A new client can look straightforward on paper and still create problems once the checks begin. A small mismatch, an outdated document or a name that triggers further review can quickly turn a simple onboarding file into a compliance issue.
That is why KYC is more than an ID check. The process has to confirm who the client is, show how the decision was made and leave a record that can stand up to later scrutiny.
This article walks through the six steps of the KYC process. After them come remote verification and the cost of weak checks. Then the red flags that should stop a file, and the questions that come up most often.
6 Steps in the KYC Process
There is no single official know your customer process. Each firm writes its own KYC procedure based on the rules it must follow. The KYC steps below run in a practical order, and each one leaves a record in the client's file.
Collect the Client's Identity Details
Every later check depends on the details below. Ask for them in one online form, built from one of our KYC form templates instead of a blank page. The client then types each detail once, and nobody copies it from an email.
- Full legal name, spelled exactly as on the ID
- Date of birth
- Home address
- An ID number, such as a taxpayer identification number, or a passport number and the country that issued it
US banks must collect at least these four details before opening an account (Customer Identification Program rule, 31 CFR 1020.220). From 10 July 2027, the EU's new AML Regulation adds place of birth and nationality (Regulation (EU) 2024/1624). Confirm the list that applies to you with your compliance officer.
Verify the ID Document and the Person
A genuine passport can still belong to someone else. KYC verification checks three things: the ID is real and in date, it belongs to the person applying, and the address is current.
The client uploads a passport or driver's license and takes a selfie. Software or a reviewer compares the selfie with the ID photo and checks the document for edits.
For the address, ask for a recent utility bill or bank statement in the client's name. If either does not match the form, the file waits for the client to explain.
Clustdoc's identity verification runs biometric checks on government-issued IDs and selfies inside the onboarding flow. You can make it a required step. The client then cannot sign contracts or send more files until their ID is verified and approved.
Screen Names Against Sanctions and PEP Lists
Next, check the client's name against sanctions lists. In the US, that includes the Specially Designated Nationals (SDN) list from the Treasury's Office of Foreign Assets Control.
Then check whether the client is a politically exposed person (PEP). PEPs include current and former government ministers, members of parliament and supreme court judges.
This KYC check often runs through a separate screening service, and the result is saved to the client's file.
A match is not proof, though. Many people share a name. Someone on the compliance team compares the date of birth and nationality, then clears or confirms the match.
Confirmed foreign PEPs get the extra checks in step 5. So do their close associates and family members, such as a spouse, children or parents. Domestic PEPs get them in higher-risk cases (FATF Recommendation 12), but EU rules apply them to all PEPs.
Score the Client's Risk
Why does the client want this account or service? Ask that first, then what activity they expect and which countries the money moves between.
This part of customer due diligence is about understanding the client. Banks in the US must do this to build a customer risk profile (31 CFR 1020.210).
Then give the client a risk level and note the reason. A salaried local client opening a savings account may be low risk. A freelancer paid by clients abroad may be medium risk.
A confirmed foreign PEP goes straight to enhanced checks. Other higher-risk signs include a cash-heavy business or payments from unknown third parties (EU AML Regulation, Annex III).
With customer scoring, we weight form answers and document uploads using your own rules. It flags high-risk or incomplete files for manual review, and every scoring decision is logged.
Apply Enhanced Customer Due Diligence to Higher-Risk Clients
The client's risk level comes back high. That calls for a closer look, which usually means more proof and a senior sign-off.
Ask for the source of funds, meaning where the money for this account comes from. For PEPs and other high-risk clients, also ask for the source of wealth: how they built their wealth overall.
Useful proof includes recent bank statements, payslips, a property sale contract or papers showing an inheritance. A senior manager then decides whether to take on the client, and nothing moves without that approval. UK accountancy firms, for example, must apply enhanced checks to high-risk clients and PEPs under the Money Laundering Regulations 2017.
Our approval workflow moves each file through the approvers your policy names, in order. You can add an outside reviewer, such as an auditor, and each decision is logged in the audit trail.
Keep Records and Review Clients Over Time
Regulators may ask how you checked a client. Keep the ID copies, screening results, risk level and approval decision together in the client's file.
Hold these records for at least five years after the relationship ends (FATF Recommendation 11). US banks keep identity details for five years after an account closes (31 CFR 1020.220).
EU and UK rules set the same five years. UK firms must then delete the personal data, apart from a few exceptions, such as a court case.
Set an expiry date on each ID document, so an expired passport leads to a request for a new one. Review higher-risk clients more often after onboarding. Recheck any client whose name, address or activity changes.
Our KYC onboarding software tracks and records every step, and each upload, approval and rejection is time-stamped. Data expiry rules can then delete client data automatically after the retention period you set.
How Remote KYC Works
Many clients never walk into an office, so the ID check happens online. This is often called eKYC, and it is the same KYC verification process run remotely. The rules do not change, only the way the proof reaches you.
US banks and credit unions may accept a state-issued mobile driver's license as identification, if their own program allows it. FinCEN said so on 8 September 2026, with the Federal Reserve, the FDIC, the NCUA and the OCC. The credential has to be unexpired, show nationality or residence and carry a photograph.
The Customer Identification Program rule neither requires nor prohibits digital credentials, FinCEN added. If one shows signs of fraud, the bank still has to weigh that before it accepts the client. A credential from a private provider counts only if that provider checks identity as strictly as the bank would.
In the EU, you can verify a client with electronic identification means instead of a paper document. National authorities decide which remote processes they accept (Directive (EU) 2015/849, Article 13). From 10 July 2027, those means must reach the eIDAS assurance level substantial or high (Regulation (EU) 2024/1624, Article 22).
What Weak KYC Checks Cost
Regulators publish what went wrong in each case, and the misses are usually plain.
In July 2025, the Financial Conduct Authority fined Barclays a total of 42 million pounds over financial crime failings. Before opening a client money account, the bank had not checked that it held enough information to understand the money laundering risk.
The same regulator fined Nationwide Building Society just over 44 million pounds in December 2025. Its systems for keeping due diligence and risk assessments up to date were ineffective, and so was its monitoring of customer transactions.
The law also sets maximum fines. In the US, each willful breach of Bank Secrecy Act rules can cost up to 286,184 dollars (31 CFR 1010.821).
When the compliance procedures themselves fail, every day and every branch can count as a separate breach (31 U.S.C. 5321).
EU countries must set a maximum fine of at least 5 million euros, or 10 percent of annual turnover. That applies to serious customer due diligence breaches by banks and other financial firms (Directive (EU) 2015/849, Article 59).
KYC Red Flags That Should Pause Onboarding
Stop the file and bring in a reviewer if you see any of these:
- The name on the ID does not match the application
- The ID has expired, or the photo or text looks edited
- The proof of address is in someone else's name
- The client will not explain where their money comes from
- Payments come from people with no clear link to the client
- Nobody can explain who owns or controls a company client
- A possible sanctions or PEP match has not been cleared
A red flag is not proof of fraud. It means the file waits until a reviewer checks it and records the decision.
If the checks cannot be completed, the FATF standard is not to open the account (Recommendation 10). The team should also consider filing a suspicious transaction report.
Add these red flags to a shared client onboarding KYC checklist, so every reviewer looks for the same problems.
Bring your KYC policy to a demo call, and we will show you how Clustdoc runs each step.
Frequently Asked Questions
What is KYC in simple terms?
KYC means know your customer. Under KYC, a business checks that each client is who they say they are. It also checks that taking them on does not bring a money laundering or fraud risk.
The checks happen before the relationship starts and again later. Businesses under anti-money laundering rules must run them, and that list goes beyond banks.
In the UK it includes accountants, tax advisers and estate agents. In the EU, crypto-asset service providers have been covered since 30 December 2024 (Regulation (EU) 2023/1113).
Is KYC mandatory in the USA?
For banks and some other financial firms, yes. Under Bank Secrecy Act rules, banks and broker-dealers must run a Customer Identification Program. So must mutual funds, futures commission merchants and introducing brokers.
These firms must also follow FinCEN's customer due diligence rule. Money services businesses, such as check cashers and money transmitters, must build identity checks into their anti-money laundering programs. Whether your business is covered depends on what it does, so confirm it with your compliance officer or lawyer.
How long does KYC verification take?
Neither the FATF standards nor the US identity rules set a fixed number of days. A file with a clear passport photo, a recent utility bill and no screening matches needs no follow-up requests.
It slows down when a photo is blurry, the address proof is too old or a name match needs review. Enhanced checks add time, because the client has to find bank statements or payslips. How fast the client answers each request matters too.
What is the difference between KYC and customer due diligence?
People often use the two terms for the same work. KYC is the everyday name for the whole process. Customer due diligence is the legal term for its main checks: identifying the client, understanding why they want the relationship and monitoring it over time (FATF Recommendation 10).
Enhanced due diligence is the stricter version for higher-risk clients, such as foreign PEPs. EU rules also allow simplified due diligence when the risk is lower.
Does KYC apply to business clients?
Yes, but for companies the checks are usually called KYB, short for know your business. The team confirms the company exists in official records. Then it runs the same ID checks from step 2 on the people who run, own or control it.


