Field notes · 2026-04-03
Sampling customer due diligence files without drowning in volume
How audit teams pick a defensible sample of CDD files when a fintech onboards thousands of accounts each month.
Full-population review is rarely practical. What matters is a sample that can explain risk coverage: high-risk ratings, overridden screening hits, politically exposed persons if present, and ordinary retail accounts that should look clean.
Agree the strata before opening folders. A common pattern for a mid-size digital lender is ten high-risk files, ten medium-risk, and ten randomly selected standard files from the last ninety days. Adjust counts when product lines differ—merchant acquiring and consumer lending rarely share the same red flags.
Document why each file entered the sample. Examiners and partner banks ask this question. A random seed plus explicit inclusion rules for overrides keeps the conversation factual rather than defensive.
Score each file against a short checklist: identity evidence present, purpose-of-account notes, source-of-funds where required, periodic review dates, and escalation if the risk rating changed. Missing one field is a finding; inventing a narrative after the fact is worse.
Share interim observations mid-engagement. Compliance leads often know where files are thin and can stage better evidence before the final report locks. That courtesy does not soften findings—it simply avoids surprises that waste remediation weeks.
Back to field notes