, candidate records and scores, identifiers and programs, false-positive counterevidence, business and expected-activity sources, jurisdiction and product factors, missing evidence and abstention.

04

Disposition and ongoing handoff

Route the complete packet to qualified compliance and business owners; record approval, rejection, enhanced review, restriction or hold with reasons and authority; separate any regulatory report; create the customer and account only through approved tools; retain receipts; notify through the lawful path; and schedule event-driven and periodic review.

Required evidence: Reviewer identity, qualification and delegation, decision, reason and policy factors, enhanced-due-diligence request, sanctions or legal escalation, reporting decision and separate record, approval conditions, scoped account request, idempotency and external receipt, notice and redress, review triggers, monitoring owner, correction and retention schedule.

Request-to-monitoring path

Bind every check to the law, policy, source, and date.

A name, document or registry record changes meaning with the institution, product, jurisdiction and time. The path makes those dependencies explicit and keeps every adverse inference reviewable.

  1. 01

    Define jurisdiction and purpose

    Confirm the regulated or policy owner, institution and product, prospective relationship, customer type, relevant jurisdictions, applicable rules and exceptions, risk appetite, required evidence and checks, decision authority, notices, accessibility, retention and redress.

    Owner
    Qualified legal, compliance, risk, privacy, and business owners
    Evidence
    Applicability memorandum, effective rule and policy versions, institution and product scope, customer taxonomy, jurisdiction matrix, required fields and sources, thresholds, reviewer roles, notices, lawful basis, consent, accessibility, retention and escalation map.
  2. 02

    Collect the minimum evidence

    Explain why each field is needed, support accessible digital and manual paths, preserve original evidence and consent, validate format and expiry, detect duplicates and hostile or forged media, and stop collection that is unnecessary, unsupported or outside the case purpose.

    Owner
    Onboarding, identity, privacy, accessibility, and security owners
    Evidence
    Field-purpose map, notices and consent, channel and session, original artifacts and digests, evidence and issuer, issue and expiry, collection and deletion times, duplicate and media-security results, applicant acknowledgement, assistance and exception path.
  3. 03

    Resolve, validate, and verify

    Separate identity resolution, evidence and attribute validation and applicant verification; query approved authoritative or credible sources; map entities, representatives, owners and controllers; record uncertainty, stale data and conflicting evidence; and offer qualified exception handling.

    Owner
    Deterministic identity and entity services with bounded extraction assistance
    Evidence
    Resolution candidates, validation responses, verification method and result, assurance level where applicable, entity and registry records, representative authority, ownership and control graph, effective dates, source quality, conflicts, exception handling and audit trail.
  4. 04

    Screen and prepare risk review

    Use current official or approved list data and versioned search settings, screen the right persons and entities, preserve potential-match evidence and counterevidence, apply deterministic policy gates, summarize expected relationship and risk indicators and route every material or uncertain case.

    Owner
    Sanctions, financial-crime, and customer-due-diligence owners
    Evidence
    List and dataset versions, query identities and fields, matching and transliteration settings, candidate details and programs, exact and conflicting identifiers, ownership propagation policy, jurisdiction and product factors, expected activity, enhanced-review triggers and case priority.
  5. 05

    Decide, enroll, and monitor

    Have qualified owners determine match and due-diligence outcomes, document disposition and reasons, keep reporting separate, create the approved customer and account through scoped tools, verify receipts, provide notice and redress and schedule periodic and event-driven review without rewriting the original case.

    Owner
    Authorized compliance, legal, business, reporting, and account owners
    Evidence
    Disposition and reason, reviewer and delegation, conditions and expiry, report decision and filing authority, account request and receipt, customer notice and redress, review schedule and triggers, source refresh, changed facts, restriction, closure, correction and retained history.

Authority model

Let software collect and compare. Keep legal findings named.

Identity evidence, data matching, risk signals and legal or business decisions are separate responsibilities. The agent supports the middle without owning the conclusion.

01

Deterministic scope and evidence controls

Code should own case, jurisdiction, policy, field purpose, consent, evidence, digest, issuer, expiry, identifier, source, list version, query, threshold, role, segregation, action scope, receipt, review trigger and retention checks.

  • Institution, product, customer type and jurisdiction applicability, required-field and document matrix, notice and consent record, accessibility and manual-path availability, policy effective dates
  • Identity-evidence format, issuer, validity and digest, authoritative-response binding, stable person and entity identifiers, ownership percentages, control roles, relationship arithmetic and effective dates
  • List and dataset publication time, exact query fields, normalization and transliteration settings, deterministic identifier agreement, candidate threshold, policy gate, case deduplication and queue priority
  • Reviewer role and delegation, segregation, account-create scope, idempotency and receipt, periodic and event-driven review, access expiry, export, deletion and correction checks
02

Bounded extraction and candidate support

A model may extract source-linked attributes, suggest entity relationships and rank potential name or record candidates. It cannot determine identity, ownership, sanctions status, criminality, risk class, account acceptance or reporting.

  • Document and registry attribute candidates with exact source locations, artifact or response digest, field confidence, deterministic validation, unreadable or forged-media flag, alternative and abstention
  • Person, organization, representative, owner and controller relationship candidates with source dates, shares, roles, conflicting records, incomplete chains and explicit assumptions
  • Name, alias and transliteration candidate ranking against a named list version with exact identifiers, programs, geographic and date context, alternatives, counterevidence and uncertainty
  • Case summaries and evidence requests that cannot label a person suspicious, infer protected traits, decide adverse action, reject an applicant, file a report, create an account or learn silently from reviewer outcomes
03

Qualified compliance and business authority

Named owners determine legal and policy applicability, source sufficiency, identity and ownership conclusions, potential-match disposition, risk classification, enhanced review, acceptance, restriction, reporting, monitoring and redress.

  • Institution and product scope, jurisdiction, customer type, due-diligence standard, beneficial-owner and control interpretation, source-of-funds or wealth need, risk appetite and exception policy
  • Identity and representative authority, ownership chain, registry conflict, sanctions or other list match, false positive, politically exposed person or adverse-information treatment where applicable and lawful
  • Enhanced due diligence, approval, rejection, restriction, account terms, filing or reporting, disclosure limits, customer notice, complaint, appeal, redress and professional or regulator communication
  • Ongoing review and monitoring, changed facts, investigation, account restriction or closure, access and provider approval, security and privacy incident, expansion, rollback and retirement

KYC-system components

Build a case that can explain what was known then.

Applicant statements, identity evidence, registries, screening lists, policy and account systems update on different schedules. Four components preserve their time and authority.

01

Case and policy registry

Bind regulated entity, institution type, product, relationship, customer type, jurisdictions, effective law and policy versions, risk appetite, required evidence and checks, reviewer authority, notices, consent, accessibility, retention, reporting and redress paths.

Operating contract: One checklist is not every jurisdiction, policy is not law, law effective today is not law at prior review, risk factor is not disposition, consent is not unlimited purpose, and digital-only is not an acceptable path for every applicant.

02

Evidence and identity registry

Preserve person and entity attributes, original artifacts and digests, issuers, validity, validation responses, verification methods, assurance, registries, representatives, ownership and control edges, effective times, conflicts, consent and provenance.

Operating contract: Document is not person, possession is not authority, validation is not verification, digital identity is not full KYC, registry is not necessarily current ownership, self-declaration is not independent proof, and old evidence never becomes new by reuse.

03

Screening and candidate engine

Acquire and version approved list and risk sources, bind queries to exact subjects, normalize and transliterate under versioned rules, calculate candidate scores, retain identifiers, programs, alternatives and counterevidence, prevent stale screening and queue material uncertainty.

Operating contract: Name similarity is not a match, no candidate is not no risk, list presence is not every legal consequence, geography is not guilt, a score is not a decision, and source refresh must not erase what a reviewer saw.

04

Review and lifecycle ledger

Route by qualification and delegation, capture findings and reasons, separate reporting, create approved customers and accounts through scoped tools, retain receipts, provide notice and redress, schedule reviews and preserve restrictions, changes, closures and corrections.

Operating contract: Reviewed is not approved, approved customer is not approved transaction, account created is not ongoing compliance, a filing decision is not a model action, closed case is not immutable truth, and later data never rewrites the original decision record.

Delivery path

Prove one customer and product scope before opening an account tool.

A system can appear complete on straightforward individuals and fail on representatives, legal entities, ownership chains, transliteration and inaccessible proofing. Start with a bounded legal and policy population.

  1. 01

    Observe the onboarding path

    Follow scope determination, notices, evidence collection, identity and entity work, ownership mapping, screening, enhanced review, decision, account creation, notice, redress, later refresh, correction, staff effort, provider cost, incidents and known harm.

  2. 02

    Define the case contracts

    Name applicant, representative, customer, entity, relationship, jurisdiction, policy, attribute, evidence, validation, verification, owner, controller, source, list, query, candidate, review, disposition, report, account, receipt, monitor, redress and correction fields and authorities.

  3. 03

    Run a shadow population

    Replay representative individual, representative, legal-entity, complex-ownership, stale-registry, alias, transliteration, weak-match, list-update, inaccessible-evidence, forged-media, trusted-referee, missing-consent, outage and adversarial cases without account creation, then compare with qualified decisions.

  4. 04

    Release a controlled cohort

    Limit institution, product, customer types, jurisdictions, channels, evidence, sources and tools; require human disposition for every case; verify source versions, reviewer authority, account idempotency, receipts, manual and redress paths, outage recovery and stop authority.

  5. 05

    Review after lifecycle events

    Compare evidence completeness, validation and candidate quality by segment, exception and review burden, account-create integrity, accessibility and redress, refresh and changed-fact handling, security, staff impact, provider and operating cost and harm before expansion or retirement.

KYC safeguards

Six controls before a due-diligence packet reaches decision.

The strongest controls prevent universal checklists, excessive collection, stale evidence, unexplained name matches, autonomous adverse decisions and indefinite retention.

Jurisdiction, institution, product, and policy time
Bind every case to the regulated or policy owner, institution type, product, relationship, customer type, jurisdictions, effective laws and policy versions, risk appetite, required checks, decision authority, reporting and review cadence; stop when applicability is unresolved.
Purpose, minimum data, accessibility, and consent
Map each field and source to a lawful and stated purpose; collect the minimum; provide notices, language, accessible and human alternatives, assistance and redress; record consent where applicable; prevent secondary use; and apply explicit retention and deletion.
Original evidence, identity steps, and provenance
Retain original artifacts and responses with digests; separate resolution, validation and verification; record issuer, validity, source and method; protect biometrics and sensitive data; expose forged, expired, weak and conflicting evidence; and never generate missing facts.
Entity, ownership, and authority graph
Use stable entity and person identifiers; version registries and organizational documents; calculate ownership exactly; record control and representative roles with effective dates; preserve incomplete or circular chains; and require qualified conclusions for beneficial ownership and authority.
List version, candidate explainability, and disposition
Screen the right subjects against current approved datasets; retain publication time, query fields, normalization and scoring; show identifiers, programs, alternatives and counterevidence; treat results as candidates; prohibit protected-trait proxies and require authorized match and risk decisions.
Permissions, security, lifecycle, and recovery
Separate collect, validate, screen, review, approve, report, create, restrict, close and administer capabilities; isolate tenants, encrypt data, protect secrets, log access, test restore, retain original decisions, refresh by policy and events, support export, correction and deletion and retire providers safely.

Outcome proof

Measure reviewable cases, not documents collected.

A system can collect more evidence and generate more hits while worsening access, review burden and harm. Proof follows each eligible applicant through scope, evidence, candidates, qualified decision, account action, redress and lifecycle review.

Baseline

  • Cases by institution, product, customer and entity type, jurisdiction, channel, language, accessibility need, evidence path, ownership complexity, source, list, candidate, exception, enhanced review, reviewer, disposition, account, redress, refresh, correction and known outcome
  • Current evidence by scope and policy version, notice and consent, original artifact and digest, validation response, verification method, entity and ownership sources, list and query version, candidate details and counterevidence, decision and reason, report record, account receipt and review
  • Manual scope analysis, applicant assistance, evidence review, registry search, ownership mapping, screening, false-positive investigation, enhanced due diligence, decision, reporting, account creation, notice, redress, refresh, correction and audit-support effort, queue age, interruption, provider fees and operating cost
  • Wrong jurisdiction, identity, entity, representative, owner, source, list, candidate, risk, disposition, report, account or review; excessive or inaccessible collection; discrimination; exposed data; failed redress or recovery; control override and harm

Outcome evidence

  • More eligible cases reach qualified reviewers with correct scope, minimum and source-linked evidence, explicit identity steps, time-safe ownership and screening sources, inspectable candidates, counterevidence and owned exceptions
  • Fewer stale, excessive, inaccessible, cross-customer, unsupported or autonomous conclusions enter decisions, and every adverse or consequential outcome retains named authority, reason, separate reporting, account receipt, notice, redress and correction
  • Applicants complete more suitable evidence paths without losing human or accessible alternatives, while qualified teams spend less avoidable time reconstructing routine sources and retain discretion for complex ownership, weak matches and changed facts
  • Comparable cohorts expose evidence and validation quality, candidate precision and workload, abstention, review agreement, enhanced-review burden, accessibility, redress, account-create failures, later changes, incidents, effort, cost and harm without assuming compliance or fraud reduction

Guardrails

  • Institution, product, applicant, person, entity, representative, owner, evidence, registry, list, query, candidate, reviewer, report or account is misbound; original evidence is lost; data crosses tenant, customer, role or purpose boundaries; or retention exceeds qualified policy
  • A document is treated as a person, a registry as current truth, an ownership gap is filled by inference, list data is stale, a fuzzy name becomes a sanctions finding, absence from a list becomes low risk, nationality or location becomes guilt or model text fabricates evidence
  • The agent sets risk appetite, determines identity, beneficial ownership, match or criminality, approves or rejects a customer, creates an account, files a report or learns silently from decisions; reviewers lack current sources, qualification or independent authority; or applicants lack redress
  • Outage loses evidence or decisions, replay duplicates accounts, restore changes case history, failed target calls appear successful, reviews lapse unseen, list refresh overwrites prior evidence, access survives role change, records cannot be exported or deleted or expansion precedes segment proof

Agent fit

Use this pattern when one legal scope and customer cohort are explicit.

Good reason to begin

  • The organization can bound one institution, product, customer type and jurisdiction set and name legal, compliance, risk, identity, ownership, sanctions, business, account, reporting, privacy, security, accessibility, retention, redress, correction, baseline, cost, harm and stop owners.
  • Applicable rules and policy versions are documented; original identity and entity evidence retain stable digests and provenance; authoritative and list sources expose versions and timestamps; reviewer authority is explicit; and account tools support scoped access, idempotency and receipts.
  • Representative individual, legal-entity, representative, ownership, registry, alias, transliteration, weak-match, inaccessible, forged-media, missing-consent and changed-fact cases plus qualified decisions exist for shadow evaluation by customer and risk segment.
  • The team can abstain, offer assisted and accessible paths, hold cases, revoke credentials, preserve manual review, separate reporting, provide notice and redress, refresh sources, correct visibly, export and delete evidence, roll back versions and retire the agent safely.

Resolve before beginning

  • Institution and product scope, jurisdiction, customer type, identity evidence, beneficial ownership, source authority, list selection, risk appetite, match disposition, acceptance, reporting, monitoring, privacy, accessibility, retention, redress or correction responsibility is unclear or disputed.
  • Rules are undocumented, evidence lacks provenance, authoritative or list sources cannot be versioned, ownership cannot be represented, identity paths exclude applicant groups without alternatives, account credentials cannot be scoped, or no qualified owner can make and explain decisions.
  • The desired first step permits universal KYC logic, excessive collection, autonomous beneficial-owner inference, fuzzy-hit rejection, protected-trait profiling, automatic customer approval or denial, regulatory filing or silent learning and omits qualified legal, compliance and redress paths.
  • The business case depends on unverified compliance, fraud prevention, perfect identity, zero false positives, automatic approvals, reduced headcount, exact savings, onboarding speed, customer conversion, account growth or financial outcome.

Source basis

Sources behind the control model.

  • 01

    Financial Action Task Force

    The FATF Recommendations

    The Recommendations, last amended in June 2026, set an international framework for anti-money-laundering, counter-terrorist-financing and counter-proliferation-financing measures, including risk-based customer due diligence. Countries implement the standards through measures adapted to their circumstances. They are not one directly applicable global law, an onboarding checklist, a customer decision or proof of compliance.

  • 02

    United States Financial Crimes Enforcement Network

    Customer Due Diligence Rule FAQs

    The FAQs updated on 6 May 2026 describe the US CDD Rule for specified covered financial institutions and February 2026 relief from identifying and verifying beneficial owners at every new account opening, subject to stated circumstances and risk-based procedures. This scope is separate from Corporate Transparency Act reporting changes and does not apply to every institution, customer, product or jurisdiction.

  • 03

    National Institute of Standards and Technology

    NIST SP 800-63A-4, Identity Proofing and Enrollment

    The final July 2025 guidance defines identity resolution, evidence and attribute validation, applicant verification, assurance levels, exception handling and enrollment for digital identity services, principally in a US federal context. It does not define legal-entity KYC, beneficial ownership, sanctions screening, customer risk, account acceptance, AML reporting or compliance with another jurisdiction.

  • 04

    United States Office of Foreign Assets Control

    Sanctions List Service

    The service provides current OFAC sanctions-list data and a search tool that uses fuzzy logic to surface potential matches. OFAC FAQ 5 describes further assessment of potential matches. These are US sanctions resources, not a global KYC rule, and a fuzzy candidate is not a valid match, legal conclusion, customer rejection or proof that a screening program is complete or compliant.

[ WORKFLOW / SYSTEMS AUDIT ]
THE FIRST ENGAGEMENT

Start with one real workflow

A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.

Show Us the WorkflowStart with the free automation readiness checklist

OBSERVEQUANTIFYDECIDEBUILD