Independent file audit · Typically 3–6 weeks

KYC Record Verification Audit

Risk-weighted sampling of customer due diligence files with independent testing of identity, beneficial ownership, and source-of-funds evidence — delivered as a findings memorandum your MLRO can act on.

KYC Record Verification Audit

At a glance

  • For: SFC, HKMA, or other licensed firms with established CDD programmes
  • Delivery: On-site sampling in Central or remote secure review
  • Timeline: Typically 3–6 weeks
  • Fees: Quote based on population size and risk mix

Next step

Share your customer population size and whether files must remain on-site. We prepare a scoping note before any fieldwork starts.

Request a scoping call

Who this engagement is for

Compliance and internal audit teams at brokerages, banks, money lenders, and asset managers in Hong Kong that need an independent check of KYC records before a thematic visit, licence renewal, or board assurance cycle. You already have written CDD procedures; you need someone to test whether the files match them.

Result you receive

A findings memorandum that lists each tested file reference (pseudonymised if required), the control or procedure clause examined, the exception observed, severity, and a suggested remediation owner. We also provide a sampling methodology note so your auditor or supervisor can see how the population was stratified.

What is included

  • Kick-off to confirm risk tiers, systems of record, and access constraints
  • Risk-weighted sample design across new, existing, and high-risk relationships
  • Hands-on verification of identity documents, address evidence, and beneficial ownership registers
  • Source-of-funds and source-of-wealth narrative testing against bank statements or equivalent support
  • Walkthrough of reviewer sign-off trails and overdue periodic reviews
  • Draft findings call with your MLRO or Head of CDD
  • Final memorandum and optional short board-ready summary

What is excluded

We do not rewrite your CDD policy manual as part of this engagement, perform transaction monitoring model validation, or provide legal opinions on whether a customer should be exited. Remediation implementation stays with your operations team unless you commission a separate follow-up review.

How work is delivered

Fieldwork may occur at your offices near Central or via controlled remote access when paper vaults are not required. Duration depends on sample size and how quickly files can be retrieved. Most mid-size populations complete within three to six weeks from access grant.

Preparation we ask of you

Provide current CDD procedures, risk rating methodology, a population extract with risk tags, and a single point of contact for vault or system access. Flag any files under active STR review so we can exclude them from sampling.

Fees and next step

Fees are quoted after we see population size, risk mix, and whether dual-language document review is required. Start with a scoping call — we respond within two business days with questions and a draft timeline.