Markets Closed
Global Markets
S&P 500 7,408.3 ▼ -1.2% DOW 51,711.65 ▼ -1.0% NASDAQ 25,137.69 ▼ -2.2% RUSSELL 2K 2,940.16 ▼ -0.7% VIX 18.7 ▲ +12.4% GOLD 4,050.7 ▼ -2.3% CRUDE OIL 92.22 ▲ +6.2% EUR/USD 1.14 ▼ -0.3% BTC 65,092 ▼ -1.4% ETH 1,880.38 ▼ -2.6%
Fintech

KYC better data rules shift bank focus from forms to validation

A Finextra opinion says US KYC clarifications allow more third-party and pre-filled data, raising the bar for bank validation controls.

Rafael Ortiz

By Rafael Ortiz · Fintech Correspondent

· 3 min read

KYC better data rules are pushing banks to rethink onboarding around verified external information rather than repeated document collection, according to Karthikeyan Subramaniam, senior specialist in IC development at BMO. In an external opinion published by Finextra, Subramaniam said recent US regulatory clarifications could reduce customer friction while keeping banks accountable for risk controls.

The argument centres on a practical problem in bank compliance: institutions often ask customers to provide information that may already exist in public records, commercial databases or prior banking relationships. Subramaniam said the limiting factor is less the availability of data than banks’ ability to validate, refresh and govern information from trusted sources.

Subramaniam pointed to two US regulatory moves in 2025. He said FinCEN and federal banking agencies allowed banks in June 2025 to obtain Tax Identification Numbers from third parties instead of collecting them directly from customers. He also said the FDIC later clarified that pre-filled information drawn from previous relationships, affiliates, vendors and other trusted sources can meet Customer Identification Program requirements if customers can review, correct and confirm the data and banks apply suitable risk controls.

What are the KYC data rule changes?

The changes described by Subramaniam allow banks to rely more on trusted third-party and previously held data in customer identification processes, subject to customer confirmation and internal controls. The mechanism matters because it shifts compliance work from gathering the same fields repeatedly to testing whether the information is accurate, current and supported by reliable sources.

Customer Identification Program requirements are part of the controls banks use to identify customers and manage financial crime risk. In Subramaniam’s view, using validated data from outside the customer form can still support oversight of beneficial ownership, sanctions exposure and suspicious activity, provided banks maintain strong governance.

He listed credit bureaus, corporate registries, beneficial ownership databases, court records, sanctions lists and adverse media as examples of information sources already available to financial institutions. The operational question for banks, he said, is how to keep that information accurate over time rather than how to ask customers for more uploads and form entries.

Subramaniam said unnecessary fields and duplicate document requests create avoidable friction for legitimate customers and can pull resources away from higher-value risk management. He cited JPMorgan, HSBC and DBS as institutions that have used tools such as SWIFT’s KYC Registry and internal automation to reduce repeat requests and increase reuse of existing data.

Artificial intelligence may speed the shift, according to Subramaniam, but he cautioned that automated systems depend on the quality of the information they receive. Without dependable external data and validation processes, he said, AI risks accelerating weak or inefficient workflows.

Finextra labels the piece as external content supplied by the author and not edited by the publication. The position advanced by Subramaniam is that banks’ next phase of KYC investment should prioritise data ecosystems, validation and enrichment rather than larger stores of customer documents.

This story draws on original reporting from Finextra Research.

More from Fintech

All Fintech →