Where identity checks end and your AML programme begins
KYC (know your customer) means confirming who your customer is by verifying their identity against reliable, independent sources. AML (anti-money laundering) is the wider programme a regulated firm runs to stop its business being used to launder money. KYC is one part of AML.
Teams that treat the two as interchangeable tend to over-invest in one and under-build the other. A firm can run a fast, accurate identity check at onboarding and still fall short on its AML obligations, because identity is a single component of a much larger duty. Getting the relationship right tells you what your identity provider is responsible for, and what stays with your compliance function.
KYC is the industry name for identifying a customer and verifying their identity before and during a business relationship. In practice that means confirming attributes such as name, address and date of birth against a reliable source that is independent of the customer. KYC is not a defined term in UK law. It maps onto the customer due diligence measures in the Money Laundering Regulations 2017.
For the person being verified, a modern KYC check can take seconds. They confirm their identity from a phone, with no document to photograph and no form to fill in, then carry on with signing up.
AML is the whole set of controls a regulated firm operates to detect and prevent money laundering and terrorist financing. It starts with a business-wide risk assessment and runs through customer due diligence, screening, ongoing monitoring, record-keeping and the reporting of suspicious activity. Identity verification is one input to that programme. The obligations sit with the firm, which is supervised by the FCA, HMRC or a professional body depending on the sector.
The KYC vs AML distinction comes down to scope. KYC settles one question: whether the customer is who they say they are. AML covers a broader duty: whether the business is protected against being used to move criminal money. KYC produces the identity evidence. AML is the programme that decides what to do with that evidence, alongside risk assessment, screening, monitoring and reporting. KYC sits inside AML as its identity-knowledge component.
|
|
KYC (know your customer) |
AML (anti-money laundering) |
|
Purpose |
Confirm who the customer is |
Stop the business being used to launder money or finance terrorism |
|
Scope |
A single component: customer identification and identity verification |
The whole regulated-firm programme |
|
What it covers |
Identify the customer and verify identity against a reliable source independent of the customer (name, address, date of birth) |
Business-wide risk assessment, CDD (which contains KYC), PEP screening, ongoing monitoring, record-keeping, and suspicious activity reporting |
|
Where it sits |
Inside CDD, which sits inside the AML programme |
The top-level programme every relevant person must run |
|
Governing framework (UK) |
Reg 28 CDD identity/verify measures, MLR 2017 |
MLR 2017 (regs 18, 27-28, 33, 35, 37, 40); SAR duty under POCA 2002 / Terrorism Act 2000 |
|
Example activities |
Electronic identity matching (the 2+2 convention), document verification |
Risk-assessing the business, screening for PEPs, monitoring transactions, keeping records for five years, filing SARs to the NCA |
|
Where KYC Match fits |
The identity-matching step |
Not the full programme; the firm keeps risk assessment, screening, monitoring, record-keeping and SARs |
The industry describes the relationship as a set of nested layers. The AML programme is the outer layer. Customer due diligence is one pillar inside it. KYC is the identity-knowledge part of CDD, covering the identify-and-verify steps. Identity matching, comparing a customer's details against independent data sources, is the specific activity that satisfies the verification step. This is how practitioners describe the structure, grounded in the regulations, rather than a set of statutory boxes.
Reading it outward: an identity match feeds the KYC step, KYC feeds CDD, and CDD is one of several duties inside the AML programme.
A regulated firm's AML programme has several components under the Money Laundering Regulations 2017, each with its own regulation:
Sanctions screening runs alongside these controls. It flows from the UK sanctions regime, overseen by OFSI under the Sanctions and Anti-Money Laundering Act 2018, and applies to everyone in the UK rather than sitting purely as a Money Laundering Regulations duty. PEP screening, by contrast, is a Money Laundering Regulations obligation. The two are distinct regimes and worth keeping separate in your control mapping.
No. A completed KYC check verifies identity, which satisfies the identification and verification part of customer due diligence. It does not carry out the business-wide risk assessment, screen for PEPs or sanctions, monitor transactions over time, keep the required records or file suspicious activity reports. Those obligations remain with the firm, which stays responsible for its full AML programme and ultimately liable for it.
Electronic identity matching is the mechanism that satisfies the verification step in KYC. It confirms a customer's identity by matching their details against independent, reliable data sources rather than a photographed document. In UK practice this follows the "2+2" convention, a guidance benchmark from JMLSG and HMRC rather than a statutory term, where at least two identity attributes are matched against at least two independent sources.
This is the step OneID's KYC Match performs. It returns a configurable count of matches across independent sources, including banks, mobile networks and public-sector data, going beyond credit reference agency data alone. It handles the identity-matching step and nothing beyond it. Your risk assessment, screening, monitoring, record-keeping and reporting stay where they belong, inside your AML programme.
Government guidance on using digital identities with the Money Laundering Regulations treats a certified digital verification service as a reliable, independent source for the identity step, while the firm remains responsible for the rest.
The identity step is measurable, so it is worth testing rather than assuming. You can run 1,000 records through KYC Match at no cost and compare the results against your existing provider, source by source. It shows you how many customers a multi-source match confirms that a single-source check would have failed, before you change anything in your onboarding. Contact OneID to set up a comparison.
Is KYC part of AML? Yes. KYC is the identity-knowledge component of customer due diligence, which is one pillar of a firm's wider AML programme. Verifying who a customer is supports anti-money-laundering controls, but it is one part of them rather than the whole thing.
Is KYC the same as CDD? No. Customer due diligence is broader. It covers identifying the customer, verifying identity, assessing the purpose of the relationship and ongoing monitoring. KYC is the identity-knowledge part of CDD, focused on confirming who the customer is.
Who do you report suspicious activity to in the UK? Suspicious activity reports go to the National Crime Agency, submitted through the UK Financial Intelligence Unit. The legal duty to report arises under the Proceeds of Crime Act 2002 and the Terrorism Act 2000, not under the Money Laundering Regulations or the FCA.
Is KYC a legal requirement in the UK? KYC is not named in UK law, but the underlying obligation is. Regulated firms must identify and verify customers under the customer due diligence measures in the Money Laundering Regulations 2017. KYC is the industry term for meeting that requirement.
What is the difference between KYC and CDD? CDD is the full due diligence duty: identify, verify, assess the relationship and monitor it over time. KYC is the identity-knowledge part of that duty. Every KYC check is part of CDD, but CDD includes steps beyond identity verification.
Does KYC verification cover sanctions and PEP screening? No. A KYC check confirms identity. Screening a customer against sanctions lists or for politically exposed person status is a separate control. Sanctions screening flows from the UK sanctions regime, and PEP screening is a Money Laundering Regulations obligation.
KYC, explained: how to verify who your customers are without losing the good ones
Know exactly who you are onboarding, at the right level of checking
The extra checks that kick in when a customer is higher risk, and what your firm still has to do