Know Your Customer, the set of procedures by which a regulated entity verifies the identity of its clients and assesses associated risks before and during a business relationship, forming a cornerstone of anti-money laundering and counter-terrorist financing compliance frameworks.

Semantic Classification

Content

  • Know Your Customer procedures require regulated entities such as banks and financial service providers to identify and verify their customers, understand the nature of their activities and assess the risk of illicit use. These procedures support anti-money laundering and counter-terrorist financing obligations.
  • KYC typically involves collecting identifying documents, screening against sanctions and politically exposed person lists, and ongoing monitoring of transactions. Requirements vary by jurisdiction and by the risk profile of the customer and product.

Current Landscape (2026)

  • The EU AML Package (adopted 30 May 2024) is reshaping KYC: the Anti-Money Laundering Authority (AMLA) became operational in Frankfurt on 1 July 2025 and, from 1 January 2026, took over all EU-level AML/CFT tasks from the European Banking Authority, ahead of direct supervision of up to ~40 high-risk cross-border institutions from 1 January 2028.
  • AMLA is due to submit roughly 23 Level 2/3 measures (RTS, ITS and guidelines) to the European Commission by 10 July 2026, including binding Regulatory Technical Standards on customer due diligence; the single-rulebook AMLR (Regulation (EU) 2024/1624) itself becomes directly applicable on 10 July 2027, lowering the occasional-transaction CDD threshold from EUR 15,000 to EUR 10,000 and standardising the UBO threshold at 25% (reducible to 15% for high-risk sectors).
  • The industry is shifting decisively from point-in-time checks to perpetual KYC (pKYC): AMLR Article 26 mandates event-driven refresh with maximum update intervals capped at one year for higher-risk and five years for other customers, moving firms toward continuous, trigger-based customer lifecycle management.
  • Deepfake and synthetic-identity fraud has become the dominant onboarding threat: FinCEN’s November 2024 alert (FIN-2024-Alert004, key term “FIN-2024-DEEPFAKEFRAUD”) flagged generative-AI bypass of KYC at scale, and FATF’s December 2025 Horizon Scan named deepfakes a direct threat to CDD controls, pushing NFC chip verification, active liveness and injection-attack detection from optional to baseline.
  • Digital identity is being formalised as the preferred verification route: the AMLR recognises eIDAS 2.0 electronic identification as equivalent to in-person checks, and CIR (EU) 2026/798 (adopted 7 April 2026) made ETSI TS 119 461 the mandatory remote-onboarding standard, with EU Digital Identity (EUDI) Wallet issuance beginning December 2026 and obliged entities required to accept it from 2027.
  • Crypto KYC tightened as MiCA’s full CASP authorisation regime applied across the EU from 30 December 2024 and the revised Transfer of Funds Regulation imposed zero-threshold Travel Rule data collection, with self-hosted wallet ownership verified by at least two methods above EUR 1,000; the US enacted the GENIUS Act in July 2025.
  • Open challenges as of 2026 include a deregulatory pull in the US (FinCEN delaying its beneficial-ownership Final Rule and BSA/CTR modernisation debates) colliding with rising financial crime, injection attacks that bypass the camera layer entirely, instant-payment fraud windows the EBA warns are ten times riskier, and extension of AML obligations to non-financial “Tranche 2” sectors (Australia from 1 July 2026, UK single professional-services supervisor).

References

Provenance