Know Your Customer (KYC)

Know your customer (KYC) is the obligation on regulated institutions to establish and verify who their customers are before serving them, and to keep that understanding current afterwards. It is the oldest requirement in financial crime compliance and the one most often reduced to a box-ticking exercise.

Also called KYC, customer identification, identity verification in a regulated context
U.S. implementation Customer Identification Program (CIP) rules under the Bank Secrecy Act
International basis FATF Recommendation 10, implemented through national AML law
Minimum data Name, date of birth, address, and an identification number
Verification method Documentary, non-documentary, or both
Wider obligation Customer due diligence — identity, beneficial ownership, purpose, monitoring
Applies to Banks, credit unions, MSBs, broker-dealers, casinos, crypto exchanges and more
Ongoing duty Refresh on triggers and on a risk-based cycle
Common failure Treating it as an onboarding gate rather than a continuing obligation

How it works

KYC at its narrowest is four data points and a verification method. Collect name, date of birth, address and an identifying number; then confirm them against something reliable.

Documentary verification means a government-issued identity document — checked for authenticity, and increasingly matched to a live face so the document’s owner is the person presenting it. Non-documentary verification checks the supplied data against independent sources: credit files, public records, databases. Most programs use both, weighted by risk.

The narrow view is where programs get into trouble, because KYC is not really a step. It is the identity component of customer due diligence, which also requires understanding beneficial ownership, understanding what the relationship is for, and monitoring it. An institution that verifies identity impeccably at onboarding and never looks again has satisfied a fraction of the obligation.

Depth scales with risk. Low-risk customers may receive simplified checks; higher-risk ones escalate to enhanced due diligence, adding source of funds and senior approval. That risk-based structure is what lets finite compliance resource go where it matters, and it depends on a risk profile that is itself built from verified identity data.

Why it matters for identity verification

KYC is the regulatory reason identity verification exists in financial services, and the relationship shapes what good looks like.

The requirement is not to be accurate. It is to be reasonable and to be able to prove it. Examiners assess whether the program was appropriate to the institution’s risk, whether it was applied consistently, and whether the institution can evidence what it checked and why. A verification system that returns a decision without a reconstructable record of how it reached one is a finding waiting to happen, regardless of its accuracy.

The commercial pressure runs the other way. KYC sits at the highest-abandonment point in any onboarding funnel, so its speed and false-rejection rate determine conversion as directly as its accuracy determines risk. The two are usually owned by different people with opposing targets.

Resolving that argues for verification that is fast, evidenced, and calibrated rather than maximal. Document authentication paired with a biometric check satisfies documentary verification in seconds and records what it did, and Microblink’s eKYC workflow is built around that combination.

KYC vs AML vs CDD

  KYC CDD AML
Scope Establishing customer identity Identity, ownership, purpose, monitoring The whole financial crime framework
Relationship Part of CDD Part of AML The umbrella
Primary output A verified identity A risk-rated customer relationship A compliance program
When At onboarding, refreshed on triggers Ongoing Continuous
Common confusion Used interchangeably with CDD Used interchangeably with KYC Used as a synonym for KYC

The terms are used loosely and the nesting is the useful part: KYC sits inside CDD, which sits inside AML. An institution with strong KYC and weak monitoring has a strong component inside a weak program.

What it can’t do

It cannot verify what a customer says about themselves. KYC establishes identity. Stated income, occupation and purpose are claims requiring independent data, and no improvement to the identity check reaches them.

It cannot detect a customer who intends to misuse a legitimate account. A real person, correctly verified, who later launders money passes every KYC check because nothing about their identity is false.

It is not a one-time event. The most common structural failure is treating KYC as a gate. A customer verified three years ago whose file has never been refreshed is not under ongoing due diligence, whatever the policy document says.

It cannot compensate for weak underlying verification. Every downstream component — risk profiling, monitoring, screening — inherits the quality of the identity check. Where that was weak, the rest is elaborate reasoning about a customer who may not exist.

Frequently asked questions

What is the difference between KYC and CDD?

KYC is the identity-establishing component; CDD is the broader obligation that also covers beneficial ownership, understanding the purpose of the relationship, and ongoing monitoring. The terms are used interchangeably in practice, and FATF treats CDD as the umbrella.

What information is required for KYC?

At minimum name, date of birth, address and an identifying number, verified against reliable independent evidence — documentary, non-documentary, or both. Institutions collect more where risk warrants it.

How often does KYC need to be refreshed?

On a risk-based cycle, and on trigger events such as a change in ownership, a significant change in activity, or adverse information surfacing. Fixed periodic review with no trigger-based refresh is a frequent examination finding.

Does KYC apply outside banking?

Yes. Money services businesses, broker-dealers, casinos, insurers and crypto exchanges carry KYC obligations, and many unregulated businesses apply similar checks for fraud reasons rather than compliance ones.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data