Skip to content

Industry-specific operational data

KYC and CDD case review files for onboarding and periodic-review agents

Quick answer

KYC case review data for AI agents should be the full due diligence file, not just a final decision: the customer risk rating and its drivers, beneficial-ownership evidence for legal entities, screening hits with analyst dispositions, enhanced due diligence (EDD) memos, source-of-funds narratives, periodic-review outcomes and approver sign-offs. License it from a bank or CLM operator with SAR-linked content removed, personal details replaced, adverse-media article text excluded, and a written basis for reuse under Regulation P.

By SourceX Editorial · Updated

What a usable CDD case file contains

A usable case file captures both the evidence an analyst gathered and the reasoning that turned it into a risk rating and an approve, escalate or exit decision. Agents that only see outcomes learn to guess labels; agents that see the evidence trail learn to assemble a file and justify it. FinCEN's 2016 CDD rule requires covered institutions to identify and verify beneficial owners of legal entity customers (31 CFR 1010.230) and to maintain risk-based due diligence that includes a customer risk profile and ongoing monitoring, a requirement placed in the AML program rules [1]. That rule, plus each institution's own BSA/AML policy, is what shapes the file you are buying.

Ask suppliers which of these components exist per case, and at what fill rate:

  • Customer and product profile: entity type, NAICS or occupation code, jurisdictions, products opened, expected activity.
  • Risk rating: the score or tier from the risk model (often a factor-weighted matrix in Fenergo, Moody's, NICE Actimize CDD-X or an in-house CLM), plus the factor values and any analyst override with its reason.
  • Beneficial ownership: the certification form, ownership chart, 25% ownership and control-prong owners, and verification evidence references.
  • Screening: sanctions, PEP and adverse-media hits with match scores and the analyst disposition (true match, false positive, inconclusive) and rationale.
  • EDD memo and source of wealth/funds narrative: free text whose length varies widely by institution and case risk, with the questions asked of the relationship manager.
  • Periodic review (KYC refresh) record: trigger (scheduled, event-driven, risk change), what changed, and the outcome.
  • Approvals: maker-checker steps, QA findings and timestamps.

As of October 2026, a February 2026 FinCEN order granted exceptive relief that changes how one legal-entity CDD requirement applies [2]. Ask whether the supplier's files span the change, because case structure before and after may differ.

Individual KYC versus corporate KYB files

Individual KYC and corporate KYB files differ enough that you should specify one or label every case. Individual files center on identity verification, occupation, expected activity and PEP status; the reasoning is short and the documents are IDs and proofs of address. Corporate files center on ownership layering, control persons, nature of business, trade jurisdictions and source of wealth for the ultimate beneficial owners, and the EDD memo carries most of the reasoning.

Mixing them without a label teaches an agent to ask individual questions of a holding company. If your product also underwrites merchants, the decision logic overlaps but the risk lens is credit and chargeback exposure; see merchant onboarding and KYB underwriting decisions for that distinct dataset. Identity-document images belong in a separate document-processing purchase, not in this one.

What must be removed before any KYC file leaves the bank

Anything that reveals whether a suspicious activity report was filed must be stripped before delivery, along with direct identifiers. Under 31 CFR 1020.320(e), a SAR and any information that would reveal its existence are confidential, and banks may not disclose them outside the rule's narrow exceptions [3]. In a KYC file, that information hides in unexpected places: an exit memo that cites "referral to FIU," a case status code such as SAR_FILED, a periodic-review trigger tied to an investigation, or a QA comment.

As of October 2026, a September 2026 joint statement from FinCEN and the banking agencies clarified that discussing underlying activity is distinct from revealing a filing [4]. Treat that as a reason for precision, not relaxation: the supplier should run a field-level and free-text scrub for SAR, FIU, 314(a) and 314(b) references, and exclude cases where the exit reason cannot be stated without them. This also keeps the dataset distinct from AML alert and fraud investigation data; for that adjacent purchase, see fraud investigation case notes and analyst decisions.

Direct identifiers come next: names, dates of birth, SSNs and TINs, account numbers, addresses, phone numbers, emails and registry numbers for small entities. Ownership charts need consistent pseudonyms so "Holding A owns 60% of OpCo B" still resolves across documents. Free-text EDD memos are the main residual risk, because a narrative about "the only licensed casino operator in a small county" identifies a customer without naming one.

Licensing basis: Regulation P and adverse-media content

The licensing basis must be settled with the bank before files move, because KYC files on individual consumers are nonpublic personal information under the Gramm-Leach-Bliley Act; corporate KYB files fall largely outside GLBA but still carry bank confidentiality and contract limits, and often personal details of beneficial owners. Regulation P limits a recipient's reuse: information received under an exception may be used only for the purpose for which it was received, and information received outside an exception can be redisclosed only as the originating institution itself could [5]. The FTC describes this as the recipient stepping into the shoes of the originating institution [6]. In practice, ask the supplier to explain how the data was de-identified, which privacy notice applied, and whether counsel signed off on the AI training use.

Adverse-media screening content raises a separate rights question. The news articles behind a hit are third-party copyrighted works, so license the disposition, the analyst's summary and the source metadata (publisher, date, URL hash), not the article text. If you need article bodies for adverse media screening training data, source them from a news licensor under a separate agreement.

Bank buyers face one more gate: third-party training data used in models at a regulated bank falls under model risk management review. See model risk management for third-party training data in banking for what validators ask for, and reviewing an AI data license as in-house counsel for license triage. For records-licensing context across financial services, see the financial services records guide.

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Matching the file to the agent task

Each agent task needs a different slice of the case file and a different label. Buying the whole file and discovering later that the label you need was never recorded is the most common expensive mistake.

Agent taskInput fieldsTarget or labelWatch for
Case assembly (onboarding)Application, documents index, screening resultsCompleted checklist, missing-item requestsChecklist versions change by policy year
Risk-rating supportProfile, ownership, product, geographyRisk tier and factor valuesOverrides without stated reasons
Screening dispositionHit record, customer profileDisposition and rationaleAuto-closed hits inflate false-positive share
EDD memo drafting (SFT)Evidence bundleApproved memo textMemos rewritten at QA; keep both versions
Periodic review (KYC refresh automation)Prior file, new activity, triggerRefresh outcome, changes notedEvent-driven reviews linked to SAR activity
Evaluation setFull case, frozenReviewer-adjudicated outcomeLeakage if eval cases share customers with training

Pair the case files with the institution's KYC procedures, risk-rating methodology and EDD templates, so the agent learns the policy that produced the decisions rather than inferring it from outcomes. Reviewer notes and QA findings also work as preference data; audit judgment data covers a similar reviewer-judgment pattern in another domain.

Request template for a KYC and CDD case dataset

A precise request describes the data, the volume range and the exclusions, and lets suppliers say what they actually hold. Use the template below and adapt the fields.

Illustrative example: invented to show structure; it does not describe an available dataset.

request: KYC/CDD case review files
customer_type: legal_entity          # or individual; label each case if mixed
case_types: [onboarding, periodic_review, event_driven_review]
period: 2022-01 to 2025-12           # note policy or rule changes inside the window
required_fields:
  - risk_tier, risk_factor_values, override_flag, override_reason
  - beneficial_owner_count, ownership_chart (pseudonymized)
  - screening_hits: [list_type, match_score, disposition, rationale]
  - edd_memo_text (draft and final if available)
  - review_outcome: [approve, approve_with_conditions, escalate, exit]
  - approvals: [role, step, timestamp_offset]
exclusions:
  - any SAR, FIU, 314(a)/314(b) reference in fields or free text
  - adverse-media article bodies (keep disposition and metadata only)
  - identity document images
de_identification:
  - direct identifiers replaced with consistent pseudonyms
  - free-text memos reviewed for indirect identifiers
  - method documented; sample checked before delivery
licensing_basis: supplier to state GLBA/Reg P basis and privacy notice
intended_use: agent SFT, risk-rating support, held-out evaluation
format: JSONL per case, with attachments indexed by case_id

Quality checks before you accept delivery

Run acceptance checks on a sample before scaling, because KYC data fails in ways that only show up at the case level. Useful checks:

  1. Join integrity: every screening hit, memo and approval resolves to a case ID, and pseudonyms are stable across tables.
  2. Label provenance: each outcome shows who decided and at which maker-checker step; drop cases closed by bulk remediation projects.
  3. Policy drift: risk tiers from different methodology versions are tagged, not pooled.
  4. Leakage scan: search free text for SAR, FIU, account-number patterns and entity registry numbers.
  5. Class balance: exits and EDD cases are usually a small minority; confirm the share is realistic rather than oversampled without a flag.

How SourceX helps with KYC and CDD case data

SourceX sources operational datasets from US companies on request and manages the licensing process; it holds no stock, and a request does not guarantee a match. Every dataset is rights-reviewed, delivered under a license defining records, uses, term and delivery, and has personal details removed or replaced with the method recorded. Finance and fintech teams can see how this works for banking and finance buyers and fintech software buyers, or browse the industry-specific operational data hub. Describe the case files you need at SourceX for buyers.

Frequently asked questions

Can a bank license KYC files for AI training at all?

Sometimes, depending on the privacy notice, the de-identification method and the bank's own counsel. Regulation P reuse limits [5] and SAR confidentiality [3] are the two constraints to resolve first. Expect banks to approve narrower field sets than you request. If you would rather describe the files and let a sourcing partner look for US holders, start at SourceX for AI data buyers.

Is a KYC/CLM vendor's customer data a source?

Only if the vendor's contracts with its bank clients permit that reuse, which they often do not. Ask for the contractual basis in writing.

How do I keep evaluation cases from leaking into training?

Split by customer and by related-entity group, not by case, because periodic reviews and affiliated entities repeat the same owners and narratives. Freeze the evaluation set before any fine-tuning run and record the split keys in the delivery manifest.

Sources

  1. Electronic Code of Federal Regulations (eCFR), "31 CFR 1010.230 - Identification and verification of beneficial owners of legal entity customers". https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-D/section-1010.230
  2. Financial Crimes Enforcement Network, "FinCEN Order: CDD exceptive relief" (2026). https://www.fincen.gov/system/files/2026-02/FinCEN-Order-CCDExceptiveRelief.pdf
  3. Electronic Code of Federal Regulations (eCFR), "31 CFR 1020.320 - Reports by banks of suspicious transactions". https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1020/subpart-C/section-1020.320
  4. Financial Crimes Enforcement Network and federal banking agencies, "Joint Statement on SAR Confidentiality" (2026). https://www.fincen.gov/system/files/2026-09/Joint-Statement-on-SAR-Confidentiality.pdf
  5. Consumer Financial Protection Bureau, "12 CFR 1016.11 - Limits on redisclosure and reuse of information (Regulation P)". https://www.consumerfinance.gov/rules-policy/regulations/1016/11/
  6. Federal Trade Commission, "How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act". https://www.ftc.gov/business-guidance/resources/how-comply-privacy-consumer-financial-information-rule-gramm-leach-bliley-act

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data