Zenoo
Learn/KYC requirements for banks: the four pil…
Guide

KYC requirements for banks: the four pillars, the rules, and 2026 changes

What a bank actually has to do to be KYC-compliant, step by step, and which laws impose it in the US, EU, and UK.

Last reviewed 8 April 202616 min read
In shortThe answer, first

A bank's KYC requirements are the legal duties to identify its customers, understand each relationship, and monitor it for the life of the account. They rest on four repeating pillars: customer identification, beneficial ownership, risk profiling, and ongoing monitoring, with enhanced checks for higher-risk cases. The specific rules vary by jurisdiction but trace back to FATF Recommendation 10.

Key facts
  • KYC is risk-based, not a single checklist, and applies for the entire life of an account, not just at onboarding.
  • The US CDD Rule (effective 11 May 2018) codifies four elements: identification, beneficial ownership, risk profiling, and ongoing monitoring.
  • The 25 per cent beneficial ownership threshold is common in US and incoming EU rules, but banks must go lower on a risk-sensitive basis.
  • In 2024 global AML enforcement fines reached about 4.6 billion US dollars, with TD Bank alone paying 3.09 billion US dollars.
  • FinCEN granted banks relief in February 2026 from re-verifying beneficial owners at every new account opening.
  • The EU AMLR (Regulation 2024/1624) applies from 10 July 2027, replacing the patchwork of directives with one rulebook.

What KYC means for a bank (and how it differs from AML)

KYC, short for know your customer, is the set of legal and regulatory obligations a bank must meet to identify who its customers are, understand the purpose and risk of each relationship, and monitor it for as long as the account is open. In the United States regulators wrap these duties under the term Customer Due Diligence (CDD); in the EU and UK they sit under the money laundering regulations; globally the standard-setter is the Financial Action Task Force (FATF), whose Recommendation 10 is the source text most national rules trace back to.

KYC is not the same as anti-money laundering (AML). KYC is one component of a bank's wider AML programme, which also covers transaction monitoring, sanctions screening, suspicious activity reporting, and governance. Put simply, KYC is where a bank meets its AML duty at the level of the individual customer relationship.

Common misconception
KYC is not a one-time check at onboarding
KYC is a box a bank ticks when it opens an account, then forgets.
Ongoing monitoring is a named pillar. KYC is a lifecycle obligation that runs for the life of the account, which is exactly why perpetual KYC (pKYC) exists.

The four pillars of bank KYC (CDD)

FinCEN's 2016 CDD Final Rule, effective for compliance from 11 May 2018, codified four minimum elements that a US bank's programme must contain. The same four ideas recur across the UK and EU regimes because they all trace back to FATF Recommendation 10.

1. Customer identification (CIP)

Introduced by the USA PATRIOT Act and in force since 2003, the Customer Identification Program rule requires a bank to collect at minimum four data points before opening an account: name, date of birth, address, and an identification number (for a US person, usually a Social Security or taxpayer number). The bank must then verify identity to a reasonable belief using documentary methods (a passport or driving licence), non-documentary methods (database and electronic checks), or both, and screen the customer against sanctions lists such as OFAC.

2. Beneficial ownership identification

For legal entity customers such as companies, LLCs, and partnerships, the bank must identify the natural persons behind the entity. The CDD Rule set two prongs: any individual who owns 25 per cent or more of the entity (the ownership prong) and one individual with significant control such as a CEO or managing member (the control prong). This is the pillar most changed by recent US policy.

3. Customer risk profiling

The bank must understand why the account exists and what normal activity should look like, then assign a risk rating from low to high. That profile becomes the baseline against which future behaviour is judged.

4. Ongoing monitoring

The bank must monitor transactions for suspicious activity, file Suspicious Activity Reports (SARs) where warranted, and keep customer information current on a risk-based schedule. To show the scale of this pillar in practice, US institutions filed 4.7 million SARs and 20.5 million Currency Transaction Reports in the 2024 financial year.

The four pillars of bank KYC
Effort scales with risk across three intensity levels underneath.
A compliant bank KYC programme
Four pillars, all tracing to FATF Recommendation 10
PILLAR 1
Customer identification (CIP)
Name, date of birth, address, ID number, then verify and screen.
PILLAR 2
Beneficial ownership
Identify the natural persons behind an entity, 25% and control prongs.
PILLAR 3
Risk profiling
Understand purpose and expected activity; assign a risk rating.
PILLAR 4
Ongoing monitoring
Watch transactions, file SARs, keep information current for the life of the account.
Matching effort to risk
Simplified
Low risk, documented
Standard
Most customers, the four pillars
Enhanced
PEPs, high-risk, complex; senior sign-off

SDD, CDD, and EDD: matching effort to risk

KYC is risk-based, not one-size-fits-all. Under FATF Recommendation 10, a bank dials the intensity of its checks up or down with the risk of the customer and the relationship. There are three broad intensity levels.

LevelWhen it appliesWhat it adds
Simplified (SDD)Demonstrably low-risk customers, with the bank documenting its reasoningLighter checks than standard CDD, applied where risk is genuinely low
Standard (CDD)The majority of customersThe four pillars: identification, beneficial ownership, risk profiling, and ongoing monitoring
Enhanced (EDD)Politically exposed persons, high-risk third countries, complex ownership, correspondent bankingSource-of-funds and source-of-wealth checks, adverse media screening, senior sign-off, more frequent review
Note
Where EDD is triggered

Enhanced due diligence is not optional for the cases that trigger it. A bank must apply EDD to politically exposed persons, customers in high-risk jurisdictions, and unusually complex structures. See what is due diligence for how these tiers fit together.

KYC vs KYB: verifying business customers and UBOs

For business customers, banks perform Know Your Business (KYB) alongside KYC. KYB verifies the company's registration, legal status, and structure, then drills into the ultimate beneficial owners (UBOs) and runs KYC on each of them. This is where onboarding gets slow, because ownership chains cross registries and jurisdictions, and each layer of a corporate structure can hide another entity.

The practical rule is that KYB establishes the entity and its control chain, while KYC establishes the identity and risk of the humans at the end of that chain. A bank cannot claim it knows its business customer until it has resolved the ownership graph and screened the people behind it.

The rules by jurisdiction: US, EU, and UK

The four pillars are globally consistent, but the specific statutes, thresholds, and supervisors differ. Here is how the three major regimes line up as of 2026.

JurisdictionCore instrumentsRegulatorKey 2025 to 2026 change
United StatesBSA, USA PATRIOT Act (CIP), 2016 CDD RuleFinCENFebruary 2026 relief from re-verifying beneficial owners at every account opening
European UnionAML Regulation (EU) 2024/1624 (the AMLR)AMLA (Frankfurt), operational 1 July 2025One directly applicable rulebook, applies from 10 July 2027
United KingdomMoney Laundering Regulations 2017, JMLSG guidanceFCAPOCA threshold raised from 1,000 to 3,000 pounds, effective 31 July 2025

Where we are now (2025 to 2026)

The rulebook that governs bank KYC changed materially across 2025 and into 2026 in all three major regimes.

United States: beneficial ownership relief

On 13 February 2026 FinCEN issued an order granting banks, mutual funds, brokers, and dealers relief from the CDD Rule requirement to re-identify and re-verify beneficial owners of a legal entity customer at every new account opening. Under the order, covered institutions may now limit beneficial ownership identification and verification to three circumstances: when the entity first opens an account, when the institution has knowledge of facts that call the previously obtained information into question, and as needed under its risk-based ongoing CDD procedures. FinCEN framed this as a risk-based efficiency measure that does not weaken the BSA framework. An earlier 2025 order also gave banks an optional method to satisfy identity verification using reliable third-party sources rather than always collecting the taxpayer number directly from the customer.

European Union: the AML package and AMLA

The EU replaced its patchwork of directives with a single, directly applicable AML Regulation (Regulation (EU) 2024/1624, the AMLR), which entered into force on 9 July 2024 and applies from 10 July 2027. This is a structural shift from minimum-harmonisation directives that each member state transposed differently, to one rulebook applied identically across the bloc. Alongside it, the new EU Anti-Money Laundering Authority (AMLA) in Frankfurt became operational on 1 July 2025 and will begin direct supervision of selected high-risk cross-border institutions from 2028. Concrete AMLR changes include a harmonised 25 per cent beneficial ownership threshold with standardised register data, a bloc-wide 10,000 euro limit on cash payments for goods and services, a ban on anonymous crypto accounts, and full CDD by crypto-asset service providers on any occasional transaction of 1,000 euro or more.

United Kingdom: MLRs, the FCA, and JMLSG

The UK operates under the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, supervised for banks by the FCA, with Joint Money Laundering Steering Group (JMLSG) guidance treated as the practical standard firms take account of. Among the 2025 updates, the Proceeds of Crime threshold was raised from 1,000 to 3,000 pounds with effect from 31 July 2025. UK enforcement stayed active: Starling Bank was fined about 29 million pounds for sanctions-screening and high-risk-account failings, and Monzo was fined about 21 million pounds in July 2025 for serious AML control failings that ran from October 2018 to June 2022 (the 21 million pound figure reflects a settlement discount on a higher headline penalty).

The cost and false-positive problem

KYC is expensive and error-prone, which is why so much of the market is built around fixing it. Industry estimates put per-customer KYC review at between 1,500 and 3,500 US dollars, with some large institutional banks spending up to 35 million US dollars a year to onboard 10,000 clients. Large institutions face AML alert false-positive rates as high as 95 per cent, a figure widely attributed to Accenture, McKinsey, and ACAMS.

The commercial cost is just as real. Fenergo's 2024 research found that 67 per cent of surveyed institutions in the UK, US, and Singapore had lost clients to slow onboarding. Meanwhile the RegTech market that sells the fix keeps growing: industry estimates put cloud spend on AML and KYC data and services at about 2.9 billion US dollars in 2025, with the KYC and AML software market projected to exceed 3.2 billion US dollars by 2028 at roughly 19.4 per cent CAGR. Treat these market-size figures as vendor and analyst estimates rather than settled fact.

Latest trends in bank KYC

  • From periodic reviews to perpetual KYC. The ongoing-monitoring pillar is being operationalised as continuous, event-driven review rather than a calendar-based refresh every one to three years.
  • Convergence then divergence. The EU is centralising onto one rulebook and one supervisor while the US is loosening a specific beneficial-ownership burden, so cross-border banks must run one control framework that flexes by jurisdiction.
  • Digital identity enters the rulebook. eIDAS 2 and the European Digital Identity Wallet in Europe, and FinCEN's explicit airtime for digital identity in the US, signal that reusable, government-anchored digital ID is becoming a first-class KYC input.
  • Automation becomes the default. Industry projections put around 70 per cent of new-account onboarding as fully automated by 2026, using biometrics, digital identity verification, and analytics.
  • The threat side is industrialising in parallel. FATF's December 2025 Horizon Scan now names deepfakes as a tool that can bypass CDD and digital-ID verification at onboarding.

A practical bank KYC checklist

A bank KYC programme runs from onboarding through to continuous monitoring. The steps below map the four pillars into an operational sequence.

  1. 1Collect the minimum CIP data: name, date of birth, address, and an identification number for each customer.
  2. 2Verify identity to a reasonable belief using documentary or non-documentary methods, and screen against sanctions lists such as OFAC.
  3. 3For entity customers, resolve the ownership chain and identify beneficial owners at the 25 per cent threshold, plus one person with significant control.
  4. 4Understand the purpose and expected activity of the relationship, then assign a risk rating from low to high.
  5. 5Apply enhanced due diligence where the customer is a PEP, sits in a high-risk jurisdiction, or has a complex structure.
  6. 6Monitor transactions and behaviour continuously, file Suspicious Activity Reports where warranted, and refresh customer information on a risk-based schedule.
  7. 7Keep an auditable record of every check, decision, and data source so an examiner can reconstruct the file.

How AI helps with bank KYC

AI is used defensively across every KYC pillar, and this is where a genuine efficiency story lives. Machine-learning models classify and authenticate identity documents and pair them with biometric liveness. AI pre-classifies sanctions, PEP, and adverse-media alerts to cut the false-positive load. It cross-references company registries to assemble ownership graphs, and it watches continuously for the unusual activity that ongoing monitoring is meant to catch.

Independent reporting describes agentic onboarding cutting KYC and AML review times by up to 60 per cent, with 80 to 90 per cent faster onboarding for standard-tier customers. A more grounded first-year return is roughly a 20 to 35 per cent reduction in analyst time on back-office case work, so treat the headline figures as best-case vendor claims rather than guaranteed outcomes.

AI on the defender’s side
Where Zenoo's AI genuinely applies

Zenoo runs 10 specialised AI agents that sit across the workflow rather than replacing a bank's verification vendors. A KYB Researcher compiles a structured company dossier of 50 or more fields in under 60 seconds versus 2 to 4 hours manually. A KYC Researcher completes individual due diligence in under 45 seconds versus 1 to 3 hours. An alert pre-classification agent dispositions screening alerts in 2 to 3 minutes versus 20 to 45 minutes, pre-classifying up to 80 per cent with high confidence. At the programme level, Zenoo cites investigation time falling from an industry benchmark of 22 hours to 12 minutes, and up to a 95 per cent reduction in false positives within 90 days. These are Zenoo's own measured or benchmarked figures.

How AI is abused against bank KYC

The same generative AI is being weaponised against the identity-verification step, and the evidence is concrete. In January 2024 an Arup finance worker in Hong Kong was tricked on a video call in which the CFO and colleagues were all deepfakes, and executed 15 transfers totalling 25.6 million US dollars in a single day. In the Netherlands, police reported in December 2025 a suspect who used stolen documents and deepfake facial manipulation to open 46 bank accounts in other people's names. Bank of Italy governor Fabio Panetta cited data in July 2025 that roughly 250 of 500,000 new online accounts were fake accounts opened using deepfakes or false identities.

The tooling is cheap and packaged. ProKYC, identified by Cato Networks in October 2024, bundled a virtual camera, emulator, facial animation, and verification-photo generation into one anti-KYC platform sold at about 629 US dollars a year. Later reporting put a verification-passing AI face at under 20 US dollars. Injection attacks that alter the video feed at the API level, so standard liveness never sees the real camera, are rising fast: iProov reported a 1,151 per cent year-on-year rise in iOS injection attacks in the second half of 2025. Synthetic identity fraud, which blends real and fabricated data specifically to pass KYC, is called the fastest-growing financial crime in the US by the Federal Reserve, with estimated annual losses of roughly 20 to 40 billion US dollars.

AI as the threat
A single vendor's liveness model is a single point of failure

KYC's identity-verification pillar is now an adversarial contest. Presentation attacks fool a camera with a deepfake; injection attacks bypass the camera entirely. FATF's December 2025 Horizon Scan explicitly names deepfakes as capable of bypassing AML controls, CDD systems, and digital-ID verification. When one liveness detector is the only line of defence, an attacker only has to beat one model. See deepfake detection in KYC and synthetic identity fraud.

What the future looks like

  • US risk-based simplification continues. The February 2026 beneficial-ownership relief and the 2025 third-party identity exemption point to reducing repetitive burden while keeping the four pillars, with digital identity given explicit standing.
  • The EU single rulebook bites, then central supervision follows. The AMLR applies from 10 July 2027 and AMLA begins direct supervision of selected cross-border institutions from 2028, giving banks a hard deadline to converge.
  • Perpetual KYC becomes the operating model. Periodic refresh cycles give way to event-driven, continuous CDD, enabled by AI and reusable digital identity.
  • The identity arms race escalates. With deepfake and injection attacks rising in four-figure percentages and fraud-as-a-service commoditised, banks will move from single-vendor liveness to layered, continuously re-tested defences, and regulators are likely to move from acknowledging deepfakes toward explicit expectations on injection-attack resistance.

Where orchestration fits: your vendors plus Zenoo

Zenoo is a KYC, KYB, and AML compliance orchestration platform. It does not replace a bank's verification vendors; it connects many of them behind one workflow, one policy engine, and one audit trail. The honest framing is your vendors plus Zenoo.

Because bank KYC now depends on multiple providers (an industry figure of about 4.7 verification providers per institution), Zenoo routes each check to the right vendor and fails over when one is down or returns low confidence, running checks in parallel. That directly strengthens the identity-verification pillar against the single-point-of-failure risk above. Zenoo's Policy Parser turns a written policy into 15 to 20 structured risk rules in under 5 minutes, and its 209-country risk database (16 indicators per country, including FATF grey and black-list status) supports the risk-profiling pillar and EDD triggers. For recordkeeping, 32 immutable audit event types across 8 categories give examiners one evidence record spanning every vendor.

Be clear about what Zenoo does not do. It does not itself verify a passport, run a facial-liveness scan, or maintain a sanctions list; those come from the bank's chosen vendors. It does not make a bank compliant on its own, because compliance is the bank's regulatory obligation. It is not a deepfake detector, though it can route to and fail over between best-in-class liveness and injection-attack detectors and combine their signals. And it does not remove the need for human analysts or a designated compliance function; it reduces manual load and speeds disposition.

Honest scope
What Zenoo does not solve

Zenoo orchestrates the checks; it is not the verification vendor, not the sanctions list, and not the liveness model. It helps a bank execute and evidence its KYC programme, but the regulatory obligation and the underlying detection models stay with the bank and its chosen providers.

Key takeaways
  • KYC is risk-based, not a single checklist, and applies for the entire life of an account, not just at onboarding.
  • The US CDD Rule (effective 11 May 2018) codifies four elements: identification, beneficial ownership, risk profiling, and ongoing monitoring.
  • The 25 per cent beneficial ownership threshold is common in US and incoming EU rules, but banks must go lower on a risk-sensitive basis.
  • In 2024 global AML enforcement fines reached about 4.6 billion US dollars, with TD Bank alone paying 3.09 billion US dollars.
  • FinCEN granted banks relief in February 2026 from re-verifying beneficial owners at every new account opening.
  • The EU AMLR (Regulation 2024/1624) applies from 10 July 2027, replacing the patchwork of directives with one rulebook.

Frequently asked questions

What are the four pillars of KYC for banks?

The four pillars, codified in the US CDD Rule, are customer identification and verification (CIP), beneficial ownership identification for entity customers, understanding the nature and purpose of the relationship to assign a risk profile, and ongoing monitoring of transactions and customer information for the life of the account.

What is the difference between CIP, CDD, and EDD?

CIP is the identification step: collecting and verifying name, date of birth, address, and an ID number. CDD is the full standard programme across all four pillars for most customers. EDD is the enhanced level applied to higher-risk cases such as PEPs, adding source-of-funds checks, adverse media screening, and senior sign-off.

What documents do banks require for KYC?

At minimum a bank collects name, date of birth, address, and an identification number. It verifies identity using documentary methods such as a passport or driving licence, non-documentary methods such as database and electronic checks, or both. Entity customers must also supply registration details and beneficial ownership information.

Did the beneficial ownership rule for banks change in 2026?

Yes. On 13 February 2026 FinCEN issued an order letting banks limit beneficial ownership identification to three circumstances: when an entity first opens an account, when facts call earlier information into question, and as needed under risk-based ongoing CDD. Banks no longer have to re-verify beneficial owners at every new account opening.

What laws require KYC in the US, EU, and UK?

In the US, the Bank Secrecy Act, the USA PATRIOT Act (CIP), and FinCEN's 2016 CDD Rule. In the EU, the AML Regulation (EU) 2024/1624, which applies from 10 July 2027, supervised by the new AMLA. In the UK, the Money Laundering Regulations 2017, supervised by the FCA with JMLSG guidance.

What is the difference between KYC and AML?

KYC is one component of a bank's broader AML programme. KYC focuses on identifying customers and monitoring their relationships. AML is the wider framework that also covers transaction monitoring, sanctions screening, suspicious activity reporting, and governance. A bank meets much of its AML duty at the customer level through KYC.

What happens if a bank fails KYC requirements?

Enforcement is expensive and public. Global AML fines reached about 4.6 billion US dollars in 2024, with TD Bank paying 3.09 billion US dollars. In the UK, Starling was fined about 29 million pounds and Monzo about 21 million pounds in July 2025. Inadequate KYC was among the most frequently cited failures.
ZenooWhere this fits, honestly

Zenoo connects your KYC, KYB, and AML vendors behind one workflow, one policy engine, and one audit trail. Your vendors plus Zenoo: routing, failover, and continuous monitoring, with 10 specialised AI agents pre-investigating the work your analysts do by hand.

Sources

Last reviewed 8 April 2026. Every statistic is traceable to a named source.
  1. 01FinCEN: Customer Due Diligence (CDD) Final Rule
  2. 02Federal Register: Customer Due Diligence Requirements for Financial Institutions (2016)
  3. 03Moody's: Four requirements of customer due diligence for banks
  4. 04FATF: The FATF Recommendations (Recommendation 10)
  5. 05Mayer Brown: FinCEN grants risk-based relief from repeat beneficial ownership verification (February 2026)
  6. 06Signicat: AMLR explained: what changes in 2027
  7. 07Cryptobriefing: EU 10,000 euro cash cap and 2027 AML regulation
  8. 08FCA: FCA fines Monzo 21m for financial crime control failings
  9. 09JMLSG: Guidance Part I (June 2023, updated August 2025)
  10. 10ComplyAdvantage: The biggest AML fines
  11. 11CNN Business: Arup revealed as victim of 25m deepfake scam
  12. 12American Banker: How the Fed aims to help banks spot synthetic identity fraud
  13. 13Biometric Update: Deepfake-as-a-service and identity fraud report
  14. 14BCG: The know your customer agentic AI revolution
  15. 15Neontri: KYC tools for banks (cost and market data)
Was this helpful?
Share