Know Your Customer (KYC)
Know Your Customer (KYC) is the process a bank, fintech, or other regulated business uses to verify a customer’s identity and assess the money laundering risk that relationship represents, both at onboarding and for as long as the relationship continues. In the US, it’s built on Section 326 of the USA PATRIOT Act. Internationally, FATF Recommendation 10 sets the standard most countries’ domestic KYC law is built around.
Key takeaways
- KYC verifies who a customer is and how much risk they carry, at onboarding and throughout the relationship.
- In the US, the legal foundation is Section 326 of the USA PATRIOT Act (the Customer Identification Program rule), effective 1 October 2003.
- Internationally, FATF Recommendation 10 sets the standard, first issued in 1990 and substantially revised in 2012 to embed a risk-based approach.
- KYC has three tiers: simplified due diligence for low-risk relationships, standard CDD for most customers, and enhanced due diligence for higher-risk ones.
- KYC/AML/CDD-related fines hit $6.6 billion globally in 2023, up 57% from 2022 (Fenergo).
- Santander UK was fined £107.7 million in 2023 specifically for prolonged KYC/CDD weaknesses (FCA).
- KYB (Know Your Business) and KYT (Know Your Transaction) extend the same core logic to companies and transactions.
On this page
What KYC actually meansWhere KYC came from: a brief historyThe legal foundation: PATRIOT Act, FATF, and UK/EU lawThe three tiers of KYC: SDD, standard CDD, EDDKYC vs CDD vs EDDThe KYC process step by stepKYC vs KYB vs KYTWhat KYC failure actually costsHow technology is changing KYCCommon KYC mistakes firms still makeBuilding a defensible KYC programmeFAQsRead more
£107.7m
FCA fine against Santander UK in 2023 for prolonged KYC/CDD weaknesses
Source: UK Financial Conduct Authority
2003
Year the US Customer Identification Program rule took effect under the PATRIOT Act
Source: FinCEN / OCC Bulletin 2003-22
$15,000
USD threshold that triggers standard CDD for occasional transactions under FATF Recommendation 10
Source: FATF Recommendation 10
What KYC actually means
Know Your Customer, KYC for short, is the process a bank, fintech, or other regulated business uses to confirm a customer really is who they claim to be, and to work out how much money laundering or fraud risk that customer represents. It happens when an account is opened, and continues for as long as the relationship lasts.
The term covers three connected activities: identifying the customer, verifying that identity against reliable evidence, and assessing and monitoring the risk the relationship presents over time. Skip any one of the three and the programme isn’t really KYC, whatever a firm chooses to call its process internally.
Where KYC came from: a brief history
KYC as a formal regulatory requirement is younger than most people assume. Financial institutions have always had some interest in knowing their customers for credit and fraud reasons, but KYC as a codified anti-money laundering obligation traces to the Bank Secrecy Act of 1970 in the US, which first required banks to keep records and report certain transactions.
The modern KYC regime most compliance teams recognise today came later, largely in response to a specific shock. The September 11 attacks exposed how thin US customer identification requirements actually were, and Congress responded within weeks with the USA PATRIOT Act, passed in October 2001, which included Section 326, the provision that eventually produced today’s Customer Identification Program rule.
Internationally, the Financial Action Task Force had already issued its original 40 Recommendations in 1990, with customer due diligence provisions among them, but FATF’s 2012 revision is what embedded the risk-based approach, simplified due diligence for genuinely low-risk relationships, enhanced due diligence for higher-risk ones, that defines KYC practice globally today.
The legal foundation: PATRIOT Act, FATF, and UK/EU law
In the US, the Customer Identification Program rule implementing Section 326 of the USA PATRIOT Act became final on 9 May 2003, with compliance required from 1 October 2003. It sets four minimum requirements for every bank: verify the identity of anyone opening an account to the extent reasonable and practicable, keep records of the information used for that verification, check the customer against government lists of known or suspected terrorists, and give customers adequate notice that identity information is being collected.
Internationally, FATF Recommendation 10 is the reference standard nearly every country’s domestic KYC law is built around. It requires financial institutions to identify and verify customers and beneficial owners, understand the purpose and intended nature of the relationship, and conduct ongoing monitoring, applied whenever a business relationship is established, whenever an occasional transaction crosses $15,000, or whenever money laundering is suspected regardless of any exemption that would otherwise apply.
In the UK, the equivalent obligations sit in the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, and across the EU in the Anti-Money Laundering Directives, both implementing FATF’s standard into binding domestic law with broadly the same core requirements.
The three tiers of KYC: SDD, standard CDD, EDD
Not every customer relationship carries the same risk, and FATF’s risk-based approach means KYC isn’t meant to apply the same intensity of checking to everyone. Three tiers cover the spectrum.
Simplified due diligence applies to genuinely low-risk relationships, a basic account with strict transaction limits, for example, and involves lighter documentation requirements without dropping monitoring entirely.
Standard customer due diligence is the default tier most relationships fall into: verify identity, understand the relationship’s purpose, screen against sanctions and PEP lists, and monitor transactions against what’s expected for that customer.
Enhanced due diligence applies where risk is genuinely higher, politically exposed persons, complex ownership structures, high-risk jurisdictions, unusual transaction patterns, and requires deeper checks: verified source of wealth and funds, senior management sign-off, and more frequent ongoing review.
KYC vs CDD vs EDD
The terms KYC, CDD, and EDD get used loosely, sometimes interchangeably, which causes real confusion. Here’s how they actually relate:
| Term | What it covers | When it applies | Typical depth |
|---|---|---|---|
| KYC | The overall umbrella: identifying, verifying, and monitoring a customer | Every regulated customer relationship | Varies by tier below |
| CDD | The standard due diligence tier within KYC | The default level for most customers | Identity verification, purpose, screening, monitoring |
| EDD | The enhanced due diligence tier within KYC | Higher-risk customers: PEPs, complex structures, high-risk jurisdictions | Source of wealth/funds, senior sign-off, closer monitoring |
KYC is the umbrella. CDD is the standard-tier process most people mean when they say KYC. EDD is the deeper version applied only where risk genuinely warrants it. None of the three is a substitute for the others; they’re layers of the same overall obligation, scaled to risk.
The KYC process step by step
- Collect identifying information: name, date of birth, address, and a government-issued identifier, at minimum.
- Verify that information against reliable, independent sources: a passport or driving licence checked against issuing databases, not just visually inspected.
- Screen the customer against sanctions lists, PEP databases, and adverse media.
- Assess risk based on the customer’s profile, product, geography, and expected activity, assigning simplified, standard, or enhanced treatment.
- Establish an expected activity profile: what normal transactions should look like for this specific customer.
- Monitor the relationship on an ongoing basis, watching for activity that departs from that expected profile.
- Refresh the file periodically, more frequently for higher-risk customers, to catch changes in risk over time.
Skipping the ongoing monitoring and periodic refresh steps is one of the most common gaps regulators flag. A firm that only does KYC well at onboarding, then never revisits it, is doing half the job the regulations actually require.
KYC vs KYB vs KYT
KYC’s core logic extends to two closely related disciplines. Know Your Business, KYB, applies the same verification and risk-assessment logic to corporate customers instead of individuals: verifying the company’s registration, structure, and, critically, its beneficial owners rather than just the entity itself. Know Your Transaction, KYT, shifts the focus from the customer to the transaction, analysing individual transactions for suspicious patterns rather than assessing the customer relationship as a whole.
None of the three replaces the others. A bank serving corporate clients needs KYB alongside KYC for the individuals who control those companies, and KYT running continuously underneath both to catch activity that doesn’t match what onboarding assumed.
What KYC failure actually costs
KYC failures are expensive, and getting more expensive. Fenergo’s annual review of global enforcement found that fines specifically tied to AML, KYC, and customer due diligence failures totalled $6.6 billion in 2023, up 57% from $4.2 billion in 2022.
Individual cases show what specifically goes wrong. The UK’s Financial Conduct Authority fined Santander UK £107.7 million in 2023 for what it called significant and prolonged weaknesses in KYC and CDD controls, particularly in monitoring business banking customers whose transaction activity should have prompted closer review. TD Bank’s $3.09 billion settlement with US authorities in 2024, one of the largest AML penalties ever, involved more than $670 million in laundered funds moving through the bank between 2018 and 2024, tied in part to inadequate ongoing monitoring, the same monitoring KYC is supposed to sustain after onboarding.
The pattern across these cases isn’t usually a total absence of KYC. It’s KYC that was strong at onboarding and weak everywhere after it, exactly the gap step six above is meant to close.
How technology is changing KYC
Manual, paper-based identity checks are increasingly the exception rather than the rule. Digital identity verification, document scanning combined with biometric matching, database checks against government and credit bureau records, and increasingly reusable digital identity credentials, have replaced much of the in-branch, paper-heavy process KYC originally relied on.
The shift brings real trade-offs: faster, more consistent verification at scale, and often better fraud detection through biometric matching, against new risks: deepfake and synthetic identity fraud specifically designed to defeat automated verification, and a growing reliance on third-party identity data providers whose own accuracy and security become part of a firm’s own risk exposure.
Common KYC mistakes firms still make
Regulatory findings across multiple markets point to a recurring set of failures. Relying on due diligence performed by another institution in a jurisdiction without equivalent AML standards, without independently verifying that reliance was reasonable. Onboarding higher-risk customers without escalating to enhanced due diligence, particularly where a customer doesn’t fit a firm’s normal client base or wasn’t physically present for verification. Letting CDD go stale, never refreshing customer information even as risk factors change. Collecting good information at onboarding but failing to build monitoring that actually uses it to flag unusual activity later.
Each of these shows up repeatedly across enforcement actions in different countries, which suggests they’re structural weaknesses in how KYC programmes get built, not isolated mistakes by any one firm.
Building a defensible KYC programme
A KYC programme that holds up under regulatory scrutiny generally shares a few features: risk tiering that’s actually documented and consistently applied, not just described in policy; ongoing monitoring that’s resourced as heavily as onboarding, since that’s where enforcement findings increasingly concentrate; periodic refresh cycles calibrated to risk, not a single fixed schedule applied uniformly; and clear escalation paths so that a red flag identified during monitoring actually reaches someone with authority to act on it.
The single most common thread across the enforcement cases above isn’t a missing policy document. It’s a gap between what the policy says and what actually happens to a customer file after the account is opened.
Check your KYC readiness
See where your onboarding and ongoing monitoring controls have gaps before a regulator finds them.
Frequently asked questions
What does KYC stand for?
KYC stands for Know Your Customer, the process regulated businesses use to verify a customer’s identity and assess their money laundering risk before and during a business relationship.
Is KYC the same as AML?
No. AML, anti-money laundering, is the broader set of laws and controls aimed at preventing money laundering. KYC is one specific component of an AML programme, focused on customer identification and risk assessment.
What documents are needed for KYC verification?
Typically a government-issued photo ID such as a passport or driving licence, proof of address, and for higher-risk relationships, additional evidence such as source of funds documentation.
How long does KYC verification take?
It varies widely by provider and method. Digital identity verification using document scanning and biometric matching can complete in minutes; manual review, particularly for enhanced due diligence cases, can take days.
What is the difference between KYC and CDD?
KYC is the overall umbrella term. Customer due diligence, CDD, is the standard-tier process within KYC that most customers go through: identity verification, understanding the relationship’s purpose, and ongoing monitoring.
What happens if a business doesn’t comply with KYC requirements?
Regulators can impose significant fines, in some recent cases running into hundreds of millions or billions of dollars, alongside remediation requirements, restrictions on business activity, and reputational damage.
Does KYC apply to businesses, not just individuals?
Yes, through Know Your Business, KYB, which applies the same verification and risk-assessment logic to corporate customers, including identifying the individuals who ultimately own or control them.
How often should KYC information be refreshed?
Frequency should scale with risk. Higher-risk customers typically need review annually or more often; lower-risk relationships might be refreshed every few years, but the schedule should be documented and risk-based, not arbitrary.
Can KYC be done entirely online?
Largely, yes, for most retail relationships. Digital identity verification tools can confirm identity documents and match biometrics remotely, though higher-risk relationships often still involve additional manual review.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 13 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Know Your Customer (KYC) is the process a bank, fintech, or other regulated business uses to verify a customer’s identity and assess the money laundering risk that relationship represents, both at onboarding and for as long as the relationship continues. In the US, it’s built on Section 326 of the USA PATRIOT Act. Internationally, FATF Recommendation 10 sets the standard most countries’ domestic KYC law is built around.