How to build a KYC policy compliant with Federal Law 115-FZ, Federal Law 152-FZ, FATF and GDPR

The choice of a biometric data storage model in KYC systems determines a company's risk profile, the level of control over information, and compliance with regulatory requirements. Local hosting provides full autonomy and protection against cross-border transfers, but requires one's own infrastructure and cybersecurity expertise. Cloud solutions speed up implementation and simplify scaling, while creating dependence on the provider and questions about the jurisdiction of the data. In this article we break down where biometrics is physically stored in both models, what requirements Federal Law 152-FZ and GDPR impose, compare the threat profiles of each approach, and provide criteria for choosing the optimal strategy for a specific business.

The requirements for customer identification and countering money laundering affect a significantly wider range of organizations than is commonly believed. The obligations to conduct KYC procedures arise not only for banks but for a wide range of companies that work with funds, digital assets, or provide financial services.

Types of companies and operations that fall under AML/KYC legislation

In the Russian legal field, the entities subject to Federal Law 115-FZ are recognized as organizations that carry out operations with funds or other property. These include credit institutions, professional participants in the securities market, insurance companies, non-state pension funds, pawnshops, leasing companies, payment acceptance operators, and factoring organizations.

With the development of the digital economy, financial platform operators, investment platform operators, operators of information systems in which digital financial assets are issued, and operators for the exchange of digital financial assets have come under regulation. Microfinance organizations, consumer cooperatives, and gambling organizers are also obliged to identify customers.

The legislation pays special attention to operations with real estate and precious metals. Real estate agencies when carrying out real estate purchase and sale transactions of 3 million rubles or more, postal organizations when transferring funds, and jewelry stores in operations with precious metals and stones are obliged to identify customers.

At the international level, the requirements extend to cryptocurrency exchanges, crowdfunding platforms, P2P money transfer services, and virtual asset service providers (VASP). In the European Union’s jurisdiction, trust companies, notaries, lawyers when conducting financial operations for clients, auditors, and tax consultants fall under the regulation.

The threshold values of operations vary depending on the type of activity: for banking operations — from 600,000 rubles for individuals and from 3 million rubles for legal entities when withdrawing cash; for real estate operations — from 3 million rubles; for the purchase of securities in cash — from 600,000 rubles. At the same time, organizations have the right to set lower identification thresholds under their internal control rules.

The main sources of requirements: Federal Law 115-FZ, Federal Law 152-FZ, the FATF recommendations, GDPR

Federal Law No. 115-FZ “On Countering the Legalization (Laundering) of Proceeds Obtained by Criminal Means and the Financing of Terrorism” forms the basis of Russian AML regulation. The law defines the range of entities, establishes mandatory procedures for identifying, verifying and updating customer data, and the requirements for internal control and the transfer of information to Rosfinmonitoring. For failure to meet the requirements, fines of up to 1 million rubles for organizations and the suspension of operations for up to 90 days are provided.

Federal Law No. 152-FZ “On Personal Data” governs the processing of personal data when conducting KYC. The law establishes the legal grounds for collecting biometric data, the requirements for protecting information, the procedure for cross-border transfer, and the rights of personal data subjects. In January 2025, amendments came into force that tighten the requirements for the localization of the data of RF citizens and strengthen control over its cross-border transfer.

The FATF (Financial Action Task Force) recommendations represent the international standard in the field of AML/CFT, recognized by 200+ jurisdictions. The 40 FATF recommendations cover the risk-based approach to identification, customer due diligence measures (Customer Due Diligence), the enhanced verification of politically exposed persons (PEP), and the requirements for data storage and internal control. Russia, as a member of FATF, is obliged to implement these standards in national legislation.

The General Data Protection Regulation (GDPR) applies to any company processing the data of EU residents, regardless of the location of the company itself. The regulation establishes the principles of data minimization, the limitation of processing purposes, and the requirements for documenting processes and obtaining consents. Fines for violating GDPR reach EUR 20 million or 4% of the company’s annual turnover. When conducting KYC for European clients, it is necessary to balance between the mandatory identification requirements and subjects’ rights to the deletion of data, which creates a legal conflict between AML obligations and privacy rights.

National regulators are constantly strengthening the requirements: in 2024 the Bank of Russia introduced mandatory biometric identification for a number of operations, and from July 2025 new requirements for identifying beneficial owners come into force. International sanctions regimes also affect KYC procedures, requiring the checking of customers against the OFAC, UN, and EU lists and national lists of extremists and terrorists.

KYC requirements of Federal Law 115-FZ: who is obliged to comply and what data to collect

Federal Law No. 115-FZ forms the legal foundation of the system for countering money laundering in Russia. The law establishes specific obligations for customer identification for a wide range of organizations, defines the volume of information collected, and governs the procedures for its processing. Failure to comply with these requirements entails substantial financial and reputational risks.

Entities subject to Federal Law 115-FZ and cases when customer identification is mandatory

Article 5 of Federal Law 115-FZ defines an exhaustive list of organizations obliged to conduct identification. These include credit institutions, professional participants in the securities market, insurance and leasing companies, telecom operators when providing mobile communication services, microfinance organizations, credit consumer cooperatives, pawnshops, payment acceptance operators, gambling organizers, and lottery operators.

Since 2024, financial platform operators, investment platform operators, and operators for the exchange of digital financial assets have been added to the entities subject to Federal Law 115-FZ. Cryptocurrency exchanges and exchangers working with Russian customers are also obliged to comply with the requirements of the law after the amendments on digital currencies came into force.

Identification becomes mandatory when concluding a bank account or deposit agreement, carrying out operations with funds in the amount of 15,000 rubles or more (for postal transfers — from 50,000 rubles), and real estate operations exceeding 3 million rubles. For currency exchange operations, the threshold is the equivalent of 40,000 rubles, for the purchase of securities in cash — 200,000 rubles.

Organizations are obliged to identify the customer regardless of the amount of the operation if there are suspicions of the legalization of proceeds or the financing of terrorism. This requirement extends to any unusual transactions that do not correspond to the customer’s objectives or that have no obvious economic sense.

The mandatory volume of data on customers, representatives, beneficiaries, and beneficial owners

Bank of Russia Regulation No. 499-P establishes the minimum list of information for identifying individuals: surname, first name, patronymic (if any), date of birth, details of the identity document, migration card data and the document confirming the right to stay in the Russian Federation for foreign citizens, address of residence or stay, INN (if any), SNILS, and contact information.

For legal entities, the mandatory items are the name, INN, OGRN, address of location, and information about licenses for the right to carry out activities subject to licensing. Additionally, information is established about the purposes of establishing the business relationship, the expected nature of the relationship, the financial position, the business reputation, and the sources of origin of the funds.

Particular attention is paid to establishing beneficial owners — individuals who directly or indirectly own more than 25% of the capital of the legal entity client or are able to control its actions. If it is impossible to identify the beneficial owner, the sole executive body is recognized as such.

Since January 2025, changes have come into force obliging organizations to establish whether customers and their beneficiaries belong to public officials (PEPs), including foreign PEPs, officials of public international organizations, as well as their spouses, close relatives, and related persons.

The procedure for identifying, verifying and updating KYC data under Federal Law 115-FZ

Identification is carried out on the basis of original documents or duly certified copies. For individuals, the main document is the passport of an RF citizen, for foreign citizens — a foreign state passport with entry marks or a migration card.

Simplified identification is allowed for operations without opening an account in the amount of up to 15,000 rubles, and for transfers without opening an account of up to 200,000 rubles per month provided that the customer passes remote identification through the Unified Identification and Authentication System (ESIA) or the Unified Biometric System (UBS).

The process part
01

Organizations are obliged to update information about customers at least once a year for an elevated degree of risk, and at least once every three years for a standard degree of risk. For a low degree of risk, updating is carried out when doubts arise about the accuracy of the available information. The updating of data is also required when the customer’s identification information changes.

02

Verification involves confirming the accuracy of the obtained data using original documents, information from reliable sources, and cross-checking of information. Since 2024, organizations have been obliged to check the validity of RF citizens’ passports through the services of the Russian MVD.

The requirements of Federal Law 115-FZ for storing KYC documents and information

Documents that are the basis for conducting operations and identification information on customers are subject to storage for five years from the day the relationship with the customer ends. Information about the movement of funds on accounts and about customers’ operations is also stored for five years from the date the operation was made.

Storage is carried out in a form that makes it possible to reproduce the documents unchanged. Storage in electronic form is allowed provided that a qualified electronic signature is used and the requirements for information protection are met. Documents must be available for provision to authorized bodies within five business days of receiving a request.

Organizations are obliged to ensure the confidentiality and protection of the stored information from unauthorized access, copying, and dissemination. At the same time, the possibility of promptly searching for and providing documents upon requests from Rosfinmonitoring and law enforcement agencies must be ensured.

Upon the termination of an organization’s operations, documents are transferred for storage to the state archive or to a legal successor. The destruction of documents before the expiration of the established storage periods entails administrative liability.

Liability and sanctions for violating the KYC requirements of Federal Law 115-FZ

Administrative liability under Article 15.27 of the Code of Administrative Offenses of the Russian Federation provides for fines for officials of 30 to 50 thousand rubles, for legal entities — from 400 thousand to 1 million rubles for failure to comply with the requirements of legislation in the field of AML/CFT. A repeat violation entails the disqualification of officials for up to three years and the suspension of the organization’s operations for up to 90 days.

Failure to submit information to Rosfinmonitoring entails a fine of 200 to 400 thousand rubles for organizations, and 20 to 30 thousand for officials. For disclosing information about the measures being taken to counter the legalization of proceeds, a fine of up to 50 thousand rubles for citizens and up to 500 thousand for legal entities is provided.

The Bank of Russia has the right to restrict or prohibit individual operations of a credit institution, introduce a ban on attracting funds from individuals, and revoke a license in case of the systematic violation of the requirements of Federal Law 115-FZ. For non-credit financial organizations, orders to eliminate violations, the restriction of a license, and exclusion from the register are provided.

Criminal liability under Article 174.1 of the Criminal Code of the Russian Federation arises for the legalization of funds acquired by a person as a result of committing a crime, and provides for imprisonment of up to seven years with a fine of up to 1 million rubles. Failure to fulfill control obligations may be qualified as complicity in the legalization of criminal proceeds if intent is proven.

Rosfinmonitoring maintains a list of organizations and individuals in respect of whom there is information about their involvement in extremist activity or terrorism. Inclusion in this list entails the blocking of accounts and the impossibility of conducting operations until exclusion from the list.

KYC and Federal Law 152-FZ: how to legally process personal data during identification

KYC procedures are inextricably linked with the processing of customers’ personal data — passport data, biometric characteristics, contact information, and information about property and income. At the same time, companies implementing KYC systems face dual regulation: on the one hand, Federal Law 115-FZ obliges them to collect and store a certain volume of information about customers, and on the other, Federal Law 152-FZ imposes strict restrictions on the processing of personal data. Let’s break down how to strike a balance between these requirements and avoid fines from Roskomnadzor.

Federal Law No. 152-FZ of 27.07.2006 “On Personal Data” requires a legal ground for any processing of personal data. In the context of KYC, there may be several such grounds, and the choice of a specific ground depends on the organization’s status and the nature of its activity.

For entities subject to Federal Law 115-FZ (banks, insurance companies, payment agents, microfinance organizations), the main legal ground is the fulfillment of an obligation provided for by law (clause 2, part 1, Article 6 of Federal Law 152-FZ). The anti-money-laundering law directly obliges these organizations to identify customers, verify their data, and store the corresponding information for five years. This means that the customer’s consent to the processing of personal data as part of mandatory identification is not required — it is enough to notify them of the fact and purposes of the processing.

Companies that are not entities subject to Federal Law 115-FZ but implement KYC for risk management (marketplaces, crypto exchanges, online services) rely on the performance of a contract (clause 5, part 1, Article 6 of Federal Law 152-FZ) or the operator’s legitimate interest. When using legitimate interest, the organization must justify the need for KYC checks to protect against fraud, prevent financial losses, or ensure the security of the platform. It is important to document this justification and conduct a balancing-of-interests assessment — customers’ rights to privacy must not be violated disproportionately.

For the processing of biometric data (face recognition, fingerprints), stronger legal grounds are required. According to Article 11 of Federal Law 152-FZ, biometrics can be processed only with the written consent of the subject or in cases provided for by the legislation on countering terrorism and extremism. Since July 2024, changes have come into force allowing the processing of biometric data for a one-time entry to the organization’s premises without consent, but for permanent identification in KYC systems, consent remains mandatory.

The requirements of Federal Law 152-FZ for notification, the processing policy, and the appointment of a responsible person

Before starting the processing of personal data as part of KYC, an organization is obliged to fulfill a number of organizational requirements established by Federal Law 152-FZ.

Notifying Roskomnadzor is the first mandatory step. Before starting the processing of personal data, the operator must send a notification to the territorial office of Roskomnadzor containing information about the purposes of processing, the categories of subjects and personal data, the processing periods, and the protective measures. For KYC systems, it is important to correctly state the purposes: “identification and verification of customers”, “fulfillment of the requirements of legislation on countering the legalization of proceeds”, “prevention of fraudulent operations”. The notification is submitted through the Roskomnadzor portal and is reviewed within 30 days. Failure to submit a notification entails a fine of up to 75 thousand rubles for legal entities.

The personal data processing policy must be developed and published on the organization’s website before data collection begins. In the policy for KYC processes, it is necessary to reflect: the legal grounds for processing for each category of data; the volume of data collected (full name, passport data, SNILS, INN, biometrics); the purposes of using each category of data; the storage periods (a minimum of 5 years for entities subject to Federal Law 115-FZ); the procedure for destroying data after the periods expire; the information protection measures; the rights of subjects and the procedure for exercising them; the contacts of the person responsible for personal data processing.

The appointment of a person responsible for organizing the processing of personal data is mandatory for all operators since September 1, 2022. The responsible person coordinates work with personal data, monitors compliance with legal requirements, and interacts with Roskomnadzor and personal data subjects. In the context of KYC, the responsible person must also ensure the consistency of the identification procedures with the requirements of Federal Law 115-FZ and the internal AML/CFT rules.

Requirements for security, storage, and access restriction for KYC data

KYC data belongs to the category of personal data requiring enhanced protection. RF Government Decree No. 1119 establishes four levels of personal data security. For typical KYC systems processing the data of more than 100,000 subjects, the second level of security (UZ-2) applies, requiring a set of organizational and technical measures.

Technical protective measures include the use of FSTEC- and FSB-certified information protection tools: firewalls, intrusion detection systems (IDS), antivirus protection tools, integrity control systems. For biometric data, the use of cryptographic protection tools during transmission and storage is mandatory — encryption by GOST or the use of a qualified electronic signature. All actions with KYC data must be recorded in audit logs with the impossibility of their modification during the storage period.

Organizational measures involve differentiating access to data on the principle of minimal necessity. Access to full KYC data is granted only to employees directly performing the identification and verification of customers. Other departments receive access to de-identified or partial data. It is mandatory to maintain a log of persons admitted to processing personal data, indicating the access level and the list of available operations.

The storage requirements establish the mandatory placement of servers with KYC data on the territory of Russia (part 5, Article 18 of Federal Law 152-FZ). Exceptions are cases provided for by international treaties, but for standard KYC procedures localization is mandatory. Backup must be carried out with the same degree of protection as the main storage. After the storage periods expire, the data is subject to guaranteed destruction with the drawing up of a certificate.

Cross-border transfer of personal data in KYC systems

International companies and platforms working with customers from different countries face the need for the cross-border transfer of KYC data. Federal Law 152-FZ establishes strict rules for such transfer, the violation of which can lead to the blocking of operations in Russia.

Countries with an adequate level of protection are the first and simplest option. Roskomnadzor has approved a list of 47 states that provide adequate protection of personal data. It includes EU countries, Canada, Israel, Argentina, New Zealand, and others. When transferring KYC data to these jurisdictions, a standard notification to Roskomnadzor and the inclusion of information about the cross-border transfer in the processing policy are sufficient.

Countries without adequate protection require additional guarantees. To transfer data to the US, China, the UAE, and most other countries, it is necessary to obtain the written consent of the subject for the cross-border transfer, indicating the specific country and the purposes of the transfer. An alternative may be the inclusion in the contract with the foreign partner of obligations to protect personal data in accordance with Russian law, but in practice it is problematic to obtain such guarantees from large international KYC service providers.

The use of international KYC platforms creates additional risks. Many global solutions store data in the cloud infrastructure of Amazon AWS, Microsoft Azure, or Google Cloud, whose servers are located outside Russia. Formally, this violates the requirement to localize the data of Russian citizens. A solution may be a hybrid architecture: primary storage on Russian servers with the transfer abroad of only de-identified data or check results without personal information.

The rights of data subjects and their exercise within KYC

Federal Law 152-FZ grants personal data subjects a wide range of rights that must be observed even during mandatory identification under Federal Law 115-FZ.

The right to access one’s data allows a customer to request information about which of their personal data is processed within KYC, for what purposes, to whom it is transferred, and on what legal ground. The operator is obliged to provide this information free of charge within 30 days. For KYC systems, it is recommended to automate this process through a personal account, where the customer can see the data collected about them and the history of its use.

The right to correct inaccurate data is especially relevant for KYC, where errors can lead to the blocking of operations. A customer has the right to demand the correction or supplementation of their data by providing supporting documents. The operator is obliged to make the changes within 7 business days or to refuse with a justification. At the same time, the change of data must not contradict the requirements of Federal Law 115-FZ on the accuracy of identification information.

The right to delete data (the right to be forgotten) in the context of KYC has substantial limitations. Entities subject to Federal Law 115-FZ cannot delete a customer’s data before the five-year storage period expires, even upon the withdrawal of consent or the termination of contractual relations. However, after this period expires, the data must be destroyed within 30 days if there are no other legal grounds for storage (court disputes, tax audits).

The right to restrict processing allows a customer to demand the cessation of the use of their data for marketing purposes or transfer to third parties not related to KYC checks. This right does not extend to mandatory identification but concerns additional ways of using the data.

Risks and fines for violating Federal Law 152-FZ when conducting KYC

Violation of the requirements of Federal Law 152-FZ when organizing KYC procedures can entail serious sanctions, the size of which grew substantially after the changes to the Code of Administrative Offenses of the Russian Federation in 2024.

Risks and fines for violating Federal Law 152-FZ when conducting KYC
Processing without a legal ground or consent (when it is required)

A fine of 100 to 300 thousand rubles for legal entities. A typical violation: collecting biometric data for KYC without written consent or processing an excessive volume of data not provided for by Federal Law 115-FZ.

Violation of the requirements for personal data protection

A fine of 60 to 100 thousand rubles. This category includes: the absence of technical protection tools of the appropriate level, the violation of the data access procedure, and information leaks through the operator’s fault. For a repeat violation, the fine increases to 500 thousand rubles.

Violation of the localization requirements

A fine of 1 to 6 million rubles for a first violation and from 6 to 18 million for a repeat one. These are the most serious sanctions that can be applied when using foreign KYC platforms without complying with the requirements to store Russians’ data on the territory of the Russian Federation.

Failure to provide information to the subject or to Roskomnadzor

A fine of 40 to 80 thousand rubles. Ignoring customers’ requests to provide information about the processing of their data or failing to provide information at the regulator’s request.

In addition to administrative fines, gross violations can lead to inclusion in the register of violators of the rights of personal data subjects with the subsequent blocking of the website on the territory of Russia. For KYC platforms, this means the effective impossibility of doing business.

It is important to understand that compliance with Federal Law 152-FZ when organizing KYC is not just a formal requirement but a necessary condition for building trusting relationships with customers and protection against reputational risks. A properly built system for processing personal data within KYC makes it possible to simultaneously meet the requirements of anti-money-laundering legislation and ensure customers’ rights to the protection of their personal information.

International FATF KYC standards: key requirements for customer identification

The Financial Action Task Force (FATF) is an intergovernmental organization founded in 1989 on the initiative of the G7, which sets international standards and develops policies to combat money laundering and terrorist financing at the national and international levels. The FATF recommendations, last updated in October 2025, form a comprehensive and consistent system of measures that countries must implement to counter money laundering, terrorist financing, and the proliferation of weapons of mass destruction.

The FATF standards are universal in nature — they have been adopted by more than 200 countries and are recognized as the global benchmark in the field of AML/CFT. For Russian companies working with international clients or planning to enter foreign markets, compliance with the FATF requirements becomes a mandatory condition for successful integration into the global financial system.

The role of FATF and the basic requirements for KYC/Customer Due Diligence

FATF defines Customer Due Diligence as a fundamental element of countering money laundering. FATF Recommendation 10 prohibits financial organizations from keeping anonymous accounts or accounts in fictitious names and establishes mandatory customer due diligence procedures.

CDD measures must be applied when establishing business relations, carrying out one-off operations above the established threshold (USD/EUR 15,000), when there is suspicion of money laundering or terrorist financing, and when there are doubts about the accuracy of previously obtained identification data.

The basic set of Customer Due Diligence measures includes four mandatory components. The first is identifying the customer and verifying their identity using reliable independent sources of documents, data, or information. The second is identifying the beneficial owner and taking reasonable measures to verify their identity, so that the financial organization is confident about who the ultimate beneficiary is. The third component requires understanding and obtaining information about the purposes and expected nature of the business relationship. The fourth element is the ongoing monitoring of the business relationship and the thorough scrutiny of operations to ensure their correspondence to the organization’s knowledge of the customer.

Image

The interpretive note to Recommendation 10 develops in detail the concepts of risk factors in relationships with customers, persons acting on behalf of the ultimate beneficiary, and special provisions for life insurance policies. If a financial organization cannot fulfill the CDD requirements, it is obliged to refrain from establishing a business relationship with the customer or to terminate it if it has already begun.

The FATF risk-based approach to assessing customers, beneficiaries, and operations

FATF revised its standards, replacing the term “commensurate” with “proportionate” in all the recommendations and interpretive notes, which emphasizes the importance of the risk-based approach in combating ML/TF. This approach allows organizations to allocate resources efficiently, directing efforts to areas of elevated risk and applying simplified measures for low-risk customers.

The proposed changes to Recommendation 1 are aimed at the broader and more effective application of the risk-based approach, especially at improving the identification of low risks and the expanded use of simplified due diligence and regulatory exemptions. Organizations must assess risks based on several key factors: the type of customer (individual, legal entity, trust structure), the geographic location of the customer and their operations, the products and services used, and the service delivery channels.

FATF recommends that countries identify sectors with a low risk of ML/TF by conducting national or subnational risk assessments, which allows financial organizations and designated non-financial businesses and professions to implement AML/CFT measures proportionate to the actual risks. For high-risk customers, enhanced due diligence measures are applied, including the additional verification of sources of funds and wealth, more frequent monitoring of operations, and restrictions on the types and volumes of transactions conducted.

An important element of the risk-based approach is the concept of tiered customer due diligence (tiered CDD), which makes it possible to provide basic services with minimal identity verification and to open access to additional services as identity confirmation improves. This mechanism is especially effective for expanding financial inclusion while maintaining control over ML/TF risks.

Enhanced KYC measures for PEPs, high-risk countries, and unusual operations

FATF Recommendation 12 requires countries to implement measures obliging financial organizations to have appropriate risk management systems to determine whether customers or beneficial owners are politically exposed persons (PEP), and if so — to apply additional measures beyond standard due diligence.

FATF defines a PEP as a person entrusted with prominent public functions in a foreign state, for example, heads of state or government, high-ranking politicians, senior government, judicial, or military officials, heads of state corporations, important figures of political parties. The definition also extends to family members and close associates of a PEP, since they represent similar reputational risks.

For foreign PEPs, enhanced due diligence measures are always applied, including obtaining the approval of senior management before establishing or continuing a business relationship, taking reasonable measures to establish the source of wealth and the source of funds, and conducting enhanced ongoing monitoring of the business relationship. For domestic PEPs and PEPs of international organizations, financial institutions must take reasonable measures to determine the customer’s status and then assess the risk of the business relationship.

Examples of red flags when working with PEPs are the use of corporate structures to conceal ownership, a discrepancy between the information provided and publicly available data (such as asset declarations and official salaries), and doing business with PEPs from higher-risk countries or high-risk sectors.

For transactions with higher-risk jurisdictions, FATF requires the application of enhanced due diligence measures, including obtaining additional information about the customer and the beneficial owner, obtaining information about the expected nature of the business relationship, and obtaining the approval of senior management to establish or continue the business relationship. Organizations must regularly update the lists of higher-risk jurisdictions based on FATF statements and conduct enhanced monitoring of all transactions related to these territories.

The FATF requirements for data storage, reporting, and internal KYC control

FATF Recommendation 11 establishes that the necessary records must be kept for at least five years after the end of the business relationship with the customer or after a one-off operation is carried out, so that organizations can fulfill the information requests of the competent AML/CFT authorities. This helps regulatory bodies reconstruct transactions for the purposes of investigation or prosecution.

FATF recommends storing the following documents as part of AML/CFT record-keeping obligations: records of transactions, both domestic and international, and all documents obtained in the process of customer due diligence, such as official identification documents. The records must be sufficient to reconstruct individual transactions and provide evidence in case of prosecution for criminal activity.

Internal KYC control under the FATF standards requires creating a multi-level management system. Organizations must develop internal AML/CFT policies, procedures, and controls approved at the level of senior management. It is necessary to appoint a compliance officer at the management level with sufficient authority and resources. Ongoing staff training programs must cover the identification of PEPs, the understanding of the associated risks, and the protocols for conducting enhanced due diligence.

Organizations must implement a transaction monitoring system to identify potential money laundering and other activities that may lead to fraud, and to detect and identify any suspicious activity in order to maintain compliance with AML/CFT requirements. Regular independent auditing must check the adequacy and effectiveness of the internal control system.

The reporting of suspicious operations is a critically important element of the FATF system. Financial organizations are obliged to promptly report any suspicious transactions to the relevant authorities, regardless of the amount of the operation or its completion. At the same time, it is prohibited to inform the customer about the filing of a suspicious operation report — a violation of this requirement entails serious sanctions.

Compliance with the FATF standards ensures not only formal compliance with international requirements but also creates an effective system for protecting the business from the risks of involvement in money laundering and terrorist financing schemes. For Russian companies striving for international development, the implementation of these standards becomes a mandatory condition for successful integration into the global financial system.


KYC and GDPR: requirements for personal data within AML/KYC

The European General Data Protection Regulation (GDPR), in effect since May 2018, creates a strict framework for processing personal data when conducting KYC procedures. Organizations conducting identification checks are obliged to ensure full transparency regarding the further use of the data collected. At the same time, financial institutions continue to meet the requirements for countering money laundering, striking a balance between privacy protection and AML obligations.

GDPR establishes three main lawful grounds for processing personal data within KYC procedures.

CategoryDescription
1. legal obligationFinancial organizations process customer data to meet the requirements of national legislation on AML/CTF. In Russia this is Federal Law 115-FZ, in the EU — the AMLD5 and AMLD6 directives.
2. legitimate interest.Organizations can rely on legitimate interest to automate AML and KYC checks provided that a legitimate interest assessment (LIA) is documented with a positive conclusion. This ground is applied for additional trustworthiness checks, fraud prevention, and protection against reputational risks.
3. consent.GDPR requires consent to be specific, informed, and freely given, ensuring that customers fully understand the purposes of using their data. Consent is applied for the collection of data beyond the mandatory minimum or for additional processing purposes. Importantly, customers can withdraw consent at any time, which creates operational difficulties for KYC processes.

GDPR principles affecting KYC (minimization, purpose and storage limitation)

The principle of data minimization requires collecting only the information necessary for a specific purpose. A business must implement KYC procedures that collect exclusively the data needed to verify identity and comply with applicable regulations. In practice, this means abandoning excessive fields in forms and constantly assessing the necessity of each data element.

The principle of purpose limitation prohibits the use of data for purposes other than those originally stated. If a document is requested for KYC checks, it cannot be used for marketing purposes without informing and obtaining the customer’s consent. Financial organizations are obliged to clearly delimit data for regulatory purposes and for commercial use.

The principle of storage limitation creates a contradiction between the requirements of GDPR and AML legislation. According to GDPR, personal data must be stored only for the time necessary for the stated purposes. However, AML/CFT legal obligations may require storing data longer (often five years or more). Organizations resolve this contradiction by documenting the legal grounds for extended storage.

The rights of data subjects and their limitations due to AML/KYC obligations

GDPR grants data subjects an extensive set of rights: access to data, the correction of inaccuracies, the deletion of information (“the right to be forgotten”), the restriction of processing, and data portability. Customers have the right to access their data and understand how it is processed, the right to correct incorrect or incomplete data, and the right to delete data under certain circumstances.

However, AML obligations substantially limit these rights. Financial organizations cannot delete KYC data at a customer’s request if this contradicts the obligations to store documents under AML legislation. The right to restrict processing also does not apply to data necessary for fulfilling legal obligations.

In 2024, the case of JU v Scalable Capital GmbH changed stakeholders’ view of KYC procedures within GDPR. The Court of Justice of the EU confirmed the priority of compensating data subjects for harm, which strengthened organizations’ responsibility for the security of KYC information.

Transferring KYC data outside the EEA and choosing processors/subprocessors

The cross-border transfer of KYC data out of the European Economic Area requires compliance with the strict conditions of GDPR. GDPR restricts the transfer of personal data from the EEA to “third countries”. Organizations can transfer data only to countries with an adequate level of protection recognized by the European Commission, or with appropriate safeguards in place.

For the transfer of data, standard contractual clauses (SCC), binding corporate rules (BCR), or the explicit consent of the data subject are used. Data processing agreements (DPA) govern how data is collected, stored, and processed, and are often sufficient to satisfy the requirements of cross-border transfer between the US and the EU.

When choosing processors and subprocessors for KYC systems, organizations are obliged to check their GDPR compliance. It is important to assess the overall level of trust in a KYC solutions provider: its values, certifications (ISO 27001, PVID, FIDO for biometrics), and the audits (penetration tests, GDPR) that the company undergoes. Contracts with processors must contain data protection obligations, restrictions on further transfer, and the right to audit.

Documenting KYC processing: DPIA, register of operations, privacy by design/by default

A data protection impact assessment (DPIA) is mandatory for KYC systems using new technologies or processing high-risk data. Given the significant risks associated with AI-based AML and KYC checks, conducting a DPIA is mandatory for organizations. A DPIA helps identify risks to the rights and freedoms of data subjects and determine appropriate measures to mitigate them.

GDPR requires a DPIA to contain: a systematic description of the processing operations and their purposes; an assessment of the necessity and proportionality of the processing operations; an assessment of the risks to the rights and freedoms of data subjects; measures to address the risks, including safeguards and security mechanisms.

The register of processing activities (ROPA) documents all of an organization’s KYC processes. Internal policies and procedures, as well as the register of processing operations, must accurately reflect the processing activity carried out through AI systems. The register includes the categories of data, the purposes of processing, the categories of recipients, the storage periods, and a description of the technical and organizational security measures.

The principles of privacy by design and privacy by default require building data protection into KYC systems at the design stage. This means using pseudonymization, encryption, minimizing access to data, and automatically applying the maximum privacy settings. In 2025, DPIAs took on heightened importance due to the introduction of comprehensive privacy regulations around the world, such as the updated GDPR guidelines and the EU AI Act.

Organizations must regularly review and update the documentation as KYC processes change and regulatory requirements evolve, ensuring ongoing compliance with both data protection requirements and anti-money-laundering obligations.

How to combine the requirements of Federal Law 115-FZ, Federal Law 152-FZ, FATF and GDPR in a single KYC policy

Building a single KYC system that simultaneously complies with Russian legislation and international standards requires a systematic approach to harmonizing the norms. Companies face the need to balance between the strict requirements of Federal Law 115-FZ for mandatory identification, the restrictions of Federal Law 152-FZ on the processing of personal data, the FATF recommendations on the risk-based approach, and the data minimization principles of GDPR.

The key to the successful integration of all the requirements is creating a multi-level architecture of processes, where each element of the KYC system is designed taking into account the strictest norms from all the applicable regimes. This approach eliminates conflicts between requirements and minimizes the risks of sanctions from various regulators.

Determining the applicable regimes depending on the jurisdictions of the business and customers

The first step toward building a comprehensive KYC policy is the precise determination of the applicable legal regimes. For a Russian company working with local customers, the basic set will be Federal Law 115-FZ and Federal Law 152-FZ. When entering international markets or serving foreign customers, the requirements of FATF are added through the national legislation of the countries of presence, and GDPR for European residents.

The criteria for determining the applicable regimes include the place of registration of the legal entity, the physical location of the data processing servers, the residency of the customers, and the nature of the services provided. A company registered in Russia but offering services to EU citizens over the internet falls under GDPR regardless of the presence of an office in Europe. Similarly, the use of payment systems or correspondent accounts in FATF countries automatically imposes obligations to comply with international AML standards.

The applicability matrix is formed through the analysis of three levels: the geography of business operations, the types of customers, and the kinds of financial transactions. For each combination, the strictest set of requirements is determined, which becomes the base for the given scenario. At the same time, the extraterritorial effect of individual norms is taken into account — GDPR applies to any processing of the data of EU citizens, and the requirements of the US OFAC may affect operations in dollars regardless of the location of the parties.

A KYC data and process map: reconciling the requirements of Federal Law 115-FZ with the restrictions of Federal Law 152-FZ and GDPR

Creating a single data map begins with an inventory of all the categories of information required by the various regimes. Federal Law 115-FZ establishes the minimum mandatory set: full name, date of birth, citizenship, document details, INN, registered address. FATF adds requirements for beneficial owners and sources of funds. GDPR and Federal Law 152-FZ impose restrictions on the volume of data collected through the minimization principle.

Reconciliation is achieved by creating a modular data structure with three levels: the mandatory minimum under Federal Law 115-FZ, an extended set for higher-risk customers under FATF, and additional data collected only with the explicit consent of the subject. Each level corresponds to a separate legal ground for processing: the fulfillment of legal requirements for the first, legitimate interest for the second, consent for the third.

The process map is built on the principle of maximum automation while retaining control points for compliance with all the norms. Initial identification is performed to the standards of Federal Law 115-FZ with the simultaneous recording of the legal ground for processing for Federal Law 152-FZ and GDPR. Document verification is carried out using technical tools that minimize the human factor and the storage time of copies. Risk assessment is automated through scoring models corresponding to the FATF methodology, with the documentation of each decision for subsequent audit.

Delimiting access to data becomes critically important. Employees of the AML unit receive full access to the information under Federal Law 115-FZ but limited access to additional data. IT specialists work only with de-identified or pseudonymized arrays. Marketing departments are completely excluded from the processes of handling KYC data, receiving only aggregated statistics.

The set of mandatory internal documents on AML/KYC and personal data

The documentary base of a single KYC system is formed from three blocks: top-level policies, operational regulations, and forms for interacting with customers. The base document is a comprehensive KYC/AML policy integrating the requirements of all the applicable regimes. It defines the general principles, roles, and responsibilities, and describes the architecture of the internal control system.

The personal data processing policy is developed taking into account the requirements of both Federal Law 152-FZ and GDPR, even if the European regulation does not formally apply. This approach ensures readiness for international expansion and simplifies interaction with foreign partners. The document includes an exhaustive list of processing purposes, data categories, storage periods, protective measures, and the rights of subjects.

The internal AML/CFT control rules detail the procedures for identification, the detection of suspicious operations, the blocking of funds, and interaction with Rosfinmonitoring. Separate annexes formalize the methodologies for assessing customer risk, the criteria for assigning risk categories, and the indicators of unusual operations. For FATF compliance, a section on working with PEPs (public officials) and customers from high-risk jurisdictions is added.

The operational level includes detailed instructions for each role in the KYC process: first-line specialists conducting identification; analysts assessing risks; compliance officers making decisions on complex cases. Escalation procedures, the order of documenting decisions, and reporting forms are spelled out separately.

Customer documentation is unified for all service channels. Personal data processing consent forms are drawn up taking into account the GDPR requirements for specificity and revocability. Processing notices include all the information required by Articles 13-14 of GDPR and Article 18 of Federal Law 152-FZ. Contracts are supplemented with provisions on identification under Federal Law 115-FZ and the right to request additional documents.

Configuring the storage and deletion periods of KYC data taking Federal Law 115-FZ, FATF and GDPR into account

Harmonizing storage periods is one of the most complex tasks when integrating different regimes. Federal Law 115-FZ requires storing identification documents for at least five years from the moment the relationship with the customer ends. FATF recommends a similar period to ensure the possibility of investigations. GDPR and Federal Law 152-FZ require the deletion of data immediately after the processing purposes are achieved.

The solution lies in creating a differentiated storage system. Data needed exclusively to comply with Federal Law 115-FZ is moved to an archive storage with restricted access immediately after the relationship with the customer ends. Access to the archive is granted only for responding to requests from regulators or law enforcement agencies. Technically, this is implemented through a separate database with enhanced encryption and detailed logging of all accesses.

For active customers, intermediate periods are set for reviewing the need to store individual categories of data. Copies of documents used for identification can be replaced with hash sums or cryptographic marks after successful verification. Biometric templates are deleted immediately after matching against the documents, and only the fact of a successful check is retained.

The automation of deletion processes becomes critically important for complying with the storage limitation principle. The system must automatically track the expiration of periods for each category of data and initiate deletion or anonymization procedures. At the same time, an audit trail is retained confirming the fact and date of deletion, which is necessary to demonstrate compliance during inspections.

Organizing compliance control: roles, audits, the regular updating of the KYC policy

An effective control system is built on the principle of three lines of defense. The first line is the operational units directly performing KYC procedures. They are responsible for the quality of identification, the completeness of the data collected, and compliance with the established procedures. The second line is the compliance unit, which controls the correspondence of the processes to the established policies and regulatory requirements. The third line is internal audit, which conducts an independent assessment of the effectiveness of the entire system.

For each line of defense, responsible persons with clearly defined authority are appointed. The AML/CFT officer required by Federal Law 115-FZ coordinates interaction with Rosfinmonitoring and ensures the fulfillment of the requirements of Russian legislation. The DPO (Data Protection Officer) is responsible for compliance with the requirements of Federal Law 152-FZ and GDPR. The risk manager controls the correspondence of the customer assessment procedures to the FATF recommendations.

The audit program includes quarterly checks of critical processes and an annual comprehensive audit of the entire KYC system. The quality of identification is checked on a sample of customer files, along with the timeliness of data updates, the correctness of risk assessment, and the completeness of sending reports to Rosfinmonitoring. Special attention is paid to technical aspects: the security of the data storage, the operability of the deletion mechanisms, and the integrity of the audit logs.

The regular updating of policies and procedures is synchronized with changes in legislation and regulatory practice. An annual cycle of scheduled review is established with the possibility of out-of-schedule changes in case of substantial innovations in the regulatory framework. The monitoring of changes is conducted in four directions: Russian legislation, European regulation, the FATF recommendations, and enforcement practice.

Staff training is conducted differentially depending on the role in the KYC process. A basic course on the fundamentals of AML/CFT and personal data protection is mandatory for all employees. Specialized programs are developed for identification specialists, analysts, IT specialists, and managers. The effectiveness of the training is checked through testing and the analysis of the quality of procedure execution.

The system of performance indicators (KPI) covers all aspects of the KYC process: the speed and quality of identification, the percentage of false positives from the monitoring system, the timeliness of sending reports to regulators, and the number of justified customer complaints about the processing of personal data. The regular analysis of KPIs makes it possible to identify problem areas and promptly adjust the processes.

Conclusion
Building a KYC system taking Russian legislation and international standards into account

Compliance with the legal AML/KYC requirements requires a systematic approach in which the norms of Federal Law 115-FZ, Federal Law 152-FZ, the FATF recommendations, and the GDPR principles form a single compliance policy. Russian legislation establishes the basic obligations for identifying customers and storing data, while international standards supplement them with a risk-based approach and enhanced guarantees of personal data protection. Companies working with customers from different jurisdictions must simultaneously meet the strictest requirements of each regime, document processes, and regularly update internal procedures.

A well-built KYC system protects the business from regulators’ sanctions, minimizes reputational risks, and opens access to international markets. Investments in technologies for automating the identification, verification, and monitoring of customers pay off through lower operating costs, a reduction in the number of false positives, and the acceleration of the onboarding of bona fide users. The regular auditing of procedures and staff training help maintain a high level of compliance and quickly adapt to changes in the regulatory environment.