SardineCon SF/2026

Learn More

O que é Know Your Employee (KYE)?

SUBSCRIBE

Know Your Employee is the practice of screening and monitoring your own staff for financial-crime risk, the same way you screen customers. It treats insiders as a distinct threat, because people with access to systems, data, and controls can defeat defenses built to stop outsiders.

What is KYE, in plain English?

Know Your Employee applies due diligence to your own people. At hiring it means background checks, identity verification, sanctions and adverse-media screening, and reference or credential checks. After hiring it means ongoing attention to behavior and access that does not fit an employee's role or known circumstances. The logic is simple: an insider with legitimate credentials can move money, leak data, or quietly disable a control in ways an outside attacker never could.

KYE sits at the intersection of compliance, HR, and security. It is not a single tool, it is a program that runs from pre-hire screening through role changes, promotions, and eventual offboarding. Staff in sensitive positions, such as those who can approve payments, edit customer records, override alerts, or access production systems, warrant heightened scrutiny relative to lower-risk roles.

The core idea for a financial-crime team is that controls assume a trustworthy operator. KYE stress-tests that assumption. The same skepticism you apply to a new customer has a place with the staff who hold the keys, because a compromised or complicit insider can turn your own tooling against you.

What KYE covers across the employee lifecycle

KYE is not a one-time check at hire; it follows the employee through the relationship:

  1. Pre-hire — Screen before access. Background check, identity verification, sanctions and adverse-media screening, and credential validation before granting any system access.
  2. Onboarding — Right-size access. Grant least-privilege access matched to the role, and flag sensitive functions such as payment approval or alert override for closer watch.
  3. Ongoing — Monitor behavior and access. Watch for lifestyle or access anomalies that do not fit the role, and re-screen periodically for new sanctions or adverse-media hits.
  4. Offboarding — Revoke and review. Remove all access promptly on exit or role change, and review recent activity for anything that should have been escalated.

Who owns KYE?

Who

Their role

HR

Runs pre-hire background checks, manages role changes, and handles the offboarding process.

Compliance

Owns sanctions and adverse-media screening of staff and sets the risk-based standard for sensitive roles.

Security or IT

Enforces least-privilege access and surfaces access anomalies such as use of systems outside a job function.

The line manager

Often the first to notice behavioral change, unexplained wealth, or reluctance to take leave.

What it looks like in practice

In practice

An analyst in a payments team starts logging in at odd hours and pulling customer records well outside the accounts assigned to them. Nothing in their caseload explains the access pattern, and a colleague mentions the analyst recently bought a car that seems out of step with their salary.

Security ties the after-hours queries to a small set of high-balance accounts, and compliance finds the analyst had cleared alerts on those same accounts without a documented reason. Access is suspended, the activity is reviewed, and the case is escalated. The outside controls never fired, because the threat was holding valid credentials the whole time.

Why KYE matters to operators

Most fraud and AML controls are built to catch outsiders: unknown devices, mismatched identities, suspicious counterparties. An insider bypasses that entire model because their access is legitimate and expected. They can approve a payment, suppress an alert, or export data without tripping a single external signal, which makes insider risk one of the hardest categories to detect after the fact.

KYE also protects the integrity of every other control. If the person tuning your monitoring rules or clearing your alerts is compromised, the whole system is only as trustworthy as they are. Treating staff screening as a real program, not a hiring formality, is what keeps that assumption honest.

What to watch for

  • Access beyond the role. An employee querying systems or accounts that have nothing to do with their assigned work.
  • Unexplained wealth. Lifestyle changes that do not fit known income, especially for staff who touch money or approvals.
  • Alert or control tampering. Alerts cleared without documented reasons, or thresholds quietly changed by someone with edit rights.
  • Reluctance to take leave. A classic insider-fraud signal, since mandatory time off can expose a scheme that needs constant tending.
  • New screening hits. Sanctions or adverse-media matches that surface on a current employee during periodic re-screening.

Quick questions

How is KYE different from KYC?

KYC verifies and monitors customers; KYE applies the same discipline to your own staff. The techniques overlap, such as sanctions and adverse-media screening, but KYE also draws on access logs and HR signals that only exist for employees.

Is KYE a regulatory requirement?

Elements of it are, depending on jurisdiction and role, such as fit-and-proper checks for certain regulated positions. Beyond specific mandates, most firms run KYE as part of a broader risk-based program because insider risk is real regardless of whether a rule names it.

Which employees need the most scrutiny?

Those in sensitive roles: anyone who can approve payments, edit customer or account data, override alerts, or access production systems. Risk scales with access, so screening and monitoring should scale with it too.

Does KYE mean spying on staff?

No. Effective programs are transparent, proportionate, and tied to defined risk, focusing on access anomalies and role fit rather than blanket surveillance. The goal is to catch misuse of privilege, not to monitor everyone equally.

What is the link between KYE and insider fraud?

KYE is the control designed to reduce insider and occupational fraud risk. When it works, it catches the access and behavior anomalies that precede or accompany an insider scheme before the loss grows.

When should access be re-reviewed?

On any role change or promotion, on a periodic cycle for sensitive roles, and immediately on exit. Stale access left in place after someone changes jobs is one of the most common insider-risk gaps.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Know Your Employee (KYE)