# Annex IV Technical Documentation Template — KYC / AML (editable)

Not legal advice. This is an operational template designed to map each claim to evidence you can
export later.

Version: v1.0  
Last updated: 2025-12-16  
Changelog:
- 2025-12-16 v1.0 Initial release

Report an issue: https://kla.digital/contact?subject=Template%20issue%20-%20Annex%20IV%20KYC%20AML

## Document control

- System name:
- Owner (function + name):
- Approvers (function + name):
- Scope / boundary (what is in-scope vs out-of-scope):
- Deployed regions and user groups:
- Versions in service (model/prompt/policy/workflow):
- Links (repo, runbooks, dashboards, risk register):

## One-page Annex IV summary (forwardable)

- Intended purpose:
- Decision(s) supported (risk scoring, alert triage, sanctions screening, SAR escalation):
- Primary users and affected persons:
- Human oversight checkpoints:
- Data sources (top 5):
- Primary harms & mitigations (top 5):
- Monitoring signals & thresholds:
- Logging & retention policy:
- Evidence export location (manifest / bundle ID):

## 1) General description (Annex IV item 1)

### 1.1 Intended purpose + outcomes

- [ ] What workflows does it support (onboarding, periodic review, transaction monitoring)?
- [ ] Which outputs are advisory vs automatic?
- [ ] What decisions are explicitly NOT made solely by the system?

### 1.2 Deployment context

- [ ] Where does it run (banking platform, fintech stack)?
- [ ] What systems does it touch (CRM, payments, case management)?
- [ ] Fallback modes

## 2) System elements & development process (Annex IV item 2)

### 2.1 Workflow components

- [ ] Input data (identity docs, watchlists, transaction data, customer profile)
- [ ] Screening logic (sanctions/PEP rules + ML)
- [ ] Alert triage model(s)
- [ ] Case management and escalation

### 2.2 Data governance

- [ ] Data sources + permissions
- [ ] Special category/sensitive data handling
- [ ] Redaction rules (what never lands in logs)
- [ ] Access controls + segregation of duties

## 3) Monitoring, functioning, control (Annex IV item 3)

### 3.1 Capabilities + limitations

- [ ] Known failure modes (name matching, transliteration, incomplete data)
- [ ] “Do not use for” boundaries
- [ ] OOD / drift detection approach

### 3.2 Human oversight triggers

- [ ] Always-review conditions (account closure, SAR filing recommendation, high-risk alerts)
- [ ] Sampled review conditions
- [ ] Escalation ladder and SLAs

## 4) Performance metrics & thresholds (Annex IV item 4)

- [ ] Precision/recall for alert triage
- [ ] False positive handling (ops load) and false negative handling (risk)
- [ ] Queue SLAs and reviewer throughput
- [ ] Threshold governance (approvals for changes)

## 5) Risk management system (Annex IV item 5)

Link risk register:  

### 5.1 Typical KYC/AML harms (prompt list)

- [ ] False positives leading to unnecessary restriction or account closure
- [ ] False negatives leading to missed suspicious activity
- [ ] Discriminatory outcomes via proxies (location, nationality, language)
- [ ] Data leakage in logs/exports (IDs, documents)
- [ ] Overreliance on automation in escalations

### 5.2 Mitigations + verification evidence

- [ ] Mitigation implemented:
- [ ] Verification evidence (sampling outcomes, reviewer disagreement handling):
- [ ] Residual risk acceptance record:

## 6) Lifecycle changes (Annex IV item 6)

- [ ] Material change definition
- [ ] Change approvals + evidence
- [ ] Versioning and rollback procedure

## 7) Standards / technical specs (Annex IV item 7)

- [ ] Standards used (if any)
- [ ] Internal controls mapped (policy-as-code references)

## 8) Declaration of conformity reference (Annex IV item 8)

- [ ] DoC location (internal reference)

## 9) Post-market monitoring plan reference (Annex IV item 9)

- [ ] Monitoring plan link:
- [ ] Sampling policy link:
- [ ] Incident response link:

## Evidence pointers

- [ ] Evidence pack manifest (bundle ID + checksums)
- [ ] Model/prompt/policy/workflow versions in effect per alert decision
- [ ] Oversight records (approvals, escalations, overrides)
- [ ] Sampling outcomes + reviewer guidance
- [ ] Incident reports + corrective actions

