What is KYC and Why is it Important?

You’ve probably encountered situations where a bank, accounting firm, investment firm, or other service provider has asked you to verify your identity. If, on the other hand, you’ve been acting on behalf of a company, you may have been asked about the company’s owners, the purpose of its business, or the source of its funds.

These are not merely administrative formalities. They are based on regulations designed to prevent money laundering and the financing of terrorism.

KYC or “Know Your Customer”, is a core process in anti-money laundering. In 2025, more than 36,000 reports of suspicious transactions were filed in Finland, which gives some idea of the importance of KYC.

The purpose of KYC is to ensure that the service provider knows who it is dealing with, who is actually behind the customer, what the customer’s normal activities are, and when those activities deviate in a way that could indicate money laundering or terrorist financing.

Elements of Know Your Customer (KYC) in the day-to-day operations of companies.

KYC and the Anti-Money Laundering Act Are Not the Same

KYC (Know Your Customer) is not a separate law in its own right. It is an international term, well-established in the industry, for what the Finnish Anti-Money Laundering Act (444/2017) refers to as “knowing your customer.”

The Money Laundering Act is a regulatory framework consisting of several parallel components:

  • Risk Assessment. The reporting entity’s own assessment of the risks of money laundering and terrorist financing associated with its operations.
  • Know Your Customer (KYC). Who needs to be identified, what information needs to be collected, and when should further details be requested.
  • Obligations regarding information gathering and reporting. The obligation to investigate unusual transactions and report suspicious cases to the Financial Intelligence Unit.
  • Data Retention. Retention period for customer identification data.
  • Supervision and Sanctions. Supervision conducted by the authorities and any sanctions resulting from noncompliance.

KYC is therefore one aspect of this overall process that is most tangibly evident in day-to-day customer relations. Who needs to be identified, what information needs to be collected, and when should more detailed questions be asked?

It’s important to keep in mind the difference between the Anti-Money Laundering Act and KYC, as they are often confused with one another. The Anti-Money Laundering Act is the entire law, while KYC is one part of it.

Why is it Important to Know Your Customers?

In 2025, the Financial Intelligence Unit received a total of 36,020 reports of suspicious transactions, nearly 50% more than two years earlier (24,745 in 2023).

However, the reports are not evenly distributed across different industries. For example, accountants accounted for only 104 of the total, even though there are thousands of accounting firms operating in Finland. This discrepancy says as much about where suspicious transactions are actually being identified and reported as it does about where the KYC process is still taking shape.

In money laundering, the aim is to transfer, convert, or use funds obtained through criminal activity in a way that makes them appear legitimate. In the financing of terrorism the focus is on the intended use of the funds, since even funds of legitimate origin can be diverted for terrorist purposes.

Without knowing the customer, it is difficult to identify anomalies. If a service provider does not know what the customer usually does, it cannot reliably assess what is unusual.

The same payment transaction may be completely normal for one customer and clearly unusual for another. For example, international payments, large cash transactions, or complex ownership arrangements do not in and of themselves indicate fraud, but they may require further investigation if they do not fit the profile previously established for the customer.

KYC therefore helps distinguish between normal business transactions and situations where the service provider must pause to ask for more information in order to detect illegal activity.

Breakdown of the number of risk-based reports received by the Financial Intelligence Unit by reporting category, years 2023–2025.

Who Monitors KYC Compliance (in Finland)?

The Finnish Money Laundering Act does not designate a single supervisory authority for all operators. Instead, the Act assigns entities subject to reporting requirements to the supervision of different authorities based on their industry.

  • The Finnish Supervisory Agency supervises most of the sectors specified in the law: accounting firms and accountants, real estate brokerage firms, providers of legal services (excluding attorneys), tax advisors, pawnshops, collection agencies, currency exchange bureaus, and financial service providers not subject to the Financial Supervisory Authority.
  • The Financial Supervisory Authority oversees the financial sector: banks, payment institutions, insurance companies, investment service firms, and providers of virtual currency services.
  • The Finnish Bar Association oversees attorneys and law firms as part of its profession’s self-regulation. The Finnish Supervisory Agency, in turn, oversees this self-regulation.

It’s important to keep this distinction in mind, because KYC isn’t just a matter for banks or the financial sector. A large proportion of the entities covered by the Anti-Money Laundering Act are ordinary B2B service companies, such as accounting firms, property management firms, law firms, and others, which often have no prior experience with financial sector regulation.

For example, a property management company can be subject to reporting requirements when it provides services covered by the Anti-Money Laundering Act. In practice, most often this means accounting services for a housing cooperative, in which case it is supervised by The Finnish Supervisory Agency in the same way as an accounting firm.

Furthermore, oversight is not merely a matter of paperwork. Administrative penalties may be imposed for violations; these can include a public warning, a fine (€1,000–100,000 for a company, €500–10,000 for an individual), or in the most serious cases, a penalty that can amount to as much as one million euros or twice the amount of the benefit gained. For a financial services provider, the penalty may amount to up to 10% of the previous year’s revenue.

These are not theoretical figures but actual measures taken by The Finnish Supervisory Agency (list in Finnish). For example, in December 2025, The Finnish Supervisory Agency imposed a penalty of 49,000 euros on a pawnshop and a penalty of 8,500 euros on an accounting firm that had failed to conduct a risk assessment at all.

Do you operate in an accounting firm? Discover what The Finnish Supervisory Agency oversight means for you in practice.

Risk Assessment Makes Knowing Your Customer Possible

KYC doesn’t happen out of thin air. Before a reporting entity can know what questions to ask a customer, it must first assess its own risks. This assessment is called a risk assessment.

A risk assessment is, therefore, a report prepared by the company itself that identifies the types of threats related to money laundering and terrorist financing associated with its operations. The goal is not to demonstrate that the company is completely risk-free. Rather, the aim is to identify the activities in which risks may arise and, based on that understanding, establish sensible procedures.

The law does not impose strict formal requirements on risk assessments. They must be in writing, and their content must reflect the company’s own operations with sufficient accuracy. Nor does the number of pages indicate anything about quality. What matters is whether the text identifies genuinely recognized and carefully substantiated risks.

The Finnish Supervisory Agency offers a downloadable template for risk assessments (in Finnish) that you can use as a guide, but you must always supplement and adapt it to suit your company’s operations.

The Anti-Money Laundering Act does not assume that every customer is automatically treated the same way. Instead, the extent to which a customer is identified is determined based on risk. The risk assessment determines which approach is followed:

  • A simplified procedure may be applied to low-risk customer relationships.
  • In situations with a higher-than-usual risk, an enhanced due diligence procedure must be applied.

This classification is referred to as risk-based evaluation. Without a proper risk assessment, it is impossible to make a well-founded classification. In such cases, many entities subject to reporting requirements end up, in practice, treating all their customers the same way. Often in an unnecessarily burdensome manner, which unnecessarily complicates day-to-day operations.

It is advisable to review the risk assessment at least once a year and whenever there are significant changes in operations, the customer base, or legislation.

The Finnish Supervisory Agency’s Risk Assessment Template (Downloadable in Finnish).

Read also: KYC for Accounting Companies – What Does Knowing Your Customer Mean, and How do You Fulfill The Obligations?

What Does KYC Mean in Practice?

Getting to know a customer starts with a basic question: Who is the customer, really?

Luonnollisen henkilön kohdalla vastaus löytyy henkilöllisyyden selvittämisestä ja todentamisesta. Yritysasiakkaan kohdalla pelkkä yrityksen nimi ei riitä, vaan palveluntarjoajan on ymmärrettävä myös, kuka yritystä edustaa, kuka käyttää yrityksessä määräysvaltaa ja keitä ovat yrityksen tosiasialliset edunsaajat.

For an individual person, the answer lies in identifying and verifying their identity. For a corporate customer, the company name alone is not sufficient. The service provider must also understand who represents the company, who exercises control over the company, and who the company’s actual beneficiaries are.

The Financial Supervisory Authority divides the obligations regarding customer due diligence into seven categories:

  • Customer identification and identity verification.
  • Identification of beneficial owners.
  • Identification of the customer’s representative (including determining whether the customer, the beneficial owner, or the customer’s representative is a politically exposed person (PEP)).
  • Gathering information about the customer’s operations, as well as the nature and scope of its business.
  • Retention of personal data (at least 5 years after the end of the customer relationship).
  • Obligation to obtain information and report suspicious transactions.
  • Ongoing monitoring procedures (including regular comparison of customers and beneficial owners against international sanctions and asset-freeze lists).

The basic idea behind KYC can be summarized as follows: A service provider must form a sufficient understanding of its customers so that it can distinguish normal activity from unusual or suspicious activity.

KYC is Part of the Entire Customer Relationship

KYC is not a one-time check that you do once and then forget. It is a process that begins before a customer relationship is established and continues for as long as the partnership lasts.

Before the customer relationship begins, the service provider must ensure that it can reliably identify the customer. If this is not possible, the law leaves no alternatives: The service provider may not establish a customer relationship, conduct business transactions, or maintain a business relationship. This is one of the few provisions in the law that leaves no room for discretion.

During the customer relationship, the obligation to know the customer continues, as in reality the customer must be monitored throughout the entire customer relationship. In practice, this may take the form of f.ex. a request to update information or a request to submit documents in connection with a specific payment. Continuous monitoring also includes regularly checking customers and their beneficiaries against sanctions and frozen asset lists (Koho KYC does this automatically). This must be done throughout the entire customer relationship, as sanctions lists are constantly updated in line with the international situation.

If a transaction deviates from the norm, the service provider must investigate the reason for it. And if, even after the investigation, the transaction still appears suspicious, or if a sufficient explanation cannot be obtained, a report must be filed with the Financial Intelligence Unit.

Retention of customer identification data continues even after the customer relationship has ended. By law, the data must be retained for at least 5 years so that the supervisory authority can, if necessary, verify retrospectively that the customer identification requirements have been properly fulfilled.

It is precisely this process from identification to ongoing monitoring and – if necessary – reporting, that is the most consuming part of day-to-day KYC operations. It never ends, which is why it’s important to have processes in place that are as automated as possible.

One of the most affordable and user-friendly KYC solutions on the market: Learn more about Koho KYC here.

KYC is Part of the Entire Customer Relationship.

How Will KYC Change in the Future (EU Anti-Money Laundering Regulation 2027)

The biggest upcoming change is the EU Anti-Money Laundering Regulation (AMLR). It entered into force in 2024, but its application will begin on July 10, 2027.

This is a directly applicable EU regulation, meaning it does not need to be specifically transposed into national law. It effectively includes all the specific obligations regarding customer due diligence that have, until now, been set forth in the national anti-money laundering law.

At the same time, Finland is reforming its anti-money laundering law so that it will henceforth operate in parallel with the directly applicable regulation. Going forward, the national law will focus particularly on risk assessments, supervision, and sanctions. In addition, the new EU Anti-Money Laundering Authority (AMLA) will issue more detailed guidelines and technical regulatory standards in 2026–2027.

From a business perspective, the change mainly affects where the details of customer identification will be found in the future. In terms of content, KYC requirements will remain largely the same, although the intensity of oversight is likely to increase.

How do You Handle KYC Requirements?

If you’re not sure whether your company is handling its KYC obligations properly, book a free Koho KYC demo. Let’s go over together how one of the most affordable and easiest solutions on the market works.

Frequently Asked Questions About KYC

Is KYC mandatory for all companies?

No. The obligation applies only to entities specifically designated as reporting entities under the Anti-Money Laundering Act. Most ordinary businesses are not required to report.

What is the difference between the simplified and the enhanced recognition procedures?

The simplified procedure may be applied when, based on a risk assessment, the customer relationship involves a low level of risk. The enhanced procedure must be applied when the risk is higher than usual, for example, when the customer is a politically exposed person.

What happens if KYC requirements are not met?

This may result in a public warning, a fine, or, in the most serious cases, a penalty payment of up to one million euros. In 2025, the Financial Supervisory Authority imposed several penalty payments totaling tens of thousands of euros for inadequate risk assessments and customer due diligence.

Is KYC the same across all industries?

Not entirely. The basic obligations (identification, risk assessment, and the obligation to obtain information and report suspicious transactions) are the same, but the entity responsible for monitoring compliance and the practical priorities vary by industry.

When should KYC information be updated?

The law does not set a specific deadline. Updates are made on a risk-based basis. In other words, the higher the risk associated with a customer, the more frequently the information should be reviewed.

The Koho KYC dashboard on the screen of the laptop on the table.

Koho KYC Handles Your Compliance Requirements

At its best, KYC is part of responsible and trustworthy business practices. It protects the financial system, companies, customers, and society.

That is why we have added Koho KYC to our services, which allows your company to meet Know Your Customer requirements easily.

Koho KYC is one of the most affordable customer identification solutions on the market. Fixed monthly price, no surprise fees.

Once the service has been activated for the first time, it automatically continues to monitor customer accounts in accordance with their requirements.

Do you want to meet your company’s KYC requirements easily?

Learn more about Koho KYC and schedule a free demo!

This article is based on training materials and guidelines published by the Licensing and Supervisory Authority (formerly the Regional State Administrative Agency), as well as statistical and indicator data published by, among others, the Police’s Financial Intelligence Unit and the Financial Supervisory Authority. Koho has not prepared this material itself but wishes to share this information with its customers. The information is accurate as of the time of publication. Always check the most up-to-date and definitive information directly on the authorities’ websites.

Would you like to have a better look?
Request a free demo!

Book a free demo, no strings attached, and let Koho PSA convince you. You can save up to 87 % in invoicing with Koho PSA. The demo will give you a better view on how Koho PSA will help your accounting company succeed.