Join our Newsletter — 33% off our NHI Course

What do banks get wrong about KYC, data governance, and compliance oversight?

A common mistake is treating KYC, privacy, and compliance as periodic paperwork instead of continuous operational controls. When customer identity checks, data handling rules, and management oversight are weakly connected, gaps appear in onboarding, monitoring, and escalation. Banks need documented processes, evidence of enforcement, and executive accountability so compliance is embedded in day-to-day operations.

Why banks misread KYC as a filing exercise instead of a control environment

The core error is using KYC as a one-time onboarding gate rather than a living identity and risk control. That turns customer due diligence into a document check, when the real job is to keep customer records, risk signals, and escalation paths current as behaviour, ownership, and transaction patterns change.

A bank that only tests KYC at account opening will miss the operational link between identity proofing, beneficial ownership, sanctions screening, and ongoing monitoring. The control has to work after onboarding, because the exposure usually appears later, when stale records are no longer good enough to explain who the customer really is or what has changed.

That is why banks increasingly need to treat identity verification as part of a broader evidence chain. NHIMG’s Identity Proofing and KYC Guide is useful here because it connects onboarding checks to the practical failure modes that appear when proofing, fraud detection, and customer due diligence are not joined up.

What data governance gets wrong when compliance teams own the policy but not the data

Data governance fails when the organisation writes handling rules but does not operationalise them in the systems that create, move, store, and report customer data. In banks, that usually means poor classification, inconsistent retention, weak lineage, and unclear access boundaries between compliance, operations, and technology teams.

The practical problem is not simply whether the rule exists, but whether the bank can demonstrate that the rule is enforced. If records can be copied into shadow repositories, exceptions are not logged, or personal data is reused beyond its stated purpose, then privacy and governance become paper controls that cannot withstand audit or incident review.

Good governance also depends on clear regulatory anchors for what must be collected, kept, protected, and evidenced. The NIST Privacy Framework is a strong reference point for linking classification, handling, and accountability, while EU General Data Protection Regulation (GDPR) illustrates why banks need purpose limitation, security of processing, and proof that governance controls are actually operating.

Why compliance oversight breaks down without executive accountability and evidence

Oversight breaks when compliance is treated as review work done by a narrow function rather than an operating model owned by management. Banks often have policies, committees, and dashboards, but still fail to connect them to named owners, measurable control outcomes, and escalation when the underlying process is weak.

The better test is whether management can show that exceptions are investigated, remediation is tracked, and control failures change behaviour. If the organisation cannot produce evidence of enforcement, then oversight is decorative: it records that controls exist, but not that anyone is accountable for keeping them effective.

That is why oversight needs to join policy, audit trail, and ongoing assurance. FATF Recommendations, the AML and KYC framework are relevant because they tie customer due diligence to ongoing risk management, and FinCEN shows how supervisory expectations focus on reporting, monitoring, and program effectiveness rather than box-ticking.

Risk and Threat Considerations

When KYC, data governance, and oversight are weakly connected, the main risk is cumulative control failure: the bank may look compliant at onboarding while remaining blind to stale identity records, incorrect customer risk ratings, and unreviewed data handling exceptions. That creates exposure to fraud, regulatory findings, and ineffective monitoring across the full customer lifecycle.

Failure mechanism: Separate teams maintain separate artefacts, so identity evidence, data rules, and oversight actions drift apart. The result is that exceptions are not escalated, remediation is not enforced, and the bank cannot prove that controls worked after the initial review.

Impact: Stale customer records, unreliable reporting, weaker suspicious activity detection, and higher audit and supervisory risk. At scale, the same weakness can affect entire portfolios, especially where onboarding, monitoring, and data retention are handled by different systems or vendors.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Banks need accountable access to KYC and oversight systems.
AU-6 — Audit Record Review, Analysis, and Reporting Oversight depends on reviewable evidence of control performance and exceptions.
Recommendation — Enforce authenticated access for staff handling KYC records and compliance actions. Review audit trails for KYC exceptions, remediation, and escalation outcomes.
ISO/IEC 27001:2022 A.5.15 — Access control Governance breaks when customer data access is not formally restricted and enforced.
Recommendation — Define and enforce access restrictions for customer and compliance data.
GDPR Article 5 — Principles relating to processing of personal data Data governance hinges on purpose limitation, minimisation, and accountability.
Recommendation — Align data handling rules to purpose limitation, minimisation, and accountability.
NIST CSF 2.0 GV.OV-01 — Oversight of cybersecurity risk management strategy The question is about management oversight of compliance controls.
ID.AM-01 — Physical devices and systems within the organization are inventoried KYC and data governance need an accurate inventory of systems holding regulated data.
Recommendation — Assign oversight for control effectiveness and exception follow-up. Inventory systems that create, store, and move KYC and customer data.

Practitioner Guidance

What to verify: Confirm that the bank can trace one customer record from onboarding evidence through ongoing review, risk rating changes, exception handling, and final disposition. If that trace breaks at any point, the control is not operating end to end.

What good looks like: Compliance should be measurable as an operating condition, not a policy library. The bank should be able to show named owners, enforced review cycles, logged exceptions, and evidence that escalations change customer risk treatment or data handling decisions.

Practitioner takeaway: The strongest banks do not “do KYC” and “do governance” as separate chores, they run them as one continuous control chain with evidence, accountability, and escalation built into daily operations.