Why checklists, and not another guide
A guide explains a subject. A checklist runs a process. The difference matters more here than in most fields, because the common failure in compliance is not ignorance of a control, it is running the controls in the wrong order and producing evidence that does not hold.
Screening a customer before you have verified who they are gives you a clean result against the wrong identity. Setting a risk rating before assessing jurisdiction and product means the rating cannot explain itself. Both look fine in a monthly report. Neither survives someone asking why.
So each checklist below is ordered, and the ordering is the argument.
The four
| Checklist | Use it when | Runs for |
|---|---|---|
| AML/CTF programme | Standing a programme up, or reviewing one you inherited | Whole programme |
| Customer risk assessment | Rating a customer at onboarding or review | Per customer |
| Enhanced due diligence | A customer has been rated high risk | Per customer |
| Sanctions alert review | A screening match needs a decision | Per alert |
If you are not sure which one you need, the readiness check asks ten questions and names the weakest area first.
How to use them
Work down. Do not skip a step because a system already does it — note which system, because "the platform handles it" is not an answer an assessor accepts without knowing how.
Where a step says record something, record it at the time. Reconstructed rationale is the single most common weakness found in file reviews: the decision was probably right, and there is no way left to show it.
