IndiciumIndicium
Log in
Glossary 97 terms — compliance, KYC, RegTech

Know the terms, ask the better questions.

Compliance, risk examination and due diligence have their own language — from supervisory law, data protection and a growing layer of AI technology. Those who speak it check more sharply, buy more precisely and don't get sold anything they don't need.

This glossary explains the terms that come up in every mandate, every tender and every supervisory conversation — brief, precise, no marketing. Each entry stands on its own. You don't have to read from the top.

Find the term, not the whole page.

Type a keyword — the list filters as you type. Browse 13 categories or search directly.

Adverse media (or negative news) refers to any negative information from publicly accessible sources — press, court reports, regulatory announcements — indicating an elevated money laundering, fraud, or reputational risk. Systematic adverse media screening is part of every risk review.

Adverse media screening searches public sources — news, legal databases, regulatory announcements — for risk-relevant information about a person or entity, including money laundering allegations, corruption, sanctions evasion, and human rights violations.

Anti-Money Laundering covers all statutory, regulatory, and operational measures designed to prevent illegally obtained assets from being introduced into the legitimate financial system. The AML regime is based on the FATF Recommendations and national legislation such as the GwG (DE), the AMLA (CH), and the EU Anti-Money Laundering Directives.

API-based compliance enables companies to integrate AML, KYC, and sanctions checks directly into their existing systems (CRM, ERP, transaction systems) without having to operate separate compliance front ends.

Article 22 GDPR grants the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects or similarly significantly affects the data subject. Central to KYC/AML screening: a suspicious activity report must never be filed without human review.

An audit trail documents every step of a compliance process — who, when, what, why — in an immutable form that can be reconstructed at any time. It is a prerequisite for demonstrating to supervisory authorities that due-diligence obligations have been met.

Automated compliance monitoring replaces manual sampling and batch procedures with continuous, rule-based, and AI-supported monitoring of transactions, business relationships, and regulatory changes in real time.

A background check is the structured review of sanctions lists, criminal records, commercial registers, negative media coverage, credit information, and other public and licensed sources in order to assess the integrity risk of a person or organisation.

BaFin is the central supervisor of credit institutions and financial services providers in Germany. Among other things, it monitors compliance with anti-money laundering obligations, penalises violations, and publishes interpretation and application guidance on the GwG.

A credit report provides information on payment defaults, dunning proceedings, insolvency proceedings, and the general creditworthiness of a person or company within the scope of a risk review.

Business partner screening systematically examines sanctions lists, register entries, adverse media, and beneficial owners before a business relationship is entered into. In regulated industries, this step frequently accounts for the largest share of compliance working time.

In addition to standard components, C-level background screening includes specific reviews such as the analysis of conflicts of interest, corporate entanglements, and the public perception of an executive. Particularly at regulated financial institutions, it is an integral part of the appointment process.

Customer Due Diligence is the fundamental review of customer identity, business structure, and the purpose of the business relationship. Under the German GwG, it comprises the identification of the contracting party, the determination of the beneficial owner, and the ongoing monitoring of transactions.

A complex ownership structure exists where several intermediate companies, often in different jurisdictions, extend the chain from the operating company to the UBO. Such structures regularly trigger EDD obligations because they increase the risk of concealed ownership.

Before a high-risk AI system may be placed on the market, the provider must complete a conformity assessment procedure and document that the AI meets the requirements of the AI Act. The procedure covers technical documentation, risk assessment, and quality management.

The corporate veil (piercing the corporate veil) refers to the legal disregard of the limitation of liability between a company and its shareholders. In the KYC context, it denotes the duty to look through the veil of the legal entity to the natural person who owns it.

The credit check provides information on payment behaviour, existing credit obligations, insolvencies, and dunning proceedings of a natural or legal person. Within integrity due diligence, it is an indicator of financial stability and potential conflicts of interest.

DORA empowers the European Supervisory Authorities to designate certain ICT third-party providers as critical and subject them to a direct oversight regime. This concerns in particular large cloud providers, data centre operators, and data aggregators on which the financial sector depends.

Under the GDPR, the transfer of personal data to third countries is permitted only where an adequacy decision of the European Commission exists or appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules) are in place. The EU-US Data Privacy Framework provides a current transfer mechanism.

The controller determines the purposes and means of the processing. The processor processes data on behalf of the controller but may not use it for its own purposes. In KYC screening, a contractual clarification of roles under Art. 28 GDPR is mandatory.

Under Art. 5(1)(c) GDPR, personal data must be adequate, relevant, and limited to what is necessary for the purpose. In the KYC context, this means collecting and storing only the data actually required for the specific compliance review.

De-risking refers to the practice of financial institutions excluding entire customer segments or countries wholesale instead of conducting an individual risk assessment. The FATF criticises this conduct because it fosters financial exclusion and can push legitimate business into informal channels.

DORA requires financial institutions to conduct regular digital resilience testing, including vulnerability assessments, penetration tests and — for systemically important institutions — Threat-Led Penetration Testing (TLPT). The tests must cover scenarios derived from the prevailing threats to the financial sector.

The director disqualification check examines whether a person is barred from serving as a managing director or board member — for example due to delayed insolvency filing or fraud. Particularly relevant when appointing executives in regulated sectors.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) obliges financial institutions in the EU to strengthen their ICT security — with requirements for ICT risk management, incident reporting, digital resilience testing, and the management of ICT third-party risks. Applicable since January 2025.

A data protection impact assessment is mandatory for processing operations likely to result in a high risk. It documents the nature, scope, and purpose of the data processing, assesses risks, and sets out mitigating measures. In the RegTech field, it is particularly relevant where automated decision-making is used.

Enhanced Due Diligence goes beyond CDD and applies to high-risk business relationships — for example involving PEPs, third countries with strategic deficiencies, or complex, opaque ownership structures. EDD requires additional evidence of the source of wealth and intensified ongoing monitoring.

NIS2 distinguishes between essential and important entities, depending on size and sectoral significance. Essential entities are subject to stricter supervision and can face higher fines. The distinction is based on sectoral size thresholds (employees, turnover).

The Artificial Intelligence Act (the EU AI regulation) regulates artificial intelligence under a risk-based approach and distinguishes four risk categories: unacceptable, high, limited, and minimal. The AI Act is the first comprehensive statutory framework for AI worldwide.

The EU imposes restrictive measures (sanctions) through Council decisions under Art. 29 TEU and Art. 215 TFEU. They include asset freezes, travel bans, and sectoral economic sanctions. The current consolidated list is published in the Official Journal of the EU.

Executive vetting comprises the detailed review of board candidates and managing directors for business entanglements, conflicts of interest, prior regulatory violations, and reputational risks — going well beyond a standard background check.

The Financial Action Task Force, headquartered in Paris, sets the internationally recognised minimum standards for combating money laundering, terrorist financing, and proliferation financing. Its 40 Recommendations form the foundation of national AML legislation worldwide.

A fit and proper assessment examines the professional qualification (fit) and personal integrity (proper) of executive directors and supervisory board members. In the financial industry, supervisory authorities such as BaFin and FINMA require this evidence prior to appointment.

The Financial Intelligence Unit is the competent national authority for receiving, analysing, and disseminating suspicious activity reports. In Germany, it is the Central Office for Financial Transaction Investigations; in Switzerland, MROS (Money Laundering Reporting Office Switzerland).

The four-eyes principle requires that risk-relevant decisions be reviewed independently by at least two qualified persons. In the compliance context, this applies in particular to the approval of high-risk business relationships and the validation of AML alerts.

The EU General Data Protection Regulation (GDPR) governs the processing of personal data throughout the EU. In force since May 2018, it harmonises the data protection laws of the member states and grants data subjects extensive rights — including the rights of access, erasure, and data portability.

The Money Laundering Reporting Officer is responsible under § 7 GwG for implementing and monitoring the internal safeguards. He or she acts as the point of contact for supervisory authorities, law enforcement bodies, and the FIU, and must be positioned at senior management level.

The German Anti-Money Laundering Act (GwG) obliges financial institutions, lawyers, notaries, real estate agents, and numerous other professions to identify contracting parties, report suspicious cases, and implement effective risk management against money laundering and terrorist financing.

The FINMA Anti-Money Laundering Ordinance specifies the obligations of financial intermediaries in Switzerland regarding identification, transaction monitoring, and reporting duties. It serves as the technical implementing standard for the Swiss Anti-Money Laundering Act.

Inspection of commercial registers provides basic data on the company name, registered office, legal form, persons authorised to represent, and capital structure of a legal entity. It is the first step of any corporate review.

Heads of international organisations (UN, IMF, World Bank, WTO, OSCE) are explicitly classified as PEPs under EU Directive 2015/849 — an extension that is not implemented in the same level of detail in all jurisdictions.

High-risk AI systems under the AI Act are AI systems operated in safety-relevant contexts — including critical infrastructure, law enforcement, and biometric identification. They must meet strict requirements for transparency, human oversight, and risk management.

HMT and OFSI administer and enforce UK financial sanctions under the Sanctions and Anti-Money Laundering Act 2018. Since Brexit, the UK has acted as an autonomous sanctions power with its own consolidated list.

A holding structure is established to consolidate operating units under a common ownership structure. In UBO analysis, the holding company is the central pass-through point: whoever controls the holding controls the operating companies beneath it.

An ICT third-party provider is an undertaking that supplies information and communication technology services to financial institutions. DORA introduces a European oversight framework for so-called critical ICT third-party providers, which can be supervised by the European Supervisory Authorities (ESAs).

Identification under the GwG requires obliged entities to collect the name, date of birth, place of residence, and nationality of a natural person, or the company name, registered office, and legal form of a legal entity, and to verify these against a valid identity document or commercial register extract.

Identity verification (IDV) confirms the identity of a person by comparison with an official identity document — in person, via video identification, or through qualified electronic signatures. As a central part of the KYC process, it must satisfy the requirements of the GwG or equivalent national law.

Integrity Due Diligence examines not only legal and ownership circumstances but specifically the reputational risk of a person or entity: corruption, sanctions, money laundering allegations, human rights violations, and negative media coverage — scaled by risk class.

A correspondent banking relationship exists where a bank grants a foreign bank access to its payment system. Owing to the elevated money laundering risk, FATF Recommendation 13 and the GwG require specific enhanced due-diligence measures.

KYC refers to the process by which a financial institution or obliged entity establishes and verifies the identity of a customer and assesses its risk profile. European financial supervision specifies KYC as part of the CDD measures under the EU Anti-Money Laundering Directive.

A KYC utility is a shared platform that collects and maintains identification data once and makes it available to multiple users (banks, insurers) — with the consent of the customer. The model promises cost reduction and improved data quality.

The Legal Entity Identifier (ISO 17442) is a standardised, globally unique identifier for legal entities engaging in financial transactions. LEI data includes entity information and the direct parent company — a basic data point for UBO analyses.

A litigation check searches electronic court registers and legal databases for lawsuits, proceedings, and judgments in which a person or company is or has been involved — a key indicator of reputational and operational risks.

DORA establishes a uniform reporting obligation for major ICT incidents at financial institutions. The incident is reported to the competent supervisory authority within defined deadlines (initial notification within 4 hours, intermediate report, final report) using standardised templates.

Media monitoring comprises the structured observation of press, blogs, trade publications, and social media for relevant news about business partners, transactions, or political changes that could affect the risk profile.

Modern RegTech platforms automatically classify adverse media hits by severity (low, medium, high), topic category (financial crime, corruption, environmental violations), and source authority in order to prioritise manual review.

The NIS2 Directive (EU 2022/2555) extends the scope of the original NIS Directive to considerably more sectors and companies, tightens security requirements, establishes personal liability of management bodies, and strengthens reporting obligations for cybersecurity incidents.

NIS2 tightens reporting obligations into a multi-stage procedure: early warning within 24 hours of becoming aware of the incident, detailed notification within 72 hours, and a final report within one month. This structure resembles the DORA regime but applies across sectors.

No-code compliance means configuring regulatory review and reporting workflows through visual interfaces instead of programming them. The trend is driven primarily by mid-sized regulated companies that do not maintain their own development staff.

A nominee director is formally entered in the commercial register but exercises the function on the instructions of the actual beneficial owner. A classic red-flag indicator in UBO analysis.

OFAC administers and enforces US economic and trade sanctions based on US foreign policy and national security interests. The OFAC SDN List (Specially Designated Nationals) is the most widely screened sanctions list in the world and has extraterritorial effect.

Under the OFAC 50 % rule and the corresponding EU doctrine, an entity is deemed sanctioned if one or more sanctioned persons cumulatively hold 50 % or more of its ownership interests. Extended interpretations also cover controlling influence below this threshold.

A politically exposed person holds a prominent public function or has done so within the preceding 12 months. Under § 1 GwG, PEPs include heads of state, ministers, members of parliament, senior judges, and senior military officers. Financial intermediaries must subject PEP business relationships to enhanced due diligence.

Under the FATF definition and the EU Anti-Money Laundering Directives, a person remains classified as a PEP for at least twelve months after leaving office. Some national laws, including the German GwG, permit a return to standard CDD measures after this period expires.

Before an executive is hired, the pre-hire integrity check reviews sanctions lists, criminal records, reputational risks, and stated qualifications — particularly relevant for regulated positions, where an inadequate review can trigger supervisory sanctions.

The AI Act prohibits AI applications classified as posing an unacceptable risk, including social scoring by public authorities, real-time facial recognition in public spaces, and manipulative AI that induces a person to engage in harmful behaviour.

The Risk-Based Approach requires that AML measures be calibrated to the actual risk of a business relationship — not to a rigid template. Higher risks require more intensive measures; low risks permit simplified procedures. A core principle of the FATF Recommendations.

RCAPs are family members (spouses, children, parents) and known close business partners or economic beneficiaries of a PEP. They are also subject to the EDD rules, because the actual corruption risk can be realised through them.

A red flag is a specific indicator of elevated risk: negative media reports, PEP status, complex offshore structures without a discernible economic purpose, list hits. Under the risk-based approach, every red flag triggers documented escalation and review steps.

RegTech refers to the use of modern technologies — AI, big data, cloud computing — to automate compliance processes, meet regulatory requirements efficiently, and monitor risks in real time. The term was coined in 2015 by the UK Financial Conduct Authority (FCA).

Regulatory change management captures, assesses, and implements changes in regulation — from GwG amendments and new EU directives to supervisory circulars — and manages their impact on compliance processes. RegTech platforms automate the capture and mapping.

Reputational risk describes the danger of direct or indirect financial losses caused by damage to the public standing of a company — for example through association with money laundering, bribery, human rights violations, or other compliance breaches.

The fully revised Swiss Federal Act on Data Protection entered into force in September 2023 and aligns Swiss data protection law more closely with the GDPR. Among other things, it introduces a duty to notify data security breaches and extended information obligations.

The risk analysis under § 5 GwG requires obliged entities to identify and assess their specific money laundering and terrorist financing risks and to derive appropriate measures. It must be documented, updated regularly, and submitted to the supervisory authority upon request.

A Risk Appetite Statement documents at board level which risks an institution deliberately accepts, which it excludes, and where the thresholds for escalation lie. It is the foundation of any risk-based compliance strategy.

In Art. 24 and Art. 32, the GDPR requires that technical and organisational measures (TOMs) be taken with regard to the likelihood and severity of the risk to the rights and freedoms of natural persons — not uniformly, but in proportion to the risk.

The sanctions list check screens a person or organisation against all relevant sanctions lists (OFAC, EU, UN, HMT, SECO) for direct hits, partial matches, and similar name variants. Hits must be handled according to defined escalation rules.

Sanctions screening compares customer, transaction, and business partner data — in real time or in batches — against all applicable national and international sanctions lists. Hits, including partial and fuzzy matches, are routed for manual review.

A Suspicious Activity Report is the formal report of a suspicion of money laundering or terrorist financing to the national Financial Intelligence Unit (FIU). In Germany, the report is filed via goAML with the German Financial Intelligence Unit (FIU).

Simplified Due Diligence reduces the scope of review where the risk assessment indicates a low money laundering risk. The relief does not, however, fully exempt from the due-diligence obligations; a documented risk justification remains required.

SECO is the competent Swiss authority for the implementation of international sanctions. It maintains the Swiss sanctions lists, provides information on changes, and monitors compliance. Unlike the EU, Switzerland generally adopts UN sanctions directly and autonomously.

Sectoral sanctions target specific economic sectors of a target state (defence, oil, financial services) rather than individually listed persons. The EU sanctions against Russia after 2014 and 2022 are the most prominent example.

Sentiment analysis in compliance evaluates the linguistic tone of press reports and trade articles by machine in order to identify negative coverage even in large volumes of text. It is a technical aid, not a legal judgment.

Smurfing (also structuring) is the technique of splitting large sums of money into many small transactions below the reporting threshold in order to evade automated transaction monitoring. Transaction monitoring systems are specifically designed to detect such patterns.

The due-diligence obligations under the GwG comprise the identification of the contracting party, the determination of the beneficial owner, obtaining information on the purpose of the business relationship, the ongoing monitoring of transactions, and the duty to file suspicious activity reports.

A criminal record extract documents the final criminal convictions of a natural person and is routinely required in regulated industries as part of background checks. Its request and storage are subject to strict data protection limits.

NIS2 requires companies to assess cybersecurity risks across their entire supply chain — one of the most significant tightenings compared with the predecessor directive. Suppliers and service providers with access to the IT infrastructure must be systematically reflected in cyber risk management.

SupTech is the supervisory-side counterpart to RegTech: technology used by supervisory authorities to analyse reported data automatically, detect risks in the financial system early, and conduct examinations more effectively.

TPRM covers the identification, assessment, monitoring, and management of risks arising from suppliers, distribution partners, consultants, and other third parties. The NIS2 Directive and DORA significantly raise the regulatory requirements for TPRM.

Technical and organisational measures under Art. 32 GDPR comprise all measures ensuring a level of protection appropriate to the risk — including pseudonymisation, encryption, and the confidentiality, integrity, availability, and resilience of systems. Documentation and the record of processing activities (RoPA) are core components.

Transaction monitoring is the continuous, software-based comparison of customer activity against expected patterns. Deviations — such as unusually large amounts, structured payments, or country outliers — trigger alerts that are analysed manually and, where substantiated, reported to the FIU as a SAR.

The AI Act requires transparency and labelling for certain AI systems — such as chatbots and deepfakes. Users must know that they are interacting with an AI system, and AI-generated content must be marked accordingly.

The German Transparency Register is a central register in which the beneficial owners of legal entities under private law and registered partnerships must be recorded. It implements the EU Anti-Money Laundering Directive and is a primary source for compliance reviews.

The ultimate beneficial owner is the natural person who ultimately controls a legal entity or legal arrangement or holds the beneficial interest in it. Identifying the UBO is a core component of every AML review under the FATF Recommendations and the GwG.

UN sanctions are imposed by resolutions of the UN Security Council under Chapter VII of the UN Charter and must be implemented by all member states. They are the only sanctions with universally binding effect under international law and take precedence over national law.

Under § 3 GwG, the beneficial owner is the natural person who holds more than 25 % of the capital shares, controls more than 25 % of the voting rights, or exercises control in a comparable manner. Its determination is a mandatory component of the CDD measures.

The Wolfsberg Group is an association of 12 global financial institutions that develop frameworks for correspondent banking, PEP identification, and sanctions compliance. Its publications — such as the Wolfsberg paper on the Risk-Based Approach — are regarded as internationally recognised industry standards.

No match. Try an abbreviation (PEP, UBO, GwG) — or clarify the term in a call.

You now know what to check. We'll show you how deep.

Terms bring clarity about the question. The answer depends on your case: is the automated Software-Report enough, or does it need human final review? That's exactly what we clarify in a short call — no sales pressure, with someone who speaks the language.

Book a discovery call See the report spectrum