SCREENING GLOSSARY · GUIDEUPDATED 2026-09-04
Screening Glossary
What is KYC (Know Your Customer)?
KYC is the operational name for what AML law calls customer due diligence: identify the customer, verify that identity from reliable independent sources, understand the purpose of the relationship, and keep that understanding current for as long as it lasts.
KYC rests on the FATF standards and, in the EU, on the anti-money-laundering framework that obliged entities apply before establishing a relationship and periodically afterwards. The most common misconception is that KYC is an onboarding form. Identification is only the first step, and the duty runs through the life of the relationship, including keeping documents, data and the risk assessment up to date.
What this workflow covers
SCOPE- Verify identity against independent sources rather than against what the customer typed.
- For corporate customers, identify the beneficial owners before the relationship opens, then screen everyone identified.
- Refreshing customers onboarded years ago under weaker standards is usually a bigger project than onboarding itself.
- Completing KYC evidences that the required controls were applied. It does not certify that the customer is legitimate.
Compliance glossary
TERMS- Obliged entity
- The EU term for a business subject to anti-money-laundering duties, such as a bank, payment institution, crypto-asset service provider, accountant or estate agent.
- Identification and verification
- Collecting who the customer says they are, then confirming it from reliable, independent documents, data or sources.
Authoritative references
SOURCES- 01The FATF Recommendations — Recommendation 10 (Customer due diligence)
Financial Action Task Force
- 02Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing
EUR-Lex, Official Journal of the European Union
Frequently asked questions
Q&A- KYC or AML: what is the difference?
- AML is the whole regime: risk assessment, controls, monitoring, reporting, training and governance. KYC is the customer-facing part of it, identifying and verifying who you are dealing with and keeping that knowledge current.
- What documents do we need?
- For individuals, a government identity document and evidence of address. For companies, registration extracts, ownership evidence and identification of controllers. National law and your own risk-based policy set the exact list, so a fixed global checklist is usually either too much or too little.
- How often do we refresh?
- On a risk-based cadence and on trigger events: a change of ownership, a change of activity, a new designation touching the customer. Fixed annual cycles for everyone are common in practice and are not what the risk-based approach asks for.
- Does KYC include sanctions screening?
- In practice yes. Screening against sanctions, PEP and watchlist data is normally performed at onboarding and repeated during the relationship, even though it rests on a separate legal obligation from customer identification.
Q.01
Q.02
Q.03
Q.04