KYB for corporate senders: onboarding a business client for cross-border payments and what monitoring inherits
KYB for corporate senders verifies the entity, its beneficial owners and its expected activity, then hands that profile to transaction monitoring as a baseline.
- KYB for a corporate sender produces four things: a verified entity, verified beneficial owners and controllers, an expected activity profile by corridor, and a risk rating with a review date. Monitoring rules are built from the third.
- Entity verification means an independent registry check of existence and good standing, the constitutional documents, the registered and operating addresses, licences where the client is itself regulated, and an authorised signatory list.
- Beneficial ownership follows the 25 percent ownership test plus one control person under the FinCEN CDD Rule and the equivalent Canadian test, with each individual identified, verified and screened for sanctions and PEP status.
- The expected activity profile is specific: corridors, currencies, counterparties, monthly volume, average and maximum ticket, frequency and source of funds. Vague profiles produce either no alerts or nothing but alerts.
- Review is event driven as well as periodic. Ownership change, a new corridor, a sustained volume deviation, adverse media, a sanctions list update touching an owner, or a lapsed licence each reopen the file.
KYB for corporate senders is the onboarding process that establishes who a business client is, who owns and controls it, what cross-border payments it is expected to make, and how much risk that represents, before the first instruction is accepted. Its output is not a tick in a box but a structured profile, and the value of the profile is that transaction monitoring reads it. A payment that fits the profile is routine; a payment that does not is an alert. This article covers entity verification, beneficial ownership, the expected activity profile, the triggers for ongoing review, and how each part of the KYB output becomes a transaction monitoring rule.
What does KYB for a corporate sender have to establish?
Four facts, each with evidence. First, that the entity exists, is in good standing and is the entity that will be sending the payments, not a similarly named affiliate. Second, who the natural persons behind it are: the beneficial owners above the ownership threshold and at least one person with significant control. Third, what the business does and what payments it will send: which corridors, to which counterparties, how often, in what amounts, funded from what source. Fourth, how risky all of that is, expressed as a rating that determines the depth of due diligence at onboarding and the frequency of review afterwards.
The documents an examiner will ask to see for a corporate client are the certificate of incorporation or registry extract, the constitutional documents, the ownership chart down to natural persons, identification for each beneficial owner and controller, the authorised signatory list, licences where relevant, the completed activity questionnaire, the risk rating with its rationale, the screening results for the entity and each individual, and the approval by a person with authority to accept the client. For a cross-border sender, the examiner will also ask how the corridors the client declared were assessed against the institution's own corridor risk and how the declared activity is checked against actual activity.
How is the entity itself verified?
Verification relies on sources independent of the client. The legal name, registration number, jurisdiction of incorporation, registered address, status and date of incorporation are confirmed against the official company registry or a reliable aggregator of registry data, and the extract is retained with its date. Constitutional documents, articles or bylaws, are collected to confirm the structure and the powers of directors. The operating address is confirmed separately from the registered address, because a registered agent's address tells the institution nothing about where the business trades. Where the client has a legal entity identifier, it is recorded and checked against the global LEI system, and it becomes the organisation identifier used in the pacs.008 debtor block.
Where the client is itself regulated, its licences are verified at source and their expiry dates recorded. A money service business in the United States is checked against FinCEN's MSB registrant search and the state money transmitter licences it claims; a Canadian MSB is checked against FINTRAC's registry. A client that will send payments on behalf of its own customers is a nested relationship, and the institution collects its AML programme, its most recent independent review and the identity of its compliance officer, because the institution will be relying on that programme for the underlying parties. The authorised signatory list names the individuals who may submit instructions, and each is identified and verified, because those are the people whose credentials will authenticate to the API.
How is beneficial ownership established and verified?
In the United States, the FinCEN customer due diligence rule requires covered financial institutions to identify and verify each individual who directly or indirectly owns 25 percent or more of the equity of a legal entity customer, and at least one individual with significant responsibility for controlling the entity. Canada's regime under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act applies a 25 percent ownership test and requires reasonable measures to confirm the accuracy of the information. Many institutions set a lower internal threshold for higher risk clients, and the policy should say so and say why.
The mechanics are an ownership chart from the client, traced through each intermediate holding company to natural persons, supported by registry extracts or share registers at each layer, and identification and verification for each natural person named. Trusts, nominees and bearer arrangements in the chain are recorded as risk factors. As of mid-2026, a US institution cannot rely on a federal beneficial ownership registry for a domestic company, because the Corporate Transparency Act's reporting requirement was narrowed in 2025 to foreign reporting companies, so ownership is collected from the client and verified independently. Each owner and controller is screened for sanctions and politically exposed person status, and a PEP or a hit on an owner raises the rating of the whole client. The certification of beneficial ownership is signed by an authorised representative and dated, and the date drives the review cycle.
A KYB file that says the client sends payments internationally has not been completed. It has been started. The file is finished when it can say which payments would surprise you.
What goes into the expected activity profile?
The profile is the part of KYB that a cross-border sender makes hard and that transaction monitoring depends on. It is collected as a structured questionnaire, not a free text description, and each answer is a value that a rule can read.
- The corridors the client expects to use, as pairs of sending and receiving country, and for each the currency, the settlement asset where stablecoins are involved and the purpose of the payments, such as supplier settlement, payroll or treasury movement.
- The counterparties the client expects to pay, by name and jurisdiction where known, and whether they are related parties, regular suppliers or a changing population of one-off beneficiaries.
- The expected monthly volume and count, the average ticket, the maximum single payment the client anticipates, and the expected frequency, such as a weekly payroll run or month-end supplier batch.
- The source of the funds being sent, for example operating revenue, financing, client money held in trust, or proceeds of asset sales, with supporting evidence proportionate to the rating.
- Whether the client sends for its own account only or on behalf of underlying customers, and if the latter, the profile of those customers and the client's own onboarding standards for them.
The profile is then compared with the institution's own corridor risk assessment. A client declaring a corridor the institution rates as high risk is not declined for that reason alone, but the declaration raises the client rating, deepens the source of funds evidence required and shortens the review interval. The profile is signed off with the file and dated, and it is the baseline against which every subsequent payment is measured.
What triggers an ongoing review?
Periodic review by rating is the floor: annually for higher risk clients, less often for lower risk, with the date set at onboarding. The reviews that matter more are event driven, and each event needs an owner who sees it first. A change in ownership or control, disclosed by the client or found in a registry refresh, reopens the beneficial ownership section. A request to use a corridor, currency or settlement asset not in the profile reopens the activity section before the first payment on that corridor is accepted. A sustained deviation from expected volume or ticket size, which monitoring will surface, reopens the profile rather than being resolved alert by alert. Adverse media on the entity or an owner, a sanctions or PEP list update that touches an owner, a licence expiry, a change of authorised signatory, or dormancy followed by sudden activity each trigger a review, and the review record shows what was checked and what changed.
The review is not a repeat of onboarding. It is a comparison of the file against current facts, with the differences documented and the rating re-confirmed or changed. Where the rating changes, the monitoring thresholds change with it on the same day, because a review that alters the rating but leaves the rules untouched has changed a label and nothing else.
How does KYB output feed transaction monitoring rules?
The connection is direct if the profile was collected as values. Expected monthly volume becomes a volume threshold with a tolerance band, and a month that exceeds the band is an alert. Maximum single payment becomes a per transaction ceiling, and the first payment above it is held for review before release rather than flagged afterwards. Declared corridors become an allow-list, and the first instruction to an undeclared country is held. Declared counterparties seed the beneficiary allow-list, and a first payment to a new beneficiary in a high risk jurisdiction triggers enhanced review of that beneficiary. Declared frequency sets a velocity rule, so that a client profiled for a monthly batch that begins sending daily is surfaced. The client rating sets the sensitivity of every one of these rules, and the source of funds statement is what the analyst compares against when an alert is worked.
On a stablecoin rail the same profile feeds the wallet layer. The counterparties in the profile are the addresses that go on the allow-list, and a payout to an address not on it is held. The settlement asset declared in the profile is the token the client is permitted to settle in, and the corridors declared are the chains and operating wallets the routing is permitted to use for that client. Each hold appears in the compliance workbench with the profile alongside it, so the analyst sees the expected value next to the actual one and records a decision, and the decision, the pacs.002 status that follows and the on chain hash are all tied to the UETR. The KYB file and the monitoring log therefore describe the same client from two directions, which is exactly what an examiner will test by picking an alert and asking to see the profile that generated it.
Where StableNet fits
StableNet, built by SpendTheBits, has KYB and KYC onboarding built into the same platform as KYT transaction monitoring, sanctions and PEP screening and wallet screening, so the expected activity profile captured at onboarding of a corporate sender is the baseline the monitoring rules read, not a document filed elsewhere. Corridors, counterparties, ceilings and settlement assets declared in the profile become the allow-lists and thresholds applied to each pacs.008 the client submits, holds are worked in the compliance workbench, and each decision is written to a tamper evident audit trail against the UETR alongside the pacs.002 status and the on chain hash of the stablecoin settlement in USDC or USDT. This suits the B2B model, where a bank or MSB onboards its own corporate clients, and the B2B2B model, where the institution offers the rail to business clients under its own programme. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.
See it on your corridors
Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.