Blog
KYB Requirements: A Practical Compliance Guide for 2026

KYB Requirements: A Practical Compliance Guide for 2026

Written by
Share this  
KYB Requirements: A Practical Compliance Guide for 2026

A Cayman foundation holding a Delaware C-Corp with a Swiss operating subsidiary applies for a fiat-to-stablecoin payments account. The applicant uploads incorporation certificates, a group chart, and identity documents, expecting a routine review. The bank pauses onboarding because the ownership chain stops at the foundation, the Swiss registry extract uses a different legal description, and no document clearly identifies who controls the treasury.

That is the practical reality of KYB requirements in cross-border finance. A checklist can tell you to collect formation documents and identify ultimate beneficial owners. It can't reconcile conflicting registries, explain a DAO's voting structure, or decide whether a founder with less than a quarter of the equity still controls the business.

The workable approach combines legal-entity verification, ownership analysis, control testing, jurisdiction-specific evidence, and monitoring after approval. The sections below focus on that operational layer, where most files either become defensible or fail review.

Table of Contents

  • Key KYB and AML Terms Defined
  • What KYB Really Means in a Cross-Border Business

    Know Your Business, or KYB, is the process of establishing that a legal entity exists, understanding how it operates, identifying who owns or controls it, and assessing the risk of maintaining a business relationship with it. Banks, payment institutions, exchanges, and other regulated providers use KYB before onboarding a company and during the relationship when relevant facts change.

    KYB isn't the same as KYC. KYC verifies people, including directors, beneficial owners, trustees, foundation council members, authorized signatories, and sometimes key controllers. KYB verifies the entity and its context. A company can pass an identity check for its director while still failing KYB because its ownership chain is incomplete or its stated activity doesn't explain the expected transactions.

    Practical rule: Treat the entity file and the people file as connected records, not as separate approval tracks.

    Cross-border evidence creates the difficulty. A Delaware certificate may confirm formation, while a Swiss extract describes the operating subsidiary, and a Cayman foundation document may identify a council without naming an economic owner. Each document can be authentic and still fail to answer the same question: who ultimately owns or controls the applicant?

    Reconcile evidence, don't just collect it

    Start with the applicant's legal name, registration number, legal form, registered office, directors, shareholders, and control persons. Compare those fields across the incorporation registry, shareholder records, constitutional documents, ownership chart, and submitted declarations. Differences need an explanation, not an automatic rejection and not a casual assumption that the documents are interchangeable.

    For teams setting up an account that combines payment rails and digital-asset activity, the practical workflow described in this guide to business fiat and crypto account setup is useful context. The important point is that account access depends on evidence that tells one coherent story across jurisdictions.

    The weakest files usually contain an old register, an unexplained intermediate holding company, or a translated document that hasn't been properly certified. Fix those gaps before escalating the application. A clean structure chart, supported by registry extracts and signed explanations, often resolves more uncertainty than another generic company certificate.

    The Global Standards That Shape KYB Today

    Modern KYB requirements come from several overlapping layers. FATF provides the international baseline, national and regional lawmakers turn that baseline into enforceable rules, and correspondent banks or payment partners often impose controls that are stricter than the minimum law in the applicant's home jurisdiction.

    FATF Recommendation 24 requires jurisdictions to make beneficial ownership information accurate, current, and accessible to competent authorities. FATF best-practice guidance also supports the use of company registries or separate beneficial ownership registers, risk-based enhanced due diligence for higher-risk legal persons, and ongoing monitoring. For cross-border platforms, the operational implication is clear: incorporation evidence alone isn't enough. The reviewer needs an ownership and control chain that can be checked and refreshed. FATF's beneficial ownership guidance sets out that direction.

    The EU approach

    The EU made beneficial ownership transparency a core part of KYB-style due diligence through Directive (EU) 2015/849. Directive (EU) 2018/843 reinforced the framework, and Regulation (EU) 2024/1624 further tightened it by requiring beneficial ownership information to be retained for five years and reported to central registers. The European Commission's overview of beneficial ownership rules also shows why cross-border operators can't assume that a mature regulatory market offers uniform evidence. At the time of the Commission's 2024 assessment, 23 Member States didn't require collection of beneficial ownership information for foreign legal entities.

    The EU model therefore combines stronger transparency expectations with uneven availability. A reviewer may need to obtain private corporate records or certified declarations when a public or central source doesn't cover the foreign entity.

    The U.S. overlay

    In the United States, the Bank Secrecy Act and FinCEN rules sit alongside the Corporate Transparency Act. The CTA created a national beneficial ownership reporting regime for many companies, and reporting companies existing before 2024 were required to report beneficial ownership information to FinCEN by January 1, 2025. That changed the onboarding question from “Is this company registered?” to “Who owns or controls it, and does the answer align with the filing and the account application?” The KYB guide covering the U.S. regime and global practice provides the relevant background.

    FATF sets the floor. The EU and U.S. translate it into different filing, registry, and verification workflows. Providers outside those regions often adopt the same controls because banks and payment partners expect comparable evidence.

    For teams documenting transaction controls and customer reviews, AML and KYC procedures are closely connected to the KYB file. A business review that ignores sanctions screening, record retention, and ongoing risk assessment is incomplete even if the incorporation documents are genuine.

    Core Documents and Data Points You Will Be Asked For

    A strong KYB file isn't a document dump. Each item should answer a defined verification question, and the reviewer should know what to do when two items disagree.

    Establish that the entity exists

    Request the certificate of incorporation or equivalent constitutive record, the current registry extract, and proof of registered address. The formation record establishes legal existence. The current extract tests whether the entity remains registered and identifies the legal name, registration number, status, directors, and sometimes shareholders. Address evidence helps distinguish a maintained registered office from an operational location that the applicant hasn't disclosed.

    Articles of association, bylaws, partnership agreements, foundation statutes, and similar constitutional documents reveal powers that a shareholder register may miss. Look for special voting rights, appointment powers, veto rights, trustee or council authority, and provisions that allow someone to control decisions without holding the largest equity position.

    Build the ownership and activity record

    The shareholder register feeds the beneficial ownership analysis, but it shouldn't be treated as conclusive where ownership runs through other entities. Ask for records for every intermediate company, trust, foundation, or nominee arrangement until the natural persons exercising ownership or control are identified. A signed structure chart can organize the file, but it can't replace source evidence.

    Tax identification numbers, recent bank references, audited financial statements where available, and management accounts help confirm that the applicant's financial profile matches its stated business. The business description should explain products, customers, operating markets, expected payment flows, use of digital assets, and the source of funds. That narrative determines whether standard checks are enough or whether enhanced due diligence is needed.

    • Formation evidence: Confirm legal existence and the entity's registered particulars.
    • Ownership records: Trace direct and indirect interests through every relevant layer.
    • Constitutional documents: Test control rights that equity records don't show.
    • Address and tax evidence: Reconcile registration, residence, and operating footprint.
    • Financial information: Compare expected activity with the entity's commercial profile.
    • Source-of-funds narrative: Explain where account inflows originate and why the payment pattern makes sense.

    Applicants operating in the Gulf often face additional documentary expectations, so a practical resource on opening a UAE corporate bank account in 2026 can help teams prepare evidence before approaching a provider.

    Common weak points include outdated certificates, missing intermediate entities, inconsistent names after transliteration, and translations that aren't certified or apostilled when the receiving institution requires that standard. Ask the provider what it accepts before commissioning documents. A notarized copy may not satisfy an apostille requirement, and a registry PDF may not prove current status if the source doesn't provide live updates.

    Beneficial Ownership and the 25 Percent Control Test

    The practical benchmark in many KYB workflows is 25% direct or indirect ownership or control. Canada defines a beneficial owner as an individual who directly or indirectly owns or controls at least 25% of a corporation or other entity, while FATF-aligned and U.S. and EU practices commonly pair the ownership test with a separate control-person test. FINTRAC's beneficial ownership guidance explains the Canadian threshold and the information expected for each beneficial owner.

    Start at the applicant. Record each direct shareholder and calculate the individual's effective interest through intermediate entities. If Individual A owns all of Holding Co., and Holding Co. owns 30% of Target Co., Individual A reaches the target through indirect ownership. The same analysis applies through multiple corporate layers, although the evidence becomes more difficult when registries are private, stale, or inconsistent.

    A flowchart explaining the process of identifying beneficial ownership through FATF and FinCEN compliance guidelines.

    Control is wider than share ownership

    A person can control an entity without crossing the equity threshold. Review board appointment rights, voting agreements, financing arrangements, reserved matters, power to appoint senior officers, trustee or foundation council authority, and practical influence over treasury or strategic decisions. A founder holding less than 25% may still be the control person if the governance documents and operating reality place key decisions in that founder's hands.

    Typical resolving evidence includes:

    • A notarized ownership declaration: Useful when a private registry doesn't expose the full chain.
    • A dated structure chart: Helpful when it lists every entity, percentage, and control relationship.
    • Constitutional documents: Necessary to test voting, appointment, and veto rights.
    • Trust or foundation records: Needed to identify settlors, protectors, trustees, council members, or equivalent controllers.
    • Tax residency disclosure: Useful for reconciling identity, residence, and reporting inconsistencies.

    Bearer shares, nominee shareholders, and layered BVI or Cayman structures create a higher evidentiary burden. A nominee declaration may identify the underlying owner, but it must be assessed alongside the nominee agreement, shareholder records, and control rights. If no natural person can be identified through ownership, the institution normally needs to identify the person exercising control through another means and document why the conclusion is reasonable.

    The threshold isn't a shortcut. It is a decision point that tells the reviewer where to look. The final file should explain both who qualifies through ownership and who qualifies through control, including the evidence used and unresolved limitations.

    Jurisdictional Variations You Need to Plan Around

    The same applicant can produce different acceptable evidence depending on where it was formed, where it operates, and where the account provider is regulated. The legal question may be similar, but the operator's workflow changes with registry access, certification rules, disclosure forms, and tax documentation.

    JurisdictionUBO ThresholdRegistry TypeUBO Directive FormDoc StandardNotes
    United States25% ownership or control benchmarkState and federal sourcesFinCEN BOI where applicableCertified or official records as requestedReconcile state formation evidence with federal beneficial ownership reporting
    European Union25% benchmark commonly used in practiceNational company and beneficial ownership registersNational and EU AML disclosuresCertified copies, translations, or apostilles may be requestedForeign legal entities can face uneven beneficial ownership data availability
    United Kingdom25% PSC benchmark commonly usedCompanies House and related filingsPSC filingOfficial extracts and certified evidence where requestedCompare PSC information with shareholder and control documents
    Cayman IslandsRisk-based ownership and control reviewRegistry and regulated-sector recordsApplicable beneficial ownership reportingNotarized or certified records may be requestedFoundation and exempted-company structures need careful controller mapping
    BVIRisk-based ownership and control reviewRegistry and regulated-sector recordsApplicable beneficial ownership reportingCertified or notarized evidence may be requestedPrivate registry access can create timing and reconciliation friction
    PanamaRisk-based ownership and control reviewPublic and private corporate recordsLocal disclosure requirementsNotarized, legalized, or apostilled records may be requestedNominee arrangements require underlying-owner evidence
    Singapore25% benchmark commonly used in practiceACRA and related registersACRA beneficial ownership recordsCertified records and residence evidence may be requestedConfirm registered controller information against group documents
    UAERisk-based ownership and control reviewFederal and emirate-level sourcesLocal UBO and licensing disclosuresAttested or legalized documents may be requestedAlign licensing, economic activity, address, and ownership evidence
    SwitzerlandRisk-based ownership and control reviewCantonal and commercial registersIntermediary or institution-specific declarationsCertified records and translations may be requestedVereins and operating structures need member and controller reconciliation
    LiechtensteinRisk-based ownership and control reviewCommercial register and private recordsLocal beneficial ownership disclosuresCertified, notarized, or legalized evidence may be requestedAnstalt structures require careful analysis of governing rights

    A single apostilled formation certificate may support several reviews, but it won't replace a jurisdiction-specific UBO declaration or proof of tax residence. A GLEIF record can help validate a Legal Entity Identifier and group relationship, while a PDF-only registry may require manual review of issue dates and signatures. Don't assume that a document accepted by one bank will satisfy another.

    Where operators lose time

    A Cayman foundation may need a good-standing record and council documentation. A UAE company may need its license, operating address, and economic activity reconciled. A Swiss Verein may require a member list that matches its governance documents. An older Liechtenstein structure may require a focused review of historical share or control arrangements.

    Build an evidence matrix before submission. Mark each field as confirmed, pending, contradictory, or not applicable. That simple classification prevents the common mistake of sending another document without explaining which unresolved question it answers.

    Realistic KYB Timelines From Application to Approval

    Approval time depends less on the number of uploaded files than on whether those files support one consistent ownership and activity story. A straightforward domestic entity can move quickly. An offshore group with several intermediate companies, private registries, foreign-language records, and crypto-related activity needs more preparation.

    The review phases

    A practical planning model looks like this:

    1. Document collection: Gather formation records, current extracts, ownership evidence, identity documents, financial information, and the business narrative. Straightforward files may take 1 to 5 business days, while offshore structures can take 2 to 6 weeks, depending on certification and registry access.
    2. Registry and corporate verification: Pull official records, compare legal particulars, and resolve status or director differences. This may take 1 to 10 days.
    3. UBO identification and identity verification: Trace each ownership layer and complete identity checks for relevant owners and controllers. Allow 3 to 15 days per layer where evidence is fragmented.
    4. Enhanced due diligence: Review source of funds, source of wealth, adverse media, sanctions exposure, licensing, and transaction rationale. This can take 5 to 20 days for complex or higher-risk files.
    5. Final approval and setup: A clean approval may require 1 to 3 days for final controls and account configuration.

    The ranges above are operational planning estimates, not a promise from a particular provider.

    An infographic showing the five stages and realistic business day timelines for the KYB onboarding process.

    Delays you can prevent

    Missing good-standing certificates, untranslated documents, and indirect chains that require notarized declarations cause avoidable rework. Adverse media linked to an intermediate holding company can also expand the review beyond the applicant itself. Fiat accounts for offshore or crypto-native entities often receive additional questions about counterparties, wallet activity, licensing, and treasury controls.

    Front-load apostille or legalization work. Prepare the structure chart before the application opens, and submit UBO identity documents in parallel rather than waiting for each corporate layer to clear. A clear explanation of the expected payment flow also reduces back-and-forth with the reviewer.

    KYB for Web3 Entities, DAOs, and Crypto-Native Companies

    Traditional KYB assumes a company has shareholders, directors, a registered office, and a clear legal personality. Web3 applicants often split those functions across a foundation, a protocol community, a multisig wallet, a service company, and a group of delegates. The reviewer must identify the legal applicant first, then map the operational and governance layer around it.

    A DAO without legal personality may not be an acceptable account holder in its own name. A foundation wrapper may become the KYB subject, with its council members, authorized representatives, and treasury controllers undergoing individual checks. A multisig is not proof of identity. A block explorer can show wallet activity and transaction history, but it doesn't establish who controls a key unless the signers provide reliable off-chain evidence.

    Evidence that changes the risk decision

    For a BVI foundation holding a DAO treasury, request foundation formation and good-standing records, council details, signatory authority, the multisig address, signer identities, threshold configuration, and governance rules. For an unaudited DeFi protocol seeking a banking partner, focus on the legal contracting entity, developer and administrator roles, treasury controls, protocol revenue, smart-contract audit history where available, and the explanation for expected fiat flows. For a stablecoin issuer operating across jurisdictions, map each issuing, reserve-holding, technology, and distribution entity rather than treating the group as a single applicant.

    Useful evidence includes:

    • Multisig attestations: Identify every signer, the signing threshold, appointment authority, and replacement process.
    • Governance records: Review token voting, delegates, timelocks, emergency powers, and treasury proposals.
    • Wallet attribution: Connect treasury addresses to the legal entity through signed declarations and transaction rationale.
    • Source-of-funds material: Explain token issuance, protocol revenue, investor funding, grants, or treasury transfers.
    • Sanctions and transaction screening: Screen relevant people, entities, and wallet exposure, while recognizing the limits of address-only attribution.
    Structure TypeLegal KYB SubjectKey Evidence RequiredCommon Failure Point
    Foundation wrapperFoundation and relevant controllersCharter, council records, good standing, authorized signersTreating the foundation as self-explanatory while ignoring council control
    DAO without legal personalityAccepted legal wrapper or responsible operating entityGovernance rules, delegates, treasury controls, signersNo identifiable contracting party or accountable controller
    Multisig treasuryLegal entity controlling the walletSigner IDs, threshold evidence, wallet attribution, authorization recordAssuming wallet ownership proves individual identity
    DeFi protocol companyOperating or service companyFormation records, governance map, revenue and treasury explanationUnaudited activity narrative that doesn't explain fiat flows
    Stablecoin groupIssuer and related operational entitiesEntity map, licensing, reserve structure, signers, counterpartiesCombining separate regulated and unregulated activities into one file

    For organizations that need business accounts and payment workflows spanning fiat and digital assets, OneSafe's services for DAOs illustrate the type of operational context a provider may need to understand. The key is still evidence, not the label “web3.”

    From One-Time Onboarding to Perpetual KYB

    A company doesn't become low risk merely because its onboarding file was complete on approval day. Directors resign, shareholders transfer interests, foundations change council members, businesses enter new markets, and treasury wallets interact with new counterparties. Perpetual KYB treats those events as reasons to reassess the relationship.

    The monitoring model should match the entity's risk. A lower-risk domestic business may receive automated re-checks on a scheduled cycle, while a higher-risk web3 entity or an entity linked to a higher-risk jurisdiction may require immediate review after a material event. There isn't one universal refresh schedule that fits every customer segment.

    Define the triggers before they occur

    Useful monitoring sources include corporate registry changes, beneficial ownership register differences, sanctions updates, regulatory action lists, adverse media, licensing changes, and unusual movements from a declared on-chain treasury. The point isn't to collect every possible alert. It is to identify signals that change the entity's ownership, control, legal status, activity, or risk profile.

    Treat these events as material change triggers:

    • Governance change: A new director, foundation council member, trustee, authorized signatory, or multisig signer.
    • Ownership change: A share transfer, capital restructure, new holding company, nominee arrangement, or trust amendment.
    • Operational change: A new jurisdiction, product, customer segment, licensing status, or payment corridor.
    • Risk event: A sanctions match, regulatory action, credible adverse media, or unexplained treasury movement.

    A diagram illustrating the four-step process for perpetual KYB, transitioning from initial onboarding to continuous monitoring and reassessment.

    When a trigger fires, record the alert, the information reviewed, the updated risk assessment, the decision to refresh or close the case, and any customer explanation. Tell customers at onboarding which changes they must report. That makes later requests easier to justify and reduces the chance that a legitimate change looks like concealment.

    Quick Reference Checklist for Operators

    Use this checklist as a working control sheet, not as a substitute for judgment. Mark each item complete only when the evidence supports the conclusion and the source is recorded.

    Entity verification

    • Legal existence: Confirm the formation record, legal form, registration number, and current status.
    • Registered address: Match the official address with the application and operating explanation.
    • Constitutional powers: Review articles, bylaws, partnership terms, foundation statutes, and appointment rights.
    • Licensing: Confirm relevant permits or regulatory permissions where the activity requires them.

    Beneficial ownership

    • 25% ownership test: Identify direct and indirect individuals at or above the applicable benchmark.
    • Control-person test: Identify people exercising substantial control even without the relevant equity stake.
    • Intermediate layers: Obtain evidence for holding companies, trusts, foundations, and nominees.
    • Identity fields: Collect and verify the core identity information for each relevant owner and controller.

    Jurisdiction and web3 overlays

    • Local filings: Check applicable FinCEN, EU, UK, Singapore, Cayman, or other local records.
    • Certification: Confirm whether documents need notarization, certification, legalization, apostille, or translation.
    • Governance: Map foundation councils, DAO delegates, multisig signers, timelocks, and treasury authority.
    • Risk prompts: Ask whether the entity is regulated, holds client funds, operates in a high-risk jurisdiction, or touches sanctioned corridors.

    Ongoing controls

    • Monitoring sources: Configure registry, sanctions, regulatory, adverse media, and relevant wallet alerts.
    • Trigger decisions: Define what ownership, governance, activity, or risk change requires reassessment.
    • Audit trail: Record evidence, reviewer reasoning, customer communications, and the final decision.

    A quick reference checklist for operators detailing essential KYB procedures including entity verification, beneficial ownership, screening, and ongoing compliance.

    Key KYB and AML Terms Defined

    • KYB: Verification of a business's legal identity, ownership, control, activity, and risk.
    • KYC: Identity verification for natural persons connected to the relationship.
    • CDD: Baseline customer due diligence applied to establish identity, ownership, purpose, and risk.
    • EDD: Additional investigation layered on CDD for higher-risk entities, people, activities, or jurisdictions.
    • UBO: The ultimate beneficial owner, meaning the natural person who ultimately owns or controls the entity.
    • Beneficial owner: A person identified through ownership or control, including indirect interests.
    • Control-person test: The assessment of who exercises substantial control regardless of equity ownership.
    • PEP: A politically exposed person whose public role can require enhanced risk assessment.
    • Adverse media: Relevant negative reporting that may indicate financial crime, misconduct, or regulatory risk.
    • Source of funds: The origin of the money used in a particular transaction or account flow.
    • Source of wealth: How a person's or entity's overall wealth was accumulated.
    • Ongoing monitoring: Continued screening and review after onboarding.
    • Perpetual KYB: Event-driven maintenance of the business relationship's KYB record.
    • Risk-based approach: Applying verification depth and monitoring intensity according to the actual risk, rather than using one identical checklist for every customer.

    EDD sits on top of CDD. It doesn't replace basic identity, entity, or ownership verification.

    Frequently Asked Operational Questions

    What if a UBO uses a nominee in a jurisdiction with limited registry access?

    Don't treat the nominee as the final answer. Obtain the nominee agreement or declaration, shareholder records, identity evidence for the underlying owner, and a signed explanation of voting and economic rights. If the documents conflict, pause approval or escalate for enhanced review rather than relying on a registry that doesn't disclose the full arrangement.

    What if a multisig signer refuses individual identification?

    The wallet can remain operational on-chain, but the account provider still needs to understand who can authorize funds. Ask whether the signer has a formal role, whether the threshold can be met without them, and whether the remaining signers provide sufficient control evidence. If a required signer won't complete KYC, the provider may be unable to establish a defensible control map.

    What should you do when a Cayman or BVI registry response is delayed?

    Use available official formation and good-standing records, request the applicant's certified corporate package, and document the registry limitation. Temporary reliance on alternative evidence is a risk decision, not an automatic right to proceed. Don't represent an unverified status as confirmed, and set a clear follow-up condition before activation or continued access.

    Is the 25% threshold cumulative across layered entities?

    Calculate indirect ownership through each layer. An individual can qualify even when they don't appear directly on the applicant's shareholder register. Separately assess control rights, because a person may qualify through governance or decision-making authority without reaching the ownership benchmark.

    A defensible KYB file answers three questions: what the entity is, who owns or controls it, and whether its activity matches the risk accepted by the provider. If your current process relies on document collection without reconciliation and trigger-based refreshes, review the workflow before the next complex application arrives. OneSafe provides multi-currency business accounts, global payment workflows, corporate cards, and crypto-compatible account functionality for eligible companies and web3 organizations, with KYB and stakeholder verification built into onboarding. Visit OneSafe to assess whether its fiat and digital-asset account infrastructure fits your cross-border operating model.

    category
    Last updated
    September 18, 2026

    Get started with Bank accounts in minutes!

    Get started with Bank accounts effortlessly. OneSafe brings together your crypto and banking needs in one simple, powerful platform.

    Start today
    Subscribe to our newsletter
    Get the best and latest news and feature releases delivered directly in your inbox
    You can unsubscribe at any time. Privacy Policy
    Thank you! Your submission has been received!
    Oops! Something went wrong while submitting the form.
    Open your account in
    10 minutes or less

    Begin your journey with OneSafe today. Quick, effortless, and secure, our streamlined process ensures your account is set up and ready to go, hassle-free

    No monthly subscription
    Simple and easy onboarding
    Unlimited transactions