Know Your Business: Why Verifying a Company Is Harder Than Verifying a Person

Know Your Business: Why Verifying a Company Is Harder Than Verifying a Person

Verifying a person takes seconds because a person has a face, a government identifier, and a device, and all three can be checked against each other in one pass. Verifying a company takes days because a company has none of those things. Its identity is a scatter of filings across registries that share no schema, its name is not unique, its address is frequently a service provider's office, and the thing regulators actually want to know is not about the company at all. They want the humans at the end of a control chain that the company itself has no obligation to make legible. That structural difference, rather than any deficiency in vendor tooling, is why business onboarding remains the slowest step in commercial financial services while consumer onboarding became a solved product. This piece covers why the problem is genuinely harder, what beneficial ownership requires in plain language, the data-source reality that determines cost, the policy churn that moved the ground under every vendor recently, and what good onboarding looks like when it is tiered by risk instead of applied uniformly.

Two ownership tests

Key Takeaways

  • A company has no biometric. Consumer verification anchors to a physical person who can be matched against a document and a live face. Corporate identity is a set of assertions in registries, which means verification is document and data reconciliation rather than a match.
  • The regulatory target is the human, not the entity. Beneficial ownership rules exist because the entity is the thing being used to obscure the person, and a chain through two or three holding companies defeats most automated resolution.
  • Data quality is the binding constraint. Company registries range from clean machine-readable APIs to scanned PDF images, jurisdiction by jurisdiction, and no amount of vendor engineering removes the gap where the underlying record is a photograph of a form.
  • Screening false positives define the workload. Sanctions and watchlist screening on business names generates far more alerts than hits, and the cost of a KYB program is mostly the human review of alerts that turn out to be nothing.
  • The ground moved recently and in both directions. US beneficial ownership reporting was narrowed sharply in 2025 to exclude domestic companies, while EU public register access was curtailed by a 2022 court ruling, so vendor data coverage today is not what a program designed two years ago assumed.
Where the cost is

Why the Problem Is Structurally Harder

Know Your Business is the process of verifying that a business entity exists, that it is what it claims to be, that the person opening the account is authorized to act for it, and that the humans who ultimately own or control it are identified and screened. Four questions, where consumer onboarding asks roughly one and a half.

The asymmetry has three sources.

No biometric anchor. Consumer verification works because a passport photograph, a live selfie, and a liveness check resolve to one physical person with high confidence. The techniques are mature, described in KYC and identity verification, and they have no corporate equivalent. A company cannot appear. It can only be described by documents, and documents are what fraud produces most easily.

No single authoritative record. A person has one government identity in their country of residence. A company may be incorporated in one jurisdiction, operate in a second, hold a tax identifier in a third, and trade under names registered in none of them. Each register holds a fragment, uses its own identifiers and formats, and has no obligation to reconcile with any other. The organization verifying the company must assemble a coherent picture from sources that were never designed to be joined.

The entity is frequently the obfuscation. This is the part that makes automation hard in principle rather than in practice. Corporate structures exist for legitimate reasons, including liability separation, tax planning, and investor arrangements, and the same structures serve concealment. A regulator asking who ultimately owns this company is asking a question the structure may have been built specifically to make expensive to answer.

Dimension KYC, verifying a person KYB, verifying a company
Identity anchor Government document plus biometric liveness Registry filings, incorporation documents, and no biometric at any point
Authoritative source One national identity system Many registries, differing per jurisdiction, with no common schema
Uniqueness Identifier is unique by construction Names are not unique; similar names across jurisdictions are routine
The real subject The person in front of you The humans behind a control chain, who are not present
Typical completion Seconds, largely automated Hours to days, with human review on a meaningful share
Failure mode Impersonation of one person A legitimate-looking structure concealing a sanctioned or criminal party
The operational lever

Beneficial Ownership, Plainly

A beneficial owner is the natural person who ultimately owns or controls a company, regardless of how many corporate layers sit in between. The definition deliberately ends at a human being, because the entire purpose of the requirement is to prevent the chain from terminating at another company.

Two tests are applied, and both matter.

The ownership test is a threshold, commonly twenty-five percent of shares or voting rights, applied by tracing through intermediate entities. A person holding forty percent of a holding company that holds eighty percent of the operating company holds thirty-two percent of the operating company and is therefore in scope.

The control test catches everyone the arithmetic misses. A person may exercise control through board appointment rights, veto powers, contractual arrangements, or informal but real influence, without holding shares at all. This test exists precisely because ownership thresholds are trivially engineered around by distributing holdings just below the line.

Three practical difficulties follow.

Chains defeat automation quickly. A single layer is usually resolvable from registry data. Two layers, particularly crossing jurisdictions, frequently require pulling filings from a register that does not expose ownership, and the trail goes to manual research or to asking the customer and accepting their attestation with corroboration.

Nominee and trust structures break the model. A nominee shareholder appears in the register while holding shares for someone else, and a trust separates legal from beneficial ownership by design. The register is accurate and does not answer the question.

Self-attestation is the fallback, and it is weak. Where registry data will not resolve the chain, the practical approach is asking the customer to declare their beneficial owners and corroborating what can be corroborated. It is the standard approach and it is an attestation, which is why the screening and monitoring layers carry as much weight as they do.

The Data-Source Reality

The gap between a vendor demonstration and production performance is almost entirely a data-coverage story.

Registry quality varies enormously. Some jurisdictions publish clean, free, machine-readable company data with ownership information included. Others publish a searchable web interface with no programmatic access. Others hold records as scanned images of paper forms, sometimes requiring an in-person or postal request for anything beyond a name confirmation. A vendor covering two hundred jurisdictions covers them at radically different depths, and the useful diligence question is not how many jurisdictions are covered but what is retrievable in the specific ones that matter to the business, and whether ownership data is among it.

Screening generates far more alerts than hits. Sanctions and watchlist screening against business names produces a high volume of potential matches, because company names are short, repetitive, frequently transliterated, and often contain common words. A name like a generic trading company with a common geographic term will match many entries. Each alert requires a human disposition, and the volume of alerts rather than the volume of genuine hits determines the operating cost of the program. Tuning matching thresholds is the central operational lever: loosen and analysts drown, tighten and genuine matches are missed. This sits inside the wider financial crime obligations described in anti-money laundering for executives.

Adverse media is where cost hides. Screening against negative news is expected by regulators for higher-risk relationships and is the least automatable component. Search results are noisy, name ambiguity is worse than in sanctions screening because there is no structured list, relevance requires judgment about whether an allegation is material and current, and coverage in languages other than English varies. Programs that budget for sanctions screening and then discover adverse media review consuming most analyst time are encountering the normal outcome.

The Ground Moved Recently

Two regulatory shifts changed what data exists, and both ran counter to the direction the industry had been planning for.

United States. The Corporate Transparency Act required companies to report beneficial ownership information to FinCEN, with the reporting regime beginning in 2024. After litigation and a period of shifting enforcement positions, an interim final rule issued in March 2025 narrowed the requirement substantially, exempting domestic reporting companies and US persons, so that the obligation now falls principally on foreign entities registered to do business in the United States. The registry also remains non-public, accessible to authorities and, under conditions, to financial institutions with customer consent. The practical consequence is that the comprehensive US ownership database many programs expected to lean on does not exist in the form anticipated.

European Union. A November 2022 Court of Justice ruling invalidated the provision of the anti-money laundering directive that gave the general public access to beneficial ownership registers, on privacy grounds. Member states restricted access in response, and subsequent legislation has worked to restore access for those with a legitimate interest, including obliged entities and journalists, rather than for the public at large. Access for regulated firms conducting due diligence generally persists, and the open-data availability that some vendors had built on does not.

The executive reading is not alarm. It is that any vendor coverage claim or program design predating these changes should be re-verified against what is actually retrievable now, because both shifts reduced automated availability rather than expanding it.

What Good Onboarding Looks Like

Tier by risk rather than verifying everyone to the same depth

Uniform depth is the most common design error. It makes low-risk onboarding needlessly slow, which costs conversion, while giving high-risk cases no additional scrutiny, which is the actual compliance exposure.

Tier Typical profile Verification depth Target time
Low Domestic, simple structure, established trading history, low-risk sector, single layer of ownership Automated registry match, automated ownership resolution, sanctions screening, no document capture Minutes, straight through
Medium Domestic with moderate complexity, or a lower-risk foreign jurisdiction, two ownership layers Registry verification plus targeted document capture, authorized signatory check, screening with analyst disposition of alerts Hours to one day
High Complex or cross-border structure, higher-risk jurisdiction or sector, nominee or trust arrangements, politically exposed persons in the chain Full documentary verification, manual ownership tracing, adverse media, source of funds enquiry, senior sign-off Days, with a defined escalation path

The tiering criteria should be written, applied consistently, and reviewable, because a regulator will ask how the tier was assigned far more often than it will ask why a particular document was accepted.

Treat document capture as a fallback, not a default

Asking a customer to upload incorporation documents, ownership charts, and proof of address is the highest-friction step available and the most common cause of abandoned applications. It should trigger when automated resolution fails or when the risk tier requires corroboration, not as the standard opening move. The design goal is that low-risk customers never see it.

Monitor perpetually instead of refreshing annually

Company control changes without notice. A director resigns, shares transfer, a new owner appears, a sanctions designation lands, litigation begins. An annual refresh means the average customer record is roughly six months stale.

Perpetual monitoring means the screening runs against the existing customer base continuously, registry changes on record entities trigger a review, and a material change moves the customer to a higher tier automatically. This is also the design that regulators increasingly expect, and it is cheaper than annual refresh campaigns because it spreads the work rather than concentrating it. The tooling patterns for automating this class of ongoing obligation are covered in RegTech and compliance automation.

Distinguish it from merchant underwriting

KYB and merchant underwriting examine the same company and answer different questions, and conflating them produces both duplicated work and gaps. KYB asks whether the entity is legitimate, correctly identified, and free of prohibited connections, driven by regulatory obligation. Underwriting asks whether this business will generate losses through chargebacks, fraud, or failure to deliver, driven by commercial risk appetite, using the processing and financial signals detailed in merchant underwriting. A company can pass one and fail the other in either direction, and the decisions should be recorded separately even when the data collection is shared.

Frequently Asked Questions

What is the difference between KYC and KYB?

KYC verifies an individual, anchored to a government document and a biometric check that resolves to one physical person in seconds. KYB verifies a business entity, which has no biometric, no single authoritative record, and a name that is not unique. KYB additionally requires identifying the natural persons who ultimately own or control the entity, and verifying that the individual opening the account is authorized to act for it, which is why it takes hours or days rather than seconds.

What is a UBO and how is one identified?

An ultimate beneficial owner is the natural person who ultimately owns or controls a company through any number of intermediate entities. Two tests apply: an ownership test, commonly a twenty-five percent threshold of shares or voting rights traced through the chain, and a control test covering board appointment rights, veto powers, and contractual influence for people who hold no shares. Identification combines registry data, customer-provided ownership structure, and corroborating documents, with self-attestation as the fallback where registry data cannot resolve the chain.

Why does business onboarding take days when consumer onboarding takes seconds?

Because the verification is data reconciliation rather than a match. There is no biometric to check against, company records live in registries that differ by jurisdiction in format, depth, and accessibility, company names are not unique, and the ownership chain must be traced to human beings who are not present. Add sanctions and adverse media screening that produce many more alerts than genuine matches, each needing human disposition, and the days are mostly waiting on registry retrieval and analyst review.

Do beneficial ownership registries make KYB automatic?

No, and recent changes moved further from that. The US requirement was narrowed substantially in 2025 to apply principally to foreign entities registered to do business there, and the registry is not public. EU public access was invalidated by a 2022 court ruling, with access since restored for obliged entities and others with a legitimate interest rather than for everyone. Registries remain a valuable input where accessible, and coverage, depth, and access rights vary enough that programs still need document capture and attestation paths.

How should verification depth be decided?

By written risk tiering applied consistently, not uniformly across all customers. Low-risk profiles, meaning domestic entities with simple structures and established trading history, should complete automatically in minutes with no document upload. High-risk profiles, meaning complex cross-border structures, higher-risk jurisdictions or sectors, nominee arrangements, or politically exposed persons in the ownership chain, warrant full documentary verification, manual ownership tracing, adverse media screening, and senior sign-off. Regulators ask how a tier was assigned more often than they question an individual document.

The Bottom Line

The instinct to treat business verification as consumer verification with more fields is what produces onboarding that is simultaneously slow and weak. It is slow because every applicant is pushed through document capture designed for the hardest cases, and weak because the hardest cases receive the same treatment as a domestic sole-shareholder company with ten years of filings.

The programs that work invert this. They resolve the straightforward majority automatically and in minutes, using registry data and screening with tuned thresholds, and they concentrate analyst time on the structures that genuinely require judgment: chains crossing several jurisdictions, nominee and trust arrangements, and any structure whose complexity exceeds what the business plausibly needs. That last signal is the one experienced reviewers weight most heavily, and no automated check produces it. A three-layer holding structure across two offshore jurisdictions for a company with modest local revenue is not a data problem to be resolved. It is the finding.