KYC Software: The Two Requirements It Misses

Customer due diligence has four measures under FATF Recommendation 10. KYC software is built around the first two, treats beneficial ownership as a separate product, and leaves ongoing due diligence largely to you. This is the mapping.

The four customer due diligence measures and which ones KYC software covers

KYC software verifies who a customer is and records that you checked. It authenticates a government-issued identity document, matches it to a live selfie, checks the identity against authoritative data, screens the person against sanctions and watchlists, and stores the result as an audit record.

That is a real and useful product. It is also roughly half of what customer due diligence requires. The obligation has four parts, the software market is built around the first two, and the gap between them is where compliance programmes get found out. Knowing which parts you are buying is the whole decision, so it is worth starting with the requirement rather than the feature list.

What is KYC software?

KYC software is the tooling that establishes and records a customer's identity at onboarding. It handles three jobs: document authentication, biometric matching to confirm the person presenting the document is its holder, and screening against sanctions, watchlist and adverse-media data. Everything it produces exists to be shown to someone later.

Coverage determines whether it works for your customer base. As of 2026, Authenticate recognises 6,500+ government ID types across 203 countries, runs the verification flow in 38 languages, and returns a decision in 30 seconds. For the data side of identity, SSN-equivalent verification spans 196 countries. Screening reaches 40 countries of global watchlist and criminal data, including the sanctions lists published by OFAC, the US Treasury's Office of Foreign Assets Control.

The audit record matters as much as the decision. A verification you cannot produce in the form your regulator asks for is a verification you did not really make.

What does KYC actually require?

Four things, and this is the part every buyer's guide skips. Most guides to this category list vendors without ever stating the obligation those vendors exist to serve. According to the Financial Action Task Force's Recommendation 10 on customer due diligence, the international standard that national regimes implement, there are four measures.

1. Identify the customer

Establish who the customer claims to be, and collect the identifying information that supports it.

2. Verify that identity

Confirm the identification using, in FATF's phrase:

reliable, independent source documents, data or information

The word doing the work there is independent. A customer supplying their own name and date of birth is identification. Checking it against a source the customer does not control is verification. Software is genuinely good at this.

3. Identify and verify the beneficial owner

For a legal-entity customer, establish the natural person who ultimately owns or controls it. In the US this is codified: FinCEN's Customer Due Diligence Rule at 31 CFR 1010.230 requires covered financial institutions to identify and verify beneficial owners of legal entity customers, under two prongs. The ownership prong can require up to four individuals depending on the ownership structure, and sometimes none. The control prong requires one individual regardless.

4. Conduct ongoing due diligence

Scrutinise the relationship over its life, not once at the start, and keep the customer information current.

Two things about that list. It is a description of the standard, not advice about your programme: which regime applies to you, whether you are a covered institution, and what your regulator expects are questions for your compliance function and your counsel, not for a vendor's blog. And measure four is written in the present continuous for a reason.

Which of those requirements does KYC software cover?

Measures one and two, almost always. Measure three, rarely, and usually as a separate product. Measure four, partially at best. Mapping the four measures against what the category actually ships is the fastest way to see which parts of your obligation you have bought tooling for and which parts you are still doing by hand.

The measureWhat KYC software typically doesWhat is left to you
1. Identify the customerCollects and structures the identifying data through a hosted or embedded flowDeciding what to collect for which risk tier
2. Verify that identityDocument forensics, biometric match, and checks against independent data. This is the category's core competenceSetting the assurance threshold, and handling referrals
3. Identify and verify the beneficial ownerUsually nothing. This is sold separately as a business-verification productSourcing registry and ownership data, and resolving the chain to a natural person
4. Ongoing due diligenceA re-verification API you can call. Rarely anything that tells you when to call itDeciding what triggers a review, and detecting that a trigger occurred

So the honest summary: buying KYC software gets you strong tooling for measures one and two, a separate purchase for measure three, and a starting point for measure four. That is not a criticism of the products. It is a description of where the category has invested, and it explains why compliance teams who bought "KYC software" still find themselves building things.

Where a platform genuinely covers more than the first two measures, it is worth knowing. Authenticate handles the identity and screening layers, business verification for the entity side, and record monitoring for the ongoing measure, through one integration. Authenticate's KYC and AML screening covers how those pieces fit together.

What is the difference between KYC and KYB?

KYC establishes a natural person. Know Your Business (KYB) establishes a company, and then the natural people behind it. They sound like the same job at different scale, and they are not: one is a document-and-biometric problem with a defined answer, and the other is a records problem with an ownership chain at the end of it.

Verifying a person is a document-and-biometric problem with a well-defined answer: this document is genuine, and this is its holder. Verifying a business is a records problem with a chain at the end of it. You confirm the entity exists in a corporate registry, establish its ownership structure, follow that structure through any intermediate entities, and arrive at a natural person you can then verify like any other customer. The data sources are registries rather than identity documents, coverage varies enormously by jurisdiction, and ownership structures are designed by people who sometimes prefer them opaque.

This is measure three, and it is why beneficial ownership is the requirement most often outsourced to a second vendor. If you onboard only individuals, you do not need it, and no amount of vendor enthusiasm should convince you otherwise. If you onboard companies, an identity-only product cannot reach the answer. Authenticate's KYB verification covers the entity side.

Why is ongoing due diligence the requirement software most often misses?

Because it is the only measure that is not an event. A verification describes a person on the day it ran. Measure four asks about the relationship over its life, and a snapshot cannot answer a question about a period.

The practical failure mode is quiet. A customer onboards cleanly in March. In September something changes: a sanctions designation, an arrest, a warrant. Nothing in a verification-only stack notices. The record in your system still says the customer cleared, and it will keep saying that until someone re-runs the check, which usually happens on an annual cycle or after an incident.

Monitoring closes that window. As of 2026, True Continuous Monitoring (TCM™) covers 95%+ of the US adult population, ingests 100,000+ new criminal records every day, refreshes its covered databases every 60 seconds, and fires an alert within 24 hours when a record changes for someone you monitor. What it watches for is deliberately broad. A new arrest, warrant, booking or sanctions hit triggers an alert, not convictions alone. True Continuous Monitoring covers the mechanics.

One boundary worth stating plainly, because vendors in this category are vague about it. Monitoring a customer's records is not the same as monitoring their transactions. Transaction monitoring, alert triage and case management are a separate discipline with separate tooling, and Authenticate does not do them. If your programme needs both, you are buying two things, and you should know that before a procurement cycle tells you.

How should you evaluate KYC software?

The same way you evaluate any verification vendor, plus four checks that are specific to this obligation. The general work of decoding coverage claims and testing what a provider tells you is covered in detail in how to evaluate identity verification software, including the ten questions worth sending any provider. What follows is the KYC-specific layer on top of that.

Jurisdiction coverage against your licence, not against a map. A provider with excellent coverage in twenty countries is a problem the day you enter the twenty-first. Ask for depth per market you are actually licensed in.

Whether screening is included or an add-on. Sanctions and watchlist screening is measure two's companion and is frequently priced separately. Establish which lists are covered, how often they refresh, and what a match returns.

Whether the audit record is exportable in the form a regulator will accept. Ask to see an actual export, not a dashboard screenshot. This is the artefact your programme is judged on.

Whether ongoing due diligence is a product or a promise. "Supports perpetual KYC" can mean a monitoring service or an API you are expected to poll. Those are very different purchases.

Which type of KYC software fits your obligation?

Whichever one covers the measures that actually apply to you. A platform onboarding individuals in a single market has a genuinely bounded obligation and should buy the bounded product. A platform onboarding companies cannot reach measure three with an identity-only tool, however good it is. Match the purchase to the measure.

Your situationWhat to buyWhy
Individuals only, one marketDocument and biometric verification with screeningMeasures one and two are the whole obligation for you. Buy the bounded product
Individuals, many marketsA verification platform with per-market depthCoverage breadth becomes the binding constraint, not features
Legal-entity customersVerification plus business verificationMeasure three cannot be reached by an identity-only product
Established AML case management already in placeThe verification layer onlyDo not re-buy orchestration you already own
Ongoing due diligence is a live findingVerification plus record monitoringMeasure four needs something that notices, not something you call
No engineering capacityA no-code verification flowMedallion™ takes this path, with the same document and country reach as the API

The cross-cutting rule: buy against the measures that apply to you, and be able to say which measure each line of your vendor spend serves. A programme that cannot answer that is usually paying twice for one measure and nothing for another.

Frequently asked questions

What is KYC software? KYC software establishes and records a customer's identity at onboarding. It authenticates a government-issued identity document, matches it to a live selfie to confirm the holder, checks the identity against independent data sources, screens the person against sanctions and watchlists, and stores the result as an audit record you can produce later.

What is the difference between KYC and AML software? KYC software answers who the customer is. AML software watches what they do. KYC covers identity verification, screening and the due-diligence record; AML covers transaction monitoring, alert triage and case management. They are complementary and usually separate purchases. A vendor strong at one is not automatically strong at the other, so establish which you are being sold.

Does KYC software make my business compliant? No. Software provides the tooling and the evidence. Written policies, a risk-based approach, staff training, record-keeping and reporting remain your programme's obligations, and your regulator assesses the programme rather than the vendor. Treat software as the part of the answer that scales, and confirm the rest with your compliance function or counsel.

What is the difference between KYC and KYB? KYC verifies a natural person from documents and biometrics. Know Your Business verifies a company: it confirms the entity in a corporate registry, establishes the ownership structure, follows that structure through any intermediate entities, and arrives at the natural person who ultimately owns or controls it. Different data sources, and coverage varies widely by jurisdiction.

How long does a KYC check take? As of 2026 the identity portion returns in 30 seconds on a modern platform, and sanctions and watchlist screening returns in the same request. What extends a KYC decision is a referral to human review, or a business-verification step where registry data is slow in a given jurisdiction. Ask any provider for the time to decision alongside the share of cases routed to a reviewer.

Is ongoing monitoring part of KYC? Yes. FATF Recommendation 10's fourth measure is ongoing due diligence on the business relationship, which means the obligation continues after onboarding. Most KYC software treats verification as an onboarding event, so ongoing due diligence is commonly the least-tooled part of a programme and the one an examiner is most likely to ask about.

What should I look for in a KYC software provider? Jurisdiction depth in the markets you are licensed in, whether sanctions screening is included or priced separately, whether the audit record exports in a form a regulator will accept, and whether ongoing due diligence is an actual monitoring product or an API you are expected to call. Ask for a sandbox and test the failure cases, not the happy path.

Buy against the measures, not the feature list

KYC software is very good at establishing who someone is and proving you checked. It is close to silent on who really owns a corporate customer, and close to silent on what happens after onboarding. Those two gaps are not vendor failures; they are where the category has not invested. If you can name which of the four measures each part of your stack serves, you will spot the gap before an examiner does.

See how Authenticate handles KYC

Related resources