Source of Funds vs Source of Wealth

Source of funds and source of wealth are related questions, but they solve different problems. A bank can know exactly which account sent a payment and still not understand how the customer obtained the money. It can also understand that a customer became wealthy through a long career or a successful business while still needing to understand the particular funds being used for a transaction today.

The useful distinction is simple. Source of funds (SoF) focuses on the origin of the money or assets used for a particular transaction, product or relationship. Source of wealth (SoW) focuses on the economic activities or events that generated or materially contributed to a customer's overall wealth over time. The first question is usually narrower and transaction-facing. The second is broader and customer-facing.

That distinction should not be turned into a universal documentary ritual. Global standards, national law, sector rules, product design and customer risk determine when information is required, when it must be corroborated, and how much evidence is proportionate. FATF's framework is risk based. Recommendation 12 contains additional measures for politically exposed persons, including reasonable measures to establish source of wealth and source of funds in the circumstances specified by the Recommendation. National frameworks can go further or apply different triggers. For example, current Australian guidance expressly links SoF and SoW to specified enhanced due-diligence situations and high ML/TF risk, while United States interagency guidance says the BSA customer due-diligence rule does not create a blanket requirement for unique additional PEP procedures. A global bank therefore needs a group principle with jurisdiction and product overlays rather than one hard-coded rule for every customer in every country.

The practical objective is not to prove that every unit of a customer's lifetime wealth is innocent. It is to reach a risk-appropriate understanding that is plausible, sufficiently supported and consistent with what the bank knows about the customer, the product and the activity. Where the applicable framework requires a particular standard, the bank must meet that standard. Where the control is risk based, it should be proportionate and effective rather than mechanically collecting documents that add little information.

Source of funds answers where the money for this activity came from; source of wealth explains the broader economic history that produced the customer's financial position. The diagram shows how both feed a risk-based customer decision.

A practical mental model

A useful way to work is to separate event, history, evidence and decision.

The event is what is happening now. A customer may be opening an investment account, making a large transfer, buying a property, funding a company, sending money to an exchange or receiving a third-party payment. The immediate question is what money or asset is being used and how the customer obtained it. That is the SoF question.

The history is how the customer reached the financial position that makes the event plausible. A senior executive may have accumulated wealth through salary, bonuses and equity awards. An entrepreneur may have built and sold a business. A family may hold inherited assets. An investor may have accumulated gains through securities or property. A company may generate funds through ordinary trading activity, capital contributions, borrowing or asset disposal. That is the SoW question.

The evidence is what allows the bank to move from an explanation to a defensible understanding. Evidence can come from information already held by the bank, customer-provided material, reliable independent records, regulated financial institutions, public registries, audited accounts, court or probate records, tax material where lawfully available, market data and other sources. No one evidence type is universally superior. A bank should ask what proposition it is trying to establish, how material the proposition is to the risk, whether the source is independent, whether the information is current and whether different sources tell a coherent story.

The decision is not automatically approve or reject. Possible outcomes can include accepting the explanation, asking for clarification, seeking additional corroboration, updating customer risk, changing monitoring, obtaining specialist or senior approval where policy or law requires it, restricting a transaction where the bank has a lawful and policy basis, considering a suspicious activity report or equivalent where the legal threshold is met, or deciding not to establish or continue a relationship. The exact action must follow the applicable legal framework and internal authority model.

This four-part model is deliberately different from a checklist. It forces the analyst to explain why a question is being asked and what decision the answer will support.

What source of funds means in practice

Source of funds is not merely the name of the bank account from which money arrived. A transfer from "Customer Current Account" explains the payment route, not necessarily the economic origin of the money. The useful question is how the customer obtained the value being used.

Depending on the case, an answer might be salary accumulated in a savings account, proceeds from selling a property, a dividend, business revenue, repayment of a loan, redemption of an investment, inheritance, a gift, a bank loan, insurance proceeds or another lawful source. For a company it might be operating revenue, capital introduced by shareholders, debt financing, proceeds from an asset sale or another business event.

The degree of inquiry depends on risk and context. A routine salary credit into a long-standing retail account may be self-explanatory from information already available to the bank. A large one-off transfer materially outside the known customer profile may require clarification. A high-risk relationship, a PEP relationship subject to enhanced measures, a complex structure, opaque third-party funding or activity involving a higher-risk jurisdiction may justify deeper analysis under the applicable framework.

The strongest SoF analysis connects three things: economic source, movement of value and customer relationship. If a customer says a payment comes from the sale of a property, the relevant facts may include ownership of the property, the sale event, the amount realised and the movement of proceeds to the customer. Not every case needs every document. The point is that the evidence should support the actual proposition rather than merely resemble the right type of paperwork.

What source of wealth means in practice

Source of wealth describes how the customer or relevant beneficial owner accumulated their overall financial position. Wolfsberg's public SoW and SoF FAQs, written mainly for private banking and wealth management, make an important distinction: the purpose of SoW work is not necessarily to account for or verify the exact value of every asset. It is to understand the activities that generated or significantly contributed to wealth and, where appropriate, assess whether the explanation is plausible and legitimate.

For an individual, wealth may arise from several sources over time. A founder can have business income, a later business sale, investments made from those proceeds and inheritance from family. A professional may have decades of salary, partnership distributions and pension assets. A customer may have property gains, securities investments or other legitimate wealth events. The bank should not force a multi-source life history into one label if doing so destroys useful information.

For a legal entity, the concept needs to be adapted. A trading company's financial position may be generated by operating revenue, retained earnings, external financing and shareholder capital. A holding company may derive value from subsidiaries and investments. A trust or personal investment vehicle may require the bank to understand the relevant settlor, contributor, beneficial owner or other controlling person's wealth depending on the legal arrangement, risk and applicable rules. The analysis should follow the real economic relationship rather than assuming that the account holder alone explains the origin of value.

SoW information is especially useful where the bank needs to judge whether the scale of assets or activity fits what is known about the customer. It is not a mathematical proof of innocence. It is a structured explanation that can be tested against reliable information and revisited when material circumstances change.

When SoF and SoW become relevant

The trigger should come from law, regulation, policy or risk, not from analyst curiosity. Common situations include enhanced due diligence, PEP relationships where the applicable rules require additional measures, private banking or wealth management, materially unusual funding, high-risk customer profiles, significant third-party funding, complex ownership, large one-off transactions, material changes in customer activity and investigation of unexplained wealth or suspicious activity.

The same trigger does not require the same response in every case. Current AUSTRAC guidance is a useful example of explicit proportionality. It states that SoF and SoW measures should be targeted to the customer's specific ML/TF risks, proportionate to the risk level and effective in managing that risk. It also notes that SoF or SoW is not relevant to every type of risk. That is an important design principle well beyond Australia: do not demand wealth evidence when it cannot logically address the risk being investigated.

FATF's PEP framework illustrates a different kind of trigger. Recommendation 12 requires additional measures for foreign PEPs and risk-based measures for domestic and international-organisation PEPs as specified in the Recommendation, including measures concerning source of wealth and source of funds. Those requirements are preventive; PEP status does not mean the person is involved in criminal activity. National implementation determines the binding operational details.

UK guidance gives another useful implementation perspective. The FCA Financial Crime Guide distinguishes SoW from SoF and explains why both can help a firm assess whether the level and type of transaction are consistent with its knowledge of the customer. The wording and legal basis are UK-specific; they should not be copied into another jurisdiction as if they were a global rule.

In the United States, interagency guidance on customers who may be considered PEPs stresses risk variation and says the CDD rule does not impose unique additional due-diligence procedures simply because a customer is a PEP. That is a useful reminder for global architecture: a PEP = true field should not automatically produce identical evidence requirements in every booking entity.

Collection is not the same as corroboration

A customer explanation is information. A bank may then decide, based on law, policy and risk, whether and how that information should be corroborated. Treating every customer statement as unverified and therefore unusable creates unnecessary friction; treating every statement as established fact creates control weakness.

Corroboration should be proposition-led. If the proposition is "the funds came from salary", evidence already held by the bank may show recurring employer credits over a long period. If the proposition is "the funds came from selling a business", relevant evidence may include ownership records, the transaction agreement, completion records, buyer payment and financial information consistent with the sale. If the proposition is "wealth was inherited", probate or estate material may be relevant where available and appropriate. If the proposition is "wealth came from investments", account statements, trade history, audited records or other evidence may support the explanation.

The quality of evidence depends on independence, relevance and integrity. An official register may confirm ownership but not the market value of an asset. A bank statement can show receipt of money but not necessarily the underlying economic source. A contract can show agreed terms but not always that the transaction completed. Tax material can provide useful corroboration in some jurisdictions and cases, but the bank should not assume it has a legal right to demand or process tax records everywhere. Public information may be reliable for one fact and speculative for another.

A good reviewer therefore asks: what does this evidence actually prove? What does it not prove? Is it independent of the customer? Does it relate to the relevant period and amount? Is the information consistent with other data? Is more evidence necessary to manage the risk, or would additional collection only create volume without insight?

A proportionate corroboration ladder starts with information already held, adds customer explanation where needed, then uses independent evidence and specialist analysis only to the level justified by the risk and the proposition being tested.

Plausibility without pretending to be a forensic accountant

Banks often need to assess plausibility, but they should be careful not to overstate what a KYC review can prove. A relationship manager or KYC analyst is not automatically qualified to determine the fair value of a private company, reconstruct tax liabilities, authenticate complex legal documents or decide whether a virtual-asset transaction is criminal. Specialist support may be required.

Plausibility testing asks whether the explanation broadly fits known facts. Does the customer's occupation and career make the claimed accumulation possible? Does a business exist and operate in the field described? Does the timing of a sale fit the movement of funds? Does the scale of a gift fit information reasonably available about the donor where donor capacity is relevant to the risk? Do the customer's account flows broadly align with the explanation?

The test should allow for ordinary human complexity. People inherit money late in life, sell businesses for unexpectedly high values, receive family support, experience divorce, change countries, make successful investments and hold records of different quality. An unusual outcome is not itself suspicious. The purpose of plausibility analysis is to identify questions that need resolution, not to force every customer into an average-income model.

Analysts should also avoid pseudo-precision. Industry salary data or valuation multiples can provide context, but they do not prove an individual's income or a company's value. Public estimates can be incomplete. Private transactions can occur above or below benchmarks for legitimate reasons. A benchmark is a reason to ask a better question, not a substitute for evidence.

Reconstructing the story across time

SoW work becomes more useful when the bank can see a timeline rather than a static label. Wealth generation is often sequential: employment income creates savings; savings finance an investment; the investment grows; the customer sells it; proceeds are reinvested; a later business or property transaction produces new wealth.

The timeline does not need to account for every minor movement. It should capture the material events needed to make the current financial position understandable. Effective dates matter. An analyst reviewing a 2026 transaction may need to know what the bank knew when the relationship began, which wealth events occurred later and when supporting information was collected.

This is also why versioning matters in systems. Overwriting source_of_wealth = business with source_of_wealth = investments loses history and can create false contradictions. A better data model can store multiple wealth-source categories, narrative context, relevant amounts or ranges where appropriate, effective periods, evidence references, confidence or verification status, the reason for collection, the policy or legal trigger and the date of review.

A wealth timeline separates long-term accumulation events from the immediate funding path for today's transaction. The current source of funds can be one branch of a much longer source-of-wealth history.

Salary, professional income and pensions

Salary is often straightforward because the bank may already observe recurring employer payments and hold occupation information. But it should still avoid treating employer name matching as universal proof. A bonus, equity vesting event, partnership distribution or pension withdrawal may look different from monthly salary and can still be legitimate.

For higher-risk or materially unusual cases, a bank might use employment information, payroll records, regulated-account statements, tax documents where appropriate and lawful, pension statements or employer information. The evidence chosen should match the fact being tested. Long employment history can contribute to SoW even when today's SoF comes from an investment sale funded by earlier earnings.

Business ownership and business sale proceeds

Entrepreneurial wealth often combines operating income, dividends, equity value and a later sale. The bank should separate these elements. Ownership records can support that the customer held the business. Financial statements can help explain its scale. A sale agreement and completion evidence can support the disposal. Payment records can support receipt of proceeds.

The bank does not need to perform an investment-bank-grade valuation for every business sale. If the price is material to the risk and appears inconsistent with available information, additional evidence or specialist review may be appropriate. The key is proportionality. Reputable advisers can strengthen confidence but do not replace the bank's own risk decision where the evidence leaves a material gap.

For companies receiving capital from owners, the same logic can run in the opposite direction. The company may have a clear source of funds from a shareholder injection, while the bank still needs, where relevant, to understand the shareholder's source of wealth or the economic source of the contribution.

Property sale and property wealth

A property sale can be a clear SoF when ownership, sale and receipt are reasonably evidenced. But property itself may have been acquired from earlier wealth, borrowing or inheritance. Whether the bank needs to trace further depends on the purpose of the control and the risk.

A mortgage-funded purchase illustrates why terminology matters. The immediate source of funds for part of the purchase may be a bank loan. The customer's deposit may have a different source, such as savings or a prior property sale. The customer's broader wealth may arise from employment or business income. Recording all three as "property" obscures useful distinctions.

Inheritance, gifts and family support

Inheritance and gifts are legitimate and common. The evidence available varies significantly by jurisdiction, family practice and age of the event. Probate records, estate statements, wills, bank transfers, gift letters and other records can help, but not every jurisdiction produces the same documents and not every family retains old records indefinitely.

When a gift or family transfer is material to the risk, the bank may need to understand the donor relationship and whether the donor could reasonably provide the funds. That does not mean every donor becomes a full customer subject to identical KYC. The extent of inquiry should follow the relevant legal basis, product risk, amount and policy.

A useful distinction is between relationship plausibility and economic provenance. A parent giving money to a child may be entirely plausible as a relationship, but the bank may still need to understand how the funds were generated. Conversely, a large third-party transfer is not suspicious merely because the donor is unrelated. Commercial, legal or investment arrangements can create legitimate third-party funding.

Investment and virtual-asset wealth

Investment wealth should be approached in the same way as other wealth: understand acquisition, holding and realisation to the extent necessary for the risk. Securities account records, custodian statements, broker records and transaction history can often provide a coherent trail.

Virtual assets can add technical complexity because value may move through self-hosted wallets, exchanges, bridges or decentralised protocols. On-chain data can corroborate some transaction facts, such as movement between addresses, but it does not automatically establish who controlled an address or whether the original acquisition was legitimate. Exchange records, fiat funding trails, wallet-control evidence, transaction history and contextual information may need to be considered together.

Analysts should avoid two opposite errors. The first is assuming crypto-origin funds are inherently suspicious. The second is assuming a visible blockchain history proves legitimacy. The proper question is whether the evidence is sufficient and coherent for the risk being assessed. Tax treatment can sometimes corroborate an explanation where relevant and lawfully available, but tax documentation should not be treated as a universal prerequisite or as proof that criminality is absent.

Cash and poorly documented wealth

Cash-heavy customers can be harder to assess because a bank statement showing a cash deposit does not identify the economic origin of the cash. The same problem arises with wealth accumulated in jurisdictions or periods where formal records are limited.

Lack of perfect documentation is not the same as illicit origin. The bank should consider alternative reliable evidence, the customer's occupation and business, transaction history, counterparties, geography, historical account use and other relevant context. Where a required fact cannot be established to the standard demanded by law or policy, the bank must follow that framework. Where the issue is residual uncertainty rather than a hard requirement, the decision should be documented and proportionate.

This is an area where financial inclusion matters. Controls designed only for customers with digitally searchable tax and banking histories can unfairly exclude people whose legitimate economic lives are less formally documented. A risk-based framework should preserve control effectiveness while allowing alternative evidence and reasoned judgment where permitted.

Third-party funding

Third-party funding deserves careful treatment because the customer's explanation may be genuine while the economic source sits with someone else. Common legitimate examples include parents funding education or property deposits, investors subscribing capital, insurers paying claims, employers paying relocation expenses, lenders advancing finance and customers receiving settlement proceeds through lawyers or escrow arrangements.

The bank should identify the relevant party and the economic reason for the payment. If the third party is itself the material source of wealth or funds and the risk requires deeper understanding, the bank may need additional information about that party. The scope should not exceed what is necessary without a legal or policy basis.

Pattern analysis can add value. Repeated transfers from unrelated parties, rapid onward movement, unexplained changes in funders or circular flows can be relevant signals. But they remain signals, not conclusions. Remittance communities, marketplace businesses, family networks and platform models can legitimately create patterns that look complex when viewed without segment context.

Linking SoF and SoW to ongoing monitoring

SoF and SoW should not sit in a static KYC document repository. When material to the customer's risk profile, they can improve ongoing monitoring by giving transaction activity economic context.

Suppose a customer's known wealth is mainly employment income and long-term listed investments. A sudden large incoming payment from the sale of a private company is not automatically suspicious. It is a material new event that may require an update because the activity does not fit the existing profile. If the customer provides a credible explanation and evidence, the bank can update its understanding. If the explanation remains inconsistent or unsupported, the issue can move into enhanced review or investigation.

Monitoring should distinguish deviation, unusual activity and suspicion. A deviation means the activity differs from what was expected or known. Unusual activity means it warrants closer examination. Suspicion is a legal or policy conclusion reached after considering the facts and applicable reporting threshold. Conflating these stages creates excessive alerts, customer friction and weak suspicious-activity reporting.

SoF and SoW can also support post-alert investigation. Investigators should be able to see what the bank previously understood, when that understanding was established, what evidence supported it and whether current activity contradicts or changes the story.

From alert to case and possible reporting

A typical escalation begins with a trigger: monitoring alert, transaction review, periodic KYC review, PEP event, relationship-manager observation, adverse information, large funding event or another control. The case should frame the question before collecting documents. For example: "Does the customer's explanation and available evidence reasonably support that the 750,000 funding is from a business sale?" is better than "Obtain five documents for source of funds."

The analyst then reviews existing information, identifies gaps, obtains proportionate clarification and corroboration, and records what is established, what remains uncertain and why it matters. If the evidence resolves the concern, the case can close with an updated profile where appropriate. If material inconsistency remains, the bank may escalate under its EDD or investigation framework.

If the facts meet the jurisdiction's suspicious activity or suspicious transaction reporting threshold, the authorised function should consider or make the report in accordance with local law. The chapter does not assume that every unresolved SoF or SoW question requires a report, customer exit or transaction rejection. Those decisions depend on the legal threshold, the institution's policy, the product and the evidence.

Customer impact and communication

SoF and SoW requests can feel intrusive because they concern salary, family wealth, inheritances, business ownership and personal transactions. Poorly designed controls can create repeated requests, inconsistent questions and long delays even when the customer has already supplied relevant information elsewhere in the bank.

Good customer communication explains the request in a neutral way, avoids implying wrongdoing, asks only for information relevant to the risk and provides realistic alternatives where acceptable. The bank should reuse verified information where policy and data-governance rules allow rather than asking the customer to repeatedly prove the same fact.

Teams should also plan for vulnerable customers, bereavement, divorce, family disputes and customers with limited digital documentation. A control can be legally correct and still be poorly implemented if it creates avoidable harm or exposes sensitive information to too many staff.

Data and system touchpoints

SoF and SoW data can touch onboarding, KYC platforms, customer master data, beneficial-ownership stores, transaction monitoring, sanctions and PEP screening, case management, document management, relationship-management systems, payment platforms, data warehouses and regulatory reporting processes.

A workable data model should distinguish the source category from the narrative and from evidence. A category such as employment, business ownership, inheritance, gift, investment, property, borrowing or other helps analytics. A narrative explains the customer's circumstances. Evidence references show what supported the conclusion. Verification status should indicate whether information is customer-stated, corroborated, partially corroborated, unresolved or not required under the relevant process.

Effective dating is essential. Systems should know when the information became valid and when it was reviewed. Provenance metadata should show which system or team supplied it. Access controls should protect sensitive documents. Retention should follow law and policy. Free text should not be the only representation because it is difficult to search and compare, but structured fields should not force false precision.

The architecture should also preserve the trigger and purpose for collecting data. A field collected because of a PEP EDD requirement is not the same as one collected voluntarily for private-banking risk management. That distinction matters for privacy, reuse, refresh logic and auditability.

BA and architecture requirements

A business analyst should turn the policy into decisionable requirements rather than a generic "capture source of funds" statement. Requirements should answer when SoF is required, when SoW is required, which customer or connected party the requirement applies to, what evidence options are acceptable, what role can decide sufficiency, what exceptions exist, what jurisdiction overlay applies and what happens when the requirement is unresolved.

The data model should support multiple sources and multiple parties. A customer can have several wealth sources and a transaction can have several funding sources. Each record may need amount or proportion where relevant, currency, time period, evidence references, source system, review status, effective date and reviewer. Not every implementation needs every field, but the design should avoid a single flat label that cannot represent reality.

Workflow design should separate request, receipt, review, clarification, escalation and approval. It should prevent a relationship manager from marking evidence verified merely because a document was uploaded. It should also prevent duplicate requests where another approved bank process already holds valid evidence that policy permits reusing.

Rules should be configuration-driven where jurisdiction or product requirements vary. Hard-coding a universal rule such as "all PEPs require three SoW documents" creates both legal and customer-outcome risk because the applicable obligations and risk vary.

Testing the control

Testing should cover more than whether a mandatory field appears on screen. Positive tests should prove that relevant triggers create the right workflow and that evidence can be linked to the correct customer, party and transaction. Negative tests should prove that the control does not trigger where policy says it is unnecessary.

Boundary tests should cover customers with several wealth sources, joint accounts, legal entities, trusts, third-party funding, multiple currencies and evidence spanning several systems. Event-driven tests should prove that a material change can update SoW without destroying history. Access-control tests should confirm sensitive documents are visible only to authorised roles.

Decision tests should include plausible but incomplete explanations, conflicting evidence, expired information, alternative evidence and cases where no document is required because the bank already has reliable information. Monitoring tests should confirm that SoF and SoW are used as context rather than as deterministic suspicious-activity rules.

Failure-mode testing matters as well. What happens if a document service is unavailable? What happens if a customer responds after the case SLA? Can an analyst see that another team is already reviewing the same funding event? Does the case preserve the evidence used at the time of decision even if the customer record later changes?

Mini case study: the founder funding a new investment account

A long-standing customer opens a new investment account and intends to fund it with 2.4 million. The customer's profile says "technology executive" and shows regular salary and bonus payments. The incoming funds arrive from a law firm's client account with a reference to a company sale.

The payment route alone does not answer SoF. The bank checks its existing records and asks the customer for context. The customer explains that they founded a software company eight years earlier and sold a majority stake. Corporate registry information supports the founder relationship. Transaction documents and completion information support the sale, and the law-firm transfer aligns with the completion mechanics. The amount being invested is consistent with the customer's share of proceeds after considering information available to the bank.

The SoF conclusion is that the investment funding is supported by business-sale proceeds. The SoW profile also changes: the customer's wealth is no longer explained mainly by salary and bonuses; business ownership and disposal now materially contribute to it. The bank records the new wealth event with an effective date and supporting evidence rather than overwriting the old employment history.

During review, the analyst notices that part of the sale consideration is deferred and dependent on future performance. That does not make the transaction suspicious. It changes the expected future pattern: additional sale-related payments may arrive later. The customer profile is updated so monitoring does not treat the next legitimate deferred payment as unexplained merely because the first review failed to capture it.

No universal legal conclusion follows from this fictional case. If the customer were a PEP, booked in another jurisdiction, involved in a higher-risk country or unable to support material aspects of the explanation, the required controls and decision could be different. The point is the method: understand the event, understand the history, corroborate what matters, update the profile and preserve the reasoning.

What good looks like

A strong SoF and SoW control can explain why information was collected, what question it answered, what evidence supported the conclusion and how the result affected the customer risk decision. It does not confuse payment route with economic source. It does not confuse wealth with one current balance. It does not turn PEP status or a large transaction into automatic suspicion. It does not demand the same evidence from every customer.

It also joins KYC to monitoring and investigation. A wealth profile that never reaches downstream controls has limited value. An alert system that ignores well-established legitimate wealth creates false positives. An investigator who cannot see historical provenance may ask the customer the same questions again and reach an inconsistent conclusion.

The end state is therefore not "document collected". It is a current, proportionate and explainable understanding of where relevant value came from, how that understanding was supported, and what the bank should do with it under the applicable legal and risk framework.

Operational deep dive: evidence, corroboration and investigation discipline

Source-of-funds and source-of-wealth work becomes difficult when the customer story spans several years, several legal entities or several forms of value. The answer is not to demand more documents without limit. The answer is to define the proposition, identify what the bank already knows, choose evidence that can actually test the proposition, and escalate only the unresolved parts that matter to the risk.

Start with the proposition, not the document list

A weak workflow starts with a fixed evidence checklist. A stronger workflow starts with a sentence that can be tested. Examples include: "the funds used for this investment came from the customer's sale of Company A"; "the customer's overall wealth is materially explained by twenty years of professional income and equity compensation"; or "the shareholder contribution funding Company B came from the beneficial owner's prior business disposal."

The proposition defines the evidence. A corporate registry may show that a person owned shares, but not what those shares were worth. A bank statement may show receipt of money, but not the underlying economic event. A contract can show agreed terms but may not prove completion. Audited accounts may support the scale of a business but not necessarily the provenance of a particular payment. Each item should therefore be labelled by what it supports and what uncertainty remains.

This approach improves customer experience because it prevents repeated requests for material that cannot answer the question. It also improves auditability because a reviewer can see why evidence was collected.

Information, corroboration and verification status

Banks often use words such as "verified" too loosely. A more useful operating model has several states.

Customer-stated means the information comes from the customer or their representative and has not been independently corroborated. That information can still be useful. Risk-based CDD often begins with customer explanation.

Corroborated means one or more reliable sources support the relevant facts. Corroboration can be partial. A registry may support ownership while transaction documents support a sale, and the payment trail may support receipt.

Unresolved means a material inconsistency or gap remains. Unresolved does not automatically mean suspicious; it means the bank has not yet reached the required level of understanding.

Not required means the institution has determined, under the applicable rule and policy, that additional corroboration is not necessary for that case. Recording this state can be valuable because it prevents future reviewers from assuming a control was missed.

A bank may use different labels, but the distinction matters. A binary verified = yes/no field hides too much. It can also mislead downstream systems into treating a customer statement as independently established.

Independence matters more than volume

Five documents that all originate from the customer may provide less assurance than one reliable independent record. Equally, an independent record is only valuable for the facts it actually establishes.

Consider a business sale. The customer provides a sale agreement, a completion statement and a letter from an adviser. Those are relevant. If all three rely on the same customer-supplied information, however, they may not independently establish the business's historical scale or the customer's ownership. Corporate records, audited accounts, buyer payment evidence or other independent information may add more value than a fourth customer-generated document.

Circular corroboration is a particular risk. A professional may write a letter based on documents supplied by the customer. A commercial database may then reproduce information originally obtained from that same public filing or customer disclosure. The fact that three screens show the same statement does not mean there are three independent sources.

The solution is not to reject professional attestations. It is to understand their basis. An attestation that clearly states what the professional independently reviewed can be useful. One that merely repeats the customer's assertion has a different evidential weight.

Proportionality in corroboration

Proportionality should affect both depth and breadth. A low-risk relationship with a clear funding path may need little beyond information already held. A materially higher-risk relationship may require independent corroboration of the key wealth-generating events and the immediate funding path.

Proportionality does not mean accepting weak evidence because the customer is commercially important. Nor does it mean demanding every historical document because the customer is wealthy. The control should focus on the facts that would change the risk decision.

One useful question is: if this fact were wrong, would the customer risk or transaction decision materially change? If yes, stronger corroboration may be justified. If no, collecting another document may add little control value.

Building a coherent wealth history

Customers can have several wealth sources. The system and analyst should be able to represent them without forcing an artificial single origin.

A plausible history might show professional income from 2001 to 2012, business ownership from 2007 to 2022, a partial business sale in 2022, investment returns from the sale proceeds from 2022 onward, and inheritance in 2025. Today's SoF could be the redemption of an investment bought using part of the 2022 sale proceeds. The SoW history explains the customer's financial capacity; the SoF path explains the current money.

Where amounts are relevant, the bank can use broad ranges or materiality bands rather than pretending to know an exact lifetime net worth. Wolfsberg's public guidance is useful here: SoW due diligence is about understanding wealth-generating activities and plausibility, not necessarily accounting for every unit of net worth.

Historical gaps should be assessed in context. Records may no longer exist, especially for older events. The bank can consider alternative sources, consistency with later records, the customer's observed activity and the materiality of the missing period. If local law or policy demands a particular verification standard, that requirement governs the decision.

Third-party funding: follow the economic reason

Third-party payments create a second analytical layer because the sender, customer and economic source may be different people.

Suppose a parent funds a child's property deposit. The payment sender is the parent, the customer is the child, and the economic reason is a gift. The bank may need to understand the donor relationship and, depending on risk and rules, how the parent obtained the money. It should not automatically subject the donor to every requirement that applies to a customer unless there is a legal or policy basis.

In a corporate setting, a shareholder may inject capital into a company. The company has a legitimate corporate purpose for receiving the funds, but the bank may still need to understand the shareholder's source if the amount, structure or risk warrants it. For an investment fund, insurer, lender or law firm, the relevant question may instead be whether the payment is consistent with the institution's role and the underlying transaction.

Repeated third-party funding can become a monitoring issue. The analyst should compare the pattern with the customer's segment and stated purpose. A marketplace, remittance business or family office can have legitimate repeated third-party flows. The same pattern in a simple personal savings account may require clarification. Context determines meaning.

Legal entities and beneficial owners

For legal entities, source analysis should distinguish the entity's own operating funds from shareholder or beneficial-owner wealth. A profitable company can fund itself from retained earnings without every payment being traced to its owners. A newly formed holding company receiving a large capital contribution may require more focus on the contributor.

The relevant person can also vary by structure. In trusts or similar arrangements, the source may relate to the settlor, contributor or another party depending on who provided the assets and what the applicable CDD rules require. For personal investment companies, the beneficial owner's wealth can be central because the entity itself may have little independent economic activity.

This is where beneficial-ownership data and SoW data should link rather than live in separate silos. If ownership changes, the bank may need to reassess whose wealth supports the structure. Historical ownership should remain visible so an investigator can reconstruct what the bank knew at the time of an earlier transaction.

Plausibility analysis without unsupported certainty

Plausibility is a structured reasonableness test. It should not become a licence to invent precise economic conclusions from weak public data.

For employment wealth, role, employer, tenure and observed income can provide context. For business wealth, company history, financial information, ownership and sale records can provide context. For investment wealth, transaction and custody records can provide context. Public salary estimates, valuation multiples and media reports can support questions but should not be treated as definitive facts about a specific customer.

A useful test is to identify both confirming and disconfirming evidence. Analysts naturally look for inconsistencies after a concern appears. Good practice also records evidence that supports an innocent explanation. This reduces confirmation bias and creates better files for second-line review.

Where specialist questions arise, route them to specialist functions. Legal teams may need to interpret complex ownership or court documents. Tax teams may need to address tax-specific issues where relevant. Fraud specialists may assess document manipulation. Blockchain analytics may help interpret virtual-asset flows. The KYC analyst should coordinate the evidence without pretending to be every specialist at once.

Virtual assets: what the chain can and cannot tell you

Blockchain records can provide strong evidence that value moved between addresses at particular times. They can sometimes show interaction with identified services or addresses associated with known activity. They do not necessarily prove the identity of the person controlling an address, the original lawful source of the asset or the legitimacy of an off-chain transaction.

A robust review may combine exchange records, fiat funding, wallet-control evidence, transaction history, on-chain analysis and customer explanation. The level of effort should follow materiality and risk. A customer who bought a modest amount through a regulated exchange years ago and can show coherent records presents a different problem from a customer claiming life-changing gains through wallets they cannot connect to themselves.

Again, unusual is not automatically suspicious. Early investment, inherited digital assets, mining, staking, business receipts and other legitimate activities can create complex histories. The bank's task is to understand the case sufficiently for the applicable control, not to treat technical complexity as guilt.

Cash and alternative evidence

Cash can be difficult because the payment trail may begin only when the cash enters the financial system. A deposit slip proves the deposit, not the cash's economic source.

For a cash-intensive business, the bank may look at business activity, sales records, tax or accounting information where lawfully available, historical cash patterns, licences, supplier relationships and other evidence appropriate to the sector. For an individual with savings accumulated over time, the evidence may be thinner. The bank should consider whether alternative evidence and long-term account behaviour make the explanation plausible.

This is an important fairness point. An overly rigid document-only model can disadvantage customers in cash-based economies, migrants, older customers or people whose historical wealth predates digital records. The risk-based approach should not become a proxy for wealth or documentation privilege.

Handling inconsistency

An inconsistency should be described precisely. "SoW failed" is less useful than "the customer stated the business was sold in March 2025 for 3.2 million, while the agreement shows a 1.8 million consideration and the account received 1.4 million after fees; the remaining difference is unexplained."

Precision allows a targeted request. The customer may explain that part of the consideration was deferred or paid into another account. The bank can then test that explanation. If the discrepancy remains material, the case can escalate.

Analysts should record the resolution path even when the outcome is benign. Those resolved explanations are valuable for future monitoring and prevent the same legitimate event from repeatedly generating concern.

The verification sequence moves from a defined proposition through existing information, proportionate corroboration and inconsistency resolution to a risk decision. Reporting or restriction occurs only where the applicable threshold and authority are met.

From review to investigation

A source review becomes an investigation when the bank is no longer simply collecting routine CDD information but testing a material concern. The handoff should preserve the original trigger, the customer's explanation, evidence obtained, unresolved issues and any relevant transaction timeline.

Investigators should avoid starting again from zero. Re-asking every question can frustrate the customer and create contradictory internal records. They should focus on the remaining hypotheses: legitimate explanation, documentation error, third-party complexity, fraud, money laundering, corruption, tax crime or another relevant risk depending on the facts.

The case outcome should separate factual findings from legal conclusions. For example, "ownership and sale are corroborated; 600,000 of the funding remains unexplained" is a factual finding. Whether that creates reasonable grounds for suspicion under a particular reporting regime is a legal and policy decision for the authorised process.

Quality assurance and effectiveness

Quality assurance should test reasoning, not just document presence. A complete file with weak logic is not a strong control.

Useful QA questions include whether the analyst distinguished SoF from SoW, identified the correct customer or connected party, used evidence relevant to the proposition, recognised limits in the evidence, considered reasonable alternative explanations, applied the correct jurisdictional rule, recorded the decision and updated downstream customer information where appropriate.

Effectiveness metrics should avoid rewarding document volume. Better measures include repeat-request rates, unresolved-case ageing, proportion of cases where existing bank data was reused, quality defects in rationale, downstream alert reduction after legitimate wealth events were correctly profiled, and issues identified through assurance sampling.

The goal is a control that is selective, explainable and useful. It should increase understanding where provenance matters and stay out of the way where it does not.

Advanced practice: worked source-of-funds and source-of-wealth cases

The cases below are fictional. Amounts and facts are illustrative, and the outcomes are framed as control decisions rather than universal legal conclusions. Their purpose is to practise separating immediate funding from broader wealth, testing explanations fairly and recording what is established, what is unresolved and what should happen next under the applicable framework.

Case 1: business sale proceeds funding an investment portfolio

A customer who has banked with the institution for six years wants to invest an illustrative 3.8 million. The incoming payment is from a solicitor's client account. The customer explains that they sold a 40 percent interest in a logistics company they helped build over fifteen years.

The existing KYC profile records the customer as a company director but does not capture the ownership history. Public corporate information supports that the customer was a long-standing shareholder. The customer supplies the sale agreement and completion statement. Payment information supports transfer from the solicitor associated with the transaction. The price is broadly consistent with financial information available about the company, although the bank does not attempt to produce its own formal valuation.

For SoF, the bank can reasonably connect the investment funding to sale proceeds. For SoW, the sale is also a material wealth-generating event, but it is not the customer's only wealth source: earlier salary, dividends and other investments remain relevant. The profile is updated with the sale event and effective date.

The practical lesson is that the same event can be both today's SoF and an important part of long-term SoW. The bank does not need to reconstruct every historical business transaction once the material proposition is adequately supported for the risk.

Case 2: inheritance with old and incomplete records

A customer in their seventies receives an illustrative 900,000 from an estate account and says the money is an inheritance from a sibling. The customer can provide estate correspondence, a bank credit and an executor's letter, but the deceased person's financial records are limited.

The analyst initially requests a long list of historical documents that the customer cannot obtain. A second reviewer reframes the proposition: does available evidence reasonably support that the payment is an estate distribution and that the amount is plausible in the context of the estate?

The bank verifies the executor relationship through available records, confirms the transfer path and reviews estate information sufficient to support the distribution. No material inconsistency remains. The customer has no other elevated risk factor requiring a deeper reconstruction.

The case closes without demanding documents that no longer exist. The learning point is that incomplete historical documentation does not equal unexplained wealth. Alternative evidence, risk level and the actual decision being made matter.

Case 3: family gift with a donor-capacity question

A first-time home buyer receives an illustrative 250,000 from a parent for a deposit. The parent is not a customer of the bank. The transfer comes directly from an account in the parent's name, and the customer provides a gift declaration.

The gift relationship is plausible, but the amount is large relative to what the bank knows about the customer. Policy requires additional understanding of material third-party funding in this product. The bank asks proportionate questions about the parent's source. The customer explains that the parent recently sold a property and provides evidence of the sale and transfer into the parent's account before the gift.

The bank does not perform full customer onboarding on the parent simply because they are the donor. It collects enough information to satisfy the relevant third-party funding control. The gift is accepted as the SoF for the deposit; the customer's own SoW remains modest and primarily employment-based.

The lesson is that SoF can come from another person's wealth. The analysis should follow the economic source while keeping the scope proportionate to the legal and policy basis.

Case 4: large virtual-asset proceeds with a coherent history

A technology professional intends to transfer an illustrative 1.6 million from a regulated virtual-asset exchange to a private-banking account. The customer says the value came from digital assets bought gradually between 2017 and 2020 using employment income and later sold in 2026.

The bank reviews exchange statements, historic fiat funding, relevant wallet and transaction information and the incoming transfer from the exchange. The records show purchases over time rather than a sudden recent acquisition. The customer's employment and income history make the initial investment plausible. On-chain analysis supports parts of the movement history but is treated as corroboration of transactions, not proof of identity or legality by itself.

There is no material contradiction. The bank records investment gains as a material SoW contributor and the exchange redemption as the immediate SoF. Monitoring is calibrated to the updated profile rather than treating every future transfer from the same regulated venue as inherently suspicious.

The lesson is that virtual-asset provenance should be evidence-led. Neither blanket rejection nor blanket acceptance based on blockchain visibility is sound risk management.

Case 5: unexplained company funding through a connected party

A newly incorporated consulting company receives an illustrative 2 million capital contribution from another company incorporated abroad. The account-opening file describes the funding as shareholder capital, but corporate records show that the sender is not a direct shareholder. Both companies are ultimately controlled by the same beneficial owner through different holding structures.

The payment is therefore not adequately explained by the original label. The bank asks for the commercial and legal basis of the contribution. The customer provides an intercompany funding agreement, but the agreement was executed after the payment and does not explain why this entity provided the funds. The beneficial owner says the money ultimately came from earlier business profits but cannot yet provide records linking those profits to the funding entity.

The bank records the SoF proposition as unresolved and escalates under its higher-risk corporate CDD process. It does not describe the payment as criminal merely because the structure is complex. Further work focuses on the funding entity's economic activity, the beneficial owner's relationship to it and the origin of the contributed value.

If the unresolved facts later meet the applicable suspicious-reporting threshold, that decision would be made under local law. Until then, the file should distinguish what is known from what is suspected.

The lesson is that connected-party labels do not replace provenance. Corporate structures often require the bank to trace economic source beyond the immediate sender, but the depth must still follow risk and law.

Case 6: a PEP with established professional wealth and a new private investment

A customer becomes classified as a foreign PEP after taking a prominent public function. The customer has banked with the institution for ten years. Their existing wealth was built before public office through a professional-services partnership and long-term investments. A new transaction involves an illustrative 600,000 investment into a private company.

The PEP event triggers the institution's enhanced process under the applicable booking-jurisdiction rules. Existing SoW information is reviewed rather than collected from scratch. The bank refreshes evidence around the major wealth sources and examines the SoF for the new investment. The funds come from a long-held investment account already known to the bank, and the transaction is consistent with the customer's established financial capacity.

The enhanced review also checks whether the private-company investment creates new corruption, conflict-of-interest or geographic risks. No material concern is identified on the available facts. Senior approval is obtained because local policy requires it for this relationship category.

The outcome is continued banking with updated records and monitoring. PEP status did not predetermine an adverse decision; it changed the level of scrutiny and governance.

The lesson reflects FATF's preventive approach. PEP controls are designed to manage increased corruption-related risk, not to assume criminal conduct. Source analysis should be rigorous, evidence-based and proportionate.

Case 7: a property sale that explains the funds but not the whole relationship

A customer receives an illustrative 1.1 million from a property sale. Ownership records, the sale agreement and the payment trail support the transaction. The SoF is clear.

During the review, however, the analyst notices that the customer owns several other properties that were not previously recorded and that the customer's profile still lists them as a salaried employee with limited income. The property sale does not itself create suspicion, but it reveals that the customer profile is materially stale.

The bank therefore completes the transaction-specific SoF review and separately refreshes SoW and customer-risk information. The customer explains that most properties were inherited jointly with siblings and provides information that broadly supports the history. The risk rating remains unchanged after review.

The learning point is that a clear SoF conclusion does not necessarily answer the broader SoW question. It may instead reveal that the relationship needs updating.

Case 8: recurring third-party credits in a personal account

A personal customer receives twenty-five credits over four months from unrelated individuals. Each transfer is modest. When combined, however, the value is material relative to the customer's known salary. The payment references contain first names and short descriptions such as "order" and "delivery".

The pattern could have several explanations: undeclared business activity, marketplace selling, community collection, remittance pooling or misuse of the account. The bank does not jump directly to a laundering conclusion. It asks the customer about the activity and reviews available transaction context.

The customer explains that they have started a small online catering business. They provide evidence of the business registration and order activity. The bank determines that the account is being used in a way that differs from the product's intended use and updates the customer relationship under its product and CDD process. Whether the customer must move to a business account is a product decision, not an AML guilt finding.

The SoF of the credits is customer payments for goods or services; the customer's emerging business income may also become part of SoW over time. Monitoring can now use the corrected purpose rather than treating all customer credits as unexplained.

The lesson is that source analysis often discovers ordinary changes in economic life. Good controls identify those changes without turning every mismatch into suspicion.

How to write the case conclusion

A strong conclusion normally answers five questions in plain language. What was the claimed source? What evidence supported it? What material inconsistency, if any, remained? How did the finding change the customer or transaction risk? What action followed under the applicable framework?

The conclusion should avoid phrases such as "source of wealth verified" if only one part of the wealth story was corroborated. It should avoid "suspicious" where the analyst only means unusual. It should also avoid automatic outcomes such as exit or reporting unless those outcomes genuinely follow from policy and the relevant legal threshold.

The discipline is simple: explain the facts, explain the uncertainty, explain the decision.

Practice close: a usable source review playbook

A good source review should be easy for another practitioner to follow. The file should show the question, the evidence, the reasoning and the outcome without requiring the reviewer to infer what happened from a document pile.

Step 1: define why the review exists

Record the trigger. It may be an onboarding requirement, an enhanced due-diligence trigger, a PEP control, a large or unusual funding event, periodic review, a monitoring alert, a third-party payment or another policy requirement.

Then state whether the control needs SoF, SoW or both. This sounds basic, but many weak files ask for wealth evidence when the question is only about one transaction, or collect a transaction receipt when the real concern is unexplained overall wealth.

Step 2: write the proposition

Turn the customer's explanation into a testable statement.

Instead of "business sale", write: "The customer states that the 1.7 million received on 4 August 2026 represents proceeds from selling their 35 percent interest in Company X."

Instead of "family wealth", write: "The customer states that inherited property and a family business materially explain their current net worth."

A precise proposition makes evidence review much easier.

Step 3: check what the bank already knows

Before contacting the customer, search approved internal sources. Existing KYC, historical account activity, prior source reviews, lending files, investment records and relationship-management information may already answer part of the question.

Reuse should be governed. Old information can be stale, and data collected for another purpose may have restrictions on reuse. But asking the customer for information the bank already holds and trusts creates unnecessary friction and duplicate records.

Step 4: identify only material gaps

List the facts that remain unresolved and explain why each matters. For a business sale this might be ownership, sale completion and receipt of proceeds. For an inheritance it might be the link to the estate and the distribution amount. For investment gains it might be acquisition, holding and realisation.

Do not convert a broad concern into a generic request for every document the customer possesses.

Step 5: choose proportionate evidence

Evidence should be relevant, reliable and as independent as reasonably needed for the risk. Consider whether information already held is sufficient before requesting new material.

When several evidence types are available, prefer the combination that directly tests the proposition. Avoid collecting three versions of the same fact while leaving the real uncertainty untouched.

Step 6: record evidence limits

Every source has limits. A registry can confirm ownership but may not show value. A bank statement can confirm receipt but not the economic source. A customer declaration can explain context but may need corroboration. A blockchain transaction can show movement between addresses but not necessarily identity or lawful origin.

Writing these limits into the case prevents later reviewers from giving evidence more weight than it deserves.

Step 7: resolve inconsistencies fairly

Describe the inconsistency precisely and give the customer a reasonable opportunity to explain it where appropriate. Timing differences, fees, deferred consideration, currency conversion, joint ownership and document conventions can create apparent mismatches.

If the explanation resolves the issue and is supported as required, record the resolution. If a material gap remains, escalate it rather than silently converting uncertainty into either acceptance or suspicion.

Step 8: make the risk decision

The decision should follow the applicable legal and policy framework. Possible outcomes include accepting the explanation, updating the profile, requesting further information, escalating for enhanced review, seeking senior approval, changing monitoring, restricting activity where authorised, considering reporting, declining a transaction or reviewing the relationship.

There is no universal outcome for an unresolved source question. The same evidence can lead to different actions depending on jurisdiction, product, customer risk and legal threshold.

Step 9: update the customer record

If the review establishes a material new wealth event or funding pattern, make sure the structured customer profile is updated. Otherwise the bank may resolve the case today and generate the same alert tomorrow.

Preserve history. Do not overwrite a prior wealth source when a new one is added unless the old information was actually wrong.

Step 10: leave an audit trail another person can understand

A concise closing rationale can follow this form:

Trigger: why the review occurred.

Claim: what the customer said.

Evidence: what information supported or contradicted the claim.

Assessment: what is established, partially supported or unresolved.

Risk impact: whether customer or transaction risk changed.

Outcome: what action followed and under which authority or process.

This format is useful for operations, second line, audit and investigations because it separates facts from conclusions.

BA acceptance criteria

A delivery team implementing source controls should be able to demonstrate the following behaviours:

  1. The workflow can distinguish SoF, SoW and combined reviews.
  2. The trigger and jurisdiction or policy basis are stored with the case.
  3. Multiple source categories and multiple connected parties can be recorded.
  4. Evidence is linked to the proposition it supports rather than only to the customer record generally.
  5. Review status distinguishes customer-stated, corroborated, partially corroborated, unresolved and not-required states or equivalent controlled statuses.
  6. Effective dates and history are preserved.
  7. Sensitive evidence has role-based access and appropriate retention.
  8. Existing approved information can be reused without forcing duplicate customer requests.
  9. The workflow supports clarification and escalation without automatically labelling the customer suspicious.
  10. A completed review can update monitoring context and customer risk where appropriate.

Test scenarios that matter

A test pack should include a simple salary-funded transaction, a business sale, inheritance with partial records, a material family gift, a PEP review, a legal entity with shareholder funding, a virtual-asset realisation, a cash-intensive business and a case where the customer explanation changes after clarification.

The test should verify not only that the screen works but that the right facts survive through case creation, approval, profile update and downstream monitoring.

The most valuable failure-mode test is often duplication: can two teams independently ask the same customer for different evidence about the same event because they cannot see each other's work? If yes, the technical control is creating customer harm and inconsistent financial-crime evidence even if every mandatory field passes validation.

Final practitioner check

Before closing a source review, ask:

  • Do I know whether I was assessing SoF, SoW or both?
  • Can I state the customer's explanation in one clear sentence?
  • Does the evidence support the important parts of that sentence?
  • Have I recorded what the evidence does not establish?
  • Have I considered a reasonable innocent explanation for any mismatch?
  • Is the depth of review proportionate to the risk and the applicable rule?
  • Have I separated unusual activity from a suspicion conclusion?
  • Will the next analyst be able to understand the decision without contacting the customer again?

If the answer to those questions is yes, the file is far more likely to be useful than one measured only by document count.

Masterclass: governing source information across a bank

Source controls often fail because responsibility is fragmented. Relationship teams know the customer but may not own evidence standards. KYC operations collect documents but may not see later transactions. Monitoring teams see activity but may not know why a wealth event was accepted. Investigators can discover better information but fail to feed it back into the customer profile. Technology teams are then asked to automate a control whose ownership and decision logic are unclear.

The solution is not to centralise every decision in one team. It is to define decision rights and data responsibilities across the lifecycle.

Source-of-funds and source-of-wealth governance connects relationship ownership, KYC operations, financial crime oversight, investigations, data and assurance around a versioned customer provenance record.

First line: know the commercial reality

The relationship or product team is often best placed to explain why the customer needs the product, what business they operate and whether a funding event makes commercial sense. That team should not be expected to make every specialist financial-crime judgment, but it should own accurate customer context and avoid treating source requests as an administrative obstacle.

Relationship teams also need clear boundaries. Commercial importance must not lower evidence standards. At the same time, the control should not ask them to obtain sensitive documents that policy does not require simply because an analyst prefers more certainty.

KYC and operations: own the evidence workflow

KYC operations should translate policy into consistent evidence collection and recording. Their role includes checking that the right party is being assessed, distinguishing SoF from SoW, identifying missing information, linking evidence to the proposition and maintaining the customer profile.

The workflow should support judgment. If policy allows several evidence routes, the system should not force analysts into a single document type. If a case falls outside analyst authority, escalation should be clear and fast.

Financial crime compliance: set the framework and challenge outcomes

Compliance should define the risk-based principles, jurisdiction overlays, mandatory triggers, escalation standards and reporting interfaces. It should also challenge whether the control is effective, not just whether procedures exist.

Important policy questions include when SoW is required, whether SoF can be satisfied from information already held, what additional measures apply to PEPs in each booking jurisdiction, when third-party funding requires information about the third party, who can approve exceptions and how unresolved source issues interact with suspicious-reporting processes.

Group policy should make room for local law. FATF establishes global standards, but implementation differs. A policy that says "all PEPs everywhere require the same evidence" can be both over-inclusive and under-inclusive because national rules and risk can differ.

Investigations: feed learning back into KYC

Investigators often discover the best provenance information in the bank. They may resolve a complex business sale, identify a legitimate inheritance, uncover an undisclosed business or establish that a customer's explanation was materially false.

That information should not remain trapped in a case system. Where lawful and appropriate, the customer profile should be updated so future monitoring and reviews use the improved understanding. The bank also needs confidentiality controls: suspicious-activity reporting information and other protected material cannot simply be copied into customer-facing workflows.

The integration should therefore distinguish reusable factual customer information from restricted investigative information.

Data and technology: preserve meaning

A source field without metadata is dangerous. Technology should preserve who the source relates to, what source category applies, what narrative explains it, which evidence supports it, what the verification status is, when the information became effective, why it was collected and which team last reviewed it.

The model should also support many-to-many relationships. One wealth source can support several products; one transaction can draw on several funding sources; one legal entity can receive funding from several shareholders; one customer can have several material wealth sources.

APIs should not reduce this to sourceOfWealth: "business". A useful service contract might return structured categories together with narrative, effective dates, status and evidence references, while ensuring sensitive documents remain in secure repositories rather than being distributed through every consuming system.

Monitoring and analytics: use source data as context

Source information can improve monitoring, but it should rarely become a deterministic rule on its own. A customer with established business-sale wealth may legitimately make large investments. A customer with salary-based wealth can still receive a legitimate inheritance. Monitoring should detect material change and inconsistency, then route it for review.

Analytics teams should track whether source-profile updates reduce repeat false positives without suppressing genuine risk. They should also watch for stale profiles: if every alert is explained as a "new wealth event" but the KYC profile never changes, the operating model is broken.

Assurance: test reasoning and customer outcomes

Second-line testing and internal audit should sample the full chain. Was the trigger correct? Was the scope proportionate? Did evidence support the proposition? Were jurisdictional rules applied correctly? Was the decision within authority? Was the profile updated? Were protected reports kept confidential? Did the customer receive repeated or contradictory requests?

Assurance should challenge both under-control and over-control. Accepting unexplained high-risk funding can expose the bank to financial crime. Requiring intrusive wealth documentation from low-risk customers without a legal or risk basis can create conduct, privacy and financial-inclusion problems.

Management information that is actually useful

Volume metrics alone do not show effectiveness. Better management information can include ageing of unresolved source reviews, repeat customer requests, proportion of cases resolved using information already held, escalations by trigger, quality defects by cause, jurisdiction-overlay errors, profile updates created from investigations, complaints arising from source requests and assurance findings.

A spike in requests may mean risk increased, but it may also mean a new rule was misconfigured. A falling escalation rate may mean better first-line quality, or it may mean analysts are closing difficult cases too easily. Metrics need interpretation.

A governance scenario

Imagine a global bank launches a new investment product. Product teams want one onboarding workflow across ten countries. Compliance specifies that source controls vary by customer type, risk and local rules. Technology proposes a single mandatory SoW document field because it is easy to implement.

That design would be wrong even if it appears controlled. Some customers may not require SoW collection. Some may require information but not a specific document. PEP rules and EDD triggers can differ. A document-only field also cannot represent multiple wealth sources or evidence already held by the bank.

The better design has a policy-decision service or configuration layer that determines whether SoF, SoW or both are required; which party is in scope; what evidence options are allowed; what approval is needed; and what happens when the requirement cannot be met. The KYC platform then executes the decision and preserves the rationale.

This is the central governance lesson: standardise the control architecture, not the customer answer. A bank can have one consistent method for triggering, evidencing, deciding and auditing source reviews while still applying different evidence depth to different risks and jurisdictions.

Knowledge checks with explained answers

1. A customer transfers 500,000 from an account in their own name at another bank. Is that enough to establish source of funds?

Not necessarily. It establishes the immediate payment route and may be useful evidence, but SoF asks how the customer obtained the money. The underlying source might be salary savings, a property sale, investment redemption, inheritance or another event. Whether the bank needs more information depends on the applicable rule, risk and what it already knows.

2. Does source of wealth require the bank to prove every unit of a customer's net worth?

No as a general proposition. Public Wolfsberg guidance for private banking describes SoW as understanding the economic, business or commercial activities that generated or materially contributed to overall wealth and says the purpose is not necessarily to account for or verify the exact value of total net worth. Local law and policy can impose more specific requirements in particular circumstances.

3. Is a large transaction automatically a reason to file a suspicious activity report?

No. Size can be a risk factor or review trigger, but suspicion is a separate conclusion under the applicable legal threshold. A large transaction can be completely legitimate. The bank should understand the event and consider the full context.

4. A PEP has long-standing wealth from a documented business career. Does PEP status mean the bank should exit the relationship?

No. FATF describes PEP measures as preventive and does not equate PEP status with criminality. The bank should apply the enhanced measures required by the applicable framework, assess risk and follow its approval and monitoring processes. The outcome depends on evidence and jurisdiction, not the label alone.

5. Can a bank statement verify source of wealth?

It can corroborate balances and movements, but it usually does not explain by itself how wealth was generated. A statement showing 2 million in an account does not tell the bank whether that wealth came from employment, business ownership, investment gains, inheritance or another source.

6. What is the difference between customer-stated and corroborated information?

Customer-stated information is an explanation provided by the customer or representative. Corroborated information has support from other reliable evidence appropriate to the proposition. The distinction should be recorded because downstream users need to know how much weight the information carries.

7. If two documents say the same thing, is that automatically stronger corroboration?

No. They may rely on the same underlying source. Evidence quality depends on relevance, independence and integrity, not document count.

8. Why should SoF and SoW have effective dates?

Because customer circumstances change. A business sale in 2026 may become a major wealth source even though the customer's earlier wealth came from salary and investments. Effective dating preserves history and lets investigators understand what the bank knew at a particular time.

9. A customer cannot produce an old inheritance document. Does that prove the explanation is false?

No. Historical records can be unavailable. The bank should consider the applicable requirement, materiality, alternative evidence and other facts. If a mandatory fact cannot be established to the required standard, the relevant legal or policy consequence applies; otherwise the bank should make a proportionate risk decision.

10. What should happen when a SoF explanation differs from the existing customer profile?

Treat the difference as a signal to clarify, not as automatic suspicion. The explanation may reflect a legitimate life event or stale KYC. If supported, update the profile. If material inconsistencies remain, escalate under the relevant EDD or investigation process.

11. Does on-chain blockchain history prove that virtual-asset wealth is legitimate?

No. It can corroborate transaction movement but may not prove address ownership, economic purpose or lawful original acquisition. It should be combined with other relevant evidence where needed.

12. What is a good closing sentence for a source review?

A good close states the claim, the evidence, any unresolved material gap, the risk impact and the action. For example: "The 700,000 funding is supported as proceeds from the customer's 2026 property sale through ownership, sale and payment evidence; no material inconsistency remains, and the profile has been updated to record the disposal."

Glossary

Source of funds (SoF): The economic origin of money or assets used for a particular transaction, product or relationship. It is more than the account from which the money was transferred.

Source of wealth (SoW): The activities or events that generated or materially contributed to a customer's or relevant beneficial owner's overall wealth over time.

Proposition: A specific statement the bank is trying to establish, such as "the funds came from the sale of Company X."

Corroboration: Supporting a proposition with relevant evidence, ideally including independent sources to the degree justified by risk and the applicable requirement.

Customer-stated information: Information provided by the customer or representative that has not necessarily been independently corroborated.

Independent source: Evidence originating outside the customer and sufficiently separate from the customer's own assertion for the fact being tested.

Circular corroboration: Multiple apparent sources repeating information that ultimately originates from the same underlying assertion or record.

Plausibility: Whether an explanation is reasonably consistent with known facts. Plausibility is not the same as proof.

Effective date: The date from which a customer fact or source event is considered relevant or valid for the relationship.

Third-party funding: Funding provided by a person or entity other than the customer or account holder, such as a parent, shareholder, lender, insurer or investor.

Unresolved source: A source explanation for which a material information or evidence gap remains after proportionate review.

Profile mismatch: Activity that differs from what the bank currently knows or expects about the customer. It can justify review but is not automatically suspicious.

Enhanced due diligence (EDD): Additional CDD measures applied where required by applicable law, regulation or risk-based policy. The exact measures and triggers vary by jurisdiction and context.

PEP: A politically exposed person as defined by the applicable framework. FATF's PEP measures are preventive and risk-based in important respects; national implementation determines binding requirements.

Suspicion: A legal or policy conclusion under the applicable reporting regime. It should not be used as shorthand for unusual activity or incomplete information.

References and further reading

The chapter uses these sources for the distinction between source of funds and source of wealth, risk-based customer due diligence, PEP controls, proportionality and jurisdiction-specific examples. FATF provides global standards, but national and regional law determines the binding obligations for a live customer decision.

Accuracy note — reviewed 17 September 2026: The chapter deliberately avoids a universal rule that every customer or every large transaction requires the same SoF or SoW evidence. PEP, enhanced-due-diligence, reporting, recordkeeping and customer-action requirements differ by jurisdiction, entity, product and risk. The binding local framework and current institutional policy must be checked for live cases.