Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should compliance teams decide between KYB and…
Governance, Ownership & Risk

How should compliance teams decide between KYB and KYC when onboarding new counterparties?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Use KYB when the counterparty is a business entity and KYC when the subject is an individual. The decision matters because the control objective changes from verifying a person to verifying legal ownership, representatives, and risk exposure. In practice, teams should align the workflow to the entity type, then collect the documents and checks that support AML and fraud controls.

How to choose the right onboarding workflow for the counterparty type

KYB and KYC are not competing checks so much as different identity questions. The practical decision is to identify whether the onboarding target is a legal person or a natural person, then route the case to the workflow that can actually verify that subject. That keeps collections, approval logic, and remediation steps aligned with the real counterparty.

For business onboarding, the control objective is usually entity existence, ownership, control, and authority to act. For individual onboarding, the objective is person-level identity proofing, including who the person is and whether the evidence presented is credible enough for the risk tier.

What KYB has to prove that KYC does not

KYB is broader than “is this company real?” because the compliance question usually extends to legal structure, beneficial ownership, directors or authorised signers, and whether the business sits in a higher-risk sector or jurisdiction. That is why KYB often needs registry data, corporate documents, ownership chains, and sanctions or adverse-media screening that can support an AML decision. A business onboarding guide should cover business identity verification around legal entities and beneficial ownership rather than treating the entity as a person.

KYC, by contrast, is about the individual behind the account or transaction. It typically relies on identity proofing, document validation, and verification steps that establish a real person, not a corporate control structure. Where remote onboarding is involved, the team should expect the evidence burden to include both authenticity checks and fraud resistance, especially if the workflow allows the customer to be opened without an in-person review. The practical takeaway is that the “right” workflow is the one that matches the subject of verification, not the easiest data source.

How to handle mixed cases, agents, and ownership chains

Many onboarding cases are not pure KYB or pure KYC. A business account may require KYB for the entity, then KYC for the director, ultimate beneficial owner, or authorised representative who is acting on behalf of that business. In those cases, teams should not collapse the checks into one generic review, because the documents, questions, and approval outcomes are different.

That distinction matters when third-party control is present. The same workflow may need to verify who owns the entity, who can bind it contractually, and who is actually submitting the application. A strong identity proofing and KYC guide helps teams separate person-level proofing from entity-level due diligence, which is especially useful when a representative, agent, or delegated signer is involved. For broader control design, practitioners also benefit from an IAM and IGA basics reference that distinguishes authentication, authorization, and entitlement governance.

Risk and Threat Considerations

Misclassifying the onboarding type creates real exposure. If a business is treated like an individual, teams may miss beneficial ownership, shell-company indicators, or authority gaps. If an individual is treated like a business, teams may over-rely on documents that do not prove the actual person, which increases fraud and account-takeover risk.

Failure mechanism: The control fails when the onboarding workflow collects the wrong evidence for the subject, or when reviewers accept partial evidence that does not establish ownership, authority, or person-level identity with enough confidence.

Impact: The result can be weak AML screening, unauthorised onboarding, fraud losses, false approvals, and downstream difficulty proving why the counterparty was accepted.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)KYB/KYC onboarding verifies external counterparties and representatives.
IA-12 — Identity ProofingKYC depends on proofing the identity of individuals during onboarding.
IA-9 — Identification and Authentication (Service and Non-Organizational Users)Business onboarding often includes non-human or delegated actors authenticating on behalf of an entity.
Recommendation — Use IA-8 to verify external counterparties before allowing account or transaction access. Apply IA-12 to establish identity proofing evidence before opening the relationship. Use IA-9 where non-organizational actors or delegated access paths need authentication controls.
ISO/IEC 27001:2022A.5.15 — Access controlOnboarding must route the right subject to the right access and verification workflow.
A.5.16 — Identity managementKYB/KYC decisions depend on correct identification and lifecycle handling of counterparties.
Recommendation — Define onboarding control rules that separate business verification from individual verification. Maintain identity records that distinguish legal entities, individuals, and authorised representatives.

Practitioner Guidance

What to prioritise: Build the first decision around legal form, not around the product team or channel. If the counterparty is a company, partnership, or other legal entity, start with KYB and add person-level KYC only for the humans who own, control, or act for that entity.

What to verify: The evidence set should answer the same question the workflow is trying to resolve. For KYB, verify entity registration, ownership, and signatory authority; for KYC, verify the individual’s identity and the reliability of the proofing evidence.

Decision rule: If the counterparty can legally contract, transact, or hold risk in its own name, treat the entity as the primary subject and require KYB. If the subject is the natural person opening or controlling the relationship, require KYC. When both are present, do both, but keep the checks distinct.

Practitioner takeaway: The most common error is not choosing the wrong acronym, it is asking the wrong identity question and then accepting evidence that cannot actually support the compliance decision.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org