AML and KYC are used interchangeably all the time — but they aren’t the same thing. KYC is one part of a wider AML programme, and confusing them is a common compliance mistake.
Quick answer
KYC (Know Your Customer) is the process of verifying who a customer is at the start of a relationship. AML (Anti-Money Laundering) is the wider framework of laws, policies and controls designed to stop criminal money entering the financial system. Put simply: KYC is the door; AML is everything inside the building. KYC is one pillar of an AML programme — not a synonym for it.[1]
What is KYC?
Know Your Customer is the identity-verification layer at the front of the customer relationship. It confirms that a person is who they claim to be, that they aren’t on a sanctions or PEP list, and that their stated reason for using a service is plausible. Under the FATF’s Recommendation 10 and most national rules, KYC is described as part of customer due diligence (CDD), with enhanced due diligence layered on top for higher-risk profiles.[1]
What is AML?
Anti-Money Laundering refers to the whole framework of laws, regulations and internal controls that regulated businesses must follow to detect and prevent money laundering and terrorist financing — from the EU’s Anti-Money Laundering Directives to the UK’s Money Laundering Regulations 2017. KYC sits inside it as one component; treating the two as identical leaves the rest of the programme under-resourced.[2]
AML vs KYC at a glance
| KYC | AML | |
|---|---|---|
| Scope | Verifying customer identity & risk | The whole framework to prevent money laundering |
| Timing | Primarily at onboarding (plus re-verification) | Across the entire customer lifecycle |
| Includes | Identity checks, screening, risk-tiering | KYC/CDD, monitoring, reporting, governance, training |
| Relationship | One pillar of AML | Contains KYC as a component |
Where does CDD fit in?
Customer due diligence (CDD) is the risk-based process of understanding a customer and the purpose of the relationship. KYC is the identity part of CDD; CDD adds beneficial-ownership checks, a risk assessment and ongoing monitoring. For higher-risk customers — such as politically exposed persons (PEPs) — enhanced due diligence (EDD) applies, with deeper investigation and senior oversight.[3]
Add expert quote before publishing
“Firms get into trouble when they treat identity verification as the whole job. Verifying who someone is at the front door is essential — but AML is what you do across the whole relationship, and regulators judge you on the whole programme.”
— Suggested placeholder for a quote from Osman Ismail (founder input, OnBoardNow / DPS Software). Replace with a real, approved quote, or remove.
The five pillars of AML
Under the US Bank Secrecy Act framework, an AML programme is built on five pillars — a useful structure internationally:[4]
- A designated compliance officer to oversee the programme.
- Internal policies, procedures and controls.
- Ongoing training for staff.
- Independent testing / audit of the programme.
- Customer due diligence (including beneficial-ownership requirements).
The five stages of KYC / the AML lifecycle
A simplified AML lifecycle — into which KYC feeds directly — typically follows five stages:[5]
- Risk assessment — understanding the risk of customer types, jurisdictions and products.
- KYC / CDD — collecting and verifying identity, ownership and risk profile.
- Screening — applying PEP, sanctions and adverse-media checks.
- Ongoing monitoring — continuously reviewing transactions and behaviour.
- Reporting — filing Suspicious Activity Reports (SARs) and meeting regulatory obligations.
Key takeaway
Without accurate KYC data, the downstream AML steps — screening, monitoring and reporting — can’t function properly. Good KYC is what makes the rest of the AML programme work.
KYC and AML in one onboarding flow
OnBoardNow handles identity verification, CDD, and PEP and sanctions screening in a single client-onboarding flow — feeding accurate KYC data into the rest of your AML programme, with a full audit trail.Book a demo →
Frequently asked questions
What is the difference between KYC and AML?
KYC verifies customer identity at onboarding; AML is the wider framework — risk assessment, screening, monitoring and reporting — that prevents money laundering. KYC is one part of AML.
What are the 5 pillars of AML?
A compliance officer, internal policies and controls, ongoing training, independent testing, and customer due diligence (including beneficial ownership).
What are the 5 stages of KYC?
In the AML lifecycle: risk assessment, KYC/CDD, screening, ongoing monitoring, and reporting.
What is the difference between AML, KYC and CDD?
AML is the overall framework. CDD is the risk-based process of understanding a customer. KYC is the identity-verification part of CDD.

Leave a Reply