Case Study 5: Automating AML, Identity and Customer-Risk Reviews

How a business could strengthen financial-crime controls while reducing repetitive administration

The opportunity

Businesses operating in regulated sectors may need to complete customer due diligence when they establish a new relationship, carry out certain transactions or identify a material change in a customer’s circumstances.

They may also need to review existing customer records throughout the relationship so that identity information, beneficial-ownership details and customer-risk assessments remain accurate and up to date.

This can involve:

  • Collecting identity and address evidence.

  • Identifying and verifying beneficial owners.

  • Confirming the purpose and intended nature of the relationship.

  • Recording expected activity.

  • Assessing customer, geographic, product and delivery-channel risks.

  • Screening for sanctions, politically exposed persons and adverse information.

  • Establishing source of funds or source of wealth where required.

  • Applying enhanced due diligence in higher-risk situations.

  • Refreshing records when reviews become due or risk factors change.

  • Escalating unusual or suspicious activity to the appropriate employee.

  • Retaining evidence of checks, decisions and approvals.

When this work is managed through emails, spreadsheets, disconnected systems and individual reminders, employees may spend significant time locating documents, rekeying information, chasing customers and assembling review files.

Incomplete records may remain open for too long. Review dates may be missed. Different employees may apply the process inconsistently, and management may have limited visibility of overdue work or emerging risk.

Automating the administrative stages of AML, identity and customer-risk reviews could help a business create a more consistent, visible and auditable process while ensuring that regulated decisions remain under appropriate human control.

What could be improved?

A manual AML and customer-risk review process may involve:

  • Checking spreadsheets for reviews approaching their due date.

  • Searching the CRM and document-management system for existing records.

  • Emailing customers for identity, address or ownership information.

  • Sending repeated reminders for missing documents.

  • Manually entering the same information into several systems.

  • Checking whether documents are current and complete.

  • Searching for company and beneficial-ownership information.

  • Carrying out screening checks in separate platforms.

  • Copying screening results into the customer file.

  • Completing customer-risk assessment forms manually.

  • Requesting additional evidence for higher-risk cases.

  • Sending cases to compliance or the nominated officer by email.

  • Recording approvals and review notes across different locations.

  • Updating review dates and creating future reminders.

  • Producing management information through manual spreadsheet exercises.

Common challenges

  • Missing, expired or inconsistent customer documents.

  • Incomplete beneficial-ownership information.

  • Review dates held across several systems.

  • Customers being asked for information the business already holds.

  • Repeated manual data entry.

  • Inconsistent risk-assessment records.

  • High volumes of false-positive screening alerts.

  • Limited evidence explaining why an alert was cleared.

  • Higher-risk cases not being escalated promptly.

  • Enhanced due diligence being applied inconsistently.

  • Periodic reviews becoming overdue.

  • Changes in customer circumstances not triggering a timely review.

  • Limited management visibility of backlogs and exceptions.

  • Difficulty demonstrating who completed, reviewed and approved each action.

  • Skilled compliance employees spending time on routine administration rather than judgement-led work.

What could automation look like?

1. Existing-record assessment

Before introducing automation, the business could assess its existing customer records and group them into categories such as:

  • Complete and in date.

  • Review due soon.

  • Review overdue.

  • Identity evidence missing or expired.

  • Address evidence missing or outdated.

  • Beneficial owner not recorded or not verified.

  • Customer-risk assessment incomplete.

  • Source-of-funds or source-of-wealth evidence required.

  • Screening result unresolved.

  • Duplicate customer record.

  • Customer relationship already closed.

  • Communication details invalid.

  • Case requiring compliance review.

This would help the business understand the scale and quality of its existing data before automated workflows begin.

It would also prevent incomplete or inaccurate information from being treated as reliable merely because it has been transferred into a new system.

2. Review-trigger engine

The workflow could monitor approved systems and create a review when a relevant trigger occurs.

Triggers could include:

  • A new customer relationship.

  • A scheduled periodic-review date.

  • An expired or soon-to-expire identity document.

  • A change of name, address or contact details.

  • A change in directors, trustees, partners or beneficial owners.

  • A material change in expected activity.

  • A new product, service or jurisdiction.

  • A significant transaction or source of funds requiring review.

  • A new screening alert.

  • Information that conflicts with the existing customer profile.

  • A request from compliance or the nominated officer.

The frequency and type of review would follow the business’s documented, risk-based policies rather than a single automated timetable for every customer.

3. Secure information and document collection

Customers could receive a secure request explaining:

  • Why information is required.

  • Which details need to be confirmed or updated.

  • Which documents are acceptable.

  • How information can be submitted securely.

  • When a response is required.

  • Who to contact for help.

  • What may happen if the review cannot be completed.

The workflow could issue approved reminders and stop chasing once the required information has been received or a case has been placed under manual control.

Information already held could be presented for confirmation where appropriate, reducing unnecessary requests and improving the customer experience.

4. Identity and address-check workflow

The process could connect with approved identity-verification services and record the results within the customer file.

It could:

  • Check whether required fields are present.

  • Identify expired or unreadable documents.

  • Compare submitted information with existing records.

  • Record the verification method, date and result.

  • Highlight mismatches for human investigation.

  • Request an alternative document where permitted by policy.

  • Route unsuccessful or uncertain checks to an authorised employee.

An automated check would provide evidence to support the process. It would not, by itself, determine whether a customer must be accepted, rejected or reported.

5. Business and beneficial-ownership checks

For companies, partnerships, trusts or other legal arrangements, the workflow could help collect and organise:

  • Registered name and number.

  • Registered and trading addresses.

  • Legal form and status.

  • Directors, partners or trustees.

  • Ownership and control information.

  • Beneficial owners.

  • Nature and purpose of the business.

  • Expected activity.

  • Relevant company documents.

  • Information obtained from approved external sources.

The system could compare submitted details with authoritative or approved data sources and highlight inconsistencies.

Complex ownership structures, missing beneficial owners, conflicting information and higher-risk jurisdictions would be routed for human review.

6. Screening and risk-signal collation

Approved screening services could be used to identify possible matches relating to:

  • Sanctions.

  • Politically exposed persons.

  • Relatives and known close associates where relevant.

  • Adverse information.

  • Internal watchlists.

  • Other risk indicators defined within the business’s policies.

The workflow could bring potential matches into a single review queue, attach the underlying evidence and prioritise them according to approved rules.

Employees would remain responsible for deciding whether a match is genuine, what further checks are required and whether the case should be escalated.

7. Customer-risk review pack

The workflow could prepare a structured case summary containing:

  • Customer and relationship details.

  • Identity and verification results.

  • Business and beneficial-ownership information.

  • Purpose and intended nature of the relationship.

  • Expected activity.

  • Products, services and delivery channels involved.

  • Geographic connections.

  • Screening results.

  • Source-of-funds or source-of-wealth information where required.

  • Previous risk rating and review history.

  • Changes since the previous review.

  • Missing information and unresolved exceptions.

The system could apply the business’s approved risk-assessment logic to organise information and suggest which parts require attention.

The final risk classification, enhanced-due-diligence requirements, customer decision and approval would remain with appropriately trained and authorised employees.

8. Exception and escalation management

Cases could be routed automatically when they contain defined exceptions, such as:

  • An unresolved identity mismatch.

  • An unclear or complex ownership structure.

  • A possible sanctions or PEP match.

  • Higher-risk geography.

  • Unexplained source of funds.

  • Activity inconsistent with the customer profile.

  • Missing mandatory evidence.

  • A risk rating above an approved threshold.

  • A customer who has not responded after the permitted contact process.

  • Information that may require consideration by the nominated officer or MLRO.

The workflow could assign an owner, set a target date, restrict access where necessary and maintain a complete record of escalation and resolution.

It should not automatically decide whether suspicion exists or submit a suspicious activity report. Those actions require confidential handling and appropriate human judgement.

9. Ongoing monitoring and record refresh

After the initial review, the workflow could support ongoing monitoring by:

  • Scheduling future reviews according to approved policy.

  • Identifying records or documents approaching expiry.

  • Detecting material changes received through connected systems.

  • Re-screening customers at approved intervals or when relevant data changes.

  • Comparing activity with the recorded purpose and expected profile where appropriate.

  • Creating an exception when information appears inconsistent.

  • Recording when a customer relationship ends.

  • Applying the business’s approved retention process.

Automated monitoring would help surface items for attention. Employees would investigate and decide the appropriate action.

10. AML and customer-risk dashboard

Management and authorised compliance employees could view:

  • New reviews opened.

  • Reviews due soon.

  • Reviews overdue.

  • Cases awaiting customer information.

  • Identity checks completed, failed or referred.

  • Beneficial-ownership exceptions.

  • Screening alerts awaiting review.

  • Enhanced-due-diligence cases.

  • Cases escalated to compliance.

  • Average completion time.

  • Workload by employee or team.

  • Reasons for delays.

  • Risk-rating distribution.

  • Human overrides and approval outcomes.

  • Quality-assurance findings.

  • Records with missing evidence.

  • Performance against internal service standards.

This could provide a clearer view of operational workload, control effectiveness and areas requiring management attention.

What could be achieved?

Assume that a regulated business completes 1,200 new-customer, periodic or event-driven AML reviews each year.

These could include a mixture of:

  • Individual customers.

  • Companies and other legal entities.

  • Standard customer due diligence.

  • Higher-risk cases requiring enhanced due diligence.

  • Scheduled periodic reviews.

  • Reviews triggered by a change in circumstances.

1. Without a structured automated process

  • Average administrative and review preparation time: 50 minutes per case.

  • Annual time: 1,200 × 50 minutes = 1,000 hours.

  • Cases returned because information is incomplete: 15%, or 180 cases.

  • Additional handling time: 180 × 25 minutes = 75 hours.

  • Total annual time: 1,075 hours.

2. With a structured automated process

  • Average human handling and review time: 20 minutes per case.

  • Annual time: 1,200 × 20 minutes = 400 hours.

  • Cases requiring additional handling because information is incomplete: 5%, or 60 cases.

  • Additional handling time: 60 × 15 minutes = 15 hours.

  • Total annual time: 415 hours.

3. Potential annual capacity released

1,075 hours − 415 hours = 660 hours

At an illustrative employment cost of £30 per hour:

660 hours × £30 = £19,800 of annual administrative capacity

These figures are illustrative. Actual results would depend on factors including:

  • Customer numbers and complexity.

  • The proportion of individual and corporate customers.

  • Existing data quality.

  • Risk profile.

  • Regulatory obligations and supervisory expectations.

  • The business’s policies and review frequencies.

  • The quality of connected data sources.

  • Screening-alert volumes and false-positive rates.

  • The extent of enhanced due diligence required.

  • Integration with existing systems.

  • Employee training and adoption.

  • The level of human review required.

The principal value would not be cost reduction alone. A stronger return could come from more consistent controls, fewer overdue reviews, faster identification of exceptions and better evidence of the decisions made.

Potential time savings

Releasing 660 hours each year would be equivalent to approximately:

  • 88 working days, based on a 7.5-hour day.

  • More than 17 working weeks, based on a five-day week.

That capacity could be redirected towards:

  • Investigating complex or higher-risk cases.

  • Reviewing genuine screening matches.

  • Improving policies and procedures.

  • Quality assurance and control testing.

  • Employee training.

  • Backlog reduction.

  • Management reporting.

  • Broader financial-crime risk work.

Automation would not remove the need for compliance expertise. It would allow that expertise to be concentrated where investigation, challenge and professional judgement add the most value.

Before and after

1. Review identification

  • Before: Employees check spreadsheets, diary reminders and separate systems to identify reviews that are due.

  • After: The workflow monitors approved data sources and creates reviews when scheduled or event-driven triggers occur.

2. Customer requests

  • Before: Employees prepare emails manually and may request information already held by the business.

  • After: Customers receive approved, targeted requests showing what must be confirmed, updated or supplied.

3. Follow-up

  • Before: Employees create reminders and repeatedly chase missing information.

  • After: The system sends controlled reminders, records each contact attempt and escalates non-response according to policy.

4. Document checks

  • Before: Employees manually inspect documents, record expiry dates and rekey details into different systems.

  • After: Approved verification tools capture results, flag missing or inconsistent information and route exceptions for human review.

5. Beneficial ownership

  • Before: Ownership information is collected and compared manually, making complex structures difficult to track.

  • After: Ownership details and supporting evidence are organised in one review pack, with conflicts or gaps clearly highlighted.

6. Screening

  • Before: Screening is completed in separate platforms and the results are copied manually into the customer file.

  • After: Potential matches are brought into a controlled queue with evidence, status, ownership and resolution history.

7. Risk assessment

  • Before: Customer-risk forms may be completed inconsistently and supporting evidence may be spread across several locations.

  • After: A structured review pack applies approved logic consistently, while an authorised employee makes and records the final decision.

8. Enhanced due diligence

  • Before: Additional checks are requested through ad hoc emails and progress can be difficult to monitor.

  • After: Higher-risk cases enter a defined workflow with required evidence, assigned responsibilities, approvals and target dates.

9. Escalation

  • Before: Exceptions may be passed between employees through email with limited visibility of ownership or response time.

  • After: Cases are routed to the correct authorised person with restricted access, a clear audit trail and recorded resolution.

10. Ongoing monitoring

  • Before: Changes in customer details may not trigger a review, and periodic refreshes can become overdue.

  • After: Approved triggers, review dates and record-expiry events create tasks automatically for investigation and action.

11. Management information

  • Before: Compliance reporting depends on manual spreadsheet consolidation and may provide only a retrospective view.

  • After: A dashboard shows current volumes, overdue reviews, exceptions, risk distribution, completion times and control outcomes.

12. Audit evidence

  • Before: It can be difficult to reconstruct which information was considered, who made a decision and why it was approved.

  • After: The workflow retains the evidence, actions, decisions, human overrides, dates and approvals associated with each review.

Controls that should remain in place

A controlled AML, identity and customer-risk review workflow could include:

  • Documented, risk-based policies and procedures.

  • Clear ownership by senior management and the nominated officer or MLRO.

  • Human approval of customer-risk classifications and material decisions.

  • Enhanced due diligence where required by policy or regulation.

  • Meaningful human review of automated outputs and potential matches.

  • Restrictions preventing the system from accepting or rejecting customers independently.

  • Restrictions preventing automated decisions that have legal or similarly significant effects without the necessary safeguards.

  • Approved identity, company-information and screening providers.

  • Regular testing of screening logic, thresholds and data quality.

  • Quality assurance of completed reviews.

  • Clear procedures for false positives and uncertain matches.

  • Secure handling of identity, financial and special-category information where applicable.

  • Role-based access and segregation of duties.

  • Encryption and secure transfer of customer documents.

  • Data-minimisation and retention controls.

  • A complete, tamper-evident audit history.

  • Monitoring of human overrides and unusual decision patterns.

  • Appropriate processes for vulnerable customers or those requiring additional support.

  • Employee training and documented responsibilities.

  • Confidential routes for internal suspicion reporting.

  • Human control over decisions concerning suspicion and suspicious activity reports.

  • Regular legal, compliance and data-protection review of the workflow.

  • Contingency procedures if an external data or verification service becomes unavailable.

The business would remain responsible for its legal and regulatory obligations, including where technology or outsourced service providers support the process.

Automation should help employees collect information, identify exceptions and maintain evidence.

It should not replace investigation, challenge or professional judgement.

The potential business impact

An automated AML, identity and customer-risk review process could help a business complete routine administration more efficiently while improving the consistency and visibility of its financial-crime controls.

Customers could receive clearer requests and fewer duplicated questions.

Operational employees could spend less time rekeying information and chasing documents.

Compliance teams could focus more attention on higher-risk customers, genuine matches, unusual activity and control improvement.

Management could gain a clearer view of overdue reviews, emerging risks, workloads and exceptions.

The business could also maintain stronger evidence showing how each review was completed, challenged and approved.

The result could be:

  • Faster customer onboarding and review completion.

  • Fewer incomplete customer files.

  • Fewer overdue periodic reviews.

  • More consistent customer-risk assessments.

  • Earlier identification of higher-risk cases.

  • Better management of screening alerts.

  • Stronger enhanced-due-diligence workflows.

  • Clearer ownership of exceptions and escalations.

  • Improved customer experience.

  • Better use of compliance expertise.

  • More reliable management information.

  • Stronger audit and regulatory evidence.

  • Reduced repetitive administration.

  • A more scalable financial-crime control environment.

How strong is your existing AML review process?

Neuranet helps businesses assess their existing AML, identity and customer-risk review processes, identify manual work and control gaps, and design structured automation around their current systems, policies and compliance responsibilities.

© 2026. All rights reserved.