KYC is one of the most important processes in modern banking and financial services. Whenever a customer opens a bank account, applies for a financial product, or starts using a payment service, the institution needs to know who that customer is and assess the risks of the relationship.
But why is KYC required, what information do banks collect, and what happens when institutions get it wrong?
In this guide, we explain how customer verification works, which documents may be requested, what the law requires, how technology is changing the process, and what it means to be KYC compliant.

What Is KYC in Banking?
KYC stands for Know Your Customer. It refers to the processes financial institutions use to identify and verify customers and to understand the nature and purpose of their relationships.
KYC is closely connected to customer due diligence (CDD) and anti-money laundering (AML) controls. FATF guidance describes customer due diligence as involving customer identification and verification, beneficial-owner identification, understanding the purpose of the relationship, and ongoing due diligence.
For banks and fintech companies, KYC is not a one-time document check. Depending on the business model and risk profile, customer information may need to be reviewed and updated throughout the relationship.
Why Is KYC Important in Banking?
Accounts and payment systems can be misused for fraud, money laundering, terrorist financing, sanctions evasion, and other financial crimes. A strong KYC framework helps an institution build a reasonable understanding of its customers and spot activity that needs further investigation.
KYC can help financial institutions:
- Verify that customers are who they claim to be
- Understand customer risk
- Identify potentially suspicious activity
- Support AML and compliance programs
- Establish appropriate account controls
- Maintain customer records
- Meet applicable regulatory obligations
- Gain greater visibility into customer activity
For businesses building financial products, KYC is a core part of a bank-ready operating model. It is also a major factor in whether banking partners will work with a program at all.
The Cost of Getting KYC Wrong
The stakes are not academic. Weak KYC and AML controls have produced some of the largest penalties in financial services:
- TD Bank agreed to pay more than $3 billion in 2024 to resolve U.S. investigations into AML program failures.
- Binance agreed to pay $4.3 billion across the DOJ, FinCEN, and OFAC in 2023.
- OKX agreed to pay roughly $504 million in 2025 in a U.S. resolution tied to AML program failures.
- Santander UK was fined £107.7 million by the FCA in 2022 for AML failings.
Beyond fines, institutions can face restrictions on growth, forced remediation programs, loss of banking relationships, and reputational damage. For a fintech, losing a banking partner over compliance gaps can be more damaging than the penalty itself.
The Legal Foundations of KYC

United States:
Three pieces of U.S. law shape most KYC obligations:
- The Bank Secrecy Act (BSA) is the foundational U.S. anti-money laundering law. It requires financial institutions to keep records and report certain activity, including suspicious activity.
- The USA PATRIOT Act requires banks to maintain a Customer Identification Program (CIP) with risk-based procedures for verifying customer identity.
- The Anti-Money Laundering Act of 2020 modernized the AML framework and strengthened enforcement. FinCEN’s customer due diligence rule also requires covered institutions to identify beneficial owners of legal-entity customers.
FinCEN administers the BSA. FFIEC examination guidance explains how banks are expected to apply these requirements in practice.
Global Comparison:
KYC expectations differ by jurisdiction. This summary is a starting point, not legal advice.
| Jurisdiction | Key framework | Main authorities | Notable points |
| United States | BSA, USA PATRIOT Act (CIP), AML Act of 2020 | FinCEN, federal banking regulators, OFAC (sanctions) | Risk-based CIP; beneficial ownership for legal entities; SAR filing |
| European Union | AML directives, moving to a single AML Regulation (AMLR) applying from July 2027 | New EU Anti-Money Laundering Authority (AMLA), national supervisors | AMLR creates a single EU rulebook; CDD threshold for occasional transactions falls to €10,000 |
| United Kingdom | Money Laundering Regulations 2017 | FCA and other supervisors | Risk-based approach supported by industry guidance |
Recent Regulatory Developments:
Regulation is moving quickly. The EU’s AMLA began operating in 2025 and is expected to supervise higher-risk cross-border institutions directly. In the U.S., stablecoin regulation was formalized through the GENIUS Act in 2025, and enforcement attention has increasingly focused on crypto exchanges and money services businesses (MSBs). Any KYC program should be reviewed against current rules for the jurisdictions it serves.
What Is the KYC Process?
Requirements vary by institution, country, product, and customer risk, but a typical KYC process includes the following steps.

Customer Identification:
The first step is collecting information that identifies the customer. For an individual, this can include name, date of birth, address, and government-issued identification details. For businesses, institutions may collect information about the legal entity, business activities, ownership structure, and the individuals who control or own the company.
Identity Verification:
After information is collected, the institution verifies it. Verification may involve reviewing government-issued identification, checking information against reliable sources, or using non-documentary methods.
FFIEC guidance notes that banks may use documentary or non-documentary methods to form a reasonable belief that they know the true identity of a customer.
Beneficial Ownership Checks:
KYC for businesses often goes beyond verifying the company itself. Financial institutions may also need to understand who owns or controls a legal entity. FATF standards include identifying the beneficial owner and taking reasonable measures to verify that person’s identity.
This matters most when a company has multiple shareholders, subsidiaries, trusts, or complex ownership arrangements.
Understanding the Customer:
A financial institution may need to understand why the customer wants the account or service. For a business, this could include:
- Business model
- Expected transaction types
- Countries served
- Expected transaction volumes
- Source of funds
- Customer base
- Products or services offered
This information helps the institution build an appropriate customer risk profile.
Risk Assessment:
Not every customer presents the same level of risk. A bank or financial platform may evaluate geography, business activity, ownership, transaction patterns, customer type, and other risk indicators. Higher-risk relationships call for enhanced due diligence, covered below.
Ongoing Monitoring:
KYC does not end when an account is opened. Customer information and transaction activity are monitored over time. FFIEC guidance describes ongoing customer due diligence as including an understanding of the nature and purpose of customer relationships and monitoring for potentially suspicious transactions.
If a customer’s business changes significantly, new information may need to be collected and verified.
Standard vs. Enhanced Due Diligence
Standard customer due diligence (CDD) applies to most customers: identify, verify, understand the relationship, and monitor.
Enhanced due diligence (EDD) applies when a customer presents higher risk. Triggers can include:
- Politically exposed persons (PEPs)
- High-risk jurisdictions
- Complex or opaque ownership structures
- Unusual transaction patterns
- Higher-risk business types
EDD typically means collecting more information (such as detailed source of funds and source of wealth), requiring senior management approval, verifying information from additional independent sources, and monitoring the account more closely.
Politically Exposed Persons (PEPs):
A PEP is someone who holds, or has held, a prominent public function, such as a senior government official, judge, or military leader. Family members and close associates may also be treated as PEPs. Because of their position, PEPs can be more exposed to bribery and corruption risk, so institutions screen customers against PEP lists and apply EDD where appropriate. Being a PEP does not mean someone is involved in wrongdoing; it means the relationship carries higher risk that must be managed.
From Monitoring to Reporting: Suspicious Activity Reports
Ongoing monitoring only matters if it leads to action. When monitoring identifies activity that appears suspicious, U.S. financial institutions are required to file a Suspicious Activity Report (SAR) with FinCEN. Institutions must also keep records supporting each filing and are generally prohibited from telling the customer that a SAR has been filed.
This is where KYC and transaction monitoring connect: KYC establishes what normal activity looks like for a customer, and monitoring flags activity that does not fit that profile.
What Are KYC Documents?
KYC documents are identification or business records used to establish and verify a customer’s identity and, where applicable, ownership or business information.

Common Individual KYC Documents:
Depending on the institution and jurisdiction, individuals may be asked for:
- Passport
- National identity card
- Driver’s license
- Proof of address
- Tax identification information
- Other government-issued identification
FFIEC guidance gives examples such as an unexpired government-issued identification document for individuals, and notes that banks may use other identification methods when appropriate.
Common Business KYC Documents:
Businesses may be asked for:
- Certificate of incorporation
- Business registration documents
- Business license
- Articles of incorporation
- Partnership agreements
- Trust documents
- Ownership information
- Identification documents for directors or beneficial owners
- Information about the nature and purpose of the business
The exact requirements depend on the financial institution, jurisdiction, customer type, and risk profile.
KYC vs. KYB: What Is the Difference?
KYC generally focuses on identifying and understanding individual customers. KYB, or Know Your Business, focuses on verifying businesses and understanding their ownership, control, activities, and risk.
For fintechs and financial platforms, both matter. A platform offering business accounts may need to verify the company, identify its beneficial owners, understand its business model, and assess expected transaction activity before providing services. This is especially relevant for international companies seeking a USA bank account for international businesses, where banks expect a clear picture of ownership, activity, and source of funds before opening an account.
How Technology Has Changed KYC
Traditional banking relied on manual paperwork and in-branch verification. Digital onboarding, often called eKYC, now handles much of this work remotely. Common methods include:
- Automated document verification, which checks whether an ID looks genuine and has not been altered
- Biometric checks, such as selfie matching and liveness detection, to confirm the person presenting the ID is the person on it
- NFC chip reading, which reads the chip in an e-passport or national ID card
- Database and registry checks, which verify identity details, business registrations, and ownership against reliable sources
- Video verification, used in some markets when a live check is needed
- Automated risk scoring, which assigns a risk level at onboarding and updates it as new information arrives
Technology makes onboarding faster and more consistent, but it does not remove the institution’s responsibility. Automated tools still need to be tested, documented, and tied to a risk-based policy.
Connecting KYC to the Rest of the Program:
A financial platform may connect customer onboarding with:
- Identity and business verification
- Sanctions screening
- PEP screening
- AML and transaction monitoring
- Risk scoring
- Case management and SAR workflows
- Reporting and audit trails
For fintechs, MSBs, wallet platforms, and other financial businesses, the challenge is often not choosing a KYC tool. The larger challenge is connecting KYC to the banking, account, payment, compliance, and settlement infrastructure that supports the whole program. That includes the payment rails customers actually use, such as domestic wire transfers, ACH, and stablecoin-based flows through a payment gateway.
PRETpayments focuses on this infrastructure layer, including KYC/KYB, AML/BSA workflows, sanctions screening, transaction monitoring, RFI handling, reporting, audit trails, and program-level controls. You can see how these pieces fit together on the PRETpayments capabilities page.
What Does KYC Compliant Mean?
Being KYC compliant means having processes designed to meet the applicable customer identification, verification, due diligence, recordkeeping, and monitoring requirements.
It does not mean collecting a passport or checking a name once. A mature compliance framework connects onboarding, identity verification, risk assessment, enhanced due diligence where needed, ongoing monitoring, recordkeeping, suspicious activity reporting, and escalation.
Requirements differ by jurisdiction and type of financial institution, so companies should design their KYC program around the regulations that apply to their specific activities.
KYC and Bank-Ready Financial Programs
For companies entering or expanding within the U.S. financial ecosystem, compliance has to be considered alongside banking access and operational infrastructure.
PRETpayments describes its model as connecting approved programs with sponsor-bank, fintech, liquidity, compliance, and settlement infrastructure through one orchestration layer. Its platform supports account infrastructure, bank sponsorship, stablecoin and wallet workflows, and compliance controls.
This bank-visible approach helps financial businesses structure onboarding and transaction activity around the controls their banking partners expect. The goal is not to collect more customer data. It is to create a controlled operating environment where customer identity, transactions, compliance records, and reporting are connected.
Benefits of a Strong KYC Framework
Better Customer Visibility:
Financial institutions gain a clearer understanding of who their customers are and why they use the service.
Reduced Financial Crime Risk:
Identity verification and ongoing due diligence help identify customers and activities that may present elevated risk.
Stronger Banking Relationships:
Clear compliance processes and reporting make it easier for banking partners to understand how a financial program operates.
More Efficient Onboarding:
Digital workflows reduce manual processes and create a consistent customer experience.
Improved Monitoring:
Connecting onboarding information with transaction monitoring helps institutions identify activity that does not match the customer’s expected profile.
Better Audit Readiness:
Appropriate records, controls, and audit trails help organizations demonstrate how their compliance processes operate.
KYC in Banking: Key Takeaways
KYC stands for Know Your Customer, but implementing it well takes much more than collecting identification documents.
A strong KYC framework includes customer identification, identity verification, beneficial ownership checks, risk assessment, enhanced due diligence for higher-risk customers, ongoing monitoring, suspicious activity reporting, and appropriate recordkeeping. For fintechs and financial businesses, KYC should also connect with KYB, AML, sanctions screening, transaction monitoring, account infrastructure, and reporting.
As financial services become more digital and global, bank-ready compliance infrastructure is an important part of building sustainable financial products.
Build Bank-Ready Financial Infrastructure With PRETpayments
KYC is only one part of building a compliant financial program. Fintechs, MSBs, wallet platforms, stablecoin companies, and cross-border businesses may also need account infrastructure, sponsor-bank relationships, payment rails, compliance workflows, settlement, and reporting.
PRETpayments helps approved programs connect these components through a bank-visible infrastructure model.
Ready to build your financial program with the right banking and compliance infrastructure? Explore PRETpayments capabilities or contact the team to discuss your program.
Frequently Asked Questions About KYC in Banking
1. What is KYC in banking?
KYC stands for Know Your Customer. It is the process banks and financial institutions use to identify and verify customers, understand the purpose of a financial relationship, assess risk, and conduct ongoing due diligence. KYC is an important part of broader customer due diligence and AML compliance.
2. What does KYC stand for?
KYC stands for Know Your Customer. It refers to the procedures financial institutions use to establish a reasonable understanding of who their customers are and the risks associated with their relationships.
3. What is the KYC process?
The KYC process generally involves collecting customer information, verifying identity, identifying beneficial owners where applicable, understanding the purpose of the relationship, assessing risk, and conducting ongoing monitoring. The exact process varies by institution, jurisdiction, product, and customer risk profile.
4. What documents are required for KYC?
Individuals may be asked for a passport, national identity card, driver’s license, proof of address, or other government-issued identification. Businesses may need to provide incorporation records, business registration information, ownership details, licenses, and identification for relevant directors or beneficial owners. Requirements vary by institution and jurisdiction.
5. Why is KYC important for banks?
KYC helps banks understand who their customers are and manage financial crime risk. It supports customer due diligence, helps identify unusual or suspicious activity, and provides the foundation for AML, sanctions, transaction-monitoring, and reporting programs. Failures can lead to significant penalties.
6. Does KYC only happen when opening a bank account?
No. KYC continues after an account is opened. Institutions may update customer information, review changes in risk, and monitor transactions throughout the relationship. FATF standards call for ongoing due diligence and scrutiny of transactions in line with the customer’s profile and risk.
7. What is the difference between CDD and EDD?
Customer due diligence (CDD) is the standard level of verification and monitoring applied to most customers. Enhanced due diligence (EDD) applies to higher-risk customers, such as PEPs or those in high-risk jurisdictions, and involves deeper information gathering, senior approval, and closer monitoring.
8. What is a Suspicious Activity Report (SAR)?
A SAR is a report U.S. financial institutions file with FinCEN when they detect activity that appears suspicious. SARs are a key output of ongoing monitoring and a regulatory obligation under the Bank Secrecy Act.
9. What does it mean to be KYC compliant?
Being KYC compliant means having processes and controls that satisfy the applicable customer identification, verification, due diligence, recordkeeping, and monitoring requirements. It is not just about collecting identification documents; organizations need processes appropriate to their products, customers, risks, and regulatory obligations.