The end-to-end KYC process is the sequence of identity checks, risk assessments, and ongoing monitoring a financial institution runs on you from the moment you apply for an account through the years after you close it. It exists because the Bank Secrecy Act requires every financial institution to maintain an anti-money laundering program that includes verifying customer identities, designating a compliance officer, training employees, and conducting independent audits.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority The rules apply the same way whether you are opening a personal checking account or onboarding a corporate entity.2FinCEN.gov. The Bank Secrecy Act
What the Bank Collects and Verifies at the Start
The Customer Identification Program rule sets the minimum. Before opening an account for an individual, a bank must obtain four pieces of information: your legal name, date of birth, a residential or business street address, and a taxpayer identification number, which is usually your Social Security number.3eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks If you do not have a street address, an APO or FPO box number is acceptable, as is the address of a next of kin or other contact person.
Then the bank verifies what you gave it. Document-based verification means presenting an unexpired government-issued ID that shows nationality or residence and bears a photograph, such as a driver’s license or passport. Non-documentary verification is also allowed and generally means cross-referencing your information against consumer reporting agencies or public databases. A utility bill or lease is sometimes requested, but that is an internal bank policy, not something the federal CIP regulation requires.
If you are not a U.S. person, the taxpayer ID slot can be filled by a passport number and country of issuance, an alien identification card number, or the number of another government-issued document showing nationality or residence and including a photograph.3eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks
For a business account, the bank collects the entity’s physical location and its EIN, and it must also identify the real people behind the entity. Under the Customer Due Diligence rule, that means every individual who directly or indirectly owns 25 percent or more of the equity, plus at least one person with significant managerial control. The person opening the account certifies this ownership information, and the bank verifies each beneficial owner using the same procedures it uses for individual customers.4eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers
Most banks now run all of this through an encrypted portal or mobile app. You upload images of your ID, and the system checks the document’s security features automatically. Many institutions add a liveness check, where the app asks you to blink or turn your head, and then compares that live image to the photo on your ID using biometric software. Automated verification can finish in seconds or take up to about 24 hours if the system flags something for a closer look. If your photo does not match or the document reads as expired, expect a resubmission request rather than a silent rejection.
Screening and Risk Classification
Once your identity is verified, your information runs through screening databases. Banks are required to check new accounts against government-provided lists of known or suspected terrorists or terrorist organizations.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority In practice they also screen against OFAC’s Specially Designated Nationals list. No standalone regulation mandates OFAC screening at account opening, but the FFIEC treats it as a baseline element of sound compliance.5Federal Financial Institutions Examination Council. BSA/AML Manual – Office of Foreign Assets Control Most institutions also check Politically Exposed Person databases and law enforcement watchlists.
The screening results, combined with the nature of the account, drive a risk rating. Low-risk accounts move on to standard activation and normal transaction limits. Medium-risk accounts may see lower initial limits or more frequent reviews. High-risk accounts get pulled into enhanced due diligence. The tiered approach concentrates compliance resources where the risk actually sits rather than putting every retail customer through the same intensive review.
Enhanced Due Diligence When You Are Flagged High-Risk
Enhanced due diligence turns on two questions: where did your wealth come from over time, and where is the specific money in these transactions coming from right now? Answering them can mean producing brokerage statements, property records, inheritance documentation, or business financials.
Several things push a customer into EDD. Complex corporate structures such as offshore trusts, layered holding companies, or entities with opaque ownership are common triggers. Residence in or significant ties to a jurisdiction the FATF has flagged is another. The FATF currently places North Korea, Iran, and Myanmar on its “call for action” list, with over 20 additional countries under increased monitoring.6Financial Action Task Force. High-Risk and Other Monitored Jurisdictions – Black and Grey Lists Politically exposed persons and their close associates routinely receive EDD as well.
EDD is manual. Senior compliance staff review the file rather than an automated engine, and it takes meaningfully longer to complete. If you cannot produce satisfactory documentation, the bank can deny the account outright or freeze funds already on deposit.
Ongoing Monitoring After the Account Opens
KYC does not end at approval. Transaction monitoring systems scan your account activity for patterns that deviate from your established profile. Unexpected large wire transfers, sudden spikes in cash deposits, transactions with sanctioned jurisdictions, or activity with no apparent business purpose can all trigger alerts.
When suspicious activity involves $5,000 or more, the bank must file a Suspicious Activity Report. It has 30 calendar days from the date it first detects facts suggesting a reportable transaction to submit the SAR. If no suspect has been identified by then, the bank gets an additional 30 days, with an absolute deadline of 60 days from initial detection. For ongoing schemes such as active money laundering, the bank must also notify law enforcement by telephone immediately, on top of filing the SAR.7eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions SAR filings are not disclosed to the customer.
Banks also perform periodic reviews of existing customer files. Federal regulations do not prescribe a specific re-KYC cycle, so most institutions schedule reviews based on the customer’s risk level. A high-risk account might be re-examined annually, while low-risk accounts can go several years between updates. During a periodic review the bank may ask you to re-confirm your address, refresh your ID, or explain changes in your transaction patterns.
What Happens to Your File After You Close the Account
Closing your account does not close your file. The Bank Secrecy Act requires banks to retain the identifying information collected during CIP for at least five years after the account is closed.8Federal Financial Institutions Examination Council. BSA/AML Manual – Appendix P – BSA Record Retention Requirements A Treasury Department order or law enforcement investigation can extend retention on a case-by-case basis. Transaction records, SAR filings, and currency transaction reports carry their own retention requirements under the same framework.
If Your Application Is Denied
If a bank denies your account based on information in a consumer report, the Fair Credit Reporting Act requires the bank to send you an adverse action notice. That notice must include the name and contact information of the reporting agency whose data contributed to the decision. You then have the right to request a free copy of the report that was used and to dispute inaccurate information. The reporting agency must investigate and correct errors. Most negative information in checking account reports cannot remain on file for more than seven years.9Consumer Financial Protection Bureau. Why Was I Denied a Checking Account?
If you suspect the denial came from a KYC screening hit rather than a consumer report, the process is less transparent. Banks are not required to disclose the specific screening database or watchlist that flagged your application. You can ask the bank’s compliance department for clarification, though what the institution can share is limited.
How Your KYC Data Is Protected
The Gramm-Leach-Bliley Act requires financial institutions to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards designed to protect customer information.10Federal Trade Commission. Gramm-Leach-Bliley Act The copies of your passport, the biometric data from your liveness check, and any beneficial ownership certifications fall under a program the institution is required to maintain and update.
The FTC’s Safeguards Rule, which implements these requirements, reaches beyond traditional banks to mortgage brokers, tax preparers, and certain fintech companies. A KYC file contains close to everything a fraudster would need, so the security program is treated as substantive. If a breach exposes your documents, the institution faces regulatory consequences on top of the identity theft exposure you carry personally.