Loading data...

KYC (Know Your Customer)

General

Identity verification required by compliance and risk policies.

KYC, or Know Your Customer, is the process a business uses to identify a customer and verify that identity through reliable information. It forms part of broader customer due diligence and anti-money laundering controls. Requirements vary by country, service, customer type, and risk, so KYC is not one universal document checklist.

For an individual, onboarding may collect legal name, date of birth, address, government identification, and a selfie or liveness check. A company account can require registration records, directors, ownership structure, and beneficial owners. Higher-risk cases may involve source-of-funds or source-of-wealth evidence and additional review.

KYC does not end automatically after account creation. Providers may update expired documents, review unusual activity, rescreen sanctions or politically exposed person information, and confirm that transactions fit the known customer profile. Automated tools assist reviewers, but a score or database match should not be treated as proof of wrongdoing without appropriate assessment.

The process matters in crypto because exchanges, custodians, brokers, and payment services connect pseudonymous blockchain activity with regulated financial systems. Verification can enable fiat deposits, withdrawals, cards, and higher account limits. It may also delay onboarding or restrict access when documentation is unavailable, inconsistent, or unsupported in a region.

Identity collection creates privacy and security risk. Passports, addresses, and biometric templates can enable fraud if exposed. Providers should collect only necessary data, limit access, secure transmission and storage, define retention, assess vendors, and maintain incident response. Users should read privacy terms and verify the domain before uploading documents.

No legitimate KYC process requires a seed phrase, private key, or remote control of a wallet. Keep submission confirmations and respond only through official support. Businesses should obtain qualified compliance and privacy advice for the jurisdictions they serve. KYC can support risk management and legal duties, but it should be proportionate, accurate, transparent, and designed to protect the sensitive people behind the data.

Customers should update inaccurate records and ask how an automated rejection can be reviewed by a person. Providers should offer secure correction and complaint routes, monitor vendor performance, and avoid collecting extra identity data merely because storage is cheap. Fair access and fraud prevention both depend on reliable, explainable verification.

Frequently asked questions

  • Regulated businesses may need to identify and verify customers, understand the purpose of a relationship, assess risk, screen restrictions, and support ongoing anti-money laundering controls. KYC also helps manage account fraud and access to banking. Exact duties depend on jurisdiction, customer, product, and risk. A provider policy may be stricter than the legal minimum.
  • Requirements vary, but an individual may provide a government-issued identity document, facial or liveness check, tax or national identifier, and proof of address. Companies may provide registration, ownership, control, and beneficial-owner information. A risk review can request source-of-funds evidence. Submit data only through the provider's verified secure channel and never provide wallet recovery words.
  • Storage depends on the provider, verification vendor, jurisdiction, retention law, and privacy policy. Review what is collected, why, who receives it, where it is processed, how long it remains, and how rights can be exercised. Choose providers with data minimization, encryption, access controls, breach procedures, and clear deletion rules. No identity database is risk-free.