Blog

AML Fundamentals

What Is KYC?

What Know Your Customer (KYC) means in practice: the data you must verify, when simplified, standard or enhanced due diligence applies, and how the rules differ by jurisdiction.

KYC, or Know Your Customer, is the regulated process of identifying a customer, verifying that identity against reliable independent evidence, understanding the purpose of the relationship, and keeping that picture current. It is not a one-off onboarding gate. In every major regime it is a continuing obligation that runs for the life of the relationship.

Key takeaways

  • KYC is the industry term. The statutory obligation regulators actually write rules about is customer due diligence (CDD), of which identification and verification is only one part.
  • Most regimes converge on a 25% beneficial ownership threshold plus a separate control test. FinCEN's CDD Rule and the EU's Anti-Money Laundering Regulation both work this way.
  • The intensity of KYC must track risk. Simplified, standard and enhanced due diligence are three distinct legal settings, not three levels of effort.
  • Refresh obligations are where most programmes fail. AUSTRAC's reformed ongoing CDD obligations have applied since 31 March 2026, with no transitional relief.
  • Jurisdictions differ far more on thresholds and triggers than on principle, so a global programme needs a rules engine rather than a single fixed checklist.

What does a KYC check actually collect and verify?

A compliant KYC check has two halves: collection and verification. Collection means capturing the attributes a rule specifies. For an individual that is typically full legal name, date of birth, residential address and, in the United States, a taxpayer identification number under the Customer Identification Program (CIP) rules implementing section 326 of the USA PATRIOT Act.

Verification is the harder half, because it requires reliable and independent evidence rather than the customer's own assertion. That means document authentication (security features, the machine-readable zone, chip data on an ePassport), a biometric liveness check binding the live person to the document photograph, and corroboration against independent sources such as electoral rolls or government registries.

The output should not sit in an onboarding silo. Verified attributes must land in the same customer record used for sanctions and PEP screening, risk rating and monitoring. Otherwise the refresh obligations below have nothing to act on. See identity verification for how the document, biometric and data-source layers fit together.

How is KYC different from AML, CDD and KYB?

These four terms get used interchangeably, and they are not equivalent. AML is the whole control framework: risk assessment, governance, screening, monitoring, reporting and training. CDD is the statutory customer-facing obligation inside that framework. KYC is the identification and verification component of CDD, and KYB applies the same logic to entities rather than natural persons.

The distinction matters at audit. A regulator does not ask whether you "did KYC". It asks whether you met a specific CDD obligation, such as whether you understood the purpose and intended nature of the relationship, which no amount of document verification satisfies.

Both directions of confusion cause findings. Teams that treat KYC as the whole of CDD under-collect relationship-purpose information. Teams that treat AML as synonymous with KYC under-invest in monitoring. See what is AML? and the difference between AML and KYC.

When does simplified, standard or enhanced due diligence apply?

Tiering is a legal setting, not a workload preference. Applying uniform checks to every customer is itself a finding, because it demonstrates the programme is not risk-based. The three tiers work as follows:

TierWhen it appliesWhat you must additionally do
Simplified (SDD)Only where your risk assessment identifies demonstrably lower risk, and only where the regime permits it. Never available where suspicion exists.Reduce the extent or timing of measures, for example verifying after establishment. You may not skip identification or monitoring entirely.
Standard (CDD)The default for the great majority of customers.Identify and verify the customer and any beneficial owners; establish the purpose and intended nature of the relationship; monitor on an ongoing basis.
Enhanced (EDD)Higher-risk cases. Under regulation 33 of the UK's Money Laundering Regulations 2017: PEPs and their family members and known close associates, correspondent relationships, persons established in FATF call-for-action countries, unusually complex or large transactions, and any case where false or stolen ID documents are discovered.Establish source of funds and source of wealth, obtain senior management approval for the relationship, and apply increased monitoring.

Note that regulation 33 makes EDD mandatory in the listed cases regardless of your own risk rating. A customer you scored as medium risk who turns out to be a PEP moves to EDD by operation of law. Our enhanced due diligence page sets out what a defensible source-of-wealth file contains.

How do KYC rules differ across the US, UK, EU, Australia and Singapore?

The principle is near-identical everywhere: identify, verify, risk-rate, monitor. The differences are in thresholds, triggers and timing, and those are what break a single global checklist.

JurisdictionCore instrumentRegulatorRequirement worth knowing
United StatesCDD Rule (BSA), plus CIP rules under USA PATRIOT Act s.326FinCENIdentify beneficial owners at 25% ownership plus a control prong. Order FIN-2026-R001, issued 13 February 2026, removed the requirement to re-identify beneficial owners at every new account opening, moving to a risk-based trigger (FinCEN).
United KingdomMoney Laundering Regulations 2017 (SI 2017/692)FCA (plus HMRC and professional body supervisors)EDD triggers are enumerated in law, not left to firm judgement (regulation 33).
European UnionRegulation (EU) 2024/1624 (AMLR)AMLA and national supervisorsDirectly applicable from 10 July 2027 (10 July 2029 for football clubs and agents); 25% beneficial ownership definition; EU-wide cash payment ceiling of EUR 10,000 (EUR-Lex).
AustraliaAML/CTF Act 2006 and AML/CTF Rules, as reformedAUSTRACNew ongoing CDD obligations apply from 31 March 2026; firms enrolled on 30 March 2026 may keep using applicable customer identification procedures for initial CDD only, until 31 March 2029 (AUSTRAC transitional rules).
SingaporeMAS Notice 626MASCDD is required for non-account holders on occasional transactions above S$20,000, and on cross-border wire transfers above S$1,500 (MAS Notice 626).

Two patterns stand out across the table. Enumerated triggers, as in the UK, constrain firm judgement. Framework regimes such as the US and Australia push the burden onto your documented risk methodology instead, and the EU is about to replace directive-based national variation with a directly applicable regulation.

The practical consequence is that a multi-jurisdiction programme should encode the strictest applicable standard per customer, and record which standard it applied and why. "We used our standard process" is not an answer to a supervisor asking about one specific higher-risk file.

What does KYC require when the customer is a company or a trust?

Entity customers add two obligations on top of identification. First, you must verify the entity itself: registered legal name, registration number, registered office, and the constitutional documents that establish how it is governed. Second, you must look through it to the natural persons behind it.

Beneficial ownership is where this gets difficult. FinCEN's CDD Rule and the EU's AMLR both set the ownership prong at 25% and add a separate control prong, which means an entity can have several beneficial owners, or none by ownership and one by control. Layered structures, such as a holding company owning a holding company owning a trust, require unwinding until you reach individuals, and the register you rely on may be self-declared rather than verified.

Trusts add a further layer. You generally need the trustee, the settlor, any protector, and the beneficiaries or class of beneficiaries. AUSTRAC's reformed rules make initial CDD on trusts explicit. See Know Your Business and why KYB is now a core part of AML compliance.

How often must KYC information be refreshed?

There is no universal interval, and that is deliberate. Refresh frequency is an output of your risk rating, documented in your AML/CTF policies. Most programmes settle on annual review for high-risk customers, two to three years for medium, and a longer cycle for low, but the cycle only defends you if you can show the rating that produced it.

Periodic review alone is insufficient. Every regime expects event-driven refresh: a new sanctions or PEP match, adverse media, a change in beneficial ownership, a change in the customer's stated business, or transaction behaviour inconsistent with the purpose you recorded at onboarding.

Australia's reforms show how hard this line has hardened. AUSTRAC granted transitional relief for initial CDD until 31 March 2029, but explicitly none for ongoing CDD, which has applied since 31 March 2026. Continuous PEP and sanctions screening and transaction monitoring are what make event-driven refresh operationally possible. MemberCheck rescreens the customer record rather than waiting for the next scheduled review.

What do regulators actually penalise in KYC failures?

Enforcement rarely turns on a single missed passport. It turns on systemic defects, and the four core requirements of FinCEN's CDD Rule are a fair proxy for what examiners test everywhere: identify the customer, identify beneficial owners, understand the nature and purpose of the relationship, and conduct ongoing monitoring with risk-based updating of customer information.

The recurring findings are procedural. Risk ratings that were never applied to anything. EDD that was triggered but never evidenced. Alerts closed without a documented rationale, customer records refreshed on paper but never re-screened, and an inability to reconstruct after the fact what was known about a customer at the time a decision was made.

There is also an evidentiary dimension firms underestimate. If you cannot reproduce the data, the match logic and the reviewer's reasoning from two years ago, you cannot demonstrate compliance even where the decision was correct. A documented AML risk assessment ties ratings to controls.

Where do KYC programmes most often fail?

Five failure modes account for most remediation work:

  • Verification without corroboration, where a document image is accepted with no independent data check.
  • Static risk ratings, assigned at onboarding and never recalculated when behaviour changes.
  • Beneficial ownership taken on trust, where a self-declaration form stands in for verification of a 25% holding.
  • Screening decoupled from the customer record, so checks run against a name string rather than the verified identity and a refresh never propagates.
  • A refresh cycle no one owns: a policy that says "annually" with no queue, no capacity model and no escalation when the backlog grows.

Each of these is detectable in your own data before a regulator finds it. Count the customers whose risk rating has never changed, whose beneficial ownership has never been checked against a registry, or whose last screening date predates their last profile change. See also where most AML programmes fail, the glossary of AML terms, and our AML fundamentals collection.

FAQ

Common questions.

What does KYC stand for?
KYC stands for "Know Your Customer". It is the regulated process of identifying a customer, verifying that identity against reliable independent evidence, understanding the purpose of the relationship, and keeping that picture current for as long as the relationship lasts.
What is the difference between KYC and CDD?
KYC is the everyday industry term; customer due diligence (CDD) is the statutory obligation. CDD is the broader duty. It covers identification and verification, which is the KYC part, plus understanding the purpose of the relationship, identifying beneficial owners, and ongoing monitoring. Regulators write rules about CDD, not about KYC.
Who counts as a beneficial owner for KYC purposes?
In most regimes, any individual holding 25% or more of the shares or voting rights in an entity, plus anyone who controls it by other means. FinCEN's CDD Rule and the EU's Anti-Money Laundering Regulation both use a 25% ownership prong alongside a separate control prong, so a company can have several beneficial owners or none by ownership at all.
When must enhanced due diligence be applied instead of standard KYC?
When the customer or transaction presents higher risk. Under regulation 33 of the UK's Money Laundering Regulations 2017, enhanced due diligence is mandatory for politically exposed persons (PEPs) and their family and close associates, correspondent relationships, customers established in FATF call-for-action countries, unusually complex or large transactions, and any case where false or stolen identity documents are discovered.
How often does KYC information need to be refreshed?
There is no single global interval. Refresh cycles are set by risk rating in your own AML/CTF policies, commonly annually for high-risk customers and on a multi-year cycle for standard risk. They must also be supplemented by event-driven reviews triggered by a sanctions or PEP hit, adverse media, a change of beneficial ownership, or transaction behaviour that no longer matches the stated purpose.
Does KYC apply differently to companies than to individuals?
Yes. For a company, trust or partnership you must verify the entity itself (legal name, registration number, registered address, governing documents), identify and verify its beneficial owners, and confirm that the person instructing you is authorised to act. This entity-level process is usually called KYB, or Know Your Business.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.