Sampling practice
How we size a KYC sample for a payment institution
When a payment institution asks for a “statistically significant” KYC sample, they often want a number that sounds scientific. In audits for fintech, the better question is whether the sample can survive a supervisor’s follow-up: why these files, why this corridor, why this period.
We start with the population that matters for the review window — usually new customers onboarded in the last quarter, plus a smaller pull of higher-risk refresh cases. Volume alone does not dictate size. A firm processing a handful of high-value remittance corridors may need denser sampling than a high-volume domestic wallet with clean exception rates.
Next we layer risk filters the firm already claims to use: nationality combinations, occupation codes, and product switches. If those filters exist on paper but not in the extract, that gap becomes a finding before we even open a folder.
We document the rationale in the scope note so management cannot later claim surprise. A sample of forty files is not magic; it is a working set large enough to show patterns and small enough to finish within the engagement calendar. If early testing reveals systemic breaks — missing beneficial ownership forms, for example — we pause and propose an expanded pull rather than pretending the first number was sacred.
The output your board should receive is not a percentage with false precision. It is a clear statement of what was tested, what broke, and which owners will fix the trail before the next regulatory conversation.