Introduction
Corporate form and compliance practice often drift apart as a business grows. This alert lists questions a management team may want to ask when reviewing AML / KYC processes, internal policies and anti-corruption controls. It does not state a required control set.
Questions to discuss
- Do written policies describe the process staff actually follow?
- Who owns AML / KYC questions when a new counterparty appears?
- How are exceptions recorded, and who can approve them?
- Where do corporate-structure changes create new compliance gaps?
Practical implications
A structure review that ignores compliance can leave the company with a tidy chart and an unusable process. A compliance review that ignores structure can write policies nobody can apply.
Conclusion
Use these questions to open a discussion. Specific control design still depends on the business, its counterparties and the applicable framework.
