The ordered, practical process to verify a business you are about to onboard, transact with, or partner with, including the documents needed, where the data comes from, and where it goes wrong.
Verifying a business (KYB, or know your business) is a seven-step process: collect and confirm the entity's core identity, verify it against authoritative registries, map its ownership and control structure, identify and verify the ultimate beneficial owners, screen the business and the people behind it, risk-assess the relationship and trigger enhanced due diligence where needed, then monitor it continuously. The company checks are the easy half. Tracing ownership up through holding companies, trusts, and cross-border layers is the hard part, and it is why KYB routinely takes far longer than verifying an individual.
KYB, short for know your business, is the process of confirming that a business customer, supplier, or partner is real, legally registered, and who it says it is, then identifying the people who own and control it and checking that none of them are sanctioned, high risk, or hidden. It is the corporate counterpart to KYC (know your customer): where KYC verifies an individual, KYB verifies a legal entity and then runs KYC on the humans behind it. For the definition and how the two compare, see what is KYB.
KYB answers four questions in sequence: does this business legally exist, who owns and controls it, are any of those parties a financial-crime risk, and how risky is the relationship overall. It is required by the same anti-money-laundering frameworks that require KYC. Globally the standard-setter is the Financial Action Task Force (FATF): Recommendation 10 sets customer due diligence for legal persons, and Recommendations 24 and 25 govern transparency of beneficial ownership of legal persons and legal arrangements.
This is the ordered process. Steps 1 to 2 establish the entity. Steps 3 to 4 establish the people. Steps 5 to 6 assess risk. Step 7 keeps it true over time. Most competitor guides stop at a six-step product flow and fold ownership and screening into single bullets. The value here is treating ownership discovery, UBO verification, and ongoing review as distinct, non-trivial steps.
Gather the entity's foundational identity data and confirm internal consistency before checking any external source. The core fields are the legal name (and any trading or doing-business-as names), the registration or company number, the jurisdiction of incorporation, the incorporation date, the registered address (and principal place of business, which is often different), the legal form (limited company, LLC, partnership, sole trader, trust, or foundation), and the current status (active, dormant, dissolved, in liquidation, or struck off).
Confirm the step 1 data against official company registries. The mechanism is the same everywhere; the data quality is not. The honest takeaway to teach is that a registry match confirms a company was registered, not that its filed data is true. Treat the registry as a starting point, then corroborate with independent data (financials, web and operational footprint, licences) and, where the regime now allows, the verified identity of the people behind it.
Map the corporate tree before hunting individuals. Pull the shareholder register and the register of directors and officers, then diagram how ownership flows upward: direct shareholders, intermediate holding companies, parents, and any trusts or foundations in the chain. Identify who the directors, officers, and senior managers are, because control is not only about equity. This map is what turns "who owns 25 per cent" from a lookup into an actual calculation, because ownership through a chain has to be multiplied through each layer.
The UBO is the natural person who ultimately owns or controls the business. This is the step that defines KYB and the step competitors treat most thinly. For the full detail, see ultimate beneficial ownership.
Under the US CDD Rule, a covered financial institution must identify each individual who directly or indirectly owns 25 per cent or more of the equity (the ownership prong) and one individual with significant responsibility to control the entity (the control prong). The EU AML Regulation harmonises a 25 per cent threshold, and FATF frames 25 per cent as a common line rather than an absolute one. Some jurisdictions and higher-risk cases use lower triggers, as low as 10 to 20 per cent in places such as Singapore and Hong Kong. State it plainly: 25 per cent is the common threshold, not a universal law, and firms should go below it on a risk-sensitive basis.
Both prongs are required. A person can be a UBO through control (senior management, a nominee arrangement, or a shareholder agreement) even with no qualifying equity. Where ownership runs through holding companies, you multiply the percentages through each layer to find who crosses the threshold at the top. Nominee directors and shareholders act as stand-ins for the true owner, and trusts separate legal ownership from beneficial interest, so the registered names are not the beneficial owners.
In the EU, the Court of Justice struck down general public access to beneficial-ownership registers in November 2022 on privacy grounds; AMLD6 restored access on a legitimate-interest basis, but transposition is uneven and the European Commission opened infringement proceedings against 11 member states in 2025. In the US, FinCEN issued an interim final rule in March 2025 exempting US-formed entities from beneficial-ownership reporting, leaving only foreign reporting companies in scope. Both positions are fast-moving and worth re-checking at the point of use.
Run screening against the entity and every person identified in steps 3 and 4. Sanctions screening covers both the business and its owners and controllers against OFAC, UK OFSI, the EU consolidated list, UN, and other relevant lists, because a sanctioned UBO can taint an otherwise clean-looking company. PEP screening covers politically exposed persons among the UBOs, directors, and officers, applying enhanced due diligence where a match is a true match. Add adverse-media checks on the entity and the individuals, and any watchlist, enforcement, or debarment lists relevant to the sector.
The point competitors under-make is that screening the company alone is not enough. The ownership work in step 4 exists so that screening reaches the humans, which is where sanctions and PEP exposure actually sits.
Apply a risk-based approach, scoring the relationship on FATF's four risk dimensions: customer, country, product or service, and delivery channel. Practical factors that raise risk include incorporation or operation in a high-risk or FATF grey or black-listed country or a secrecy jurisdiction; a cash-intensive, high-value-goods, crypto, gambling, or money-services industry; structural complexity such as many layers, cross-border chains, trusts, or nominee arrangements; and shell-company red flags such as no physical premises or employees, minimal online presence, a registered-agent-only address, or activity inconsistent with the stated business.
Where risk is high, enhanced due diligence (EDD) is triggered: source-of-funds and source-of-wealth checks on UBOs, deeper ownership verification, financial statements, senior management sign-off, and more frequent review. Low-risk cases may qualify for simplified due diligence with documented reasoning.
One-off KYB decays. Directors change, ownership is restructured, a UBO becomes sanctioned, a company is struck off, and adverse media appears. A verification that was accurate at onboarding can be wrong within weeks, which is why regulators and vendors are moving from periodic reviews to continuous, event-driven monitoring, the perpetual-KYC pattern applied to businesses. Build re-screening and registry-change monitoring so a material change re-opens the case automatically, and keep an audit trail of every check and decision, because one-time verification is no longer treated as sufficient. Record retention is typically a minimum of five years after the relationship ends.
KYB providers commonly request the following at onboarding. The company documents establish the entity; the individual documents support UBO and director verification. Financial statements are usually requested only where enhanced due diligence applies.
Most KYB failures are not exotic. They come from trusting a registry too much, stopping at the company, or treating verification as a one-off.
Manual KYB is slow and repetitive because the same data is re-checked across disconnected systems. Independent estimates put a manual business verification at more than two weeks, and full corporate or SME onboarding commonly at 90 to 120 days, driven largely by ownership tracing. Automation compresses this by pulling registries, resolving ownership graphs, and running screening in parallel. Vendor case studies claim large reductions, but those are self-reported single-customer figures and should be read as such, not as industry norms.
The seven steps are the same everywhere, but the pressure points differ by sector.
Regulation sits behind KYB rather than being the focus of the process. Keep it light and follow the glossary and UBO pages for depth. The 2025 to 2026 items below moved recently and are worth re-checking at the point of use.
Globally, FATF Recommendation 10 sets customer due diligence for legal persons, and Recommendations 24 and 25 govern beneficial-ownership transparency for legal persons and arrangements. In the US, the BSA and USA PATRIOT Act CDD Rule still require banks to identify legal-entity beneficial owners under the 25 per cent ownership prong and the control prong, while the Corporate Transparency Act's separate BOI reporting rule was cut back in March 2025 so that US-formed entities are exempt and only foreign reporting companies file. In the EU, the AML Regulation (EU) 2024/1624 applies from 10 July 2027 with a harmonised 25 per cent threshold, AMLD6 governs register access on a legitimate-interest basis, and the AML Authority (AMLA) is standing up. In the UK, the Money Laundering Regulations 2017 set the CDD duty, and the Economic Crime and Corporate Transparency Act 2023 is adding mandatory identity verification at Companies House, phased in from November 2025.
The seven steps depend on different data providers: a registry source per jurisdiction, a UBO and ownership data provider, one or more screening providers, and a monitoring feed. Most teams stitch these together themselves. The average financial institution uses 4.7 verification providers, and most compliance teams stitch together 6 to 8 disconnected tools. Zenoo is an orchestration platform: it connects the providers you choose behind one integration, one policy engine, and one audit trail, so the seven steps run as one workflow instead of seven manual handoffs. See the KYB use case and the vendor marketplace.
Where Zenoo genuinely helps, framed as Zenoo's own measured figures: for steps 1 to 4, the KYB Researcher agent compiles a 50-plus-field company dossier in under 60 seconds versus 2 to 4 hours manually, and the full KYB pipeline runs registry lookup, ownership graphing, and UBO discovery end to end in under 30 minutes versus 3 to 5 business days, discovering 2 to 4 times more persons by cross-referencing multiple sources. For step 5, Zenoo routes sanctions, PEP, and adverse-media checks to your chosen providers with failover and runs them in parallel, with alert pre-classification dispositioning up to 80 per cent of alerts and cutting per-alert time from 20 to 45 minutes to 2 to 3 minutes. For step 6, the Policy Parser turns a written KYB policy into structured risk rules in under 5 minutes, and a 209-country risk database with 16 indicators per country supports the risk assessment and EDD triggers. For step 7, continuous re-screening plus one immutable audit trail (32 event types across 8 categories) gives examiners a single evidence record across every provider.
Zenoo does not itself hold a company registry, publish a sanctions or PEP list, or verify a passport; those come from the providers it orchestrates. If your underlying registry or ownership data is thin, or a jurisdiction's beneficial-ownership register is closed, Zenoo cannot invent the data. It does not make you compliant on its own; it helps you execute and evidence the process a human still signs off. See KYB orchestration for how this works in practice.
Zenoo orchestrates your registry, UBO, and screening providers so the seven steps run behind one integration, one policy engine, and one audit trail, instead of seven manual handoffs. AI agents handle UBO discovery and continuous monitoring, and every check lands in a single evidence record. Your providers plus Zenoo.