KYC in France: Customer Identification and Verification Requirements

Learn about KYC in France, including identity verification, beneficial ownership, risk-based due diligence and ongoing AML/CFT requirements.

KYC identity verification process for customers in France

KYC in France involves identifying customers, verifying their identities and, where required, identifying their beneficial owners before establishing a business relationship. For organisations covered by French anti-money laundering and counter-terrorist financing (AML/CFT) legislation, these checks form part of customer due diligence and help manage financial crime risks.

The requirements vary according to an organisation’s legal status, activities, customer type and risk profile. Depending on the circumstances, additional checks, enhanced due diligence and ongoing monitoring may also be necessary.

This guide explains the French regulatory framework, the information required for individual and business customers, beneficial ownership verification, risk-based checks and procedures for handling incomplete information. It also outlines practical ways to strengthen KYC processes and develop relevant compliance knowledge.

What Is KYC and Why Does It Matter in France?

Know Your Customer (KYC) is the process of establishing who a customer is, verifying relevant identity information and understanding the purpose and nature of the business relationship.

In France, KYC supports lutte contre le blanchiment de capitaux et le financement du terrorisme (LCB-FT), the French framework for combating money laundering and terrorist financing.

For covered entities, Article L. 561-5 of the French Monetary and Financial Code establishes customer identification and verification obligations, including relevant beneficial ownership checks.

KYC helps organisations establish reliable customer profiles, understand ownership structures and identify relationships that require closer scrutiny. It also provides a foundation for assessing whether customer activity is consistent with the expected purpose of the relationship.

Two activities are particularly important:

  • Identification: Collecting the information needed to establish who the customer is.

  • Verification: Checking that information against appropriate, reliable evidence or an accepted verification method.

Collecting a name or registration number alone may not satisfy the applicable requirements. Covered organisations must complete the verification measures required by the relevant legal framework.

KYC, AML and Customer Due Diligence: What Is the Difference?

Although connected, these terms describe different aspects of compliance.

  • KYC focuses on identifying and verifying customers and understanding their relationships.

  • AML/CFT refers to the wider framework for preventing and detecting money laundering and terrorist financing.

  • Customer due diligence (CDD) encompasses relevant identification, verification, beneficial ownership and ongoing vigilance measures.

KYC therefore supports a broader compliance system that may include transaction monitoring, sanctions screening, internal controls and suspicious transaction reporting.

For a more detailed comparison, read KYC versus AML: Key Differences Explained.

KYC in France involves identifying customers, verifying their identities and, where required, identifying their beneficial owners before establishing a business relationship. For organisations covered by French anti-money laundering and counter-terrorist financing (AML/CFT) legislation, these checks form part of customer due diligence and help manage financial crime risks. The requirements vary according to an organisation’s legal status, activities, customer type and risk profile. Depending on the circumstances, additional checks, enhanced due diligence and ongoing monitoring may also be necessary. This guide explains the French regulatory framework, the information required for individual and business customers, beneficial ownership verification, risk-based checks and procedures for handling incomplete information. It also outlines practical ways to strengthen KYC processes and develop relevant compliance knowledge. What Is KYC and Why Does It Matter in France? Know Your Customer (KYC) is the process of establishing who a customer is, verifying relevant identity information and understanding the purpose and nature of the business relationship. In France, KYC supports lutte contre le blanchiment de capitaux et le financement du terrorisme (LCB-FT), the French framework for combating money laundering and terrorist financing. For covered entities, Article L. 561-5 of the French Monetary and Financial Code establishes customer identification and verification obligations, including relevant beneficial ownership checks. KYC helps organisations establish reliable customer profiles, understand ownership structures and identify relationships that require closer scrutiny. It also provides a foundation for assessing whether customer activity is consistent with the expected purpose of the relationship. Two activities are particularly important: Identification: Collecting the information needed to establish who the customer is. Verification: Checking that information against appropriate, reliable evidence or an accepted verification method. Collecting a name or registration number alone may not satisfy the applicable requirements. Covered organisations must complete the verification measures required by the relevant legal framework. KYC, AML and Customer Due Diligence: What Is the Difference? Although connected, these terms describe different aspects of compliance. KYC focuses on identifying and verifying customers and understanding their relationships. AML/CFT refers to the wider framework for preventing and detecting money laundering and terrorist financing. Customer due diligence (CDD) encompasses relevant identification, verification, beneficial ownership and ongoing vigilance measures. KYC therefore supports a broader compliance system that may include transaction monitoring, sanctions screening, internal controls and suspicious transaction reporting. For a more detailed comparison, read KYC versus AML: Key Differences Explained.     Which Businesses Must Follow KYC Requirements in France? Article L. 561-2 of the French Monetary and Financial Code identifies the categories of persons and entities subject to French AML/CFT obligations. These include specified financial institutions and designated non-financial professionals. Depending on their activities and the applicable provisions, covered entities may include: Banks and specified financial institutions. Payment service providers and electronic money institutions. Relevant insurance and investment-sector entities. Certain professionals involved in property transactions. Notaries, accountants, lawyers in specified circumstances and other designated professionals. Certain gambling operators, company service providers and other expressly covered businesses. Not every business operating in France is automatically subject to identical statutory KYC requirements. Organisations should determine whether their activities and legal status bring them within the relevant provisions and whether sector-specific rules or exceptions apply. The roles of the main French authorities ACPR (Autorité de contrôle prudentiel et de résolution): Supervises relevant banking and insurance-sector entities within its remit. Its AML/CFT regulatory guidance explains requirements relevant to supervised organisations. AMF (Autorité des marchés financiers): Supervises relevant financial market participants within its remit. Its AML/CFT resources provide guidance for relevant market participants. TRACFIN (Traitement du renseignement et action contre les circuits financiers clandestins): France’s financial intelligence unit, which receives and analyses suspicious transaction reports and other information within its statutory remit. Understanding which rules and supervisory expectations apply is essential to designing an appropriate KYC programme. What Information and Documents Are Required for KYC in France? Required information depends on the customer type, the relationship, applicable legislation and the risks identified. Articles L. 561-5 and L. 561-5-1 address customer identification, verification and the collection of information about the purpose and nature of the business relationship. There is no single document checklist suitable for every customer and sector. Organisations should establish acceptable evidence and verification procedures that reflect their legal obligations. KYC Requirements for Individual Customers Relevant identification information may include: Full legal name. Date and place of birth, where required. Nationality or residential address, where relevant. Information about the intended business relationship. Additional information necessary for the applicable risk assessment. Verification evidence may include a passport, national identity card or another permitted method. The appropriate evidence depends on the applicable rules and circumstances. Remote onboarding requires particular care. Organisations should use verification methods permitted by the relevant French framework, which may include qualifying electronic identification or other recognised procedures. An uploaded identity document does not automatically establish that the person presenting it is genuine. If information conflicts with supporting evidence, the discrepancy should be investigated rather than ignored. KYC Requirements for Companies and Other Legal Entities Business customer due diligence involves establishing that the entity exists, understanding its structure and identifying the people who own, control or represent it. Relevant information may include: Legal name and legal form. Registration details and corporate evidence. Registered office or other relevant address. Ownership and control information. Identity of relevant representatives. Evidence of representative authority. Purpose and intended nature of the relationship. Company registration evidence can establish important details but may not reveal the complete ownership structure. For example, verifying a French company’s registration and director may not identify the natural persons who ultimately control it through several intermediate companies. Check Individual customer Business customer Identification Personal identity information Legal-entity information Verification Appropriate identity evidence Corporate and supporting evidence Representation Where applicable Representatives and their authority Ownership Where relevant Relevant beneficial owners Additional due diligence Based on applicable rules and risk Based on applicable rules and risk  This table is a practical summary, not a universal statutory checklist. How Does Beneficial Ownership Verification Work in France? A beneficial owner (bénéficiaire effectif) is the natural person who ultimately owns or controls a customer or for whom an operation or activity is carried out, as defined by the applicable legal framework. Article L. 561-2-2 and related provisions of the French Monetary and Financial Code address beneficial ownership. For companies, Article R. 561-1 includes ownership of more than 25% of the capital or voting rights and certain other forms of control. A percentage alone does not capture every form of control. Organisations should consider direct and indirect ownership, voting arrangements and other relevant control mechanisms. A practical verification process involves: Establishing the ownership structure: Obtain relevant corporate information and supporting documents. Tracing indirect ownership: Examine intermediate entities where necessary to identify the natural persons ultimately concerned. Assessing other forms of control: Consider whether control exists beyond direct shareholding. Consulting relevant official information: Use available company and beneficial ownership register information appropriately. Resolving discrepancies: Investigate material differences between customer declarations, corporate documents and register information. Official register information can support verification, but complex structures or unexplained discrepancies may require additional evidence and escalation.     How to Carry Out KYC Checks in France: A Step-by-Step Process Step 1 — Identify the Customer and Understand the Relationship Collect the required identifying information and establish the purpose and intended nature of the relationship. For a company, this may involve understanding its activities, ownership and intended use of the service. For an individual, it may involve understanding why the service is needed and how the relationship is expected to operate. Step 2 — Verify Identity and Supporting Information Check customer information against appropriate evidence and use verification methods permitted by the applicable rules. For individuals, this may involve identity documents or accepted electronic verification. For businesses, it may involve registration details, corporate documents, ownership information and representative authority. Document unresolved inconsistencies and investigate them before treating verification as complete. Step 3 — Assess the Customer’s Risk Profile Assess relevant risk factors, including: Customer type and ownership complexity. Geographic exposure. Products and services involved. Delivery channels, including remote onboarding. Expected transaction patterns. Indicators of higher money laundering or terrorist financing risk. The measures applied should reflect both the assessed risk and mandatory legal requirements. Internal risk models must not override statutory obligations. Step 4 — Complete Relevant Screening and Additional Checks Depending on the circumstances, conduct politically exposed person (PEP) checks, relevant sanctions screening and enquiries into the source of funds or source of wealth. These activities serve different purposes: PEP checks identify people whose public functions or relevant connections may trigger additional due diligence. Sanctions screening assesses whether applicable restrictive measures affect a person or transaction. Source-of-funds enquiries examine where money involved in a transaction or relationship originated. Source-of-wealth enquiries examine how a person accumulated their wealth, where relevant. PEP status does not establish wrongdoing, and not every customer requires the same level of investigation. Step 5 — Record Decisions and Maintain the Customer File Keep records of verification measures, supporting evidence, risk assessments, screening results and decisions. Files should allow an authorised reviewer to understand what was checked, how discrepancies were handled and why a relationship was accepted, restricted or escalated. Article L. 561-12 establishes record-retention obligations for covered entities, subject to applicable provisions. Retention arrangements should also account for relevant data protection requirements. Practical KYC checklist Confirm the organisation’s applicable obligations. Collect required customer information. Verify identity and supporting evidence. Identify beneficial owners where applicable. Understand the relationship’s purpose and nature. Complete relevant risk assessments and screening. Resolve or escalate material discrepancies. Record decisions and establish review arrangements.  Mid-article CTA: Develop your AML/KYC knowledge Understanding the steps is only part of effective compliance. Professionals who want to develop their understanding of customer due diligence and the wider French and EU AML/CFT framework can explore the AML/KYC Compliance Course — France/EU as a learning resource.  Explore the AML/KYC Compliance Course — France/EU   When Are Enhanced Due Diligence and Ongoing KYC Reviews Needed? French AML/CFT requirements apply a risk-based approach, but organisations must still complete all mandatory checks. Standard due diligence involves the applicable identification, verification, relationship-purpose and ongoing vigilance measures. Simplified due diligence may be used only where the relevant legal conditions are met. It does not permit organisations to disregard mandatory requirements. Enhanced due diligence (EDD) involves additional measures where required by law or justified by the circumstances and risk. Article L. 561-10 addresses specified situations requiring additional vigilance, including relevant PEP relationships and certain higher-risk exposures. Article L. 561-10-2 addresses enhanced examination of certain complex, unusually large or apparently unjustified transactions. PEP status may trigger additional measures, including applicable approvals and source-of-wealth or source-of-funds enquiries. The precise measures depend on the relevant provisions and circumstances. Ongoing KYC reviews Article L. 561-6 requires covered entities to exercise ongoing vigilance and examine transactions for consistency with their knowledge of the business relationship. Organisations should establish procedures to: Update customer and beneficial ownership information when required or when material changes occur. Reassess risk when new information becomes available. Investigate relevant changes in business activity or transaction behaviour. Review screening alerts and document decisions. Escalate unresolved concerns. There is no single review interval suitable for every relationship. Frequency and scope should reflect applicable rules and customer risk. KYC reviews complement rather than replace transaction monitoring. Learn more in AML Transaction Monitoring Explained. What Happens When KYC Requirements Cannot Be Satisfied? Missing, inconsistent or unverifiable information should be investigated rather than treated as a routine administrative issue. Organisations should request additional evidence where appropriate, document their actions, escalate unresolved concerns and determine whether the relationship can lawfully proceed. Under Article L. 561-8 of the French Monetary and Financial Code, an inability to complete required identification, verification or relationship-purpose checks may prevent a covered entity from establishing or continuing the business relationship or carrying out the relevant transaction. The precise consequences depend on the applicable provisions and circumstances. A discrepancy does not automatically establish suspicious activity or require a suspicious transaction report. However, when the applicable statutory reporting conditions are met, the organisation must assess and fulfil its reporting obligations. Eligible professionals submit suspicious transaction reports to TRACFIN under the relevant framework. Internal escalation and external reporting are separate processes. Common KYC Compliance Mistakes to Avoid Mistake How to avoid it Confusing identification with verification Check information against appropriate evidence. Accepting inconsistent documents Investigate discrepancies and document the outcome. Overlooking beneficial ownership Examine direct, indirect and other relevant forms of control. Applying inconsistent risk assessments Use documented, risk-based criteria. Neglecting information updates Establish appropriate review triggers. Keeping incomplete records Document evidence, decisions and rationale. Misinterpreting screening results Assess potential matches carefully before reaching conclusions. Failing to escalate issues Define clear escalation routes and responsibilities.  These weaknesses can reduce the effectiveness of KYC controls and make it harder to demonstrate that appropriate measures were taken. For more guidance, read Common AML Compliance Mistakes.     How Can Organisations Strengthen Their KYC Compliance Procedures? Effective KYC requires more than collecting documents. Organisations need procedures that reflect their legal obligations, business activities and customer risks. Establish written procedures. Define required information, acceptable verification methods, responsibilities and escalation criteria. Apply consistent risk-based processes. Use documented assessment criteria and ensure the resulting checks meet mandatory legal requirements. Improve recordkeeping and quality assurance. Review customer files for missing evidence, inconsistent decisions and weaknesses in beneficial ownership checks. Define escalation procedures. Staff should understand how to handle failed verification, potential sanctions matches, PEP-related alerts and other material concerns. Provide relevant staff training. Employees involved in onboarding, verification and compliance oversight need appropriate knowledge of their responsibilities. Update training when relevant rules and procedures change. Review procedures periodically. Assess whether controls continue to reflect current legislation, supervisory guidance, products, customer risks and operational changes. The AML Compliance Officer Guide provides further context on compliance oversight. Organisations can also explore AML Compliance Training in France. Training can strengthen staff understanding, but it does not guarantee compliance. Effective implementation also requires appropriate governance, systems and oversight.

Which Businesses Must Follow KYC Requirements in France?

Article L. 561-2 of the French Monetary and Financial Code identifies the categories of persons and entities subject to French AML/CFT obligations. These include specified financial institutions and designated non-financial professionals.

Depending on their activities and the applicable provisions, covered entities may include:

  • Banks and specified financial institutions.

  • Payment service providers and electronic money institutions.

  • Relevant insurance and investment-sector entities.

  • Certain professionals involved in property transactions.

  • Notaries, accountants, lawyers in specified circumstances and other designated professionals.

  • Certain gambling operators, company service providers and other expressly covered businesses.

Not every business operating in France is automatically subject to identical statutory KYC requirements. Organisations should determine whether their activities and legal status bring them within the relevant provisions and whether sector-specific rules or exceptions apply.

The roles of the main French authorities

  • ACPR (Autorité de contrôle prudentiel et de résolution): Supervises relevant banking and insurance-sector entities within its remit. Its AML/CFT regulatory guidance explains requirements relevant to supervised organisations.

  • AMF (Autorité des marchés financiers): Supervises relevant financial market participants within its remit. Its AML/CFT resources provide guidance for relevant market participants.

  • TRACFIN (Traitement du renseignement et action contre les circuits financiers clandestins): France’s financial intelligence unit, which receives and analyses suspicious transaction reports and other information within its statutory remit.

Understanding which rules and supervisory expectations apply is essential to designing an appropriate KYC programme.

What Information and Documents Are Required for KYC in France?

Required information depends on the customer type, the relationship, applicable legislation and the risks identified.

Articles L. 561-5 and L. 561-5-1 address customer identification, verification and the collection of information about the purpose and nature of the business relationship.

There is no single document checklist suitable for every customer and sector. Organisations should establish acceptable evidence and verification procedures that reflect their legal obligations.

KYC Requirements for Individual Customers

Relevant identification information may include:

  • Full legal name.

  • Date and place of birth, where required.

  • Nationality or residential address, where relevant.

  • Information about the intended business relationship.

  • Additional information necessary for the applicable risk assessment.

Verification evidence may include a passport, national identity card or another permitted method. The appropriate evidence depends on the applicable rules and circumstances.

Remote onboarding requires particular care. Organisations should use verification methods permitted by the relevant French framework, which may include qualifying electronic identification or other recognised procedures. An uploaded identity document does not automatically establish that the person presenting it is genuine.

If information conflicts with supporting evidence, the discrepancy should be investigated rather than ignored.

KYC Requirements for Companies and Other Legal Entities

Business customer due diligence involves establishing that the entity exists, understanding its structure and identifying the people who own, control or represent it.

Relevant information may include:

  • Legal name and legal form.

  • Registration details and corporate evidence.

  • Registered office or other relevant address.

  • Ownership and control information.

  • Identity of relevant representatives.

  • Evidence of representative authority.

  • Purpose and intended nature of the relationship.

Company registration evidence can establish important details but may not reveal the complete ownership structure. For example, verifying a French company’s registration and director may not identify the natural persons who ultimately control it through several intermediate companies.

Check

Individual customer

Business customer

Identification

Personal identity information

Legal-entity information

Verification

Appropriate identity evidence

Corporate and supporting evidence

Representation

Where applicable

Representatives and their authority

Ownership

Where relevant

Relevant beneficial owners

Additional due diligence

Based on applicable rules and risk

Based on applicable rules and risk

This table is a practical summary, not a universal statutory checklist.

How Does Beneficial Ownership Verification Work in France?

A beneficial owner (bénéficiaire effectif) is the natural person who ultimately owns or controls a customer or for whom an operation or activity is carried out, as defined by the applicable legal framework.

Article L. 561-2-2 and related provisions of the French Monetary and Financial Code address beneficial ownership. For companies, Article R. 561-1 includes ownership of more than 25% of the capital or voting rights and certain other forms of control.

A percentage alone does not capture every form of control. Organisations should consider direct and indirect ownership, voting arrangements and other relevant control mechanisms.

A practical verification process involves:

  1. Establishing the ownership structure: Obtain relevant corporate information and supporting documents.

  2. Tracing indirect ownership: Examine intermediate entities where necessary to identify the natural persons ultimately concerned.

  3. Assessing other forms of control: Consider whether control exists beyond direct shareholding.

  4. Consulting relevant official information: Use available company and beneficial ownership register information appropriately.

  5. Resolving discrepancies: Investigate material differences between customer declarations, corporate documents and register information.

Official register information can support verification, but complex structures or unexplained discrepancies may require additional evidence and escalation.

How to Carry Out KYC Checks in France: A Step-by-Step Process

Step 1 — Identify the Customer and Understand the Relationship

Collect the required identifying information and establish the purpose and intended nature of the relationship.

For a company, this may involve understanding its activities, ownership and intended use of the service. For an individual, it may involve understanding why the service is needed and how the relationship is expected to operate.

Step 2 — Verify Identity and Supporting Information

Check customer information against appropriate evidence and use verification methods permitted by the applicable rules.

For individuals, this may involve identity documents or accepted electronic verification. For businesses, it may involve registration details, corporate documents, ownership information and representative authority.

Document unresolved inconsistencies and investigate them before treating verification as complete.

Step 3 — Assess the Customer’s Risk Profile

Assess relevant risk factors, including:

  • Customer type and ownership complexity.

  • Geographic exposure.

  • Products and services involved.

  • Delivery channels, including remote onboarding.

  • Expected transaction patterns.

  • Indicators of higher money laundering or terrorist financing risk.

The measures applied should reflect both the assessed risk and mandatory legal requirements. Internal risk models must not override statutory obligations.

Step 4 — Complete Relevant Screening and Additional Checks

Depending on the circumstances, conduct politically exposed person (PEP) checks, relevant sanctions screening and enquiries into the source of funds or source of wealth.

These activities serve different purposes:

  • PEP checks identify people whose public functions or relevant connections may trigger additional due diligence.

  • Sanctions screening assesses whether applicable restrictive measures affect a person or transaction.

  • Source-of-funds enquiries examine where money involved in a transaction or relationship originated.

  • Source-of-wealth enquiries examine how a person accumulated their wealth, where relevant.

PEP status does not establish wrongdoing, and not every customer requires the same level of investigation.

Step 5 — Record Decisions and Maintain the Customer File

Keep records of verification measures, supporting evidence, risk assessments, screening results and decisions. Files should allow an authorised reviewer to understand what was checked, how discrepancies were handled and why a relationship was accepted, restricted or escalated.

Article L. 561-12 establishes record-retention obligations for covered entities, subject to applicable provisions. Retention arrangements should also account for relevant data protection requirements.

Practical KYC checklist

  • Confirm the organisation’s applicable obligations.

  • Collect required customer information.

  • Verify identity and supporting evidence.

  • Identify beneficial owners where applicable.

  • Understand the relationship’s purpose and nature.

  • Complete relevant risk assessments and screening.

  • Resolve or escalate material discrepancies.

  • Record decisions and establish review arrangements.


Mid-article CTA: Develop your AML/KYC knowledge

Understanding the steps is only part of effective compliance. Professionals who want to develop their understanding of customer due diligence and the wider French and EU AML/CFT framework can explore the AML/KYC Compliance Course — France/EU as a learning resource.

Explore the AML/KYC Compliance Course — France/EU

When Are Enhanced Due Diligence and Ongoing KYC Reviews Needed?

French AML/CFT requirements apply a risk-based approach, but organisations must still complete all mandatory checks.

Standard due diligence involves the applicable identification, verification, relationship-purpose and ongoing vigilance measures.

Simplified due diligence may be used only where the relevant legal conditions are met. It does not permit organisations to disregard mandatory requirements.

Enhanced due diligence (EDD) involves additional measures where required by law or justified by the circumstances and risk.

Article L. 561-10 addresses specified situations requiring additional vigilance, including relevant PEP relationships and certain higher-risk exposures. Article L. 561-10-2 addresses enhanced examination of certain complex, unusually large or apparently unjustified transactions.

PEP status may trigger additional measures, including applicable approvals and source-of-wealth or source-of-funds enquiries. The precise measures depend on the relevant provisions and circumstances.

Ongoing KYC reviews

Article L. 561-6 requires covered entities to exercise ongoing vigilance and examine transactions for consistency with their knowledge of the business relationship.

Organisations should establish procedures to:

  • Update customer and beneficial ownership information when required or when material changes occur.

  • Reassess risk when new information becomes available.

  • Investigate relevant changes in business activity or transaction behaviour.

  • Review screening alerts and document decisions.

  • Escalate unresolved concerns.

There is no single review interval suitable for every relationship. Frequency and scope should reflect applicable rules and customer risk.

KYC reviews complement rather than replace transaction monitoring. Learn more in AML Transaction Monitoring Explained.

What Happens When KYC Requirements Cannot Be Satisfied?

Missing, inconsistent or unverifiable information should be investigated rather than treated as a routine administrative issue.

Organisations should request additional evidence where appropriate, document their actions, escalate unresolved concerns and determine whether the relationship can lawfully proceed.

Under Article L. 561-8 of the French Monetary and Financial Code, an inability to complete required identification, verification or relationship-purpose checks may prevent a covered entity from establishing or continuing the business relationship or carrying out the relevant transaction. The precise consequences depend on the applicable provisions and circumstances.

A discrepancy does not automatically establish suspicious activity or require a suspicious transaction report. However, when the applicable statutory reporting conditions are met, the organisation must assess and fulfil its reporting obligations.

Eligible professionals submit suspicious transaction reports to TRACFIN under the relevant framework. Internal escalation and external reporting are separate processes.

Common KYC Compliance Mistakes to Avoid

Mistake

How to avoid it

Confusing identification with verification

Check information against appropriate evidence.

Accepting inconsistent documents

Investigate discrepancies and document the outcome.

Overlooking beneficial ownership

Examine direct, indirect and other relevant forms of control.

Applying inconsistent risk assessments

Use documented, risk-based criteria.

Neglecting information updates

Establish appropriate review triggers.

Keeping incomplete records

Document evidence, decisions and rationale.

Misinterpreting screening results

Assess potential matches carefully before reaching conclusions.

Failing to escalate issues

Define clear escalation routes and responsibilities.

These weaknesses can reduce the effectiveness of KYC controls and make it harder to demonstrate that appropriate measures were taken. For more guidance, read Common AML Compliance Mistakes.

How Can Organisations Strengthen Their KYC Compliance Procedures?

Effective KYC requires more than collecting documents. Organisations need procedures that reflect their legal obligations, business activities and customer risks.

Establish written procedures. Define required information, acceptable verification methods, responsibilities and escalation criteria.

Apply consistent risk-based processes. Use documented assessment criteria and ensure the resulting checks meet mandatory legal requirements.

Improve recordkeeping and quality assurance. Review customer files for missing evidence, inconsistent decisions and weaknesses in beneficial ownership checks.

Define escalation procedures. Staff should understand how to handle failed verification, potential sanctions matches, PEP-related alerts and other material concerns.

Provide relevant staff training. Employees involved in onboarding, verification and compliance oversight need appropriate knowledge of their responsibilities. Update training when relevant rules and procedures change.

Review procedures periodically. Assess whether controls continue to reflect current legislation, supervisory guidance, products, customer risks and operational changes.

The AML Compliance Officer Guide provides further context on compliance oversight. Organisations can also explore AML Compliance Training in France.

Training can strengthen staff understanding, but it does not guarantee compliance. Effective implementation also requires appropriate governance, systems and oversight.

Frequently Asked Questions

Covered entities generally need to identify and verify customers, identify relevant beneficial owners, understand the purpose and nature of the relationship, and conduct ongoing vigilance. Additional checks may apply depending on risk and customer circumstances. Exact requirements depend on the organisation’s legal obligations and activities.

Article L. 561-2 of the French Monetary and Financial Code identifies the entities subject to AML/CFT obligations, including specified financial institutions and designated non-financial professionals. The scope depends on the applicable provisions and activities. Not every French business has identical statutory KYC duties.

Depending on the circumstances, acceptable evidence may include a passport, national identity card, qualifying electronic identification or another permitted method. Businesses may need corporate registration, ownership and representation documents. Organisations must follow the requirements applicable to their sector and customer type.

Identification involves collecting information that establishes who the customer is. Verification involves checking that information against appropriate evidence or an accepted method. Collecting a name is identification; checking the details against reliable identity evidence is verification.

Organisations establish a company’s legal identity, verify relevant corporate information and confirm the authority of its representatives. They also identify and verify beneficial owners where required, considering direct and indirect ownership and other forms of control. Discrepancies may require further evidence and investigation.

Covered entities generally must identify and verify customers before establishing a business relationship. A limited statutory exception may permit verification during establishment where specified conditions are satisfied, including low risk and the need to avoid interrupting normal business. It is not a general permission to postpone checks.

Organisations must conduct ongoing vigilance and update relevant information as required. Review frequency should reflect the applicable rules and customer risk. Changes in ownership, circumstances or transaction behaviour may trigger a review. There is no single universal interval for every relationship.

Investigate the issue, request additional evidence where appropriate, document actions and escalate unresolved concerns. If required due diligence cannot be completed, applicable rules may prevent the relationship or transaction from proceeding. Separately assess whether the circumstances trigger a suspicious transaction reporting obligation.