III The Method

Ten Questions a Database Cannot Answer

The questions that decide whether a counterparty damages you are mostly not questions about records, which is why the instrument built to hold records cannot reach them.

One sentence on this firm's compliance page does more work than the rest of it: we do not conduct "check-the-box" due diligence, and we do not provide copy-and-paste reports. It refuses a product that sells well, and a refusal is worth making only if the reason can be stated.

Here is the reason. A compliance database aggregates records other people created: corporate filings, sanctions designations, court indices, insolvency notices, press archives. It reproduces them quickly, cheaply and at scale, and at that it is excellent. Its limitation is not accuracy and never was. The limitation is that the questions determining whether a relationship will damage you are mostly not questions about records.

The firm's compliance page asks ten of its own: whether a company or individual actually exists, whether officials are politically exposed, sanctions exposure, trails of litigation and bankruptcy, a history of fraud, allegations of corruption, whether these people will honour their debts, whether they will steal your money, and whether doing business with them damages your reputation. What follows keeps the ones an instrument cannot reach and adds three the work throws up. Each item defeats the instrument for a different reason.

The ten questions

1. Does this entity exist in the way it is described? Existence is the easy half. A search returns an incorporation, a number, an address and a filing history, none of it evidence of trading. Regulation 28(18) of the Money Laundering Regulations 2017 requires verification from documents or information obtained from a reliable source independent of the person whose identity is being verified. A database reproducing the subject's own filing is not independent of it; it is the subject's assertion at one remove, delivered faster.

2. Who decides? Every regime answers by proxy, because a workable rule must. Under 31 CFR 1010.230 a beneficial owner means each individual holding 25 per cent or more of the equity interests, plus a single individual with significant responsibility to control or manage the entity — and the institution may rely on information supplied by the customer itself, absent knowledge calling it into question. FATF assessment criterion 12.1 requires, in relation to foreign politically exposed persons, risk-management systems to determine whether a customer or beneficial owner is one; the FATF glossary defines such a person by office held, and states the definition is not intended to cover middle-ranking or more junior individuals. Neither rule is the answer. The person who decides may hold four per cent, hold no title, and hold a relationship with the chairman that predates the company.

3. What happens when the named principal is unavailable? Screening returns the current officers. It does not return the dependency. The question is what the counterparty can still perform when one person is dead, ill, detained or estranged from the board: who else signs, and whether the succession on paper is the one that would occur. The control prong compounds this: it asks for one individual. A file naming one controller is not a finding about continuity.

4. Is there a litigation or bankruptcy trail that never reached a database because it settled? Article 30.1 of the LCIA Arbitration Rules, in force since 1 October 2020, has the parties undertake as a general principle to keep confidential all awards and all materials created for the arbitration; Article 30.3 provides that the LCIA publishes no award without the written consent of every party and the tribunal. Substantial parties contract into that deliberately, so the disputes most worth knowing about are absent from any index by design, and a counterparty returning nothing is indistinguishable, on the face of a report, from one that is well advised.

5. Is there a history of fraud that was handled internally? Internal resolution is built to leave nothing: a resignation, restitution, a confidentiality clause. One regime cuts against it. Under the FCA's SYSC 22 a firm must give a regulatory reference where another firm is considering a candidate for a senior management or certification role, disclosing what it reasonably considers relevant to fitness and propriety, over six years, and serious misconduct with no time limit. Elsewhere, a fraud dealt with quietly produces a clean record and a few people who know. Only one of those can be bought by subscription.

6. Are the corruption allegations sourced or repeated? The FATF's 2022 methodology sets out the criteria by which national rules are judged. The phrase "adverse media" does not appear in it. Identity verification carries a source standard — reliable, independent. Allegations carry none. So screening products aggregate published assertions without grading provenance, and republication reads as corroboration. Three results can be one source. Establishing where a claim began and who made it is a research task with an answer. It is not a search.

7. Will they honour their debts? Capacity and willingness are separate properties and only the first is measured. Accounts, ratings and filings describe what a counterparty could pay. Willingness shows in conduct towards parties with no leverage: the supplier too small to litigate, the contractor held past terms, the minority holder bought out at a number they still resent. Those accounts exist in the people who were on the other side of them.

8. What does the relationship do to your own standing? Section 7 of the Bribery Act 2010 puts the fact in legal form: a commercial organisation is guilty of an offence where a person associated with it bribes another intending to obtain or retain business, or an advantage in the conduct of business, for it, and the defence is proving adequate procedures were in place. Association extends beyond employment. Exposure created by a counterparty is thus half a fact about them and half a fact about your own structure, and no screening product reaches the second half.

9. What has changed since onboarding? Regulation 28(11) requires ongoing monitoring, including scrutiny of transactions and keeping due diligence information current. Automation performs well against events that generate records: a designation, a filing, a judgment, a change of officer. It performs poorly against what moves risk — the founder's quiet exit from operations, a funder nobody has met, the departure of the finance director who used to say no. Regulation 35 adds a clock: where a person ceases to hold a prominent public function, the requirements continue for at least twelve months, and longer where the firm considers it appropriate.

10. Will they steal your money? This one the site asks in terms, ninth of its ten. It cannot be answered, because it asks about an act that has not happened. What enquiry produces is narrower: whether this has been done before and with what consequence, whether the proposed structure would permit it, and whether anyone in the arrangement would notice if it began.

The economy of the defensible file

Compliance theatre is usually called laziness. It is better understood as a rational response to how the duty is written. Regulation 19 requires a firm to establish and maintain policies, controls and procedures to mitigate the risks identified in its own risk assessment. Regulation 76 lets a supervisor penalise a contravention of a relevant requirement, and regulation 76(4) forbids a penalty where the supervisor is satisfied the person took all reasonable steps and exercised all due diligence to comply. The protection is procedural. Being wrong about a customer is not the test; failing to have done the specified things is.

The FATF states the divergence from the other side. Its 2022 methodology grades technical compliance and effectiveness on separate scales, and says assessing effectiveness is a fundamentally different exercise: not checking whether specific requirements are met, but judging whether defined outcomes are being achieved. The body that writes the standard scores the paperwork and the result separately, because they come apart.

Section 77 of the Financial Services and Markets Act 2023 required the Treasury to amend the Money Laundering Regulations so that, for a domestic politically exposed person, the starting point is a lower level of risk than for a non-domestic one. That amendment took effect on 10 January 2024, as regulation 35(3A). No individual changed. The classification did, and with it the file. A compliance record is an artefact of a rule, and the rule is not the person.

Two products are sold under one name. One is a defensible file: reproducible, auditable, disclosable to a regulator or an investment committee. It answers a requirement to show the specified steps were taken. The other is an accurate answer about a counterparty: slow, partly unverifiable to anyone who was not present, sometimes negative. It answers nothing about procedure. Both are legitimate. The failure is buying the first while believing you hold the second, and nothing in the transaction announces which one arrived.

Nothing here is legal advice; what an obligation requires in a specific territory is a question for counsel there.

The work sits under KYC & Enhanced Due Diligence and Due Diligence Investigations, and the same problem in its personal form under Background Screening. What a filing cannot hold is set out in What Filings Never Record.

Sources

  1. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 28 (customer due diligence measures; ongoing monitoring)
  2. The Money Laundering Regulations 2017, regulation 19 (policies, controls and procedures)
  3. The Money Laundering Regulations 2017, regulation 35 (enhanced due diligence: politically exposed persons)
  4. The Money Laundering Regulations 2017, regulation 76 (power to impose civil penalties: fines and statements)
  5. Financial Services and Markets Act 2023, section 77 (politically exposed persons: domestic PEPs)
  6. 31 CFR 1010.230 - Beneficial ownership requirements for legal entity customers (eCFR, current)
  7. FATF - Methodology for Assessing Technical Compliance with the FATF Recommendations and the Effectiveness of AML/CFT/CPF Systems (2022)
  8. LCIA Arbitration Rules 2020, Article 30 (Confidentiality), effective 1 October 2020
  9. Bribery Act 2010, section 7 (failure of commercial organisations to prevent bribery)
  10. FCA Handbook, SYSC 22.2 (regulatory references: getting, giving and updating references)
  11. Privy Consul - KYC & Enhanced Due Diligence (International Due Diligence Questions)
  12. The Money Laundering and Terrorist Financing (Amendment) Regulations 2023 (SI 2023/1371) — inserting regulation 35(3A), in force 10 January 2024