Compliance fundamentals · 12 min read

    Know Your Customer (KYC)

    Know Your Customer (KYC) is the regulatory process by which financial institutions and other obliged entities verify a customer's identity, assess their risk profile and monitor the relationship over time. It is the foundation of every AML programme — and increasingly the first impression customers form of a digital brand.

    ~$60M

    Average annual KYC operations spend per large bank

    SEON

    38%

    Onboarding drop-off when KYC takes more than 5 minutes

    Industry benchmark

    5+ yrs

    Minimum KYC record retention under FATF / EU AMLR

    Regulatory

    2027

    EU AMLR / AMLA harmonised KYC rulebook in force

    EU AML package

    What is KYC?

    KYC (Know Your Customer, sometimes Know Your Client) is the set of controls regulated firms use to confirm that a customer is who they claim to be, understand the nature of their activity, and assess the financial-crime risk they pose. It applies at onboarding and throughout the lifetime of the relationship.

    In a B2B context the equivalent is KYB — Know Your Business — which extends KYC to legal entities and the natural persons who ultimately own or control them (Ultimate Beneficial Owners, or UBOs).

    Why KYC matters

    • Mandatory under FATF, EU AMLR, US BSA, UK MLRs and most national AML regimes
    • Prevents fraud, identity theft and account takeover at onboarding
    • Protects firms from being used as a conduit for laundering or terrorist financing
    • Demonstrates audit-ready controls to regulators and correspondent banks
    • Drives customer experience — strong eKYC turns compliance into a growth lever

    The 4 components of KYC

    Customer Identification Program (CIP)

    Collect and verify name, date of birth, address and government ID for every customer.

    Customer Due Diligence (CDD)

    Understand the nature and purpose of the relationship and assess customer risk.

    Enhanced Due Diligence (EDD)

    Apply deeper checks for high-risk customers — PEPs, high-risk jurisdictions, complex structures.

    Ongoing monitoring

    Continuously screen, refresh data and review behaviour throughout the relationship.

    The KYC process, step by step

    1. 1

      Collect customer data

      Capture identity attributes, ID documents, address proof and beneficial ownership data.

    2. 2

      Verify identity

      Validate documents, run biometric/liveness checks and confirm against authoritative sources.

    3. 3

      Screen against risk data

      Check customer (and UBOs) against sanctions, PEP and adverse-media lists.

    4. 4

      Assess and assign risk

      Score the customer based on geography, product, channel and behaviour.

    5. 5

      Approve, decline or escalate

      Auto-approve low risk, escalate medium/high risk to a compliance officer.

    6. 6

      Monitor continuously

      Re-screen, refresh data and review activity throughout the relationship.

    KYC documents checklist

    Exact requirements vary by jurisdiction, risk rating and product, but most regimes converge on the following core artefacts.

    Individuals (KYC)

    • Government-issued photo ID (passport, national ID, driver's licence)
    • Proof of current address (utility bill, bank statement, tax letter < 3 months)
    • Selfie with biometric liveness check
    • Tax identification number where applicable
    • Source of funds / source of wealth evidence (EDD)

    Businesses (KYB)

    • Certificate of incorporation and articles of association
    • Recent commercial registry extract (< 3 months)
    • Beneficial ownership declaration (25%+ UBOs)
    • Board resolution or authorised-signatory list
    • Proof of registered office address
    • Tax / VAT registration number
    • License where the business is regulated

    KYC verification methods

    Most modern KYC stacks combine several of the following — the right mix depends on customer risk, geography and the product being onboarded.

    Document verification

    Authenticate ID documents using OCR, MRZ parsing and security-feature analysis.

    Biometric & liveness

    Match a live selfie to the document portrait with passive liveness (PAD).

    Database checks

    Validate identity attributes against authoritative registries and credit-bureau data.

    Knowledge-based (KBA)

    Challenge questions derived from credit history — fading as deepfake risk rises.

    Address verification

    Confirm address via postal record, utility data or geo-IP signals.

    Manual KYC vs eKYC

    Manual KYCeKYC
    Time to verifyDays to weeksUnder 3 minutes
    Cost per checkHigh (analyst-led)A fraction of manual
    Onboarding drop-off30–50%Often <10%
    Fraud resistanceLimited (visual review)High (PAD + database)
    ScalabilityLinear with headcountElastic, API-driven
    Audit trailPaper / scatteredImmutable, time-stamped

    Levels of customer due diligence

    Simplified Due Diligence (SDD)

    Lower-risk customers (e.g. listed companies, regulated FIs) — reduced verification permitted under risk-based approach.

    Standard Customer Due Diligence (CDD)

    Default level for the majority of customers — full identity verification, screening and risk assessment.

    Enhanced Due Diligence (EDD)

    High-risk customers — PEPs, high-risk jurisdictions, complex ownership, unusual transactions. Requires senior approval and source-of-funds evidence.

    eKYC & digital identity

    eKYC (electronic KYC) replaces paper and branch visits with a fully digital onboarding journey. A typical eKYC flow takes under 3 minutes:

    Document capture & OCR

    Biometric face match & liveness

    Database & sanctions checks

    Risk scoring & decisioning

    Done well, eKYC reduces drop-off, fraud and onboarding cost simultaneously — and is now the regulatory expectation in most digital-first jurisdictions.

    Common KYC challenges in 2026

    • Deepfakes and generative-AI-assisted document forgery
    • Synthetic identity fraud combining real and fabricated attributes
    • Onboarding drop-off when checks add too much friction
    • Fragmented global rules — what's compliant in one jurisdiction isn't in another
    • Operationalising perpetual KYC at scale without alert fatigue
    • Document quality and language variability across markets

    KYC red flags

    Indicators that should automatically escalate to enhanced review or trigger a SAR/STR consideration:

    • Mismatched data between application, document and database checks
    • Reluctance or refusal to provide standard KYC information
    • Customer or UBO connected to high-risk or sanctioned jurisdictions
    • Last-minute changes to beneficiaries, signatories or controlling parties
    • Structuring — multiple sub-threshold transactions to evade reporting
    • Suspicious device, IP or geolocation signals during onboarding

    Key regulations driving KYC

    FATF Recommendations 10–12

    Global standard for CDD, beneficial ownership and PEP requirements.

    EU AMLR & AMLD 6

    Harmonised CDD, EDD and beneficial-ownership rules across the EU from 2027.

    US Bank Secrecy Act & CIP rule

    Customer Identification Program is mandatory for all US financial institutions.

    UK Money Laundering Regulations 2017

    Risk-based CDD and EDD obligations enforced by the FCA, HMRC and other supervisors.

    MiCA (EU 2023/1114)

    Brings full KYC obligations to crypto-asset service providers across the EU.

    eIDAS 2 / EUDI Wallet

    Standardises high-assurance digital identity to power compliant eKYC across the EU.

    KYC best practices

    • Use a risk-based approach — calibrate friction to risk, not to every customer
    • Combine document verification with biometric liveness checks
    • Verify beneficial ownership for all legal entities (UBOs)
    • Move from periodic refresh to perpetual KYC (pKYC)
    • Keep an immutable audit trail of every check and decision
    • Integrate KYC with screening, risk scoring and transaction monitoring
    • Don't treat KYC as a one-off onboarding task
    • Don't apply the same friction to every customer regardless of risk
    • Don't store PII without proper encryption and access controls

    How to choose a KYC provider

    A short buyer's checklist when shortlisting eKYC vendors:

    • Regulator-grade data: sanctions, PEP, adverse media refreshed daily
    • Biometric liveness with Presentation Attack Detection (PAD) certification
    • Broad geographic and document coverage for your markets
    • Immutable audit trail and configurable retention
    • Modular pricing — pay for what you actually use
    • API-first plus low-code workflows for non-technical compliance teams
    • Built-in continuous / perpetual KYC monitoring

    New to the terminology?

    Look up CDD, EDD, UBO, PEP, eKYC and 30+ other AML/KYC terms in plain language.

    Frequently asked questions

    What does KYC stand for?

    KYC stands for Know Your Customer (sometimes Know Your Client). It is the process by which regulated firms verify the identity, suitability and risk of their customers.

    Is KYC the same as AML?

    No. AML (Anti-Money Laundering) is the broader regulatory framework. KYC is a core component of AML — the part focused on identifying and risk-assessing customers.

    What documents are needed for KYC?

    Typically a government-issued photo ID (passport, national ID, driver's licence), proof of address (utility bill, bank statement) and — for businesses — incorporation documents, registry extract and beneficial ownership data.

    What is eKYC?

    eKYC (electronic KYC) is the fully digital version of KYC: document capture, biometric verification, database checks and screening performed online in minutes, often via mobile.

    How long must KYC records be kept?

    Most jurisdictions (FATF, EU AMLR, US BSA, UK MLRs) require KYC records to be retained for at least 5 years after the end of the business relationship.

    What is perpetual KYC (pKYC)?

    Perpetual KYC replaces fixed periodic refresh cycles with continuous, event-driven monitoring — customer data is automatically re-verified whenever a relevant change occurs.

    How much does KYC cost?

    Costs vary widely. Large banks spend on the order of tens of millions per year on KYC operations; per-check digital eKYC pricing typically ranges from cents (database-only) to a few euros (full document + biometric + screening).

    How long does a KYC check take?

    A modern eKYC flow completes in under 3 minutes for most customers. Manual or branch-based KYC can take days to weeks, particularly for businesses with complex ownership structures.

    Is KYC required for crypto?

    Yes. Under the EU's MiCA Regulation and FATF Recommendation 16 (Travel Rule), crypto-asset service providers must perform KYC on customers and exchange originator/beneficiary data on transfers above defined thresholds.

    What is the difference between KYC and KYT?

    KYC verifies who the customer is. KYT (Know Your Transaction) monitors what they do — analysing transactions in real time for patterns indicative of money laundering, fraud or sanctions evasion.

    Onboard customers in minutes, not days.

    ComplianceSuite delivers eKYC, KYB, biometric liveness, sanctions/PEP screening and risk scoring in one audit-ready platform — deployed in 48 hours.