Know your customer (KYC) explained: what the term actually covers
Know your customer, usually shortened to KYC, is the set of checks a regulated business runs to establish who its customer is, who ultimately owns or controls them, and what the relationship is for. The obligation runs for the life of the relationship, not only at onboarding, and the detail differs by country.
This entry describes how the term is used in practice. It is not legal advice, and no firm should design a KYC programme from a glossary. The applicable rules are the ones in force in the jurisdictions the firm operates in.
What does KYC mean?
The international reference point is FATF Recommendation 10, which sets out the customer due diligence obligation at the heart of every national regime. Broadly it requires a firm to identify the customer and verify that identity from reliable, independent source material, to identify the beneficial owner and take reasonable measures to verify who that is, to understand the purpose and intended nature of the relationship, and to conduct ongoing monitoring.
Those four elements survive translation into national law almost everywhere. What varies is the evidence accepted, the thresholds, the record-keeping periods and the sectors caught.
Customer due diligence, simplified and enhanced
KYC is usually described in three tiers, applied according to assessed risk rather than uniformly:
- Simplified due diligence (SDD) applies where risk is demonstrably low. It reduces the depth or timing of verification. It never removes the obligation to identify the customer or to monitor.
- Customer due diligence (CDD) is the standard case: identify, verify, understand the purpose, monitor.
- Enhanced due diligence (EDD) applies to higher-risk situations. It typically adds source of funds and source of wealth enquiry, senior management approval to open or continue the relationship, and closer ongoing monitoring.
Politically exposed persons are the clearest EDD trigger. FATF Recommendation 12 asks firms to have systems to determine whether a customer or beneficial owner is a foreign PEP, to obtain senior management approval, to establish source of wealth and source of funds, and to monitor the relationship more closely. Family members and close associates are in scope. Whether domestic PEPs attract the same treatment is a national policy choice, which is exactly the kind of detail that does not travel between markets.
Beneficial ownership: who is actually behind the customer
A beneficial owner is the natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted. The point of the concept is that a company is never the real answer to "who am I dealing with".
Ownership percentage thresholds are the usual mechanism, and they are set nationally. In the European Union, the new AML Regulation, Regulation (EU) 2024/1624, defines beneficial ownership through an ownership interest of 25% or more, tightening the previous "more than 25%" formulation so that an exact quarter is now caught, with scope for a lower threshold in specified higher-risk sectors. The Regulation applies from 10 July 2027. Other jurisdictions use their own figures and their own register arrangements, and control can also arise without any shareholding at all, through voting rights, appointment rights or contractual arrangements.
KYC example: onboarding a repair network
An insurer takes on a bodyshop group as an approved supplier. Verifying the trading entity is straightforward, but the shareholder register shows two holding companies, one of them overseas, and no individual named directly.
Unwinding the chain takes a week and produces two individuals, each holding 30% indirectly, plus a third who holds only 5% but has the contractual right to appoint the board. That third person is a beneficial owner through control, and a check that stopped at the share percentages would have missed the person who actually runs the business.
How KYC differs from AML
KYC is a component. Anti money laundering is the whole programme, and it also contains transaction monitoring, sanctions screening, training, governance, record-keeping and regulatory reporting. A firm can hold complete KYC files and still have no functioning AML programme, because knowing who the customer is achieves nothing if nobody looks at what they then do.
KYC is also not fraud prevention, though they share tooling and often share a team. Fraud controls ask whether this specific transaction or claim is what it appears to be, and work with fraud indicators on individual files. KYC asks who this counterparty is over the life of a relationship.
Where KYC obligations differ by jurisdiction
The FATF Standards, first issued in 1989 and now committed to by more than 200 countries and jurisdictions, are the reason KYC looks broadly similar everywhere. They are recommendations to states, not directly applicable law, so what binds a firm is always the national implementation.
Points where markets diverge in ways that catch people out:
- Which sectors are regulated at all. Insurers, brokers, lawyers, estate agents and dealers in high-value goods are in scope in some regimes and not in others.
- Acceptable identity evidence, including whether remote or digital verification is permitted and on what terms.
- Ownership thresholds and register access, which have moved repeatedly in the last few years.
- Reliance on third parties, where the liability for a failed check usually stays with the firm relying, not the firm relied on.
For claims staff, the practical consequence is narrow and worth knowing. Where a claim payment goes to someone other than the policyholder, or a third-party supplier is onboarded, KYC obligations can attach to a step that looks like ordinary claims administration.