One customer, several products, one audit trail. See how neobanks run perpetual CDD under FFIEC and EU AML rules, and who owns liability in a BaaS stack.
Table of contents
- KYC for neobanks differs from a traditional bank's because one customer often uses several products, so the applicable due-diligence bar is the highest of them, not the average.
- Regulators increasingly expect perpetual customer due diligence, continuous and trigger-based, rather than a periodic review on a fixed calendar.
- In a banking-as-a-service stack, the sponsor bank owns the AML program. The OCC's 2024 consent order against Blue Ridge Bank, after a 2022 agreement, was a clear signal that partner-bank oversight of fintech programs is non-negotiable.
- The single customer base is both the neobank advantage and the compliance trap: convenient for the user, but it means a lending or crypto product can raise the KYC bar for the whole relationship.
- Reusable identity lets one verified credential serve several products while producing the separate, product-specific audit trails each regulator expects.
- The audit pack is knowable in advance: the FFIEC BSA/AML Examination Manual sets out what an examiner will look for.
KYC for neobanks is the identity verification and ongoing customer due diligence a digital bank performs across its products, from checking to lending to crypto, usually on a single customer base. Because one customer may use several products, the applicable KYC bar is the highest of them, and regulators increasingly expect perpetual, not periodic, due diligence.
TL;DR
KYC for neobanks looks like a traditional bank's until you notice the structure: one customer, several products, one platform. That single customer base is the neobank's advantage and its compliance trap. When the same person opens checking, takes a loan, and trades crypto on one app, the due-diligence bar that applies is the highest of those products, not a comfortable average.
On top of that, regulators are moving from periodic reviews to perpetual customer due diligence, continuous monitoring with trigger-based refresh. And in a banking-as-a-service model, the sponsor bank owns the AML program, a lesson the OCC's enforcement against Blue Ridge Bank made expensive and public. This guide explains perpetual CDD, the single-customer-base problem, who owns liability across sponsor-bank, EMI, and chartered models, what triggers re-verification, and how reusable identity serves several products while keeping the separate audit trails each regulator expects.
11 min read. Last updated 26 August 2026.
What does KYC for neobanks involve?
KYC for neobanks covers the same core as any regulated financial institution, verify identity, screen against sanctions and PEP lists, assess risk, and monitor on an ongoing basis, but the delivery is different. A neobank onboards digitally at scale, often across several products, and frequently operates on top of a sponsor bank's licence rather than its own charter. That changes both how KYC is done and who is accountable for it.
The defining feature is the single customer base across multiple products. A traditional bank might silo checking, lending, and investment in separate systems with separate onboarding; a neobank typically has one customer record spanning everything. That is great for user experience and dangerous for compliance if the KYC bar is set to the lowest-risk product rather than the highest. The platform mechanics are covered in our identity verification software comparison; the neobank twist is the shared customer base and the BaaS accountability question.
What is perpetual customer due diligence, and how does it differ from periodic?
Periodic customer due diligence reviews a customer on a schedule, every one, two, or three years by risk tier, regardless of whether anything has changed. Perpetual customer due diligence replaces the calendar with continuous monitoring and event-driven refresh: the customer's risk profile updates whenever new information arrives, a sanctions-list change, a shift in transaction behaviour, a life event, rather than waiting for the next scheduled review.
The direction of travel across the FFIEC framework in the US and the EU AML regime is toward this continuous model, because periodic review leaves long windows where a customer who became high-risk is still treated as low-risk. For neobanks, perpetual CDD is also a better fit for the product reality: a customer who was low-risk with a checking account looks different the moment they start trading crypto, and a perpetual model catches that immediately. This is the same principle as perpetual KYC, applied to a multi-product bank.
Why does the single customer base raise the KYC bar?
Here is the trap. A neobank onboards a customer for a simple checking account at a modest KYC bar. Months later the same customer enables lending and then crypto trading, products that carry higher AML risk and stricter due-diligence expectations. Because it is one customer record, the relationship as a whole now sits at the highest applicable bar, and a KYC posture calibrated to the checking account is no longer sufficient.
The mistake is to verify once at the lowest product's standard and never re-base when the customer adds higher-risk products. The correct design treats product activation as a trigger: when a customer adds lending or crypto, the relationship is re-assessed and, if needed, re-verified to that product's standard. Set the KYC bar to the highest-risk product the customer actually uses, not the one they signed up with, and re-evaluate as their product mix changes. The AML compliance software layer is what monitors the behaviour that should trigger this.
Who owns the AML program: sponsor bank, EMI, or charter?
This is the question that defines liability, and getting it wrong is expensive. In a banking-as-a-service model, where a neobank fronts a customer experience on top of a chartered sponsor bank, the sponsor bank owns the BSA/AML program and is accountable to the regulator. The OCC's enforcement against Blue Ridge Bank made this unmistakable: after a 2022 agreement to fortify its fintech partnerships, Blue Ridge received a January 2024 consent order over continued BSA/AML deficiencies tied to its fintech programs, including weak controls and insufficient oversight, and ultimately wound down its BaaS business.
The lesson for neobanks and their partners is that the bank cannot outsource its AML accountability to a fintech, and the fintech cannot assume the bank has it covered. Under an EMI or e-money licence, the licensed entity owns its obligations directly, and a fully chartered neobank owns them outright. Whichever model you operate, KYC for neobanks requires a clear, documented answer to who owns the AML program and demonstrable oversight of every party touching customer onboarding. Ambiguity here is exactly what regulators punish, and it connects to why your KYC vendor is your biggest data breach risk: outsourcing the function never outsources the accountability.
What triggers a re-verification?
In a perpetual model, re-verification is event-driven, and the triggers are knowable. Adding a higher-risk product, such as crypto or lending, should re-base the relationship to that product's standard. A material change in transaction behaviour, sudden volume, new geographies, patterns inconsistent with the known profile, should prompt review. A sanctions or watchlist update that newly matches a customer requires immediate action. Life events and data changes, a new address, a name change, expiry of an identity document, should refresh the relevant verification. And any external signal, adverse media or a regulatory change, can trigger reassessment.
The point is that triggers, not the calendar, drive re-verification. A neobank that re-verifies only on a fixed cycle will miss the customer whose risk changed the week after onboarding, which is precisely the window enforcement actions tend to expose. Wire the triggers into monitoring so the refresh is automatic and evidenced.
How does reusable identity work across products?
The single customer base creates a tension: you want one smooth identity experience for the customer, but each product needs its own defensible audit trail. Reusable identity resolves it. A customer is verified once to the appropriate standard, and that verified credential is re-presented as they activate checking, lending, or crypto, so they are not re-onboarded from scratch for each product, while the system records a product-specific audit trail each time the credential is used.
That gives you one credential and several audit trails, the user convenience of a single onboarding and the regulatory defensibility of per-product records. Built on a decentralised model, the underlying identity data stays sharded with a customer-held key rather than copied into each product silo, so reuse does not multiply your data-breach surface. This is the model behind decentralised, reusable KYC, and for early-stage neobanks it pairs with the build-it-in-from-day-one approach in KYC for fintech startups.
What audit pack applies to neobanks?
A neobank, or its sponsor bank, is examined against the same standards as any BSA/AML program, and in the US the FFIEC BSA/AML Examination Manual is the reference an examiner uses. Expect scrutiny of the customer identification program, customer due diligence and beneficial-ownership procedures, ongoing monitoring, sanctions screening, suspicious activity reporting, and, crucially for BaaS, the oversight of third-party fintech relationships and who is accountable for each control.
The defensible posture is to maintain, per customer and per product, evidence of what was verified, at what standard, when it was refreshed and why, and how the sponsor-bank-to-fintech responsibilities are divided and supervised. A neobank that can produce that mapping, and show perpetual rather than stale due diligence, is in a far stronger position than one whose answer to who owned a control is a shrug. KYC for neobanks is ultimately judged on that clarity of ownership and the freshness of the due diligence.
The bottom line
KYC for neobanks is shaped by two things a traditional bank rarely faces at once: a single customer base spanning several products, and a banking-as-a-service structure that splits operation from accountability. The first means the due-diligence bar is the highest product the customer uses, not the one they joined with. The second means, in BaaS, the sponsor bank owns the AML program, as Blue Ridge learned the hard way.
Run perpetual, trigger-based due diligence rather than periodic reviews, re-base the relationship when customers add higher-risk products, use reusable identity to serve many products while keeping per-product audit trails, and document exactly who owns each control. Do that, and the neobank's single customer base becomes a compliance strength instead of a liability.
Book a neobank compliance walk-through, or see how it works.
Related resources
- Identity verification software comparison 2026
- Perpetual KYC: from photograph to video
- AML compliance software in 2026
- Why your KYC vendor is your biggest data breach risk
- KYC for fintech startups
- Decentralised KYC
- KYC software
Cited sources
- OCC, enforcement actions including Blue Ridge Bank (2022 agreement and 2024 consent order): https://www.occ.gov/topics/laws-and-regulations/enforcement-actions/index-enforcement-actions.html
- FFIEC BSA/AML Examination Manual: https://bsaaml.ffiec.gov/manual
- FinCEN, Bank Secrecy Act and customer due diligence: https://www.fincen.gov/
- Anti-Money Laundering Authority (AMLA), EU AML framework: https://www.amla.europa.eu/about-amla_en
- Financial Conduct Authority (FCA): https://www.fca.org.uk/
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.