A failing RICA process usually shows up as incomplete identity records, missing proof of address, poor retention of verification evidence, or inconsistent checks between individual and business customers. Another warning sign is when teams cannot prove who was verified, when, and against what documentation. Those gaps create audit exposure and weaken lawful data handling.
What failing RICA controls look like in day-to-day operations
RICA failures are usually visible long before an audit or regulator asks questions. The process starts to drift when onboarding staff treat verification as a formality rather than an evidence-driven control, and when records are accepted without a consistent standard for identity, address, and customer classification. At that point, the issue is not just administrative quality. It becomes a trust problem because the organisation can no longer show that each record was collected, checked, and retained in a defensible way.
For compliance teams, the practical warning signs are usually repetitive rather than dramatic: missing or unreadable supporting documents, inconsistent treatment between branches or channels, manual workarounds that bypass mandatory fields, and exceptions that are approved but never revisited. If the same gaps keep appearing across customer types, the process is probably weak rather than isolated. The FATF Recommendations — AML and KYC Framework remain a useful reference point because they reinforce the expectation that customer due diligence must be reliable, repeatable, and evidence-backed. In practice, many compliance teams discover process failure only after they cannot reconstruct a customer file that should have been complete from the start.
How weak RICA workflows break in practice
A healthy RICA workflow does three things well: it identifies the right person or entity, it captures the required supporting evidence, and it preserves enough proof to show the decision was made correctly. When any one of those steps becomes optional, the whole process starts to fail. The most common breakdown is inconsistent intake. Staff may verify some customers thoroughly while accepting abbreviated checks for others, usually because of time pressure, poor training, or unclear decision rules. Over time, that creates uneven records that are hard to defend.
Another common failure mode is poor evidence handling. Even when the right documents were collected, the organisation may not retain the version that was reviewed, may not timestamp the verification event, or may not tie the record back to the person who approved it. That matters because compliance is not only about whether a check happened. It is also about whether the organisation can prove what happened, who did it, and under what standard. The process should therefore produce a clear trail from submission to approval, including exception handling and follow-up where required.
RICA processes also weaken when business rules and individual-customer rules blur together. A retail customer and a business account often require different checks, but teams sometimes apply one template to both. That creates false confidence because the file looks populated even though the underlying verification logic was wrong. Similarly, if rejected or incomplete applications can still progress into downstream systems, the control has become advisory instead of mandatory.
- Check whether every required field is truly enforced, not merely displayed.
- Confirm that identity and address evidence is legible, current, and linked to the specific record.
- Verify that exceptions are tracked, reviewed, and closed rather than left as permanent waivers.
- Test whether an auditor could reconstruct the decision from the retained evidence alone.
If the organisation cannot reproduce the verification trail without relying on memory or side conversations, the process has already moved from compliant workflow to informal judgement.
Where RICA fails most often and what those gaps mean
Tighter verification controls often slow onboarding and increase documentation overhead, so organisations must balance customer friction against evidential quality. The tradeoff is that faster processing usually produces weaker assurance unless the control design is disciplined.
Some failures are technical, while others are governance problems. A technical failure appears when systems do not force completion of required checks or when records can be saved with missing evidence. A governance failure appears when people know the rules but apply them inconsistently, especially across channels or customer segments. Where regulators expect strong recordkeeping, inconsistency is not a minor flaw. It is a sign that the compliance process is not operating as a control, only as guidance.
One nuance is that not every gap means the same thing. A missing document may be a recoverable exception if it is detected immediately and closed with proper escalation. Repeated missing documents, however, suggest a broken intake design. Likewise, occasional data-entry errors are different from a pattern of unverifiable approvals. Guidance versus consensus is important here: organisations sometimes assume that a long-running manual practice is acceptable because it has not yet been challenged, but that is not the same as demonstrable compliance. The strongest indicator of failure is not a single defect. It is a repeatable inability to prove completeness, consistency, and retention across the full customer lifecycle.
When those gaps are systemic, the process stops serving its purpose and becomes a liability because it creates records that look compliant but cannot reliably support audit, dispute handling, or regulatory review.
Practitioner Guidance
What to prioritise: Focus first on evidence completeness and traceability, because those are the fastest ways to tell whether the process is truly operating or merely producing paperwork. A file that cannot show the who, when, and what of verification should be treated as suspect even if the customer was eventually onboarded.
What to verify: Test a sample of records end to end and confirm that each one has a clear chain from submitted evidence to approval, including any exceptions. The key question is whether a reviewer could defend the decision without relying on staff memory or undocumented judgment.
Common mistake: Treating isolated missing documents as a one-off issue when the real problem is inconsistent enforcement. If the same defect appears across branches, channels, or customer types, the control design needs correction, not just better reminders.
Practitioner takeaway: A RICA process is failing when it cannot consistently prove completion, not just when it occasionally omits a document.
Related resources from NHI Mgmt Group
- What are the signs that an access review process is failing in practice?
- What are the signs that PCI DSS 4.0 compliance is failing in DevOps environments?
- What are the signs that procurement compliance controls are failing in a sourcing process?
- What are the signs that a fintech organisation is struggling to balance speed and compliance?