3.1 The Architecture of Onboarding Walkthrough Audits
During the active execution phase of an AML compliance audit, the fieldwork team performs deep, data-driven Walkthrough Audits across all onboarding channels.
A walkthrough requires selecting a transaction or client entry at its initial point of intake and tracking its path down through every single system processing loop, database screening filter, risk-scoring matrix calculation, and final account clearance sign-off to verify that real-world operations match documented corporate policy.
3.2 The Audit Verification Path for High-Risk File Testing
Auditors select a statistically weighted sample of customer files flagged as high-risk (such as cash-intensive vendors, foreign corporate structures, or PEPs) and execute a rigorous File Review Checklist:
The Onboarding Control Verification Path:
[Select High-Risk File Account Entry] ──► Verify Official Government Photo ID Logs & Address Provenance Documents
                                                    │
                                                    â–¼
                                     [Check UBO Aggregation Sheets]
                                                    │
                                                    â–¼
                       Verify Passport Extractions for All Natural Persons Holding >= 25% Equity
                                                    │
                                                    â–¼
                                      [Audit EDD Source of Wealth Logs]
                                                    │
                                                    â–¼
                        Check Legitimate Corporate Accounts and Signed Analyst Tax Summaries

3.3 Testing the Integrity of Suspended and Rejected Onboarding Registries
A critical point of control failure manifests when a compliance system correctly flags an illicit entity or rejects an onboarding request, but operational staff fail to document or enforce the block.
Auditors extract the complete history from the Rejected Onboarding Registry, cross-verifying active customer ledgers to confirm that blocked individuals have not successfully bypassed perimeters by altering name spellings, creating alternative sub-accounts, or utilizing proxy shell entities, validating the absolute sovereignty of onboarding defenses.

Â