What are the KYC documentation requirements?
Chapter 2: KYC Documentation Requirements
Know Your Client documentation forms the foundation of your compliance obligations. The 2025 Compliance Report and Joint CSA/CIRO Staff Notice 31-368 specify exactly what must be documented and how.
2.1 Required KYC Elements
CIRO requires specific information to be collected and documented for each client:
| Element | Documentation Required | Update Trigger |
|---|---|---|
| Personal circumstances | Name, age, employment, dependents, life stage | Material change |
| Financial circumstances | Income, assets, liabilities, liquidity needs | Material change or annually |
| Investment knowledge | Experience level, understanding of products | As relevant |
| Investment objectives | Growth, income, preservation, time horizon | Material change |
| Risk profile | Tolerance AND capacity assessed separately | Material change |
| Investment time horizon | Short, medium, long-term needs | Material change |
| Account purpose | Registered, non-registered, specific goals | As relevant |
Documentation means more than checking boxes. The Joint CSA/CIRO Staff Notice 31-368 specifically identified inadequate documentation: "Some registrants used KYC forms with 'low', 'medium' and 'high' checkboxes for risk tolerance and risk capacity without explaining these terms or documenting how the risk profile was determined."
2.2 Risk Tolerance vs. Risk Capacity
This distinction is critical and frequently misunderstood.
Key Distinction
Risk Tolerance: The client's willingness to accept risk. This is subjective. CIRO describes it as the "sleep at night test": how much uncertainty can the client tolerate before it interferes with their peace of mind?
Risk Capacity: The client's ability to endure financial loss. This is objective, based on financial circumstances including income, assets, liabilities, liquidity needs, and how much of total investments a particular account represents.
The regulatory requirement is clear: "Risk tolerance and risk capacity are separate considerations and should be assessed separately, and a client's overall risk profile should reflect the lower of the two."
That last part matters: the lower of the two. A client who is willing to accept high risk (high tolerance) but cannot afford significant losses (low capacity) should have a low risk profile. If you determine otherwise, the rationale must be clearly documented.
Risk tolerance and risk capacity are separate considerations and should be assessed separately, and a client's overall risk profile should reflect the lower of the two.
When CIRO, PIPEDA, or Law 25 changes, the Dispatch explains what it means.
Once a month: what is changing across CIRO, PIPEDA, and Quebec Law 25, and what it means for advisors using AI tools. A five-minute read.
Subscribe, free2.3 The "Reasonability" Review
The 2025 Compliance Report introduces explicit expectations for reasonability review:
"Recent examinations have identified deficiencies in KYC and suitability information, including issues related to the reasonability of data provided by clients."
This means reviewing whether KYC information makes sense given client circumstances. A 75-year-old retiree with moderate savings claiming high risk tolerance and aggressive growth objectives should prompt further discussion and documentation of that discussion.
The report found "instances where KYC information should have been queried for reasonability, but it was not." Your documentation should reflect not just what information you collected, but that you considered whether it was reasonable.
2.4 When to Update KYC
KYC is not a one-time exercise. Documentation must be updated:
- Before taking any investment action if information may have changed materially
- When the client informs you of changes
- At regular intervals appropriate to the client's circumstances
- When reasonability concerns arise about existing information
The standard is not "collect once and file." The standard is maintaining information that is current, accurate, and reasonable.
Key Takeaways
- Document all required KYC elements, not just checkboxes
- Assess risk tolerance AND risk capacity separately
- Risk profile reflects the lower of the two
- Review KYC for reasonability, not just completeness
- Update documentation when circumstances change