KYC documents are the identity and address records that prove who a customer is. Here are the types that are accepted, the checks that confirm a document is real, and how long you have to keep the records.
A US bank can verify your identity from your passport and open your account without needing to keep a copy of your passport. 31 CFR 1020.220 asks the bank to record a description of the document instead, meaning the document type, the issuing authority, the number and the expiry date. Keeping the image is allowed. It is not required.
What data you can collect vs what data you can store decides how much personal data ends up in your systems, how long it stays there, and what you can show a regulator years later. The rules also differ depending on whether you are verifying a person, an address, or a company.
This guide will walk you through everything you need to know about KYC documents.
What are KYC Documents?
KYC documents are the official identity and address records a regulated business collects and checks before letting a customer use its services. They give the business a defensible answer when a regulator asks how it knows the customer is real.
The Three Types of KYC Documents
Every KYC document falls into one of three groups.
- Proof of identity. Confirms the name, date of birth, and photograph of the person.
- Proof of address. Confirms the residential address the person has declared.
- Entity documents. Confirms the legal existence, registered address and ownership of a company.
What Regulators Require You to Collect
Recommendation 10 of the Financial Action Task Force (FATF), the global body that sets anti-money laundering standards, requires firms to verify a customer’s identity using reliable, independent source documents, data or information. It names no specific document, which is why accepted lists vary so widely between countries.
The United States is more prescriptive. Its customer identification programme rule sets four data elements for every customer, namely name, date of birth, address and an identification number.
Which Documents are Accepted for KYC Verification?
Below are the types of documents that are accepted under the first two categories:
Proof of Identity Documents
A passport is accepted almost everywhere, because it carries a machine-readable zone and, on newer versions, an embedded chip. Both give a verification system structured data to check rather than an image to judge by eye. Other commonly accepted proof of identity documents include the passport, national identity card, driver’s licence, residence permit and government-issued photo identity card.
Proof of Address Documents
Most firms accept an address proof only if it was issued in the last three months, because an older bill no longer evidences where the customer lives now. Other commonly accepted proof of address documents include the utility bill, bank or credit card statement, tenancy agreement, council tax or local property tax bill, government correspondence and employer letter.
How Identity Documents and Address Documents Differ
The two document types answer different questions, and one rarely substitutes for the other.
| Types | Proof of identity | Proof of address |
| Question it answers | Who is this person | Where does this person live |
| Typical documents | Passport, national ID, driver’s licence | Utility bill, bank statement, tenancy agreement |
| Photograph required | Usually yes | No |
| Validity rule | Must be unexpired | Usually issued within three months |
| Can one document do both | Only where the ID shows a registered address | Only where the ID shows a registered address |
What Documents are Required for Business KYC?
Business KYC needs entity documents alongside identity documents for the people who own and control the company. The KYC documentation set has to prove three things, that the company legally exists, that you know who ultimately controls it, and that those controllers are themselves verified individuals.
Documents that Prove the Company Exists
These include the certificate of incorporation or registration, the business or trading licence, proof of registered business address, and the articles of association or equivalent constitutional document.
Documents that Prove Who Owns the Company
Ownership evidence includes the shareholder register, a beneficial ownership declaration, and a full identity document set for every director and ultimate beneficial owner. An ultimate beneficial owner is the real person who ultimately owns or controls the company, however many holding companies sit in between.
How is a KYC Document Verified as Genuine?
Automated verification runs in four stages, and a forged document usually fails more than one of them. Most decisions are returned without a person reviewing the file, though borderline results are routed to a human reviewer.
Reading the Data and Comparing it with the Machine-Readable Zone
Optical character recognition, software that reads printed text from an image, extracts the fields on the document. The machine-readable zone, the two lines of coded text at the foot of a passport photo page, repeats the same details. An altered printed name no longer matches the coded version. An altered date of birth or document number in the coded version fails its own check digit, a single character calculated from the digits before it.
Security Features and Signs of Tampering
Genuine documents carry holograms, microprint, ultraviolet patterns and specific typefaces at specific positions. Forensic checks look for the wrong font weight, a hologram that reflects incorrectly, or pixel-level compression artefacts around a name or date. This stage catches a genuine document that someone has edited, which a photo match on its own would clear.
The Chip Read and the Database Check
An electronic passport or ID card holds a chip signed cryptographically by the issuing authority. Validating that signature confirms the data came from the government that issued it and has not been changed since. Where no chip exists, the extracted data can be checked against civil registries or voter rolls instead.
Matching the selfie to the document photo
The final stage ties the document to the person presenting it. A selfie is matched against the photograph on the document, and liveness detection confirms a real person is in front of the camera rather than a printed photo, a replayed video or a face swap.
Why do KYC Documents Get Rejected?
Most rejections come from poor capture rather than fraud. A blurred photograph and a forged document produce the same failed check and the same unhelpful message, so a team that never separates the two causes will keep asking genuine customers to resubmit KYC docs.
- The document has expired. Expiry is checked before anything else, and a licence that lapsed last month fails immediately.
- The image is unusable. Glare, cropped corners and motion blur hide the exact security features the forensic stage needs to read.
- The address proof is too old. A utility bill dated four months ago fails the three-month rule at most firms.
- Details do not match across documents. A middle name on the passport and not on the bank statement will hold the file for manual review.
- The document shows signs of editing. Font inconsistency, compression artefacts and a failed check digit all point at manipulation.
- The biometric check fails. The selfie does not match the document photograph, or liveness detection rejects the capture.
How Long are KYC documents Kept on File?
For five years, and this five-year clock does not start when the customer hands you the document. It starts on the day they stop being your customer. So the total time you hold the file is the length of the relationship plus five years.
Five years, counted from when the relationship ends
Recommendation 11 of the FATF standards requires firms to keep customer due diligence records, meaning the checks run to establish who the customer is, for at least five years after the business relationship ends. The same five years applies from the date of an occasional transaction, which is a one-off deal for someone who never becomes an ongoing customer. National rules are built on that template, so five years holds in most markets.
| Framework | Retention period | When the clock starts |
| FATF Recommendation 11 | At least 5 years | End of the business relationship, or date of the occasional transaction |
| US customer identification programme rule | 5 years for the identifying information | Date the account is closed |
| EU AMLR Article 77, from 10 July 2027 | 5 years | Termination, occasional transaction, or refusal to onboard |
When you can keep a record instead of a copy
The two frameworks take different starting points when it comes to keeping a record. The US rule requires the identifying information and a description of the document relied on, so keeping the image is optional.
The EU requires a copy by default, then allows firms to store a reference to the information instead, but only on three conditions. 1) The stored information cannot be modified or altered, 2) it has to be producible for a regulator immediately, and 3) the firm has to name in its own internal procedures which categories it stores by reference and how it retrieves them. Article 77 also states that retained records must not be redacted.
What changes in the EU from July 2027
Article 77 of the EU Anti-Money Laundering Regulation, known as AMLR, applies directly in all member states from 10 July 2027 and replaces the national retention rules currently in force. The period is five years, counted from termination of the relationship, the occasional transaction, or a refusal to onboard. Personal data must then be deleted, and a regulator can require a further period of up to five years case by case.
How Shufti handles KYC document verification
If your customers are in Vietnam, Indonesia, Brazil, South Asia or the Gulf, you have seen the pattern. Verification clears a passport, then fails on a national ID in a non-Latin script, and the customer abandons the session on the third retry.
Most vendors trained their document models on Western documents first and added everything else afterwards, which is why accuracy drops most in markets where growth is happening.
Shufti document verification runs on proprietary optical character recognition trained natively on 150+ languages across 240+ countries and territories. The forensic layer inspects security features, font placement, and pixel-level edits rather than only matching the photograph, so an altered document fails even when the image quality is perfect. Stripe uses Shufti specifically for MENA and APAC documents despite running its own verification capability.
Test Shufti’s document checks against your own rejected verifications, then book a 20-minute demo.
Frequently Asked Questions
What are KYC documents?
KYC documents are the official identity and address records a regulated business collects to confirm who a customer is. A passport or national ID proves identity. A utility bill or bank statement issued in the last three months proves address.
What is the difference between identity documents and proof of address?
An identity document confirms who a person is and normally carries a photograph. A proof of address confirms where they currently live and carries no photograph. One document covers both only where the national ID shows a registered address.
How long are KYC documents kept on file?
At least five years under FATF Recommendation 11, counted from the end of the business relationship rather than from collection. The US sets five years from account closure. EU AMLR Article 77 sets the same five-year period across all member states from 10 July 2027.















