Back to research
Regulation

KYC, KYB and AML Explained: Fintech's Compliance Backbone

Every fintech that touches money has to answer three questions about its customers: who are you, what is your business, and are you laundering money? The answers determine whether the firm operates or gets shut down.

Updated 11 min read
In this research

KYC, KYB, and AML are related but not interchangeable parts of financial-crime compliance. KYC and KYB are industry terms for the customer due-diligence work applied to individuals and organisations; AML is the wider legal and operational framework that includes due diligence, risk assessment, ongoing monitoring, controls and suspicious-activity reporting. They share a purpose (preventing financial crime), but they operate at different points in the customer lifecycle and apply differently to different types of counterparty.

KYC is about establishing and periodically reconfirming who an individual customer is. KYB applies equivalent scrutiny to corporate customers, which turns out to be considerably harder. AML is neither a check nor a one-time event: it is a continuous programme that includes monitoring, investigation and reporting where the applicable legal test is met. All three sit on related regulatory foundations, but the exact duties differ by activity and jurisdiction. Working through them in order is the clearest way to see how they fit together without treating this overview as a compliance checklist.

Defining the Three Terms Precisely

Know Your Customer (KYC) describes the identity-verification element of customer due diligence for individuals. The precise evidence and controls depend on the relationship and risk: firms commonly collect identifying data, validate reliable independent evidence, and screen for sanctions and politically exposed person (PEP) risk. A government identity document and a biometric or liveness check are common in remote digital onboarding, but neither is a universal legal checklist for every customer and every channel. FATF's digital identity guidance[1] says firms should assess whether a digital identity system is sufficiently reliable and independent for the risk and context. Enhanced Due Diligence (EDD) applies where the law or assessed risk requires additional measures, including specified higher-risk relationships and PEP cases.

Know Your Business (KYB) applies the same underlying principle (understand who you are dealing with) to corporate customers, and immediately the complexity increases. A company does not have a face or a passport. Verifying that a business legally exists requires checking its registration in the relevant national registry. Identifying who owns or controls it can require tracing through layered structures to natural persons. The ownership thresholds and control indicators are jurisdiction- and date-specific: for example, the current UK definition in regulation 5 of the Money Laundering Regulations[2] is not identical to every current EU implementation or to the directly applicable EU AML Regulation that applies from 10 July 2027. A cross-border programme therefore cannot safely reduce beneficial ownership to one universal percentage.

Anti-Money Laundering (AML) is not a check. It is an ongoing programme: a combination of policies, controls, transaction monitoring, staff training and reporting obligations, designed to detect and investigate activity that may indicate financial crime. An alert is an input to that process, not the legal test for a report. In the UK regulated sector, the disclosure duties in Part 7 of the Proceeds of Crime Act 2002[3] turn on statutory concepts such as knowledge, suspicion or reasonable grounds, with the precise duty depending on the person's role and facts. Relevant disclosures are made to the National Crime Agency's UK Financial Intelligence Unit (UKFIU).

The Regulatory Foundations

The global framework comes from the Financial Action Task Force, an intergovernmental body whose 40 Recommendations[4] set the baseline that national regulators are expected to implement. FATF membership carries mutual evaluation obligations: member jurisdictions are periodically assessed on whether their legal frameworks and actual supervision meet the Recommendations. Being greylisted (placed on FATF's list of jurisdictions under increased monitoring) has material consequences for any financial firm operating in or through that country.

In the European Union, the AML framework has been progressively tightened through a series of directives. The 4th Anti-Money Laundering Directive (2015) introduced mandatory UBO registers and risk-based CDD requirements. The 5th (2018) extended the scope to cryptocurrency exchanges and custodian wallet providers, enhanced access to UBO registers, and added further requirements for high-risk third countries. Directive (EU) 2018/1673, commonly called 6AMLD and adopted in 2018, focused on criminal liability: it harmonised the definition of money laundering across member states, set out 22 categories of predicate offences, and covered aiding, abetting, inciting and attempting money laundering. Member states implemented it through national criminal law after adoption.

That directive-based framework is now mid-replacement. The EU's 2024 AML package created a new Anti-Money-Laundering Authority (AMLA), based in Frankfurt, which became operational on 1 July 2025, and a directly applicable Anti-Money-Laundering Regulation (AMLR, Regulation (EU) 2024/1624[5]) that replaces the patchwork of national directive transpositions from 10 July 2027. From 2028, AMLA will directly supervise around 40 of the highest-risk institutions across the EU. Compliance teams designing programmes today should build against the AMLR, not just the directives it supersedes.

In the UK, the primary statutory vehicle is the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017[6], which transposed the 4th AMLD into domestic law and has since been amended. Post-Brexit divergence from EU AML rules is possible, while UK firms operating across borders may also need to account for the rules that apply to their EU activities and counterparties. The Proceeds of Crime Act 2002, Part 7[3], and the Terrorism Act 2000 provide the underlying criminal-law framework for disclosures and offences such as tipping off.

These rules can support enforcement against firms and, depending on the facts, responsibilities and applicable regime, against individuals. That does not create automatic personal liability for every MLRO or senior manager when a control fails. The FCA's published decisions and financial-crime guidance are more useful than a universal formula: they show that governance, reasonable steps, evidence and the allocation of responsibility matter in each case.

How KYC Works in Practice

The standard identity verification flow starts with data collection: the customer provides name, date of birth, and residential address. They then upload or photograph a government-issued identity document. At this point, automated document authenticity checks begin: examining security features, detecting manipulation, cross-referencing document templates from the issuing country. The dominant vendors in this space (Onfido, Jumio, Sumsub, and Veriff) all provide document verification as a commodity, differentiated largely by the depth of their country coverage, false positive rates, and integration flexibility.

The biometric liveness check follows: the customer is asked to perform an action (look at the camera, turn their head, blink) to confirm they are physically present rather than presenting a photograph or using a deepfake. Liveness detection has become a meaningful technical battleground as presentation attacks have grown more sophisticated. Major vendors now offer passive liveness (detecting whether a face is live without requiring any deliberate action from the customer), as the attacks against active liveness (instructed actions) have matured.

Parallel to document and biometric verification runs sanctions and PEP screening. Every customer's name is checked against multiple consolidated sanctions lists: OFAC (US), UN Security Council, EU, HMRC/OFSI (UK), as well as commercial PEP databases maintained by providers such as ComplyAdvantage, Refinitiv World-Check, and Dow Jones. PEP classification is not binary: a PEP is any individual who holds or has held a prominent public function, and the definition extends to family members and known close associates. The risk level associated with a PEP varies significantly: a local councillor in a low-corruption jurisdiction is not equivalent to a minister in a state with high corruption indices.

Customer Risk Assessment (CRA) aggregates these signals to assign a risk rating that determines the CDD tier applied and the refresh frequency. Standard CDD applies for a low-risk retail customer. EDD, which requires documented evidence of the source of wealth and source of funds, alongside senior management sign-off, applies for PEPs, high-value customers, and those from FATF high-risk jurisdictions.

How KYB Works in Practice

Corporate verification starts with establishing that the entity legally exists in the jurisdiction it claims to be registered in. In the UK, that means a Companies House lookup: verifying registered name, company number, registered address, and current status (active, not struck off). Across the EU, equivalent registries exist at member-state level: the Registro Mercantil in Spain, the Handelsregister in Germany, the Greffe du Tribunal de Commerce in France. Data quality varies considerably between jurisdictions.

After establishing the entity, the firm identifies and verifies the people required by the applicable customer-due-diligence rules. That normally includes beneficial owners and any person purporting to act on the customer's behalf; directors and senior managers are also relevant to understanding ownership, control and risk. It does not follow that every director must always complete the same retail KYC flow. The measures should reflect the person's role, the legal requirement and the risk assessment. Director lists can change or lag reality, so registry data should not be treated as conclusive on its own.

UBO identification is a recurring KYB challenge. The firm applies the ownership and control tests that govern the relevant entity and activity, then traces layered ownership until it can identify the natural persons who meet those tests or document the applicable alternative-control analysis. A threshold alone is not enough: trusts, foundations, nominee arrangements and rights exercised through other means can change the analysis. EU member states maintain national beneficial-ownership registers, but access and implementation differ. The European Court of Justice's 2022 ruling restricting general public access also changed how some firms can use register data. A registry result is therefore evidence to assess, not a complete cross-border determination.

Ongoing monitoring of corporate customers matters more than most firms' practices reflect. Ownership structures change. Directors resign and are replaced. Companies move their registered office to a different jurisdiction. A customer whose UBO structure was unproblematic at onboarding may, two years later, have a beneficial owner who has been sanctioned. Point-in-time KYB treats that risk as resolved; perpetual KYB treats it as continuously open.

Transaction Monitoring and SAR Filing

AML transaction monitoring starts from a baseline: what does normal look like for this customer, given their stated profile, their account type, and their peer group? Deviation from that baseline, whether in volume, frequency, geography, counterparty, or transaction type, generates an alert for review.

Rules-based monitoring engines flag specific patterns: unusually large cash transactions inconsistent with the customer's stated profile, structuring (a pattern of transactions broken into smaller amounts that suggests deliberate avoidance of scrutiny), rapid round-trip transactions, payments to or from sanctioned countries, or activity sharply inconsistent with a customer's stated business purpose. Machine learning-based monitoring systems, offered by vendors such as ThetaRay, Featurespace, and NICE Actimize, add behavioural anomaly detection on top of static rules, reducing false positive rates by clustering peer groups more accurately and identifying novel laundering typologies that rules libraries have not yet caught.

When a transaction or pattern of transactions is flagged, a compliance analyst performs alert triage. The analyst determines whether the activity can be explained using what the firm knows about the customer or whether suspicion remains. In the UK regulated sector, a nominated officer who receives information giving the required knowledge or suspicion must consider a disclosure to the UK Financial Intelligence Unit under Part 7 of POCA. Failure to disclose can be a specific criminal offence; that is legally distinct from the principal money-laundering offences, although the underlying facts may engage both. Separate tipping-off and prejudicing-an-investigation offences restrict what can be disclosed to a customer after a relevant disclosure or investigation. The statutory tests and defences matter, so firms should follow current NCA guidance and obtain legal advice on difficult cases.

SAR quality is a recurring FCA concern. Filing volumes are not a proxy for programme quality. A SAR that mechanically describes a transaction without articulating why it is suspicious, without providing contextual detail about the customer's known profile and the specific deviation from it, and without capturing the analyst's reasoning, provides limited intelligence value to the NCA and provides limited evidence of genuine compliance effort if the firm is later under scrutiny. The wider RegTech stack is increasingly capable of generating case summaries to support analyst decision-making, but the substantive analytical judgment remains a human obligation.

The Shift to Perpetual KYC

Traditional periodic review treated customer files like an audit schedule: high-risk customers refreshed annually, standard-risk customers every three to five years. That approach has an obvious flaw: a customer who becomes a PEP in month seven of a three-year refresh cycle, or whose UBO is sanctioned in month fourteen of an annual cycle, is not caught until the next scheduled review, which may be years away.

Perpetual KYC (pKYC) replaces the periodic schedule with continuous, event-driven monitoring. Rather than waiting for a refresh date, the system monitors for triggering events: sanctions list additions, PEP database updates, adverse media alerts, document expiry, changes in registered ownership at Companies House. When a trigger fires, a review workflow is initiated immediately. The customer's file is re-screened, and EDD may be required if the trigger implies elevated risk.

Several UK challenger banks and neobanks have built pKYC architectures in recent years, partly from genuine compliance ambition and partly from pragmatism: manual periodic reviews create compliance backlogs that scale badly with customer volume. A firm with two million customers on a three-year refresh cycle needs to process over 650,000 reviews per year without a material triggering event in sight. pKYC converts that into a smaller, more manageable queue of event-driven cases, and it is increasingly what the FCA expects sophisticated firms to demonstrate. The tooling to support it sits in the orchestration layer, discussed below.

The RegTech Stack for KYC and AML

The vendor market for KYC and AML has segmented into distinct layers, and understanding the layers helps clarify why firms typically use multiple products rather than a single platform. The full RegTech stack for neobanks is covered in detail separately; the highlights relevant to KYC and AML are as follows.

Identity verification is dominated by Onfido (now part of Entrust), Jumio, Sumsub, and Veriff. Each offers document verification, biometric liveness, and varying combinations of database checks and AML screening. Selection criteria typically centre on country coverage (Sumsub and Onfido have strong global coverage), false positive and false negative rates, API latency, and price per check. Sumsub has gained significant share among crypto and neobank clients, partly on price and partly on depth of integration with orchestration platforms.

Sanctions, PEP, and adverse media data is supplied by ComplyAdvantage (real-time updating, strong API-first design), Refinitiv World-Check (extensive coverage depth, historically preferred by large banks), and Dow Jones Risk and Compliance. The choice here involves trade-offs between coverage depth, false positive rate, update frequency, and cost: World-Check's breadth can generate high alert volumes that overwhelm analyst capacity if not tuned carefully.

Transaction monitoring for larger institutions is typically handled by NICE Actimize, which dominates the enterprise segment, or Fiserv AML Manager. For fintechs and neobanks, ThetaRay (particularly for cross-border payments), Featurespace (behavioural analytics), and Unit21 (case management plus monitoring) are more common. ThetaRay uses unsupervised machine learning and proprietary AI algorithms to identify suspicious activity in correspondent banking and cross-border payment flows, where traditional rules-based systems can struggle.

Orchestration platforms sit above the individual point solutions. Alloy and Unit21 are the most widely used in the fintech segment: they integrate outputs from identity verification vendors, sanctions databases, and transaction monitoring into a unified decision engine, add case management workflows, and provide the audit trail that regulators want to see when they review a firm's AML processes. The orchestration layer is also where pKYC logic lives: event triggers from sanctions databases or registry monitors route into the case management queue without requiring manual monitoring of each individual data source.

What Good Looks Like, and What Regulators Actually Find

The FCA's enforcement actions and Financial Crime Guide[7] describe recurring weaknesses including poor risk assessment, weak oversight and ineffective or inadequately tested controls. Automated screening can support a sound programme, but the firm still has to understand, test, govern and escalate the results appropriately.

EDD documentation failures are the second persistent category. A high-risk customer who has been assigned EDD should have a file that explains the source of their wealth (not "salary" without further investigation), the expected volume and nature of their transactions, senior management's specific sign-off, and the date of the next review. The FCA has repeatedly found[8] that EDD records are either absent or formulaic, copying template language rather than reflecting genuine analysis of the specific customer.

KYB failures tend to concentrate at the UBO identification stage. Firms verify the entity and the named directors but do not trace the ownership structure to the ultimate natural persons. Nominee arrangements and intermediate holding companies are accepted at face value rather than looked through. This is not a technical capability gap: the information is often available, and the MLRs require firms to take reasonable measures to obtain it. It is more often a resource or process gap: the firm's KYB flow was designed for simple structures and was never tested against opaque ones.

SAR filing remains analytically shallow at many firms. A SAR filed with the minimum required fields, describing the transaction without reasoning about its suspicious characteristics or the customer's known profile, is technically compliant and substantively weak. The NCA's UKFIU has published guidance on what makes a useful SAR; the FCA has noted in thematic reviews that SAR quality across the industry does not consistently meet that standard. The shift to broader regulatory obligations under frameworks like DORA has increased pressure on compliance functions: the risk is that AML analytical capacity is thinned by competing regulatory demands rather than protected as core.

What the better-performing firms share is not a more expensive technology stack. It is a compliance programme designed around the actual risks their customer base presents: genuinely calibrated risk appetite rather than checkbox-driven CDD, analysts who understand the typologies they are looking for, and senior management who treat the MLRO function as substantive rather than administrative. The RegTech vendors can accelerate that programme; they cannot substitute for it.

Vendor examples throughout describe publicly documented product categories and are not endorsements.

Sources

Numbered references are anchored to the specific claims they support. Primary documents are preferred wherever available.

  1. FATF's digital identity guidance fatf-gafi.org
  2. UK definition in regulation 5 of the Money Laundering Regulations legislation.gov.uk
  3. Part 7 of the Proceeds of Crime Act 2002 legislation.gov.uk
  4. 40 Recommendations fatf-gafi.org
  5. Regulation (EU) 2024/1624 eur-lex.europa.eu
  6. Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 legislation.gov.uk
  7. Financial Crime Guide handbook.fca.org.uk
  8. The FCA has repeatedly found fca.org.uk

Frequently asked questions

What is the difference between KYC and AML?

KYC (Know Your Customer) is the identity-verification element of customer due diligence, performed at onboarding and refreshed when the applicable programme requires it. AML (Anti-Money Laundering) is the wider, ongoing framework of risk assessment, controls, monitoring, investigation and legally required reporting. An unresolved alert is not itself the statutory trigger for a Suspicious Activity Report; the relevant legal test and reporting duty depend on the jurisdiction, role and facts.

Which firms are required to carry out KYC and AML?

Any firm that falls within the scope of the UK Money Laundering Regulations 2017: banks, payment institutions, e-money institutions, credit firms, crypto asset exchanges registered with the FCA, and a range of other regulated entities. The obligations also apply to certain non-financial businesses such as accountants, solicitors, and estate agents when conducting specified activities. Operating a regulated fintech without a compliant KYC and AML programme is not a grey area; it is a condition of authorisation.

What counts as a UBO under UK and EU rules?

There is no safe single definition for a cross-border overview. In the UK, regulation 5 of the Money Laundering Regulations uses more than 25% ownership or voting rights alongside control through other means. Current EU rules depend on the applicable national implementation; the directly applicable EU Anti-Money-Laundering Regulation uses its own tests from 10 July 2027. Firms must apply the current rule for the relevant entity, activity, jurisdiction and date rather than reuse one percentage globally.

What happens if a firm fails to file a Suspicious Activity Report?

In the UK regulated sector, a nominated officer's failure to make a required disclosure can be a specific criminal offence under Part 7 of the Proceeds of Crime Act 2002. It is distinct from the principal money-laundering offences. The exact test, timing, available defences and the rules on tipping off depend on the facts, so a firm should follow current NCA guidance and seek legal advice where needed. Control failures may also lead to regulatory action against a firm or responsible individuals.

How long does KYC take with modern RegTech tools?

A low-risk digital identity check can return an automated result quickly, but there is no universal completion time. It depends on the evidence used, the reliability of the identity system, the customer's circumstances, screening matches and the firm's review process. Manual review and Enhanced Due Diligence can take much longer, particularly where ownership, source of funds or source of wealth needs to be established.

Update history

  1. Separated UK and EU beneficial-ownership tests, removed the false unresolved-alert SAR trigger and narrowed individual-accountability language.
KYCKYBAMLcomplianceregtechfinancial crime

The CloudFintech Briefing

Independent fintech analysis — AI in banking, payments, crypto, and regulation. No spam, unsubscribe any time.

By subscribing you agree to our Privacy Policy.