Join our Newsletter — 33% off our NHI Course
Home Glossary Identity Beyond IAM Know Your Customer Process
Identity Beyond IAM

Know Your Customer Process

← Back to Glossary
By NHI Mgmt Group Updated September 6, 2026 Domain: Identity Beyond IAM

Know Your Customer process is the set of checks an organisation uses to verify a customer’s identity, assess risk, and meet regulatory obligations before and during onboarding. In practice, it combines document verification, screening, monitoring, and review steps to reduce fraud and support AML compliance.

Expanded Definition

The Know Your Customer process sits at the point where identity verification becomes a controlled business decision. It is not just a one-time document check; it is a lifecycle of customer due diligence that can include identity proofing, sanctions and PEP screening, risk scoring, source-of-funds checks, and periodic review. In regulated environments, KYC also helps establish whether the customer profile matches the expected use of the service and whether enhanced due diligence is needed.

The boundary that is often missed is between KYC and adjacent controls. KYC does not replace fraud analytics, transaction monitoring, or AML investigation work, but it supplies the customer identity baseline those controls depend on. Where evidence is weak, the organisation may still onboard, but with tighter review, restricted products, or escalation for manual approval. For a standards-level view of the AML expectations that shape KYC programmes, see FATF Recommendations — AML and KYC Framework.

Industry consensus is strong on the need for risk-based KYC, but not on a single universal operating model. The practical reality is that KYC quality depends on the data source, the customer type, and the level of trust the organisation is prepared to assign at onboarding.

Examples and Use Cases

KYC appears in different forms depending on the service model and the regulatory burden. Common examples include:

  • A bank verifies a new retail customer’s identity with government-issued documents and liveness checks before enabling account access.
  • A payments provider screens a business customer against sanctions, adverse media, and beneficial ownership data before activating merchant services.
  • A cryptoasset platform applies enhanced due diligence when a customer’s geography, activity pattern, or ownership structure raises AML concern.
  • A fintech revisits customer records during periodic review to confirm that risk ratings still match observed behaviour and account usage.
  • An insurer or lending platform requires stronger evidence for higher-risk customers, even when the same product can be sold through a simpler path.

The main tradeoff is friction versus assurance. A lighter process improves conversion, but weak verification increases false identities, account abuse, and downstream remediation work.

Security Implications

When KYC is poorly designed, the immediate problem is not just regulatory weakness. The organisation may end up trusting a customer record that does not reflect a real, reachable, or consistent identity. That creates exposure to synthetic identities, impersonation, mule activity, account takeover facilitation, and abuse of financial products or limits.

Weak KYC also degrades the value of every control that depends on customer identity quality. Screening can miss true matches when names, addresses, or ownership data are incomplete. Monitoring becomes harder when the baseline profile is wrong. Investigations slow down because analysts cannot tell whether the issue is genuine risk escalation or bad onboarding data.

A common practitioner observation is that KYC failures often show up later as exception handling. Rework, manual overrides, duplicated records, and repeated requests for the same documents are often signs that the onboarding model is accepting poor evidence and pushing uncertainty downstream.

Domain and Governance Relevance

KYC matters because it turns identity assurance into an operational control with legal and accountability implications. In banking, payments, lending, and other regulated services, it helps determine whether a customer can be trusted for onboarding, what level of diligence is required, and whether ongoing review must continue after the initial check.

For identity governance, the important point is that KYC establishes the origin of trust, not just the presence of a name or document. That baseline affects who can be onboarded, what services they can access, how much monitoring they receive, and when a relationship should be restricted or terminated. In NHI-heavy environments, the same logic reappears when organisations use customer-style due diligence for machine accounts, delegated access, or automated service relationships: the trust decision is only as strong as the evidence behind it.

Practically, KYC is as much about accountability as it is about verification. Organisations need a clear owner for standards, escalation thresholds, review cadence, and exceptions, because the control fails when no one is responsible for deciding what “enough evidence” means.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63IAL2 — Identity Assurance Level 2KYC depends on the strength of identity proofing before trust is granted.
Recommendation — Apply IAL requirements to raise proofing strength before onboarding trust is established.
NIST CSF 2.0PR.AC-1 — Identity and Access ManagementKYC establishes the identity baseline that later access decisions rely on.
Recommendation — Use PR.AC-1 to ensure verified identity data supports account access decisions.
CIS Controls v86 — Access Control ManagementKYC failures often create weak or ungoverned customer access paths.
Recommendation — Use Control 6 to restrict onboarding outcomes when identity evidence is insufficient.
DORAICT risk management — ICT risk managementKYC programmes in financial services must be governed as operational risk controls.
Recommendation — Treat KYC governance as part of ICT risk management and business resilience oversight.
NIS2Risk management measures — Risk management measuresKYC assurance affects trust, monitoring, and control quality in regulated services.
Recommendation — Embed KYC evidence standards into risk management measures for regulated service access.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org