Know your customer (KYC) is the set of processes a financial institution uses to identify its customers, verify who they are, understand the purpose of the relationship, and keep that understanding current. KYB (from the phrase "know your business") is the same discipline applied to legal entity customers, adding verification of the entity's existence and identification of its beneficial owners. In US law the core requirements are the customer identification program rule (31 CFR 1020.220 for banks), the customer due diligence rule (31 CFR 1010.230), and the ongoing due diligence element of the AML program rule (31 CFR 1020.210).
Know your customer (KYC) is the set of processes a financial institution uses to establish who its customers are, verify that identity, understand the nature and purpose of each relationship, and keep that understanding current over time. KYB (from the phrase "know your business") is the application of the same processes to customers that are legal entities, such as corporations, limited liability companies, and partnerships, where the institution must also establish that the entity exists and identify the individuals who own or control it. Neither term appears in the regulations as a defined requirement; both are industry shorthand for a group of specific legal obligations.
The legal components
US anti-money laundering law builds KYC from three rules. Each has a different trigger and a different output.
| Rule | What it requires |
|---|---|
| Customer identification program (CIP), 31 CFR 1020.220 for banks, with parallel rules for broker-dealers and other institutions | Collect minimum identifying information before opening an account, verify identity within a reasonable time, check government lists, give notice, and keep records. |
| Customer due diligence (CDD) rule, 31 CFR 1010.230 | Identify and verify the beneficial owners of legal entity customers. |
| Ongoing due diligence, 31 CFR 1020.210(b)(2)(v) | Understand the nature and purpose of each relationship to build a customer risk profile, and conduct ongoing monitoring to report suspicious transactions and, on a risk basis, update customer information. |
Customer identification program
The CIP rule requires a bank to form a reasonable belief that it knows the true identity of each customer. Under 31 CFR 1020.220(a)(2), the bank must obtain, at minimum, four items before opening an account: name; date of birth, for an individual; address; and an identification number, which for a US person is a taxpayer identification number and for a non-US person may be a passport number, alien identification number, or number from another government-issued document.
The rule recognizes two verification methods:
- Documentary verification relies on documents. For an individual, this means an unexpired government-issued identification bearing a photograph or similar safeguard, such as a driver's license or passport. For an entity, it means documents showing the entity exists, such as certified articles of incorporation, a government-issued business license, a partnership agreement, or a trust instrument.
- Non-documentary verification relies on other sources, such as contacting the customer or comparing information the customer provides against a consumer reporting agency, a public database, or another source. The bank's non-documentary procedures must address situations such as a customer who cannot present a suitable document, a document the bank is unfamiliar with, and an account opened without the customer appearing in person.
The CIP must also include procedures for checking whether the customer appears on any list of known or suspected terrorists designated by the government, for giving customers adequate notice that identity information is being requested, and for recordkeeping. Identifying information is kept for five years after the account is closed, and records of verification methods for five years after the record is made. Many institutions also verify identity through digital document capture and biometric comparison of a live image to the photograph on the document; these are implementations of the documentary and non-documentary methods, not separate legal categories.
Beneficial ownership under the CDD rule
The CDD rule, 31 CFR 1010.230, requires covered financial institutions to identify and verify the beneficial owners of legal entity customers. A beneficial owner has two prongs, defined in 1010.230(d):
- Ownership prong: each individual, if any, who directly or indirectly owns 25 percent or more of the equity interests of the legal entity. An entity may have between zero and four such individuals.
- Control prong: a single individual with significant responsibility to control, manage, or direct the entity, such as a chief executive officer, chief financial officer, managing member, general partner, or other individual who regularly performs similar functions. Every legal entity customer has one.
Information is collected through the certification form in Appendix A to 1010.230 or by other means, provided the individual supplying it certifies its accuracy. The institution verifies the identity of each beneficial owner using risk-based procedures that include at least the elements of its CIP; it may generally rely on the customer's representation of who the owners are, absent knowledge of facts that call that representation into question. Section 1010.230(e) excludes many regulated and public entities from the definition of legal entity customer.
On February 13, 2026, FinCEN granted exceptive relief (FIN-2026-R001) from the requirement to identify and verify beneficial owners each time an existing legal entity customer opens a new account. Under the order, identification and verification are required when a legal entity customer first opens an account, when the institution learns facts that reasonably call previously obtained information into question, and as the institution's risk-based ongoing due diligence procedures require.
Business verification (KYB)
KYB covers more than beneficial ownership. A typical business verification process establishes the following for the customer:
- Existence and formation: formation documents from the state of organization, such as articles of incorporation or organization, and the entity's registration number.
- Standing: whether the entity remains active and in good standing with its state of formation, often shown by a certificate of good standing from the secretary of state.
- Identity of the business: legal name, trade names, principal address, and employer identification number.
- Ownership and control: the ownership chain through any intermediate entities, the beneficial owners under both prongs, and the individuals authorized to act on the account.
- Nature of the business: industry, products, customer base, geographic footprint, licensing where the activity requires a license, and expected account activity.
Status of Corporate Transparency Act reporting
The Corporate Transparency Act established a separate regime under which certain companies report beneficial ownership information directly to FinCEN. That regime has been narrowed. FinCEN issued an interim final rule in March 2025 and a final rule, effective August 14, 2026, under which entities created in the United States and their beneficial owners are exempt from reporting; reporting applies only to foreign entities registered to do business in a US state or tribal jurisdiction, and those entities need not report US-person beneficial owners. The CTA reporting regime and the CDD rule are distinct: the narrowing of CTA reporting did not remove a financial institution's own obligation under 31 CFR 1010.230 to collect beneficial ownership information from its legal entity customers.
Ongoing monitoring and enhanced due diligence
KYC continues after onboarding. The AML program rule requires ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information, including beneficial ownership information. The customer risk profile built at onboarding sets the level of scrutiny, as described in the customer risk rating article, and transaction monitoring compares actual activity against it.
Enhanced due diligence (EDD) is the additional scrutiny applied to higher-risk customers. The FFIEC BSA/AML Examination Manual describes it as a risk-based matter rather than a fixed checklist: it commonly includes the source of funds and source of wealth, the purpose of expected transactions, more senior approval of the relationship, and more frequent review. Certain EDD is mandatory by regulation: 31 CFR 1010.620 requires enhanced scrutiny of private banking accounts held by or for senior foreign political figures, and 31 CFR 1010.610 sets due diligence requirements for correspondent accounts for foreign financial institutions.
Politically exposed persons
A politically exposed person (PEP) is commonly understood as a foreign individual who is or has been entrusted with a prominent public function, together with that person's immediate family members and close associates. On August 21, 2020, FinCEN and the federal banking agencies issued a Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons. The statement explains that the CDD rule does not create a regulatory requirement, and that there is no supervisory expectation, for banks to apply unique additional due diligence steps to customers because they are PEPs. Due diligence is instead commensurate with the risk of the particular relationship, and the agencies do not interpret the term to include US public officials. The separate private banking requirement in 31 CFR 1010.620 still applies where its conditions are met.
Who performs KYC and KYB
Onboarding teams collect and verify information under procedures owned by the compliance function. Higher-risk cases and EDD reviews are usually handled by specialist due diligence analysts, with approval by compliance management or a designated officer for the highest-risk relationships. Many institutions use third-party data providers for identity and business verification; the institution remains responsible for the adequacy of the process. KYC files are reviewed during BSA/AML examinations and in independent testing, where the reviewer samples accounts to confirm that required information was collected, verified, and refreshed.
Primary sources
- 31 CFR 1020.220: Customer identification program requirements for banks: minimum information, verification methods, list checks, notice, and records.
- 31 CFR 1010.230: Beneficial ownership requirements for legal entity customers: the 25 percent ownership prong and the control prong.
- 31 CFR 1020.210: Bank AML program rule, including risk-based ongoing customer due diligence and monitoring.
- FinCEN, FIN-2026-R001 (February 13, 2026): Exceptive relief from identifying and verifying beneficial owners at each new account opening.
- 31 CFR 1010.620 and 1010.610: Due diligence for private banking accounts (including senior foreign political figures) and for foreign correspondent accounts.
- Joint Statement on BSA Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons (August 21, 2020): FinCEN and federal banking agencies on risk-based treatment of PEPs.
- FinCEN, Beneficial Ownership Information Reporting: Current status of Corporate Transparency Act reporting after the August 2026 final rule.
- FFIEC BSA/AML Examination Manual: Examination procedures for CIP, customer due diligence, beneficial ownership, and enhanced due diligence.