KYC Checklist: Documents and Steps for Customer Onboarding
A KYC checklist turns customer due diligence requirements into a sequence a team can follow — and an examiner can test. This checklist covers individual and business customers, the documents commonly accepted, and the points where standard KYC becomes enhanced due diligence.
KYC requirements are written as principles — identify, verify, understand, monitor. Onboarding teams need them as steps. A checklist closes that gap and gives every case the same minimum standard, which is exactly what examiners test when they sample files.
Use the checklist below as a starting point and adapt it to your regulator's rules and your own risk assessment. For the programme-level controls that sit around it, see our AML compliance checklist.
KYC Checklist for Individual Customers
| Step | What to do | Evidence |
|---|---|---|
| 1. Identify | Collect full legal name, date of birth, nationality, residential address and an identification number | Application data captured in the onboarding record |
| 2. Verify identity | Confirm the identity against an independent, reliable source | Passport, national ID card or driving licence; or electronic (database) verification |
| 3. Confirm the person | For remote onboarding, link the identity to the applicant | Selfie with liveness detection matched to the ID photo, or video verification |
| 4. Verify address | Where your rules require it, confirm the residential address | Recent utility bill, bank statement or government letter; or electronic verification |
| 5. Screen | Check against sanctions lists, PEP lists and adverse media | Screening results and the disposition of any match |
| 6. Understand the relationship | Record the purpose and intended nature of the relationship, occupation and expected activity | Customer declarations captured in the file |
| 7. Risk-rate | Assign a risk rating using your documented methodology | Risk score and the factors behind it |
| 8. Enhanced due diligence | For high-risk customers and PEPs: source of funds and wealth, senior management approval | EDD documentation and approval record |
| 9. Keep records | Retain identification data and records | At least five years after the relationship ends (FATF minimum; local rules may be longer) |
| 10. Monitor | Monitor transactions and refresh KYC periodically and on trigger events | Monitoring alerts and review records |
KYC Documents: What Is Commonly Accepted
| Purpose | Commonly accepted | Alternatives |
|---|---|---|
| Identity | Valid passport; national identity card | Driving licence (where accepted); electronic or database verification; government digital identity such as Singapore's Myinfo |
| Address | Utility bill or bank statement, typically recent (many firms use a three-month window) | Government correspondence; tenancy agreement; electronic address verification |
| Source of funds (EDD) | Payslips, sale contracts, bank statements showing the funds | Inheritance or loan documentation, depending on the source |
| Source of wealth (EDD) | Employment history, business ownership records | Probate records, investment statements, public records |
Documents must be valid on the day they are checked — expired identity documents are one of the most common file-review findings. For how to prove source of funds and source of wealth, see our source of funds vs source of wealth guide.
KYC Checklist for Business Customers (KYB)
For companies, partnerships and other legal entities, the checklist extends to the entity and the people behind it:
- Registration — certificate of incorporation or a current registry extract confirming the entity exists.
- Constitution — articles of association or equivalent, showing the powers that bind the entity.
- Addresses — registered office and, if different, principal place of business.
- Directors and senior management — names, and identity verification for the key individuals.
- Authorised signatories — evidence of authority, such as a board resolution, and identity verification.
- Ownership structure — an ownership chart tracing every layer to natural persons.
- Ultimate beneficial owners — identify and verify each UBO, commonly at a 25% ownership threshold or through control by other means.
- Nature of business — activities, countries of operation and expected transactions.
- Screening — the entity, its UBOs, directors and signatories against sanctions, PEP and adverse media sources.
Our KYB guide covers this process in detail, and the UBO glossary entry works through how to calculate indirect ownership.
When the Checklist Changes: Simplified and Enhanced Due Diligence
A risk-based approach means the checklist flexes with risk.
Simplified due diligence may be permitted for demonstrably low-risk customers, such as listed companies or regulated financial institutions in jurisdictions with equivalent standards — subject to your regulator's rules and a documented risk assessment.
Enhanced due diligence is required for higher-risk situations, including:
- politically exposed persons and their family members and close associates;
- customers connected to high-risk jurisdictions, including those on FATF lists;
- complex or opaque ownership structures;
- activity that is unusual or inconsistent with the customer's profile.
Common KYC Checklist Mistakes
- Expired documents accepted, or documents not checked for validity on the day.
- Proof of address outside the accepted window — an old statement treated as current.
- Screening once, at onboarding only, with no rescreening when lists change.
- No recorded purpose of the relationship, leaving monitoring with no baseline to compare against.
- Undocumented risk ratings — a score with no record of the factors that produced it.
- Ownership collected but not verified for business customers.
- No refresh — KYC files that are never updated after onboarding.
Most of these are workflow failures, not knowledge failures — which is why automated KYC workflows that enforce each step tend to fix them more reliably than training alone.
Frequently Asked Questions
What documents are needed for KYC?
Typically a government-issued photo identity document such as a passport or national ID card, and — where required — proof of address such as a recent utility bill or bank statement. Many regulators also accept reliable electronic verification instead of documents.
What is a KYC checklist?
A KYC checklist is the step-by-step list of information to collect and checks to perform before onboarding a customer: identification, verification, screening, understanding the relationship, risk rating, enhanced due diligence where needed, record keeping and ongoing monitoring.
How long must KYC records be kept?
FATF sets a minimum of five years after the business relationship ends or the occasional transaction is completed. Some jurisdictions require longer.
What is the difference between a KYC and a KYB checklist?
A KYC checklist covers individual customers. A KYB checklist covers business customers and adds proof of registration, constitutional documents, directors, signatories, the ownership structure and the verification of ultimate beneficial owners.
Is proof of address always required for KYC?
Not everywhere. Requirements depend on the regulator and the firm's risk-based policy; many regimes accept electronic verification of the address or do not require separate address evidence for lower-risk customers.
Sources
- FATF — The FATF Recommendations (Recommendations 10 and 11: customer due diligence and record keeping)
- MAS — Circular on non-face-to-face customer due diligence measures
This article is general information, not legal advice. Requirements change — check the current text with the regulator before relying on it.
Turn Your KYC Checklist Into an Automated Workflow
One Constellation enforces every step of your KYC policy — identity, screening, risk rating and EDD — with a complete audit trail for each customer file.
