us

216.73.217.78

Back
Blogs

KYC in Banking: Requirements, Process, and What Regulators Actually Check

KYC in Banking: Requirements, Process, and What Regulators Actually Check
Richard M. AUGUST 18, 2023 17 minutes read

TL;DR

 

  • The FCA fined Nationwide £44,078,500 in December 2025 for out-of-date customer files.
  • The penalty targeted maintenance of existing customers, not checks at account opening.
  • Bank KYC has four obligations, and only two of them happen at onboarding.
  • The UK, EU and US all set KYC record retention at five years.
  • India prescribes a refresh in years, while the UK leaves it risk-based.

On 12 December 2025 the Financial Conduct Authority (FCA) fined Nationwide Building Society £44,078,500 for inadequate anti financial crime systems and controls between October 2016 and July 2021. The reason? They failed to implement satisfactory systems for ensuring risk assessments and due diligence up to date across their customer base. Nor did they have proper systems in place to keep track of what they did afterwards.

The Final Notice describes a customer who received more than £27 million in proceeds of fraud against a government support scheme through personal accounts, most of it inside a single week.

That gap between the rules a bank reads and the failures a regulator punishes is the subject of this guide. KYC in banking is usually taught as a list of documents to collect on day one. Supervisors assess it as a set of obligations with clocks attached.

What is KYC in banking?

KYC basically means to know your customer. In banking, that would include understanding the purpose of the relationship of the customers, assess the financial crime risk it carries, and keep that assessment current for as long as the account stays open. KYC is a part of a bank’s wider anti-money laundering programme, and is usually the first step within KYC rather than the whole of it.

Having a clear distinction between the two is important because banks might think of buying a KYC tool to comply with regulations, when in reality they’re only having some part of it addressed.

There are four obligations that regulated firms have to comply with and only two of them pertain to the initial onboarding of a customer.

Why is KYC mandatory for banks?

KYC is mandatory for the banking industry because primary legislation makes it a condition of operating rather than a matter of good practice, and because an unmeasured customer is an unpriced risk. No single global rulebook sets out which KYC banks must perform, since the obligation is written nationally. Two frameworks nonetheless set the substance for most of the world’s banks, and they agree on what a bank must do while differing on how precisely they say it.

KYC banking regulations in the United States

The Bank Secrecy Act of 1970 established the recordkeeping baseline, and section 326 of the USA PATRIOT Act turned identification into a written programme requirement. FinCEN’s implementing rule for banks at 31 CFR 1020.220 requires a Customer Identification Programme, meaning a documented procedure for collecting and verifying a customer’s name, date of birth, address and identification number. The same rule requires screening against federal terrorist lists within a reasonable period after the account opens, and it is the source of the identification notice most account-opening screens now carry.

A separate FinCEN rule adds a beneficial ownership requirement for legal entity customers, so a bank opening a company account must identify the natural persons behind it. That part of the US framework has been under active revision through 2025 and 2026, so treat any specific threshold as a point to confirm against the current rule text rather than a settled number.

KYC regulations for banks in the UK and EU

In the UK the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017) carry the obligation and the FCA supervises it. In the EU the framework is being replaced rather than amended. Regulation (EU) 2024/1624, the Anti-Money Laundering Regulation known as AMLR, was published in the Official Journal on 19 June 2024 and applied from 10 July 2027. Because a regulation applies directly with no national transposition step, the same customer due diligence text will bind a bank in Dublin and a bank in Tallinn. For a group running one KYC policy per market today, that removes the local-interpretation argument which has justified the divergence, and it makes the 27 separate policies a cost rather than a defence. The Anti-Money Laundering Authority (AMLA), which will supervise the largest cross-border firms, has been operational since 1 July 2025.

The importance of KYC in banking is easiest to see in the negative. A bank that cannot evidence who its customers are cannot price its own risk, cannot answer a supervisor, and cannot rely on its own transaction monitoring, because monitoring compares behaviour against an expected profile that KYC is supposed to establish. When the profile is stale, the comparison means little and the alerts that follow are noise.

What are the KYC requirements for banks?

KYC requirements for banks fall into four obligations, and how strong a bank’s programme is, is based on all four. If one of the four is very strong, and others aren’t, it won’t be considered satisfactory. The Nationwide notice is a clear example of it, as they weren’t able to fulfil one of the four obligations, but were doing just fine in the other three.

Identification and due diligence establish the record. Ongoing monitoring and record-keeping keep that record usable. The Nationwide notice is a reminder that a bank can perform the first pair adequately and still be fined over the second.

Customer identification

Collect and verify a customer’s identity at the very start of the relationship. A bank must record what information/documents were collected, the type and number of any document that was used, the methods and results of any non-documentary verification, and how any substantive discrepancy was resolved, if there was any.

Customer due diligence and risk rating

Establish the purpose and intended nature of the relationship, then assign a risk rating that reflects it. Enhanced due diligence is the higher tier of the same obligation rather than a separate one, applied where risk is elevated by a politically exposed person, a high-risk jurisdiction, an opaque ownership structure or a product with known laundering utility. What a supervisor tests is rarely the rating itself. It is whether the reasoning behind the rating was recorded and whether anyone has looked at it since.

Ongoing monitoring

Scrutinise transactions against the expected profile and keep due diligence information current. Two review types sit inside this obligation, and the Nationwide notice turned on the absence of both. Periodic review runs on a cycle set by risk. Event-driven review runs when something changes, such as a customer’s occupation, an account’s transaction pattern, a new party added to a mandate, or a screening hit that did not exist at onboarding.

Record keeping

Retain due diligence documents and transaction records for the statutory period, produce them on request, and then delete the personal data. Retention is a ceiling as well as a floor, a point covered in the clock section below.

KYC bank requirements What the rule requires What a supervisor asks to see
Customer identification Collect and verify name, date of birth, address and identification number, and screen against government lists The documented procedure, plus the record of what was collected, how it was verified and how discrepancies were resolved
Customer due diligence Establish the purpose and intended nature of the relationship, assign a risk rating, and apply enhanced measures to higher-risk cases The rating, the reasoning behind it, the trigger that escalated a case, and the date of last review
Ongoing monitoring Scrutinise activity against the expected profile and keep due diligence information current Periodic and event-driven review records, and evidence that new controls reached the whole customer book
Record-keeping Retain due diligence and transaction records for the statutory period, then delete personal data Retrieval on request, and evidence of deletion once the period expires

What does the KYC in the banking process look like?

The KYC banking process runs in five stages, and the first four usually complete within minutes of an application. Collect identity data, verify it, screen the customer, rate the risk, then monitor. The fifth stage has no end date, which is why it is the stage that decays.

The five stages end to end

  1. Collection: Capture identity data and the supporting document or credential, either through a branch, an app or an onboarding flow for banks.
  2. Verification: Confirm the document is genuine and that the person presenting it is its holder, usually through document forensics plus a biometric liveness check.
  3. Screening: Check the customer against sanctions lists, politically exposed person data and adverse media before the account transacts.
  4. Risk rating: Combine identity, screening and declared purpose into a rating that sets the monitoring intensity and the review cycle.
  5. Monitoring and refresh: Compare activity against the expected profile, and re-verify when the risk picture changes or the review cycle falls due.

Can banks onboard customers remotely?

Yes, and remote onboarding is now the default retail channel in most markets. Remote does not mean unsupervised, because the evidential burden is identical and in some respects heavier. A bank still has to show what it verified and how, which is why document capture is paired with liveness detection to prove a live person was present rather than a photograph or a screen replay.

Some markets keep a person in the decision for certain customer types. Thees Buschmann, a DACH compliance specialist at Chevron Group, has made the point that German rules require a human to make the final video-identification decision, which caps how far automation can go in that market. Where that applies, video assisted verification is the route that satisfies the requirement without returning the customer to a branch.

What documents do banks need for KYC?

In most cases, for an individual’s account, banks would only need a government-issued photo identity document plus evidence of address. KYC documents such as passports, national identity cards, driving licences, residence permits, utility bills, and bank statements could also be used based on where the bank is located and what value each of these documents holds in that region/country.

For company accounts, the bank needs incorporation records, evidence of the ownership structure, and identification of the stakeholders behind it. Accepted document types in that case are set nationally rather than internationally, so a number of documents would be needed to satisfy different regulators.

Several markets have moved further, accepting a national digital identity or an authoritative database check in place of an uploaded document, which removes the document from the journey without removing the evidence.

Bank KYC Lifecycle

Which KYC obligations carry a clock?

Retention is the only KYC obligation with a fixed deadline in every major regime, and the rest are risk-based unless a national regulator says otherwise. That distinction is the one most guides collapse. Retention is also the most precisely drafted rule in the framework, while refresh is the most misread, because the absence of a stated interval gets mistaken for the absence of a duty.

How long must banks retain KYC records?

Five years is the floor in all three major regimes, though the clock starts in different places. The US rule runs two separate clocks. Under 31 CFR 1020.220 a bank retains the customer’s identifying information for five years after the account closes, and retains the description of documents relied on, the verification methods and results, and the resolution of discrepancies for five years after that record is made. A bank that dates everything from account closure is therefore holding some records longer than required and, more awkwardly, may have deleted others too early.

In the UK, regulation 40 of the Money Laundering Regulations 2017 sets five years from the end of the business relationship, caps transaction records at ten years, and then requires the bank to delete the personal data unless a specific exception applies. Retention is a ceiling as well as a floor in that framework, so an archive that keeps everything forever is a breach in the other direction. From 10 July 2027 the AMLR harmonised the EU position at five years, replacing the national variation that currently runs from five years in some member states to ten in others.

How often must banks refresh KYC?

No universal cadence exists in the UK or the EU. Both require due diligence information to be kept up to date on a risk-sensitive basis, which is precisely why the Nationwide notice turned on the absence of any periodic or event-driven review process rather than on a missed date. A bank cannot breach a deadline that was never set, but it can fail to have a process at all, and the absence of a process is what regulators cite.

India takes the opposite approach. The Reserve Bank of India’s Master Direction on Know Your Customer prescribes periodic updation at least once every two years for high-risk customers, once every eight years for medium risk and once every ten for low risk. The practical implication for a multi-market bank is that one global refresh policy will either breach the prescriptive regimes or over-invest in the risk-based ones.

Obligation The clock Where
Retain identifying information 5 years after the account closes US, 31 CFR 1020.220
Retain verification records and discrepancy resolutions 5 years after the record is made US, 31 CFR 1020.220
Retain due diligence and transaction records 5 years from the end of the relationship, transaction records capped at 10 UK, MLRs 2017 reg. 40
Delete personal data Once the retention period expires UK, MLRs 2017 reg. 40
Retain due diligence records 5 years, harmonised across all member states EU, AMLR, from 10 July 2027
Refresh customer KYC Risk-sensitive, no stated interval UK and EU
Refresh customer KYC Every 2, 8 or 10 years by risk tier India, RBI Master Direction

Ray Blake, a former head of compliance and MLRO who now runs Risk Alert 24/7, puts the decay problem in domestic terms. Compliance technology cannot be installed and forgotten, because like a house plant an unmaintained system dies. The cadence is only the visible part of that. What decays underneath is the assumption that the customer described in the file is still the customer holding the account.

What are the penalties for KYC failures in banking?

Penalties for KYC failures in banking run from public fines to restrictions on growth, and the fine is often not the most expensive part. Since 2021 the FCA has imposed 13 fines totalling £300,767,526 on banks for anti-money laundering systems and controls failings. Every one of those notices also produced a remediation programme and years of supervisory attention, which is the cost that does not appear in the press release.

The Nationwide penalty shows how the arithmetic works. The FCA calculated £62,969,297 and applied a 30% discount because the firm settled, landing at £44,078,500. Early cooperation is worth roughly a third of the headline number, which is a real incentive to self-report rather than contest.

Money is not the only lever. In May 2026 the Office of the Comptroller of the Currency issued aconsent order against a nationalte bank for deficiencies in its Bank Secrecy Act and anti-money laundering compliance programme, carrying a zero-dollar civil money penalty. No fine, and yet a consent order constrains what a bank may launch and where it may expand until the deficiencies close. For a growing institution that is frequently the more expensive outcome.

Oonagh van den Berg of Raw Compliance AI describes the underlying change in supervisory posture. Regulators have moved from asking whether a framework looks right on paper to asking whether it is operationally effective and defensible. A policy document that describes annual reviews satisfies the first question and fails the second if nobody ran them.

Where bank KYC programmes actually fail

Programmes fail at the joins rather than at the checks. Onboarding is well funded because it is measured, visible and tied to conversion. Periodic review is funded from a different budget, often sits with a different team, and produces no metric anyone celebrates. The customer record splits in two as a result, and the version that justified a risk rating at account opening is not the version a reviewer opens three years later.

Tom Gadsden, VP of Product at Shufti, argues the fix is structural rather than procedural. The next step is consolidating KYC, fraud and AML into one view, setting the account’s nature and purpose at onboarding and joining that record to transaction monitoring, so the monitoring layer knows what the account was opened to do. Without that join, monitoring is comparing behaviour against an assumption instead of against a stated purpose.

The sequence matters too. James Eastham of Scion Compliance makes the case for front-loading friction on higher-value relationships, because those customers expect questions upfront, and the error is going light at onboarding and then querying every subsequent transaction. Five checks worth running against your own programme:

  • Name the owner of each customer file: If onboarding, monitoring and review sit in three teams, confirm who is accountable for the record end to end.
  • Set review triggers, not only review dates: A calendar cycle catches slow drift and misses the sudden change, which is the one that appears in enforcement notices.
  • Check that new controls reached the whole book: Nationwide implemented remediation workstreams that did not apply across its entire customer base, and partial coverage was part of the finding.
  • Test retrieval and deletion: Produce a five-year-old due diligence file on demand, then confirm that expired personal data was actually deleted.
  • Join the onboarding record to monitoring: Check that the stated purpose captured at account opening is visible to the team reviewing alerts.

Where Shufti’s KYC solution fits in bank KYC

The obligation that decays is rarely the one a bank under-resources deliberately. Periodic review lives in a different system from onboarding, often under a different team, and the record that justified a risk rating three years ago is not the record the reviewer opens today.

Shufti’s ongoing monitoring layer holds each verified customer against the risk baseline built at onboarding from their identity, documents and screening results. When a sanctions match, an adverse media hit or a behavioural anomaly crosses a configured threshold, Shufti triggers re-verification of that customer automatically rather than waiting for the next scheduled review, and the alert arrives with the supporting evidence already attached. The same baseline record carries forward into the review, so the comparison is like with like and the reviewer is not rebuilding the file from raw data.

Test how Shufti’s KYC solution keeps a bank’s KYC record current between reviews using your own data, then book a demo.

Frequently Asked Questions

Why is KYC mandatory for banks?

Because primary legislation makes it a condition of operating. In the US, section 326 of the USA PATRIOT Act requires a written Customer Identification Programme. In the UK, the Money Laundering Regulations 2017 impose customer due diligence. Supervisors treat gaps as a licensing matter rather than a policy preference.

What documents do banks need for KYC?

For an individual, a government-issued photo identity document such as a passport, national identity card or driving licence, plus evidence of address. Accepted types vary by jurisdiction, and several markets now accept a national digital identity or an authoritative database check instead of an uploaded document.

How long does bank KYC take?

Automated checks on a straightforward retail application usually resolve in under a minute, and Shufti reports most verifications completing in 15 to 60 seconds. Cases needing enhanced due diligence, manual review or a video session take longer, from a few hours to several working days.

Can banks onboard customers remotely?

Yes. Remote onboarding is the default retail channel in most markets, using document capture with a biometric liveness check or a national digital identity where one exists. Some jurisdictions still require a person in the decision for certain customer types, which is where video-assisted verification applies.

How often must banks refresh KYC?

The UK and EU set no fixed cadence and require information to be kept current on a risk sensitive basis. India prescribes minimum intervals of two years for high-risk customers, eight years for medium risk and ten years for low risk under the RBI Master Direction on KYC.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.