Skip to main content
WIDTH IntelligenceKYC & AML
Compliance workflow design guide

What Should a Compliance Workflow Look Like?A practical guide to connected compliance operations

Learn how to build a connected compliance workflow across KYC, KYB, monitoring, investigations, decisions and audit-ready records.

15-minute read26 August 2026
COMPLIANCE WORKFLOWCONNECTED
01TriggerStartSTART
02AssessContextCONTEXT
03DecideOwnedOWNED
04MonitorLoopLOOP
EVIDENCEKept with the decisionACCOUNTABILITYOwner always clear
Article overview

A good compliance workflow should answer five questions without sending an analyst through several systems: what triggered the review, what happens next, who owns the decision, what evidence supports it and what could reopen it.

The questions are simple. The work rarely is. Customer data, screening results, approvals and transaction alerts often live in different places. Each tool may work, yet the decision remains hard to reconstruct.

What is a compliance workflow?

A compliance workflow is the controlled sequence of tasks, evidence, decisions and approvals used to apply policy to a customer, transaction, alert or case.

It defines the trigger, required information, owner, decision conditions, deadlines, records and events that may cause a later review. A procedure explains how to complete a task; a workflow shows how that task contributes to a decision.

  • What triggered the review?
  • What needs to happen next?
  • Who owns the decision?
  • What evidence supports it?
  • What could reopen it?

What should the workflow look like at a glance?

The exact process depends on the organisation, sector, jurisdiction, product and risk appetite. A practical lifecycle follows eight connected stages.

Trigger and ownership → Information collection → Verification and screening → Risk assessment and decision → Ongoing controls → Alert triage → Investigation and action → Quality assurance and improvement

It is a loop, not a conveyor belt.

A new beneficial owner, sanctions result, transaction pattern or investigation outcome may send the customer back to verification, enhanced due diligence or risk assessment.

The eight stages of an effective compliance workflow

  1. Begin with a clear trigger and ownerRecord why the review started, what is in scope, which policy version applies, when it is due and who owns the next action.
  2. Collect and validate the right informationGather only what the decision requires. Show whether evidence is complete, current, missing or expired, and route exceptions to an authorised reviewer.
  3. Verify and screen without losing evidenceKeep identity, ownership, sanctions, PEP and adverse-media results connected to the customer record—not reduced to a bare pass or fail.
  4. Make risk and decision logic explainableShow which factors changed the outcome, record missing data and overrides, and preserve the evidence, reviewer, approver and rationale.
  5. Carry the decision into ongoing controlsUse onboarding context to shape risk ratings, expected activity, screening frequency, transaction monitoring and event-driven reviews.
  6. Triage signals before opening a caseTreat an alert as a signal. Give the reviewer the trigger, customer risk, related activity, earlier cases and escalation rule before deciding what happens next.
  7. Investigate, decide and record the actionConnect the alert, customer, ownership, transactions, evidence and earlier decisions in one controlled case with clear authority and outcomes.
  8. Use completed work to improve the controlFeed quality findings and outcomes back into risk factors, monitoring logic, procedures, workflow design, training and management reporting.

A practical compliance workflow example

A company was approved six months ago. A registry update reveals a new director. Soon afterwards, transaction monitoring identifies payments outside the customer’s expected geographic profile.

In a disconnected process, each event lands in a different queue. In a connected workflow, the director change starts updated KYB checks, the new director is screened, the transaction alert attaches to the same record and both events inform one risk reassessment. If escalation criteria are met, a single case opens with the relevant evidence and approval route.

  1. The director change creates an event against the customer.
  2. The workflow requests updated KYB evidence and screens the director.
  3. The transaction alert links to the same customer and historical assessment.
  4. Combined information triggers a risk reassessment.
  5. One case opens with both events when escalation criteria are met.
  6. The decision updates risk, monitoring and the next review date.

Technology prevents context from disappearing. The compliance judgement still belongs to the institution.

What should be automated, and what should remain human?

Automation works best for repeatable, rules-based tasks. Human judgement matters most when evidence is ambiguous, risk is material or accountability cannot be delegated.

Technology can supportPeople should remain central to
Required-field validation and approved data retrievalUncertain matches and conflicting evidence
Screening, monitoring rules and missing-evidence checksComplex ownership and authorised exceptions
Work routing, deadline tracking and context assemblySuspicious-activity decisions and proportionate remediation
AI summaries and draft rationaleChallenge, override, approval and the final conclusion

AI may help prepare a case. It should never make accountability disappear.

Five questions to test your workflow design

  • Can every review be traced to a recorded trigger?
  • Does every open item have a named owner and decision authority?
  • Does the evidence remain connected to the decision?
  • Can exceptions and later risk events follow controlled routes?
  • Can management see decision quality and risk—not only volume and speed?

If any answer is unclear, automation may simply move confusion faster.

How should compliance workflow performance be measured?

Handling time matters, but it should not stand alone. A balanced view covers control quality, risk effectiveness, operational health and governance.

Control quality

Quality-assurance pass rates, rework and evidence completeness.

Risk effectiveness

Reopened cases, missed context and outcomes by risk level.

Operational health

Queue age by risk and time spent waiting for evidence or approval.

Governance

Overdue reviews and decisions missing policy references or authority.

Faster closure is not an improvement if rework increases or relevant context is missed.

Common compliance workflow mistakes

Automating a broken process

Automation scales the existing design. Unclear decision rights and exception paths become faster confusion.

Treating every case the same

Consistency does not mean uniform effort. Risk-based routes should remain defined and controlled.

Separating onboarding from monitoring

Customer information loses value when it cannot inform later screening, monitoring and investigation.

Optimising for closure rather than judgement

Speed-only targets encourage weak rationales, premature closure or unnecessary escalation.

Building the audit trail afterwards

Actor, time, evidence, policy and rationale should be captured while the work happens.

How WIDTH supports a connected compliance workflow

WIDTH is designed to connect compliance work across the customer lifecycle rather than leave each control in a separate queue.

KYC Onboarding and KYB Onboarding support structured collection, verification, screening and risk review. Transaction Monitoring brings customer and transaction signals into alert workflows. Case Management connects alerts, evidence, tasks, approvals and outcomes in one investigation record.

Risk Graph Intelligence helps teams examine connections across customers, companies, owners, accounts, transactions and earlier cases. WIDTH AI Reviewer can assist with evidence preparation while keeping the reviewer accountable.

Together, these capabilities support one platform, one workflow and one source of truth. Product scope and configuration depend on institutional requirements; technology does not replace the organisation’s risk assessment, governance or judgement.

Risk-based, jurisdiction-aware by design

The workflow must reflect the laws, rules and guidance that actually apply to the organisation. FATF provides an international risk-based framework; jurisdictions translate it into local requirements.

References

See the FATF risk-based approach update and the FCA Financial Crime Guide. This article is general information, not legal advice.

Frequently asked questions

A compliance workflow turns policy into controlled, repeatable work. It defines triggers, tasks, evidence, ownership, decisions, approvals and records so the organisation can manage risk consistently and explain what it did.

Connected compliance operations

Build the workflow before adding more tools

See how WIDTH connects onboarding, monitoring, investigations, approvals and audit-ready decisions in one compliance environment.

Make every compliance decision easier to follow

Connect customer context, evidence, ownership and approvals across the full compliance lifecycle.