Subscribe to get high-signal insights on how modern fintech is built.

fintech

KYC Isn't One Check — It's Five

One API call hides five separate compliance obligations, each with its own failure mode.

By Alex Kugell ·

You're building a fintech product. Somewhere in your second or third sprint, someone drops a ticket: "Add KYC." You find an identity verification provider, integrate their SDK, collect a selfie and a government ID, and check the box.

You just completed one of the five checks. The other four are still missing, and any one of them can produce a regulatory enforcement action on its own.

KYC is five distinct obligations stacked on top of each other, each mandated by a different piece of regulation, each with its own data sources, latency constraints, and failure modes. Understanding where one check ends and the next begins is the difference between a compliant onboarding flow and an expensive conversation with a regulator.

Check 1: Customer Identification Program

Section 326 of the Patriot Act requires every financial institution to collect and verify four pieces of information from each customer: full legal name, date of birth, address, and an identification number. For US persons, that identification number is a Social Security number. For non-US persons, it is a passport or government ID number.

"Verify" means more than collecting a form. The institution must confirm the information against documents (a driver's license, a passport) or through non-documentary methods (database checks against credit bureau records, public records). If you're using a KYC provider like Sumsub, Jumio, or Onfido, this is what their SDK handles: document capture, optical character recognition, liveness detection to prove the person holding the ID is the person on the ID.

Think of it like a post office verifying your identity before handing over a certified letter. They need to see your face, see your ID, and confirm the name matches. That part is intuitive. What most engineers miss is that the post office only checks whether you are who you claim to be. It does not check whether you're on a government watchlist, whether you're a foreign official, or whether a newspaper reported you for fraud last month.

CIP answers one question: is this person real, and do they have documents to prove it? The remaining four checks ask whether that real person should be allowed to transact.

Check 2: Sanctions screening

Every transaction you process, every account you open, every relationship you maintain must be screened against government sanctions lists. The primary US list is OFAC's Specially Designated Nationals (SDN) list, which contains over 12,000 entries and is updated multiple times per month, sometimes several times per week.

But OFAC's SDN list is one of many. A compliant screening program also checks the EU Consolidated Sanctions List, the UK's Office of Financial Sanctions Implementation list, the UN Security Council list, and country-specific lists depending on your operating jurisdictions. A global financial institution may screen against 20 or more lists simultaneously.

The engineering constraint is matching. Sanctions lists contain names transliterated from Arabic, Cyrillic, and Mandarin. A single person may appear as "Mohammed," "Muhammad," "Mohamed," or "Mohamad." An entity may be listed under a name that differs by one character from a legitimate customer's name. Fuzzy matching algorithms are required, and fuzzy matching produces false positives.

Industry estimates put the false positive rate for sanctions screening at 90 to 95%. For every genuine match, the system generates 10 to 20 alerts that a compliance analyst must review manually. Each false positive costs time and money. But a false negative, letting a sanctioned person transact, costs a regulatory enforcement action.

TD Bank paid $3.09 billion in 2024 for AML failures that included sanctions screening gaps. Starling Bank was fined £29 million the same year for deficiencies in its sanctions screening program. These are not theoretical penalties.

Sanctions screening must run at onboarding and again at every transaction. A customer who cleared screening yesterday may appear on tomorrow's OFAC update. This is where check 2 bleeds into check 5 (ongoing monitoring), but the initial screen is a distinct gate: no account opens without it.

Check 3: Politically Exposed Persons

A Politically Exposed Person is someone who holds or has held a prominent public function. Heads of state, senior government officials, military officers, judges of supreme courts, senior executives of state-owned enterprises. Their immediate family members and close associates also qualify.

PEPs are not prohibited from opening accounts. They are higher risk. The regulatory requirement is that you identify them and apply enhanced due diligence (EDD), which means deeper investigation into the source of their funds, closer monitoring of their transactions, and senior management approval before establishing the relationship.

The constraint is coverage. There is no single global PEP database. Providers like Dow Jones Risk & Compliance, Refinitiv World-Check, and ComplyAdvantage maintain their own PEP lists, compiled from government records, corporate filings, and media sources across hundreds of jurisdictions. Dow Jones alone tracks roughly 2.4 million PEP-linked records, including relatives and close associates. Each provider has different coverage depth in different regions. A provider strong in European PEP coverage may have gaps in Southeast Asia.

If you integrate one PEP screening provider, you have one provider's view of who qualifies as politically exposed. Whether that view is complete enough depends on where your customers are located.

The consequence of missing a PEP is not that you onboarded a criminal. It is that you failed to apply the right level of scrutiny to a high-risk customer. When a regulator examines your files and finds a senior government official's family member with no EDD flag, the question they ask is why you didn't apply enhanced scrutiny.

Check 4: Adverse media screening

Sanctions lists and PEP databases capture government designations and political positions. They do not capture fraud allegations, money laundering investigations, corruption proceedings, or regulatory actions that haven't resulted in a formal designation.

Adverse media screening fills that gap. It scans news sources, court records, regulatory filings, and other public information for negative coverage of your customer. A customer who is under investigation for financial fraud will not appear on a sanctions list. They may appear in a Financial Times article.

Major screening providers monitor thousands of news sources across dozens of languages. LexisNexis covers over 20,000 sources in more than 100 languages. Dow Jones Factiva indexes 17,000 licensed sources. ComplyAdvantage monitors 11,000 sources across 200 countries. The challenge is signal-to-noise. A name match against a news article about financial crime may be your customer, or it may be someone with the same name in a different country accused of something unrelated.

Adverse media alerts require human judgment. The system can flag that "John Smith" appears in an article about a money laundering investigation. A compliance analyst must determine whether that John Smith is the same John Smith who applied for an account this morning.

Unlike sanctions screening, adverse media does not produce a binary pass/fail. It produces a risk signal that feeds into the customer's overall risk assessment. A single negative article from an unreliable source may not change anything. Multiple articles from credible outlets about financial crime in the customer's industry and geography will trigger enhanced due diligence.

Check 5: Ongoing monitoring

The first four checks happen at onboarding. The fifth never stops.

Ongoing monitoring re-runs sanctions screening, PEP checks, and adverse media screening continuously against your existing customer base. OFAC's list updates arrive without warning. A customer's uncle becomes a cabinet minister. A news story breaks about a fraud ring involving a company your customer owns.

The regulatory expectation is that these changes trigger a compliance response within a reasonable timeframe. If a customer appears on today's OFAC update, the institution must detect it and act. "Act" can mean freezing the account, blocking transactions, filing a Suspicious Activity Report, or escalating to enhanced review.

The engineering design here is different from onboarding screening. At onboarding, you screen one customer against all lists. In ongoing monitoring, you screen all customers against every list update. The direction reverses: instead of running a single name through many databases, you run a database update through your entire customer base.

For a bank with two million customers, a single OFAC update means re-screening two million records. If your screening infrastructure only runs at onboarding, you've built a system that was compliant on day one and degrades every day after.

Ongoing monitoring also includes transaction monitoring: watching for patterns that suggest money laundering, terrorist financing, or sanctions evasion. Structuring (breaking large transactions into smaller ones to avoid reporting thresholds), rapid movement of funds through multiple accounts, transactions with high-risk jurisdictions. Transaction monitoring is its own discipline with different engineering constraints than the screening checks above.

Five checks, five failure modes

Each check can fail independently. You can have perfect identity verification and no sanctions screening. You can screen against OFAC but miss PEP coverage in the jurisdictions where your customers operate. You can run all four onboarding checks and never re-screen an existing customer.

A compliance team evaluating your KYC program looks at each check separately. They want to see documentation for how each one works, what data sources it uses, how false positives are handled, and how the results are stored. "We use [provider name] for KYC" is not an answer to that question.

When someone drops a ticket that says "add KYC," the first question to ask is which of the five checks they mean. The second is what happens when each one returns a result that requires human judgment, because at least three of them will.

Sources

Frequently Asked Questions

What are the five steps of KYC?
Customer Identification Program (CIP) verifying identity documents, sanctions screening against OFAC and global watchlists, Politically Exposed Person (PEP) checks, adverse media screening, and ongoing monitoring that re-runs these checks continuously after onboarding.
How often is the OFAC sanctions list updated?
OFAC updates the Specially Designated Nationals list multiple times per month, sometimes multiple times per week. The list contains over 12,000 entries. A customer who was clean at onboarding can appear on the list tomorrow, which is why ongoing monitoring is a separate obligation from initial screening.
What is the false positive rate for sanctions screening?
Industry estimates put false positive rates for sanctions screening at 90-95%. For every real match, the system generates roughly 10-20 alerts that require human review. Most false positives come from common name collisions across a global customer base.
What happens if a bank skips a KYC check?
BSA/AML enforcement actions regularly produce fines in the hundreds of millions. TD Bank paid $3.09 billion in 2024 for AML failures. Starling Bank was fined £29 million for sanctions screening gaps. These are not edge cases.

Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.

Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.

Keep reading

ai & mlTabular Foundation Models Are Coming for Your Risk TeamNVIDIA's Kumo Tabular compresses months of model-building into one forward pass. The catch is that regulators still want...
analysisThe Card Networks Are Going Back to Co-opsThe two largest card networks chose to co-own their stablecoin instead of controlling it outright.
opinionWhat AFSP v0.1 Won't Let Your Agent DoThe first agent-to-bank protocol requires three minutes of cryptographic handshaking to open a savings account.
View more ›