Skip to content
Bankautomation

KYC software for banks: AML KYC software and KYC automation for the refresh queue

KYC software for banks runs customer due diligence as a workflow: it works out who is due for review, requests and chases documents, routes each file by risk and keeps the evidence on the record. Onboarding gets the attention and the budget. Periodic refresh is where the backlog lives, because it is a queue that regenerates itself every year whether anyone staffed it or not.

Run the demo

camt.053 · NOSTRO USD · value date 03 sep 2026

Nostro cash break, sample data

Match rate

75.0%

Breaks

4

At risk

$533.9k

Oldest

4d

Date ±1d
Amount

This console matches the first rows a side. It left out statement and ledger , so anything in them is not counted below. To run a full file, .

BRK-001

Aged 0d

$219,105.40

2026-09-03 · both sides

REF//FX/SPOT/7741 · INTERBANK FX DESK

Amount differs by 164.80 USD (0.075%)

Re-price the ledger leg on the correspondent rate source for the value date and post 164.80 USD to FX variance.

FX RATE SOURCE

→ Treasury Ops

BRK-002

Aged 4d

$187,650.00

2026-08-30 · ledger

PAY/90012/R · KESTREL LOGISTICS

Second ledger entry for 187,650.00 USD against REF//PAY/90012

Confirm the original entry REF//PAY/90012 cleared, then reverse this posting under maker-checker and note the reversal on the original item.

DUPLICATE POSTING

→ Finance

BRK-003

Aged 0d

$123,760.00

2026-09-03 · both sides

REF//TRF/554121 · HALCYON TRADING

Statement 61,880.00 vs ledger 123,760.00 (50% short)

Split the ledger posting and match the settled leg; leave the residual 61,880.00 USD open against the same reference.

PARTIAL SETTLEMENT

→ Payments Ops

BRK-004

Aged 0d

$3,410.00

2026-09-03 · statement

REF//CHG/Q3FEES · CORRESPONDENT CHARGES

On the statement, nothing in the ledger

Post 3,410.00 USD to the charges account for the period and add it to the standing accrual so it stops surfacing as a break.

FEE NOT ACCRUED

→ Finance

Everything matched under these tolerances.

Tighten the date or amount tolerance to see the breaks it was absorbing.

Correspondent statement

camt.053 · NOSTRO USD

Value date Reference Amount
2026-09-02 REF//NONREF/2026090301 1,284,500.00
2026-09-02 REF//INV/88231 96,400.00
2026-09-03 REF//TRF/554120 452,180.25
2026-09-03 REF//FX/SPOT/7741 218,940.60
2026-09-01 REF//SEPA/33421 74,220.00
2026-09-03 REF//CHG/Q3FEES 3,410.00
2026-09-03 REF//TRF/554121 61,880.00
2026-09-02 REF//PAY/90012 187,650.00
2026-09-02 REF//INV/88245 242,015.00
2026-09-03 REF//TRF/554133 18,905.50
2026-09-01 REF//PAY/90044 505,300.00
2026-09-03 REF//INV/88260 132,640.75

Internal nostro ledger

Core banking export

Value date Reference Amount
2026-09-02 NONREF/2026090301 1,284,500.00
2026-09-02 INV/88231 96,400.00
2026-09-03 TRF/554120 452,180.25
2026-09-03 FX/SPOT/7741 219,105.40
2026-08-31 SEPA/33421 74,220.00
2026-09-02 PAY/90012 187,650.00
2026-09-03 TRF/554121 123,760.00
2026-08-30 PAY/90012/R 187,650.00
2026-09-02 INV/88245 242,015.00
2026-09-03 TRF/554133 18,905.50
2026-09-01 PAY/90044 505,300.00
2026-09-03 INV/88260 132,640.75
Matched pairs are tinted on both sides. Breaks carry the brass left rule and appear in the worklist.

Sample data only. Matching runs in your browser; classification is written by the model when you press Run. Matching done in your browser. Writing classifications… Classifications written by the model on this run. Decision support, not a compliance determination. The classification model was unavailable, so the built-in rule classifier wrote these. Same matching, same numbers. This console classifies up to 12 runs a minute and this run went over, so the built-in rule classifier wrote these. Same matching, same numbers. Wait a minute for the model, or . The model wrote the first 8 classifications; the rule classifier wrote the remaining .

Open the full resolver

Refresh is an operations problem wearing a compliance badge

The population is calculable: customers whose risk rating and last review date make them due. The work is repetitive: request documents, chase, verify, escalate anything that does not fit. The failure mode is boring: it slips, and slippage is only visible once the overdue count is large enough to be a finding.

Treated as a workflow with owners, ages and escalation, refresh stops being an annual panic. Treated as a spreadsheet, it always becomes one.

What the workflow does

  1. 01Builds the due population from risk rating, entity type and last review date, on a schedule.
  2. 02Assigns by risk and workload, with a queue per team and a visible age per case.
  3. 03Requests and tracks the standard document set for the entity type, and chases on a cadence you configure.
  4. 04Escalates anything unusual to a reviewer rather than letting it sit in an analyst queue.
  5. 05Records the completed review with its evidence, its approver and the policy version in force.

Entity complexity is where tooling earns its keep

Case typeWhat makes it slowWhat automation removes
Individual, low risk Volume Document chasing and manual queue building
SME with a simple structure Document collection Requests, reminders and completeness checks
Corporate with layered ownership Ownership tracing Nothing about the judgement, everything about the tracking
Trust or partnership Non standard documents Standardized evidence checklists per type
Politically exposed relationship Enhanced review and approval chain Routing, escalation and approval enforcement

Swipe the table sideways to read every column.

The line we will not cross

Automation prepares, requests, routes, tracks and evidences. It does not decide whether a customer relationship is acceptable, and it does not clear a review. A person makes that call, an approver confirms it, and both are recorded.

Building the due population, which is the whole game

Everything else in refresh depends on whether the due population can be calculated rather than estimated. It is a function of three inputs: the risk rating, the date of the last completed review, and any event that triggers an off cycle review. If those three can be queried together, the overdue number is a fact that updates itself. If any one of them lives in a spreadsheet, the number is an estimate, and an estimate is what an examiner will test first.

InputUsually lives inWhat goes wrong
Risk rating Customer or CRM system Rating changes without moving the review date
Last review date Case system, sometimes a spreadsheet Recorded when the file closed rather than when it was approved
Event triggers Monitoring output, relationship notes, email Never reaches the refresh queue at all
Cadence rules The policy document Not expressed anywhere a system can read

Swipe the table sideways to read every column.

The refresh backlog, and how it forms without anyone deciding

Periodic refresh backlogs are rarely created by a decision. They form because the population that becomes due each month is calculated from risk ratings and onboarding dates that were set years apart, so the due volume arrives unevenly while the team size does not change. A quiet quarter is followed by one where three times the normal volume falls due, and the overflow becomes a backlog that never fully clears because the next uneven quarter arrives before it does.

Making the due population visible several months ahead turns that from a recurring surprise into a capacity plan. The same view also shows which segments are generating the volume, which is usually where the outreach process, rather than the analysis, is the constraint. A refresh that is waiting on a customer to return a document is not the same item as one waiting on an analyst, and counting them together produces a backlog number that cannot be acted on.

The fourth row is the one most often overlooked. A cadence that exists only in prose has to be applied by a person, and people apply prose inconsistently. Expressed as configuration, the cadence applies itself and a change to the policy changes the population the same day.

Chasing, which is most of the elapsed time

A refresh case is rarely slow because the review is hard. It is slow because a document was requested, nothing came back, and three weeks passed before anybody noticed. The elapsed time in most refresh operations is dominated by waiting, and waiting is the easiest thing in the whole program to automate without touching a decision.

  1. 01Request the document set derived from the customer type and jurisdiction, rather than assembled by hand.
  2. 02Chase on a schedule, with escalation to the relationship owner after a defined number of attempts.
  3. 03Track the request as an item with an age, so a stalled case is visible without a person reviewing the list.
  4. 04Check completeness and expiry automatically, so a file does not reach an analyst missing a document or carrying an expired one.
  5. 05Record every request, every chase and every receipt, because that record is what proves the effort was made when a relationship has to be exited.

The exit conversation nobody plans for

Some refresh cases end with a customer who will not or cannot provide what is required. Exiting a relationship is a serious step and it is frequently delayed, not because the decision is unclear but because the evidence of reasonable effort has to be assembled before anybody is comfortable taking it. When every request, chase and escalation is already an item with a timestamp and an actor, that evidence exists the moment it is needed, and the decision gets made on its merits instead of on how much work the paperwork would be.

Measuring the queue honestly

  • Overdue population, by risk rating, reported as a count and as a proportion of the due population.
  • Age of the oldest overdue case, which is the number that embarrasses a program fastest.
  • Elapsed time split into waiting on the customer and waiting on the bank, because these have different owners.
  • Cases reopened after completion, which usually indicates a completeness check that is not being applied.
  • Proportion of cases triggered by an event rather than by the calendar, which shows whether triggers work at all.

For the program level view around this queue, see AML compliance software, and for the alert side of the same operation, BSA AML monitoring software.

Questions about kyc software for banks

Do you perform identity verification or screening?

No. Screening and verification stay with the providers you already use. This orchestrates the work around them: what was requested, what came back, what is missing, who reviewed it and who approved.

Can refresh cycles differ by risk rating?

Yes, cycles and evidence requirements are configured per risk rating and entity type, and changes to them are versioned and approved like any other rule.

How does this connect to our customer system?

By scheduled export or API from the system of record, the same file-first approach used everywhere else in the product. The customer master stays where it is.

What does the evidence pack contain?

The review, the documents collected, the checks recorded, the rationale, the approver, the timestamps and the policy version in force at the time. Exportable per customer or per population and period.

More banking automation pages

Every process line we cover, in one place.

Account reconciliation software Where the differences start, account by account. Bank reconciliation software Statement against ledger, MT940 and camt.053 native. Automated reconciliation software Match rates, tolerances, and what auto-match must never mean. Payment reconciliation software Instructed, settled and posted, reconciled three ways. Financial reconciliation software The same engine, framed for the finance team. ATM reconciliation software Cash, switch and network settlement, balanced daily. Credit union reconciliation software Corporate, share draft, card, ATM and shared branching. ACH reconciliation software Origination, receipt, returns and FedACH settlement. Federal Reserve account reconciliation Master account, FIRD, Fedwire and FedNow against the GL. Correspondent bank reconciliation Due from, due to and respondent settlement against the GL. AML compliance software Program workflow, evidence and cadence. Not a detection model. AML software for banks What to ask, and what to refuse to buy. Compliance workflow automation Maker-checker, SLAs and evidence as a system property. BSA AML monitoring software Alert triage as a worklist, not a second inbox. RPA for banks Why screen-scraping bots break, and what replaces them. General ledger reconciliation software Sub-ledger to GL, and the suspense account nobody owns. Balance sheet reconciliation software Certification, sign-off and the quarter-end pack. ISO 20022 payment automation Structured data, repair rates and CBPR+ deadlines. Nostro reconciliation automation The most bank-specific reconciliation there is.

Get started

Put your first reconciliation on rails

Create an account, and we will email you how onboarding works and what a first source connection looks like. The Reconciliation Break Resolver is open to try right now, on sample data, without an account.

Run the demo

No card required to create an account. Sample data only in the demo. Bankautomation is operations software, not a regulated service.