KYC requirements differ by country because every jurisdiction builds its own rulebook on top of a shared Financial Action Task Force (FATF) baseline. Regulators set different verification standards, national identity systems vary in coverage, beneficial ownership thresholds move, and supervisory risk appetites diverge. One global principle ends up expressed through dozens of national rulebooks.
This guide covers fifteen markets across five regions: What each regulator expects, where the rules diverge, and which country guide to open next.
Why KYC Requirements Differ by Country
The gap between jurisdictions almost never sits in principle. It sits in the detail: Which document counts as proof of identity, whether a video call can stand in for a branch visit, how far up an ownership chain a firm has to look, and where the resulting records may be stored. A firm expanding from London to Mumbai keeps the same policy and rebuilds most of the operation.
For each country below you will find the regulator, the core identity requirement, and the one or two rules that tend to surprise teams arriving from another market. This guide summarizes and routes; where we have a full country guide, it is linked at the end of that country’s section. Where a market also regulates virtual assets, crypto-specific rules apply on top; our crypto compliance page covers how those checks work.
The Shared Baseline: FATF and Core CDD
Recommendation 10 of the FATF standards sets the floor almost every national regime is built on. Four obligations recur everywhere: Identify and verify the customer, identify the beneficial owner behind a legal entity, understand the purpose of the relationship, and monitor it on an ongoing basis. A risk-based approach governs how much effort each of those demands. Five-year record retention is close to universal.
Anyone new to the subject should start with KYC and customer onboarding, which walks the sequence from data collection to approval, then see how customer risk assessment and KYC fit together in practice.
FATF listings also feed directly into country risk models. As of the June 2026 plenary, 22 jurisdictions sit on the list of countries under increased monitoring, commonly called the grey list. Three remain subject to a call for action: Iran, North Korea, and Myanmar. These lists change three times a year, which is exactly why country risk tables age badly.
KYC Requirements by Country and Region
Identity infrastructure shapes almost everything downstream, and it is the quickest way to read a country's rules. The regional grouping below covers fifteen markets; global KYC requirements beyond these are being added as the country guides expand.
North America
United States
KYC requirements in the United States begin with the Customer Identification Program rules under the Bank Secrecy Act (BSA), which oblige banks to collect a name, date of birth, address, and taxpayer identification number, usually a Social Security Number. The separate Customer Due Diligence Rule from the Financial Crimes Enforcement Network (FinCEN) requires beneficial owners at 25 percent or more to be identified. In February 2026, FinCEN granted exceptive relief ending the requirement to re-verify those owners at every new account opening. Read our full AML guide for the United States.
Canada
KYC requirements in Canada are set by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. Canada is unusual in prescribing exactly five acceptable identity verification methods, including a dual-process approach drawing on two independent sources. Amendments that received Royal Assent in March 2026 extended mandatory enrollment with FINTRAC and raised administrative penalty ceilings sharply. Read our full AML guide for Canada.
Europe and the United Kingdom
United Kingdom
KYC requirements in the United Kingdom sit under the Money Laundering Regulations, supervised by the Financial Conduct Authority and interpreted through Joint Money Laundering Steering Group guidance. Amendment regulations that took effect on 30 June 2026 narrowed mandatory enhanced due diligence to jurisdictions subject to a FATF call for action and converted euro-denominated thresholds into sterling. Grey-listed countries remain a risk factor rather than an automatic trigger. Read our full AML guide for the United Kingdom.
European Union
KYC requirements in the European Union are in the middle of the largest overhaul in two decades. The Anti-Money Laundering Regulation applies directly across all 27 member states from 10 July 2027, replacing nationally transposed directives with a single rulebook, and the Anti-Money Laundering Authority has been operational in Frankfurt since July 2025. The beneficial ownership threshold shifts from more than 25 percent to 25 percent or more, which quietly brings exact quarter-stake holders into scope.
Germany
KYC requirements in Germany run through the Geldwäschegesetz, supervised by BaFin, with beneficial ownership notified to the Transparenzregister. VideoIdent remains an accepted route for remote onboarding, subject to conditions BaFin tightened in its revised interpretation guidance. German firms now face a two-stage planning problem, since national substance gives way to the EU regulation in 2027. Read our full AML guide for Germany.
Asia-Pacific
India
KYC requirements in India changed structurally in November 2025, when the Reserve Bank of India repealed the 2016 KYC Master Direction and replaced it with ten institution-specific directions covering commercial banks, non-banking financial companies, payments banks, and cooperative banks separately. Aadhaar-based eKYC, the Video-based Customer Identification Process, and the Central KYC Records Registry are the three rails almost every onboarding flow uses. Video verification records must be stored on systems located in India.
Japan
KYC requirements in Japan are governed by the Act on Prevention of Transfer of Criminal Proceeds, with the Financial Services Agency and JAFIC overseeing application. Japan is moving in the opposite direction to most markets on remote onboarding: From 1 April 2027, IC chip reading becomes the principal verification method, and submitting photographs of identity documents will no longer be permitted for non-face-to-face account opening at banks. Firms relying on image-upload flows need a migration plan rather than a patch.
Singapore
KYC requirements in Singapore are set out in binding notices rather than guidance. MAS Notice 626 applies to banks, while payment service providers work to Notices PSN01 and PSN02, and the distinction matters more than most teams assume. Myinfo, the government data service behind Singpass, lets a consenting resident prefill verified identity attributes, though foreigners without Singpass still need document and biometric checks. Read our full AML guide for Singapore.
Malaysia
KYC requirements in Malaysia flow from the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act and Bank Negara Malaysia's AML/CFT policy document. A separate eKYC policy document sets the technical bar for remote onboarding, including MyKad chip reading and facial comparison against the chip photograph rather than the printed image. Record retention runs to six years, longer than the five-year norm elsewhere. Read our full AML guide for Malaysia.
Philippines
KYC requirements in the Philippines are driven by BSP Circular 1170, which formally permits electronic verification and recognizes the PhilSys national ID as primary proof of identity. The Anti-Money Laundering Council receives covered and suspicious transaction reports. The Philippines exited the FATF grey list in February 2025, which has eased correspondent banking friction without softening domestic obligations. Read our full AML guide for the Philippines.
Australia
KYC requirements in Australia expanded dramatically on 1 July 2026, when the second tranche of AML/CTF reforms brought lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones into scope. AUSTRAC has put the number of newly regulated businesses at roughly 90,000. The obligation attaches to the designated service provided, not to the professional title, which catches firms that assumed they were outside the perimeter.
Middle East and Africa
United Arab Emirates
KYC requirements in the United Arab Emirates depend heavily on where an entity is licensed. The Central Bank supervises onshore banks and payment firms, the Dubai Financial Services Authority covers the DIFC, the Financial Services Regulatory Authority covers ADGM, and VARA regulates virtual assets in Dubai outside the DIFC. Emirates ID verification through UAE Pass is an accepted onboarding path, though an expatriate-majority population means document-based verification stays central rather than residual. Read our full AML guide for the United Arab Emirates.
Saudi Arabia
KYC requirements in Saudi Arabia are set by the Saudi Central Bank through its AML/CTF rules and rulebook, with the Capital Market Authority covering securities activity. Nationals and residents are verified against government records through Absher and Nafath, using the national ID or the Iqama residency credential. Reliance on those sources does not transfer the compliance obligation, a point SAMA has made explicit.
Nigeria
KYC requirements in Nigeria run on a three-tier account structure set by the Central Bank of Nigeria, with documentation and transaction limits tightening at each level. Since December 2023, Tier 2 and Tier 3 accounts must have both a Bank Verification Number and a National Identification Number linked, verified against NIBSS and NIMC rather than self-declared. Nigeria left the FATF grey list in October 2025 after more than two years.
Latin America
Brazil
KYC requirements in Brazil are anchored in Law 9,613/1998 and Circular 3,978/2020 from Banco Central do Brasil, with COAF acting as the financial intelligence unit. Identity turns on the CPF for individuals and the CNPJ for companies, validated against Receita Federal records, and a registration flagged as irregular will stop onboarding outright. Brazil's data protection law shapes retention and processing alongside the AML rules. Read our full AML guide for Brazil.
At a Glance
|
Country |
Primary Regulator |
Distinctive Requirement |
|---|---|---|
|
United States |
FinCEN |
Beneficial ownership verified once at onboarding, not at every new account |
|
Canada |
FINTRAC |
Five prescribed identity verification methods, including dual-process |
|
United Kingdom |
FCA |
Mandatory enhanced due diligence narrowed to call-for-action countries |
|
European Union |
AMLA and national supervisors |
Single rulebook applies directly from July 2027 |
|
Germany |
BaFin |
VideoIdent permitted; ownership filed to the Transparenzregister |
|
India |
Reserve Bank of India |
Institution-specific KYC directions; video KYC data stored in India |
|
Japan |
Financial Services Agency |
IC chip reading becomes the principal method from April 2027 |
|
Singapore |
MAS |
Separate binding notices by license type; Myinfo prefill |
|
Malaysia |
Bank Negara Malaysia |
MyKad chip read and face match; six-year retention |
|
Philippines |
BSP |
PhilSys national ID accepted as primary proof of identity |
|
Australia |
AUSTRAC |
Tranche 2 professions in scope since July 2026 |
|
United Arab Emirates |
CBUAE, DFSA, FSRA, VARA |
Obligations differ by licensing zone |
|
Saudi Arabia |
SAMA |
Verification against Absher and Nafath government records |
|
Nigeria |
Central Bank of Nigeria |
Both BVN and NIN required above Tier 1 |
|
Brazil |
Banco Central do Brasil |
CPF and CNPJ validated against Receita Federal |
High-Level Comparison: Where the Big Differences Are
Four differences account for most of the divergence between the regimes above.
Identity Infrastructure: National ID Versus Document Capture
The sharpest dividing line is whether a country has a queryable national identity database. India, Singapore, the Philippines, Malaysia, Nigeria, Brazil, Saudi Arabia, and the UAE all do, and onboarding in those markets can resolve to an authoritative government record in seconds. The United States, the United Kingdom, Canada, and Australia do not, so verification there means triangulating documents against credit files, electoral data, and commercial databases.
The consequence shows up in conversion rates and in coverage gaps. National ID rails work beautifully for residents and not at all for everyone else, which is why expatriate-heavy markets such as the UAE keep full document flows running in parallel rather than as a fallback.
Beneficial Ownership Thresholds
Twenty-five percent is the common anchor, used by the US CDD Rule, the UK register of people with significant control, Singapore, and the FATF standard itself. The edges are where errors happen. The EU moves from more than 25 percent to 25 percent or more in 2027, and the European Commission holds a reserved power to drop the figure as low as 15 percent for sectors assessed as high risk.
In August 2026 FinCEN finalized the rule exempting domestically formed companies and US persons from reporting to its beneficial ownership registry, closing a rollback that began with interim relief in March 2025. The separate obligation on banks to collect and verify beneficial owners at onboarding did not change. A registry closing is not a due diligence obligation lifting, and the two were widely conflated through 2026.
Remote Onboarding and eKYC Acceptance
Acceptance of remote verification is not a straight line from restrictive to permissive. India treats a properly conducted video session as equivalent to face-to-face verification, with no transaction cap attached. Malaysia sets detailed technical conditions, including reading the MyKad chip rather than photographing the card. Japan is tightening: Image-based verification for remote bank account opening ends in April 2027 in favor of IC chip reads, on the reasoning that forged documents are too hard to detect from photographs.
Europe is layering a public alternative underneath all of this. Every EU member state must make a certified European Digital Identity Wallet available by the end of 2026, with acceptance obligations following for regulated sectors. Firms building EU onboarding in 2026 are building against a rail that does not fully exist yet.
Data Localization and Cross-Border Transfer
Where verification data can sit is an architecture decision, not a policy footnote. India requires video verification recordings to be stored on systems located in India. Brazil's general data protection law governs retention alongside central bank rules. In the UAE, onshore, DIFC, and ADGM operate under different data regimes within the same country. Firms that centralize a single KYC datastore and then expand into these markets tend to discover the constraint late, after the integration is built.
How Technology Handles Multi-Country KYC
A modern KYC platform standardizes identity verification and screening across jurisdictions while accommodating local rules. In practice that means configurable onboarding flows per market, support for local document and credential types, connections to national identity sources where they exist, sanctions screening and politically exposed person screening against the lists each regulator expects, and ongoing monitoring that keeps customer records current rather than frozen at onboarding.
The operational test is whether a single policy engine can express fifteen different rulebooks without fifteen separate builds. Regional data residency, per-market retention periods, and audit trails an examiner can follow are the parts teams tend to underestimate.