Organisations should treat KYB as layered due diligence, not a single registry lookup. Start by confirming the entity exists and is active, then trace the ownership chain through each intermediary until natural persons are identified. In cross border structures, use jurisdiction specific registries, verify UBOs individually, and escalate opaque chains for enhanced due diligence before onboarding or continued relationship approval.
How to structure KYB when ownership spans jurisdictions and holding companies
KYB works best as a staged ownership investigation, not a one-time check. The practical question is not only whether an entity exists, but who ultimately controls it, where each layer is registered, and whether the structure obscures beneficial ownership. The more jurisdictions and intermediaries involved, the more the process should rely on corroborated evidence rather than a single source.
What a layered KYB workflow should verify
Start with entity existence, legal status, and registry consistency, then move outward through the ownership chain until you can identify the natural persons behind control. In complex structures, each intermediary should be checked in its home jurisdiction because names, company numbers, director records, and filing quality can differ materially. KYB and Business Identity Verification Guide is a useful reference point for tracing beneficial ownership, legal entities, and merchant onboarding checks.
Where ownership crosses borders, use the strongest available registry evidence in each jurisdiction and compare it against incorporation documents, annual filings, shareholder registers, and control rights. If a holding company sits between the customer and the beneficial owner, verify whether it is a genuine operating or investment vehicle, or simply a pass-through layer. That distinction matters because layered ownership can be legitimate while still creating higher verification burden.
When the chain is incomplete, contradictory, or routed through opaque jurisdictions, escalate to enhanced due diligence before approval. Identity Proofing and KYC Guide is relevant here because the same diligence mindset applies when identity evidence must be tested across documents, entities, and control relationships rather than against one record alone.
Where complexity creates real KYB failure modes
The main failure mode is false confidence from a visible intermediate entity. A clean local registry record can still hide a foreign parent, nominee arrangement, trust, or control agreement that changes the true risk picture. Another common issue is stale ownership data, where the entity exists but the disclosed controller has changed and the structure has not been updated in filings.
Cross-border structures also increase the chance of mismatched transliterations, inconsistent entity names, and registry records that do not expose the same depth of data. That creates a verification gap, not just an administrative inconvenience, because onboarding decisions may be based on an incomplete view of control. FATF Recommendations, AML and KYC Framework are the key baseline for beneficial ownership and customer due diligence expectations across jurisdictions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | KYB requires verifying external business actors and their controlling persons. |
| AC-6 — Least Privilege | Complex ownership should tighten access and approval until control is clear. | |
| Recommendation — Verify external parties and their controllers before granting business access. Limit onboarding and account privileges until beneficial ownership is resolved. | ||
| CIS Controls v8 | CIS-5 — Account Management | KYB decisions affect who may be trusted, onboarded, or kept active. |
| Recommendation — Review entity accounts and remove access when ownership evidence becomes stale. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Business ownership verification depends on consistent identity records across entities. |
| A.5.18 — Access rights | KYB outcome determines whether access and relationship rights should remain in force. | |
| Recommendation — Maintain controlled identity records for entities, owners, and authorised representatives. Approve or revoke business access only after ownership checks are complete. | ||
Practitioner Guidance
What to prioritise: Treat the ownership chain as the product to verify, not a single registration field. The first pass should confirm legal existence and active status, then test whether every material intermediary is explainable and documentable.
What to verify: For each layer, verify registry name, number, jurisdiction, directors, shareholders where available, and the nature of control. If control cannot be traced to natural persons with reasonable confidence, the case should remain open pending escalation.
Escalation / exception: Escalate immediately when the structure uses multiple holding companies, offshore intermediaries, nominee features, or inconsistent disclosures across jurisdictions. In those cases, approval should depend on documented enhanced due diligence, not on the absence of a match in a single database.
Practitioner takeaway: The key judgement is whether the structure is transparent enough to explain control, not whether it is merely registered somewhere. A KYB process that cannot reconstruct ownership across jurisdictions has not completed due diligence, it has only found surface-level records.
Related resources from NHI Mgmt Group
- How should organisations implement IAM when business ownership and access decisions are spread across multiple departments?
- How should organisations structure KYB checks for non-face-to-face business relationships in the Philippines?
- How should organisations structure compliance monitoring when identity verification rules change across multiple jurisdictions?
- How should organisations handle Australian privacy compliance when personal data is spread across multiple jurisdictions?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org