The KYC process explained: steps, documents and common mistakes
Know Your Customer, or KYC, is how regulated businesses confirm that clients are who they say they are and understand the risk they bring. Done well, it protects the business without making good customers wait. Done badly, it is slow, inconsistent and still misses the risks that matter.

Key takeaways
- KYC has three core parts: identify the customer, understand the risk, and keep the file up to date.
- Due diligence is risk-based: simplified, standard or enhanced, depending on who the customer is and what they do.
- For companies, the key question is who ultimately owns or controls them: the beneficial owners.
- Most delays come from incomplete document requests and manual screening, not from the checks themselves.
What KYC is, and who needs it
KYC is part of a wider anti-money laundering (AML) and counter-terrorist financing framework. Banks, payment companies, insurers, investment firms, crypto platforms and, in many countries, lawyers, accountants and real estate agents are legally required to do it. Many other businesses choose to, because knowing who you deal with reduces fraud and protects reputation.
The exact rules depend on the country and the sector, but most are built on the same international standards, such as the recommendations of the Financial Action Task Force (FATF). The principles below apply almost everywhere; the details, such as which documents are accepted, come from your local regulator.
The core steps
1. Customer identification. Collect and record who the customer is: for individuals, full name, date of birth, address and an official identification number; for companies, legal name, registration number, registered address and the people who run it.
2. Verification. Confirm the details against reliable, independent sources: official identity documents, company registries, utility bills or bank statements for address, and electronic verification services where they are permitted.
3. Customer due diligence (CDD). Understand the purpose of the relationship and the expected activity, and assess the risk. A local salaried individual opening a savings account and an offshore holding company moving large sums are very different risks.
4. Screening. Check the customer and related parties against sanctions lists, lists of politically exposed persons (PEPs) and adverse media.
5. Ongoing monitoring. KYC is not a one-time task. Monitor activity for anything unusual, and refresh the file periodically, more often for higher-risk customers.
Documents typically requested
For individuals:
- A valid government-issued photo ID, such as a passport, national ID card or driving licence.
- Proof of address, usually dated within the last three months.
- For higher-risk relationships, evidence of source of funds or source of wealth.
For companies:
- Certificate of incorporation or a current registry extract.
- Articles of association or equivalent constitutional documents.
- A register of directors and shareholders, and an ownership structure chart.
- Identification for directors, authorised signatories and beneficial owners.
Ask for everything in one clear, complete request. Sending documents back and forth one at a time is the single biggest cause of slow onboarding.
Most delays come from incomplete document requests and manual screening, not from the checks themselves.
Simplified, standard and enhanced due diligence
Due diligence should match the risk. Most frameworks describe three levels:
- Simplified due diligence for clearly low-risk customers, such as listed companies or government bodies, where fewer checks are justified.
- Standard due diligence for the majority of customers.
- Enhanced due diligence (EDD) for higher-risk cases: PEPs, customers from high-risk jurisdictions, complex ownership structures, cash-intensive businesses or unusual transaction patterns. EDD means more evidence, senior approval and closer monitoring.
A written risk-scoring model, applied the same way to every customer, keeps these decisions consistent and easy to explain to an auditor.
Beneficial ownership: the question behind the company
When the customer is a company, the real question is who ultimately owns or controls it. These people are the ultimate beneficial owners, or UBOs. Many jurisdictions use an ownership threshold, often 25 percent, but control can also come through voting rights, agreements or senior management roles.
Identifying UBOs can mean tracing ownership through several layers of holding companies, sometimes across countries and languages. This is where document review and access to registry, court and gazette records matter, and where manual work tends to pile up.
Common mistakes that slow KYC down
- Incomplete first requests. Customers asked for documents in several rounds lose patience, and some leave.
- Inconsistent decisions. Without a written risk model, two analysts can reach different outcomes on the same file.
- Name matching problems. Transliteration between scripts, for example Arabic and Latin, produces many spellings of the same name, causing both missed matches and false alerts.
- Treating KYC as one-off. Files that are never refreshed become outdated, and periodic reviews pile up into a backlog.
- Poor record keeping. If you cannot show what was checked, when and by whom, the check might as well not have happened.
Scaling KYC without adding risk
As volumes grow, the answer is rarely just more analysts. Start with a clear process: written procedures, a risk model and checklists per customer type. Then use technology for the repetitive parts: electronic identity verification, automated screening and document extraction. Keep people focused on judgement: reviewing alerts, investigating complex ownership and making risk decisions.
For backlogs, periodic reviews and peaks, many firms use specialist support teams working to their procedures. Responsibility for the decisions stays with the regulated firm, but the preparation, research and document work can scale up and down with demand.
Frequently asked questions
AML, anti-money laundering, is the overall framework of laws and controls that prevent financial crime. KYC is one part of it: the process of identifying customers and understanding their risk. AML also covers transaction monitoring, reporting suspicious activity and staff training.
It depends on risk and on local rules. A common approach is to review high-risk customers every year, medium-risk every two to three years and low-risk every three to five years, plus an immediate review whenever something significant changes.
Parts of it can. Many regulators allow firms to use third parties for tasks such as document collection, verification, screening and research, provided the firm stays responsible for the final decisions and oversees the work. Check your local regulator's outsourcing rules before you start.


