deepidv
Back to Playbooks
The Deep Brief · Curated Playbook · Global · Sep 25, 2026 · 19 min read

The Business Verification Playbook: KYB for the Prosecution Era

An executive playbook for business verification: entity truth, person-level director and UBO proofing, and event-driven monitoring, run in five phases.

Blueprint of a business verification program connecting registries, ownership resolution, person proofing, and evidence
Curated Playbook
19 min read · Advanced · Global

Full name + work email required. We'll email you a copy.

Business verification just crossed the line every compliance discipline eventually crosses: from paperwork obligation to prosecutable duty. In September 2026 the UK secured its first convictions for director identity verification failures, fining a verified director for an unverified colleague's continued service, while the A7 case showed a Moscow-backed network settling an estimated $86 billion through companies whose filings were perfectly in order. The two stories are one lesson read from both ends: regulators now punish programs that verified documents about companies instead of the humans who control them, and adversaries industrialized exactly that gap years ago.

This playbook is the systematic answer: treat the business customer as a structure that resolves to people, verify those people with the same rigor applied to high-risk individuals, and keep the answer true after onboarding with monitoring that runs on events rather than anniversaries. Five phases over roughly sixteen weeks, covering the entity layer, ownership resolution, person-level proofing, continuous control monitoring, and the evidence and adversarial operations that keep the program honest.

The threat model: four fictions, one economy

Corporate-vehicle fraud runs on fictions layered until scrutiny gives up, and four cover the field. The fictitious company: entities that exist only as filings, typically dissolving inside 200 days after moving sums their trading history cannot explain. The nominee human: a real, verifiable person whose name is on the filings and whose control is a private agreement the registry never sees. The obscured owner: control routed through layering, cross-holdings, trusts, and disclosure-light jurisdictions until no natural person appears above the threshold. The stale file: a KYB file true at onboarding and refreshed annually, defending a snapshot against a motion picture.

The economy behind all four is rational: a shell costs less than a synthetic identity, a nominee costs a fee, and the expected penalty was, until this month, an administrative letter. The convictions repriced the defense's side of the ledger. This playbook reprices the attack's.

Reference architecture: person-anchored KYB

The architecture that survives the threat model treats entity data as the outer shell and verified humans as the core, with evidence assembled by the system rather than the analyst. Two properties matter most. Verticality: every check feeds the evidence vault directly, so the case file assembles itself as the case happens. And symmetry between onboarding and monitoring: the same resolution and proofing machinery runs at account opening and on every triggering event afterward, so the back book ages at the same standard as the front door.

The program expresses this as four gates a business customer passes and keeps passing. The entity gate: the company is real, registered, and coherent with its declared business. The person gate: every director and UBO is a liveness-verified human bound to their claimed role. The control gate: the resolved structure matches observed control on the live account. The continuity gate: events re-open the earlier gates automatically, so passage is a state, not a ceremony.

54%
of business identity checks are still run manually
Source: industry survey, 2026

Phase 0: book census and exposure audit (weeks 1-2)

Programs inherit books, and the book is where enforcement will look first. Phase 0 answers four questions per corporate customer: when was the entity last verified against its registry; which directors and UBOs are identified; which of those persons were ever identity-proofed rather than database-confirmed; and what evidence exists per answer. The output is an exposure register ranked by the product of gap and stakes, and it becomes the first exhibit of program good faith.

Phase 1: entity truth and resolution (weeks 3-5)

Phase 1 automates the outer shell. Registry verification runs against primary sources across every jurisdiction the book touches, with document forensics on the instruments the registries do not hold. The resolution engine assembles ownership across layers and borders until natural persons emerge or the dead end itself becomes a finding: an unresolvable structure is a risk verdict routed to enhanced due diligence, not a data-quality nuisance. Mismatch between registry, declaration, and observation is signal, logged and adjudicated, never silently reconciled to whichever source unblocks the funnel.

Phase 2: the person gate (weeks 6-9)

Phase 2 is the program's center of gravity: every resolved director, PSC, and UBO completes identity proofing as a person, not a record, through government document authentication, biometric matching, and structural passive liveness with injection defense, run from the person's own phone in minutes. The corporate twist is role binding: the verified identity is bound to the claimed position and cross-checked against the resolved structure. Two attack classes make the biometric layer non-negotiable: the rendered owner (a deepfake face presenting a genuine document on a remote call) and the industrial nominee (the same face or document recurring behind formally unrelated entities, caught by cross-entity reuse analytics).

Phase 3: the control and continuity gates (weeks 10-12)

Phase 3 makes passage a state. Event feeds wire into the decision plane: registry filings and director changes, ownership transfers, sanctions and PEP updates, adverse media, and the customer's own transaction posture where it contradicts the declared business. Each event class maps to a proportionate re-check within hours, not at renewal. The control gate adds the comparison legacy programs never run: resolved structure versus observed behavior, which is what catches the nominee arrangement the registry cannot see, because private agreements leave public footprints in behavior.

Phase 4: evidence and audit operations (weeks 13-16)

Phase 4 assumes the examination and builds backward. Per-customer case files export on demand: the entity's verification history, the resolved structure with its sources and dead ends, every person's proofing record with method and date, and every event trigger and its disposition, assembled in minutes. Two service levels are worth committing to in writing: any regulator request for a customer's complete verification evidence is met within 24 hours, and any confirmed sanctions touch on a resolved person reaches decision-makers the same day.

Phase 5: adversarial assurance (ongoing)

A KYB program that has never been attacked by its own side is a hypothesis. From week 16, a standing red-team calendar runs synthetic shell applications, nominee personas recycling faces across applications, rendered-face proofing attempts, quiet control transfers mid-quarter, and the stale-file drill. Each drill scores catch rate, time to detection, and evidence quality, and each miss converts to a dated fix.

Pull quote

“Data-layer vendors pass the paperwork; person-layer stacks catch the human, and the difference is the entire post-conviction era in one demo.”

— The buyer's evaluation test

The regulatory and liability map

RegimePerson-level obligationEnforcement posture
UK ECCTA 2023Director identity verification with Companies House; existing directors by November 2026First convictions September 2026; cross-liability established
EU AML packageHarmonized 25% UBO threshold; centralized registers; verification dutiesNew supervisor phasing in; register interconnection underway
FATF Rec. 24/25Multipronged beneficial ownership transparency, adequate and up-to-dateMutual evaluations grading person-level effectiveness
Australia tranche 2Lawyers, accountants, real estate in scope; UBO identificationAUSTRAC supervision sweeps of newly regulated sectors
US FinCEN CDDBank-side beneficial ownership identification at account openingBank examinations carrying the person-verification weight
US CIP credential FAQsVerifiable digital credentials acceptable within CIPOpens credential-based corporate officer verification

Read as one map, the direction is uniform: registers centralize, thresholds harmonize around 25 percent with control-by-other-means, and enforcement moves from entity disclosure to person verification, with the UK simply arriving first at the courtroom.

Measurement and the program checklist

Ten numbers run the program, but two moving in opposite directions tell its health: proofed-person coverage rising, oldest-evidence age falling. When both stall, the funnel veto is back, and it is a leadership conversation, not a tooling one.

Checklist · Person-anchored KYB checklist
  • Census the book: entity, directors, UBOs, and evidence per customer
  • Resolve ownership to natural persons, documenting every dead end as a finding
  • Proof every director and UBO with document, biometric, and structural liveness
  • Bind each verified person to their declared role against the resolved structure
  • Wire event triggers: filings, control changes, sanctions, adverse media
  • Compare resolved structure to observed account behavior
  • Export a complete per-customer case file within 24 hours
  • Red-team the gates quarterly, converting every miss to a dated fix

Business Verification Playbook FAQ

What is a business verification (KYB) program?
The end-to-end discipline of verifying corporate customers: confirming the entity against registries and documents, resolving ownership to natural persons, identity-proofing those directors and UBOs with liveness, screening continuously, and keeping evidence per decision, maintained by event-driven re-checks after onboarding.
Why does KYB now require person-level verification?
Because enforcement moved there: the UK's first director verification convictions punished unverified humans behind verified filings, and cases like A7 showed entity-level checks passing industrial-scale abuse. Registries verify claims; only person proofing verifies people.
How long does a person-anchored KYB program take to deploy?
Roughly sixteen weeks in five phases: census, entity and resolution automation, the person gate, event-driven monitoring, and evidence operations, with adversarial testing ongoing from week sixteen. A ninety-day variant covers the top risk tier and all new onboarding.
What should trigger re-verification of a business customer?
Events: registry filings, director and control changes, ownership transfers, sanctions and PEP updates, adverse media, and behavior contradicting the declared business. The annual review remains only as a floor.
How do you catch nominee directors?
At the person layer: identity proofing with liveness that nominees must complete as themselves, reuse analytics that spot the same face, document, or device across unrelated entities, role binding against the resolved structure, and behavior-versus-declaration comparison on the live account.
What evidence should a KYB program be able to produce?
A complete case file per customer within 24 hours: entity verification history, the resolved structure with sources and documented dead ends, every person's proofing record with method and date, and every event trigger with its disposition, assembled by the system rather than reconstructed by analysts.
Does a deepfake threaten business onboarding?
Yes: a rendered face presenting a genuine document can defeat remote proofing that lacks structural liveness, which makes deepfake defense at the person gate a KYB control, not just a retail one.
TagsIdentity VerificationAMLBankingLivenessGlobalAdvancedPlaybook

Relevant Articles

What is deepidv?

Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.

Learn More