KYC / AML
KYC/AML is the global framework requiring regulated firms to identify customers, assess financial-crime risk, monitor activity and report suspicions. Its detailed legal duties are set by national and regional laws built around FATF standards.
Know Your Customer and anti-money laundering, commonly abbreviated KYC/AML, describe the compliance framework used to prevent financial systems from being used for money laundering, terrorist financing and related crime. KYC is the process of identifying and understanding a customer. AML is the broader set of controls, monitoring and reporting obligations.
KYC/AML is in force globally through national and regional laws rather than through one worldwide statute. Requirements vary by jurisdiction, sector and risk level, but financial institutions and other covered businesses commonly apply similar core controls when serving customers across borders.
The FATF standards behind national AML law
The Financial Action Task Force, or FATF, is an intergovernmental body that sets international standards for combating money laundering, terrorist financing and financing connected to weapons proliferation. Its 40 Recommendations are not directly binding on consumers or companies. Instead, FATF members and other jurisdictions translate them into domestic law, regulation and supervisory practice.
The Recommendations call for a risk-based approach. A firm should identify, assess and mitigate its money-laundering and terrorist-financing risks, then apply controls proportionate to those risks. FATF evaluations can affect a country's international standing, including through increased-monitoring or high-risk lists, which in turn can lead firms to apply tighter controls to relevant cross-border relationships.
Customer due diligence and enhanced due diligence
Customer due diligence, or CDD, is required when establishing many business relationships, carrying out specified transactions, suspecting criminal activity or doubting previously obtained identity information. It generally requires a regulated entity to identify the customer, verify that identity using reliable and independent sources, understand the purpose and intended nature of the relationship, and identify the beneficial owner.
A beneficial owner is the natural person who ultimately owns or controls a customer entity, or on whose behalf a transaction is conducted. Verification may involve identity documents, official registries, corporate records, databases or other evidence, depending on the jurisdiction and risk.
Enhanced due diligence, or EDD, applies where risk is higher. It can require additional identity evidence, deeper checks on ownership and control, information about source of funds or source of wealth, senior management approval, and more frequent transaction monitoring. Examples may include higher-risk jurisdictions, complex ownership structures, private banking relationships and certain politically exposed persons.
Who is a regulated entity?
The exact perimeter is set by local law. It usually includes banks, payment institutions, electronic money issuers, money transmitters, securities firms, insurers offering relevant products, investment managers and many crypto-asset service providers. It may also cover designated non-financial businesses and professions, such as casinos, real estate intermediaries, trust and company service providers, dealers in high-value goods, accountants and lawyers when they undertake specified financial or corporate transactions.
- A regulated entity must maintain policies, internal controls, staff training and independent oversight appropriate to its risks.
- It must not treat identity verification as a one-time event. Customer information and risk assessments need updating when circumstances change.
- Some firms rely on specialist vendors for document checks, biometric matching or screening, but the regulated entity generally remains accountable for compliance.
Sanctions and politically exposed person screening
Sanctions screening checks customers, beneficial owners, counterparties and, where relevant, transactions against applicable government sanctions lists. Sanctions obligations are legally distinct from AML rules, but firms commonly operate the controls together. A potential name match requires investigation because names can be shared, translated or spelled differently. Confirmed matches can require asset freezes, payment blocks, reports or other action under the applicable regime.
Politically exposed persons, or PEPs, are individuals entrusted with prominent public functions, such as senior government officials, senior judges, military leaders or executives of state-owned enterprises. Being a PEP is not evidence of wrongdoing. It is a risk factor because public position can create exposure to bribery or corruption. Many frameworks also address family members and close associates, with risk-sensitive measures rather than automatic refusal of service.
Record-keeping, monitoring and reporting
Regulated entities must conduct ongoing monitoring to determine whether transactions are consistent with what they know about a customer, their business and their risk profile. Monitoring can combine automated alerts with human review. It should detect unusual patterns, but an unusual transaction is not by itself proof of crime.
Where there are reasonable grounds for suspicion, firms must generally file a suspicious activity report or suspicious transaction report with the relevant financial intelligence unit. Reports are confidential, and firms are usually prohibited from telling the customer that a report has been made, a restriction known as tipping off. Firms must also retain CDD records, transaction records and supporting evidence for the period required by local law, often at least five years. These records help authorities reconstruct transactions and support investigations while creating important obligations to protect personal data and limit access.