How to Handle a Customer Who Presents Inconsistent KYC Information Across Multiple Interactions

Pathik Shah Pathik Shah 9 min read AML Insights
Article Summary

  • Customer-provided information that is inconsistent across different interactions, products, or time periods is one of the most important and most underused risk signals in the CDD process. It is not the inconsistency itself that is the risk indicator, but the question of why it exists and whether the explanation is credible.
  • The compliance framework requires the institution to have a current and accurate picture of the customer. Where information is inconsistent with what was previously provided, or across different products or contact points, the institution no longer has that picture, and the CDD must be refreshed until it does.
  • The five categories of inconsistency that present the highest compliance risk are: identity information (name, date of birth, address, nationality); source of wealth declarations; declared occupation or employment; declared purpose of the account or relationship; and declared activity versus actual transaction patterns.
  • The compliance officer must conduct an investigation that distinguishes innocent explanations (legitimate life changes, customer error, data entry mistakes) from potentially suspicious ones (deliberate misrepresentation, identity fraud, concealment). This requires specific analytical skills and a structured approach.
  • Documentation is critical: the institution must be able to demonstrate, in any subsequent review, that it identified the inconsistency, investigated it, reached a documented conclusion about its explanation, and updated the CDD accordingly.

AML Expert
Talk to an expert

AML Expert

Get tailored guidance on your compliance obligations, SAR filing, or AML program review.

Reach Out Now

Authored by

Pathik Shah

Founder, NIYEAHMA Consultants LLP

CAMS | FCA | CISA | CS | DISA (ICAI) | FAFP (ICAI)

28 years in AML/CFT advisory across UAE, UK, Singapore, India, Hong Kong, Australia and the GCC

Expert Panel

Dipali Vora — AML/CFT Practitioner | Associate Member, ICSI

Jyoti Maheshwari — AML/CFT Practitioner | Published in ACAMS Today & AMLverse

Why KYC Information Inconsistency Is a Risk Signal

The CDD process generates a substantial volume of customer-provided information across the life of the customer relationship. Onboarding documentation, periodic review updates, product application forms, customer service interactions, and contact centre records all contain KYC information about the customer. The customer who maintains a consistent and coherent account of themselves across all of these interactions provides the institution with a reliable picture of their risk profile. The customer whose account of themselves varies is signalling, intentionally or not, that the picture is incomplete or inaccurate.

The compliance significance of inconsistency varies significantly depending on what is inconsistent. Inconsistency in address over time reflects the fact that people move, which is entirely normal. Inconsistency in declared occupation over time may reflect career changes, which is normal, or may reflect deliberate concealment of an occupation that the customer knows would attract compliance scrutiny. Inconsistency in source of wealth across different product applications is harder to explain innocently, because the source of wealth does not typically change materially between product applications filed at the same time.

The compliance officer who discovers a material inconsistency in a customer file and does nothing because they cannot prove the inconsistency is suspicious has misunderstood the standard. The obligation is to investigate the inconsistency. The outcome of the investigation determines what happens next. Not investigating is not a neutral act. It is a decision to leave an unresolved risk indicator in the customer file, which is itself a compliance failure.

Dipali Vora | AML/CFT Practitioner | Associate Member, ICSI

The Five High-Risk KYC Information Inconsistency Categories

1. Identity Information Inconsistency

Inconsistency in core identity information, including name variations that go beyond common spelling alternatives, date of birth differences that cannot be attributed to data entry errors, and nationality that changes between applications, is a serious risk indicator that may indicate identity fraud, use of multiple identities, or deliberate concealment.

The investigation of identity inconsistency should include re-verification of the identity documents, comparison of the inconsistent elements against all available records, and an assessment of whether the inconsistency can be attributed to an innocent explanation such as a formal name change or data entry error.

2. Source of Wealth Inconsistency

Inconsistency in source of wealth declarations across different products, different time periods, or different contact points is a specific red flag that warrants prompt investigation. The customer who declares business income as their source of wealth on a current account application and inheritance on a savings application filed in the same period cannot have two different sources of wealth simultaneously. The investigation should specifically ask the customer to explain the inconsistency and should assess whether the explanation is credible and can be corroborated.

3. Occupation and Employment Inconsistency

Occupation inconsistency that goes beyond the normal career changes of a working life is a risk indicator, particularly where the inconsistency involves a shift between an occupation that would attract compliance scrutiny, such as a government official or a politically exposed person, and one that would not. The investigation should assess whether the change is consistent with the customer's life circumstances, whether it can be corroborated, and whether it coincides with any change in the customer's transaction patterns or risk profile.

4. Account Purpose Inconsistency

Where the declared purpose of an account or relationship changes materially between the onboarding declaration and the periodic review, or between what the customer says in a customer service interaction and what the transaction pattern shows, this is a risk indicator that may indicate that the declared purpose was not the actual purpose at onboarding. The investigation should assess whether the changed purpose has a credible explanation and whether the account history is consistent with either the original or the revised purpose.

5. Declared Activity Versus Actual Transaction Pattern

The most operationally visible form of inconsistency is the mismatch between what the customer said they would use the account for and what they have actually used it for. The customer who declared they were a domestic retail business and whose account shows regular international transfers to high-risk jurisdictions is presenting a significant inconsistency that requires investigation. This form of inconsistency is addressed through transaction monitoring that compares actual patterns against the expected patterns established in the customer profile, and should generate alerts when the divergence is material.

The customer who presents inconsistent KYC information across multiple interactions is not automatically a financial criminal. They may be confused, they may have made an error, their circumstances may have changed, or the institution may have recorded their information incorrectly. The job of the compliance officer investigating the inconsistency is not to assume the worst interpretation but to investigate the inconsistency thoroughly enough to determine what the true explanation is. Sometimes the answer is innocent. When it is, document the investigation and the explanation. When it is not, you have your risk indicator.

Pathik Shah | Founder, NIYEAHMA Consultants LLP

The Investigation Process

The investigation of a customer information inconsistency should follow a structured approach. Identify the specific inconsistency precisely; assess whether the inconsistency has an obvious innocent explanation before escalating; if not, gather all available information about the customer from all touchpoints in the institution; consider whether the customer can be asked to explain the inconsistency and whether that would be appropriate in the circumstances; assess the credibility of any explanation provided; and reach a documented conclusion about the significance of the inconsistency for the customer risk profile.

The decision about whether to ask the customer to explain an inconsistency requires judgment. Where the inconsistency is minor and has an obvious innocent explanation, raising it with the customer may be unnecessary and may cause undue alarm.

Where the inconsistency is material and cannot be explained without customer input, a customer communication that asks for clarification without revealing the specific compliance concern behind the request is the appropriate approach. Where the inconsistency is serious enough that customer contact would risk tipping off the customer to an STR investigation, the investigation should proceed without customer contact and the STR assessment should be based on the available information.

The investigation of customer information inconsistency is one of the most intellectually demanding compliance tasks, because it requires the compliance officer to assess the probability of innocent versus suspicious explanations for information gaps without the benefit of certainty. The standard is not certainty. It is whether the evidence, taken as a whole, raises a suspicion that is not adequately explained by the information available. That is a judgment standard that requires experience and confidence in making judgment calls under uncertainty.

Jyoti Maheshwari | AML/CFT Practitioner | Published in ACAMS Today and AMLverse
Practitioner Checklist: Handling Customer Information Inconsistency
  • Implement a process for identifying customer information inconsistencies across all touchpoints, including onboarding documentation, periodic reviews, product applications, and customer service interactions.
  • Classify identified inconsistencies by category and severity, with escalation procedures for the five high-risk inconsistency categories.
  • Investigate all material inconsistencies using the structured approach: identify specifically, assess for innocent explanation, gather all available information, consider customer contact, assess explanation credibility.
  • Document the investigation, the explanation considered, the conclusion reached, and the update to the customer risk profile.
  • Update the customer CDD to reflect the outcome of the inconsistency investigation, including any changes to the risk classification or monitoring level.
  • Apply the tipping-off assessment before contacting the customer about an inconsistency, and proceed without customer contact where the tipping-off risk is present.
  • File an STR where the investigation cannot resolve a material inconsistency to a comfortable conclusion and the residual suspicion meets the threshold.

Frequently Asked Questions

Everything you need to know about handling customer information inconsistency and how AML Guild supports your business.

There is no universal de minimis threshold, but proportionality applies. The compliance officer should apply judgment about whether an inconsistency is sufficiently material to warrant investigation. A middle initial present in one record and absent in another is not typically material. A date of birth that differs by one digit between two records is likely a data entry error that should be corrected without a full investigation. A source of wealth declaration that differs materially between two product applications in the same period is material and warrants investigation. The threshold for investigation should be proportionate to the risk significance of the inconsistency, with all five high-risk categories warranting investigation regardless of their surface-level magnitude.

Where the customer offers an explanation that cannot be independently corroborated, the compliance officer must assess the plausibility of the explanation in the context of everything else known about the customer. A plausible explanation that is consistent with the customer profile and transaction history may be accepted as the basis for a documented risk assessment, with the explanation and its limits noted. An explanation that is implausible, that is inconsistent with the customer profile, or that is of the type that should be corroborable but has not been provided in corroborated form, should be treated as unresolved and may itself be an additional risk indicator.

Work with this expert
Pathik Shah
Pathik Shah Founder, NIYEAHMA Consultants LLP

Work With Pathik Shah on CDD and Inconsistency Investigation

Whether you are building the inconsistency identification and investigation process for your CDD programme, reviewing a specific customer file that presents material inconsistencies, training the compliance team on the analytical skills required for inconsistency investigation, or assessing whether a pattern of inconsistency in a customer portfolio warrants a systematic review, Pathik Shah and the AML Guild network provide the CDD expertise that complex customer situations require.