Explainer

KYC, KYB and AML: What They Mean and How They Differ

KYC verifies individual customers, KYB verifies businesses and their owners, and AML is the wider legal framework for detecting and preventing illicit finance.

KYC, KYB and AML are often used interchangeably, but they describe different parts of a financial crime compliance program. KYC, or Know Your Customer, concerns the identity and risk of an individual. KYB, or Know Your Business, extends similar checks to a company and the people who ultimately own or control it. AML, or Anti Money Laundering, is the broader set of laws, controls and reporting duties behind both.

The terms matter because a firm may need to verify a consumer opening an account, a merchant seeking payment services, or both. The correct process depends on the product, jurisdiction, customer type and level of risk. Requirements vary between the United States, the European Union and individual countries, but the underlying objective is similar: stop financial systems from being used to hide proceeds of crime or fund terrorism.

What KYC means for individual customers

KYC is the process of establishing who a customer is and assessing the risk they present before, and sometimes during, a business relationship. A bank opening a checking account, a crypto asset platform onboarding a user, or a payment provider accepting a new merchant customer may collect identifying information and verify it using reliable, independent sources.

For an individual, KYC commonly includes a legal name, date of birth, residential address and a government identity document. Firms may check document security features, compare a selfie or live video to the document photo, verify an address, and screen the person against sanctions lists, politically exposed person lists and adverse media sources. A politically exposed person is someone entrusted with a prominent public function, as well as certain family members and close associates, who may present a higher corruption risk.

KYC is not simply an identity check. A valid passport can establish identity, but it does not answer whether an account's expected activity is credible or whether the person is subject to sanctions. Institutions generally create a customer risk profile using factors such as location, occupation, product use, payment patterns and links to higher risk countries.

What KYB means for businesses and beneficial owners

KYB applies when the customer is a legal entity, such as a corporation, limited liability company, partnership, charity or trust. It seeks to establish that the business exists, understand its ownership and control, and assess the nature and purpose of the relationship. This is important because companies can be used to obscure the people moving or benefiting from funds.

A KYB review commonly confirms a company's registered name, legal form, registration number, address, incorporation status and directors. It also identifies authorized account users and examines the business's industry, expected transaction volumes and source of funds where appropriate. Information may be checked against official company registries, formation documents, tax records and other reliable sources.

A central KYB task is identifying beneficial owners. A beneficial owner is a natural person who ultimately owns or controls an entity, directly or through one or more other entities. Thresholds and tests differ by jurisdiction and entity type. In the EU, anti money laundering rules have generally used a 25 percent ownership or control indicator, while US beneficial ownership rules and customer due diligence obligations use different definitions and have changed through rulemaking and litigation. Firms must apply the rules that govern them rather than rely on one universal percentage.

AML is the umbrella obligation

AML refers to the overall legal and operational framework intended to prevent, detect and report money laundering, terrorist financing and related financial crime. Money laundering is the process of making criminal proceeds appear legitimate. AML programs typically include governance, written policies, employee training, independent testing, recordkeeping, sanctions controls, customer screening and transaction monitoring.

Monitoring looks for activity that is unusual in light of what the firm knows about a customer. It may identify rapid movement of funds, transactions inconsistent with a stated business purpose, repeated transfers involving high risk locations, or attempts to evade reporting thresholds. An alert is not proof of wrongdoing. It requires investigation, and where the legal standard is met, a report to the relevant authority. In the US, this may be a Suspicious Activity Report filed with the Financial Crimes Enforcement Network. EU reporting is generally made to a national financial intelligence unit.

Customer due diligence and enhanced due diligence

Customer due diligence, often called CDD, is the baseline process within AML compliance. It generally involves identifying and verifying the customer, identifying beneficial owners where relevant, understanding the purpose of the relationship, and conducting ongoing monitoring. KYC and KYB supply much of the information needed for CDD.

Enhanced due diligence, or EDD, is a deeper set of measures for higher risk situations. It can involve obtaining more information about source of wealth and source of funds, senior management approval, more frequent review and closer transaction monitoring. Source of funds concerns where money used in a transaction came from. Source of wealth concerns how a person accumulated their overall assets.

  • CDD is risk based: lower risk relationships may receive simpler checks where law permits, while higher risk relationships require more scrutiny.
  • EDD may be required for politically exposed persons, certain cross border correspondent banking relationships, customers linked to high risk jurisdictions, or complex ownership structures.
  • Verification is not a one time event. Customer records and risk assessments should be updated when circumstances change or monitoring identifies concerns.

Who must comply

Banks, credit unions, payment institutions, electronic money issuers, money transmitters, broker dealers, investment firms, insurers offering certain products, casinos and many crypto asset service providers are commonly subject to AML duties. Depending on the country, obligations can also apply to accountants, lawyers, real estate professionals, trust and company service providers, dealers in high value goods and other gatekeepers. Not every business that asks for identification is legally subject to the same AML regime.

In the US, obligations principally arise under the Bank Secrecy Act and regulations administered by the Treasury Department's Financial Crimes Enforcement Network, alongside sanctions rules administered by the Office of Foreign Assets Control. In the EU, AML directives and the newer AML package set a framework implemented and supervised through EU and national authorities. Firms operating across both markets often face overlapping, not identical, requirements.

How KYC, KYB and AML work together

In practice, AML is the program; KYC and KYB are onboarding and ongoing due diligence components. A fintech may use KYC to verify a consumer, KYB to verify a marketplace seller and its beneficial owners, then monitor both for suspicious behavior throughout the relationship. If risk rises, it applies EDD, restricts activity or files a report when required.

Good compliance therefore combines reliable identity and business data with proportionate risk assessment and human review. The aim is not to treat every customer as suspicious. It is to know enough about customers and their activity to identify risk, meet legal duties and avoid enabling illicit finance.