Know Your Customer is the risk-based process financial institutions use to identify customers, understand relationships, and support ongoing financial-crime controls.
Know Your Customer (KYC) is the risk-based process a financial institution uses to identify a customer, understand the purpose and expected activity of the relationship, and keep relevant information current. KYC is an umbrella term rather than one universal rule: the exact customer identification, due diligence, monitoring, and recordkeeping duties depend on the institution, jurisdiction, product, and customer.
| Concept | Main question | Typical output |
|---|---|---|
| KYC | Who is the customer, and what risks does the relationship present? | Overall customer-information and risk-control process |
| Customer Identification Program | Can the institution form a reasonable belief that it knows the customer’s identity? | Required identifying information, verification, notices, and records |
| Customer due diligence | What is the nature, purpose, ownership, and expected activity of the relationship? | Customer risk profile and ongoing monitoring |
| Enhanced Due Diligence | What additional information or review is appropriate for elevated risk? | Deeper verification, approvals, source information, or monitoring |
The labels are not interchangeable. A bank can complete the minimum identity steps and still need additional CDD, sanctions, fraud, or suspicious-activity controls.
Under 31 CFR 1020.220, a bank’s written CIP must be appropriate for its size and business and include risk-based procedures for verifying identity to the extent reasonable and practicable. Before opening an account, the bank generally obtains:
The bank then uses documentary or nondocumentary methods, or both, to verify identity. Its procedures must address situations in which identity cannot be verified, required records, customer notice, and comparison with government lists when an applicable list has been designated.
CIP applies to a “customer” and “account” as defined by the rule. It does not require looking through every intermediary or account in the same way, and an existing customer can receive different treatment when the bank has a reasonable belief it knows the person’s true identity.
CDD adds relationship context to identity. A covered institution develops a risk profile by understanding the nature and purpose of the relationship. Its ongoing processes identify and report suspicious transactions when required and maintain or update customer information on a risk basis.
For a legal-entity customer, current FinCEN rules and guidance can require beneficial-owner identification and verification. Account type, exclusions, exemptions, exceptive relief, and later facts that call earlier information into question can affect what must be collected or refreshed. A static checklist is therefore not a safe substitute for the current CDD rule.
Assume an LLC applies for an operating account expected to receive domestic customer payments and make payroll and supplier payments.
The bank’s process may include:
Six months later, the account begins sending international payments that are inconsistent with the original profile. That change does not by itself prove wrongdoing. It can prompt the bank to review transactions, seek an explanation or updated information, revise the risk profile, and determine whether other BSA obligations apply.
In securities regulation, FINRA uses “know your customer” for obtaining essential facts about a customer and the authority of people acting for that customer. Suitability and Regulation Best Interest address recommendations and investment conduct. Banking KYC instead usually refers to identification and financial-crime risk controls.
Collecting income, net worth, objectives, and risk tolerance for an investment account may support securities obligations, but those fields are not a universal description of bank CIP requirements.
This page provides general financial and regulatory education, not legal or compliance advice. Use the rules and guidance applicable to the institution, jurisdiction, customer, and review date.