AML/KYC document collection without the spreadsheet
A new corporate client comes on board with three beneficial owners, a holding company in another jurisdiction, and a director who travels constantly. Your onboarding checklist is a spreadsheet with a tab per owner. Column A lists what you need: passport, proof of address, structure chart, source-of-funds evidence. Column B is meant to say whether it has arrived. Two weeks in, half the cells say “chasing”, one says “got it? check with Maria”, and one passport turns out to be for the wrong person entirely.
This is AML and KYC collection as most firms run it, and it is the one workflow where the spreadsheet is most obviously the wrong tool.
The stakes are recordkeeping, not just receipt
AML and KYC work turns on a simple question you may have to answer long after the fact: for this Client, and for each beneficial owner, what did we request, what did we receive, who reviewed it, and what did we accept. Not “do we have some files somewhere.” The specific chain of asks and decisions.
A spreadsheet cannot hold that chain. It records a status someone typed, at a moment they remembered to type it, with no memory of what was actually asked or when the file came in. The files themselves live somewhere else — an inbox, a shared drive, a folder named after the client. The tracker and the documents are two systems, and they drift apart the moment the first correction arrives. When a passport expires and the client sends a new one, the old cell just gets overwritten. The version you originally reviewed is gone.
For high-stakes, repetitive collection, that is exactly the gap you cannot afford. You need to show what you did, per item, and keep the evidence of it.
A KYC Pack instead of a tab per owner
Clivanta treats each thing you ask for as a Request Item — one specific ask, with its own status, its own conversation, versioned files, and an immutable activity log. Your standard KYC procedure becomes a Pack: the reusable set of Request Item templates for onboarding a regulated client.
A KYC Pack might carry, per beneficial owner:
- Certified copy of passport or national ID, with instructions on certification and a note on acceptable formats.
- Proof of address dated within your policy window, with the acceptable document types spelled out.
- Ownership and control structure chart, showing the path from the individual to the Client.
- Source-of-funds and source-of-wealth evidence, with a description of what you will and won’t accept.
Each of these is its own Request Item with an owner, a due date, and a status that moves through the lifecycle requested → submitted → needs revision | accepted. The ask carries the instructions, so the client is not guessing what “proof of address” means. That alone removes a round of back-and-forth.
Because the Pack is a firm-level standard, it is copied as a snapshot into each onboarding when you start it. If you refine your KYC procedure next quarter, later edits to the Pack never rewrite the record of what you asked a client for last month.
What “outstanding” means when it is a stored fact
The most useful thing in AML collection is a reliable answer to what is still missing, and for how many owners. In a spreadsheet that answer is derived by hand, and it is only as current as the last person to update it.
In Clivanta, outstanding is read from the stored, audited status of each Request Item — requested or needs revision, never inferred from whether a file happens to sit in a folder. Your worklist, the client’s portal view of what is still needed, and the reminders that chase the routine items all read the same status. A client can pause a reminder with a logged acknowledgment when they genuinely need a week; the item stays open and comes back on its own, and you keep both the relationship and the record.
When a client uploads, AI pre-checks run in the background. They classify the document type, extract its date and the entity or person named on it, detect duplicates by file hash, and flag a likely wrong entity — the parent’s certificate uploaded under the subsidiary, or a document that belongs to a different owner. These checks are advisory. They surface a concern for a person to look at. They never accept, reject, or move anything on their own. A Firm User always makes the decision, which is precisely what you want in a file you may have to stand behind.
From uploaded Document to accepted Evidence
There is a distinction that matters here more than almost anywhere else. A file a client uploads is a Document — raw, not yet reviewed. It only becomes Evidence when a member of your firm accepts it against the Request Item. Acceptance is a decision with a name and a timestamp, and it promotes that Document to a permanent part of the Engagement record.
In a folder, an accepted passport and an unreviewed one look identical. In Clivanta they do not. You can always tell which file you actually relied on for each owner, who signed off on it, and when. If a client sends a corrected structure chart, the superseded version is retained as a previous attempt, never deleted, so the trail of what you saw and when stays intact. This is the substance of a defensible audit trail: every meaningful action logged, attributable, and kept.
When you need the file for a review, an inspection, or an internal quality check, the record exports cleanly — an Excel request list showing every ask and its status, a ZIP of the accepted Evidence, CSV metadata, and an Evidence index PDF. You are not reconstructing a story from an email thread. The story is already written down.
Fewer moving parts, a stronger file
None of this makes AML judgement easier, and none of it is legal advice about your obligations. What it changes is the mechanics: the collection, the versions, the status, and the record. Those are the parts that a spreadsheet and an inbox handle worst, and they are the parts an inspector is most likely to test.
Firms doing regulated onboarding at any volume feel this most, which is why Clivanta is positioned for financial services and regulated clients as well as audit. The request-and-response loop is the same everywhere; AML just raises the cost of getting the record wrong.
Collect the documents once. Keep the proof of what you did.
Clivanta runs the audited request-and-response loop for professional-services firms. See how it works →