KYC Requirements in the UK: A Compliance Guide for Banks and Fintechs
KYC requirements in the UK are the customer due diligence and verification obligations that regulated firms must meet under the Money Laundering Regulations 2017 and Financial Conduct Authority (FCA) rules. What does that mean day to day? You identify and verify every customer, apply a risk-based approach, monitor activity on an ongoing basis, and keep records for at least five years. Banks, payment firms, e-money institutions, and cryptoasset businesses all fall within scope. Each must report suspicious activity to the National Crime Agency (NCA).
For compliance and onboarding teams, the question is rarely whether KYC applies. The real question is how to run it across an entire customer base without slowing legitimate business. This guide walks through the regulatory framework, the specific checks UK firms must run, the documentation you need to collect, and how KYC obligations sit inside the wider AML regime.
The Regulatory Framework Behind KYC Requirements in the UK
A handful of authorities and rules underpin KYC in the UK, and compliance teams should know each one by name. The framework starts with standards set by the Financial Action Task Force (FATF), which the UK then wrote into domestic law.
At the core sits the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, usually shortened to the MLR 2017. They set out customer due diligence, enhanced due diligence, record-keeping, and reporting duties for regulated firms. The Financial Conduct Authority (FCA) supervises most financial services firms for AML compliance and can impose penalties when controls fail. Then there is the Prudential Regulation Authority (PRA), part of the Bank of England, which supervises the safety and soundness of banks, building societies, and insurers; its expectations intersect with financial crime controls. HM Revenue and Customs (HMRC) supervises certain sectors such as money service businesses for AML purposes. The National Crime Agency (NCA) receives Suspicious Activity Reports and runs the Financial Intelligence Unit.
KYC Requirements for Banks in the UK
Banks carry the most demanding KYC requirements in the UK. High transaction volume and heavy exposure to financial crime are the reasons. Under the MLR 2017 and FCA supervision, a bank must verify the identity of every customer before opening an account, build a risk profile, and keep that profile current for the life of the relationship.
For retail and corporate customers alike, that means collecting and verifying identity data, screening against sanctions and politically exposed persons lists, and establishing the source of funds where risk warrants it. Corporate clients add another layer. Banks must identify beneficial owners and understand ownership structures, which is where know-your-business checks sit on top of individual KYC. Ongoing transaction monitoring is mandatory, not optional. Customer information also has to be refreshed at intervals proportionate to risk. Failures carry real consequence: the FCA has fined UK banks heavily for weak customer due diligence and monitoring controls.
KYC Hub's global KYC solution gives banks identity verification, ID verification, liveness checks, and document authentication in one workflow. Phone verification and digital signature come built in, so onboarding stays fast without weakening controls. Get a free demo.
KYC Checks UK Firms Must Run
The MLR 2017 frames KYC as a set of obligations, not a single step. Regulated firms must apply each of the following.
Customer Due Diligence (CDD). Identify the customer and verify that identity using reliable, independent sources before establishing a business relationship or carrying out an occasional transaction above the regulatory threshold. That covers legal name, date of birth, and address. For entities, it adds verification of beneficial ownership.
Risk-based approach. How much scrutiny a customer gets should track the risk they present. Lower-risk relationships may qualify for simplified due diligence; higher-risk ones trigger enhanced measures. Document the risk assessment that drives these calls.
Enhanced Due Diligence (EDD) applies to higher-risk customers, including politically exposed persons and those tied to high-risk third countries. Expect deeper checks, more source-of-funds evidence, and closer ongoing scrutiny.
Ongoing monitoring. Watch transactions and customer behavior for activity that does not fit the expected profile. Customer information stays current throughout the relationship.
Know or suspect money laundering or terrorist financing? Suspicious Activity Reporting kicks in: the firm must submit a Suspicious Activity Report to the National Crime Agency.
These checks sit within the broader AML compliance framework that UK regulated firms operate under. They work best when they reinforce one another rather than running as isolated steps.
KYC Documentation Requirements for B2B Onboarding
Documentation requirements vary by institution and by customer risk. Still, UK firms generally collect proof of identity and proof of address, plus evidence of structure and control for corporate customers. The list below reflects common acceptable evidence.
Proof of identity is a valid passport, UK or EU driving licence, national identity card, or residence permit.
Proof of address. A utility bill, bank statement, or council tax bill dated within the last three months works. So does a current tenancy agreement or mortgage statement.
For corporate and business accounts, expect a certificate of incorporation, register of directors and beneficial owners, and confirmation of ownership against Companies House records. Layered ownership structures need more digging. Resolve ultimate beneficial ownership rather than stopping at the immediate holding entity.
In digital onboarding, identity documents are increasingly verified through automated document authentication and a liveness check. That check confirms the applicant is a real, present person, not a photograph or deepfake. Here electronic identity verification replaces manual document review and removes the slowest part of onboarding.
How AML and KYC Requirements Fit Together in the UK
KYC is just one piece of a wider anti-money laundering obligation. The MLR 2017 require regulated firms to maintain policies, controls, and procedures across the whole AML lifecycle, and customer verification is the entry point. A firm can verify identity perfectly and still fall short on its AML duties. Skip transaction monitoring, sanctions screening, or suspicion reporting, and the program comes apart.
Record-keeping ties the two together. Firms must retain customer due diligence records and transaction records for at least five years after the business relationship ends or the transaction completes, and supervisors can ask to see them. Staff need training to recognize and escalate suspicious activity. For most UK firms, the practical move is to bring verification, screening, and monitoring under one system rather than stitching together point tools. That thinking is what sits behind perpetual KYC approaches, which keep risk profiles continuously current.
How KYC Hub Supports UK Compliance Teams
Meeting KYC requirements in the UK at scale is as much a tooling problem as a regulatory one. When onboarding drags or monitoring throws off noise, the bottleneck usually traces back to the technology, not the rules.
KYC Hub gives UK banks and fintechs a single platform for the full set of obligations. Identity verification, ID verification, and document authentication confirm who a customer is. Liveness checks and phone verification add assurance for remote onboarding, and digital signature closes out the workflow. Automated screening against sanctions and politically exposed persons lists runs at onboarding and continuously thereafter. Ongoing monitoring flags activity that diverges from the expected profile. Configurable workflows let compliance teams encode their own risk-based rules, and records stay stored and retrievable for audit, which supports the five-year retention requirement.
The result? A control environment that satisfies FCA and MLR 2017 expectations while letting good customers through quickly. Get a free demo.



