Know Your Customer screening is the process of verifying a customer’s identity and assessing regulatory risk before granting access to services. In practice, it combines identity evidence, sanctions and watchlist checks, and business rules to confirm that the person or organisation is legitimate enough to onboard.
Expanded Definition
Know Your Customer screening is the pre-onboarding process used to verify identity evidence, assess sanctions exposure, and apply risk rules before a service relationship begins. In regulated environments, it is the control point that separates a valid customer from a prohibited, high-risk, or fictitious one.
Its scope is broader than a one-time document check. Effective screening often includes beneficial ownership review, watchlist matching, politically exposed person checks, and ongoing monitoring when the risk profile changes. The exact workflow varies by jurisdiction and sector, and definitions vary across vendors and regulators, so a screening program should be designed to satisfy the applicable obligations rather than a generic checklist. For baseline policy context, organisations often map their process to the FATF Recommendations and then operationalise it with internal risk thresholds. A useful NHI parallel is that the same discipline used to decide who can onboard as a customer should also govern which non-human identities are trusted to access systems and data.
The most common misapplication is treating KYC as a single pass at signup, which occurs when teams skip re-screening after ownership changes, adverse media, or sanctions updates.
Examples and Use Cases
Implementing KYC screening rigorously often introduces onboarding friction and false-positive review work, requiring organisations to weigh customer experience against regulatory defensibility.
- A bank screens a new business customer against sanctions lists, then escalates for enhanced due diligence when the beneficial owner is located in a higher-risk jurisdiction.
- A fintech uses document verification plus biometric liveness checks to reduce impersonation risk before account activation, while retaining manual review for edge cases.
- An insurer screens applicants and related entities against politically exposed person data and adverse media to set pricing and approval conditions.
- A payments platform re-runs screening when a customer’s ownership structure changes, because an originally low-risk account can become restricted after a merger or acquisition.
- For NHI governance, the same control logic described in the Ultimate Guide to NHIs is applied to service onboarding: identity proofing, approval thresholds, and review gates before credentials are issued.
Standards and guidance continue to evolve, so organisations should align screening depth to the use case instead of assuming one workflow fits every customer class. The identity assurance concepts discussed in FATF Recommendations are often translated into risk-based onboarding rules, while the same logic can inform internal approval flows for privileged service accounts.
Why It Matters in NHI Security
KYC matters in NHI security because the control logic is the same: verify legitimacy before access is granted, then keep re-evaluating risk as conditions change. When that discipline is weak, organisations end up onboarding fraudulent customers, shell entities, or third-party relationships that later become conduits for abuse, fraud, and account takeover. The same weak gates that let a bad customer through often correlate with poor credential governance, excessive trust, and missing audit trails.
NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, and that lack of visibility is closely related to weak identity governance across both human and non-human populations. The Ultimate Guide to NHIs also notes that 97% of NHIs carry excessive privileges, which is why screening discipline should not stop at customer identity and should extend to every identity granted access to resources. KYC and NHI governance share a common failure mode: trust is granted once and never revisited.
Organisations typically encounter the cost of weak screening only after a sanctioned party, fraudulent entity, or misrepresented customer has already been onboarded, at which point KYC becomes operationally unavoidable to unwind exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity proofing and legitimacy checks reduce risky onboarding for non-human identities. |
| NIST SP 800-63 | IAL2 | Identity evidence strength maps to assurance levels used in customer verification. |
| NIST CSF 2.0 | PR.AA-01 | Access is granted only after identities are verified and authorized. |
| NIST AI RMF | Risk-based screening reflects AI governance principles for trustworthy operations. | |
| NIST Zero Trust (SP 800-207) | Zero Trust requires continuous verification rather than one-time onboarding trust. |
Apply documented risk thresholds and monitor screening decisions for bias and drift.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org