In a crypto service, KYC can be one component of an AML program. Other AML controls can include customer risk assessment, sanctions screening, transaction monitoring, record keeping, escalation procedures, and suspicious-activity controls.
KYC and AML Defined
| Concept | Meaning | Main purpose |
|---|---|---|
| KYC | Customer identification and due diligence | Establish who the customer is and understand the relationship |
| AML | Broader anti-money-laundering framework | Manage financial-crime risk before, during, and after activity |
The simplest distinction is scope: KYC is customer-focused; AML is system-wide. A service can complete a customer's identity check and still continue applying AML controls throughout the life of the account or transaction relationship.
What KYC Does
Customer Identification
KYC establishes who the customer claims to be. That can involve collecting legal name, date of birth, address, nationality, contact details, or other identity information.
Identity Verification
The provider can check those details against accepted evidence such as identity documents, electronic records, selfies, or liveness tools. The exact method varies by service and jurisdiction.
Customer Due Diligence Context
KYC also supports due diligence by giving the provider a customer profile it can use to understand the relationship and relevant risk. The full verification process is covered in What Is KYC in Crypto?.
What AML Covers
Risk Assessment
AML controls look beyond identity alone. A provider can evaluate product type, customer profile, geography, transaction behavior, payment methods, sanctions exposure, or other risk factors.
Transaction Monitoring
Monitoring evaluates account or transaction activity over time for unusual patterns, changes in behavior, or other indicators that need review. It is not the same thing as the initial identity check.
Suspicious-Activity Controls
A wider AML framework can include internal escalation, documentation, investigation, restrictions, record keeping, and reporting where applicable rules require them. The exact procedures differ by provider and jurisdiction.
How KYC Fits Inside AML
A simplified relationship can look like this:
- The provider collects customer information.
- Identity evidence is checked through KYC.
- The customer or relationship is assigned a risk profile.
- Account or transaction activity is monitored or screened where appropriate.
- Cases that meet internal criteria can be escalated for additional review.
- Customer information can be refreshed if circumstances or risk change.
This is only a conceptual model. The important point is that KYC helps establish the customer, while AML extends to the wider risk controls used before, during, and after activity.
Before, During and After Account Use
| Stage | KYC role | AML role |
|---|---|---|
| Before access | Identify and verify the customer | Set initial risk controls |
| During use | Maintain or update customer information where needed | Monitor activity and reassess risk |
| After unusual activity | Provide verified customer context | Escalate, investigate, document, restrict, or report where required |
This lifecycle view explains why passing KYC does not mean a user has passed every possible future AML review. Identity verification is one step; transaction and account risk can still change later.
How KYC and AML Work Together in Practice
At Onboarding
KYC can establish who the customer is and whether the identity evidence is credible. AML controls can use that customer information when determining the initial risk profile and which controls should apply.
During Account Use
AML does not end after identity verification. The provider may continue monitoring transaction patterns, payment behavior, sanctions exposure, or changes from expected activity according to its policies and obligations.
When Risk Changes
A change in customer circumstances or activity can lead to additional due diligence. That may involve updating KYC information, requesting supporting documents, increasing monitoring, or reviewing whether the relationship should continue.
KYC Data and AML Decisions Are Not the Same Thing
KYC creates and maintains customer information. AML can use that information alongside transaction data, sanctions results, internal risk rules, and other controls. The distinction matters because:
- A customer can complete KYC and still be subject to ongoing AML monitoring.
- An AML review can consider activity that was not part of the original identity check.
- Updating customer information can be one response inside a wider AML process.
- Transaction-focused controls can operate alongside KYC rather than replace it.
- Passing KYC does not guarantee that every future transaction will proceed without review.
Where KYT Fits
KYT, or Know Your Transaction, is commonly used in crypto for transaction-level screening or monitoring. It can examine blockchain addresses, transaction history, exposure to known services, and other transaction signals.
KYT is narrower than AML and different from KYC: KYC focuses on the customer identity; KYT focuses on transaction activity; AML is the broader risk-control framework that can use both types of information. See KYT vs KYC for the dedicated comparison.
Common Terminology Mistakes
- KYC is not the whole AML program.
- AML is not simply an identity-document check.
- KYT is not a replacement for KYC.
- Transaction monitoring does not prove a person's identity.
- Passing KYC does not mean future activity can never be reviewed.
For practical purposes, the cleanest model is: KYC identifies and understands the customer; AML manages the broader financial-crime risk framework; KYT examines transaction-level activity.
FAQ
Is KYC part of AML?
Commonly, yes. KYC and customer due diligence are often components of a broader AML framework, while AML also includes controls that continue beyond identity verification.
Can AML exist without KYC?
AML is broader than KYC, so it includes controls other than identity verification. Whether a particular service must apply KYC depends on its legal and operational context.
What is the main difference between KYC and AML?
KYC focuses on who the customer is and the customer relationship. AML covers the wider set of controls used to understand and manage money-laundering and related financial-crime risk.
Is KYC only done at account opening?
Not always. Some providers can request updated customer information or additional due diligence later if circumstances, products, or risk change.
Where does KYT fit?
KYT focuses on transaction activity and transaction-level risk signals. It can complement KYC within a broader AML or risk-control framework.