Financial audit of KYC verification applications fails early when the auditor accepts the product’s own grain. Product people count users. Accounting cares about events that should have created (or prevented) a booking. Those are not the same table.
Start by writing the assertion in a sentence a partner will not rewrite: for example, “Every account that reached funded status in March had a completed verification event whose vendor path is identified.” That sentence tells you the population is funded accounts, not selfie attempts. A different assertion — “every watchlist hit was either cleared or blocked before payout” — produces a different population entirely. Mixing them in one sample is how files become anecdotal.
Exports lie in boring ways
Most KYC applications dump a CSV that collapses retries. You will see one row per applicant and a last status. That is convenient and often wrong for completeness testing. Ask for the event log, even if it is ugly: timestamps, vendor callback IDs, HTTP-ish error codes, and the operator who overrode a fail. If the firm cannot produce that log, document the limitation before you sample. Do not silently sample the pretty CSV and later claim you tested overrides.
In the lab we use a synthetic pack where 18% of “success” rows have a prior fail with no operator note. Trainees who skip the event log miss all of them. That is the point of the pack.
Strata that earn their keep
Useful strata for this topic are rarely demographic. Prefer channel (app vs assisted desk), vendor path (IDV-A vs IDV-B), outcome (pass, fail, override), and whether a financial event followed within a cut-off window you defined. Age of customer is a weak stratum unless your assertion is about simplified due diligence thresholds.
Write a skip log. “Could not open the PDF” is a skip with a reason. “Looked dull” is not. Committees in GB have seen both. Only one survives.
How large is large enough
We do not teach a magic number. We teach a recorded rationale: expected exception rate, what an exception costs in the assertion, and what you will do if the first wave is clean. If you stop at 25 photogenic fails, you have a gallery, not a sample. Module 02 of the KYC Application Audit Lab spends a full sitting on that rationale so it exists before anyone opens a file.
When the application log is messier than the policy PDF — it always is — the sample instruction should say so. Policy is criteria. The log is the condition’s raw material. Pretending they match is how KYC application audits become theatre.