Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Know Your Customer’s Customer
Governance, Ownership & Risk

Know Your Customer’s Customer

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Governance, Ownership & Risk

Know Your Customer's Customer is an extended diligence approach that examines the downstream customers served by a business partner or intermediary. It is used when regulators or risk conditions require visibility beyond the immediate counterparty, especially where financial crime exposure may be indirect or obscured.

What Know Your Customer's Customer Means in Practice

Know Your Customer's Customer extends due diligence beyond the immediate counterparty to the downstream customers that intermediary serves. It matters when indirect exposure, hidden distribution chains, or layered relationships make the true risk profile unclear.

That shift changes the unit of analysis. Instead of asking only whether the direct business partner is legitimate, organisations also ask what types of customers, sectors, geographies, payment flows, or resale channels sit behind that partner and whether those patterns increase financial crime exposure.

Why the Term Exists

The term reflects a practical gap in standard customer due diligence. A direct customer can look acceptable on its face while still acting as a conduit into higher-risk activity, including fraud, sanctions exposure, money laundering typologies, or misuse of the partner’s platform or distribution channel.

In many programmes, Know Your Customer's Customer is not a universal obligation but an enhanced diligence response. It is used when the risk is indirect, when the intermediary obscures the end user, or when the business model depends on customers whose own customer base creates material exposure.

For financial crime and onboarding teams, the key question is not simply “who is our counterparty?” but “what business is that counterparty really enabling?” The answer can materially affect acceptance decisions, ongoing monitoring, and escalation thresholds.

How It Differs from Standard Customer Due Diligence

Standard due diligence focuses on the immediate customer or relationship holder. Know Your Customer's Customer adds a second layer, looking through that relationship to understand the parties, use cases, and transaction patterns ultimately reached through it.

This is especially relevant in correspondent relationships, resellers, marketplaces, payment intermediaries, platform providers, and other models where customer identity and activity are not fully visible at the first hop. The stronger the intermediary’s control over downstream onboarding and transaction monitoring, the more important it becomes to understand those controls rather than relying on the intermediary’s assurance alone.

The concept is often confused with collecting more documents from the direct customer. In reality, it is about visibility and risk attribution, not just paperwork. The goal is to understand the downstream customer base well enough to judge whether the intermediary’s business model is compatible with the organisation’s risk appetite and regulatory duties.

What Good Visibility Looks Like

Effective extended diligence usually combines business-model analysis, customer-base profiling, transaction-flow review, and an assessment of the intermediary’s own controls. A useful review asks whether downstream customers are screened, whether activity is monitored, and whether the partner can identify unusual patterns when they arise.

Where the downstream customer base is broad or opaque, FATF Recommendations, the AML and KYC framework provide the core baseline for customer due diligence, beneficial ownership, and ongoing risk-based controls. For identity assurance at onboarding, NHIMG’s Identity Proofing and KYC Guide explains how stronger verification methods reduce the chance that the first layer of trust is already compromised.

When the downstream customer profile itself creates risk, the practical issue is whether the intermediary can still demonstrate transparency, escalation, and control. If it cannot, the organisation may need to treat the relationship as higher risk even if the direct counterparty appears compliant on paper.

Risk and Threat Considerations

Know Your Customer's Customer is designed to reduce hidden exposure, because the direct counterparty may not be the real source of financial crime, sanctions, fraud, or misuse. Indirection creates a blind spot: the immediate customer can be legitimate while the downstream customer base contains the behaviour or geography that drives the actual risk.

Failure mechanism: Risk is created when an intermediary cannot reliably reveal, screen, or monitor the customers it serves, allowing unsafe activity to flow through a relationship that otherwise appears acceptable.

Impact: Organisations can misprice risk, miss suspicious activity, fail due diligence expectations, and retain relationships that become vectors for laundering, sanctions breach, fraud enablement, or regulatory scrutiny.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Downstream customer visibility depends on external-user identity assurance and proofing.
IA-12 — Identity ProofingKYC-style onboarding depends on proofing the identity of external parties.
AU-6 — Audit Record Review, Analysis, and ReportingOngoing monitoring of downstream activity depends on reviewing and analysing transaction evidence.
Recommendation — Apply IA-8 to verify non-organizational users behind intermediary relationships. Use IA-12 to strengthen identity proofing where customer onboarding risk is high. Use AU-6 to review downstream activity for suspicious patterns and escalation triggers.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe term is used to manage indirect counterparty risk through a risk-based diligence strategy.
ID.RA-01 — Asset Vulnerabilities and Cybersecurity RisksExtended diligence identifies exposures created by opaque downstream customer relationships.
Recommendation — Align KYC2C reviews to a documented risk strategy for indirect exposure and escalation. Assess downstream customer relationships as part of risk analysis for the relationship.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsIntermediaries function as third-party relationships whose downstream risks must be governed.
A.5.20 — Addressing information security within supplier agreementsContracts can require intermediaries to provide downstream visibility and screening assurances.
A.5.21 — Managing information security in the ICT supply chainIndirect exposure often flows through layered supplier and distribution chains.
Recommendation — Set supplier-relationship controls that require visibility into downstream customer risk. Include contract terms that obligate downstream customer transparency and monitoring. Extend supply-chain governance to the downstream customer chain behind intermediaries.
SOC 2 (AICPA)CC6.1 — Logical and Physical Access ControlsAccess governance depends on knowing who is ultimately served through the counterparty relationship.
CC9.2 — Vendor and Third-Party Risk ManagementThe concept evaluates risk inherited from business partners and their customer base.
Recommendation — Use CC6.1 to enforce access controls around downstream customer visibility and review. Apply CC9.2 to assess third-party relationships that pass exposure through to downstream customers.

Practitioner Guidance

Governance implication: Treat Know Your Customer's Customer as an escalation path, not a blanket requirement. Use it when the business model, distribution chain, or regulatory context makes downstream visibility materially important to the decision about onboarding, monitoring, or retention.

What to watch for: Opaque reseller structures, platform aggregation, high-risk customer segments, weak downstream screening, and inconsistent explanations of who actually uses the product or service are the signals that usually justify deeper review. The most useful judgment is often whether the intermediary can evidence control over its own customer base, not just describe it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org