Source-aware field guide · 20 answers
Compliance and Governance Operations
Plain-language records and workflows for due diligence, screening, monitoring, privacy, complaints, change control and oversight.
Published · reviewed for scope, source visibility and answer ownership
How to use this guide
Plain-language records and workflows for due diligence, screening, monitoring, privacy, complaints, change control and oversight. The guide is written for broker and prop firm compliance teams, founders, operations staff and software implementers. The collection organizes evidence and responsibilities. It is educational and cannot determine the legal requirements for a particular business.
Use every answer to resolve one operational question: Which policy, applicable requirement, evidence and accountable human support the decision, and when must it be reviewed? Legal definitions, thresholds, filings and retention periods vary by jurisdiction and activity. Qualified advisers and authorities remain controlling sources.
The supporting set is FATF — International standards on AML and CFT; OFAC — Sanctions list search; European Commission — Data protection in the EU. These links provide standards, regulator material or official product documentation for the subject; they do not imply endorsement, worldwide applicability or a verified feature in a particular deployment. Check the current source, contract, configuration and qualified local advice before a production, trading or compliance decision.
What Is KYC?
Know Your Customer describes processes used to identify and verify a customer and understand relevant risk under applicable law and policy.
- Use it to
- Map required data, evidence, providers, human decisions and refresh triggers.
- Check the boundary
- A document check alone may not satisfy the complete customer due-diligence process.
What Is KYB?
Know Your Business describes processes used to identify and verify a legal entity, its existence, ownership, control, representatives and intended relationship.
- Use it to
- Separate entity, person, ownership and authority evidence.
- Check the boundary
- Company registration does not prove ultimate ownership or permission to provide a service.
What Is AML?
Anti-money-laundering frameworks use risk assessment, due diligence, monitoring, reporting, governance and records to prevent and detect misuse under applicable requirements.
- Use it to
- Translate obligations into controlled workflows and accountable decisions.
- Check the boundary
- Buying screening software does not create a complete AML program.
What Is Customer Due Diligence?
Customer due diligence identifies and verifies customers and beneficial owners, understands the relationship and applies ongoing review under applicable requirements and risk.
- Use it to
- Connect onboarding evidence with monitoring and refresh events.
- Check the boundary
- CDD is not necessarily complete when an account first opens.
What Is Enhanced Due Diligence?
Enhanced due diligence applies additional information, verification, approval or monitoring where higher risk or a specific requirement warrants it.
- Use it to
- Define triggers, proportionate measures, decision authority and closure evidence.
- Check the boundary
- EDD should not become an unexplained request for every possible document.
What Is a Beneficial Owner?
A beneficial owner is ultimately a natural person who owns or controls a customer or on whose behalf a transaction is conducted, according to applicable definitions.
- Use it to
- Trace intermediate entities and document ownership and control separately.
- Check the boundary
- Thresholds differ and stopping at a holding company does not identify the ultimate person.
What Is a Politically Exposed Person?
A politically exposed person is an individual entrusted with a prominent public function under applicable definitions, with related family or associates handled according to the framework.
- Use it to
- Record the source, role, dates, relationship, risk review and decision.
- Check the boundary
- PEP status is not an accusation of wrongdoing and should not trigger automatic rejection.
What Is Sanctions Screening?
Sanctions screening compares customer, counterparty or transaction data with applicable current lists and restrictions, followed by match resolution and escalation.
- Use it to
- Preserve list version, input fields, matching logic, reviewer and outcome.
- Check the boundary
- Name similarity is not proof of a true match and missed aliases create false negatives.
What Is a Customer Risk Rating?
A customer risk rating combines documented factors under an approved methodology to support proportionate due diligence and ongoing review, while leaving accountable decisions reviewable.
- Use it to
- Version factors, weights or rules, evidence, overrides and refresh triggers.
- Check the boundary
- A numeric score is not objective truth and should not replace reasoned human review.
What Is Transaction Monitoring?
Transaction monitoring applies rules, models or review to activity in order to identify patterns requiring investigation under applicable policy and requirements.
- Use it to
- Version scenarios, data, thresholds, alerts, investigations and outcomes.
- Check the boundary
- An alert is a prompt for review rather than proof of suspicious conduct.
What Is Suspicious Activity Reporting?
Suspicious-activity reporting is a jurisdiction-specific process for escalating and, where required, filing information about suspected activity through authorized channels.
- Use it to
- Protect confidentiality and route decisions to qualified responsible officers.
- Check the boundary
- Publicly confronting a customer or treating an alert as guilt can create legal and fairness risks.
How to Design Compliance Record Keeping
Compliance record keeping preserves evidence, decisions, communications, versions and retrieval capability for required periods under access and integrity controls.
- Use it to
- Map each record class to purpose, owner, retention and disposal.
- Check the boundary
- Keeping data without searchable identifiers or context does not create usable evidence.
What Is Data Minimization?
Data minimization means collecting and retaining personal data that is adequate, relevant and limited to the stated purpose under the applicable framework.
- Use it to
- Challenge every field, copy and access path against the documented purpose.
- Check the boundary
- More data can increase risk and does not automatically improve verification.
What Is Valid Privacy Consent?
Valid consent under applicable privacy law generally requires a freely given, specific, informed and unambiguous indication with evidence and a way to withdraw where consent is the basis.
- Use it to
- Separate optional purposes and retain version, time and action evidence.
- Check the boundary
- Preselected boxes or bundled service conditions may not establish valid consent.
How to Handle a Data Subject Request
A data-subject request workflow receives, authenticates, searches, reviews, responds to and records a person's applicable privacy request within required scope and time.
- Use it to
- Balance identity verification, rights, exemptions and third-party data.
- Check the boundary
- Exporting one CRM profile may omit logs, providers and other systems.
How to Build a Data Retention Schedule
A retention schedule assigns record categories, purposes, applicable requirements, time periods, holds, deletion methods and accountable owners.
- Use it to
- Connect policy periods to actual system jobs and deletion evidence.
- Check the boundary
- Indefinite defaults and forgotten backups can defeat the published schedule.
How to Perform Vendor Due Diligence
Vendor due diligence evaluates legal entity, service scope, security, privacy, continuity, subcontractors, financial stability, compliance and exit for the proposed dependency.
- Use it to
- Scale evidence to criticality and track unresolved risks through approval.
- Check the boundary
- Certificates and questionnaires are point-in-time evidence, not permanent assurance.
What Is Model Governance?
Model governance controls the purpose, ownership, data, design, validation, changes, monitoring and human use of automated rules or statistical models.
- Use it to
- Inventory models and define where humans can review or override outcomes.
- Check the boundary
- Calling a score advisory does not remove its impact on real decisions.
How to Govern Marketing Approvals
Marketing governance reviews product claims, audience, evidence, risks, comparisons, channels and required approvals before publication and after material change.
- Use it to
- Retain the approved version and the sources supporting each objective claim.
- Check the boundary
- Disclaimers cannot rescue a false, unbalanced or outdated headline.
What Should a Compliance Board Report Include?
A compliance board report should present defined risks, breaches, complaints, monitoring, remediation, resources and decisions with trends and material limitations.
- Use it to
- Link summary metrics to accountable source records and requested actions.
- Check the boundary
- Green status without thresholds or overdue items can hide unresolved exposure.
Primary and official references
These sources establish definitions, standards or official product behavior used across this guide. Follow the exact source and check its current version before a live implementation.
