Three levels of due diligence, one common standard
Customer due diligence covers every check an institution runs on a customer’s identity, business, and source of funds. National regimes all derive from a common framework. The 40 Recommendations of the Financial Action Task Force (FATF) set that framework, and mutual evaluations, in which countries review one another, check how it is applied. A jurisdiction found deficient is placed under increased monitoring. Recommendation 1 establishes the risk-based approach. Recommendation 10 names the four events that trigger due diligence: establishing a business relationship, an occasional transaction above a threshold, a suspicion of money laundering or terrorist financing, and doubts about data already collected. The same grid shows up in every market. Local law transposes it, and a local authority supervises how it is applied.
The due diligence level is how intensively an institution scrutinizes a given business relationship. Each customer gets its own level, which can be revised over the life of the relationship. It rests on a risk rating that the institution must be able to justify with documentation. Everywhere, that rating is built on four factors: customer, product, distribution channel, and geography.
| Level | Trigger | What it adds to the file | Operational impact |
|---|---|---|---|
| Simplified due diligence (SDD) | Low risk, demonstrated and documented: capped product, limited-purpose e-money, counterparty that is itself regulated and supervised | Lighter or deferred verification, fewer documents, automated consistency checks | Onboarding in minutes. Low caps that cannot be raised without additional documentation |
| Standard due diligence | Default case, when no aggravating factor applies | Verified identity, business activity, declared source of funds, and beneficial owners for a legal entity | The file must be complete before the first payout, not before the first sale |
| Enhanced due diligence (EDD) | Politically exposed person, high-risk third country, correspondent banking relationship, opaque ownership structure, high integrity-risk sector | Documented source of wealth, senior management sign-off, closer transaction monitoring | Onboarding takes weeks. More frequent reviews, and the institution may exit the relationship on its own decision |
Being on the FATF “gray list” means a jurisdiction is under increased monitoring. The listing carries no sanction in itself. Its effects come from correspondent banks worldwide, which then apply enhanced due diligence to flows from that jurisdiction. Those effects last well beyond delisting. Malta was on the list from June 2021 to June 2022, and local media reported that around 40 licenses had been surrendered by the end of 2021 (The Shift News, November 2021). Lebanon was added in October 2024, with its cash-based economy explicitly cited. Nigeria, South Africa, Mozambique, and Burkina Faso were removed at the October 24, 2025 plenary.
- Politically exposed person: FATF Recommendation 12 covers the individual, their family members, and their known close associates. The status does not lapse automatically the day after the person leaves office.
- High-risk third country: residence, nationality, registered office, and the place where the transaction is carried out. These are four independent criteria. They do not overlap, and each is checked separately.
- Opaque ownership structure: chains of holding companies, trusts, nominee shareholders, and bearer shares where they still exist.
- Correspondent banking relationship: the correspondent bank must know its respondent bank’s customers without having access to them. Nested banking, where a third bank uses the second bank’s account, grows out of that blind spot.
- High integrity-risk sector: gambling, adult content, pharmaceuticals, and digital asset brokerage. The card networks keep their own list, separate from the supervisor’s, with their own registration fees.
Account tiers turn KYC into a lever for financial inclusion
An account tier is a level of account access with regulatory caps, available with reduced due diligence. Tiers resolve a tension between financial inclusion and due diligence: requiring proof of address shuts out people who have none. The first tier opens with a minimal identifier and low caps. Higher tiers lift those caps but require full due diligence. Four continents designed the mechanism independently, with no country copying another. That they converged without a shared model shows how strong the underlying constraint is.
| Market | Legal framework | Entry tier | What lifts the caps |
|---|---|---|---|
| India | Master Direction – Know Your Customer, Reserve Bank of India, issued February 25, 2016, updated August 14, 2025 | Account opened via Aadhaar e-KYC with a one-time passcode. Aggregate balance capped at ₹1 lakh, total credits at ₹2 lakh per year, account unusable after one year | Full due diligence at a branch, or via V-CIP, the RBI’s standardized video identification process |
| China | Three-category bank account regime introduced by the People’s Bank of China in 2015 | Category II and III accounts, opened remotely, with balance and transaction caps | Opening a Category I account at a branch, in person |
| Mexico | Disposiciones de carácter general for credit institutions, issued under Article 115 of the Ley de Instituciones de Crédito (CNBV) | Level 1 and 2 accounts, simplified file, monthly caps set in investment units (UDIs) | Upgrade to levels 3 and 4, with a complete file and face-to-face verification |
| Nigeria | Central Bank of Nigeria’s three-tier regime, built on the Bank Verification Number launched with NIBSS in 2014 | Tier 1 account, with low balance and transaction limits | BVN and full documentation, for Tier 2 and then Tier 3 |
| Colombia | Depósito de bajo monto, a simplified account category whose prototype is Daviplata (Banco Davivienda, 2011) | Opened from a phone, with balance and transaction caps | Migration to a regular deposit account, with a complete file |
Tiers affect payment acceptance design in three ways. The first is product. A tier cap is a binding regulatory limit, not an internal risk setting, and customer support cannot lift it case by case. The second is cash management: funds collected for a customer stuck in the entry tier pile up and cannot be paid out. The third is conversion. A flow that demands full due diligence up front loses the customers the entry tier would have captured.
Tiers come with an obligation to monitor the caps. When an account hits its limit, it must be blocked, not just flagged. The Reserve Bank of India spells this out for OTP-based e-KYC: the account becomes unusable after 12 months unless full due diligence has been completed. A monitoring setup that only raises an alert lets the account run outside the regime, sometimes for months.
India: Aadhaar e-KYC, V-CIP, and a central KYC registry
Aadhaar is a 12-digit identifier issued by the Unique Identification Authority of India (UIDAI). It is backed by biometric and demographic data and governed by the 2016 Aadhaar Act. India has turned it into public identity infrastructure. Financial institutions use it to verify customers without a branch visit. An authorized institution queries UIDAI and gets back a digitally signed response, with no paper documents involved. UIDAI’s published counters show how far the system has scaled.
Access to Aadhaar e-KYC requires authentication user agency or e-KYC user agency status. That status is contracted with UIDAI and limited to authorized categories. A foreign provider cannot plug in with just an API key. Most nonbank firms go through a licensed partner, and that partner is who they negotiate with. Three channels remain outside online authentication. Offline Aadhaar XML is downloaded by the customer and signed by UIDAI. Masked Aadhaar shows only the last four digits. The Virtual ID (VID) is a revocable token that stands in for the number.
The Central KYC Records Registry (CKYCR), run by CERSAI, has centralized KYC records for India’s financial sector since 2016. It is the second layer of the system, after Aadhaar authentication. A customer verified once receives a 14-digit KYC identifier, which lets another institution retrieve the record instead of rebuilding it. Portable due diligence has worked in India for 10 years, while Europe is still building it one directive at a time.
Video KYC: one method, as many regimes as supervisors
Remote identification covers any method of verifying a customer’s identity without the customer being physically present. Video KYC is the variant in which the customer shows an official ID document to a camera. Europe has no single method, and won’t before 2027. Each member state authorizes its own methods, through a supervisory circular or by reference to national law. A single banking group may therefore run four or five different onboarding flows across the EU. The regimes differ less on the principle than on the evidence required and on who keeps it.
| Regime | Proof of identity | Proof of presence | Technical requirements |
|---|---|---|---|
| V-CIP, Reserve Bank of India | Official document shown on camera, or offline Aadhaar XML, with a consistency check | Live video interview with random questions; liveness detection mandatory | Infrastructure hosted on the institution’s own premises, end-to-end encryption, GPS coordinates and timestamp in the recording, penetration tests by a CERT-In-empaneled auditor |
| Videoident, Germany | Document read and its optical security features checked on screen | Live video interview with a trained agent | Recording retained, human agent required. The Chaos Computer Club publicly defeated a flow of this kind in August 2022, reopening the debate on the required level of assurance |
| Video identification, Spain | Document read, automated checks, human review after the fact | Video recorded by the customer, with no live agent | Recording and audit trail retained. Methods authorized since 2016 by SEPBLAC, Spain’s financial intelligence unit and AML supervisor |
| Reusing a bank identity | The bank that already performed due diligence vouches for the customer (BankID, itsme, iDIN, Smart-ID) | Strong authentication with the vouching bank | No video capture. The relying party inherits due diligence without knowing its exact scope |
| Querying a government registry | Signed response from the registry (Aadhaar in India, Myinfo in Singapore, BVN in Nigeria) | A factor tied to the registry, often a code sent to the mobile number on file | Access authorization, contract with the authority, consent logged for every request |
Liveness detection is the check that tells a person actually in front of the camera from a reproduction of their face. Two attack vectors are routinely confused. A presentation attack holds a screen, a photo, or a mask up to the lens, and image analysis catches it. An injection attack replaces the camera feed with synthetic video upstream of the sensor. The stream that arrives is perfectly clean, so this check cannot detect it. The ISO/IEC 30107-3 standard governs how these checks are evaluated, and test levels and the attack vectors covered vary from one certification to the next. A certification that covers presentation attacks alone proves nothing about resistance to injection.
The EU’s anti-money laundering package will end this patchwork on a date that is already set. Regulation (EU) 2024/1624, adopted on May 31, 2024, applies from July 10, 2027. It replaces national transpositions with a directly applicable text, which removes the leeway in which local methods grew up. Directive (EU) 2024/1640 accompanies it. Regulation (EU) 2024/1620 creates the Anti-Money Laundering Authority (AMLA), whose seat was set in Frankfurt am Main in February 2024. AMLA will draft the technical standards for remote onboarding and, from 2028, will directly supervise a first group of cross-border institutions.
Beneficial ownership registers
The beneficial owner is the natural person who ultimately controls a legal entity. FATF, EU law, UK law, and the US customer due diligence rule all use the same benchmark threshold: 25% of the capital or voting rights. But identifying the owner is more than applying that threshold. Control can also come through a shareholders’ agreement, the power to appoint directors, or financing, without any single stake reaching a quarter. When no beneficial owner can be identified, the regimes require the institution to name the senior managing official as a fallback.
| Register | Who reports | Who has access | What it does not guarantee |
|---|---|---|---|
| EU national registers | Every company incorporated in the member state | Authorities, obliged entities, and, since Directive (EU) 2024/1640, people with a legitimate interest | Accuracy. The data is self-declared, and how thoroughly it is verified varies by country |
| PSC register, UK | Every company registered with Companies House | The public, free of charge | The filer’s honesty. Identity verification has been mandatory only since November 18, 2025 |
| Register of Overseas Entities, UK | Foreign entities that own property in the UK | The public, with restrictions on trust information | Coverage. The register covers property ownership only, not business activity |
| Beneficial Ownership Information, FinCEN (US) | Since the March 26, 2025 interim final rule, only foreign companies registered in a US state | Authorized agencies, and financial institutions with the reporting company’s consent | Universal coverage. Companies formed in the US no longer have to report |
A beneficial ownership register records what the company declares. It does not establish who actually owns it. Three mechanisms are enough to hollow it out. A nominee shareholder appears on the register without holding real power. A chain of holding companies dilutes each stake below the threshold, layer after layer, until no name surfaces. A trust separates the settlor, the trustee, and the beneficiary, often across jurisdictions whose registers do not go equally deep. That is why FATF’s March 2022 revision of Recommendation 24 requires countries to combine several sources of information rather than rely on the register alone.
KYB for platform sellers
KYB is the verification of a legal entity entering into a business relationship. KYC applies to individuals. No business identifier is mandatory worldwide, and no cross-border register can be searched with a single query. A platform onboarding 2,000 sellers a week in 20 countries therefore deals with 20 formats, 20 registers, and 20 update cycles. Most of the cost lies in the internal reference database, not in each individual check. That database lists, for every country, which business number to ask for and which official source to check it against.
| Market | Identifier | Issuing registry | What it lets you verify |
|---|---|---|---|
| Brazil | CNPJ | Receita Federal | Existence, tax status, declared activity. A business chave Pix is tied to its holder’s CNPJ |
| India | CIN for the company, GSTIN for indirect tax | Ministry of Corporate Affairs, tax authority | Registration, legal form, tax registration status |
| Singapore | UEN (Unique Entity Number) | Accounting and Corporate Regulatory Authority | Existence, plus direct addressing: PayNow uses the UEN as the proxy for legal entities |
| Malaysia | SSM registration number | Suruhanjaya Syarikat Malaysia | Existence, plus DuitNow addressing by business registration number |
| Thailand | Corporate tax ID | Thai Revenue Department | PromptPay uses this number to address legal entities, which ties the account to a registered entity |
| Indonesia | NIB and NPWP | OSS system, tax authority | Business license and tax registration, checked separately |
| United Kingdom | Company number | Companies House | Existence, directors, persons with significant control, filed accounts |
| Nigeria | RC number | Corporate Affairs Commission | Existence and legal form. The director is verified through their BVN |
| Japan | 13-digit corporate number (法人番号) | National Tax Agency | Official name and address, publicly available free of charge |
| Mexico | RFC | Servicio de Administración Tributaria | Tax registration, in practice a prerequisite for payouts |
The Legal Entity Identifier (LEI) is a 20-character code defined by ISO 17442, issued by accredited organizations and overseen by GLEIF. It is a global identifier, but it is not mandatory outside the financial sector. What sets it apart is its relationship data. The LEI shows the direct parent and the ultimate parent, which no national register does. Renewal is annual and paid, so part of the population sits in lapsed status. A lapsed LEI still identifies the entity, but its ownership hierarchy is no longer attested.
The card networks set their own KYB requirements on top of the supervisor’s. Under Visa and Mastercard rules, an aggregator that collects payments for sellers must onboard and monitor its sponsored merchants. Visa rules require a sponsored merchant to contract directly with the acquirer once its annual volume exceeds $1 million. In 2022, Visa replaced its Global Brand Protection Program with the Visa Integrity Risk Program. Mastercard runs the Mastercard Registration Program. Under both, high integrity-risk categories are registered, monitored, and billed, regardless of any legal requirement.
- Matching the director, the beneficial owner, and the payout account holder. These three names should line up, and in fraudulent files they almost never do.
- Age of the registration. A company incorporated three weeks before onboarding, in a high-ticket category, warrants a manual review before the first payout.
- The same business identifier reused across several seller accounts, often with slightly different spellings of the company name.
- Declared category versus the actual catalog. Check the published listings, not the sign-up form.
- A change of payout account shortly before a large payout. It signals a compromised seller account and calls for a cooling-off period.
Sanctions and screening
Financial sanctions are measures that freeze assets and prohibit making funds available to specifically designated individuals or entities. Screening is the process by which an institution checks the parties to a transaction against those designation lists. The regime differs from AML due diligence. AML tolerates a calibrated, documented residual risk; an asset freeze tolerates none. A payment made to a designated person is a violation, whatever the intent. Under US rules, civil liability is strict. Dollar clearing alone gives US authorities jurisdiction, even over a flow between two non-US banks. The nexus comes from routing through a New York correspondent bank, which the customer does not choose.
| List | Authority | Reach | What sets it apart |
|---|---|---|---|
| SDN List and non-SDN lists | Office of Foreign Assets Control, US Department of the Treasury | US persons, and any transaction with a US nexus, including dollar clearing | The broadest and most demanding regime. Secondary sanctions risk reaches firms with no US presence at all |
| EU Consolidated Financial Sanctions List | European Commission, based on Council decisions and regulations | EU persons and transactions carried out in the EU | Each measure has its own legal basis. Obligations vary from one sanctions regime to another |
| UN Security Council Consolidated List | United Nations | All member states, once transposed into national law | The common baseline that other lists incorporate, transposed with varying delays from country to country |
| UK Sanctions List and OFSI Consolidated List | Foreign, Commonwealth and Development Office, HM Treasury | UK persons and transactions with a UK nexus | A standalone regime since Brexit, with deliberate differences in scope |
| National lists (Switzerland’s SECO, Australia’s DFAT, Global Affairs Canada, Japanese authorities) | National authorities | Depends on the nexus of the transaction or the party | Screening only against US and EU lists leaves documented gaps on some corridors |
Two rules extend a designation to structures owned by a designated person, so the list never contains every entity covered. OFAC has applied the 50% rule since revised guidance issued on August 13, 2014. An entity owned 50% or more, directly or indirectly, individually or in the aggregate, by one or more designated persons is itself blocked, even though it is not on the list. The EU uses an ownership test of more than 50%, supplemented by a set of control indicators. Screening on names alone therefore misses these owned entities. Catching them means tracing the ownership chain as it stood on the date of the transaction.
Screening comes down to comparing character strings. A name written in Arabic, Cyrillic, or Chinese arrives transliterated, and every transliteration produces variants. Mohammed, Muhammad, and Mohamed are the same person. Screening engines therefore use fuzzy matching with an adjustable similarity threshold. A lower threshold multiplies false positives and swamps the review team. A higher threshold produces false negatives, letting through a transaction that benefits a designated person, and the asset-freeze regime tolerates none. Threshold tuning must be documented, tested against known test sets, and rerun with every list update.
Remediation and periodic review
Remediation means reworking a backlog of due diligence files that no longer meet the standard. It is rarely planned for in workload forecasts, yet it weighs heavily on budgets once it starts. Volumes run to tens or hundreds of thousands of files. The timeline is set externally and cannot be negotiated. The per-customer onboarding cost, optimized for years, says nothing about the cost of reworking an old file for a customer who no longer responds.
- Supervisory follow-up. The authority sets the deadline, and progress is reported periodically, file by file.
- Acquisitions. The acquired portfolio was built under a different regime, sometimes in a different country. The files cannot be converted; they have to be redone.
- A change of standard. When Regulation (EU) 2024/1624 starts to apply on July 10, 2027, it will trigger projects like this across the EU.
- A structural collection gap. A field never filled in, a document never requested, discovered years later across the entire backlog.
- A country added to the gray list. Lebanon’s listing in October 2024 moved every relationship linked to that market into enhanced due diligence overnight.
Traditional periodic review schedules a reassessment at a fixed interval, with a frequency set by risk level. The model has two mirror-image flaws. It forces reviews of files that nothing has changed, and it leaves untouched, for a full cycle, files that changed the day after their review. Ongoing due diligence, often called perpetual KYC, works the other way around: events trigger the review. A change of director in the register, a change in the ownership structure, the customer’s country of residence being added to a list, or a break in the transaction profile is enough to reopen the file. The periodic cycle then remains as a safety net rather than the main trigger.
De-risking is when an institution exits entire categories of relationships rather than bear the cost of monitoring them. FATF and the World Bank have documented it for a decade. Remittance corridors to Africa and the Pacific still bear the marks, with operators cut off from banking services. Exiting is a business decision made under compliance pressure, not a compliance decision in the strict sense. How it is characterized shapes the institution’s defense. A business decision generally falls under its freedom to contract, while a compliance decision is judged against a documented risk assessment.
What breaks in production, and what it costs
Failures seen in production stem from how compliance controls are implemented, and more rarely from how the law is interpreted. They come from operational trade-offs that nobody decided when it mattered. The same failures recur from one market to the next under different names. Each one can be caught before go-live by explicitly testing the point in question.
| Failure | Root cause | What it costs | Prevention |
|---|---|---|---|
| Funds collected for a customer who was never verified | Payment collection starts before the file is complete, with no cap attached | Orphaned balances that cannot be paid out and are hard to return. The supervisor sees funds held with no legal basis | Cap collections until the file is complete, from the moment the flow is designed |
| Sanctions alert not handled in time | False-positive volume sized on the average, not on list-update peaks | Transactions executed without disposition. A clear-cut breach, regardless of the outcome | Size for the peak, and document the queue prioritization rule |
| e-KYC consent not logged | The integration logs the registry’s response, not the request or the consent | Files unusable for the entire period affected. They cannot be reconstructed after the fact | Test the audit trail end to end during acceptance testing, on a real file |
| Beneficial owner frozen at onboarding | No review triggered by a register event | The file is wrong from the first change in shareholding, and nothing flags it | Subscribe to register change notifications for the entire legal-entity portfolio |
| Verification redone in every country | No single customer database across subsidiaries or brands | Higher costs, a worse customer experience, and personal data duplicated for no reason | A single customer database, subject to each market’s data localization rules |
| List reloaded without rescreening the customer base | The engine screens the transaction flow, never the existing portfolio | A customer designated after onboarding stays active and keeps being served | Full portfolio rescreen on every update, with timestamped proof that it ran |
- Actual coverage by country, distinguishing registers queried live from copied databases. A copied database goes stale, and its age is never displayed.
- Sanctions list latency, between official publication and availability in the vendor’s feed.
- The liveness detection test level, with the standard applied and the attack vector actually covered.
- Raw data returned, not just the verdict. A “rejected” with no reason can be neither challenged nor improved.
- Where processing and storage take place, market by market. India, Indonesia, and Nigeria impose constraints that a European master agreement ignores.
- Reversibility, with a usable export of the verified-file backlog. A due diligence file that cannot be ported locks you in for years.