Private Banking Compliance: A Client-Lifecycle Control Map

Private banking compliance is not one onboarding check. It is a lifecycle of identity, ownership, source-of-wealth, suitability, transaction, communication and review controls that must remain connected as the client relationship changes.

This guide provides a seven-stage control map for professionals evaluating private-bank operations. Requirements differ by jurisdiction, client type, product and institution; use the map as operational guidance, not legal advice.

The PRIVATE-7 lifecycle

Stage Core question Evidence example Decision owner
P — Prospect and purpose Why is the relationship and service requested? relationship rationale, expected activity relationship/compliance owner
R — Relevant identity and ownership Who is the client and who ultimately owns or controls assets/entities? verified identity, beneficial ownership map onboarding control owner
I — Income and wealth evidence Is source of wealth/funds understood proportionately to risk? dated source inventory, corroboration, gaps compliance decision owner
V — Vulnerability and risk Which geography, product, PEP, sanctions, tax or conduct factors change review depth? documented risk assessment authorized risk owner
A — Advice and activity Is the service/recommendation within mandate and supported by current client information? mandate, product evidence, approvals adviser/supervisor
T — Transaction and behavior monitoring Does actual activity fit the expected profile, and are alerts resolved? alert rationale, investigation, escalation monitoring owner
E — Event-driven and periodic review Which events trigger refresh, restriction or exit? review log, changed ownership, new jurisdiction relationship and compliance governance

Separate four records

A common failure is combining different judgments into one risk rating. Maintain connected but distinct records:

  1. Client identity record: verified person/entity and ownership.
  2. Financial-background record: source-of-funds and source-of-wealth evidence.
  3. Service and suitability record: mandate, knowledge, objectives, constraints and product decision.
  4. Monitoring record: expected activity, alerts, investigations, decisions and review triggers.

The records can share identifiers, but each has a different purpose, evidence standard and owner.

A worked control walkthrough

Consider a new client using a holding company to invest proceeds from a business sale.

  • Prospect: document the requested service and expected transaction pattern.
  • Identity: verify the individual, company and beneficial ownership chain.
  • Wealth: obtain proportionate evidence of the sale and flow of funds.
  • Risk: assess jurisdictions, intermediaries, public-office exposure, sanctions and product complexity.
  • Advice/activity: confirm mandate and relevant client information before any recommendation or execution.
  • Monitoring: compare incoming funds and later transfers with the expected profile.
  • Review: trigger refresh if ownership, residence, control, transaction behavior or service scope changes.

Do not treat a completed onboarding file as permanent truth. The lifecycle must include change detection.

Decision rules for escalation

Escalate when:

  • identity or beneficial ownership cannot be resolved;
  • source evidence is inconsistent with known facts or expected activity;
  • a sanctions, PEP or adverse-information issue requires specialist review;
  • requested products or transactions sit outside the documented mandate;
  • monitoring alerts repeat without a durable explanation;
  • the relationship owner and control function disagree on material risk;
  • a mandatory-reporting or restriction threshold may apply.

Do not include the client in a confidential internal escalation unless authorized. Do not “tip off” or disclose protected reporting activity where law prohibits it.

Supervisory evidence

For every material decision, retain:

  • the requirement or internal policy basis;
  • evidence reviewed and its date;
  • unresolved uncertainty;
  • decision, conditions and authority;
  • review or expiry trigger;
  • link to any alert, exception or remediation action.

FINRA Rule 2090 requires member firms to use reasonable diligence to know essential facts about every customer and the authority of persons acting for them. The exact application depends on the regulated activity and relationship. The FFIEC BSA/AML Manual provides US banking examination guidance on customer due diligence, risk assessment and related controls. The OCC’s Private Wealth Management booklet addresses risk management in private wealth activities.

A monthly control review

  • Sample new relationships across risk levels and client structures.
  • Test beneficial ownership and source evidence against policy.
  • Review overrides, ageing alerts and recurring exceptions.
  • Compare actual activity with the expected profile.
  • Confirm that event triggers caused timely refresh.
  • Check supervisor decisions and segregation of duties.
  • Track remediation to evidence-based closure.

Practical next step

Use PRIVATE-7 to map one current client journey from prospect to review. Mark every stage with its system of record, control owner, decision threshold and escalation route. Any blank cell is a governance question—not automatically a control failure, but something that requires a documented answer.

Readers who need a deeper distinction between baseline and enhanced due diligence can use MTF Institute’s guide CDD and EDD: What Changes When Risk Increases.

References

Continue learning

Practise this capability in MTF Institute's Advanced Professional Certificate in Enterprise Risk Management (ERM) & Business Continuity through structured lessons and applied work.