Section 1 · Lesson 1.5
KYC, KYT and CDD: the three pillars of compliance in plain terms
When a newcomer enters the world of AML, they drown in three-letter acronyms: KYC, KYT, CDD, EDD, AML/CFT. Behind them lie not bureaucratic rituals but three different questions a service asks about a client and their money. In this lesson we'll lay out each term neatly, show how they differ, where they apply and how they connect — so that you stop confusing them for good.
Three questions, not three words
The easiest way to remember these acronyms is to tie each one to the simple question a compliance officer asks:
- KYC (Know Your Customer) — WHO is this person? Verifying identity before the relationship begins.
- CDD (Customer Due Diligence) — HOW risky are they, and what should we expect? Assessing the risk profile and ongoing observation.
- KYT (Know Your Transaction) — WHERE is their money coming from and going to? Analysing the operations themselves and the origin of funds on-chain.
KYC handles identity, CDD handles the risk profile and behaviour, KYT handles the money. The first two are traditionally about "the person and their documents"; the third is unique to crypto, because the blockchain, for the first time in the history of finance, made the transactions themselves publicly verifiable.
KYC: know your customer
KYC is the front door. Before an exchange, exchanger or custodial wallet lets you deposit and withdraw funds, it must make sure you are a real person — not a synthetic identity, not a front man, and not someone on a sanctions list. The classic KYC set includes three layers of checking.
- Identification. Collecting data: name, date of birth, citizenship, address, taxpayer number. The client declares who they are.
- Verification. Confirming those data with documents: a passport or ID, a utility bill for the address, plus a "liveness" selfie so the photo on the document matches a live face. The service checks that what was declared is true.
- Screening. Running the identity against sanctions lists (OFAC, EU, UN), against PEP databases (politically exposed persons) and against adverse media. Checking whether this client can be served at all.
It's important to understand: KYC is a one-off (or periodically refreshed) event at entry. It says nothing about what the client does after registering. Example: a person passes KYC at an exchange flawlessly — a real passport, a clean face, no sanctions. But a month later they start receiving funds from a known darknet market's address. KYC won't catch this — because KYC looks at the person, not at their money. This is where the other two pillars come into play.
CDD: due diligence and the risk profile
CDD is what turns a one-off check into an ongoing, monitored relationship. If KYC answers "who," CDD answers "what to expect and how risky it is." At registration the service assigns the client a risk level based on many factors: country of residence, type of activity, expected volumes, source of wealth, and whether the client is a PEP.
What CDD is made of
- Risk profiling. A student from the EU planning to deposit €200 a month is low risk. The owner of an offshore company from a high-laundering jurisdiction promising turnover in the millions is high risk.
- Understanding the nature of the relationship. The service records the "normal" pattern: what amounts, how often, with whom. This is the baseline for future comparison.
- Ongoing monitoring. The key word is "ongoing." CDD doesn't end at entry; the service watches whether behaviour deviates from the expected profile.
- Refreshing data. Periodic review: has the client changed country, become a PEP, changed the nature of their operations?
An example of CDD at work: a client declared an expected turnover of €500 a month and a "private individual" profile. Six months later €80,000 a week passes through their account in transfers to dozens of different counterparties. That is a sharp divergence from the profile — a trigger for investigation, even if each individual operation looks legitimate. It's precisely CDD as a continuous process that catches such anomalies.
EDD: enhanced due diligence for high-risk clients
When CDD reveals elevated risk, EDD kicks in (Enhanced Due Diligence) — not a separate pillar but a deeper mode of that same CDD. EDD is applied to PEPs, to clients from high-risk jurisdictions, and to unusually large or complex operations with no obvious economic sense.
What EDD adds: confirming the source of funds and the source of wealth with documents — not "where did the money on the account come from" but "where did your capital come from in the first place"; approval of the relationship at senior-management level; more frequent and closer monitoring; and a deeper analysis of the ownership structure if the client is a company.
The difference by example: an ordinary client deposits €1,000 — standard KYC is enough. A PEP from a high-corruption country wants to deposit €1,000,000 — here EDD will demand documentary proof that the money was earned legally (a business sale, an inheritance, declared income), and the decision to serve them will be made by top management, not a rank-and-file operator.
KYT: know your transaction
KYT is what makes crypto compliance fundamentally new. In a traditional bank, transactions are hidden inside private systems: you can't check where someone else's payment came from. On the blockchain, every operation is public and recorded forever. KYT exploits this: it analyses not the person but the money and its path.
- Checking the origin. On an incoming deposit, the KYT system traces the chain of transactions backward: did these coins come from a mixer, a sanctioned address, a hacked exchange, a darknet market? A "dirty" coin history is a red flag, even if the client themselves is clean.
- Scoring the address and amount. Each wallet and operation is assigned a risk score based on links to known categories. This is the very "score" that an AML check returns.
- Real-time monitoring. KYT runs on every transaction, not just at entry — it catches the moment a clean client suddenly receives funds from a dangerous source. Transaction-level, not one-off, control.
This is exactly why an AML wallet check is, in essence, a KYT tool. You enter an address, and the service answers the question "where did this money come from and go to, and how risky is it" — regardless of who the owner is.
How the three pillars work together
Picture a client's registration and life on an exchange as a single conveyor belt:
KYC at entry → checked the passport and face, ran the sanctions screen → CDD assigned a risk profile → we watch behaviour → KYT on every transaction → we check the coins' origin → anomaly → EDD investigation and, possibly, a report to the regulator.
No pillar replaces another. KYC without KYT — you know the person but not that they're pushing dirty money through the account. KYT without KYC — you see suspicious coins but don't know whom to hold accountable. CDD ties it all into a continuous process of risk assessment.
Where each one applies
- Centralised exchanges and exchangers. The full set: KYC + CDD/EDD + KYT. Regulated VASPs are obliged to under FATF.
- Non-custodial services and AML checkers. Mainly KYT — they analyse transactions and addresses without verifying identity, because they don't hold users' funds.
- Banks working with crypto companies. Classic KYC/CDD/EDD plus a requirement that the crypto counterparty has KYT in place.
- DeFi protocols. Formally, KYC is often absent, but screening tools at the interface and wallet level (KYT) are increasingly being adopted under the pressure of sanctions compliance.
A typical beginner's mistake: assuming that passing KYC makes a client "clean" forever. Identity verification and the cleanliness of the money flow are two different dimensions. An honest person can unknowingly receive dirty coins through P2P; a fraudster with a genuine passport can push darknet funds around. That is precisely why mature compliance keeps all three pillars going at once.
Lesson summary. KYC — "who you are" (identity at entry). CDD — "how risky you are and how you behave" (risk profile + ongoing monitoring), and EDD is its enhanced mode for high-risk clients. KYT — "where your money comes from" (analysis of the on-chain transactions themselves). In crypto, it is KYT that became the main innovation: for the first time money can be checked directly, without asking the owner. The AML wallet check that AMLConsensus performs is the practical embodiment of KYT.
This material is for educational purposes.