Field GuideLast reviewed October 2026
Identity and trust: KYB, KYC and ongoing monitoring
Who a platform must verify before a business can move money, how KYB, KYC and ongoing monitoring work, why your sponsor bank or card network sets the real bar, and who pays when a fake company, a deepfake or a missed alert gets through.
The industry on one page
A landscaping company in Texas, Greenline LLC, wants to take card payments through the scheduling software it already uses. It was formed in Delaware, has two owners and would like its first payout on Friday. Before the software company says yes, it needs to know whether Greenline is a real business that's allowed to do what it says, whether the people behind it are who they claim to be, and, once it's live, whether its money keeps behaving like a landscaping company's.
Each of those is a layer of this industry:
- KYB (know your business), the entity: does the company exist, is it in good standing, who owns and controls it, what does it actually do, and is that business allowed on your platform.
- KYC (know your customer) and UBO checks, the people: the person applying, the people who sign, the ultimate beneficial owners (the humans at the top of the ownership chain, UBOs for short) and whoever controls the company.
- KYT (know your transaction) and ongoing monitoring, the behaviour: transaction monitoring, re-screening against sanctions lists and the news, reviews on a schedule and when something changes, and reporting suspicious activity.
The business and its owners apply to your platform. You check them through verification vendors, which query the data sources: business registries, credit bureaus and other data brokers. Your sponsor bank (the licensed bank that holds the money for a fintech) or the card network sets the bar you must meet. Regulators examine the bank, which is how their expectations reach you. Suspicious activity gets reported to FinCEN in the US or FINTRAC in Canada, by you if you hold your own licence and by your bank if you don't.
What I'd want a new PM in this space to take away:
- Thin data: KYB is mostly a data problem, and in my experience the data is thin more often than contradictory. Registries rarely disagree; they just say very little. A US state registry is a filing office: in most states it records what people file and can't check or reject it. It tells you a company exists, rarely who owns it, and almost never verifies anyone. Since 2025 the federal ownership database doesn't cover US companies either, so the platform builds its own ownership graph from what the applicant declares and has to keep it current. A clean match also proves less than it seems, because a hijacked company, where a fraudster has filed changes to a real business's record, matches the registry perfectly.
- The bank's rulebook: on a sponsor bank, the bank's and the network's rules are the ones you actually work to. Most platforms that onboard businesses aren't banks. The legal duty to verify customers and report suspicious activity sits with the bank, which pushes it down to you by contract, and with the card networks' rules for payment facilitators. The regulator reaches you through the bank's consent order (a formal enforcement agreement). This is weaker for licensed money transmitters and for UK and EU firms, which regulators fine directly.
- Monitoring: onboarding is a snapshot, and the big failures have been in monitoring. The largest penalties of 2024 to 2026 were for monitoring that wasn't switched on, alert backlogs and screening against part of a sanctions list. Growth tends to break monitoring before anything else, because onboarding scales with vendors and monitoring scales with people. People also cost more than checks: in the worked example in How the money moves, the data you pay for per check is a few percent of the yearly cost.
- AI fraud and digital IDs: deepfake selfies, faked camera feeds and AI-made ID images sold for $15 are real; FinCEN warned banks about them in November 2024. Trust is moving toward layered signals and digital IDs, and in September 2026 US regulators said a signed digital credential, such as a mobile driver's licence, counts as government ID for opening an account. Documents plus a selfie, backed by bureau data, are still the base of almost every check, though. More in AI fraud and digital IDs.
So an identity program ends up as a data pipeline that never finishes, run to a bar someone else sets, where the expensive part starts after approval. It's hard for a few reasons. The truth sits in several places: existence in a registry, the tax ID at the IRS, ownership with the applicant, behaviour in your own ledger. Every country answers "who owns this company?" differently, and the US answer changed in 2025. And you get judged on what you missed, often years later, while the good customers you slowed down rarely come up.
Sponsor banks and the 2024 Synapse collapse are in B2B payments: spend management; sanctions, the travel rule and FINTRAC's penalties from the payments side are in B2B payments: cross-border payouts; brand vetting for business texting, a cousin of KYB, is in Phone numbers, messaging and voice.
The main players
The diagram shows roles; the mental map needs names. These are the companies and agencies I'd want to recognize in week one, layer by layer, in no particular order.
Identity verification
- What they do
- Check a person's ID document, selfie and liveness; orchestrate data checks
- Main players
- Entrust (Onfido), Persona, Veriff, Socure, Incode, GBG
- What they control
- The capture flow, the pass rate, what counts as a match
KYB and business data
- What they do
- Pull registries, normalize company records, map ownership
- Main players
- Moody's (Orbis), Dun & Bradstreet, Middesk, Trulioo, Kyckr, Baselayer
- What they control
- Coverage, freshness, how entities get matched
Credit bureaus and risk data
- What they do
- Confirm a person's details against records; score fraud risk from phone, device and behaviour
- Main players
- Experian, TransUnion, LexisNexis Risk Solutions, BioCatch, Prove
- What they control
- Whether someone with a thin file can be verified without a document
Sanctions and PEP data
- What they do
- Keep the lists of sanctioned people, politically exposed people and bad news
- Main players
- LSEG (World-Check), LexisNexis Risk Solutions, Moody's, ComplyAdvantage
- What they control
- List coverage and how many false hits you review
Transaction monitoring and case management
- What they do
- Raise alerts on behaviour, hold the investigation record
- Main players
- NICE Actimize, Quantexa, Hawk, Sardine, Unit21
- What they control
- Rules, models, the audit trail an examiner reads
Sponsor banks and card networks
- What they do
- Hold the licence and the money; write the onboarding rules
- Main players
- The Bancorp, Coastal Community Bank, Lead Bank; Visa, Mastercard
- What they control
- Risk appetite, prohibited lists, approval of every program
Registries and government
- What they do
- Record that companies exist; confirm tax IDs and Social Security numbers
- Main players
- Delaware and other Secretaries of State, IRS, SSA, Corporations Canada, Companies House, GLEIF
- What they control
- Legal existence, data access and fees
How they make money, and who's moving:
- Identity verification vendors charge per verification, a dollar or two at list price. The fast growers are private: Veriff says its revenue passed $100M and doubled in 2025, and Persona raised at a $2B valuation. The public incumbents, Mitek and GBG, grew by low single digits. Digital ID networks like ID.me and CLEAR grow alongside.
- KYB and business-data providers sell annual platforms plus a fee per lookup. Moody's KYC revenue grew by about a fifth in 2025, and Clearlake took Dun & Bradstreet private for $7.7B. The specialists report faster growth, but their figures are their own.
- Bureaus and risk-data companies earn on every check. LexisNexis Risk Solutions grew 8% in 2025, led by financial crime and identity. Buyers keep paying for signals: a private equity firm bought most of BioCatch at a $1.3B value.
- Sanctions data is a subscription business: screening is almost four-fifths of LSEG's risk intelligence revenue. ComplyAdvantage is the best-known fast grower.
- Transaction monitoring sells annual platforms priced by volume. NICE Actimize, the large-bank incumbent, made about $450M in 2024, and NICE was in talks to sell it in September 2026. Graph and AI challengers like Quantexa and Sardine are growing fast.
- Sponsor banks charge fintechs program fees and earn on deposits and card fees. The Bancorp's fintech fees grew by about a fifth in 2025; Coastal took on deposits from Evolve, a bank under a 2024 Fed order.
- Registries charge filing and search fees: Companies House took in about £240M in 2025-26, and Delaware charges $10-20 per online status check.
As of October 2026. Players change through acquisitions and funding rounds, so treat this as a map to check before you rely on it.
When Greenline signs up through its scheduling software, a KYB vendor like Middesk pulls its Delaware record and matches its EIN with the IRS. An identity vendor like Persona checks both owners, leaning on bureau data from a company like Experian. A screening provider like World-Check runs every name against sanctions lists. The sponsor bank, The Bancorp for example, set every threshold in that flow and audits a sample. After go-live a monitoring tool like Unit21 watches the payouts. Greenline signs one contract, and six or seven companies have a say in whether it gets paid.
How a business gets approved, step by step
Follow Greenline from application to monitoring. Most applications that stall go to manual review for documents. Approval is a snapshot: the checks continue for as long as the account is live.
- Applied: legal name and trade names (a DBA, "doing business as"), entity type, state and date of formation, registration number, EIN (the US federal tax ID), addresses, website, what it sells, expected volume, the payout bank account, and the people: owners of 25% or more plus one person who controls the company, each with name, date of birth, address and ID number. Breaks: the applicant types the trade name where the legal name should go.
- Business verified: find the right entity in the Delaware registry, and in Texas, where it's registered to operate. Check it's active and in good standing, look at recent changes, match the EIN to the legal name, classify the address and website, assign an industry code, check the prohibited lists, and build the ownership tree. Breaks: a name mismatch, an EIN that belongs to a parent company, a two-week-old LLC the vendor's copy of the registry hasn't caught yet, a foreign parent. These go to manual review, which usually means asking for documents: the articles of organization, the IRS letter confirming the EIN, an operating agreement, a bank statement.
- People verified: each owner and the control person, by data checks first and a document plus selfie when the data isn't enough; sanctions and PEP screening (politically exposed persons) on the company and every person. Breaks: a thin credit file, an owner abroad with no Social Security number, an owner who won't take a selfie.
- Approved, with limits: a risk rating and usually some limits: a volume cap, a rolling reserve (a share of each payout held back for a while), a delay on early payouts. Breaks: nobody revisits the limits.
- Monitored, for as long as it's live: re-screening on every list update, transaction monitoring against what Greenline said it would do, a review when owners, bank accounts or volumes change, and a refresh on a schedule set by risk. Breaks: the expected activity captured at onboarding was wrong, so every alert is noise.
Two exits sit off that path. Manual review sends a case back to the main path once the documents arrive, or to a decline. Offboarding comes from monitoring: restrict the account, close it, return the money, file a suspicious activity report if there's reason to suspect something, and keep the records for five years.
Vendors say older KYB setups send 30-70% of applications to a human, and every document round trip loses applicants, so most stuck applications are sitting in manual review waiting on a document. The cost after approval is bigger still: in the worked example in How the money moves, ongoing monitoring and review are most of what the program costs in a year. That holds for a typical platform; a high-volume payment facilitator can spend more on review at onboarding instead.
The checks compared
US state registry lookup
- What it proves
- The company exists, and its status
- Rough cost (Oct 2026)
- Cents to a few dollars; Delaware charges $10-20 a status check
- Good customers it fails
- Sole proprietors (often not registered), brand-new companies
- How fraud beats it
- A hijacked or freshly formed company matches perfectly
EIN and name match (IRS)
- What it proves
- The tax ID belongs to that legal name
- Rough cost (Oct 2026)
- Often bundled; only companies that file 1099s can ask the IRS directly
- Good customers it fails
- Trade names, recent name changes
- How fraud beats it
- A real EIN paired with its real name
Ownership check
- What it proves
- Who owns 25% or more, and who controls
- Rough cost (Oct 2026)
- Mostly analyst time
- Good customers it fails
- Holding companies, funds, foreign parents
- How fraud beats it
- Nominees, or stakes kept just under the threshold
Bureau or database match
- What it proves
- Name, date of birth, SSN and address appear together in records
- Rough cost (Oct 2026)
- Roughly $0.20-1 (estimate)
- Good customers it fails
- Thin files, newcomers, people who moved or changed name
- How fraud beats it
- Synthetic identities built to match
SSA's eCBSV
- What it proves
- SSN, name and date of birth match Social Security's records
- Rough cost (Oct 2026)
- About $0.50, prepaid in annual tiers
- Good customers it fails
- Typos and name changes (most mismatches)
- How fraud beats it
- A stolen real identity passes
Phone, email and device signals
- What it proves
- Phone tenure, email age, device reputation, human or bot
- Rough cost (Oct 2026)
- Cents
- Good customers it fails
- Prepaid phones, new devices, privacy browsers
- How fraud beats it
- SIM swaps, device farms, aged emails bought in bulk
Document plus selfie and liveness
- What it proves
- The person matches a genuine-looking ID and is really there
- Rough cost (Oct 2026)
- About $1-2 at list price
- Good customers it fails
- Poor cameras, worn cards, some faces more than others
- How fraud beats it
- Deepfakes fed through a virtual camera; AI-made documents
Passport chip read
- What it proves
- Data signed by the issuing government
- Rough cost (Oct 2026)
- More (needs a mobile SDK)
- Good customers it fails
- No NFC phone, or no chip in the document
- How fraud beats it
- Very hard to forge; taking over the account later
Mobile driver's licence or other signed credential
- What it proves
- Data signed by the issuer and bound to a device
- Rough cost (Oct 2026)
- Low per check
- Good customers it fails
- Most people can't present one online yet
- How fraud beats it
- Taking over the phone or wallet
Bank login (Interac in Canada)
- What it proves
- A bank already verified this person
- Rough cost (Oct 2026)
- A fee per check
- Good customers it fails
- No eligible bank account
- How fraud beats it
- Taking over the bank login
List prices come from vendors' public pages; enterprise deals run lower, and the database and signal prices are my estimates, since bureaus don't publish theirs.
Then the question every business applicant raises: who counts as an owner, and where can you check it?
Owner threshold
- US
- 25% or more, plus one control person
- Canada
- 25% or more of shares or votes, or control
- UK
- More than 25%, or significant control
- EU
- 25% or more from July 10, 2027; can drop to 15% for higher-risk types
Public register
- US
- None for US companies; FinCEN's database now covers only about 28,000 foreign companies
- Canada
- Federal companies only, public since January 2024; Quebec has its own
- UK
- Yes, the PSC register (people with significant control)
- EU
- National registers, closed to the general public since a 2022 court ruling
Who verifies
- US
- The bank, which pushes it down to you
- Canada
- You confirm by a different method; report mismatches on high-risk federal companies within 30 days
- UK
- Companies House verifies directors' and owners' identity since November 2025
- EU
- You; registers gain powers to check
Next change
- US
- FinCEN rewrite of the ownership rule, under White House review since September 17, 2026
- Canada
- British Columbia's register (launch unconfirmed)
- UK
- Identity checks mandatory for everyone after November 17, 2026
- EU
- AMLR applies July 10, 2027; EU Company Certificate from July 2028
More on how the four fit together in Regulatory layering.
Choosing what to check: five questions
- Who holds the legal duty? A bank, a licensed money transmitter, a marketplace under the INFORM Consumers Act, or nobody, because you're a B2B software company checking for fraud reasons. That sets your floor, and if there's a bank, its program sets the bar.
- How fast can money leave? Instant payouts and instant credit lines put the loss right after onboarding, so check more up front. A product where money moves slowly can approve with limits and lean on monitoring.
- Who are your applicants? Most US small businesses have no employees (about 30 million of 36 million), and many are sole proprietors with no registry record at all. For them the work is the person and what the business really does. The ownership graph starts to matter with mid-market and cross-border customers.
- Where are they from? It depends on where they were formed and where the owners live. A Delaware check costs money per lookup, a UK company is free to query, EU ownership registers are mostly closed to you, and an owner abroad has no SSN and no US credit file.
- What must you prove? Your bank or network will ask. Sponsor banks and auditors want to see, for every field, which source it came from and when. If you can't show that, it doesn't count as checked.
My defaults: for people, data checks come first and a document plus selfie is the step-up when the data isn't enough. For businesses I'd pull the registry record, the EIN match and the change history, since a match on its own says little. Store the ownership graph with dates and sources. Approve with limits and relax them on good behaviour. Subscribe to registry changes where you can. Size the monitoring team for next year's volume, and spend on what happens after approval at least as carefully as on the front door.
The primitives
01
Entity & identity
What is the unit of record, and how do we know it is the same one?
Products tend to blur the legal entity (Greenline LLC), the account on your platform (Greenline's two locations, each with its own payouts) and the person (an owner who also owns a second company you onboarded last year).
Keep them as separate records. One entity can have many accounts. One person can own several entities, sign for others and be a consumer customer too. When a fraud team asks "what else is this person connected to?", that link is the answer.
Identifiers are local, and none covers every small business:
| Identifier | Who issues it | Where it falls short |
|---|---|---|
| State file number | Each US Secretary of State | One per state; a company registered in four states has four |
| EIN | IRS | Not public; a sole proprietor may use their SSN instead |
| Corporation number and Business Number | Corporations Canada or a province; CRA | Federal and provincial registers are separate |
| Company number (CRN) | Companies House | UK only |
| EU register number (EUID) | National registers | Ownership data sits in a separate register |
| LEI | GLEIF, through local issuers | About 3 million worldwide; rare among small businesses |
| D-U-N-S | Dun & Bradstreet | Proprietary |
An ownership link needs more than a percentage. Give each one a type (shares, votes, a right to appoint the board, a trust role, a nominee), a date and a source. Thresholds differ by a word: the US, Canada and the EU say 25% "or more"; the UK says "more than" 25%. An owner with exactly 25% is in scope in Toronto and out of scope in London.
On the people side, synthetic identities and account takeover both break the model. A synthetic identity breaks the assumption that a set of details belongs to one real person. Account takeover breaks the assumption that the person logged in is the person you verified.
02
State & lifecycle
What states exist, and what moves an entity between them?
One customer has a state in the registry, on your platform and in your alert queue, and these drift apart unless you connect them.
- The registry's: formed, active and in good standing, delinquent (a missed annual report or franchise tax), administratively dissolved or revoked, reinstated within a window each state sets, or gone.
- Your platform's: started, submitted, auto-verified or pending review or documents requested, approved (with limits) or declined, active, under review, restricted, offboarded. Add states nobody plans for: frozen for sanctions, and "keep open", when law enforcement asks you not to close an account.
- The alerts': new, in triage, escalated, case open, report filed, closed with no action.
A person's verification has a lifecycle too. Documents expire, addresses change, and in the EU from July 2027 customer information must be refreshed at least yearly for high-risk customers and every five years for the rest. Assurance also comes in levels.
If Greenline misses its Delaware annual report in March, the registry moves it to delinquent while your platform still says "active". Nothing is wrong yet, but if a fraudster later reinstates the company and changes its officers, you'd want to have seen both events, so subscribe to the registry's state changes where you can.
Watch one more state: "closed automatically". A US regulator's April 2026 order against a payments-heavy bank criticized alerts that closed themselves. No alert should close without a human or a validated model giving a reason.
03
System of record & ledger
Who owns the truth, and how do systems reconcile?
Every fact has an owner, and the platform owns fewer than its dashboard suggests.
| Fact | System of record |
|---|---|
| The company exists, and its status | The registry; a monopoly in each state or country |
| Tax ID belongs to the name | IRS or CRA; not public |
| Who owns it (US) | Nobody public: the bank's or platform's own due-diligence record |
| Who owns it (Canada) | The company's own register; for federal companies, a copy at Corporations Canada |
| Who owns it (UK) | The PSC register at Companies House |
| Who owns it (EU) | National ownership registers |
| What you checked, when, and the result | Your KYB and KYC record |
| Who reviewed an alert, and why they closed it | Your case-management system |
| Document images and biometric templates | Usually the verification vendor, on its own retention schedule |
Your KYB record is a derived record. For each field it should say where the value came from, when you pulled it and whether it matched. That provenance is what sponsor banks and auditors ask for, and when an examiner asks why you approved someone, the source and date of each verified fact is your answer.
The case-management system is the record a regulator reads: who saw what, when, and why they closed it. Keep verification records five years in the US and Canada. A biometric law like Illinois's wants templates destroyed on a schedule, so the usual answer is to keep the results and delete the templates.
For banking-as-a-service the ledger is a record of its own. When Synapse, a middleware company between fintechs and banks, collapsed in 2024, its records and the banks' didn't reconcile, and end users were left short by tens of millions of dollars.
04
Rules & policy
What logic decides outcomes, and who can change it?
Law is only one of the kinds of rules that shape every decision.
- Law: the bank rules on customer identification and beneficial ownership in the US, Canada's PCMLTFR, the UK's money laundering regulations, the EU's AMLR from July 2027, and the INFORM Consumers Act for marketplaces.
- Network rules: Visa requires a payment facilitator (a payfac, a company that signs up merchants under its own card acceptance account) to check every applicant against its list of terminated merchants, and bans some industries outright unless the payfac is registered for high risk. Mastercard requires a check against MATCH, its list of terminated merchants, before onboarding.
- Your bank's policy: a prohibited and restricted business list, how deep KYB goes, which vendors you may use, how fast alerts must be worked, how often customers get refreshed.
- Your own policy: risk appetite and auto-approval thresholds.
Many hard calls aren't data questions at all. What counts as "control"? Do you onboard a company that's delinquent but can cure it? Is a registered agent's address, a virtual office or a UPS store acceptable? How far up a foreign ownership chain do you go? Write those calls down as policy, separate from the data, because that's where two platforms with the same vendors end up differing.
Visa's high-brand-risk list is a set of merchant category codes plus activities such as cyberlockers, skill games like daily fantasy sports, and buying crypto. A marketplace may not sign those merchants at all; only payfacs registered for high risk can.
Thresholds trade false accepts against false rejects. You tune them; your sponsor bank approves them.
05
Effective dating
Which version of the rule applied at that moment?
Ownership changes over time, lists change daily, and the rules changed a lot in 2025 and 2026.
| Change | Effective | Status (Oct 2026) |
|---|---|---|
| US banks may collect only the last four SSN digits and get the rest from a third party | June 27, 2025 | Live, optional |
| FinCEN's guidance easing suspicious activity reporting | October 9, 2025 | Live |
| Canada: report ownership mismatches on high-risk federal companies | October 1, 2025 | Live |
| UK: identity checks for new directors and owners | November 18, 2025 | Live; transition ends November 17, 2026 |
| US: banks re-verify a company's owners only at the first account, or when in doubt | February 13, 2026 | Live |
| Canada: maximum FINTRAC penalties 40 times higher | March 26, 2026 | Live |
| FinCEN's new AML program rule | Proposed April 2026 | No final rule yet |
| US ownership reporting ends for US companies (final rule) | August 14, 2026 | Live |
| Digital credentials accepted as ID for account opening (US) | September 8, 2026 | Live |
| EU digital identity wallets due in every member state | December 24, 2026 | Upcoming; many will be late |
| EU AMLR and its ownership and refresh rules | July 10, 2027 | Upcoming |
| EU banks must accept the wallet on request | Around December 2027 | Upcoming |
| EU Company Certificate | July 31, 2028 | Upcoming |
Inside your data, store dates on ownership, list versions and clocks. Canada's register records when someone became and stopped being a significant owner, and your graph needs valid-from and valid-to dates too. A sanctions screen is only as good as the list version it ran against. A US suspicious activity report is due 30 days from initial detection of the activity, and examiners argue about that detection date.
Picture Greenline selling 30% of itself to a new investor in May. If your graph only holds the current owners, you can't answer the question an examiner will ask in December: who owned it when you paid out in June? Examiners keep coming back to what you knew and when, so date every ownership link, list version and review.
06
Interfaces & standards
What format and protocol do counterparties speak?
The standards are a patchwork, and most of them sit behind a vendor's API.
- Registries. Companies House offers a free API (600 requests every five minutes) and a streaming API that pushes changes as they happen; it's the cheapest major registry to build on. Corporations Canada has an API and open data. Most US states offer web search pages, some bulk data and per-lookup fees, so vendors scrape or license.
- Tax IDs. IRS TIN Matching takes up to 25 pairs at once interactively or 100,000 in bulk, but only for payers who file 1099s.
- SSNs. SSA's eCBSV answers yes or no on SSN, name and date of birth, with the person's consent.
- Documents. ICAO 9303 for passports (the machine-readable zone and the chip), the barcode on the back of US driver's licences, ISO/IEC 18013-5 and 18013-7 for mobile driver's licences in person and online.
- Liveness. ISO/IEC 30107-3 tests presentation attacks: a mask, a printout or a screen held to the camera. Injection attacks, where a fake video feed replaces the camera, are a separate problem with a newer standard. Web capture is easier to inject into than a mobile SDK. A "certified liveness" check usually means it resists masks and printouts and says nothing about faked camera feeds, so ask which attacks it was tested against.
- Identity levels. NIST SP 800-63-4 (August 2025) for US government, not binding on fintechs but marketed to; eIDAS's "substantial" and "high" in the EU.
- Codes. MCC (ISO 18245, the card networks' merchant category) and NAICS (the government's industry codes) don't map one to one; a new NAICS version is proposed for data from January 2027.
07
Networks & counterparties
Who sits between us and the outcome, and what do they want?
A business approval runs through a chain, and the platform sits in the middle of it.
| Party | What they control |
|---|---|
| Registries and tax agencies | Whether a company exists; who may check a tax ID |
| Data aggregators | Coverage, freshness and how records get matched |
| KYB and identity platforms | The workflow, decision rules and audit trail |
| Bureaus, SSA, phone carriers through aggregators | Whether a person's details can be confirmed without a document |
| Screening and monitoring vendors | List coverage, alert volume |
| Sponsor bank or acquirer | Policy, vendor approval, the right to stop new onboarding |
| Card networks | Merchant rules, MATCH, fines passed down to the payfac |
| Regulators and intelligence units | Rules, penalties, requests about specific people |
| Consortiums | Shared fraud data: Early Warning in the US, Cifas in the UK |
| Credential issuers and wallet makers | Who gets a digital ID, and whether apps can read it |
Information flows through the chain too. FinCEN sends banks lists of law-enforcement subjects every two weeks (a 314(a) request), and banks answer only with matches. Institutions with an AML program requirement can share information with each other under 314(b). A platform without one can't join, so if you aren't a regulated institution yourself, your bank is both your rule-setter and your only window into what other institutions know.
08
Regulatory layering
Jurisdiction × activity × entity type: is it a license or a certification?
Separate the layers, because each binds a different party and has a different enforcer.
Law
- What it says
- US bank rules on identifying customers and owners; Canada's PCMLTFR; UK money laundering regulations and company law; EU AMLR
- Binds
- Banks, licensed money transmitters, other regulated firms
- Enforced by
- Regulators, through penalties and orders
Law aimed at platforms
- What it says
- The INFORM Consumers Act
- Binds
- Online marketplaces
- Enforced by
- The FTC, up to $53,088 a violation
Network rules
- What it says
- Visa and Mastercard payfac and merchant rules
- Binds
- Acquirers, which pass them to payfacs
- Enforced by
- Fines and assessments
Partner policy
- What it says
- The sponsor bank's program agreement and risk appetite
- Binds
- The fintech
- Enforced by
- Contract, onboarding freezes, termination
Registry practice
- What it says
- What each registry checks before accepting a filing
- Binds
- Filers
- Enforced by
- Registries, now more strictly in the UK
Which layer reaches you depends on what you are. For most US platforms on a sponsor bank, the one that binds you day to day is the contract with the bank. A payfac gets its KYB requirements from the network and its bank; the bank rules themselves bind the bank. A marketplace has INFORM directly: once a seller makes 200 sales and $5,000 in a year, you have 10 days to collect and verify its bank account, tax ID and contact details, and sellers above $20,000 must show their identity to buyers. A B2B software company that doesn't move money may have no legal KYB duty at all, and checks for fraud and trust.
Beneficial ownership is where the four jurisdictions split most:
- US. The Corporate Transparency Act was meant to give FinCEN a register of every company's owners. An interim rule in March 2025 and a final rule effective August 14, 2026 cut it to foreign companies: about 28,000 instead of the 32.6 million FinCEN once expected. FinCEN is deleting the data it had on US people. Banks still collect owners under their own rule, so the change mattered less to platforms than the headlines suggested: their ownership checks always came from the bank.
- Canada. Federal companies must file their significant owners with Corporations Canada, publicly since January 2024. Most Canadian companies are incorporated in a province instead, and only Quebec has a public register of its own. Since October 1, 2025, firms that report to FINTRAC must flag mismatches on high-risk federal companies within 30 days.
- UK. The register of people with significant control has been public for years. Since November 18, 2025 Companies House checks the identity of directors and owners itself. Between 6 and 7 million people have to verify by November 17, 2026, and by the end of June just over half of directors had.
- EU. In 2022 the EU's top court struck down public access to ownership registers on privacy grounds, and several countries closed theirs. The 2024 directive reopens them to people with a "legitimate interest". From July 10, 2027 the AMLR sets one method across the EU: multiply percentages down each chain of ownership, add them across chains, and count control by other means.
09
Exceptions & reversals
What goes wrong, and how is it undone?
Most of the work in this team lives in exceptions, and several of them run on someone else's clock. The restrict, review, close and report paths are where examiners look and where good customers get hurt, so it pays to design them before the happy path.
| Exception | The way back | Clock |
|---|---|---|
| Name or EIN mismatch at onboarding | Ask for documents; manual review | Days per round trip |
| Fraudulent filing on a real company's registry record | Some states can now mark or reject it; in others, a court order | Weeks to months |
| Merchant listed on MATCH | Only the acquirer that listed it can remove it | Its timeline |
| Person can't be verified (US bank rule) | Restrict the account, then close it after attempts fail; consider a suspicious activity report | Set by the bank's procedures |
| Sanctions false positive | Clear it with date of birth, nationality and address; unfreeze; apologize | Hours to days |
| Sanctions true match | Block or reject; report to OFAC within 10 business days | Unblocked only by an OFAC licence or delisting |
| 314(a) match | Answer FinCEN within two weeks; a match alone isn't a reason to close | Two weeks |
| Law enforcement "keep open" letter | Keep an account you'd otherwise close | Until the letter lapses |
| Ownership mismatch, high-risk federal company (Canada) | Report to Corporations Canada | 30 days |
| Wrongful offboarding | Reinstate; since August 2025 US exits draw scrutiny for political or reputational reasons | Weeks |
| Regulator-ordered lookback | Re-review a past period and file the reports you missed | Months, with consultants |
Lookbacks are the expensive one. The Fed's 2024 order against Evolve Bank & Trust required a review of its fintech partners' wires over six months for missed reports; the FDIC told Sutton Bank to re-run identity checks on every prepaid customer since mid-2020. If your bank gets one, your operations team does the work.
A fraudster can reinstate a dissolved company, name themselves an officer and apply to your platform, and the registry match will be perfect. The way back starts with the victim business asking the state to fix the record, which in some states needs a court.
10
Liability allocation
When it fails, who pays?
The regulator fines the licensed party, which pushes the cost down by contract until it reaches someone who can't push further.
| Failure | Who pays | How |
|---|---|---|
| Customer identification or due-diligence failure | The bank, then its fintech | Penalties and consent orders on the bank; indemnities, remediation and freezes for the fintech |
| Merchant fraud at a payfac | The acquirer to the network, then the payfac | Network rules; contract |
| Wrong industry boarded (a high-risk merchant as low-risk) | The acquirer, then the payfac | Network assessments |
| Marketplace skips seller verification | The marketplace | FTC civil penalties; Temu paid $2M in the first case, in 2025 |
| Synthetic identity becomes a bust-out (maxing out credit, then vanishing) | Whoever extended the credit | Often booked as a credit loss, not fraud |
| Deepfake-opened account used as a mule (an account that moves stolen money) | US: mostly the scam victim. UK: sending and receiving payment firms, 50/50 | UK reimbursement rules since October 2024 |
| Account takeover | Consumer accounts: the institution. Business accounts: usually the business | Reg E for consumers; contract for businesses |
| Biometrics collected without consent | The platform and its identity vendor | Illinois's BIPA lets people sue; Texas's law lets the attorney general |
| Bad data from a registry or vendor | Whoever relied on it | Registries don't vouch for filings; vendor contracts disclaim accuracy |
| Sanctions breach | The US person who processed it | Strict liability; contracts move the cost, not the liability |
Illinois's biometric law is the one people underestimate: $1,000 per negligent violation and $5,000 per intentional one, with a right to sue. Since a 2024 amendment, repeated scans of one person count once, but class sizes still make it costly: Onfido settled for $28.5M. Financial institutions are exempt, and courts have extended that to some of their vendors; a marketplace or gig platform doesn't get the shield.
If Greenline is really a front and $80,000 of stolen card payments flow through it before you catch on, the cardholders' banks charge the payments back, the acquirer collects from you, and you can't collect from a company that's gone. Every relaxed setting (auto-approval, instant payouts, skipped selfies) is also a decision about who absorbs that kind of loss, and it belongs in the spec and the contract.
What's different here
How the money moves
The platform pays for almost everything. Vendors charge per check, per profile or per year; the sponsor bank charges program fees on top and keeps a veto; the customer pays in time, which shows up as churn; and regulators charge for failure.
| Flow | Who pays whom | Rough amount (Oct 2026) |
|---|---|---|
| KYB check (registry plus tax ID) | Platform → KYB vendor | A few dollars per business; Delaware passes through $10-20 |
| Person check by data | Platform → vendor → bureaus | Under a dollar (estimate) |
| eCBSV | Vendor or bank → SSA | About $0.50 a check, prepaid in annual tiers from about $5,000 to $470,000 |
| Document plus selfie | Platform → identity vendor | About $1-2 at list price |
| Sanctions and PEP screening | Platform → screening vendor | Cents per name; mid-market contracts roughly $20,000-330,000 a year |
| Transaction monitoring and case management | Platform → vendor | Roughly $25,000-220,000 a year for fintech-focused tools |
| Program fees | Fintech → sponsor bank | Not public per program; The Bancorp earned about $140M in fintech fees in 2025 |
| Analyst time | Platform → its own team | A US compliance officer earns about $80,000 a year |
| Penalties and remediation | Licensed party → regulator; fintech pays by contract | From thousands to billions |
A year of KYB and monitoring for 1,000 businesses
Say Greenline's platform approves 1,000 businesses in year one on a sponsor bank, from 1,300 applications. Each business has about two people to check besides the company. All figures are ranges built on assumptions, rounded.
| Line | What drives it | Per year |
|---|---|---|
| Onboarding checks | KYB, people, screening, extra documents for about a fifth | $10,000-28,000 |
| Onboarding manual review | A quarter to two-fifths of applications, half an hour to 90 minutes each | $8,000-55,000 |
| Ongoing screening | Platform contract plus reviewing re-screen hits | $12,000-66,000 |
| Transaction monitoring and cases | Platform, 500-2,000 alerts, escalated cases, drafting reports for the bank | $35,000-311,000 |
| Fixed program cost | A named compliance owner the bank requires, plus audits and policy work | $165,000-325,000 |
| Total | $230,000-785,000, or about $230-785 per approved business |
The checks you pay for one by one are a few percent of the total, which is why I'd budget identity as headcount rather than as a price per check. People and platforms are the rest, and monitoring (ongoing screening, transaction monitoring and most of the fixed cost) is most of it. The swing factor is alerts: halving false positives on 2,000 alerts saves about $35,000. At 10,000 businesses the fixed cost spreads and the cost per business falls to roughly $80-200.
The shape depends on the business. A payfac taking 10,000 applications a month spends far more on onboarding review, where the manual review rate decides everything. And a large bank's corporate onboarding is a different product: one vendor put it at about $2,600 and three months per corporate client in 2023.
Why do false positives cost so much? Large US banks' numbers from 2017 show roughly 16 million alerts producing 640,000 reports, so about 4% of alerts led to a report. For sanctions name hits, the true-match rate rounds to zero. Most of a monitoring team's day is clearing alerts that were never going to matter. The industry total for financial-crime compliance in the US and Canada was about $61B a year in a vendor-commissioned study, and labour was the biggest part.
Who holds the power
Power here follows who can stop you onboarding. As I read it, the regulator sets the floor, the partner sets the bar, and one partner's consent order can reset the bar for everyone on that bank.
- The sponsor bank holds the veto. It sets risk appetite, prohibited businesses, vendors, alert deadlines and exits, and it can override your decision to keep a customer. When its regulator issues an order, its rules change for every fintech on it at once: Evolve's 2024 order required the Fed's approval before any new fintech partner or product.
- Card networks set the payfac rules, run MATCH and fine the acquirer, which fines you.
- Regulators set the floor and reach most platforms through the bank. Licensed firms meet them directly: Block paid $80M to 48 state regulators and $40M to New York's regulator in 2025, with no bank in between.
- Data brokers hold coverage. Whether a person with a thin credit file can be verified without a document is decided by bureau data.
- Registries are gaining power where the state verifies at the source. Companies House stopped about 27,000 suspicious filings in 2025-26.
- Wallet makers (Apple, Google, Samsung) decide whether a verifier can read a mobile driver's licence.
- Applicants hold the truth and the documents, and they leave if you're slow.
How the rules work
What's written and what's enforced differ, and in 2025-2026 the US and Europe moved in opposite directions.
The US is loosening the paperwork and keeping the penalties. The ownership register shrank to foreign companies. October 2025 guidance dropped automatic 90-day reviews of continuing activity and the need to document decisions not to file a report. FinCEN's April 2026 proposal for AML programs would limit enforcement over upkeep failures to "significant or systemic" ones, and counts AI tools as evidence that a program works. An August 2025 executive order took reputation risk out of bank supervision and put exits on political grounds under scrutiny. Even so, the big penalties kept coming, as the table below shows.
Canada raised the stakes. Maximum FINTRAC penalties rose 40-fold in March 2026, and FINTRAC issued a record 35 penalty notices worth over CAD 247M in 2025-26, mostly against money services businesses.
The EU tightened. From July 10, 2027 the AMLR fixes refresh cycles (one year for high risk, five for the rest), how ownership is calculated, what data you collect on each person (including place of birth and nationality, which US rules don't ask for), and a draft standard makes a government digital ID the preferred way to verify people remotely.
October 2024
- Who
- TD Bank (US)
- Amount
- About $3.1B
- What triggered it
- About 92% of transaction volume never monitored, 2014-2023
October 2024
- Who
- Starling (UK)
- Amount
- About £29M
- What triggered it
- Screened customers against only a fraction of the UK sanctions list; onboarded high-risk customers despite a restriction
January and April 2025
- Who
- Block (Cash App)
- Amount
- $80M and $40M
- What triggered it
- Due diligence, monitoring and a report backlog after rapid growth
July 2025
- Who
- Monzo (UK)
- Amount
- About £21M
- What triggered it
- Onboarded 34,000+ high-risk customers in breach of a restriction while growing from 600,000 to 5.8 million customers
July 2025
- Who
- Barclays (UK)
- Amount
- £42M
- What triggered it
- Onboarding and monitoring of two clients
October 2025
- Who
- A payments and crypto money services business (Canada)
- Amount
- About CAD 177M
- What triggered it
- About 1,000 missed suspicious transaction reports
March 2026
- Who
- Canaccord Genuity
- Amount
- $80M
- What triggered it
- An under-resourced program that missed suspicious activity
April 2026
- Who
- A payments-heavy New York savings bank
- Amount
- Order, no fine
- What triggered it
- Payments growth without proportionate controls; alerts closed automatically
The triggers tell you more than the amounts do. Almost every case here is a program that grew faster than its monitoring, and a weak identity check on its own rarely shows up.
What mistakes cost
Mistakes here get paid for in several ways.
- Growth. A consent order on your sponsor bank can freeze new onboarding and new products for months while the regulator approves each one.
- Remediation. Lookbacks, re-verifying existing customers and outside consultants often cost as much as the fine, and the fintech's team does the work. I'd rank this as the costliest one, because when a monitoring program can't keep up, the fix lands on every customer at once.
- Fraud losses. TransUnion put lenders' exposure to suspected synthetic identities on new US accounts at about $3.3B in the first half of 2025. Whoever extended the credit owns it.
- Lost customers. Every document request loses applicants, and over-correction after an order (mass exits) hurts good customers, which since 2025 also draws regulatory attention in the US.
- Penalties and lawsuits. From FTC penalties under INFORM to biometric class actions to billion-dollar bank cases. People are exposed too: TD's case brought prosecutions of employees, and FinCEN started paying whistleblowers up to 30% of sanctions over $1M in 2026.
AI fraud and digital IDs
My verdict as of October 2026: the AI fraud is real and growing, the regulators have moved toward cryptographic credentials, and almost nobody can present one online yet. I'd build in layers, treating the document as one weak signal among many, and get ready for signed credentials without waiting for them.
What's real
- FinCEN's November 2024 alert. From 2023 into 2024, FinCEN saw more reports of deepfakes: AI-altered or AI-generated images on driver's licences and passports, combined with stolen or invented personal data to build synthetic identities that "successfully opened accounts" and then moved money for criminals. The detail that matters for product: most were caught on re-review after the account showed odd behaviour rather than at onboarding. FinCEN flagged third-party webcam plugins and applicants claiming "technical glitches" to dodge live checks.
- Forgery as a service. An online service sold AI-generated ID images for $15 in early 2024, and journalists used one to pass a crypto exchange's check.
- Injection attacks. Instead of holding a mask to the camera, the attacker replaces the camera feed with a virtual camera and plays a deepfake. Entrust, whose latest report covers over a billion verifications, says deepfake selfies rose by more than half in 2025 and are about one in five biometric fraud attempts. Vendors' percentages are measured on their own traffic, so they tell you the direction more than the size.
- Uneven accuracy. In the US Department of Homeland Security's tests of remote identity checks, reported in 2026, only 5 of 16 selfie-to-ID systems met all its goals. For the median system, an impostor who looked similar to the real person was about 11 times more likely to be wrongly accepted than a random one.
- Mules and takeovers. These come after onboarding. In the UK, Cifas counted 78,000 account takeover cases in 2025, almost a fifth of its database, and mule cases rose by about two-thirds in the first half of 2026.
What's not there yet
- Mobile driver's licences. 21 states and Puerto Rico issue them, with over 8 million credentials, and about 45% of Americans live where one is available. Few states let people present them online, and the Northeast, Texas and Florida don't issue them yet.
- The EU wallet. Every member state must offer one by December 24, 2026, and banks must accept it on request about a year later. One consultancy expects only 8 to 12 of the 27 to be ready by the end of 2026.
- The UK. It dropped plans for a mandatory national digital ID for right-to-work checks in January 2026; digital checks are still coming, through certified private providers.
- Losses. Onboarding fraud is a slice. The FBI logged about $21B of reported internet crime losses in 2025, and investment scams were about half of scam losses.
Where the rules moved
US
- What changed
- Joint FAQs from FinCEN and the bank regulators: a signed government digital credential, like an mDL, counts as government ID, in person or online
- When
- September 8, 2026
- What it means for you
- Allowed if your bank's identification program says so and you can read the credential; for private credentials, you must check the issuer verifies to your standard
US
- What changed
- NIST 800-63-4 adds a digital-evidence route for remote identity proofing
- When
- August 2025
- What it means for you
- A reference, not a rule; vendors will market to it
EU
- What changed
- AMLR: verify with an ID document or an eIDAS digital ID at "substantial" or "high"
- When
- July 10, 2027
- What it means for you
- No data-only route like the US or Canada
EU
- What changed
- AMLA's draft standard: digital ID first for remote checks, remote document checks as the fallback
- When
- Draft, 2026
- What it means for you
- May change before final
UK
- What changed
- Statutory register of certified identity providers; trust framework 1.0
- When
- December 2025; September 2026
- What it means for you
- 46 providers and 64 certified services by mid-2026
Canada
- What changed
- Five FINTRAC methods: photo ID with authentication and face match, credit file (3+ years old), two independent sources, affiliate, reliance
- When
- In force
- What it means for you
- Newcomers fail the credit-file method; Interac's bank-login check is the local digital ID
Biometric privacy
A selfie check collects biometrics, and that has its own law. Illinois requires written consent before you collect and a published retention schedule (see Liability allocation). Texas lets only the attorney general sue, but Meta and Google settled for well over a billion dollars each. Colorado and Washington have laws too. If an applicant refuses a selfie, which business owners often do, you need another path: data checks with manual review, a document only, or a digital credential.
Questions to ask an identity vendor
- Which attacks was your liveness tested against: masks and printouts, or injected camera feeds too?
- How do you defend web capture, where injection is easiest?
- What are your false-reject rates by age, skin tone and camera quality, and who measured them?
- Can you read a mobile driver's licence or a passport chip, and in which flows?
- Where are images and templates stored, and for how long?
What usually goes wrong
| Symptom | Likely cause | First thing to check |
|---|---|---|
| Business stuck in review for days | Trade name vs legal name, EIN belongs to a parent, new LLC not yet indexed, foreign parent | The match result per field, then which document would settle it |
| Approved company turns out to be a hijacked real business | Recent officer, agent or address change, or a reinstatement, that a data match accepted | The registry's change history and the officer list before the change |
| Fraud from brand-new LLCs | Companies formed with stolen identities | The person's check, address type, company age, formation agent patterns |
| Terminated merchant back under a new company | Fresh LLC with a relative as owner | Matching on people, phone, address, device and bank account, not just the entity |
| High-risk merchant boarded as low-risk | Industry code assigned from the application, not the website | Website review at onboarding and again later |
| Good applicants fail the person check | Thin file, name changes, newcomers, poor cameras | Which check failed, and whether a document step-up was offered |
| Synthetic identity passes, then busts out months later | Details built to match bureau data | eCBSV, synthetic-identity scores, how fast details get reused across applications |
| Selfie check passed by a deepfake | Injected camera feed, often through web capture | Device and virtual-camera signals; mobile SDK vs web |
| Account taken over after a clean onboarding | SIM swap, stolen credentials, social engineering of support | Changes to phone, email or payout account before the loss |
| Alert backlog growing every week | Customers grew faster than the team; rules never tuned | Alerts per analyst per day, and the share closed as false positives |
| Sanctions hit missed on a company | Screened the company but not its owners | Whether owners were screened, and aggregated under the 50% rule |
| Bank freezes new onboarding | A consent order at the bank, or your audit findings | The program agreement's approval clauses |
| Marketplace fined | Sellers over 200 sales and $5,000 not verified within 10 days | The seller verification queue and the 10-day timer |
Words that mean something else here
| Term | What you'd assume | What it means here |
|---|---|---|
| Good standing | The company is legitimate | Its filings and state taxes are current; nothing more. A status check isn't a certificate of good standing |
| Active | Doing business | In a registry: not dissolved. From a vendor: found. On your platform: can move money |
| Verified | Someone checked it | Usually a vendor matched it to a source, which may itself be self-declared. In the UK since November 2025, a verified director is a legal status |
| Beneficial owner | Someone who owns a stake | In the US, also one control person who may own nothing. UBO is industry slang for the person at the top |
| KYB | A legal requirement | An industry term. The law says customer due diligence (US) or client identification (Canada) |
| KYC | An ID check | To regulators: identity plus understanding what the customer does and why |
| Customer (US bank rules) | Whoever opens the account | For a business account, the business; the person signing isn't a "customer" for identification purposes |
| Shell company | A fraud | A company with no operations, often legal. In money-laundering talk: one used to hide owners |
| Registered agent | The company's office | The address for legal papers, often shared by thousands of companies |
| High risk | One list | A bank's customer rating, Visa's high-brand-risk categories or MATCH's terminated merchants: three lists with three owners |
| Liveness | Proof a person is there | Usually resistance to masks and printouts; faked camera feeds are a separate test |
| Match rate | How often checks succeed | A file was found, the details agreed, or a yes from SSA: three different numbers |
| Digital ID | A government credential | A scan of a plastic card, a vendor profile, a bank login or a signed credential; only the last counts as a digital credential under the 2026 US FAQs |
| False positive | A mistake | In screening: a name hit that's someone else. In monitoring: an alert that led to no report, though it may have been worth a look |
| Perpetual KYC | A legal standard | A vendor term for reviewing on events instead of on a calendar |
| PEP | Any politician | US: senior foreign political figures. Canada and the EU: domestic ones too |
What surprised me
Placeholders in your voice, drafted from the earlier guides. Rewrite each with your own moment.
"KYB is a lookup." In the telco guide, the brand check for business texting was an exact match on EIN and legal name, and typos failed it. KYB looks like that with more fields, but a hijacked company passes the match perfectly. The match tells you the record exists, and the change history tells you whether to trust it.
"Ownership is public data." In the US there's no register to query for US companies, and since August 2026 there won't be one. The platform builds the ownership graph itself, dates it and keeps it current.
"The regulator is my counterparty." In spend management I learned fintechs rent a sponsor bank's charter. They also inherit its exam findings: one bank's consent order changed the onboarding rules for every fintech on it in a week.
"Approval is the finish line." I designed onboarding as the product. The money and the failures are in what comes after: alerts, reviews, refreshes, a team sized for last year's customers.
"A selfie is proof." A certified liveness check is certified against masks and printouts. A faked camera feed is a different attack, and the document itself is now the weakest signal in the stack.
Sources
Undated entries were read on October 3, 2026; "search result" means seen only as a search snippet.
US rules and regulators
- Cornell LII: 31 CFR 1020.220, customer identification, 31 CFR 1020.100, definitions, 31 CFR 1010.230, beneficial owners, 12 CFR 21.11, suspicious activity reports, 31 CFR 1020.320, bank reports
- FinCEN: Beneficial ownership information reporting; Alert on deepfake media (Nov 2024); 314(a) fact sheet (Sep 2026); PEP interagency statement (Aug 2020, search result)
- OCC, Fed, FDIC, NCUA and FinCEN: FAQs on verifiable digital credentials (Sep 2026)
- Federal Reserve: Evolve order (Jun 2024)
- IRS, TIN Matching (Aug 2026); eCBSV fees, Federal Register (Apr 2025, search result); SSA, eCBSV (search result)
- NIST, SP 800-63A-4 identity assurance levels (Aug 2025)
- FTC, INFORM Consumers Act guidance
- NASS, Business filing fraud report (Jul 2026)
- Delaware Division of Corporations, online status and certificates
- SBA Office of Advocacy, 2025 small business profiles (search result); OMB, NAICS 2027 proposal (Jul 2026, search result)
- DOJ, TD Bank case (search result); Illinois IDFPR and CSBS, Block multistate action (Jan 2025, search result)
Canada
- FINTRAC: Beneficial ownership requirements; Methods to verify identity; Changes to the regime; 2025-26 enforcement results (Jul 2026); PEP FAQ (search result)
- ISED, federal ownership filing announcement (Jan 2024, search result); Corporations Canada, data services (search result)
- Quebec's register, via Doane Grant Thornton (search result); British Columbia, corporate ownership transparency (search result)
- Interac verification service, via BMO (search result)
UK and EU
- Companies House: Annual report 2025 to 2026; identity verification for PSCs (Jan 2026); streaming API (search result); GOV.UK, identity verification rollout and people with significant control (search results)
- GOV.UK, OfDIA 2026 annual report (Jul 2026)
- FCA: Monzo fine, Starling fine, Barclays fine (2024-2025, search results)
- Cifas, Fraudscape 2026 and six-month update (search results)
- EUR-Lex: AMLR, Regulation (EU) 2024/1624; eIDAS 2, Regulation (EU) 2024/1183
- AMLR Article 26 and AMLA's draft due-diligence standard, Article 7, Springlex copies (2026)
- eucrim, AMLD6
Card networks and identifiers
- Visa, Payment Facilitator and Marketplace Risk Guide (Apr 2021); Mastercard, Quick Reference Booklet (search result)
- GLEIF, The LEI in numbers, Q2 2026 (search result)
Research and surveys
- BPI, Getting to effectiveness
- LexisNexis Risk Solutions and Forrester, True cost of compliance (Feb 2024, vendor-commissioned)
- DHS remote identity validation results, via idtechwire (Mar 2026)
- A vendor's payments KYB case study (Apr 2026, vendor); a bank-onboarding vendor's KYC trends report (2023 data, vendor)
- SSA eCBSV pilot results, via SentiLink (Apr 2021, vendor)
- Entrust 2026 Identity Fraud Report (Nov 2025, search result, vendor)
- TransUnion synthetic identity exposure, via Banking Exchange (Nov 2024) and TransUnion's H1 2025 report (search result)
- Route Fifty, mobile driver's licences (Aug 2026); b2trust, eIDAS 2 status (Apr 2026)
Company results and releases (the main players)
- Identity verification: Entrust, see the fraud report above; Persona, Series D (Apr 2025, search result); Veriff, revenue release (Dec 2025) and plans; Socure, Effectiv acquisition (Oct 2024, search result); Incode, valuation (Dec 2021, search result) and DHS test results (2026, vendor); GBG, FY26 results (2026, search result); Mitek, FY2025 results (Dec 2025, search result); ID.me, funding (Sep 2025, search result); CLEAR, 10-Q (Q3 2025, search result); Sumsub, pricing; Stripe, Identity (search result)
- KYB and business data: Moody's, FY2025 10-K (search result); Dun & Bradstreet, FY2024 10-K (search result) and Clearlake, acquisition completed (Aug 2025, search result); Middesk, about (search result) and matching docs; Trulioo, US KYB growth (Oct 2025, search result, vendor); Kyckr, FY2026 results (Jul 2026, search result, vendor); Baselayer, Series A (Aug 2026); Middesk, Vendr pricing data (Feb 2026)
- Bureaus and risk data: Experian, FY26 results (May 2026, search result); TransUnion, FY2025 10-K (search result); RELX, 2025 results (Feb 2026, search result); BioCatch, Permira acquisition (Sep 2024, search result); Prove, Portabl acquisition (Jan 2025, search result)
- Sanctions data: LSEG, Risk Intelligence investor webinar (Jun 2025); ComplyAdvantage, Vendr pricing data (Feb 2026)
- Transaction monitoring: NICE Actimize sale, Calcalist (Sep 2026); Quantexa, Series F (2025, search result); Hawk, Series C (Apr 2025, search result); Sardine, Series C (Feb 2025, search result); Unit21, Vendr pricing data (2025)
- Sponsor banks: The Bancorp, FY2025 10-K (search result); Coastal Financial, 4Q25 results (Jan 2026, search result); Lead Bank, Series B (Sep 2025, search result)
Law firms and press
- Orrick, FinCEN lifts ownership reporting (Sep 2026); DLA Piper, CDD exceptive relief (Mar 2026, search result) and Canada AML bills (Mar 2026); American Banker, FinCEN moves to rewrite due diligence (Sep 2026)
- MoFo, last four TIN digits order (Jul 2025, search result); King & Spalding, SAR FAQs (Oct 2025); Gibson Dunn, AML program proposal and mid-year AML 2026; Mayer Brown, debanking executive order (Aug 2025, search result)
- Law Debenture, directors still unverified (2026); William Fry, EU court ruling on ownership registers (search result); Noerr, AMLR ownership rules; Linklaters, EU digital company law (May 2025, search result); Hogan Lovells, AMLA consultation
- McDermott, first INFORM case (2025, search result); Sidley, BIPA amendment retroactive (Apr 2026, search result); Orrick, Onfido BIPA settlement (May 2023); Katten, BIPA and financial institutions (search result); Texas Tribune, Meta settlement (Jul 2024, search result); Hunton, Google settlement (search result); BCLP, biometric laws tracker (search result)
- Banking Dive on Block and New York and Piermont and Sutton (2024-2025); Fortune, TD Bank (Oct 2024, search result)
- Cointelegraph, AI-generated IDs pass KYC (Feb 2024, search result); The Register, UK digital ID climbdown (Jan 2026, search result); Alston & Bird, FBI IC3 2025 report (2026, search result); APP reimbursement first year, Bratby (search result)
Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.