The Platform PM

Field GuideLast reviewed October 2026

Identity and trust: KYB, KYC and ongoing monitoring

Who a platform must verify before a business can move money, how KYB, KYC and ongoing monitoring work, why your sponsor bank or card network sets the real bar, and who pays when a fake company, a deepfake or a missed alert gets through.

The industry on one page

The parties. A business applies to your platform, which checks it through verification vendors that query registries and data bureaus. Your sponsor bank or card network sets the bar, regulators examine the bank, and suspicious activity gets reported to them, by you or by your bank.

A landscaping company in Texas, Greenline LLC, wants to take card payments through the scheduling software it already uses. It was formed in Delaware, has two owners and would like its first payout on Friday. Before the software company says yes, it needs to know whether Greenline is a real business that's allowed to do what it says, whether the people behind it are who they claim to be, and, once it's live, whether its money keeps behaving like a landscaping company's.

Each of those is a layer of this industry:

  • KYB (know your business), the entity: does the company exist, is it in good standing, who owns and controls it, what does it actually do, and is that business allowed on your platform.
  • KYC (know your customer) and UBO checks, the people: the person applying, the people who sign, the ultimate beneficial owners (the humans at the top of the ownership chain, UBOs for short) and whoever controls the company.
  • KYT (know your transaction) and ongoing monitoring, the behaviour: transaction monitoring, re-screening against sanctions lists and the news, reviews on a schedule and when something changes, and reporting suspicious activity.

The business and its owners apply to your platform. You check them through verification vendors, which query the data sources: business registries, credit bureaus and other data brokers. Your sponsor bank (the licensed bank that holds the money for a fintech) or the card network sets the bar you must meet. Regulators examine the bank, which is how their expectations reach you. Suspicious activity gets reported to FinCEN in the US or FINTRAC in Canada, by you if you hold your own licence and by your bank if you don't.

What I'd want a new PM in this space to take away:

  1. Thin data: KYB is mostly a data problem, and in my experience the data is thin more often than contradictory. Registries rarely disagree; they just say very little. A US state registry is a filing office: in most states it records what people file and can't check or reject it. It tells you a company exists, rarely who owns it, and almost never verifies anyone. Since 2025 the federal ownership database doesn't cover US companies either, so the platform builds its own ownership graph from what the applicant declares and has to keep it current. A clean match also proves less than it seems, because a hijacked company, where a fraudster has filed changes to a real business's record, matches the registry perfectly.
  2. The bank's rulebook: on a sponsor bank, the bank's and the network's rules are the ones you actually work to. Most platforms that onboard businesses aren't banks. The legal duty to verify customers and report suspicious activity sits with the bank, which pushes it down to you by contract, and with the card networks' rules for payment facilitators. The regulator reaches you through the bank's consent order (a formal enforcement agreement). This is weaker for licensed money transmitters and for UK and EU firms, which regulators fine directly.
  3. Monitoring: onboarding is a snapshot, and the big failures have been in monitoring. The largest penalties of 2024 to 2026 were for monitoring that wasn't switched on, alert backlogs and screening against part of a sanctions list. Growth tends to break monitoring before anything else, because onboarding scales with vendors and monitoring scales with people. People also cost more than checks: in the worked example in How the money moves, the data you pay for per check is a few percent of the yearly cost.
  4. AI fraud and digital IDs: deepfake selfies, faked camera feeds and AI-made ID images sold for $15 are real; FinCEN warned banks about them in November 2024. Trust is moving toward layered signals and digital IDs, and in September 2026 US regulators said a signed digital credential, such as a mobile driver's licence, counts as government ID for opening an account. Documents plus a selfie, backed by bureau data, are still the base of almost every check, though. More in AI fraud and digital IDs.

So an identity program ends up as a data pipeline that never finishes, run to a bar someone else sets, where the expensive part starts after approval. It's hard for a few reasons. The truth sits in several places: existence in a registry, the tax ID at the IRS, ownership with the applicant, behaviour in your own ledger. Every country answers "who owns this company?" differently, and the US answer changed in 2025. And you get judged on what you missed, often years later, while the good customers you slowed down rarely come up.

Sponsor banks and the 2024 Synapse collapse are in B2B payments: spend management; sanctions, the travel rule and FINTRAC's penalties from the payments side are in B2B payments: cross-border payouts; brand vetting for business texting, a cousin of KYB, is in Phone numbers, messaging and voice.

The main players

The diagram shows roles; the mental map needs names. These are the companies and agencies I'd want to recognize in week one, layer by layer, in no particular order.

Identity verification

What they do
Check a person's ID document, selfie and liveness; orchestrate data checks
Main players
Entrust (Onfido), Persona, Veriff, Socure, Incode, GBG
What they control
The capture flow, the pass rate, what counts as a match

KYB and business data

What they do
Pull registries, normalize company records, map ownership
Main players
Moody's (Orbis), Dun & Bradstreet, Middesk, Trulioo, Kyckr, Baselayer
What they control
Coverage, freshness, how entities get matched

Credit bureaus and risk data

What they do
Confirm a person's details against records; score fraud risk from phone, device and behaviour
Main players
Experian, TransUnion, LexisNexis Risk Solutions, BioCatch, Prove
What they control
Whether someone with a thin file can be verified without a document

Sanctions and PEP data

What they do
Keep the lists of sanctioned people, politically exposed people and bad news
Main players
LSEG (World-Check), LexisNexis Risk Solutions, Moody's, ComplyAdvantage
What they control
List coverage and how many false hits you review

Transaction monitoring and case management

What they do
Raise alerts on behaviour, hold the investigation record
Main players
NICE Actimize, Quantexa, Hawk, Sardine, Unit21
What they control
Rules, models, the audit trail an examiner reads

Sponsor banks and card networks

What they do
Hold the licence and the money; write the onboarding rules
Main players
The Bancorp, Coastal Community Bank, Lead Bank; Visa, Mastercard
What they control
Risk appetite, prohibited lists, approval of every program

Registries and government

What they do
Record that companies exist; confirm tax IDs and Social Security numbers
Main players
Delaware and other Secretaries of State, IRS, SSA, Corporations Canada, Companies House, GLEIF
What they control
Legal existence, data access and fees

How they make money, and who's moving:

  • Identity verification vendors charge per verification, a dollar or two at list price. The fast growers are private: Veriff says its revenue passed $100M and doubled in 2025, and Persona raised at a $2B valuation. The public incumbents, Mitek and GBG, grew by low single digits. Digital ID networks like ID.me and CLEAR grow alongside.
  • KYB and business-data providers sell annual platforms plus a fee per lookup. Moody's KYC revenue grew by about a fifth in 2025, and Clearlake took Dun & Bradstreet private for $7.7B. The specialists report faster growth, but their figures are their own.
  • Bureaus and risk-data companies earn on every check. LexisNexis Risk Solutions grew 8% in 2025, led by financial crime and identity. Buyers keep paying for signals: a private equity firm bought most of BioCatch at a $1.3B value.
  • Sanctions data is a subscription business: screening is almost four-fifths of LSEG's risk intelligence revenue. ComplyAdvantage is the best-known fast grower.
  • Transaction monitoring sells annual platforms priced by volume. NICE Actimize, the large-bank incumbent, made about $450M in 2024, and NICE was in talks to sell it in September 2026. Graph and AI challengers like Quantexa and Sardine are growing fast.
  • Sponsor banks charge fintechs program fees and earn on deposits and card fees. The Bancorp's fintech fees grew by about a fifth in 2025; Coastal took on deposits from Evolve, a bank under a 2024 Fed order.
  • Registries charge filing and search fees: Companies House took in about £240M in 2025-26, and Delaware charges $10-20 per online status check.

As of October 2026. Players change through acquisitions and funding rounds, so treat this as a map to check before you rely on it.

When Greenline signs up through its scheduling software, a KYB vendor like Middesk pulls its Delaware record and matches its EIN with the IRS. An identity vendor like Persona checks both owners, leaning on bureau data from a company like Experian. A screening provider like World-Check runs every name against sanctions lists. The sponsor bank, The Bancorp for example, set every threshold in that flow and audits a sample. After go-live a monitoring tool like Unit21 watches the payouts. Greenline signs one contract, and six or seven companies have a say in whether it gets paid.

How a business gets approved, step by step

A business from application to monitoring. Most applications that stall go to manual review for documents. Approval is a snapshot: the checks continue for as long as the account is live, and for a typical platform that's where most of the cost sits.

Follow Greenline from application to monitoring. Most applications that stall go to manual review for documents. Approval is a snapshot: the checks continue for as long as the account is live.

  1. Applied: legal name and trade names (a DBA, "doing business as"), entity type, state and date of formation, registration number, EIN (the US federal tax ID), addresses, website, what it sells, expected volume, the payout bank account, and the people: owners of 25% or more plus one person who controls the company, each with name, date of birth, address and ID number. Breaks: the applicant types the trade name where the legal name should go.
  2. Business verified: find the right entity in the Delaware registry, and in Texas, where it's registered to operate. Check it's active and in good standing, look at recent changes, match the EIN to the legal name, classify the address and website, assign an industry code, check the prohibited lists, and build the ownership tree. Breaks: a name mismatch, an EIN that belongs to a parent company, a two-week-old LLC the vendor's copy of the registry hasn't caught yet, a foreign parent. These go to manual review, which usually means asking for documents: the articles of organization, the IRS letter confirming the EIN, an operating agreement, a bank statement.
  3. People verified: each owner and the control person, by data checks first and a document plus selfie when the data isn't enough; sanctions and PEP screening (politically exposed persons) on the company and every person. Breaks: a thin credit file, an owner abroad with no Social Security number, an owner who won't take a selfie.
  4. Approved, with limits: a risk rating and usually some limits: a volume cap, a rolling reserve (a share of each payout held back for a while), a delay on early payouts. Breaks: nobody revisits the limits.
  5. Monitored, for as long as it's live: re-screening on every list update, transaction monitoring against what Greenline said it would do, a review when owners, bank accounts or volumes change, and a refresh on a schedule set by risk. Breaks: the expected activity captured at onboarding was wrong, so every alert is noise.

Two exits sit off that path. Manual review sends a case back to the main path once the documents arrive, or to a decline. Offboarding comes from monitoring: restrict the account, close it, return the money, file a suspicious activity report if there's reason to suspect something, and keep the records for five years.

Vendors say older KYB setups send 30-70% of applications to a human, and every document round trip loses applicants, so most stuck applications are sitting in manual review waiting on a document. The cost after approval is bigger still: in the worked example in How the money moves, ongoing monitoring and review are most of what the program costs in a year. That holds for a typical platform; a high-volume payment facilitator can spend more on review at onboarding instead.

The checks compared

US state registry lookup

What it proves
The company exists, and its status
Rough cost (Oct 2026)
Cents to a few dollars; Delaware charges $10-20 a status check
Good customers it fails
Sole proprietors (often not registered), brand-new companies
How fraud beats it
A hijacked or freshly formed company matches perfectly

EIN and name match (IRS)

What it proves
The tax ID belongs to that legal name
Rough cost (Oct 2026)
Often bundled; only companies that file 1099s can ask the IRS directly
Good customers it fails
Trade names, recent name changes
How fraud beats it
A real EIN paired with its real name

Ownership check

What it proves
Who owns 25% or more, and who controls
Rough cost (Oct 2026)
Mostly analyst time
Good customers it fails
Holding companies, funds, foreign parents
How fraud beats it
Nominees, or stakes kept just under the threshold

Bureau or database match

What it proves
Name, date of birth, SSN and address appear together in records
Rough cost (Oct 2026)
Roughly $0.20-1 (estimate)
Good customers it fails
Thin files, newcomers, people who moved or changed name
How fraud beats it
Synthetic identities built to match

SSA's eCBSV

What it proves
SSN, name and date of birth match Social Security's records
Rough cost (Oct 2026)
About $0.50, prepaid in annual tiers
Good customers it fails
Typos and name changes (most mismatches)
How fraud beats it
A stolen real identity passes

Phone, email and device signals

What it proves
Phone tenure, email age, device reputation, human or bot
Rough cost (Oct 2026)
Cents
Good customers it fails
Prepaid phones, new devices, privacy browsers
How fraud beats it
SIM swaps, device farms, aged emails bought in bulk

Document plus selfie and liveness

What it proves
The person matches a genuine-looking ID and is really there
Rough cost (Oct 2026)
About $1-2 at list price
Good customers it fails
Poor cameras, worn cards, some faces more than others
How fraud beats it
Deepfakes fed through a virtual camera; AI-made documents

Passport chip read

What it proves
Data signed by the issuing government
Rough cost (Oct 2026)
More (needs a mobile SDK)
Good customers it fails
No NFC phone, or no chip in the document
How fraud beats it
Very hard to forge; taking over the account later

Mobile driver's licence or other signed credential

What it proves
Data signed by the issuer and bound to a device
Rough cost (Oct 2026)
Low per check
Good customers it fails
Most people can't present one online yet
How fraud beats it
Taking over the phone or wallet

Bank login (Interac in Canada)

What it proves
A bank already verified this person
Rough cost (Oct 2026)
A fee per check
Good customers it fails
No eligible bank account
How fraud beats it
Taking over the bank login

List prices come from vendors' public pages; enterprise deals run lower, and the database and signal prices are my estimates, since bureaus don't publish theirs.

Then the question every business applicant raises: who counts as an owner, and where can you check it?

Owner threshold

US
25% or more, plus one control person
Canada
25% or more of shares or votes, or control
UK
More than 25%, or significant control
EU
25% or more from July 10, 2027; can drop to 15% for higher-risk types

Public register

US
None for US companies; FinCEN's database now covers only about 28,000 foreign companies
Canada
Federal companies only, public since January 2024; Quebec has its own
UK
Yes, the PSC register (people with significant control)
EU
National registers, closed to the general public since a 2022 court ruling

Who verifies

US
The bank, which pushes it down to you
Canada
You confirm by a different method; report mismatches on high-risk federal companies within 30 days
UK
Companies House verifies directors' and owners' identity since November 2025
EU
You; registers gain powers to check

Next change

US
FinCEN rewrite of the ownership rule, under White House review since September 17, 2026
Canada
British Columbia's register (launch unconfirmed)
UK
Identity checks mandatory for everyone after November 17, 2026
EU
AMLR applies July 10, 2027; EU Company Certificate from July 2028

More on how the four fit together in Regulatory layering.

Choosing what to check: five questions

  1. Who holds the legal duty? A bank, a licensed money transmitter, a marketplace under the INFORM Consumers Act, or nobody, because you're a B2B software company checking for fraud reasons. That sets your floor, and if there's a bank, its program sets the bar.
  2. How fast can money leave? Instant payouts and instant credit lines put the loss right after onboarding, so check more up front. A product where money moves slowly can approve with limits and lean on monitoring.
  3. Who are your applicants? Most US small businesses have no employees (about 30 million of 36 million), and many are sole proprietors with no registry record at all. For them the work is the person and what the business really does. The ownership graph starts to matter with mid-market and cross-border customers.
  4. Where are they from? It depends on where they were formed and where the owners live. A Delaware check costs money per lookup, a UK company is free to query, EU ownership registers are mostly closed to you, and an owner abroad has no SSN and no US credit file.
  5. What must you prove? Your bank or network will ask. Sponsor banks and auditors want to see, for every field, which source it came from and when. If you can't show that, it doesn't count as checked.

My defaults: for people, data checks come first and a document plus selfie is the step-up when the data isn't enough. For businesses I'd pull the registry record, the EIN match and the change history, since a match on its own says little. Store the ownership graph with dates and sources. Approve with limits and relax them on good behaviour. Subscribe to registry changes where you can. Size the monitoring team for next year's volume, and spend on what happens after approval at least as carefully as on the front door.

The primitives

01

Entity & identity

What is the unit of record, and how do we know it is the same one?

Products tend to blur the legal entity (Greenline LLC), the account on your platform (Greenline's two locations, each with its own payouts) and the person (an owner who also owns a second company you onboarded last year).

Keep them as separate records. One entity can have many accounts. One person can own several entities, sign for others and be a consumer customer too. When a fraud team asks "what else is this person connected to?", that link is the answer.

Identifiers are local, and none covers every small business:

IdentifierWho issues itWhere it falls short
State file numberEach US Secretary of StateOne per state; a company registered in four states has four
EINIRSNot public; a sole proprietor may use their SSN instead
Corporation number and Business NumberCorporations Canada or a province; CRAFederal and provincial registers are separate
Company number (CRN)Companies HouseUK only
EU register number (EUID)National registersOwnership data sits in a separate register
LEIGLEIF, through local issuersAbout 3 million worldwide; rare among small businesses
D-U-N-SDun & BradstreetProprietary

An ownership link needs more than a percentage. Give each one a type (shares, votes, a right to appoint the board, a trust role, a nominee), a date and a source. Thresholds differ by a word: the US, Canada and the EU say 25% "or more"; the UK says "more than" 25%. An owner with exactly 25% is in scope in Toronto and out of scope in London.

On the people side, synthetic identities and account takeover both break the model. A synthetic identity breaks the assumption that a set of details belongs to one real person. Account takeover breaks the assumption that the person logged in is the person you verified.

More on Entity & identity →

02

State & lifecycle

What states exist, and what moves an entity between them?

One customer has a state in the registry, on your platform and in your alert queue, and these drift apart unless you connect them.

  • The registry's: formed, active and in good standing, delinquent (a missed annual report or franchise tax), administratively dissolved or revoked, reinstated within a window each state sets, or gone.
  • Your platform's: started, submitted, auto-verified or pending review or documents requested, approved (with limits) or declined, active, under review, restricted, offboarded. Add states nobody plans for: frozen for sanctions, and "keep open", when law enforcement asks you not to close an account.
  • The alerts': new, in triage, escalated, case open, report filed, closed with no action.

A person's verification has a lifecycle too. Documents expire, addresses change, and in the EU from July 2027 customer information must be refreshed at least yearly for high-risk customers and every five years for the rest. Assurance also comes in levels.

If Greenline misses its Delaware annual report in March, the registry moves it to delinquent while your platform still says "active". Nothing is wrong yet, but if a fraudster later reinstates the company and changes its officers, you'd want to have seen both events, so subscribe to the registry's state changes where you can.

Watch one more state: "closed automatically". A US regulator's April 2026 order against a payments-heavy bank criticized alerts that closed themselves. No alert should close without a human or a validated model giving a reason.

More on State & lifecycle →

03

System of record & ledger

Who owns the truth, and how do systems reconcile?

Every fact has an owner, and the platform owns fewer than its dashboard suggests.

FactSystem of record
The company exists, and its statusThe registry; a monopoly in each state or country
Tax ID belongs to the nameIRS or CRA; not public
Who owns it (US)Nobody public: the bank's or platform's own due-diligence record
Who owns it (Canada)The company's own register; for federal companies, a copy at Corporations Canada
Who owns it (UK)The PSC register at Companies House
Who owns it (EU)National ownership registers
What you checked, when, and the resultYour KYB and KYC record
Who reviewed an alert, and why they closed itYour case-management system
Document images and biometric templatesUsually the verification vendor, on its own retention schedule

Your KYB record is a derived record. For each field it should say where the value came from, when you pulled it and whether it matched. That provenance is what sponsor banks and auditors ask for, and when an examiner asks why you approved someone, the source and date of each verified fact is your answer.

The case-management system is the record a regulator reads: who saw what, when, and why they closed it. Keep verification records five years in the US and Canada. A biometric law like Illinois's wants templates destroyed on a schedule, so the usual answer is to keep the results and delete the templates.

For banking-as-a-service the ledger is a record of its own. When Synapse, a middleware company between fintechs and banks, collapsed in 2024, its records and the banks' didn't reconcile, and end users were left short by tens of millions of dollars.

More on System of record & ledger →

04

Rules & policy

What logic decides outcomes, and who can change it?

Law is only one of the kinds of rules that shape every decision.

  • Law: the bank rules on customer identification and beneficial ownership in the US, Canada's PCMLTFR, the UK's money laundering regulations, the EU's AMLR from July 2027, and the INFORM Consumers Act for marketplaces.
  • Network rules: Visa requires a payment facilitator (a payfac, a company that signs up merchants under its own card acceptance account) to check every applicant against its list of terminated merchants, and bans some industries outright unless the payfac is registered for high risk. Mastercard requires a check against MATCH, its list of terminated merchants, before onboarding.
  • Your bank's policy: a prohibited and restricted business list, how deep KYB goes, which vendors you may use, how fast alerts must be worked, how often customers get refreshed.
  • Your own policy: risk appetite and auto-approval thresholds.

Many hard calls aren't data questions at all. What counts as "control"? Do you onboard a company that's delinquent but can cure it? Is a registered agent's address, a virtual office or a UPS store acceptable? How far up a foreign ownership chain do you go? Write those calls down as policy, separate from the data, because that's where two platforms with the same vendors end up differing.

Visa's high-brand-risk list is a set of merchant category codes plus activities such as cyberlockers, skill games like daily fantasy sports, and buying crypto. A marketplace may not sign those merchants at all; only payfacs registered for high risk can.

Thresholds trade false accepts against false rejects. You tune them; your sponsor bank approves them.

More on Rules & policy →

05

Effective dating

Which version of the rule applied at that moment?

Ownership changes over time, lists change daily, and the rules changed a lot in 2025 and 2026.

ChangeEffectiveStatus (Oct 2026)
US banks may collect only the last four SSN digits and get the rest from a third partyJune 27, 2025Live, optional
FinCEN's guidance easing suspicious activity reportingOctober 9, 2025Live
Canada: report ownership mismatches on high-risk federal companiesOctober 1, 2025Live
UK: identity checks for new directors and ownersNovember 18, 2025Live; transition ends November 17, 2026
US: banks re-verify a company's owners only at the first account, or when in doubtFebruary 13, 2026Live
Canada: maximum FINTRAC penalties 40 times higherMarch 26, 2026Live
FinCEN's new AML program ruleProposed April 2026No final rule yet
US ownership reporting ends for US companies (final rule)August 14, 2026Live
Digital credentials accepted as ID for account opening (US)September 8, 2026Live
EU digital identity wallets due in every member stateDecember 24, 2026Upcoming; many will be late
EU AMLR and its ownership and refresh rulesJuly 10, 2027Upcoming
EU banks must accept the wallet on requestAround December 2027Upcoming
EU Company CertificateJuly 31, 2028Upcoming

Inside your data, store dates on ownership, list versions and clocks. Canada's register records when someone became and stopped being a significant owner, and your graph needs valid-from and valid-to dates too. A sanctions screen is only as good as the list version it ran against. A US suspicious activity report is due 30 days from initial detection of the activity, and examiners argue about that detection date.

Picture Greenline selling 30% of itself to a new investor in May. If your graph only holds the current owners, you can't answer the question an examiner will ask in December: who owned it when you paid out in June? Examiners keep coming back to what you knew and when, so date every ownership link, list version and review.

More on Effective dating →

06

Interfaces & standards

What format and protocol do counterparties speak?

The standards are a patchwork, and most of them sit behind a vendor's API.

  • Registries. Companies House offers a free API (600 requests every five minutes) and a streaming API that pushes changes as they happen; it's the cheapest major registry to build on. Corporations Canada has an API and open data. Most US states offer web search pages, some bulk data and per-lookup fees, so vendors scrape or license.
  • Tax IDs. IRS TIN Matching takes up to 25 pairs at once interactively or 100,000 in bulk, but only for payers who file 1099s.
  • SSNs. SSA's eCBSV answers yes or no on SSN, name and date of birth, with the person's consent.
  • Documents. ICAO 9303 for passports (the machine-readable zone and the chip), the barcode on the back of US driver's licences, ISO/IEC 18013-5 and 18013-7 for mobile driver's licences in person and online.
  • Liveness. ISO/IEC 30107-3 tests presentation attacks: a mask, a printout or a screen held to the camera. Injection attacks, where a fake video feed replaces the camera, are a separate problem with a newer standard. Web capture is easier to inject into than a mobile SDK. A "certified liveness" check usually means it resists masks and printouts and says nothing about faked camera feeds, so ask which attacks it was tested against.
  • Identity levels. NIST SP 800-63-4 (August 2025) for US government, not binding on fintechs but marketed to; eIDAS's "substantial" and "high" in the EU.
  • Codes. MCC (ISO 18245, the card networks' merchant category) and NAICS (the government's industry codes) don't map one to one; a new NAICS version is proposed for data from January 2027.
More on Interfaces & standards →

07

Networks & counterparties

Who sits between us and the outcome, and what do they want?

A business approval runs through a chain, and the platform sits in the middle of it.

PartyWhat they control
Registries and tax agenciesWhether a company exists; who may check a tax ID
Data aggregatorsCoverage, freshness and how records get matched
KYB and identity platformsThe workflow, decision rules and audit trail
Bureaus, SSA, phone carriers through aggregatorsWhether a person's details can be confirmed without a document
Screening and monitoring vendorsList coverage, alert volume
Sponsor bank or acquirerPolicy, vendor approval, the right to stop new onboarding
Card networksMerchant rules, MATCH, fines passed down to the payfac
Regulators and intelligence unitsRules, penalties, requests about specific people
ConsortiumsShared fraud data: Early Warning in the US, Cifas in the UK
Credential issuers and wallet makersWho gets a digital ID, and whether apps can read it

Information flows through the chain too. FinCEN sends banks lists of law-enforcement subjects every two weeks (a 314(a) request), and banks answer only with matches. Institutions with an AML program requirement can share information with each other under 314(b). A platform without one can't join, so if you aren't a regulated institution yourself, your bank is both your rule-setter and your only window into what other institutions know.

More on Networks & counterparties →

08

Regulatory layering

Jurisdiction × activity × entity type: is it a license or a certification?

Separate the layers, because each binds a different party and has a different enforcer.

Law

What it says
US bank rules on identifying customers and owners; Canada's PCMLTFR; UK money laundering regulations and company law; EU AMLR
Binds
Banks, licensed money transmitters, other regulated firms
Enforced by
Regulators, through penalties and orders

Law aimed at platforms

What it says
The INFORM Consumers Act
Binds
Online marketplaces
Enforced by
The FTC, up to $53,088 a violation

Network rules

What it says
Visa and Mastercard payfac and merchant rules
Binds
Acquirers, which pass them to payfacs
Enforced by
Fines and assessments

Partner policy

What it says
The sponsor bank's program agreement and risk appetite
Binds
The fintech
Enforced by
Contract, onboarding freezes, termination

Registry practice

What it says
What each registry checks before accepting a filing
Binds
Filers
Enforced by
Registries, now more strictly in the UK

Which layer reaches you depends on what you are. For most US platforms on a sponsor bank, the one that binds you day to day is the contract with the bank. A payfac gets its KYB requirements from the network and its bank; the bank rules themselves bind the bank. A marketplace has INFORM directly: once a seller makes 200 sales and $5,000 in a year, you have 10 days to collect and verify its bank account, tax ID and contact details, and sellers above $20,000 must show their identity to buyers. A B2B software company that doesn't move money may have no legal KYB duty at all, and checks for fraud and trust.

Beneficial ownership is where the four jurisdictions split most:

  • US. The Corporate Transparency Act was meant to give FinCEN a register of every company's owners. An interim rule in March 2025 and a final rule effective August 14, 2026 cut it to foreign companies: about 28,000 instead of the 32.6 million FinCEN once expected. FinCEN is deleting the data it had on US people. Banks still collect owners under their own rule, so the change mattered less to platforms than the headlines suggested: their ownership checks always came from the bank.
  • Canada. Federal companies must file their significant owners with Corporations Canada, publicly since January 2024. Most Canadian companies are incorporated in a province instead, and only Quebec has a public register of its own. Since October 1, 2025, firms that report to FINTRAC must flag mismatches on high-risk federal companies within 30 days.
  • UK. The register of people with significant control has been public for years. Since November 18, 2025 Companies House checks the identity of directors and owners itself. Between 6 and 7 million people have to verify by November 17, 2026, and by the end of June just over half of directors had.
  • EU. In 2022 the EU's top court struck down public access to ownership registers on privacy grounds, and several countries closed theirs. The 2024 directive reopens them to people with a "legitimate interest". From July 10, 2027 the AMLR sets one method across the EU: multiply percentages down each chain of ownership, add them across chains, and count control by other means.
More on Regulatory layering →

09

Exceptions & reversals

What goes wrong, and how is it undone?

Most of the work in this team lives in exceptions, and several of them run on someone else's clock. The restrict, review, close and report paths are where examiners look and where good customers get hurt, so it pays to design them before the happy path.

ExceptionThe way backClock
Name or EIN mismatch at onboardingAsk for documents; manual reviewDays per round trip
Fraudulent filing on a real company's registry recordSome states can now mark or reject it; in others, a court orderWeeks to months
Merchant listed on MATCHOnly the acquirer that listed it can remove itIts timeline
Person can't be verified (US bank rule)Restrict the account, then close it after attempts fail; consider a suspicious activity reportSet by the bank's procedures
Sanctions false positiveClear it with date of birth, nationality and address; unfreeze; apologizeHours to days
Sanctions true matchBlock or reject; report to OFAC within 10 business daysUnblocked only by an OFAC licence or delisting
314(a) matchAnswer FinCEN within two weeks; a match alone isn't a reason to closeTwo weeks
Law enforcement "keep open" letterKeep an account you'd otherwise closeUntil the letter lapses
Ownership mismatch, high-risk federal company (Canada)Report to Corporations Canada30 days
Wrongful offboardingReinstate; since August 2025 US exits draw scrutiny for political or reputational reasonsWeeks
Regulator-ordered lookbackRe-review a past period and file the reports you missedMonths, with consultants

Lookbacks are the expensive one. The Fed's 2024 order against Evolve Bank & Trust required a review of its fintech partners' wires over six months for missed reports; the FDIC told Sutton Bank to re-run identity checks on every prepaid customer since mid-2020. If your bank gets one, your operations team does the work.

A fraudster can reinstate a dissolved company, name themselves an officer and apply to your platform, and the registry match will be perfect. The way back starts with the victim business asking the state to fix the record, which in some states needs a court.

More on Exceptions & reversals →

10

Liability allocation

When it fails, who pays?

The regulator fines the licensed party, which pushes the cost down by contract until it reaches someone who can't push further.

FailureWho paysHow
Customer identification or due-diligence failureThe bank, then its fintechPenalties and consent orders on the bank; indemnities, remediation and freezes for the fintech
Merchant fraud at a payfacThe acquirer to the network, then the payfacNetwork rules; contract
Wrong industry boarded (a high-risk merchant as low-risk)The acquirer, then the payfacNetwork assessments
Marketplace skips seller verificationThe marketplaceFTC civil penalties; Temu paid $2M in the first case, in 2025
Synthetic identity becomes a bust-out (maxing out credit, then vanishing)Whoever extended the creditOften booked as a credit loss, not fraud
Deepfake-opened account used as a mule (an account that moves stolen money)US: mostly the scam victim. UK: sending and receiving payment firms, 50/50UK reimbursement rules since October 2024
Account takeoverConsumer accounts: the institution. Business accounts: usually the businessReg E for consumers; contract for businesses
Biometrics collected without consentThe platform and its identity vendorIllinois's BIPA lets people sue; Texas's law lets the attorney general
Bad data from a registry or vendorWhoever relied on itRegistries don't vouch for filings; vendor contracts disclaim accuracy
Sanctions breachThe US person who processed itStrict liability; contracts move the cost, not the liability

Illinois's biometric law is the one people underestimate: $1,000 per negligent violation and $5,000 per intentional one, with a right to sue. Since a 2024 amendment, repeated scans of one person count once, but class sizes still make it costly: Onfido settled for $28.5M. Financial institutions are exempt, and courts have extended that to some of their vendors; a marketplace or gig platform doesn't get the shield.

If Greenline is really a front and $80,000 of stolen card payments flow through it before you catch on, the cardholders' banks charge the payments back, the acquirer collects from you, and you can't collect from a company that's gone. Every relaxed setting (auto-approval, instant payouts, skipped selfies) is also a decision about who absorbs that kind of loss, and it belongs in the spec and the contract.

More on Liability allocation →

What's different here

How the money moves

The platform pays for almost everything. Vendors charge per check, per profile or per year; the sponsor bank charges program fees on top and keeps a veto; the customer pays in time, which shows up as churn; and regulators charge for failure.

FlowWho pays whomRough amount (Oct 2026)
KYB check (registry plus tax ID)Platform → KYB vendorA few dollars per business; Delaware passes through $10-20
Person check by dataPlatform → vendor → bureausUnder a dollar (estimate)
eCBSVVendor or bank → SSAAbout $0.50 a check, prepaid in annual tiers from about $5,000 to $470,000
Document plus selfiePlatform → identity vendorAbout $1-2 at list price
Sanctions and PEP screeningPlatform → screening vendorCents per name; mid-market contracts roughly $20,000-330,000 a year
Transaction monitoring and case managementPlatform → vendorRoughly $25,000-220,000 a year for fintech-focused tools
Program feesFintech → sponsor bankNot public per program; The Bancorp earned about $140M in fintech fees in 2025
Analyst timePlatform → its own teamA US compliance officer earns about $80,000 a year
Penalties and remediationLicensed party → regulator; fintech pays by contractFrom thousands to billions

A year of KYB and monitoring for 1,000 businesses

Say Greenline's platform approves 1,000 businesses in year one on a sponsor bank, from 1,300 applications. Each business has about two people to check besides the company. All figures are ranges built on assumptions, rounded.

LineWhat drives itPer year
Onboarding checksKYB, people, screening, extra documents for about a fifth$10,000-28,000
Onboarding manual reviewA quarter to two-fifths of applications, half an hour to 90 minutes each$8,000-55,000
Ongoing screeningPlatform contract plus reviewing re-screen hits$12,000-66,000
Transaction monitoring and casesPlatform, 500-2,000 alerts, escalated cases, drafting reports for the bank$35,000-311,000
Fixed program costA named compliance owner the bank requires, plus audits and policy work$165,000-325,000
Total$230,000-785,000, or about $230-785 per approved business

The checks you pay for one by one are a few percent of the total, which is why I'd budget identity as headcount rather than as a price per check. People and platforms are the rest, and monitoring (ongoing screening, transaction monitoring and most of the fixed cost) is most of it. The swing factor is alerts: halving false positives on 2,000 alerts saves about $35,000. At 10,000 businesses the fixed cost spreads and the cost per business falls to roughly $80-200.

The shape depends on the business. A payfac taking 10,000 applications a month spends far more on onboarding review, where the manual review rate decides everything. And a large bank's corporate onboarding is a different product: one vendor put it at about $2,600 and three months per corporate client in 2023.

Why do false positives cost so much? Large US banks' numbers from 2017 show roughly 16 million alerts producing 640,000 reports, so about 4% of alerts led to a report. For sanctions name hits, the true-match rate rounds to zero. Most of a monitoring team's day is clearing alerts that were never going to matter. The industry total for financial-crime compliance in the US and Canada was about $61B a year in a vendor-commissioned study, and labour was the biggest part.

Who holds the power

Power here follows who can stop you onboarding. As I read it, the regulator sets the floor, the partner sets the bar, and one partner's consent order can reset the bar for everyone on that bank.

  • The sponsor bank holds the veto. It sets risk appetite, prohibited businesses, vendors, alert deadlines and exits, and it can override your decision to keep a customer. When its regulator issues an order, its rules change for every fintech on it at once: Evolve's 2024 order required the Fed's approval before any new fintech partner or product.
  • Card networks set the payfac rules, run MATCH and fine the acquirer, which fines you.
  • Regulators set the floor and reach most platforms through the bank. Licensed firms meet them directly: Block paid $80M to 48 state regulators and $40M to New York's regulator in 2025, with no bank in between.
  • Data brokers hold coverage. Whether a person with a thin credit file can be verified without a document is decided by bureau data.
  • Registries are gaining power where the state verifies at the source. Companies House stopped about 27,000 suspicious filings in 2025-26.
  • Wallet makers (Apple, Google, Samsung) decide whether a verifier can read a mobile driver's licence.
  • Applicants hold the truth and the documents, and they leave if you're slow.

How the rules work

What's written and what's enforced differ, and in 2025-2026 the US and Europe moved in opposite directions.

The US is loosening the paperwork and keeping the penalties. The ownership register shrank to foreign companies. October 2025 guidance dropped automatic 90-day reviews of continuing activity and the need to document decisions not to file a report. FinCEN's April 2026 proposal for AML programs would limit enforcement over upkeep failures to "significant or systemic" ones, and counts AI tools as evidence that a program works. An August 2025 executive order took reputation risk out of bank supervision and put exits on political grounds under scrutiny. Even so, the big penalties kept coming, as the table below shows.

Canada raised the stakes. Maximum FINTRAC penalties rose 40-fold in March 2026, and FINTRAC issued a record 35 penalty notices worth over CAD 247M in 2025-26, mostly against money services businesses.

The EU tightened. From July 10, 2027 the AMLR fixes refresh cycles (one year for high risk, five for the rest), how ownership is calculated, what data you collect on each person (including place of birth and nationality, which US rules don't ask for), and a draft standard makes a government digital ID the preferred way to verify people remotely.

October 2024

Who
TD Bank (US)
Amount
About $3.1B
What triggered it
About 92% of transaction volume never monitored, 2014-2023

October 2024

Who
Starling (UK)
Amount
About £29M
What triggered it
Screened customers against only a fraction of the UK sanctions list; onboarded high-risk customers despite a restriction

January and April 2025

Who
Block (Cash App)
Amount
$80M and $40M
What triggered it
Due diligence, monitoring and a report backlog after rapid growth

July 2025

Who
Monzo (UK)
Amount
About £21M
What triggered it
Onboarded 34,000+ high-risk customers in breach of a restriction while growing from 600,000 to 5.8 million customers

July 2025

Who
Barclays (UK)
Amount
£42M
What triggered it
Onboarding and monitoring of two clients

October 2025

Who
A payments and crypto money services business (Canada)
Amount
About CAD 177M
What triggered it
About 1,000 missed suspicious transaction reports

March 2026

Who
Canaccord Genuity
Amount
$80M
What triggered it
An under-resourced program that missed suspicious activity

April 2026

Who
A payments-heavy New York savings bank
Amount
Order, no fine
What triggered it
Payments growth without proportionate controls; alerts closed automatically

The triggers tell you more than the amounts do. Almost every case here is a program that grew faster than its monitoring, and a weak identity check on its own rarely shows up.

What mistakes cost

Mistakes here get paid for in several ways.

  • Growth. A consent order on your sponsor bank can freeze new onboarding and new products for months while the regulator approves each one.
  • Remediation. Lookbacks, re-verifying existing customers and outside consultants often cost as much as the fine, and the fintech's team does the work. I'd rank this as the costliest one, because when a monitoring program can't keep up, the fix lands on every customer at once.
  • Fraud losses. TransUnion put lenders' exposure to suspected synthetic identities on new US accounts at about $3.3B in the first half of 2025. Whoever extended the credit owns it.
  • Lost customers. Every document request loses applicants, and over-correction after an order (mass exits) hurts good customers, which since 2025 also draws regulatory attention in the US.
  • Penalties and lawsuits. From FTC penalties under INFORM to biometric class actions to billion-dollar bank cases. People are exposed too: TD's case brought prosecutions of employees, and FinCEN started paying whistleblowers up to 30% of sanctions over $1M in 2026.

AI fraud and digital IDs

My verdict as of October 2026: the AI fraud is real and growing, the regulators have moved toward cryptographic credentials, and almost nobody can present one online yet. I'd build in layers, treating the document as one weak signal among many, and get ready for signed credentials without waiting for them.

What's real

  • FinCEN's November 2024 alert. From 2023 into 2024, FinCEN saw more reports of deepfakes: AI-altered or AI-generated images on driver's licences and passports, combined with stolen or invented personal data to build synthetic identities that "successfully opened accounts" and then moved money for criminals. The detail that matters for product: most were caught on re-review after the account showed odd behaviour rather than at onboarding. FinCEN flagged third-party webcam plugins and applicants claiming "technical glitches" to dodge live checks.
  • Forgery as a service. An online service sold AI-generated ID images for $15 in early 2024, and journalists used one to pass a crypto exchange's check.
  • Injection attacks. Instead of holding a mask to the camera, the attacker replaces the camera feed with a virtual camera and plays a deepfake. Entrust, whose latest report covers over a billion verifications, says deepfake selfies rose by more than half in 2025 and are about one in five biometric fraud attempts. Vendors' percentages are measured on their own traffic, so they tell you the direction more than the size.
  • Uneven accuracy. In the US Department of Homeland Security's tests of remote identity checks, reported in 2026, only 5 of 16 selfie-to-ID systems met all its goals. For the median system, an impostor who looked similar to the real person was about 11 times more likely to be wrongly accepted than a random one.
  • Mules and takeovers. These come after onboarding. In the UK, Cifas counted 78,000 account takeover cases in 2025, almost a fifth of its database, and mule cases rose by about two-thirds in the first half of 2026.

What's not there yet

  • Mobile driver's licences. 21 states and Puerto Rico issue them, with over 8 million credentials, and about 45% of Americans live where one is available. Few states let people present them online, and the Northeast, Texas and Florida don't issue them yet.
  • The EU wallet. Every member state must offer one by December 24, 2026, and banks must accept it on request about a year later. One consultancy expects only 8 to 12 of the 27 to be ready by the end of 2026.
  • The UK. It dropped plans for a mandatory national digital ID for right-to-work checks in January 2026; digital checks are still coming, through certified private providers.
  • Losses. Onboarding fraud is a slice. The FBI logged about $21B of reported internet crime losses in 2025, and investment scams were about half of scam losses.

Where the rules moved

US

What changed
Joint FAQs from FinCEN and the bank regulators: a signed government digital credential, like an mDL, counts as government ID, in person or online
When
September 8, 2026
What it means for you
Allowed if your bank's identification program says so and you can read the credential; for private credentials, you must check the issuer verifies to your standard

US

What changed
NIST 800-63-4 adds a digital-evidence route for remote identity proofing
When
August 2025
What it means for you
A reference, not a rule; vendors will market to it

EU

What changed
AMLR: verify with an ID document or an eIDAS digital ID at "substantial" or "high"
When
July 10, 2027
What it means for you
No data-only route like the US or Canada

EU

What changed
AMLA's draft standard: digital ID first for remote checks, remote document checks as the fallback
When
Draft, 2026
What it means for you
May change before final

UK

What changed
Statutory register of certified identity providers; trust framework 1.0
When
December 2025; September 2026
What it means for you
46 providers and 64 certified services by mid-2026

Canada

What changed
Five FINTRAC methods: photo ID with authentication and face match, credit file (3+ years old), two independent sources, affiliate, reliance
When
In force
What it means for you
Newcomers fail the credit-file method; Interac's bank-login check is the local digital ID

Biometric privacy

A selfie check collects biometrics, and that has its own law. Illinois requires written consent before you collect and a published retention schedule (see Liability allocation). Texas lets only the attorney general sue, but Meta and Google settled for well over a billion dollars each. Colorado and Washington have laws too. If an applicant refuses a selfie, which business owners often do, you need another path: data checks with manual review, a document only, or a digital credential.

Questions to ask an identity vendor

  1. Which attacks was your liveness tested against: masks and printouts, or injected camera feeds too?
  2. How do you defend web capture, where injection is easiest?
  3. What are your false-reject rates by age, skin tone and camera quality, and who measured them?
  4. Can you read a mobile driver's licence or a passport chip, and in which flows?
  5. Where are images and templates stored, and for how long?

What usually goes wrong

SymptomLikely causeFirst thing to check
Business stuck in review for daysTrade name vs legal name, EIN belongs to a parent, new LLC not yet indexed, foreign parentThe match result per field, then which document would settle it
Approved company turns out to be a hijacked real businessRecent officer, agent or address change, or a reinstatement, that a data match acceptedThe registry's change history and the officer list before the change
Fraud from brand-new LLCsCompanies formed with stolen identitiesThe person's check, address type, company age, formation agent patterns
Terminated merchant back under a new companyFresh LLC with a relative as ownerMatching on people, phone, address, device and bank account, not just the entity
High-risk merchant boarded as low-riskIndustry code assigned from the application, not the websiteWebsite review at onboarding and again later
Good applicants fail the person checkThin file, name changes, newcomers, poor camerasWhich check failed, and whether a document step-up was offered
Synthetic identity passes, then busts out months laterDetails built to match bureau dataeCBSV, synthetic-identity scores, how fast details get reused across applications
Selfie check passed by a deepfakeInjected camera feed, often through web captureDevice and virtual-camera signals; mobile SDK vs web
Account taken over after a clean onboardingSIM swap, stolen credentials, social engineering of supportChanges to phone, email or payout account before the loss
Alert backlog growing every weekCustomers grew faster than the team; rules never tunedAlerts per analyst per day, and the share closed as false positives
Sanctions hit missed on a companyScreened the company but not its ownersWhether owners were screened, and aggregated under the 50% rule
Bank freezes new onboardingA consent order at the bank, or your audit findingsThe program agreement's approval clauses
Marketplace finedSellers over 200 sales and $5,000 not verified within 10 daysThe seller verification queue and the 10-day timer

Words that mean something else here

TermWhat you'd assumeWhat it means here
Good standingThe company is legitimateIts filings and state taxes are current; nothing more. A status check isn't a certificate of good standing
ActiveDoing businessIn a registry: not dissolved. From a vendor: found. On your platform: can move money
VerifiedSomeone checked itUsually a vendor matched it to a source, which may itself be self-declared. In the UK since November 2025, a verified director is a legal status
Beneficial ownerSomeone who owns a stakeIn the US, also one control person who may own nothing. UBO is industry slang for the person at the top
KYBA legal requirementAn industry term. The law says customer due diligence (US) or client identification (Canada)
KYCAn ID checkTo regulators: identity plus understanding what the customer does and why
Customer (US bank rules)Whoever opens the accountFor a business account, the business; the person signing isn't a "customer" for identification purposes
Shell companyA fraudA company with no operations, often legal. In money-laundering talk: one used to hide owners
Registered agentThe company's officeThe address for legal papers, often shared by thousands of companies
High riskOne listA bank's customer rating, Visa's high-brand-risk categories or MATCH's terminated merchants: three lists with three owners
LivenessProof a person is thereUsually resistance to masks and printouts; faked camera feeds are a separate test
Match rateHow often checks succeedA file was found, the details agreed, or a yes from SSA: three different numbers
Digital IDA government credentialA scan of a plastic card, a vendor profile, a bank login or a signed credential; only the last counts as a digital credential under the 2026 US FAQs
False positiveA mistakeIn screening: a name hit that's someone else. In monitoring: an alert that led to no report, though it may have been worth a look
Perpetual KYCA legal standardA vendor term for reviewing on events instead of on a calendar
PEPAny politicianUS: senior foreign political figures. Canada and the EU: domestic ones too

What surprised me

Placeholders in your voice, drafted from the earlier guides. Rewrite each with your own moment.

"KYB is a lookup." In the telco guide, the brand check for business texting was an exact match on EIN and legal name, and typos failed it. KYB looks like that with more fields, but a hijacked company passes the match perfectly. The match tells you the record exists, and the change history tells you whether to trust it.

"Ownership is public data." In the US there's no register to query for US companies, and since August 2026 there won't be one. The platform builds the ownership graph itself, dates it and keeps it current.

"The regulator is my counterparty." In spend management I learned fintechs rent a sponsor bank's charter. They also inherit its exam findings: one bank's consent order changed the onboarding rules for every fintech on it in a week.

"Approval is the finish line." I designed onboarding as the product. The money and the failures are in what comes after: alerts, reviews, refreshes, a team sized for last year's customers.

"A selfie is proof." A certified liveness check is certified against masks and printouts. A faked camera feed is a different attack, and the document itself is now the weakest signal in the stack.

Sources

Undated entries were read on October 3, 2026; "search result" means seen only as a search snippet.

US rules and regulators

Canada

UK and EU

Card networks and identifiers

Research and surveys

Company results and releases (the main players)

Law firms and press

Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.