Remediation

Also called KYC Remediation, File Remediation, Look-Back Review, Backlog Remediation

ComposedNot built

Remediation, in compliance vocabulary, is the project of going back through existing customer files, sometimes a targeted batch, sometimes an entire back-book of every customer a bank has ever onboarded, to fix records found deficient against a standard they should have met all along. It's distinct from ordinary Periodic Review: a periodic review is a planned, ongoing part of ordinary operations; remediation is reactive, usually forced by a regulator finding gaps during an examination, an internal audit surfacing the same thing, or a consent order that requires it as a condition of a settlement.

The reason "remediation" carries a specific dread inside banking compliance departments is scale and cost. When a regulator finds that a bank's KYC files have systemic gaps, missing beneficial-ownership documentation, expired verification, inconsistent risk ratings: the fix isn't updating a policy going forward; it's re-touching every affected existing file, which for a large bank can mean hundreds of thousands of customer records. Real, publicized remediation programs following AML enforcement actions in the 2010s ran for years and cost major banks hundreds of millions of dollars in analyst labor, largely because re-collecting a document from a customer who already gave it once, and has since moved, changed banks, or simply stopped answering, is slow and expensive at that scale.

Who actually built this

There's no single body that defined remediation the way FATF defined the risk-based approach: it's an emergent compliance-operations practice, shaped by how regulators have actually enforced AML law. Formal consent orders and enforcement actions from bank regulators are what typically trigger a named remediation program and set its scope and deadline; the execution methodology (sampling, prioritization, analyst workflow) is standard project-management and compliance-ops practice, often run by specialized remediation consultancies rather than in-house teams. Solidus has no role in any of this today.

Solidus today

No Solidus product has managed, tracked, or supported a remediation program for any customer. The connection to Solidus's own thesis is real but unproven: a portable credential removes the need to re-contact a customer for a document they've already provided elsewhere, which is exactly the cost center that makes remediation programs so expensive. That's a hypothesis about where reuse could matter someday, not evidence that it has.

See also

Periodic Review is the planned, ongoing counterpart to remediation's reactive, forced cleanup. Re-KYC is the specific document-refresh action a remediation project often has to perform at scale. Credential Portability is the mechanism that would, if it worked at scale, make remediation cheaper, stated as a hope, not a result.

Where it comes from

Someone else specified this. Solidus assembles it.

Not a single spec, "remediation" is what compliance departments call the project of fixing a KYC file, or an entire back-book of files, found deficient after a regulatory exam, a consent order, or an internal audit surfaces the gap. The practice has a specific, well-earned reputation inside banking because of a wave of large, regulator-mandated "look-back" remediation programs that followed AML enforcement actions at major global banks through the 2010s, some running for years and involving thousands of contract analysts re-checking existing customer files. Solidus did not originate the practice and holds no regulatory authority to mandate or run one for anyone.

How to check this

Solidus has not built this. The entry explains the concept.

None. This entry states what has not been built, not what has.

Related

Remediation · Solidus Lexicon