AML and KYC: how identity data drives financial crime prevention

AML and KYC are usually written as one term. They are not the same thing. KYC establishes who a customer is. AML establishes whether that customer's behaviour makes sense given who they are. One produces the data. The other acts on it. Programs fail more often at the seam between the two than inside either one. This page covers both frameworks, how they connect in practice, what regulators require now, and where most programs break down. Each section links to a deeper page on the specific control.
AML and KYC controls running across the customer identity lifecycle

Table of Contents

Key takeaways

  • AML is the framework of laws, controls and reporting duties aimed at stopping illicit funds from entering the financial system.
  • KYC is the process of establishing and verifying customer identity and risk, at onboarding and afterwards.
  • KYC produces the customer data that AML monitoring measures behaviour against. Without it, alerts have no baseline.
  • The EU AML Package was adopted in 2024. AMLA became operational in July 2025 and the AML Regulation applies from July 2027.
  • Enforcement has moved past record fines into mandated remediation, external monitors and personal liability for named officers.

What AML means

Anti-Money Laundering (AML) is the set of laws, regulations and internal controls that prevent criminals from presenting illegally obtained funds as legitimate income.

Laundering runs in three stages. Placement introduces illicit funds into the financial system. Layering moves them through transactions that obscure their origin. Integration returns them as apparently clean assets. AML frameworks are designed to disrupt each stage, and each stage leaves a different kind of trace.

The scale is contested but large. United Nations estimates put laundered funds at 2 to 5 percent of global GDP, or roughly 800 billion to 2 trillion US dollars a year.

An AML program normally contains:

  • Transaction monitoring that flags activity inconsistent with a customer’s expected behaviour
  • Sanctions, PEP and adverse media screening, run continuously rather than once
  • Customer risk scoring based on geography, product, channel and ownership structure
  • Suspicious activity reporting to the national financial intelligence unit
  • Staff training, independent testing and a documented audit trail for every risk decision

What KYC means

Know Your Customer (KYC) is the process of verifying a customer’s identity, understanding what they do, and assessing the risk they present before and during the relationship.

KYC has three levels of depth.

Customer Identification Program (CIP). Collecting and verifying identifying information. For individuals that means a government issued photo ID and evidence of address. For legal entities it means registration data, ownership structure and the identification of ultimate beneficial owners, drawn from the strongest available registry per country rather than a single aggregated source.

Customer Due Diligence (CDD). Establishing the purpose of the relationship and the expected pattern of activity, then assigning a risk tier. The tier sets how deep the checks go and how often they repeat.

Enhanced Due Diligence (EDD). Applied to higher risk cases such as politically exposed persons, complex offshore structures, or customers in high risk jurisdictions. EDD adds source of funds and source of wealth evidence, and usually senior sign off.

KYC is not a one time exercise. Common practice refreshes high risk customers every 12 months and standard risk customers every 24 to 36 months, with an immediate review whenever something material changes.

How the two connect

The relationship is sequential and it is where most operational failure sits.

  1. KYC gathers identity, ownership and expected activity at onboarding. That becomes the customer’s baseline.
  2. AML risk models use the baseline to decide what normal looks like for this specific customer.
  3. Monitoring flags deviation from that baseline. Screening flags changes in status such as a new sanctions listing or an ownership change.
  4. An analyst compares the flagged activity against the KYC file. If the activity fits the profile, the alert closes. If it does not, and cannot be explained, the case escalates to a suspicious activity report.

KYC tells you who the customer is. AML tells you whether the behaviour fits. If the KYC file is stale, step 4 has nothing reliable to compare against, and the analyst is guessing.

AML and KYC compared

DimensionAMLKYC
PurposeDetect, prevent and report money laundering and terrorist financingEstablish identity, ownership and risk level
ScopeProgram level, spanning the whole customer lifecycleProcess level, at onboarding and on refresh
Main controlsTransaction monitoring, sanctions and adverse media screening, SAR filingDocument verification, database checks, ownership mapping, risk classification
OutputAlerts, case files, regulatory reportsVerified identity record and risk tier
OwnerCompliance and financial crime teamsCompliance, onboarding and client services
RelationshipThe umbrella frameworkOne required component within it

Where most programs break

Almost every KYC file is accurate on the day it is created and decays from that point.

Sanctions lists are updated multiple times per week. Ownership structures change without notice. Adverse media appears years after onboarding. Under a purely periodic model with a 12 to 36 month cycle, any of these can sit undetected until the next scheduled review.

That gap is the reason regulators have shifted their language from periodic review towards ongoing due diligence. Two operating models have emerged in response.

Periodic review. Full file review on a fixed schedule set by risk tier. Predictable to resource, but blind between cycles.

Event driven review, also called perpetual KYC. Continuous screening and monitoring that triggers a targeted review when something material changes, rather than a full file review on a calendar. Faster to detect, but it depends entirely on the quality and freshness of the underlying customer data.

Most institutions now run a hybrid. The practical question is not which model is better in theory. It is whether your customer data is current enough for either one to work.

Further reading: perpetual KYC compared with periodic review, trigger events that should force a refresh, and how to scope a KYC remediation project.

The eight components regulators look for

1. Written policies. Documented procedures covering identification, due diligence, monitoring, escalation and reporting. Reviewed at a stated interval.

2. A designated officer. A named, qualified individual accountable for the program and acting as the contact point for regulators.

3. A business wide risk assessment. Where the business is exposed, by customer type, product, geography and delivery channel. Updated at least annually.

4. Customer risk classification. A tiered model with documented criteria, and a defined level of due diligence per tier.

5. Transaction monitoring. Rules or models that measure activity against each customer’s expected profile, with tuning based on outcomes rather than left at vendor defaults.

6. Screening. Sanctions, PEP and adverse media checks against the relevant lists, including OFAC and the EU consolidated list. Rescreening is continuous because the lists change constantly.

7. Suspicious activity reporting. A defined route to the national financial intelligence unit. In the United States, filing is due within 30 calendar days of initial detection. Informing the customer of a report is prohibited in most jurisdictions.

8. Records and training. Most regimes require KYC and transaction records to be retained for at least five years. Staff in customer facing and transaction handling roles need recurring training with evidence of completion.

Regulatory landscape

RegionFramework and authorityWhat it requires in practice
European UnionAML Package adopted 2024. AMLA operational July 2025, AML Regulation applies July 2027. 6AMLD remains in forceHarmonised rules applied directly rather than transposed, central beneficial ownership registers, criminal liability extending to legal entities and their directors
United StatesBank Secrecy Act, FinCEN, Anti-Money Laundering Act of 2020Customer due diligence rule, beneficial ownership reporting, SAR filing within 30 days
United KingdomMoney Laundering Regulations 2017, Proceeds of Crime Act, FCA supervisionRisk based approach, independent audit of the program, beneficial ownership verification
Asia PacificMAS in Singapore, AUSTRAC in Australia, HKMA in Hong KongCountry specific rules, active enforcement in Singapore and Australia, differing acceptance of remote digital verification
Global baselineFATF 40 RecommendationsThe standard most national regimes are built from, applied across more than 200 jurisdictions and tested through mutual evaluation

Countries that fail FATF evaluation can be added to the grey or black list, which raises the cost of correspondent banking for every institution operating there.

What non-compliance actually costs

Fines are the visible part and rarely the expensive part.

Fines. In 2024, TD Bank was penalised more than 3 billion US dollars after investigators established it had processed around 470 million dollars in illicit transactions linked to a money laundering network. Binance settled Bank Secrecy Act and related violations for 4.3 billion dollars in 2023. Smaller cases carry the same logic at a different scale. The FCA fined Monzo 5.4 million pounds over deficiencies in its AML controls, including weaknesses in monitoring that allowed suspected mule account activity.

Remediation. The Monzo case is instructive because of what followed. The bank had to rebuild transaction monitoring, rework risk assessment and align onboarding KYC with ongoing monitoring. Remediation programs of that kind run for years and consume senior management time that was budgeted for growth.

Supervisory measures. Regulators can cap onboarding, restrict product lines or install an external monitor with access to your operations.

Personal liability. Under 6AMLD, criminal liability extends to legal entities and their directors. Compliance officers have been named personally in enforcement actions in several jurisdictions.

Licence withdrawal. Payment institutions and smaller banks have lost authorisation entirely after repeated failures. This is the outcome that ends the business rather than costing it money.

Building a program: five steps

Step 1. Assess your own exposure. Map risk across customer types, products, geographies and channels before choosing any control. Write it down and date it.

Step 2. Define risk tiers and what each one triggers. Three tiers is enough for most businesses. What matters is that each tier states the required evidence, the approval level and the refresh cadence.

Step 3. Decide how identity and ownership get verified. For entities, decide how you will establish beneficial ownership above the applicable threshold, commonly 25 percent, and how you will keep that current.

Step 4. Choose controls proportionate to your scale. Modular verification and screening tools cover most obligations for smaller businesses. Enterprise monitoring platforms make sense at volume. Either way, plan for how the data stays current, not only how it is captured.

Step 5. Test, document, adjust. Periodic internal review, independent audit where required, and evidence that findings led to changes. Supervisors read the remediation trail as closely as the policy.

Further reading: enhanced due diligence checklist, customer risk rating methodology, and source of funds compared with source of wealth.

Who is responsible for what

RoleResponsibility
BoardApproves policy and risk appetite. Holds ultimate accountability
MLRO or Chief Compliance OfficerDesigns and runs the program. Owns reporting and regulator contact
Compliance analystsInvestigate alerts, conduct EDD, prepare reports
Onboarding and client servicesCollect and verify documentation. First line of defence
Data and technologyMaintain screening, monitoring and the data pipelines both depend on

Where the practice is heading

Fewer false positives. Rule based monitoring generates alert volumes that swamp analysts. Model driven approaches trained on outcomes reduce that volume, but require clean labelled data to work.

Verification at the point of onboarding, in the flow. Biometric checks and liveness detection have moved remote onboarding from exception to default in most markets.

Government backed digital identity. Schemes in the EU and UK will standardise part of the identification step, which shifts the compliance burden towards ongoing monitoring rather than initial verification.

Data quality as the constraint. Every trend above depends on the same input. Screening, monitoring and reporting are all limited by whether the customer record is accurate and current.

Frequently asked questions

What is the difference between AML and KYC? AML is the broader framework of laws and controls designed to prevent, detect and report financial crime. KYC is one required component within it, focused on establishing customer identity, ownership and risk. KYC produces the data that AML monitoring measures behaviour against.

Who has to comply? Banks, payment institutions, insurers, investment firms, crypto asset service providers, gambling operators, real estate agents, accountants and lawyers, among others. The list of obliged entities varies by jurisdiction. The core obligations are broadly consistent.

How long does KYC take? Straightforward individual verification takes minutes with automated tools. Corporate cases with layered ownership or offshore structures take days to weeks, mainly because ownership evidence has to be obtained rather than looked up.

How often does KYC need to be refreshed? Regulations require information to be kept current rather than prescribing a universal interval. Common practice is every 12 months for high risk customers and every 24 to 36 months for standard risk, with an immediate review triggered by any material change.

What happens if a business fails to comply? Consequences range from fines and public censure to restrictions on business activity, mandated remediation under an external monitor, loss of banking relationships and withdrawal of authorisation. Individual officers can face personal criminal liability, including under 6AMLD in the European Union.

Can a small business run a proportionate program? Yes. A risk based approach means the depth of control should match the exposure. Modular verification, screening and monitoring tools make a defensible program achievable without an enterprise budget. What supervisors expect is evidence that the risk was assessed and the controls follow from it.

Next step

If your KYC files are accurate at onboarding and unreliable eighteen months later, the problem is not your onboarding process. It is that nothing keeps the record current.

Start by measuring it. Take a sample of 100 customer records, check each against current sanctions, PEP, adverse media and ownership data, and count how many have changed since the file was last touched. That number tells you whether you have a compliance program or a compliance archive.

We can run that check against your existing records and show you where the decay sits. Book a 30 minute walkthrough.

Products

Explore STRIKE products

NexusAPI Centre

A single connection to every data source. Integrate once and orchestrate every check from one API.

Explore Nexus
VerifyMeKYC Flow

Build your own onboarding flow: identity, biometrics, screening and monitoring in one place.

Explore VerifyMe
Global SphereData quality

Keep records clean, complete and decision-ready with validation and enrichment at the source.

Explore Global Sphere