Practical guide
KYC vs AML vs sanctions screening: a practical comparison
Separate KYC, KYB, CDD, AML, and sanctions screening so your onboarding workflow records what each control actually verifies and leaves unresolved.
On this page
The terms describe related, not interchangeable work
KYC means know your customer. It usually refers to identifying and understanding a customer as part of onboarding and ongoing due diligence. KYB applies related identity and business-understanding work to organizations. AML is the wider anti-money-laundering framework. Sanctions screening compares submitted identities with selected sanctions data.
The exact duties depend on the jurisdiction and type of institution. FinCEN’s CDD material provides a useful official example of how identity, ownership, relationship purpose, and ongoing diligence remain distinct.
KYC and KYB establish the subject of the relationship
For a person, the organization needs reliable identity information under its applicable process. For a business, the legal entity, registration information, relevant ownership, and people acting for it can matter. A trading name by itself may not identify the contracting entity.
Sanctions screening can use verified information collected by those processes, but it does not authenticate a passport, validate a selfie, or prove a corporate ownership chain merely by matching a name.
Sanctions screening compares the subject with a source
A screening result identifies potential candidates or no matches within selected coverage. A reviewer then determines whether a candidate and the customer are the same identity. Applicable restrictions still need separate analysis.
OFAC’s match guidance is about comparing the actual identifying facts. It is not a claim that a sanctions search completes all customer due diligence.
AML also concerns activity and program controls
An AML program can include transaction-related review, reporting obligations, training, internal controls, responsible personnel, and independent testing. Which requirements apply is an institution-specific question. A sanctions case can be one input to that program without replacing it.
For example, an invented corporate customer could have verified incorporation details and no direct-list match while still requiring further source-of-funds inquiry. Each conclusion has a scope. The application should retain those scopes instead of combining them into an unexplained risk score.
Use a control map in the onboarding design
Assign each step an input, output, owner, and failure path. Keep the user-facing workflow simple while preserving the underlying distinctions for reviewers. A missing identity document, an unavailable sanctions source, and a confirmed candidate should not share the same generic error.
Illustrative control map
Identity: verified / unresolved / failed verification
Business identity: identified legal entity / unresolved
Ownership diligence: assessed / further work required
Sanctions screening: potential_match / no_match / incomplete
Identity review of a candidate: open / confirmed / dismissed
Business decision: recorded separately under approved policyWhere SanctionsKit fits
SanctionsKit provides selected-source screening, retained result evidence, per-match review, counterparty records, and ongoing sanctions monitoring. Its dashboard helps people investigate API and manual screening results in the same workflow.
Use separate services and procedures for controls outside that scope. Clear boundaries make integrations easier to test and procurement claims easier to substantiate. Start with customer screening and the product overview.