Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 28, 2026

AML Compliance: KYC, CDD, Screening, and Monitoring

An AML operations guide to customer due diligence, beneficial ownership, KYC inputs, screening, risk rating, enhanced checks, transaction monitoring, investigations, and governance.

By DiditUpdated
aml-compliance-kyc-cdd-screening-monitoring-guide.png

AML and KYC are connected but not interchangeable. KYC, or Know Your Customer, establishes and maintains an understanding of who a customer is and the risk of the relationship. AML, or anti-money laundering, is the broader framework for preventing, detecting, investigating, and reporting suspected money laundering and related financial crime.

KYC supplies identity, ownership, purpose, and initial risk context. AML controls use that context for sanctions and politically exposed person screening, ongoing customer review, transaction monitoring, alert investigation, reporting, records, training, and governance. A document check may support KYC, but neither KYC nor AML is complete when the document passes.

This guide is the AML-compliance companion to the broader KYC lifecycle guide. It does not repeat how to run identity proofing or a general KYC program. It starts where identity, ownership, and customer context become inputs to screening, monitoring, investigation, reporting, and governance.

Key takeaways

  • KYC is a component of AML. It identifies and assesses the customer; AML also governs continuing activity, investigations, reporting, and program oversight.
  • CDD is risk-based and ongoing. Customer due diligence covers identity, beneficial ownership, purpose, risk, and continuing scrutiny—not only account opening.
  • Screening and transaction monitoring answer different questions. Screening compares people or entities with external risk data; transaction monitoring evaluates behavior and activity.
  • A potential match is not a confirmed match. Names collide, sources change, and context matters; review and documented resolution are part of the control.
  • Technology does not own accountability. Providers can collect evidence, score matches, and generate alerts, while the obliged organization remains responsible for policy, decisions, records, and regulatory reporting.

What is the difference between AML and KYC?

KYC focuses on the customer relationship. It asks:

  • Who is the customer?
  • Who owns or controls a business customer?
  • Why is the relationship being established?
  • What activity is expected?
  • What customer risk is present?
  • When must the record be refreshed?

AML covers the wider control system. It asks those KYC questions and also:

  • Is the customer or related party exposed to sanctions, political influence, or other relevant risk?
  • Does actual activity fit the customer profile?
  • Which alerts require investigation?
  • When should activity be restricted or reported?
  • Are records, governance, training, and independent oversight adequate?

The FATF Recommendations, as amended June 2026, are the international standard. Recommendation 10 establishes customer due diligence, while related recommendations address recordkeeping, politically exposed persons, correspondent relationships, new technologies, and suspicious-transaction reporting. Jurisdictions implement these standards differently, so a global framework still needs country- and sector-specific legal analysis.

KYC, CDD, EDD, screening, and monitoring compared

ControlPurposeTypical triggerMain output
KYCKnow and risk-assess the customerOnboarding and material changeCustomer identity and risk record
CDDApply customer due diligenceRelationship, qualifying transaction, suspicion, or doubtIdentity, beneficial owner, purpose, risk, ongoing plan
EDDApply enhanced due diligenceHigher-risk customer, product, geography, ownership, or behaviorAdditional evidence, approvals, source analysis, closer monitoring
Sanctions screeningIdentify possible targeted-financial-sanctions exposureOnboarding, payment, data change, list updateCandidate or resolved match
PEP screeningIdentify politically exposed persons and related riskOnboarding and rescreeningPEP relationship and required enhanced measures
Ongoing screeningDetect changes in customer external-risk dataSource update or scheduled rescreenNew or changed candidate match
Transaction monitoringIdentify activity inconsistent with profile or typologyTransaction or aggregated behaviorAlert with evidence and rule/model context
Investigation and reportingResolve alerts and meet reporting dutiesEscalated suspicionCase decision, restriction, report, or closure rationale

CDD is the bridge. It creates the customer context that makes later signals interpretable. A large transfer can be expected for one business and highly unusual for another. Without purpose, ownership, expected activity, and risk, monitoring becomes a collection of decontextualized thresholds.

The AML and KYC lifecycle

1. Assess enterprise and product risk

Before rating individual customers, understand the exposure created by products, delivery channels, geographies, customer types, transaction features, and operating model. The FATF risk-based approach guidance describes proportionality as central: identify and understand risk, then apply measures that match it.

This assessment should influence the information collected, screening scope, workflow branches, approval authority, transaction rules, review cadence, and monitoring intensity.

2. Identify the customer and beneficial owner

Collect the information necessary to identify a natural person or legal entity. For a business, identify the natural persons who ultimately own or control it, understand the ownership and control structure, and verify the relevant people according to the applicable requirement and risk.

Entity registration alone is not enough. A genuine company can be controlled by a hidden or prohibited person, while a complex structure may be legitimate but require more evidence to understand.

3. Verify identity using reliable evidence

Validate documents, data, digital credentials, authoritative sources, or permitted combinations. Link the applicant or representative to the claimed identity. Keep evidence authenticity, holder linkage, and customer eligibility as distinct decisions.

FATF’s digital identity guidance asks regulated entities to understand a digital identity system’s assurance and determine whether it is sufficiently reliable and independent for the risk. A technology label does not transfer responsibility.

4. Understand purpose and expected activity

Record why the customer wants the product, how it will be used, expected transaction patterns, source and destination context where relevant, and the nature of the business. Collect proportionate evidence rather than a generic questionnaire whose answers never influence policy.

Expected activity should become usable monitoring context. If onboarding data is stored as free text that the monitoring system cannot access, the lifecycle is disconnected.

5. Screen relevant people and entities

Screen the customer, beneficial owners, controllers, representatives, and other required parties against relevant sources. Depending on law and policy, this can include sanctions, politically exposed persons, relatives and close associates, adverse media, or other lists.

A match engine should preserve the source, list entry, matching fields, transliteration, aliases, date, threshold, and reason. Reviewers need enough evidence to decide whether the customer and listed subject are the same.

6. Assign customer risk

Combine customer, product, geography, channel, ownership, screening, and other relevant factors under a documented methodology. The result should be explainable: which factors mattered, what data supported them, and which controls follow.

Avoid using nationality or geography as a substitute for full analysis. Risk indicators can justify more scrutiny without proving wrongdoing. The February 2025 FATF amendments increased the focus on proportionality and simplified measures in lower-risk situations rather than indiscriminate exclusion.

7. Apply enhanced or simplified measures where justified

Higher risk may require more evidence, source-of-funds or source-of-wealth work, senior approval, closer monitoring, or other enhanced measures. Lower risk may permit simplified measures where law and policy allow, but not when suspicion or a specific higher-risk condition exists.

EDD is not “collect every possible document.” Each additional step should respond to an identified risk and have a decision rule.

8. Decide and preserve the audit record

Approve, decline, restrict, or route the relationship with a recorded rationale. Preserve the policy and risk-model version, evidence, screening results, reviewer actions, approval authority, timestamps, and reasons required for audit and later review.

If the organization cannot complete required due diligence, the response depends on applicable law and circumstances. It may need to avoid or terminate the relationship and consider reporting, while avoiding improper disclosure to the customer.

9. Monitor activity and customer changes

Ongoing due diligence tests whether transactions remain consistent with the organization’s knowledge of the customer, business, risk, and expected activity. FATF’s banking guidance describes monitoring as both transaction scrutiny and identifying changes to the customer profile that may require new or additional CDD.

Monitoring can be real-time, periodic, event-driven, or a combination. Higher-risk relationships generally justify greater depth or frequency; lower-risk relationships may justify proportionate controls.

10. Investigate, report, and learn

An alert is a prompt for analysis, not a conclusion. Investigators collect related transactions, customer history, external information, prior alerts, linked accounts, and explanations. The organization then documents why the case was closed, escalated, restricted, or reported.

Reporting decisions belong to the obliged organization and its authorized people. Provider alert labels should not automatically file a report or disclose suspicion to the customer.

AML screening explained

Sanctions screening

Sanctions controls seek possible matches to designated people, entities, vessels, or other subjects under applicable regimes. Lists, ownership rules, and prohibitions differ. A simple exact-name comparison cannot address aliases, transliteration, dates, geography, identifiers, and ownership or control.

PEP screening

A politically exposed person is not necessarily involved in crime. The FATF PEP guidance describes PEP measures as preventive and risk-based. A PEP result should trigger the required assessment and measures, not an automatic accusation or universal decline.

Adverse media and other sources

Adverse information can contribute to a risk assessment when the source, relevance, subject linkage, date, severity, and reliability are understood. Search results and allegations are not court findings. Reviewers need provenance and a documented way to weigh conflicting evidence.

Ongoing rescreening

Customer data and external sources change. Rescreening can be triggered by source updates, customer changes, review schedules, or events. The system should identify what changed instead of forcing analysts to repeat every prior resolution.

Transaction monitoring explained

Transaction monitoring compares current activity with rules, models, typologies, customer context, peer behavior, and historical patterns. Useful signal families can include:

  • value, frequency, velocity, and structuring patterns;
  • changes from expected customer activity;
  • unusual counterparties, corridors, assets, or timing;
  • movement through linked accounts or wallets;
  • rapid in-and-out movement or circular flows;
  • activity following a customer, device, ownership, or risk change.

No rule is suspicious in every context. A threshold creates an alert; investigation determines whether the facts support a concern. Monitoring design should state the scenario, data dependencies, time window, threshold, segmentation, expected false positives, disposition path, and owner.

The EU AML Regulation 2024/1624, which generally applies from 10 July 2027, requires ongoing monitoring and a risk-based intensity. Its rules illustrate why customer due diligence, transaction context, records, and reporting belong in one system even when different components perform each task.

Potential match, alert, case, and report

StageMeaningWhat should happen next
Potential matchData resembles an external source subjectCompare identifiers and context
AlertA screening or monitoring condition firedTriage evidence under documented priority
CaseRelated evidence is assembled for investigationInvestigate, document, escalate, or close
Suspicion decisionAuthorized analysis finds or rejects reasonable concernApply policy and legal duties
Regulatory reportRequired information is submitted to the competent bodyProtect confidentiality and preserve records

Collapsing these stages creates two opposite failures: every alert becomes an accusation, or alerts are closed without enough evidence. Clear states, roles, and reasons make quality measurable.

How to evaluate AML and KYC controls

Source coverage and provenance

Ask which sanctions regimes, PEP categories, ownership data, adverse information, and transaction fields are covered. Review source authority, update cadence, effective dates, correction handling, and historical reconstruction. A total list count does not show relevance to your obligations.

Matching and threshold controls

Test aliases, transliteration, reordered names, dates, identifiers, entities, common names, and missing fields. Review results at the proposed threshold, not only a vendor-selected accuracy headline. Measure candidate volume, true resolutions, false positives, and missed known cases.

Customer-risk methodology

Every risk score should map to evidence, factor weighting, policy consequences, overrides, and review. Validate that low risk actually receives proportionate measures and higher risk triggers bounded enhanced controls.

Monitoring design

Inventory scenarios and models, their data inputs, segmentation, thresholds, owners, versions, validation, alert routing, and retirement criteria. Confirm that onboarding data and customer changes reach monitoring in time.

Investigation operations

Inspect queues, priorities, evidence timelines, related entities, notes, approvals, segregation of duties, service levels, and disposition codes. Reviewers should be able to explain why a case was opened and closed.

Governance and testing

Assign owners for policy, data, models, lists, investigations, reporting, quality assurance, training, audit, and change control. Test end-to-end from customer creation through a simulated alert, case, decision, and record export.

Common AML and KYC mistakes

Treating KYC as a one-time gate

Identity, ownership, sanctions exposure, and behavior change. Connect refresh and rescreening to events instead of relying only on a calendar.

Auto-declining every name match

Common names and incomplete data produce candidates. Resolve identity with available attributes and route uncertainty according to legal and risk requirements.

Using one risk score without reasons

An opaque number cannot show which evidence is missing or which control should follow. Preserve factor-level explanation and policy version.

Monitoring without customer context

Static transaction thresholds generate noise when expected activity, customer type, product, and history are unavailable. Feed the KYC record into monitoring.

Blanket de-risking

Rejecting entire categories may exclude legitimate customers without addressing specific risk. Apply proportionate measures and document the actual risk and mitigation.

Letting technology file the conclusion

Tools generate evidence, matches, and alerts. Authorized people and governed processes own suspicion, reporting, restriction, and customer decisions.

An operating-model checklist

Before launch or material change, confirm that:

  • enterprise, product, geography, customer, and channel risks are documented;
  • customer and beneficial-owner evidence is collected and verified proportionately;
  • purpose and expected activity become usable monitoring context;
  • screening sources, thresholds, aliases, and ownership logic match obligations;
  • potential matches, alerts, cases, decisions, and reports remain distinct states;
  • enhanced and simplified measures have defined triggers and limits;
  • transaction scenarios are versioned, validated, and connected to customer risk;
  • refresh, rescreening, investigation, and reporting have owners and service levels;
  • decisions, overrides, evidence, and policy versions are auditable;
  • privacy, access, retention, confidentiality, and redress are built into operations.

Using Didit across AML and KYC

Didit lets teams combine ID Verification, AML Screening, Transaction Monitoring, and conditional controls through the Workflow Orchestrator. Published rates include $0.20 per AML screening, $0.07 per user per year for ongoing AML monitoring, and $0.02 per transaction for Transaction Monitoring.

Current module prices are listed on the pricing page. These checks and alerts support a risk-based program; the organization remains responsible for its policies, match resolution, investigations, regulatory decisions, and records.

Frequently asked questions

What do AML and KYC stand for?

AML means anti-money laundering. KYC means Know Your Customer. KYC establishes the customer identity and risk context used by the broader AML control framework.

Is KYC part of AML?

Yes. KYC and customer due diligence are foundational AML controls, while AML also includes screening, transaction monitoring, investigations, reporting, governance, training, and independent oversight.

What is the difference between CDD and KYC?

KYC is the common customer-focused term. CDD is the structured due-diligence process of identifying and verifying the customer and beneficial owner, understanding the relationship, assessing risk, and conducting ongoing scrutiny.

Is sanctions screening the same as AML?

No. Sanctions screening is one control within a wider compliance framework. AML also covers customer due diligence, other risk screening, transaction monitoring, investigations, reporting, records, and governance.

What is enhanced due diligence?

EDD means additional, risk-responsive measures for higher-risk situations. It can include more evidence, source-of-funds or wealth work, senior approval, or closer monitoring, depending on applicable requirements.

Does a PEP match mean the customer is a criminal?

No. PEP status is a risk factor requiring preventive measures under applicable rules. It is not a finding of criminal conduct and should not automatically become a universal decline.

How often should customers be rescreened?

There is no universal frequency. Use applicable requirements and a documented risk approach, with event-driven rescreening when lists, ownership, identity data, customer risk, or other material facts change.

Primary references

AML and KYC work when identity, risk, behavior, and investigation remain connected over time. Establish the customer with reliable evidence, apply proportionate controls, monitor what changes, investigate alerts with context, and preserve why every material decision was made.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page
AML Compliance: KYC, CDD, Screening, and Monitoring