Token导航 LogoToken导航TokenDH.com
研究检索只读github未标认证来源可访问许可证需确认审计通过

know-your-customer了解你的客户

Agent Skill

know-your-customer 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

1,746

周安装

75

GitHub Stars

58

下载量

612
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:know-your-customer(了解你的客户)
来源仓库:https://github.com/joellewis/finance_skills
仓库路径:skills/know-your-customer
安装命令:
npx skills add https://github.com/joellewis/finance_skills --skill know-your-customer
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/joellewis/finance_skills --skill know-your-customer

简介

know-your-customer 用于查找、检索和筛选相关信息。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中根据关键词、任务场景或来源线索快速定位候选结果时使用。
  • 可结合来源仓库、安装命令和原始 README 继续核验具体用法。
  • 安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Know Your Customer

Purpose

Guide the implementation of customer identification, due diligence, and ongoing monitoring requirements under federal and FINRA rules. This skill covers CIP, CDD, beneficial ownership, enhanced due diligence, and profile maintenance — enabling a user or agent to design compliant onboarding and customer monitoring processes.

Layer

9 — Compliance & Regulatory Guidance

Direction

prospective

When to Use

  • Designing customer onboarding or account opening workflows
  • Implementing Customer Identification Programs (CIP)
  • Collecting beneficial ownership information for legal entity accounts
  • Determining when enhanced due diligence (EDD) is required
  • Building customer risk rating and profiling systems
  • Establishing triggers for KYC refresh and ongoing monitoring
  • Understanding what "essential facts" must be gathered under FINRA Rule 2090
  • Evaluating documentary vs non-documentary identity verification methods
  • Designing systems that feed KYC data into suitability and AML processes

Core Concepts

FINRA Rule 2090 — Know Your Customer

Every FINRA member must use reasonable diligence, with regard to the opening and maintenance of every account, to know and retain the essential facts concerning every customer and concerning the authority of each person acting on behalf of the customer. "Essential facts" are those required to: (a) effectively service the account, (b) act in accordance with any special handling instructions, (c) understand the authority of each person acting on behalf of the customer, and (d) comply with applicable laws, regulations, and rules.

Customer Identification Program (CIP)

Required under USA PATRIOT Act Section 326 and implementing regulations (31 CFR 1020.220 for banks; similar requirements apply to broker-dealers under SEC Rule 17a-8 and FINRA rules). The CIP must include:

  • Identity verification for each customer opening an account: name, date of birth (for individuals), address, and identification number (SSN for US persons; passport number/country or other government ID for non-US persons)
  • Verification procedures using documentary methods (government-issued ID), non-documentary methods (credit bureau checks, public database searches, financial statement review), or a combination
  • Recordkeeping — retain identifying information and verification methods for 5 years after account closure
  • Comparison with government lists — check customer names against OFAC and other government terrorist/sanctions lists
  • Customer notice — inform customers that information is being collected to verify identity

Customer Due Diligence (CDD) Rule

FinCEN's CDD Rule (31 CFR 1010.230, effective May 2018) requires covered financial institutions to:

  1. Identify and verify the identity of customers (overlaps with CIP)
  2. Identify and verify the identity of beneficial owners of legal entity customers — any individual who owns 25% or more of the equity interests, plus one individual with significant responsibility for managing the entity (a control person)
  3. Understand the nature and purpose of customer relationships to develop a customer risk profile
  4. Conduct ongoing monitoring to identify suspicious transactions and, on a risk basis, maintain and update customer information

The 25% beneficial ownership threshold applies to legal entities (corporations, LLCs, partnerships). Certain entities are exempt: publicly traded companies, regulated financial institutions, government entities, and others listed in the rule.

Enhanced Due Diligence (EDD)

Higher-risk customers require additional scrutiny beyond standard CDD:

  • Politically Exposed Persons (PEPs) — senior foreign political figures and their families/associates. No US regulatory definition mandates PEP screening for domestic customers, but FinCEN guidance and FATF standards expect it for foreign PEPs. Firms should understand the source of wealth and funds.
  • Foreign correspondent accounts — BSA Section 312 requires EDD for correspondent accounts maintained for foreign financial institutions, with heightened requirements for institutions in jurisdictions of concern
  • High-risk jurisdictions — countries identified by FATF, FinCEN advisories, or firm risk assessments as presenting elevated ML/TF risk
  • Complex ownership structures — multi-layered entities, trusts with opaque beneficiary structures, nominee arrangements
  • Unusual account activity — customers whose transaction patterns deviate significantly from expected activity based on their profile

EDD measures include: senior management approval for account opening, source of wealth/funds verification, more frequent account reviews, enhanced transaction monitoring, and ongoing negative media screening.

Documentary vs Non-Documentary Verification

Documentary methods: Unexpired government-issued photo ID (driver's license, passport, state ID), documents showing formation of a legal entity (articles of incorporation, partnership agreement, trust instrument).

Non-documentary methods: Credit bureau inquiries, public database verification (Lexis-Nexis, etc.), financial statement verification, references from other financial institutions. Required as a backup when documentary verification is unavailable, inconclusive, or the customer is not physically present (e.g., online account opening).

Firms must use non-documentary methods in at least the following situations: (1) the customer opens an account without appearing in person, (2) the firm is not familiar with the documents presented, (3) other circumstances that increase risk.

Ongoing Monitoring and Profile Updates

KYC is not a one-time event. Customer profiles must be updated when:

  • Material life events occur (retirement, marriage/divorce, inheritance, job loss, significant health changes)
  • Account review triggers fire (periodic reviews, risk-based reviews, transaction-triggered reviews)
  • Transaction patterns deviate significantly from the established profile
  • The customer provides new information that changes their investment profile
  • Regulatory changes require additional information (e.g., new beneficial ownership requirements)

FINRA does not mandate a specific refresh cycle, but firms typically establish risk-based review schedules (e.g., annual review for high-risk accounts, every 3 years for standard risk).

SEC Requirements for Investment Advisers

Investment advisers have a fiduciary duty to understand their clients, which creates KYC-like obligations independent of FINRA rules. Form ADV Part 2A describes the adviser's services and client relationships. The SEC expects advisers to gather sufficient information to fulfill their fiduciary duty of care — including financial situation, investment objectives, risk tolerance, and any constraints. FinCEN's 2024 final rule (31 CFR Part 1032, effective January 1, 2026) extends BSA/AML requirements — including CIP and CDD — to SEC-registered investment advisers.

Recordkeeping Requirements

  • CIP records: Identifying information, verification documents/methods, and resolution of discrepancies must be retained for 5 years after account closure
  • CDD/beneficial ownership: Copies of beneficial ownership certification forms and verification records retained for 5 years after account closure
  • Account records: FINRA Rule 4512 requires maintenance of customer name, tax ID, address, date of birth, employment status, associated person relationship, trusted contact person, and other information specified in the rule
  • Reliance on other institutions: Under Section 326 reliance provisions, a firm may rely on another financial institution's CIP if: (a) the relying firm's CIP incorporates this reliance, (b) the other institution is subject to an AML program rule, and (c) the other institution enters into a written contract for this purpose

Worked Examples

Example 1: Opening a trust account without identifying beneficial owners

Scenario: A wealth management firm opens a revocable living trust account for a family trust. The account opening team collects the trust agreement and identifies the grantor/trustee but does not collect beneficial ownership information on the trust beneficiaries. The trust holds $2M in investable assets. Compliance Issues: Potential CDD Rule violation. While revocable living trusts are generally exempt from the beneficial ownership requirement (since the grantor maintains control), irrevocable trusts and other legal entity structures require beneficial ownership identification. The team must correctly classify the trust type. Additionally, FINRA Rule 4512 requires identification of all persons authorized to transact in the account. Analysis: The firm should have a clear trust classification workflow that determines: (1) whether beneficial ownership requirements apply based on the trust type, (2) who has authority to act on the account, and (3) what documentation is required. For revocable trusts, identifying the grantor/trustee as the beneficial owner and control person is typically sufficient, but the firm should verify the trust is truly revocable and document the determination. The trust agreement must be reviewed — not just collected.

Example 2: Failing to update KYC after a client retires

Scenario: A long-standing client retires at age 65 after 20 years at the firm. Her account profile still lists her investment objective as "aggressive growth," risk tolerance as "high," and annual income at $250,000. Post-retirement, her income drops to $80,000 (Social Security and pension) and she begins taking regular distributions from the account. No profile update is triggered. Compliance Issues: Stale KYC data leading to potential suitability violations. The client's investment profile has materially changed — time horizon has shifted, income has declined, liquidity needs have increased (regular distributions), and risk capacity has decreased. Continued aggressive growth recommendations based on outdated profile data would likely violate suitability obligations. Analysis: The firm should have systems that flag material life events (age milestones, distribution patterns, income changes) as triggers for KYC refresh. A representative who knows a client has retired but does not update the profile is failing the "reasonable diligence" standard of Rule 2090. Best practice: establish automated triggers (client turns 65, regular withdrawals begin, account balance drops significantly) and require profile confirmation at each periodic review.

Example 3: Onboarding a high-risk foreign entity

Scenario: A broker-dealer receives an account application from a newly formed LLC registered in Delaware with a single listed owner who is a citizen of a jurisdiction flagged in a FinCEN advisory. The stated purpose is "general investing." The LLC provides articles of organization but limited information about the source of funds. Compliance Issues: Multiple red flags requiring enhanced due diligence: newly formed entity, high-risk jurisdiction connection, limited transparency on source of funds, Delaware LLC (common in layering structures). Standard CDD is insufficient. Analysis: The firm must: (1) complete standard CDD including beneficial ownership (25% owners and one control person), (2) escalate to enhanced due diligence given the risk factors, (3) verify source of funds and source of wealth, (4) conduct OFAC screening on all identified individuals, (5) obtain senior management approval before opening, (6) establish enhanced ongoing monitoring. The firm should also consider whether the limited information provided is itself a red flag warranting a SAR filing or account refusal. Simply accepting "general investing" as a purpose statement for a high-risk entity is insufficient.

Common Pitfalls

  • Treating KYC as a one-time account-opening exercise rather than an ongoing obligation
  • Collecting but not verifying beneficial ownership information — the CDD Rule requires both identification and verification
  • Applying the same due diligence to all customers regardless of risk — risk-based approach is required
  • Not documenting when a customer declines to provide information and failing to narrow the recommendation universe accordingly
  • Relying solely on documentary verification for online/remote account opening without implementing non-documentary backup methods
  • Failing to establish automated triggers for profile refresh (life events, transaction anomalies, age milestones)
  • Not screening beneficial owners and control persons against OFAC and other sanctions lists
  • Confusing the CDD Rule's beneficial ownership requirements with FINRA Rule 4512's account record requirements — they overlap but are distinct
  • Incomplete trust classification leading to incorrect application of beneficial ownership requirements
  • Not training frontline staff to recognize when a customer's circumstances have changed, triggering a profile update obligation

Cross-References

  • anti-money-laundering (Layer 9): KYC/CDD data feeds directly into AML monitoring and suspicious activity detection
  • investment-suitability (Layer 9): Customer profile gathered through KYC is the foundation for suitability analysis
  • reg-bi (Layer 9): Reg BI's Care Obligation requires understanding the customer's investment profile — sourced from KYC
  • investment-policy (Layer 5): IPS constraints (time horizon, risk tolerance, liquidity) derive from KYC profiling

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.49%
按下载量换算223

Claude

27.58%
按下载量换算169

Cursor

19.38%
按下载量换算119

Gemini CLI

8.06%
按下载量换算49

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills