KYC, explained: how to verify who your customers are without losing the good ones
KYC (know your customer) is how a regulated business confirms who its customers are. Under the UK's Money Laundering Regulations 2017, firms must identify each customer and verify their identity using a reliable source that is independent of the customer. It sits inside customer due diligence, which sits inside a firm's wider anti-money-laundering programme.
For the person on the other side of the check, KYC is the few seconds between wanting to open an account and being allowed to use it. When it works, the customer barely notices. When it fails, a genuine customer gives up at the last step, often one of the most valuable you were trying hardest to win.
That tension sits at the centre of every onboarding decision a compliance or growth team makes. What follows covers what KYC means, where it fits in the regulatory picture, what a check actually verifies, and how modern electronic checks recover legitimate customers that a single credit check quietly turns away.
KYC stands for know your customer. It is the process of establishing who a customer is and confirming that they are genuinely that person before, and during, a business relationship. The term is industry shorthand rather than a phrase written into UK law. The legal obligation it describes lives inside customer due diligence under the Money Laundering Regulations 2017.
The three terms nest inside one another. Anti-money-laundering (AML) is the whole programme a regulated firm runs to stop its business being used to launder money. Customer due diligence (CDD) is the part of that programme dealing with customers. KYC is the knowing-and-identifying step within CDD, and identity matching is the specific check that verifies a customer against reliable, independent sources.
A firm's AML programme covers more than any single check. It includes a written risk assessment, CDD, ongoing monitoring, record-keeping, staff training, and reporting suspicious activity to the National Crime Agency. KYC is one component of that programme rather than the whole of it.
|
Layer |
What it is |
Where it sits |
|
AML |
The whole programme that stops a firm being used to launder money |
Top level; the full obligation on a regulated firm |
|
CDD |
The due-diligence obligation on customers, under Reg 28 |
Inside AML |
|
KYC |
Knowing and identifying the customer |
Inside CDD |
|
Identity matching |
Verifying the customer against reliable, independent sources |
The verify step of KYC |
The difference between KYC and AML and the three tiers of customer due diligence each get fuller treatment in their own guides.
A KYC check does two things. It identifies the customer, meaning it establishes who they claim to be, and it verifies that identity, meaning it confirms the claim against evidence. Regulation 28 of the Money Laundering Regulations 2017 sets both as core requirements of customer due diligence.
The regulations define what verify means. Under Reg 28(18), to verify is to confirm identity "on the basis of documents or information in either case obtained from a reliable source which is independent of the person whose identity is being verified".
In practice, firms verify a standard set of identity attributes: a customer's name, address and date of birth. That dataset comes from industry guidance published by the Joint Money Laundering Steering Group, not from the wording of Reg 28 itself. The regulation sets the standard of evidence; the guidance describes what firms typically check against it.
Both approaches are valid under the regulations. Document KYC asks the customer to supply a passport, driving licence or utility bill, which the firm then checks. Electronic KYC confirms the same identity attributes against reliable digital data sources, without the customer having to photograph or upload anything. Reg 28 permits electronic identification processes where they are secure and provide an appropriate level of assurance.
For the customer, the difference is felt in seconds. A document check means finding the passport, taking a photo in decent light, waiting, and sometimes retaking it when the first attempt fails. An electronic check can confirm the same person with a tap and no upload. The drop-off between those two experiences is where good customers are lost.
HMRC sets the bar for what an electronic check has to do. Its guidance states that for a digital check to provide satisfactory evidence of identity on its own, it must use data from multiple sources, and across time, or incorporate qualitative checks that assess the strength of the information supplied. A check against a single source, at a single point in time, is not normally enough on its own.
The "2+2" convention means matching at least two identity attributes, typically name and address, against at least two independent, reliable data sources. It is an industry convention rather than a term written into law. Reg 28 requires verification from a reliable independent source, and HMRC guidance requires an electronic check to draw on multiple sources; firms meet both in practice through 2+2.
Writing "the 2+2 rule under the Money Laundering Regulations" would be inaccurate, because the regulations name no such rule. The value of the convention is that it gives a firm a defensible, repeatable way to satisfy the multi-source standard. Our own guide to the 2+2 rule works through how firms apply it.
The Money Laundering Regulations 2017 apply KYC duties to a defined list of "relevant persons". Regulation 8(2) covers credit institutions, financial institutions, auditors, insolvency practitioners, external accountants and tax advisers, independent legal professionals, trust or company service providers, estate agents and letting agents, high value dealers, casinos, art market participants, cryptoasset exchange providers, and custodian wallet providers.
Supervision is split across bodies. The Financial Conduct Authority supervises financial services and cryptoasset firms, HMRC supervises sectors such as estate agency and accountancy that do not fall under a professional body, the Gambling Commission supervises casinos, and professional bodies supervise their own members. Sector-specific duties for estate and letting agents and accountants are covered in their own guides.
A meaningful minority of legitimate customers have little or no conventional credit footprint. They are more likely to be younger adults and recent movers, or people new to the UK. A KYC check that relies on a single credit reference agency can fail them. They are no risk. That one source simply holds nothing to match them against. Those are often the customers a growth team most wants to keep.
The scale is documented in Tier-1 data. The FCA's Financial Lives 2024 survey, published in May 2025, found around 0.9 million UK adults were unbanked in 2024, down from 1.3 million in 2017. It also found that 22% of the 15.3 million applicants for regulated credit agreements were declined a product in the two years to May 2024, and that 13.1 million adults, 24% of the total, had low financial resilience.
Multi-source matching recovers many of these customers. Instead of relying on one dataset, it confirms name, address and date of birth across several independent sources, so a customer who is invisible to one is still verifiable through others. The check stays inside the same regulatory standard while failing far fewer genuine people.
This is where OneID's KYC Match fits. It performs the identity-matching step, returning a configurable count of independent data-source matches to meet and exceed the 2+2 convention. It goes beyond credit reference agency data, matching identity attributes across banks, mobile networks, insurance data, public sector data, finance applications and CRAs, in whatever configuration a firm chooses. It runs as a real-time API or as a batch check across an existing book. OneID is a digital verification services provider, certified under the UK's Digital Verification Services Trust Framework.
KYC Match performs the identity-matching step only. A firm keeps the rest of its customer due diligence: the risk assessment, source of funds where required, sanctions and PEP screening, and ongoing monitoring. Government guidance published on 26 February 2026 confirms that certified digital identity services are a reliable and independent source for the identity step, that firms should still make their own risk assessment and apply enhanced due diligence where needed, and that they remain ultimately liable for applying CDD appropriately.
What does KYC stand for? KYC stands for know your customer. It is the process a regulated business uses to establish who a customer is and confirm they are genuinely that person, throughout a business relationship.
Is KYC a legal requirement in the UK? Yes, for regulated firms. The Money Laundering Regulations 2017 require relevant persons to carry out customer due diligence, which includes identifying and verifying each customer's identity from a reliable, independent source.
What documents do you need for KYC? Traditionally a passport, driving licence or utility bill. Documents are only one route. Electronic KYC can confirm the same identity attributes against reliable digital data sources without any document upload.
Can KYC be done without documents? Yes. Electronic verification confirms a customer's name, address and date of birth against independent, reliable data sources. The regulations permit electronic identification where it is secure and provides an appropriate level of assurance.
What is the difference between KYC and AML? KYC is knowing who your customer is. AML is the whole programme that stops your business being used to launder money, and KYC is one part of it. KYC sits inside customer due diligence, which sits inside AML.
What is the "2+2" rule in KYC? Matching at least two identity attributes, usually name and address, against at least two independent, reliable data sources. It is an industry convention that helps firms meet the multi-source standard, not a rule named in law.
Who needs to complete KYC checks? Regulated "relevant persons" under the Money Laundering Regulations 2017, including banks and financial firms, accountants, legal professionals, estate and letting agents, high value dealers, casinos, and cryptoasset firms.
Every genuine customer your current check fails is revenue that walked out at the last step, and a person who felt suspected when they had done nothing wrong. Most firms never see the size of that loss, because a failed check looks like a non-customer rather than a missed one.
You can measure it directly. Run 1,000 records through KYC Match for free and compare the results against your existing provider, by contacting OneID. The comparison shows how many of the customers you are currently failing were verifiable all along.
Know exactly who you are onboarding, at the right level of checking
The extra checks that kick in when a customer is higher risk, and what your firm still has to do