Know Your Customer and Anti-Money-Laundering Obligations
7 steps · one page
In short
Being asked to prove who you are, when you are the one handing over money, is one of the more counterintuitive experiences in finance. The request is easier to understand once you know that it is not about you.
Scope, and one category of information is deliberately absent. This article explains why a firm asks for documents and what legal obligation it is discharging when it does. It states no reporting threshold, no transaction size that triggers a filing, and nothing about how obligations might be avoided. That omission is deliberate and is stated rather than concealed: material of that kind functions as instruction for the people these rules exist to catch, and it does nothing for a reader trying to understand a request they have just received. United States framework, verified 17 August 2026; the European Union operates a separate regime and the closing section says so.
The firm is not assessing your trustworthiness. It is producing evidence for its own examiner.
Where the obligation comes from
The framework rests on the Bank Secrecy Act, which dates from 1970, and its basic architecture has not changed since: private institutions collect financial intelligence, it is aggregated centrally, and it is made available to law enforcement.
| Instrument | What it added |
|---|---|
| Bank Secrecy Act (1970) | The reporting and recordkeeping architecture |
| USA PATRIOT Act (2001), section 326 | Customer identification programmes — the requirement behind the document request |
| USA PATRIOT Act, section 352 | A mandatory AML programme with four minimum elements, set out below |
| Customer Due Diligence Rule (2016, amended 2017) | Understanding the nature and purpose of the relationship; ongoing monitoring; updating information on a risk basis |
| Anti-Money Laundering Act of 2020 | The most substantial reform in two decades — examination priorities, effectiveness standards, corporate beneficial ownership reporting, and information sharing with foreign affiliates |
The four minimum elements of an AML programme are internal policies, procedures and controls; a designated compliance officer; an ongoing employee training programme; and an independent audit function that tests the programme.
What the brokerage rule adds
For brokerage firms, the self-regulatory layer described in Who Regulates What imposes its own requirement on top.
A member firm must have a written AML programme, approved in writing by a member of senior management, containing policies reasonably expected to detect and cause the reporting of suspicious transactions, and annual independent testing conducted by someone with a working knowledge of the underlying requirements.
The Bank Secrecy Act applies to all broker-dealers. There are no exceptions. Which is why the request cannot be waived by the person you are speaking to, however reasonable your explanation is — the obligation runs to the state, not to the customer, and the firm's own liability is what is at stake.
Worked example
The asymmetry worth understanding, because it explains the tone of these interactions. The customer bears the inconvenience. The firm bears the liability. And the duty is owed to neither of them — it is owed to a regulator. So there is nothing to negotiate and no discretion for staff to exercise, and a refusal that sounds inflexible is inflexible by design. It also means the request is not evidence that anything is wrong. Identity verification at account opening applies to every customer opening a new account, not to selected ones.
It does not stop at onboarding
The requirement most people are unaware of is that the obligation is continuing rather than one-off.
Firms must understand the nature and purpose of a customer relationship, monitor it on an ongoing basis, and update customer information on a risk basis. So a question arriving years after an account was opened is not a sign that earlier answers were unsatisfactory.
A firm's programme must also be risk-based, which means the depth of enquiry legitimately differs between customers. For accounts held by legal entities rather than individuals, the identification of beneficial owners applies — though a firm is generally not required to look through a trust to its beneficiaries, or through an intermediary holding an omnibus account, and may verify the named accountholder instead.
A recent change, and an illustration of why nothing in this area should be assumed to be current. On 13 February 2026 the central financial-intelligence bureau granted exceptive relief from the requirement to identify and verify the beneficial owners of a legal entity customer at each new account opening. Institutions may now limit that identification to three circumstances: when the entity first opens an account; when the institution learns facts that reasonably call into question the reliability of information previously obtained; and as needed under its own risk-based ongoing due diligence. Every other obligation — programme, recordkeeping and reporting — continues unchanged. This portal reports the relief as a fact and takes no view on it. The reason it appears here is procedural: an article written six months earlier would have described the previous position with complete confidence, and a reader would have had no way of knowing.
Two things that are easier to bear once explained
Sanctions screening produces false matches. Names are checked against lists, and a person who shares a name with a listed individual can be delayed while that is resolved. The delay reflects a name collision rather than any allegation.
A firm may be unable to tell you what is happening. Suspicious-activity reporting is subject to statutory confidentiality: a firm that has filed such a report, or that has information which would reveal that one exists, is prohibited by federal law from disclosing that fact to the person concerned — so where a firm has concerns it may be legally restricted in what it can say about them. An account restriction accompanied by no explanation is therefore not necessarily rudeness or incompetence — it may be a legal constraint on the firm. A reader in that position should seek their own legal advice rather than an explanation from the firm, because the firm may not be permitted to give one.
Other jurisdictions
The European Union operates a separate and differently structured regime, and terminology overlaps without equivalence. A reader with accounts in more than one jurisdiction should expect different documentation, different retention periods and different thresholds, and should not assume that satisfying one framework satisfies another.
Frequently asked
8 questions
Why does a firm need to verify my identity when I am the one paying?
Because it is not assessing your trustworthiness — it is producing evidence for its own examiner. Section 326 of the USA PATRIOT Act requires customer identification programmes, and the duty is owed to a regulator rather than to you.
Where does the framework come from?
The Bank Secrecy Act of 1970, extended by the USA PATRIOT Act in 2001, the Customer Due Diligence Rule of 2016 and the Anti-Money Laundering Act of 2020. The basic architecture is unchanged since 1970: private institutions collect financial intelligence, it is aggregated centrally, and it is made available to law enforcement.
What must a firm's programme contain?
Four minimum elements: internal policies, procedures and controls; a designated compliance officer; ongoing employee training; and an independent audit function testing the programme. Brokerage firms must additionally have a written programme approved in writing by senior management, with annual independent testing.
Can the request be waived?
No. The Bank Secrecy Act applies to all broker-dealers with no exceptions, the obligation runs to the state rather than to the customer, and the firm's own liability is at stake. A refusal that sounds inflexible is inflexible by design.
Does being asked mean I am suspected of something?
No. Identity verification at account opening applies to every customer opening a new account, not to selected ones.
Why am I being asked again years later?
Because the obligation is continuing rather than one-off. Firms must understand the nature and purpose of a relationship, monitor it on an ongoing basis, and update information on a risk basis. A later question is not a sign that earlier answers were unsatisfactory.
Why might my account be restricted with no explanation?
Suspicious-activity reporting is subject to statutory confidentiality: a firm is prohibited by federal law from telling the person concerned that such a report exists. A restriction with no explanation may be a legal constraint on the firm rather than rudeness — and a reader in that position should seek their own legal advice, since the firm may not be permitted to explain.
Why was I delayed over my name?
Sanctions screening checks names against lists, and someone sharing a name with a listed individual can be delayed while that is resolved. The delay reflects a name collision rather than an allegation.
References
- FINRA Rule 3310 — Anti-Money Laundering Compliance Program —
- FINRA — Anti-Money Laundering frequently asked questions —
- FinCEN Order FIN-2026-R001 (13 February 2026) — exceptive relief from beneficial owner identification at each account opening —
- FinCEN — Customer Due Diligence Rule frequently asked questions —
- 31 CFR 1023.320 — Reports by brokers or dealers of suspicious transactions (paragraph (e): confidentiality of the report and of information revealing its existence) —
- OCC — Bank Secrecy Act and related regulations —
Educational and informational only — not investment advice, a recommendation, or an offer to buy or sell any security. Investing involves risk, including the possible loss of principal. Worked examples use fictional companies and figures.