KYC and customer onboarding with an analyst in the loop
In short
A KYC onboarding agent reads the documents a new customer submits, extracts the fields your policy needs, pulls results from the screening, registry and identity verification services you already use, and applies your risk rules to propose a rating. An analyst reviews the prepared file and approves, edits or rejects before any account is opened, and every step is traced for examiners. Built for retail, business and private banking onboarding teams, and for periodic KYC reviews that run on a schedule.
The problem
Onboarding teams spend most of each case collecting and re-keying: identity documents, proof of address, company registry extracts, ownership details, source-of-funds letters. Screening hits have to be looked up and cleared one by one, periodic reviews pile up on the calendar, and every file has to show an examiner why the customer was accepted at the rating they got. Customers wait for an account while analysts do work a system could prepare, and the judgment calls that actually need an analyst get the least time.
What it moves
- Time to onboard
- Time from a complete application to an opened account, by customer segment.
- Analyst time per file
- How long an analyst spends on a prepared file compared with assembling it by hand.
- Rework rate
- How often files come back for missing documents or corrections.
- Periodic review backlog
- How many reviews are overdue, and whether scheduled reviews start on time.
How the agent works
Step 1
Application arrives
A new customer's application and documents arrive from your onboarding portal, a relationship manager's upload or an email inbox, as PDFs, scans or images.
Step 2
Read and extract
Documents are converted to text with a vision-capable model and extracted into a fixed schema, such as names, dates of birth, addresses, registration details, directors and owners, with the source page for every field.
Step 3
Gather screening results
Prompt injection detection runs on document text before any model reasons over it, and the agent calls your sanctions screening, company registry and identity verification providers over API for their results.
Step 4
Apply your risk rules
Rules nodes apply your policy deterministically, by jurisdiction, product, ownership and screening outcome, to propose a risk rating and list what is missing or inconsistent.
- Human review
Step 5
Analyst review
The prepared file, with extracted fields, screening results, the proposed rating and any gaps, pauses for an analyst to approve, edit or reject, or to request missing documents.
Step 6
Open and schedule
Once approved, the agent sends the account opening request to your core banking or CRM system over API, files the case with its trace, and records the next review date for the scheduled periodic review to pick up.
Controls
Self-host in your own AWS, Azure, GCP, IBM Cloud, OpenShift or Kubernetes environment, or run on Dynamiq Cloud, so customer documents stay in the infrastructure you choose. Our engineers build the extraction schema, risk rules and review step with your onboarding and compliance teams, and test them on past files before a live application reaches the agent.
- Rules your experts own
- Risk scoring and document requirements run as decision tables your compliance team can read and edit, with effective dates for each policy change.
- An analyst decides every account
- The agent prepares the file and proposes a rating. Opening, declining or escalating an account always needs a person's approval.
- Rules you can read
- Risk rules run as deterministic nodes, not a model's judgment, so the same file gets the same outcome and a reviewer can see which rule fired.
- Source page on every field
- Each extracted field links to the document and page it came from, so an analyst checks the evidence, not a summary.
- No wider access than the analyst
- Onboarding runs in a private project, and database access can resolve to each analyst's own credentials, so the agent never sees more than the analyst could.
- Examiner-ready trail
- Every run is traced and replayable, from the documents read to the screening results, the rule that set the rating and the analyst's decision.
Systems it connects to
- Onboarding portals and document inboxes
- Sanctions, PEP and adverse media screening, over API
- Company registries and identity verification providers, over API
- Core banking and CRM (Salesforce, Microsoft Dynamics 365), over API
- Case management (Jira, ServiceNow)
- Document storage (SharePoint, Box, Google Drive)
- Slack and Microsoft Teams for analyst review
- Your KYC policy and risk methodology as a knowledge base
Built with
- Agent BuilderDesign an agent on a visual canvas or in the open-source Python SDK. Both compile to the same engine, so what you build ships either way.
- KnowledgeA knowledge base converts your documents into searchable context: ingestion, chunking, embedding and storage, managed for you or pointed at your own vector store.
- Guardrails and approvalsDetect PII and prompt injection before a model sees them, enforce content policies, and pause tool steps for a person to approve.
- ObservabilityEvery run is traced and replayable, node by node, with the cost, latency and tokens each step used.
Industries
- Financial servicesBack-office automation, customer service by phone and chat, and KYC and AML work, on one governed platform your compliance team can audit.
- InsuranceAnswer policyholders by phone and chat, prepare claims and underwriting files, and keep an adjuster or underwriter approving every decision.
Questions and answers
Does the agent approve or open accounts on its own?
No. It prepares the file and proposes a risk rating; an analyst approves, edits or rejects before any account is opened.
Does Dynamiq verify identities or run sanctions screening itself?
No. The agent calls the identity verification and screening providers you already use over API and brings their results into the file, with the source attached.
Can it onboard business customers and beneficial owners?
Yes. The extraction schema is yours to define, so it can pull directors, shareholders and ownership details from registry extracts and corporate documents, and your rules decide what needs a closer look.
How does it handle periodic KYC reviews?
A schedule trigger starts a review when it falls due, and the agent prepares the refreshed file for an analyst the same way it does for a new customer.
Can examiners see why a customer was accepted?
Yes. Every run is traced and replayable, including each document read, each screening result, the rule that set the rating and the analyst's decision.

See this agent on your data.
Talk to our team. We will walk through how it works in your environment, with your systems.