KYC (Know Your Customer)
Also known as: Know Your Customer · Customer Identification Program · CIP · Customer due diligence · CDD
The process of identifying and profiling a customer — confirming who they are, assessing their risk and keeping that current — before and throughout the relationship.
Legal basis
31 CFR 1020.220 (Customer Identification Program)
KYC has three layers: identify (the person exists and is who they claim to be), profile (what their expected activity and risk are) and monitor (their behavior stays consistent with that profile). When the customer is a company, the same process is called KYB.
For US banks, the first layer is the Customer Identification Program rule. Before opening an account, a bank must obtain at minimum the customer's name, date of birth, address and an identification number — a taxpayer ID for US persons — and verify the identity through documents, non-documentary methods or both. The customer due diligence rule adds the rest: understand the nature and purpose of the relationship to build a risk profile, and conduct ongoing monitoring to report suspicious activity and keep information current.
Traditional KYC happens once, at account opening. Fraud does not: synthetic identities pass onboarding, and straw buyers pass any document check. That is why the trend is continuous KYC, which keeps observing the customer after they are in.
Frequently asked questions
What information is required for KYC?
For US bank accounts, the CIP rule requires at minimum name, date of birth, address and an identification number, which for a US person is a taxpayer identification number such as an SSN. The bank must then verify that information.
What is the difference between KYC and CIP?
CIP is the regulatory minimum for identifying and verifying a customer at account opening. KYC is the broader practice, which also covers understanding the customer's risk and monitoring the relationship over time under the customer due diligence rule.