What is KYC in Banking?
In banking, KYC is the set of checks a bank runs before it opens an account and repeats through the life of the relationship: verifying the customer's identity, identifying beneficial owners for corporate accounts, understanding the expected purpose and activity of the account, and assigning a risk rating that determines how closely the account is monitored. The principle is identical outside banking; only the documents and thresholds differ by sector.
What are the full forms of AML, KYC, CDD and EDD?
AML is anti-money laundering. KYC is Know Your Customer. CDD is Customer Due Diligence. EDD is Enhanced Due Diligence. AML is the overall framework; KYC is the customer identification and understanding process inside it; CDD is the standard level of checks applied to most customers; EDD is the additional level applied to higher-risk ones.
AML vs KYC: Quick Answer
What AML Covers
Governance, risk assessment, controls and reporting
What KYC Covers
What is KYC? Meaning and full form
Identification and verification
KYC starts with confirming who a customer actually is, typically through official identity documents and, for corporate customers, registration and ownership records. The KYC documents requested in the UAE vary by customer type and risk level, but a standard set usually includes:
For individual customers: passport copy, Emirates ID for residents, visa page where applicable, proof of address, and information on occupation, source of funds and source of wealth.
For corporate customers: trade licence, memorandum and articles of association, certificate of incorporation, shareholder and ownership registers, board or authorised signatory resolutions, and identification documents for directors, authorised signatories and ultimate beneficial owners.
For both: a record of the intended purpose and nature of the relationship, expected activity, and screening results against sanctions, PEP and adverse media sources
Beneficial ownership and purpose of relationship
Customer risk assessment and ongoing due diligence
AML and KYC Comparison Table
Scope, timing, ownership, outputs and examples
How KYC Works Within the AML Lifecycle
Onboarding
Ongoing monitoring and trigger events
Enhanced due diligence and exit decisions
KYC, CDD and EDD: Related but Not Identical
Definitions and practical examples
These terms are closely related and sometimes used loosely, but it helps to separate them. KYC is often used as the broad industry term for the customer identification and understanding process. Customer Due Diligence, or CDD, is the standard set of checks applied to most customers to satisfy that process (Cabinet Resolution No. 134 of 2025, Articles 6 to 15).
Enhanced Due Diligence, or EDD, is the additional set of checks applied specifically to higher-risk customers or relationships. In practice, many practitioners use KYC as an umbrella term covering both CDD and EDD, though exact usage can vary by jurisdiction and organisation.
Who Owns AML and KYC Responsibilities?
First line, compliance and senior management
Front-line staff who interact directly with customers typically carry out the practical KYC steps, such as collecting and verifying documents. The AML compliance officer owns the wider AML programme, including policy design, risk assessment methodology and reporting decisions, and is the person who files suspicious transaction reports with the FIU through goAML. Senior management and, in many structures, the board retain ultimate accountability for the programme's overall adequacy.
Common Misconceptions
KYC is not a one-time document collection exercise
Treating KYC as a box-ticking exercise completed once at onboarding misses its ongoing nature; ongoing monitoring and periodic refresh are core parts of KYC, not optional extras.
AML is not only transaction monitoring
AML is sometimes reduced in people's minds to transaction monitoring alone, but monitoring is only one component of a wider framework that also includes risk assessment, customer due diligence, sanctions screening, reporting, governance and independent testing.
Practical Example: From Onboarding to Suspicious Report Decision
Sources, jurisdiction caveat and expert review
Definitions in this article draw on widely used Financial Action Task Force concepts and general UAE AML terminology as set out in the UAE's Federal AML, CFT and CPF law and its Cabinet Resolution executive regulations, verified against the primary text of Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, current as of 4 August 2026. KYC is primarily an industry and practitioner term rather than a term defined identically in every jurisdiction's legislation, and its precise scope can vary by regulator and sector; readers working under a specific regulator's rulebook should confirm that regulator's own defined terms.
Pro AML Training is part of NIYEAHMA, a compliance training and advisory practice with more than five years of experience in AML and financial crime compliance. The team has trained more than 10,000 professionals across more than 300 client organisations, delivering more than 12,000 hours of training to banks and financial institutions, DNFBPs, capital market companies, insurers and virtual asset service providers, across more than 10 jurisdictions including the UAE, the United Kingdom, Australia, Singapore, India, Saudi Arabia and Hong Kong.
Disclaimer: This article is for general informational purposes and does not constitute legal advice. For advice specific to your organisation, consult a qualified UAE legal or compliance professional.