KYC stands for Know Your Customer: knowing who your customer is. It is about more than a copy of a passport. You establish who the customer is, who is behind the customer, what the customer does and what risk comes with that. Only then do you decide whether to do business with the customer.
For many organisations, KYC is not a choice. The Wwft requires institutions that run a risk of becoming involved in money laundering or terrorist financing to carry out customer due diligence. The Dutch term for this is cliëntenonderzoek.
Why KYC exists
Criminals use companies and financial institutions to launder money. A good KYC process makes that harder. You know who you are doing business with, you recognise unusual behaviour and you report unusual transactions to FIU-Nederland, the Dutch Financial Intelligence Unit. This protects your organisation against fines, reputational damage and misuse.
Who must carry out KYC?
The Wwft applies to a long list of institutions. Among others:
- banks and payment institutions
- investment institutions and fund managers
- trust offices
- estate agents and intermediaries in real estate
- accountants, tax advisers and bookkeeping firms
- notaries and lawyers, for certain activities
Not sure whether your organisation falls under the Wwft? Check with your supervisor, such as DNB, the AFM or the Bureau Financieel Toezicht.
The steps of a KYC investigation
Customer due diligence follows fixed steps. The Wwft describes them in Article 3.
- Identification and verification. You establish who the customer is and verify this with reliable documents, such as an identity document or an extract from the Trade Register.
- Establishing the UBO. For a company, you find out who the ultimate beneficial owners are: the natural persons who own or control it.
- Purpose and nature of the relationship. You understand why the customer wants to do business with you and what use you can expect.
- PEP and sanctions screening. You check whether the customer or the UBO is a politically exposed person (PEP), and whether they appear on sanctions lists.
- Determining the risk. Based on everything you know, you determine the risk profile. If the risk is higher, you carry out an enhanced investigation.
- Ongoing monitoring. KYC does not stop after acceptance. You keep an eye on the relationship and the transactions, and you update the file.
A risk-based approach
Not every customer requires the same investigation. The Wwft has three levels:
- simplified customer due diligence where the risk is demonstrably low
- standard customer due diligence for most customers
- enhanced customer due diligence where the risk is high, for example with PEPs, complex structures or high-risk countries
Always record why you choose a particular level. A supervisor wants to be able to follow your reasoning.
KYC and the AMLR
From 10 July 2027 the European Anti-Money Laundering Regulation, the AMLR, applies. The regulation is directly applicable in all Member States and replaces a large part of the national rules. For KYC, this means among other things:
- more uniform rules across the EU, including for UBO research
- stricter and more precise requirements on which data you record
- supervision of the largest institutions by the new European supervisory authority AMLA
Start putting your files in order now. Then the transition in 2027 will be a small step.
Doing KYC yourself or outsourcing it
Many organisations carry out KYC themselves. That requires experienced analysts, good systems and capacity for peaks, such as a remediation project or a large influx of new customers. An alternative is to outsource the execution. You then remain responsible for the policy and the decisions, but the investigation itself is carried out by specialists.