This checklist covers what a complete KYB review file for a business applicant should contain before it goes to a decision. It follows the order an analyst works in, and each section ends with the question the file has to answer. For the reasoning behind each step, and the evidential limit of each source, read how to verify a business for KYB.
Use it alongside your own policy. Your risk appetite, your regulator and any partner or sponsor bank decide which items are mandatory for which applicants.
One rule applies to every line below: record the source, the capture date and what the source does not establish. A tick without a source is a claim, and a file full of claims will not survive a quality review or an examiner's sample.
1. File setup
- Product or account requested, and the partner or sponsor bank behind it
- Requirement set the file is reviewed against (internal policy version, partner requirements with the date you read them)
- Declared business activity, customer types and geographies, copied from the application as claims to test
- Risk triggers that move the file to enhanced due diligence under your policy
The file answers: what are we deciding, and against which rules?
2. Legal existence
- Registry search in the jurisdiction of formation: exact legal name, registration number, entity type, formation date, status
- Registered agent and registered address
- Name changes, mergers, dissolutions and reinstatements in the filing history
- Foreign registration in the states where the business actually operates
- Formation document (certificate of formation or incorporation, articles) that matches the registry record
- Certificate of good standing if your policy or the partner requires one, checked against the registry and dated (see what good standing proves)
The file answers: does this entity exist in the form claimed? It does not yet answer who controls it.
3. Tax identifier
- EIN or the local tax or registration identifier
- IRS document tying the EIN to the exact legal name (the IRS says its digital CP575 notice is accepted by banks and other institutions as written confirmation of an entity's EIN)
- Method of verification recorded: database check, document review only, or not verified
The file answers: is the tax identifier tied to this legal name, and how do we know?
4. Addresses
- Registered address, labelled as such
- Operating address, with the document that evidences it (lease, utility bill, bank statement, regulator record)
- Address type assessed against the stated activity (virtual office, co-working space, registered-agent building, residence, warehouse)
- For remote businesses, where the controlling people are located
The file answers: where does this business actually operate?
5. Ownership and control
- Ownership chart from the applicant to every natural person at or above your threshold (the US CDD rule sets 25 percent of equity interests; partners may set their own)
- Every intermediate entity named, with its jurisdiction and registration evidence
- The document that evidences each ownership link (operating agreement, membership ledger, share register, cap table, foreign registry extract), read and matched to the entity
- The control person: one individual with significant responsibility to control, manage or direct the entity
- Signatures, dates and capacity on ownership documents checked
- Discrepancies against the registry, the website and public sources listed, each with its resolution
For US applicants, remember that FinCEN's interim final rule of March 26, 2025 exempted entities created in the United States from reporting beneficial ownership to FinCEN, so ownership evidence has to come from the applicant and your own verification.
The file answers: who owns and controls this business, and is the chain complete? See ultimate beneficial owner.
6. People
- Identity verification for each beneficial owner, the control person and each authorized signer, per policy
- Which checks ran, where, and on what date; which are left to the partner or the customer
- Authority of the applicant to act for the business (registry officer listing, resolution, operating agreement provisions)
- Professional footprint of the principals, where it helps corroborate the business
The file answers: are these real people, and is the person applying entitled to bind the business?
7. Screening
- Entity names screened: legal name, trade names, prior names
- People screened: owners, control person, directors, signers
- Lists and sources covered, the date, the name variants used
- Sanctions exposure through ownership: under OFAC's 50 percent rule, entities owned 50 percent or more in the aggregate by one or more blocked persons are themselves considered blocked
- PEP and adverse media results, each potential match dispositioned with the reason (confirmed, discounted as a namesake with the identifiers that differ, or unresolved)
The file answers: what did we search, and what did we find? A zero-match result is only as good as the names and lists behind it.
8. Business activity
US banks must understand the nature and purpose of customer relationships to develop a customer risk profile (31 CFR 1020.210). In practice:
- Website reviewed: functional, specific, consistent with the application; domain registration date and archive history noted
- Operating evidence: contracts, invoices, fulfilment or shipping records, app listings, customer reviews, regulator records
- Industry classification (NAICS, MCC where relevant) matched to what the business actually does
- Regulated activity assessed: money transmission, lending, custody, virtual currency, third-party payment processing, and whether licences or registrations are needed and held
- Claimed facts and independently found facts kept in separate columns
The file answers: what does this business really do, and does it fit the product?
9. Expected activity and source of funds
- Expected monthly volume, transaction size, counterparties and countries
- Plausibility against the business's age, size and model
- Source-of-funds evidence where risk or inconsistency requires it, in the applicant's own name
- Account purpose in the applicant's words, with own funds and customer or third-party funds kept distinct
The file answers: does the expected activity make sense for this business?
10. Red flags reviewed
Check the file against the common shell and front-company patterns: recent formation with large claims, a registered-agent address as the only address, nominee officers, layered offshore ownership, documents with signs of alteration, and a website that does not match the business. Each is a reason to ask, not a finding of wrongdoing. The shell company red flags guide shows each with a real case.
11. Consolidated request list
- Every open item in one list, sent once
- For each: what is needed, why, what will be accepted, who provides it, and what it unblocks
- Items already found in public or authorized sources removed before sending
12. Recommendation and sign-off
- Summary of established facts with sources
- Open gaps and why each is open
- Risk rating under your methodology, with the reasoning
- Recommendation: approve, approve with conditions, request more information, escalate, or decline
- Second review where your policy requires four-eyes review
- Decision and decision-maker recorded; the decision stays with the institution
Record keeping: for US covered financial institutions, 31 CFR 1010.230(i) requires beneficial ownership identifying information to be kept for five years after the account is closed, and verification records, including a description of documents relied on and the resolution of each substantive discrepancy, for five years after the record is made.
A file that holds up
The files that survive a second look share three habits. Every fact carries its source and date. Every check states its scope. And the file distinguishes "not found" from "not searched". If you want to see those habits on a full file, the sample KYB review walks through an illustrative applicant.
Sweat AI is an AI-native BPO for banks and fintechs, starting with back-office workflows like KYB, onboarding and fraud reviews. We work KYB files against this structure, 24/7, and return each with source-linked evidence, one consolidated request list and a recommendation for your team's decision. See outsourced KYB review.
Questions
Is this checklist a substitute for our KYB policy?
No. It is a working structure for a single file. Your policy, your risk appetite and any partner or sponsor bank requirements decide which items are mandatory, which thresholds apply and when enhanced due diligence is triggered.
How long do we have to keep beneficial ownership records?
For US covered financial institutions, 31 CFR 1010.230(i) requires identifying information to be kept for five years after the account is closed, and verification records, including the resolution of each substantive discrepancy, for five years after the record is made. Check your own regulator's and state rules as well.
Where do KYB files most often fall short?
A frequent gap is an ownership picture that looks complete but stops at an intermediate company, or relies on a document that was never actually read. Trace every owner above your threshold to a natural person and note which document shows it.
When should the review stop and go back to the applicant?
After you have exhausted the public and authorized sources you can reach. Then send one consolidated request that names each missing item, why it is needed, what will be accepted and what it unblocks.
Sources
- 31 CFR 1010.230, Beneficial ownership requirements for legal entity customers (Cornell LII), accessed 2026-09-30
- 31 CFR 1020.210, Anti-money laundering program requirements for banks (Cornell LII), accessed 2026-09-30
- OFAC FAQ topic: entities owned by blocked persons (50 percent rule), accessed 2026-09-30
- IRS, Understanding your CP575 notice, accessed 2026-09-30
- FinCEN, Beneficial Ownership Information Reporting, accessed 2026-09-30