HomeGlossaryKYC Compliance
Glossary

KYC Compliance

KYC compliance means meeting the legal and regulatory obligations to identify, verify and understand customers, apply risk-based due diligence, keep records, and review customer information on an ongoing basis.

Why it matters

Non-compliance carries direct penalties and can restrict a firm's licence. Regulators increasingly examine not only whether checks were done, but whether they were consistent, documented and proportionate to risk.

How it works

  1. A written KYC policy aligned to the applicable law and regulator guidance.
  2. Identification and verification procedures with clear standards for acceptable documents.
  3. Risk assessment that drives simplified, standard or enhanced due diligence.
  4. Screening against sanctions, PEP and adverse media.
  5. Record keeping and an audit trail for every decision.
  6. Periodic review and re-verification based on risk and document expiry.

Common challenges

How IDWise supports this

IDWise addresses this within the Continuous Trust Platform through the following modules, configured per market, product line and risk tier.

Frequently asked questions

What records must be kept for KYC compliance?

Identity documents, verification results, screening outcomes, risk assessments and the decisions taken, for the retention period set by the regulator.

How do firms keep KYC compliant across markets?

By configuring journeys, document rules and retention per market and product line, and by keeping a complete audit trail centrally.

What triggers a KYC review?

Document expiry, changes in customer risk, unusual activity, or a scheduled periodic review.

Related terms

See how IDWise applies this in practice.

Talk to an IDWise specialist about your markets, regulators and risk controls.

Book a demo →