Regulation & Policy

The KYC Process, End to End

KYC is not a single identity check but an operating cycle that starts with an account-opening trigger and continues through review. Its effectiveness depends on linking reliable evidence, proportionate risk decisions and timely follow-up.

The KYC Process, End to End

For a bank, fintech or regulated payments provider, the KYC process is an operational chain rather than a checkbox at signup. A customer may begin with a mobile application, but the resulting file has to support a defensible decision: who is seeking the relationship, whether the available evidence is reliable, what financial-crime risk the relationship presents and when it should be revisited.

That workflow sits within rules that differ across jurisdictions but have a common purpose. In the United States, KYC obligations trace to the Bank Secrecy Act of 1970. The framework expanded substantially following the September 11 attacks, notably through the USA PATRIOT Act and its Customer Identification Program, or CIP, requirements. Measures adopted after the 2008 financial crisis also strengthened expectations around customer due diligence, beneficial ownership and risk-based controls. In the EU, firms work under the Anti-Money Laundering Directives and national implementing laws, with a shift toward the EU Anti-Money Laundering Authority and directly applicable rules underway.

The process starts when an event requires the firm to know more about a person or business. The most familiar trigger is opening an account, but it can also be a new product, a change in ownership, an unusually large transaction, a shift in a customer's behavior or an expiry of identity evidence. Firms should define these triggers in policy and make them visible in their case-management systems. Otherwise, a review can depend too heavily on an employee noticing a problem.

At this stage, the institution also determines which legal regime and customer type apply. An individual opening a US bank account is handled differently from a company seeking merchant acquiring services, a politically exposed person, or a customer introduced through an intermediary. The result is a route through the firm's onboarding and due-diligence controls, not yet an approval.

Collection is where the firm obtains the information and evidence required for the route it has selected. Under the US CIP rule, the minimum data set for an individual is name, date of birth, address and an identification number. For a US person, that number is generally a taxpayer identification number; for certain non-US persons, it can be a passport number, alien identification card number or other government-issued document number, subject to the rule's conditions.

The operational challenge is to request enough information without collecting unrelated data. A remote flow may capture document images, a selfie or other liveness evidence, contact details and device signals. A business onboarding flow may add formation records, ownership information, control persons, expected activity and source-of-funds details. Data-protection rules, including the EU General Data Protection Regulation, make purpose limitation, retention controls and security material parts of this stage.

Verification tests whether the collected claims and documents can be relied upon. It can involve checking a document's security features, comparing a face to a document portrait, querying authoritative or commercial data sources, validating an address and screening names against sanctions, politically exposed person and adverse-media sources. No single test is conclusive in every case. A genuine document does not necessarily establish that its presenter is the rightful holder, while a database mismatch can reflect stale records or transliteration differences.

Exceptions need controlled handling. Automated checks can resolve straightforward cases quickly, but unclear matches, suspected impersonation and unavailable data sources should move to trained reviewers. Firms also need audit trails that show the evidence used, the checks performed and why an exception was accepted or rejected.

Risk rating turns identity and customer information into an operating decision. It drives whether to approve the relationship, what level of due diligence applies and how often the file is reviewed. A low-risk customer may proceed with standard due diligence and a longer review cycle. Higher-risk cases can require enhanced due diligence, including deeper checks on source of wealth or funds, senior approval and closer transaction monitoring.

  • Customer factors, such as occupation, ownership structure, political exposure and previous adverse information.
  • Product and channel factors, including remote onboarding, cross-border payments, cash intensity and use of intermediaries.
  • Geographic exposure, taking account of sanctions, corruption and financial-crime risks linked to relevant countries.
  • Expected account activity, which provides a baseline for later monitoring.

A rating is not a prediction of criminality. It is a documented assessment of exposure and control needs. Poorly designed models can produce excessive false positives, inconsistent treatment or discriminatory outcomes, so governance, testing and human escalation remain important.

KYC does not end at account opening. Ongoing review refreshes expired documents, updates ownership and address information, responds to screening alerts and compares actual activity with the expected profile. A periodic review may be scheduled by risk tier, while event-driven reviews follow changes such as a new beneficial owner, sanctions development or unusual transaction pattern. When information cannot be refreshed or risk cannot be managed, firms may restrict or exit a relationship, subject to applicable law and customer-protection obligations.

The most consequential recent development for remote onboarding is FinCEN's publication of FAQs on 8 September 2026 addressing the treatment of verifiable digital credentials under the CIP rule. The guidance matters because credentials designed to be cryptographically checked may allow a customer to present attributes from an issuer without relying solely on a scanned physical document.

The practical effect is not a blanket approval of every digital identity product. Institutions still need procedures reasonably designed to form a reasonable belief that they know the customer's true identity, and they remain responsible for vendor oversight, fraud controls, recordkeeping and risk-based escalation. For US and EU firms, the direction of travel is toward more reusable digital evidence, but the core discipline remains the same: collect appropriate information, verify it reliably, make a proportionate risk decision and keep the file current.

More in Regulation & Policy