KYC Remediation After an Acquisition
A practical playbook for assessing inherited KYC files, prioritising gaps and moving an acquired client book onto one defensible AML standard
KYC Remediation After an Acquisition
How to Regularise an Inherited Client Book
KYC remediation after an acquisition begins with an uncomfortable fact: the client book may have transferred on day one, but confidence in its AML records did not.
The acquired firm may have used different risk categories, accepted different identity evidence, stored approvals in email, or relied on a system that cannot export the reasoning behind a decision. Some files will be complete. Others will look complete until someone asks when the evidence was verified, who approved an exception or whether an ownership change was ever reviewed.
Treating the whole book as a generic backlog misses the point. This is a control integration exercise. The acquiring firm needs to establish what it inherited, measure every active relationship against its current standard, and create a defensible route from the old process to the new one.
Why an acquired client book is a distinct AML problem
Ordinary remediation usually starts with a known defect: expired documents, incomplete source-of-wealth evidence, missing beneficial owners or overdue reviews. An acquisition adds a second problem. The acquiring team may not know whether the previous process was followed consistently enough for the records to be trusted.
The questions become:
Were the required checks actually completed?
Is the evidence available and readable?
Can the firm reconstruct why the customer was accepted?
Were exceptions approved by the right person?
Does the previous risk methodology align with the acquiring firm’s current policy?
Can the firm identify changes that occurred after onboarding?
That last question is often overlooked. A file can have been correct when it was created and still be inadequate now because ownership, control, address, business activity or sanctions exposure has changed.
Do all acquired customers need to be reverified?
Not necessarily, but the answer depends on the applicable jurisdiction, the records received and the quality of the previous checks.
In the UK, the Joint Money Laundering Steering Group’s current guidance includes specific treatment for the acquisition of a financial services firm or customer portfolio. Its approved Part I guidance says wholesale re-verification may not be necessary where underlying customer records are acquired, or appropriate warranties exist, but it also calls for due-diligence enquiries and sample testing. Where procedures were inadequate, cannot be checked, or records are inaccessible, verification should be completed as soon as practicable using a risk-based approach. The current JMLSG guidance and subsequent revisions should be checked at the point of use.
This is not permission to accept the acquired book at face value. It is a reason to build a proportionate evidence-based plan before contacting every customer.
The FCA’s 2026 review of customer due-diligence processes and controls reinforces the broader standard: stronger firms documented each stage of enhanced due diligence and maintained clear senior-management oversight, while weaker practices included failures to gather or record the purpose and intended nature of the relationship.
Start with evidence preservation, not customer outreach
The first risk in acquired-book remediation is losing context during the transfer.
Before changing systems, preserve:
The original documents and their metadata.
Verification dates and methods.
Risk assessments and the version of the methodology used.
Screening results, disposition notes and reviewer identity.
Approval records and exceptions.
Periodic-review dates and open actions.
Customer communications relevant to outstanding evidence.
Data showing which services, funds or entities the customer is connected to.
A folder containing PDFs is not a complete migration. Without the decision trail, the acquiring firm receives evidence without knowing how it was assessed.
The migration team should also document fields that cannot be mapped cleanly. If the previous system had three risk levels and the new policy has five, silently translating “medium” into a new category creates false precision. Record the mismatch and rerun the risk assessment under the current methodology.
Build the acquired-book gap map
The next step is to assess the whole population against one target standard.
Start by defining the standard for each customer and entity type. A natural person, an operating company, a trust and an SPV should not share an identical checklist. Requirements should reflect jurisdiction, product, ownership complexity and risk.
Then create a structured inventory for every active relationship:
Which required documents are present?
Which are missing, expired or unreadable?
Has identity and beneficial ownership been verified?
Is the purpose of the relationship recorded?
Is source of funds or source of wealth required and evidenced?
Is current screening complete?
Does the risk rating follow the acquiring firm’s methodology?
Is the next review date known?
Can every conclusion be traced to evidence and an approver?
This is the specific version of the wider checklist discussed in another article: KYC remediation problem that firms rarely budget for. The output should not be a loose list of defective files. It should be a gap map segmented by defect type, customer risk and operational dependency.
Choose between a bulk exercise and phased remediation
There are two broad migration strategies.
A bulk exercise reviews and refreshes the entire active book within a defined programme. It is appropriate when the inherited records are materially unreliable, the systems cannot support ongoing use, or a regulatory commitment requires a firm deadline.
Phased remediation moves customers onto the new standard by risk, trigger event or scheduled review. It is appropriate when the inherited controls can be validated, the highest-risk cases are identifiable, and immediate wholesale outreach would create more disruption than risk reduction.
The decision should be made by cohort, not for the book as a whole. A practical sequence is:
High-risk customers and PEP-linked relationships.
Files with inaccessible or unverified records.
Complex entities with unresolved ownership.
Customers approaching a review or document expiry.
Customers creating a new account, fund interest or service relationship.
Lower-risk records with complete, validated evidence.
This prevents the easiest files from consuming the programme while the riskiest remain unresolved.
Design outreach around the customer, not the file
Acquired-book programmes often generate several requests to the same person because that person appears across related companies or products. The client sees repeated questions; the project team sees separate cases.
Before outreach, resolve duplicate identities and group related requests. Tell the customer what has transferred, what needs updating and why. Pre-fill known information, ask for confirmation where appropriate, and request only the evidence needed to close the identified gaps.
The difference between a good remediation campaign and an indiscriminate re-papering exercise is preparation. Customers should not have to reconstruct the acquiring firm’s data model for it.
Migrate the decision trail, not just the documents
A remediated file should show:
The inherited evidence.
The defects found.
The new checks completed.
Any customer response.
The resulting risk assessment.
The reviewer and approver.
The date the file entered the new standard.
The monitoring and review rules that apply next.
AI can accelerate the first pass by classifying documents, extracting fields, identifying missing evidence and comparing files with the target standard. It can also prepare screening rationales and draft case summaries. Human oversight remains essential for exceptions, higher-risk conclusions and final acceptance decisions.
The useful question is not how quickly software can mark files complete. It is how quickly the firm can produce a population-wide view, direct attention to genuine exceptions and leave every conclusion traceable. That is the operating model behind AI-led KYC remediation.
Stop the inherited backlog from returning
The programme is not complete when the final old file is closed. It is complete when every migrated relationship has an owner, a review rule and an event-monitoring path.
Ownership changes, document expiries, new screening information and changes in expected activity should create review tasks before the record becomes stale. The acquired book must enter the same operating rhythm as new customers, or the firm will recreate the backlog under its own name.
This is also the right moment to retire duplicate tools and spreadsheets and move every record into a controlled KYC periodic review process. Running the acquired and acquiring processes in parallel for too long preserves the inconsistency the programme was meant to remove.
Where Steward fits
Steward supports end-to-end onboarding, document review, screening, ongoing monitoring and periodic review for investment services. For an acquired book, the practical value is a structured first pass across the population, a clear exception queue and an audit trail that connects inherited evidence to the new decision.
Using Steward, AI does the heavy lifting: migration and gap analysis; your analyst just has to review. Book a demo to see it in action.
Related Insights

The AML AI Readiness Gap in North America
North American firms allocate funds to AI for AML, yet 54% use 8-10 fragmented systems. Why AI adoption isn't the same as operational readiness.

AML Red Flags for Payroll and Annex 1 Firm
Identify AML red flags in payroll and Annex 1 firms: understand sector-specific risks, connect anomalies to customer context, and build effective controls.

How to Set Up AML Controls for a UK Business
A practical operating model for building AML controls that work across payroll and Annex 1 businesses