KYC stands for Know Your Customer. It is the process organisations use to identify, verify and understand a customer before starting or continuing a business relationship.
Good KYC goes beyond collecting an identity document. It helps a compliance team assess who the customer is, why they want the service and whether further review is needed.
KYC is common across banks, payment firms, insurers, FinTechs, wealth managers, digital platforms and other regulated organisations. It also supports wider anti-money laundering and counter-terrorist financing controls.
Quick Answer: What Is KYC?
KYC is a compliance process used to verify identity, understand the purpose of a customer relationship, assess risk and retain evidence for future review.
A typical KYC workflow covers:
- Customer information collection
- Identity and address verification
- Sanctions, PEP and adverse media screening
- Customer risk scoring
- Enhanced due diligence where risk is higher
- Approval, record keeping and ongoing monitoring
The principle is straightforward: an organisation should understand who it is dealing with before providing services.
Why KYC Matters
Without effective KYC, an organisation may onboard someone without understanding their identity, sanctions exposure, political exposure, adverse media profile or expected activity.
That creates both compliance and operational risk. Therefore, KYC should operate as a controlled workflow, not a one-off form or document checklist.
For teams managing broader financial crime controls, WIDTH's AML monitoring workflow connects customer context with screening, alerts and review activity.
KYC, AML, CDD and KYB: What Is the Difference?
| Term | Meaning | Role |
|---|---|---|
| KYC | Know Your Customer | Identifies and understands an individual customer. |
| AML | Anti-Money Laundering | The wider framework of controls used to detect and manage financial crime risk. |
| CDD | Customer Due Diligence | The checks used to assess the customer and business relationship. |
| EDD | Enhanced Due Diligence | A deeper review applied to higher-risk relationships. |
| KYB | Know Your Business | Verifies a company, its ownership and the people behind it. |
When the customer is a legal entity, teams usually need KYB onboarding and beneficial ownership checks as well as KYC on directors, shareholders or ultimate beneficial owners.
What Information Is Collected During KYC?
The exact information depends on the customer, service, risk level and applicable rules. Most individual KYC reviews include:
- Full legal name and date of birth
- Nationality and residential address
- Government-issued identity document
- Contact and employment information
- Purpose and intended nature of the relationship
- Source of funds or wealth where relevant
- Expected account or transaction activity
Data collection should remain proportionate. Teams need enough information to make a defensible decision without creating unnecessary friction.
How the KYC Process Works
- Collect customer information. Capture identity, contact details and relationship purpose.
- Verify identity. Check reliable documents and supporting evidence.
- Run screening. Review sanctions, PEP, adverse media and relevant watchlist results.
- Assess risk. Consider customer, geography, product, channel and expected activity.
- Review exceptions. Investigate potential matches, missing evidence or unusual risk indicators.
- Approve or escalate. Record the decision, rationale, reviewer and any conditions.
- Monitor and refresh. Reassess the profile when information or risk changes.
A structured KYC onboarding process helps teams keep evidence, reviews and approvals connected from the start.
What Is KYC Screening?
KYC screening compares a customer with relevant risk data. This commonly includes sanctions lists, politically exposed person records, adverse media, watchlists and internal risk lists.
A possible match is not automatically a confirmed risk. Analysts still need to compare identifiers, investigate the context and document why they cleared or escalated the alert.
Where an alert requires deeper investigation, compliance case management gives teams a controlled place for evidence, ownership, escalation and decisions.
What Is a Risk-Based Approach to KYC?
A risk-based approach applies stronger controls where risk is higher. It avoids treating every customer in exactly the same way.
| Lower-risk relationship | Higher-risk relationship |
|---|---|
| Standard identity checks and normal review frequency | Additional evidence, deeper screening and more frequent review |
| Simple profile and expected activity | Complex profile, higher-risk geography or unusual activity |
| Routine approval | Specialist or senior approval where required |
Risk-based KYC does not mean overlooking lower-risk customers. It means matching the depth and frequency of review to the assessed risk.
When Is Enhanced Due Diligence Required?
Enhanced due diligence is a deeper review used when risk is elevated. It may be appropriate for a PEP, a customer linked to a higher-risk jurisdiction, unclear source of funds, significant adverse media or activity that does not fit the stated profile.
Common EDD measures
- Collecting additional identity or relationship evidence
- Reviewing source of funds and source of wealth
- Obtaining senior approval
- Applying tighter monitoring
- Increasing the frequency of periodic reviews
EDD is not a punishment. It gives the organisation enough information and control to decide whether it can manage the relationship responsibly.
Why KYC Is Not a One-Time Check
Customer risk changes. A person may become politically exposed, appear in adverse media, change occupation or begin activity that differs from the original profile.
Ongoing KYC combines event-driven reviews, periodic refreshes and monitoring. The aim is to keep the customer record current and reassess risk when meaningful changes occur.
Common KYC Challenges
| Manual KYC | Workflow-led KYC |
|---|---|
| Documents spread across inboxes and folders | One connected customer record |
| Screening screenshots stored as evidence | Results and review decisions captured together |
| Inconsistent risk scoring | Defined assessment rules and review controls |
| Unclear task ownership | Assigned owners, statuses and escalation paths |
| Slow audit preparation | Searchable, audit-ready decision history |
These are workflow problems. Asking analysts to work harder will not resolve fragmented tools, unclear ownership or missing audit trails.
How KYC Differs Across Industries
Banks use KYC for account opening and periodic reviews. Payment firms may combine user verification with transaction risk. Insurers assess policyholders, beneficiaries and claims-related risk. CSPs often connect individual KYC with corporate KYB and beneficial ownership reviews.
The context changes, but the operational requirement remains: onboard customers efficiently while keeping risk decisions consistent and reviewable.
How WIDTH Supports KYC Workflows
The WIDTH compliance platform helps teams connect customer data, verification, screening, risk scoring, case reviews and audit evidence in one operating environment.
WIDTH does not replace compliance judgement. It helps teams apply that judgement consistently, maintain accountability and retrieve evidence when a reviewer or auditor needs it.
This moves KYC beyond isolated checks. Customer profiles, alerts, decisions and ongoing reviews become part of connected risk intelligence.
FAQs About KYC
What does KYC stand for?
KYC stands for Know Your Customer. It is the process of identifying, verifying and understanding a customer during a business relationship.
Is KYC the same as AML?
No. KYC is one component of a wider AML framework. AML also covers monitoring, reporting, governance and other financial crime controls.
What documents are used for KYC?
Common documents include a passport or national identity card, proof of address and, where relevant, evidence of income, funds or wealth.
What is the difference between KYC and KYB?
KYC focuses on individuals. KYB verifies businesses, ownership structures and the people who control them.
Can KYC be automated?
Data collection, verification, screening and workflow routing can be automated. Human judgement remains important for exceptions, risk assessments and final decisions.
How often should KYC be updated?
The frequency should reflect risk and applicable requirements. Reviews may be periodic or triggered by material changes, alerts or unusual activity.
KYC Is the Starting Point for Better Risk Decisions
Effective KYC connects identity, screening, risk assessment, approval and ongoing review. When these steps sit in disconnected tools, teams lose time and visibility.
A connected workflow gives compliance teams clearer ownership, stronger audit evidence and a more complete view of customer risk. That makes KYC more than an onboarding requirement. It becomes the foundation for smarter risk decisions.