Agent skill

Know Your Customer

by JoelLewis in JoelLewis/finance_skills

Guide customer onboarding identification, due diligence, and profile maintenance under FINRA Rule 2090, the CIP rules, and the FinCEN CDD Rule.

MITAuto-check passedBusiness, Finance & HR

Install Know Your Customer

skills CLI
$ npx skills add JoelLewis/finance_skills --skill know-your-customer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install JoelLewis/finance_skills know-your-customer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/know-your-customer .claude/skills/know-your-customer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
know-your-customer
GitHub stars
206
Token cost
~3.6k tokens
SKILL.md length
1,768 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Guide customer onboarding identification, due diligence, and profile maintenance under FINRA Rule 2090, the CIP rules, and the FinCEN CDD Rule.

  • Works in 4 steps: Identify and verify the identity of… → Identify and verify the identity of… → Understand the nature and purpose of… → …
  • The user asks about onboarding identity verification
  • SKILL.md covers Core Concepts, Worked Examples, Common Pitfalls and Cross-References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Know Your Customer is an agent skill from JoelLewis/finance_skills. Guide customer onboarding identification, due diligence, and profile maintenance under FINRA Rule 2090, the CIP rules, and the FinCEN CDD Rule. Use when the user asks about onboarding identity verification, beneficial ownership collection for entity accounts, enhanced due diligence for PEPs or high-risk customers at account opening, assigning the initial customer risk rating, KYC refresh triggers, or documentary vs non-documentary verification. Also trigger when users mention 'account opening requirements', 'who…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Fundraising and pitch decks and Customer success. The repository describes itself as: Claude Code skill plugins for financial services — 81 skills across 7 domain plugins covering investment management, compliance, advisory practice, trading, and operations. The licence is MIT.

When your agent uses it

  • The user asks about onboarding identity verification
  • Beneficial ownership collection for entity accounts
  • Enhanced due diligence for PEPs
  • High-risk customers at account opening

Example prompts

  • “account opening requirements”
  • “who is the beneficial owner”
  • “new client identity check”
  • “/know-your-customer”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify and verify the identity of customers (overlaps with CIP)
  2. Identify and verify the identity of beneficial owners of legal entity customers — any individual who owns 25% or more of the equity…
  3. Understand the nature and purpose of customer relationships to develop a customer risk profile
  4. Conduct ongoing monitoring to identify suspicious transactions and, on a risk basis, maintain and update customer information

What it can do on your machine

Read from SKILL.md and the folder at commit 5c498ea. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Know Your Customer loads about 3.6k tokens when it runs. Until then it costs about 217 tokens; SKILL.md has 1,768 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~217
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from JoelLewis/finance_skills at commit 5c498ea, republished under its MIT licence (© JoelLewis). 1,768 words, ~3,587 tokens.

Download SKILL.mdSave it as .claude/skills/know-your-customer/SKILL.md (or your agent's skills folder).
name
know-your-customer
description
Guide customer onboarding identification, due diligence, and profile maintenance under FINRA Rule 2090, the CIP rules, and the FinCEN CDD Rule. Use when the user asks about onboarding identity verification, beneficial ownership collection for entity accounts, enhanced due diligence for PEPs or high-risk customers at account opening, assigning the initial customer risk rating, KYC refresh triggers, or documentary vs non-documentary verification. Also trigger when users mention 'account opening requirements', 'who is the beneficial owner', 'new client identity check', 'how often to update KYC', 'essential facts for the account', 'foreign customer onboarding', or ask what information must be gathered before opening an account. (For ongoing transaction monitoring, SAR filing, and surveillance-driven risk re-rating, use anti-money-laundering.)

Know Your Customer

Regulatory status current as of June 2026 — verify effective dates, dollar thresholds, and pending rulemakings against current SEC/FINRA/FinCEN sources before advising.

Core Concepts

FINRA Rule 2090 — Know Your Customer

Every FINRA member must use reasonable diligence, with regard to the opening and maintenance of every account, to know and retain the essential facts concerning every customer and concerning the authority of each person acting on behalf of the customer. "Essential facts" are those required to: (a) effectively service the account, (b) act in accordance with any special handling instructions, (c) understand the authority of each person acting on behalf of the customer, and (d) comply with applicable laws, regulations, and rules.

Customer Identification Program (CIP)

Required under USA PATRIOT Act Section 326 and implementing regulations. The broker-dealer CIP rule is 31 CFR 1023.220; the bank CIP rule is 31 CFR 1020.220. (SEC Rule 17a-8 separately requires broker-dealers to comply with BSA recordkeeping and reporting.) The CIP must include:

  • Identity verification for each customer opening an account: name, date of birth (for individuals), address, and identification number (SSN for US persons; passport number/country or other government ID for non-US persons)
  • Verification procedures using documentary methods (government-issued ID), non-documentary methods (credit bureau checks, public database searches, financial statement review), or a combination
  • Recordkeeping — retain identifying information and verification methods for 5 years after account closure
  • Comparison with government lists — check customer names against OFAC and other government terrorist/sanctions lists
  • Customer notice — inform customers that information is being collected to verify identity
Customer Due Diligence (CDD) Rule

FinCEN's CDD Rule (31 CFR 1010.230, effective May 2018) requires covered financial institutions to:

  1. Identify and verify the identity of customers (overlaps with CIP)
  2. Identify and verify the identity of beneficial owners of legal entity customers — any individual who owns 25% or more of the equity interests, plus one individual with significant responsibility for managing the entity (a control person)
  3. Understand the nature and purpose of customer relationships to develop a customer risk profile
  4. Conduct ongoing monitoring to identify suspicious transactions and, on a risk basis, maintain and update customer information

The 25% beneficial ownership threshold applies to legal entities (corporations, LLCs, partnerships). Certain entities are exempt: publicly traded companies, regulated financial institutions, government entities, and others listed in the rule.

Enhanced Due Diligence (EDD)

Higher-risk customers require additional scrutiny beyond standard CDD:

  • Politically Exposed Persons (PEPs) — senior foreign political figures and their families/associates. No US regulatory definition mandates PEP screening for domestic customers, but FinCEN guidance and FATF standards expect it for foreign PEPs. Firms should understand the source of wealth and funds.
  • Foreign correspondent accounts — BSA Section 312 requires EDD for correspondent accounts maintained for foreign financial institutions, with heightened requirements for institutions in jurisdictions of concern
  • High-risk jurisdictions — countries identified by FATF, FinCEN advisories, or firm risk assessments as presenting elevated ML/TF risk
  • Complex ownership structures — multi-layered entities, trusts with opaque beneficiary structures, nominee arrangements
  • Unusual account activity — customers whose transaction patterns deviate significantly from expected activity based on their profile

EDD measures include: senior management approval for account opening, source of wealth/funds verification, more frequent account reviews, enhanced transaction monitoring, and ongoing negative media screening.

Documentary vs Non-Documentary Verification

Documentary methods: Unexpired government-issued photo ID (driver's license, passport, state ID), documents showing formation of a legal entity (articles of incorporation, partnership agreement, trust instrument).

Non-documentary methods: Credit bureau inquiries, public database verification (Lexis-Nexis, etc.), financial statement verification, references from other financial institutions. Required as a backup when documentary verification is unavailable, inconclusive, or the customer is not physically present (e.g., online account opening).

Firms must use non-documentary methods in at least the following situations: (1) the customer opens an account without appearing in person, (2) the firm is not familiar with the documents presented, (3) other circumstances that increase risk.

Ongoing Monitoring and Profile Updates

KYC is not a one-time event. Customer profiles must be updated when:

  • Material life events occur (retirement, marriage/divorce, inheritance, job loss, significant health changes)
  • Account review triggers fire (periodic reviews, risk-based reviews, transaction-triggered reviews)
  • Transaction patterns deviate significantly from the established profile
  • The customer provides new information that changes their investment profile
  • Regulatory changes require additional information (e.g., new beneficial ownership requirements)

FINRA does not mandate a specific refresh cycle, but firms typically establish risk-based review schedules (e.g., annual review for high-risk accounts, every 3 years for standard risk).

SEC Requirements for Investment Advisers

Investment advisers have a fiduciary duty to understand their clients, which creates KYC-like obligations independent of FINRA rules. Form ADV Part 2A describes the adviser's services and client relationships. The SEC expects advisers to gather sufficient information to fulfill their fiduciary duty of care — including financial situation, investment objectives, risk tolerance, and any constraints. FinCEN's 2024 final rule (31 CFR Part 1032) would extend BSA/AML program and SAR requirements to SEC-registered investment advisers, but its effective date was postponed from January 1, 2026 to January 1, 2028, and FinCEN has said it will revisit the rule's substance (and the companion proposed adviser CIP rule, jointly with the SEC) before then — verify current status.

Recordkeeping Requirements
  • CIP records: Identifying information, verification documents/methods, and resolution of discrepancies must be retained for 5 years after account closure
  • CDD/beneficial ownership: Copies of beneficial ownership certification forms and verification records retained for 5 years after account closure
  • Account records: FINRA Rule 4512 requires maintenance of customer name, tax ID, address, date of birth, employment status, associated person relationship, trusted contact person, and other information specified in the rule
  • Reliance on other institutions: Under Section 326 reliance provisions, a firm may rely on another financial institution's CIP if: (a) the relying firm's CIP incorporates this reliance, (b) the other institution is subject to an AML program rule, and (c) the other institution enters into a written contract for this purpose

Worked Examples

Show full SKILL.md (798 more words)Show less
Example 1: Opening a trust account without identifying beneficial owners

Scenario: A wealth management firm opens a revocable living trust account for a family trust. The account opening team collects the trust agreement and identifies the grantor/trustee but does not collect beneficial ownership information on the trust beneficiaries. The trust holds $2M in investable assets. Compliance Issues: Potential CDD Rule violation. While revocable living trusts are generally exempt from the beneficial ownership requirement (since the grantor maintains control), irrevocable trusts and other legal entity structures require beneficial ownership identification. The team must correctly classify the trust type. Additionally, FINRA Rule 4512 requires identification of all persons authorized to transact in the account. Analysis: The firm should have a clear trust classification workflow that determines: (1) whether beneficial ownership requirements apply based on the trust type, (2) who has authority to act on the account, and (3) what documentation is required. For revocable trusts, identifying the grantor/trustee as the beneficial owner and control person is typically sufficient, but the firm should verify the trust is truly revocable and document the determination. The trust agreement must be reviewed — not just collected.

Example 2: Failing to update KYC after a client retires

Scenario: A long-standing client retires at age 65 after 20 years at the firm. Her account profile still lists her investment objective as "aggressive growth," risk tolerance as "high," and annual income at $250,000. Post-retirement, her income drops to $80,000 (Social Security and pension) and she begins taking regular distributions from the account. No profile update is triggered. Compliance Issues: Stale KYC data leading to potential suitability violations. The client's investment profile has materially changed — time horizon has shifted, income has declined, liquidity needs have increased (regular distributions), and risk capacity has decreased. Continued aggressive growth recommendations based on outdated profile data would likely violate suitability obligations. Analysis: The firm should have systems that flag material life events (age milestones, distribution patterns, income changes) as triggers for KYC refresh. A representative who knows a client has retired but does not update the profile is failing the "reasonable diligence" standard of Rule 2090. Best practice: establish automated triggers (client turns 65, regular withdrawals begin, account balance drops significantly) and require profile confirmation at each periodic review.

Example 3: Onboarding a high-risk foreign entity

Scenario: A broker-dealer receives an account application from a newly formed LLC registered in Delaware with a single listed owner who is a citizen of a jurisdiction flagged in a FinCEN advisory. The stated purpose is "general investing." The LLC provides articles of organization but limited information about the source of funds. Compliance Issues: Multiple red flags requiring enhanced due diligence: newly formed entity, high-risk jurisdiction connection, limited transparency on source of funds, Delaware LLC (common in layering structures). Standard CDD is insufficient. Analysis: The firm must: (1) complete standard CDD including beneficial ownership (25% owners and one control person), (2) escalate to enhanced due diligence given the risk factors, (3) verify source of funds and source of wealth, (4) conduct OFAC screening on all identified individuals, (5) obtain senior management approval before opening, (6) establish enhanced ongoing monitoring. The firm should also consider whether the limited information provided is itself a red flag warranting a SAR filing or account refusal. Simply accepting "general investing" as a purpose statement for a high-risk entity is insufficient.

Common Pitfalls

  • Treating KYC as a one-time account-opening exercise rather than an ongoing obligation
  • Collecting but not verifying beneficial ownership information — the CDD Rule requires both identification and verification
  • Applying the same due diligence to all customers regardless of risk — risk-based approach is required
  • Not documenting when a customer declines to provide information and failing to narrow the recommendation universe accordingly
  • Relying solely on documentary verification for online/remote account opening without implementing non-documentary backup methods
  • Failing to establish automated triggers for profile refresh (life events, transaction anomalies, age milestones)
  • Not screening beneficial owners and control persons against OFAC and other sanctions lists
  • Confusing the CDD Rule's beneficial ownership requirements with FINRA Rule 4512's account record requirements — they overlap but are distinct
  • Incomplete trust classification leading to incorrect application of beneficial ownership requirements
  • Not training frontline staff to recognize when a customer's circumstances have changed, triggering a profile update obligation

Cross-References

  • anti-money-laundering (compliance plugin): KYC/CDD data feeds directly into AML monitoring and suspicious activity detection
  • investment-suitability (compliance plugin): Customer profile gathered through KYC is the foundation for suitability analysis
  • reg-bi (compliance plugin): Reg BI's Care Obligation requires understanding the customer's investment profile — sourced from KYC
  • investment-policy (wealth-management plugin): IPS constraints (time horizon, risk tolerance, liquidity) derive from KYC profiling
  • account-opening-compliance (client-operations plugin): The onboarding compliance workflow that operationalizes CIP verification, CDD, and beneficial ownership collection defined here
  • account-opening-workflow (client-operations plugin): The operational account opening process where KYC data collection and verification are embedded

© JoelLewis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/compliance/skills/know-your-customer of JoelLewis/finance_skills.

Open the folder on GitHubat commit 5c498ea

Compare with similar skills

Know Your Customer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Know Your Customer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Know Your Customer this skillJoelLewis/finance_skills206—~3.6kAutomated safety check: PassMIT
Gtm Board And Investor Communicationgithub/awesome-copilot40k1 repos~4.7kAutomated safety check: PassMIT
Board Deck Builderalirezarezvani/claude-skills28k1 repos~1.9kAutomated safety check: PassMIT
Board Deck Builderborghei/Claude-Skills891—~4.5kAutomated safety check: PassMIT
Alpaca Broker Account Onboardingalpacahq/alpaca-skills154—~2.3kAutomated safety check: PassApache-2.0
Apify Buying Signal Detectionapify/awesome-skills266—~5.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Official

    Board meeting preparation, investor updates, and executive communication.

    40k GitHub starsUsed in 1 repo~4.7k tokens
    Business, Finance & HRAuto-check passed
  • Board Deck Builder

    alirezarezvani/claude-skills

    Assembles comprehensive board and investor update decks by pulling perspectives from all C-suite roles.

    28k GitHub starsUsed in 1 repo~1.9k tokens
    Business, Finance & HRAuto-check passed
  • Board Deck Builder

    borghei/Claude-Skills

    Assembles board and investor update decks by pulling perspectives from all C-suite roles.

    891 GitHub stars~4.5k tokensUpdated 3 days ago
    Business, Finance & HRAuto-check passed
  • Alpaca Broker Account Onboarding

    alpacahq/alpaca-skills

    Open and manage brokerage accounts via the Alpaca Broker API — account creation, KYC/CIP, identity & disclosures, agreements, document upload (incl.

    154 GitHub stars~2.3k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Apify Buying Signal Detection

    apify/awesome-skills

    Official

    Set up a recurring buying-signal detection pipeline that finds companies showing buying intent across three signal types — job postings (hiring for the persona), fundraising events (recent raises)…

    266 GitHub stars~5.1k tokensUpdated 18 days ago
    Business, Finance & HRAuto-check: notes
  • Investor Outreach

    affaan-m/ECC

    Draft cold emails, warm intro blurbs, follow-ups, update emails, and investor communications for fundraising.

    277k GitHub starsUsed in 6 repos~664 tokens
    Business, Finance & HRAuto-check passed

More from JoelLewis/finance_skills

All 91 skills in this repo
  • Asset Allocation

    JoelLewis/finance_skills

    Determine how to distribute capital across asset classes using strategic and tactical allocation frameworks.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Bet Sizing

    JoelLewis/finance_skills

    Determine how much capital to allocate to individual positions within a portfolio.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Commodities

    JoelLewis/finance_skills

    Analyze commodity markets including futures curve dynamics, roll yield, and supply/demand fundamentals.

    206 GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Currencies And Fx

    JoelLewis/finance_skills

    Analyze currency markets, exchange rate mechanics, and FX risk management for international portfolios.

    206 GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Debt Management

    JoelLewis/finance_skills

    Provide frameworks for managing and paying off personal debt effectively.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Diversification

    JoelLewis/finance_skills

    Build diversified portfolios using correlation analysis, efficient frontier construction, and factor-based diversification.

    206 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Know Your Customer

What does Know Your Customer do?

Guide customer onboarding identification, due diligence, and profile maintenance under FINRA Rule 2090, the CIP rules, and the FinCEN CDD Rule. Know Your Customer is an agent skill from JoelLewis/finance_skills. Guide customer onboarding identification, due diligence, and profile maintenance under FINRA Rule 2090, the CIP rules, and the FinCEN CDD Rule.

When should I use Know Your Customer?

Know Your Customer fits situations like: the user asks about onboarding identity verification; beneficial ownership collection for entity accounts; enhanced due diligence for PEPs; high-risk customers at account opening.

How do I install Know Your Customer in Claude Code?

Run `npx skills add JoelLewis/finance_skills --skill know-your-customer -a claude-code`. Or copy the skill folder (plugins/compliance/skills/know-your-customer in JoelLewis/finance_skills) into .claude/skills/know-your-customer in your project. Claude Code loads it when a task matches its description.

How do I install Know Your Customer in Codex?

Run `npx skills add JoelLewis/finance_skills --skill know-your-customer -a codex`. Or copy the skill folder (plugins/compliance/skills/know-your-customer in JoelLewis/finance_skills) into .agents/skills/know-your-customer in your project. Codex loads it when a task matches its description.

Can I use Know Your Customer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JoelLewis/finance_skills --skill know-your-customer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/know-your-customer, .gemini/skills/know-your-customer, .github/skills/know-your-customer and .opencode/skills/know-your-customer in your project.

What does Know Your Customer need to run?

SKILL.md names no scripts, command-line tools or credentials: Know Your Customer is instructions for the agent only.

Does Know Your Customer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Know Your Customer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Know Your Customer use?

Know Your Customer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Know Your Customer use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Know Your Customer?

Skills that share tags, products or a category with Know Your Customer: Gtm Board And Investor Communication (github/awesome-copilot, 40k stars), Board Deck Builder (alirezarezvani/claude-skills, 28k stars), Board Deck Builder (borghei/Claude-Skills, 891 stars) and Alpaca Broker Account Onboarding (alpacahq/alpaca-skills, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Know Your Customer?

JoelLewis (a GitHub user) maintains it in JoelLewis/finance_skills, which has 206 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on July 18, 2026.

Source: JoelLewis/finance_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.