Skip to content
Risk And Compliance 13 min read

KYB vs KYC: Why Business Verification Differs for Payment Operators

How KYB's beneficial ownership complexity, UBO screening requirements, and orchestration tooling differ from KYC — and what that means for embedded.

PB
By Shaun Toh
Last updated: August 26, 2026
TL;DR

KYB is structurally harder than KYC because beneficial ownership structures involve nested legal entities, offshore vehicles, and PEP screening across the full UBO tree — not just a name and ID number check.

Every operator onboarding businesses onto a payment platform or embedded finance product faces the same uncomfortable truth at the intersection of risk and compliance: KYB (Know Your Business) is not KYC (Know Your Customer) with a few extra fields. It is a structurally harder problem that requires different tooling, different risk logic, and different organizational investment. Platforms that treat KYB as an extension of consumer identity verification — collecting a business registration number and calling it done — routinely discover this the hard way when they surface in a regulatory exam or absorb a wave of synthetic business fraud.

The global AML compliance market now exceeds $25 billion annually, with a meaningful portion driven by the accelerating demand for automated KYB solutions as embedded finance expands the population of entities that need to be verified. Getting the framework right is both a regulatory requirement and a competitive differentiator: faster, more accurate KYB directly determines onboarding conversion for B2B products.

KYB vs KYC infographic: KYC verifies an individual (ID, address, sanctions and PEP screening); KYB verifies a business across a five-layer stack — business identity, ownership and beneficial-owner (UBO) resolution through nested entities and offshore vehicles, risk and sanctions screening, and ongoing monitoring — plus KYB risk tiers, common operator mistakes, the tooling layer, and an operator checklist.
Why KYB is structurally harder than KYC: the five-layer verification stack, risk tiers, where operators get it wrong, and the tooling layer.

Why KYB Is Structurally Harder Than KYC

Consumer identity verification has a relatively clean data model. An individual has a name, a date of birth, a government-issued ID, and a set of authoritative registry sources (credit bureaus, DMV records, passport databases) that can confirm identity with high confidence in most developed markets. Fraud vectors exist — synthetic identities, document forgery — but the verification problem is bounded.

Business verification has no equivalent simplicity. A legal entity may exist in multiple jurisdictions simultaneously. Its beneficial ownership structure may include holding companies, trusts, and offshore vehicles deliberately structured to obscure ultimate ownership. The controlling persons — beneficial owners identified through an equity or voting threshold that is itself regime-specific, detailed below — may themselves be entities rather than individuals, requiring recursive unwinding of the corporate tree. Nominee directors are common in certain jurisdictions. Shelf companies purchased for legitimate tax purposes are indistinguishable at registration from shells purchased for fraud.

The Beneficial Ownership Register problem is central. FATF's Recommendation 24 requires countries to maintain accurate and current beneficial ownership information, but implementation quality varies enormously. The UK's Companies House register is reasonably accurate and publicly searchable. The Delaware Division of Corporations famously allows anonymous LLCs with no public beneficial ownership disclosure — a feature, not a bug, for its largest customers. Many offshore jurisdictions (Cayman Islands, BVI, Panama) maintain beneficial ownership registers only for regulatory use, not public access. This means automated lookup against government registers is high-confidence in some markets and close to useless in others.

PEP (Politically Exposed Person) screening adds another layer of complexity for KYB that doesn't exist for typical retail KYC. When a business has a UBO (Ultimate Beneficial Owner) who is a foreign government official, their family member, or a close associate, enhanced due diligence obligations apply — and the relationship between the PEP and the business may be several ownership layers removed. First-degree PEP screening on individual customers is relatively tractable. PEP screening on the full beneficial ownership tree of a corporate entity with international shareholders is significantly more involved.

UBO Thresholds and the Control Prong: US, EU, UK

"25% is the beneficial-ownership threshold" is the shorthand every operator repeats, but the underlying rule differs by regime, and none of the three major frameworks defines beneficial ownership as a single number.

United States. FinCEN's Customer Due Diligence Rule (31 CFR 1010.230) defines a beneficial owner as either of two people, not one. Under the equity prong: "each individual, if any, who, directly or indirectly, through any contract, arrangement, understanding, relationship or otherwise, owns 25 percent or more of the equity interests of a legal entity customer." Under the control prong: "a single individual with significant responsibility to control, manage, or direct" the entity — the rule names an executive officer or senior manager such as a CEO, CFO, COO, managing member, general partner, president, vice president, or treasurer, or "any other individual who regularly performs similar functions." A covered institution must identify and verify at least one control-prong individual on every legal-entity customer, regardless of whether anyone clears the 25% line.

European Union. The AMLD framework (Directive (EU) 2015/849, Article 3(6)) treats ownership as an evidentiary indicator rather than a bright-line legal test: "a shareholding of 25% plus one share or an ownership interest of more than 25% ... shall be an indication of direct ownership" — one factor pointing toward beneficial ownership, alongside indirect ownership through corporate structures and control exercised by other means (governance agreements, dominant influence, appointment rights). Member states retain discretion to set a lower percentage domestically.

United Kingdom. The Companies Act 2006 (Schedule 1A) defines a person with significant control (PSC) through five alternative conditions, and only the first two involve a percentage at all: holding, directly or indirectly, more than 25% of the shares; holding more than 25% of the voting rights; holding the right to appoint or remove a majority of the board of directors; having the right to exercise, or actually exercising, significant influence or control; or — the fifth condition, and the one that reaches nested trusts and unincorporated firms rather than companies — where the trustees of a trust, or the members of a firm that is not itself a legal person, meet any of the other four conditions (or would if they were individuals), and X has the right to exercise, or actually exercises, significant influence or control over that trust's or firm's activities. Meeting any single condition is sufficient — a shareholder at 10% who nonetheless controls board appointments is a PSC under the third condition even though no percentage test is met, and someone who controls a trust or unincorporated firm that itself meets any of the first four conditions is a PSC under the fifth without ever appearing on a share register.

The practical read for an operator building or buying a KYB flow: three regimes, three different legal instruments (a Treasury rule, an EU directive, and a UK statute), and three different structures — one with an explicit second prong for control, one that treats the percentage as an indicator rather than a rule, and one that runs five independent tests where a percentage satisfies only two of them. A form that asks only "who owns 25%+ of this business" and stops there fails the US control prong, understates the EU's indirect-ownership reach, and misses every UK PSC captured only through board-appointment rights or "significant influence."

Why an entity with no 25%+ owner still needs a named individual

The US control prong — and the UK's board-appointment and significant-influence conditions — exist because plenty of legitimate businesses have no natural person who clears an ownership threshold at all: private-equity-owned portfolio companies where the fund itself, not a person, is majority shareholder; employee-owned cooperatives; widely-held partnerships. None of that removes the underwriting obligation — someone still has to be the accountable natural person on file. This is where automated onboarding flows built around a single ownership-percentage field genuinely stall: the flow has nowhere to put "no one owns 25%, but the CFO runs the company," and the application either gets rejected for incomplete ownership data or routed to manual review specifically to capture the control-prong individual by hand.

What gets collected, and why layered structures stall onboarding

In practice, a KYB file above the lightest tier collects: the certificate of incorporation or formation; a register of members, share ledger, or equivalent ownership record; an organisational chart tracing ownership through each intermediate entity to the natural persons at the top; government-issued ID and proof of address for every identified beneficial owner and the control-prong individual; and, at the enhanced tier, source-of-funds documentation. Each of those is a fresh registry lookup or a fresh document request, and every additional layer of intermediate ownership multiplies the number of lookups required before the chain resolves to a natural person.

Layered structures stall onboarding for a specific mechanical reason, not a vague "complexity" one: automated registry lookups only work where the intermediate jurisdiction actually publishes ownership data. A UK-incorporated subsidiary resolves cleanly through Companies House. The moment the chain passes through a Delaware LLC (no public beneficial-ownership disclosure) or a Cayman, BVI, or Panama entity (ownership registers held for regulatory access only, not public lookup), the automated chain breaks and the analyst is back to requesting documents directly from the applicant — the same jurisdictions already flagged in the Beneficial Ownership Register problem above are precisely where chain-resolution stalls in production KYB systems.

FATF Recommendations vs Market Practice

FATF's corporate structure transparency recommendations have been incorporated into law across most FATF member jurisdictions, but the gap between formal legal requirements and actual market practice remains substantial.

The EU's 6th Anti-Money Laundering Directive (6AMLD, implemented in 2021) and its successor, the Anti-Money Laundering Authority Regulation (AMLA), establish the legal framework for beneficial ownership disclosure and UBO register accuracy across EU member states. The AMLA — headquartered in Frankfurt — began operations on July 1, 2025, with the EBA completing its AML/CFT mandate transfer to AMLA in January 2026 (EU Council, February 2024; Federal Ministry of Finance Germany, July 2025). AMLA will directly supervise 40 large, high-risk cross-border financial institutions from January 2028. For payment operators with significant EU business volumes, AMLA compliance will require documented beneficial ownership verification procedures, risk appetite frameworks, and data retention policies that meet the new regulatory standards.

In practice, most payment operators today apply a risk-tiered approach that varies significantly from the full FATF ideal:

  • Tier 1 (Light due diligence): Sole traders, micro-businesses, businesses in low-risk categories. Typically: business registration verification, control person identity check, sanctions screening. Automated, takes minutes.
  • Tier 2 (Standard due diligence): SMEs in standard risk categories. Business registration + financial statements or bank statements + beneficial ownership declaration + PEP/sanctions screening on UBOs. May involve document upload; typically 1-3 days with automated review.
  • Tier 3 (Enhanced due diligence): High-value merchants, regulated businesses, complex corporate structures, high-risk geographies. Full beneficial ownership tree mapping, source of funds documentation, site visit or video call, ongoing transaction monitoring with elevated thresholds. Days to weeks; often involves human analysts.

What actually drives a risk tier

Tier assignment is not just "high volume equals high risk." The OCC's Comptroller's Handbook on merchant processing — the examination guidance US acquiring banks are assessed against — sets out the underwriting parameters examiners expect to see, and reserve practice sits directly on top of them. Baseline underwriting must confirm the merchant is correctly classified under a merchant category code, and ongoing exception monitoring runs against parameters that commonly include large average ticket size, large daily or weekly sales volume, and high chargeback activity, checked against the merchant's own application estimates for volume and average ticket size.

Two of those drivers change what happens next, not just the tier label:

  • Chargeback history. OCC guidance tells examiners that a bank should reject a merchant with a history of substantial chargeback volume at the initial review stage, not merely tier it upward.
  • Future or delayed delivery. The same handbook defines this as "sales transactions on products or services that are delivered in the future" — its own examples are airline tickets, concert tickets, and travel/tour packages — and ties it directly to reserve sizing: "holdback reserves are also used to limit a bank's credit risk when the merchant's product or service involves future/delayed delivery."

Cross-border exposure — jurisdiction risk on the merchant, its directors, and its UBOs — is covered in depth in sanctions screening for payment operators rather than re-derived here. At the prohibited end of the spectrum, OCC's own definition of a high-risk merchant account names businesses "specially regulated by the United States (such as gambling or gaming services or tobacco products)" alongside those with historically high refund/chargeback rates or elevated bankruptcy risk.

The forward-delivery problem

Long fulfilment lag is a common surprise for a first-time merchant, and the mechanism is structural rather than punitive: dispute clocks for undelivered-goods claims are generally understood to run from around the delivery or service date rather than the original payment date. Practically, that means a merchant taking payment today for a package delivered in 90 days can be carrying well over 90 days of unfulfilled obligation on top of the standard dispute window before the acquirer's exposure on that transaction even begins to run down.

Stripe's own reserve guidance for connected accounts describes exactly this mechanic in its underwriting language: reserve sizing depends on an account's exposure, defined as "its unfulfilled volume that's subject to refunds and disputes," and Stripe names "whether its industry commonly has extended delivery times" — citing event ticketing, travel and lodging, and made-to-order goods such as furniture — as a factor that raises reserve risk, alongside a worked example of "a large transaction with an unusually long delivery time" that needs a hold released only when its return window closes. The operator implication: a business with a long fulfilment lag should expect a reserve sized and timed to its delivery window — not to the standard dispute-window average — as a structural feature of onboarding into that category, not a penalty for a weak application. How that reserve is later adjusted, escalated, or released as the merchant relationship continues is covered in ongoing merchant monitoring and offboarding.

Corporate and commercial card programmes run the same tiering on the businesses they issue cards to, not just on marketplace sellers — a programme manager onboarding a company onto a fleet or expense-card product is doing KYB on that company before a single card gets produced, a step that sits upstream of the day-to-day mechanics covered in issuing programme operations.

The problem with this tiering in practice is that tier assignment is often based on surface indicators (business type, stated volume) that sophisticated bad actors know to optimize around. A fraudulent marketplace claiming $50K monthly volume (Tier 1) that rapidly scales to $500K before chargeback exposure surfaces — and subsequent chargeback representment cycles — is a pattern that automated tiering without velocity check triggers consistently misses.

The Orchestration Layer: Middesk, Alloy, and ComplyAdvantage

The tooling for KYB has matured significantly since 2020, with a set of specialized vendors now providing API-first access to the data sources and decisioning logic that operators need.

Middesk has emerged as the standard for US business identity verification. Its core product aggregates Secretary of State filings, IRS EIN verification, business credit data, and address validation into a single API call that returns a structured risk assessment. For US-focused operators, Middesk covers the majority of standard KYB data needs without requiring direct integrations to 50 separate state databases. The platform's watchlist screening and beneficial ownership modules extend into the full KYB surface.

Alloy operates as an identity orchestration layer — rather than being a data source itself, it connects to 200+ data providers (including Middesk, LexisNexis, Socure, and dozens of document verification vendors) and applies configurable decisioning workflows on top. For operators that need to handle both KYC and KYB within a unified policy engine, and particularly those operating across multiple jurisdictions with different data sources, Alloy's orchestration model avoids the fragmentation of managing separate vendor relationships per market.

ComplyAdvantage and its peers (Dow Jones Risk & Compliance, Refinitiv World-Check) provide the ongoing screening infrastructure — PEP lists, sanctions lists, adverse media — that needs to be applied both at onboarding and on an ongoing basis as lists update. ComplyAdvantage differentiates on its own-built media screening engine, which captures adverse media (negative news about businesses and their principals) faster than pure list-based approaches. For KYB specifically, ongoing monitoring is as important as onboarding screening: a business that was clean at onboarding may have a UBO who became a PEP, faced regulatory action, or appeared in adverse media six months later.

How Stripe and Adyen Handle KYB at Scale

The embedded finance platforms have had to solve KYB at a scale that makes manual review processes economically unviable. Stripe's approach for Stripe Connect (which underpins thousands of B2B marketplaces and platform businesses) and Adyen's marketplace and platform products both reflect years of iteration on automated KYB at volume.

Stripe's identity verification layer for Connect uses a combination of automated document verification, database checks, and a risk-tiered review queue where human analysts handle exceptions. Stripe applies its network data advantage — transaction patterns across its merchant base — to identify behavioral signals that supplement the identity data. A new sub-merchant whose transaction velocity, category mix, and geographic distribution match known fraud patterns will be flagged regardless of how clean their documentation looks — a signal detection approach that mirrors techniques covered in AI fraud detection in 2026. The company has also progressively automated more of the beneficial ownership collection process, using pre-fill from database sources to reduce the documentation burden on legitimate businesses.

Adyen's KYB for platform businesses is more explicitly tiered by expected volume and risk category, reflecting its focus on larger enterprise clients versus Stripe's SME-heavy mix. Adyen applies a stricter upfront due diligence standard, with slower onboarding times compensated by lower ongoing monitoring overhead for businesses that clear the initial bar. For the marketplaces Adyen serves — often large European platforms with established legal entities — this tradeoff is appropriate.

Both approaches share a common insight: the goal of automated KYB is not to eliminate human review, but to make human review economically sustainable by reserving it for the cases where it creates genuine value. A fully manual KYB process can support tens of thousands of merchants per year. An automated system with human exception handling can support millions, at a cost structure that makes embedded finance business models viable.

The EU AMLA framework — now operational since July 2025, with full direct supervision beginning in 2028 — will raise the documentation and procedural bar for EU-regulated operators, but the fundamental competitive dynamic in KYB tooling — faster, more accurate, more automated — will only accelerate as regulatory requirements make basic compliance table stakes and operators compete on how far above the floor they can get. Platforms that invest in data-quality ownership verification today, rather than minimum-viable KYB, will find that their fraud rates and regulatory exposure diverge significantly from those that don't over the next three years.

Sources & methodology (6)

FinCEN's Customer Due Diligence Rule defines a beneficial owner under two prongs: the equity prong (each individual owning 25% or more of the entity's equity interests) and the control prong (a single individual with significant responsibility to control, manage, or direct the entity, such as a CEO, CFO, COO, managing member, general partner, president, vice president, or treasurer, or any other individual who regularly performs similar functions)

Checked:

Article 3(6) of the EU's 4th Anti-Money Laundering Directive (2015/849) treats a shareholding of 25% plus one share, or an ownership interest of more than 25%, held by a natural person as an indication of direct ownership — an evidentiary indicator rather than the legal test itself, which also reaches indirect ownership and control exercised by other means

Checked:

The UK's Companies Act 2006 (Schedule 1A) defines a person with significant control (PSC) through five specified conditions, only the first two of which involve a percentage: holding more than 25% of shares; holding more than 25% of voting rights; holding the right to appoint or remove a majority of the board of directors; having the right to exercise, or actually exercising, significant influence or control; and a fifth condition reaching trusts and unincorporated firms — where the trustees of a trust, or the members of a firm that is not a legal person under the law governing it, meet any of the other four conditions (or would if they were individuals), and X has the right to exercise, or actually exercises, significant influence or control over that trust's or firm's activities. Any one condition is sufficient to establish PSC status.

Checked:

OCC's Comptroller's Handbook (Merchant Processing) requires baseline underwriting to confirm the merchant is properly classified under a merchant category code, and describes exception-monitoring parameters that commonly include large average ticket size, large daily/weekly volume, and high chargeback activity; guidance also tells examiners a bank should reject a merchant with a history of substantial chargeback volume at initial review

Checked:

OCC's Comptroller's Handbook defines "future or delayed delivery" as sales transactions on products or services delivered in the future (examples given: airline tickets, concert tickets, travel/tour packages) and states that holdback reserves are used to limit a bank's credit risk when the merchant's product or service involves future/delayed delivery; its high-risk merchant account definition separately names businesses specially regulated in the US, such as gambling/gaming services or tobacco products

Same source as above, appendix/glossary and risk-mitigation sections.

Checked:

Stripe's connected-account reserve guidance defines account risk in terms of "exposure" — its unfulfilled volume subject to refunds and disputes — and names "whether its industry commonly has extended delivery times or high loss rates (for example, event ticketing, travel & lodging, furniture or construction)" as a factor affecting reserve risk, with a worked scenario for "a large transaction with an unusually long delivery time" held until its return window closes

Checked:

Source types explained in our Methodology.

Shaun Toh By Shaun Toh · Director, Digital Payments · Razer

More Risk And Compliance briefings