CommsPliant Lexicon

KYC - Know Your Customer

Understanding who a customer is, checking their identity and keeping that understanding relevant throughout the relationship.

Why does the bank need to know so much about me?

You want to open an account. The bank asks who you are, what you do and how you expect to use it.

This forms part of KYC — Know Your Customer. These checks help financial institutions understand their customers and reduce the risk of their services being used for money laundering or terrorist financing. A routine request does not, by itself, mean you are under suspicion. FCA — Customer checks.

Two questions explain an important distinction:

Who do you say you are? That is identification.

What reliable, independent evidence supports that? That is verification.

The institution also needs to understand the relationship, including who ultimately owns or controls a business customer. FATF — Recommendation 10.

Why might they ask again?

Your provider may periodically ask whether your details are still correct: your name, home address or telephone number. Sometimes you simply confirm that nothing has changed. Banks may also request additional identity information. HSBC — Customer information updates.

But customer information extends beyond contact details. A business might change owners, enter new markets or start receiving different payments. Those changes can prompt further checks. HMRC — Changing customer circumstances.

In practice

The same business, a different payment pattern

Fictional example.

Maya opens an account for her ceramics business. The bank checks her identity, the business and its ownership, and records that payments are expected mainly from UK retailers.

A year later, Maya starts selling through an overseas distributor. Larger international payments begin arriving.

During a routine update, Maya confirms that her name, address and the ownership of the business are unchanged. That answer is accurate.

The bank also asks about the new payments. Maya supplies the distribution agreement and explains the arrangement.

The reviewer now has two different pieces of information: the customer’s identifying details remain current, but the business activity has developed.

The agreement gives the reviewer evidence to examine. The next question is whether it explains the payments and what the new activity means for the customer assessment.

Professional view

Are KYC and CDD interchangeable?

KYC is an established industry expression. Customer due diligence — CDD is the term used in FATF Recommendation 10 for measures covering customer identification and verification, beneficial-owner identification and reasonable verification measures, understanding the relationship, and ongoing scrutiny. FATF — Recommendation 10.

For operational purposes, an internal label such as “KYC complete” needs a defined scope. Completing identity verification, refreshing customer information and completing a risk review describe different work. A status label is useful only when the record shows what was completed.

FATF provides international standards. A firm’s applicable obligations depend on the jurisdiction and activities involved; the FCA and HMRC references here describe the UK context. FATF — The Recommendations.

Professional judgement

When can a firm rely on earlier identity verification, and what should trigger fresh checks?

FATF’s Interpretive Note to Recommendation 10 permits reliance on earlier identification and verification unless there are doubts about the information’s truthfulness. It does not require repeating those steps for every transaction. It also identifies a material change in account use that is inconsistent with the customer’s business profile as a circumstance that may raise such doubts. FATF — Interpretive Note to Recommendation 10, paragraph 10.

The practical distinction is between reviewing the relationship and repeating identity verification.

In Maya’s example, the new activity raises questions about how the account is used. Requesting another passport copy would not explain the overseas payments. If the review also reveals doubts about identity information, those doubts need to be addressed.

A useful review therefore identifies which information has become inadequate and what evidence would resolve the gap.

Does confirming that “nothing has changed” provide enough information to complete a customer review?

It depends on what was confirmed and what other information the institution holds.

A customer may accurately confirm their name and address while their business activity has changed substantially. The scope of the question limits what the answer establishes.

The FCA explains that ongoing monitoring involves assessing whether transactions are consistent with the institution’s knowledge of the customer, their business and risk profile. FCA — Ongoing customer monitoring.

Applied to Maya’s fictional case, useful questions include:

  • Does the agreement identify the distributor responsible for the payments?

  • Do the amounts and timing fit the sales arrangement described?

  • Are payments arriving from the expected payer?

  • What remains unexplained?

These are practical review questions, not a prescribed checklist.

The distinction matters when designing an update form. “Have your contact details changed?” and “Has the way your business operates changed?” establish different facts. A completed form can still leave the reason for the review unresolved.

What should the record explain when unusual activity does not lead to a higher customer risk rating?

The FCA’s Financial Crime Guide identifies an inability to evidence customer risk ratings, and unsupported overrides of risk scores, as examples of poor practice. It also asks how findings from monitoring feed back into the customer’s risk profile. FCA — FCG 3.2.3 and 3.2.5.

A practical implication is that explaining a payment and assessing the customer’s continuing risk are distinct judgements.

In Maya’s case, the agreement might explain why the payment arrived. The reviewer still needs to consider what the new overseas activity means for the wider relationship.

If the existing rating remains appropriate, a useful record would explain:

  • What activity and evidence were reviewed.

  • Which relevant risk factors changed or remained stable.

  • Why the existing category remains appropriate under the firm’s methodology.

  • Who made the decision, when, and what follow-up was agreed.

These are suggested documentation prompts, not a regulatory form. They help a later reviewer understand the decision rather than infer it from a closed task or an unchanged score.

Why it matters

In Maya’s case, the contact details, business description and risk assessment answer different questions.

A precise request helps her provide relevant information. A reasoned review helps the bank decide whether that information is sufficient and what should happen next.

For a compliance team, the value lies in being able to follow the connection between what changed, what was examined and why the decision was made.

Common misunderstandings

  • “KYC is just a passport check.” Identity evidence is one component; the relationship also needs to be understood.

  • “My details have not changed, so the bank has nothing to review.” Identifying details can remain unchanged while business activity develops.

  • “A legitimate explanation means the risk rating must stay the same.” Explaining the activity and assessing its effect on the relationship are separate judgements.

  • “KYC complete means every future transaction is legitimate.” A completed review cannot establish that.

Connected terms

Customer Due Diligence (CDD) · Anti-Money Laundering (AML) · Ultimate Beneficial Owner (UBO) · Enhanced Due Diligence (EDD) · Transaction Monitoring.