Join our Newsletter — 33% off our NHI Course

What is the difference between KYC and due diligence in digital asset compliance?

KYC is the process of identifying and verifying who a customer is, while due diligence is the broader ongoing assessment of risk, behaviour, and relationship context. In digital asset compliance, KYC establishes the baseline identity record, and due diligence helps determine whether activity remains consistent with policy, regulatory obligations, and the client’s expected use of the platform.

KYC and due diligence solve different compliance problems

KYC is the onboarding and identity-verification layer: it answers who the customer is, whether the person or entity can be identified reliably, and whether the record is strong enough to support account opening. In digital asset markets, that baseline matters because the same platform may later have to justify why a wallet, account, or trading relationship was accepted in the first place.

Due diligence is broader and more dynamic. It asks whether the relationship, activity, source of funds, transaction pattern, jurisdictional exposure, and counterparty context still fit the expected risk profile. In practice, KYC creates the customer record, while due diligence tests whether that record remains credible as behaviour changes.

The distinction is especially important in digital asset compliance because activity can move quickly across wallets, venues, and jurisdictions. A clean KYC file does not by itself explain abnormal transaction velocity, repeated exposure to higher-risk counterparties, or a change in the purpose of the relationship.

How the two work together in a digital asset programme

A compliant programme usually treats KYC as a point-in-time control and due diligence as a lifecycle control. The first captures identity evidence and initial risk attributes. The second uses those attributes, plus ongoing monitoring, to decide whether the customer should remain on standard terms, be reviewed, restricted, or escalated.

That means the operational handoff matters. If onboarding collects only the minimum identity facts but no usable risk context, due diligence becomes weak because there is no baseline to compare against. If onboarding is strong but review processes are shallow, the firm may know who the customer is while still missing why the relationship has become higher risk.

For digital asset firms, this is where policy, transaction monitoring, and client risk scoring intersect. KYC supports account establishment and initial screening. Due diligence supports ongoing judgement about consistency, exceptions, and whether additional verification or review is required.

Risk and Threat Considerations

The main failure mode is treating KYC as a one-time checkbox and assuming it is enough to manage an evolving relationship. In digital asset compliance, that can leave firms exposed to misclassification, missed escalation, and weak detection of changes in behaviour or beneficial ownership that should alter the risk decision.

Failure mechanism: Static identity collection is accepted as sufficient even when transaction patterns, wallet linkages, sanctions exposure, or customer purpose have changed, so the firm continues to rely on stale baseline data.

Impact: The result can be inadequate suspicious activity review, control failure in higher-risk relationships, regulatory findings, and avoidable exposure to financial crime or sanctions risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RR-01 — Organizational Context Digital asset compliance depends on defining customer risk context and review ownership.
ID.AM-03 — Asset Management KYC and due diligence both rely on maintaining an accurate customer and relationship record.
PR.DS-01 — Data is managed consistent with the organization's risk strategy Ongoing due diligence uses collected customer data to support compliance decisions.
Recommendation — Define review ownership for customer risk changes and escalation triggers. Maintain current customer and relationship records for ongoing assessment. Use customer data consistently with the firm's risk-based compliance strategy.
CIS Controls v8 6.1 — Establish and Maintain an Asset Inventory Compliance monitoring works better when the firm knows which customer relationships and accounts exist.
6.3 — Require Approved Assets to be Managed Due diligence depends on governed handling of customer risk records and monitoring inputs.
8.2 — Inventory and Control of Software Assets Digital asset compliance platforms depend on controlled systems that support identity and monitoring workflows.
Recommendation — Maintain an inventory of customer accounts and review-relevant records. Keep customer risk records and monitoring inputs under controlled management. Control the systems that collect, store, and assess customer compliance data.
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Exposure Digital asset compliance often tracks accounts and wallets whose abuse changes due diligence conclusions.
NHI-07 — Overprivileged Non-Human Identities Platform and compliance systems need limited access so review data cannot be misused or altered.
NHI-10 — Third-Party and Supply Chain Risk Digital asset firms often rely on vendors for identity, screening, or monitoring support.
Recommendation — Reduce exposure from credentials that can alter customer risk or activity. Limit system access to preserve the integrity of customer review data. Assess third-party dependencies that affect customer onboarding and review.
NIST SP 800-63 IAL — Identity Assurance Level KYC is fundamentally about how strongly a customer identity has been verified.
Recommendation — Set the assurance level required for customer identity verification.

Practitioner Guidance

What to verify: Check that your KYC file can support an initial risk rating, but also that due diligence procedures define what evidence or activity triggers a review. If the program cannot explain when a customer moves from standard monitoring to enhanced review, the control design is incomplete.

Decision rule: Treat KYC as the minimum entry condition and due diligence as the ongoing decision layer. If the customer’s activity, counterparty profile, or documented purpose no longer matches the onboarding narrative, escalate for review rather than relying on the original KYC outcome.

Practitioner takeaway: The strongest programmes do not choose between KYC and due diligence, they connect them, so identity evidence, behaviour monitoring, and risk review all point to the same compliance decision.