Vendor comparison
Trulioo vs Middesk vs deepidv: KYB After the Convictions
Trulioo, Middesk, and deepidv compared on KYB after the UK's first director verification convictions: entity data, person proofing, and event-driven refresh.
An operational engineering analysis evaluating deepidv, Trulioo, and Middesk against the KYB regime taking shape after the UK's first director identity verification convictions, the $86 billion A7 sanctions case, and the shift from registry disclosure to person-level proof.
September 2026 redefined the KYB buying question. When a court fines a verified director for another director's verification failure, and a sanctions network settles $86 billion through correctly filed companies, the vendor evaluation stops being about data coverage and starts being about what, exactly, gets verified: records about the company, or the humans who control it. Trulioo, Middesk, and deepidv answer that question with three different architectures.
The post-conviction scorecard
| Capability | deepidv | Trulioo | Middesk |
|---|---|---|---|
| Entity and registry verification | Via data integrations in decision plane | Global registry coverage, core strength | US-centric registry depth, core strength |
| UBO and director identification | Structure resolution as workflow input | Global business verification with ownership data | US filings, licenses, watchlists |
| Person-level proofing of directors and UBOs | Liveness-anchored document and biometric verification, native | Individual verification available, data-first heritage | Out of core scope, partner territory |
| Deepfake and synthetic-face defense at proofing | deepeye structural liveness, injection detection | Standard vendor stack | Not the product's layer |
| Event-driven re-verification | Registry, sanctions, and control-change triggers in policy | Ongoing monitoring of data sources | Monitoring of US records |
| Per-decision evidence for prosecution-grade audits | System-assembled, method-named records | Match records per data source | Report-based records |
Three architectures meet the person-level era
deepidv: the humans are the product
deepidv approaches KYB from the layer the convictions just made decisive: the people. Entity and registry checks run as data inputs to the decision plane, but the program's core is putting every resolved director and UBO through real identity proofing, document authentication, biometric match, and structural liveness, so a nominee, a borrowed identity, or a rendered face fails at enrollment rather than surfacing in an investigation. Re-verification triggers on events, and every decision lands in an evidence record with its method named. The honest boundary: deepidv consumes registry data rather than owning proprietary registry pipes, so data-coverage-first buyers should read the next two sections.
Trulioo: the registry layer at global width
Trulioo's strength is breadth: business verification across a very large registry footprint, with entity data, ownership information, and watchlist screening served through one integration. For a platform onboarding businesses across dozens of countries, that width is the real requirement. The regime's pressure point is depth at the person layer: registry and database confirmation of a director is not the same act as proofing the living human, and the UK's convictions turned precisely on unverified humans behind verified filings. Trulioo fits naturally as the resolution and screening layer inside a stack whose person proofing meets the new bar, a pairing the UK CDD comparison explored from the individual side.
Middesk: US entity truth, by design
Middesk owns a narrower question and answers it well: is this US business real, registered, licensed, and in good standing, assembled from state filings, IRS checks, licenses, and watchlists. For US-only onboarding at the entity layer, it is a clean choice. The boundaries are the map and the layer: coverage is US-centric, and the product verifies records about companies rather than proofing the humans who control them. Post-conviction KYB built on Middesk alone is entity assurance with a person-shaped hole; Middesk plus a person-proofing engine is a coherent architecture.
The test that decides it: the nominee director
One scenario separates the three architectures. A prospective business customer's filings are immaculate: active registration, clean licenses, plausible UBO declaration. The listed director, however, is a nominee, and the declared UBO has never touched the company. Registry-layer verification passes this customer at every data source, because every record is real. The architectures diverge at the person step: a program that identity-proofs the director and UBO with liveness discovers either an unreachable person, a refusal, or a face that fails structural checks, and a program that cross-references the verified face against other onboarded entities catches the same nominee serving twelve companies. The A7 pattern is this scenario at industrial scale, and it is why beneficial ownership verification has become the audit's first question. Data layers see filings. Only person layers see people.
Frequently asked questions
What is the difference between Trulioo, Middesk, and deepidv for KYB?
Middesk verifies US business entities from state and federal records; Trulioo provides global registry, ownership, and watchlist data with individual verification alongside; deepidv centers on proofing the resolved directors and UBOs as living humans with liveness, event-driven re-verification, and per-decision evidence.
Does registry verification satisfy the UK's new director rules?
No. The Economic Crime and Corporate Transparency Act requires directors to verify their identities, and the first convictions in September 2026 punished verification failures at the person level, including a verified director who allowed an unverified colleague to act.
Can a KYB program pass a nominee director without person-level checks?
Yes, easily: nominee arrangements produce real filings at every registry, so data-layer verification passes them. Person-level proofing with liveness, plus cross-entity checks on reused faces and documents, is what surfaces the nominee.
Which vendor should a US fintech use for business verification?
For entity truth alone, Middesk's US registry depth is a strong fit. For onboarding that must also satisfy person-level expectations, pair the entity layer with an engine like deepidv, or use Trulioo where global coverage drives the choice.
How often should business customers be re-verified?
On events rather than anniversaries: registry filings, ownership transfers, sanctions updates, and director changes should trigger re-resolution and re-proofing automatically, a posture the A7 case's inside-the-cycle structuring makes non-optional.
Ship this with one API
Everything above runs on the deepidv verification engine: one modular API, drop-in SDKs, and an MCP server your coding assistant can build against. Read the docs or see it live on your use case.
Start verifying identities today
Go live in minutes. No sandbox required, no hidden fees.