Skip to content
Reference

KYC and KYB: Customer and Business Due Diligence Explained

The short version

Know your customer (KYC) is the set of processes a financial institution uses to identify its customers, verify who they are, understand the purpose of the relationship, and keep that understanding current. KYB (from the phrase "know your business") is the same discipline applied to legal entity customers, adding verification of the entity's existence and identification of its beneficial owners. In US law the core requirements are the customer identification program rule (31 CFR 1020.220 for banks), the customer due diligence rule (31 CFR 1010.230), and the ongoing due diligence element of the AML program rule (31 CFR 1020.210).

Know your customer (KYC) is the set of processes a financial institution uses to establish who its customers are, verify that identity, understand the nature and purpose of each relationship, and keep that understanding current over time. KYB (from the phrase "know your business") is the application of the same processes to customers that are legal entities, such as corporations, limited liability companies, and partnerships, where the institution must also establish that the entity exists and identify the individuals who own or control it. Neither term appears in the regulations as a defined requirement; both are industry shorthand for a group of specific legal obligations.

The legal components

US anti-money laundering law builds KYC from three rules. Each has a different trigger and a different output.

RuleWhat it requires
Customer identification program (CIP), 31 CFR 1020.220 for banks, with parallel rules for broker-dealers and other institutionsCollect minimum identifying information before opening an account, verify identity within a reasonable time, check government lists, give notice, and keep records.
Customer due diligence (CDD) rule, 31 CFR 1010.230Identify and verify the beneficial owners of legal entity customers.
Ongoing due diligence, 31 CFR 1020.210(b)(2)(v)Understand the nature and purpose of each relationship to build a customer risk profile, and conduct ongoing monitoring to report suspicious transactions and, on a risk basis, update customer information.

Customer identification program

The CIP rule requires a bank to form a reasonable belief that it knows the true identity of each customer. Under 31 CFR 1020.220(a)(2), the bank must obtain, at minimum, four items before opening an account: name; date of birth, for an individual; address; and an identification number, which for a US person is a taxpayer identification number and for a non-US person may be a passport number, alien identification number, or number from another government-issued document.

The rule recognizes two verification methods:

The CIP must also include procedures for checking whether the customer appears on any list of known or suspected terrorists designated by the government, for giving customers adequate notice that identity information is being requested, and for recordkeeping. Identifying information is kept for five years after the account is closed, and records of verification methods for five years after the record is made. Many institutions also verify identity through digital document capture and biometric comparison of a live image to the photograph on the document; these are implementations of the documentary and non-documentary methods, not separate legal categories.

Beneficial ownership under the CDD rule

The CDD rule, 31 CFR 1010.230, requires covered financial institutions to identify and verify the beneficial owners of legal entity customers. A beneficial owner has two prongs, defined in 1010.230(d):

Information is collected through the certification form in Appendix A to 1010.230 or by other means, provided the individual supplying it certifies its accuracy. The institution verifies the identity of each beneficial owner using risk-based procedures that include at least the elements of its CIP; it may generally rely on the customer's representation of who the owners are, absent knowledge of facts that call that representation into question. Section 1010.230(e) excludes many regulated and public entities from the definition of legal entity customer.

On February 13, 2026, FinCEN granted exceptive relief (FIN-2026-R001) from the requirement to identify and verify beneficial owners each time an existing legal entity customer opens a new account. Under the order, identification and verification are required when a legal entity customer first opens an account, when the institution learns facts that reasonably call previously obtained information into question, and as the institution's risk-based ongoing due diligence procedures require.

Business verification (KYB)

KYB covers more than beneficial ownership. A typical business verification process establishes the following for the customer:

Status of Corporate Transparency Act reporting

The Corporate Transparency Act established a separate regime under which certain companies report beneficial ownership information directly to FinCEN. That regime has been narrowed. FinCEN issued an interim final rule in March 2025 and a final rule, effective August 14, 2026, under which entities created in the United States and their beneficial owners are exempt from reporting; reporting applies only to foreign entities registered to do business in a US state or tribal jurisdiction, and those entities need not report US-person beneficial owners. The CTA reporting regime and the CDD rule are distinct: the narrowing of CTA reporting did not remove a financial institution's own obligation under 31 CFR 1010.230 to collect beneficial ownership information from its legal entity customers.

Ongoing monitoring and enhanced due diligence

KYC continues after onboarding. The AML program rule requires ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information, including beneficial ownership information. The customer risk profile built at onboarding sets the level of scrutiny, as described in the customer risk rating article, and transaction monitoring compares actual activity against it.

Enhanced due diligence (EDD) is the additional scrutiny applied to higher-risk customers. The FFIEC BSA/AML Examination Manual describes it as a risk-based matter rather than a fixed checklist: it commonly includes the source of funds and source of wealth, the purpose of expected transactions, more senior approval of the relationship, and more frequent review. Certain EDD is mandatory by regulation: 31 CFR 1010.620 requires enhanced scrutiny of private banking accounts held by or for senior foreign political figures, and 31 CFR 1010.610 sets due diligence requirements for correspondent accounts for foreign financial institutions.

Politically exposed persons

A politically exposed person (PEP) is commonly understood as a foreign individual who is or has been entrusted with a prominent public function, together with that person's immediate family members and close associates. On August 21, 2020, FinCEN and the federal banking agencies issued a Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons. The statement explains that the CDD rule does not create a regulatory requirement, and that there is no supervisory expectation, for banks to apply unique additional due diligence steps to customers because they are PEPs. Due diligence is instead commensurate with the risk of the particular relationship, and the agencies do not interpret the term to include US public officials. The separate private banking requirement in 31 CFR 1010.620 still applies where its conditions are met.

Who performs KYC and KYB

Onboarding teams collect and verify information under procedures owned by the compliance function. Higher-risk cases and EDD reviews are usually handled by specialist due diligence analysts, with approval by compliance management or a designated officer for the highest-risk relationships. Many institutions use third-party data providers for identity and business verification; the institution remains responsible for the adequacy of the process. KYC files are reviewed during BSA/AML examinations and in independent testing, where the reviewer samples accounts to confirm that required information was collected, verified, and refreshed.

Primary sources

Common questions

What is the difference between KYC and KYB?
KYC is the process of identifying and verifying customers and understanding their relationships. KYB applies the same process to legal entity customers and adds verification that the business exists and is in good standing, and identification of its beneficial owners and controllers.
What information does a customer identification program require?
Under 31 CFR 1020.220, a bank must obtain at least the customer's name, date of birth for an individual, address, and an identification number before opening an account, then verify identity through documentary or non-documentary methods within a reasonable time.
Who is a beneficial owner under the CDD rule?
Under 31 CFR 1010.230(d), a beneficial owner is each individual who directly or indirectly owns 25 percent or more of a legal entity customer's equity interests, plus one individual with significant responsibility to control, manage, or direct the entity.
Do US companies still file beneficial ownership reports under the Corporate Transparency Act?
No. Under FinCEN's final rule effective August 14, 2026, entities created in the United States and their beneficial owners are exempt from BOI reporting. Reporting applies only to foreign entities registered to do business in the United States. Banks' separate duty to collect beneficial ownership information under the CDD rule is unchanged.
Are banks required to apply enhanced due diligence to every politically exposed person?
No. The 2020 joint statement by FinCEN and the federal banking agencies says there is no regulatory requirement or supervisory expectation of unique additional steps for PEPs as a class; due diligence is commensurate with the risk of the relationship. The private banking rule in 31 CFR 1010.620 imposes enhanced scrutiny for senior foreign political figures where it applies.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.