KYC, KYB and AML are related, but they are not interchangeable. KYC focuses on understanding and verifying an individual customer. KYB applies business-verification steps to an organisation and the people behind it. AML is the wider risk and compliance framework in which KYC, KYB, screening and monitoring may operate.

The distinction matters when you compare providers. A product called a “KYC check” may verify an identity but exclude politically exposed person (PEP) and sanctions screening. A product called an “AML check” may be a point-in-time name screen, not a complete anti-money laundering and counter-terrorism financing program.

Key takeaways

  • KYC asks: Who is this individual, and can their identity be verified?
  • KYB asks: Does this business exist, who represents it, and who ultimately owns or controls it?
  • AML asks: What money laundering and terrorism financing risks exist, and how will they be assessed, controlled and monitored?
  • CDD connects the layers: Initial and ongoing customer due diligence uses KYC or KYB information alongside risk assessment, screening and monitoring.

KYC vs KYB vs AML: the quick comparison

TermPrimary subjectMain questionTypical componentsWhat it does not prove by itself
KYCAn individualIs this customer who they claim to be?Identity data, document checks, consent and sometimes biometricsThat the person is low risk or clear of sanctions and PEP concerns
KYBA company, trust, partnership or other organisationDoes the entity exist, and who owns, controls or represents it?Registry data, entity status, officeholders, authority and ownership informationThat every ownership layer is resolved or every related person is verified
AMLThe customer relationship and its financial-crime riskWhat risks exist, and what controls are appropriate?Risk assessment, PEP and sanctions checks, CDD, monitoring, records and reportingThat one screening result makes the whole organisation compliant

What is KYC?

Know Your Customer (KYC) is the process of collecting and verifying information about a customer. For an individual, this commonly starts with their name, date of birth, address and identity documents. The organisation then uses appropriate evidence to establish that the person is who they claim to be.

Australian identity-verification workflows may use the Document Verification Service (DVS). The Australian Government's IDMatch service explains that DVS compares biographic information on an Australian-issued identity document with the original record and usually returns a yes or no result. DVS does not check a facial image. A separate biometric or face-verification step may be added where it is available, proportionate and supported by the required consent.

That distinction is important: an identity-document match is evidence about the document details. It is not a character assessment, a credit decision, a Nationally Coordinated Criminal History Check, a sanctions clearance or a complete customer-risk decision.

KYC can include

  • Customer identity details
  • Identity-document verification
  • Consent and audit evidence
  • Face matching or liveness when separately included

KYC does not automatically include

  • PEP, sanctions or watchlist screening
  • Source-of-funds or source-of-wealth checks
  • Transaction monitoring
  • A final compliance or onboarding decision

For a detailed identity-only service scope, see the KYC Check Australia page and the guide to Australia's Document Verification Service.

What is KYB?

Know Your Business (KYB) verifies an organisation rather than only one individual. The starting point may be a legal name, ABN, ACN, entity type, registration status, registered address and available officeholder information. A useful KYB workflow also records who is acting for the organisation and whether that person has authority to do so.

KYB becomes more complex when ownership and control pass through other companies, partnerships, trusts or foreign entities. An ABN lookup cannot, by itself, resolve every person who ultimately owns or controls a business. Extra documents and manual review may be needed to follow an ownership chain and identify the relevant natural persons.

This is why KYB often leads back to KYC. Once relevant directors, representatives, controllers or beneficial owners are identified, the organisation may need to verify those individuals and screen them according to its risk-based policy.

  1. Collect the entity's identifying information and proposed relationship.
  2. Compare core details with appropriate registry or independent data.
  3. Identify officeholders and the person acting for the entity.
  4. Establish the representative's authority where required.
  5. Collect ownership and control information and resolve relevant individuals.
  6. Apply KYC and risk screening to people who are in scope.

See the KYB Check Australia page for the practical distinction between registry evidence, ownership collection and related-person checks.

What is AML?

Anti-money laundering (AML) is a framework of risk assessment, policies, controls and ongoing activity. It is much broader than verifying an identity or screening a name once. In Australia, the legal framework is generally described as AML/CTF because it also addresses counter-terrorism financing, with proliferation-financing risk included in current AUSTRAC guidance.

AUSTRAC's AML/CTF program overview describes a program as including a risk assessment and documented policies, procedures, systems and controls. The exact obligations depend on whether an organisation is a reporting entity, the designated services it provides and the risks it reasonably faces.

Initial customer controls

Identify the customer and specified related people, collect and verify KYC information, understand the nature and purpose of the relationship, assign risk and conduct required screening.

Screening and escalation

Check for PEP and targeted-financial-sanctions concerns, review potential matches and apply enhanced due diligence or escalation when the circumstances require it.

Ongoing controls

Keep KYC information and risk assessments current, monitor unusual transactions and behaviours, and respond to material changes during the relationship.

Governance and evidence

Maintain appropriate policies, responsibilities, training, records, reporting processes, reviews and independent evaluation where required.

A KYC and AML screening check can support the identity, PEP, sanctions and evidence layer of initial onboarding. It should not be described as a replacement for the customer's own AML/CTF program, risk assessment, transaction monitoring, reporting duties or professional judgement.

How is CDD different from KYC?

Customer due diligence (CDD) is the process that uses KYC information to understand and manage a customer relationship. KYC is therefore an input to CDD, not a complete substitute for it. For a business customer, CDD can also use KYB information and the KYC results of relevant individuals.

AUSTRAC's overview of customer due diligence describes three connected elements: identification, verification and monitoring. It separates CDD into initial work before a designated service is provided, ongoing work throughout a business relationship and enhanced measures for higher-risk customers or specified circumstances.

CDD stagePurposePossible activities
Initial CDDUnderstand the customer before starting the relationship or designated serviceKYC or KYB, related-person identification, risk rating, PEP and sanctions checks
Ongoing CDDKeep the customer profile and risk understanding currentInformation reviews, reverification where appropriate and monitoring for unusual activity
Enhanced CDDManage higher risk or specified circumstancesAdditional information, source-of-funds or wealth enquiries, approvals and closer review

Where do PEP, sanctions and watchlist checks fit?

PEP and sanctions checks are screening controls, not synonyms for KYC or AML. They compare a person's identifying details with relevant data sources to find possible matches. The quality of the input matters: a name alone can produce ambiguity, while date of birth, nationality or other permitted identifiers can help distinguish people with similar names.

A potential match is not automatically a confirmed match and should not automatically produce an adverse decision. It needs review against the available identifiers, the source record and the organisation's escalation policy. A PEP result also does not mean the person has committed an offence. It indicates that the relationship may require a more careful risk assessment and, in some circumstances, additional due diligence.

Screening is normally strongest when it follows identity verification. That order reduces the risk of screening the wrong person and makes the resulting evidence easier to review.

How the checks work together

Onboarding an individual

  1. Collect identity and relationship information.
  2. Verify appropriate KYC information.
  3. Screen PEP, sanctions and other sources when required.
  4. Assign risk and review any potential match.
  5. Apply ongoing controls appropriate to the relationship.

Onboarding a business

  1. Collect the entity profile and purpose of the relationship.
  2. Verify core KYB information against appropriate sources.
  3. Identify representatives, owners and controllers in scope.
  4. Run KYC and screening for relevant individuals.
  5. Resolve gaps, assign risk and retain review evidence.

Which check should you choose?

Choose the smallest workflow that answers the real onboarding question, then add risk controls where they are genuinely required. Product labels are not standardised across every provider, so compare the stated inclusions rather than buying by acronym alone.

Choose KYC when

You need to verify an individual's identity and retain a clear consent and verification outcome, without assuming that broader AML screening is included.

View the KYC check

Choose KYC + AML screening when

You need identity verification plus point-in-time PEP, sanctions or watchlist screening to support a risk-based initial CDD workflow.

View KYC and AML screening

Choose KYB when

The customer is a business or other entity and you need to verify its details, understand who acts for it and coordinate checks for relevant owners or controllers.

View the KYB check

Frequently asked questions

Is KYC the same as AML?

No. KYC is the process of collecting and verifying information about a customer. AML is the broader framework used to identify, assess, manage and monitor money laundering and terrorism financing risk. KYC is often one part of an AML program.

Is KYB just KYC for a company?

KYB applies similar verification principles to a business or other organisation, but it usually goes further than checking a business name or registration number. It can involve entity status, officeholders, representatives, authority to act, ownership and control, followed by KYC and screening for relevant individuals.

Does a KYC check include sanctions and PEP screening?

Not always. A KYC product may cover identity verification only. Sanctions, politically exposed person and other watchlist screening should be stated separately unless the product clearly includes them. Check the scope before assuming they are bundled.

What is the difference between KYC and identity verification?

Identity verification tests whether identity information or documents can be confirmed. KYC is broader: it can include collecting information about the customer, verifying identity, understanding the relationship and applying risk-based checks required by the organisation.

What is customer due diligence?

Customer due diligence, or CDD, is the process of understanding a customer and their risk. In an AML/CTF setting it can include identifying the customer and related people, collecting and verifying KYC information, assigning risk, screening, keeping information current and monitoring the relationship.

Does passing KYC mean a customer is low risk?

No. A successful identity verification result confirms only the matters tested. The customer may still require sanctions or PEP screening, source-of-funds enquiries, enhanced due diligence, transaction monitoring or another risk decision under the organisation’s policy.

Is a one-off AML screening check a complete AML program?

No. A point-in-time screening result can support initial due diligence, but an AML/CTF program can also require governance, risk assessment, policies, staff responsibilities, record keeping, reporting, ongoing customer due diligence and transaction monitoring.

When would a business need KYC, KYB and AML screening together?

A business customer can require all three layers: KYB to verify the entity, KYC to verify relevant representatives or beneficial owners, and AML screening and risk controls to assess PEP, sanctions and other money laundering or terrorism financing risks.

The simplest way to remember the difference

KYC verifies people. KYB verifies organisations. AML manages financial-crime risk. CDD is the ongoing process that connects those activities to the customer relationship. In practice, the layers often work together, but each answers a different question and has different limits.

AuthNTick offers separately scoped KYC, KYC and AML screening, and KYB workflows. If your use case spans several customer types, request a business quote so the required checks and review boundaries can be mapped before onboarding starts.