Fintech 4 min read
KYC
Know your customer Also known as: know your customer, eKYC
Definition
Know your customer (KYC) is the process in which a financial company identifies a customer and verifies their identity, usually at onboarding, as part of its anti-money laundering duties. eKYC is the remote, digital form of that process.
Cite this entry
Text
"KYC". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/kyc/
HTML
<a href="https://ordergroup.co/glossary/kyc/">KYC</a> - Order Group
How KYC works
KYC is an industry name, not a legal term. The law speaks of customer due diligence: in Poland, środki bezpieczeństwa finansowego under the Anti-Money Laundering Act of March 1, 2018, and in the EU, from July 10, 2027, customer due diligence under the Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624. KYC is the part of it that a customer sees: who they are and how the company knows it.
Lenders are covered. The Polish Act lists loan institutions within the meaning of the Consumer Credit Act among obliged institutions (Article 2(1)(25)). The AMLR counts as a financial institution a creditor within the meaning of the Consumer Credit Directive 2008/48/EC (Article 2(1)(6)(g)), and financial institutions are obliged entities (Article 3). Due diligence applies, among other cases, when a business relationship is established (Polish Act Article 35(1); AMLR Article 19(1)).
Due diligence has more parts than the identity check. The Polish Act lists identifying and verifying the customer, identifying the beneficial owner, assessing the business relationship and ongoing monitoring (Article 34(1)). The AMLR lists among the due diligence measures also checks for targeted financial sanctions and politically exposed persons (Article 20(1)). For a natural person the Polish Act requires, among other data, the name, citizenship, PESEL number (or date and country of birth when there is none) and the series and number of the identity document (Article 36(1)).
Verification confirms that data. Under the Polish Act it uses an identity document or other documents, data or information from a reliable and independent source, including, where available, electronic identification means or trust services under the eIDAS Regulation (Article 37(1)). The AMLR narrows this to two routes (Article 22(6)): an identity document, passport or equivalent, where relevant with information from reliable and independent sources, or electronic identification means at assurance level substantial
or high
under eIDAS together with relevant qualified trust services. Records are kept for five years: from the end of the relationship under the Polish Act (Article 49(1)), and under the AMLR also from a refusal to enter into one (Article 77(3)).
eKYC is the remote form of the same process: a scan of the identity document, often compared with a selfie, or an electronic identity. It is a way of performing KYC, not a separate legal duty.
What KYC means for your software
For a lending app, KYC is a series of states in the application, with outside services in between. Requirements for the system:
- Methods are configuration. Keep the order of verification methods (electronic identity, document scan, manual review) in the backend, so a change after new technical standards does not need a new app version.
- Every attempt is recorded. Store which method and which provider checked what, when and with what result. The record outlives the customer relationship by five years.
- Verification has its own status. An application waiting for KYC, a failed attempt and a manual review are separate states with messages the customer understands, not one generic
pending
. - Retries are rules. Decide how many attempts a customer gets, what happens after the limit and whether a rejected application blocks a new one. Put those rules where they can be changed.
- Interruptions are normal. A dropped connection or a provider timeout should leave the application resumable, and the app should ask for the result again instead of assuming it.
- Account checks are not identity checks. A verification transfer or a bank login through open banking confirms the account and helps against fraud, but neither is among the identity verification means that Article 22(6) of the AMLR lists from July 10, 2027.
- Other checks run next to KYC. In Poland a lender also checks the PESEL restriction before a consumer credit agreement, and a lender may add device fingerprinting against fraud. They are separate steps with separate records.
| Route | Legal basis | What the system needs |
|---|---|---|
| Identity document, with information from reliable and independent sources where relevant | AMLR Art. 22(6)(a); Polish AML Act Art. 37(1) | Document capture, provider result, copy kept for five years |
| Electronic identification, substantial or high, with qualified trust services | AMLR Art. 22(6)(b); eIDAS | Integration with the eID scheme, record of the assurance level |
| Data needed to identify a natural person | Polish AML Act Art. 36(1) | Fields for name, citizenship, PESEL, document series and number |
| Sanctions and politically exposed persons | AMLR Art. 20(1)(d) and (g) | Screening step and its result in the customer record |
| Record retention | Polish AML Act Art. 49; AMLR Art. 77(3) | Retention policy tied to the end of the relationship |
Rules and regulation
The AMLR applies from July 10, 2027 and is directly applicable in all Member States (Article 90); only football agents and professional football clubs get a later date, July 10, 2029. Under Article 28(1), the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) had to develop draft regulatory technical standards on customer due diligence by July 10, 2026 and submit them to the European Commission for adoption. They specify, among other things, the information to collect for standard, simplified and enhanced due diligence. Until the AMLR applies, Polish lenders follow the Anti-Money Laundering Act of 2018. This entry is not legal advice; which duties apply depends on the company's status.
From our projects
In Aasa24, the lending app we have built and developed for Aasa Polska since May 2023, KYC runs inside the card application. The customer applies for the Visa credit card with an online identity check that includes a scan of the identity document. In April 2025 the app got handling of application status 49, "Credit Card - KYC". In May 2025 we added retrying the process after a negative result, and from August 2025 a positive bank account verification moves the card application on to the KYC status. In October 2025 the app started asking for the KYC result when the customer taps Next
on a pending card application.
In March 2026 we changed a retry rule: an application rejected after three failed KYC attempts no longer prevents the customer from going through KYC on a new application. In June 2026 we added retries of KYC tasks. We did not build the identity verification service; it is an external service.
Sources
- Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (AMLR) - EUR-Lex
- Ustawa z dnia 1 marca 2018 r. o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu (tekst jednolity Dz.U. 2025 poz. 644) - Sejm RP
- Regulation (EU) No 910/2014 on electronic identification and trust services (eIDAS) - EUR-Lex
FAQ
-
KYC is identifying a customer and verifying their identity. eKYC is the same process done remotely, with a document scan, a selfie or an electronic identity. It is a method; the legal duties stay the same.
-
In Poland, loan institutions are obliged institutions under the Anti-Money Laundering Act. Under the AMLR, consumer credit lenders are financial institutions and obliged entities from July 10, 2027.
-
Until July 10, 2027, the Polish AML Act allows verification based on documents, data or information from a reliable and independent source (Article 37(1)), so whether a transfer is enough is a question for your lawyer. From that date, Article 22(6) of the AMLR names an identity document or electronic identification with qualified trust services, and a transfer is not among them. A transfer remains useful for confirming the bank account and against fraud.
-
Five years. Under the Polish Act the period runs from the end of the business relationship; under the AMLR also from a refused relationship.
Building a system that depends on KYC?
See how we build software for this domain, with case studies and the stack we use.