Know Your Customer
Know Your Customer (KYC) is a due diligence process that financial institutions and other businesses use to verify who their customers are and to assess the risk each customer may pose. It combines identity verification with an evaluation of a customer's profile so an organization understands who it is doing business with. KYC is implemented through policies and procedures rather than a single check.
KYC refers to the set of policies and procedures organizations, particularly financial institutions and investment and financial services firms, implement to verify the identities of customers or clients and to assess associated risk. It encompasses identity verification and, in the case of investment and financial services, assessment of financial profiles, and functions as an ongoing risk-management and compliance process rather than a one-time control. The scope, specific steps, and regulatory obligations of a KYC program vary by jurisdiction and by the governing regulatory framework, which should be confirmed against applicable current requirements. KYC is distinct from payment-security standards such as PCI DSS and does not itself govern the storage or protection of cardholder or authentication data.
Why it matters
KYC is a foundational compliance and due diligence process that helps financial institutions and other businesses understand who they are doing business with before and during a customer relationship. By combining identity verification with an assessment of the risk a customer may pose, KYC is intended to help organizations manage risk and meet regulatory obligations. Because it functions as an ongoing process rather than a single check, it supports continued monitoring of customer relationships over time.
For investment and financial services firms in particular, KYC extends beyond identity verification to include assessment of a customer's financial profile, helping the organization tailor its risk management to each client. The specific obligations, steps, and depth of a KYC program vary by jurisdiction and by the governing regulatory framework, so organizations should confirm requirements against the applicable current regulations rather than assuming a uniform standard.
It is important to recognize the boundaries of what KYC addresses. KYC is distinct from payment-security standards such as PCI DSS and does not itself govern the storage or protection of cardholder or authentication data. Treating KYC as a customer-identity and risk-assessment discipline, separate from data-protection controls, helps organizations apply the right framework to each obligation.
Who it's relevant to
Inside KYC
Common questions
Answers to the questions practitioners most commonly ask about KYC.