Know Your Customer (KYC)

Know Your Customer is the risk-based process financial institutions use to identify customers, understand relationships, and support ongoing financial-crime controls.

Know Your Customer (KYC) is the risk-based process a financial institution uses to identify a customer, understand the purpose and expected activity of the relationship, and keep relevant information current. KYC is an umbrella term rather than one universal rule: the exact customer identification, due diligence, monitoring, and recordkeeping duties depend on the institution, jurisdiction, product, and customer.

Key Takeaways

  • KYC is broader than checking an identity document at account opening.
  • In U.S. banking, a Customer Identification Program (CIP) and customer due diligence (CDD) are related but distinct parts of Bank Secrecy Act compliance.
  • Legal-entity relationships can require identification and verification of beneficial owners under current rules and applicable relief.
  • Ongoing monitoring is used to compare activity with the institution’s understanding of the customer and to update information on a risk basis.
  • KYC does not prove that a customer or transaction is legitimate, suspicious, or criminal.
  • Securities suitability and investment recommendations are separate from banking KYC, even though customer information can overlap.

KYC, CIP, CDD, and EDD

ConceptMain questionTypical output
KYCWho is the customer, and what risks does the relationship present?Overall customer-information and risk-control process
Customer Identification ProgramCan the institution form a reasonable belief that it knows the customer’s identity?Required identifying information, verification, notices, and records
Customer due diligenceWhat is the nature, purpose, ownership, and expected activity of the relationship?Customer risk profile and ongoing monitoring
Enhanced Due DiligenceWhat additional information or review is appropriate for elevated risk?Deeper verification, approvals, source information, or monitoring

The labels are not interchangeable. A bank can complete the minimum identity steps and still need additional CDD, sanctions, fraud, or suspicious-activity controls.

U.S. Bank Customer Identification Program

Under 31 CFR 1020.220, a bank’s written CIP must be appropriate for its size and business and include risk-based procedures for verifying identity to the extent reasonable and practicable. Before opening an account, the bank generally obtains:

  • name;
  • date of birth for an individual;
  • address; and
  • an identification number.

The bank then uses documentary or nondocumentary methods, or both, to verify identity. Its procedures must address situations in which identity cannot be verified, required records, customer notice, and comparison with government lists when an applicable list has been designated.

CIP applies to a “customer” and “account” as defined by the rule. It does not require looking through every intermediary or account in the same way, and an existing customer can receive different treatment when the bank has a reasonable belief it knows the person’s true identity.

Customer Due Diligence and Ongoing Monitoring

CDD adds relationship context to identity. A covered institution develops a risk profile by understanding the nature and purpose of the relationship. Its ongoing processes identify and report suspicious transactions when required and maintain or update customer information on a risk basis.

For a legal-entity customer, current FinCEN rules and guidance can require beneficial-owner identification and verification. Account type, exclusions, exemptions, exceptive relief, and later facts that call earlier information into question can affect what must be collected or refreshed. A static checklist is therefore not a safe substitute for the current CDD rule.

Worked Example: Business Account Opening and Review

Assume an LLC applies for an operating account expected to receive domestic customer payments and make payroll and supplier payments.

The bank’s process may include:

  1. obtaining identifying information for the legal entity and the person opening the account;
  2. verifying the entity through formation documents and reliable records;
  3. identifying and verifying beneficial owners when the current rule requires it;
  4. understanding the business, account purpose, expected activity, and relevant geographic exposure; and
  5. assigning monitoring and review procedures consistent with the assessed risk.

Six months later, the account begins sending international payments that are inconsistent with the original profile. That change does not by itself prove wrongdoing. It can prompt the bank to review transactions, seek an explanation or updated information, revise the risk profile, and determine whether other BSA obligations apply.

KYC Is Not Investment Suitability

In securities regulation, FINRA uses “know your customer” for obtaining essential facts about a customer and the authority of people acting for that customer. Suitability and Regulation Best Interest address recommendations and investment conduct. Banking KYC instead usually refers to identification and financial-crime risk controls.

Collecting income, net worth, objectives, and risk tolerance for an investment account may support securities obligations, but those fields are not a universal description of bank CIP requirements.

Risks and Common Mistakes

  • Treating KYC as a single global statute with identical requirements everywhere.
  • Equating identity verification with complete due diligence.
  • Collecting excessive information without a defined legal, risk, privacy, or operational purpose.
  • Assuming a successful digital check proves the document, device, customer, and source of funds are all legitimate.
  • Treating a higher-risk classification as an accusation of criminal conduct.
  • Refreshing every customer on a rigid schedule without considering current rules and risk triggers.
  • Confusing beneficial ownership for AML purposes with ownership definitions used in tax, securities, or property law.
  • Describing investment suitability as the main purpose of banking KYC.

Authoritative Sources

FAQs

Is KYC completed once at account opening?

No. Identity procedures are concentrated at onboarding, but CDD and monitoring can require later review or updates when risk, activity, ownership, or information changes.

Does a KYC review mean a customer is suspected of a crime?

No. KYC is a standard compliance process. Additional questions can result from routine policy, missing information, changed activity, or heightened risk without establishing misconduct.

This page provides general financial and regulatory education, not legal or compliance advice. Use the rules and guidance applicable to the institution, jurisdiction, customer, and review date.

Browse Banking