Use case

Back-Book Remediation

Bringing an existing customer base up to a standard it was never onboarded against, after a finding, a merger, or a rule change. The work is triage before it is screening.

Last updated

Team reviewing reports together on a tablet in an open-plan office

Remediation funnel

Most of the book does not need touching.

  1. AnalystDefine the standardWhole bookWhat "remediated" means, agreed before anything is touched.
  2. AutomatedSegmentWhole bookSplit by risk, product, jurisdiction and data completeness.
  3. AutomatedRe-screenIn scopeRun the population against current lists and data.
  4. AutomatedTriageFlaggedSeparate genuine gaps from data-quality noise.
  5. AnalystWork the gapsReal gapsOutreach, document collection, enhanced due diligence where warranted.
  6. AnalystClose and evidenceRemediatedRecord the standard met, per customer, with the date and basis.
3 analyst3 automated
The shares are illustrative, but the shape is not. A remediation that treats every customer as a full review fails on capacity, so the value of the early stages is how much they remove from the later ones.

A remediation is not a large screening exercise. Screening the whole book is the cheap part and can be done in a weekend. The expensive part is the human work at the end, and the purpose of everything before it is to make that population as small as it honestly can be.

That is why the diagram narrows. Each stage exists to remove work from the next one.

Define done before touching anything

The most common failure is starting without a written definition of what remediated means. Without it there is no test for whether a file is finished, so the programme cannot close, and it usually runs a second time when a reviewer disagrees with an implicit standard nobody wrote down.

The definition is a business decision, not a system one: which fields must be present, what verification is acceptable, what evidence has to exist for each risk band.

Segment before you screen

Sequencing matters because remediations get interrupted. Scope changes, resourcing moves, a regulator asks for something else. Working in risk order means that whenever the programme is disturbed, the population most likely to contain a genuine problem has already been covered.

Screening everything first and sorting afterwards loses that property, and it is not recoverable later.

Most flags are not risk

In practice the majority of what surfaces is data quality: missing dates of birth, name formats that never normalised, addresses recorded inconsistently across systems. These are real work, but they are a different workstream, with different people, at a different cost.

Programmes that push both through one analyst queue are the ones that overrun, because the genuine cases wait behind the formatting.

The output is per customer

A remediation is not finished by a report saying the book has been remediated. It is finished when each customer's file carries a record of the standard met, the date it was met, and the basis.

That is the artefact a supervisor examines, and it is the reason evidence has to be produced during the work rather than summarised after it.

For the model that stops the gap reopening, see perpetual KYC. For the rule changes that commonly trigger this, see EU AML package readiness and Tranche 2 readiness. For the components, see PEP and sanctions screening and enhanced due diligence.

What we do.

A definition agreed first

Remediation without a written standard cannot be finished, because nobody can say which files are done. This is the step most often skipped under time pressure and the one that causes programmes to run twice.

Segmentation before screening

Sequencing by risk means the population most likely to contain a real problem is worked first, which matters if the programme is stopped or rescoped part way through.

Batch re-screening

The whole in-scope population against current lists and current data, rather than the lists that applied when each customer was onboarded.

Separating gaps from noise

Most flags in a remediation are data quality, not risk. Treating them identically is what turns a six-month programme into an eighteen-month one.

Evidence per customer

The output is not a report saying the book was remediated. It is a per-customer record showing what standard was met, when, and on what basis.

Highlights.

  • A written definition of done, agreed before work starts
  • Risk-based sequencing, so the order survives a change of scope
  • Data-quality gaps separated from genuine due diligence gaps
  • Per-customer evidence, not a programme-level assertion

Questions

Common questions about back-book remediation.

What usually triggers a back-book remediation?
A regulatory finding, an acquisition that brings in a book onboarded to someone else's standard, or a rule change that raises the bar for customers you already have. The EU AML package and the Australian reforms both create the third kind, because the new standard applies to existing customers rather than only to new ones.
Why segment before screening rather than after?
Because the order matters if the programme is interrupted, rescoped or slowed, which most are. Sequencing by risk means the population most likely to contain a genuine problem has already been worked when that happens. Screening everything first and sorting later loses that.
What proportion of flags are real?
In most programmes, a small minority. The bulk are data quality: missing fields, inconsistent name formats, addresses that never normalised. They still need resolving, but they are a different workstream with different people and a different cost, and conflating the two is the most common reason remediations overrun.
When is a customer actually remediated?
When the file meets the standard written down at the start, and there is a record showing that, with a date and a basis. Without an agreed definition there is no point at which the answer is yes, which is why the definition step comes before any screening.
How does this differ from perpetual KYC?
Remediation is a finite programme that closes a gap created in the past. Perpetual KYC is the standing model that stops the gap reopening. Firms that remediate without changing the operating model usually find themselves remediating again.

Talk to the MemberCheck team.

Get in touch and we'll walk you through how MemberCheck can help.