How KYC for non-residents differs from standard KYC for resident customers in 2025
In 2025, companies in the EU and the CIS are obliged to implement customer due diligence (CDD) and enhanced due diligence (EDD) procedures based on a risk-based approach. At the same time, the identification procedures for non-residents differ substantially from standard KYC checks of residents in the depth of analysis, the volume of documents, and the technologies applied.
The main difference lies in the mandatory application of enhanced due diligence (EDD) for most non-residents. By 2025, extensive verification of customer data has become typical practice: from detailed questionnaires about the purpose of opening an account to proof of the source of wealth. For residents, basic identity verification and a check against local databases are sufficient, whereas non-residents are checked against international sanctions lists, PEP databases and adverse-media monitoring systems.
The bank conducts due diligence, including verifying the owner’s identity, the legality of the business, and the source of funds. If residents can confirm their income with a certificate from their place of work or a tax return, non-residents are required to provide documentary confirmation of the entire chain of the origin of funds, including the initial source of capital.
The technological requirements also differ. The new KYC 2025 standards require mandatory electronic customer identification (eKYC) using digital onboarding and remote verification. For residents, a one-time biometric identification is often enough, while from 2025 non-residents have to confirm their identity more often than before — each time a card is reissued, i.e. once a year.
Verification timeframes differ substantially: if residents pass KYC in a few minutes, verifying non-residents can take from several days to weeks. In 2024-2025, banking requirements for foreign clients became even stricter: every document and the origin of funds is checked, sometimes even to the point of requiring physical presence.
The monitoring of non-residents’ transactions is conducted in real time using stricter thresholds and algorithms for detecting suspicious operations. The periodic updating of data for non-residents is carried out more often — at least once a year versus the standard 3-5 years for low-risk residents.
Who to consider an international client and a non-resident for KYC purposes
Determining a client’s status is critically important for choosing the right verification procedure. Non-residents are considered to be clients who are foreign citizens, as well as persons without a permanent place of residence in the country where the business operates.
For KYC purposes, an international client is recognized as an individual or legal entity that meets at least one of the criteria:
For individuals:
- Citizenship of a country other than the country of service
- Tax residency in another jurisdiction (staying less than 183 days a year)
- No permanent registration of place of residence in the bank’s country
- Holding only a temporary visa or residence permit
- Foreign clients opening accounts despite being non-residents of the country where the company operates
For legal entities:
- Registration in a foreign jurisdiction
- Control by foreign beneficiaries (more than a 25% ownership stake)
- Conducting the main activity outside the country of service
- Nominal shareholders of the company or those who hold the company’s bearer shares
- No real presence and economic activity in the bank’s country
A special category consists of clients with multiple citizenship or dual tax residency. In such cases, the principle of maximum caution is applied — the client is checked as a non-resident using the strictest procedures.
It is important to take into account the dynamic nature of status: a resident can become a non-resident when changing tax residency, relocating, or changing the company’s ownership structure. KYC systems must track such changes and automatically adjust the level of verification.
Elevated-risk factors when working with non-residents and foreign clients
When doing business with individuals or organizations from higher-risk countries, FATF recommends that financial institutions apply enhanced due diligence measures. Identifying risk factors becomes the basis for determining the depth and frequency of checks.
| Risk factors | Description |
| Geographic risk factors | Clients residing in countries classified as high-risk by FATF or the European Union automatically require the application of EDD. Such jurisdictions include countries from FATF’s black and grey lists, states with a high level of corruption according to the Transparency International index, and offshore zones with an opaque reporting system. An additional risk is posed by clients from countries under international sanctions, jurisdictions with an unstable political situation or active military conflicts, and regions with high terrorist activity. |
| Factors related to the nature of the activity | It is important to know the nature of their business or occupation, the sources of their funds or wealth, as well as the typical patterns, volume, frequency and purpose of their transactions. An elevated risk is posed by: – Businesses with intensive cash turnover – Trade in precious metals and stones – Operations with virtual assets and cryptocurrency – Intermediary services without a transparent business model – Clients with complex legal structures or opaque financial activity |
| Status-related risk factors | Under FATF standards, politically exposed persons (PEP) belong to the high-risk client category, since they hold positions that can potentially be used for money laundering. This category includes not only the PEPs themselves but also their family members and close business partners. |
| Transactional factors | Operations without obvious economic logic, transactions through multiple intermediary accounts in different jurisdictions, and a mismatch between the volume of operations and the declared activity profile raise suspicion. Since 2023, and with reinforcement in 2025, a rule has been in effect: any cryptocurrency operation of 600,000 rubles or more automatically falls under financial monitoring. |
| Documentary risk factors | Special attention is required for clients who provide documents from jurisdictions with a weak verification system, use complex corporate structures with unclear beneficiaries, refuse to disclose the sources of funds, or provide contradictory information. A combination of several risk factors requires the application of the strictest verification procedures, including requesting additional documents, conducting on-site inspections, setting operation limits, and enhanced real-time monitoring of all transactions. |
International KYC requirements 2025 for foreign clients and non-residents
Working with international clients and non-residents requires compliance with a multi-level regulatory system that in 2025 became even more comprehensive. Financial institutions and online services face the need to simultaneously meet global standards, regional directives and local jurisdictional requirements. At the same time, regulators increasingly require instant verification and continuous monitoring of clients regardless of their geographic location.
The complexity of international KYC lies not only in the differences in regulatory requirements but also in the practical aspects: verifying documents in dozens of languages, validating against international databases, assessing jurisdictional risks, and ensuring cross-border data transfer in compliance with information protection requirements. Automating these processes through biometric identification and AI-OCR platforms becomes critically important for scaling a business into international markets.
The basic elements of KYC under FATF standards and global KYC 2025
The FATF Recommendations, updated in October 2025, establish a comprehensive and consistent system of measures to combat money laundering and terrorist financing. These standards serve as the foundation for national regulators when developing local KYC requirements.
FATF Recommendation 10 forms the core of the global CDD (Customer Due Diligence) requirements. Financial institutions are prohibited from keeping anonymous accounts or accounts in fictitious names. CDD procedures must be applied when establishing business relations, carrying out one-off operations above the established threshold, when there are suspicions of money laundering or terrorist financing, and when there are doubts about the accuracy of previously obtained identification data.
A key innovation of 2025 is the strengthened focus on the risk-based approach (RBA). Countries must apply a risk-based approach after assessing the risks in order to prevent money laundering and terrorist financing. This means differentiating control measures: simplified procedures for low-risk clients and enhanced due diligence for high-risk categories.
FATF recommends a threshold of USD 1,000 or EUR for applying the Travel Rule, although countries set their own thresholds or may not have them at all. The Travel Rule requires financial institutions and virtual asset service providers to collect and transmit information about the originator and the beneficiary when conducting transactions, which is especially relevant for cross-border transfers.
The 2025 standards also emphasize the technological component. FATF stresses the importance of KYC (know your customer) and KYB (know your business) protocols, requiring financial organizations to invest in advanced software and tools for verifying the identity and business of their clients. The digital transformation of identification processes is becoming not just a competitive advantage but a mandatory requirement for compliance with international standards.
Additional requirements for KYC of non-residents: EDD, source of funds and sanctions compliance
Non-residents automatically fall into the elevated-risk category, which activates Enhanced Due Diligence (EDD) requirements. EDD is required for persons or situations that present an elevated risk, including non-residents or persons subject to economic sanctions. The EDD procedure goes far beyond standard identity verification.
EDD requires significantly more evidence and detailed information. The entire EDD process must be documented, and this information must be retained. Financial institutions are obliged not only to identify the client but also to understand the nature of their business, the sources of their wealth, and the purposes of establishing the business relationship.
Verifying the source of funds and the source of wealth becomes a mandatory element when working with non-residents. For politically exposed persons (PEPs), it is necessary to establish the sources of their funds and wealth. This requirement extends not only to PEPs but to all non-resident clients from high-risk jurisdictions.
Sanctions screening for international clients includes checking against multiple lists: FATF Recommendation 19 states that EDD measures must be applied to business relations and transactions with individuals and legal entities from countries for which FATF requires it. In 2025, the number of sanctions lists and their mutual integration reached an unprecedented level, requiring automated solutions for effective checking.
High-risk clients are identified based on their involvement in high-risk industries, connections to politically exposed persons, or operations in countries with financial risks. The categories requiring the mandatory application of EDD include clients from jurisdictions with weak AML controls, companies with complex ownership structures, offshore companies, and organizations carrying out large cash transactions.
Regional blocs
Regional blocs: the EU and the United Kingdom (6AMLD, AMLR, AMLA, eKYC)
In 2025, the European Union is undergoing a revolution in KYC/AML regulation. The AMLR regulation enters into force 21 days after publication and applies from July 10, 2027, but preparation for its implementation is already transforming the approaches of financial institutions.
The creation of a single European regulator, AMLA, marks the transition from directives to direct regulation. AMLA will begin its operations by December 31, 2025, centralizing supervision of high-risk financial institutions.
AMLR sets a cash payment limit of EUR 10,000, while member states may set a lower threshold. For transactions from EUR 3,000, periodic enhanced customer due diligence will be required. The new rules govern the basic requirements for due diligence in cash transactions and in establishing cooperation with clients, including KYC procedures.
6AMLD expands the list of predicate offenses and tightens liability. Member states are obliged to conduct national risk assessments every four years and provide the results to obliged entities. The minimum prison term for money laundering offenses has been increased to four years, and legal entities are now criminally liable for failing to prevent illegal activity.
eKYC in the EU is developing within the framework of the eIDAS 2.0 regulation, ensuring cross-border recognition of digital identity. Biometric verification is becoming the standard for remote onboarding, while video identification is accepted by most European regulators as the equivalent of physical presence.
The US and North America (BSA, FinCEN, CDD, BOI reporting)
In 2025, the United States radically revised its beneficial ownership reporting requirements. FinCEN issued an interim rule that revises the definition of a “reporting company”, exempting all companies created in the US from the requirement to report beneficial ownership information. Now only foreign companies registered to do business in the US must file BOI reports.
The Bank Secrecy Act (BSA) and the USA PATRIOT Act require financial institutions to verify identities, track transactions and report suspicious activity. The Customer Due Diligence Rule, which came into force in May 2018, requires financial institutions to identify and verify the beneficial owners of legal entity clients.
FinCEN expanded the meaning of “customer due diligence requirements under applicable law” to include any legal requirements or prohibitions aimed at countering money laundering or terrorist financing. This allows financial institutions to make broader use of the BOI database for the purposes of BSA/AML compliance, sanctions checks and the filing of suspicious activity reports.
For non-residents, the US applies especially strict control measures. Banks must verify the client’s identity, conduct Customer Due Diligence (CDD) and monitor accounts under KYC rules to prevent money laundering and terrorist financing. Enhanced Due Diligence is mandatory for foreign financial institutions and non-resident individuals.
Asia and the Middle East (video-KYC, e-KYC, local registries)
The Asia-Pacific region demonstrates the most innovative approach to digital identification. Many online financial institutions in India now verify users’ identities through the country’s electronic KYC (eKYC) system — Aadhaar. This biometric system covers more than a billion people and has become a model for other emerging markets.
Singapore and Hong Kong have advanced frameworks, where the Monetary Authority of Singapore (MAS) and the Hong Kong Monetary Authority (HKMA) apply strict protocols, including digital KYC. Video-KYC is widely accepted by the region’s regulators as a full-fledged alternative to physical presence when opening accounts.
Japan requires verifying the client’s name, address and date of birth against official documents in accordance with the Act on Prevention of Transfer of Criminal Proceeds. South Korea has introduced a system of digital certificates for online verification, integrated with government databases.
The Middle East is characterized by a combination of traditional and innovative approaches. The UAE, Saudi Arabia, Qatar, Jordan and Egypt support card deposits with limits of up to AED 18,000 per transaction for users verified through KYC. The region is actively developing local biometric identification providers adapted to the requirements of Islamic banking and local legislation.
Many countries in the region are creating national registries and centralized KYC systems. For example, the UAE is implementing UAE Pass — a single digital identification system for citizens and residents. Saudi Arabia is developing the Absher platform for government and financial services with integrated KYC.
Russia, the CIS and the EAEU when working with foreign clients
In 2025, Russia and the EAEU countries are adapting their KYC systems to the conditions of sanctions pressure and the need to develop alternative financial corridors. Non-resident legal entities or their authorized representatives who have passed identification at a foreign bank on behalf of a Russian bank have the right not to be present in person when opening an account in the Russian Federation.
The RF Government has approved a list of countries whose non-residents may undergo remote identification to conduct financial operations on the territory of Russia. This creates a basis for developing cross-border financial services within friendly jurisdictions.
Since the beginning of 2020, repatriation requirements have been abolished for foreign trade contracts whose debt amount is denominated in rubles for certain categories of goods. This simplification substantially eases work with non-residents from friendly countries, reducing the administrative burden on business.
For citizens of the EAEU countries, preferential tax regimes and simplified identification procedures apply. Workers from the EAEU countries are subject to personal income tax at a rate of 13% regardless of tax residency status, which creates more favorable conditions for labor migration and doing business.
Under sanctions, Russian banks have strengthened the verification of the sources of funds and beneficial ownership for international transactions. Particular attention is paid to identifying hidden ties with unfriendly jurisdictions through complex corporate structures.
Biometric identification is being actively implemented through the Unified Biometric System, which in the future may become the basis for cross-border recognition of digital identity within the EAEU.
Data and documents for online KYC of foreigners in 2025
Online identification of international clients requires a clear understanding of what data and documents are needed to comply with the global standards of 2025. Regulators are introducing increasingly strict requirements for protecting client data and ensuring that KYC information is used strictly for its intended purpose. When working with non-residents, the volume of required information substantially exceeds the standard set for residents, which is due to the elevated risks of cross-border operations and the difficulty of verifying foreign data sources.
The mandatory set of data for non-resident individuals
The basic requirements for identifying non-resident individuals in 2025 are unified on the basis of FATF recommendations, but each jurisdiction supplements them with its own requirements. The process includes confirming the client’s identity using reliable documents such as passports, driver’s licenses or national identity cards.
Identification data and the identity document
The initial identification of a non-resident begins with verifying the main identity document. For non-residents, the main document is a valid international passport with a photograph. The system must recognize and verify passports from more than 200 countries, including the machine-readable zone (MRZ) and security features.
The following are mandatory to record: the full name according to the document in Latin script and in national transcription, the date and place of birth, the document series and number, the issuing authority, the date of issue and the expiration date. For citizens of countries with a non-Latin alphabet, an official transliteration of the name is required. If there are several citizenships, the data of all passports is recorded.
Biometric verification has become a mandatory element: the client’s selfie is matched with the photo in the document through face recognition algorithms with an accuracy of no less than 99%. The liveness check (liveness detection) protects against the use of photographs or video recordings instead of the real presence of a person.
Address, tax status, citizenship and country of birth
Financial institutions usually request confirmation of both the foreign residential address and the address in the country where the business operates. To confirm the address, utility bills no older than three months, bank statements from international banks, and a residence permit from local authorities are accepted.
Tax status is determined through the tax identification number (TIN) of the country of residence. In its absence, an official explanation of the reasons and alternative confirmations of tax residency are required. For US citizens, it is mandatory to indicate the social security number (SSN) or individual taxpayer identification number (ITIN) as part of the FATCA requirements.
Information about citizenship includes all held citizenships with the dates of acquisition. For persons with OCI (Overseas Citizen of India) or PIO (Person of Indian Origin) cards, a copy of the relevant card is required together with the foreign passport. The country of birth is recorded separately from citizenship to identify potential ties with high-risk jurisdictions.
Information about the source of funds and the source of wealth
EDD requires verifying the legitimacy of the source of funds and the source of wealth for all non-residents. The source of funds is confirmed by documents on current income: salary certificates, contracts, dividend payments, documents on the sale of assets. The confirmation period is a minimum of the last 6 months.
The source of wealth covers the history of capital accumulation: inheritance, entrepreneurial activity, investments, real estate. Documentary confirmation of the origin of substantial assets above the established thresholds (usually from USD 100,000) is required.
When discrepancies are identified between the declared income and the volume of operations, additional documents are requested: tax returns for the last 2-3 years, audited financial statements, bank reference letters.
The mandatory set of data for foreign legal entities
Verifying foreign companies presents a particular challenge due to the differences in the corporate law of different countries and multi-level ownership structures. FATF and other regulatory bodies have identified sectors vulnerable to money laundering and terrorist financing that require enhanced KYC procedures.
Registration documents, ownership structure and UBO
The basic package of registration documents includes:
- a certificate of incorporation (Certificate of Incorporation),
- constituent documents (Articles of Association, Memorandum),
- an extract from the trade register no older than 30 days.
All documents must be apostilled or legalized by a consulate and translated into the language of the country of business by a certified translator.
It is generally accepted that the ultimate beneficial owner (UBO) is a person who owns more than 25% of the company’s shares or controls more than 25% of the voting rights. The ownership structure is disclosed down to the individuals through all levels of holding companies. For each intermediate legal entity, a minimum set of registration documents is required.
The verification process includes confirming the identity of potential UBOs through official identification documents such as passports or driver’s licenses. Each identified UBO undergoes the full KYC procedure as an individual with additional verification of the sources of wealth.
For complex structures with cross-ownership or cyclical ties, a detailed ownership diagram certified by an auditor or legal consultant is required. Nominal ownership must be disclosed with an indication of the real beneficiaries and the documents confirming the nominee agreements.
Confirmation of real presence and business activity in the country
The real presence of a business is confirmed by documents on the lease or ownership of office premises, utility bills in the company’s name, and documents on the number of staff and the payroll fund. Companies without a physical presence (virtual offices) are subject to enhanced verification.
Business activity is verified through: licenses to conduct activity in the relevant jurisdiction, contracts with counterparties, financial statements for the last reporting period, bank statements with turnover. The volume and nature of operations must correspond to the declared business profile.
For holding companies and SPVs (Special Purpose Vehicles), justification of the business model and the economic feasibility of the structure is required. The absence of operational activity is not grounds for refusal but requires additional risk analysis.
Undergo individual verification. The following are required: passport data, confirmation of residential address, and a CV describing experience and qualifications. Special attention is paid to politically exposed persons (PEPs), their close partners or family members.
Is conducted against international databases covering all levels: international organizations, national governments, regional administrations, state corporations. The identification of a PEP automatically moves the client to the high-risk category with the application of EDD.
Who are not formal owners or directors (shadow directors) are identified through an analysis of powers of attorney, management agreements, and corporate decisions. Their identification is critical for understanding the real management structure of the company.
Additional documents and checks for clients from high-risk and sanctioned jurisdictions
Clients from countries designated by FATF as high-risk, or those subject to economic sanctions, require expanded due diligence. The list of high-risk jurisdictions is updated by FATF three times a year and includes countries with insufficient anti-money-laundering measures.
Additional requirements include:
- a detailed business dossier describing all types of activity over the last 3 years,
- audited financial statements by international audit firms,
- bank references from financial institutions with a rating of no lower than investment grade,
- a legal opinion on legal capacity and trustworthiness from an international law firm.
Sanctions list screening covers all applicable regimes: the UN, the US (OFAC), the EU, the UK, and local sanctions lists. Screening is carried out not only for an exact match but also for the similarity of names, addresses, and identification numbers, taking into account possible spelling variations.
Adverse media monitoring is carried out across international and local sources in all relevant languages. The temporal depth of the check is a minimum of 7 years. Any mentions in the context of financial crimes, corruption, or sanctions violations require a detailed investigation.
Transactional analysis for clients from high-risk jurisdictions involves the prior agreement of expected volumes and directions of payments, the justification of each transaction above the established limits, and monthly reporting on the operations conducted. Modern AI-based systems make it possible to automate most of these checks, ensuring the processing of documents from 200+ countries in seconds while maintaining verification accuracy at 98-99%.
How to build a KYC process for international clients online: the 2025 scheme
Working with international clients requires a fundamentally different approach to building the KYC process. In 2025, it is not enough to simply adapt existing procedures — a comprehensive architecture is needed that takes into account multi-jurisdictional requirements, technological capabilities, and the specifics of remote verification.
An effective KYC process for non-residents is built on three fundamental principles: a risk-based approach, maximum automation, and compliance with the requirements of all applicable jurisdictions. Each stage must be configured to work with documents from different countries and various data formats, and to take into account the cultural specifics of clients.
Preliminary assessment of the jurisdiction, product and service channel risk
Risk assessment begins even before the first contact with the client. In 2025, regulators require preliminary scoring on three key parameters, each of which affects the depth of the subsequent checks.
Jurisdictional risk is determined through an analysis of the client’s country of residence, citizenship and actual location. High-risk jurisdictions include those on FATF’s lists (grey and black), countries under international sanctions, and offshore zones with an opaque ownership structure. For clients from such jurisdictions, expanded verification (EDD) is automatically applied with additional requirements for documents and sources of funds.
Product risk depends on the type of services the client plans to use. Payment services, cryptocurrency operations, international transfers and private banking are high-risk products. For such products, lower thresholds for transaction monitoring and a more frequent periodicity of updating KYC data are set.
The service channel determines the technical requirements for the identification process. Fully remote onboarding without physical presence requires mandatory biometric verification with a liveness check. At the same time, EU regulators, from July 2025, allow the use of a qualified electronic signature (QES) as an alternative to video identification for citizens of member states.
Based on the combination of these three factors, a client risk matrix is formed that determines the necessary level of checks: simplified (SDD), standard (CDD) or enhanced (EDD). An automated risk-scoring system makes it possible to instantly categorize a client and apply the appropriate verification scenario.
Online KYC onboarding of foreigners: a step-by-step scenario
The process of onboarding international clients in 2025 is a clearly structured sequence of automated checks with minimal human involvement. The entire process takes from 3 to 15 minutes depending on the complexity of the case.
Collecting the application and consents to the processing of personal data
The first step is critically important from the standpoint of regulatory compliance. The application form must be adapted to the client’s jurisdiction and take into account language requirements and local data protection legislation.
For clients from the EU, compliance with GDPR is mandatory, with explicit consent to each type of data processing, the right to be forgotten and data portability. American clients must be notified about the transfer of data in accordance with the California Consumer Privacy Act (CCPA) and other state regulations. For clients from the Asia-Pacific region, local requirements apply — from the PDPA in Singapore to the PIPL in China.
The system automatically determines the applicable legislation by IP address, the indicated country of residence and citizenship, forming the appropriate set of consents. All consents are recorded with timestamps and stored in an immutable form for subsequent audit.
Uploading and automatic document recognition (AI-OCR, IDP)
Modern intelligent document processing (IDP) systems are capable of recognizing more than 10,000 document types from 200+ countries. In 2025, multimodal verification became the standard, including optical character recognition, analysis of security features and verification of the machine-readable zone (MRZ).
Deep-learning-based algorithms extract all the necessary data: name, date of birth, document number, expiration date, registration address. In parallel, the document’s authenticity is checked through an analysis of holograms, watermarks, microtext and other security features. Recognition accuracy reaches 99.85% even for low-quality documents or those photographed at an angle.
For passports with an NFC chip, biometric data is additionally read directly from the chip, which rules out the possibility of forgery. The system automatically cross-checks the data from the visual zone of the passport with the information from the chip, revealing any discrepancies.
Biometric identification: selfie, liveness, comparing the face with the document
Biometric verification has become a mandatory element of remote KYC for non-residents. The process includes three key components that provide reliable protection against fraud.
The liveness check (liveness detection) uses a combination of passive and active methods. The passive check analyzes micro-movements, skin texture, reflections in the eyes. The active one requires the performance of random actions: turning the head, blinking, smiling. Modern algorithms detect attempts to use photographs, video recordings, masks and even deepfake with 99.9% accuracy.
Matching the face with the document is performed through neural network algorithms that are robust to changes in lighting, angle, age-related changes and accessories. The system takes into account the ethnic features of facial geometry, ensuring the same accuracy for representatives of all races. The false acceptance threshold is set at the level of 1:1,000,000, which corresponds to the requirements of the banking sector.
The entire biometric verification process takes less than 30 seconds and does not require installing additional applications — it works directly in the browser through WebRTC.
Checking against sanctions lists, PEP, adverse media and global KYC databases
Screening against international databases happens in parallel with biometric verification. The system checks the client against 1,700+ sanctions lists, including OFAC, UN, EU, UK and the local lists of individual jurisdictions.
PEP status verification covers not only the client themselves but also their immediate relatives and business partners. The database includes more than 2 million profiles of politically exposed persons, updated in real time. Fuzzy-search algorithms take into account various options for the transliteration of names, aliases, and maiden names.
Adverse media monitoring uses natural language processing technologies to analyze news sources in 90+ languages. The system filters out irrelevant matches, highlighting only significant risks: accusations of money laundering, corruption, fraud, sanctions violations.
Global KYC databases make it possible to obtain additional information about the client: address confirmation, credit history, court cases. Integration with international data sources significantly speeds up the verification process and improves the quality of the check.
Ongoing monitoring of international clients: periodic review, triggers and profile updates
Continuous monitoring of non-resident clients requires a more complex configuration than for local clients. In 2025, regulators tightened the requirements for the frequency of data updates and expanded the list of trigger events for an out-of-schedule check.
Is determined by the client’s risk level: high-risk profiles are checked quarterly, medium risk every six months, low risk annually. For clients from FATF jurisdictions or under sanctions, monthly monitoring is applied regardless of other risk factors.
Include a change in the sanctions status of the client’s country, appearance in negative news, a sharp change in transactional behavior, or an attempt to conduct an operation into a high-risk jurisdiction. The system automatically initiates the KYC update procedure when any of the 40+ preset triggers fires.
Can occur either in a simplified mode (confirming the relevance of the data) or through a full re-verification cycle. When documents, address or beneficial owners change, the provision of supporting documents and passing a biometric check are required.
The key advantage of automated monitoring is the ability to proactively manage risks. The system notifies in advance about the approaching expiration of documents, changes in sanctions lists, and the need to update data. This makes it possible to maintain continuity of service and avoid sudden account blocks, which is critically important for international business.
Technical and organizational requirements for the KYC process for international and non-resident clients in 2025
Working with non-residents and international clients requires a fundamentally different approach to building the KYC infrastructure. Companies face the need to simultaneously comply with the requirements of several jurisdictions, ensure the protection of personal data during cross-border transfer, and integrate technologies capable of working with the documents and biometric data of clients from 200+ countries. The technical and organizational aspects become critically important for ensuring the continuity of processes, minimizing risks, and maintaining a high level of conversion when onboarding international clients.
Requirements for data protection and cross-border transfer (GDPR and local personal data laws)
The cross-border transfer of personal data within KYC processes is regulated by a set of international and local norms, non-compliance with which entails fines of up to 4% of the company’s annual turnover. GDPR remains the basic standard for working with European clients and requires the mandatory application of one of the mechanisms for legalizing data transfer: a European Commission adequacy decision, standard contractual clauses (SCC 2021), or binding corporate rules (BCR).
Local personal data laws impose additional restrictions. China requires a security assessment before any transfer of data abroad under the PIPL. Russia insists on the primary storage of citizens’ data on the territory of the country (Federal Law 152-FZ). Since August 2023, India has been applying the Digital Personal Data Protection Act, which allows cross-border transfer only to countries approved by the government. Brazil, through the LGPD, effectively duplicates the European requirements with minor national specifics.
Technically, companies must implement a multi-level data storage architecture with the possibility of geographic separation. Encryption in transit (minimum TLS 1.3) and at rest (AES-256) is becoming a mandatory standard. Systems must support the automatic deletion of data after the expiration of the retention periods, which vary from 5 years in the EU to 10 years in some Asian jurisdictions. Data subjects’ rights — access, correction, deletion, portability — must be technically implemented for all categories of clients regardless of their location.
e-KYC automation 2025: biometrics, video identification and global data sources
Technically, companies must implement a multi-level data storage architecture with the possibility of geographic separation. Encryption in transit (minimum TLS 1.3) and at rest (AES-256) is becoming a mandatory standard. Systems must support the automatic deletion of data after the expiration of the retention periods, which vary from 5 years in the EU to 10 years in some Asian jurisdictions. Data subjects’ rights — access, correction, deletion, portability — must be technically implemented for all categories of clients regardless of their location.
For non-residents, includes a mandatory liveness check (liveness detection) with 99.9% accuracy and comparing the face with the photo in the document. Systems must work correctly with different anthropological types and take into account the specifics of lighting and camera quality in different regions.
Mandatory in Germany for financial services and recommended in India for high-risk transactions, requires the recording and storage of video sessions with the possibility of automatic analysis and the detection of signs of fraud.
Implies connecting to international sanctions lists (UN, OFAC, EU, UK), PEP databases (more than 3 million profiles), adverse media, and the national registries of various countries.
APIs must process requests taking into account the transliteration of names, various formats of dates and addresses, and national identifiers. Systems must support real-time verification with a response of less than 100 milliseconds to maintain an acceptable user experience.
Infrastructure scalability is critical when working with international clients: systems must withstand peak loads of up to 10,000 requests per minute, support horizontal scaling, and ensure availability at the level of 99.9%. Multilingual interfaces and documentation are a mandatory requirement, and the translation must take into account the legal and cultural specifics of each region.
Documentation, reporting and the role of the compliance officer when working with non-residents
Documenting KYC processes for international clients requires keeping detailed records of each verification stage, including timestamps, check results, decisions made and their justifications. The audit trail must be retained in an unchanged form for a minimum of 5 years after the end of the business relationship, and in some jurisdictions up to 10 years. Systems must automatically generate reports for regulators in formats that comply with local requirements: XML for FinCEN, specialized formats for European FIUs, structured files for Asian regulators.
When working with non-residents, the compliance officer performs an expanded set of functions. In addition to standard control over compliance with procedures, they must track changes in the legislation of all jurisdictions where clients are present, coordinate interaction with local regulators, and manage the risks associated with differences in legal systems. It is mandatory to develop and maintain a risk matrix by country and product, regularly train staff in the specifics of working with documents from various countries, and conduct internal audits with a focus on cross-border operations.
Policies and procedures must cover specific scenarios: working with clients from high-risk jurisdictions, the specifics of verifying diplomatic personnel and international organizations, and escalation procedures when discrepancies are identified in foreign clients’ documents. Separate attention is paid to enhanced due diligence (EDD) procedures for clients from countries not on FATF’s “white lists”, with mandatory documentation of the sources of funds and wealth.
The incident management system must take into account the international context: different time zones for prompt response, language barriers when communicating with clients, and the specifics of interacting with the law enforcement agencies of various countries. Regular reporting to the board of directors must include metrics on the geographic distribution of risks, the effectiveness of KYC procedures for various categories of non-residents, and statistics on refusals and their reasons broken down by jurisdiction.
A KYC checklist for international clients and non-residents for 2025
An effective KYC system for international clients requires a systematic approach and regular auditing of all components of the process. The checklists presented will help assess your organization’s readiness to work with non-residents and identify areas that need improvement in line with the current 2025 requirements.
A checklist of KYC/EDD processes and policies
| Basic policies and procedures: | – A KYC policy has been approved with a separate section for non-residents and international clients – Criteria have been defined for classifying clients into resident/non-resident categories in accordance with local legislation and international standards – A risk matrix has been drawn up taking jurisdictions into account (a minimum of 3 levels: low, medium, high) – Clear triggers have been established for the transition from standard KYC to enhanced due diligence (EDD) – The procedure for working with clients from FATF Grey List and Black List jurisdictions has been defined |
| Identification and verification procedures: | – A process for recognizing and verifying international documents has been implemented (passports, ID cards, driver’s licenses of at least 50 countries) – A procedure has been set up for verifying the authenticity of documents through apostille or consular legalization for high-risk jurisdictions – Biometric verification has been organized with support for various types of documents – Verification of non-residents’ addresses through international databases and alternative sources has been implemented |
| Enhanced due diligence (EDD): | – A list of additional documents for EDD has been approved (account statements, tax returns, contracts) – A procedure has been implemented for verifying the source of funds and the source of wealth – A process has been set up for identifying ultimate beneficial owners (UBO) with an ownership threshold in accordance with local regulation – Enhanced monitoring of high-risk clients’ transactions has been organized |
| Monitoring and data updates: | – The frequency of reviewing non-resident profiles has been established (no less than once every 12 months for standard risk) – Automatic monitoring of changes in sanctions lists and PEP status has been implemented – Alerts have been set up for changes in a client’s risk profile or their jurisdiction – A process has been organized for documenting all checks and decisions on a client |
A checklist of client data and documents
| Mandatory data for non-resident individuals: | – Full name in Latin script and in the original spelling – Date and place of birth with the country indicated – Citizenship (primary and additional, if any) – The series, number and expiration date of the identity document – The permanent residential address in the country of residence – The tax identification number (TIN) of the country of residence – Contact details (phone with an international code, email) – Occupation and the name of the employer |
| Mandatory data for non-resident legal entities: | – The full name in the language of registration and in English – The registration number and date of registration – The legal address in the country of registration – The actual address where the business operates – The tax number in the country of registration – Activity classification codes (OKVED, NAICS, SIC) – The ownership structure down to the ultimate beneficiaries (a threshold of 10% or in accordance with local regulation) – Data of the directors and persons with signing authority |
| Documents for a standard check: | – A scan of a passport or ID card with a machine-readable zone (MRZ) – Address confirmation no older than 3 months (utility bills, bank statements) – The client’s selfie for biometric verification – A completed KYC questionnaire with the client’s signature |
| Documents for enhanced due diligence (EDD): | – An income certificate or a tax return for the last year – Bank statements for 3-6 months from the main accounts – Documents confirming the source of the initial capital – Letters of recommendation from banks or professional advisors – For legal entities: financial statements for the last 2 years |
A checklist of the technological infrastructure and global KYC providers
| Technology base: | – An automatic document recognition system (AI-OCR) has been implemented with support for at least 100 types of international documents – A biometric system has been set up with liveness-detection algorithms and a comparison accuracy of no less than 99% – Integration with an API for real-time document verification has been implemented – Secure data storage has been ensured with encryption in accordance with the AES-256 standards – A system for managing consents to the processing of personal data has been implemented |
| Data sources and checks: | – International sanctions lists have been connected (UN, OFAC, EU, UK at a minimum) – Access to global PEP databases with coverage of at least 200 countries has been set up – Verification against Interpol and international law enforcement databases has been organized – Adverse media checking services in several languages have been connected – Address verification through global postal databases has been set up |
| Compliance and reporting: | – The system complies with GDPR requirements for processing the data of EU citizens – Logging of all actions with the possibility of auditing has been implemented – Automatic generation of reports for the regulator has been set up – A data storage mechanism has been implemented in accordance with the requirements of the jurisdiction (usually 5-7 years after the termination of relations) – Backup has been organized with recovery in no more than 4 hours |
| Scaling and performance: | – The system processes at least 100 applications per hour without loss of performance – The time for a full client check does not exceed 5 minutes for standard KYC – The API supports simultaneous work with several jurisdictions – The ability to configure individual verification scenarios for different products has been implemented – System availability of 99.9% (SLA) has been ensured |
Regularly going through all the items on the checklists will make it possible to keep the KYC system up to date and ensure compliance with international requirements. Automating key processes through specialized platforms substantially simplifies meeting most of the requirements and reduces operational risks when working with international clients.
Verifying non-residents and foreign clients requires companies not only to understand the basic principles of KYC but also to have a deep knowledge of international standards, regional regulatory specifics, and the ability to quickly adapt to changing compliance requirements. Successful work with an international audience is impossible without automated solutions capable of verifying documents from hundreds of jurisdictions in real time, conducting biometric identification with protection against forgery, and ensuring the continuous monitoring of customers against global databases. Companies that have built an effective KYC process for non-residents gain a competitive advantage: accelerated onboarding, the minimization of fraud and sanctions-violation risks, and scalability to new markets without a critical increase in operating costs.
Implementing a comprehensive KYC platform that covers all stages — from automatic document recognition and liveness checks to continuous screening against international lists — makes it possible for a business to comply with the 2025 requirements and confidently serve customers from anywhere in the world.