Field Notes
How we size KYC file samples before a partner-bank visit
Partner banks rarely ask for “all files.” They ask whether your stated KYC procedure shows up in the folders you actually keep. Sample size is where those conversations get tense.
Start from the risk bands you already use
If your policy already splits customers into lower, standard, and higher due-diligence bands, build the sample from those bands rather than from a single random draw across the whole book. A thin sample of higher-risk files tells a partner more than a large sample of low-risk retail wallets.
Fix the period before you fix the count
Agree whether you are testing new onboardings in the last quarter, refreshes overdue this year, or a mix. Mixing without saying so makes findings hard to defend later.
Write the method into the working papers
Infrastructure Sync records the population definition, exclusion rules (test accounts, staff wallets), and how replacements were chosen when a file was inaccessible. That paragraph is often what a partner’s own auditor reads first.
What “enough” usually means in practice
For a mid-sized e-wallet preparing for a bank visit, we often see cohorts of 25–40 higher-risk files plus a smaller standard-risk control set. Exact numbers depend on how concentrated your book is — we settle this on the scoping call, not in a marketing brochure.