Isn't this where documentation of actual KYC would come in? "Flagged for reason X; Overridden by local manager - follows 10 lines of CYA justification"? Normally that's good enough for administrations.
The second time it's flagged for reason X+1, include 10 lines from rank 2 manager.