OneID® | News and Events

KYC vs AML: What's the Difference?

Written by The OneID Team® | 23/07/26 07:00

Where identity checks end and your AML programme begins

KYC (know your customer) means confirming who your customer is by verifying their identity against reliable, independent sources. AML (anti-money laundering) is the wider programme a regulated firm runs to stop its business being used to launder money. KYC is one part of AML.

Teams that treat the two as interchangeable tend to over-invest in one and under-build the other. A firm can run a fast, accurate identity check at onboarding and still fall short on its AML obligations, because identity is a single component of a much larger duty. Getting the relationship right tells you what your identity provider is responsible for, and what stays with your compliance function.

What is KYC?

KYC is the industry name for identifying a customer and verifying their identity before and during a business relationship. In practice that means confirming attributes such as name, address and date of birth against a reliable source that is independent of the customer. KYC is not a defined term in UK law. It maps onto the customer due diligence measures in the Money Laundering Regulations 2017.

For the person being verified, a modern KYC check can take seconds. They confirm their identity from a phone, with no document to photograph and no form to fill in, then carry on with signing up.

What is AML?

AML is the whole set of controls a regulated firm operates to detect and prevent money laundering and terrorist financing. It starts with a business-wide risk assessment and runs through customer due diligence, screening, ongoing monitoring, record-keeping and the reporting of suspicious activity. Identity verification is one input to that programme. The obligations sit with the firm, which is supervised by the FCA, HMRC or a professional body depending on the sector.

What is the difference between KYC and AML?

The KYC vs AML distinction comes down to scope. KYC settles one question: whether the customer is who they say they are. AML covers a broader duty: whether the business is protected against being used to move criminal money. KYC produces the identity evidence. AML is the programme that decides what to do with that evidence, alongside risk assessment, screening, monitoring and reporting. KYC sits inside AML as its identity-knowledge component.

 

KYC (know your customer)

AML (anti-money laundering)

Purpose

Confirm who the customer is

Stop the business being used to launder money or finance terrorism

Scope

A single component: customer identification and identity verification

The whole regulated-firm programme

What it covers

Identify the customer and verify identity against a reliable source independent of the customer (name, address, date of birth)

Business-wide risk assessment, CDD (which contains KYC), PEP screening, ongoing monitoring, record-keeping, and suspicious activity reporting

Where it sits

Inside CDD, which sits inside the AML programme

The top-level programme every relevant person must run

Governing framework (UK)

Reg 28 CDD identity/verify measures, MLR 2017

MLR 2017 (regs 18, 27-28, 33, 35, 37, 40); SAR duty under POCA 2002 / Terrorism Act 2000

Example activities

Electronic identity matching (the 2+2 convention), document verification

Risk-assessing the business, screening for PEPs, monitoring transactions, keeping records for five years, filing SARs to the NCA

Where KYC Match fits

The identity-matching step

Not the full programme; the firm keeps risk assessment, screening, monitoring, record-keeping and SARs

 

How do KYC, CDD and AML fit together?

The industry describes the relationship as a set of nested layers. The AML programme is the outer layer. Customer due diligence is one pillar inside it. KYC is the identity-knowledge part of CDD, covering the identify-and-verify steps. Identity matching, comparing a customer's details against independent data sources, is the specific activity that satisfies the verification step. This is how practitioners describe the structure, grounded in the regulations, rather than a set of statutory boxes.

Reading it outward: an identity match feeds the KYC step, KYC feeds CDD, and CDD is one of several duties inside the AML programme.

What does an AML programme include?

A regulated firm's AML programme has several components under the Money Laundering Regulations 2017, each with its own regulation:

  • Business-wide risk assessment: identifying and assessing the money laundering and terrorist financing risks the business faces (Reg 18).
  • Customer due diligence: identifying the customer, verifying identity against a reliable, independent source, and assessing the purpose of the relationship (Regs 27-28). KYC is the identity part of this.
  • Ongoing monitoring: scrutinising activity through the relationship and keeping CDD information up to date (Reg 28(11)).
  • Enhanced due diligence and PEP measures: extra scrutiny in higher-risk situations, including politically exposed persons (Regs 33 and 35).
  • Simplified due diligence: lighter measures where the firm assesses the risk as low (Reg 37).
  • Record-keeping: retaining CDD and transaction records, generally for five years (Reg 40).
  • Suspicious activity reporting: submitting a SAR to the National Crime Agency through the UK Financial Intelligence Unit. This duty arises under the Proceeds of Crime Act 2002 and the Terrorism Act 2000, not under the Money Laundering Regulations themselves.

Sanctions screening runs alongside these controls. It flows from the UK sanctions regime, overseen by OFSI under the Sanctions and Anti-Money Laundering Act 2018, and applies to everyone in the UK rather than sitting purely as a Money Laundering Regulations duty. PEP screening, by contrast, is a Money Laundering Regulations obligation. The two are distinct regimes and worth keeping separate in your control mapping.

Does KYC on its own meet AML requirements?

No. A completed KYC check verifies identity, which satisfies the identification and verification part of customer due diligence. It does not carry out the business-wide risk assessment, screen for PEPs or sanctions, monitor transactions over time, keep the required records or file suspicious activity reports. Those obligations remain with the firm, which stays responsible for its full AML programme and ultimately liable for it.

Where does electronic identity matching fit?

Electronic identity matching is the mechanism that satisfies the verification step in KYC. It confirms a customer's identity by matching their details against independent, reliable data sources rather than a photographed document. In UK practice this follows the "2+2" convention, a guidance benchmark from JMLSG and HMRC rather than a statutory term, where at least two identity attributes are matched against at least two independent sources.

This is the step OneID's KYC Match performs. It returns a configurable count of matches across independent sources, including banks, mobile networks and public-sector data, going beyond credit reference agency data alone. It handles the identity-matching step and nothing beyond it. Your risk assessment, screening, monitoring, record-keeping and reporting stay where they belong, inside your AML programme.

Government guidance on using digital identities with the Money Laundering Regulations treats a certified digital verification service as a reliable, independent source for the identity step, while the firm remains responsible for the rest.

See where your identity checks stand

The identity step is measurable, so it is worth testing rather than assuming. You can run 1,000 records through KYC Match at no cost and compare the results against your existing provider, source by source. It shows you how many customers a multi-source match confirms that a single-source check would have failed, before you change anything in your onboarding. Contact OneID to set up a comparison.

FAQ

Is KYC part of AML? Yes. KYC is the identity-knowledge component of customer due diligence, which is one pillar of a firm's wider AML programme. Verifying who a customer is supports anti-money-laundering controls, but it is one part of them rather than the whole thing.

Is KYC the same as CDD? No. Customer due diligence is broader. It covers identifying the customer, verifying identity, assessing the purpose of the relationship and ongoing monitoring. KYC is the identity-knowledge part of CDD, focused on confirming who the customer is.

Who do you report suspicious activity to in the UK? Suspicious activity reports go to the National Crime Agency, submitted through the UK Financial Intelligence Unit. The legal duty to report arises under the Proceeds of Crime Act 2002 and the Terrorism Act 2000, not under the Money Laundering Regulations or the FCA.

Is KYC a legal requirement in the UK? KYC is not named in UK law, but the underlying obligation is. Regulated firms must identify and verify customers under the customer due diligence measures in the Money Laundering Regulations 2017. KYC is the industry term for meeting that requirement.

What is the difference between KYC and CDD? CDD is the full due diligence duty: identify, verify, assess the relationship and monitor it over time. KYC is the identity-knowledge part of that duty. Every KYC check is part of CDD, but CDD includes steps beyond identity verification.

Does KYC verification cover sanctions and PEP screening? No. A KYC check confirms identity. Screening a customer against sanctions lists or for politically exposed person status is a separate control. Sanctions screening flows from the UK sanctions regime, and PEP screening is a Money Laundering Regulations obligation.