Lire en français →

CHECKLISTS

KYC document collection checklist

By Sygnet Research. Written by Sygnet, sourced, checked before publication.

This checklist is for compliance analysts, ops leads, and founders setting up or auditing a KYC document collection process, whether for a new onboarding flow or a review ahead of an audit. Run through it before you finalize a vendor contract or ship a new onboarding form, not after.

Identity documents

  • Confirm which ID types are accepted (passport, national ID, driver's licence) and which are rejected
  • Check document expiry date against today, not against submission date (expired-but-not-yet-caught documents are a common gap)
  • Verify photo matches the applicant via liveness check or manual review
  • Capture both sides of the document where data exists on the back (address, MRZ line, signature)
  • Confirm the extraction pipeline can read the document type reliably; see ID card and passport extraction
  • Store a redaction or masking policy for sensitive fields you don't need to retain

Proof of address

  • Require a document dated within an acceptable window (commonly 3 months, confirm your own policy)
  • Accept only approved document types (utility bill, bank statement, tax notice, lease)
  • Match the name on the address document against the ID document exactly (middle names and transliterations cause false mismatches)
  • Cross-reference the address format against local postal standards if operating across countries
  • Review extraction logic for this document type: proof of address extraction

Business and entity documents (for business KYC/KYB)

  • Collect a recent company registration extract (e.g. Kbis in France) and confirm it's not expired
  • Pull company statutes or articles of association to verify legal structure and signatories
  • Identify ultimate beneficial owners (UBOs) above the relevant ownership threshold
  • Verify the entity's registered address matches what's declared on the application
  • See structured extraction references: Kbis extract data extraction, company statutes extraction

Financial documents

  • Collect bank statements or RIB/IBAN confirmation to verify account ownership
  • Check that the account holder name matches the applicant or entity name
  • Flag statements with inconsistent formatting or obvious tampering signs (mismatched fonts, misaligned totals)
  • Reference extraction logic: bank statement extraction, RIB and IBAN extraction

Data handling and retention

  • Define retention periods per document type and jurisdiction (don't default to "keep forever")
  • Confirm encryption at rest and in transit for stored documents
  • Document your legal basis for processing under applicable privacy law
  • Walk through the GDPR checklist for document AI projects before go-live
  • Review your vendor's posture: security and compliance

Process and audit trail

  • Log every document submission with timestamp, source, and reviewer (manual or automated)
  • Record the confidence score for any automated extraction and set a manual-review threshold
  • Keep a rejection log with stated reasons, searchable later for audits
  • Test your actual extraction accuracy periodically, not just at onboarding; see invoice AI accuracy testing for methodology that applies broadly

Common mistakes

  • Accepting a proof of address that's within date at submission but will be stale by the time of review.
  • Treating OCR output as ground truth without a confidence threshold or human fallback.
  • Letting document policy drift between regions without a single source of truth.
  • Skipping a renewal workflow, so documents that were valid at onboarding quietly expire.
  • Storing raw documents indefinitely because nobody set a retention date.
  • Assuming manual review scales; it doesn't past a few hundred applications a month.

FAQ

How often should KYC documents be refreshed?

There's no universal rule; it depends on risk tier and jurisdiction. Higher-risk customers (politically exposed persons, high-transaction-volume accounts) typically need more frequent refresh, sometimes annually. Lower-risk retail customers might only need a refresh triggered by an event (address change, large transaction). Build your refresh cadence into the onboarding system itself, not a spreadsheet someone checks quarterly.

Should we build our own document extraction or buy a vendor?

It depends on document volume, variety, and how much engineering time you want to spend maintaining parsing rules as formats change. If you're processing a handful of document types at moderate volume, buying usually wins on time-to-value. Read build vs buy IDP for a fuller breakdown, and compare specific vendors before committing, since accuracy and compliance posture vary a lot: Sygnet vs Klippa, Sygnet vs Mindee.

Does OCR work well enough for KYC documents?

Plain OCR struggles with low-quality scans, handwriting, and documents with inconsistent layouts, which describes a lot of real-world KYC submissions. Vision-language models handle layout variation and degraded images better, at a higher per-document cost. See OCR vs VLM for where the tradeoff actually lands, and check pricing before assuming one approach is cheaper at scale.

NEXT STEP

See it on your own documents

One email when we publish something worth your time.