Hero background
Compliance Updates12 min read

AML KYC Requirements: A Lender's Guide

By Michael Dunleavey
September 29, 2025Updated July 21, 2026
kyc for lenderscustomer identification programknow your customer compliance

Understanding AML and KYC: Why the Distinction Matters for Lenders

Anti-Money Laundering and Know Your Customer are among the most frequently cited terms in financial compliance — and among the most frequently conflated. For lenders, understanding the distinction between them is not an academic exercise. It determines which regulatory obligations apply to your program, when they apply, and what documentation you need to demonstrate compliance.

The short version: KYC is a process within AML. AML is the broader regulatory framework; KYC is the customer-facing compliance procedure that sits at its foundation. Getting this right — and building it into your lending workflow from the start — is what separates institutions with sound compliance programs from those carrying live regulatory exposure.

Lenders operating on Salesforce can embed both frameworks into a single automated workflow. Schedule a Compliance Discussion to see how LASER's COMPLY pillar handles this for your program.

On this page:

What AML Is — and What It Isn't

Anti-Money Laundering refers to the comprehensive framework of laws, regulations, and procedures designed to prevent the use of the financial system to conceal illegally obtained funds. In the United States, the primary statutory framework is the Bank Secrecy Act, administered by the Financial Crimes Enforcement Network.

The BSA requires covered financial institutions to establish and maintain AML/CFT programs with four core components:

Program ComponentWhat It Requires
Internal ControlsWritten policies, procedures, and controls — including customer due diligence and ongoing monitoring
Independent TestingRegular audit or review of program effectiveness
AML/CFT OfficerA designated U.S.-based compliance officer
Ongoing TrainingRegular employee training on AML obligations

AML compliance is not limited to banks. The BSA's definition of "financial institution" covers a broad range of entities — including loan and finance companies, mortgage brokers, equipment financiers, and fintech platforms that extend credit.

What KYC Is — and How It Fits Within AML

Know Your Customer is the specific process financial institutions use to verify the identity of customers, assess their risk profile, and determine whether they qualify to open accounts or access financial services. KYC is a required component of every institution's AML program — not a separate obligation, but the customer-facing entry point into the broader compliance framework.

KYC has three primary components:

Customer Identification Program (CIP). The foundational KYC requirement under the USA PATRIOT Act, implemented through 31 CFR § 1020.220. CIP requires institutions to collect and verify specific identifying information before establishing any account — including a credit facility.

Customer Due Diligence (CDD). The ongoing process of assessing a customer's risk profile for money laundering or other financial crime. CDD determines which customers require standard verification, enhanced scrutiny, or ongoing monitoring.

Enhanced Due Diligence (EDD). Applied to higher-risk customers — including politically exposed persons, customers with complex ownership structures, and those operating in higher-risk jurisdictions. EDD requires additional verification and more intensive ongoing monitoring.

Yes — for institutions covered by the Bank Secrecy Act (BSA), Know Your Customer is a legal requirement, not a best practice. The BSA and its implementing regulations mandate a Customer Identification Program (CIP) and Customer Due Diligence, including beneficial-ownership verification. Whether a specific non-bank lender is bound depends on whether it qualifies as a BSA "financial institution."

For lenders, the practical answer is usually yes. The BSA's definition of "financial institution" reaches loan and finance companies, mortgage brokers, equipment financiers, and fintech platforms that extend credit — so KYC's identity-verification obligations under 31 CFR § 1020.220 attach at account opening, including when the "account" is a credit facility. Skipping or under-documenting KYC is not a process gap; it is live regulatory exposure.

CIP Requirements: What Lenders Must Collect and Verify

The Customer Identification Program requirement is the most operationally significant KYC obligation for most commercial lenders. Under 31 CFR § 1020.220, institutions must collect and verify the following information before establishing any account:

  • Full legal name
  • Date of birth (for individuals)
  • Address — residential for individuals; principal place of business for entities
  • Identification number — Social Security number or Individual Taxpayer Identification Number for U.S. persons; passport number or other government-issued document number for non-U.S. persons

Verification may be documentary (driver's license, passport, government-issued ID), non-documentary (credit bureau data, public records, third-party identity verification services), or a combination of both. When non-documentary verification involves pulling a consumer credit report, FCRA permissible purpose and compliance obligations apply alongside CIP requirements.

Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)

CIP answers a narrow question: is this customer who they claim to be? Customer Due Diligence answers a broader one: what money-laundering and financial-crime risk does this customer represent, and how closely should we watch the relationship? FinCEN's CDD Rule (31 CFR § 1010.230), effective since 2018, formalized CDD as a fifth pillar of the AML program alongside the four core components above.

For lenders, CDD has four working elements: identifying and verifying the customer (the CIP function); identifying and verifying the beneficial owners of legal-entity customers; understanding the nature and purpose of each customer relationship to establish a baseline risk profile; and conducting ongoing monitoring to identify and report suspicious activity and keep that profile current. In practice, CDD is what turns a one-time identity check into a living risk rating.

Enhanced Due Diligence applies when that rating comes back elevated. Higher-risk categories — politically exposed persons, customers with opaque or multi-layered ownership structures, cash-intensive businesses, and customers connected to higher-risk jurisdictions — require more than the standard file. EDD typically means collecting additional information on the source of funds and the purpose of the relationship, obtaining senior-management approval before onboarding, and monitoring the account more frequently and against tighter thresholds. The obligation is risk-based: the regulation prescribes no fixed checklist, so the depth of diligence must be defensible against the specific risk each customer presents.

When the borrower is a business rather than an individual, identity verification cannot stop at the entity. The CDD Rule requires covered institutions to identify and verify the natural persons behind a legal-entity customer at account opening, using two tests. The ownership prong captures each individual who directly or indirectly owns 25% or more of the entity's equity. The control prong captures at least one individual with significant responsibility to control or manage the entity — a CEO, CFO, managing member, general partner, or similar officer — regardless of ownership percentage.

For a commercial lender onboarding an LLC, a partnership, or a closely held corporation, that means collecting the same CIP-level identifying information for each beneficial owner and control person as for an individual borrower: name, date of birth, address, and identification number, verified documentarily or non-documentarily. The purpose is to keep shell companies and nominee structures from obscuring who actually stands behind a credit relationship — a common vector for money laundering and fraud. Institutions should also refresh beneficial-ownership information when a triggering event, such as a change in ownership or activity inconsistent with the customer's profile, signals the file has gone stale.

Ongoing Monitoring and Suspicious Activity Reporting

KYC is often treated as an onboarding gate — verify the customer once, open the account, move on. The regulations treat it as a continuous obligation. Ongoing monitoring is the fourth element of the CDD Rule: institutions must monitor customer activity to identify and report suspicious transactions and, on a risk basis, keep customer information current. A risk rating assigned at onboarding is a starting point, not a permanent label — activity that diverges from a customer's established profile is precisely the signal monitoring exists to catch.

Where monitoring surfaces activity with no apparent lawful purpose or a pattern consistent with money laundering or fraud, institutions subject to suspicious activity reporting must file a Suspicious Activity Report (SAR) with FinCEN, generally within 30 calendar days of initial detection. The quality of that filing depends directly on the quality of the underlying records: an examiner reviewing a SAR decision will look for the transaction history, the customer risk profile, and the documented rationale behind the escalation.

For a lender, the practical implication is that identity verification, risk rating, transaction data, and escalation decisions cannot live in separate systems. When the KYC record and the activity it should be measured against sit on the same platform, monitoring becomes a continuous property of normal operations rather than a periodic manual review that falls behind the moment volume rises.

Where FCRA Intersects with AML/KYC

The interaction between FCRA and BSA/AML CIP requirements creates a sequencing obligation that many lenders overlook. As detailed in our analysis of KYC timing and FCRA compliance, the BSA/AML framework requires identity verification before account opening, while FCRA governs permissible purpose for credit pulls but does not explicitly mandate completed KYC first.

This gap — if not closed through workflow design — creates both a compliance deficiency and a fraud vulnerability. Completing CIP verification before pulling credit reports satisfies both regulatory frameworks simultaneously and is the primary structural defense against synthetic identity fraud, which targets incomplete identity verification at the point of application. Sequencing the checks this way is exactly what loan application fraud prevention inside Salesforce is built to enforce.

How GLBA and the FTC Safeguards Rule Add to AML/KYC Obligations

AML/KYC compliance does not operate in isolation. The Gramm-Leach-Bliley Act governs how financial institutions protect the nonpublic personal information collected during KYC and throughout the lending relationship. The FTC Safeguards Rule (16 CFR Part 314) operationalizes GLBA's protection mandate through specific requirements for access controls, encryption, multi-factor authentication, vendor oversight, and incident response.

For lenders, this means the information collected during CIP verification — identity documents, financial data, identification numbers — is simultaneously subject to BSA/AML CIP requirements and GLBA/Safeguards Rule data protection obligations. Building a compliance program that addresses both frameworks within a single workflow is the most efficient and audit-ready approach.

Recordkeeping and Retention Requirements

An AML/KYC program is only as strong as the records that prove it ran. Under the CIP rule (31 CFR § 1020.220(a)(3)), institutions must retain the identifying information collected at account opening for five years after the account is closed, and must keep a description of the documents relied on, the methods used to verify identity, and the resolution of any discrepancies for five years after the record is made. Beneficial-ownership records obtained under the CDD Rule carry the same five-year-after-closure retention.

For lenders, the practical failure mode is not the absence of records but their fragmentation — identity documents in one system, verification results in another, and the compliance decision undocumented altogether. Examiners assess whether an institution can reconstruct, for any given account, who was verified, how, when, and by whom. A program that stores CIP data, the verification method, the permissible-purpose basis for any credit pull, and the reviewer's decision on a single record produces that reconstruction on demand — rather than as a scramble across disconnected systems once an examination or audit begins.

Building an Integrated AML/KYC Compliance Program

The most common compliance failure pattern in lending is not ignorance of the requirements — it is managing them as separate workstreams. AML team handles CIP. Compliance team handles FCRA. IT handles data security. The result is gaps at the intersections, duplicated effort, and documentation that does not hold up under examination.

The most effective approach is building an integrated compliance infrastructure that addresses CIP, FCRA, and GLBA/Safeguards Rule requirements within a single operational workflow. When compliance controls are embedded into the technology platform — rather than managed as separate manual processes — institutions reduce duplication, minimize gaps at framework intersections, and generate audit-ready documentation as a byproduct of normal lending operations.

LASER's COMPLY pillar is built for exactly this integration. Pre-built, pre-configured Salesforce objects automate CIP verification, documentation, and sequencing — ensuring every credit relationship begins with verified identity, documented compliance, and the audit trail regulators require. See how automated lending compliance software embeds FCRA permissible purpose, OFAC screening, and GLBA access controls into a single credit workflow.

What This Means for Your Institution

AML and KYC requirements are not optional for commercial lenders — and they are not solely a bank obligation. Non-bank lenders, equipment financiers, and fintech platforms that extend credit are covered institutions under the BSA, subject to the same CIP and AML/CFT program requirements as depository institutions. Those requirements are also evolving quickly — a May 2026 Executive Order set accelerated 60-, 90-, and 180-day deadlines for new AML/KYC guidance and proposed rules that lenders should be tracking now.

Understanding where AML ends and KYC begins — and how both intersect with FCRA and GLBA — is the foundation of a compliance program that functions under examination. The institutions that build this understanding into their technology workflows, rather than their policy binders, are the ones that demonstrate the kind of effective, risk-based compliance programs that regulators increasingly expect.

Further Reading


Schedule a Compliance Discussion to see how LASER's COMPLY pillar automates AML/KYC compliance inside Salesforce — from CIP verification through ongoing monitoring — without adding manual steps to your lending workflow.

Frequently Asked Questions

Is KYC a legal requirement?

Yes. For institutions covered by the Bank Secrecy Act (BSA), Know Your Customer is a legal requirement rather than an optional best practice. The BSA and its implementing regulations mandate a Customer Identification Program (CIP) under 31 CFR § 1020.220 and Customer Due Diligence under FinCEN's CDD Rule, including beneficial-ownership verification. Because the BSA's definition of 'financial institution' reaches loan and finance companies, equipment financiers, and fintech platforms that extend credit, most non-bank lenders are legally required to perform KYC at account opening — including when the account is a credit facility.

Do non-bank commercial lenders have to comply with AML and KYC requirements?

Yes. Non-bank commercial lenders — including equipment financiers and fintech platforms — are covered financial institutions under the Bank Secrecy Act when they extend credit. Customer Identification Program obligations under 31 CFR § 1020.220 apply to account-opening activities, including credit facilities.

What information must lenders collect under a Customer Identification Program?

At minimum: full legal name, date of birth, address, and a government-issued identification number. Verification may be documentary (ID documents), non-documentary (credit bureau or other data source verification), or a combination of both methods.

How do AML and KYC requirements interact with FCRA permissible purpose?

The BSA/AML CIP requires identity verification before account opening. FCRA governs permissible purpose for pulling consumer credit reports. When non-documentary KYC verification involves a credit bureau pull, FCRA compliance obligations — including adverse action notices — apply alongside BSA obligations. Sequencing CIP verification before the credit pull satisfies both frameworks.

Can Salesforce automate AML/KYC compliance workflows for lenders?

Yes. LASER's COMPLY pillar automates CIP verification, documentation, and recordkeeping inside a 100% Salesforce-native environment — eliminating manual compliance steps and building the audit trail regulators require as a byproduct of normal lending operations.

What is the difference between CDD and EDD?

Customer Due Diligence (CDD) is the baseline process every covered institution applies to understand a customer's risk profile and monitor the relationship over time, formalized in FinCEN's CDD Rule (31 CFR § 1010.230). Enhanced Due Diligence (EDD) is the heightened scrutiny applied to higher-risk customers — such as politically exposed persons, complex ownership structures, or higher-risk jurisdictions — and typically adds source-of-funds review, senior-management approval, and more frequent monitoring. CDD applies to every customer; EDD applies to the subset whose risk rating is elevated.

Who counts as a beneficial owner under KYC requirements?

Under the CDD Rule, a legal-entity customer's beneficial owners are identified by two tests: the ownership prong — each individual who directly or indirectly owns 25% or more of the entity's equity — and the control prong — at least one individual with significant responsibility to control or manage the entity, such as a CEO, CFO, managing member, or general partner. Lenders must collect and verify CIP-level identifying information for these individuals when onboarding a business borrower.

How long must lenders retain AML/KYC records?

Under the CIP rule (31 CFR § 1020.220(a)(3)), the identifying information collected at account opening must be retained for five years after the account is closed. Records describing the documents relied on, the verification methods used, and the resolution of any discrepancies must be kept for five years after the record is made. Beneficial-ownership records collected under the CDD Rule carry the same five-year-after-closure retention.

Michael Dunleavey

Founder — LASER Credit Access

Michael Dunleavey brings over 15 years of experience in credit infrastructure and lending compliance, helping financial institutions streamline operations on Salesforce.

Ready to Transform Your Credit Operations?

Discover how LASER Credit Access streamlines compliance and decisioning natively inside Salesforce — unified in a single app, ready from day one.