When an exchange, a bank or a broker asks you an uncomfortable question, the request almost never comes from a lawyer. It comes from a compliance department, and knowing what that department is, what it is obliged to do and what it cannot do for you changes how you should respond.
The legal department advises the firm on what the law is. The compliance function is responsible for the firm actually following it, day to day, and for proving to a regulator that it did. Different jobs, different incentives, often different reporting lines.
What a financial intermediary is
A financial intermediary sits between you and something you want to do with money: an exchange, a bank, a broker, a payment provider, a custodian. Because it stands in that position, most legal systems make it carry obligations that do not apply to you as an individual. The intermediary is the point at which the state can impose record-keeping, identification and reporting duties without regulating every private person.
Two consequences follow, and they explain most of what feels arbitrary about dealing with these firms:
- The obligations are the firm's, not yours. When it asks you for documents, it is discharging its own duty, not enforcing one of yours.
- Failure is expensive for the firm. Supervisory penalties, licence conditions and personal liability for named officers are all possible outcomes. That asymmetry is why a firm will close an account rather than take a risk on it.
The compliance function
Compliance is the internal function responsible for making sure the firm follows the rules that apply to it, and for producing evidence that it did. Its typical work:
Onboarding and identification
Deciding whether a prospective client can be accepted at all, and on what conditions. This is where identity checks, document collection and initial risk classification happen.
Ongoing monitoring
Watching activity against the profile the client gave at onboarding. The trigger for most uncomfortable questions is not size but inconsistency: activity that does not match what the firm was told to expect.
Investigation and escalation
Reviewing alerts, requesting explanations and documents, and deciding whether to clear, restrict or report. This is the stage at which most people meet compliance for the first time.
Reporting
Where the applicable rules require it, filing a report with the designated authority. In many systems the firm is prohibited from telling you that it has done so, which is why a frozen account is often accompanied by an unhelpful answer.
Governance and evidence
Writing the policies, training staff, testing whether the controls work, and keeping records. Much of the function exists to be auditable later.
KYC and AML are not the same thing
The two terms are used interchangeably in conversation, which obscures a useful distinction.
AML: the objective
Anti-money laundering is the whole regime whose purpose is to prevent the financial system being used to disguise the proceeds of crime, and in most systems to counter terrorist financing alongside it.
It is the body of law, supervision and obligation. AML is the why.
KYC: one of its methods
Know your customer is the set of processes for establishing who a client is and what they are likely to do: identification, verification, understanding the purpose of the relationship, and keeping that picture current.
KYC is a component of an AML programme, not a synonym for it. KYC is part of the how.
An AML programme normally contains a good deal more than KYC: transaction monitoring, sanctions screening, risk assessment, record retention, staff training, an independent testing function and internal reporting lines. You often see the wider activity called customer due diligence, of which identification is only the first step.
If you think the only obligation is KYC, you expect the questions to stop once your passport is verified. They do not, because identification is the beginning of the process rather than the end of it. Monitoring runs for the life of the relationship, and the question that arrives three years later is a different obligation being discharged, not a failure of the first one.
Compliance is not the legal department
This is the distinction that most changes how you should read a message from a financial institution.
| Legal department | Compliance function | |
|---|---|---|
| Core question | What does the law permit or require? | Are we in fact doing it, and can we show that? |
| Output | Advice, opinions, contracts, litigation strategy | Policies, controls, monitoring, reports, records |
| Orientation | Often advisory, and often after the fact | Operational and continuous |
| Client | The firm | The firm, with duties owed toward the supervisor |
| Typical reporting line | General counsel | A designated compliance officer, frequently with a direct line to the board |
| Privilege | Legal advice may attract professional privilege | Compliance records are generally created to be shown to a supervisor |
Compliance records are frequently produced in order to be examined. What you write in an explanation to a compliance team is documentation, and it is likely to be read later by people who were not part of the conversation. That is a reason to be accurate, complete and unemotional, and a reason not to improvise.
Neither department is your adviser. The legal department acts for the firm. The compliance function answers to the firm and, in practice, to its supervisor. If your position is genuinely difficult, the person you need is your own lawyer.
Who supervises them
Firms of this kind normally sit under a supervisory authority, and the word regulator covers several different kinds of body: a government department, an independent statutory authority, a central bank, or in some sectors a self-regulatory organisation that a statute recognises. Which one applies to a given firm depends on its licence and its country, and it is worth establishing rather than assuming.
Two things follow. The firm is answerable to somebody, which means there is usually a complaints route beyond the firm itself. And the supervisor's expectations, not only the statute, shape how conservatively a compliance team behaves.
How to deal with them well
- Answer the question asked. Volunteering unrelated information enlarges the file and can create new questions.
- Prefer documents to narrative. A compliance officer needs something to put in a record. An explanation with no evidence behind it is difficult for them to close.
- Be consistent. Contradicting something you said at onboarding is a bigger problem than the original fact usually was.
- Do not treat silence as hostility. A firm may be prohibited from explaining. Escalating angrily against a person who is not allowed to answer achieves nothing.
- Keep your own records. If you ever need to show how your holdings were acquired, the work is far easier done in advance. See source of funds.
If an account has already been restricted, the sequence of what to do, and what makes it worse, is set out in exchange froze your account. For what these firms collect and hold about you, see what exchanges collect at KYC.
General information, not legal advice. This site does not provide legal advice and no professional or advisory relationship is created. How compliance functions are structured, what they are obliged to do, which authority supervises them and what they may tell you all differ between countries and between firms, and change over time. This page describes a common shape, not the rule in your jurisdiction. If your account or your funds are at stake, take advice from a lawyer licensed where you live.