Knowledge base topic · 9 entries
Onboarding Governance
Build practical onboarding review records for entity roles, ownership, screening, funding evidence, privacy choices and accountable case decisions.
Published Updated
Browse the entries in this topic
Understand the topic
An onboarding system collects information; governance determines how that information becomes a justified decision. A company record, screening result or completed upload may answer one narrow question while leaving another unresolved. This collection helps reviewers preserve those distinctions: who the applicant is, which people own or control it, who can act for it, what a possible match means and which person has authority to decide the case.
The entity pages begin with roles and relationships. A director, shareholder, beneficial owner and authorized signer can be the same person, but they do not have to be. An ownership chart should show every relevant link and explain the evidence behind it. Multiplying percentages through a simple chain helps describe economic ownership; it does not automatically settle control, legal thresholds or complex arrangements. The worked examples show the calculation and its limits without assigning a universal beneficial-ownership rule.
Screening pages focus on review evidence rather than automatic conclusions. A possible PEP match needs identity and role assessment; PEP status is not proof of wrongdoing. A sanctions name similarity requires the applicable list context, supporting identifiers and an authorized escalation process. A similarity score is not a probability of criminality or a universal permission to release an account. Preserve uncertainty when the available evidence cannot support a definite conclusion.
Funding and risk reviews then connect the intended relationship with its documented context. Source of funds concerns the particular money involved, while source of wealth concerns how a person's broader assets accumulated. The evidence requested should answer the actual question under the applicable policy. A risk review records factors, changes, unresolved issues and the decision rationale. It should not turn nationality, a software status or an unexplained number into a substitute for relevant evidence and qualified judgment.
Review does not end at initial approval. Ownership changes, new activities, conflicting information or expiring evidence may create specific refresh tasks. A case-closure record should explain the decision at a point in time and preserve what remains outstanding. The privacy page separately records notices, processing purposes, lawful-basis assessments and choices. A checkbox acknowledging a notice is not automatically consent for every use, and withdrawing an optional preference does not by itself decide every legal retention obligation.
The sources include FATF standards and guidance, OFAC's own screening explanations, UK ICO guidance and provider documentation for technical workflow examples. Their scopes differ. FATF standards require implementation through applicable systems; OFAC and ICO materials address their respective frameworks; a provider callback describes a technical event. These pages are operational worksheets, not country-specific legal advice, a universal document checklist or a promise of approval. Adapt them with the responsible policy owners for the actual entity, activities, customers and markets, and keep the evidence necessary to explain each decision.
Published by FxTrusts, a supplier of brokerage and prop firm technology. Prepared with AI-assisted research and drafting; reviewed against the cited public sources. Examples are illustrative. Product links describe our services.
Continue with the broader guides
Connect this reference to platform selection and the wider operating workflow.
References and implementation tasks
- Implementation guide
Beneficial Ownership Chart: Trace Direct and Indirect Holdings
Trace a simple ownership chain, multiply indirect holdings and document control rights separately, with evidence dates and unresolved links kept visible.
- Checklist
Customer Risk Reviews: Inputs, Changes and Human Decisions
Record relevant customer-risk factors, supporting evidence and changes, with explained exceptions and a named decision owner instead of an unexplained score.
- Checklist
Due Diligence Refresh: Events That Need a Review
Turn ownership changes, new activity, conflicting information and expiring evidence into specific due-diligence review tasks with owners and recorded outcomes.
- Reference
KYB Entity Roles: Applicant, Owner and Authorized Signer
Map the applicant entity, directors, shareholders, beneficial owners and signers, with separate evidence for identity, ownership, control and authority.
- Checklist
Onboarding Case Closure: Decisions, Reasons and Audit Trail
Close onboarding cases with evidence versions, explicit outcomes, open issues and authorized reasons, preserving provider results and communications.
- Checklist
PEP Screening: A Review Record for a Potential Match
Review a potential PEP match through identity, public-role evidence, risk assessment and authorized decisions, without equating status with wrongdoing.
- Checklist
Privacy and Consent Evidence in Client Onboarding
Separate notices, lawful-basis decisions and optional consent choices, preserving versions, timestamps, withdrawals and access restrictions in onboarding.
- Checklist
Sanctions Match Review: Record Evidence and Escalation
Document potential sanctions matches using list context, identifiers, evidence and authorized escalation, without treating a similarity score as a release rule.
- Reference
Source of Funds vs Source of Wealth: Evidence and Purpose
Distinguish a specific deposit's origin from broader wealth accumulation, then match evidence to the review question without one universal document set.
