What is KYC?

In short

  • KYC (Know Your Customer) is the process by which you establish who your customer is, what they do and what risk they bring.
  • In the Netherlands this is called cliëntenonderzoek (customer due diligence). The Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft) requires it of banks, funds, trust offices, estate agents, accountants and notaries, among others.
  • The core: identification and verification, establishing the UBO, understanding the purpose of the relationship, PEP and sanctions screening, and ongoing monitoring.
  • From 10 July 2027 the European AMLR applies, harmonising the rules across the EU.

KYC stands for Know Your Customer: knowing who your customer is. It is about more than a copy of a passport. You establish who the customer is, who is behind the customer, what the customer does and what risk comes with that. Only then do you decide whether to do business with the customer.

For many organisations, KYC is not a choice. The Wwft requires institutions that run a risk of becoming involved in money laundering or terrorist financing to carry out customer due diligence. The Dutch term for this is cliëntenonderzoek.

Why KYC exists

Criminals use companies and financial institutions to launder money. A good KYC process makes that harder. You know who you are doing business with, you recognise unusual behaviour and you report unusual transactions to FIU-Nederland, the Dutch Financial Intelligence Unit. This protects your organisation against fines, reputational damage and misuse.

Who must carry out KYC?

The Wwft applies to a long list of institutions. Among others:

  • banks and payment institutions
  • investment institutions and fund managers
  • trust offices
  • estate agents and intermediaries in real estate
  • accountants, tax advisers and bookkeeping firms
  • notaries and lawyers, for certain activities

Not sure whether your organisation falls under the Wwft? Check with your supervisor, such as DNB, the AFM or the Bureau Financieel Toezicht.

The steps of a KYC investigation

Customer due diligence follows fixed steps. The Wwft describes them in Article 3.

  1. Identification and verification. You establish who the customer is and verify this with reliable documents, such as an identity document or an extract from the Trade Register.
  2. Establishing the UBO. For a company, you find out who the ultimate beneficial owners are: the natural persons who own or control it.
  3. Purpose and nature of the relationship. You understand why the customer wants to do business with you and what use you can expect.
  4. PEP and sanctions screening. You check whether the customer or the UBO is a politically exposed person (PEP), and whether they appear on sanctions lists.
  5. Determining the risk. Based on everything you know, you determine the risk profile. If the risk is higher, you carry out an enhanced investigation.
  6. Ongoing monitoring. KYC does not stop after acceptance. You keep an eye on the relationship and the transactions, and you update the file.

A risk-based approach

Not every customer requires the same investigation. The Wwft has three levels:

  • simplified customer due diligence where the risk is demonstrably low
  • standard customer due diligence for most customers
  • enhanced customer due diligence where the risk is high, for example with PEPs, complex structures or high-risk countries

Always record why you choose a particular level. A supervisor wants to be able to follow your reasoning.

KYC and the AMLR

From 10 July 2027 the European Anti-Money Laundering Regulation, the AMLR, applies. The regulation is directly applicable in all Member States and replaces a large part of the national rules. For KYC, this means among other things:

  • more uniform rules across the EU, including for UBO research
  • stricter and more precise requirements on which data you record
  • supervision of the largest institutions by the new European supervisory authority AMLA

Start putting your files in order now. Then the transition in 2027 will be a small step.

Doing KYC yourself or outsourcing it

Many organisations carry out KYC themselves. That requires experienced analysts, good systems and capacity for peaks, such as a remediation project or a large influx of new customers. An alternative is to outsource the execution. You then remain responsible for the policy and the decisions, but the investigation itself is carried out by specialists.

Frequently asked questions

Is KYC mandatory?

Yes, for institutions subject to the Wwft. They must carry out customer due diligence before entering into a business relationship or carrying out an occasional transaction, and continue to monitor the relationship afterwards.

What is the difference between KYC and CDD?

KYC is the broad concept: knowing who your customer is. CDD (Customer Due Diligence) is the investigation itself, with fixed steps such as identification, verification and UBO research. In the Wwft, CDD is called cliëntenonderzoek.

Can I outsource KYC?

Yes. You may have another party carry out the customer due diligence. You do, however, remain responsible for the investigation and for the decision to accept a customer.

How long must I retain KYC data?

The Wwft requires you to retain the customer due diligence data for five years after the end of the business relationship or after the transaction.

How often must I review a customer again?

That depends on the risk. You review high-risk customers more often and more thoroughly. In addition, you carry out a new investigation when something changes, for example a new UBO or a change in activities.

Outsource your KYC?

BlueMonks carries out your customer due diligence in full, with experienced analysts and our own KYC platform. You stay in control of every decision.