- Aug 18, 2026
- 20 min read
KYC and AML Explained: Key Differences, Regulations, and Best Practices
This KYC and AML compliance guide helps you understand key differences, global regulations, and best practices for banking, crypto, and fintech.

KYC (Know Your Customer) is a fundamental component of AML (Anti-Money Laundering) regulations, requiring financial institutions to verify the identity, suitability, and risks associated with customers to prevent illegal activities such as money laundering and terrorism financing.
KYC is the first line of defense for both regulated and non-regulated businesses, as it takes place when bringing new customers on board. It provides an opportunity to spot potential criminals before they become customers (for example, by spotting a fake ID), preventing financial crime from taking place through a business.
However, KYC alone is not enough to prevent financial crime: customers must be continually monitored for signs of criminal activity. Where suspicious activity is detected, businesses are required to investigate and report to the appropriate authorities. This is all part of a broader AML framework that businesses need to have in place to meet their regulatory obligations.
Non-compliance with KYC and broader AML laws can carry significant risks, including the potential for regulatory penalties, financial losses, and reputational damage.
What is KYC?
KYC refers to the set of processes businesses use to identify and verify customers, assess their risk, and, where required, monitor their activity on an ongoing basis. Its purpose is to establish who customers are and understand the potential risks they may pose. KYC is a key part of Customer Due Diligence (CDD), which involves assessing and managing a customer’s money laundering and terrorist financing (ML/TF) risks based on factors such as their identity, activities, and risk profile.
The scope of identity information to be obtained varies by jurisdiction. Usually, businesses need at least the following data:
- Name
- Nationality/residence
- Date of birth
- Address.
During the verification process, customers provide businesses with certain credentials, such as their ID. It's on the businesses to ensure that submitted documents aren’t fake and that customers are who they say they are. This is done through various checks, including document verification, liveness checks, and consultations with government databases and lists.
Suggested read: What Is KYC? A Complete Guide to Know Your Customer Verification
What is perpetual KYC?
Perpetual KYC (pKYC) is a continuous approach to KYC that keeps customer information and risk assessments up to date throughout the customer lifecycle, rather than treating KYC as a one-time check at onboarding. It helps businesses detect changes in a customer’s identity, risk profile, or activity and trigger a review when new information or risk signals emerge.
What is AML?
Anti-Money Laundering (AML) is a series of measures and procedures carried out by financial institutions and other regulated entities to prevent financial crimes. For regulated businesses, this includes analyzing customers and their transactions, recordkeeping, reporting to AML authorities on suspicion of money laundering, and so forth.
Although the name refers specifically to money laundering, AML frameworks generally also address terrorist financing, sanctions evasion, and other related forms of financial crime. AML encompasses the organization’s policies, processes, technology, governance, and regulatory reporting arrangements.
The Financial Action Task Force (FATF) establishes international anti-money laundering/counter-terrorism financing standards through its Recommendations. Countries then implement these standards through national or regional laws adapted to their legal systems and risk environments. As a result, the underlying principles are similar worldwide, but the businesses covered and the required checks vary between jurisdictions.
National authorities also issue guidelines that help businesses understand their AML obligations.
Regulated entities are required to comply with local AML regulations. A number of non-regulated businesses may also be subject to the same AML requirements as regulated financial institutions.
Suggested read: AML Policy Explained: A Step-by-Step Guide to AML Compliance
AML vs. KYC: Key differences
AML involves a broad range of measures, usually referred to as an AML compliance program. KYC is just one component of this program and therefore sits inside AML.
Put simply, the difference between KYC and AML is that KYC focuses on understanding the customer, whereas AML governs how an organization prevents, detects, investigates, and reports money laundering and related financial crime. KYC supplies identity and risk information that the wider AML framework then uses throughout the customer lifecycle.
In recent years, it’s become clear that KYC alone isn’t enough anymore to stop criminals from scamming companies. Our research shows that 76% of fraud takes place after KYC. Fraud that goes undetected post-onboarding often represents unmonitored money laundering exposure, since the proceeds of fraud are themselves laundered. So, while KYC remains an important part of any company’s security structure, businesses need a broader approach.
AML program requirements can vary across jurisdictions. But, usually, they involve the following:
- KYC and Customer Due Diligence (CDD)
- Enhanced Due Diligence (EDD), when needed
- Risk assessment
- AML policies and internal controls
- Ongoing monitoring
- Suspicious activity and transactions reports
- AML compliance officer appointment
- AML training programs for staff
KYC vs. AML: Comparative overview
The following comparison shows how KYC and AML compliance differ in scope and purpose:
| AML | KYC | |
| Scope | Preventing money laundering and maintaining regulatory compliance | Knowing who the customers are and the risks they may pose |
| Focus | Detecting, investigating, and reporting signs of money laundering | Verifying customers’ identities, investigating their background, and determining their individual risk |
| Key processes | Taking a risk-based approach to AMLCreating an AML frameworkAppointing an AML compliance officerAML staff trainingCustomer identification and verification, usually prior to establishing a business relationship (including KYC)Transaction monitoring to identify suspicious activityInvestigating suspicious activityReporting suspicious activity to the appropriate authoritiesKeeping accurate records in line with regulatory requirements | Collecting identity information from customersVerifying the accuracy of this information |
Why KYC and AML go hand in hand
KYC is a key part of any AML program. It is the process by which new customers have their identities verified and their individual risk levels assessed.
KYC involves:
- Identifying new customers. Collecting information such as their name, address, and date of birth.
- Verifying their identity. Checking the information a customer has given is accurate using resources such as official documents and government databases.
- Carrying out Customer Due Diligence (CDD) to determine customers’ level of risk. Looking at things such as the customer’s source of funds and whether they are on any official lists of high-risk individuals (e.g., politically exposed persons or sanctioned individuals).
Without effective KYC, an AML program cannot function properly, as there would be no way to know who customers are, whether they are who they say they are, or what steps need to be taken to mitigate money laundering risks.
Identity verification may show that a person is genuine, but it cannot establish that all their future activity will be legitimate. To combat financial crime, effective AML procedures connect onboarding data and risk scoring with screening, transaction monitoring, investigation, and reporting throughout the relationship.
Understanding when KYC and AML are mandatory
AML compliance, including KYC, is mandatory for regulated entities under AML/CFT regulations. The scope of regulated entities varies across jurisdictions. Usually, this includes:
- Banks
- Credit institutions
- Insurance companies
- E-money institutions
- Payment institutions
- Virtual Asset Service Providers (VASPs)
- Gambling service providers
- Art dealers, etc.
VASPs fall under AML regulations in many countries, including the US, Canada, the UK, France, Singapore, Japan, South Korea, South Africa, UAE, and others. In some other countries, VASPs aren’t yet even written into law, or are banned altogether.
Depending on local AML regulations, obliged entities may also include real estate professionals, lawyers, accountants, trust and company service providers, dealers in precious metals or high-value goods, and other designated non-financial businesses and professions. A business’s legal duties depend on what it does and where it operates, rather than simply whether it describes itself as a bank or fintech.
CDD, which begins with KYC identity verification, is required in several cases as described in national AML regulations. These typically include, but are not limited to, cases where the client:
- Establishes a business relationship with a business for the first time (for example, by opening an account with a bank or crypto exchange platform)
- Raises suspicions of money laundering or terrorist financing.
AML requirements may also apply to certain transactions or activities, depending on the applicable jurisdiction and thresholds. For example, iGaming businesses may be subject to AML requirements once a customer’s activity reaches a specified threshold.
National rules may set additional triggers, verification deadlines, occasional-transaction thresholds, or sector-specific exemptions. This is why KYC requirements for banks, crypto platforms, payment companies, and other obliged entities cannot be reduced to a single universal checklist.
Not all AML-obliged entities are financial institutions. Certain non-financial businesses and sectors may also fall within the scope of AML legislation and have obligations such as customer identification, recordkeeping, and risk management. Other businesses may have separate legal or regulatory requirements to identify and verify their customers—for example, for security reasons. Businesses should therefore determine which requirements apply to their sector and jurisdiction. Even where AML controls are not mandatory, a risk-based approach can help businesses manage fraud, money laundering, and other risks without creating unnecessary friction for legitimate customers.
For transportation businesses, for example, verifying customers can help meet security requirements, secure better payment terms, and reduce insurance costs. For e-commerce and delivery businesses, stronger KYC can help access more favorable payment solutions and reduce withdrawal costs, while emerging measures such as Verification of Payee further increase the importance of accurate customer and payment information.
KYC and AML in banking, crypto, and fintech
Banking, fintech, and crypto markets are the most vulnerable to money laundering and fraud. Effective KYC/AML processes can mitigate this by:
- Meeting regulatory requirements and reducing reputational risk. In these industries, KYC/AML is a regulatory requirement. By complying with AML laws and regulations, businesses can avoid hefty fines and other regulatory penalties while protecting their reputation. At the same time, robust KYC processes help businesses identify and prevent criminals from accessing their services and using them to launder money or commit fraud.
- Detecting fraudsters. In financial services, fraudsters may use fake IDs or employ sophisticated schemes, such as money muling or synthetic identities. So, KYC helps businesses verify the identities of their customers and identify potential fraud risks, making it harder for fraudsters to use stolen or fabricated identities to access their services.
- Improving user experience. When businesses optimize their KYC/AML flows based on applicant risk profiles, users don’t have to undergo additional checks. This reduces drop-offs and improves the user experience.
Although the core principles are shared, how KYC and AML operate depends heavily on the product and the risks it poses.
AML/KYC in banking: Banks generally face some of the most extensive AML obligations because they provide accounts, cash services, lending, international payments, correspondent banking, and other products that can be exploited at several stages of the money laundering process. Controls commonly include CDD and beneficial-ownership checks, sanctions screening, customer risk rating, transaction monitoring, recordkeeping, and suspicious activity reporting. Higher-risk relationships, with PEPs or customers linked to high-risk jurisdictions, may require EDD and more intensive monitoring.
AML/KYC in crypto: Crypto exchanges and other regulated VASPs must verify users, screen customers and wallets, monitor on-chain and off-chain activity, investigate exposure to illicit services, and comply with the FATF Travel Rule. Anonymous customers, rapid cross-border transfers, mixers, privacy-enhancing tools, self-hosted wallets, sanctions exposure, and links between on-chain addresses and verified accounts can all require additional controls.
AML/KYC in fintech: A payment institution, e-money issuer, digital lender, neobank, broker, or remittance platform may face different obligations. Some fintechs hold their own licenses; others provide services through regulated partners. Each must establish which entity performs customer checks, monitoring, investigations, and reporting, while retaining appropriate oversight of outsourced functions.
Suggested read: The Ultimate KYC/AML and Fraud Prevention Guide for Fintechs
Key challenges in KYC and AML compliance
Anyone involved in KYC and AML compliance will face a number of challenges, but the good news is that these can all be overcome with the right approach and resources. The following are some of the most common challenges and how they can be mitigated.
Resource and operational constraints
Many AML teams struggle with resource constraints, especially when a business is scaling rapidly. This can lead to bottlenecks in areas such as customer onboarding, hampering a business’s ability to grow.
Scalable AML and KYC compliance tools can help by allowing you to rapidly add extra capacity when needed. Because many processes are automated, this additional capacity can be added without increasing headcount. Automation doesn’t just make processes faster; it often reduces the risk of human error as well. For example, detecting deepfakes or manipulated images is difficult and time-consuming for humans. Automation and AI can perform these tasks quickly and with high accuracy.
Adapting to an evolving regulatory landscape
AML regulations are updated frequently to strengthen protections and match the changing tactics of money launderers. AML/KYC frameworks must stay up to date with these changes to maintain compliance, which can be laborious. Any gaps in a framework created by a change to regulations could expose a business to the risk of penalties and reputational harm.
Choosing the right AML and KYC tools can help with this. Look for tools that are regularly updated to match the latest changes in AML regulations, so you can be confident that they and you will remain compliant.
Managing false positives and alert fatigue
False positives occur when a legitimate customer or transaction is flagged as suspicious. This can happen for a number of reasons, including criteria that are too broad or sensitive, and failure to properly risk-score customers. False positives can waste resources on unnecessary investigations and can prevent genuine customers from being onboarded.
Good AML and KYC tools reduce false positive rates using technology such as AI to learn from data, understand context, and make real-time adjustments to AML transaction monitoring criteria and avoid excessive low-quality alerts.
How fraud and money laundering are connected
Fraud and money laundering are often closely linked. Fraud generates illicit funds, and money laundering is the process of disguising their criminal origin and making them appear legitimate. Here’s how the process typically works:
- A fraud is committed—for example, an investment scam, phishing attack, or romance scam.
- The fraudster receives the proceeds. These funds now have a traceable connection to the underlying crime.
- The criminal then attempts to conceal the origin. If the funds are spent or deposited directly, they may be detected, traced, or seized. This is where money laundering begins.
Criminals may attempt to disguise the origin of funds by:
- Moving funds through multiple wallets or bank accounts
- Converting funds between different cryptocurrencies
- Using mixers or cross-chain bridges, where legally permitted
- Exchanging crypto for fiat through multiple services
- Purchasing assets that can later be sold to obscure the source of the funds
Suggested read: The Three Stages of Money Laundering: How Placement, Layering, and Integration Work in 2026
Countering sophisticated criminal schemes
As AML systems become more sophisticated, criminals adapt to use new tactics and exploit gaps in those systems. Examples of this in financial crime include:
- Deepfakes and synthetic media: Fraudsters increasingly use AI-generated images, videos, or documents to bypass KYC checks. Standard document verification or facial recognition may fail against sophisticated deepfakes unless tools use advanced detection technology. For example, global cryptocurrency exchange MEXC spotted 3,097 fraudulent liveness cases using AI deepfake technology in July–August 2025, representing a 15% increase on the previous period.
- Money mule networks with clean identities: Criminals often recruit or coerce individuals with legitimate, verified identities to move illicit funds. Because these “mules” pass KYC checks, detection requires behavioral monitoring, transaction analysis, and network-based risk assessment, not just static identity verification.
- Targeting smaller entities and those in less-regulated areas and sectors: Smaller regulated businesses often have fewer resources and less sophisticated KYC/AML processes, making them attractive targets for fraudsters looking to get through onboarding checks. Money launderers, by contrast, may prefer non-regulated businesses because they often have no KYC requirement to get through in the first place, as well as less oversight, fewer compliance controls, and fewer reporting obligations.
Staying current with criminals' latest strategies can be difficult, especially for businesses running older technology.
AI-powered AML/KYC tools are among the most effective ways to proactively respond to new and emerging threats.
Navigating cross-border regulatory requirements
Where a business operates across multiple jurisdictions, it will often need to comply with different AML/KYC requirements in those markets. This can create challenges for compliance teams who will need to be familiar with different regulations, and AML systems will need to be designed for different regimes.
Choosing AML/KYC tools that are designed for international markets can make it much more straightforward to meet the requirements of different regulatory regimes smoothly and cost-effectively.
Strengthening organizational risk culture
Risk culture is often overlooked. If employees do not understand the importance of financial crime risk management, lack the necessary knowledge, or do not adopt the right mindset, there is no guarantee that processes will be followed effectively.
Building a strong risk culture must start at the top and be reinforced at every level of the organization. The entire team should be engaged through targeted training and appropriate incentives. The right tools can support this effort by streamlining training, reducing the administrative burden of AML compliance, and helping secure buy-in from all relevant personnel.
Key global KYC/AML regulations in 2026
Each country has its own set of regulations, which set out the applicable reporting processes and the consequences of non-compliance.
The FATF Recommendations provide the international baseline, but they are not a directly applicable global law. Each jurisdiction determines which entities are obliged, what KYC compliance requires, how suspicious activity must be reported, and which regulator supervises the business. Companies operating internationally must assess every relevant national or regional regime.
Are regulations getting tighter?
Generally, yes. 2026 is a major year for AML/CFT regulatory developments, with 2027 set to bring further significant changes as new EU rules begin to apply.
AML/KYC regulations are expected to become increasingly comprehensive in the coming years, with stricter rules and the closing of existing loopholes. Regulators are expanding AML and transaction monitoring obligations to cover a wider range of industries, aiming to prevent money laundering, fraud, and terrorist financing in previously lightly regulated sectors. As part of this trend, companies in these industries are expected to implement robust AML and KYC controls.
FATF’s 2025 amendments to Recommendation 1 strengthened the emphasis on proportionality and financial inclusion. Effective AML regulations increasingly expect controls to be demonstrably connected to risk, supported by reliable data, and adjusted when the risk changes.
AML/KYC regulations by country
The following overview summarizes major developments and frameworks for AML/KYC requirements around the world.
US
The main AML regulation in the US is the Bank Secrecy Act. This imposes requirements on regulated entities, such as:
- Establishing comprehensive AML compliance programs,
- Performing ID verification and customer due diligence (CDD)
- Monitoring and reporting suspicious transactions
- Making Currency Transaction Reports (CTRs) for cash transactions over $10,000
- Maintaining detailed records for at least five years
- Having regular, independent testing of the program's effectiveness
Additional AML regulations in the US include the Patriot Act and the Anti-Money Laundering Act (AMLA) 2020.
The requirements differ by type of financial institution. Banks, for example, must operate a Customer Identification Program, while FinCEN’s CDD Final Rule requires covered financial institutions to identify and verify customers; understand the nature and purpose of relationships; conduct ongoing monitoring; and identify and verify the beneficial owners of legal-entity customers, subject to exceptions.
In February 2026, FinCEN granted exceptive relief so covered institutions no longer have to identify and verify a legal entity customer’s beneficial owners every time that same customer opens another account. In April 2026, FinCEN also proposed reforms intended to make AML/CFT programs more effective, risk-based, and aligned with national priorities.
Separately, the US Treasury's Office of Foreign Assets Control (OFAC) administers economic and trade sanctions, requiring businesses to screen customers and transactions against OFAC's Specially Designated Nationals (SDN) list and other sanctions lists. Unlike BSA/AML obligations, sanctions compliance is generally strict liability, regardless of intent.
Suggested read: AML Laws and Regulations in the US
EU
Regulation (EU) 2024/1624, known as the AML Regulation or AMLR, establishes directly applicable AML/CFT rules across the EU. Key requirements include:
- Carrying out ID verification and CDD
- Establishing transparency about the beneficial ownership of assets
- Reporting suspicious activity
- Retaining records for at least five years from the date a business relationship ends or the last transaction takes place
It generally applies from July 10, 2027.
The AMLR also widens the list of obliged entities well beyond banks and traditional financial firms. Newly covered sectors include crypto-asset service providers, crowdfunding platforms, traders in high-value goods, and professional football clubs and agents. The high-value goods category captures dealers in jewelry, watches, luxury vehicles, yachts, aircraft, art, and cultural goods above EUR 10,000 in transaction value. Football clubs and agents join on a later timeline, with a deadline to be compliant by July 10, 2029 rather than 2027.
Additionally, Directive (EU) 2024/1640 addresses national supervisory and FIU mechanisms, with phased transposition deadlines.
In 2026, obliged entities continue to comply with applicable national laws, while the EU’s new Authority for Anti-Money Laundering and Countering the Financing of Terrorism, operational since July 2025, is currently issuing draft technical standards and building supervisory convergence ahead of the 2027/2028 rollout.
Suggested read: MiCA Regulation and EU Crypto Rules
APAC
AML regulations vary considerably across the Asia-Pacific (APAC) region.
Australia’s reformed AML/CTF regime introduced updated obligations for existing reporting entities from March 31, 2026. Lawyers, accountants, real estate professionals, dealers in precious metals and stones, trust and company service providers, and providers of certain additional virtual asset services came within scope from July 1, 2026. Depending on their activities, regulated entities must:
- Implement and maintain a risk-based AML/CTF program
- Conduct CDD, including identity and beneficial-ownership checks
- Monitor customers and transactions on an ongoing basis
- Report suspicious matters and other prescribed transactions
- Comply with Travel Rule requirements for relevant virtual-asset transfers
- Keep the required customer and transaction records
- Some requirements and transitional arrangements vary according to the service provided
Singapore’s AML/CFT framework combines legislation such as the Corruption, Drug Trafficking, and Other Serious Crimes (Confiscation of Benefits) Act 1992 and the Financial Services and Markets Act 2022 with sector-specific laws and Monetary Authority of Singapore (MAS) notices. The Payment Services Act 2019 and the associated MAS notices are particularly relevant to payment service providers and digital payment token businesses. Obligations commonly include:
- Assessing and mitigating money laundering, terrorism-financing, and proliferation-financing risks
- Identifying and verifying customers and beneficial owners
- Conducting ongoing CDD and account reviews
- Monitoring and reporting suspicious transactions
- Keeping the required records
- Applying enhanced measures to higher-risk customers and relationships
In July 2026, MAS also published additional supervisory expectations for digital payment token service providers, covering areas such as enterprise-wide risk assessment, customer risk assessment, transaction monitoring, and the use of data and technology.
In Hong Kong, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO) establishes CDD and recordkeeping requirements for financial institutions, including SFC-licensed virtual asset trading platforms. The Banking Ordinance and other related legislation also form part of the framework for relevant institutions. Requirements include:
- Implementing and maintaining a risk-based AML/CFT compliance program
- Carrying out CDD and KYC procedures
- Identifying and verifying beneficial owners
- Maintaining ongoing customer and transaction monitoring
- Reporting suspicious transactions to the relevant authorities
- Keeping detailed customer and transaction records
- Maintaining appropriate compliance, control, and independent-review arrangements
The Securities and Futures Commission (SFC) and Hong Kong Monetary Authority (HKMA) supervise regulated entities within their respective remits.
Suggested read: AML/KYC Compliance in the Philippines
LATAM
Latin American (LATAM) countries each have their own AML laws. Brazil’s AML regulations are set out in several instruments, including Law No. 9,613/1998 (the 'AML Law'). Brazil’s AML regulatory requirements include:
- Implementing risk-based internal controls
- Carrying out ID verification and CDD
- Maintaining ongoing transaction monitoring
- Reporting suspicious activity to the authorities within 24 hours
- Keeping detailed records for at least five years
Argentina’s AML rules are also set out in several acts. These include Law 25.246 (AML Law) and Law 26.683 (which established money laundering as a separate criminal offense). Under Argentinian AML rules, regulated entities must take steps, including:
- Taking a risk-based approach to AML
- Appointing an AML compliance officer
- Verifying customer identities and carrying out CDD
- Carrying out transaction monitoring
- Reporting suspicious activities to the authorities
- Keeping detailed records for the required time limit
Guides to AML regulations by country
Here you can find the list of our articles for each country:
- Australia
- Argentina
- Brazil
- Canada
- Chile
- Colombia
- Germany
- Hungary
- India
- Indonesia
- Lithuania
- Malaysia
- Netherlands
- Philippines
- Saudi Arabia
- Singapore
- South Africa
- Thailand
- UAE
- UK
- USA
How organizations apply KYC and AML
The following are key AML processes and how they work in practice, including where KYC fits in.
The risk-based approach to AML/KYC
A risk-based approach means identifying, assessing, and understanding exposure to money laundering, terrorist financing, proliferation financing, and related financial crime, then applying controls proportionate to the risks. It is the cornerstone of the FATF Recommendations and a central requirement in many national AML regimes.
This allows organizations to direct scrutiny and resources where they will be most effective.
A business-wide risk assessment should consider customers, products and services, transaction types, delivery channels, jurisdictions served, technologies, third parties, and the scale and complexity of operations. The organization then evaluates the likelihood and impact of each risk, considers the effectiveness of existing controls, and identifies risk exposure requiring further action.
Customer due diligence applies the framework to individual relationships. This may include screening for identity and beneficial ownership, occupation or business activity, source of funds or wealth, PEP or sanctions exposure, adverse media, product use, and geography. Lower-risk relationships may receive simplified processes, while standard CDD applies in ordinary cases and EDD is used for higher-risk customers or situations.
However, risk should also change when new information appears. A customer assessed as low risk at onboarding may become higher risk following unusual activity, a new PEP match, adverse media, a change of ownership, or movement into a high-risk jurisdiction.
Customer onboarding and CDD
Customer onboarding is the process of bringing a new customer into your business. KYC is the regulatory requirement that obliged entities must follow as part of the onboarding process.
KYC involves collecting identifying information from new customers (such as name, address, and date of birth) and verifying that it is genuine. This can be done through document-based methods (e.g., passports, ID cards, driver’s licenses) or non-document-based methods (e.g., trusted databases, bank account checks, or credit bureau data). Once verified, Customer Due Diligence uses this information to determine the customer’s money laundering risk. The overall goal is to onboard genuine customers with minimal friction, while identifying and investigating high-risk individuals who may need to be blocked or reported.
AI is increasingly critical to KYC and customer onboarding. It can automate many parts of the process, including checking ID documents, carrying out liveness checks, and checking government lists for PEPs and sanctioned individuals. Using AI for KYC can make the process faster, more consistent, and more effective while also reducing costs.
Ongoing transaction monitoring
Transaction monitoring is the process that allows any signs of suspicious activity by a customer to be spotted. Modern AML tools allow businesses to adjust monitoring rules and thresholds and take customer and transaction context into account, helping them detect genuine signs of financial crime without generating excessive false positives.
Effective AML transaction monitoring uses the customer’s expected activity and risk profile as context.
Suggested read: Transaction Monitoring in AML: Ultimate Guide for 2026
Case management and investigation
When suspicious activity is flagged, a case must be created and assigned to an appropriate person for investigation. They will then carry out the necessary checks to determine whether there is reason to suspect money laundering or other financial crime. If there are signs of financial crime, then a report will need to be made to the relevant authorities.
The case should combine relevant customer, transaction, screening, and risk information with notes, decisions, approvals, and deadlines. Consistent workflows create an audit trail, including the rationale for filing or not filing a Financial Intelligence Unit (FIU) report.
Regulatory reporting
Regulated entities will need to report any suspicious activity they detect in line with the regulations for the relevant country. Each jurisdiction will have its own reporting criteria, including what should trigger a report and deadlines for submission.
The types of FIU reports and terminology vary between jurisdictions: they include Suspicious Activity Reports (SARs), Suspicious Transaction Reports (STRs), and Suspicious Matter Reports (SMRs).
Compliance oversight
A compliant AML risk framework will have both internal and external oversight to ensure it functions as intended and meets regulatory compliance requirements.
Internally, businesses should have people handling the first line of defense (monitoring, investigating, and reporting on cases) and a second line team responsible for monitoring and oversight (as well as functions such as policy development and education).
Externally, regular independent audits should be conducted to assess how well a financial risk team meets regulatory requirements and to identify areas for improvement.
Oversight must test whether financial crime AML compliance controls work in practice.
AI and automation in KYC/AML
Businesses can implement either manual (performed by a human compliance team) or automated KYC/AML checks. Automated KYC/AML and sanctions screening solutions reduce the risk of losing applicants by increasing pass rates.
AI and automation in AML/KYC compliance software can support identity verification, risk scoring, screening, behavioral analysis, AML transaction monitoring, and investigation. Organizations remain accountable for automated controls and should test performance, protect data, monitor limitations, retain explainable records, and use human review for higher-risk decisions.
Automated KYC checks
By automating KYC, businesses obtain customer identity data through online identity verification. This process can occur on a mobile or web platform, and usually involves five steps:
- The user selects their ID document type
- The user uploads photos of their document
- The KYC platform screens and validates the document
- Users upload a photo of themselves holding the document
- The KYC platform verifies that the user is a real person.
Automated KYC procedures can also include biometric checks. One of them is called liveness, which is a face authentication process that verifies whether the client is a real person.
Modern automated KYC/AML checks do not always require a customer to hold their document. Depending on the jurisdiction and risk, KYC compliance software may capture the document in real time, extract and validate its data, inspect security features, read an NFC chip, compare the customer’s face with the portrait, and perform passive or active liveness detection. Document-free verification may also check customer information against trusted databases where legally supported.
Suggested read: Machine-Readable Passports vs Biometric Passports: A Complete Guide
Automated AML and sanctions screening
Automated KYC and AML screening solutions are beneficial in terms of costs and efficiency. They reduce manual work and protect businesses from crime by getting reliable data from trustworthy sources, such as:
- PEP lists
- Sanctions lists
- Watchlists
- Adverse media
With automated AML solutions, businesses can build verification flows that comply with AML/KYC requirements in a given jurisdiction.
AML screening software can compare customers, beneficial owners, and counterparties against updated data throughout the relationship. Context such as aliases, spelling, dates of birth, nationality, and identifiers helps teams distinguish genuine matches from similar names.
KYC/AML vendor selection guide
Before comparing KYC/AML providers, businesses should document their legal obligations, risks, jurisdictions, systems, reporting needs, service levels, and in-house responsibilities.
Key questions for evaluating a KYC/AML platform include:
- Coverage: Which countries, languages, identity documents, databases, sanctions sources, payment types, and crypto assets are supported?
- Verification quality: Can the provider detect document tampering, injection attacks, duplicates, masks, deepfakes, and other presentation or identity attacks?
- AML capabilities: Does the platform provide configurable screening for PEP, sanctions, watchlists, adverse media, transactions, and wallets? Can it support ongoing monitoring, perpetual KYC, and Travel Rule workflows?
- Risk and case management: Can teams create risk rules, combine identity and behavioral signals, prioritize alerts, manage investigations, preserve audit trails, and produce jurisdiction-appropriate reports?
- Explainability and governance: Can reviewers see why a check failed or alert appeared?
- Integration and scale: Can the service maintain performance during peak periods and during expansion?
- Security and privacy: Which certifications, encryption, access controls, retention settings, hosting locations, deletion processes, incident procedures, and subprocessors apply?
- User experience: What are the completion, false-positive, manual-review, and processing rates for relevant customer populations?
Suggested read: AML Compliance Buyer’s Guide for Finance 2026
Best practices for KYC/AML compliance
Effective KYC/AML compliance should connect policy, people, data, and technology across the customer lifecycle. Best practices include:
- A risk-based approach. This involves assessing users to determine the money laundering risk they pose. Additional checks can then be carried out on higher-risk individuals.
- Compliance officers. An AML compliance officer will be responsible for managing your AML program and ensuring regulatory compliance.
- An appropriate risk culture. This defines your organization’s values, beliefs, attitudes, and behaviors towards AML risks. A good risk culture is essential to ensure your framework is followed effectively.
- Regular team training. To ensure every member of your team understands their role in preventing money laundering.
- Keeping policies up to date. Policies must be regularly reviewed to ensure they remain compliant with the latest AML rules.
- KYC. This includes identity verification, customer due diligence (CDD), and enhanced due diligence (EDD) for higher-risk individuals.
- Transaction monitoring. This involves assessing customer transactions to identify any suspicious activity or patterns.
- Reporting suspicious activity. Your AML compliance program must take into account reporting requirements, including the different types of reports you must make, the thresholds for making those reports, the information they must contain, and the reporting time limits.
- Keeping comprehensive records. Most AML regimes require records to be kept for a set period (5 years is common).
- Independent audits. Your AML compliance program should be regularly reviewed by independent experts to verify its effectiveness and identify any areas that require improvement.
Bybit case study
Bybit, a global crypto trading and staking platform, needed to implement an automated KYC solution to fight fraud, stay compliant with AML regulations, and stop fraudsters from passing the onboarding stage.
Sumsub rose to the challenge by adding two levels of verification checks:
- ID verification and biometric liveness for users who wish to withdraw up to 50 BTC;
- Proof of address verification for those who wish to operate with larger sums.
Since integration, Sumsub has solved Bybit’s previous issues with delayed checks and verification errors:
- Verification time has been reduced to about one minute;
- The average pass rate has reached 78% for first-level verification;
- Forgery attempt detection has risen to 99%.
ANNA case study
ANNA, which stands for “Absolutely No-Nonsense Admin”, is a business account and tax app for small businesses. The company previously used a verification provider that couldn’t verify certain types of documents during the KYC process. On top of that, verification time was longer than expected, and pass rates were low. Eventually, the company started working with Sumsub, integrating the following solutions:
- AML Monitoring
- ID Verification
- Liveness/Face Match
- Proof of Address
As a result, manual work was reduced by 95%. Pass rates increased by 88%, while fraud attempts went down by 6%.
Kaizen Gaming case study
Kaizen Gaming is one of the fastest-growing game tech companies globally. Before partnering with Sumsub, the company’s verification procedures were approximately 15% automated, meaning their internal compliance team had to perform 85% of the checks manually. This led to customer drop-offs and an unpleasant user experience.
Realizing the issue, Kaizen Gaming needed a more sophisticated (and automated) solution to ensure seamless customer onboarding in compliance with regulatory requirements across markets.
The company partnered with Sumsub, integrating the following features:
- Automated Data Extraction
- ID Verification
- Proof of Address
- Bank Card Verification
As a result, Kaizen Gaming automated its onboarding, increasing overall performance by 350%.
FAQ: KYC and AML
-
What is the difference between KYC and AML?
KYC is just one component of an AML program: it identifies, verifies customers, and assesses their risk, while AML is the broader framework of risk assessment, policies, monitoring, investigation, reporting, training, governance, and controls used to prevent money laundering and related financial crime.
-
Is KYC part of AML compliance?
Yes, KYC is a key part of AML compliance. It is a primary part of any AML framework as it allows businesses to verify users’ identities and accurately assess their individual levels of risk.
-
What is an AML policy?
An AML policy is a set of internal rules and measures to prevent money laundering and terrorist financing.
-
What are KYC and AML checks?
KYC and AML checks may include customer identification, identity document or database verification, biometric and liveness checks, proof of address, beneficial ownership verification, CDD, sanctions and PEP screening, adverse media checks, customer risk scoring, transaction monitoring, wallet screening, and ongoing review. The checks required depend on the business, jurisdiction, customer, product, and risk level.
-
What are the main AML and KYC regulations?
Each country has its own AML regulations, which typically include provisions for KYC. Some countries share a regulatory framework. For example, EU member states follow EU AML standards. In general, most major economies follow the Financial Action Task Force (FATF) Recommendations when legislating for their approach to money laundering.
-
What is a Politically Exposed Person?
Politically Exposed Person (PEP) is someone who is, or has been, entrusted with prominent national or international public functions. This includes individuals holding high-level positions in government, political parties, or international organizations, as well as their close family members and close associates. PEPs pose a higher risk to businesses as they may potentially misuse their influence for financial gain.
Relevant articles
- Article
- Jul 14, 2026
- 10 min read
Learn how to create an AML compliance policy covering CDD, MLRO duties, SAR filing, and audits, and get a free FINRA template to help you get started.

- Article
- 1 week ago
- 11 min read
Learn what age gating, age assurance, age estimation, and age verification mean, how the checks work, and what privacy tradeoffs they involve.

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


