us

216.73.216.229

Back
Blogs

KYC Verification Process: The Steps, Methods, and Documents You Need

KYC Verification Process: The Steps, Methods, and Documents You Need
Richard M. APRIL 25, 2025 9 minutes read

This guide walks through the KYC verification process step by step, the three core stages, the checks and documents each one runs on, the methods providers use, and how to choose or implement it.

Every regulated business asks new customers the same question before letting them in. Are you really who you say you are? KYC verification, short for Know Your Customer verification, is the process that answers it, and this guide is about that process itself, not the theory behind it.

Below is the three-step sequence in order, the checks and documents each step actually runs on, the methods providers use to run them, how the process changes by region, and what to look for when you choose a provider or build the process yourself.

The KYC verification process: three core steps

The KYC verification process runs in three steps, and every regulated sector follows the same underlying sequence even when the depth of each step changes with the customer’s risk. And it does not end once a customer is onboarded. A customer who passes every check on day one can still become a money-laundering risk six months later, which is why the third step never really switches off.

  1. Customer Identification Program (CIP): Collects and verifies who the customer is.
  2. Customer Due Diligence (CDD): Assesses how risky that customer is and screens them against watchlists.
  3. Ongoing monitoring: Tracks the customer’s activity for as long as the relationship continues.

Regulators require all three steps by law, and if you get them wrong, you can face penalties. The EU’s Anti-Money Laundering Authority can fine serious breaches up to €10 million or 10% of annual turnover, whichever is higher, and FinCEN has issued US penalties in the hundreds of millions of dollars for a single bank

Here is what happens at each stage.

Step 1: Customer Identification Program (CIP)

Customer Identification Program answers a simple question: ‘Is this person really who they say they are?’ To do so, a business collects four core data points under CIP, the customer’s full name, date of birth, residential address, and an identification number, then verifies each against a reliable source, usually a government-issued document. 

In the United States, these steps are stated in Section 326 of the USA PATRIOT Act, codified at 31 CFR 1020.220, which requires banks to maintain a written Customer Identification Program that does exactly this.

Step 2: Customer Due Diligence (CDD)

Once identity is confirmed, Customer Due Diligence decides how risky the customer is. The process entails screening the customer against sanctions lists, watchlists, and politically exposed person (PEP) databases, meaning individuals who hold or have held a prominent public position and therefore carry higher corruption risk, then assigns a risk rating to that individual.

Risk level Trigger criteria Required action
Low Standard retail customer, domestic geography, predictable transaction pattern Basic CDD: identity checks and watchlist screening
Medium Foreign national, high-value transactions, complex ownership structure Standard CDD plus enhanced watchlist screening and source-of-funds review
High PEP match, sanctioned jurisdiction, adverse media hit, unusual activity Enhanced Due Diligence (EDD): a deeper, source-of-wealth investigation

Most customers clear standard due diligence without ever needing an enhanced review because of their low risk. On the other hand, the customers who do trigger EDD are the ones a compliance team should focus on, and that is exactly what the next section addresses.

Step 3: Ongoing monitoring

The third step is ongoing monitoring that watches transactions and behaviour for signs of new risk after the account has been opened, including unusual transaction patterns, logins from unexpected locations, and activity that no longer matches the customer’s original profile. When something looks off, the customer can be re-verified or escalated for review.

Security teams often call this model perpetual KYC, or pKYC, since it replaces a fixed annual review with continuous, trigger-based re-checks. The section on periodic refresh below sets out how often that should happen by risk tier.

Is it three steps or four? Where EDD fits

Some frameworks present a four-step model, but it is an extension of the three-step process rather than a replacement for it.

Framework Step 1 Step 2 Step 3 Step 4
Three-step (traditional) CIP: identity verification CDD: risk assessment and screening Ongoing monitoring
Four-step (emerging) CIP: identity verification CDD: standard risk assessment EDD: enhanced due diligence for high-risk cases Ongoing monitoring

The four-step view simply breaks Enhanced Due Diligence out of CDD and gives it its own named stage. That makes operational sense for a fintech, crypto exchange, or wealth manager that runs EDD often enough to justify a dedicated workflow and escalation team. 

A different four, inside the regulation itself

A separate four shows up in the regulatory text, and it is easy to confuse with the four-step question above. FinCEN’s CDD Rule, at 31 CFR 1020.210(b), sets out four core elements a bank’s due diligence programme must cover: identifying and verifying customer identity, identifying and verifying beneficial owners, understanding the nature and purpose of the relationship, and ongoing monitoring. 

Those four elements sit entirely inside the three steps above rather than beside them. The first maps to CIP, the middle two sit inside CDD, and the fourth is the ongoing monitoring step. They describe what CDD has to contain in detail, not a fourth step layered on top of it.

What are KYC checks?

A KYC step is the framework, whereas a KYC check is the individual verification performed inside it, and these two should not be confused as one.

Check What it confirms
Document authentication The submitted ID is genuine, current, and unaltered
Biometric liveness A real person is present, not a photo, mask, or deepfake
Face match The live selfie matches the photo on the document
Sanctions screening The customer does not appear on a government or international sanctions list
PEP screening The customer is not a politically exposed person, or is flagged for enhanced review if they are
Adverse media screening No credible negative press ties the customer to financial crime
Address verification The declared address is real and belongs to the customer

KYC verification documents

KYC verification usually requires a government-issued photo ID and proof of address, with additional source of funds documents required for higher-risk customers. Below is a list of some KYC documents that can be used for KYC verification.

Document type Examples What it verifies
Government photo ID Passport, national ID, driving licence Identity and nationality
Proof of address Utility bill, bank statement Residential address
Source of funds (high risk) Payslip, tax return, bank statement Financial legitimacy

Documents for business customers

Business customers need a different document set that proves the company is real and shows who stands behind it. That means a certificate of incorporation, a registered business address, an ultimate beneficial ownership (UBO) register showing who actually owns and controls the company, and identification for its directors. 

Business verification is a distinct discipline called Know Your Business (KYB), which applies the same logic as KYC to a legal entity instead of a person.

How long does KYC verification take?

Automated KYC verification typically takes seconds to a few minutes. Manual or document-heavy reviews can take one to several business days, depending on the customer’s risk level, document quality, and whether enhanced due diligence applies. Speed comes down to how much of the process runs without a human in the loop.

KYC review and periodic refresh

KYC obligations continue well past onboarding. Regulators now expect proof that a customer’s profile stays current for as long as the relationship lasts, not just on the day it started. Three review models exist side by side. 

Risk tier Typical refresh cadence
Low risk Every 3 years, or trigger-based only
Medium risk Every 1 to 2 years
High risk (PEP, sanctioned jurisdiction) Annually, plus continuous trigger-based screening

How Shufti handles KYC verification end to end

If you have ever watched a genuine customer abandon onboarding on the third document retry, you have seen the real cost of a KYC stack that was not built for the markets your customers are actually in. Most identity verification vendors patch that gap with a third-party liveness engine bolted onto someone else’s document OCR, which is exactly where the handoffs between vendors tend to break.

Shufti runs identity verification, biometric liveness, and AML screening as one workflow it owns end to end, across 240+ countries and territories and in 150+ languages, with iBeta Level 3 conformance under ISO/IEC 30107-3 for liveness attack detection. Macropay, a cross-border payments fintech, runs its KYB and KYC compliance through that single layer instead of stitching together separate tools.

See how Shufti runs identification, due diligence, and monitoring in one workflow on your own onboarding flow, then book a demo.

Frequently Asked Questions

What are the three steps in the KYC verification process?

The three steps are Customer Identification Program (CIP), which verifies identity using government documents and biometrics, Customer Due Diligence (CDD), which screens for sanctions, PEP, and watchlist risk, and ongoing monitoring, which tracks activity after onboarding.

Are there 4 steps in the KYC process?

Some frameworks split Enhanced Due Diligence (EDD) out of CDD as its own stage, which produces four steps, CIP, CDD, EDD, and ongoing monitoring, instead of three. It is an extension of the three-step model, not a different process.

What documents are required for KYC verification?

Most programmes require a government-issued photo ID, such as a passport, national ID, or driving licence, plus proof of address such as a utility bill or bank statement. Higher-risk customers may need source-of-funds documents too.

How long does KYC verification take?

Automated document and biometric verification typically completes in seconds to a few minutes. Manual review or enhanced due diligence can extend that to one or several business days.

Is KYC verification safe?

Yes, with a reputable provider. Look for encryption in transit and at rest, data minimisation, and compliance with a recognised privacy framework such as the GDPR before trusting a provider with identity data.

How do I get KYC verified?

You typically submit a government-issued ID, complete a short biometric liveness check such as a selfie or brief video, and provide an address for verification. Automated platforms can complete all three in under a minute.

Can KYC verification be done online?

Yes. Document-based and biometric checks, database verification, and video KYC can all run entirely online, which is why most banks, crypto exchanges, and gaming platforms now onboard customers remotely by default.

What happens if KYC verification fails?

A failed check usually routes the customer to resubmit a clearer document or retry the liveness check. If identity still cannot be confirmed, or the customer is flagged on a sanctions or PEP list, the business declines or escalates the account for manual review.

How often does KYC need to be updated?

It depends on risk tier. Low-risk customers are often reviewed every few years or only when a trigger event occurs. High-risk customers, including PEPs and those in higher-risk jurisdictions, typically need an annual review plus continuous automated screening.

What happens if a business fails to comply with KYC requirements?

Penalties can be severe. The EU's Anti-Money Laundering Authority can fine serious breaches up to 10% of annual turnover or €10 million, whichever is higher, and FinCEN has issued US penalties in the hundreds of millions of dollars. Non-compliance can also mean lost banking relationships and personal liability for compliance officers.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.