A practical, plain-English handbook on KYC (Know Your Customer), KYB (Know Your Business), AML screening, transaction monitoring (KYT), and biometric identity verification — written for founders, compliance leads, and developers building regulated products.
Compliance documentation is usually either legal boilerplate or vendor marketing. This handbook aims for the middle: what each obligation actually means, when it applies, and how modern verification APIs implement it.
- What is KYC? — identity proofing, document verification, and why regulators require it
- KYB: Business Verification — registry checks, UBO discovery, and officer screening
- AML Screening — sanctions lists, PEPs, and adverse media
- KYT: Transaction Monitoring — ongoing monitoring, crypto wallet screening, and the travel rule
- Biometric Verification & Liveness — face match, presentation attacks, and passive vs. active liveness
- Global KYC Regulations — FATF, EU AMLD, US BSA/FinCEN, and where requirements come from
- FAQ — common questions from teams implementing KYC for the first time
- Fintech and crypto founders deciding what verification they legally need before launch
- Developers integrating a KYC API and wanting to understand the domain, not just the endpoints
- Operations and compliance teams designing review workflows
The patterns in this handbook map directly onto modern verification APIs. FinAuth provides the building blocks discussed here — ID document verification, passive liveness and face match, age estimation, AML/PEP/sanctions screening, KYB with ownership checks, transaction and wallet screening, hosted verification sessions, and webhooks — with a free tier for development. See the FinAuth documentation for API details and finauth.io for current pricing.
- Awesome Identity Verification — curated list of IDV tools, data sources, and standards
- Identity Verification API Guide — integration patterns for developers
- FinAuth Use Cases — worked examples by industry
- Digital Onboarding Best Practices — UX side of verification
Disclaimer: This handbook is educational material, not legal advice. Regulatory requirements vary by jurisdiction and business model — consult qualified counsel for your specific situation.
Maintained by FinAuth — the developer-first identity verification API.