Skip to content
KEDBYTE
How Identity Works
Chapter
49

Know Your Customer

Part V · Identity, Society and the Law|11,987 words|about 52 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

49.0 What this chapter gives you#

  1. You will be able to explain why a bank asks for your documents, and name the international body whose rules made it do so.
  2. You will be able to state what customer due diligence requires, item by item, and say when a firm may do less and when it must do more.
  3. You will be able to work out the beneficial owners of a layered company using the 25 per cent test and the multiplication rule, showing your arithmetic.
  4. You will be able to define a politically exposed person in the three categories the standard uses, and say how long the status lasts in Europe and what the global standard says instead.
  5. You will be able to describe how sanctions screening works, name the real list sources and formats, and explain why almost every alert is wrong.
  6. You will be able to set a periodic review cycle from a customer’s risk rating, and say what triggers a review before the cycle is due.
  7. You will be able to compare video, document plus liveness and database verification, and say which regulator permits which.
  8. You will be able to describe India’s Aadhaar-based electronic KYC, what the 2018 Supreme Court judgment did to it, and what is lawful today.
  9. You will be able to quote real figures for what this system costs and how many people it locks out.
  10. You will be able to read a KYC file and tell whether it would survive a supervisor’s inspection.

Almost every identity check you have ever passed exists because of a rule written for banks. The passport photograph a mobile network wanted, the selfie a cryptocurrency exchange asked for, the utility bill a landlord demanded, the video call a stockbroker made you sit through: none of these were invented by the companies that asked for them. They are copies, some faithful and some careless, of obligations that governments placed on financial institutions to make crime harder to bank.

That set of obligations is called know your customer, usually shortened to KYC. It is part of a larger framework called anti-money laundering, or AML, the body of law designed to stop criminals turning the proceeds of crime into money that looks clean. KYC is the identity part of it, and it says, in effect: before you take this person’s money, find out who they are, write it down, keep the record, and keep watching.

This matters far beyond banking, because KYC was the first identity verification system that had to work at population scale, under legal compulsion, with an auditor checking. Everything that came later, digital identity wallets, online age checks, remote onboarding for insurance and telecoms and gambling, inherited its vocabulary, its risk-based structure, its document lists, its retention periods and its failure modes. When a modern identity product talks about assurance levels, liveness detection, document authenticity and ongoing monitoring, it is speaking a language compliance officers wrote first.

This chapter explains that system from the bottom. We start with the plain idea, follow it to where it misleads, then set out the real rules with their numbers, article references and dates, carrying one company through the whole process from application to periodic review. At the end we count the cost, both the money the industry spends and the people it leaves outside, because a chapter describing only the machinery and not its casualties would be dishonest.

The plain version#

The club with a doorman#

Imagine a private club. Anyone may apply to join, and the club is happy to have members, because members pay fees and the club lives on fees. But the town council has told the club it will be shut down and fined if it lets thieves use its back rooms to divide up stolen goods.

The club cannot read minds and cannot tell a thief from an honest person by looking. So it does the only thing it can: it puts a doorman at the entrance with a ledger and gives him three instructions.

The first instruction is: find out who this person is. Not their reputation, but their name, their date of birth and where they live, checked against something official they did not make themselves. A letter from their mother does not count. A passport does.

The second instruction is: find out what they intend to do here. A member who says they will come for lunch twice a month is a different proposition from one who will host weekly parties for forty guests from out of town. Write down what they say, because the point of writing it down is to notice later if reality does not match.

The third instruction is: keep watching. Membership is not a moment, it is a relationship. If the lunch-twice-a-month member starts arriving at three in the morning with crates, that is worth a look, and the only way to know it is odd is to have written down what normal was supposed to be.

That is the whole of KYC. Identify, understand, monitor. Everything else is detail about how hard to look, at whom, and how often.

What the doorman actually writes down#

Let us be concrete. Meera Nair walks into a bank branch in Kochi and asks to open a savings account. What the bank must collect is not mysterious: her full name, date of birth, address, and a document a serious institution issued that ties a face to a name. In India that might be a passport, a driving licence, a voter identity card, or proof of possession of an Aadhaar number. In Ireland it would be a passport or national identity card plus something showing where she lives. In the United States it would be name, address, date of birth and a taxpayer identification number.

The bank does two separate things with that. First it identifies her, meaning it records the claimed facts. Then it verifies them, meaning it checks those facts against a source Meera does not control. The two steps are genuinely different and people confuse them constantly. Writing “Meera Nair, born 14 March 1991” on a form is identification. Holding her passport up to the light, or asking the government’s database whether that number belongs to that name and face, is verification.

Then the bank asks what the account is for. Meera says salary and household expenses, roughly forty thousand rupees a month in, most of it out again within the month. That sentence is now the yardstick. If in eighteen months the account receives eleven separate deposits of nine lakh rupees each from strangers, the bank has something to compare against, and something to explain if it did nothing. Then it keeps watching, quietly and mostly by computer, for the rest of the relationship.

The three sizes of check#

Not every member is worth the same amount of the doorman’s time. A retired schoolteacher joining to play bridge on Tuesdays is not the same risk as a stranger with a suitcase of cash and no explanation. So the rules both let the club and require it to vary the depth of the check, and there are three settings.

The middle setting is the normal one, just described: identify, verify, understand the purpose, monitor. That is standard due diligence, or just customer due diligence.

The low setting applies where the risk is genuinely small: a small government-backed savings account for a low-income customer, a pension that cannot be cashed in early, a regulated bank opening an account with another regulated bank. Here the rules allow the club to do less, later, or with fewer documents. This is simplified due diligence, and simplified does not mean skipped. The doorman still writes the name in the ledger; he just may not send someone to check the address this week.

The high setting applies where the risk is obviously greater: someone connected to a country with weak controls, someone whose ownership is buried under four holding companies, someone who holds or held serious political power, someone whose business handles a great deal of cash. Here the club must do more: more documents, senior approval, an explanation of where the money came from, closer watching afterwards. This is enhanced due diligence.

The whole system is built on that dial. Regulators almost never say “do exactly this for everyone”. They say “assess the risk, act in proportion to it, and be able to show us your reasoning”. That last clause shapes the industry, because a defensible file matters as much as a correct decision.

Two customers, not one#

There is one more idea, the one non-specialists find strangest. When a company opens an account, the bank has to know two things: the company, and the humans behind it.

A company is a legal person. It has a name, a registration number and an address, and it can hold money. But a company cannot go to prison or enjoy a yacht. Somewhere behind it is a human being who ultimately owns or controls it and benefits from what it holds. That person is the beneficial owner, and finding them is the hardest and most gamed part of the process, because criminals do not open accounts in their own names. They open them for a company owned by another company in another country owned by a third whose director is a professional nominee who has never met anyone involved. Each layer is legal. The stack is the crime. So the rules force the bank to climb the stack until it reaches a human.

The doorman does not decide guilt#

Finally, the part almost everyone misunderstands: the doorman is not deciding whether you are a criminal. He is neither qualified nor asked to. He is building a record so that if something goes wrong later there is a name attached to the money, and so the pattern of an account can be compared with what it was supposed to be. The purpose of KYC is not conviction; it is traceability and deterrence. That distinction explains much behaviour that otherwise looks irrational, including why a bank will close your account without telling you why.

Where the plain version stops being true#

The club analogy hides who is really giving the orders#

In the analogy the town council tells the club what to do. In reality no single council exists. The rules come from an intergovernmental body with no treaty power, are turned into law by individual countries at different speeds and in different words, and are enforced by national supervisors with very different appetites. A bank operating in eleven countries follows eleven overlapping rules, and usually applies the strictest one everywhere because that is cheaper than eleven processes.

The honest version: there is no global KYC law. There is a global standard that almost every country has copied, and the copies differ in ways that matter. A verification method fully lawful in Germany may be unacceptable in France. Build an identity product assuming one rule and you will ship something illegal somewhere.

“Verified” is a claim about a moment, not a state#

The plain version implies that once the doorman has checked you, you are checked. Documents expire. People move. Companies restructure. Someone who was nobody in particular in 2019 may be a deputy minister in 2026, and a shareholder who held 20 per cent may have bought another 10.

The honest version: KYC is not a gate, it is a subscription. The rules require ongoing due diligence, meaning keeping documents and information up to date and reviewing the relationship, and re-examination whenever something changes. The industry expresses this as a review cycle measured in years, which we set out precisely later, but the cycle is a floor and not a schedule: any trigger event, a change of ownership, a sudden change in behaviour, a news story, pulls the review forward.

The person named as owner is frequently not the owner#

The plain version says the bank climbs the stack until it reaches a human. In practice the climb often stops early, for a legally sanctioned reason. Every major framework has a fallback: if, after exhausting all reasonable means, a firm cannot identify a natural person who owns or controls the entity, it may record the senior managing official instead. That is a sensible safety valve for genuinely diffuse ownership. It is also a well-known escape hatch, because a structure designed to be opaque produces exactly the conditions in which the fallback applies, and the file then names a professional director who knows nothing.

The honest version: the 25 per cent test is a threshold, not a truth. Someone determined to stay off the file holds 24 per cent through each of five chains, or uses a nominee, or uses control mechanisms that are not shareholdings at all. These rules raise the cost of hiding; they do not make hiding impossible.

A name is not an identity, and a sanctions list is a list of names#

The plain version implies the doorman has a list of banned people and checks it. He has a list of names, dates of birth, passport numbers of varying completeness, and many aliases transliterated from other scripts. Matching against it is not a lookup but fuzzy string comparison across scripts and spellings, and it fails in both directions: tighten the threshold and you miss a listed person who spells their name differently, loosen it and you stop thousands of innocent people who share three letters with an entry.

The honest version: sanctions screening is a statistical process with a tunable error trade-off. The overwhelming majority of alerts are wrong, and the industry accepts that because one miss costs far more than ten thousand false alarms. That asymmetry is deliberate policy, and its cost falls mostly on people with common names, names from non-Latin scripts, and names shared with sanctioned individuals.

The identity check that is free for the bank is not free for you#

The plain version treats the check as a small friction. For most readers of this book it is. For a great many people it is a wall. If you have no permanent address, no utility bill in your own name, no passport and no birth certificate, a system built on documents cannot verify you however honest you are. And as rules tighten, banks conclude that whole categories of customer, certain corridors, certain remittance businesses, are not worth the compliance cost, and exit them. That is de-risking, and its victims are the customers of the businesses that got dropped.

The honest version: KYC has a measurable exclusion cost, and it falls on the poor, the displaced and the undocumented. Any honest account has to hold two facts at once: this system exists for good reasons, and it does real harm to people who did nothing.

Cleanliness is not what is being measured#

The plain version suggests the system stops dirty money. The evidence is weaker than the size of the system implies. The United Nations Office on Drugs and Crime puts the amount laundered globally at 2 to 5 per cent of world output each year, roughly 800 billion to 2 trillion United States dollars. Those figures have been quoted for well over a decade and are estimates built on estimates; what is not disputed is that the amount seized is a very small fraction of any of them.

The honest version: the effectiveness of AML as a crime-reduction programme is genuinely contested, and this is a place where experts disagree. One camp argues it is a costly ritual producing paperwork rather than convictions. The other argues its value is deterrent and evidential rather than interdictive, making large-scale laundering expensive and awkward and leaving a trail that prosecutions depend on. Both can point to real evidence. No one credible claims the current system stops most laundering.

The technical version#

The machine that wrote the rules#

The Financial Action Task Force, universally called FATF, was created by the Group of Seven summit held in Paris in 1989 and issued its first Forty Recommendations in 1990. It has no treaty behind it and cannot make law anywhere. Its power comes from mutual evaluation, in which member countries assess each other against the standard and publish the result, and from listing, in which countries with serious deficiencies go on public lists that the market reads as a warning.

The current standard, formally the International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation, was adopted on 16 February 2012 and amended repeatedly since; as of August 2026 the FATF website states it was last updated in June 2026. The amendment history matters because practitioners cite recommendation numbers as though they were stable, and the text under those numbers moves.

Date What changed
Oct 2021 R.23, group-wide DNFBP duties
Mar 2022 R.24, beneficial ownership
Feb 2023 R.25, legal arrangements
Oct 2023 R.4, 30, 31, 38 asset recovery
Feb 2025 R.1, R.10, R.15, glossary
Jun 2026 R.6, humanitarian carve-outs

The February 2025 revision is the most important recent one here. It amended Recommendations 1, 10 and 15, the Introduction and the Glossary, with the explicit aim of promoting financial inclusion by strengthening the requirement that measures be proportionate to risk and making simplified measures easier to apply in demonstrably lower-risk situations, and the Interpretive Note to Recommendation 10 was further updated in June 2025. At the plenary of 17 to 19 June 2026 in Paris, FATF revised Recommendation 6 to carry through the humanitarian exemptions in United Nations Security Council resolutions 2664 and 2761, approved a consultation on strengthened Recommendation 16 guidance on payment transparency, added Bosnia and Herzegovina and Iraq to the list of jurisdictions under increased monitoring, and removed Algeria and Namibia.

The listing power is not symbolic. International Monetary Fund working paper WP/21/153, by Mizuho Kida and Simon Paetzold, published in 2021 and titled “The Impact of Gray-Listing on Capital Flows: An Analysis Using Machine Learning”, found grey-listing associated with a fall in capital inflows of about 7.6 per cent of gross domestic product, of which roughly 3.0 percentage points was foreign direct investment, 2.9 portfolio flows and 3.6 other investment. That is why finance ministries treat FATF assessments as binding in practice despite their lack of legal force.

Recommendation 10 in detail#

Recommendation 10 is the load-bearing text of this chapter. It prohibits anonymous accounts and accounts in obviously fictitious names, then requires customer due diligence when establishing business relations, when carrying out occasional transactions above the designated threshold, which the Interpretive Note sets at USD or EUR 15,000, when carrying out occasional wire transfers covered by Recommendation 16, when there is a suspicion of money laundering or terrorist financing regardless of any exemption or threshold, and when there are doubts about previously obtained identification data.

The measures are four, and worth learning in order, because every national rule is a translation of them.

  1. Identify the customer and verify that customer’s identity using reliable, independent source documents, data or information.
  2. Identify the beneficial owner and take reasonable measures to verify that person’s identity, such that the institution is satisfied it knows who the beneficial owner is; for legal persons and arrangements this includes understanding the ownership and control structure.
  3. Understand and, as appropriate, obtain information on the purpose and intended nature of the business relationship.
  4. Conduct ongoing due diligence and scrutiny of transactions throughout the relationship, ensuring they are consistent with the institution’s knowledge of the customer, their business and risk profile, and where necessary the source of funds.

Two structural points follow. First, the risk-based approach in Recommendation 1 governs all of it: institutions may reduce the extent of measures where risks are lower and must increase them where risks are higher, but may never omit measures entirely on risk grounds unless the standard says so. Second, Recommendation 22 applies the requirements of Recommendations 10, 11, 12, 15 and 17 to designated non-financial businesses and professions, meaning casinos, real estate agents, dealers in precious metals and stones, lawyers, notaries, accountants, and trust and company service providers, each in specified circumstances. That is why your conveyancing solicitor now asks for your passport. Record keeping sits in Recommendation 11, which requires records to be kept for at least five years, in a form sufficient to reconstruct individual transactions.

The thresholds, side by side#

The European Union has replaced its directive-based regime with a directly applicable regulation. Regulation (EU) 2024/1624, the AMLR, was adopted on 31 May 2024, entered into force on 9 July 2024 and applies from 10 July 2027, with 10 July 2029 for certain obliged entities named in Article 3(3)(n) and (o). It sits alongside Directive (EU) 2024/1640, the sixth directive, to be transposed by 10 July 2027, and Regulation (EU) 2024/1620, which created the Anti-Money Laundering Authority, AMLA, seated in Frankfurt am Main and operational since 1 July 2025, with direct supervision of a selected group of high-risk obliged entities beginning in 2028.

Article 19 of the AMLR sets out when customer due diligence must be applied, and its thresholds differ from the FATF baseline.

Trigger FATF baseline EU AMLR Art 19
Occasional transaction 15,000 USD or EUR 10,000 EUR
Transfer of funds 1,000 USD or EUR 1,000 EUR
Crypto-asset transfer risk-based 1,000 EUR
Occasional cash handling national 3,000 EUR

Article 19 also requires due diligence whenever there is a suspicion of money laundering or terrorist financing, regardless of any derogation, exemption or threshold, whenever there are doubts about previously obtained data, and for gambling services at 2,000 EUR or more on collecting winnings or wagering a stake. Where an obliged entity participates in creating a legal entity or arrangement, or in transferring ownership of one, due diligence applies irrespective of value.

The operative articles are Article 20 for the due diligence measures, 21 for what to do when you cannot complete them, 22 for identification and verification, 23 for timing, 24 for reporting discrepancies to the beneficial ownership register, 25 for purpose and intended nature, 26 for ongoing monitoring, 33 for simplified and 34 for the scope of enhanced due diligence. Article 80 adds a Union-wide limit of 10,000 EUR on large cash payments for goods or services, a KYC rule by another route: above that limit the transaction must go through a channel where a customer is known.

Simplified and enhanced: what actually triggers each#

Simplified due diligence is permitted, not required, and only where the institution’s own risk assessment finds the risk genuinely lower. The typical qualifying factors are a customer that is itself a regulated financial institution under equivalent supervision, a public authority, a company listed on a regulated market with disclosure requirements, a product with tightly limited functionality such as a pension that cannot be surrendered early or a stored-value instrument with hard caps, and a geography with effective controls.

What it permits is narrower than people assume: verification delayed, updates less frequent, monitoring less intense, or information inferred from the product’s design rather than gathered afresh. It never permits skipping identification. The February 2025 FATF revisions aim to make these paths genuinely usable, because supervisors had been treating any simplification as a finding, so firms defaulted to maximum diligence for everyone, which is precisely the behaviour that produces exclusion.

Enhanced due diligence is required, not permitted, and the triggers are: a customer or transaction connected with a high-risk third country; any politically exposed person; cross-border correspondent banking; complex or unusually large transactions and unusual patterns with no apparent economic or lawful purpose; non-face-to-face relationships where the remote channel is not adequately controlled; private banking; cash-intensive businesses; nominee shareholders or bearer shares; and any case the institution’s own model rates high. The measures are consistent across regimes: additional information on the customer and the intended relationship, source of funds and source of wealth, senior management approval, and enhanced ongoing monitoring.

Two terms are constantly confused. Source of funds is where the money in this transaction came from: the sale of a flat on a stated date, a dividend from a named company. Source of wealth is how the customer’s whole net worth was built: twenty years running a logistics business, an inheritance, a share sale in 2017. A file documenting the first and not the second fails inspection.

Beneficial ownership: the arithmetic and the registers#

Recommendation 24 requires countries to assess the risks of misuse of legal persons and to ensure that adequate, accurate and up-to-date beneficial ownership and control information is available. Its March 2022 revision added definitions of nominee shareholder, nominee director and nominator and pushed countries towards registers or equivalent mechanisms; Recommendation 25 does the same job for legal arrangements such as trusts and was revised in February 2023. The number everyone knows is 25 per cent, and the number is real, but the test around it varies.

Regime Ownership test Status Aug 2026
EU AMLR Art 52 25 per cent or more Applies 10 Jul 2027
US 31 CFR 1010.230 25 per cent or more In force
FATF R.24 no fixed figure In force
EU lower tier max 15 per cent Commission may set

Article 52 of the AMLR is the clearest statement of the test in any major instrument, and it settles two questions older rules left open. It defines beneficial ownership through ownership interest as direct or indirect ownership of 25 per cent or more of the shares, voting rights or other ownership interest, including rights to a share of profits and to the balance on liquidation. It then states the arithmetic: indirect ownership is calculated by multiplying the interests held by the intermediate entities in the chain, and the results of different chains are added together. It also empowers the Commission to set a lower threshold for categories of corporate entities exposed to higher risk, capped at 15 per cent, though it may set a figure between 15 and 25 where a risk assessment justifies it. Article 51 covers the identification duty for legal entities, and Article 53 covers beneficial ownership through control where the ownership calculation does not resolve, using tests such as control of over 50 per cent of shares or voting rights, the right to appoint or remove a majority of the board, veto rights and rights over profit distribution.

The United States rule looks similar and is not the same. Under 31 CFR 1010.230, adopted in 2016, amended at 82 Federal Register 45183 on 28 September 2017 with a compliance date of 11 May 2018, a covered financial institution opening an account for a legal entity customer must obtain name, date of birth, address and identification number for each individual owning 25 per cent or more of the equity interests directly or indirectly, and for a single individual with significant responsibility to control, manage or direct the entity. That second element, the control prong, guarantees at least one human name on the file even when ownership is diffuse. The rule excludes many entity types, including federally regulated financial institutions and issuers of securities registered under section 12 of the Securities Exchange Act of 1934.

Collecting beneficial ownership at each bank separately is wasteful and inconsistent, so the policy answer has been central registers. The European Union’s fifth anti-money laundering directive, Directive (EU) 2018/843, entered into force in July 2018 with a transposition deadline of 10 January 2020, and required member states to make beneficial ownership information on corporate entities accessible to any member of the public.

On 22 November 2022 the Court of Justice of the European Union, in joined cases C-37/20 and C-601/20, brought by WM and Sovim SA against Luxembourg Business Registers, declared that provision invalid, holding that general public access was a serious interference with the rights to respect for private life and protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights, and was not limited to what was strictly necessary or proportionate. Registers across the Union closed public access within days. Directive (EU) 2024/1640 rebuilds access on a narrower footing, opening registers to competent authorities, obliged entities, and persons or organizations able to demonstrate a legitimate interest, explicitly naming journalists, civil society bodies and academia, with transposition due by 10 July 2027 and some access provisions phased to 2029.

The American story ran in the opposite direction. The Corporate Transparency Act, enacted as part of the Anti-Money Laundering Act of 2020, created a federal beneficial ownership reporting regime administered by FinCEN, with reporting beginning on 1 January 2024. On 26 March 2025 FinCEN published an interim final rule removing the requirement for United States companies and for reporting on United States person beneficial owners, and on 11 August 2026 issued a final rule making that permanent, effective 14 August 2026. As of August 2026, entities created in the United States are exempt from beneficial ownership reporting altogether, and only foreign entities registered to do business in a state or tribal jurisdiction are reporting companies; those registered before 26 March 2025 had a filing deadline of 25 April 2025, and later registrants have 30 calendar days from notice.

That divergence is the largest live disagreement in this field. Europe is building narrowed but real registers. The United States created a national register and then exempted its own companies from it within three years. A firm designing a global beneficial ownership process in 2026 cannot assume registry data exists.

Politically exposed persons#

Recommendation 12 covers politically exposed persons, and its structure is often misreported. There are three categories carrying different duties.

A foreign PEP is an individual who is or has been entrusted with prominent public functions by a foreign country, for example heads of state or of government, senior politicians, senior government, judicial or military officials, senior executives of state owned corporations, and important political party officials. A domestic PEP is the same list entrusted domestically. An international organization PEP is a person entrusted with a prominent function by an international organization, meaning senior management or equivalent, that is, directors, deputy directors and board members. All three definitions explicitly exclude middle-ranking and more junior individuals.

The duties differ sharply between the first category and the other two.

PEP type Detection duty Extra measures
Foreign Risk management systems Always required
Domestic Reasonable measures Only if higher risk
Intl organization Reasonable measures Only if higher risk
Family or associate Follows the PEP Follows the PEP

For foreign PEPs, and for the other two categories where the relationship is assessed as higher risk, four things are required: appropriate risk management systems to determine the status, senior management approval to establish or continue the relationship, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. The requirements apply equally where the PEP is the beneficial owner rather than the customer, and the Interpretive Note extends determination duties to beneficiaries of life insurance policies, at the latest at payout.

The history matters for anyone reading older material. FATF first issued mandatory requirements for foreign PEPs and their family members and close associates in June 2003, under Recommendations 6 and 12 of the 2003 Forty Recommendations, then in February 2012 extended them to domestic and international organization PEPs, aligning with Article 52 of the United Nations Convention against Corruption, adopted in October 2003 and in force from December 2005.

The FATF Guidance on politically exposed persons covering Recommendations 12 and 22, published in June 2013, defines family members as individuals related to a PEP directly by consanguinity or through marriage or similar civil partnership, and close associates as individuals closely connected socially or professionally, such as partners outside the family unit, prominent members of the same political party, and business partners sharing beneficial ownership with the PEP.

On duration the two main frameworks openly disagree, and this is a real divergence rather than a drafting accident. The FATF guidance states that the language of Recommendation 12 is consistent with an open-ended approach, that is, once a PEP could always remain a PEP, and that handling a client who is no longer entrusted with a prominent public function should rest on risk assessment rather than prescribed time limits; the risk factors it lists are the informal influence the person could still exercise, the seniority of the position held, and whether the previous and current functions are linked. Article 45 of Regulation (EU) 2024/1624 takes the opposite drafting route, requiring obliged entities to weigh the continuing risk and to apply one or more of the enhanced measures in Article 34(4) until that risk no longer exists, but in any case for not less than 12 months after the person ceased to hold the function, including where the firm takes on a former PEP as a new customer. Article 43 requires lists of prominent public functions to be produced and Article 46 covers family members and close associates.

The practical consequence is that the European 12 months is a floor, not an expiry date. A former head of state remains a serious risk for decades, and both frameworks expect the risk assessment, not the calendar, to decide. The guidance also makes one point firms ignore: commercial PEP databases are not required by the Recommendations and are not sufficient alone, and the customer is the most valuable source of information about their own status, so the file should show they were asked.

Sanctions screening#

Sanctions screening is a separate obligation from KYC, though it runs in the same workflow and is usually managed by the same team. KYC asks who this is. Screening asks whether dealing with this person or entity is prohibited. A sanctions hit is absolute: there is no risk-based dial, and no due diligence makes a prohibited dealing lawful.

The list sources are public and stable, and any serious implementation consumes them directly. The United Nations Security Council Consolidated List merges the entries of the Council’s sanctions committees and is published in HTML, PDF and XML, the XML being the form screening systems ingest; the version last updated on 13 August 2026 contained 736 individuals and 275 entities, and it changes whenever a committee acts. The United States Office of Foreign Assets Control publishes the Specially Designated Nationals and Blocked Persons List, the SDN list, plus further lists such as the Sectoral Sanctions Identifications List, in fixed-width, comma-separated and XML formats through a dedicated Sanctions List Service, updated several times a week. The European Commission publishes the European Union consolidated list in machine-readable form, and the United Kingdom’s Office of Financial Sanctions Implementation, OFSI, part of HM Treasury, publishes the United Kingdom list. The OFSI Annual Review for 2024 to 2025 reported 394 suspected breach cases opened and 214 closed, 19 general licences issued and 904 specific licensing decisions, with 329 breach reports relating to Russia, 19 to the global anti-corruption regime and 18 to Libya.

The matching problem is where the engineering lives. A screening engine compares a customer name, and usually date of birth, nationality, place of birth and document numbers, against every alias on every list. Names arrive transliterated from Arabic, Cyrillic, Persian, Chinese and Korean, with no canonical spelling. The standard techniques are normalization to a common character set and case, token reordering so surname-first and given-name-first forms match, phonetic encoding of the Soundex and Metaphone family, and edit-distance measures such as Levenshtein or Jaro-Winkler, combined into a score with a configurable cut-off.

Customer record submitted for screening
  name: SUNITA RAO
  dob:  1979-11-02
  nat:  IN
  doc:  passport, IN

List candidate returned by the engine
  entry: RAU, Sunita  (alias: RAO, Sunita)
  list:  national list, entry 4471
  dob:   1968-04-17
  nat:   XX

Scoring
  token match       1.00   both tokens present
  phonetic          0.94   RAO / RAU same code
  edit distance     0.89   one substitution
  combined          0.93   over 0.85 cut-off
  ALERT RAISED

Analyst disposition
  dob mismatch      11 years
  nationality       does not match
  outcome           FALSE POSITIVE, discounted
  reviewer          initials and timestamp stored

That disposition record is not optional decoration. Supervisors inspect discounted alerts far more often than true hits, because a bank that quietly lowers its threshold to reduce workload shows up as a pattern of thinly reasoned discountings.

On error rates, be careful with the numbers that circulate. A widely quoted claim is that up to 99 per cent of sanctions screening alerts in cross-border payments are false positives. The figure most defensible from a primary source is narrower: in a presentation to the European Central Bank’s Advisory Group on Market Infrastructures for Payments on 7 December 2021, the European Credit Sector Associations stated that most banks then had an estimated alert rate for payments requiring manual review of between 3 and 15 per cent of transactions. The same presentation sets out the mechanism: both the payer’s and the payee’s payment service provider must screen before debiting or crediting, alert review requires a human, and a human cannot fit inside the execution time of an instant credit transfer. Its proposed remedy was daily screening of customer databases instead of every transaction, which would work fully only if a single harmonized European list existed.

[UNVERIFIED: a supervisory or peer-reviewed source for the commonly cited 99 per cent sanctions screening false positive rate]

So the honest summary is that the alert rate is a matter of record and sits in the low double digits of a percentage of payments, while the share of those alerts that are false is very high, plausibly above 90 per cent, but the figures quoted in industry commentary are estimates rather than supervised statistics.

Ongoing monitoring and the review cycle#

Ongoing monitoring has two components that are often conflated. Transaction monitoring watches behaviour against expectations and generates alerts. Periodic review, also called KYC refresh, re-examines the file itself and refreshes the identity data, the ownership picture and the risk rating. India gives the clearest published cycle, because the Reserve Bank states it numerically in the Master Direction, Know Your Customer (KYC) Direction, 2016.

Risk rating RBI periodic updation
High At least every 2 years
Medium At least every 8 years
Low At least every 10 years

The Direction also carried a transitional relaxation permitting delayed compliance for certain low-risk individual customers up to 30 June 2026. European and British institutions typically use shorter self-imposed cycles, commonly one year for high risk, three for medium and five for low, but those are policy choices rather than published thresholds. The distinction matters: the Indian figures are a regulatory standard, the European ones are convention.

The cycle is only a backstop. Every framework requires review on a trigger, and the standard trigger list is what an examiner will test.

Trigger events that pull a review forward
  1  change of beneficial ownership or control
  2  change of legal form, name or jurisdiction
  3  new director, signatory or authorized person
  4  customer becomes a PEP or is linked to one
  5  adverse media or law enforcement request
  6  a new sanctions designation touching the file
  7  transaction pattern departs from the profile
  8  identity document reaches its expiry date
  9  a suspicious transaction report is filed
 10  the customer moves to a higher-risk product

Article 26 of the AMLR places ongoing monitoring on a statutory footing, requiring obliged entities to monitor transactions for consistency with the customer profile and to keep documents, data and information up to date. Under the FATF standard the same duty is the fourth measure inside Recommendation 10, and in the United States it is the CDD Rule’s fifth pillar, added to the four traditional pillars of a Bank Secrecy Act programme.

eKYC: how identity is actually verified now#

Electronic KYC, eKYC, means completing identification and verification without the customer being physically present with a human. There are three families, differing in what the trust rests on.

The first is document plus liveness. The customer photographs an identity document, the system checks its security features and extracts the data, then captures a selfie or short video and compares the face to the document portrait, with a liveness check to establish that a live person and not a photograph, screen or mask is present. Trust rests on the document’s security and the biometric comparison.

The second is video identification, in which a trained operator conducts a live audio-visual call, inspects the document on camera, asks questions and records the session. Trust rests on a trained human plus the recording.

The third is authoritative database verification, in which the claimed identity is checked against a government or regulated register, sometimes with a one-time password to a registered mobile number or a biometric match performed by the authority. Trust rests on the register.

Jurisdictions permit different combinations, and the differences are not cosmetic.

Jurisdiction Primary anchor Instrument
EU Risk-based, technology neutral EBA/GL/2022/15
Germany Video identification rules BaFin 3/2017 (GW)
India V-CIP and Aadhaar e-KYC RBI KYC Direction 2016
Global tech Identity proofing components ETSI TS 119 461

The European Banking Authority issued Guidelines on the use of remote customer onboarding solutions, reference EBA/GL/2022/15, published on 22 November 2022 and applying from 2 October 2023. They are technology-neutral but prescriptive about controls. For unattended onboarding, where the customer interacts with no employee, liveness detection is required in every case regardless of risk profile, imagery must be captured under adequate lighting with the person unambiguously recognizable, and the institution must verify that the document reproduction shows original security features and unaltered personal data, guarding specifically against an image displayed on a screen from a photograph or scan of the original, the classic replay attack. Where optical character recognition is used, the institution must satisfy itself the captured data is accurate. For attended solutions, staff must be trained in anti-money laundering requirements and in detecting deception techniques and behavioural indicators.

Germany reached this ground earlier and by a different route. BaFin permitted video identification in item III of Circular 1/2014 of 5 March 2014, replaced it with Circular 4/2016 of 10 June 2016, and replaced that with Circular 3/2017 (GW), dated 4 October 2017 and in force from 15 June 2017. The German requirements are unusually specific: the operator must verify optical security features such as holograms, identigrams and kinematic structures, with a match assumed if the criteria are met for at least three randomly selected features from different categories; the person must enter a transaction number valid only for that purpose, centrally generated and delivered by email or short message; and the complete procedure must be recorded in both vision and sound and retained.

At the standards layer, ETSI TS 119 461, titled Policy and security requirements for trust service components providing identity proofing of trust service subjects, decomposes identity proofing into attribute collection, attribute validation, binding to the applicant, and issuance of the result. Version 1.1.1 appeared in July 2021 and version 2.1.1 in February 2025. It is the closest thing Europe has to a common technical vocabulary for what an eKYC provider does.

One recurring design error is worth naming. Document plus liveness answers two questions, is this document genuine and is this the person in it, but not a third, is it still valid and not reported lost or stolen. That requires a check against an issuing or revocation source, and many remote onboarding flows silently omit it. Chapter 48 covers how these confidences are expressed as graded assurance levels; here it is enough that a genuine document in the wrong hands defeats the whole flow.

India: Aadhaar e-KYC, the judgment, and where it stands#

India is the most instructive single jurisdiction here, because it built the largest database-backed eKYC system in the world, had it constrained by its Supreme Court, and then rebuilt it under the constraint. Chapter 50 treats the Aadhaar system itself, its enrolment, architecture and documented failures. Here we deal only with what it means for KYC.

The statutory frame is the Prevention of Money-laundering Act, 2002 and the Prevention of Money-laundering (Maintenance of Records) Rules, 2005. The operational frame is the Reserve Bank of India’s Master Direction, Know Your Customer (KYC) Direction, 2016, reference RBI/DBR/2015-16/18, dated 25 February 2016 and updated as of 14 August 2025. It defines the officially valid documents, or OVDs: the passport, the driving licence, proof of possession of an Aadhaar number, the voter’s identity card, the job card issued under the national rural employment guarantee scheme and signed by a state government officer, and the letter issued by the National Population Register. Where the OVD lacks the current address, deemed documents may be used, including utility bills not more than two months old, property or municipal tax receipts and pension payment orders.

From 2013 Aadhaar-based electronic KYC let a bank obtain a customer’s name, address, date of birth, gender and photograph directly from the Unique Identification Authority of India after the customer authenticated by fingerprint, iris or a one-time password. It collapsed account opening from days to minutes and spread very fast.

On 26 September 2018 a five-judge bench of the Supreme Court of India delivered judgment in Justice K.S. Puttaswamy (Retd.) and another v Union of India, reported at (2018) 1 SCC 809. The majority was written by Sikri J, with Chief Justice Dipak Misra and Khanwilkar J concurring; Bhushan J wrote separately and Chandrachud J dissented, making the outcome 4 to 1. The Aadhaar Act, 2016 was upheld in the main, including section 7, which permits Aadhaar to be required for subsidies and benefits funded from the Consolidated Fund of India. Three of the things struck down bear directly on KYC. Section 57, which let any body corporate or person require Aadhaar authentication under a law or any contract, was struck down insofar as it enabled private entities to demand authentication, removing the legal basis on which banks, telecom operators and fintech firms had been running Aadhaar e-KYC. Mandatory linking of bank accounts to Aadhaar, imposed through Rule 9 of the Prevention of Money-laundering (Maintenance of Records) Rules, 2005, was struck down as failing the proportionality test, as was mandatory linking to mobile connections. And section 33(2), permitting disclosure in the interest of national security on a senior officer’s authorization, was struck down, while regulation 27 of the Aadhaar (Authentication) Regulations, 2016, allowing five-year retention of authentication transaction data, was held impermissible with six months set as the limit.

Parliament answered with the Aadhaar and Other Laws (Amendment) Act, 2019, Act No. 14 of 2019, passed by the Lok Sabha on 4 July 2019 and the Rajya Sabha on 8 July 2019. It established that Aadhaar authentication may be made mandatory for a service only by a law of Parliament and is otherwise voluntary and consent-based. It created offline verification, a mode in which identity is checked without contacting the authentication server at all, using a digitally signed data package the resident downloads and shares, with the recipient forbidden from collecting biometrics. And it inserted section 11A into the Prevention of Money-laundering Act, 2002, permitting reporting entities to verify a client by Aadhaar authentication or offline verification, by passport, or by any other document notified by the central government, with the client choosing among the available methods. It also created civil penalties of up to one crore rupees. The mechanics followed in the Aadhaar (Authentication and Offline Verification) Regulations, 2021.

The position as of August 2026 is therefore this. Aadhaar-based e-KYC is lawful for banks and other reporting entities, but voluntary for the customer, requiring explicit consent, and for entities other than banks requiring notification or approval to act as an authentication user agency. Offline verification, using the signed XML package or the QR code on the Aadhaar letter, is open to a far wider set of relying parties precisely because it involves no authentication request and no biometrics. A customer who does not wish to use Aadhaar must be offered an alternative officially valid document.

The Reserve Bank also fixed the shape of remote onboarding. On 9 January 2020 it amended the KYC Direction to permit the video-based customer identification process, V-CIP, treating it as equivalent to face-to-face identification where the prescribed standards are met: a live, secured, audio-visual interaction conducted by an official of the regulated entity, with facial recognition and liveness detection, geo-tagging showing the customer is in India, end-to-end encryption, and technology infrastructure hosted in India. Business correspondents may facilitate at the customer’s end but may not conduct the session. Where Aadhaar OTP-based e-KYC opens an account without full due diligence, the Direction caps the aggregate deposit balance at one lakh rupees, aggregate annual credits at two lakh rupees and term loans at sixty thousand rupees a year, and the account ceases to be operational after one year unless full due diligence is completed.

The August 2025 amendments pushed towards inclusion, adding Aadhaar face authentication as an accepted method and requiring officials to record detailed reasons when rejecting a KYC application from a person with a disability, with an express expectation that digital liveness checks must not exclude persons with special needs.

India also operates a shared register that most countries lack. The Central KYC Records Registry, CKYCR, has run since 2016 under the Central Registry of Securitisation Asset Reconstruction and Security Interest of India, CERSAI, serving reporting entities across banking, securities, insurance and pensions. A customer verified once receives a 14-digit KYC Identifier, and another institution can retrieve that record instead of repeating the work. Reported volumes have passed one hundred crore, one billion records. [UNVERIFIED: the exact number of records held by the Central KYC Records Registry as of August 2026]

A file end to end#

All of this is easier to hold if you watch it applied once. Anand Spice Traders Private Limited is an invented company of realistic shape that exports cardamom and pepper. It applies for a current account in Kochi and a euro account in Dublin, so the same facts pass through two regimes. Its share register looks like this.

Anand Spice Traders Private Limited, share capital
  Meera Anand                     40 per cent  direct
  Kalyani Holdings Pte Ltd        45 per cent  direct
  Sunita Rao                       8 per cent  direct
  Seven employees, 1 per cent each 7 per cent  direct
                                 ====
                                 100 per cent

Kalyani Holdings Pte Ltd, Singapore, share capital
  Rajan Anand                     60 per cent
  Sunita Rao                      40 per cent
                                 ====
                                 100 per cent

Now do the arithmetic Article 52 of the AMLR sets out: multiply along each chain, then add the chains.

Person Calculation Total
Meera Anand 40 direct 40.0
Rajan Anand 45 x 60 per cent 27.0
Sunita Rao 45 x 40, plus 8 26.0
Each employee 1 direct 1.0

Three beneficial owners, then. Sunita is the interesting one, because neither of her holdings reaches 25 per cent alone: the indirect chain gives 18 per cent and the direct holding 8 per cent, and only the addition carries her over the line. A firm that evaluated each chain separately, which was common practice under the older directives, would have missed her entirely. That is exactly the gap the explicit aggregation rule closes.

Under the American CDD Rule the answer would be the same three names on the ownership prong, plus one more: a single individual with significant responsibility to control, manage or direct the company, typically the managing director, recorded under the control prong even though he may own nothing.

Next, PEP determination. Rajan Anand’s sister is a minister in a state government, which makes her a domestic PEP and Rajan a family member of one, so the duty is to take reasonable measures to determine the status and then assess the risk. The bank assesses it as higher risk, because her department awards agricultural procurement contracts and the company sells agricultural commodities. That triggers the enhanced measures: senior management approval before opening, documented source of wealth for Rajan, and enhanced ongoing monitoring.

Screening produces one alert, on Sunita Rao, against a list entry for a Sunita Rau. The scoring block earlier in this chapter is that alert: date of birth differs by eleven years, nationality does not match, the passport number is not hers. The analyst discounts it and records the reasons and their own identity, the part that survives inspection.

Verification then differs by bank. Meera and Rajan, both resident in India, complete the Kochi bank’s V-CIP session: live audio-visual interaction with a bank official, face match against the officially valid document, liveness check, geo-tag confirming presence in India, session recorded. Sunita, resident in Singapore, cannot use V-CIP and is verified in Dublin through certified copies of her passport, a database check and an interviewer-led remote session run to the EBA guidelines.

Now the profile. The company states expected annual turnover of 18 crore rupees, inward remittances from six named buyers in the Gulf and Europe, consignments between 30 and 90 lakh rupees, and no cash deposits above one lakh rupees. That sentence is the yardstick. The risk rating comes out high on three factors, a foreign corporate shareholder layer, a PEP association and a cash-adjacent commodity trade, so the Reserve Bank’s cycle requires updation at least every two years and the Dublin bank’s policy sets twelve months.

Fourteen months later, monitoring fires. A single inward remittance of 4.2 crore rupees arrives from a counterparty not on the list of six, incorporated in a jurisdiction added to the increased-monitoring list at the June 2026 plenary, and it is roughly five times the top of the stated consignment range. The alert is not evidence of anything; it is a departure from a written expectation, which is the only reason it could be detected at all. The relationship manager obtains the contract and the bill of lading, and the review is pulled forward under trigger 7 above. Here is the whole path, drawn once.

   APPLICATION
        |
        v
  +-----------------+  claimed name, dob, address, ids
  | IDENTIFY        |
        |
        v
  +-----------------+  doc, database, or video check
  | VERIFY          |
        |
        v
  +-----------------+  climb chains, multiply, then add
  | RESOLVE OWNERS  |
        |
        v
  +-----------------+  sanctions, PEP, adverse media
  | SCREEN          |--> hit? -> prohibited, stop
        |
        v
  +-----------------+  expected turnover, counterparties
  | PROFILE         |
        |
        v
  +-----------------+  simplified / standard / enhanced
  | RATE RISK       |
        |
        v
  +-----------------+<-------------------+
  | MONITOR         |                    |
        |                                |
        +--> alert -> investigate --------+
        |
        +--> trigger event ---> REVIEW ---+
        |
        +--> cycle due -------> REVIEW ---+
        |
        v
    EXIT or CONTINUE

The resulting file is what an examiner reads. For each element it should show what was collected, from what source, when, by whom, and why the conclusion was reached.

{
  "customer_id": "AST-0001",
  "type": "legal_entity",
  "legal_name": "Anand Spice Traders Private Limited",
  "incorporation": {"country": "IN", "number": "U01122KL"},
  "identification": {
    "method": "registry_extract",
    "source": "national company registry",
    "collected": "2026-02-11"
  },
  "beneficial_owners": [
    {"name": "Meera Anand", "pct": 40.0,
     "basis": "direct", "verified": "v_cip"},
    {"name": "Rajan Anand", "pct": 27.0,
     "basis": "indirect 45x60", "verified": "v_cip"},
    {"name": "Sunita Rao", "pct": 26.0,
     "basis": "18 indirect + 8 direct",
     "verified": "assisted_remote"}
  ],
  "control_person": "managing director, recorded",
  "pep": {"status": "family_of_domestic_pep",
          "assessment": "higher_risk",
          "approved_by": "senior_management"},
  "screening": {"alerts": 1, "true_hits": 0,
                "discount_reason": "dob and nat differ"},
  "profile": {"turnover_inr": 180000000,
              "counterparties": 6},
  "risk_rating": "high",
  "next_review": "2028-02-11",
  "retention_until": "at least 5 years after exit"
}

What it costs, and who pays#

The price has two currencies. The first is money spent by institutions. LexisNexis Risk Solutions publishes an annual study called True Cost of Financial Crime Compliance; the edition released on 26 September 2023, based on responses from 1,181 financial crime compliance professionals, put the global cost for financial institutions at 206.1 billion United States dollars, with regional editions in early 2024 giving 61 billion for the United States and Canada, 85 billion for Europe, the Middle East and Africa, and 45 billion for Asia Pacific. These are vendor survey estimates rather than audited accounts, and should be read as order-of-magnitude indicators.

Per customer, the vendor Fenergo has run repeated surveys. Its 2023 study, based on more than 1,100 senior executives at corporate and institutional banks, reported an average of 2,598 dollars per commercial client KYC review, up about 17 per cent on the year, and 95 days to complete a review globally, up from 84 days in 2022. Its 2024 survey reported that nearly 65 per cent of firms spend between 2,000 and 5,000 dollars per review, that KYC consumes over 30 per cent of compliance budgets and 40 per cent at the largest firms, and that 74 per cent of asset managers had lost investors to slow onboarding.

Figure Value Source year
Global compliance cost 206.1 bn USD 2023 study
Cost per commercial review 2,598 USD 2023 survey
Days per review, global 95 days 2023 survey
KYC share of compliance over 30 per cent 2024 survey

The second currency is exclusion, and here the figures come from better sources. The World Bank’s Identification for Development programme tracks the number of people with no official proof of identity: over one billion in the late 2010s, revised to 850 million in the 2021-based analysis published in 2023, and about 800 million in the data reported alongside the Global Findex 2025 release in November 2025, with coverage in Sub-Saharan Africa rising from about 70 to about 80 per cent. Global Findex 2025 reports that 79 per cent of adults worldwide now hold a financial account, a record, and that a great many still do not.

The link is direct. A regime that requires an officially valid document cannot onboard a person who has none. That is not an implementation failure; it is the design working as specified. The mitigations, tiered accounts with balance and transaction caps, simplified due diligence for small-value products, alternative documents such as employment guarantee job cards, exist precisely to blunt it, and the February 2025 FATF revisions were made to encourage their use.

The third cost is de-risking, where institutions exit whole categories rather than manage their risk. The clearest measured evidence is in correspondent banking, the network of accounts banks hold with each other to move money across borders. Data published by the Bank for International Settlements on 13 December 2021 recorded that active correspondent banking relationships fell about 4 per cent in 2020 and roughly 25 per cent between 2011 and 2020. When a corridor loses its correspondents, remittances get slower and dearer, and the people who feel it are migrant workers sending money home.

Two further facts frame the debate. The FinCEN Files, published on 20 September 2020 by BuzzFeed News and the International Consortium of Investigative Journalists, comprised 2,657 leaked documents including 2,121 suspicious activity reports, covering more than two trillion dollars of transactions between 1999 and 2017 that the filing banks had themselves flagged as suspicious. The reports had been filed. The money had still moved. And enforcement has produced very large penalties without obviously changing the aggregate picture: on 11 December 2012 HSBC Holdings and HSBC Bank USA entered a deferred prosecution agreement with the United States Department of Justice, admitting anti-money-laundering and sanctions violations and forfeiting 1.256 billion dollars, with total payments reported at about 1.9 billion; and Danske Bank’s Estonian branch handled roughly 200 billion euros of non-resident flows between 2007 and 2015, after which the bank paid United States and Danish authorities more than two billion dollars in December 2022.

Put those together and the honest position is uncomfortable. The system costs hundreds of billions of dollars a year, keeps hundreds of millions of people at the edge of the financial system, produces alerts that are wrong more than nine times in ten, and has not on any published measure interdicted more than a small fraction of laundered money. It also created the only working, audited, population-scale identity verification practice that exists, and every digital identity system now being built rests on its shoulders. Both are true. A designer who believes only the first will build something naive; one who believes only the second will build something cruel.

49.98 Common wrong ideas#

Wrong: KYC is a single global law. Right: It is a set of obligations enacted separately by each country, almost all of it copied from the FATF Recommendations, which are a non-binding standard adopted on 16 February 2012 and last updated in June 2026; wording, thresholds and permitted verification methods differ materially between jurisdictions, so a compliant process in one place can be unlawful in another.

Wrong: Once a customer is verified, they are verified. Right: Verification is a claim about a moment and it decays; the standards require ongoing due diligence, firms must refresh files on a risk-based cycle, which under the Reserve Bank of India’s KYC Direction is at least every two years for high risk, eight for medium and ten for low, and they must pull that review forward on any trigger such as a change of ownership or of behaviour.

Wrong: The 25 per cent beneficial ownership threshold identifies the real owner. Right: It identifies anyone who crosses an arbitrary line; Article 52 of Regulation (EU) 2024/1624 requires indirect holdings to be multiplied along each chain and the chains then added together, and every framework has a fallback allowing the senior managing official to be recorded when no natural person can be identified, which is precisely the outcome a deliberately opaque structure produces.

Wrong: Politically exposed person status expires after twelve months. Right: The twelve months in Article 45 of Regulation (EU) 2024/1624 is a minimum period during which enhanced measures must continue, not an expiry, and the FATF guidance of June 2013 states plainly that the handling of a former PEP should rest on risk assessment rather than prescribed time limits.

Wrong: A sanctions screening hit means the customer is sanctioned. Right: A hit is a fuzzy string match above a configurable score threshold, produced by phonetic and edit-distance algorithms across transliterated aliases; the great majority of alerts are false positives that an analyst must discount with a recorded reason, and that discounting record is what supervisors inspect most closely.

Wrong: Simplified due diligence means no due diligence. Right: It lets a firm reduce the extent, timing or frequency of measures where documented risk is genuinely lower, but identification still happens, and the February 2025 FATF revisions were made to encourage its proper use.

Wrong: Aadhaar-based e-KYC was banned by the Supreme Court of India. Right: The judgment of 26 September 2018 in Justice K.S. Puttaswamy v Union of India, (2018) 1 SCC 809, struck down section 57 of the Aadhaar Act insofar as it let private entities compel authentication, and struck down mandatory Aadhaar linking of bank accounts under Rule 9 of the Prevention of Money-laundering (Maintenance of Records) Rules, 2005; the Aadhaar and Other Laws (Amendment) Act, 2019 then restored a voluntary consent-based route and added section 11A to the Prevention of Money-laundering Act, so Aadhaar e-KYC is lawful today but optional for the customer.

Wrong: Beneficial ownership registers are becoming universally public. Right: The Court of Justice of the European Union invalidated general public access on 22 November 2022 in joined cases C-37/20 and C-601/20, Directive (EU) 2024/1640 rebuilds access for those with a legitimate interest by 10 July 2027, and a FinCEN final rule effective 14 August 2026 permanently exempted United States companies from reporting entirely, leaving only foreign reporting companies in scope.

Wrong: KYC stops money laundering. Right: The United Nations Office on Drugs and Crime estimates that 2 to 5 per cent of global output, some 800 billion to 2 trillion dollars, is laundered annually and the amounts interdicted are a small fraction of that; the defensible claims are that KYC raises the cost of laundering, produces traceable records prosecutions rely on, and deters casual abuse, and researchers genuinely disagree about how much of that is worth its cost.

49.99 Chapter summary in 20 lines#

  1. KYC is the identity component of anti-money-laundering regulation, and the first identity verification practice to operate at population scale under legal compulsion and external audit.
  2. The Financial Action Task Force was created by the Group of Seven summit in Paris in 1989, issued its first Forty Recommendations in 1990, and adopted the current standard on 16 February 2012, last updated in June 2026.
  3. FATF has no treaty power, and its influence rests on mutual evaluation and public listing, which an IMF working paper of 2021 associated with a fall in capital inflows of about 7.6 per cent of gross domestic product.
  4. Recommendation 10 requires four things: identify and verify the customer, identify and take reasonable measures to verify the beneficial owner, understand the purpose of the relationship, and conduct ongoing due diligence throughout it.
  5. The FATF occasional transaction threshold is 15,000 dollars or euros, while Article 19 of Regulation (EU) 2024/1624 sets 10,000 euros, with 1,000 for transfers of funds and crypto-asset transfers and 3,000 for occasional cash handling.
  6. Simplified due diligence reduces the extent, timing or frequency of measures where documented risk is lower, and never removes identification altogether.
  7. Enhanced due diligence is mandatory for high-risk third countries, politically exposed persons, correspondent banking and unusual transactions, and requires senior management approval, source of funds, source of wealth and closer monitoring.
  8. Source of funds is where this specific money came from, source of wealth is how the whole net worth was built, and a file documenting only the first will fail inspection.
  9. Article 52 of Regulation (EU) 2024/1624 sets beneficial ownership at 25 per cent or more, multiplies indirect holdings along each chain and then aggregates the chains, and lets the Commission set a lower threshold for higher-risk categories down to 15 per cent.
  10. The United States rule at 31 CFR 1010.230 uses the same 25 per cent ownership prong but adds a control prong naming one individual with significant responsibility to control, manage or direct the entity.
  11. On 22 November 2022 the Court of Justice of the European Union invalidated general public access to beneficial ownership registers in joined cases C-37/20 and C-601/20, and the 2024 directive rebuilds access only for those showing a legitimate interest.
  12. A FinCEN final rule effective 14 August 2026 permanently exempted United States companies from beneficial ownership reporting, leaving only foreign reporting companies in scope.
  13. Recommendation 12 defines foreign, domestic and international organization PEPs, always requires enhanced measures for foreign PEPs, and requires them for the other two only where the relationship is higher risk.
  14. FATF guidance of June 2013 rejects fixed time limits on PEP status, while Article 45 of Regulation (EU) 2024/1624 sets a floor of not less than 12 months of continued measures after a person leaves office.
  15. Sanctions screening runs against the United Nations Consolidated List, which held 736 individuals and 275 entities on 13 August 2026, the OFAC SDN list, the European Union consolidated list and the United Kingdom list maintained by OFSI.
  16. Screening uses normalization, token reordering, phonetic encoding and edit distance to produce a score, so alerts are statistical rather than definitive, and the recorded reason for discounting one is what supervisors inspect.
  17. Ongoing monitoring has two halves, transaction monitoring against a written profile and periodic file review, with the Reserve Bank of India requiring updation at least every two years for high risk, eight for medium and ten for low.
  18. Remote onboarding takes three forms, document plus liveness, video identification and database verification, governed in Europe by EBA/GL/2022/15 from 2 October 2023, in Germany by BaFin Circular 3/2017 (GW), and described technically by ETSI TS 119 461 version 2.1.1 of February 2025.
  19. India’s Supreme Court judgment of 26 September 2018 struck down section 57 of the Aadhaar Act and mandatory bank account linking, after which the Aadhaar and Other Laws (Amendment) Act, 2019 restored voluntary consent-based e-KYC and inserted section 11A into the Prevention of Money-laundering Act.
  20. The system costs on the order of 206 billion dollars a year by one 2023 industry study and about 95 days and 2,598 dollars per commercial client review, and it coexists with roughly 800 million people who have no official proof of identity at all.

Chapter sources: the FATF International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation, adopted 16 February 2012 and last updated June 2026, in particular Recommendations 1, 10, 11, 12, 16, 22, 24 and 25 with their Interpretive Notes, the amendment record of October 2021, March 2022, February 2023, October 2023, February 2025 and June 2026, and the FATF Plenary outcomes of 17 to 19 June 2026; FATF Guidance on Politically Exposed Persons (Recommendations 12 and 22), June 2013, sections II and IV; Regulation (EU) 2024/1624 of 31 May 2024, applying from 10 July 2027, Articles 19 to 26, 33, 34, 42 to 46, 51 to 53 and 80; Directive (EU) 2024/1640 and Regulation (EU) 2024/1620, both of 31 May 2024; Directive (EU) 2018/843, transposition deadline 10 January 2020; the Court of Justice of the European Union judgment of 22 November 2022 in joined cases C-37/20 and C-601/20, WM and Sovim SA v Luxembourg Business Registers; EBA Guidelines EBA/GL/2022/15 of 22 November 2022; BaFin Circular 3/2017 (GW) of 4 October 2017 and its predecessors of 10 June 2016 and 5 March 2014; ETSI TS 119 461 versions 1.1.1 of July 2021 and 2.1.1 of February 2025; 31 CFR 1010.230 as amended at 82 Federal Register 45183 of 28 September 2017; the FinCEN interim final rule of 26 March 2025 and final rule of 11 August 2026; Reserve Bank of India Master Direction RBI/DBR/2015-16/18 of 25 February 2016, updated 14 August 2025, with the V-CIP amendment of 9 January 2020; the Prevention of Money-laundering Act, 2002 section 11A and the Prevention of Money-laundering (Maintenance of Records) Rules, 2005 Rule 9; Justice K.S. Puttaswamy (Retd.) v Union of India (2018) 1 SCC 809 of 26 September 2018; the Aadhaar and Other Laws (Amendment) Act, 2019, Act No. 14 of 2019, and the Aadhaar (Authentication and Offline Verification) Regulations, 2021; the United Nations Security Council Consolidated List as last updated 13 August 2026; the OFSI Annual Review 2024 to 2025; the European Central Bank AMI-Pay meeting of 7 December 2021, item 2.3; IMF Working Paper WP/21/153, Kida and Paetzold, 2021; Bank for International Settlements correspondent banking data of 13 December 2021; the LexisNexis Risk Solutions True Cost of Financial Crime Compliance study of 26 September 2023 and its 2024 regional editions; Fenergo KYC surveys of 2023 and 2024; World Bank ID4D estimates and the Global Findex 2025 database; UNODC money laundering estimates; the ICIJ and BuzzFeed News FinCEN Files of 20 September 2020; and the United States Department of Justice announcement of the HSBC deferred prosecution agreement of 11 December 2012.