What ID copy does your bank actually need?
The difference between an official KYC upload and an ad hoc emailed copy — and what to redact either way.
Short answer
- Official app or portal: expect to send the full document — redacting there can make the check fail.
- Ad hoc email or message: verify the request on the number on your card before sending anything.
- Your date of birth is frequently required for KYC name-and-DOB matching, so check before hiding it.
Opening an account, or sometimes just keeping one open, a bank asks to verify your identity. Unlike a hotel or a landlord, this one usually has a real regulatory basis — but not every way of asking for it is equally safe, and it’s worth knowing the difference.
Why banks ask: KYC and anti-money-laundering rules
Financial institutions are generally required by law to know who their customers are — a set of checks usually called KYC (know your customer), part of wider anti-money-laundering regulation. This isn’t a bank being nosy; verifying identity before opening or maintaining an account is a compliance obligation in most places, and it’s one of the few ID requests in this guide series with a hard legal basis behind it.
The channel matters more than usual here
Most legitimate KYC verification happens through the bank’s own app or secure upload portal — built for exactly this, and the system the compliance check is actually designed around. That’s a different situation from a request to email a photo, message it, or send it some other ad hoc way. If someone claiming to be from your bank asks for a copy outside the official channel, verify the request independently — call the number on your card or their official site — before sending anything.
What an official KYC upload needs
Official portals are usually designed to capture the full, unredacted document, because the verification system is built to check it against the data you provide (name, date of birth, document number) and sometimes to match your face to the photo. Redacting fields there can cause the check to fail — this is one of the few cases in this guide series where the full document, through the right channel, is genuinely what’s required.
Official portal versus an ad hoc request
| The bank’s own app or portal | Email, message or other ad hoc request | |
|---|---|---|
| Is it expected? | Yes — the KYC check is built around it | Rarely; verify independently before sending anything |
| Send the full document? | Usually yes — redacting can make the check fail | No — send a redacted, watermarked copy |
| Date of birth | Required for name-and-date matching | Often required too; check before hiding it |
| Number and MRZ | Required | Cover unless that specific check needs them |
| Watermark | Not applicable | Always, naming the request and date |
If you’re sending a copy outside that system
Sometimes a copy is requested by email or in person for a specific, limited purpose — a mortgage broker, an account opening step handled by a human rather than the app. There, the usual rules apply:
- The document number and the machine-readable zone can usually be covered unless the specific check needs them.
- Your signature can usually be covered unless it’s being compared to one on file.
- Your date of birth is frequently required for KYC name-and-DOB matching — check before hiding it, rather than assuming it’s safe to cover.
- Add a watermark naming the request and date regardless.
Do it on your phone when a redacted copy is appropriate
For the cases where a redacted copy is the right call, Anonymize my ID produces one entirely on-device — see how to redact a passport or ID card for exactly which fields to cover. When in doubt about what a specific KYC process needs, ask the bank directly rather than guessing — sending too little can be as much of a hassle as sending too much.
Frequently asked questions
Why does a bank need a copy of my ID?
Banks are generally required by anti-money-laundering and know-your-customer (KYC) rules to verify who their customers are before opening or maintaining an account. That's a legitimate, regulated requirement — the question is how they collect it.
Is it safe to upload my ID through my bank's official app or portal?
That's generally the safest channel for this specific purpose — it's built for it, usually encrypted in transit, and is what the KYC requirement actually expects. It's a different situation from being asked to email or message a copy outside that system.
A bank employee asked me to email a copy of my ID — is that normal?
Be cautious. Legitimate KYC verification almost always happens through the bank's own secure upload system, not a personal email exchange. If email is genuinely the only option offered, send a redacted, watermarked copy and confirm the request through an official channel first.
What should I redact if I do send a copy outside an official portal?
The document number, the machine-readable zone, and your signature at minimum. Your date of birth is often required for KYC matching, so you may need to leave that visible — check what the specific check actually requires before hiding it.