HOW BANKING WORKS · IDENTITY, AML AND FINANCIAL-CRIME CONTROLS 61
Before a bank can protect money, move money or lend money, it has to know whose claim it is dealing with.
Know Your Customer is the banking discipline of turning a name, account application or corporate form into an accountable relationship the institution can identify, verify, understand and monitor over time.
A bank account is not only a number. It is a legal and operational relationship between an institution and a customer. Payments leave that relationship. Loans enter it. Deposits are owed through it. Complaints, tax information, sanctions obligations, fraud controls and financial-crime monitoring all depend on the bank being able to answer a first question reliably: who is this?
This article begins Batch 16 under How Banking Works: identity, AML and financial-crime controls.
The quick answer
KYC is not photocopying an identity document. It is the wider process of identifying the customer, verifying identity using reliable evidence, understanding who has authority to act, understanding the purpose and expected nature of the relationship, assessing relevant risk, and keeping that understanding current as circumstances change.
For companies and other legal persons, KYC also reaches beyond the named customer to the people who ultimately own or control it where the applicable rules require. For higher-risk relationships, the bank may need deeper evidence about ownership, source of funds, source of wealth, public functions or other risk factors. The exact measures depend on jurisdiction, customer type and risk.
Why identity comes before banking
A deposit is a claim. A loan is a claim. A payment is an instruction that changes claims. None of these works safely if the bank cannot identify the party whose rights and obligations are being created or changed.
When an account is opened, the institution is not simply creating a login. It is accepting a person or organisation into a regulated financial network. The customer may receive the ability to hold money, send money, receive money, borrow, convert currencies or connect to other financial services.
Identity therefore sits at the front of the banking sequence:
identify → verify → understand authority and purpose → assess risk → establish relationship → monitor → refresh when reality changes.
The Basel Committee’s current Sound Management of Risks Related to Money Laundering and Financing of Terrorism guidance requires systematic customer identification and verification and ongoing monitoring consistent with the risk profile. FATF’s Recommendations provide the global AML/CFT/CPF baseline.
Identification and verification are different jobs
Identification means establishing what identity is being claimed: name, date of birth, incorporation details, address or other required attributes depending on the customer.
Verification means obtaining reliable evidence that supports that claim.
| Step | Core question |
|---|---|
| Identification | Who does the customer say they are? |
| Verification | What reliable evidence supports that identity? |
| Authority | Who is permitted to act for this customer? |
| Ownership and control | Which natural persons ultimately own or control the customer where relevant? |
| Purpose | Why does this banking relationship exist and what activity is reasonably expected? |
A document by itself does not answer every one of these questions. The process is relational rather than documentary.
For an individual, identity usually starts with the person
A retail customer can be asked for information such as legal name, date of birth, residential address, nationality or other attributes required by the applicable framework. The bank then verifies those details using suitable documentary or electronic evidence.
The exact evidence can vary. A bank may use government-issued identity documents, trusted digital identity systems, authoritative databases or combinations of methods. The control goal is not loyalty to one document format. It is confidence that the bank has established the correct person with evidence appropriate to the risk.
For a company, the named customer is not the whole identity
A company is a legal person. It can own property, borrow, hold bank accounts and enter contracts. But a company acts through human beings and can itself be owned or controlled through other entities.
The bank therefore needs to understand the entity’s legal existence, authorised representatives, ownership and control structure, and the natural persons who ultimately own or control it under the applicable beneficial-ownership rules.
Article 62 owns that deeper layer: Beneficial Ownership | Why Banks Need to Know Who Ultimately Controls the Money.
The person acting for the customer must also be understood
A director, employee, trustee, attorney, accountant or other representative may operate an account for someone else. The bank then needs to distinguish:
- the customer who owns the relationship;
- the person acting on the customer’s behalf;
- the legal authority permitting that action;
- the beneficial owner where applicable.
These roles can be held by different people. Collapsing them into “the account holder” can hide who actually controls the relationship.
KYC asks what the relationship is for
Two customers with identical names and documents can use banking very differently. One receives a salary and pays household bills. Another operates an international trading company with suppliers and customers across several jurisdictions.
The bank therefore seeks to understand the purpose and intended nature of the relationship: why the account is being opened, the kinds of services expected, and the broad pattern of activity that would make sense for that customer.
This initial understanding becomes part of the baseline used later for monitoring.
KYC is not a prediction that the customer will behave perfectly
A customer profile is an evidence-based representation, not a permanent forecast. People change jobs. Businesses expand. Families move. Companies acquire subsidiaries. Payment patterns evolve.
The bank should therefore treat expected activity as a starting model that can be updated when real behaviour provides new evidence.
This is why KYC and transaction monitoring belong to one continuous system rather than two isolated departments.
Source of funds and source of wealth answer different questions
These concepts are often used too casually.
| Concept | Question |
|---|---|
| Source of funds | Where did the specific money used in this relationship or transaction come from? |
| Source of wealth | How did the person accumulate their broader wealth or assets over time? |
Not every ordinary customer is asked for the same depth of evidence. Requirements depend on applicable law, risk profile and the nature of the relationship. Higher-risk circumstances can justify deeper inquiry.
A bank should not turn risk-based due diligence into universal suspicion
The purpose of KYC is not to treat every customer as a criminal. It is to create enough reliable information for the institution to use proportionate controls.
Low-risk relationships should not automatically receive the same depth of scrutiny as genuinely higher-risk situations unless the applicable rules require it. Risk-based control allows the institution to concentrate attention where the consequences of opacity are greater.
Politically exposed persons are about influence risk, not guilt
People entrusted with prominent public functions can present elevated corruption or abuse-of-position risk because of the authority they hold or held. Applicable frameworks can therefore require enhanced due diligence, senior approval, source-of-wealth or source-of-funds measures, and closer monitoring depending on the exact category and jurisdiction.
A PEP designation is not an accusation. It is a risk factor that changes the depth of control.
KYC and sanctions screening are neighbours, not synonyms
KYC establishes and understands the customer. Sanctions screening asks whether the customer, connected parties or transaction may be subject to applicable legal restrictions.
The same identity data supports both functions, but the questions differ:
KYC: who are you? Sanctions: does an applicable restriction affect you or this transaction?
Article 64 owns sanctions screening.
KYC and credit underwriting are also different
Identity does not prove repayment capacity. A customer can be perfectly identified and still be unable to service a loan.
Credit underwriting asks whether future cash flow can support the debt. KYC asks whether the bank understands the party and relationship it is dealing with.
Read How Banks Decide Whether a Borrower Can Repay.
KYC and account authentication solve different identity moments
KYC establishes the customer relationship. Account authentication asks whether the actor interacting today is authorised to act for that customer.
A bank can perform excellent onboarding and still suffer account takeover later.
Read Account Takeover | How Identity Failure Becomes Banking Loss.
Stolen identity creates a false relationship
An applicant can present genuine personal information belonging to someone else. If the bank verifies the data but fails to verify control of the identity, it can create an account under the victim’s name for another person’s use.
This is why digital KYC increasingly combines documentary evidence with liveness, device, database and other signals where lawful and appropriate.
Synthetic identity complicates the idea of “real document, real person”
A fabricated identity can combine real and invented attributes. The bank may find individual pieces of evidence that look plausible while the overall person does not exist as represented.
Good KYC therefore tests coherence across data sources rather than assuming one correct field proves the entire identity.
Digital KYC changes evidence collection, not the enduring question
A branch can inspect a physical document. A digital bank can use trusted digital identity, electronic document checks, biometric comparison, database verification and remote interaction.
Technology can improve reach and speed. It can also create new attack surfaces and new dependencies on vendors or data sources.
Read A Digital Bank Still Has a Balance Sheet.
Non-face-to-face relationships require compensating evidence
The lack of physical presence does not make digital banking inherently illegitimate. It changes how the institution gets confidence in identity, authority and document integrity.
Risk can be managed through stronger electronic verification, trusted data, additional authentication, transaction limits, delayed capabilities or enhanced review where justified.
KYC becomes stale
A company changes ownership. A customer moves country. A director changes. An ordinary private individual enters a prominent public role. A business changes from local consulting to cross-border commodities trading.
The information collected at onboarding may no longer represent the customer accurately.
Ongoing due diligence therefore includes periodic or event-driven refresh depending on risk and applicable rules.
Event-driven review can matter more than a calendar date
A bank may schedule periodic refreshes. But a material ownership change or unusual activity should not wait two years simply because the next review date has not arrived.
Good KYC responds to evidence. The calendar is one trigger, not the only trigger.
The customer profile should learn from transaction monitoring
If actual activity repeatedly differs from what the bank expected, one possibility is suspicious activity. Another is that the customer’s legitimate business has changed and the KYC profile is outdated.
The monitoring system therefore should not only create alerts. It should feed evidence back into customer understanding.
Article 63 owns that loop: Transaction Monitoring | How Banks Look for Activity That Does Not Fit.
What happens when the bank cannot complete due diligence?
Under FATF-aligned frameworks, a bank may be unable to establish or continue a relationship if required customer due diligence cannot be completed satisfactorily. Depending on the jurisdiction and facts, it may refuse onboarding, restrict services, exit the relationship or consider whether reporting obligations arise.
The exact legal steps vary. The durable principle is that a bank should not knowingly maintain a relationship whose required identity and control information it cannot establish.
False positives can exclude legitimate people
Identity systems can fail legitimate customers because names are transliterated differently, documents are unusual, addresses do not fit expected formats or databases are incomplete.
A high-quality control environment therefore needs escalation and human review rather than assuming every mismatch is wrongdoing.
Financial inclusion and crime control can conflict if the bank responds to uncertainty only by refusing service. Better evidence can sometimes solve the problem more fairly than broader exclusion.
Privacy is part of good KYC design
KYC requires personal and corporate information. Collecting that information creates a second obligation: protect it, restrict access and retain it according to law and legitimate purpose.
More data is not automatically better. Unnecessary collection increases privacy and cyber exposure without necessarily improving risk understanding.
A bank should know why it holds each sensitive data element
If data does not support a legal obligation, risk decision, customer service or defensible operational need, its collection should be questioned.
Good KYC is precise enough to support accountability without becoming indiscriminate surveillance.
A worked retail example
A customer opens a salary account. The bank verifies identity using reliable evidence, records the purpose of the relationship and expects ordinary salary credits, bill payments, card spending and savings activity.
Two years later the account begins receiving large business-like payments from many unrelated counterparties. This does not prove criminal activity. It does tell the bank that the original customer profile may no longer explain the account.
The appropriate response can include review, refreshed information and monitoring proportionate to the new facts.
A worked corporate example
A private company opens an operating account. The bank verifies the entity’s legal existence, identifies authorised directors and signatories, maps the ownership chain and establishes the relevant beneficial owners under applicable rules.
Six months later the company is sold to a new holding company in another jurisdiction. The bank should not assume the original beneficial-ownership picture remains correct. Ownership, control and the risk assessment need to be refreshed.
KYC is an information architecture for accountability
The bank does not need to know everything about a customer. It needs enough reliable, relevant and current information to understand who owns the relationship, who can operate it, why it exists and whether later activity remains coherent with that understanding.
This makes KYC the front door to every downstream control:
- sanctions screening needs names, identifiers and ownership;
- transaction monitoring needs a customer profile;
- fraud controls need a stable identity state;
- credit underwriting needs verified parties and authority;
- complaint handling needs to know who has rights over the account;
- regulatory reporting needs reliable customer attribution.
When KYC fails, every downstream control starts from bad coordinates
If the bank has the wrong identity, it can monitor the wrong customer, screen the wrong person, assign the wrong risk and send sensitive information to the wrong party.
The initial error therefore propagates. KYC quality is not an administrative detail. It is foundational data quality for the banking relationship.
The World Return: every financial claim needs an accountable owner and actor
Banking allows claims to travel far from the human beings who create them. Companies transact through employees. Trusts act through trustees. Digital accounts move money without face-to-face contact. Cross-border payments pass through several institutions.
KYC reconnects those abstractions to accountable identity. It does not guarantee good behaviour. It makes the relationship legible enough for rights, obligations and risk to have an owner.
financial systems become dangerous when claims can move faster than accountability can follow.
The Wintour House durability test
Identity documents will change. Biometrics will change. Digital identity systems will change. AI-assisted verification will change. Banking interfaces will change.
The enduring KYC questions will remain:
- who is this customer?
- what reliable evidence supports that identity?
- who is authorised to act?
- who ultimately owns or controls the relationship where relevant?
- why does the relationship exist?
- does later activity still fit the customer we understand?
- what evidence would make us update that understanding?
Five misconceptions to remove
| Misconception | Better model |
|---|---|
| “KYC means collecting a passport.” | KYC identifies, verifies, understands authority, purpose, risk and keeps the relationship current. |
| “A verified customer is a safe borrower.” | Identity and repayment capacity are different questions. |
| “KYC is finished when the account opens.” | Material changes in ownership, behaviour or risk can require ongoing review. |
| “More information is always better KYC.” | Information should be relevant, reliable, proportionate and protected. |
| “A higher-risk classification means wrongdoing.” | Risk classification determines control intensity; it is not a declaration of guilt. |
Observable mastery
- Why must banking begin with identity?
- What is the difference between identification and verification?
- Why are customer, authorised representative and beneficial owner not always the same person?
- How is KYC different from credit underwriting, account authentication and sanctions screening?
- Why can an account profile need to change after onboarding?
- Why is proportionality important to both control quality and financial inclusion?
- Which KYC questions still matter if physical documents disappear completely?
If those answers connect, Know Your Customer becomes visible for what it really is: not paperwork at the edge of banking, but the identity architecture that allows a financial claim to remain connected to a real, accountable relationship as money begins to move.
Continue through identity and financial-crime controls
- A Digital Bank Still Has a Balance Sheet
- Account Takeover
- Basel Committee — AML/CFT Risk Management
- FATF Recommendations
- How Banking Works
Source note: FATF Recommendations and Basel AML/CFT guidance linked above were checked on 4 September 2026. Customer-due-diligence obligations vary by jurisdiction, institution, customer type and risk. This article is an educational systems explanation, not legal or compliance advice.