KYC process explained: Steps, requirements, and automation

Describe your business process. Moxo builds it.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The KYC (Know Your Customer) process is the regulatory framework organizations use to verify customer identity, assess risk, and monitor ongoing activity across three core stages: the Customer Identification Program (CIP), Customer Due Diligence (CDD), and ongoing monitoring.

The three stages are well understood. How they execute across teams in practice is where most organizations lose time.

Fenergo's 2025 research found that 70% of financial institutions lost clients due to slow or inefficient onboarding, up from 48% in 2023.

Average annual KYC and AML spend now stands at $72.9 million per financial institution, and 52% of banks spend 61 to 150 days on client KYC reviews. Most of that time is not verification. It is chasing documents, routing reviews, and escalating exceptions through email.

This article explains the three stages of the KYC process (CIP, CDD, and ongoing monitoring), why operational breakdowns during handoffs and document collection lead to long review times and high costs, and how automation can address those workflow challenges to reduce client onboarding time.

Key takeaways

The KYC process has three stages, but the handoffs between them are where onboarding stalls. Customer identification, due diligence, and ongoing monitoring are well-defined requirements. The operational challenge is moving work between the client, compliance analysts, legal, and relationship managers without losing weeks to incomplete submissions and unrouted reviews.

Most KYC costs come from coordination, not verification. AI can verify an identity in seconds. The 61 to 150 days banks spend on a single review reflects time lost chasing documents and reconciling data across disconnected systems.

Automation works best when it targets the workflow. Automating identity verification is step one. Automating document collection, risk-based routing, and exception escalation around verification is where real cycle time reductions compound.

What is the KYC process?

KYC is the regulatory obligation requiring organizations to verify who their customers are, assess the risk they present, and monitor their activity throughout the relationship. Its purpose is preventing fraud, money laundering, and terrorist financing. The regulatory basis spans FATF recommendations, the Bank Secrecy Act, USA PATRIOT Act, EU Anti-Money Laundering Directives, and jurisdiction-specific frameworks.

KYC applies to any regulated organization onboarding customers: banks, fintechs, insurance companies, cryptocurrency exchanges, real estate firms, and professional services firms. It is not a one-time check. It is a lifecycle obligation spanning identification, due diligence, and continuous monitoring.

The relationship between KYC and AML is worth clarifying: KYC is one component of a broader AML compliance program. KYC asks "who is this customer?" AML asks "what is this customer doing?" Both questions get answered well only when you orchestrate the KYC onboarding workflow as a structured process rather than a checklist.

The three stages of the KYC process

Stage 1: Customer Identification Program (CIP)

Collecting and verifying basic customer information: full name, date of birth, address, and government-issued identification. For individuals, this means a passport, national ID, or driver's license plus proof of address.

For corporate entities (KYB), this includes business registration, beneficial ownership documentation identifying all individuals with 25%+ ownership, and authorized signatory verification.

The regulatory requirement is straightforward. The operational challenge is getting clients to submit complete, valid documents on the first attempt. The average onboarding team sends three rounds of follow-up requests because the initial submission was incomplete, expired, or in the wrong format. A KYC onboarding checklist sets out the full document requirements by customer type.

Stage 2: Customer Due Diligence (CDD)

Assessing the customer's risk profile based on collected information. This includes screening against sanctions lists, PEP databases, and adverse media, then assigning a risk tier (low, medium, high) that determines ongoing scrutiny.

Standard CDD applies to most customers. Enhanced Due Diligence (EDD) is triggered for PEPs, high-risk jurisdictions, complex corporate structures, or unusual transaction patterns. Risk tiering sounds clean on paper. In practice, when a PEP flag appears, legal needs to weigh in.

When a corporate structure is complex, a senior reviewer or committee decides. These escalation paths are almost never structured. They happen through Slack messages and forwarded emails, a gap that AI for customer onboarding in banking is built to close.

Stage 3: Ongoing monitoring

Continuous or periodic re-evaluation of the customer's risk profile and activity. This includes transaction monitoring for suspicious patterns and periodic KYC reviews at intervals based on risk tier (quarterly for high-risk, annually for medium, at renewal for low).

Ongoing monitoring is where most KYC programs quietly fail. The initial onboarding is thorough because it has a deadline. Periodic reviews get deferred, rescheduled, and eventually rushed or missed.

The annual review for your highest-risk client was due four months ago. The compliance officer who owned it transferred departments. Nobody reassigned it.

Common KYC process bottlenecks

Incomplete submissions and the follow-up spiral. Clients submit wrong formats, forget proof of address, or send expired IDs. Each incomplete submission triggers follow-up that sits in the client's inbox. Three rounds of chasing is standard. Five is not uncommon. The client replied to your secure portal link by emailing their passport to someone's personal Gmail with the subject line "here u go." That loop is exactly what automating KYC workflows is designed to remove.

Unstructured escalation paths. When screening flags a PEP match, the next step should be automatic: route to senior compliance with screening output, risk score, and context. In practice, the analyst sends a Slack message, the senior reviewer asks for documents to be forwarded, and the escalation takes three days before review even begins.

Disconnected systems and manual re-entry. Verification lives in the IDV platform. Screening results in the AML system. Documents in email. Records in the CRM. Compliance analysts re-enter data across systems, and every re-entry is a reconciliation risk.

Periodic review decay. Initial onboarding KYC is thorough. Periodic reviews have no external forcing function. They get deferred until an auditor asks. Fenergo data shows 52% of banks spend 61 to 150 days on client KYC reviews, most of it re-gathering data that already exists somewhere.

How to use automation across the KYC process

Start where the work is repetitive and rule-based, and let automation carry it. These are the parts of KYC that are ready to automate today:

  • Document capture. OCR pulls data from IDs and proof of address in seconds, and rejects expired or invalid files before they reach an analyst.
  • Screening. Sanctions and PEP checks run in real time, with fuzzy matching that trims false positives.
  • Risk scoring. Each customer gets a tier automatically, so standard cases flow through CDD and high-risk ones route to EDD.
  • Document collection. Structured forms, completeness checks, and automated reminders end the follow-up spiral.
  • Periodic reviews. They trigger on schedule with the file prepopulated, so analysts review instead of re-gather.

Then draw a hard line at judgment. Enhanced due diligence, PEP clearances, suspicious activity referrals, and calls on complex ownership structures stay with experienced compliance professionals. Automation prepares the evidence and routes it to the right person. A human still owns the decision.

The real gain comes when these steps stop running as separate tools and connect into one onboarding compliance automation flow. A validated document moves straight into screening, then scoring, then the right reviewer's queue, with no one re-keying data or chasing a handoff.

How Moxo orchestrates the KYC process end to end

The KYC process does not break at the stages. It breaks at the handoffs between them, and that is the layer Moxo is built for: a process orchestration platform that turns the three stages into one structured workflow with a clear owner at every handoff.

Clients submit documents through a magic link while an AI agent validates completeness at submission, so analysts only open complete packages.

Cases then route by risk tier on their own, with PEP flags and complex structures escalated to senior compliance or legal with full context attached, and periodic reviews trigger on schedule, prepopulated with existing data.

AI agents handle the execution work while compliance professionals own every risk decision, and each action lands in a compliance-grade audit trail across 65+ action types. The result is shorter cycle times, fewer incomplete submissions, and an audit trail regulators can read without manual reconstruction

Check out our guide on AI-powered customer onboarding to learn how this orchestration extends across the full client lifecycle.

Make your KYC process flow

Structured handoffs, not better policies. The KYC process is already well defined: three stages, clear regulatory requirements, established document standards. What is not defined in most organizations is how work moves between stages, who owns each handoff, and how exceptions are escalated when the standard path does not apply.

The organizations that onboard clients fastest are the ones that close that gap, running KYC as a workflow with clear ownership, automated routing, and audit trails that satisfy regulators without manual reconstruction.

Moxo orchestrates the KYC lifecycle so AI handles document validation, screening, and routing while humans retain ownership of every risk decision. Explore how it works in practice with client onboarding automation.

FAQ

What are the three steps of KYC?

The three stages are the Customer Identification Program (CIP), which collects and verifies basic identity information; Customer Due Diligence (CDD), which assesses the customer's risk profile through screening and risk tiering; and Ongoing Monitoring, which continuously or periodically re-evaluates the customer's activity and risk posture throughout the relationship.

How long does the KYC process take?

AI-powered identity verification takes seconds to minutes. The overall cycle depends on human steps: document collection (days to weeks if incomplete), compliance review (hours to days), and EDD when triggered (days to weeks for committee decisions). Fenergo data shows 52% of banks spend 61 to 150 days on client KYC reviews, most of it on document gathering and data re-entry.

What is the difference between KYC and AML?

KYC is one component of a broader AML compliance program. KYC verifies customer identity and assesses risk at onboarding and periodic review. AML encompasses KYC plus ongoing transaction monitoring, suspicious activity reporting, sanctions compliance, and regulatory filing. KYC asks "who is this customer?" AML asks "what is this customer doing?"

What happens if KYC fails?

If an organization fails to conduct adequate KYC, it faces regulatory penalties, potential criminal liability, reputational damage, and loss of banking relationships. AML and KYC fines totaled approximately $4.6 billion globally in 2024. If a customer fails KYC (identity cannot be verified, screening flags unresolvable risks), the organization must decline the relationship and file a Suspicious Activity Report if warranted.

Describe your business process. Moxo builds it.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.