KYC investigation under the Wwft: steps, duties and enforcement

KYC Investigation: Protect Your Fintech from Fraud

A KYC investigation is the client investigation that banks, payment institutions, crypto-asset service providers, notaries, accountants and law firms in the Netherlands must carry out under the Wet ter voorkoming van witwassen en financieren van terrorisme (Wwft, the Money Laundering and Terrorist Financing Prevention Act). It has three fixed components: establishing and verifying who the client is, understanding the ownership, the purpose of the relationship and the risk it carries, and monitoring the relationship for as long as it lasts. How deep each component goes is risk-based, so there is no single template that fits every client. A file that does not hold up is not a paperwork problem: it exposes the institution to supervisory enforcement and, in serious cases, to criminal liability.

What a KYC investigation is under Dutch law

Dutch law does not use the English abbreviation. The Wwft speaks of clientenonderzoek, client due diligence, and sets out in one provision what that investigation must achieve. The institution must identify the client and verify that identity, identify the ultimate beneficial owner and take reasonable measures to verify who that person is, establish the purpose and intended nature of the business relationship, check whether the person acting on the client’s behalf is authorised to do so, and monitor the relationship and the transactions within it on a continuous basis. Those five elements are the backbone of every KYC investigation, whatever software the institution uses to run it.

The second organising principle is proportionality. The Wwft prescribes a risk-based approach: the institution decides how far to go, but it must be able to explain that decision. A salaried Dutch consumer opening a savings account is not the same risk as an offshore holding structure with a nominee director, and the file should show that difference. Supervisors rarely fine institutions for asking too few questions in the abstract; they fine them for having no defensible reason for the depth they chose.

How KYC relates to anti-money laundering as a whole

KYC is the client-level layer of a wider anti-money-laundering framework. The framework also contains transaction monitoring, staff training, governance, record keeping and the reporting duty. It is worth keeping two bodies of law apart. The Wwft imposes preventive duties on gatekeepers and is enforced mainly by administrative supervisors. Money laundering itself is a criminal offence and is defined in articles 420bis to 420quater of the Wetboek van Strafrecht (Dutch Criminal Code), not in the Wwft. An institution can therefore breach the Wwft without anyone having laundered a cent, and a client can commit money laundering even though the institution’s file was faultless.

The practical consequence is that a KYC investigation serves two masters. It has to satisfy the supervisor that the institution has done what the Wwft asks, and it has to give the institution enough information to notice when something is genuinely wrong. Files built only for the first purpose tend to fail the second.

Which businesses must carry out a KYC investigation

The Wwft applies to a defined list of institutions rather than to business in general. It covers banks, payment service providers and electronic money institutions, life insurers, investment firms and fund managers, crypto-asset service providers, trust offices, notaries and civil-law notaries, lawyers, accountants, tax advisers and administration offices, estate agents and property appraisers, dealers in goods who accept cash payments above the threshold set in the Act, art dealers and pawnbrokers. Providers of games of chance are covered as well. If your organisation appears on that list, the client investigation is not optional and cannot be outsourced away: an institution may rely on a third party for parts of the work, but it remains responsible for the outcome. Our overview of the KYC obligations that apply to Dutch businesses sets out the duties per category in more detail.

For law firms the scope is narrower than many clients assume, and the nuance matters. A Dutch lawyer is an obliged institution only when advising on or acting in a defined set of services, broadly the purchase and sale of immovable property or businesses, managing money or securities, setting up or managing companies, and comparable transactional work. Advice on a client’s legal position and representation in legal proceedings fall outside the reporting duty, which is how the legal professional privilege is preserved. Firms that blur the two either report what they should not, or fail to report what they must.

The legal framework: Wwft, the Sanctions Act and the EU single rulebook

Three sets of rules sit on top of each other, and confusing them is the single most common structural error in Dutch compliance files. The Wwft governs the client investigation and the reporting of unusual transactions. The Sanctiewet 1977 (Sanctions Act) governs screening against sanctions lists and the freezing of assets. EU regulations sit above both, and from 2027 they take over much of the detail.

What the Wwft requires

The Wwft is the Dutch implementation of the European anti-money-laundering directives. It obliges every institution to carry out its own documented risk assessment, to translate that assessment into written policies, procedures and measures, to run the client investigation before entering into a business relationship or carrying out an occasional transaction above the statutory threshold, and to report unusual transactions to FIU-Nederland. It also requires the institution to keep the file for five years after the end of the relationship or after the transaction, and to make it accessible to the supervisor on request. Longer retention is sometimes defended on tax grounds, but the Wwft period itself is five years, and keeping personal data longer than necessary is a problem under the GDPR rather than a safe default.

Sanctions screening is a separate duty

Screening a client against the EU sanctions lists is not part of the Wwft investigation; it flows from the Sanctiewet 1977 and directly applicable EU regulations, and it applies to a much broader group of businesses. The test is also different, and the difference is expensive. A company is caught by an asset freeze when a designated person or entity holds fifty per cent or more of the shares or voting rights, or otherwise exercises control over it. That fifty per cent ownership and control test has nothing to do with the twenty-five per cent threshold used to identify an ultimate beneficial owner under the Wwft. Institutions that screen only at twenty-five per cent, or that assume a UBO check doubles as a sanctions check, routinely miss frozen counterparties. Our separate guidance on sanctions compliance for businesses sets out how that screening should be organised.

What changes from 10 July 2027

In 2024 the European Union replaced the directive-based system with a package that will apply far more uniformly. Regulation (EU) 2024/1624, the AML Regulation, contains the substantive client due diligence rules and applies from 10 July 2027. Directive (EU) 2024/1640 covers supervision, registers and financial intelligence units and must be transposed by the same date. Regulation (EU) 2024/1620 created the Anti-Money Laundering Authority, AMLA, which is based in Frankfurt and became operational in 2025; it will draft the technical standards and will eventually supervise a selected group of high-risk cross-border institutions directly.

Because the AML Regulation is a regulation, much of what now sits in the Wwft will apply straight from Brussels, and national room for interpretation will shrink. Institutions that have built their procedures around Dutch supervisory guidance alone should start mapping them against the regulation now, rather than in the spring of 2027. Until that date, however, the Wwft as it stands is the operative law, and a KYC investigation is judged against it.

Customer acceptance, identification and verification

The investigation starts before a single document is requested, with the question of which clients the institution is prepared to accept at all.

The institution’s own risk assessment

The Wwft requires a systematic integrity risk assessment covering the products offered, the delivery channels used, the countries involved and the types of client served. That assessment is the document supervisors ask for first, because everything else is supposed to follow from it. It should produce a written acceptance policy that states plainly which relationships are refused outright, which are permitted only with enhanced due diligence and senior sign-off, and which follow the standard route. Anonymous accounts and relationships with shell banks are prohibited by law; beyond that, the boundary is a commercial decision the institution has to be able to justify.

A workable acceptance policy also protects the commercial side of the business. If the criteria are written down, a relationship manager knows before the pitch that a cash-intensive prospect in a high-risk jurisdiction will take weeks rather than days, and compliance is not cast as the department that kills deals at the last minute.

Identifying and verifying individuals

For natural persons, identity is established from a valid identity document and verified against it. Remote onboarding is now the norm and is accepted, provided the method is reliable: chip reading of a passport or identity card, a verified iDIN or DigiD flow, a qualified electronic identification under the eIDAS Regulation, or a first payment from an account in the client’s own name at a European bank. Whatever route is chosen, the institution must be able to explain why it is reliable enough for the risk involved.

Data protection runs alongside. A copy of an identity document contains more information than the institution needs, and the GDPR principle of data minimisation applies with full force. Retain what the Wwft requires, restrict access to those who need it, log consultations, and delete on schedule. Supervisory pressure to hold more and privacy law pressure to hold less are both real, and the file should show a deliberate choice between them.

Identifying legal entities

For companies and other legal entities the starting point is a recent extract from the Chamber of Commerce trade register, supported by the articles of association and, where relevant, the shareholders’ register. The extract shows the statutory directors and the limits on their authority to represent the company, which is the point most often overlooked: a contract signed by someone who is authorised only jointly binds nobody. For foreign entities the equivalent register documents are needed, and legalisation or certified translation may be required before they can be relied on.

Due diligence, ultimate beneficial owners and enhanced due diligence

Once identity is fixed, the KYC investigation turns to the question that actually carries the risk: who is behind the client, and does the intended activity make sense.

Finding the ultimate beneficial owner

An ultimate beneficial owner is the natural person who ultimately owns or controls the entity. For most companies the test is a direct or indirect holding of more than twenty-five per cent of the shares or voting rights, or control by other means, for example through a contractual right to appoint the board. If no such person can be identified after exhausting all reasonable means, the statutory directors are registered as pseudo-UBOs. That fallback is meant to be exceptional; a file that reaches for it immediately invites questions.

The Dutch UBO register at the Chamber of Commerce is no longer publicly accessible. After the judgment of the Court of Justice of the European Union of 22 November 2022, which struck down general public access as a disproportionate interference with privacy, the Netherlands closed the public part of the register. Access is now tiered: competent authorities and FIU-Nederland obtain full data, while Wwft institutions can consult a limited set for their own client investigation, and access for parties with a legitimate interest is being arranged by decree. Two practical points follow. The register is a check, not a source: an institution may not rely on it alone and must form its own view of the ownership structure. And where the register and the institution’s own findings differ, the institution must report the discrepancy back to the Chamber of Commerce.

Politically exposed persons and high-risk countries

Enhanced due diligence is mandatory in a number of situations, not merely advisable. It applies where the client or the beneficial owner is a politically exposed person, or an immediate family member or close associate of one; the status continues for a period after the person leaves office. In those cases the Wwft requires approval from senior management before the relationship starts or continues, measures to establish the source of the wealth and the source of the funds involved, and intensified ongoing monitoring. Enhanced due diligence is also mandatory where the client is established in, or the transaction runs through, a country the European Commission has designated as high-risk, and where the relationship is unusually complex or the transaction has no apparent economic or lawful purpose.

Simplified due diligence exists at the other end of the scale, but it is not an exemption. It permits lighter verification and less frequent review for demonstrably low-risk situations. Even then the institution must still identify the client, still monitor the relationship, and still be able to show why the low-risk classification was justified.

Source of funds and source of wealth

The two are often used interchangeably and should not be. Source of funds concerns the money used in a particular transaction; source of wealth concerns how the client’s overall assets were built up. A client can explain the origin of a single payment perfectly well while the underlying fortune remains unexplained, and it is usually the second gap that turns into an enforcement finding. Evidence should be documentary where the risk warrants it: sale agreements, tax filings, audited accounts, inheritance documents. A note recording that the client said the money came from a property sale is not source-of-funds evidence.

Ongoing monitoring and the duty to report unusual transactions

A client approved today can become a problem tomorrow, which is why monitoring is a statutory element of the client investigation rather than an optional extra. The institution must keep the relationship under review, ensure the transactions carried out remain consistent with the profile it has built, and update the file when the picture changes: a new beneficial owner, a change of business model, adverse media, a shift in the countries the money moves through.

When a transaction becomes unusual

Dutch law works with unusual transactions, not with the international concept of suspicious transactions, and the difference is deliberate. The indicators are laid down in the Uitvoeringsbesluit Wwft 2018. Some are objective: fixed situations and thresholds where a report is required automatically, without any assessment of the client. One is subjective and open-ended, covering every transaction where the institution has reason to assume it may be connected to money laundering or terrorist financing. The subjective indicator is where judgment lives, and where files are tested afterwards. Our article on the difference between money laundering and unusual transactions explains how the two concepts interact.

How and when to report

An unusual transaction must be reported to FIU-Nederland without delay, through the goAML portal. There is no fixed number of days: the obligation is to report as soon as reasonably possible, and the clock starts when the unusual character becomes known to the institution, which may be long after the transaction itself. Attempted and intended transactions are covered as well, so a payment the institution refuses to execute can still be reportable. FIU-Nederland then decides whether the transaction is declared suspicious and passed on to the investigation and prosecution services; that decision is not the institution’s to make.

Two protections and one prohibition come with the reporting duty. A report made in good faith does not expose the institution or its employees to civil liability, and the data supplied cannot be used against the reporting institution in a prosecution for the underlying offence. The prohibition is on tipping off: the institution may not inform the client, or any third party, that a report has been made or is being considered. Telling a client that their payment was reported is itself a breach.

When the investigation cannot be completed

If the client investigation does not produce the required result, the consequence is prescribed rather than discretionary. The institution may not enter into the business relationship, may not carry out the transaction, and must terminate an existing relationship. It must also consider whether the circumstances themselves warrant a report to FIU-Nederland. Continuing to serve a client whose ownership structure was never resolved, on the basis that the file will be completed later, is one of the most frequently penalised failures in Dutch supervisory practice.

Supervision, fines and criminal liability

Wwft supervision in the Netherlands is divided by sector rather than concentrated in one authority, and the first question in any enforcement file is which supervisor is competent. De Nederlandsche Bank supervises banks, payment and electronic money institutions, insurers, trust offices and crypto-asset service providers. The Autoriteit Financiele Markten supervises investment firms, fund managers and financial service providers. The Bureau Financieel Toezicht supervises notaries, accountants and tax advisers. The Bureau Toezicht Wwft, part of the Tax Administration, supervises traders, estate agents and pawnbrokers, the Kansspelautoriteit supervises gambling providers, and the local deken supervises lawyers. Each publishes its own guidance, and that guidance is how the open norms of the Act are given content in practice.

The enforcement ladder runs from an informal norm-transferring conversation, through a formal instruction and an order subject to a penalty payment, to an administrative fine. The Wwft assigns breaches to fine categories, and the maximum for the heaviest category is set by law and by the Besluit bestuurlijke boetes financiele sector; for financial undertakings a turnover-related maximum can apply. Because those figures are amended from time to time, the point to plan around is not the headline number but the fact that fining decisions are published, including the name of the institution. For most firms the publication does more damage than the payment.

Beyond administrative enforcement, intentional breach of the core Wwft duties is an economic offence and can be prosecuted. The Public Prosecution Service has concluded criminal settlements with several large Dutch financial institutions over failures in their gatekeeper role, and those cases established that persistent, structural under-investment in client due diligence is treated as criminal conduct rather than as a compliance shortcoming. Individuals are exposed too: policymakers and day-to-day managers can be prosecuted personally, and for regulated firms a Wwft failure regularly triggers a fresh suitability and integrity assessment of the board members involved. If a supervisor or the Public Prosecution Service opens a file, the institution should take legal advice before the first interview, not after it.

Where KYC investigations go wrong in practice

Most of the problems we see are not exotic. They repeat across sectors, and they are fixable.

The first is documentation that is technically present but substantively empty. Files contain identity documents, screening screenshots and a risk score, yet nothing explains why the client’s activity makes commercial sense or how the analyst reached the conclusion. Supervisors read the reasoning, not the attachments. A short written narrative, signed off by a second pair of eyes, is worth more than another certified copy.

The second is friction with the commercial side, and the de-risking reflex it produces. Refusing or terminating a relationship because a file is hard rather than because the risk is unacceptable is not a neutral choice. Dutch courts have repeatedly held that a bank’s freedom to refuse or end a relationship is limited by its duty of care and by the standards of reasonableness and fairness, particularly where the client would in effect be shut out of payment traffic altogether. A defensible termination rests on a documented risk assessment, a genuine opportunity for the client to supply the missing information, and a reasonable notice period.

The third is cross-border complexity. A Dutch payment institution serving a Spanish client held through a Luxembourg holding and a trust in a third country faces overlapping rule sets that rarely align neatly. The workable answer is to apply the strictest applicable standard and to record why, rather than to litigate the conflict of laws in every file. Where the structure itself resists explanation, that is information about the client, not merely an administrative obstacle.

The fourth is treating screening lists and country classifications as static. Sanctions designations change at short notice, and the European Commission’s high-risk country list is amended by delegated regulation. Screening that runs only at onboarding will miss a client who is designated three months later. Re-screening the portfolio against updated lists, and recording when that happened, closes a gap that supervisors specifically look for.

The fifth is the assumption that technology settles the question. Automated identity verification, name screening and transaction monitoring genuinely reduce error and cost, and they produce the audit trail the supervisor wants. They also produce false positives at volume, and an alert closed without reasoning is worse than no alert at all. Perpetual monitoring models, in which registry changes and list updates feed a dynamic risk score instead of a five-yearly refresh, are becoming the standard for larger institutions, and European digital identity wallets will over time make verification cheaper still. Neither removes the obligation to think about the client in front of you.

Getting your KYC framework in order

A KYC investigation that holds up rests on four things: a risk assessment the institution actually believes in, an acceptance policy that follows from it, files that record reasoning rather than only documents, and monitoring that continues after onboarding. Everything else, including the software, is implementation. With the European single rulebook applying from 10 July 2027, the sensible sequence is to fix the reasoning now and adjust the detail as the technical standards appear.

Law & More advises financial institutions, crypto-asset service providers, trust offices, professional service firms and their directors on Wwft and sanctions compliance. We draft and review risk assessments and client acceptance policies, carry out file remediation, advise on individual UBO and sanctions questions, and represent institutions and board members in supervisory investigations, enforcement proceedings and criminal investigations. If you are facing a specific question or an information request from a supervisor, please contact our lawyers.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Share capital is the equity of a company divided into shares, as laid down in

A verbal agreement in commercial transactions is binding under Dutch law. Contracts are formed by

Explore whether verbal agreements can be enforced and understand their legal standing in the Netherlands.
Explore the evolving Dutch art law landscape in 2025 and gain insights on protecting your

A participation agreement is the contract between a company, its existing shareholders and an incoming

Explore mergers and acquisitions in the Netherlands for 2025. Get expert legal insights for individuals

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.