A plain-English guide to what KYC verification is, how the process actually works step by step, the laws behind it, and how AI and deepfakes are changing it in 2026.
KYC verification is the regulated process by which a bank or other obliged business confirms a customer is who they claim to be, using reliable and independent sources. It is not a one-off document scan but a lifecycle: identify the customer, verify that identity, assess their risk, and keep monitoring for as long as the relationship lasts.
KYC verification, short for Know Your Customer, is the regulated process by which a financial institution or other obliged business confirms that a customer is who they claim to be, before and during a business relationship, using reliable and independent sources. It is a set of obligations, not a single product or a one-time document check.
Under the FATF standard, the global baseline that national laws implement, the operative obligation is Customer Due Diligence (CDD) in Recommendation 10. This requires obliged entities to identify the customer and verify their identity from reliable, independent sources; identify and take reasonable measures to verify any beneficial owner; understand the purpose and nature of the relationship; and conduct ongoing due diligence throughout the relationship. "KYC" is the everyday umbrella term for this discipline. "Identity verification" (IDV) is the narrower technical step of proving a claimed identity is real and belongs to the person presenting it.
KYC matters because it is the front door to the entire anti-money-laundering system. Get it wrong and you either let criminals in, which invites fines and real harm, or you turn good customers away at onboarding and lose revenue. For the practical "how we think about running KYC" angle, see our companion piece on KYC meaning and a practical guide to Know Your Customer.
These terms are constantly conflated. Getting them straight is the fastest way to understand the field.
AML is the whole regime: risk assessment, KYC and CDD, transaction monitoring, sanctions screening, suspicious activity reporting, and record-keeping. KYC is specifically the "know who your customer is" part of that regime. CDD is the formal regulatory obligation that KYC delivers, split into simplified, standard, and enhanced tiers. CIP (Customer Identification Programme) is the US rule for the data you must collect up front. KYB (Know Your Business) verifies a legal entity and its beneficial owners, whereas KYC verifies a natural person. Onboarding a company needs both: KYB on the entity plus KYC on the individuals behind it.
A correct KYC process runs as a lifecycle, not a single gate. Each step feeds the next, and the last step loops back for as long as the customer stays with you.
Step two of the process, proving the data is real, uses three overlapping families of method.
Documentary verification captures an ID document, authenticates it (security features, machine-readable zone or chip, tamper checks), extracts the data, and matches it to the collected identity.
Non-documentary or electronic verification matches the claimed identity attributes against independent, reliable data sources. In the UK, JMLSG guidance treats a "2+2" check, matching at least two attributes such as name and address against at least two independent, reliable sources, as one accepted way to satisfy Regulation 28 electronically.
Biometric verification and liveness match a selfie to the document portrait (face match), then run a liveness or presentation attack detection (PAD) check to confirm a real, present human rather than a photo, mask, screen replay, or deepfake. PAD is standardised by ISO/IEC 30107, independent labs test to 30107-3, and the key error metrics are APCER (attacks wrongly accepted) and BPCER (genuine users wrongly rejected).
The risk score from step three sets how much diligence a customer gets. Getting the tier wrong in either direction is costly: too little on a high-risk customer invites fines, too much on a low-risk one adds friction and drop-off.
Exact requirements vary by jurisdiction and risk tier, but a standard individual KYC check typically collects the following.
US banking agencies, with FinCEN's concurrence, issued an order (27 June 2025 for OCC, FDIC, and NCUA-supervised banks, with a companion Federal Reserve order on 31 July 2025) allowing banks to collect the last four digits of a customer's tax identification number from the customer and verify the full nine-digit number through a reliable third party, rather than collecting the full number directly.
KYC is a legal requirement for regulated entities under FATF-aligned national law. The specific rulebook depends on where you operate. FATF requires CDD when establishing a business relationship, for certain occasional transactions above a threshold, on any suspicion of money laundering or terrorist financing, and where there is doubt about previously obtained identification data.
Three regulatory shifts are live right now. The EU AML package creates a single rulebook (AMLR) directly applicable across all 27 member states from 10 July 2027, and a new EU-level supervisor, AMLA, became operational on 1 July 2025 in Frankfurt. In parallel, eIDAS 2.0 and the EU Digital Identity Wallet push the regulated sector towards verify-once, cryptographically-assured credentials, with wallets available across the EU by around December 2026. In the UK, the Money Laundering Regulations 2017 remain the operative rulebook, and in the US the FinCEN CIP rule is the baseline.
Enforcement is escalating. TD Bank paid roughly 3.09 billion US dollars in October 2024 across US regulators for BSA and AML failures rooted in weak customer controls, and in the UK the FCA fined Starling Bank 28.9 million pounds (announced 27 September 2024) over financial-crime control and sanctions-screening failings. FinCEN's FY2024 Year in Review records 4.7 million suspicious activity reports and 20.5 million currency transaction reports filed, the reporting engine that KYC feeds; without knowing the customer, a report is noise.
Country risk is a moving input. FATF's grey list changed several times in 2025: its June 2025 update added Bolivia and the British Virgin Islands and removed Croatia, Mali, and Tanzania, while its October 2025 update removed Burkina Faso, Mozambique, Nigeria, and South Africa. KYC risk models therefore need refreshing on every FATF plenary.
MarketsandMarkets estimates the identity verification market at roughly 14.34 billion US dollars in 2025, forecast to reach around 29.32 billion by 2030 at about 15.4% CAGR. Market-sizing figures vary materially by research house and scope, so treat this as an illustrative estimate rather than a settled fact.
KYC is also where compliance cost and customer growth collide. Vendor research from Fenergo reports that around 67% of surveyed institutions in the UK, US, and Singapore lost prospective clients to slow or complex onboarding in 2024, and estimates abandoned KYC processes strip roughly 3.3 billion US dollars a year out of banking. More than 60% of KYC attempts happen on mobile, where failed liveness checks and unclear capture instructions drive drop-off.
As for how long verification takes, there is no single reliable benchmark. In practice, automated electronic KYC (eKYC) can complete in seconds to minutes for straightforward individuals, while complex, high-risk, or corporate cases can take days to weeks because of manual review, beneficial-ownership unwinding, and enhanced due diligence.
AI is now core to making KYC both more accurate and less painful. In verification specifically, AI is used to authenticate documents and detect forgery at scale, spotting manipulation invisible to the human eye; to match faces and detect liveness or presentation attacks, measured against ISO/IEC 30107-3 error rates; to score risk and tier CDD by combining identity attributes, country risk, product, and channel; to cut false positives in noisy sanctions, PEP, and adverse-media screening so analysts spend time on real hits; and to reduce onboarding friction, which is itself a commercial and compliance win.
Zenoo does not replace your verification vendors. It orchestrates them and adds an AI analyst layer on top of the results they return. Zenoo runs 10 specialised AI agents that assist analysts, cutting alert investigation from an industry benchmark of 22 hours to about 12 minutes and delivering a 95% reduction in false positives for most teams within 90 days (Zenoo, metrics registry). Honest agent-level capabilities include a KYC Researcher that compresses individual due-diligence research from 1 to 3 hours to under 45 seconds, a Document Classifier recognising 30+ AML and KYC document types in under 15 seconds, pre-classification of up to 80% of screening alerts, and a 209-country risk database with 16 indicators each feeding risk tiering (all Zenoo, metrics registry). These accelerate the analyst's work on top of vendor outputs; they do not perform the underlying document or biometric verification.
The same generative AI that helps defenders is now the attacker's toolkit. Vendor research from Sumsub's 2025 to 2026 report shows the overall identity fraud rate actually fell (2.6% in 2024 to 2.2% in 2025) while sophisticated multi-step attacks jumped from 10% to 28% of cases, up about 180% year on year. The threat is shifting from volume to quality.
Sumsub also reports deepfake fraud up over 1,100%, synthetic identity document fraud up more than 300% in the US, and a single largest country jump of over 2,100% in the Maldives. Injection attacks bypass the camera entirely, feeding a pre-made deepfake video stream straight into the verification pipeline, which is why ISO 30107-style PAD plus injection defence is now essential. Synthetic identity fraud, which blends real and fabricated data to create a person who does not exist but still passes checks, is a growing threat that we cover in a dedicated guide.
The Arup case (January 2024, Hong Kong) is the canonical example. An employee was deceived by a live deepfake video call impersonating the CFO and colleagues into making 15 transfers totalling around 25.6 million US dollars (HK$200m) in a single day; as of early 2025 no funds had been recovered. It shows that KYC and authentication controls cannot rely on "it looked and sounded like them". Sumsub also warns that agentic AI scams, autonomous fraud agents running whole attack chains, are poised to surge in 2026. No single verification vendor stays ahead of every attack vector, which is precisely why layered, swappable controls matter.
Several attributed forecasts point the same way.
The frame here is always "your vendors plus Zenoo", never "replace". Zenoo is a KYC, KYB, and AML orchestration platform. It does not perform document authentication, face matching, liveness or PAD, or sanctions data provision itself. Those come from specialist vendors. Zenoo's job is to connect many of them and run the workflow around them: routing checks to the right provider and failing over when one is down or returns a poor result, keeping one immutable audit trail across all providers, and letting you route by cost as well as coverage. This matters because no single vendor catches every deepfake or covers every country. The metrics registry notes the average institution already uses about 4.7 verification providers (Zenoo, metrics registry).
Zenoo does not decide whether a passport is genuine, whether a selfie is live, or whether a face matches; that is the underlying IDV or biometric vendor's job, and Zenoo orchestrates and records those decisions. Zenoo does not replace your legal obligation to run a compliant CIP and CDD programme or to file reports; it helps you operate it. Zenoo does not itself provide sanctions, PEP, or adverse-media data; it connects to providers that do. And Zenoo is not a magic deepfake detector; defeating deepfakes and injection attacks depends on the specialist detection vendors Zenoo routes to, plus keeping that roster swappable so you can add the best detector as threats evolve.
Zenoo orchestrates your KYC, KYB, and AML vendors behind one workflow: routing checks to the right provider, failing over when one is down, and keeping a single audit trail across all of them. Your vendors plus Zenoo, not a replacement.