KYB verification is the controlled process of identifying a business, matching it to an authoritative legal-entity record, examining its ownership and management, applying the required risk checks and preserving enough evidence to explain the resulting decision.
The abbreviation means Know Your Business. It is often described as KYC for companies, but the comparison hides the hardest part. A person is normally assessed as one subject. A company may be a trading name, a legal entity, a branch, a subsidiary or one node inside a multinational ownership chain. The applicant completing a form may be authorised to act, may be a director, or may have no formal relationship visible in the source record.
A useful KYB process therefore answers five questions in order:
- Which legal entity is this? Resolve the submitted name, website, address and identifier to one official record.
- Does it exist and can it act? Confirm registration, current status, jurisdiction and relevant filing details.
- Who owns or controls it? Trace shareholders, controlling persons and the wider group to the depth required by policy.
- What risk checks apply? Screen the resolved entities and people, assess relevant company facts and investigate exceptions.
- What happens after approval? Monitor the facts that could make the original decision stale.
The output should not be a vague confidence score. It should separate entity match, legal existence, ownership resolution, risk findings and evidence coverage. A failed source retrieval is different from a completed check that found no concern. Combining those outcomes in one number makes the decision difficult to audit and dangerous to automate.
KYB verification is complete when the business has been resolved to the correct legal entity, required ownership and risk questions have been answered, unresolved gaps are visible, and the evidence can be reproduced later.
Why KYB checks need a new operating model in 2026
Three changes are forcing enterprises to rethink business verification. First, regulatory information is moving at different speeds across jurisdictions. In the United States, FinCEN’s final rule of 11 August 2026 made permanent broad exemptions from federal beneficial ownership reporting for US-created companies and US persons. That change affects one reporting regime; it does not give a bank, marketplace, insurer or procurement team a verified answer about who owns a counterparty.
Second, corporate registries are strengthening identity and filing controls, but coverage remains fragmented. One jurisdiction may expose shareholders and filing images; another may publish only basic company details; a third may restrict access or use a different definition of control. A global KYB policy cannot assume that every source returns the same fields, freshness or legal meaning.
Third, automated workflows are consuming company data directly. An onboarding agent, payment-control workflow or procurement system may act on a result without a researcher reading the underlying record. That raises the standard for provenance. The system must know where each fact came from, when it was retrieved, whether the source was available and which rule converted the evidence into a decision.
The result is a shift from document collection to evidence orchestration. Documents remain useful, but they should not automatically outrank a current official record. A certificate uploaded by the applicant can prove what was provided; it may not prove that the company remains active today. The strongest process compares submitted information with current source data and records every difference.
The KYB evidence stack
Control frameworkScreening results are only reliable when they are attached to the correct entity and the correct controlling people.
The seven checks in an enterprise KYB verification process
There is no universal checklist that fits every sector and jurisdiction. The sequence below is a practical core that can be expanded by risk tier, product, geography and legal obligation.
1. Resolve the submitted business to one legal entity
Start with the identifiers least likely to be ambiguous: registration number, jurisdiction, tax or VAT identifier where appropriate, registered name and registered address. Use the website and trading name as supporting signals, not as substitutes for legal identity. If the search returns several plausible entities, stop and request disambiguation instead of selecting the first result.
Record both the submitted value and the matched value. A difference may be harmless—such as punctuation or an old trading address—or it may reveal that the applicant supplied the wrong entity. Company matching should produce an explicit status such as exact match, supported variation, ambiguous match or no match.
2. Verify legal existence and current status
Confirm the entity in the relevant official company source. Capture its legal name, registration number, formation date, entity type, registered office and current status. Do not translate an unavailable source into an active status. “Not retrieved” is an evidence gap; “active” is a positive source finding.
Status labels also need interpretation. Active, good standing, registered and live may not be equivalent across jurisdictions. Store the original source value alongside any normalised status used by the workflow.
3. Confirm directors, officers and authorised representatives
Determine which officers are visible in the official record and whether the person acting for the company has a defensible relationship to it. A director match does not automatically prove transaction authority, and an authorised employee may not be listed as a director. Keep corporate-office verification separate from authority validation so a positive result in one control cannot silently satisfy the other.
4. Resolve ownership and control
Collect direct shareholders where available, calculate indirect holdings when the data supports it, identify controlling persons and trace corporate shareholders through the chain. Preserve the path used to reach each conclusion. A beneficial owner without an explainable ownership path is an assertion, not a reproducible finding.
Thresholds should be policy inputs rather than hard-coded assumptions. Ownership percentage, voting rights, the right to appoint directors and other forms of control can all matter. The correct test depends on the governing rule and the purpose of the check.
5. Apply risk checks to the resolved subjects
Screen the legal entity, relevant parent companies, beneficial owners, directors and representatives according to policy. Keep source identity and screening identity linked. Common names, transliteration and historical names can create false positives, while a missed alias can create false negatives. The reviewer should see which subject was screened, which identifiers were used and why a result was accepted or dismissed.
6. Add financial and operating context
For credit, procurement and higher-risk onboarding, legal existence is not enough. Recent accounts, filing behaviour, company age, group dependencies and material changes may alter the decision. The relevant depth depends on exposure. A low-value software supplier should not necessarily receive the same financial review as a critical manufacturer or a counterparty receiving large payments.
7. Preserve the evidence package
Store source name, source URL where permitted, retrieval timestamp, source-effective date, raw value, normalised value and the policy rule applied. Include unavailable fields and failed retrievals. This evidence package makes the decision reviewable and gives future monitoring a valid baseline.
Example KYB evidence coverage matrix
Illustrative caseCoverage should be visible by control. A single “passed” label would hide the partial ownership path and unresolved authority in this example.
Why ownership makes KYB verification difficult
Ownership work expands quickly because every corporate shareholder can open another branch. A simple company may have two individual owners. A complex group may involve holding companies, funds, nominees, cross-holdings and entities registered in several jurisdictions. The analyst is not merely collecting names; the analyst is testing whether the available chain is sufficient for the policy question.
Separate four concepts that are often collapsed:
- Direct ownership: the immediate shareholder recorded against the subject company.
- Indirect ownership: an interest held through one or more intermediary entities.
- Ultimate beneficial ownership: the natural person or persons who ultimately own or control the entity under the applicable test.
- Group relationship: the wider corporate family, including parents and subsidiaries that may matter even when they do not determine the UBO conclusion.
A defensible ownership investigation records the path, percentage where available, relationship type, source and effective date. It also states why tracing stopped. Valid stop reasons can include reaching a natural person, reaching a listed company covered by a policy exception, meeting the required threshold, encountering a restricted source or exhausting available evidence.
How ownership tracing workload can expand
Illustrative modelBranching can multiply the number of records that need resolution. Stopping rules keep the review proportionate without hiding an incomplete chain.
Design the KYB decision before automating the checks
Many KYB projects start with data fields and end with an unclear decision. Reverse that sequence. Define the permitted outcomes, the evidence required for each outcome and the exceptions that force human review.
A practical decision model uses three operational recommendations:
- Proceed: required identity, ownership and risk controls are complete within policy, with no finding that requires escalation.
- Review: the entity is sufficiently resolved to continue investigation, but a material mismatch, risk result or evidence gap requires a named reviewer.
- Hold: the workflow should not proceed because the entity cannot be resolved, a prohibited status or finding applies, or required evidence is unavailable under policy.
These recommendations should sit above separate control verdicts. A case might show “entity verified,” “ownership incomplete,” “screening clear on resolved subjects” and “evidence coverage partial.” The overall recommendation is Review, but the reviewer can immediately see why.
Do not let a high match score override a missing control. Confidence that two names refer to the same company says nothing about whether ownership has been resolved. Likewise, complete evidence does not mean low risk; it means the system successfully answered the required questions.
Example decision routing for a KYB case
Policy frameworkThe recommendation is reproducible because it follows visible evidence states and policy rules rather than an unexplained composite score.
KYB verification is a lifecycle, not an onboarding event
Approval captures a company at one point in time. The legal entity may later change status, replace directors, file new accounts, alter its ownership or move within a group. A risk-based review calendar is useful, but it leaves a blind period between scheduled checks.
Ongoing KYB combines event monitoring with periodic policy review. Event monitoring watches defined company facts and opens a case when a relevant change appears. Periodic review confirms that the relationship, risk tier, evidence requirements and unresolved questions remain appropriate. The two controls serve different purposes.
Good monitoring begins with the exact entity resolved during onboarding. Name-only lists create avoidable false matches. Store the jurisdiction and registration number, then connect monitoring events to the same internal customer, supplier or merchant ID.
Prioritise signals that can change identity, control or viability:
- company status, dissolution, restoration or insolvency-related events;
- direct and indirect ownership changes;
- director and officer appointments or resignations;
- new financial statements and material filing changes;
- registered name, address and identifier changes;
- new evidence gaps, source failures or conflicting records.
Route events by materiality. A punctuation correction should not share a queue with a dissolution filing. Ownership changes may trigger renewed screening; a new filing may trigger financial analysis; an address update may require only data maintenance. See the separate supplier monitoring guide for a detailed alert and review model.
A 30-day plan to improve KYB verification
Days 1–5: map decisions and failure modes
List every current outcome, the control owner and the evidence required. Review recent false positives, abandoned cases and approvals that could not be reconstructed. Identify where “no data” is being mistaken for “no risk.”
Days 6–10: define the canonical entity record
Choose the identifiers, raw source fields, normalised values and timestamps that every case must preserve. Separate trading names from legal names and internal IDs from external identifiers.
Days 11–15: encode ownership and evidence rules
Document thresholds, control tests, stopping reasons, acceptable source types and jurisdiction exceptions. Make partial ownership resolution visible rather than forcing a binary answer.
Days 16–20: build the review queue
Create separate routes for identity ambiguity, ownership gaps, risk findings and source failure. Assign owners and service levels. Design the case view around old value, new value, source and required decision.
Days 21–25: connect workflows
Use the CompanyDelta API for deterministic retrieval and webhooks for change delivery. Preserve raw evidence alongside workflow-ready fields rather than discarding provenance during integration.
Days 26–30: test against known hard cases
Use similar-name companies, inactive entities, multi-layer ownership, unavailable sources and conflicting applicant data. Measure match accuracy, evidence completeness, review rate, decision time and reopened cases before increasing automation.
Do not optimise only for straight-through approval. A KYB system that approves quickly but cannot explain its matches will fail procurement, audit and risk review. The enterprise objective is a lower cost per defensible decision—not merely a lower cost per API call.
KYB verification questions answered
What is KYB verification?
KYB verification identifies a business, matches it to an authoritative legal-entity record, examines required ownership and management information, applies relevant risk checks and records the evidence used for the decision.
What is the difference between KYB and KYC?
KYC focuses on an individual. KYB focuses on a legal entity and usually extends to the people who own, control or represent it. The two processes intersect when KYB requires identity checks on beneficial owners, directors or authorised representatives.
What information is needed for a KYB check?
A strong starting set is legal name, jurisdiction, registration number, registered address and the applicant’s relationship to the company. Ownership, director, filing and risk information can then be collected according to policy.
Is a company registration certificate enough for KYB?
No. It can support the evidence package, but it does not necessarily prove current status, current ownership or the authority of the person acting. Compare submitted documents with current authoritative records.
What is UBO verification?
UBO verification is the process of identifying and evidencing the natural person or persons who ultimately own or control a company under the applicable ownership and control tests.
How should unavailable registry data be handled?
Record it as an evidence gap with the source, time and reason. Apply a policy decision such as retry, request alternative evidence, send to review or hold. Do not convert an unavailable result into a negative finding.
How often should KYB be refreshed?
Use a combination of event-driven monitoring and risk-based periodic review. Higher-risk or higher-exposure relationships usually justify deeper monitoring, while the exact frequency depends on policy and applicable obligations.
Which KYB changes should trigger a review?
Typical triggers include company-status changes, ownership or director changes, new financial filings, insolvency-related events, identifier changes and material conflicts between applicant data and official records.
Can KYB verification be fully automated?
Deterministic retrieval, matching and low-risk rules can be automated. Ambiguous identity, incomplete ownership, conflicting evidence and material risk findings should enter a controlled human review path.
What should a KYB audit trail contain?
It should preserve submitted data, matched entity identifiers, source names, retrieval times, source-effective dates, raw and normalised values, ownership paths, screening subjects, exceptions, reviewer actions and the policy version used.
Make every company decision explainable.
Resolve the entity, preserve the evidence and monitor the facts that can make an approval stale.