= Know your customer =

Know your customer or know your client (KYC) guidelines and regulations in financial services require professionals to verify the identity, suitability, and risks involved with maintaining a business relationship with a customer. These procedures fit within the broader scope of anti-money laundering (AML) and counter terrorism financing (CTF) regulations.

KYC requirements have evolved from simple identity verification into comprehensive risk management frameworks designed to prevent illicit financial activity. These procedures enable institutions to further understand their clients financial behaviour, identity, transactions, and aids in assessing exposure to money laundering and/or fraud. In addition to verifying personal or corporate identities, modern KYC standards often include customer and enhanced due-diligence for higher risk clients, ensuring compliance with global regulations.

KYC processes are also employed by companies of all sizes for the purpose of ensuring their proposed customers, agents, consultants, or distributors are anti-bribery compliant and are actually who they claim to be. Banks, insurers, export creditors, and other financial institutions are increasingly required to make sure that customers provide detailed due-diligence information. Initially, these regulations were imposed only on the financial institutions, but now the non-financial industry, fintech, virtual assets dealers, and even non-profit organizations are included in regulations in many countries.

== Requirements ==

In the United States, the Financial Industry Regulatory Authority (FINRA) Rule 2090 states that financial institutions must use reasonable diligence to identify and retain the identity of every customer and every person acting on behalf of those customers. In enforcing this rule, these organizations are expected to collect all information essential to knowing their customers. Information deemed necessary for enforcing know your customer requirements include the customer identification program (CIP), customer due diligence (CDD), and enhanced due diligence (EDD).

=== Customer Identification Program ===
Section 326 of the USA Patriot Act requires banks and other financial institutions to have a Customer Identification Program (CIP). This act requires financial institutions to at minimum, verify the identity of anyone looking to open an account, maintain records of this information, and verify if this person is on the list of known or suspected terrorists that financial institutions are provided by the U.S government. Financial institutions must collect four pieces of identifying information about its customers including:

- Name
- Date of birth
- Address
- Identification number

=== Customer due diligence ===
The Bank Secrecy Act, the common name for the Currency and Foreign Transaction Reporting Act of 1970 and its amendments and other statutes, established the customer due diligence (CDD) rule as part of an effort to improve financial transparency and deter money laundering. The CDD rule enhances CDD requirements for "U.S. banks, mutual funds, brokers or dealers in securities, futures commission merchants, and introducing brokers in commodities." The CDD rule requires that financial institutions identify and verify the identity of customers associated with open accounts. The CDD rule has four core requirements:

1. Identify and verify the identity of customers
2. Identify and verify the identity of the beneficial owners of companies opening accounts
3. understand the nature and purpose of customer relationships to develop customer risk profiles
4. conduct ongoing monitoring to identify and report suspicious transactions, and on a risk basis, to maintain and update customer information

Beneficial owner information is required for any individual who owns 25 percent or more of a legal entity and an individual who controls the legal entity.

=== Enhanced due diligence ===
Enhanced due diligence is required when initial identity checks have been completed and high-risk factors have been identified for an individual or a business. These measures may be needed based upon factors such as the jurisdiction the customer is based in, the products they are using, or the nature of the customer. When these requirements have been met "enhanced" or additional due diligence above and beyond CDD is conducted which identifies the following information:

- Source of wealth and funds check
- Additional identity research
- Risk identification and assessment
- Nature of the client
- Details of company background and activities
- Director and shareholder information

== Know your customer's customer ==
Know your customer's customer (KYCC) is a process that identifies a customer's customer activities and nature. This includes the identification of the customer's customers and assessing the risk levels associated with their activities.

KYCC is a derivative of the standard KYC process that arose because of the growing risk of fraud obscured by second-tier business relationships (e.g. a customer's supplier).

KYCC is not just an issue of legal compliance, you need to know the beneficiaries of your client in order to protect your business from various risks, which can include the infiltration of illegal funds into your organization. By extending the steps of know your customer to all of your client's various connections, proper due diligence can be exercised.

== Know your business ==
Know your business (KYB) is an extension of KYC laws implemented to reduce money laundering. KYB is a set of practices to verify a business. It includes verification of registration credentials, location, the UBOs (ultimate beneficial owners) of that business, etc. Also, the business is screened against blacklists and grey lists to check if it was involved in any sort of criminal activity such as money laundering, terrorist financing, corruption, etc. KYB is significant in identifying fake business entities and shell companies. It is crucial for efficient KYC and AML compliance.

According to the European Union's 5th AML directive, KYB is required for the following AML-regulated entities:

- Credit institutions
- Estate agents
- External accountants
- Financial institutions
- Gambling services
- Notaries
- Services auditors
- Tax advisors
- Trusts
- Investment firms
Know your business (KYB) protocols typically include verifying business activities to determine whether they align with a company's risk tolerance. High-risk sectors may include gambling facilities, money services businesses, and adult entertainment industries, among others. KYB service providers such as LexisNexis and Enigma Technologies offer data and ongoing monitoring solutions that enable verification during both initial onboarding and throughout the entire business relationship lifecycle.

== Electronic know your customer ==
Electronic know your customer (eKYC) involves the use of internet or digital means of identity verification. This may involve checking information provided is valid by using systems to validate ID and proof of address documents or by checking information against government databases such as the official passport database of a country.

In response to the digitalization of financial services, especially by neobanks and fintech platforms, the adoption of eKYC procedures has accelerated globally. eKYC systems often combine ID document verification, biometric authentication (e.g., facial recognition and liveness checks), and real-time risk monitoring to authenticate users. Some countries have implemented national guidelines or regulations around eKYC. For example, the Qatar Central Bank introduced a formal eKYC framework in 2023 aligned with its national fintech strategy, allowing digital onboarding of non-resident users with regulatory approval.

eKYC is also being explored in conjunction with digital identity wallets and verifiable credentials as part of broader digital identity initiatives in jurisdictions like the European Union under the eIDAS framework.

==Laws by country==

Different countries implement Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations through their respective financial intelligence units or regulatory authorities, aligning with international standards set by the Financial Action Task Force (FATF)
- Australia: The Australian Transaction Reports and Analysis Centre (AUSTRAC), established in 1989, monitors financial transactions in Australia, and sets client identification requirements under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006
- Canada: The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), established in 2000, is Canada's financial intelligence unit. It updated its regulations in June 2016 regarding acceptable methods to determine the identity of individual clients to ensure compliance with AML and KYC regulations. A pending lawsuit is active in Canada challenging the constitutionality of the new legislation.
- European Union: The EU 4th AML directive came into effect in June 2016. Strengthening due-diligence, this legislation requires the beneficial owner of companies be held in a central register.
- India: The Reserve Bank of India (RBI) first issued Know Your Customer (KYC) guidelines for banks in 2002, establishing standardized procedures for customer identification and verification.
- Italy: The Banca d'Italia exercises regulation power for the financial industry, in 2007 set KYC requirements for financial institutions that operate on Italian territory.
- Japan: Enacted the Act on Identification of Customers by Financial Institutions 2003, requiring financial institutions to verify customer identity and maintain transaction records as part of the countries anti-money laundering framework.
- Mexico: The "Federal Law for Prevention and Identification of Operations with Resources from Illicit Origin", promulgated in 2012 with president Felipe Calderon's administration and came into force in 2013 with the president Enrique Peña Nieto administration.
- Namibia: Financial Intelligence Act, 2012 (Act No. 13 of 2012) published as Government Notice 299 in Gazette 5096 of 14 December 2012. It establishes customer identification, record keeping, and reporting obligations for financial institutions as part of the country's anti-money laundering and counter-terrorism financing regime.
- New Zealand: Updated KYC laws were enacted in late 2009 and entered into force in 2010. KYC is mandatory for all registered banks and financial institutions (the latter has an extremely wide meaning).
- South Korea: Act on Reporting and Use of Certain Financial Transaction Information establishes customer due-diligence, record keeping, and reporting requirements for financial institutions as part of South Korea's anti-money laundering framework.
- United Arab Emirates:The key guidelines overseeing KYC in the UAE are the Government Pronouncement Regulation No. (20) of 2018 On Anti Money Laundering and Battling the Supporting of Psychological warfare and Funding of Unlawful Bureau Choice No. (10) of 2019 Concerning the Carrying out Guideline of Pronouncement Regulation No.
- United Kingdom: The Money Laundering Regulations 2017 are the underlying rules that govern KYC in the UK. Many UK businesses use the guidance provided by the European Joint Money Laundering Steering Group along with the Financial Conduct Authority's 'Financial Crime: A guide for firms' as an aid to compliance.

==See also==

- Anti-money laundering
- Anti-money laundering software
- Bribery
- Certified copy
- De-banking
- Financial Action Task Force on Money Laundering
- International Business Registration Number
- Political corruption
- Politically exposed person
