KYC
Knowing the customer before giving them a product. Where the obligation comes from, what a KYC process specifically checks, and how it differs from AML and KYB.
In short
KYC stands for know your customer. It is the set of checks an organization runs to establish who a person is before onboarding them, and to keep that digital identity current for as long as the relationship lasts.
It is not a one-time onboarding step. It is an ongoing obligation: the organization has to know who its customer is on day one and keep knowing it the following year.
The obligation comes from anti-money-laundering, not from the product
KYC was not invented by a product team to reduce fraud. It was born as a regulatory requirement of anti-money-laundering and counter-terrorism-financing regimes, and it spread from there.
That explains two things that surprise anyone seeing it for the first time.
The first: KYC requires keeping evidence, not just verifying. A process that checks correctly but leaves no auditable record of how it checked does not comply.
The second: the obligation reaches far more organizations than banks. In several countries in the region the same duty falls on notary offices, real estate agencies, currency exchanges, betting platforms, and companies that extend credit without being financial institutions.
What a KYC process checks
Behind the acronym are concrete checks, and each one answers a different question.
- Identification — collecting the person's data and the document that claims to prove it.
- Document authenticity — that the document presented is genuine and not an alteration or a reproduction.
- Biometric match — that the face of the person being onboarded matches the one on the document.
- Presence — that there is a real person at the moment of capture, and not a photograph, a video, or a generated face. This is the check that got added once faking a face stopped being expensive.
- Watchlist screening — that the person does not appear on watchlists and does not qualify as a politically exposed person.
- Risk profiling — classifying the customer to define how closely they get monitored afterward.
All six produce evidence. That evidence is the process's real deliverable.
Where a KYC is required
The obligation is not uniform across the region, and it is worth knowing which one applies before designing the process.
- [Colombia](/regulacion/colombia) — SARLAFT for entities supervised by the Superintendencia Financiera, and SAGRILAFT for the real sector.
- [Mexico](/regulacion/mexico) — the anti-money-laundering law, which reaches financial institutions and a broad catalog of vulnerable activities outside the financial system.
- [Brazil](/pt/regulacao/brasil) — the AML/CFT duties over regulated institutions.
In all three cases the duty takes the same shape: identify, keep the evidence, and keep it up to date. What changes is who supervises it, above what threshold, and on what timelines.
KYC, AML, and KYB are not the same thing
The three terms show up together and name different things.
- KYC — knowing the person being onboarded. It happens mainly at onboarding and gets updated afterward.
- AML — the full anti-money-laundering program, of which KYC is one part. It also includes transaction monitoring, reporting to the authority, and institutional risk management.
- KYB — knowing the business customer, which adds verifying its legal existence, its ownership structure, and who ultimately controls it.
The common mistake is treating KYC as if it were the entire program. Verifying each person well at onboarding does not cover what happens with their transactions six months later.
Frequently asked questions
It stands for know your customer. It names the set of checks an organization runs to establish who a person is before onboarding them, and to keep that information current for as long as the relationship lasts. It is not a one-time onboarding step: it is an ongoing obligation, so the organization has to know who its customer is on day one and keep knowing it the following year.
Six distinct things. Identification collects the person's data and the document that claims to prove it. Document authenticity confirms it is genuine and not an alteration or a reproduction. Biometric match confirms that the face of the person being onboarded matches the one on the document. Presence confirms that there is a real person at the moment of capture, and not a photograph, a video, or a generated face. Watchlist screening confirms that the person does not appear on watchlists and does not qualify as a politically exposed person. And risk profiling classifies the customer to define how closely they get monitored afterward. All six produce evidence, and that evidence is the process's real deliverable.
KYC is knowing the person being onboarded, mainly at onboarding and with later updates. AML is the full anti-money-laundering program, of which KYC is one part: it also includes transaction monitoring, reporting to the authority, and institutional risk management. KYB is knowing the business customer, which adds verifying its legal existence, its ownership structure, and who ultimately controls it. The common mistake is treating KYC as if it were the entire program: verifying each person well at onboarding does not cover what happens with their transactions six months later.