KYC vs AML: One Is a Check, the Other Is a Regime
KYC is the check you run on one client. AML is the regime that requires it. What each covers, where they overlap, and what firms get wrong about both.

Introduction
Two acronyms, one meeting, and nobody quite agrees which is which. Compliance says the firm needs AML. Sales says they already run KYC on every new client. Both people think they're describing the same work.
They aren't. The gap between them is where inspections go badly.
Here's the short version. KYC is something you do to one client, at the start. AML is the framework that tells you to do it, plus everything you still owe afterwards. One is a task. The other is a regime with that task sitting inside it.
That distinction isn't academic. Firms buy an identity-checking tool, tick the box, and find out during a supervisory visit that identity checks were maybe a fifth of what they owed.
The Short Answer, Before the Detail
KYC stands for Know Your Customer. AML stands for Anti-Money Laundering.
AML is the wider of the two. It's the body of law, supervision and internal procedure built to stop criminal money moving through legitimate businesses. KYC is one obligation inside that body: establish who your client is before you do business with them.
So asking "do we need KYC or AML?" works a bit like asking whether you need a driving test or traffic law. You take the test because the law says so, and passing it doesn't excuse you from everything else on the road.
Why the two words got tangled
Vendors did most of the tangling, honestly. Identity verification is the part of AML that's easiest to sell as software, so it got the loudest marketing. Search for AML tools and you'll mostly find KYC products with AML in the page title.
The rest of the regime is harder to package. Transaction monitoring, suspicious activity reporting, a written risk assessment, staff training, record retention: none of that demos well in fifteen minutes.
What KYC Actually Covers
KYC answers one question: is this person or company who they say they are?
In practice it breaks into three checks, and most firms only run the first.
Document verification. Is the passport, ID card or company registration genuine and unexpired? Modern checks read the security features and the machine-readable zone rather than eyeballing a scan.
Liveness. Is a real person presenting that document right now, rather than someone holding a photo of it? This is the check that catches the most common fraud pattern, where a genuine document is used by the wrong person.
Screening comes third, and sanctions screening is its own obligation with no threshold.
Does the client appear on sanctions lists, or are they a politically exposed person whose file needs extra scrutiny?
Run all three and you know who you're dealing with on day one, which is the whole subject of our guide to client identity verification. That's the whole scope. KYC has nothing to say about what that client does with you in month seven, and that silence is exactly the space AML fills.
What AML Adds That KYC Never Touches
Five obligations sit outside identity checking, and every one of them is where firms get caught short.
- 1A written risk assessment. You have to document which clients, products, countries and delivery channels expose you to laundering risk, and grade them. Supervisors ask for this document first, and a surprising number of firms don't have one.
- 2Ongoing monitoring. The relationship gets watched, not just opened. A client who passed KYC in January and starts moving unusual sums in June is an AML problem, and no identity check will flag it.
- 3Suspicious activity reporting. When something looks wrong you file a report with the national financial intelligence unit, and you don't tell the client you did. Getting the timing wrong here is a criminal matter in most jurisdictions, not a fine.
- 4Record keeping, usually five years after the relationship ends. Identity evidence, the reasoning behind risk decisions, the paperwork behind every report.
- 5Someone accountable. Most regimes want a named officer responsible for the whole thing, plus documented staff training.
Worth saying plainly: a firm can run flawless KYC and still fail an AML inspection on all five.
KYC and AML side by side
| KYC | AML | |
|---|---|---|
What it is | A check | A regime |
Question it answers | Who is this client? | Is criminal money moving through us? |
When it runs | At onboarding, then on review | Continuously, for the life of the relationship |
Scope | One client at a time | The whole firm: policy, people, records, reporting |
Who does it | Onboarding, sales, operations | A named compliance officer, with the board accountable |
Typical evidence | ID document, liveness result, screening hit | Risk assessment, monitoring logs, filed reports, training records |
Failure looks like | You onboarded an impostor | You had no procedure, or you had one and ignored it |
Who Has to Do This, and Under Which Law
The standards are global. The wording is local.
Every regime in this list descends from the same source, the Financial Action Task Force and its 40 Recommendations, which is why the shape of the obligations rhymes across borders even when the article numbers don't.
It stopped being a banking topic a long time ago
This is the part that catches professional firms. Banks have known for decades. Under most national regimes the obliged parties also include notaries, lawyers, accountants and auditors, estate agents, company formation and trust service providers, and dealers in high-value goods above a cash threshold.
If you're a five-person conveyancing practice, you're an obliged entity with the same core duties as a bank, minus the compliance department. That's not a comfortable position, and it's the reason identity checking has to live inside the work you already do rather than beside it.
Where to look, by jurisdiction
- United States run on the Bank Secrecy Act, supervised by FinCEN, with the Customer Due Diligence Rule covering beneficial ownership
- European Union members implement the money laundering directives nationally, so the duties match but the statute names don't
- United Kingdom: the Money Laundering Regulations 2017
- Germany: the Geldwaeschegesetz, with BaFin supervising and reports going to the FIU
- France: the LCB-FT regime in the Code monetaire et financier, with reports to Tracfin
- Spain: Ley 10/2010, with Sepblac receiving reports
- Brazil: Lei 9.613/1998, with reports to COAF
Where the Two Meet: The Moment Someone Signs
There's one point where identity and the wider regime stop being separate concerns, and it's the signature.
A signed agreement is the evidence that a relationship exists, and proving the file itself is intact is a separate exercise covered in document verification. If you can't show who was on the other end when it was signed, the identity check you ran three weeks earlier in a different tool proves very little. The two records live apart, and joining them later means digging through an inbox.
This is the practical failure, and it's boring rather than dramatic. Sales collected a passport scan by email. Compliance approved it in a spreadsheet. The contract went out through a signing tool that never saw either. Three systems, three timestamps, no single trail.
Running the check inside the signing flow closes that. The identity result, the liveness test, the screening outcome and the signature itself end up in one audit trail, anchored so nobody can quietly revise it afterwards. When a supervisor asks how you knew who signed, the answer is one record instead of three.
Identity Checks Inside the Signing Flow
Document verification, liveness, and sanctions and PEP screening run in the same flow as the agreement, with one tamper-evident audit trail covering both.
Four Mistakes That Show Up in Inspections
Treating the acronyms as synonyms. A firm that says "we're AML compliant, we do KYC" has usually done a fifth of the work and doesn't know it yet.
Buying a tool instead of writing a procedure. Software runs checks. It doesn't decide your risk appetite, and a supervisor will ask for the written assessment before asking which vendor you use.
Onboarding once and never looking again is the third. Risk ratings age. A client who was low risk at signup can change ownership, jurisdiction or behaviour, and nothing about the original check will tell you.
Keeping identity evidence somewhere other than the agreement. Two records that don't reference each other are hard to defend under questioning, even when both are perfectly good on their own.
Thresholds, retention periods and reporting deadlines differ by country and by profession, and they change. Treat this article as the map, not the territory, and confirm the current figures with your national supervisor before you build a procedure on them.
Conclusion
KYC tells you who walked through the door. AML is everything you owe from that moment until five years after they leave.
Getting the vocabulary right matters because budget follows it. A firm that thinks the two words mean the same thing buys identity verification and calls the programme finished, then discovers during an inspection that the risk assessment, the monitoring and the reporting were never anyone's job.
Start with the written risk assessment, because it's what supervisors open first and what every other decision hangs off. Then make sure the identity check and the signed agreement end up in the same place, since that's the pair you'll be asked to produce together.
Tags
Frequently Asked Questions
Answers to popular questions about Chaindoc and secure document workflows.
KYC is a check you run on an individual client to confirm they are who they claim to be. AML is the wider regime of law, policy and procedure aimed at stopping criminal money passing through your business. KYC is one obligation inside AML, alongside ongoing monitoring, suspicious activity reporting, record keeping and staff training.
KYC sits inside AML. The AML regime requires customer due diligence, and KYC is how you carry that requirement out.
No, and this is the most expensive misunderstanding in the field. Identity verification covers the start of a relationship. An AML programme also needs a documented risk assessment, ongoing transaction monitoring, a process for filing suspicious activity reports with your national financial intelligence unit, retention of records for several years after the relationship ends, a named responsible officer and evidence that staff were trained. A firm with flawless KYC can fail an inspection on every one of those.
Far more businesses than most people expect. Banks and payment firms are obvious, but national regimes typically also capture notaries, lawyers, accountants, auditors, estate agents, company formation and trust service providers, and dealers in high-value goods taking large cash payments. A small professional practice carries the same core duties as a large institution.
In a compliance function, AML is the programme rather than a single control. It covers the written risk assessment, the due diligence procedures including KYC, transaction monitoring, the reporting line to the financial intelligence unit, record retention and training, together with the governance that makes someone accountable for all of it.
More e-signature and blockchain guides
Practical guides on electronic signatures, blockchain audit trails, and secure document management — handpicked to build on what you just read.





