This guide walks through the KYC verification process step by step, the three core stages, the checks and documents each one runs on, the methods providers use, and how to choose or implement it.
Every regulated business asks new customers the same question before letting them in. Are you really who you say you are? KYC verification, short for Know Your Customer verification, is the process that answers it, and this guide is about that process itself, not the theory behind it.
Below is the three-step sequence in order, the checks and documents each step actually runs on, the methods providers use to run them, how the process changes by region, and what to look for when you choose a provider or build the process yourself.
The KYC verification process: three core steps
The KYC verification process runs in three steps, and every regulated sector follows the same underlying sequence even when the depth of each step changes with the customer’s risk. And it does not end once a customer is onboarded. A customer who passes every check on day one can still become a money-laundering risk six months later, which is why the third step never really switches off.
- Customer Identification Program (CIP): Collects and verifies who the customer is.
- Customer Due Diligence (CDD): Assesses how risky that customer is and screens them against watchlists.
- Ongoing monitoring: Tracks the customer’s activity for as long as the relationship continues.
Regulators require all three steps by law, and if you get them wrong, you can face penalties. The EU’s Anti-Money Laundering Authority can fine serious breaches up to €10 million or 10% of annual turnover, whichever is higher, and FinCEN has issued US penalties in the hundreds of millions of dollars for a single bank.
Here is what happens at each stage.
Step 1: Customer Identification Program (CIP)
Customer Identification Program answers a simple question: ‘Is this person really who they say they are?’ To do so, a business collects four core data points under CIP, the customer’s full name, date of birth, residential address, and an identification number, then verifies each against a reliable source, usually a government-issued document.
In the United States, these steps are stated in Section 326 of the USA PATRIOT Act, codified at 31 CFR 1020.220, which requires banks to maintain a written Customer Identification Program that does exactly this.
Step 2: Customer Due Diligence (CDD)
Once identity is confirmed, Customer Due Diligence decides how risky the customer is. The process entails screening the customer against sanctions lists, watchlists, and politically exposed person (PEP) databases, meaning individuals who hold or have held a prominent public position and therefore carry higher corruption risk, then assigns a risk rating to that individual.
| Risk level | Trigger criteria | Required action |
| Low | Standard retail customer, domestic geography, predictable transaction pattern | Basic CDD: identity checks and watchlist screening |
| Medium | Foreign national, high-value transactions, complex ownership structure | Standard CDD plus enhanced watchlist screening and source-of-funds review |
| High | PEP match, sanctioned jurisdiction, adverse media hit, unusual activity | Enhanced Due Diligence (EDD): a deeper, source-of-wealth investigation |
Most customers clear standard due diligence without ever needing an enhanced review because of their low risk. On the other hand, the customers who do trigger EDD are the ones a compliance team should focus on, and that is exactly what the next section addresses.
Step 3: Ongoing monitoring
The third step is ongoing monitoring that watches transactions and behaviour for signs of new risk after the account has been opened, including unusual transaction patterns, logins from unexpected locations, and activity that no longer matches the customer’s original profile. When something looks off, the customer can be re-verified or escalated for review.
Security teams often call this model perpetual KYC, or pKYC, since it replaces a fixed annual review with continuous, trigger-based re-checks. The section on periodic refresh below sets out how often that should happen by risk tier.
Is it three steps or four? Where EDD fits
Some frameworks present a four-step model, but it is an extension of the three-step process rather than a replacement for it.
| Framework | Step 1 | Step 2 | Step 3 | Step 4 |
| Three-step (traditional) | CIP: identity verification | CDD: risk assessment and screening | Ongoing monitoring | – |
| Four-step (emerging) | CIP: identity verification | CDD: standard risk assessment | EDD: enhanced due diligence for high-risk cases | Ongoing monitoring |
The four-step view simply breaks Enhanced Due Diligence out of CDD and gives it its own named stage. That makes operational sense for a fintech, crypto exchange, or wealth manager that runs EDD often enough to justify a dedicated workflow and escalation team.
A different four, inside the regulation itself
A separate four shows up in the regulatory text, and it is easy to confuse with the four-step question above. FinCEN’s CDD Rule, at 31 CFR 1020.210(b), sets out four core elements a bank’s due diligence programme must cover: identifying and verifying customer identity, identifying and verifying beneficial owners, understanding the nature and purpose of the relationship, and ongoing monitoring.
Those four elements sit entirely inside the three steps above rather than beside them. The first maps to CIP, the middle two sit inside CDD, and the fourth is the ongoing monitoring step. They describe what CDD has to contain in detail, not a fourth step layered on top of it.
What are KYC checks?
A KYC step is the framework, whereas a KYC check is the individual verification performed inside it, and these two should not be confused as one.
| Check | What it confirms |
| Document authentication | The submitted ID is genuine, current, and unaltered |
| Biometric liveness | A real person is present, not a photo, mask, or deepfake |
| Face match | The live selfie matches the photo on the document |
| Sanctions screening | The customer does not appear on a government or international sanctions list |
| PEP screening | The customer is not a politically exposed person, or is flagged for enhanced review if they are |
| Adverse media screening | No credible negative press ties the customer to financial crime |
| Address verification | The declared address is real and belongs to the customer |
KYC verification documents
KYC verification usually requires a government-issued photo ID and proof of address, with additional source of funds documents required for higher-risk customers. Below is a list of some KYC documents that can be used for KYC verification.
| Document type | Examples | What it verifies |
| Government photo ID | Passport, national ID, driving licence | Identity and nationality |
| Proof of address | Utility bill, bank statement | Residential address |
| Source of funds (high risk) | Payslip, tax return, bank statement | Financial legitimacy |
Documents for business customers
Business customers need a different document set that proves the company is real and shows who stands behind it. That means a certificate of incorporation, a registered business address, an ultimate beneficial ownership (UBO) register showing who actually owns and controls the company, and identification for its directors.
Business verification is a distinct discipline called Know Your Business (KYB), which applies the same logic as KYC to a legal entity instead of a person.
How long does KYC verification take?
Automated KYC verification typically takes seconds to a few minutes. Manual or document-heavy reviews can take one to several business days, depending on the customer’s risk level, document quality, and whether enhanced due diligence applies. Speed comes down to how much of the process runs without a human in the loop.
KYC review and periodic refresh
KYC obligations continue well past onboarding. Regulators now expect proof that a customer’s profile stays current for as long as the relationship lasts, not just on the day it started. Three review models exist side by side.
| Risk tier | Typical refresh cadence |
| Low risk | Every 3 years, or trigger-based only |
| Medium risk | Every 1 to 2 years |
| High risk (PEP, sanctioned jurisdiction) | Annually, plus continuous trigger-based screening |
How Shufti handles KYC verification end to end
If you have ever watched a genuine customer abandon onboarding on the third document retry, you have seen the real cost of a KYC stack that was not built for the markets your customers are actually in. Most identity verification vendors patch that gap with a third-party liveness engine bolted onto someone else’s document OCR, which is exactly where the handoffs between vendors tend to break.
Shufti runs identity verification, biometric liveness, and AML screening as one workflow it owns end to end, across 240+ countries and territories and in 150+ languages, with iBeta Level 3 conformance under ISO/IEC 30107-3 for liveness attack detection. Macropay, a cross-border payments fintech, runs its KYB and KYC compliance through that single layer instead of stitching together separate tools.
Frequently Asked Questions
What are the three steps in the KYC verification process?
The three steps are Customer Identification Program (CIP), which verifies identity using government documents and biometrics, Customer Due Diligence (CDD), which screens for sanctions, PEP, and watchlist risk, and ongoing monitoring, which tracks activity after onboarding.
Are there 4 steps in the KYC process?
Some frameworks split Enhanced Due Diligence (EDD) out of CDD as its own stage, which produces four steps, CIP, CDD, EDD, and ongoing monitoring, instead of three. It is an extension of the three-step model, not a different process.
What documents are required for KYC verification?
Most programmes require a government-issued photo ID, such as a passport, national ID, or driving licence, plus proof of address such as a utility bill or bank statement. Higher-risk customers may need source-of-funds documents too.
How long does KYC verification take?
Automated document and biometric verification typically completes in seconds to a few minutes. Manual review or enhanced due diligence can extend that to one or several business days.
Is KYC verification safe?
Yes, with a reputable provider. Look for encryption in transit and at rest, data minimisation, and compliance with a recognised privacy framework such as the GDPR before trusting a provider with identity data.
How do I get KYC verified?
You typically submit a government-issued ID, complete a short biometric liveness check such as a selfie or brief video, and provide an address for verification. Automated platforms can complete all three in under a minute.
Can KYC verification be done online?
Yes. Document-based and biometric checks, database verification, and video KYC can all run entirely online, which is why most banks, crypto exchanges, and gaming platforms now onboard customers remotely by default.
What happens if KYC verification fails?
A failed check usually routes the customer to resubmit a clearer document or retry the liveness check. If identity still cannot be confirmed, or the customer is flagged on a sanctions or PEP list, the business declines or escalates the account for manual review.
How often does KYC need to be updated?
It depends on risk tier. Low-risk customers are often reviewed every few years or only when a trigger event occurs. High-risk customers, including PEPs and those in higher-risk jurisdictions, typically need an annual review plus continuous automated screening.
What happens if a business fails to comply with KYC requirements?
Penalties can be severe. The EU's Anti-Money Laundering Authority can fine serious breaches up to 10% of annual turnover or €10 million, whichever is higher, and FinCEN has issued US penalties in the hundreds of millions of dollars. Non-compliance can also mean lost banking relationships and personal liability for compliance officers.















