What Is KYC?
KYC (Know Your Customer) is the process of identifying and verifying a customer. Its purpose is to determine who an institution is entering into a relationship with, who ultimately stands behind a particular entity, and what money laundering or terrorist financing risks may be associated with the customer. KYC is one of the core components of an AML framework. However, it goes beyond simply collecting a copy of an identity document or a company’s registration details. The information gathered during the process should help the institution understand the customer, the nature of the intended business relationship, and the customer’s expected activity. It then provides a baseline for assessing the customer throughout the relationship.
Under the Polish AML Act, KYC is not defined as a separate procedure under that name. In practice, activities commonly referred to as KYC primarily fall within the scope of customer due diligence measures (środki bezpieczeństwa finansowego), which include customer identification and verification, identifying the beneficial owner, assessing the business relationship, and conducting ongoing monitoring.
Example:
A payment institution receives an application from a company operating an online store. Before activating the service, it verifies the company’s information and authorized representatives, identifies the beneficial owner, and reviews the nature of the customer’s business and how the customer expects to use the service. The information collected helps the institution not only decide whether to establish the relationship, but also build a customer profile. If the customer later begins using the service in a way that differs significantly from its declared business activity, this may trigger a reassessment of the customer’s risk.
What Does the KYC Process Look Like in Practice?
The scope of KYC is not the same for every customer. It depends on factors such as the type of customer, the nature of the relationship, the ownership structure, geographic exposure, and the identified level of risk. In practice, the process consists of several interconnected steps.
1. Customer Identification
The first step is to collect the required customer information. For an individual, the Polish AML Act requires information such as the person’s first and last name, citizenship, PESEL number or, if no PESEL number has been assigned, the date and country of birth, as well as the series and number of the identity document. For a legal entity, identification includes information such as its name, legal form, address, registration details, and certain information about the person representing the entity. Identification therefore means establishing who the customer is. It is not yet the same as confirming that the information provided is accurate.
2. Identity Verification
The next step is to confirm the information obtained using a reliable and independent source. This may include an identity document, a current document or information from an appropriate registry, or another reliable source. The Polish AML Act also allows the use of appropriate electronic identification methods and trust services where available. It is therefore important to distinguish between the two steps: the customer is first identified, and the information is then verified.
3. Identifying the Beneficial Owner
For customers that are companies or other legal entities, it may be necessary to identify the individual who ultimately owns or controls the entity or benefits from it. The process should not be limited to checking the information available in Poland’s Central Register of Beneficial Owners (CRBR). The Polish AML Act expressly states that an obligated institution cannot rely solely on information from the CRBR when applying this customer due diligence measure.
For simple ownership structures, identifying the beneficial owner may be relatively straightforward. More complex structures involving several companies, foreign entities, or other arrangements that make it more difficult to determine ultimate control may require additional analysis.
4. Understanding the Purpose and Nature of the Relationship
KYC is not limited to answering the question, “Who is the customer?” An institution should also understand why the customer wants to establish the relationship and how they intend to use the products or services offered. This information is important for ongoing monitoring. For example, if a business declares a particular business model, expected transaction volume, and geographic area of activity, those details create a baseline against which its actual activity can later be assessed.
5. Customer Risk Assessment
The information collected during KYC is used to assess the customer’s money laundering and terrorist financing risk. Relevant factors may include:
- the type and nature of the customer’s business;
- ownership structure;
- geographic areas associated with the customer;
- products and services used;
- the nature and expected value of transactions;
- the purpose and expected duration of the relationship;
- other circumstances that may affect the level of risk.
The Polish AML framework follows a risk-based approach. This means that the scope and intensity of the measures applied should reflect the risk identified in the specific business relationship. In practice, this stage may also include checks related to PEP status and other factors relevant to the customer’s risk profile.
6. Ongoing Monitoring and KYC Updates
The KYC process does not end once the customer has been successfully onboarded. Customer information may become outdated over time. The beneficial owner may change, the company’s structure may be modified, the nature of its business may evolve, the way it uses a product may change, or its geographic exposure may expand. For this reason, customer due diligence under the Polish AML Act also includes ongoing monitoring of the business relationship and ensuring that documents, data, and information remain current. KYC should therefore be treated as an ongoing process, not as a one-time check performed only when a customer is onboarded.
Individual vs. Corporate KYC – What Needs to Be Verified?
The underlying objective is the same, but the scope of the process differs depending on whether the customer is an individual or a business entity.
| Individual | Company / Legal Entity | |
|---|---|---|
| Customer identification | Information used to establish the person’s identity | Company name, legal form, address, and registration details |
| Verification | Identity document or another reliable and independent source | Registries, documents, and other reliable sources relating to the entity |
| Representation | The customer generally acts on their own behalf | Verification of persons acting on behalf of the company and their authority to do so |
| Beneficial owner | Depending on the nature of the customer and relationship | Identification of individuals who ultimately own or control the entity |
| Ownership structure | Generally not applicable | May require analysis of several levels of ownership and control |
| Customer profile | Purpose of the relationship, expected activity, and risk factors | Business model, industry, geography, nature of the relationship, and expected activity |
For a corporate customer, simply confirming that the company exists in the relevant registry is not enough to complete the KYC process. The institution must also establish who is authorized to act on the company’s behalf, identify the beneficial owner and, where necessary, understand the ownership and control structure. The Polish AML Act also requires verification of the identity and authority of a person acting on behalf of the customer.
KYC Under the Polish AML Act
The term KYC is used broadly within the AML industry. From the perspective of Polish law, however, the key concept is customer due diligence measures (środki bezpieczeństwa finansowego). Article 34 of the Polish AML Act sets out four main areas:
- identifying the customer and verifying the customer’s identity;
- identifying and verifying the beneficial owner and, where appropriate, determining the ownership and control structure;
- assessing the business relationship and, where appropriate, obtaining information about its purpose and intended nature;
- conducting ongoing monitoring of the business relationship, including transaction analysis, examining the source of funds where justified by the circumstances, and keeping customer information up to date.
This illustrates why treating KYC as nothing more than identity document verification is an oversimplification. An identity document is only one source used to verify customer information. Effective risk management requires a broader understanding of who stands behind the customer, the nature of the relationship, what activity can reasonably be expected, and whether any material changes occur during the relationship. Customer due diligence measures must also be documented. An obligated institution should be able to demonstrate that the measures it applied were appropriate for the identified level of risk.
When Should KYC Be Performed and Updated?
The most obvious point is when establishing a business relationship, meaning when the institution begins working with a customer. However, this is not the only situation covered by the Polish AML Act. Customer due diligence measures must also be applied in situations including certain occasional transactions, suspected money laundering or terrorist financing, and cases where doubts arise regarding the accuracy or completeness of previously obtained customer identification information. The specific thresholds for occasional transactions depend on the type of transaction and the category of obligated institution.
These requirements are also not limited to new customers. The Act requires appropriate measures to be applied to existing customers based on the identified level of risk. This is particularly relevant when the nature or circumstances of the relationship change or when information concerning the customer or beneficial owner changes. In practice, this means that KYC should be updated not only according to an established review schedule, but also when an event occurs that makes the existing information no longer accurately reflect the customer. Examples may include a change in company ownership, expansion into a new market, a significant change in the business model, or other new information affecting the customer’s risk assessment.
KYC vs. CDD and EDD – What’s the Difference?
In AML materials, KYC often appears alongside the terms CDD and EDD. These concepts are related, but they are not interchangeable.
- KYC (Know Your Customer) is primarily a practical term for the process of understanding the customer—establishing their identity, collecting relevant information, and building a customer profile that can be used to assess risk.
- CDD (Customer Due Diligence) refers to the broader due diligence process applied to a customer. In the Polish regulatory context, its closest equivalent is the set of środki bezpieczeństwa finansowego under the Polish AML Act: identification, verification, beneficial ownership, assessment of the relationship, and ongoing monitoring.
- EDD (Enhanced Due Diligence) refers to enhanced scrutiny applied in higher-risk situations. The Polish AML Act requires enhanced customer due diligence measures where a higher risk of money laundering or terrorist financing has been identified.
The relationship can therefore be simplified as follows:
KYC helps you understand the customer → CDD defines the due diligence applied to that customer → higher risk may require EDD.
This does not mean that every customer should go through the same set of checks. The scope of the process should reflect the risk of the specific relationship rather than follow a single universal checklist.
What Happens if KYC Cannot Be Completed?
Sometimes the issue is not that the customer presents a high level of risk, but that the institution cannot obtain or reliably verify the information required to apply customer due diligence measures. This may happen, for example, when the customer’s identity cannot be verified, the beneficial owner cannot be identified, or the institution cannot obtain the information needed to understand the business relationship. In such cases, an obligated institution cannot simply accept the missing information and proceed.
Under Article 41 of the Polish AML Act, if one of the required customer due diligence measures cannot be applied, the obligated institution must, depending on the circumstances, refuse to establish the business relationship, refuse to carry out an occasional transaction, refrain from carrying out a transaction through a bank account, or terminate an existing business relationship. The institution should also assess whether the circumstances provide grounds for submitting the appropriate notification to GIIF (the General Inspector of Financial Information).
This does not mean that every missing piece of information automatically indicates an attempt to launder money. The key question is whether the institution can apply the required measures and properly assess the associated risk. Effective KYC is not about collecting as many documents as possible. It is about obtaining and verifying the information needed to genuinely understand the customer, assess the associated risk, and respond to changes that occur throughout the business relationship.
KYC OUTSOURCING
Need Support With Your KYC Processes?
We can handle day-to-day tasks related to customer identification and verification, beneficial ownership analysis, PEP and sanctions screening, risk assessment, and KYC data updates. Tell us briefly about your organization and the processes you would like to improve or outsource. We’ll tailor the scope of our support to your needs.
Contact us
office@amloutsourcing.pl
Explore more AML articles
- What is AML (Anti-Money Laundering)
- KYC vs. AML: What’s the Difference?
- What Is an AML Officer and What Do They Do?