What a bank actually has to do to be KYC-compliant, step by step, and which laws impose it in the US, EU, and UK.
A bank's KYC requirements are the legal duties to identify its customers, understand each relationship, and monitor it for the life of the account. They rest on four repeating pillars: customer identification, beneficial ownership, risk profiling, and ongoing monitoring, with enhanced checks for higher-risk cases. The specific rules vary by jurisdiction but trace back to FATF Recommendation 10.
KYC, short for know your customer, is the set of legal and regulatory obligations a bank must meet to identify who its customers are, understand the purpose and risk of each relationship, and monitor it for as long as the account is open. In the United States regulators wrap these duties under the term Customer Due Diligence (CDD); in the EU and UK they sit under the money laundering regulations; globally the standard-setter is the Financial Action Task Force (FATF), whose Recommendation 10 is the source text most national rules trace back to.
KYC is not the same as anti-money laundering (AML). KYC is one component of a bank's wider AML programme, which also covers transaction monitoring, sanctions screening, suspicious activity reporting, and governance. Put simply, KYC is where a bank meets its AML duty at the level of the individual customer relationship.
FinCEN's 2016 CDD Final Rule, effective for compliance from 11 May 2018, codified four minimum elements that a US bank's programme must contain. The same four ideas recur across the UK and EU regimes because they all trace back to FATF Recommendation 10.
Introduced by the USA PATRIOT Act and in force since 2003, the Customer Identification Program rule requires a bank to collect at minimum four data points before opening an account: name, date of birth, address, and an identification number (for a US person, usually a Social Security or taxpayer number). The bank must then verify identity to a reasonable belief using documentary methods (a passport or driving licence), non-documentary methods (database and electronic checks), or both, and screen the customer against sanctions lists such as OFAC.
For legal entity customers such as companies, LLCs, and partnerships, the bank must identify the natural persons behind the entity. The CDD Rule set two prongs: any individual who owns 25 per cent or more of the entity (the ownership prong) and one individual with significant control such as a CEO or managing member (the control prong). This is the pillar most changed by recent US policy.
The bank must understand why the account exists and what normal activity should look like, then assign a risk rating from low to high. That profile becomes the baseline against which future behaviour is judged.
The bank must monitor transactions for suspicious activity, file Suspicious Activity Reports (SARs) where warranted, and keep customer information current on a risk-based schedule. To show the scale of this pillar in practice, US institutions filed 4.7 million SARs and 20.5 million Currency Transaction Reports in the 2024 financial year.
KYC is risk-based, not one-size-fits-all. Under FATF Recommendation 10, a bank dials the intensity of its checks up or down with the risk of the customer and the relationship. There are three broad intensity levels.
Enhanced due diligence is not optional for the cases that trigger it. A bank must apply EDD to politically exposed persons, customers in high-risk jurisdictions, and unusually complex structures. See what is due diligence for how these tiers fit together.
For business customers, banks perform Know Your Business (KYB) alongside KYC. KYB verifies the company's registration, legal status, and structure, then drills into the ultimate beneficial owners (UBOs) and runs KYC on each of them. This is where onboarding gets slow, because ownership chains cross registries and jurisdictions, and each layer of a corporate structure can hide another entity.
The practical rule is that KYB establishes the entity and its control chain, while KYC establishes the identity and risk of the humans at the end of that chain. A bank cannot claim it knows its business customer until it has resolved the ownership graph and screened the people behind it.
The four pillars are globally consistent, but the specific statutes, thresholds, and supervisors differ. Here is how the three major regimes line up as of 2026.
The rulebook that governs bank KYC changed materially across 2025 and into 2026 in all three major regimes.
On 13 February 2026 FinCEN issued an order granting banks, mutual funds, brokers, and dealers relief from the CDD Rule requirement to re-identify and re-verify beneficial owners of a legal entity customer at every new account opening. Under the order, covered institutions may now limit beneficial ownership identification and verification to three circumstances: when the entity first opens an account, when the institution has knowledge of facts that call the previously obtained information into question, and as needed under its risk-based ongoing CDD procedures. FinCEN framed this as a risk-based efficiency measure that does not weaken the BSA framework. An earlier 2025 order also gave banks an optional method to satisfy identity verification using reliable third-party sources rather than always collecting the taxpayer number directly from the customer.
The EU replaced its patchwork of directives with a single, directly applicable AML Regulation (Regulation (EU) 2024/1624, the AMLR), which entered into force on 9 July 2024 and applies from 10 July 2027. This is a structural shift from minimum-harmonisation directives that each member state transposed differently, to one rulebook applied identically across the bloc. Alongside it, the new EU Anti-Money Laundering Authority (AMLA) in Frankfurt became operational on 1 July 2025 and will begin direct supervision of selected high-risk cross-border institutions from 2028. Concrete AMLR changes include a harmonised 25 per cent beneficial ownership threshold with standardised register data, a bloc-wide 10,000 euro limit on cash payments for goods and services, a ban on anonymous crypto accounts, and full CDD by crypto-asset service providers on any occasional transaction of 1,000 euro or more.
The UK operates under the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, supervised for banks by the FCA, with Joint Money Laundering Steering Group (JMLSG) guidance treated as the practical standard firms take account of. Among the 2025 updates, the Proceeds of Crime threshold was raised from 1,000 to 3,000 pounds with effect from 31 July 2025. UK enforcement stayed active: Starling Bank was fined about 29 million pounds for sanctions-screening and high-risk-account failings, and Monzo was fined about 21 million pounds in July 2025 for serious AML control failings that ran from October 2018 to June 2022 (the 21 million pound figure reflects a settlement discount on a higher headline penalty).
KYC is expensive and error-prone, which is why so much of the market is built around fixing it. Industry estimates put per-customer KYC review at between 1,500 and 3,500 US dollars, with some large institutional banks spending up to 35 million US dollars a year to onboard 10,000 clients. Large institutions face AML alert false-positive rates as high as 95 per cent, a figure widely attributed to Accenture, McKinsey, and ACAMS.
The commercial cost is just as real. Fenergo's 2024 research found that 67 per cent of surveyed institutions in the UK, US, and Singapore had lost clients to slow onboarding. Meanwhile the RegTech market that sells the fix keeps growing: industry estimates put cloud spend on AML and KYC data and services at about 2.9 billion US dollars in 2025, with the KYC and AML software market projected to exceed 3.2 billion US dollars by 2028 at roughly 19.4 per cent CAGR. Treat these market-size figures as vendor and analyst estimates rather than settled fact.
A bank KYC programme runs from onboarding through to continuous monitoring. The steps below map the four pillars into an operational sequence.
AI is used defensively across every KYC pillar, and this is where a genuine efficiency story lives. Machine-learning models classify and authenticate identity documents and pair them with biometric liveness. AI pre-classifies sanctions, PEP, and adverse-media alerts to cut the false-positive load. It cross-references company registries to assemble ownership graphs, and it watches continuously for the unusual activity that ongoing monitoring is meant to catch.
Independent reporting describes agentic onboarding cutting KYC and AML review times by up to 60 per cent, with 80 to 90 per cent faster onboarding for standard-tier customers. A more grounded first-year return is roughly a 20 to 35 per cent reduction in analyst time on back-office case work, so treat the headline figures as best-case vendor claims rather than guaranteed outcomes.
Zenoo runs 10 specialised AI agents that sit across the workflow rather than replacing a bank's verification vendors. A KYB Researcher compiles a structured company dossier of 50 or more fields in under 60 seconds versus 2 to 4 hours manually. A KYC Researcher completes individual due diligence in under 45 seconds versus 1 to 3 hours. An alert pre-classification agent dispositions screening alerts in 2 to 3 minutes versus 20 to 45 minutes, pre-classifying up to 80 per cent with high confidence. At the programme level, Zenoo cites investigation time falling from an industry benchmark of 22 hours to 12 minutes, and up to a 95 per cent reduction in false positives within 90 days. These are Zenoo's own measured or benchmarked figures.
The same generative AI is being weaponised against the identity-verification step, and the evidence is concrete. In January 2024 an Arup finance worker in Hong Kong was tricked on a video call in which the CFO and colleagues were all deepfakes, and executed 15 transfers totalling 25.6 million US dollars in a single day. In the Netherlands, police reported in December 2025 a suspect who used stolen documents and deepfake facial manipulation to open 46 bank accounts in other people's names. Bank of Italy governor Fabio Panetta cited data in July 2025 that roughly 250 of 500,000 new online accounts were fake accounts opened using deepfakes or false identities.
The tooling is cheap and packaged. ProKYC, identified by Cato Networks in October 2024, bundled a virtual camera, emulator, facial animation, and verification-photo generation into one anti-KYC platform sold at about 629 US dollars a year. Later reporting put a verification-passing AI face at under 20 US dollars. Injection attacks that alter the video feed at the API level, so standard liveness never sees the real camera, are rising fast: iProov reported a 1,151 per cent year-on-year rise in iOS injection attacks in the second half of 2025. Synthetic identity fraud, which blends real and fabricated data specifically to pass KYC, is called the fastest-growing financial crime in the US by the Federal Reserve, with estimated annual losses of roughly 20 to 40 billion US dollars.
KYC's identity-verification pillar is now an adversarial contest. Presentation attacks fool a camera with a deepfake; injection attacks bypass the camera entirely. FATF's December 2025 Horizon Scan explicitly names deepfakes as capable of bypassing AML controls, CDD systems, and digital-ID verification. When one liveness detector is the only line of defence, an attacker only has to beat one model. See deepfake detection in KYC and synthetic identity fraud.
Zenoo is a KYC, KYB, and AML compliance orchestration platform. It does not replace a bank's verification vendors; it connects many of them behind one workflow, one policy engine, and one audit trail. The honest framing is your vendors plus Zenoo.
Because bank KYC now depends on multiple providers (an industry figure of about 4.7 verification providers per institution), Zenoo routes each check to the right vendor and fails over when one is down or returns low confidence, running checks in parallel. That directly strengthens the identity-verification pillar against the single-point-of-failure risk above. Zenoo's Policy Parser turns a written policy into 15 to 20 structured risk rules in under 5 minutes, and its 209-country risk database (16 indicators per country, including FATF grey and black-list status) supports the risk-profiling pillar and EDD triggers. For recordkeeping, 32 immutable audit event types across 8 categories give examiners one evidence record spanning every vendor.
Be clear about what Zenoo does not do. It does not itself verify a passport, run a facial-liveness scan, or maintain a sanctions list; those come from the bank's chosen vendors. It does not make a bank compliant on its own, because compliance is the bank's regulatory obligation. It is not a deepfake detector, though it can route to and fail over between best-in-class liveness and injection-attack detectors and combine their signals. And it does not remove the need for human analysts or a designated compliance function; it reduces manual load and speeds disposition.
Zenoo orchestrates the checks; it is not the verification vendor, not the sanctions list, and not the liveness model. It helps a bank execute and evidence its KYC programme, but the regulatory obligation and the underlying detection models stay with the bank and its chosen providers.
Zenoo connects your KYC, KYB, and AML vendors behind one workflow, one policy engine, and one audit trail. Your vendors plus Zenoo: routing, failover, and continuous monitoring, with 10 specialised AI agents pre-investigating the work your analysts do by hand.