Compliance

What is KYB?

KYB, short for Know Your Business, is the due diligence process used to confirm a business is a real, legally registered entity. It also identifies the individuals who ultimately own or control it. KYB is sometimes called corporate KYC. KYC verifies an individual. KYB verifies a legal entity first, then traces through its ownership to the humans behind it.

KYB applies whenever a regulated business onboards another business as a customer, vendor, or partner. Banks, payment platforms, and fintechs all run KYB before opening an account for a business customer.

What does KYB actually verify?

KYB checks three things. All three are required before a business relationship can proceed:

  • The entity itself: legal name, registration status, good standing, formation documents, and a tax identifier such as an EIN
  • Beneficial ownership: the individuals who ultimately own or control the business, traced through however many holding companies sit in between
  • Risk exposure: sanctions, politically exposed persons (PEP) status, and adverse media tied to the business or its owners

Ongoing monitoring is now standard practice, not a one-time check at onboarding.

What is a beneficial owner?

A beneficial owner is a natural person who ultimately owns or controls a business. Their name may never appear on the paperwork. Identifying them is the hardest part of KYB, especially when ownership runs through several holding companies. This concept sits at the center of FATF's global standards on beneficial ownership transparency, which most national frameworks are built to implement.

Thresholds vary by jurisdiction:

  • United States: 25% or more ownership under FinCEN's beneficial ownership rule, plus one individual with significant control regardless of ownership stake
  • European Union: Also 25% today. Regulation (EU) 2024/1624 (AMLR), applying from July 2027, adds a mechanism to lower this to 15% for specific high-risk categories, pending a Commission assessment due by 2029
  • Higher-risk scenarios generally: Lower thresholds and more scrutiny apply for shell companies and complex ownership chains

What is the difference between the CDD Rule and the Corporate Transparency Act?

This is the most confused part of US KYB. The two are not the same obligation.

FinCEN's Customer Due Diligence (CDD) Rule, codified at 31 CFR 1010.230, requires banks to identify and verify beneficial owners at onboarding. It sits on the institution. It has not changed.

The Corporate Transparency Act's BOI reporting requires businesses themselves to file ownership data with FinCEN. This regime went through real upheaval:

  • BOI reporting took effect January 1, 2024
  • A federal court blocked it nationwide on December 3, 2024 (Texas Top Cop Shop v. Garland)
  • The Supreme Court stayed that injunction on January 23, 2025, though enforcement stayed paused due to a separate nationwide order (Smith v. Treasury)
  • FinCEN's March 26, 2025 interim rule removed BOI reporting for US-formed entities entirely
  • FinCEN made that exemption permanent on August 11, 2026, effective August 14, and will delete previously submitted US-person data

BOI reporting now applies only to entities formed abroad and registered to do business in the US. This changes nothing for banks, though. The CDD Rule still applies. It applies regardless of a business's own BOI filing status.

How does KYB work outside the US?

Frameworks differ by region, but share a common foundation in FATF's Recommendations 24 and 25.

In the UK, the FCA sets KYB standards through its Financial Crime Guide. In the EU, current requirements run through the existing AML Directives, with AMLR tightening central ownership registers once it takes effect in 2027.

In February 2025, FATF updated its standards to balance thorough due diligence against financial inclusion, requiring countries to allow simplified due diligence in genuinely lower-risk cases.

What is the KYB process?

A typical KYB workflow runs through five steps:

  1. Verify the business is a real, registered legal entity in good standing
  2. Identify every beneficial owner above the relevant threshold, plus anyone with control
  3. Screen the business and its owners against sanctions lists, PEP databases, and adverse media
  4. Assign a risk score based on industry, geography, and ownership complexity
  5. Monitor on an ongoing basis, since ownership and risk change over time

Common red flags include unnecessarily complex ownership structures, high-risk jurisdictions, and beneficial owners appearing on sanctions or PEP lists.

Why KYB matters for payment platforms

For fintechs onboarding business customers, KYB is both a compliance requirement and a product experience. A process that is too slow drives legitimate businesses away. One that is too weak creates exposure to shell companies. Both put banking relationships and licenses at risk.

KYB sits alongside OFAC screening, KYC on individual users, and the broader compliance risk management framework a platform runs. For platforms under a money transmission license, robust KYB is one of the core controls regulators expect during an examination.

An identity verification API that handles both individual and business verification is increasingly the technical foundation for running KYC and KYB together.

How does Due handle KYB?

Due's Accounts API runs KYB as a submission-based flow: create a business account, then work through the requirements the API returns.

Due uses a parent and child applicant model. The company is the parent applicant, holding registration details and corporate documents. Individuals connected to it, such as shareholders and directors, are child applicants.

A typical submission requires:

  • Company information: legal name, registration number, tax ID, and registered address
  • Company documents: incorporation certificate, shareholder registry, and directors registry
  • A KYB questionnaire covering the business and its risk profile
  • Identity verification for each linked beneficial owner or director

Once every requirement is fulfilled, the submission moves to review. Due sends a webhook when the final decision lands, so the business account can be connected to wallets or payment methods as soon as it clears.

Continue learning

Meta transaction

Category
Read more

Gas fees

Category
Read more

Batch payments

Category
Read more

Wallet-as-a-Service (WaaS)

Category
Read more

Wallet screening

Category
Read more

KYT (Know Your Transaction)

Category
Read more

KYB (Know Your Business)

Category
Read more

Settlement finality

Category
Read more

Stablecoin redemption

Category
Read more

E-Money Token (EMT)

Category
Read more

MiCA

Category
Read more

Travel Rule

Category
Read more

CCTP (Cross-Chain Transfer Protocol)

Category
Read more

Stablecoin depeg

Category
Read more

FX risk (currency risk)

Category
Read more

Banking-as-a-Service (BaaS)

Category
Read more

ISO 20022

Category
Read more

Nostro and vostro accounts

Category
Read more

UETR (Unique End-to-End Transaction Reference)

Category
Read more

Stablecoin settlement

Category
Read more

Automatic reconciliation

Category
Read more

Balance reconciliation

Category
Read more

Identity verification API

Category
Read more

Interbank settlement

Category
Read more

Open banking

Category
Read more

FedGlobal ACH

Category
Read more

Ledger API

Category
Read more

Subsidiary ledger

Category
Read more

Cross-chain bridges

Category
Read more

Ledger sharding

Category
Read more

Reconciliation API

Category
Read more

ACH debit

Category
Read more

Ledger database

Category
Read more

Stablecoin reserves

Category
Read more

Transaction reconciliation

Category
Read more

Closed loop payments

Category
Read more

Open loop payments

Category
Read more

Stablecoin sandwich

Category
Read more

ACH reversal

Category
Read more

Layer 2 blockchain

Category
Read more

Layer 1 blockchain

Category
Read more

FedNow API

Category
Read more

eCheck

Category
Read more

Payment controls

Category
Read more

Faster Payment System (FPS)

Category
Read more

Request for payment (RfP)

Category
Read more

Stablecoin orchestration

Category
Read more

ACH API

Category
Read more

BACS

Category
Read more

ACH payment returns

Category
Read more

Stablecoin yield

Category
Read more

Cash float

Category
Read more

BAI2

Category
Read more

Compliance risk management

Category
Read more

ACH transfer limit

Category
Read more

Deposit Account Control Agreement (DACA)

Category
Read more

Currency Transaction Report (CTR)

Category
Read more

Crypto faucet

Category
Read more

FBO account

Category
Read more

OTC trading

Category
Read more

Virtual IBAN

Category
Read more

Third-party payment

Category
Read more

Ledger balance

Category
Read more

Issuer Identification Number (IIN)

Category
Read more

CASPs (Crypto-Assets Service Providers)

Category
Read more

Section 314(b)

Category
Read more

OFAC (Office of Foreign Assets Control)

Category
Read more

Penny test

Category
Read more

Cash pooling

Category
Read more

Money transmission

Category
Read more

Core banking

Category
Read more

Sweep account

Category
Read more

Flow of funds

Category
Read more

Cash application

Category
Read more

Bank Reconciliation

Category
Read more

Clearing account

Category
Read more

Cash reconciliation

Category
Read more

Take rate

Category
Read more

CHAPS (Clearing House Automated Payment System)

Category
Read more

The Clearing House (TCH)

Category
Read more

A2A payments

Category
Read more

Bulk Electronic Clearing System (BECS)

Category
Read more

Real-time gross settlement (RTGS)

Category
Read more

Same-day ACH

Category
Read more

ACH return codes

Category
Read more

PYUSD (PayPal USD)

Category
Read more

Sort Code

Category
Read more

Atomic settlement

Category
Read more

Payment orchestration

Category
Read more

T2

Category
Read more

Financial Crimes Enforcement Network (FinCEN)

Category
Read more

Unified Payments Interface (UPI)

Category
Read more

Programmable money

Category
Read more

QR code payments

Category
Read more

CHIPS (Clearing House Interbank Payments System)

Category
Read more

Nacha

Category
Read more

FedACH

Category
Read more

XRP (Ripple)

Category
Read more

EURC (Euro Coin)

Category
Read more

USDC (USD Coin)

Category
Read more
Download Due & Move Money Without Borders