Customer Due Diligence and KYC
Know Your Customer (KYC) is often treated as a box-ticking exercise at account opening, but it's really the foundation that every later financial crime control depends on. Get it wrong at the...
Know Your Customer (KYC) is often treated as a box-ticking exercise at account opening, but it's really the foundation that every later financial crime control depends on. Get it wrong at the start and transaction monitoring, sanctions screening and suspicious activity reporting are all working from a distorted picture of who the customer actually is.
Establishing identity with confidence
Verifying identity means more than capturing a name and a document number. Staff need to confirm that the person or entity is who they claim to be, using reliable, independent sources — government-issued ID, registry checks for companies, or trusted electronic verification tools. The standard of evidence should scale with the risk of the relationship, not default to the minimum every time.
Understanding purpose and nature of business
Beyond identity, firms need a working understanding of why the customer wants the relationship and how they intend to use it. A personal current account and a high-turnover trading business call for very different lines of questioning. This context is what later lets monitoring teams judge whether activity is consistent with what was expected — without it, every transaction looks equally unremarkable or equally suspicious.
Assigning and using a risk rating
A risk rating translates everything gathered at onboarding — customer type, geography, product, channel, expected activity — into a single, actionable classification that drives how much scrutiny the relationship receives going forward. Getting the inputs right matters more than the label itself: a rating built on thin or generic information gives false comfort.
Keeping information current through ongoing review
Customer circumstances change — a business expands into new markets, an individual's employment changes, a dormant account suddenly becomes active. Periodic and trigger-based reviews exist to catch these shifts and update the risk rating and due diligence file accordingly, so the picture the firm holds stays accurate rather than frozen at the moment of onboarding.
Worked Example
Worked example: A small import business onboards with a stated purpose of purchasing goods from two named overseas suppliers, generating modest, predictable monthly outflows. Eighteen months later, the account starts receiving frequent inbound payments from unrelated individuals and making outbound payments to a much wider set of counterparties in a new region. This is precisely the kind of drift that ongoing review is designed to catch — the original due diligence file no longer reflects how the account is actually being used, which should trigger a refreshed assessment rather than being left until the next scheduled review date.
Key Takeaways
- Identity verification standards should scale with risk, not default to a fixed minimum.
- Understanding a customer's purpose and expected activity is what makes monitoring meaningful later on.
- A risk rating is only as good as the information feeding into it.
- Ongoing review catches drift between what was expected at onboarding and what's actually happening now.
Common Pitfalls to Avoid
A frequent pitfall is collecting information at onboarding and never using it again — a due diligence file that sits unread until a regulator asks for it provides no real protection. Another is over-relying on a generic risk-rating questionnaire without capturing enough narrative detail to make sense of an unusual pattern later. Good KYC is a living record, not a one-time form.
Building This Into Team Practice
A single training session rarely changes behaviour on its own. For onboarding and operations teams, "Customer Due Diligence and KYC" works best when it's reinforced through short, regular refreshers rather than treated as a one-off module — especially since the underlying subject matter (verifying identity, understanding a customer's purpose and nature of business, risk rating, verification methods, and ongoing review) tends to evolve as new typologies, products and regulatory expectations emerge. Teams that set aside time to discuss real, anonymised cases from their own environment alongside the course content consistently retain the material better than those who complete it in isolation. Managers can reinforce this further by referencing the course's own scenarios in team meetings and by making it clear that raising a genuine concern is treated as good practice, not an inconvenience.
Why This Belongs in a Structured CPD Programme
Financial crime rules and typologies don't stand still, and neither should training. Embedding this course within a wider, structured CPD programme — rather than delivering it as an isolated annual requirement — gives onboarding and operations teams the chance to build genuine capability over time: to be able to collect, assess and refresh customer information proportionately to risk, and to keep that capability current as the environment around them changes. Learnsignal designs its compliance library so that individual courses like this one connect naturally into a broader learning pathway, letting firms track completion, refresh knowledge on a sensible cycle, and evidence a genuinely proportionate training programme rather than a box-ticking exercise.
How This Fits Into a Broader Compliance Programme
CDD and KYC are the entry point to the whole financial crime control framework — weak due diligence at onboarding quietly undermines transaction monitoring, sanctions screening and reporting further down the line. Firms that resource this stage properly, rather than treating it as a formality to clear before the 'real' business begins, see fewer costly remediation exercises later.
Frequently Asked Questions
How much documentation is 'enough' for due diligence?
There's no universal number — the right level of documentation is whatever is proportionate to the risk the relationship presents, applied consistently and recorded clearly enough that another reviewer could follow the reasoning.
What triggers a review outside the normal schedule?
Common triggers include a significant change in transaction pattern, adverse media, a change in ownership or control, or new information that changes the customer's risk profile.
Is electronic identity verification as reliable as in-person checks?
Reputable electronic verification tools can meet or exceed the reliability of manual document checks, provided they draw on independent, authoritative data sources and the firm understands their limitations for higher-risk scenarios.
How long does the "Customer Due Diligence and KYC" course take to complete?
This is an interactive foundational course designed for a minimum of 30 minutes, with the exact length depending on the pace of the individual learner and how much of the practice and assessment content they engage with — some learners will comfortably spend longer working through the scenarios in detail.
Solid due diligence at onboarding sets up everything downstream, including work on beneficial ownership and control and enhanced due diligence for higher-risk customers. See Learnsignal's CPD-accredited compliance training for the full onboarding-to-monitoring pathway.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team

