Use KYB when the counterparty is a business entity and KYC when the subject is an individual. The decision matters because the control objective changes from verifying a person to verifying legal ownership, representatives, and risk exposure. In practice, teams should align the workflow to the entity type, then collect the documents and checks that support AML and fraud controls.
How to choose the right onboarding workflow for the counterparty type
KYB and KYC are not competing checks so much as different identity questions. The practical decision is to identify whether the onboarding target is a legal person or a natural person, then route the case to the workflow that can actually verify that subject. That keeps collections, approval logic, and remediation steps aligned with the real counterparty.
For business onboarding, the control objective is usually entity existence, ownership, control, and authority to act. For individual onboarding, the objective is person-level identity proofing, including who the person is and whether the evidence presented is credible enough for the risk tier.
What KYB has to prove that KYC does not
KYB is broader than “is this company real?” because the compliance question usually extends to legal structure, beneficial ownership, directors or authorised signers, and whether the business sits in a higher-risk sector or jurisdiction. That is why KYB often needs registry data, corporate documents, ownership chains, and sanctions or adverse-media screening that can support an AML decision. A business onboarding guide should cover business identity verification around legal entities and beneficial ownership rather than treating the entity as a person.
KYC, by contrast, is about the individual behind the account or transaction. It typically relies on identity proofing, document validation, and verification steps that establish a real person, not a corporate control structure. Where remote onboarding is involved, the team should expect the evidence burden to include both authenticity checks and fraud resistance, especially if the workflow allows the customer to be opened without an in-person review. The practical takeaway is that the “right” workflow is the one that matches the subject of verification, not the easiest data source.
How to handle mixed cases, agents, and ownership chains
Many onboarding cases are not pure KYB or pure KYC. A business account may require KYB for the entity, then KYC for the director, ultimate beneficial owner, or authorised representative who is acting on behalf of that business. In those cases, teams should not collapse the checks into one generic review, because the documents, questions, and approval outcomes are different.
That distinction matters when third-party control is present. The same workflow may need to verify who owns the entity, who can bind it contractually, and who is actually submitting the application. A strong identity proofing and KYC guide helps teams separate person-level proofing from entity-level due diligence, which is especially useful when a representative, agent, or delegated signer is involved. For broader control design, practitioners also benefit from an IAM and IGA basics reference that distinguishes authentication, authorization, and entitlement governance.
Risk and Threat Considerations
Misclassifying the onboarding type creates real exposure. If a business is treated like an individual, teams may miss beneficial ownership, shell-company indicators, or authority gaps. If an individual is treated like a business, teams may over-rely on documents that do not prove the actual person, which increases fraud and account-takeover risk.
Failure mechanism: The control fails when the onboarding workflow collects the wrong evidence for the subject, or when reviewers accept partial evidence that does not establish ownership, authority, or person-level identity with enough confidence.
Impact: The result can be weak AML screening, unauthorised onboarding, fraud losses, false approvals, and downstream difficulty proving why the counterparty was accepted.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | KYB/KYC onboarding verifies external counterparties and representatives. |
| IA-12 — Identity Proofing | KYC depends on proofing the identity of individuals during onboarding. | |
| IA-9 — Identification and Authentication (Service and Non-Organizational Users) | Business onboarding often includes non-human or delegated actors authenticating on behalf of an entity. | |
| Recommendation — Use IA-8 to verify external counterparties before allowing account or transaction access. Apply IA-12 to establish identity proofing evidence before opening the relationship. Use IA-9 where non-organizational actors or delegated access paths need authentication controls. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Onboarding must route the right subject to the right access and verification workflow. |
| A.5.16 — Identity management | KYB/KYC decisions depend on correct identification and lifecycle handling of counterparties. | |
| Recommendation — Define onboarding control rules that separate business verification from individual verification. Maintain identity records that distinguish legal entities, individuals, and authorised representatives. | ||
Practitioner Guidance
What to prioritise: Build the first decision around legal form, not around the product team or channel. If the counterparty is a company, partnership, or other legal entity, start with KYB and add person-level KYC only for the humans who own, control, or act for that entity.
What to verify: The evidence set should answer the same question the workflow is trying to resolve. For KYB, verify entity registration, ownership, and signatory authority; for KYC, verify the individual’s identity and the reliability of the proofing evidence.
Decision rule: If the counterparty can legally contract, transact, or hold risk in its own name, treat the entity as the primary subject and require KYB. If the subject is the natural person opening or controlling the relationship, require KYC. When both are present, do both, but keep the checks distinct.
Practitioner takeaway: The most common error is not choosing the wrong acronym, it is asking the wrong identity question and then accepting evidence that cannot actually support the compliance decision.
Related resources from NHI Mgmt Group
- How should compliance and fraud teams evaluate KYC and KYB programmes as AI changes onboarding risk?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?
- How should teams decide between policy-heavy compliance automation and continuous monitoring?