02/07/2026

Compliance Essentials #22 – The key stages of KYC

Phoenix Compliance Essentials #22

Today’s focus: the key stages of KYC

You are onboarding a new customer. Do you know exactly what needs to be verified?

KYC enables institutions to identify and verify customers, understand their activities and assess their level of risk in order to prevent ML/FT-P-C risks.

1️⃣ Identify the customer

Identification must be carried out before establishing the business relationship or, at the latest, before the first transaction.

👉 Individuals:

Information to be collected: surname, first names, date of birth and residential address.

Documents to be collected: valid identity document and proof of address.

👉 Legal entities and similar legal arrangements:

Information to be collected: company name and legal form, country of incorporation, registered office, identity of directors and beneficial owners. For trusts: settlor, trustee(s), protector and beneficiaries.

Documents to be collected: articles of association and an extract from the companies register issued within the last three months, beneficial ownership register. For trusts: the trust deed or equivalent document, together with identification documents for the relevant parties.

Identification also includes integrity checks: screening, adverse media searches and consultation of the Monaco National Asset Freeze List.

2️⃣ Assess the risk

This is not a mere formality. It is the cornerstone of the framework.

The risk-based approach consists of classifying customers according to different levels of risk (e.g. low, medium or high).

This assessment is based in particular on the five risk factors: products and services, transaction conditions, distribution channels, customer profile and the geographical areas concerned.

👉 The level of risk determines the level of due diligence to be applied and the extent of the KYC measures. For example, a high-risk customer may require the collection of evidence supporting the customer’s socio-economic profile, enhanced integrity checks and a specific review.

3️⃣ Validate the customer file

A complete KYC file is not enough. It must be analysed, challenged and approved. Approval is the final line of defence before establishing the business relationship.

Are the information collected, the level of risk and the intended transactions consistent with the customer’s profile?

👉 For high-risk customers or PEPs, approval must be given by a member of senior management.

The objective is to ensure that the decision to establish the business relationship is based on a sufficient understanding of the customer and their level of risk.

➡️ Update the customer file

A KYC file is never static. It must be updated regularly to reflect changes in the customer’s profile.

👉 The frequency of reviews is determined by internal procedures and the risk-based approach.

👉 An update may also be triggered by a significant event (for example, a customer becoming a PEP).

Every update must be properly documented and traceable.