What is Know Your Customer (KYC)? A Guide to Compliance

Updated August 20, 2026
KYC regulations are mandatory verification standards that financial institutions must follow to confirm customer identities, assess risk, and prevent financial crimes. Failing to meet them carries real consequences: TD Bank paid $3 billion in fines in 2024 after investigators found it had approved more than $470 million in illicit transactions. U.S. regulators issued more than $4.3 billion in AML-related penalties that same year.
Know Your Customer (KYC) compliance is the first line of defense against money laundering, terrorist financing, and identity fraud. It governs how banks, credit unions, fintechs, and other regulated entities verify who their customers are, what risk those customers carry, and how their accounts should be monitored over time.
This guide explains what KYC regulations require, how the core components work, which legal frameworks apply, and how digital verification tools like eKYC and mobile KYC can improve compliance without sacrificing customer experience.
Key takeaways
- KYC regulations require financial institutions to verify customer identity, assess risk, and monitor accounts continuously, not just at onboarding.
- The three core components of KYC are the Customer Identification Program (CIP), Customer Due Diligence (CDD), and Enhanced Due Diligence (EDD) for high-risk accounts.
- KYC and Anti-Money Laundering (AML) serve different functions: KYC establishes who the customer is, while AML monitors ongoing activity for suspicious behavior.
- Digital KYC tools, including eKYC and mobile KYC, reduce onboarding time and cost while maintaining compliance with government regulations.
- AI-powered fraud, including deepfakes and synthetic identities, is making traditional KYC checks insufficient. Organizations need identity verification that produces cryptographically defensible records.
What are KYC regulations?
KYC regulations are legally binding requirements that compel financial institutions to verify the identity of their customers, understand the nature of their financial activity, and assess the risk of money laundering or terrorist financing. The term "Know Your Customer" covers both the regulatory framework and the practical processes institutions use to meet it.
These requirements exist because financial institutions are the primary channel through which illicit funds move. Without robust identity verification, criminal networks can open accounts, layer transactions, and obscure the origin of illegal money.
KYC regulations apply at account opening and continue throughout the customer relationship. A customer's risk profile can change, and institutions are required to detect and respond to those changes.
Why KYC regulations exist
KYC requirements in the United States trace back to the Bank Secrecy Act (BSA) of 1970, which first required financial institutions to help identify and report money laundering. After the September 11, 2001 terrorist attacks, the USA PATRIOT Act expanded those obligations significantly, requiring institutions to implement formal Customer Identification Programs and enhanced due diligence for high-risk accounts.
The Financial Action Task Force (FATF), an intergovernmental body established in 1989, sets the global standards that most jurisdictions treat as law. More than 200 jurisdictions align their AML and KYC frameworks with FATF recommendations.
The stakes are not abstract. In August 2025, U.S. Treasury investigators revealed that Chinese money-laundering networks had processed approximately $312 billion in illicit transactions through U.S. financial institutions over several years. KYC failures enable that kind of activity.
Core components of KYC compliance
KYC compliance is built on three interconnected components. Each one addresses a different stage of the customer relationship.
Customer Identification Program (CIP)
The CIP is the foundation of KYC. Under Section 326 of the USA PATRIOT Act, every financial institution must implement a written, risk-based CIP before opening any account.
At minimum, institutions must collect and verify four pieces of information for every customer:
- Full legal name
- Date of birth
- Current address
- Government-issued identification number (Social Security number, passport number, or equivalent)
For business entities, institutions must also identify and verify the identity of any individual who owns 25% or more of the entity and any individual who controls it. This beneficial ownership requirement, codified in FinCEN's 2016 Customer Due Diligence (CDD) Final Rule, applies to corporations, LLCs, partnerships, and similar structures.
Institutions must retain CIP records for five years after an account is closed.
Customer Due Diligence (CDD)
CDD goes beyond identity verification. It requires institutions to understand the nature and purpose of the customer relationship and build a risk profile that determines how closely the account will be monitored.
CDD involves three tiers of scrutiny:
- Simplified Due Diligence (SDD): Used for low-risk accounts where money laundering risk is minimal.
- Standard CDD: Verifies identity and assesses risk level for most customers.
- Enhanced Due Diligence (EDD): Applied to high-risk customers, including politically exposed persons (PEPs), accounts with complex ownership structures, and customers in high-risk jurisdictions.
FinCEN's CDD Final Rule requires institutions to conduct ongoing monitoring and update customer risk profiles when significant changes occur, such as new ownership or unusual transaction patterns.
Enhanced Due Diligence (EDD)
EDD applies when initial checks reveal elevated risk. It requires institutions to collect additional information, including:
- Source of wealth and funds
- Detailed background on the customer's business activities
- Director and shareholder information for entities
- Adverse media and sanctions screening
The USA PATRIOT Act established mandatory EDD obligations for foreign banking accounts, offshore jurisdictions, and correspondent banking relationships. FATF's 2003 Forty Recommendations formalized EDD as a global standard.
Ongoing monitoring
KYC is a continuous obligation. Institutions must monitor customer accounts throughout the lifecycle of the relationship, not just at onboarding.
Ongoing monitoring includes watching for:
- Unusual or sudden changes in transaction volume
- Cross-border activity inconsistent with the customer's profile
- Transactions involving sanctioned entities or watchlisted individuals
- Adverse media references
- Unusually large deposits or withdrawals
When suspicious activity is detected, institutions must file a Suspicious Activity Report (SAR) with FinCEN and relevant law enforcement. High-risk accounts require more intensive monitoring than standard accounts.
Who must comply with KYC regulations
KYC requirements apply to any institution that opens or maintains financial accounts. In the United States, covered institutions include:
- Banks and credit unions
- Broker-dealers and investment advisers
- Mutual funds and futures commission merchants
- Money services businesses (MSBs), including cryptocurrency exchanges
- Insurance companies
- Real estate agents and title companies in certain transaction types
- Private lenders and lending platforms
The scope of KYC has expanded significantly since the BSA's original focus on depository institutions. U.S. covered institutions are now required to identify and report more than 200 federal and state crimes, including drug trafficking, fraud, embezzlement, and terrorist financing.
KYC document requirements
Two categories of documentation are required for KYC verification: proof of identity with a photograph and proof of address.
For individuals, commonly accepted documents include:
- Government-issued photo ID (driver's license, passport, state ID card)
- Proof of address (utility bill, bank statement, government correspondence)
For business entities, institutions typically require:
- Certified articles of incorporation or equivalent formation documents
- Government-issued business license
- Partnership agreement or trust instrument
- Beneficial ownership certification identifying all individuals with 25%+ ownership
Institutions must verify that documents are authentic and unexpired. Digital identity verification tools can automate much of this process, but human review remains essential for high-risk cases.
KYC vs. AML: understanding the connection
KYC and Anti-Money Laundering (AML) are related but distinct. KYC focuses on customer identification and verification at onboarding and throughout the relationship. AML is the broader regulatory framework that uses KYC data, along with ongoing transaction monitoring and reporting, to detect and prevent financial crimes.
Think of it this way: KYC establishes who your customer is. AML ensures their ongoing activity remains legitimate.
Both are legally required. Institutions cannot maintain effective AML programs without strong KYC processes, and KYC data is only valuable if it feeds into active monitoring and reporting systems.
What is eKYC?
Electronic KYC (eKYC) is the digitalization of the KYC process. It uses internet-based tools to verify identity documents, conduct biometric authentication, and assess risk in real time, replacing paper-based and in-person verification workflows.
eKYC systems typically combine:
- ID document verification (scanning and authenticating government-issued IDs)
- Biometric authentication (facial recognition and liveness detection)
- Database checks against government records, sanctions lists, and PEP databases
- Real-time risk monitoring
eKYC lowers costs for financial institutions, accelerates onboarding, and creates a better customer experience, all while maintaining compliance with government regulations. It is part of the broader trend toward business process automation in financial services.
What is mobile KYC?
Mobile KYC establishes a customer's identity using a smartphone or tablet. Customers use their device to scan government-issued documents and capture a selfie or short video for biometric comparison.
A well-designed mobile KYC flow allows customers to complete verification in minutes, from anywhere. AI evaluates the submitted information, checks it against authoritative data sources, and flags anomalies for human review.
Mobile KYC reduces fraud, improves compliance standards, and meets the expectations of customers who expect digital experiences to be fast and intuitive.
AI-era challenges for KYC compliance
Traditional KYC checks were designed for a world where forged documents were difficult to produce and impersonation required physical presence. That world no longer exists.
Generative AI can now produce convincing fake IDs, fabricate financial documents, and generate deepfake video that defeats basic liveness detection. Synthetic identities, which combine real and fabricated personal information, can pass standard document verification checks.
The consequences are measurable. Fraud losses reported to the FTC rose to $12.7 billion in 2024, a 25% increase in a single year.
For compliance teams, this means KYC processes that rely solely on document uploads and selfie comparisons are no longer sufficient for high-risk moments. Organizations need identity verification that:
- Detects deepfakes and injected biometric attacks in real time
- Produces cryptographically signed records that bind identity to documents and transactions
- Includes human-in-the-loop review for cases that automated systems cannot resolve
- Monitors for fraud signals across the full customer lifecycle, not just at onboarding
The regulatory floor is compliance. The operational requirement is fraud prevention that keeps pace with the tools attackers are using.
Implementing an effective KYC program
A strong KYC program is risk-based, automated where possible, and continuously updated. The following practices define effective implementation:
- Start with a written CIP. FinCEN requires a documented, risk-based Customer Identification Program. The policy must define how identity is verified, what documents are accepted, how records are retained, and how high-risk accounts are escalated.
- Automate document verification. Manual document review is slow and error-prone. Automated credential analysis can authenticate government-issued IDs in seconds, checking security features, expiration dates, and database matches.
- Apply risk-based due diligence. Not every customer requires the same level of scrutiny. Low-risk accounts can move through simplified due diligence. High-risk accounts, including PEPs, entities with complex ownership, and customers in high-risk jurisdictions, require EDD.
- Monitor accounts continuously. KYC is not a one-time event. Establish automated monitoring for transaction anomalies, adverse media, and changes in customer behavior. Update risk profiles when significant changes occur.
- Train your team. Regulations evolve. Staff responsible for KYC decisions need regular training on current requirements, emerging fraud tactics, and escalation procedures.
- Audit your program regularly. Systematic reviews reveal gaps in compliance controls before regulators do. Audits should cover policy documentation, verification procedures, monitoring effectiveness, and recordkeeping.
- Use third parties carefully. When using third-party vendors to collect and verify customer profiles, financial institutions must ensure those vendors employ specific risk controls and remain in compliance with government regulations. A third-party vendor should be transparent about their processes and able to provide AML and customer identification certificates annually.
Penalties for KYC non-compliance
Non-compliance with KYC regulations carries severe consequences. Penalties include multi-million-dollar fines, criminal prosecution for individuals, enhanced regulatory oversight, and reputational damage that can affect customer acquisition for years.
Recent enforcement actions establish the stakes:
- TD Bank paid $3 billion in fines in 2024 for KYC and AML failures.
- U.S. regulators issued more than $4.3 billion in AML-related penalties in 2024 alone.
- Penalties for transaction monitoring violations more than doubled year over year in 2024, exceeding $3.3 billion.
The cost of compliance is real. Financial institutions are projected to spend $51.7 billion on AML-KYC compliance technology and operations by 2028. But the cost of non-compliance is higher, measured in fines, legal exposure, and lost customer trust.
Benefits of a strong KYC process
Beyond regulatory compliance, a well-executed KYC program delivers measurable business value:
- Fraudulent activity, terrorism financing, and financial crimes are prevented or minimized through thorough verification.
- Identity theft is reduced when customers are verified against authoritative sources with biometric confirmation.
- Reputational risk is contained by avoiding association with illicit activity.
- eKYC dramatically accelerates onboarding compared to traditional paper-based processes, which could take weeks or months.
- Transparent verification builds trust between customers and financial institutions.
- Digital KYC processes save time and money compared to manual workflows.
- Automated compliance tools adapt to changing regulations across jurisdictions without requiring institutions to rebuild their processes from scratch.
How Proof supports KYC compliance
Online notarization and digital identity verification can help financial institutions meet the requirements of eKYC and mobile KYC. Financial institutions can integrate the Notarize platform into their existing workflow so customers can easily get documents notarized online that are required to be certified for KYC, resulting in better compliance and an improved customer experience.








































.jpg)





























































.jpg)


































