Introducing Complead. One AI-native platform for financial crime compliance. Read the story
New Ready Integrations available Check the new integrations
Meet Complead at Money20/20 USA, Las Vegas 18-21 October 2026 Meet with us

KYC Requirements by Country: How the Rules Differ

In short

How KYC requirements differ across 15 markets: Regulators, identity rails, beneficial ownership thresholds, eKYC rules, and links to our country AML guides.

KYC requirements differ by country because every jurisdiction builds its own rulebook on top of a shared Financial Action Task Force (FATF) baseline. Regulators set different verification standards, national identity systems vary in coverage, beneficial ownership thresholds move, and supervisory risk appetites diverge. One global principle ends up expressed through dozens of national rulebooks.

This guide covers fifteen markets across five regions: What each regulator expects, where the rules diverge, and which country guide to open next.

Why KYC Requirements Differ by Country

The gap between jurisdictions almost never sits in principle. It sits in the detail: Which document counts as proof of identity, whether a video call can stand in for a branch visit, how far up an ownership chain a firm has to look, and where the resulting records may be stored. A firm expanding from London to Mumbai keeps the same policy and rebuilds most of the operation.

For each country below you will find the regulator, the core identity requirement, and the one or two rules that tend to surprise teams arriving from another market. This guide summarizes and routes; where we have a full country guide, it is linked at the end of that country’s section. Where a market also regulates virtual assets, crypto-specific rules apply on top; our crypto compliance page covers how those checks work.

The Shared Baseline: FATF and Core CDD

Recommendation 10 of the FATF standards sets the floor almost every national regime is built on. Four obligations recur everywhere: Identify and verify the customer, identify the beneficial owner behind a legal entity, understand the purpose of the relationship, and monitor it on an ongoing basis. A risk-based approach governs how much effort each of those demands. Five-year record retention is close to universal.

Anyone new to the subject should start with KYC and customer onboarding, which walks the sequence from data collection to approval, then see how customer risk assessment and KYC fit together in practice.

FATF listings also feed directly into country risk models. As of the June 2026 plenary, 22 jurisdictions sit on the list of countries under increased monitoring, commonly called the grey list. Three remain subject to a call for action: Iran, North Korea, and Myanmar. These lists change three times a year, which is exactly why country risk tables age badly.

Lead on compliance.

Join 800+ companies that trust Complead to detect risk, prevent fraud and stay compliant.

One Platformall compliance, risk & fraud requirements in a platform

KYC Requirements by Country and Region

Identity infrastructure shapes almost everything downstream, and it is the quickest way to read a country's rules. The regional grouping below covers fifteen markets; global KYC requirements beyond these are being added as the country guides expand.

North America

United States

KYC requirements in the United States begin with the Customer Identification Program rules under the Bank Secrecy Act (BSA), which oblige banks to collect a name, date of birth, address, and taxpayer identification number, usually a Social Security Number. The separate Customer Due Diligence Rule from the Financial Crimes Enforcement Network (FinCEN) requires beneficial owners at 25 percent or more to be identified. In February 2026, FinCEN granted exceptive relief ending the requirement to re-verify those owners at every new account opening. Read our full AML guide for the United States.

Canada

KYC requirements in Canada are set by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. Canada is unusual in prescribing exactly five acceptable identity verification methods, including a dual-process approach drawing on two independent sources. Amendments that received Royal Assent in March 2026 extended mandatory enrollment with FINTRAC and raised administrative penalty ceilings sharply. Read our full AML guide for Canada.

Europe and the United Kingdom

United Kingdom

KYC requirements in the United Kingdom sit under the Money Laundering Regulations, supervised by the Financial Conduct Authority and interpreted through Joint Money Laundering Steering Group guidance. Amendment regulations that took effect on 30 June 2026 narrowed mandatory enhanced due diligence to jurisdictions subject to a FATF call for action and converted euro-denominated thresholds into sterling. Grey-listed countries remain a risk factor rather than an automatic trigger. Read our full AML guide for the United Kingdom.

European Union

KYC requirements in the European Union are in the middle of the largest overhaul in two decades. The Anti-Money Laundering Regulation applies directly across all 27 member states from 10 July 2027, replacing nationally transposed directives with a single rulebook, and the Anti-Money Laundering Authority has been operational in Frankfurt since July 2025. The beneficial ownership threshold shifts from more than 25 percent to 25 percent or more, which quietly brings exact quarter-stake holders into scope.

Germany

KYC requirements in Germany run through the Geldwäschegesetz, supervised by BaFin, with beneficial ownership notified to the Transparenzregister. VideoIdent remains an accepted route for remote onboarding, subject to conditions BaFin tightened in its revised interpretation guidance. German firms now face a two-stage planning problem, since national substance gives way to the EU regulation in 2027. Read our full AML guide for Germany.

Asia-Pacific

India

KYC requirements in India changed structurally in November 2025, when the Reserve Bank of India repealed the 2016 KYC Master Direction and replaced it with ten institution-specific directions covering commercial banks, non-banking financial companies, payments banks, and cooperative banks separately. Aadhaar-based eKYC, the Video-based Customer Identification Process, and the Central KYC Records Registry are the three rails almost every onboarding flow uses. Video verification records must be stored on systems located in India.

Japan

KYC requirements in Japan are governed by the Act on Prevention of Transfer of Criminal Proceeds, with the Financial Services Agency and JAFIC overseeing application. Japan is moving in the opposite direction to most markets on remote onboarding: From 1 April 2027, IC chip reading becomes the principal verification method, and submitting photographs of identity documents will no longer be permitted for non-face-to-face account opening at banks. Firms relying on image-upload flows need a migration plan rather than a patch.

Singapore

KYC requirements in Singapore are set out in binding notices rather than guidance. MAS Notice 626 applies to banks, while payment service providers work to Notices PSN01 and PSN02, and the distinction matters more than most teams assume. Myinfo, the government data service behind Singpass, lets a consenting resident prefill verified identity attributes, though foreigners without Singpass still need document and biometric checks. Read our full AML guide for Singapore.

Malaysia

KYC requirements in Malaysia flow from the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act and Bank Negara Malaysia's AML/CFT policy document. A separate eKYC policy document sets the technical bar for remote onboarding, including MyKad chip reading and facial comparison against the chip photograph rather than the printed image. Record retention runs to six years, longer than the five-year norm elsewhere. Read our full AML guide for Malaysia.

Philippines

KYC requirements in the Philippines are driven by BSP Circular 1170, which formally permits electronic verification and recognizes the PhilSys national ID as primary proof of identity. The Anti-Money Laundering Council receives covered and suspicious transaction reports. The Philippines exited the FATF grey list in February 2025, which has eased correspondent banking friction without softening domestic obligations. Read our full AML guide for the Philippines.

Australia

KYC requirements in Australia expanded dramatically on 1 July 2026, when the second tranche of AML/CTF reforms brought lawyers, conveyancers, accountants, real estate professionals, trust and company service providers, and dealers in precious metals and stones into scope. AUSTRAC has put the number of newly regulated businesses at roughly 90,000. The obligation attaches to the designated service provided, not to the professional title, which catches firms that assumed they were outside the perimeter.

Middle East and Africa

United Arab Emirates

KYC requirements in the United Arab Emirates depend heavily on where an entity is licensed. The Central Bank supervises onshore banks and payment firms, the Dubai Financial Services Authority covers the DIFC, the Financial Services Regulatory Authority covers ADGM, and VARA regulates virtual assets in Dubai outside the DIFC. Emirates ID verification through UAE Pass is an accepted onboarding path, though an expatriate-majority population means document-based verification stays central rather than residual. Read our full AML guide for the United Arab Emirates.

Saudi Arabia

KYC requirements in Saudi Arabia are set by the Saudi Central Bank through its AML/CTF rules and rulebook, with the Capital Market Authority covering securities activity. Nationals and residents are verified against government records through Absher and Nafath, using the national ID or the Iqama residency credential. Reliance on those sources does not transfer the compliance obligation, a point SAMA has made explicit.

Nigeria

KYC requirements in Nigeria run on a three-tier account structure set by the Central Bank of Nigeria, with documentation and transaction limits tightening at each level. Since December 2023, Tier 2 and Tier 3 accounts must have both a Bank Verification Number and a National Identification Number linked, verified against NIBSS and NIMC rather than self-declared. Nigeria left the FATF grey list in October 2025 after more than two years.

Latin America

Brazil

KYC requirements in Brazil are anchored in Law 9,613/1998 and Circular 3,978/2020 from Banco Central do Brasil, with COAF acting as the financial intelligence unit. Identity turns on the CPF for individuals and the CNPJ for companies, validated against Receita Federal records, and a registration flagged as irregular will stop onboarding outright. Brazil's data protection law shapes retention and processing alongside the AML rules. Read our full AML guide for Brazil.

At a Glance

Country

Primary Regulator

Distinctive Requirement

United States

FinCEN

Beneficial ownership verified once at onboarding, not at every new account

Canada

FINTRAC

Five prescribed identity verification methods, including dual-process

United Kingdom

FCA

Mandatory enhanced due diligence narrowed to call-for-action countries

European Union

AMLA and national supervisors

Single rulebook applies directly from July 2027

Germany

BaFin

VideoIdent permitted; ownership filed to the Transparenzregister

India

Reserve Bank of India

Institution-specific KYC directions; video KYC data stored in India

Japan

Financial Services Agency

IC chip reading becomes the principal method from April 2027

Singapore

MAS

Separate binding notices by license type; Myinfo prefill

Malaysia

Bank Negara Malaysia

MyKad chip read and face match; six-year retention

Philippines

BSP

PhilSys national ID accepted as primary proof of identity

Australia

AUSTRAC

Tranche 2 professions in scope since July 2026

United Arab Emirates

CBUAE, DFSA, FSRA, VARA

Obligations differ by licensing zone

Saudi Arabia

SAMA

Verification against Absher and Nafath government records

Nigeria

Central Bank of Nigeria

Both BVN and NIN required above Tier 1

Brazil

Banco Central do Brasil

CPF and CNPJ validated against Receita Federal

KYC rules differ. Your workflow should not.

Complead brings onboarding, customer risk assessment and screening into one flow across the markets you serve.

800+financial institutions use Complead
70+countries served

High-Level Comparison: Where the Big Differences Are

Four differences account for most of the divergence between the regimes above.

Identity Infrastructure: National ID Versus Document Capture

The sharpest dividing line is whether a country has a queryable national identity database. India, Singapore, the Philippines, Malaysia, Nigeria, Brazil, Saudi Arabia, and the UAE all do, and onboarding in those markets can resolve to an authoritative government record in seconds. The United States, the United Kingdom, Canada, and Australia do not, so verification there means triangulating documents against credit files, electoral data, and commercial databases.

The consequence shows up in conversion rates and in coverage gaps. National ID rails work beautifully for residents and not at all for everyone else, which is why expatriate-heavy markets such as the UAE keep full document flows running in parallel rather than as a fallback.

 

Beneficial Ownership Thresholds

Twenty-five percent is the common anchor, used by the US CDD Rule, the UK register of people with significant control, Singapore, and the FATF standard itself. The edges are where errors happen. The EU moves from more than 25 percent to 25 percent or more in 2027, and the European Commission holds a reserved power to drop the figure as low as 15 percent for sectors assessed as high risk.

In August 2026 FinCEN finalized the rule exempting domestically formed companies and US persons from reporting to its beneficial ownership registry, closing a rollback that began with interim relief in March 2025. The separate obligation on banks to collect and verify beneficial owners at onboarding did not change. A registry closing is not a due diligence obligation lifting, and the two were widely conflated through 2026.

Remote Onboarding and eKYC Acceptance

Acceptance of remote verification is not a straight line from restrictive to permissive. India treats a properly conducted video session as equivalent to face-to-face verification, with no transaction cap attached. Malaysia sets detailed technical conditions, including reading the MyKad chip rather than photographing the card. Japan is tightening: Image-based verification for remote bank account opening ends in April 2027 in favor of IC chip reads, on the reasoning that forged documents are too hard to detect from photographs.

Europe is layering a public alternative underneath all of this. Every EU member state must make a certified European Digital Identity Wallet available by the end of 2026, with acceptance obligations following for regulated sectors. Firms building EU onboarding in 2026 are building against a rail that does not fully exist yet.

Data Localization and Cross-Border Transfer

Where verification data can sit is an architecture decision, not a policy footnote. India requires video verification recordings to be stored on systems located in India. Brazil's general data protection law governs retention alongside central bank rules. In the UAE, onshore, DIFC, and ADGM operate under different data regimes within the same country. Firms that centralize a single KYC datastore and then expand into these markets tend to discover the constraint late, after the integration is built.

How Technology Handles Multi-Country KYC

A modern KYC platform standardizes identity verification and screening across jurisdictions while accommodating local rules. In practice that means configurable onboarding flows per market, support for local document and credential types, connections to national identity sources where they exist, sanctions screening and politically exposed person screening against the lists each regulator expects, and ongoing monitoring that keeps customer records current rather than frozen at onboarding.

The operational test is whether a single policy engine can express fifteen different rulebooks without fifteen separate builds. Regional data residency, per-market retention periods, and audit trails an examiner can follow are the parts teams tend to underestimate.

Frequently asked questions

Is KYC the same in every country?

No. The objectives are the same almost everywhere, because nearly every country has adopted the FATF standards: Identify the customer, verify that identity, find the beneficial owner, understand the relationship, and monitor it. What differs is the implementation. Each regulator decides which documents are acceptable, whether remote verification is allowed and under what conditions, what ownership threshold triggers beneficial owner identification, how long records are kept, and where those records may be stored. A firm that meets the standard in one market usually has the right policy for the next one but rarely the right operational setup. The country guides linked throughout this page cover those operational differences market by market; for the concepts underneath all of them, start with what KYC is and how it works.

What is the FATF baseline for KYC?

The baseline is FATF Recommendation 10 on customer due diligence, supported by Recommendation 11 on record keeping and Recommendations 12 through 17 on politically exposed persons, correspondent banking, reliance on third parties, and related topics. Recommendation 10 requires financial institutions to identify and verify customers using reliable, independent source documents or data, to identify and take reasonable measures to verify beneficial owners, to understand the purpose and intended nature of the business relationship, and to conduct ongoing due diligence. It also sets the risk-based approach: Simplified measures where risk is lower, enhanced measures where it is higher. FATF does not write national law; each country transposes these principles through its own legislation and supervisory guidance, which is where the variation begins. FATF's separate lists of high-risk and monitored jurisdictions feed the country risk element of that risk-based approach, and the FATF grey list and blacklist change after each of the three plenaries a year.

Which countries accept eKYC or fully remote onboarding?

Most of the markets in this guide accept some form of remote verification, but the conditions vary widely. India permits video-based customer identification as a full equivalent to in-person verification, alongside Aadhaar-based eKYC. Singapore lets residents prefill verified data through Myinfo. Malaysia allows eKYC under a dedicated policy document that specifies chip reading and facial comparison. The Philippines permits electronic verification under BSP Circular 1170, and Germany accepts VideoIdent under BaFin conditions. The United Kingdom and United States allow non-face-to-face onboarding as long as the verification is reliable, which in practice means document checks combined with database and biometric checks. Japan is the notable exception moving the other way: From April 2027, uploading photographs of identity documents will no longer be sufficient for remote bank account opening, and IC chip reading becomes the principal method. The detail for each market is in the guides to KYC in India, KYC in Malaysia, and KYC in Japan.

What is the beneficial ownership threshold for KYC?

Twenty-five percent ownership or control is the most common trigger, and it appears in the US Customer Due Diligence Rule, the UK's register of people with significant control, Singapore's notices, and the FATF guidance itself. Two things make this harder than it looks. First, the threshold is a floor, not a ceiling: Regulators expect firms to look below 25 percent when risk warrants it, and the EU's new regulation gives the European Commission a reserved power to lower the figure to 15 percent for high-risk sectors. Second, the exact wording matters. The EU is moving from "more than 25 percent" to "25 percent or more" from July 2027, which brings a shareholder with exactly 25 percent into scope for the first time. In the United States, the closure of the FinCEN beneficial ownership registry for domestic companies in 2026 did not change the obligation on banks to identify and verify beneficial owners at onboarding. The United States and European Union guides cover the mechanics in each regime.

Do KYC records have to be stored in the country where the customer is onboarded?

In several markets, yes, or partly. India requires video verification recordings to be kept on systems located in India. The United Arab Emirates runs different data regimes for onshore entities, the DIFC, and ADGM, so a single datastore may not satisfy all three. Brazil's general data protection law governs how identity data is retained and transferred alongside the central bank's AML rules. Other jurisdictions, including the United Kingdom and Singapore, focus on accessibility and security rather than physical location, provided the records can be produced to the regulator promptly. The practical consequence is that data residency needs to be designed before a multi-country KYC stack is built, not retrofitted after. The UAE, Brazil, and India guides set out the specific rules.

How long do KYC records have to be kept?

Five years after the end of the business relationship or the date of the transaction is the FATF baseline and the norm in the United States, the United Kingdom, the European Union, Singapore, and most other markets. Some regulators go further. Malaysia requires six years. Several jurisdictions extend the period on request from a competent authority or where an investigation is open. Retention also covers more than the identity documents themselves: Account files, business correspondence, results of any analysis performed, and the audit trail of decisions all fall within scope. Since the period runs from the end of the relationship rather than its start, a long-standing customer can generate a retention obligation lasting decades. Country-specific periods are noted in each guide, including KYC in Malaysia and KYC in the United Kingdom.

Which documents are accepted for KYC verification?

The answer depends on whether the country has a national identity system. Where one exists, such as Aadhaar in India, PhilSys in the Philippines, MyKad in Malaysia, Emirates ID in the UAE, or the CPF in Brazil, the national credential is usually the primary proof of identity and can often be verified directly against the issuing database. Where one does not exist, as in the United States, the United Kingdom, Canada, and Australia, firms rely on a combination of government-issued photo identification, typically a passport or driving license, plus a separate proof of address such as a utility bill, bank statement, or tax document, cross-checked against credit bureau or electoral data. For companies, the document set expands to incorporation records, registers of directors and shareholders, and beneficial ownership declarations. The guide to KYC documents explains what each document proves and how it is verified.

Which businesses have to comply with KYC rules?

Banks, payment institutions, e-money issuers, securities firms, and insurers are in scope in every market covered here. Beyond that core, the perimeter varies. Crypto exchanges and virtual asset service providers are regulated for AML and KYC in the United States, the European Union, the United Kingdom, Singapore, Japan, and the UAE among others, though under different licensing regimes. The larger recent change is the extension to professions outside finance. Australia's second tranche of AML/CTF reforms, in force since July 2026, brought lawyers, accountants, real estate agents, conveyancers, trust and company service providers, and dealers in precious metals and stones under AUSTRAC supervision, with the obligation attaching to the service performed rather than the professional title. The EU's regulation applies a single scope definition across all member states from 2027. The Australia guide covers the tranche 2 perimeter in detail, and the guide to building an AML compliance program covers what falls on a newly regulated business once it is in scope.

Minhac Celik
Written by Minhac Celik Marketing Lead

Minhac Celik is Marketing Lead at Complead, covering US regulation, PEP and entity screening, onboarding fraud and company news.

Originally published , updated

Back to blog