What does KYB verification involve?
KYB establishes that a business exists, that it actually trades, and who ultimately owns it. Confirm the entity in the official registry, check it operates rather than merely being registered, identify every beneficial owner at the common 25% threshold plus one control person, verify each owner as a person, then screen all of them.
This guide is for compliance and onboarding teams at platforms that serve business customers: payment providers, marketplaces, B2B fintechs, and lenders. It walks the full KYB sequence, from registry lookup to beneficial-owner verification, with the decision points marked.
What KYB has to establish
Know Your Business answers four questions, in order of difficulty:
- Does this business legally exist?
- Is it actually operating, or a shell?
- Who really owns and controls it?
- Are any of those people or entities sanctioned, politically exposed, or otherwise outside your risk appetite?
Most fraud hides in questions 3 and 4. Registering a company is cheap and fast in most jurisdictions; the paperwork of a real business and the paperwork of a mule company look identical on day one. The owners behind it are the part that's hard to fake, which is why regulators keep tightening exactly there.
Step 1: Confirm the entity exists
- Pull the record from the official registry for the jurisdiction (state Secretary of State in the US, Companies House in the UK, and so on), not from a data aggregator alone. Aggregators lag; registries are the source
- Match legal name, registration number, formation date, and registered address against what the customer entered. Exact-match failures are usually typos; treat repeated "typos" as a signal
- Check status: active, dissolved, suspended, delinquent. A dissolved company applying for a merchant account is not confused, it's shopping
- Collect the tax identifier and validate its format (EIN, VAT number, or local equivalent)
Step 2: Check the business is real, not just registered
Existence is a filing; operation leaves traces. Score these signals rather than gating on any single one:
- Website, domain age, and whether the site matches the stated line of business
- A physical footprint consistent with the business type (a freight company at a residential mail drop deserves a question)
- Formation date versus claimed revenue. Registered last Tuesday and processing $2M a month is a story that needs evidence
- Industry codes and licenses for regulated verticals (money services, pharma, gambling all carry their own registries to check)
Step 3: Identify and verify the beneficial owners
This is the heart of KYB and the step fraudsters most rely on you skipping.
- Collect the ownership structure down to the natural persons. The common threshold is every individual owning or controlling 25% or more, plus one control person (CEO, CFO, or managing member). Your regulator or bank partner may set a lower threshold; use theirs.
- Flatten holding-company layers. Corporate shareholders get unwrapped until you reach humans. Three shell layers ending in the same person is a structure with a purpose, and the purpose is usually you.
- Verify each UBO as a person, not a name on a form. Government ID capture plus a live selfie for each beneficial owner, exactly as you'd verify a consumer. A KYB program that carefully diagrams ownership but never proves the people exist has verified an org chart, not a business.
- Cross-check against registries where they exist (PSC register in the UK, beneficial-ownership filings where local law provides access), and note discrepancies rather than silently preferring one source.
Step 4: Screen everyone you found
Run the entity and every verified UBO through screening:
- Sanctions lists: OFAC, UN, EU, UK as a floor, plus lists relevant to your corridors. Screen the company AND the owners; sanctioned individuals hide behind clean-named entities as a matter of technique
- PEP status on all UBOs and control persons: not prohibited, but it escalates due diligence
- Adverse media on entity and owners
- Your own graph: shared addresses, phones, bank accounts, or UBOs across "unrelated" applicants in your customer base. Fraud rings reuse infrastructure, and your own data is the one list only you can screen against
Step 5: Decide, document, and re-check
| Finding | Action |
|---|---|
| Everything verifies, no hits | Approve; set review cycle by risk tier |
| Ownership unclear or layered offshore | Request documents, escalate to enhanced due diligence, approve only with senior sign-off |
| Sanctions hit on entity or UBO | Hold, investigate, and take competent advice; a true match carries reporting obligations, not just a rejection |
| Operating signals weak | Approve with limits (volume caps, settlement delays) and an early review date, or decline |
Document each decision with the evidence you used. Then re-verify on triggers, not just calendars: ownership changes, unusual volume, new corridors, or a UBO turning up in fresh adverse media.
Keep the funnel alive
KYB fails commercially when every applicant waits days for manual review. The fix is the same shape as consumer onboarding: automate the registry pulls, the UBO identity checks, and the screening; spend the humans only on the exceptions. Applicants abandon slow onboarding, and the good ones have somewhere else to go. The bad ones, annoyingly, are patient.
For verifying the individual people behind the business, the same machinery applies as in how to integrate a KYC API; for the screening layer in depth, see how to run sanctions and PEP screening. Verifa's KYC/AML platform covers the UBO identity and screening steps through the same API, with all models in-house. For what the watchlists behind that screening contain, see AML screening explained.