Blog · Automation
KYC: definition, obligations, and practical verification

On this page
KYC (Know Your Customer) refers to the identity and status verification of clients, mandated by the AML-CFT framework. Who is affected, which documents to collect, how often to update files: a comprehensive overview.
KYC stands for “Know Your Customer.” The term refers to all the checks that a regulated professional must perform on their clients: verifying their identity, understanding their situation, and assessing the risk they pose. These checks take place before the business relationship begins and continue throughout its duration.
KYC is not an optional best practice. It is a legal obligation arising from the anti-money laundering and counter-terrorism financing (LCB-FT) framework, codified in Articles L561-1 and following of the French Monetary and Financial Code.
Who is subject to KYC?
All professions regulated under AML-CFT: banks, payment institutions, insurance companies and brokers, wealth managers, financial investment advisors, digital asset service providers, as well as notaries, accountants, real estate agents, and gambling professionals. The full list is set out in Article L561-2 of the French Monetary and Financial Code, and we detail it in our article on AML-CFT obligations.
In practice, if your business requires you to identify your clients before working with them, you are conducting KYC, whether the term is used internally or not.
Which documents should be collected?
For an individual
The foundation is a valid official ID document, of which the professional keeps a copy. Depending on the risk level and the nature of the relationship, additional supporting documents may be required: proof of address, professional status, income, and source of funds.
For a legal entity
A standard file includes a recent registration extract (Kbis or equivalent), up-to-date articles of association, the identity of the legal representative, and the powers they hold. Additional elements are needed to understand the company’s actual activity: nature of the business, geographic area, and turnover.
Beneficial owners
For any legal entity, beneficial owners must be identified: the natural persons who directly or indirectly hold more than 25% of the capital or voting rights, or who exercise control over the company. This identification relies on the client’s declarations and is cross-checked with the beneficial ownership register.
When to verify, and how often to update?
Verification first takes place at the start of the business relationship. The file must be complete before the relationship can begin in earnest.
It then continues throughout the relationship. The French Monetary and Financial Code requires ongoing vigilance: file elements must remain up to date and consistent with observed transactions. The update frequency depends on the establishment’s risk classification. In practice, a low-risk client may be reviewed every three to five years, a high-risk client annually, or even more frequently.
This update cycle is the most operationally demanding: following up with clients, collecting renewal documents, verifying completeness, and logging each check.
How a KYC verification is conducted
A well-executed verification follows four steps.
1. Collection: the client submits their documents, with follow-ups until the file is complete.
2. Verification: documents are read and checked. Validity, consistency between documents, and alignment with declared information are verified.
3. Screening: the client and their beneficial owners are cross-checked against sanctions and asset-freeze lists, and the professional verifies whether they are a politically exposed person (PEP), which triggers additional due diligence measures.
4. Decision: based on the file, the professional either accepts the business relationship, rejects it, or accepts it with specific due diligence measures. The responsibility for this decision remains with the regulated professional, regardless of the tools used.
Record-keeping and traceability
Documents and information relating to client identity must be retained for five years after the end of the business relationship. Those relating to transactions must be kept for five years from their execution. In the event of an inspection by the ACPR or the AMF, the institution must be able to demonstrate who verified what, when, and on which document. The audit trail is as critical as the file itself.
Automate preparation, retain decision-making
Much of KYC work is repetitive: collecting documents, sending reminders, extracting information from files, checking completeness, and keeping the register up to date. This part can be automated effectively, delivering measurable time savings. The decision to enter into a business relationship and the due diligence measures, however, remain the responsibility of your teams.
This is the approach we apply in our KYC and AML-CFT automation projects: workflows that prepare complete and traceable files, with compliance teams making the final call. For a concrete example applied to platforms, see also our article on KYC for marketplaces.
What is the difference between KYC and AML-CFT?
AML-CFT is the overarching framework: risk classification, due diligence, Tracfin reporting, and internal controls. KYC is one component of it: customer identification and verification. Conducting KYC alone is not sufficient for AML-CFT compliance, but there can be no AML-CFT compliance without robust KYC.
How long must KYC documents be retained?
Five years after the end of the business relationship for identity and customer knowledge documents, and five years after execution for transaction-related documents.
Is KYC mandatory for a fintech?
Yes, provided the fintech operates in a regulated activity: payment institution, electronic money institution, digital asset service provider, among others. The obligations are determined by the status, not the company size.
Can KYC be outsourced or automated?
Execution can be: document collection, reminders, data extraction, and screening may be entrusted to tools or service providers. Responsibility cannot: it remains fully with the regulated professional, who must retain control and traceability of the process.
Related articles
Aug 11, 2026
DORA Regulation: Who is affected and what are the obligations
The European DORA regulation has applied since January 2025 to financial entities. IT risk management, incidents, resilience testing, provider oversight: what it mandates, and how it changes your contracts.
Aug 11, 2026
AML-CFT: obligations, regulated entities and required framework
AML-CFT imposes a comprehensive framework on banks, insurers, brokers, financial advisors, and many other professions: risk classification, customer due diligence, Tracfin reports, and internal controls. An overview of the obligations.
Jun 11, 2026
n8n vs Make vs Zapier: which tool to automate your processes?
Zapier for quick starts, Make for complex visual scenarios, n8n for sovereignty and control. An honest comparison to help you choose.