Introduction

Corporate form and compliance practice often drift apart as a business grows. This alert lists questions a management team may want to ask when reviewing AML / KYC processes, internal policies and anti-corruption controls. It does not state a required control set.

Questions to discuss

  • Do written policies describe the process staff actually follow?
  • Who owns AML / KYC questions when a new counterparty appears?
  • How are exceptions recorded, and who can approve them?
  • Where do corporate-structure changes create new compliance gaps?

Practical implications

A structure review that ignores compliance can leave the company with a tidy chart and an unusable process. A compliance review that ignores structure can write policies nobody can apply.

Conclusion

Use these questions to open a discussion. Specific control design still depends on the business, its counterparties and the applicable framework.