us

216.73.217.78

Back
Blogs

What is KYC? Know Your Customer Meaning, Process, and Requirements

What is KYC? Know Your Customer Meaning, Process, and Requirements
Amir RizwanAmir Rizwan MAY 31, 2026 13 minutes read
In short. KYC is four regulatory requirements, and the fourth is ongoing monitoring. Most programmes stop after the first three. UK misuse of facility cases rose 43% in 2025, while identity fraud filings fell 3%.

In July 2025 the Financial Conduct Authority fined Monzo £21,091,300 after finding the bank “failed to design, implement and maintain adequate customer onboarding, customer risk assessment and transaction monitoring systems to mitigate the risk of financial crime.” Some customers were signed up using well-known London landmarks as their home address.

Those three failures map onto the KYC requirements. There are four in all, and the last one, ongoing monitoring, runs for as long as the account stays open, and we’ll discuss it along with all the other three in this article.

What is KYC?

KYC, short for know your customer, is the set of obligations a regulated business carries to establish who its customers are and to keep that picture current for as long as the relationship lasts.

In the United States those obligations are written down. The Financial Crimes Enforcement Network (FinCEN) Customer Due Diligence Rule requires covered financial institutions to have written policies covering four things.

The four things KYC requires

Under the rule, a covered institution must have written policies that do four things.

  • Identify and verify the customer: In the rule’s words, “identify and verify the identity of customers.” This is the document check, the database lookup, or the biometric match at sign-up.
  • Identify and verify the beneficial owners: Firms must “identify and verify the identity of the beneficial owners of companies opening accounts,” meaning the real people behind a corporate customer.
  • Understand the nature and purpose of the relationship: Firms must “understand the nature and purpose of customer relationships to develop customer risk profiles,” which means recording what the account is for before deciding how closely to watch it.
  • Conduct ongoing monitoring: The rule asks firms to conduct ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.

The third requirement is worth pausing on, because the fourth depends on it. It asks a firm to record what a customer says they will do with the account, in enough detail that later behaviour can be compared against it. 

How KYC relates to CDD, EDD, KYB, and AML

These terms are often used loosely, and the differences matter once you are reading a regulation. The table below explains what CDD, EDD, KYB and AML mean and how they relate to KYC.

Term What it means How it relates to KYC
KYC Knowing who your customer is and what risk they carry, at onboarding and afterwards The overall practice
CDD The standard checks applied to most customers The default level of KYC
EDD Deeper checks for higher-risk customers, including source of wealth and closer monitoring The raised level of KYC
KYB The same work applied to a company, plus the people who own or control it KYC for businesses
AML The wider programme covering screening, transaction monitoring, suspicious activity reporting, governance, and training KYC is one part of AML

What is KYC data?

KYC data is the evidence a firm holds to support its conclusion about who a customer is and what risk they carry. It falls into four groups.

  • Identity attributes: Full name, date of birth, nationality, and residential address, taken from a document or an authoritative database instead of a form the customer filled in.
  • Evidence artefacts: The document image, the chip read, the biometric template, the database response, and the timestamps showing when each was captured.
  • Decision records: Who approved the customer, on what basis, against which version of the policy, and what changed at each later review.

What are the KYC requirements and regulations?

KYC requirements come from national law, and most national law traces back to one global standard. The Financial Action Task Force (FATF) Recommendations set customer due diligence as the baseline for countries.

Recommendation 10 says when it must be applied. The triggers are the start of a business relationship, an occasional transaction above a threshold, any suspicion of money laundering or terrorist financing, and any doubt about data the firm collected earlier.

Framework What it requires Status
FATF Recommendation 10 Customer due diligence at onboarding, above transaction thresholds, on suspicion, and whenever earlier data looks doubtful Global standard that member countries write into national law
United States, FinCEN Customer Due Diligence Rule Identify and verify customers, identify beneficial owners, understand the nature and purpose of the relationship, conduct ongoing monitoring In force
European Union, Regulation (EU) 2024/1624 One directly applicable rulebook covering how due diligence is carried out across all member states Adopted 31 May 2024, applies from 10 July 2027, and from 10 July 2029 for entities listed in Article 3(3)(n) and (o)
United Kingdom, Money Laundering Regulations 2017 Risk-based customer due diligence, with enhanced measures for higher-risk relationships In force, supervised by the Financial Conduct Authority and other bodies depending on sector
Singapore, Monetary Authority of Singapore notices Customer due diligence and ongoing monitoring for financial institutions In force

Who has to do KYC?

FATF splits obliged parties into two groups, and both appear in national law in some form.

  • Financial institutions: Banks, payment and e-money firms, lenders, insurers, investment firms and brokers, and crypto asset service providers in countries that have brought them into scope.
  • Designated non-financial businesses and professions: Casinos and other gambling operators, real estate agents, dealers in precious metals and stones, and legal and accounting professionals when they handle client money or set up companies.
  • Businesses outside the regulated perimeter: Marketplaces and gig platforms often run KYC without a legal duty, because payment partners require it by contract.

A firm operating in several countries has to satisfy each set of rules it touches, which is why multi-market programmes usually settle on the strictest requirement and apply it everywhere.

What are the steps in the KYC process?

The KYC process has five steps. Four of them happen at onboarding and take seconds to minutes. The fifth runs for the life of the relationship and has no end date.

The five checks

  • Collect and verify identity: Capture a government document or query an authoritative database, then confirm the data is genuine and not simply well formatted.
  • Match the person to the identity: A face capture with liveness detection confirms the applicant is physically present and is the person the document describes.
  • Screen against risk lists: Sanctions and politically exposed person screening, plus adverse media, produces the signals that decide whether standard or enhanced due diligence applies.
  • Build the risk profile: Occupation, country, expected activity, and product type combine into a rating that sets how closely the account is watched.
  • Monitor and refresh: Transaction behaviour, biometric re-checks, and periodic review keep the profile accurate as the relationship ages.

What triggers a KYC refresh?

Reviewing every customer on a fixed calendar is the most common approach, and you could argue that it’s the weakest one, because criminals do not work on a schedule or on your review cycle. A risk-based programme also refreshes when something happens.

  • A change in risk rating, from a new sanctions designation, an adverse media hit, or a change in the customer’s stated circumstances.
  • A material change to customer details, such as a new address, a new phone number, or a new beneficial owner on a company file.
  • Behaviour that departs from the profile, meaning money in, counterparties, or countries the original record did not anticipate.
  • A product or limit upgrade, where the customer moves to a service carrying more risk than the one they were rated for.
  • Expiry of the underlying evidence, including an identity document that has lapsed since it was captured.
  • Doubt about data already held, which FATF names directly and which many internal policies leave without an owner.

What are the main KYC methods?

Step one of the process asks you to verify an identity. The method is how you do it. What you can use comes down to the evidence that exists in a given market, and five approaches cover most regulated onboarding.

Method What it proves Friction Where it fits
Document plus biometric The document is genuine, and the applicant is the person it describes Moderate, roughly 30 to 90 seconds The default for consumer onboarding, and the fallback everywhere else
Electronic identity verification Name, date of birth, and address match authoritative databases Low, no upload needed Markets with deep civil registry or credit bureau coverage
National digital identity or wallet A credential the state issued and stands behind Low Markets with mature schemes, and the EU as digital identity wallets roll out
Chip read over near-field communication The cryptographically signed chip inside an e-passport or e-ID Low, but needs a compatible phone High-assurance onboarding where the document carries a chip
Video KYC with a live agent Everything above, with a trained person deciding in real time High Countries that require human oversight of the identification

What automated KYC means

The term describes how the five above are run when software handles capture, forensic document analysis, liveness & face matching, and screening without a person touching the file. Automation changes throughput, consistency, and cost per case, but does not change what the rules require.

Why does KYC fail after onboarding?

KYC fails after onboarding because the customer who passes verification and the customer who commits the fraud are often the same person at different points in time. A document check tells you nothing about what someone will do with the account in three months.

From the source

“Fraud and money laundering isn’t a one-time thing. A user can pass KYC and then become a money mule.”

Tom Gadsden, VP of Product at Shufti, speaking on Fighting AI Fraud With AI, The Crypto Conversation, Brave New Coin, 16 July 2026.

What the 2025 UK fraud data shows

Cifas recorded 444,000 fraud cases to the UK National Fraud Database in 2025, the highest number in a single year since the database opened. Four figures inside that total describe one movement.

  • Identity fraud filings fell 3%: Cifas attributes that drop to criminals switching tactics rather than to less fraud overall.
  • Account takeover rose 6% to more than 78,000 cases: These are cases where somebody seizes control of an account that already exists.
  • Misuse of facility rose 43% to more than 106,000 cases: These are cases where an account obtained legitimately is later used for fraud.
  • A new money mule filing category logged over 22,000 cases in its first year.

Why the gap exists

Onboarding usually sits with growth or product, measured on approval rate and time to account. On the other hand, ongoing monitoring usually sits with financial crime, measured on alert quality and analyst workload.

These are two separate owners, with two different budgets, following two different roadmaps, and the customer record often does not survive the transition that takes place between these two.

That division also explains how the fourth requirement passes audits while failing in practice. For example, if a supervisor asks to see the monitoring policy will be shown one, that’s easy. But the more useful question is which onboarding attributes the monitoring rules actually read, and for many firms the answer is very few.

How to extend KYC past onboarding

The pieces are usually already in the stack. What is missing is the decision to use them once the account is open.

  • Re-check the biometric, not only the transaction rules: Compare a fresh selfie against the profile you captured at onboarding whenever an account’s risk changes. Transaction rules track the money, not the person holding the credentials, so this is the only check that tells you who is operating the account now.
  • Feed the onboarding profile into monitoring: Your monitoring system needs the record of what the customer said they would do with the account. Without it, it scores them against a generic peer group, and that is where most false positives start.
  • Trigger review on behaviour, not only on the calendar: A date set a year in advance has no relationship to when a customer’s risk changed. Add event triggers alongside the periodic cycle, so a new sanctions hit, a change in risk rating, or activity outside the stated profile pulls the file up on its own.

None of this replaces onboarding checks. It extends them.

The four KYC obligations mapped across the customer lifecycle, showing three completing at onboarding and ongoing monitoring continuing indefinitely.What does a KYC analyst do?

A KYC analyst decides the cases that a software cannot decide alone. Their job typically involves:

  • Deciding flagged onboarding cases, where a document anomaly, a failed biometric, or a partial screening match needs judgement.
  • Running enhanced due diligence on higher-risk customers, which means establishing source of wealth and unpicking ownership structure.
  • Handling periodic and event-driven review, revisiting customers whose risk rating has aged or whose behaviour has drifted from the profile on file.

What automation changed

Automation has changed the shape of the role without removing it. The clerical work of gathering documents, chasing database responses, and reading screening hits one source at a time is what automation can help with now. But the part that was always the actual job, which is forming a defensible view on an unclear file and writing down the reasoning, still stays with a human. 

That matters for the fourth FinCEN requirement, because a monitoring programme is only as defensible as its record of who reviewed what, when, and on what evidence.

How Shufti handles KYC after onboarding

The account that costs you money is usually one that passed verification cleanly. It opened, went unused for a few weeks, and then started moving money for somebody else. Most verification stacks never see that happen, because the check ended at sign-up and nothing was carried forward.

Shufti keeps the onboarding biometric as an enrolled profile the account can be tested against later. For a returning user, a live selfie is compared to that profile to support re-KYC, account recovery, or step-up verification, and the KYC solution re-verifies when risk changes instead of only at sign-up. It covers 240+ countries and territories and 150+ languages, and a genuine customer does not have to repeat full onboarding to clear the check.

See how biometric re-verification behaves on your own onboarding data, then book a 20-minute demo.

Frequently Asked Questions

Q: What is a KYC check?

A KYC check is a single verification step inside the wider process. Common checks include document authentication, a biometric liveness and face match, an authoritative database lookup, and sanctions or politically exposed person screening. A full KYC decision combines several checks.

Q: What is KYC data?

KYC data is the evidence supporting a firm's conclusion about a customer. It covers identity attributes such as name and date of birth, evidence artefacts such as document images and biometric templates, risk attributes such as screening results and source of funds, and decision records showing who approved the customer.

Q: What is a KYC analyst?

A KYC analyst reviews the cases automation cannot clear. They decide flagged onboarding files, run enhanced due diligence on higher-risk customers by establishing source of wealth and ownership, and carry out periodic reviews of existing customers. The analyst owns the decision and the reasoning behind it.

Q: What is an example of a KYC?

A customer uploads a national identity card, the system confirms the document is genuine and extracts the details, a selfie with liveness detection matches the person to the card, and screening returns no sanctions or adverse media hit. The account opens, and monitoring then tracks whether behaviour matches the expected profile.

Q: What does KYC mean?

KYC means know your customer. It refers to the duties a regulated business has to establish a customer's identity, understand the purpose of the relationship, assess the risk that customer carries, and keep checking that assessment for as long as the relationship lasts.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.