AML screening for smaller, less 'obvious' corporate clients - how deep do you go?
Still getting my head around the nuances of AML screening, particularly for smaller corporate clients that don't immediately scream 'high risk'. My firm uses a pretty robust system for initial due diligence, but I'm curious about ongoing monitoring when the client's structure or activities change slightly. For example, if a client in a relatively low-risk sector suddenly adds a new director based in a jurisdiction with a less stringent regulatory framework, how do you guys approach rescreening or re-evaluating the risk profile without over-investing resources on what might be a minor change? Is it always a full re-run of checks, or are there more proportionate approaches for these incremental shifts in risk? Interested to hear how others balance thoroughness with practical efficiency.
That's a great point about ongoing monitoring, especially with subtle changes. We've found it helpful to establish clear internal triggers for re-screening, not just based on sector, but also on the nature of the change itself – a new director from a higher-risk jurisdiction would definitely be one of them.