AML Compliance: KYC, CDD, Screening, and Monitoring
An AML operations guide to customer due diligence, beneficial ownership, KYC inputs, screening, risk rating, enhanced checks, transaction monitoring, investigations, and governance.

AML and KYC are connected but not interchangeable. KYC, or Know Your Customer, establishes and maintains an understanding of who a customer is and the risk of the relationship. AML, or anti-money laundering, is the broader framework for preventing, detecting, investigating, and reporting suspected money laundering and related financial crime.
KYC supplies identity, ownership, purpose, and initial risk context. AML controls use that context for sanctions and politically exposed person screening, ongoing customer review, transaction monitoring, alert investigation, reporting, records, training, and governance. A document check may support KYC, but neither KYC nor AML is complete when the document passes.
This guide is the AML-compliance companion to the broader KYC lifecycle guide. It does not repeat how to run identity proofing or a general KYC program. It starts where identity, ownership, and customer context become inputs to screening, monitoring, investigation, reporting, and governance.
Key takeaways
- KYC is a component of AML. It identifies and assesses the customer; AML also governs continuing activity, investigations, reporting, and program oversight.
- CDD is risk-based and ongoing. Customer due diligence covers identity, beneficial ownership, purpose, risk, and continuing scrutiny—not only account opening.
- Screening and transaction monitoring answer different questions. Screening compares people or entities with external risk data; transaction monitoring evaluates behavior and activity.
- A potential match is not a confirmed match. Names collide, sources change, and context matters; review and documented resolution are part of the control.
- Technology does not own accountability. Providers can collect evidence, score matches, and generate alerts, while the obliged organization remains responsible for policy, decisions, records, and regulatory reporting.
What is the difference between AML and KYC?
KYC focuses on the customer relationship. It asks:
- Who is the customer?
- Who owns or controls a business customer?
- Why is the relationship being established?
- What activity is expected?
- What customer risk is present?
- When must the record be refreshed?
AML covers the wider control system. It asks those KYC questions and also:
- Is the customer or related party exposed to sanctions, political influence, or other relevant risk?
- Does actual activity fit the customer profile?
- Which alerts require investigation?
- When should activity be restricted or reported?
- Are records, governance, training, and independent oversight adequate?
The FATF Recommendations, as amended June 2026, are the international standard. Recommendation 10 establishes customer due diligence, while related recommendations address recordkeeping, politically exposed persons, correspondent relationships, new technologies, and suspicious-transaction reporting. Jurisdictions implement these standards differently, so a global framework still needs country- and sector-specific legal analysis.
KYC, CDD, EDD, screening, and monitoring compared
| Control | Purpose | Typical trigger | Main output |
|---|---|---|---|
| KYC | Know and risk-assess the customer | Onboarding and material change | Customer identity and risk record |
| CDD | Apply customer due diligence | Relationship, qualifying transaction, suspicion, or doubt | Identity, beneficial owner, purpose, risk, ongoing plan |
| EDD | Apply enhanced due diligence | Higher-risk customer, product, geography, ownership, or behavior | Additional evidence, approvals, source analysis, closer monitoring |
| Sanctions screening | Identify possible targeted-financial-sanctions exposure | Onboarding, payment, data change, list update | Candidate or resolved match |
| PEP screening | Identify politically exposed persons and related risk | Onboarding and rescreening | PEP relationship and required enhanced measures |
| Ongoing screening | Detect changes in customer external-risk data | Source update or scheduled rescreen | New or changed candidate match |
| Transaction monitoring | Identify activity inconsistent with profile or typology | Transaction or aggregated behavior | Alert with evidence and rule/model context |
| Investigation and reporting | Resolve alerts and meet reporting duties | Escalated suspicion | Case decision, restriction, report, or closure rationale |
CDD is the bridge. It creates the customer context that makes later signals interpretable. A large transfer can be expected for one business and highly unusual for another. Without purpose, ownership, expected activity, and risk, monitoring becomes a collection of decontextualized thresholds.
The AML and KYC lifecycle
1. Assess enterprise and product risk
Before rating individual customers, understand the exposure created by products, delivery channels, geographies, customer types, transaction features, and operating model. The FATF risk-based approach guidance describes proportionality as central: identify and understand risk, then apply measures that match it.
This assessment should influence the information collected, screening scope, workflow branches, approval authority, transaction rules, review cadence, and monitoring intensity.
2. Identify the customer and beneficial owner
Collect the information necessary to identify a natural person or legal entity. For a business, identify the natural persons who ultimately own or control it, understand the ownership and control structure, and verify the relevant people according to the applicable requirement and risk.
Entity registration alone is not enough. A genuine company can be controlled by a hidden or prohibited person, while a complex structure may be legitimate but require more evidence to understand.
3. Verify identity using reliable evidence
Validate documents, data, digital credentials, authoritative sources, or permitted combinations. Link the applicant or representative to the claimed identity. Keep evidence authenticity, holder linkage, and customer eligibility as distinct decisions.
FATF’s digital identity guidance asks regulated entities to understand a digital identity system’s assurance and determine whether it is sufficiently reliable and independent for the risk. A technology label does not transfer responsibility.
4. Understand purpose and expected activity
Record why the customer wants the product, how it will be used, expected transaction patterns, source and destination context where relevant, and the nature of the business. Collect proportionate evidence rather than a generic questionnaire whose answers never influence policy.
Expected activity should become usable monitoring context. If onboarding data is stored as free text that the monitoring system cannot access, the lifecycle is disconnected.
5. Screen relevant people and entities
Screen the customer, beneficial owners, controllers, representatives, and other required parties against relevant sources. Depending on law and policy, this can include sanctions, politically exposed persons, relatives and close associates, adverse media, or other lists.
A match engine should preserve the source, list entry, matching fields, transliteration, aliases, date, threshold, and reason. Reviewers need enough evidence to decide whether the customer and listed subject are the same.
6. Assign customer risk
Combine customer, product, geography, channel, ownership, screening, and other relevant factors under a documented methodology. The result should be explainable: which factors mattered, what data supported them, and which controls follow.
Avoid using nationality or geography as a substitute for full analysis. Risk indicators can justify more scrutiny without proving wrongdoing. The February 2025 FATF amendments increased the focus on proportionality and simplified measures in lower-risk situations rather than indiscriminate exclusion.
7. Apply enhanced or simplified measures where justified
Higher risk may require more evidence, source-of-funds or source-of-wealth work, senior approval, closer monitoring, or other enhanced measures. Lower risk may permit simplified measures where law and policy allow, but not when suspicion or a specific higher-risk condition exists.
EDD is not “collect every possible document.” Each additional step should respond to an identified risk and have a decision rule.
8. Decide and preserve the audit record
Approve, decline, restrict, or route the relationship with a recorded rationale. Preserve the policy and risk-model version, evidence, screening results, reviewer actions, approval authority, timestamps, and reasons required for audit and later review.
If the organization cannot complete required due diligence, the response depends on applicable law and circumstances. It may need to avoid or terminate the relationship and consider reporting, while avoiding improper disclosure to the customer.
9. Monitor activity and customer changes
Ongoing due diligence tests whether transactions remain consistent with the organization’s knowledge of the customer, business, risk, and expected activity. FATF’s banking guidance describes monitoring as both transaction scrutiny and identifying changes to the customer profile that may require new or additional CDD.
Monitoring can be real-time, periodic, event-driven, or a combination. Higher-risk relationships generally justify greater depth or frequency; lower-risk relationships may justify proportionate controls.
10. Investigate, report, and learn
An alert is a prompt for analysis, not a conclusion. Investigators collect related transactions, customer history, external information, prior alerts, linked accounts, and explanations. The organization then documents why the case was closed, escalated, restricted, or reported.
Reporting decisions belong to the obliged organization and its authorized people. Provider alert labels should not automatically file a report or disclose suspicion to the customer.
AML screening explained
Sanctions screening
Sanctions controls seek possible matches to designated people, entities, vessels, or other subjects under applicable regimes. Lists, ownership rules, and prohibitions differ. A simple exact-name comparison cannot address aliases, transliteration, dates, geography, identifiers, and ownership or control.
PEP screening
A politically exposed person is not necessarily involved in crime. The FATF PEP guidance describes PEP measures as preventive and risk-based. A PEP result should trigger the required assessment and measures, not an automatic accusation or universal decline.
Adverse media and other sources
Adverse information can contribute to a risk assessment when the source, relevance, subject linkage, date, severity, and reliability are understood. Search results and allegations are not court findings. Reviewers need provenance and a documented way to weigh conflicting evidence.
Ongoing rescreening
Customer data and external sources change. Rescreening can be triggered by source updates, customer changes, review schedules, or events. The system should identify what changed instead of forcing analysts to repeat every prior resolution.
Transaction monitoring explained
Transaction monitoring compares current activity with rules, models, typologies, customer context, peer behavior, and historical patterns. Useful signal families can include:
- value, frequency, velocity, and structuring patterns;
- changes from expected customer activity;
- unusual counterparties, corridors, assets, or timing;
- movement through linked accounts or wallets;
- rapid in-and-out movement or circular flows;
- activity following a customer, device, ownership, or risk change.
No rule is suspicious in every context. A threshold creates an alert; investigation determines whether the facts support a concern. Monitoring design should state the scenario, data dependencies, time window, threshold, segmentation, expected false positives, disposition path, and owner.
The EU AML Regulation 2024/1624, which generally applies from 10 July 2027, requires ongoing monitoring and a risk-based intensity. Its rules illustrate why customer due diligence, transaction context, records, and reporting belong in one system even when different components perform each task.
Potential match, alert, case, and report
| Stage | Meaning | What should happen next |
|---|---|---|
| Potential match | Data resembles an external source subject | Compare identifiers and context |
| Alert | A screening or monitoring condition fired | Triage evidence under documented priority |
| Case | Related evidence is assembled for investigation | Investigate, document, escalate, or close |
| Suspicion decision | Authorized analysis finds or rejects reasonable concern | Apply policy and legal duties |
| Regulatory report | Required information is submitted to the competent body | Protect confidentiality and preserve records |
Collapsing these stages creates two opposite failures: every alert becomes an accusation, or alerts are closed without enough evidence. Clear states, roles, and reasons make quality measurable.
How to evaluate AML and KYC controls
Source coverage and provenance
Ask which sanctions regimes, PEP categories, ownership data, adverse information, and transaction fields are covered. Review source authority, update cadence, effective dates, correction handling, and historical reconstruction. A total list count does not show relevance to your obligations.
Matching and threshold controls
Test aliases, transliteration, reordered names, dates, identifiers, entities, common names, and missing fields. Review results at the proposed threshold, not only a vendor-selected accuracy headline. Measure candidate volume, true resolutions, false positives, and missed known cases.
Customer-risk methodology
Every risk score should map to evidence, factor weighting, policy consequences, overrides, and review. Validate that low risk actually receives proportionate measures and higher risk triggers bounded enhanced controls.
Monitoring design
Inventory scenarios and models, their data inputs, segmentation, thresholds, owners, versions, validation, alert routing, and retirement criteria. Confirm that onboarding data and customer changes reach monitoring in time.
Investigation operations
Inspect queues, priorities, evidence timelines, related entities, notes, approvals, segregation of duties, service levels, and disposition codes. Reviewers should be able to explain why a case was opened and closed.
Governance and testing
Assign owners for policy, data, models, lists, investigations, reporting, quality assurance, training, audit, and change control. Test end-to-end from customer creation through a simulated alert, case, decision, and record export.
Common AML and KYC mistakes
Treating KYC as a one-time gate
Identity, ownership, sanctions exposure, and behavior change. Connect refresh and rescreening to events instead of relying only on a calendar.
Auto-declining every name match
Common names and incomplete data produce candidates. Resolve identity with available attributes and route uncertainty according to legal and risk requirements.
Using one risk score without reasons
An opaque number cannot show which evidence is missing or which control should follow. Preserve factor-level explanation and policy version.
Monitoring without customer context
Static transaction thresholds generate noise when expected activity, customer type, product, and history are unavailable. Feed the KYC record into monitoring.
Blanket de-risking
Rejecting entire categories may exclude legitimate customers without addressing specific risk. Apply proportionate measures and document the actual risk and mitigation.
Letting technology file the conclusion
Tools generate evidence, matches, and alerts. Authorized people and governed processes own suspicion, reporting, restriction, and customer decisions.
An operating-model checklist
Before launch or material change, confirm that:
- enterprise, product, geography, customer, and channel risks are documented;
- customer and beneficial-owner evidence is collected and verified proportionately;
- purpose and expected activity become usable monitoring context;
- screening sources, thresholds, aliases, and ownership logic match obligations;
- potential matches, alerts, cases, decisions, and reports remain distinct states;
- enhanced and simplified measures have defined triggers and limits;
- transaction scenarios are versioned, validated, and connected to customer risk;
- refresh, rescreening, investigation, and reporting have owners and service levels;
- decisions, overrides, evidence, and policy versions are auditable;
- privacy, access, retention, confidentiality, and redress are built into operations.
Using Didit across AML and KYC
Didit lets teams combine ID Verification, AML Screening, Transaction Monitoring, and conditional controls through the Workflow Orchestrator. Published rates include $0.20 per AML screening, $0.07 per user per year for ongoing AML monitoring, and $0.02 per transaction for Transaction Monitoring.
Current module prices are listed on the pricing page. These checks and alerts support a risk-based program; the organization remains responsible for its policies, match resolution, investigations, regulatory decisions, and records.
Frequently asked questions
What do AML and KYC stand for?
AML means anti-money laundering. KYC means Know Your Customer. KYC establishes the customer identity and risk context used by the broader AML control framework.
Is KYC part of AML?
Yes. KYC and customer due diligence are foundational AML controls, while AML also includes screening, transaction monitoring, investigations, reporting, governance, training, and independent oversight.
What is the difference between CDD and KYC?
KYC is the common customer-focused term. CDD is the structured due-diligence process of identifying and verifying the customer and beneficial owner, understanding the relationship, assessing risk, and conducting ongoing scrutiny.
Is sanctions screening the same as AML?
No. Sanctions screening is one control within a wider compliance framework. AML also covers customer due diligence, other risk screening, transaction monitoring, investigations, reporting, records, and governance.
What is enhanced due diligence?
EDD means additional, risk-responsive measures for higher-risk situations. It can include more evidence, source-of-funds or wealth work, senior approval, or closer monitoring, depending on applicable requirements.
Does a PEP match mean the customer is a criminal?
No. PEP status is a risk factor requiring preventive measures under applicable rules. It is not a finding of criminal conduct and should not automatically become a universal decline.
How often should customers be rescreened?
There is no universal frequency. Use applicable requirements and a documented risk approach, with event-driven rescreening when lists, ownership, identity data, customer risk, or other material facts change.
Primary references
- FATF Recommendations, as amended June 2026
- FATF Guidance on Digital Identity
- FATF Risk-Based Approach Guidance for the Banking Sector
- FATF Guidance on Politically Exposed Persons
- Regulation (EU) 2024/1624
AML and KYC work when identity, risk, behavior, and investigation remain connected over time. Establish the customer with reliable evidence, apply proportionate controls, monitor what changes, investigate alerts with context, and preserve why every material decision was made.
Related articles
- Flutter SDK: Add Identity Verification to Your App
- W3C Decentralized Identifiers (DIDs) Specification
- Adverse Media Screening: Process, Tuning, and Risks
- KYC Software: Buyer's Guide and Evaluation Criteria
- FIDO2 Explained: WebAuthn, Passkeys, and Security
- ID Verification API: Integration and Evaluation Guide