KYB onboarding is the verification of a business entity and the people behind it before enabling services or payments. It confirms company existence, ownership, control, and risk signals so firms can judge whether the organisation is legitimate, compliant, and suitable for ongoing financial activity.
Expanded Definition
KYB onboarding is the control point where a firm verifies that a business customer exists, is authorised to act, and is not presenting obvious financial, legal, or ownership risk. Unlike consumer onboarding, KYB must resolve company registration, beneficial ownership, control relationships, and the legitimacy of the activity being requested. In practice, it sits at the intersection of compliance, fraud prevention, and access governance.
Definitions vary across vendors, but the core expectation is consistent: a business should not receive payment capability, account access, or delegated system permissions until the organisation and its controllers have been screened against policy and regulatory requirements. For regulated sectors, the process is often informed by the FATF Recommendations and adapted to local sanctions, tax, and corporate registry obligations.
In NHI-heavy environments, KYB also shapes how machine-to-machine access is granted to external organisations, because the business relationship often determines who can request tokens, API keys, or delegated access. The most common misapplication is treating KYB as a one-time document check, which occurs when ownership changes, shell entities, or downstream access risk are not revalidated.
Examples and Use Cases
Implementing KYB onboarding rigorously often introduces friction for legitimate customers, requiring organisations to weigh faster activation against stronger fraud and compliance controls.
- A payments platform verifies company registration, directors, and beneficial ownership before enabling settlement accounts, reducing the chance of illicit merchant activity.
- A B2B SaaS provider reviews the customer’s legal entity, domain ownership, and signer authority before issuing administrative access and API credentials.
- A fintech checks whether a reseller is authorised to open sub-accounts on behalf of another business, because delegated activity can mask the true risk owner.
- A critical infrastructure supplier uses KYB checks before exposing integration endpoints to a third party, aligning with the visibility and lifecycle concerns described in the Ultimate Guide to NHIs.
- An online marketplace re-screens merchants after ownership changes or unusual transaction patterns, since initial approval may no longer reflect current control or sanction exposure.
For organisations designing identity workflows, KYB is easiest to understand when paired with the broader controls described in Ultimate Guide to NHIs and the risk-based onboarding model reflected in FATF Recommendations.
Why It Matters in NHI Security
KYB onboarding matters in NHI security because the business behind an integration often determines the trust boundary for every secret, token, and service account that follows. If the customer organisation is fake, opaque, or improperly authorised, downstream identities can be abused for payment fraud, data exfiltration, or supply chain compromise. This is especially important where external partners receive machine credentials tied to business relationships rather than individual humans.
NHIMG research shows that 92% of organisations expose NHIs to third parties, and that exposure becomes much harder to govern when counterparties are not properly vetted through KYB. The same research also shows only 5.7% of organisations have full visibility into their service accounts, which means weak onboarding checks can persist unnoticed into production. The operational lesson is that KYB is not just compliance paperwork; it is a prerequisite for knowing whether an external organisation should ever be trusted with identity-bearing access.
In practice, the need for KYB becomes obvious only after a suspicious partner, fraudulent merchant, or compromised integration has already been granted access, at which point the onboarding decision itself becomes the control failure that must be investigated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | KYB supports governance oversight by validating who is allowed to operate under a business relationship. |
| NIST SP 800-63 | Identity proofing concepts inform how organisations verify the legal entity and authorised representatives. | |
| OWASP Agentic AI Top 10 | Agentic and automated workflows need trusted counterparties before external tools or actions are enabled. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Third-party access to machine identities depends on knowing which business controls the requesting entity. |
Require KYB approval before granting access and reassess counterparties when ownership or risk changes.
Related resources from NHI Mgmt Group
- What breaks when KYB is treated as a one-time onboarding check?
- When should organisations prioritise KYB controls over onboarding speed?
- How should organisations design KYB onboarding to balance compliance, fraud prevention, and conversion rates?
- How should security teams build a practical KYB process for B2B onboarding?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org