AML/KYC Remediation: Turning a Compliance Challenge into a Controlled Transformation Programme

Chris Burke
Chris Burke

Overview

AML and KYC remediation programmes can quickly become some of the most complex transformation initiatives within a financial institution. Below is a case study of where Brickendon’s “failure is not an option” programme management methodology was implemented in a global G-SIB’s AML/KYC rationalisation programme. 

The challenge is rarely just reviewing customer files. Banks operate different technology platforms, apply different risk methodologies, store information differently and often have different interpretations of how KYC processes should operate. When thousands of customers and potentially tens of thousands of accounts need to be reviewed, migrated or remediated, these differences become a significant operational challenge. 

The key to successful AML/KYC remediation is therefore to treat it as a structured transformation programme:  

Why KYC remediation becomes complex 

At first glance, KYC remediation can appear relatively straightforward: identify the customers requiring review, validate their information, apply the appropriate risk assessment and update the target system. 

At scale, the reality is very different. 

Brickendon has led programmes involving migrating thousands of customer KYC files and tens of thousands of associated accounts. Across this population, often around 20% is considered high risk and therefore potentially required early manual remediation.   

Four challenges in particular emerge in programmes of this type. 

System differences 

One part of the organisation used an established KYC vendor platform while another part relied on internally developed technology. Even the way information is captured differed significantly,  from structured, defined data fields to free-text information. These differences make direct migration difficult and create a requirement for mapping, interpretation and, frequently, manual intervention in order to complete the programme.  

Risk-model divergence. 

The two parts of the organisation looked at the same customer and reached different risk classifications because their models work differently. For example, one model used a defined number of weighted risk factors to derive a score, while the other allowed particular risk factors (i.e. “black ball factors”) to override the wider assessment and determine the customer’s risk level.  

Customer overlap 

Customers already existed in both parts of the organisations, but it wasn’t possible to simply recreate the customer. This would have generated unnecessary work and duplication. The appropriate action was to look at existing records and manually or programmatically compare the two. Where risk ratings or underlying information differ, those discrepancies need to be investigated and remediated and then written up so for future cases this could be a formula the analysts could follow.  

Scale 

Once thousands of customers and tens of thousands of accounts are involved, small inefficiencies become major delivery problems, including significant time and budget. The solution requires not only AML/KYC expertise, but effective programme governance, prioritisation and repeatable workflows. 

This is why simply adding more analysts is rarely enough. 

A three-stage approach: Discover, Architect, Implement 

The approach set out by Brickendon breaks the problem into three distinct phases: first understand the challenge, then design the solution, and finally execute it within the existing operational environment in our “failure is not an option” delivery philosophy.  

1. Discover 

The first stage establishes exactly what needs to be remediated and why. 

This starts with identifying overlapping customers and analysing the existing KYC population. The KYC files, underlying risk models and system structures are assessed and mapped against one another. 

The objective is not yet to process every file. It is to understand the population sufficiently well to determine what types of remediation are required and in what order they should be addressed. 

The output is a high-level prioritisation of customers and remediation activity agreed with the business.  

This is particularly important where higher-risk customers require more immediate attention. A risk-based approach ensures that scarce specialist resources are directed towards the cases where they create the greatest value. 

2. Architect 

Once the customer population and differences between the organisations are understood, the next stage is to turn those findings into repeatable processes. 

Rather than treating thousands of KYC files as thousands of independent problems, recurring scenarios are identified and a defined workflow is created for each. 

Those workflows can then be tested through rapid proofs of concept. The results allow the team to validate the proposed approach before committing to remediation at scale. 

Each scenario is documented and incorporated into a detailed delivery roadmap.  

This stage is critical because it transforms the programme from a large collection of individual cases into a manageable set of known remediation patterns. 

The principle is simple: 

Understand the differences → identify the scenarios → define the workflows → test them → scale them. 

3. Implement 

The final stage moves from design into industrialised delivery. 

Rather than waiting for the entire analysis and design exercise to finish before remediation begins, the roadmap can be delivered iteratively using Agile principles. 

KYC files are integrated and remediated into the target platform while the underlying processes are continually refined as the team learns from actual cases. Progress is communicated through end-of-sprint reporting and regular “show and tell” sessions with management.  

This creates an important feedback loop: 

Remediate → learn → refine → accelerate

Instead of assuming that every possible scenario can be predicted at the start of the programme, the operating model improves as delivery progresses. 

Governance must run across the entire programme 

Programme governance and reporting should not be treated as a final reporting exercise. 

It sits across discovery, architecture and implementation. 

Customer-overlap analysis, KYC file and risk-model analysis, system mapping and prioritisation begin early. Workflow design and proofs of concept follow, before the programme progressively moves towards Agile remediation and integration into the target KYC platform.  

That structure gives management visibility not simply of how many files have been processed, but of whether the remediation operation itself is becoming more predictable and effective. 

The programme ultimately concludes with completion reporting and an executive pack documenting the outcome.  

KYC remediation is a transformation problem 

Perhaps the most important lesson is that large AML/KYC remediation exercises should not be viewed simply as exercises in adding compliance resources. 

They sit at the intersection of regulation, data, technology, risk, operations and programme delivery. 

The difficult part is often not identifying what KYC requires. It is reconciling different systems, different data structures, different customer populations and different risk methodologies, and then creating a controlled process capable of dealing with those differences at scale. 

A successful programme therefore combines deep AML/KYC knowledge with strong transformation capability. 

The objective should be to move rapidly from an apparently complex population of individual cases towards a smaller number of understood, tested and repeatable remediation scenarios. 

That is what makes Brickendon’s Discover → Architect → Implement approach so incredibly powerful and successful at scale.

Turn AML/KYC remediation into lasting competitive advantage 

Brickendon can help you: 

  • Discover the true nature of your KYC population, identifying risk, complexity and remediation priorities. 
  • Architect repeatable, scalable workflows that address each remediation scenario. 
  • Implement at pace, with strong governance, Agile delivery and continuous refinement. 

Done effectively, AML/KYC remediation is more than clearing a regulatory backlog. It is an opportunity to create a more consistent, controlled and scalable KYC operating environment.  

Facing a complex AML/KYC migration or remediation programme?

Brickendon combines deep KYC expertise with technology, data and programme delivery to help financial institutions turn complex remediation challenges into controlled, scalable execution.