Three-level KYC model: how simplified, full, and enhanced checks work

International KYC standards divide customer verification into three levels: simplified, full, and enhanced. Each level is applied depending on the client's risk assessment, type of operations, and regulatory requirements. This article examines specific criteria for choosing the verification level, mandatory documents and procedures for each case, as well as compliance with FATF recommendations, EU, UK, US regulations, and Russian Federation legislation

Simplified KYC: what it is and when simplified verification is allowed

Defining simplified KYC and its place among KYC levels

Simplified KYC (simplified customer verification) is a basic level of identification procedures applied to customers with minimal risk of involvement in money laundering or terrorist financing. This approach allows financial institutions to optimize resources, directing their main efforts to verifying high-risk customers, while maintaining the necessary level of control over operations with a low probability of abuse.

In the modern three-level client verification system, simplified KYC occupies the initial position in the hierarchy of control procedures.
First level

Simplified due diligence (SDD) – applied to clients with proven low risk.

Second level

Customer due diligence (CDD) – also called standard or full due diligence – covers most medium-risk customers.

Third level

Enhanced due diligence (EDD) – designed for high-risk clients requiring in-depth study.

The key difference of simplified KYC lies in the reduced volume of collected data and simplified verification methods while retaining all mandatory identification elements. According to the updated FATF recommendations from February 2025, countries are obliged not only to permit but also to actively encourage the use of simplified measures in low-risk situations. This change emphasizes the importance of a proportional approach, where the intensity of verification corresponds to the actual level of threat.

Terms and limitations of simplified KYC application

The use of simplified KYC is permitted only if strict criteria are met, as determined by the organization’s risk-based approach. Financial institutions may use simplified procedures for clients from regulated jurisdictions with effective anti-money laundering systems, for public companies whose shares are traded on recognized exchanges and are subject to disclosure, and for government bodies and institutions with a transparent governance structure.

Typical scenarios for applying SDD include operations with amounts below established thresholds — usually less than 1000 US dollars or euros according to FATF recommendations. Simplified verification is allowed for basic financial products with limited functionality: electronic wallets with transaction limits, insurance policies with low premiums, pension accounts without early withdrawal options. In the cryptocurrency sector, many exchanges provide limited access to trading without full verification — for example, with a daily withdrawal limit of up to 10,000-50,000 US dollars.

It is critically important to understand the limitations of simplified KYC. Simplified verification never means a complete absence of identification — minimum requirements for establishing customer identity remain mandatory.

Simplified verification never means a complete absence of identification — minimum requirements for customer identification remain mandatory.

If a client’s risk profile changes, for example, due to an increase in transaction volumes or a change in the geography of operations, the organization is obliged to switch to standard or enhanced verification. The use of SDD is prohibited for clients from high-risk jurisdictions, in cases of suspected money laundering, for politically exposed persons (PEPs) and their close relatives.

Minimum set of data, documents and checks for simplified KYC

With simplified KYC, organizations collect a basic set of identification data: the client’s full name, date of birth, and registration or residential address. For legal entities, the name, registration number, and legal address are required.

Unlike full verification, SDD allows identity verification after business relationships have been established — for example, when the account balance exceeds a certain threshold.

Documentary requirements are significantly simplified. For individuals, one identity document—a passport or national ID card—is sufficient. Proof of address may not be required or may be accepted in a simplified form without notarization. Biometric verification is often limited to a basic photograph without liveness detection or may not be applied at all for certain categories of clients.

  1. SDD verification procedures are characterized by automation and minimization of manual control.
  2. Automatic data matching with public registers is used, and a shortened check against sanctions lists is applied — only against the main international lists without in-depth screening.
  3. Transaction monitoring is carried out with increased thresholds for alert generation.
  4. The frequency of updating client data is reduced — instead of annual updates, it can be done once every 2-3 years if there is no suspicious activity.

Modern technological solutions allow for simplified KYC in a matter of minutes. Automated systems using artificial intelligence can instantly assess a client’s risk level, conduct necessary checks against databases, and decide on the possibility of applying a simplified procedure.

This ensures a balance between security requirements and the convenience of the client experience, which is critically important for the competitiveness of financial services in the digital age.

Full KYC: Requirements for Standard Customer Identification

Full KYC is a basic level of customer verification that forms the foundation of the anti-money laundering system in financial institutions worldwide. Unlike simplified procedures, standard identification provides sufficient depth of verification for most operations and customers with a medium level of risk.

Definition of full KYC and cases of mandatory application

Full KYC, also known as Customer Due Diligence (CDD) in international terminology, is a standard set of customer identification and verification procedures that includes checking identity, residential address, sources of funds, and the nature of business relationships. This level of verification is applied to the vast majority of financial institution clients and is the minimum necessary standard for compliance with regulatory requirements.

Mandatory full KYC is triggered when certain events occur. The first and main one is the establishment of permanent business relations with a client, regardless of the amount of the first transaction. Banks, brokers, crypto exchanges, and payment systems are obliged to conduct full identification when opening an account, issuing a card, or providing access to a trading platform.

One-off operations also require full verification when thresholds are exceeded. According to FATF recommendations and EU directives, the threshold is 15,000 euros for one-off transactions or 1,000 euros for money transfers. In the US, thresholds vary: $10,000 for cash transactions and $3,000 for money transfers through systems like Western Union.

Full identification becomes mandatory in case of any suspicions of money laundering or terrorist financing, regardless of the transaction amount. Regulators also require full KYC when there are doubts about the accuracy of previously obtained customer data or when there is a significant change in the nature of their activities.

Special cases for applying full KYC include real estate transactions regardless of the payment method, life insurance with an annual premium exceeding 2500 euros or a one-time payment of 5000 euros or more, and any transactions with virtual assets on regulated platforms.

List of data, documents and checks for full KYC (including basic monitoring)

The standard full KYC procedure requires the collection and verification of a specific set of data. For individuals, the following are mandatory:

  1. full name,
  2. date and place of birth,
  3. citizenship,
  4. address of permanent registration and actual residence,
  5. contact information,
  6. identification numbers (passport, TIN or similar),
  7. occupation and employer.

Documentary proof includes a valid photo ID (passport, driver’s license, national ID card). For address verification, utility bills no older than 3 months, bank statements, lease agreements, or registration certificates are accepted. When opening corporate accounts, additional documents required include articles of incorporation, information on beneficial owners, and proof of representative authority.

The verification process for full KYC includes several mandatory steps.

01
Document authenticity verification
It is carried out through the analysis of security elements, machine-readable zones, and reconciliation with databases of invalid documents. Biometric verification compares the photo in the document with the client’s selfie, using face recognition algorithms and liveness detection technologies to protect against fakes.
02
Screening against sanctions lists and PEP (politically exposed persons) databases
It is carried out at the onboarding stage and regularly updated. Organizations check clients against UN, OFAC, EU lists, national sanctions lists, Interpol databases, and local lists of terrorists and extremists.
03
Source of funds analysis for full KYC
Focuses on the compliance of the declared income with the operations performed. For employees, an income statement is sufficient; for entrepreneurs, a tax return or bank statements; for investors, confirmation of asset sales or dividend payments.
04
Basic transaction monitoring after full KYC
Includes tracking of atypical operations that exceed the client’s usual activity profile. The systems automatically record a sharp increase in turnover, multiple transfers slightly below threshold values (structuring), transactions with high-risk jurisdictions, and frequent cash operations.
05
Periodic data refresh
It is carried out every 1-3 years depending on the client’s risk profile. In case of changes in personal data, change of citizenship or residency, or significant changes in financial situation, the client is obliged to provide updated information.
06
Documenting full KYC results
It is stored for 5 years after the termination of business relations in accordance with international standards. The client’s file includes copies of all documents, verification results, justification of the risk category, transaction history, and correspondence on compliance issues.
07
Technological implementation of full KYC
In modern systems, it takes from several minutes to several hours, depending on the complexity of the checks.

Automated platforms process documents through OCR systems, perform biometric verification in seconds, instantly cross-reference data with dozens of databases, and generate a client risk profile based on hundreds of parameters.

Enhanced KYC: enhanced verification of high-risk clients

Enhanced KYC (EDD — Enhanced Due Diligence) represents the most detailed level of client verification, applied to individuals and organizations with increased risks of money laundering, terrorist financing, or other financial crimes. Unlike standard identification procedures, enhanced verification involves a deep, multi-level analysis of the client, their activities, sources of funds, and business connections. Financial organizations are obliged to apply Enhanced KYC not only when establishing relationships with high-risk clients but also throughout the entire service period, adapting the intensity of monitoring to the changing risk profile.

When enhanced KYC is triggered and what triggers are used

The Enhanced KYC procedure is triggered when specific risk indicators are identified, which can be divided into several categories. The first group of triggers is related to the client’s personal status: politically exposed persons (PEPs), their relatives, and close associates automatically fall under enhanced scrutiny according to international FATF standards and national regulatory requirements. This category also includes individuals listed on OFAC, UN, EU sanctions lists, or national lists of extremists and terrorists.

Geographical triggers are activated when a client resides or conducts business in high-risk jurisdictions — countries from the FATF “grey” or “black” lists, states with a high level of corruption according to the Transparency International index, offshore zones with an opaque ownership structure. Transactional patterns requiring Enhanced KYC include operations for amounts exceeding established thresholds (usually from 15,000 euros for one-time operations), unusually complex payment schemes without obvious economic logic, frequent transfers to high-risk countries.

Industry risk factors cover clients from sectors with increased vulnerability to money laundering: casinos and gambling businesses, trading in precious metals and stones, real estate transactions, non-profit organizations with international activities, cryptocurrency exchanges and exchangers. Behavioral triggers include attempts to avoid standard identification procedures, providing unreliable or contradictory information, unexplained changes in the nature and volume of operations, refusal to disclose sources of funds or beneficial owners.

Additional verification measures and sources of information for enhanced KYC

Enhanced KYC involves a significant expansion of the range of verification measures and the involvement of multiple sources of data verification. In-depth identity verification includes biometric verification using liveness detection technologies to exclude fakes, cross-checking documents through government databases and international verification services, and analyzing the history of document and registration address changes. Financial organizations request additional documents: income statements for an extended period, tax returns, bank statements from other accounts, and documents of ownership of assets.

Verification of the source of wealth requires documentary evidence of the origin of funds through employment contracts, dividend payments, asset purchase and sale agreements, and inheritance documents.

The entire chain of funds movement from the original source to the client’s current account is analyzed. Business reputation investigation includes studying negative mentions in the media through specialized adverse media databases, checking lawsuits and investigations through national and international court registries, and analyzing connections with other high-risk individuals through link graph building systems.

Verification of corporate structures under Enhanced KYC involves building a complete ownership scheme down to the ultimate beneficial owners, checking all legal entities in the ownership chain, and analyzing the economic feasibility of complex corporate structures. Commercial databases such as Bureau van Dijk, Dun & Bradstreet, national registers of legal entities, and industry-specific information sources are used. Additionally, specialized data providers are engaged for real-time screening against sanctions lists, monitoring changes in PEP status, and tracking new negative mentions.

Documentation of enhanced KYC results and enhanced ongoing monitoring

Documenting Enhanced KYC requires creating a comprehensive client dossier, recording all verification stages, information sources used, identified risks, and decisions made. An extended client risk profile is formed with a detailed justification of the assigned risk level, a risk matrix across various parameters (geographical, industry, transactional), recommendations for further monitoring, and control measures. Each document and information source is saved with the date of receipt, verification method, and responsible employee.

The decision to accept a client for service at a high level of risk is made collectively with the mandatory participation of the organization’s management and the compliance department.

The decision protocol contains a justification for the economic feasibility of working with the client, a list of additional control measures, and a schedule for reviewing the risk level. All Enhanced KYC materials are stored in a secure document management system with access differentiation and auditing of all user actions.

Enhanced transaction monitoring involves lowering the thresholds for automatic alerts (often 2-3 times lower than standard), daily analysis of operations instead of the standard weekly or monthly, and the application of advanced monitoring scenarios taking into account the specifics of identified risks. Monitoring systems are configured to detect changes in client behavioral patterns, new counterparties from high-risk jurisdictions, and signs of payment structuring to circumvent threshold values.

Periodic review of Enhanced KYC dossiers is conducted at least once a year, and quarterly for particularly high-risk clients. During the review, information on beneficial owners is updated, PEP status and sanctions restrictions are checked, changes in the client’s business nature are analyzed, and data on sources of funds and financial position are updated. Based on the results of the review, the risk level may be changed with a corresponding adjustment of control measures.

The entire history of risk profile changes and decisions made is stored in the system to ensure an audit trail and compliance with regulatory requirements for storing KYC data for a minimum of five years after the termination of business relations.

International KYC Standards and Regulations Defining Verification Levels

The three-level client verification system is not an invention of individual companies or states, but the result of many years of work by international organizations to standardize the fight against money laundering. These standards form a single legal framework that allows financial institutions to operate in any jurisdiction without a radical restructuring of verification processes.

FATF Recommendations on SDD, CDD, and EDD and a Risk-Based Approach

The Financial Action Task Force (FATF) laid the foundation for the modern identification system in its 40 recommendations, the latest edition of which came into force in October 2023. Recommendation 10 details three levels of verification: Simplified Due Diligence (SDD), Customer Due Diligence (CDD), and Enhanced Due Diligence (EDD).

FATF defines the risk-based approach as a fundamental principle: the intensity of verification should correspond to the level of client risk.

Organizations are required to develop their own risk matrices that take into account the geography of operations, types of clients, products, and service delivery channels.
Low risk

Allows SDD with verification of only basic identification data. Standard risk requires full CDD with identity verification, identification of beneficial owners, and understanding the purpose of business relationships.

High risk

Automatically launches EDD with enhanced transaction monitoring and regular data updates.

The most important innovation of 2023 is the strengthening of requirements for the verification of virtual assets and cryptocurrency transactions. FATF now requires the same levels of verification to be applied to digital asset transactions, which effectively makes the three-tier system universal for all types of financial transactions.

Consolidating simplified, full, and enhanced KYC in EU, UK, and US requirements

The European Union has implemented FATF recommendations through a series of anti-money laundering directives. The Sixth AML Directive (AMLD6), which came into force in June 2021, and the upcoming Seventh Directive clearly delineate three levels of verification.

Simplified KYC is permitted for clients from EEA countries, government agencies, and public companies listed on regulated exchanges, provided there are no suspicious factors. Full KYC is mandatory for all new clients, with verification through reliable independent sources. Enhanced KYC applies to politically exposed persons (PEPs), clients from high-risk jurisdictions, and when establishing correspondent relationships with banks from third countries.

After Brexit, the UK retained European standards but strengthened them through the Money Laundering Regulations 2022. The British approach is distinguished by detailed criteria for transitioning between verification levels and the mandatory use of biometric verification technologies for remote identification during full and enhanced KYC.

The United States formalized a three-tiered system through the requirements of the Bank Secrecy Act and the USA PATRIOT Act, administered by FinCEN. The American model is unique due to its mandatory Customer Identification Program (CIP) for all financial institutions and stricter penalties for violations.

  1. Simplified KYC in the USA is applied very restrictively — only for certain types of pension accounts and government programs.
  2. Enhanced KYC is automatically triggered for transactions over $10,000 and any operations involving jurisdictions from the OFAC list.

Compliance of international standards with KYC requirements in the Russian Federation and CIS countries

Russian legislation has adapted international standards through Federal Law 115-FZ “On Counteracting the Legalization of Proceeds from Crime,” which is regularly updated to comply with FATF recommendations.

Simplified identification corresponds to international simplified KYC and is applied to transactions up to 15,000 rubles for individuals and up to 40,000 rubles for legal entities. Full identification is similar to full KYC and requires personal presence or the use of the Unified Biometric System. Enhanced due diligence, corresponding to enhanced KYC, is mandatory for foreign public officials and clients from countries that do not comply with FATF recommendations.

Kazakhstan has harmonized its national legislation with international standards through Law No. 466-VI “On Counteracting the Legalization of Proceeds,” establishing an identical three-tier system with a special emphasis on verifying beneficial owners during standard and enhanced verification.

Belarus implemented international standards through Law No. 165-Z, adding national specifics in the form of mandatory verification through state databases at any level of identification. Uzbekistan and Armenia updated their legislation in 2023-2024 to fully comply with FATF recommendations, which allowed them to exit the organization’s gray list.

The key feature of CIS countries is the preservation of stricter requirements for personal presence during initial identification, which distinguishes them from the European and American practice of fully remote verification. However, the active development of national biometric systems is gradually bringing CIS approaches closer to international standards, making the three-level KYC system a universal tool for global financial compliance.

Conclusion
Risk-based KYC model ensures compliance and operational efficiency

The division of identification procedures into three levels—simplified, full, and enhanced—reflects the logic of a modern approach to customer verification, where the intensity of the check corresponds to the degree of potential risk. Companies gain the ability to rationally allocate resources: simplified verification accelerates the onboarding of customers with a minimal threat profile, standard identification covers the majority of users, and enhanced verification focuses on situations requiring a detailed analysis of sources of funds, purposes of cooperation, and the reliability of counterparties.

FATF recommendations provide a universal framework within which national regulators establish their own norms, taking into account the specifics of the jurisdiction, industry risks, and technological capabilities. Proper application of a multi-level KYC system allows businesses to simultaneously comply with legal requirements, minimize verification costs for low-risk clients, and promptly identify suspicious activity where it is most likely. Automation of document recognition, biometric authentication, and transaction monitoring processes makes such a model not only secure but also scalable for companies of any size.