TL;DR
- KYCC is a market term, not a regulatory obligation with a rule of its own.
- FATF confirmed in 2016 that correspondents need not vet their respondents’ customers.
- Two US provisions do reach through, covering payable-through accounts and nested relationships.
- US law pulls customer data across, while UK and EU law require provable access instead.
- Treating KYCC as compulsory pushed banks to exit whole regions instead.
In October 2016 the Financial Action Task Force (FATF) published guidance on correspondent banking services to help businesses understand what they are not required to perform KYCC (Know Your Customer’s Customers).
Previously, banks thought they were obliged to run due diligence on their customers’ customers, and rather than performing that additional check, banks were dropping clients to save the extra cost. Despite that guidance, the market still sells KYCC as an emerging requirement even when no KYCC rule exists.
However, there are two specific places where the law does reach past your customer to the parties behind them, and both are written as account features rather than as a general duty. This guide sets out where that line falls and what to build instead of dropping customers.
What is KYCC?
KYCC means looking past your direct customer to the customers they serve and assessing the risk that arrives through them. The KYCC full form is know your customer’s customer, and search engines return it both ways, so knowing your customer’s customer without the apostrophe describes the same thing. The KYCC meaning that matters operationally is narrower than most definitions allow, because the phrase names a risk question rather than a legal duty.
One confusion is worth clearing first. KYCC looks downstream, at whoever your customer serves. Beneficial ownership looks upstream, at the people who own or control your customer. Only one of the two is codified. Almost every AML regime requires you to identify a UBO, and none requires you to identify your customer’s customers, save for two narrow exceptions this guide comes to below.
What is the difference between KYC and KYCC?
The difference between KYC and KYCC is a difference of legal standing rather than of depth. KYC is an obligation you owe about a person who is already your customer. KYCC describes an inference you may want to draw about people you have no relationship with, no contract with, and usually no lawful basis to profile.
| Criteria | KYC | KYCC |
| Subject | Your direct customer | Your customer’s customers |
| Legal status | Codified in every major AML regime | No standalone rule in any regime |
| Who holds the duty | You | Your customer, in almost every case |
| What evidence looks like | Verified identity records, a risk rating, monitoring history | An assessment of the intermediary, plus proof you can reach its records |
| When it applies | Every customer, tiered by risk | Only where a named account feature or trigger is present |
That distinction carries a practical consequence. Because your customer’s customers are not your customers, you cannot compel their identity documents, and asking your customer for a client list creates a data protection problem for both parties before it creates any compliance benefit. What you can ask for is evidence that your customer runs the controls it says it runs.
Is KYCC required by law?
No AML regime contains a standalone KYCC obligation, and the international standard setters have said so directly rather than leaving it to inference.
What FATF says
FATF clarified in June 2015, and restated in its October 2016 guidance, that a correspondent must perform customer due diligence on the respondent institution and is not required to conduct due diligence on each individual customer of that respondent. The clarification was not academic housekeeping.
FATF wrote it because de-risking had become the default response to an obligation nobody could size, and because avoiding risk rather than managing it runs against the risk-based approach at the core of the Recommendations.
What supervisors expect
Supervisors reached the same conclusion in practice, not just in principle. A September 2020 study by the Financial Stability Institute at the Bank for International Settlements, Closing the loop: AML/CFT supervision of correspondent banking, reports that every jurisdiction surveyed had clarified that correspondents are not required to perform due diligence on the customers of their respondents, and had issued guidelines or best practices saying so.
So a firm defending its KYCC programme on the grounds that supervisors expect one is defending it on the wrong basis. What supervisors expect is a defensible assessment of the respondent, not a register of the respondent’s clients.
Why the term means different things
The phrase travels badly, which is part of why no single rule governs it. In correspondent banking, the customer’s customer is the respondent’s account holder. In card acquiring and payment facilitation, it is the sub-merchant, and one layer further down it is the cardholder that the sub-merchant charges. Outside financial services, the phrase has been borrowed again, for tracing the provenance of a telephone number through the chain of carriers that handled it. Three sectors, three different risk questions, three separate rulebooks, and no common obligation running through any of them.
How does KYCC apply to correspondent banking?
Correspondent banking is where the KYCC question started and where the answer is drawn most precisely. FATF Recommendation 13 governs these relationships, and the duties it generates point at the respondent institution rather than at the people who bank with it.
What you must check
Under regulation 34 of the UK MLR 2017, which implements the FATF standard, a correspondent entering a payment relationship with a third-country respondent must gather enough information to understand the respondent’s business fully, determine its reputation and the quality of its supervision from credible public sources, assess its money laundering and terrorist financing controls, obtain senior management approval before opening the relationship, and document which institution is responsible for what. Every one of those duties points at the institution. Not one of them asks who its customers are.
Payable-through accounts
A payable-through account is a correspondent account through which the foreign bank lets its own customers transact, directly or through a subaccount, in banking activities usual in the United States. Where a US covered institution owes enhanced due diligence, 31 CFR 1010.610(b)(1)(iii)(A) requires it to take reasonable steps to obtain from the foreign bank the identity of any person with authority to direct transactions through that payable-through account, together with the source and the beneficial owner of the funds in it.
That is a real reach-through to the customer’s customer, and it exists for a structural reason. Once the respondent hands its customers direct access, the account has stopped behaving like the respondent’s account and started behaving like theirs.
What are nested relationships, and why are they a risk
Nesting, sometimes called downstream correspondent clearing, occurs where your respondent provides correspondent services to other institutions that then reach your account through it. The risk is one of inherited exposure you never priced. Payments arriving in your account originate with institutions you never assessed, chartered in jurisdictions you may never have reviewed, and your monitoring shows the respondent’s name rather than theirs. US law treats this as the second reach-through.
Under 31 CFR 1010.610(b)(2) the covered institution must determine whether the respondent in turn maintains correspondent accounts for other foreign banks that use the account, and if it does, take reasonable steps to obtain information relevant to assessing and mitigating the resulting risk, including where appropriate the identity of those foreign banks. Note where that provision stops. It reaches institutions, not the individuals banking with them.

How US, EU and UK rules differ
The American and European frameworks address the same risk through opposite architectures, and which one applies decides what you actually have to build.
| Regime | Instrument | What it asks about the customer’s customer |
| United States | 31 CFR 1010.610(b)(1)(iii)(A) and (b)(2) | The correspondent itself obtains the identity of those who can direct payable-through transactions, the source and beneficial owner of the funds, and the identity of nested foreign banks |
| United Kingdom | MLRs 2017 reg. 34(1)(f) | The correspondent must be satisfied the respondent has verified and monitors those customers, and can hand over the CDD documents on request |
| European Union, to 9 July 2027 | Directive (EU) 2015/849 art. 19(e) | Same shape as the UK, being satisfied the respondent has done the work and can supply the data on request |
| European Union, from 10 July 2027 | Regulation (EU) 2024/1624 arts. 36 to 39 | Correspondent enhanced due diligence becomes a mandatory category, with dedicated articles for crypto-asset service providers and individual third-country respondents |
The consequence is concrete rather than academic. A firm that has built a warehouse of downstream customer data has built the wrong artefact for a UK or EU relationship, where the examinable output is a documented assurance plus a tested ability to obtain records on request. A firm holding nothing but a contractual assurance has built the wrong artefact for a US payable-through account, where the regulation expects the institution itself to hold identity and beneficial ownership information.
One caution on the 2027 change. Regulation (EU) 2024/1624 replaces the directive with a single directly applicable rulebook from 10 July 2027, so read its corresponding articles against your own relationships rather than assuming the substance simply carries over. Its prohibition on correspondent relationships with shell institutions is not the novelty some coverage suggests, since UK law has carried an equivalent ban since 2017 at regulation 34(2).
Which businesses need to perform KYCC?
Any business that moves value on behalf of an intermediary inherits risk from that intermediary’s customers, though only a few face a codified reach-through. The distinction between real obligation and commercial prudence is worth keeping straight when you scope a programme.
- Correspondent banks: The only sector where the reach-through is written into the rules, and only where a payable-through account or a nested relationship is present.
- Payment processors, acquirers and payment facilitators: Sub-merchant risk is real, and transaction laundering, where a legitimate merchant account is used to process payments for an undisclosed business, is the classic failure. The duty here runs through merchant agreements and card scheme rules rather than through any AML KYCC provision.
- Banking-as-a-service and embedded finance providers: The sponsor institution holds the regulatory relationship while the programme manager holds the customer relationship, which splits knowledge from accountability.
- Marketplaces and platforms: Your seller’s buyers are two steps removed, and dispute and chargeback patterns usually surface the problem before any screening does.
- Virtual asset service providers: Intermediary providers and self-hosted wallets put counterparties beyond your view, and the EU has legislated the point separately at article 37 of Regulation (EU) 2024/1624, which covers cross-border correspondent relationships involving crypto-asset services.
If you sit outside those five, the honest answer is that KYCC is a risk-management choice for you rather than a compliance requirement, and it should be justified on its own terms.
Why KYCC programmes go wrong
KYCC programmes fail in two predictable ways, and neither failure is technological.
The first is the de-risking spiral. An obligation with no defined edge produces costs with no defined edge, and the cheapest way to cap an unbounded cost is to exit the relationship. FATF issued its clarification because that pattern had already taken hold across correspondent networks. The money does not stop moving when a bank withdraws; it simply moves through channels with less transparency, which raises the high risk the exit was supposed to reduce.
, describes the mechanism plainly. “The strength of a verification process is determined by the weakest point in the chain, and that weak point is very often a country, not a tool.” Criminals build an identity where standards are loose, then present it where controls are assumed to be reliable.
Read against the KYCC question, that observation reframes the whole exercise. What reaches you through an intermediary is not the identity of its individual customers; it is the standard that intermediary applies and the jurisdiction where it applies that standard. Assess the standard, and you have assessed most of your exposure. Enumerate the customers, and you hold a list without knowing how carefully any name on it was ever checked.
Can KYCC be automated?
Parts of it automate well, and the parts that matter are not usually the parts demonstrated in a sales meeting. No system can automate the collection of a data set you have no right to collect, so the productive target is the intermediary and the flow rather than the downstream customer. Six things are worth building.
- Screen the intermediary properly, including the people behind it: Entity-level screening that never touches directors, officers and beneficial owners leaves the obvious gap, which is why business AML screening should cover the individuals as well as the company.
- Resolve the entity across jurisdictions: The same business registers under different names in different registries and clears screening each time, so name-variant and cross-border matching does more for accuracy than adding another list.
- Record the reach-through test, not just its outcome: Whether the account is payable-through, whether nesting is present, and what you did about each, written down and dated.
- Contract for the data, then test the contract: UK regulation 34(1)(f)(ii) makes the respondent’s ability to hand over records on request part of your obligation, so a clause nobody has ever exercised is not evidence that it works.
- Monitor the flows for the shape of downstream risk: Structuring, fan-in and fan-out patterns, beneficiary concentration and velocity tell you more about an intermediary’s book than any list of its clients would.
- Re-run the assessment on a trigger rather than a calendar: A new nested institution, a change of ownership, a jurisdictional downgrade or a spike in returned payments each justify a fresh look, and an annual review will miss all four.
None of that requires knowing your customer’s customer by name. All of it is evidence you can put in front of a supervisor.
Where Shufti fits in downstream risk
If your business sits behind an intermediary, the honest position is that you will never see its customer list, and the exposure still lands on your balance sheet. What you can see is the money, and most compliance stacks make that harder than it needs to be by scoring transactions in one system while the identity evidence sits in another.
Shufti’s Transaction Monitoring scores each transaction against AML and fraud rules anchored to the verified identity behind the account and evaluates beneficiary risk inside the same engine rather than in a separate queue. Verified identity, screening status, customer risk and transaction behaviour resolve into one decision trail a reviewer can export and defend. An alert on an intermediary’s flow therefore arrives with its context already attached, instead of being reassembled from three systems after the question has been asked.
Frequently Asked Questions
What is KYCC?
KYCC, or know your customer's customer, means looking past your direct customer to the customers they serve and assessing the risk arriving through them. The term describes a risk question rather than a legal duty, since no AML regime contains a standalone KYCC rule.
What is the difference between KYC and KYCC?
KYC is a codified obligation about your own customer, tiered by risk and owed on every relationship. KYCC concerns parties you have no relationship or contract with, and applies as a legal duty only where a specific account feature such as a payable-through account is present.
Why is KYCC important for AML compliance?
Risk reaches you through intermediaries whether or not a rule names it. An intermediary applying weak standards in a loose jurisdiction passes that weakness to you, so assessing the intermediary's controls and monitoring its flows protects you where enumerating its customers would not.
Which businesses need to perform KYCC?
Correspondent banks face the only codified reach-through, and then only for payable-through or nested accounts. Payment processors, banking-as-a-service providers, marketplaces and virtual asset service providers carry genuine downstream exposure, but as a risk-management choice rather than a named obligation.
How does KYCC apply to correspondent banking?
Correspondents owe due diligence on the respondent institution, not on each of its customers, as FATF confirmed in 2016. Two exceptions apply under US law, covering payable-through accounts and nested relationships, both requiring information about parties beyond the respondent itself.
What are nested relationships, and why are they a risk?
Nesting occurs where your respondent provides correspondent services to other institutions that reach your account through it. Payments then originate with institutions you never assessed, in jurisdictions you never reviewed, while your monitoring displays only the respondent's name.
Can KYCC be automated?
The useful parts automate well. You can automate the screening of an intermediary and its officers, entity resolution across jurisdictions, and transaction-flow monitoring. A list of your customer's customers falls outside that, because you generally have no lawful basis to hold one.















