Effective assurance over customer due diligence has three layers: in-line quality control that prevents defects reaching the file, independent quality assurance that tests whether the process is producing acceptable outcomes, and periodic independent testing that challenges the design of the controls themselves.
On this page
The three-layer model
- Quality control. First line, close to the work, often pre-release. Focused on completeness, accuracy and adherence to the standard. Its purpose is to prevent defective files, not to measure them.
- Quality assurance. Independent of the people who performed the work, sampling after the event. Focused on whether outcomes are acceptable and whether the reasoning holds. Its purpose is to measure and to inform change.
- Independent testing. Separate from the operation entirely, on a defined cycle. Focused on control design as well as operation: is the risk methodology sound, is the trigger logic adequate, does the assurance function itself work.
Firms that collapse these into one activity generally end up with a first-line checking function reporting favourable results to the managers whose throughput it constrains.
Regulatory basis, stated carefully
The Money Laundering Regulations 2017 set the statutory framework for policies, controls and procedures, and the FCA Financial Crime Guide sets out expectations for firms the FCA supervises, including compliance monitoring and audit arrangements proportionate to the business.
The FCA's April 2026 findings on customer due diligence processes and controls observed weak independent assurance and version control among the weaknesses it identified, and described regular and independent testing as part of stronger practice. Those findings describe the firms reviewed; the nature and scale of assurance appropriate to any given firm depends on its size, sector, supervisor and risk profile. This page is general information, not legal or compliance advice.
Sampling design
- Stratify by risk and impact. Higher-risk customers, EDD cases, overrides and exited relationships warrant heavier sampling than standard low-risk files.
- Cover every outcome type. Including cases closed with no action, which are the easiest to under-sample and the hardest to defend later.
- Sample by analyst, team and vendor. Otherwise a localised quality problem is diluted into an acceptable aggregate.
- Include recently changed configuration. New rules and thresholds should be sampled disproportionately after release.
- Document the sampling basis and revisit it when the population or the risk profile changes.
Agora practitioner interpretation
We would run two distinct checks rather than one. Mechanical completeness and consistency checks can run across the entire population automatically, so they need not be sampled at all. Human sampling should then be spent on the questions only a person can answer: was the reasoning sound, was the evidence sufficient, was the risk rating credible.
Defect taxonomy and severity
A defect taxonomy makes results comparable over time and actionable. Each category should name the control it affects, define severity by regulatory and risk impact, and specify the remediation route.
- Critical. The conclusion is unsupportable or a required measure was not performed, for example EDD engaged but not evidenced.
- Major. The conclusion may stand but key evidence or reasoning is missing, such as an ownership chain without sources.
- Minor. Administrative or presentational defects with no effect on the conclusion.
Severity should never be set by remediation effort. A field that takes seconds to fix can still be a critical defect if the control depends on it.
Closing the loop
- Correct the individual file, with the correction itself recorded.
- Determine whether the defect is isolated or systemic, using cohort testing.
- Where systemic, scope the affected population and remediate it as a programme. See KYC remediation.
- Fix the cause: guidance, training, system validation, rule change or process redesign.
- Re-test after the change and record whether the defect rate moved.
- Retain the whole loop as evidence that assurance drives change, which is what independent testing looks for.
Reporting that is worth reading
- Defect rate by severity, trend over time, and volume behind each rate.
- Breakdown by team, vendor, customer segment and control.
- Ageing of open defects and of remediation actions.
- Override volumes and reasons, from the risk assessment and elsewhere.
- Coverage: what proportion of the population was tested and what was not.
- Actions taken since the last report and their measured effect.
Common pitfalls
- QA performed by the same team that did the work, or reporting into it.
- Checklists that test for presence of a field rather than adequacy of the conclusion.
- Fixed sample percentages with no risk stratification.
- Defects corrected file by file with no root cause work.
- No testing of configuration changes after release.
- Assurance findings reported but never tracked to closure.
Where technology helps
Population-wide completeness testing, configuration change tracking, defect capture and trend reporting are all natural automation targets, and they free scarce expert attention for judgement-based review. The Agora Due Diligence Platform includes quality control and batch remediation capabilities, with the underlying evidence structured as described in building a defensible CDD audit trail.
Primary sources
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- FCA Financial Crime Guide, chapter 3
- HMRC AMLG11300, customer due diligence (updated 16 July 2026)
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
Frequently asked questions
What is the difference between quality control and quality assurance in KYC?
Quality control is generally performed within the first line, close to the work and often before a case is released, to catch and correct defects. Quality assurance is performed independently of the people who did the work, usually on a sample after the event, to test whether the process as a whole is producing acceptable outcomes.
What did the FCA say about independent testing in 2026?
In its April 2026 findings on customer due diligence processes and controls, the FCA described stronger practice as including regular and independent testing alongside risk-tailored due diligence and documented enhanced due diligence steps, and observed weak independent assurance and version control among the weaknesses it found.
How large should a QA sample be?
Large enough to support a conclusion about the population it represents, and stratified so that higher-risk and higher-impact cases are sampled more heavily. Firms should document the sampling basis and review it, rather than sampling a fixed percentage because it has always been that percentage.
What should a defect taxonomy contain?
Defect categories mapped to the control they affect, each with a severity definition, an example, and a defined remediation route. Severity should reflect regulatory and risk impact rather than how long the fix takes.
Can quality assurance be automated?
Completeness and consistency testing can be automated across the whole population rather than a sample, which is a significant gain. Judgement-based assessment of whether a conclusion was reasonable on the evidence needs a competent independent reviewer.
Related resources
Governance and assurance
Building a Regulator-Defensible CDD Audit Trail
Remediation and ongoing KYC
KYC Remediation: How to Modernise Customer File Remediation
CDD and onboarding
Customer Risk Assessment: A Practical CDD Framework
CDD and onboarding
Enhanced Due Diligence (EDD): Triggers, Evidence and Controls
Where the technology fits
Agora is a technology provider: the platform supports the control described above, and your own teams operate it and hold the accountable decisions.
Next step
Assurance that tests the whole population
See automated completeness and consistency checks alongside sampled human review in the Agora platform.