Join our Newsletter — 33% off our NHI Course

Why do corporate onboarding workflows need both KYC and KYB controls?

Corporate onboarding needs both controls because the risk sits at two levels. KYB verifies the business itself, while KYC confirms the individuals acting for that business. If either side is weak, firms can miss hidden ownership, sanctioned parties, or misuse of corporate structures. Together, the controls improve fraud prevention, compliance, and confidence in customer identity.

Why This Matters for Security Teams

Corporate onboarding is not just a compliance checkpoint. It is the first place where fraud, sanctions exposure, and account takeover risk can enter the business relationship. KYB establishes that the organisation exists and is legitimate; KYC establishes which people are actually behind the request, who can bind the entity, and whether they are allowed to act. That split matters because shell companies, nominee directors, and delegated signatories can make a business look clean while the human actor is not.

Current guidance from the FATF Recommendations — AML and KYC Framework treats customer due diligence as a layered obligation, not a single identity check. NHIMG research shows why that layering matters in practice: the Ultimate Guide to NHIs — Standards notes that 97% of NHIs carry excessive privileges, which is a useful reminder that identity failures often become privilege failures once onboarding is complete. In practice, many security teams encounter misuse of corporate onboarding only after a fraudulent account has already moved money, accessed systems, or signed an agreement.

How It Works in Practice

Effective onboarding uses KYB and KYC as complementary controls, with each one answering a different question. KYB asks whether the organisation is real, active, and legally registered. KYC asks whether the individuals behind the request are authentic, reachable, and authorised to act on behalf of that entity. Together, they reduce blind spots around beneficial ownership, control relationships, and delegated authority.

Practitioners usually implement this as a risk-based workflow:

  • Verify the legal entity through registration records, tax identifiers, and business registry data.
  • Identify beneficial owners, directors, and authorised signatories, not just the contact person.
  • Screen both the business and the individuals against sanctions, watchlists, and adverse media.
  • Validate authority to act through board resolutions, power of attorney, or equivalent evidence.
  • Apply enhanced due diligence when ownership is opaque, cross-border, or unusually complex.

The control logic is similar to how identity teams govern privileged non-human access: one layer confirms what the entity is, another confirms who can operate it. NHIMG has documented how supply chain compromise can cascade from a single trusted identity, including in the GitHub Action tj-actions Supply Chain Attack, where trust in an upstream workflow became the entry point. The same pattern appears in corporate onboarding when a legitimate company wrapper hides an unvetted individual actor. For digital onboarding, frameworks such as eIDAS 2.0 — EU Digital Identity Framework are increasingly relevant because they strengthen proofing and assurance across jurisdictions.

These controls tend to break down when onboarding is optimised for speed across multiple jurisdictions because evidence requirements, ownership transparency, and authority validation vary too much for a single static checklist.

Common Variations and Edge Cases

Tighter onboarding controls often increase friction, manual review, and abandonment risk, so organisations have to balance conversion against assurance. That tradeoff is real, but the answer is not to weaken one layer and hope the other compensates.

There is no universal standard for exactly how much KYB evidence is enough or when KYC must be expanded to every beneficial owner, but current guidance suggests a risk-based approach. Lower-risk corporate customers may only need standard verification, while high-risk structures, intermediaries, or politically exposed persons usually require deeper checks. For example, a local operating subsidiary with transparent ownership is a different case from an offshore holding company controlled through multiple layers. In the second case, KYB without KYC leaves the true decision-makers invisible.

That is why the strongest programmes treat onboarding as an ongoing control, not a one-time form. Changes in ownership, signatories, or corporate structure should trigger re-verification, especially after merger activity, sanctions updates, or unusual transaction behaviour. NHIMG’s Schneider Electric credentials breach is a reminder that trust in the wrong identity, once established, can be expensive to unwind. The practical standard is simple: verify the company, verify the people, then keep verifying when the risk changes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, and NIS2 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-01 Identity proofing and authorization support onboarding assurance.
NIST SP 800-63 IAL2 KYC depends on stronger identity proofing for real people.
OWASP Non-Human Identity Top 10 NHI-02 Entity trust and authority gaps mirror identity governance failures.
NIST AI RMF GOVERN Risk-based oversight fits layered KYB and KYC onboarding controls.
NIS2 Supplier and access assurance affect regulated onboarding decisions.

Use appropriate proofing and evidence checks for individuals acting on behalf of a business.