Yes, "the document", without telling which document. When calling the support, they first said that it must be indicated, no kidding. And then they said that it was not possible (despite getting screenshots).
It is sometimes a matter of having the wrong attribute set somewhere in a database and welcome to hell.
Anyway, it's utterly bizarre to me that banks can get a license to run their business with what seems only a marketing and it-team with virtually no recourse for the customer, it was a WTF moment for me and I hope to never get in such a dystopian situation for something I really rely on, be it banking or (utility) services. (and I got a slightly better understanding how it must feel like for the victims of the Dutch childcare benefits scandal (https://www.politico.eu/article/dutch-scandal-serves-as-a-wa...))
Being a bit stubborn, he still kept the message and just applied rot13 to it.
Until I read that the law in my country explictely forbids "deceiving" the police...
Still, actual terror group would do it the same way intelligence agencies call their division 'room 10' as a code for something else. As a species, we certainly are a little weird.
You might see dumb things because banks will do anything they can think of to ensure they comply, and enough in the eyes of the regulator is that they don't allow banned transactions.
Yes, you're meant to do KYC checks, but also be on the look out for things that your non-sanctioned customers might be doing (post KYC checks) that involves interacting with Sanctioned entities.
Hence lots of pattern matching on names of sanctioned countries/organisations/people.
What would have happened if your acquaintance was from Middle-East or Middle-East looking? Probably the story would not have ended so happily or at least not so fast.