Guide·Aug 13, 2026·9 min read

KYB Verification: What It Checks, What It Cannot, and Where It Belongs

What KYB verification actually checks, how it differs from KYC, what it cannot prove, and how to buy business verification software that changes the decision rather than filling a portal.

KYB verification is a check on the company, not on the person

KYB verification, short for know your business, is the process of confirming that a company is real, currently registered, and controlled by the people who say they control it. It answers four questions before you commit to an entity: does this company exist as claimed, who actually owns and directs it, is it in good standing, and is there anything on public record that should change your answer.

That last question carries most of the value. A perfectly registered company can still be carrying an unsatisfied judgment, a winding-up petition, an enforcement notice, a security interest over the assets you were about to lend against, or a beneficial owner on a sanctions list under a different spelling. None of that is on a certificate of incorporation. All of it changes the decision.

The problem shows up anywhere a complex operational process decides something about a company: a lender approving business credit, a bank onboarding a business account, an insurer writing a commercial risk, a buyer approving a supplier, a freight team taking on an unfamiliar counterparty, an HR team engaging a contracting entity rather than a person. The problem is identical across all of them, and so is the failure mode. The check gets run, the answer lands somewhere nobody decides from, and the decision gets made anyway. We build Floowed, the decision platform, so we will be explicit about where we sit and where we do not.

KYB vs KYC: one verifies a company, the other verifies a person

This is the most-searched confusion in the category, and it is simpler than the acronyms suggest. KYC verifies a natural person: is this individual real, are they who they claim to be, are they present. The evidence is an identity document, a biometric check, a bureau or telco match. KYB verifies a legal entity: does this company exist, is it active, who owns it, who directs it, what is on its record. The evidence is registry data, filings, court and insolvency records, and the documents the entity submits.

They are not alternatives. KYB contains KYC: a company is ultimately a set of people, and the point of resolving beneficial ownership is to arrive at natural persons you can screen individually. Skip that step and you have confirmed a structure exists without asking who benefits from it.

KYCKYB
SubjectA natural personA legal entity
Core questionAre you who you say you are?Does this company exist, and who is behind it?
Primary sourcesIdentity documents, biometrics, bureau and telco recordsCompany registries, filings, courts, insolvency and security registers
Typical failureStolen or synthetic identityShell structure, nominee ownership, undisclosed control
RelationshipA step inside KYB, run on each owner and directorThe wrapper that tells you which people to run KYC on

For the individual side, see our guides to KYC document automation and PEP screening.

What a complete KYB check covers

KYB verification is not one lookup. It is a set of independent checks against different sources, and the value is in the combination.

Registration and legal existence. The registry is the anchor: legal name, registration number, incorporation date, entity type, registered address, status, filing history. ACRA in Singapore, Companies House in the UK, the equivalent elsewhere. The most common finding is not fraud. It is a real company no longer in good standing, or a trading name with no registered entity behind it.

Beneficial ownership, past the registered agent. The part that separates a real check from a formality. Entities routinely present a corporate shareholder, a holding company, a nominee director or a formation agent as their visible layer, so resolving ownership means walking that structure to natural persons. Where a jurisdiction publishes an ownership register you check against it. Where it does not, you reconstruct the chain from shareholding filings and test the entity's declaration against what the registry shows. A mismatch between declared and filed control is one of the highest-value findings here.

Directors and officers. Who is legally empowered to bind the company, and whether the person who signed what you are relying on appears on the filings at all.

Standing and solvency. Court records and judgments, insolvency and bankruptcy registers, winding-up filings. A judgment is public, dated and directly relevant, and routinely missed, because it lives in a different system from the registry.

Regulatory filings and licence status. Whether the entity holds the licence its business model requires. Claiming a regulated activity without the licence to perform it is not a grey area.

Collateral and security registers. UCC filings in the US, the PPSR in Australia and New Zealand, charge registers elsewhere. Who already holds a security interest over the assets, which matters directly if you are lending against them.

Sanctions, PEP lists and adverse media. Screened against the entity and every natural person the ownership walk produced, plus the signal that surfaces in reporting before it reaches a register. Regulators move slowly. Journalists do not.

That is where our Business Verification agent looks, and we should be precise about what it means. We do not own registry data and we are not a KYB data vendor. We reach those sources through integrations, resolve the entity against them, and land what comes back inside the decision. That last part is the whole point.

What KYB verification cannot tell you

This is where evaluations go wrong, and where every vendor in the category, ours included, has an incentive to be vague.

A registry record is a filing, not a fact. Registries record what somebody submitted, they do not audit it, and filing obligations are usually annual. "Confirmed against the registry" means the filing says this, not that it is true today. Nor does a clean record prove the business trades: a dormant, correctly registered shell passes with nothing to flag. Evidence of real operations comes from elsewhere, from bank activity, tax filings, contracts and a verifiable address.

Ownership coverage is uneven. Beneficial-ownership transparency varies enormously by jurisdiction, and access varies again. Depth per market is the biggest practical difference between data sources, and it is the thing to test on your own markets rather than take from a coverage map.

It is not identity verification. Floowed does not perform identity, biometric or liveness verification of individuals. Where a decision needs a national ID validated or a face matched to a document, that runs through third-party providers the customer must already hold access to, and we take the result as an input. The two controls fail independently, and a design that assumes one covers the other has a gap.

It says nothing about the documents alongside it. A registry confirms the company, not whether the financial statement attached to the case was altered after it was produced. That is a separate discipline, covered in our guide to document fraud detection.

Business verification software: three shapes, and which one you need

Search "business verification software" and you get three genuinely different products under one phrase. They are complements, and buying the wrong shape is the common expensive mistake.

Data providers and registry aggregators hold the records and sell access, usually per lookup. What happens to the data next is your problem. Onboarding and screening platforms run the checks as a workflow and route hits to a reviewer, so what comes back is a verdict in their console that somebody then carries into wherever the decision is made. Decision platforms treat verification as one input among several, so the finding is not a report but a variable your own rules gate on.

We are the third. Not a claim to hold registry data better than the firms whose business that is, and not a replacement for a screening platform you already run. A claim about where the answer lands.

The same check, in half a dozen vocabularies

Entity verification is a property of companies, not of industries. An ownership chain does not know what business it is being walked for. What changes is which decision the answer feeds, and which finding is disqualifying.

Lending and credit. Registration status, ownership, security interests, judgments and insolvency history feed the credit decision alongside the financials. Credit and risk teams already treat a UCC or PPSR position as material, because it affects recovery. Our guide to reading a business credit report covers the bureau layer next to it.

Banking and fintech onboarding. Non-credit onboarding, same machinery: registration certificates, board resolutions, ownership declarations and source-of-funds evidence, checked against the registry rather than taken from the form.

Insurance. Commercial underwriting needs the insured entity to exist in the form declared, the intermediary to be licensed, and the counterparty on a claim payment to be the entity on the contract. An entity that changed legal form between inception and claim is a registry-level finding.

Supply chain and supplier onboarding. Does the entity exist, is it in good standing, is the bank account being requested attached to the entity you contracted with. This is where a dormant shell with a plausible name does the most damage, because approval is often a form rather than a decision.

Shipping, freight and trade. Counterparty verification before you carry, finance or insure a cargo for somebody new. The ownership walk carries unusual weight, because sanctions exposure often sits two layers above the entity that signed.

HR and workforce. Where the engagement is with an entity rather than a person: agencies, umbrella companies, contracting vehicles. Does it exist, is it trading, is it insured, and are the directors who the contract says they are.

We should be exact about what that list is. It is capability: those checks run on a freight counterparty the way they run on a credit applicant, because the sources are the same. It is not a customer list. Our deployments to date are in lending, and we are not going to dress domain knowledge up as a track record we do not have.

A verification that lands in a portal is not a control

Here is the pattern we see in almost every operation we look at. The check gets run properly. Somebody opens a screening console, reads the result, then retypes the conclusion into another system or attaches a PDF and writes "verified" in a comment field. The verification was real. The control was a transcription step done under time pressure by whoever was on shift, and it fails predictably: the detail that mattered does not travel, the finding goes stale between onboarding and decision, and it gets overridden quietly, because nothing knows a rule was supposed to apply.

The alternative is that verification runs inside the decision rather than beside it. In Floowed, the Decision Engine resolves the entity as part of the case, and every finding lands as a first-class variable your own rules can gate on: entity status, whether declared control matches filed control, judgments, insolvency flags, registered security interests, sanctions and PEP hits, adverse media. Your team writes what each one does. An entity that is not active can be a hard gate that blocks automated approval however well the rest of the case scores. An ownership mismatch can route to manual review with the reason attached and the override logged. Outcomes are the same three every time: recommended to approve, manual review, or reject. The finding stays attached to the case, on the audit trail, with the rule version that ran on it.

Where the entity's own paperwork is the only evidence available, document intelligence reads it however it arrives, scanned, photographed or handwritten, and those fields land in the same policy alongside the registry data. Three routes in, one decision: your systems, external sources, and documents.

One precision point, because the category over-promises here. Resolving an entity draws on external sources that change between runs, and reading a document is machine learning rather than a lookup, so we will not claim the pipeline end to end returns identical output every time. The determinism claim belongs to the rules: given the same inputs, the Decision Engine produces the same outcome every time, and shows you the inputs it used and the rule version that ran.

How to choose business verification software

1. Which jurisdictions, and how deep in each? Coverage maps are marketing. Give every vendor ten real entities from your own book, including the awkward markets, and compare what comes back.

2. Does it resolve beneficial ownership, or stop at the registered agent? Ask to see a multi-layer structure walked to natural persons. Most often claimed, least often delivered.

3. What happens to the finding? The question that separates a report from a control. If the answer is "it appears in our dashboard", you are buying information and building the control yourself. Ask too whether your own team can write the rule, and whether the finding, the rule version, the inputs and the outcome are retained together.

4. What happens when the registry has nothing? Sole proprietorships, informal businesses, weak registries. Ask what the fallback is, and whether documents can carry the check instead.

Where Floowed fits, and where it does not

Floowed is the answer when the verification feeds a decision somebody has to defend: a credit approval, an onboarding, a supplier approval, a counterparty engagement, a claim payment. The Business Verification agent confirms the entity against registries, resolves ownership past the registered agent, and pulls court, insolvency, regulator, security-register, sanctions and adverse-media findings through the integration layer. Every one lands as a variable in rules your team wrote. Same rules. Every case. Every time. No exceptions.

Where we are not the answer: we are not a KYB data vendor and we do not own the registry data. We do not perform identity, biometric or liveness verification of individuals. We do not certify that a correctly registered company is a real trading business. And we are not the system of record for the process we sit in front of: yours stays yours, and we integrate in both directions. The bound is narrow by design, anywhere a complex operational process reads a case and decides something. A workflow with no judgement in it does not need us. See what a decisioning platform is.

FAQ

What is the difference between KYB and KYC? KYC verifies a natural person, using identity documents and biometric or bureau checks. KYB verifies a legal entity, using registries, filings and public records. KYB contains KYC: the ownership walk produces the people you then run KYC on.

What documents are needed for KYB verification? Typically a certificate of incorporation, the current registry extract or annual return, articles or constitution, an ownership declaration, board resolutions, proof of registered address, and identity documents for directors and owners. The list is jurisdiction-specific and risk-based, and what matters is checking those documents against the registry rather than filing them.

Is KYB verification a legal requirement? For regulated financial institutions, entity-level due diligence including beneficial-ownership identification is a standard part of customer due diligence obligations in most jurisdictions, and you should take the specific requirement from your own regulator. In procurement, logistics and workforce engagement it is commercial risk management rather than a mandate, which is why it gets skipped.

What does business verification software cost? Data providers price per lookup or per entity, screening platforms per case or per seat. Floowed is quote-only and consumption-based, sized to your operation on one short call, and business verification is one capability inside the platform rather than a separate line item.

The bottom line

KYB verification is a narrow, checkable discipline: confirm the entity exists and is active, walk the ownership to natural persons, and read the record for what should change your mind. It is not identity verification, and a registry extract is a filing rather than a fact. Inside those limits it catches what nothing else in an onboarding stack can see, but only if the finding changes the outcome by itself, under rules somebody wrote down and can show an auditor a year later. Verification without enforcement is a portal somebody checks.

Start free or book a demo and run a real entity through it.

Run a real file through it.

See the whole decision: every gate, every reason, on record.

Book a demo