Skip to main content
Category: AML and KYC

Know Your Customer

Also known as: KYC, Know Your Client
Simply put

Know Your Customer (KYC) is a due diligence process that financial institutions and other businesses use to verify who their customers are and to assess the risk each customer may pose. It combines identity verification with an evaluation of a customer's profile so an organization understands who it is doing business with. KYC is implemented through policies and procedures rather than a single check.

Formal definition

KYC refers to the set of policies and procedures organizations, particularly financial institutions and investment and financial services firms, implement to verify the identities of customers or clients and to assess associated risk. It encompasses identity verification and, in the case of investment and financial services, assessment of financial profiles, and functions as an ongoing risk-management and compliance process rather than a one-time control. The scope, specific steps, and regulatory obligations of a KYC program vary by jurisdiction and by the governing regulatory framework, which should be confirmed against applicable current requirements. KYC is distinct from payment-security standards such as PCI DSS and does not itself govern the storage or protection of cardholder or authentication data.

Why it matters

KYC is a foundational compliance and due diligence process that helps financial institutions and other businesses understand who they are doing business with before and during a customer relationship. By combining identity verification with an assessment of the risk a customer may pose, KYC is intended to help organizations manage risk and meet regulatory obligations. Because it functions as an ongoing process rather than a single check, it supports continued monitoring of customer relationships over time.

For investment and financial services firms in particular, KYC extends beyond identity verification to include assessment of a customer's financial profile, helping the organization tailor its risk management to each client. The specific obligations, steps, and depth of a KYC program vary by jurisdiction and by the governing regulatory framework, so organizations should confirm requirements against the applicable current regulations rather than assuming a uniform standard.

It is important to recognize the boundaries of what KYC addresses. KYC is distinct from payment-security standards such as PCI DSS and does not itself govern the storage or protection of cardholder or authentication data. Treating KYC as a customer-identity and risk-assessment discipline, separate from data-protection controls, helps organizations apply the right framework to each obligation.

Who it's relevant to

Compliance officers
Compliance teams design and maintain the policies and procedures that make up a KYC program, aligning identity verification and risk assessment with the obligations of their jurisdiction and governing regulatory framework. They should confirm specific requirements against current applicable regulations, since scope and steps vary.
Financial institutions and financial services firms
Banks, investment firms, and other financial services providers use KYC to verify customer or client identities and assess associated risk. For investment and financial services, this extends to evaluating financial profiles as part of an ongoing risk-management process.
Fraud and risk analysts
Risk teams rely on KYC outputs to understand who a customer is and the risk that customer may pose, supporting broader risk-management efforts. KYC is one input among many and addresses customer identity and risk rather than payment-data protection.
Payment security and PCI DSS practitioners
Security engineers and PCI DSS practitioners should note that KYC is a distinct compliance discipline focused on customer identity and risk. It does not govern the storage or protection of cardholder or authentication data, which fall under payment-security standards such as PCI DSS.

Inside KYC

Customer Identification Program (CIP)
The process of collecting and verifying identifying information about a customer, such as name, address, date of birth, and a government-issued identification number, at the point of onboarding. In a payments context this supports establishing who a merchant, cardholder, or account holder is before a relationship is established.
Customer Due Diligence (CDD)
Assessment of the customer's risk profile based on the nature of the relationship, expected activity, and other factors. CDD informs how closely an account is monitored and what additional controls may apply.
Enhanced Due Diligence (EDD)
Additional scrutiny applied to customers assessed as higher risk, which may involve gathering more information about the source of funds, business relationships, or ownership structures. EDD is intended to help mitigate risk for relationships that warrant closer review rather than to eliminate it.
Beneficial Ownership Identification
Identifying the natural persons who ultimately own or control a legal entity customer, such as a merchant business. This helps reduce the risk that entities are used to obscure the parties behind an account.
Ongoing Monitoring
Continuous or periodic review of customer activity to confirm that transactions are consistent with the known profile and to identify activity that may warrant further review. Monitoring controls involve trade-offs between false positives and false negatives and do not guarantee detection of all illicit activity.
Sanctions and Watchlist Screening
Comparing customer identities against applicable sanctions lists, politically exposed person references, and other watchlists. The scope and lists applied depend on the jurisdiction and the obligations of the institution.

Common questions

Answers to the questions practitioners most commonly ask about KYC.

Is KYC part of PCI DSS?
No. KYC is a customer due diligence and identity verification obligation that arises primarily from anti-money laundering (AML) and counter-terrorist financing laws and regulations, along with applicable financial regulator and card brand onboarding requirements. It is not a control defined by PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS. An organization may be subject to KYC obligations and PCI DSS obligations at the same time, but satisfying one does not satisfy the other, and they are assessed against different frameworks.
Does completing KYC at onboarding stop fraud?
No. KYC is intended to verify who a customer or merchant is and to support risk assessment, but it does not by itself prevent fraud. It may help reduce certain risks, such as onboarding of clearly fictitious entities, but it does not address transaction-level fraud types such as card-not-present fraud, account takeover, chargeback fraud, or friendly (first-party) fraud, and it can be defeated by synthetic identity techniques. KYC is one layer that works alongside ongoing monitoring and transaction fraud controls, each of which addresses different risks.
How does KYC relate to the cardholder data an organization handles under PCI DSS?
The two involve different data sets and different governing obligations. KYC typically relies on identity attributes and documentation used to verify a customer or merchant, while PCI DSS governs the protection of cardholder data such as the primary account number (PAN), cardholder name, expiration date, and service code, and prohibits storage of sensitive authentication data after authorization. Where KYC records and cardholder data are stored in the same environment, teams should apply the relevant controls to each data type and confirm scope boundaries rather than treating the datasets as interchangeable.
What is the difference between KYC at onboarding and ongoing monitoring?
Onboarding KYC establishes and verifies identity before or at the start of a relationship, while ongoing monitoring is the continued review of activity and periodic re-verification over the life of the relationship. Onboarding alone provides a point-in-time view and can become stale as behavior, ownership, or risk changes. Implementation teams generally treat these as complementary phases, since risk indicators that are not visible at onboarding may emerge later through activity monitoring.
How does KYC intersect with merchant underwriting for acquirers and payment processors?
Merchant underwriting frequently incorporates KYC-style verification of the merchant entity and its beneficial owners as part of assessing acceptance risk. This can inform decisions on approval, pricing, reserves, and ongoing merchant risk monitoring. The specific verification steps, documentation, and risk thresholds vary by acquirer, processor, region, and applicable card brand and network rules, so teams should base their procedures on the current requirements that apply to their program rather than a fixed checklist.
What limitations should implementers keep in mind when relying on KYC controls?
KYC verification can produce both false positives, such as legitimate customers flagged or delayed, and false negatives, such as bad actors passing checks through synthetic or stolen identities. Document-based and data-based verification each have trade-offs in accuracy, friction, and coverage. Requirements also vary by jurisdiction, entity type, and risk tier, and they change over time. Implementers should validate their approach against the obligations currently applicable to them and treat KYC as one component within a broader risk and fraud program rather than a standalone safeguard.

Common misconceptions

KYC and PCI DSS are the same thing or one satisfies the other.
KYC is a set of customer identification and due diligence practices tied to anti-money-laundering and regulatory obligations, while PCI DSS is a payment security standard focused on protecting cardholder data and sensitive authentication data. Meeting one does not satisfy the other; they address different objectives and are governed by different frameworks.
Completing KYC at onboarding means a customer is verified permanently and requires no further attention.
KYC is intended to be an ongoing process. Initial identification is complemented by ongoing monitoring and periodic review, because a customer's risk profile and activity can change over time. Onboarding checks alone do not confirm continued legitimacy.
KYC prevents fraud such as account takeover or synthetic identity fraud.
KYC may help reduce certain risks by verifying identity and beneficial ownership, but it does not prevent all fraud. Synthetic identity fraud, account takeover, and first-party fraud can occur despite KYC controls, and detection involves false-positive and false-negative trade-offs. KYC is one control among several rather than a guarantee.

Best practices

Apply a risk-based approach that calibrates the depth of due diligence to the assessed risk of the customer, reserving enhanced due diligence for higher-risk relationships.
Treat KYC as an ongoing lifecycle by combining onboarding identification with continuous or periodic monitoring and refreshing customer information when risk factors change.
Identify and verify beneficial owners of legal entity customers to reduce the risk that ownership structures obscure the parties behind an account.
Confirm sanctions and watchlist screening obligations against the applicable jurisdictional requirements, since the lists and scope vary by region and change over time.
Keep KYC controls distinct from, and coordinated with, payment data protection controls governed by PCI DSS, ensuring identity data collection does not create unnecessary exposure of cardholder data or sensitive authentication data.
Document due diligence decisions, monitoring outcomes, and escalation criteria so that the rationale for risk ratings and enhanced review can be reviewed and audited.