search

Know Your Customer (KYC): Best Practices for Customer Due Diligence

5/5/2026

"Know your customer" is one of those phrases that everyone in banking uses and few can define precisely. It is not a single regulation. It is a stack of three related obligations — identification, due diligence, and ongoing monitoring — that operate on different timelines and fail in different ways.

This guide separates them, then covers the practices that distinguish programs that survive examination from those that do not.

The Three Layers

Layer 1: Customer Identification Program

The CIP is a discrete, one-time obligation at account opening. The institution must have a written, board-approved program that includes procedures for:

  • Collecting minimum identifying information before the account is opened: name, date of birth for individuals, address, and an identification number
  • Verifying identity within a reasonable time after account opening, through documentary methods, non-documentary methods, or both
  • Recordkeeping of the information collected and the verification performed
  • Comparing customers against government lists as required
  • Providing notice to customers that information is being collected to verify identity

CIP answers one question: is this person who they say they are?

Layer 2: Customer Due Diligence

CDD is broader and asks a different question: what should we expect from this relationship? Under the CDD rule, institutions must have risk-based procedures for:

  • Understanding the nature and purpose of customer relationships to develop a customer risk profile
  • Conducting ongoing monitoring to identify and report suspicious transactions
  • Maintaining and updating customer information on a risk basis

And for legal entity customers, identifying and verifying beneficial owners.

Layer 3: Ongoing Monitoring

The relationship is not static. Monitoring compares actual activity against the expected profile, and it feeds back into the profile when the business genuinely changes. This layer is continuous and is where most programs fall behind.

The frequent failure is treating all three as onboarding tasks. CIP genuinely is one. CDD is not, and monitoring definitionally is not.

Getting the Profile Right at Onboarding

The customer risk profile is the benchmark everything is later measured against, and a vague profile makes monitoring useless. If the file says "retail business," every subsequent alert requires reconstruction from scratch.

Information worth capturing for a business customer:

  • The specific nature of the business — not "consulting" but what is consulted on, for whom
  • Expected monthly volume and value of deposits, by type
  • Expected currency activity, specifically
  • Expected wire and ACH activity, including counterparties and geographies
  • Source of funds and, for higher-risk relationships, source of wealth
  • Number of locations and states of operation
  • Whether the business serves other businesses or consumers

For individuals: occupation and employer, expected activity levels, source of funds for significant deposits, and any foreign connections.

Two practices materially improve quality. First, ask the questions as part of the account-opening conversation rather than as a form to complete afterwards — the answers are better and the customer experiences it as service rather than interrogation. Second, record the expectation in a structured field, not free text, so monitoring can actually compare against it.

Beneficial Ownership

For legal entity customers, the institution must identify and verify:

  • The ownership prong — each individual who directly or indirectly owns 25 percent or more of the equity interests
  • The control prong — a single individual with significant responsibility to control, manage, or direct the entity, such as a chief executive officer, chief financial officer, managing member, or general partner

Points that consistently cause difficulty:

There may be no owner under the ownership prong. A widely held entity may have nobody at 25 percent. The control prong individual is still required — there is always exactly one of those.

Ownership can be indirect. An individual owning 50 percent of a holding company that owns 60 percent of the customer holds 30 percent indirectly and is a beneficial owner. Layered structures require working the chain, and structures designed to obscure ownership are themselves a risk indicator.

Verification standards match CIP. Beneficial owners are verified to the same standard as individual customers, though the institution may rely on information provided by the person opening the account absent knowledge of facts calling it into question.

Certain entity types are excluded from the beneficial ownership requirement, including many regulated entities. Know which exclusions your procedures apply.

This is separate from the Corporate Transparency Act. The CDD rule obligates banks to collect beneficial ownership from customers. The Corporate Transparency Act created a separate reporting regime obligating companies themselves to report to FinCEN. They are different obligations with different histories, and staff conflate them constantly.

Risk Rating Customers

A risk rating drives the depth of due diligence and the intensity of monitoring, so the methodology has to be defensible and consistently applied.

Most institutions rate across four dimensions:

Dimension

Higher-risk indicators

Customer type

Cash-intensive business, MSB, PEP, nonprofit, complex ownership

Products and services

Wires, remote deposit capture, foreign exchange, trade finance

Geography

Foreign activity, high-risk jurisdictions, border regions

Delivery channel

Non-face-to-face onboarding, third-party introduction

 

Three practices distinguish good methodologies:

Document the "why," not just the score. A rating with no recorded rationale cannot be defended or reviewed.

Allow and record overrides. An analyst who knows the customer may reasonably rate above or below the model. Overrides should be permitted, documented, approved, and periodically reviewed as a set — a model overridden 40 percent of the time is a model that needs recalibration.

Re-rate on a schedule and on trigger. Periodic review by rating tier, plus event-driven re-rating on ownership change, activity change, negative news, or SAR filing.

Enhanced Due Diligence

EDD applies to relationships the institution has identified as higher risk. Categories commonly include foreign correspondent accounts, private banking for non-U.S. persons, politically exposed persons, cash-intensive businesses, money services businesses, and certain nonprofits.

EDD typically means:

  • More information at onboarding, including source of wealth for the individuals behind the entity
  • Senior management approval to open or continue the relationship
  • More frequent periodic review — annually or more often rather than every three years
  • Tighter monitoring thresholds and, in some cases, manual review of activity
  • Site visits for certain business types

The measure of an EDD program is not the length of the questionnaire. It is whether the additional information changes anything — whether it feeds monitoring, informs the rating, and produces decisions.

Keeping Information Current

This is the weakest link in most programs. Information collected at onboarding decays: businesses change activity, owners change, addresses change, and the profile silently stops describing the customer.

What works:

Risk-based refresh cycles, not universal ones — annually for high risk, less frequently for low, with the tiers defined and justified.

Event triggers that force refresh: ownership change, signer change, a significant shift in activity, negative news, a SAR filing, or a returned mailing.

Refresh at natural touchpoints. A loan renewal, a new account, or a service change is when the customer is already engaged and information is easiest to obtain.

Report on staleness. A metric showing the percentage of customers whose information exceeds the refresh interval, reported to management. Programs without this metric discover the backlog at examination.

Where KYC Programs Fail Examination

  • Profiles too vague to monitor against. "Retail" as an expected activity description.
  • Beneficial ownership collected but not verified, or collected only at onboarding with no process for change.
  • Risk ratings that never change. A portfolio where nobody has been re-rated in three years.
  • EDD that is documentation only — a longer file with no change in monitoring or review frequency.
  • Refresh backlogs with no metric and no owner.
  • Inconsistent application — two similar customers rated differently, with no recorded reason.

Institutions strengthening this area usually start with the profile fields at onboarding, because every downstream control inherits their quality. Structured coverage of the whole framework is available through our AML compliance training and the broader Certificate in BSA and AML Compliance.

Handling Difficult Customer Types

Most KYC frameworks work smoothly until they meet a customer that does not fit the template. Four categories generate the majority of escalations, and each has an established approach.

Money services businesses. MSBs are legal customers, and banking them is not prohibited — but they require the institution to confirm FinCEN registration and any state licensing, to understand the specific services offered, and to assess the MSB's own AML program. The failure mode is not banking them; it is banking them on retail-customer due diligence. Institutions that decide as a matter of policy not to serve MSBs should record that decision and apply it consistently, because inconsistent application creates its own problems.

Nonprofits and charities. Risk varies enormously between a local food bank and an organization moving funds to a conflict region. Due diligence should establish the mission, the funding sources, the geography of disbursement, and who controls the accounts. Blanket treatment of all nonprofits as higher risk wastes resources; blanket treatment as lower risk misses the ones that matter.

Politically exposed persons. There is no U.S. list of PEPs, so identification depends on screening tools, customer disclosure, and analyst judgment. PEP status is not itself disqualifying — it triggers enhanced due diligence, senior approval, and attention to source of wealth rather than only source of funds.

Professional service providers holding client funds. Attorneys' trust accounts, title companies, and escrow agents hold funds belonging to third parties the bank never sees. The relevant due diligence is on the professional's own controls and on understanding the expected flow, since transaction-level monitoring against the accountholder's profile is inherently limited.

Across all four, the same principle applies: the answer to a difficult customer type is calibrated due diligence and documented reasoning, not reflexive exit. Wholesale de-risking of a category — closing every account in a customer class rather than assessing them individually — has drawn explicit supervisory criticism, and it pushes activity into channels with no visibility at all.

One organizational note that predicts program quality better than any policy detail: whether the people opening accounts are measured on anything other than speed. Onboarding staff working to a stopwatch will record whatever fills the field fastest, and no amount of downstream monitoring recovers from a profile that says "retail." Institutions that add a quality dimension to account-opening review — sampling new profiles for specificity and coaching on the results — see the benefit across every control that depends on the profile, which is most of them.

Frequently Asked Questions

What is the difference between KYC, CIP, and CDD?

KYC is the umbrella term for knowing who your customers are and what to expect from them. CIP is the specific regulatory requirement to identify and verify a customer's identity at account opening. CDD is the broader, ongoing obligation to understand the nature and purpose of the relationship, develop a risk profile, identify beneficial owners of legal entities, and monitor activity against expectations.

Who counts as a beneficial owner?

Under the ownership prong, any individual who directly or indirectly owns 25 percent or more of the equity interests of a legal entity customer. Under the control prong, one individual with significant responsibility to control, manage, or direct the entity. There may be no individual meeting the ownership prong, but there is always one under the control prong.

How often should customer information be updated?

On a risk basis. High-risk relationships are commonly reviewed annually or more frequently; lower-risk relationships less often. Beyond the periodic cycle, specific events should trigger an immediate refresh — ownership or signer changes, significant activity changes, negative news, or a SAR filing.

Is the CDD rule the same as the Corporate Transparency Act?

No. The CDD rule requires banks to collect beneficial ownership information from legal entity customers at account opening. The Corporate Transparency Act established a separate regime requiring companies themselves to report beneficial ownership to FinCEN. They are distinct obligations, and a change to one does not automatically change the other.

What triggers enhanced due diligence?

The institution's own procedures define the categories, justified by its risk assessment. Common triggers are foreign correspondent accounts, private banking for non-U.S. persons, politically exposed persons, cash-intensive businesses, money services businesses, and complex or opaque ownership structures.

Can we open an account before verifying identity?

CIP requires collecting the required information before the account is opened, but verification may occur within a reasonable time after opening. The program must specify what "reasonable" means for the institution and must include procedures for what happens when identity cannot be verified — including when to close the account and whether to file a SAR.

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026