Playbook

KYC exceptions and maker-checker: put people on the files that need them.

When every application goes to a person, the team spends its day on clean files and the difficult ones wait in the same queue.

The problem

Checks are manual and uneven, so every file is reviewed by hand. Clean files take as long as difficult ones, and two reviewers may decide the same case differently.

The playbook

  1. Write your KYC policy as rules and bands: what passes, what fails, what needs a person.
  2. Apply those rules the same way to every file.
  3. Send only files outside the band to a person, with the reason it was flagged.
  4. Require a second person to approve before any write to the core (maker-checker).
  5. Keep the system read-only by default; open only the APIs it needs.
  6. Keep a kill switch for every automated step.
  7. Log every read, decision and write in one audit log.
  8. Review exception reasons weekly and tune the rules with compliance.

What a good exception carries

FieldExample
ReasonName on address proof does not match ID
EvidenceThe two documents, side by side
Rule triggeredName match below your threshold
OwnerThe reviewer assigned
Decision and approverMaker and checker, with time

KYC requirements, periodicity and acceptable documents are set by your regulator and your own board-approved policy; confirm them with your compliance team.

How AutoKYC does it

AutoKYC handles onboarding and periodic re-KYC for banks, NBFCs and insurers. Customers send documents on WhatsApp, the web or at a branch; ID, address and income documents are read on arrival, and name, date of birth and address are matched to the application. Anything missing is asked for in the same conversation, and a video-KYC slot can be booked there too. PAN, CKYC and account-aggregator checks run where you allow them. Your policy rules and bands are applied the same way every time; outside the band a person decides, and only the exceptions reach a person, with the reason. Below threshold, maker-checker requires a second person to approve before anything is written to your core, and it writes only through the APIs you open; it is read-only by default, with a kill switch per agent. Re-KYC runs on WhatsApp by risk segment, and every read, decision and write is in one audit log. It runs on managed cloud, in your VPC or on-premises.

Questions

What is maker-checker in KYC?

A control where one person (the maker) prepares or decides a case and a second person (the checker) approves it before any change is written to the core system.

How do I reduce manual KYC review?

Write the policy as rules and bands, apply them the same way to every file, and send only files outside the band to a person, with the reason they were flagged.

See it on your own data. AutoKYC — Onboarding in hours, on WhatsApp. Book a 30-minute working session with an engineer.

General guidance, current as of the date above. Figures and examples are illustrative unless a source is linked.