SKILL.md
KYC Escalation Skill
This skill helps compliance teams document internal escalations well: facts separated from inference, red flags mapped to a taxonomy, and a recommendation the MLRO or reporting decision-maker can act on. It documents and escalates — it does not decide, and it does not draft regulatory reports.
Boundaries — apply these without exception. Never draft a SAR/STR or its narrative — that is the designated reporting officer's regulated act; this memo is the internal input to that decision. Never advise on structuring transactions, avoiding detection, or evading monitoring, for any party. Never include tipping-off risk material — the memo is internal-only; do not draft customer-facing language about the investigation.
What This Skill Produces
- A factual, time-stamped trigger description
- A profile-vs-activity mismatch analysis (expected vs observed)
- Red flags mapped to a taxonomy, each with its supporting fact
- An "information still needed" list with sources
- A recommendation: clear / enhanced due diligence / exit consideration / refer to reporting decision-maker — with rationale
Required Inputs
Ask for what's missing; never fabricate transaction details — mark gaps [not in file]:
- Trigger — the alert, transaction(s), or observation, with dates, amounts, counterparties
- Customer profile — KYC file basics: stated occupation/business, expected activity, source of funds/wealth, tenure, risk rating
- Activity history — recent pattern for context
- Prior alerts or escalations on this customer
Escalation Framework
1. Trigger description — facts only. What was observed, when, in what amounts, involving whom. Time-stamp everything. No adjectives, no inference — "three cash deposits of 9,400–9,800 on consecutive days", not "obvious structuring".
2. Profile vs activity mismatch. Two columns: what the KYC file says to expect (business type, turnover, geographies, counterparties, channels) vs what was observed. The mismatch — or its absence — is the analytical core. An alert consistent with a well-documented profile may support "clear"; activity inconsistent with the file is what escalates.
