AML and KYC are related but distinct: AML is the broad framework of laws and controls that prevent money laundering and terrorism financing, set out in Australia by the AML/CTF Act 2006, while KYC is the specific process of verifying a customer's identity, which regulators fold into customer due diligence. KYC is one control inside an AML programme, not a separate requirement running in parallel to it.
What does each one actually cover?
| AML | KYC | |
|---|---|---|
| Focus | Preventing financial crime across the business | Verifying customer identity |
| Purpose | Combat money laundering and terrorism financing | Prevent fraud and confirm who the customer is |
| Typical scope | Banks, money service businesses, broker-dealers, casinos | Banks, investment firms, insurers, credit card companies |
| When it applies | Ongoing, for the life of the relationship | Primarily at onboarding, refreshed periodically |
What does this look like in a real onboarding flow?
Take a bank onboarding a new business customer. KYC covers the first part, what AUSTRAC calls initial customer due diligence: verifying the identity of the individuals opening the account, confirming the business is legally registered, and identifying its ultimate beneficial owners. The US equivalent is FinCEN's CDD rule, which likewise requires identifying beneficial owners of legal entity customers. That's where KYC's job ends — it has answered "who is this, really?" AML picks up from there and never really stops: screening the business and its owners against sanctions and PEP lists at onboarding and again every time those lists update; scoring the relationship's risk based on factors like the industry, countries involved, and expected transaction volume; monitoring actual transactions against that expected pattern once the account is live; and filing a suspicious activity report if something doesn't fit. KYC answered a question once (with periodic refreshes); AML keeps asking a different question — is this relationship still behaving the way we'd expect — for as long as the account exists.
Why does the distinction matter in practice?
Treating KYC as a one-time onboarding checkbox, separate from ongoing AML monitoring, is a common gap — a customer who was verified correctly at onboarding can still become a laundering risk later if nothing checks their activity afterward. Identity verification establishes who the customer is; transaction monitoring and PEP and sanctions screening are what keep that assessment current.
Where do AML and KYC overlap?
Both exist to stop the same underlying harm — a business being used, knowingly or not, to move illicit funds — and in practice regulators expect them to work together rather than as separate silos. An AML risk assessment is typically what ties KYC output (who the customer is) to the ongoing AML controls (how closely they're monitored) applied to that customer.
Do smaller businesses need both?
Yes, if they're a reporting entity under AML/CTF law at all — there's no size threshold that removes the KYC obligation once a business is in scope. The practical difference for a smaller team is usually how much of the process is automated rather than manual, not whether the requirement applies.



