Learn more about the latest security and privacy threats
Back

KYC (Know Your Customer)

Updated July 13, 2026

Table of contents
  • KYC, short for Know Your Customer, is the process regulated firms use to verify who their customers are and assess the risk they pose.
  • It is a legal requirement for regulated firms, and the foundation on which the rest of anti-money-laundering compliance is built.
  • A KYC check confirms a customer's identity against reliable sources, screens them for risk, and is kept current through ongoing monitoring.
  • KYC is not a one-time gate: it runs from onboarding through the life of the relationship, because risk changes over time.
  • Modern KYC is electronic and remote, and the strongest versions resist fraud with chip reads and liveness rather than easily faked photos.
  • KYC is one part of the wider AML framework, and its business counterpart, verifying companies, is KYB.

KYC, or Know Your Customer, is the process by which a regulated firm verifies a customer's identity and assesses their risk, before and throughout the business relationship, using reliable, independent sources. It confirms a person is who they claim to be, screens them for risk, and keeps that current, forming the identity foundation the rest of AML compliance depends on.

TL;DR

KYC is how a regulated firm verifies who a customer is and assesses their risk, using reliable sources, before and throughout the relationship. It is legally required and the foundation of anti-money-laundering compliance: you cannot monitor, screen or report meaningfully without reliably knowing your customer. A KYC check confirms identity, screens for sanctions and PEP risk, and is kept current through ongoing monitoring. Modern KYC is electronic and resists fraud with chip reads and liveness. It is one part of the broader AML framework, and its business-side counterpart, verifying companies and their owners, is KYB.

What is KYC (Know Your Customer)?

KYC, short for Know Your Customer, is the process a regulated firm follows to establish and verify who its customers are. At its simplest, it answers one question with evidence: is this person who they claim to be. It then adds a second: what risk do they pose. Together those answers let a firm decide whether, and on what terms, to do business with someone.

KYC exists because the financial system depends on institutions being able to trust, and account for, the people they serve. Anti-money-laundering law makes this a duty rather than a courtesy: regulated firms must identify and verify customers using reliable, independent sources, and keep records of having done so. KYC is therefore both a control against financial crime and the entry point to nearly every regulated relationship, delivered in most modern products through KYC software. Its counterpart for companies, verifying a business and the people who own it, is Know Your Business.

Why does Know Your Customer matter?

Know Your Customer matters because it is the foundation everything else in compliance rests on. You cannot monitor transactions, screen against sanctions, or report suspicious activity in any meaningful way if you do not reliably know who your customer is. Get identity wrong at the start and every downstream control is built on sand. That is why KYC is the first and most fundamental of a firm's anti-money-laundering obligations.

It also matters commercially and reputationally. Regulators require it, and inadequate KYC is a compliance failure that attracts penalties. Beyond that, weak identity checks let fraudsters and criminals into a firm using stolen or fabricated identities, causing direct losses and turning the firm into a vehicle for crime. Strong KYC protects the firm from regulatory action, from fraud, and from unknowingly serving the very people the rules are meant to exclude, which is why it anchors any serious AML compliance programme.

What are the steps in the KYC process?

A modern KYC process runs in a clear sequence. It begins with customer identification, collecting the identifying information a customer provides. It then verifies that identity against reliable, independent sources, historically by checking documents, and increasingly by reading the cryptographically signed chip in a modern passport or ID, combined with a liveness check to confirm a real, live person is present and matches the document.

Next comes screening: checking the customer against sanctions lists, politically exposed person data and adverse media, to surface risk. The firm then assesses the customer's overall risk and, for higher-risk cases, applies enhanced due diligence. Finally, because none of this stays static, the relationship is kept under ongoing monitoring, so changes in behaviour or risk are caught after onboarding. The strongest programmes treat KYC as continuous rather than a one-off event, the case for perpetual over periodic checks.

What is the difference between KYC and CDD?

KYC and customer due diligence, or CDD, are closely related and often used loosely, but there is a useful distinction. KYC is commonly used as the umbrella term for knowing your customer, while CDD refers specifically to the due-diligence measures within it: identifying and verifying the customer, understanding the purpose of the relationship, and assessing risk. In many frameworks, CDD is the formal regulatory term and KYC is the everyday one.

The practical takeaway is that they describe the same underlying activity at different levels of formality. Within CDD there are gradations: simplified due diligence for low-risk cases, standard due diligence for most, and enhanced due diligence for higher-risk customers such as PEPs. So when people say KYC, they usually mean the whole process of knowing and risk-assessing a customer, of which CDD, in its regulatory sense, is the core. Both sit inside the wider anti-money-laundering framework.

Who needs to perform Know Your Customer checks?

Any regulated firm that onboards customers needs to perform KYC. That includes banks, payment providers and fintechs, crypto and digital-asset platforms, lenders and credit providers, insurers, gaming and gambling operators, and many designated non-financial businesses such as certain professional-services firms. Wherever a firm is regulated for anti-money-laundering purposes and takes on customers, KYC is a baseline obligation, not an option.

Beyond the strictly regulated, many businesses adopt KYC-style verification voluntarily as a fraud and trust control, because onboarding an unverified or fraudulent user causes losses even where no AML rule applies. Marketplaces and platforms increasingly verify users for exactly this reason. The common thread is that wherever money, credit or trust flows to a person, confirming who that person really is protects the business, which is why identity verification has spread well beyond its banking origins into almost every digital service that matters.

What is the difference between KYC and AML?

KYC and AML are frequently conflated, but they operate at different levels. Anti-money laundering, or AML, is the entire framework of laws, controls and obligations aimed at preventing money laundering. KYC, Know Your Customer, is one component of that framework: the part concerned with verifying a customer's identity and assessing their risk. In short, KYC sits inside AML, not alongside it.

The relationship is best understood as foundation and structure. AML sets the objective and prescribes the controls; KYC delivers the identity foundation those controls depend on. Transaction monitoring, sanctions screening and suspicious activity reporting are all AML controls that build on knowing the customer. So a firm does not choose between KYC and anti-money laundering; it performs KYC as part of meeting its AML obligations. We unpack this in detail in our guide to KYC vs AML, but the essence is that KYC is the identity layer within the broader anti-money-laundering effort.

How is KYC changing in 2026?

KYC is evolving quickly. The most immediate shift is in fraud resistance: as generative tools make fake images and videos convincing, verification that relies on an uploaded photo is increasingly exposed, and chip reads plus layered liveness have become the standard, the subject of our guide to deepfake detection. The second is a move from one-off checks to continuous, perpetual verification, so risk is refreshed as it changes rather than only at onboarding.

The third shift is reusability and data minimisation. The industry is moving away from every firm independently re-verifying and then storing each customer's data, toward reusable credentials, a verified user carrying a KYC passport across services, and architectures that avoid pooling sensitive identity data into breach-prone central stores. The fourth is regulation: harmonising rules in the EU and rising expectations elsewhere raise the bar for how defensible and privacy-preserving verification must be. Together these mean KYC is judged less on how slick its onboarding looks and more on how reliable, continuous and privacy-aware it is.

How does Zyphe approach KYC?

Zyphe approaches KYC as an infrastructure problem, built so that strong verification and strong data protection are the same thing. Verification reads the NFC chip in modern documents to the ICAO 9303 and eIDAS standards, with two-step liveness and no image upload, which removes a common deepfake surface, and customers are screened against sanctions, PEP and adverse-media data as part of the same flow.

What sets it apart is the data architecture. Personal data is sharded across a network of more than 60,000 decentralised nodes, with a customer-held key and no master key, so verification never creates the central honeypot that makes identity databases attractive breach targets. Verified users can carry a reusable credential across services, removing repeat verification, and data residency can be pinned per region. Integration takes around fifteen minutes through a single API, and the same platform extends to business verification for companies. The result is KYC that is fast, fraud-resistant and privacy-preserving, on decentralised infrastructure. Book a demo to see it against your onboarding.

The bottom line

KYC, KYC, is the process of reliably establishing who a customer is and what risk they pose, and it is the foundation the whole of anti-money-laundering compliance rests on. It is legally required, it runs from onboarding through the life of the relationship, and it is only as valuable as it is reliable, which is why modern KYC leans on chip reads and liveness rather than easily faked photos, and increasingly on continuous rather than one-off checks. It is one part of the broader AML framework, and its business-side counterpart is KYB. Get identity right, keep it current, and hold it safely, and everything downstream becomes possible.

Cited sources

Frequently Asked Questions

KYC stands for Know Your Customer. It is the process by which a regulated firm verifies a customer's identity and assesses their risk, using reliable, independent sources, before and throughout the business relationship. It is the identity foundation on which the rest of anti-money-laundering compliance is built.

It involves identifying the customer, verifying their identity against reliable sources (increasingly via chip reads and liveness), screening them against sanctions, PEP and adverse-media data, assessing their risk with enhanced due diligence for higher-risk cases, and keeping the information current through ongoing monitoring.

Yes, for regulated firms. Anti-money-laundering law requires firms to identify and verify customers using reliable, independent sources and to keep records. The exact rules vary by jurisdiction, but performing KYC is a near-universal obligation for regulated financial and many other services.

AML is the whole framework aimed at preventing money laundering, while KYC is one part of it: verifying a customer's identity and risk. KYC sits inside AML and provides the identity foundation that monitoring, screening and reporting all build on.

KYC is commonly the umbrella term for knowing your customer, while customer due diligence, or CDD, is the formal set of due-diligence measures within it: identifying and verifying the customer, understanding the relationship, and assessing risk. They describe the same activity at different levels of formality.

Any regulated firm onboarding customers: banks, payment providers, fintechs, crypto platforms, lenders, insurers, gaming operators and many designated non-financial businesses. Many unregulated platforms also adopt KYC-style verification voluntarily as a fraud control.

KYC verifies an individual customer, while KYB, Know Your Business, verifies a company and identifies the people who ultimately own or control it. A firm onboarding businesses needs both, because resolving a company's ownership surfaces individuals who each then require KYC.

Modern electronic KYC can complete in under a minute to a few minutes for the customer, versus the days a manual process can take. Straightforward cases verify automatically, while higher-risk cases that need enhanced due diligence take longer.

Compliance without the data honeypot

Zyphe verifies identity without holding your customers' PII. See it in action.

Book a demo