AML vs KYC: what is the difference?
AML is the entire regulatory regime a firm must operate — risk assessment, policies, training, screening, reporting and recordkeeping. KYC is one part of that regime: identifying and verifying the client and understanding their risk. Put simply, KYC is something you do to a client; AML is something your business must be.
Written by Andréas Hobbelin · Last updated
Side by side
The two terms are used interchangeably in everyday conversation, but they operate at different levels:
- Scope — AML covers the whole firm; KYC covers an individual client relationship.
- Trigger — AML obligations exist from the moment you are an obliged subject; KYC is triggered by a client or transaction.
- Output — AML produces policies, risk assessments, training and reports; KYC produces a client file.
- Owner — AML is owned by management and the appointed representative; KYC is executed by the client-facing team.
- Failure mode — an AML failure is systemic (no risk assessment, no training); a KYC failure is file-level (missing UBO, unverified ID).
Where CDD, EDD and screening fit
Customer due diligence (CDD) is the formal name for the KYC measures required by law. Enhanced due diligence (EDD) is the intensified version applied to higher-risk clients. PEP and sanctions screening are checks performed inside CDD and EDD. All of them sit under the AML umbrella.
Why the distinction matters in practice
Firms that treat AML as 'collecting ID copies' pass the KYC step and fail the AML inspection, because there is no documented risk assessment, no consistent application of measures and no evidence of training. Conversely, a good manual with weak file execution fails too. Supervisors look for both.
Frequently asked questions
Is CDD the same as KYC?
In practice they describe the same activity. CDD is the legal term used in Ley 10/2010 and the EU directives; KYC is the industry term.
Which comes first, AML or KYC?
AML comes first at firm level — your risk assessment and procedures determine how KYC is applied to each client.
Sources and further reading
Put this into practice
PropComply structures KYC/CDD once per client and shares it securely with the parties in the transaction — each keeping their own independent decision.
Request access