A remediation is not a large screening exercise. Screening the whole book is the cheap part and can be done in a weekend. The expensive part is the human work at the end, and the purpose of everything before it is to make that population as small as it honestly can be.
That is why the diagram narrows. Each stage exists to remove work from the next one.
Define done before touching anything
The most common failure is starting without a written definition of what remediated means. Without it there is no test for whether a file is finished, so the programme cannot close, and it usually runs a second time when a reviewer disagrees with an implicit standard nobody wrote down.
The definition is a business decision, not a system one: which fields must be present, what verification is acceptable, what evidence has to exist for each risk band.
Segment before you screen
Sequencing matters because remediations get interrupted. Scope changes, resourcing moves, a regulator asks for something else. Working in risk order means that whenever the programme is disturbed, the population most likely to contain a genuine problem has already been covered.
Screening everything first and sorting afterwards loses that property, and it is not recoverable later.
Most flags are not risk
In practice the majority of what surfaces is data quality: missing dates of birth, name formats that never normalised, addresses recorded inconsistently across systems. These are real work, but they are a different workstream, with different people, at a different cost.
Programmes that push both through one analyst queue are the ones that overrun, because the genuine cases wait behind the formatting.
The output is per customer
A remediation is not finished by a report saying the book has been remediated. It is finished when each customer's file carries a record of the standard met, the date it was met, and the basis.
That is the artefact a supervisor examines, and it is the reason evidence has to be produced during the work rather than summarised after it.
For the model that stops the gap reopening, see perpetual KYC. For the rule changes that commonly trigger this, see EU AML package readiness and Tranche 2 readiness. For the components, see PEP and sanctions screening and enhanced due diligence.
