Skip to main content
← All terms

KYC (Know Your Customer)

Definition

KYC (Know Your Customer) is the regulated process of verifying a customer's identity and assessing their risk before and during a financial relationship.

KYC, short for Know Your Customer, is the regulated process financial institutions use to verify who their customers are, understand the purpose of the relationship, and assess the risk that the customer presents. It is a legal requirement in most jurisdictions and applies before an account is opened and continuously thereafter.

KYC exists to prevent financial institutions from being used β€” knowingly or otherwise β€” for money laundering, terrorist financing, fraud, sanctions evasion and tax evasion. It is the customer-facing component of a broader anti-money laundering (AML) compliance programme.

The obligation extends well beyond banks. It typically applies to microfinance institutions, credit unions and SACCOs, payment providers, mobile money operators, insurers, securities firms, crypto-asset service providers, and in many jurisdictions to lawyers, accountants, real estate agents and dealers in precious metals.

Why KYC exists

The international standard-setter is the Financial Action Task Force (FATF), an intergovernmental body founded in 1989 whose recommendations form the basis of most national AML laws. FATF Recommendation 10 sets out customer due diligence obligations, and member countries transpose these into domestic legislation and regulator guidance.

Because implementation is national, the specific documents, thresholds and timelines differ by jurisdiction β€” but the underlying architecture is consistent almost everywhere: identify the customer, verify the identity, understand the relationship, rate the risk, and monitor over time.

The four pillars of KYC

1. Customer Identification Programme (CIP)

Collecting identifying information and verifying it against reliable, independent sources. For an individual this is typically full name, date of birth, residential address and a government-issued identification number. Verification may be documentary (an ID document plus proof of address) or non-documentary (matching details against a national ID database, credit bureau or telecom record).

2. Customer Due Diligence (CDD)

Going beyond identity to understand the customer: the nature and purpose of the relationship, the expected source of funds, the anticipated pattern of transactions, and β€” for entities β€” the ownership and control structure. CDD produces the baseline against which future activity is judged.

3. Enhanced Due Diligence (EDD)

Additional scrutiny for higher-risk customers. EDD typically requires senior management approval to onboard, documented evidence of source of wealth as well as source of funds, and more frequent review. Triggers commonly include:

  • Politically exposed persons (PEPs) β€” individuals holding prominent public functions, plus their family members and close associates
  • Customers based in or transacting with high-risk or sanctioned jurisdictions
  • Complex ownership structures, trusts, or bearer-share entities
  • Cash-intensive businesses, money service businesses and other high-risk sectors
  • Adverse media findings or unexplained wealth

4. Ongoing monitoring

KYC is not a one-time gate. Institutions must monitor transactions against the expected profile, screen customers against sanctions and PEP lists on a continuing basis, refresh customer records periodically, and investigate and report suspicious activity to the national financial intelligence unit.

The KYC process step by step

  1. Collect identifying information and required documents at onboarding.
  2. Verify the information against independent sources β€” a national ID registry, a business registry, a credit bureau, or a document-authentication and biometric check.
  3. Screen the customer against sanctions lists, PEP databases and adverse media.
  4. Identify beneficial owners for legal entities β€” the natural persons who ultimately own or control the customer. Many jurisdictions use a 25% ownership threshold as the trigger, alongside a separate control test.
  5. Risk-rate the customer, usually into low, medium and high bands, driven by geography, product, channel, occupation or industry, and expected transaction profile.
  6. Approve or escalate. Low-risk customers may qualify for simplified due diligence; high-risk customers require EDD and senior sign-off.
  7. Monitor and refresh. Transaction monitoring runs continuously; periodic review cycles are commonly annual for high risk, and every two to five years for lower risk, with event-driven reviews when something changes.

Common KYC documents

Individuals

  • Government-issued photo identification β€” national ID card, passport, driver's licence
  • Proof of address β€” utility bill, bank statement, lease, or a letter from a recognised authority
  • Tax or national identification number where applicable
  • A photograph or liveness check, in digital onboarding

Businesses (Know Your Business, or KYB)

  • Certificate of incorporation or business registration
  • Memorandum and articles of association, or equivalent constitutional documents
  • Register of directors and shareholders
  • Proof of registered business address
  • Board resolution or mandate identifying authorised signatories
  • Identification documents for directors, authorised signatories and beneficial owners
  • Tax registration and, where relevant, a trading or operating licence

eKYC and digital verification

eKYC is the electronic execution of the same obligations. Rather than collecting paper, the institution verifies identity through digital means:

  • Document capture with automated authenticity checks
  • Biometric matching β€” a selfie or liveness check compared against the ID photograph
  • Direct verification against national identity databases or registries
  • Mobile network operator and credit bureau data matching
  • Electronic signature and audit-trailed consent capture

eKYC shortens onboarding from days to minutes and removes branch dependency. It also concentrates risk: presentation attacks, synthetic identities and document forgery all target the automated check, so most institutions retain manual review for exceptions and higher-risk profiles.

KYC vs AML vs CDD vs KYB

  • AML (Anti-Money Laundering): The full compliance programme β€” policies, controls, monitoring, reporting, training, and audit.
  • KYC (Know Your Customer): The customer-facing part of AML β€” identifying, verifying, and risk-rating customers.
  • CDD (Customer Due Diligence): The due diligence work inside KYC β€” understanding purpose, source of funds, and ownership.
  • KYB (Know Your Business): KYC applied to business customers, including beneficial ownership identification.
  • EDD (Enhanced Due Diligence): The heightened version of CDD for higher-risk customers.

In short: CDD and EDD are components of KYC, KYC is a component of AML, and KYB is KYC for entities.

Cost, friction and financial inclusion

KYC imposes real costs on both sides of the relationship.

For institutions, it means verification infrastructure, screening subscriptions, compliance staff, monitoring systems and periodic refresh campaigns β€” largely fixed costs that fall heavily on small-ticket, high-volume portfolios where the revenue per customer is low.

For customers, documentary requirements can be a barrier. Proof of address is difficult where addressing systems are informal; identity documents are not universal; business registration papers may be outdated or unavailable for small traders. This is why FATF and national regulators explicitly endorse a risk-based approach: applying simplified due diligence to demonstrably low-risk products β€” small-balance accounts, capped mobile wallets, small-value credit β€” so that compliance does not exclude the customers financial systems are meant to reach.

There is also a standing tension with data protection law. KYC compels the collection and retention of substantial personal data, while privacy regimes require minimisation, purpose limitation, security and defined retention periods. Institutions have to satisfy both: collect what the AML rules require, keep it for the mandated retention period, protect it, and delete it when neither obligation applies.

Consequences of weak KYC

Enforcement is significant and public. Regulators have imposed very large penalties on institutions for systemic KYC and AML failures, and consequences extend beyond fines to remediation orders, business restrictions, deferred prosecution agreements, personal liability for compliance officers, licence conditions and revocation. Correspondent banking access β€” the ability to move money internationally β€” is often the first casualty, which for a small institution can be existential.