Overview
Know your customer or know your client (KYC) laws, regulations and guidelines in financial services require regulated businesses and professionals to verify the identity of a customer, and the suitability and risks involved with maintaining a business relationship with them. These procedures fit within the broader scope of anti-money laundering (AML) and counter terrorism financing (CTF) regulations.
KYC processes are also used by companies of all sizes to determine whether their proposed customers, agents, consultants, or distributors are anti-bribery compliant and are who they claim to be. Banks, insurers, export creditors, and other financial institutions are increasingly required to make sure that customers provide detailed due-diligence information. Initially, these regulations were imposed only on financial institutions, but regulations now apply in many countries to fintech, virtual assets dealers, non-financial industries, and non-profit organizations.
Requirements
AML/CFT legislation strengthens the prevention of and the fight against money laundering, its predicate offences and terrorist financing. It places legally binding obligations on sectors exposed to the risk of money laundering or the financing of terrorism to monitor their customers and transactions, and to report suspicious activities to governments.
In the European Union these sectors are described as obliged entities, whereas in the United States the term covered institutions is used.
Obliged entities are required to identify and assess the risks of money laundering and terrorist financing to which they are exposed. This business-wide risk assessment must be kept up-to-date. To manage these risks and comply with relevant AML legislation, obliged entities must have internal policies, procedures and controls in place. This includes applying Customer Due Diligence (CDD) measures and may require Enhanced Due Diligence (EDD) checks for certain categories of customers or transactions.
4 sources for this section
- 1Know your customer — Wikipedia, revision 1375040511
- 4"Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing". eur-lex.europa.eu. Archived from the original on 2026-02-20. Retrieved 2026-04-23.
- 5"Anti-money laundering: Council and Parliament strike deal on stricter rules". Consilium. 2024-01-18. Archived from the original on 2026-04-29. Retrieved 2026-04-25.
- 6"Industry Letter - January 22, 2024: Guidance on Assessment of the Character and Fitness of Directors, Senior Officers, and Managers". Department of Financial Services. Archived from the original on 2026-02-07. Retrieved 2026-04-25.
Customer Identification Program (CIP)
An AML/CFT Customer Identification Program (CIP) is a legally mandated framework requiring financial institutions to verify the identity of any person or entity opening a new account. It is the foundation on which the broader KYC framework, to prevent money laundering and terrorist financing, is built. It ensures that regulated entities can identify and verify their customers before granting them access to the global financing system.
The FinCEN 2004 CIP Rule provides interpretative guidance with respect to the CIP obligations set out in the USA Patriot Act. The rule mandates that financial institutions implement a written risk-based Customer Identification Program. The program must ensure that: financial institutions are able to form a reasonable belief that they know the true identity of every customer; collect minimum data as specified in the USA Patriot Act; verify the identity of the prospective customer within a reasonable time; check watchlists of suspected terrorists; and give customers adequate notice that the financial institution is confirming their identity.
Financial institutions must also retain information for five years after an account is closed.
Under its AML/CFT regulatory framework, the European Union imposes similar requirements on obligated entities. Specifically, they should obtain name, address, date of birth, nationality and ID documentation for individuals and corporate name, registered address, proof of incorporation and ultimate beneficial ownership information for legal entities.
3 sources for this section
- 1Know your customer — Wikipedia, revision 1375040511
- 7"USA PATRIOT Act". Archived from the original on 2026-05-14. Retrieved 2026-06-01.
- 4"Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing". eur-lex.europa.eu. Archived from the original on 2026-02-20. Retrieved 2026-04-23.
Customer Due Diligence (CDD)
Customer Due Diligence (CDD), a KYC process that is part of AML/CFT legislation, requires financial institutions to verify a clients' identity, understand the nature and purpose of a relationship, assess financial crime or terrorist financing risk, and report suspicious transactions. Financial institutions are obligated to monitor the risk level of clients throughout the lifecycle of the relationship.
Beneficial owner information is required for any individual who owns 25 percent or more of a legal entity and an individual who controls the legal entity.
CDD obligations for financial institutions operating in the European Union are set out in the 2024 AML Regulation. This consolidated and expanded the requirements included in the five AML Directives, and created a single, centralised rule book.
4 sources for this section
- 1Know your customer — Wikipedia, revision 1375040511
- 8"What is customer due diligence". www.moodys.com. Archived from the original on 2025-07-05. Retrieved 2026-06-10.
- 9"Information on Complying with the Customer Due Diligence (CDD) Final Rule". fincin.gov. February 3, 2024. Archived from the original on February 3, 2024. Retrieved February 3, 2024.
- 4"Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing". eur-lex.europa.eu. Archived from the original on 2026-02-20. Retrieved 2026-04-23.
Enhanced Due Diligence (EDD)
The formal concept of additional CDD obligations for certain categories of higher risk customers or transactions was established by the USA Patriot Act of 2001. This established mandatory Enhanced Due Diligence (EDD) obligations. It required US financial institutions to maintain additional rigorous screening for foreign banking accounts, offshore jurisdictions and correspondent banking relationships to combat terrorist financing. FinCEN set out the formal obligations needed to fully implement EDD in a 2007 rule.
Requirements to undertake EDD checks and monitoring for higher risk business relationships, customers and transactions were included in the FATF's Forty Recommendations in 2003.
The European Union's AML/CFT legislative framework provides an insight into the current scale of EDD obligations. These requirements were established fully by the 4th AML Directive and consolidated into a single central rulebook by the recent 2024 AML Regulation. This requires EDD to be applied in certain specific situations, such as business relationships with Politically Exposed Persons, cross-border correspondent relationships for crypto-asset service providers, or business relationships involving persons in third countries with significant strategic deficiencies in their national AML/CFT regimes.
The EU regulation also identifies a series of factors (Risk Factors) that indicate to obliged entities that relationships or transactions may pose a higher risk of money laundering or terrorist financing and hence require the application of EDD obligations, processes and monitoring. Factors include the reputation, nature or behaviour of customers, complex ownership, customer domicile, presence of nominee shareholders, cash-intensive businesses, use of private banking, payments from unknown third parties, use of new technologies, or transactions linked to oil, tobacco, arms, precious metals or stones.
5 sources for this section
The source notesEvidence & further reading11 sources
- Know your customer — Wikipedia, revision 1375040511 Wikipedia contributors · Reference source · accessed 2026-09-22
- "Know your client CIPR". cipr.co.uk. Archived from the original on 2026-01-06. Retrieved 2025-11-23. cipr.co.uk · Reference source · link imported 2026-09-22
- "Customer identification: Know your customer (KYC)". Government of Australia. 31 March 2025. Retrieved 31 March 2025. austrac.gov.au · Reference source · link imported 2026-09-22
- "Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing". eur-lex.europa.eu. Archived from the original on 2026-02-20. Retrieved 2026-04-23. eur-lex.europa.eu · Reference source · link imported 2026-09-22
- "Anti-money laundering: Council and Parliament strike deal on stricter rules". Consilium. 2024-01-18. Archived from the original on 2026-04-29. Retrieved 2026-04-25. consilium.europa.eu · Reference source · link imported 2026-09-22
- "Industry Letter - January 22, 2024: Guidance on Assessment of the Character and Fitness of Directors, Senior Officers, and Managers". Department of Financial Services. Archived from the original on 2026-02-07. Retrieved 2026-04-25. dfs.ny.gov · Reference source · link imported 2026-09-22