Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Relationship Bankers Don't Belong in KYC DecisionsEnforcement & Penalties
3 min readFor AML Compliance Officers

Relationship Bankers Don't Belong in KYC Decisions

The Conventional Wisdom

Many private banks and wealth managers see relationship managers as key players in Customer Due Diligence. They know the clients well, understand the business context, and can explain unusual transactions. This often leads to their involvement in KYC exception decisions, risk ratings, and enhanced due diligence reviews. Institutions formalize this through "four eyes" policies, requiring both compliance and business approval on high-risk onboarding. The belief is that business judgment helps avoid false positives and maintains client service.

Why This Approach Fails

The Julius Baer case highlights a major flaw in this approach. FINMA confiscated about CHF 10 million from the bank after finding serious AML breaches linked to Russian PEP relationships. The issue arose when Julius Baer waived internal policy after an employee recommended a PEP client due to personal connections. FINMA criticized the bank for failing to challenge the decision.

Relationship managers face a conflict of interest. They're incentivized to retain clients, not challenge their own recommendations. This isn't about ethics but about the design of incentives. Relationship managers focus on acquiring clients, while compliance officers focus on mitigating risk. These roles need distinct decision rights.

The Evidence

Julius Baer's case is its fifth FINMA action in under a decade, indicating a systemic issue. FINMA's findings show the consequences of relationship influence in compliance decisions:

  • The bank didn't verify the origin of assets for high-risk clients.
  • It ignored negative media reports and suspicious behavior.
  • It breached reporting obligations under Switzerland's Anti-Money Laundering Act.

These aren't technical errors but judgment failures. The CHF 10 million penalty and additional capital requirements underscore the need for independent oversight. FINMA's proceedings against former employees emphasize personal accountability in KYC decisions.

What to Do Instead

Remove relationship managers from KYC exception approvals. They can provide information but shouldn't have decision-making power.

Information Gathering: Relationship managers submit written requests explaining why a client can't meet standard requirements, including supporting documentation and business context.

Independent Review: A compliance officer, independent of the business unit, reviews the request. They can approve, reject, or request more information without business sign-off. For PEPs and high-risk categories, escalate to the MLRO or a compliance committee without revenue responsibility.

Documentation Requirements: Each exception needs a written decision memo detailing policy waivers, compensating controls, residual risks, and approval authority. The memo should note any conflicts of interest.

Ongoing Monitoring: Flag exception accounts for enhanced monitoring and periodic reviews. Relationship managers shouldn't be surprised by increased scrutiny.

For PEPs, don't accept relationship-manager attestations as sufficient. Require independent documentation like tax returns, sale agreements, or employment contracts. If a relationship manager claims long-term knowledge of a family, insist on documentation.

Adverse media assessments should be handled by compliance. Relationship managers have too much incentive to downplay negative press. Julius Baer's failure to assess negative media likely stemmed from relationship managers minimizing concerns.

When Relationship Managers Add Value

Relationship managers offer insights that compliance teams need. They understand transaction patterns, business cycles, and client behavior beyond data analysis. A compliance analyst might flag a pattern that a relationship manager recognizes as routine.

Involve relationship managers in:

  • Periodic Reviews: Confirm if the customer's business activity and risk profile align with onboarding information. Document their input, then make your own risk determination.

  • Alert Disposition: When transaction monitoring triggers an alert, relationship managers can provide context. However, compliance decides whether to file a Suspicious Activity Report.

  • Customer Exit Decisions: If exiting a relationship for AML concerns, relationship managers should manage client communication to avoid tipping off. They execute the decision, not make it.

Julius Baer's case shows the risk of confusing information sharing with decision rights. Relationship managers can inform KYC decisions without controlling them. This distinction might cost some client relationships short-term but will save regulatory scrutiny and financial penalties long-term.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like