What Is KYC and Why Exchanges Ask for ID
Published: August 20, 2026Anonymity
Also available in:EspañolРусский
KYC is the procedure a financial company uses to establish who its customer is and to keep proof of it on file. It is not a one-off formality at sign-up: it is an obligation that runs for as long as you use the service.
What KYC means
The acronym stands for Know Your Customer. Some jurisdictions use their own wording for the same thing — "customer identification", "customer due diligence" — but the requirement is identical.
The reasoning is straightforward: the law forbids a financial institution from serving someone it knows nothing about. So the platform has to do three things — establish who the customer is, understand the nature of their activity, and retain what it collected for a set period, so it can produce the file if a regulator or an investigator asks.
One detail explains everything else: KYC was not invented by exchanges and does not benefit them. It is a requirement the state passes to the company, and the company passes to you. That is why the inconsistency you notice is real — one service asks for documents at registration, another only at withdrawal, a third never asks. The difference is not how friendly they are; it is which law applies to each of them.
The international frame is shared: the recommendations of the FATF, the intergovernmental body on money laundering. Recommendation 10 covers customer due diligence, and Recommendation 16 — the travel rule — requires sender and recipient details to travel with the transfer itself. The threshold above which a full set of verified data is required is USD/EUR 1,000; in the European Union that threshold dropped to zero in 2026. The rule now applies in more than seventy jurisdictions.
What you are actually asked for
Verification is almost always split into levels, and it helps to know that in advance — it is easy to clear the first step and hit the next one exactly when you try to withdraw.
Basic level. Name, date of birth, nationality, sometimes a phone number. Enough to open an account and fund it with a small amount.
Document and selfie. A photograph of a passport or national ID, plus a picture of your face — usually turning your head or reading out random digits, so that a live person can be told apart from a held-up photo. This is what most people mean by "doing KYC".
Proof of address. A utility bill, bank statement or certificate, typically no older than three months, showing your name and address together.
Source of funds. This appears at larger amounts: statements, contracts, declarations. Formally it belongs to enhanced due diligence — the version applied to higher-risk customers and transactions.
Without a reason, platforms rarely push you past the first level. The reason is usually the amount, the country, the pattern of transactions, or an internal rule firing.
KYC, AML and ongoing monitoring
These terms sit next to each other so often that they look interchangeable. They are not.
AML — anti-money-laundering — is the whole system: policies, reporting, transaction monitoring, staff training, a designated compliance officer.
KYC is one part of that system, the part where the customer is established. There is a second part users never see: ongoing monitoring, where software compares your behaviour against what it expects and flags the difference.
The practical consequence: finishing verification does not mean you are "done with AML". Identification happens once; monitoring never stops, and a question about a specific transfer can arrive a year after you signed up.
How long it takes and why it gets rejected
When the automated path works, it takes minutes. The document is read, the face is matched, the answer comes back immediately.
Manual review kicks in when automation cannot decide, and then it runs from a few hours to several days. The usual triggers: glare or cropped edges on the document photo, an expiry date that just passed, a name spelled differently on the ID than in the form, an address on the proof that does not match the one you declared.
A rejection normally means one of three things: the document cannot be read, the data does not agree with itself, or your country of residence is not served by that platform. The last one gets communicated vaguely and looks like a technical fault, though the decision was made from a list of jurisdictions.
What you are risking when you hand over documents
Companies that sell verification services rarely write about this, and it is the question people ask most.
The risk is not the check itself but what remains afterwards: the company holds a file where your name, address, document photo and face are tied to your transaction history and balances. That combination has value on its own, and people go after it.
The clearest recent example is Coinbase. The breach happened in December 2024 and was disclosed in May 2025, in a filing with the US Securities and Exchange Commission. Around 70,000 customers were affected, and what got out was not passwords but the verification material itself: names, addresses, phone numbers, images of government IDs, bank identifiers and account balances. There was no intrusion. An employee at a support contractor in India was bribed and photographed her screen with a personal phone. The company refused to pay the USD 20 million ransom and estimated losses of up to USD 400 million.
The lesson is not "verification is bad" but something more specific: the safety of your documents equals the safety of the weakest contractor used by the company you gave them to — a contractor you neither choose nor know about. The second risk is retention. Files sit for years after you stop using a service, because the law requires keeping them rather than deleting them on request; five years is a common minimum, and some jurisdictions have moved to ten.
Hence a practical rule: verify where it is genuinely needed for what you are trying to do, rather than "just in case", and avoid handing the same document set to ten platforms in a row.
Where verification is not required
There is a category of services that does not ask for documents: non-custodial exchanges, which never hold customer funds and never open accounts. The swap happens as a single operation — you send one coin and receive another to your own wallet.
This is not a loophole or a grey area; the difference is that there is no account for an identity to be attached to. We covered it with its limits and caveats in a separate article — crypto exchange without KYC: why ID is required. It is also worth remembering that skipping verification does not make activity invisible: tax authorities get their data through an entirely different route.
In short
KYC is customer identification that the law requires of financial companies — not something they came up with. You get asked for a document, a selfie, sometimes proof of address and source of funds, in levels that rise with the amount. Automated review takes minutes, manual review takes days. The larger risk is not the check but the storage: the file outlives your use of the service and leaks through people far more often than through break-ins.
If all you need is to swap one coin for another, look at current rates and the exchange terms: an operation with no account and no custody of funds does not need documents.
