09 Feb 2026

Mapping AML controls onto application event logs

A control matrix that names “enhanced due diligence” but cannot point to an event type is decoration. Mapping is the unglamorous fix.

Symbolic lock over a laptop representing application controls

AML frameworks love nouns: screening, EDD, periodic review, source of funds. KYC verification applications love verbs with timestamps: requested, received, failed, overridden, expired. Financial audit lives in the verbs, because verbs can be sampled and joined to money. The mapping exercise is simply writing, for each control you intend to test, which event types would prove it operated.

Take “watchlist hits are reviewed before the customer can pay out.” The events you need might be: hit created, queue entered, reviewer assigned, decision recorded, payout permission flipped. If the application logs only “hit created” and “customer active,” you do not have operating effectiveness evidence for the review. You have a toaster light.

A table that fits on one page

We ask lab seats to fill five columns: control statement, assertion (often completeness or cut-off), event type(s), what absence means, and where the financial join would land. Absence matters. If EDD is required above a threshold and the log never shows an EDD workflow starting, that is not “no news is good news.” It is a missing event you must treat as an exception or as a scope limit if the log cannot contain it.

Vendor-hosted screening is a frequent hole. The KYC application may store a boolean “cleared” while the reasoning lives in another tenant you cannot see. Map that honestly: your test of operating effectiveness stops at the boolean unless the firm can export the vendor decision payload. Do not invent a review you did not inspect. The attestation essay covers what the vendor letter can and cannot patch.

Periodic review is not an onboarding log

Many KYC apps were built for day-zero verification. Periodic refresh is a different event family: trigger, outreach, new document, new screen, decision to restrict. If you are financially auditing restrictions — frozen balances, declined cards — you need those later events, not a prettier version of the onboarding sample. Mixing them inflates a false comfort that “KYC works.”

GB programmes often discover this during a thematic review, when someone finally asks whether a restriction in the application matched a restriction in the ledger. Mapping first would have made that question cheaper. It is also why our control ledger sketch starts with event families rather than policy chapters.

If you cannot get logs at all, stop mapping and write the limitation. A colourful matrix with no extract is worse than a one-paragraph scope cut. We would rather you test one control that exists as an event than ten that exist as slides.

← Field notes