This page is for anyone interviewing for a KYC, CDD or AML analyst role, from first job to experienced reviewer. Expect a few questions on why you chose compliance, then checks on due diligence levels, beneficial ownership, customer risk rating, PEP and sanctions screening, red flags, alert investigation and suspicious reporting. You'll also get stories from past work and what-would-you-do cases, such as documents that don't match or a client who won't name its owners. Rules differ by country, so learn the local regulator's version of each point before the day.
Search all questions by round, difficulty and level, or save the ones you want to practise.
Path: the short route that led you here, a course, a job or a project.
The hook: one specific part of the work you like, such as piecing together a story from records.
Next step: why this role is the right move now.
"I studied commerce, and my first job was in account opening operations at a bank. Most of it was checking forms, but every so often a file didn't add up, like a company whose address turned out to be a shared office with fifty other firms registered there. I found I really liked pulling on those threads and working out what was actually going on. So I asked to move into the KYC team, did an AML certification course in my own time, and spent the last two years on onboarding and periodic reviews. What keeps me interested is that no two cases are the same. I'd like this role because it adds transaction monitoring, and I want to see the whole picture, not just the file at the door."
Saying you fell into it and any back-office job would do, with nothing about what you like in the work.
What draws you: investigation, judgement, protecting the institution.
Your fit: a trait that suits the work, such as patience with detail.
Respect for the business: you see compliance as part of the bank, not against it.
"I've done a bit of both. In college I worked a summer in a branch helping with account openings, and I noticed I cared more about whether the documents were right than whether we hit the day's target. I'm good at detail and I'm comfortable being the person who asks one more question. Compliance also appeals to me because it matters beyond the bank. If a laundering network gets an account, that money funds real harm somewhere. I don't see it as being against the sales side, though. A good analyst helps the business take on clients safely, and I like the idea of being the person who gets a hard file over the line properly instead of just saying no."
Describing compliance as a quieter job with less pressure, or as the team that exists to block deals.
The queue: onboarding files, periodic reviews or alerts assigned by risk and deadline.
The work: verify, screen, research, decide, write it up.
The people: questions to relationship teams, reviews by a checker or quality team.
"I'd expect most of the day to be working through a queue with deadlines attached. That could be new client files, where I verify identity and ownership, run screening and check the documents match. It could be periodic reviews of existing clients, or monitoring alerts, where I look at why a transaction was flagged and whether it fits what we know about the customer. A big part is writing it up clearly, because if my reasoning isn't recorded, a regulator or auditor treats it as never done. I'd also expect back-and-forth with relationship managers when something is missing, and my work going to a checker or quality team. Most cases will be routine. The skill is staying careful enough to catch the one that isn't."
Describing the job as catching criminals all day, with no mention of queues, documentation or review.
Placement: dirty money first enters the financial system.
Layering: moves that break the trail between the money and its source.
Integration: the money comes back looking legitimate.
"The three stages are placement, layering and integration. Placement is getting criminal proceeds into the system in the first place, for example lots of cash deposits kept small so they don't draw attention, or cash mixed into a busy restaurant's takings. Layering is moving it around to hide where it came from, like rapid transfers between accounts in different countries, shell companies paying each other invoices for services nobody delivered, or converting to other assets and back. Integration is when it comes back out looking clean, such as buying property, lending it back to yourself through a company, or paying it as salary from a front business. In practice the stages overlap, and as an analyst I'm usually seeing one piece of one stage in a single account."
Listing the three names with no example, or mixing up which stage is which.
Structuring: cash kept just under reporting limits, spread over days or branches.
Mule signs: many unrelated senders, money out almost as fast as it comes in.
Profile mismatch: activity that doesn't fit the customer's age, job or stated purpose.
"For structuring, I'd look for repeated cash deposits that sit just below the reporting threshold, often on consecutive days or at several different branches or machines, as if someone is working around the limit. For a mule account, the classic picture is a new account, often held by a student or someone with little income, suddenly receiving transfers from lots of people who have no obvious link to them, and then sending it straight out, maybe to an overseas account or a crypto exchange, within hours. The balance stays near zero even though a lot moves through. The common thread is that the activity doesn't match the profile. A student with no job isn't normally handling that kind of volume, so I'd want to understand why before assuming anything."
Naming 'large transactions' as the only red flag, with no link to the customer's profile.
What it is: the intergovernmental body that sets global anti-money laundering standards.
How it works: countries turn its recommendations into law and get evaluated on it.
In the job: country lists feed geography risk and trigger extra checks.
"The FATF, the Financial Action Task Force, is an intergovernmental body that sets the international standards for fighting money laundering and terrorist financing. Its recommendations cover things like customer due diligence, politically exposed persons, beneficial ownership, record keeping and suspicious transaction reporting. Countries write those into their own laws, and the FATF and its regional bodies evaluate how well each country does it. So the local rules I follow, whether that's a central bank's KYC rules or another regulator's handbook, largely trace back to those standards. In daily work it shows up most in geography risk. The FATF publishes a list of high-risk jurisdictions and a list of jurisdictions under increased monitoring. A customer or payment linked to those countries raises the risk score and can mean enhanced checks."
Calling the FATF a regulator that fines banks directly, or not knowing that its country lists affect risk ratings.
Possible typology: over-invoicing moves extra value to the seller under cover of trade.
Related signs: related parties, vague goods, odd routes, third-party payers, repeat invoicing.
Checks: price references, shipping documents, counterparties, the customer's normal trade.
"Over-invoicing is a classic way to move value across borders. If the buyer pays far more than the goods are worth, the extra is really a transfer to the seller dressed up as trade. Under-invoicing does the reverse, and the same shipment billed twice or goods that never ship at all are other versions. So I'd check the price against market references for that product, and look at whether the goods description is specific or vague. I'd check the shipping documents make sense, the route and any transit through high-risk places, and whether the buyer and seller are related. I'd also look at who pays, since payments from unrelated third parties are a warning sign, and whether this product fits the customer's normal trade. There can be a genuine reason, like specialised quality, so I'd ask for it and document the answer before escalating."
Treating a high price as fraud against the buyer only, or escalating without checking any market reference.
Standard: identify and verify, beneficial owners, purpose of the relationship, ongoing monitoring.
Simplified: lighter measures for clearly low risk, only where the rules allow it.
Enhanced: extra checks for higher risk, such as source of wealth and senior sign-off.
"Standard due diligence is the baseline for everyone: I identify the customer and verify it with reliable documents, identify any beneficial owners, understand what the relationship is for and what activity to expect, and then keep monitoring it. Simplified due diligence is a lighter version for customers the rules treat as clearly low risk, for example some government bodies or listed companies, depending on the jurisdiction. It reduces the checks but never removes them, and it's off the table the moment there's any suspicion. Enhanced due diligence is for higher risk, like politically exposed persons, links to high-risk countries or complex ownership. There I dig into source of funds and source of wealth, get senior management approval where required, and set more frequent reviews and closer monitoring."
Treating simplified due diligence as no checks at all, or thinking enhanced checks are only for customers already suspected of a crime.
The entity: registration, constitution, registered address, checked against the official registry.
The people: directors, signatories and beneficial owners identified and screened.
The purpose: nature of business, expected activity, countries involved.
"First the company itself: its certificate of incorporation, its constitutional documents, proof of registered and trading address, and I'd check those against the official company registry, not just the copies we're given. Then a board resolution authorising the account and naming the signatories. Next the people: identify and verify the directors and authorised signatories, and trace the ownership down to the natural persons who ultimately own or control it. Everyone gets screened against sanctions, PEP and adverse media lists, and the company does too. Finally I need to understand the business: what it sells, who its customers and suppliers are, which countries it deals with, and what volumes it expects. That expected activity is what monitoring later compares against, so a vague answer there is a problem."
Stopping at the incorporation certificate and director IDs, with no mention of beneficial owners or expected activity.
Map it: an ownership chart down to natural persons, backed by documents.
Do the maths: multiply through each layer and add direct and indirect stakes.
Look at control: voting rights, board appointment, nominees, trusts; fall back to the senior managing official.
"I start with an ownership chart that goes down to real people, and I verify each layer with registry extracts or certified share registers. Then I work out indirect stakes by multiplying through the chain. If someone owns 60 percent of a holding company that owns 50 percent of our client, that's 30 percent indirect, and I add any direct holding they also have, though some rules treat majority control of a layer as control of its whole stake. I compare that to the threshold our rules set, which varies by jurisdiction. Ownership isn't the only test, so I also look for control by other means, like the right to appoint the board, special voting shares or a nominee arrangement. If a layer is a trust, I identify the settlor, trustees, beneficiaries and anyone with control. If nobody meets the test, the rules usually point to the senior managing official, but I'd document why and treat unexplained complexity as a risk factor."
Stopping at the first corporate shareholder, or ignoring control that isn't expressed as shares.
Look for simple causes: typing error, date format, a system entry mistake.
Get evidence: clarification and a supporting document; never guess.
Decide: fix and record it, or escalate if the story doesn't hold.
"First I'd see if there's a simple explanation. Is it a typo on the form? Is it the date written day-first on one and month-first on the other? Was it keyed in wrongly by our own team? The passport is the stronger document, so I'd treat it as the reference point. Then I'd ask the customer, through the proper channel, to clarify, and if the address proof is the one that's wrong, request a corrected or alternative document. I wouldn't approve the file until it's resolved. If the explanation is sensible and the documents line up, I record what happened and move on. But if the documents show signs of tampering, the explanations keep changing, or they belong to different people, that's a possible identity fraud and I'd escalate it, and consider whether a suspicious report is needed."
Picking whichever date looks right and approving, or refusing the customer outright with no attempt to clarify.
Explain: it's a legal requirement, and our confidentiality obligations protect it.
Hold: no onboarding or continued relationship without it.
Assess: a firm refusal is a risk signal; escalate and consider a report.
"I'd start by assuming it might be a genuine privacy worry, so I'd have the relationship manager explain that identifying beneficial owners is a legal requirement for us, not a choice, and that the information is kept confidential under our own obligations. Sometimes that's enough, and they'll share it directly with compliance rather than in a group email. If they still refuse, I can't onboard them, or if they're an existing client, I'd escalate for a decision on restricting or exiting the relationship under our policy. I'd also look at the refusal in context. A client who won't reveal its owners, combined with other things like an offshore parent or unusual activity, might mean someone is deliberately hiding. That's a reason to escalate internally and consider whether a suspicious report is warranted, and I'd document every step."
Accepting the refusal and onboarding anyway because the client is well known or the RM vouches for them.
Factors: customer type and industry, geography, products, delivery channel.
Overlays: PEP status, adverse media, complex ownership, past alerts.
Outcome: the rating drives the level of due diligence and the review cycle.
"Most risk models look at a handful of factors. Who the customer is and what they do, since cash-intensive trades, money services or dealers in high-value goods score higher. Where they are and where they transact, including countries on international watch lists or with weak controls. Which products they use, like cross-border wires, trade finance or cash services. And how we deal with them, since non-face-to-face onboarding carries more identity risk. On top of that come overlays like PEP status, adverse media or complex ownership. A cash-heavy business in a high-risk location would almost certainly come out high risk, which means enhanced due diligence, a clear understanding of where the cash comes from, and more frequent reviews. If the model gave it medium, I'd challenge it and record why."
Treating the risk rating as a fixed label set at onboarding that never changes.
Cycle: frequency set by risk, with higher risk reviewed more often.
What's checked: documents, ownership, rescreening, actual versus expected activity, rating.
Triggers: ownership change, adverse news, alerts or reports, unusual change in behaviour.
"A periodic review is a refresh of what we know. How often depends on the risk rating and the firm's policy, so high-risk customers come round more often than low-risk ones. In the review I check the identity documents are still valid, the address and occupation or business are current, the ownership hasn't changed, and I rescreen everyone for sanctions, PEP status and adverse media. Then I compare what the account actually did against what the customer said they'd do, and I re-rate the risk if things have moved. An earlier review gets triggered by events: a change of owners or directors, negative news, a sanctions or PEP hit, repeated alerts or a suspicious report, a dormant account suddenly waking up, or the customer asking for a higher-risk product."
Describing a review as just collecting a new copy of the ID.
Situation: the file or alert and why it looked routine.
What you noticed: the specific detail and how you checked it.
Result: what changed, and what you'd tell others to watch for.
"At my last company I was doing a periodic review on a small import business rated medium risk. The earlier reviews had been approved without comment. When I pulled the registry extract, I noticed a new shareholder had been added the previous year, a holding company in a jurisdiction we treated as high risk, and it now owned most of the shares. Nobody had updated our file because the customer never told us. I asked the relationship team to get the new ownership chart, which led to a person who had adverse media about a customs fraud case. The client was re-rated high, put through enhanced checks and in the end exited. Since then I always check the live registry myself rather than trusting what's already in the file."
A vague story about 'being very detail-oriented' with no specific finding or outcome.
Who: people in prominent public functions, plus family members and close associates.
Extra steps: senior approval, source of wealth and source of funds, closer monitoring.
Balance: a PEP is a risk factor, not a reason to refuse.
"A politically exposed person is someone who holds or has held a prominent public function, like a head of state, senior politician, senior judge or military officer, a senior executive of a state-owned company, or a senior official of an international organisation. Their family members and close business associates are covered too. Middle-ranking officials usually aren't. Under the FATF standards, foreign PEPs always get enhanced due diligence, while domestic PEPs and those from international organisations depend on the risk, though some countries treat every PEP the same way. Enhanced means senior management approval to start or continue the relationship, establishing source of wealth, meaning how they built their overall fortune, and source of funds, meaning where the money in this account came from, plus closer ongoing monitoring. Being a PEP isn't wrongdoing, though. It just means more exposure to bribery and corruption risk, so we look harder."
Saying PEPs should simply be refused, or forgetting family members and close associates.
Compare: name and aliases, date of birth, nationality, address, ID or registration numbers.
Decide: discount only on a clear, documented difference; otherwise escalate.
True match: stop, freeze or reject as the rules require, and report.
"Screening tools use fuzzy matching, so they throw up a lot of hits on similar names, especially with transliterated names that can be spelled several ways. For each hit I open the actual list entry and compare it with what we hold: full name and aliases, date of birth, nationality, address, passport or registration numbers, and for companies, owners and directors. If a strong identifier clearly differs, like a different date of birth and nationality, I can discount it and record exactly why. If I can't rule it out, I escalate and the payment or onboarding waits. Sanctions aren't risk-based the way AML is, so a true match means we don't deal, we freeze where required and report to the relevant authority. I'd also remember that under some regimes a company owned or controlled by a listed person can be caught too."
Discounting a hit because the name 'looks different' with no identifier compared or recorded.
Hold: urgency never lowers the standard for a sanctions release.
Get identifiers: request date of birth, address, ID or registration details through the right channel.
Decide or escalate: discount with evidence, or pass to the sanctions team; true match means block and report.
"A name and a country aren't enough to discount a sanctions hit, so the payment stays held, whatever the pressure. I'd tell the business honestly that I need more information, and that the fastest way to release it is to get it quickly. Then I'd request the missing identifiers through the proper channel, like a request to the sending bank for the party's date of birth, full address, ID number or company registration. When they come back, I compare them with the list entry. If they clearly differ, I document why and release it under our sign-off rules. If they match or I still can't tell, it goes to the sanctions team or officer, and if it's a true match we don't process it, we freeze or reject it as the rules require, and report it. I'd also keep the business updated so they're not guessing."
Releasing the payment because the client is important, or because the name 'probably isn't the same person'.
Understand the trigger: which rule fired and why.
Build context: KYC profile, expected activity, a look-back period, counterparties, past alerts.
Decide and record: close with a clear rationale, or escalate; update the profile if needed.
"First I read the alert itself, which scenario fired and on what, because that tells me what the system thinks it's seeing. Then I pull the customer's profile: who they are, their job or business, their risk rating and the activity they told us to expect. I look at the account over a look-back period, not just the flagged transaction, to see if it's a one-off or a pattern, and I check who the money came from and went to, where, and whether those counterparties appear elsewhere. I check previous alerts and any past reports. If I need more, I'll use open sources or ask the relationship team for information without revealing why. Then I decide. If there's a reasonable explanation, I close it with a rationale someone else could follow. If not, I escalate for a suspicious activity report and flag whether the risk rating needs changing."
Looking only at the single flagged transaction and closing it because the amount 'seems normal'.
Pattern: amounts, timing, branches, and where the money goes next.
Profile: job, income, expected activity; any recent life change on file.
Resolve: get an explanation and evidence, update the profile, or escalate.
"I'd look closely at the pattern first. Are the deposits just under a reporting threshold? Are they at different branches on the same day, as if spread out on purpose? And what happens to the money after, does it sit there or go straight out, maybe abroad? Then I'd compare with the profile: their job, income and what we expected from the account. There can be a real reason. Maybe they've started a business, sold something or received an inheritance. So I'd ask the relationship team to get an explanation and supporting evidence, without revealing any suspicion. If it checks out, I update the expected activity and maybe the risk rating. If the explanation is weak, doesn't match the evidence, or the pattern looks like structuring, I escalate it for a suspicious activity report and trigger an early review."
Closing it because the customer has banked with you for years, or assuming guilt without checking for a legitimate reason.
The basics: who, what, when, where, how much, through which accounts.
The why: what makes it suspicious against what you know of the customer.
The craft: chronological, factual, plain language, stands on its own.
"The reader has never seen our systems or this customer, so the narrative has to stand on its own. I cover who is involved with identifying details, what happened, when, through which accounts and for how much, and where the money came from and went. Then the most important part, why it's suspicious: what we expected from this customer and how the activity differs, and what we checked that didn't explain it. I write it in time order, in plain language, and I avoid internal codes or rule names that mean nothing outside the bank. I stick to facts and say clearly where something is my inference. I don't need to prove a crime or name one. The standard is suspicion, and my job is to make it easy for an investigator to see what I saw and act on it."
A narrative that just lists transactions with no explanation of why they're suspicious, or one that accuses the customer of a specific crime.
Context: the case and who needed to decide.
Your approach: lead with the decision needed, then the key facts.
Outcome: the decision and what you learned about writing for seniors.
"I'd investigated a customer with transfers through five companies in three countries, and the head of financial crime had to decide whether to exit the relationship. My first draft was two pages in the order I'd found things, which was useless to her. I rewrote it so the first two lines said what decision was needed and my recommendation. Below that I put three points: what the customer told us they did, what the money actually did, and why the gap worried me. I added a one-line diagram of the fund flow and moved the detail to an appendix. She read it in a few minutes, asked one question and approved the exit. Now I write every escalation that way, recommendation first."
Describing a long, chronological write-up and saying the senior person should just read it all.
Don't tip off: never mention suspicion, an investigation or a report.
Stay neutral: use the approved wording about routine checks.
Record and route: note the call and pass it to the right team.
"The key thing is not to tip them off. Telling a customer, even indirectly, that they're under suspicion or that a report is being made is usually an offence, and it can wreck an investigation. So I wouldn't mention the escalation or hint at it. In most firms an analyst wouldn't handle that call directly, so I'd follow our process, often routing it through the relationship or operations team with approved wording. What they can say is neutral and true, something like the transaction is going through standard checks and we'll be in touch when it's complete. I wouldn't give a firm release time I can't promise, and I wouldn't make up a technical fault. I'd log the call on the case, because what the customer says can matter to the investigation."
Explaining that the payment looks suspicious, or inventing a false technical reason to calm them down.
The error: what it was, stated plainly.
The fix: correct the file, and find why it happened.
The change: the habit or checklist you added so it didn't repeat.
"In my first year, quality control picked up that I'd approved a file where the proof of address was more than three months old, which was past our policy limit. It wasn't a fraud risk in that case, but it was a clear miss. I owned it straight away, got the updated document and corrected the file the same day. Then I looked at why it happened. I'd been checking that the document existed, not its date. So I went back through my other files from that month and found one more with the same issue, which I fixed before QC found it. After that I added the date check to my own checklist, and I suggested the team template show the document date next to the upload, which the team lead adopted."
Blaming the system, the deadline or the checker, or claiming QC has never found anything in your work.
The situation: why the backlog built up and what was at stake.
Prioritising: by risk and deadline, not by what's quickest.
Speaking up: telling the lead early and suggesting a plan.
"We had a remediation project where a regulator had asked the bank to refresh a large set of older files, and on top of that two people left the team. Within a few weeks my queue was well over what I could clear by the deadline. The first thing I did was tell my team lead with numbers, rather than quietly working late and hoping. Then I sorted the queue by risk and due date, so high-risk and overdue files went first. I noticed many files were stuck waiting on the same missing documents, so I batched those requests to the relationship managers in one list each week instead of chasing file by file. We got temporary help for the low-risk ones. We met the deadline, and our QC pass rate held steady, which mattered more to me than speed."
Saying you caught up by working faster and skimming the lower-risk files.
The change: what changed and why.
How you learned it: reading the source, asking questions.
How you applied it: changed your checks, maybe helped the team.
"At my last company the beneficial ownership threshold for company customers was lowered after a local rule change, which meant some owners who used to fall below the line now had to be identified and verified. I read the actual circular rather than just the summary email, because I wanted to know exactly which customer types it covered and from when. I updated my own checklist and noticed our template still showed the old number, so I flagged that to the procedures team. I also offered to walk two newer colleagues through a couple of example files. Over the following weeks, periodic reviews picked up the extra owners, and I kept a short note of the tricky cases in case QC questioned any."
Saying you just waited for training, or not being able to name any change you had to adapt to.
Check first: look at a few of the cases before assuming anything.
Talk to them: privately, as a colleague, not an accuser.
Escalate if needed: poor closures are a regulatory risk, not a personal matter.
"I'd start by checking my assumption. Some alert rules produce a lot of low-value hits, and there might be a genuine reason the same explanation fits many of them. So I'd look at a few of the closed cases myself. If they really do look thin, like no look-back or no reference to the customer's profile, I'd talk to my teammate privately first. Maybe they're under pressure on numbers, or nobody showed them what a good rationale looks like, and I could help. If it carries on, or if I see something closed that clearly should have been escalated, I'd raise it with the team lead or quality team. It's not about getting anyone in trouble. A weakly closed alert is exactly what a regulator finds on review, and it could mean real laundering got through."
Saying it's not your business, or going straight to the manager without looking at a single case.
Sources: regulator and FATF publications, internal bulletins, sanctions updates.
Habit: a regular slot, not only when training is due.
Use it: connect what you read to cases and share with the team.
"I have a few regular sources. Sanctions lists change often, so I rely on our internal updates and read the summaries when a big set of designations comes out. I read the publications from our regulator and the FATF, especially their typology reports, because they show real cases, like how mule networks are recruited online. I also keep an eye on enforcement actions against banks, since they show exactly which control failures got firms fined. I spend a bit of time on it every week rather than waiting for annual training. And when I read something useful, I try to connect it to our work. After reading about a trade-based scheme, I shared a short note with the team on what the invoices looked like, and we used it in our next training session."
Relying only on mandatory annual training, or not being able to name a single source.
The pressure: who, what they wanted, why it mattered to them.
Your stand: what was missing and why you couldn't approve without it.
The path: what you offered to help get it done properly, and the result.
"A relationship manager had a large new corporate client and wanted the account open before month end. The ownership chart stopped at a trust, and we had no details of who the beneficiaries or controllers were. He was pushing hard and copied his manager in. I stayed calm and explained in writing exactly what was missing and why I couldn't approve without it, pointing to the policy rather than making it personal. Then I made it easy: I sent him a short list of the three documents I needed and offered to join a call with the client's lawyer to explain. The documents came in a week later, the file went through, and the account opened a few days after month end. He grumbled, but he now sends me the full pack up front."
Either giving in because the client was important, or describing the RM as the enemy with no attempt to help.
The purpose: protecting the bank, its customers and the wider system.
How you work: clear asks, fast feedback, explain the why.
The limit: where you won't bend, and why that helps the business too.
"I see the role as helping the bank take on and keep the right customers safely. Most of the time that isn't saying no, it's saying yes, once we have what we need. So I try to be specific about what's missing and why, answer quickly, and explain the reason so the front office can get it right next time. I'd rather send one clear list than chase five times. Where I won't bend is on the things that genuinely protect everyone, like beneficial ownership, sanctions and suspicious activity. A bank that onboards the wrong client faces fines, damage to its name and sometimes restrictions on its business, and that hurts the sales team far more than a delayed account. When people see it that way, the 'department of no' label tends to fade."
Either treating the business as the enemy, or suggesting rules can be relaxed to keep clients happy.
ClapAssist is an AI interview assistant for Mac and Windows. It listens to the interview on your computer and shows you what to say, in short lines you can read while you talk. Your resume and notes are never stored on our servers. It stays out of screen share on every plan; only you can see it.