There’s a quiet assumption embedded in most compliance workflows that KYC and due diligence are roughly the same thing. Run the name through the database, check the sanctions lists, verify the ID. Box ticked, relationship approved.After nearly a decade running due diligence operations across Europe and Eurasia, and reviewing thousands of reports across jurisdictions ranging from Western Europe to the former Soviet periphery, I can tell you that assumption carries real risk. Not theoretical risk. The kind that surfaces in a bad investment, a regulatory inquiry, or a reputational incident that nobody saw coming because nobody actually looked.KYC was designed for onboarding velocity. It answers a narrow question: is this person on a list? Enhanced due diligence asks a different question entirely: who is this person, and what does their history actually tell us about the risk they represent?The gap between those two questions is where most problems live.
Corporate affiliations and employment history
A subject’s current position is almost always clean. That’s the point — people structure their affairs accordingly. What KYC doesn’t capture is the directorship someone held five years ago at a company with beneficial ownership tied to a sanctioned individual, or the decade they spent at a state-owned enterprise in a high-risk jurisdiction before pivoting to the private sector. Mapping that kind of corporate history requires active research across multiple registries, often in multiple languages, not a single database query.
Credential and licensing verification
Misrepresented credentials are more common than the industry likes to acknowledge. A fund manager claiming professional designations they don’t hold, a consultant citing academic qualifications that don’t exist, a counterparty whose regulatory licensing has lapsed or been revoked — none of this surfaces in standard KYC. Verification requires going to primary sources: professional bodies, bar associations, academic institutions, regulatory registers. It’s not glamorous work, but it’s exactly the kind of thing that protects you when a relationship goes wrong.
Civil litigation and regulatory history
Sanctions lists capture a narrow slice of legal and regulatory history. Civil litigation — commercial disputes, fraud allegations, arbitration proceedings, regulatory sanctions that didn’t rise to the level of a criminal charge — falls almost entirely outside the scope of standard screening. Yet a subject’s litigation record is often the clearest available signal of how they actually operate in business relationships. It takes real research to surface it, but it’s rarely hidden.
Non-indexed databases and local sources
Most KYC processes are, at their core, sophisticated searches of English-language, Google-indexed sources with database overlays. That works reasonably well for subjects with significant Western presence. It misses almost everything else. Corporate registry filings in Romania, court records in Turkey, local business press in Arabic — these sources require language capability, jurisdictional knowledge, and direct access to databases that don’t surface through standard search. If it’s not indexed and in English, standard KYC treats it as if it doesn’t exist.None of this is an argument against KYC. It’s a necessary baseline, and for lower-risk onboarding it does exactly what it’s supposed to do. The problem is when organizations treat it as a substitute for actual due diligence on higher-risk counterparties, transactions, or markets.The standard should match the risk. When it doesn’t, the gap is invisible right up until it isn’t.This is the problem Clarytas was built to address.