← Industry Insights
KYC

KYC Requirements in the UK: A Compliance Guide for Banks and Fintechs

Updated Jun 2026 · 5 min read
SHAREinXf
What are the KYC Requirements in the UK?

KYC requirements in the UK are the customer due diligence and verification obligations that regulated firms must meet under the Money Laundering Regulations 2017 and Financial Conduct Authority (FCA) rules. What does that mean day to day? You identify and verify every customer, apply a risk-based approach, monitor activity on an ongoing basis, and keep records for at least five years. Banks, payment firms, e-money institutions, and cryptoasset businesses all fall within scope. Each must report suspicious activity to the National Crime Agency (NCA).

For compliance and onboarding teams, the question is rarely whether KYC applies. The real question is how to run it across an entire customer base without slowing legitimate business. This guide walks through the regulatory framework, the specific checks UK firms must run, the documentation you need to collect, and how KYC obligations sit inside the wider AML regime.

The Regulatory Framework Behind KYC Requirements in the UK

A handful of authorities and rules underpin KYC in the UK, and compliance teams should know each one by name. The framework starts with standards set by the Financial Action Task Force (FATF), which the UK then wrote into domestic law.

At the core sits the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, usually shortened to the MLR 2017. They set out customer due diligence, enhanced due diligence, record-keeping, and reporting duties for regulated firms. The Financial Conduct Authority (FCA) supervises most financial services firms for AML compliance and can impose penalties when controls fail. Then there is the Prudential Regulation Authority (PRA), part of the Bank of England, which supervises the safety and soundness of banks, building societies, and insurers; its expectations intersect with financial crime controls. HM Revenue and Customs (HMRC) supervises certain sectors such as money service businesses for AML purposes. The National Crime Agency (NCA) receives Suspicious Activity Reports and runs the Financial Intelligence Unit.

KYC Requirements for Banks in the UK

Banks carry the most demanding KYC requirements in the UK. High transaction volume and heavy exposure to financial crime are the reasons. Under the MLR 2017 and FCA supervision, a bank must verify the identity of every customer before opening an account, build a risk profile, and keep that profile current for the life of the relationship.

For retail and corporate customers alike, that means collecting and verifying identity data, screening against sanctions and politically exposed persons lists, and establishing the source of funds where risk warrants it. Corporate clients add another layer. Banks must identify beneficial owners and understand ownership structures, which is where know-your-business checks sit on top of individual KYC. Ongoing transaction monitoring is mandatory, not optional. Customer information also has to be refreshed at intervals proportionate to risk. Failures carry real consequence: the FCA has fined UK banks heavily for weak customer due diligence and monitoring controls.

KYC Hub's global KYC solution gives banks identity verification, ID verification, liveness checks, and document authentication in one workflow. Phone verification and digital signature come built in, so onboarding stays fast without weakening controls. Get a free demo.

KYC Checks UK Firms Must Run

The MLR 2017 frames KYC as a set of obligations, not a single step. Regulated firms must apply each of the following.

Customer Due Diligence (CDD). Identify the customer and verify that identity using reliable, independent sources before establishing a business relationship or carrying out an occasional transaction above the regulatory threshold. That covers legal name, date of birth, and address. For entities, it adds verification of beneficial ownership.

Risk-based approach. How much scrutiny a customer gets should track the risk they present. Lower-risk relationships may qualify for simplified due diligence; higher-risk ones trigger enhanced measures. Document the risk assessment that drives these calls.

Enhanced Due Diligence (EDD) applies to higher-risk customers, including politically exposed persons and those tied to high-risk third countries. Expect deeper checks, more source-of-funds evidence, and closer ongoing scrutiny.

Ongoing monitoring. Watch transactions and customer behavior for activity that does not fit the expected profile. Customer information stays current throughout the relationship.

Know or suspect money laundering or terrorist financing? Suspicious Activity Reporting kicks in: the firm must submit a Suspicious Activity Report to the National Crime Agency.

These checks sit within the broader AML compliance framework that UK regulated firms operate under. They work best when they reinforce one another rather than running as isolated steps.

KYC Documentation Requirements for B2B Onboarding

Documentation requirements vary by institution and by customer risk. Still, UK firms generally collect proof of identity and proof of address, plus evidence of structure and control for corporate customers. The list below reflects common acceptable evidence.

Proof of identity is a valid passport, UK or EU driving licence, national identity card, or residence permit.

Proof of address. A utility bill, bank statement, or council tax bill dated within the last three months works. So does a current tenancy agreement or mortgage statement.

For corporate and business accounts, expect a certificate of incorporation, register of directors and beneficial owners, and confirmation of ownership against Companies House records. Layered ownership structures need more digging. Resolve ultimate beneficial ownership rather than stopping at the immediate holding entity.

In digital onboarding, identity documents are increasingly verified through automated document authentication and a liveness check. That check confirms the applicant is a real, present person, not a photograph or deepfake. Here electronic identity verification replaces manual document review and removes the slowest part of onboarding.

How AML and KYC Requirements Fit Together in the UK

KYC is just one piece of a wider anti-money laundering obligation. The MLR 2017 require regulated firms to maintain policies, controls, and procedures across the whole AML lifecycle, and customer verification is the entry point. A firm can verify identity perfectly and still fall short on its AML duties. Skip transaction monitoring, sanctions screening, or suspicion reporting, and the program comes apart.

Record-keeping ties the two together. Firms must retain customer due diligence records and transaction records for at least five years after the business relationship ends or the transaction completes, and supervisors can ask to see them. Staff need training to recognize and escalate suspicious activity. For most UK firms, the practical move is to bring verification, screening, and monitoring under one system rather than stitching together point tools. That thinking is what sits behind perpetual KYC approaches, which keep risk profiles continuously current.

How KYC Hub Supports UK Compliance Teams

Meeting KYC requirements in the UK at scale is as much a tooling problem as a regulatory one. When onboarding drags or monitoring throws off noise, the bottleneck usually traces back to the technology, not the rules.

KYC Hub gives UK banks and fintechs a single platform for the full set of obligations. Identity verification, ID verification, and document authentication confirm who a customer is. Liveness checks and phone verification add assurance for remote onboarding, and digital signature closes out the workflow. Automated screening against sanctions and politically exposed persons lists runs at onboarding and continuously thereafter. Ongoing monitoring flags activity that diverges from the expected profile. Configurable workflows let compliance teams encode their own risk-based rules, and records stay stored and retrievable for audit, which supports the five-year retention requirement.

The result? A control environment that satisfies FCA and MLR 2017 expectations while letting good customers through quickly. Get a free demo.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

Is KYC a legal requirement in the UK?

Yes. KYC obligations are mandatory for regulated firms under the Money Laundering Regulations 2017, supervised by the FCA and other authorities. Firms that fail to apply adequate customer due diligence can face regulatory penalties and, in serious cases, criminal liability.

Which regulator enforces KYC requirements in the UK?

The Financial Conduct Authority (FCA) is the primary supervisor for most financial services firms, while HMRC supervises certain sectors such as money service businesses. The Prudential Regulation Authority oversees the soundness of banks and insurers, and the National Crime Agency receives Suspicious Activity Reports.

How long must UK firms keep KYC records?

Regulated firms must retain customer due diligence and transaction records for at least five years after the business relationship ends or the relevant transaction is completed. These records must remain accessible for supervisory review during that period.

What is the difference between KYC and AML in the UK?

KYC is the customer identification and verification component, while AML is the broader regime that also includes transaction monitoring, sanctions screening, suspicious activity reporting, and staff training. KYC is the entry point into an AML program, not a substitute for it.

What documents are needed for KYC in the UK?

Firms typically require a government-issued proof of identity such as a passport or driving licence, plus a proof of address such as a recent utility bill or bank statement. Corporate customers must also provide incorporation and ownership evidence verified against Companies House.

[ KYC HUB ]

Automate your compliance operations

Replace manual checks and spreadsheets with automated screening, workflows and audit-ready records.

Explore the compliance automationBook a demo
[ RELATED READING ]
KYC vs eKYC: Which Method Should Your Institution Use in 2026?
[ KYC ]

KYC vs eKYC: Which Method Should Your Institution Use in 2026?

KYC vs eKYC isn't just a compliance choice, it's a cost and risk decision. Learn which method fits your product under RBI's 2025 guidelines.

Mar 2026 · 7 min read
KYC Requirements in Saudi Arabia: A Comprehensive Guide for Financial Institutions
[ KYC ]

KYC Requirements in Saudi Arabia: A Comprehensive Guide for Financial Institutions

Complete guide to KYC requirements in Saudi Arabia. Learn about SAMA regulations, compliance obligations, required documents, and penalties for financial institutions

Jan 2026 · 9 min read
Aadhar Card OCR API for KYC & Document Verification
[ KYC ]

Aadhar Card OCR API for KYC & Document Verification: A Buyer's Guide

An Aadhar card OCR API reads name, DOB, gender, and a masked Aadhaar number straight off the card so your KYC flow skips manual data entry. Here is how it works and how to evaluate one.

Dec 2025 · 10 min read