Doocat

KYC Know Your Customer Guide for Banks and MFIs: Checklist, Workflow, and Controls

Content authorBy DoocatPublished onReading time13 min read
A banking advisor assists a customer with KYC onboarding on a tablet in a bright, modern office with natural light.

This article turns KYC know your customer from a scattered set of manual checks into a documented, repeatable workflow you can run across your onboarding team. You'll get a KYC checklist template to adapt and the controls that make the whole thing defensible in an audit, with a clear split between individual and business requirements.

Why KYC needs to be a workflow

Your KYC Know Your Customer checks are happening. The issue sits in the proof. They live in an analyst's inbox and across a shared drive nobody has cleaned out since 2022, with the decisive context stuck in the memory of the one person who knows why a client was approved two years ago. When an examiner asks you to show why that customer was onboarded and who signed off, you spend three days reconstructing a decision that needed three clicks to prove.

That gap between doing the work and proving the work is where fines come from. Global anti-money laundering enforcement reached $4.6 billion in 2024, and the Financial Conduct Authority described Starling Bank's controls as "shockingly lax" after finding it had screened against 39 of 3,088 designated persons under financial sanctions since 2017. The system around the checks failed.

So this guide treats KYC know your customer as an operating model for day-to-day onboarding. You already know why it matters. What you need is a way to standardize the work and connect it to the systems your team already uses, with each step documented. You'll leave with a checklist and the controls that hold it together, with a clear view of how individual and business requirements diverge.

The core parts of KYC know your customer

Before the checklist, you need a shared mental model your whole team can point to. KYC Know Your Customer rests on three pillars, and every task in this article hangs off one of them.

The first part of KYC know your customer is customer identification. You collect who the customer is and verify it against reliable independent sources before the relationship opens. The second is customer due diligence, where you assess the risk that customer brings and decide how much scrutiny the relationship warrants. FATF Recommendation 10 frames customer due diligence as identifying and verifying the customer, with the beneficial owner identified and the purpose of the relationship understood. The third pillar is ongoing monitoring, which keeps the record current for as long as the customer stays with you.

Two more parts sit around these pillars. Enhanced due diligence is customer due diligence turned up when a profile carries higher risk. And the audit trail is the documentation layer that records every step and its evidence, with the owner tied to the record. The rest of this article expands each part into steps you can assign and defend after they are digitized.

The KYC checklist template

Professional infographic UI illustrating a KYC onboarding workflow with a central checklist card and sequential process cards, featuring icons and ambient li…

Here's the artifact. Copy it into your onboarding process and adapt the fields to your jurisdiction and product mix. The point is to organize those things so each item maps to a step in the onboarding workflow, with a clear owner and a place to attach evidence.

Treat every line below as a KYC know your customer workflow step inside the onboarding process. Each one needs two things the paper version lacks: a named owner who is accountable for completing it, and an evidence field where the supporting document or screening result lives. That's what makes the difference between a KYC checklist template and an auditable process.

The checklist also differs by customer type and by risk level, which is why it splits into the three subsections below. A sole trader and a holding company with foreign shareholders don't move through the same steps, and a low-risk salaried customer doesn't warrant the depth you'd apply to a politically exposed one.

Customer identification data

Capture this baseline before the relationship is established.

For an individual customer, the mandatory fields are:

  • Full legal name and any former names

  • Date of birth and nationality

  • Residential address and a national identifier such as a tax or ID number

For a business customer, the equivalent set covers the registered legal name and the registration number, with the country of incorporation and nature of the business included in the same record. Each field has to be captured before onboarding completes and cross-checked against a reliable independent source, because FATF Recommendation 10 requires verification using reliable independent documents or information from an external source.

In a digital form, every field becomes a required step that blocks progression until it's filled and validated. That's how you stop an analyst from waving a half-complete profile through under deadline pressure. The form enforces the sequence so nothing gets skipped, and the completed record feeds straight into the customer due diligence work that follows.

Ready to digitise your financial institution?

Talk to our team about your roadmap and discover scalable digital banking solutions tailored to banks, fintechs and microfinance institutions.

Request a Demo

Document requirements checklist

Documents are how you verify the identity data you collected for KYC know your customer. For an individual, that means a government-issued photo ID plus a recent proof of address, such as a utility bill or bank statement within a set age limit.

For a business, the set is heavier:

  • Certificate of incorporation and a current registry extract

  • Register of directors and authorized signatories

  • Beneficial ownership documentation down to the individuals who ultimately control the entity

Document quality drives most onboarding delays. An address on the utility bill that doesn't match the form or a name spelled two ways across two files can stop the file; so can a draft resolution that was never signed. Each one triggers a round of back-and-forth that adds days. A KYC checklist template with written acceptance standards and expiry rules kills most of that friction before it starts. Define what you accept and what you reject on sight, with re-request rules built in, so the analyst isn't making a judgment call every time. The standard sits inside the workflow, and the customer due diligence decision waits until the evidence clears it.

Risk rating and screening steps

This is where collected KYC know your customer data becomes a decision. You assign the customer one of three risk tiers and screen the identity against sanctions lists and politically exposed person (PEP) status, with watchlist checks included in the same step. The tier sets the depth of customer due diligence you apply now and the frequency of monitoring later, which ties this step directly to the enhanced due diligence and monitoring sections ahead.

The operational logic is simple to record even when the underlying model is complex. Capture the inputs that drove the rating and the screening results with their timestamp, with the analyst tied to the tier decision. You're building a scoring model somewhere else. Here you're recording the outcome and the reasoning so it can be reconstructed. Screening runs at account opening and repeats through the relationship, because a customer clean today can appear on a list tomorrow. Wire the screening step so it fires again on schedule and on trigger, which is exactly what the monitoring section builds on.

Individual versus business customers

A person and a company need different steps because the risk lives in different places for each. For an individual, the work concentrates on confirming identity and verifying the residential address, with the occupation and source of funds established for the expected activity. It's linear and, for a low-risk salaried customer, fast. A business is a different animal. There you have to unpack the ownership structure and identify the beneficial owners, with authorized signatories confirmed and the entity's nature and expected activity understood.

Beneficial ownership is where corporate onboarding gets slow and where mistakes get expensive. FATF sets the minimum ownership threshold at 25% for classifying an ultimate beneficial owner, and that threshold can be reached through combined holdings or exercised through control instead of direct equity. Layered or foreign ownership means you're chasing individuals through several corporate vehicles before you reach a natural person. This is part of why the average corporate client can take up to 100 days to onboard, with more than 40% of that time spent on KYC due diligence and account opening.

So the KYC know your customer workflow has to branch. One process, two paths. The individual path stays short and mostly automated, while the business path opens the ownership-mapping and signatory steps and slows the customer due diligence gate until the structure is fully resolved. Designing that branch once is what lets your team handle both customer types without inventing the process from scratch each time.

Ready to digitise your financial institution?

Talk to our team about your roadmap and discover scalable digital banking solutions tailored to banks, fintechs and microfinance institutions.

Request a Demo

When enhanced due diligence applies

Enhanced due diligence is customer due diligence with the depth turned up, applied when a customer presents higher risk than the standard profile. The trick is knowing exactly when to escalate, so build the triggers into the workflow instead of leaving them to an analyst's instinct.

The common triggers are worth stating plainly:

  • PEP status, whether the customer is a politically exposed person or closely associated with one

  • A connection to a high-risk jurisdiction

  • A complex or opaque corporate structure, or expected activity that doesn't fit the customer's profile

When a trigger fires, enhanced due diligence demands source-of-funds and source-of-wealth documentation, which means proving where a specific deposit came from and how the customer accumulated their wealth over time.

Governance drives most enhanced due diligence failures. The information existed. The escalation didn't happen. Deutsche Bank's $186 million penalty cited persistent control deficiencies and poor customer due diligence, the kind of gap where a risk was visible but never rose to anyone empowered to act on it. That's why senior management approval of every high-risk relationship has to be a documented, mandatory step in the workflow, with the approver and the timestamp captured. A high-risk customer needs a documented name attached to the sign-off for enhanced due diligence to exist.

Ongoing monitoring and review triggers

The KYC know your customer process continues after the account opens. The customer record you built at onboarding starts decaying the moment it's filed, because people move and companies restructure while clean profiles pick up adverse media. Keeping the record current for the life of the relationship is the third pillar, and it needs two modes of review planned in advance.

The first mode is the scheduled periodic review, tied to the risk tier you set earlier. High-risk customers are reviewed more often than low-risk ones, which is the whole reason the risk rating fed forward. The second mode is event-driven, where a specific change forces a review outside the schedule.

Build these triggers explicitly:

  • A change of director or beneficial owner

  • A move into a new jurisdiction or a spike in transaction activity

  • An adverse media hit or a fresh sanctions match on rescreening

Monitoring frequency follows the risk rating for each customer. That's what regulators mean by a risk-based approach, and it's also how you avoid burning your team's hours reviewing low-risk salaried customers at the same cadence as a high-risk corporate. TD Bank's $3.1 billion resolution traced in large part to transaction monitoring that didn't keep pace with the activity flowing through it, a reminder that monitoring which exists on paper but doesn't fire in practice is worth nothing.

When a trigger fires, it feeds back into the same workflow. The customer re-enters the customer due diligence and screening steps, with an owner assigned and the evidence attached to the existing record. One workflow runs on a loop for as long as the customer stays.

Building the audit trail and controls

When an examiner arrives, they want to see one thing: the story of each customer, told through documentation. Why this customer was onboarded and who approved it, with the checks and timing clear. If you can produce that in minutes with the evidence attached, the review is short. If you're reconstructing it from memory and email threads, it isn't.

Record-keeping expectations for KYC know your customer are concrete. FATF Recommendation 11 requires records to be held for at least five years after the business relationship ends, and jurisdictions extend that. Belgium requires KYC records for 10 years after a relationship closes, so your retention rules have to reflect each jurisdiction where you operate. The value sits in an immutable trail that captures each checklist step and the evidence attached, with the owner tied to the record, so the record can't be quietly edited after the fact.

Three internal controls turn a good checklist into a defensible process. Maker-checker approvals mean the person who completes a step isn't the one who signs it off. Documented escalation paths make sure a high-risk finding reaches someone empowered to act. And version-controlled procedures let you show an examiner what your policy says today and what it said when a given customer was onboarded. That last point matters more than it sounds, because regulators assess whether decisions were reasonable and supported by evidence at the time they were made. This layer lets you stand behind the checklist.

Turning the checklist into a workflow

A KYC checklist template is a good start and a poor operating model. The shift you're after is from a static document to a live, standardized onboarding workflow your whole team runs the same way every time. That move is practical, and it happens in a sequence.

Start by assigning an owner to each step, so accountability is fixed before anything is automated. Then digitize the data and document capture so the required fields block progression and the evidence attaches to the record automatically. From there, wire the workflow into your onboarding and monitoring systems, with the core banking connection carrying the customer record across them instead of being re-keyed at each stage. Begin with your low-risk individual profiles and prove the process before you scale it to the complex corporate paths. Given that nearly half of banks report losing clients to slow or inefficient onboarding, the connected version pays for itself in retained business as much as in passed audits.

This is where a platform earns its place. Doocat builds banking infrastructure for banks and microfinance institutions, with digital KYC and document capture across every service, while multi-step approval chains and tamper-evident event logging express the audit trail and maker-checker control in software. If you're ready to convert the checklist in this guide into your own connected onboarding workflow, book a call with the Doocat team to map your KYC Know Your Customer process onto a system built to run it.

Ready to digitise your financial institution?

Talk to our team about your roadmap and discover scalable digital banking solutions tailored to banks, fintechs and microfinance institutions.

Request a Demo

Keep the same decision file you would keep for an approved customer. Include the identity data, documents submitted, screening results, rejection reason, analyst notes, and review timestamps. Retain it under your jurisdiction’s record-keeping policy because regulators can ask why a relationship was declined or exited.

Update it on the schedule set in your risk-based AML policy. Low-risk files should have a longer review cycle than high-risk files, but the interval must be written down and applied consistently. Also review the file when a trigger occurs, such as a new address or sanctions match.

Don’t complete onboarding until mandatory identity and verification documents are received, checked, and recorded. If your internal rules allow limited access before completion, restrict product use, document the exception, and set an expiry date. The file should show who approved the exception and why.

KYC, or kyc know your customer, verifies a person’s identity, address, and expected account activity. Business checks go further because the institution must confirm the legal entity, authorized signatories, and the individuals who own or control it. That ownership mapping is the main reason business onboarding takes longer.

Doocat helps banks and MFIs turn checklist items into assigned workflow tasks with document capture, approval chains, and event logs. The practical value is control evidence. Each decision has an owner, timestamp, and attached file, which makes audit preparation easier and reduces reliance on email trails.

Schedule a Meeting

Book a time that works best for you

You Might Also Like

Discover more insights and articles

A customer advisor assists a client with the KYC onboarding process on a tablet in a bright, modern office setting.

KYC Banking Workflows: How Banks and MFIs Can Scale Onboarding and Compliance

This article treats KYC banking as an operational workflow you can map. It walks the full journey a customer takes from first data capture through ongoing review, and shows where your handoffs and exception queues leak time or risk.

A finance professional reviews documents and reports at a modern office desk, taking notes while using a laptop in warm daylight.

Fintech Payment Infrastructure for Banks, MFIs, and Wallet Providers

This article breaks payment systems into their real parts and shows how rails and wallets hand off into settlement, while reconciliation and exception handling keep the record straight. It is written for wallet providers and for fintech payment teams inside banks or microfinance institutions who already run a payment product but keep hitting the same operational walls as volume grows.

A customer and bank advisor collaborate at a modern desk, focused on a tablet, in a bright, spacious bank branch.

Customer Experience in Banking Industry: How to Fix Friction Across Digital and Branch Channels

This article treats customer experience in banking industry work as an operational problem that lives in the handoffs between your digital and branch channels. It uses customer journey mapping to walk through where friction accumulates during onboarding and when support or compliance work crosses channels, then gives you a way to map it with owners so you can prove that a fix worked.

A diverse team collaborates in a bright meeting room, discussing a mobile banking app and business dashboard at a natural wood table.

Bank Customer Experience in Mobile-First Markets: How to Improve Digital Journeys

This article is a mobile-first guide to finding and fixing the operational blockers that break the banking customer journey in markets where the phone is the only channel customers have. It walks through where journeys fail in bank customer experience and who owns the fix, with measurement tied to whether people actually complete what they came to do.