AML, KYB, and Beneficiary Verification: How to Build Compliance for B2B Customers

Onboarding a company is not the same as onboarding an individual. Behind every legal entity stands a chain of ownership, directors, founders, and ultimate beneficiaries, each of whom must be identified and checked against sanctions, PEP, and reputational databases. A KYB check (Know Your Business) is a set of procedures by which an organization establishes the legal standing, ownership structure, and reputation of a corporate customer or counterparty. Unlike KYC, where the object is an individual, KYB is directed at a legal entity and all persons associated with it: directors, founders, authorized signatories, and ultimate beneficiaries. The practical goal of KYB is to form a substantiated judgment: does the company exist de facto, does it operate lawfully, who stands behind it, and what risks does interacting with it carry. Without this judgment it is impossible to assign the customer a risk level, to fulfill the requirements of Federal Law 115-FZ and the FATF Recommendations, or to protect one's own business from regulatory and financial consequences.

How to Conduct a KYB Check of a Company

Which Data and Documents to Collect on the Company and Associated Persons

Information gathering is the first and most extensive stage of KYB. Its task is to obtain a sufficient array of data so that the subsequent checks rely on facts rather than on the customer’s declarations.

The minimum package for a legal entity includes registration data (name, jurisdiction, registration number, date of registration, legal address), constituent documents (the charter or its equivalent, a founding agreement if any), information on the size and distribution of the authorized capital, an up-to-date extract from the register of legal entities (in Russia — the EGRUL), and information on the types of activity and licenses.

For associated persons, identification data is collected on directors, members of the collegial executive body, founders (participants, shareholders), and persons acting on behalf of the company without a power of attorney. The volume of information on each person is analogous to the requirements for identifying an individual under Federal Law 115-FZ: full name, date of birth, citizenship, identity document, registration address, INN (if available).

At this same stage, information on the ownership structure is requested: who the participants are and in what shares, whether the ownership chain includes other legal entities. If companies are present among the participants, the process is repeated for each link until an individual is reached. This information will become the basis for the subsequent identification of the UBO, examined in a separate section.

Data sources are divided into primary (documents provided by the customer) and external (state registers, commercial databases, open sources). Relying only on primary documents is a common mistake: the customer may provide outdated or distorted information. Cross-verification through external sources reduces this risk.

For Russian companies, the key external source is the EGRUL: it contains information on registration, founders, the size of shares, the director, and the status of the legal entity. For foreign counterparties, national registers are used: Companies House (UK), Handelsregister (Germany), SEC EDGAR and state registers (USA). When working with offshore jurisdictions, access to registry data may be limited — in such cases the volume of documents requested from the customer increases.

The volume of data collected depends on the customer’s risk profile, the jurisdiction of registration, the type of activity, and the requirements of internal policy. For a customer from a regulated industry (a bank, an insurance company), the basic set may be sufficient. For a company from a high-risk jurisdiction or with an opaque ownership structure, the list is expanded: financial statements, licenses, evidence of real operating activity, and reference letters from the servicing bank are requested.

How to Verify Registration, Status, and Authority

The collected documents and registry data must be verified. The goal is to ensure that the company is registered, operating, not in the process of liquidation or bankruptcy, and that the information it has provided corresponds to reality.

For Russian legal entities, verification of the fact of registration and current status is performed through the EGRUL (available on the Federal Tax Service website). The extract will show whether the company is registered, whether it is active, and whether entries have been made about the start of liquidation, reorganization, or exclusion from the register by decision of the registering authority. Separately, it is worth checking for a mark of unreliability of information — the Federal Tax Service enters such records if the address, director, or founder was not confirmed during a check.

Next comes the comparison of data from the customer’s documents with the registry data. The name, OGRN, INN, address, director, composition of founders, and size of shares in the EGRUL extract must match the constituent documents and the customer’s questionnaire. Discrepancies are a signal: they may indicate either a technical error or an attempt to mislead.

If the contract is signed by the general director, their authority is confirmed by the EGRUL extract and the decision (minutes) on the appointment. If a representative acts under a power of attorney — the power of attorney itself is checked: by whom it was issued, whether the term has expired, whether the scope of authority corresponds to the nature of the operation. In a number of cases, the charter limits the director’s authority by the transaction amount or the type of operation — this is also a subject of verification.

For foreign legal entities, the procedure is analogous in logic but more complex technically. Registration documents (Certificate of Incorporation, Certificate of Good Standing, an extract from the commercial register) are requested from the customer and verified through the national register. If there is no direct online access to the register, commercial databases or requests through registration agents are used. Documents issued abroad, depending on the jurisdiction, may require an apostille or consular legalization.

At this same stage, it is advisable to check for the company’s presence in bankruptcy registers (in Russia — the Unified Federal Register of Bankruptcy Information), the Federal Bailiff Service databases (enforcement proceedings), and arbitration courts. A significant volume of debts or court disputes does not necessarily mean a denial of service, but it affects the assigned risk level.

Automating this stage is critical for scalability. With manual verification, a single company can take from several hours to several business days — depending on the jurisdiction and the complexity of the structure. KYB-class platforms perform queries to registers, data comparison, and report generation in seconds, freeing up the compliance team’s resource for the analysis of non-standard cases.

Automate the KYB check: from a registry query to a ready result

Manual verification of a single company can take hours, and with a complex jurisdiction — days. The NeuroVision KYB module performs verification of status, registration data, and associated persons against registers — including the EGRUL/EGRIP, the bankruptcy register, the Federal Bailiff Service, and the database of nominee directors — with an average API response time of under one second. We will connect the module to your infrastructure via REST API or SDK and configure the verification scenarios and trigger thresholds for your internal policies.

As an output, you will receive a structured result for each counterparty with risk flags and justification, while up to 90% of cases are handled without operator involvement. The module’s coverage is more than 100 countries, and the availability SLA is 99.99%. To start, we will need a description of your verification scenarios and your requirements for data sources.

Request a demonstration of the KYB module

How to Verify Directors, Founders, and Authorized Signatories

Decisions are made, contracts are signed, and funds are managed by specific individuals. Verifying these persons is a mandatory part of KYB, without which the picture remains incomplete.

The list of persons to be verified is formed on the basis of the data collected earlier. It includes: the sole executive body (general director, president, managing director — depending on the form), members of the collegial executive body (if applicable), founders (participants, shareholders), and persons vested with signing authority on the basis of a power of attorney or an internal administrative document.

Identification is performed for each person. The composition of the information is determined by Federal Law 115-FZ (subparagraph 1, paragraph 1, Article 7) and the organization’s internal procedures: full name, date and place of birth, citizenship, details of the identity document, registration address, INN. For foreign citizens, the data of migration documents is additionally recorded.

The director indicated by the customer must match the person recorded in the EGRUL (or an analogous register of a foreign jurisdiction). If another director is listed in the register — this is a significant discrepancy requiring immediate clarification.

A separate block of checks is related to identifying signs of nominee status. A director or founder may be a front — this is a common practice in schemes for concealing the real owners. The indicators: a person is simultaneously listed as a director or founder in a large number of companies (a «mass director» or «mass founder» in Russian practice), a person is registered at a mass-registration address, the age and professional profile do not correspond to the scale of the business. Information about mass directors and mass addresses is available through the Federal Tax Service and a number of commercial services.

The presence of disqualification is checked — against the Federal Tax Service register of disqualified persons.

A disqualified person is not entitled to hold a leadership position, and their presence as a director renders the corresponding entry in the EGRUL invalid.

In parallel, AML screening of each identified person is conducted: a check against sanctions lists, PEP lists, and adverse media databases. The details of these checks are disclosed in the section on embedding AML into the KYB process, but the screening begins precisely here — at the stage of identifying individuals.

The result is a confirmed list of the company’s key persons with an indication of their roles, the scope of their authority, and the identified risks. This list forms the basis of the customer file and is used when making a decision about the start or continuation of cooperation.

How to Identify and Verify a Company’s UBO

Verifying the company and its directors is a necessary but insufficient step. Until the ultimate beneficial owner (UBO) is established, the risk picture remains incomplete. The UBO — the individual who ultimately derives benefit from the business or controls it — most often becomes the source of sanctions, corruption, and reputational threats. The ownership structure is far from always transparent: chains of holdings, trusts, nominee holders, and offshore jurisdictions are capable of concealing the real beneficiary behind several corporate layers.

Image

Under Russian law (Article 3 of Federal Law No. 115-FZ), a beneficial owner is recognized as an individual who directly or indirectly owns more than 25% of a legal entity’s capital or has the ability to control its actions. The 25% threshold coincides with the FATF Recommendation (Recommendation 24) and the basic EU standard under the AMLD Directives. Certain jurisdictions set stricter thresholds: India lowered it to 10%, and a number of EU states have the right to lower the bar to 15% for high-risk sectors. For the KYB process this means that the threshold for determining the UBO depends on the customer’s jurisdiction and the jurisdiction of your organization, and in cross-border relationships the stricter of the two should be applied.

How to Build the Ownership Structure and Disclose Direct and Indirect Ownership

The starting point is the corporate documents: the founding agreement, the charter, the register of shareholders or participants, corporate agreements, decisions of general meetings. For Russian companies, the base layer of data is taken from the EGRUL; for foreign ones — from national registers (Companies House in the UK, the FinCEN BOI Registry in the USA, ACRA in Singapore).

On the basis of these documents, an ownership tree is built — a diagram in which each node represents a legal entity or an individual, and each connection represents a participation share. The task is to traverse the tree until each branch terminates in an individual. If company «A» is 60% owned by company «B», and company «B» is 80% owned by the individual Ivanov, then Ivanov’s share in company «A» is calculated multiplicatively: 60% × 80% = 48%. Since 48% exceeds 25%, Ivanov is the UBO of company «A» by the criterion of indirect ownership.

In multi-level structures, branching and intersections are possible: a single person may own shares through several parallel chains. In such a case, the shares are summed. If direct ownership is 10%, and through an intermediate company — another 18%, the total share of 28% exceeds the threshold.

To verify the ownership chain, the following are used:

  • registers of legal entities (EGRUL, foreign corporate registries);
  • registers of beneficial owners, if they exist in the jurisdiction (the PSC Register in the UK);
  • extracts from registers of shareholders or shares;
  • constituent and corporate documents obtained from the customer;
  • commercial databases aggregating information from several jurisdictions.

Automating this stage reduces manual work and lowers the probability of error. Platforms with KYB functionality obtain data from registers via API, automatically build the ownership tree, and calculate the final shares, signaling when thresholds are exceeded.

How to Identify Control Without a Formal Share

Legislation and the FATF standards define the UBO not only through a share in the capital but also through actual control. A person with a share of less than 25% may turn out to be the UBO if they are able to determine the company’s decisions. Typical mechanisms of such control:

  • the right to appoint or remove members of the board of directors or the sole executive body;
  • the right of veto over key decisions, enshrined in a corporate agreement or the charter;
  • a power of attorney or shareholders’ agreement granting the authority to vote on behalf of other participants;
  • actual management of the company’s activity without a legally formalized position;
  • nominee structures in which the registered owner acts on the instructions of another person.

To identify informal control, the following are analyzed: the charter and corporate agreements (shareholders’ agreements), minutes of general meetings, trust declarations, powers of attorney for management, as well as actual circumstances — who signs key contracts, who manages the bank accounts, who makes personnel decisions.

Trusts and nominee holders deserve special attention. If shares are formally listed under a trust manager (trustee), the beneficiary is the person in whose interests the trust was created, not the manager. Similarly, with a nominee shareholder, the UBO is the person on whose behalf the nominee holds the shares.

Signals for an in-depth control check: the disproportionate influence of a minority participant on management, frequent changes of directors, the presence of offshore links in the chain, the absence of real activity at intermediate companies (signs of a shell company), as well as cases where nominee directors or shareholders are found in the databases of known nominee services.

What to Do If the UBO Cannot Be Confirmed

If all reasonable measures have been taken but the ultimate beneficiary has not been established, Federal Law 115-FZ (subparagraph 2, paragraph 1, Article 7) allows the sole executive body of the customer — as a rule, the general director — to be recognized as the beneficial owner. An analogous approach is enshrined in international practice: FATF Recommendation 10 provides that, when it is impossible to identify the UBO, the company’s senior management is considered as the controlling person.

Such a fallback is not a reason to cease work. The inability to establish the UBO is itself a red flag. Depending on the customer’s risk level, it is recommended to:

  • record all the steps taken and the responses received (or refusals to respond) in the customer file — this is critically important for audit and reporting to the regulator;
  • raise the level of verification (EDD — Enhanced Due Diligence): request notarized declarations of beneficial ownership, conduct additional screening of management, check for negative mentions in the media;
  • set a shorter cycle for reviewing information: instead of an annual update — once a quarter or upon any change in the structure;
  • at a high risk level — consider refusing to establish a business relationship.

According to Article 6.1 of Federal Law No. 115-FZ, legal entities are obliged to update information on their beneficial owners at least once a year and to provide it upon request by Rosfinmonitoring or the tax authorities within a seven-day period. The absence of such information or a refusal to provide it entails administrative fines: from 100,000 to 500,000 rubles for legal entities (Article 14.25.1 of the Code of Administrative Offenses of the Russian Federation).

Disclosing the UBO should be built in as a mandatory element of the KYB pipeline — alongside registration verification and director screening. Automating the construction of the ownership tree, the calculation of shares, and the monitoring of changes in registers makes it possible to scale the process without a proportional growth of the compliance team. Integration with AML screening at this stage ensures a single point of decision-making, where data on the ownership structure and data on sanctions, PEP status, and negative media profile are analyzed jointly.

Disclose the ownership structure and verify every link in a single loop

Building the ownership tree, calculating aggregate shares, and checking each beneficiary against sanctions and PEP lists are tasks that scale with difficulty when performed manually. The NeuroVision KYB module automatically builds the ownership chain based on data from the registers of more than 100 countries, calculates direct and indirect shares, and the AML loop immediately checks the identified UBOs against 1,700+ sources — from the consolidated UN and OFAC lists to Rosfinmonitoring and adverse media.

We will configure the KYB–AML linkage so that data on the ownership structure and the results of compliance screening form a single counterparty file. You will receive an end-to-end process — from the first query to a ready card with a risk assessment — without manual transfer of data between systems. Continuous monitoring of changes in registers and lists will make it possible to track the emergence of new risks after onboarding.

Submit a request for a solution selection

How to Embed AML into the KYB Check of a B2B Customer

A KYB check establishes that a company exists, is registered, and is managed by certain persons. But by itself it does not answer the question of whether it is safe to work with this company. The answer is given by AML screening — a check of the company and all persons associated with it against sanctions lists, lists of public officials (PEP), and sources of negative information (adverse media).

In practice, AML does not exist separately from KYB: it is a single process in which the data collected at the stage of identifying the company immediately enters the compliance-check loop. The company’s registration details, the full names of directors, founders, and UBOs are input data for sanctions screening and reputational risk analysis. If these stages are split into different processes or conducted manually with a delay, the probability grows of missing a match that, by the time of the screening, had already appeared in the updated lists.The principle of cascading: not only the legal entity is checked but also every person in the chain of ownership and management. If the company is clean but its beneficiary is included in a sanctions list, the risk extends to the entire structure. FATF, in Recommendation 24, directly points to the need to ensure access to reliable data on the real owners of legal entities. In Russian legislation, an analogous requirement is enshrined in Article 7 of Federal Law No. 115-FZ: financial monitoring entities are obliged to identify beneficial owners and check them against the lists related to extremism, terrorism, and money laundering.

Image

The result of embedding AML into KYB is a single counterparty file in which the company’s legal structure, data on associated persons, and the results of all compliance checks are interconnected and available for re-analysis when circumstances change.

How to Check the Company, Directors, Founders, and UBO Against Sanctions Lists

Sanctions screening is the comparison of data on the company and individuals with the lists of restrictive measures of state and interstate regulators. The minimum set of sources for an international B2B loop: the consolidated list of the UN Security Council, the OFAC lists (SDN, SSI, and other programs), the consolidated EU sanctions list, the HM Treasury and OFSI lists (UK), as well as the Rosfinmonitoring lists for operations involving Russian counterparties. Depending on the jurisdictions of the business, additional national lists may be required — Switzerland (SECO), Canada, Australia (DFAT), Japan.

Four categories of subjects are subject to verification: the legal entity itself, its directors and authorized signatories, the founders at each level of ownership, and the UBO. Missing any of these levels creates a blind spot: sanctions restrictions often extend not only to direct persons on the lists but also to structures affiliated with them. The OFAC 50 Percent Rule assumes that a legal entity in which one or more persons on the SDN list collectively own 50% or more is itself considered blocked — even if its name is absent from the list. EU and UK regulators apply the same logic.

Technically, screening works through fuzzy-matching algorithms that compare names, dates of birth, addresses, and identifiers from the customer file with entries in the sanctions databases. This is necessary because the spelling of names in different languages, transliteration, typos, and deliberate distortions are a common phenomenon. The solution used must support working with Cyrillic and Latin scripts simultaneously and allow the trigger threshold to be configured: too strict a threshold will miss matches with spelling variations, too soft a one will bury compliance officers in false positives.

Sanctions lists are updated frequently — up to daily changes. A one-time check at onboarding does not protect against the situation where a counterparty or its beneficiary ends up on a list after the start of cooperation. Sanctions screening must be continuous: at each update of the lists, the system automatically rescans the base of active customers and notifies the responsible employee of new matches.

The following are recorded as a result: the date of the check, the list of sources used and their version, the result for each subject (match / no match / requires manual review), as well as the decision of the responsible person if a match was identified and reviewed.

Configure sanctions screening with daily updates and fuzzy matching

Sanctions lists are updated up to several times a week, and transliteration and variations in name spelling make exact matching insufficient. The NeuroVision AML module aggregates data from 1,700+ sources — the UN, OFAC (SDN and other programs), the EU, HMT/OFSI, Rosfinmonitoring, and national lists by region — and updates the key lists daily. Fuzzy-matching algorithms work with Cyrillic and Latin scripts simultaneously, and the trigger threshold is configurable to reduce false matches without missing real ones.

We will connect sanctions screening to your KYB pipeline: every company, director, founder, and UBO will be checked automatically at onboarding and again — at each update of the lists. Automation makes it possible to reduce the manual load on the compliance team by up to 80%. The approximate integration timeline for the AML loop is 1–2 days depending on the set of sources and information-security requirements.

Request an AML screening estimate

How to Check PEP and Negative Mentions for the Company and Associated Persons

PEP screening and the check for negative mentions (adverse media) are two separate but closely related stages that complement sanctions screening and help assess reputational and corruption risks.

A politically exposed person (PEP, Politically Exposed Person) is an individual who holds or has held a prominent state or public position.

By the FATF classification, three categories are distinguished: foreign PEPs (heads of state, ministers, senior judges, generals, heads of state corporations of other countries), domestic PEPs (analogous positions in the country of registration of the checking organization), and PEPs of international organizations (heads of the UN, the World Bank, the IMF). PEP status also extends to immediate relatives and business partners — the so-called RCA (Relatives and Close Associates).

PEP status does not mean involvement in unlawful activity. It means an elevated risk of corruption, bribery, and money laundering by virtue of access to state resources and levers of influence. The FATF Recommendations (Recommendation 12) and Federal Law 115-FZ require applying enhanced measures to PEPs: establishing the sources of the origin of funds and property, obtaining senior management approval to establish or continue the business relationship, and conducting enhanced monitoring of operations.

Within a KYB check, all identified individuals undergo PEP screening: directors, founders, authorized signatories, and UBOs. If the ultimate beneficiary of a company turns out to be a PEP or a close relative of a PEP, this automatically raises the counterparty’s risk level and launches the enhanced due diligence (EDD) procedure.

The check for negative mentions (adverse media screening) is aimed at identifying publications linking the company or its key persons to corruption, fraud, criminal prosecution, violation of sanctions regimes, or participation in money-laundering schemes. The sources are publications of regulators, court decisions, investigations by law-enforcement agencies, and materials from authoritative media.

Adverse media closes the zone that formal lists do not cover. A person may not appear in any sanctions list but be a subject in a criminal investigation or a public corruption scandal. Without a media check, this information will remain outside the perimeter of compliance.

In practice, PEP screening and adverse media are most often implemented through a single query to a compliance platform that aggregates data from hundreds and thousands of sources. The result is a list of matches with an indication of the category (PEP / RCA / adverse media), the source, and the degree of relevance. The compliance officer’s task is to verify the matches, filter out false positives, and document the conclusions in the customer file.

Combine PEP screening and the adverse media check in a single query

A beneficiary’s PEP status or a key person’s connection to a corruption scandal in the media can drastically change a counterparty’s risk profile. The NeuroVision AML module combines PEP screening — including checking immediate relatives and business partners (RCA) — with the analysis of negative mentions from publications of regulators, court decisions, and authoritative media within a single query to 1,700+ sources. The system assesses the significance of each match and ranks the results, reducing the share of false positives.

We will configure the module so that the results of the PEP and adverse media checks are recorded in the customer card with an indication of the category, source, and degree of relevance. The built-in case management will allow the compliance officer to verify matches, leave comments, and form an audit log — without transferring data to external systems.

Get a consultation on compliance modules

When Enhanced Due Diligence Is Needed

A standard KYB check with AML screening is sufficient for counterparties with a transparent structure, understandable activity, and the absence of matches against sanctions and PEP lists. The transition to enhanced due diligence (EDD) is dictated by a number of triggers.

A match against sanctions lists, PEP status of a beneficiary or director, the identification of negative mentions linking the company or its key persons to financial crimes — these are the most obvious grounds.

A complex or opaque ownership structure is the second trigger. If the ownership chain passes through several jurisdictions, includes nominee directors, trusts, or funds, and the UBO cannot be established by standard means — this is a direct signal for EDD. The same applies to situations where the customer cannot or refuses to provide supporting documents.

The jurisdiction of registration or activity also affects the decision. If a company is registered in a country with a high level of corruption, a weak AML/CFT regime (including jurisdictions from the FATF high-risk lists), in an offshore zone with opaque corporate legislation, or in a country under sectoral sanctions — a standard check is insufficient.

The characteristics of the business itself: activity in high-risk industries (cryptocurrencies, cash turnover, commodity trading, gambling, the defense industry), volumes of operations disproportionate to the declared scale of activity, frequent changes of directors or founders, a mismatch between the declared profile and the actual operations.

Negative information from internal systems: if during transaction monitoring (KYT) or a repeat check anomalies are detected — volumes uncharacteristic of the customer’s profile, payment routes through transit jurisdictions, the structuring of operations — the compliance service initiates EDD even in the absence of external matches.

At the procedural level, EDD means a deeper analysis of the sources of the origin of funds and wealth of the key persons, an expanded check of business reputation (including queries to open registers and databases of court decisions in several jurisdictions), an assessment of the economic sense of the planned operations, as well as approval of the decision on the customer at the level of senior management.

The absence of clear criteria for the transition to EDD is one of the typical vulnerabilities of compliance programs. Regulators and external auditors expect that the EDD triggers are formalized in internal policy, applied uniformly, and documented. Any decision — both to conduct EDD and to refrain from it — is recorded in the customer file together with its justification.

Formalize EDD triggers and manage cases in a single system

The absence of clear criteria for the transition to enhanced due diligence is a vulnerability that regulators and auditors identify first. The NeuroVision compliance loop makes it possible to set escalation rules — from a beneficiary’s PEP status and the jurisdiction of registration to anomalies in transactional behavior — and apply them uniformly to all counterparties. Every decision is recorded in case management with a full history of actions, comments from the responsible specialist, and an audit log.

We will configure the scenarios and trigger thresholds for your internal policy, connect the needed data sources, and ensure the routing of cases to the responsible employee. Standard checks are handled automatically — up to 90% of cases without manual intervention — while non-standard situations are escalated with full context for decision-making. The platform’s availability SLA is 99.99%.

Sign up for a demonstration of the compliance platform

How to Make Decisions and Conduct Monitoring

The data collected on the company, its ownership structure, and associated persons is only half the work. The second half is turning it into a substantiated decision: accept the customer, reject them, or limit cooperation. After a decision is made, a continuous monitoring cycle begins: it is precisely during the stage of an active relationship that the risks most often manifest that could not be identified at onboarding.

How to Assign Risk and Make a Decision on the Customer

The risk-based approach (Risk-Based Approach, RBA) is the foundation of the decision on every B2B customer. FATF directly states: compliance resources must be concentrated where the risks are higher rather than distributed evenly across all counterparties. Every company that has passed a KYB check and AML screening receives a final risk assessment that determines the depth of further measures and the frequency of review.

The assessment is composed of several categories of factors. Country risk takes into account the jurisdiction of the company’s registration, the location of the UBO and key persons, and the presence of the jurisdiction in the FATF lists or in lists of countries with elevated risks. Industry risk is determined by the customer’s sector of activity: financial services, cryptocurrency operations, gambling, trading in precious metals, and a number of other industries raise the overall profile. Structural risk depends on the transparency of the ownership chain: multi-level holdings, nominee directors, trusts, and offshore links increase the probability of concealing the ultimate beneficiary. Transactional risk is assessed by the expected volumes, frequency, and directions of payments — especially in cross-border operations. Personal risk takes into account PEP status, the presence of sanctions matches, criminal records, and negative media mentions for directors, founders, and UBOs.

Based on the totality of factors, the customer is assigned a risk level — as a rule, low, medium, or high (specific models may be more detailed depending on internal policy). Each level determines the further course of action:

  • Low risk — a standard due diligence procedure (SDD/CDD), a standard review frequency (usually once a year or less often, depending on the jurisdiction), automatic decision-making.
  • Medium risk — a standard procedure with additional measures: clarification of the source of funds, a request for additional documents, a shortened review interval. The decision may be made automatically with oversight from a compliance officer.
  • High risk — enhanced due diligence (EDD), mandatory participation of a senior compliance specialist or the MLRO in the decision-making, the shortest possible review cycle. At this level, additional verification of the UBO from independent sources, confirmation of the origin of capital, and a detailed analysis of the customer’s business model may be required.

The «accept / reject / accept with restrictions» decision is recorded with an indication of the grounds, the date, and the responsible person. If a customer is rejected, the reasons are documented so that during an audit or a regulator’s request the logic of the decision can be reproduced. In the Russian context, Federal Law 115-FZ obliges entities subject to the law to conduct an assessment of the degree of risk of suspicious operations before the start of servicing the customer and to record its results in the questionnaire.

Automating scoring reduces the load on the compliance unit. Scoring engines make it possible to set the rules for calculating the score, the thresholds for each level, and the escalation conditions. The final decision on high-risk customers remains with a human: no regulator recognizes a fully automated refusal or approval in the EDD zone.

What to Record in the Customer File

The customer file is a structured evidence base confirming the fulfillment of compliance obligations. During a regulator’s inspection or an external audit, it is precisely the completeness and coherence of the file that determine whether proper due diligence was conducted.

Several blocks are recorded in the file of a corporate B2B customer.

CategoryDescription
Company identification dataThe full and abbreviated name, registration number, INN (or equivalent), legal and actual address, date of registration and current status, information on licenses and permits.
Data on the ownership and management structureThe list of founders and their shares, information on directors and authorized signatories, the ownership chain up to the established UBO, documentary confirmation of each link (register extracts, constituent documents, corporate decisions).
AML screening resultsThe dates and results of checks of the company, directors, founders, and UBO against sanctions lists, PEP lists, and adverse media databases. If matches are found — the results of the analysis are recorded: confirmed match or deemed false positive, with justification.
Risk assessmentThe assigned level, the date of assessment, the factors that influenced the final score, the full name of the employee who approved the assessment. When the risk level changes, an entry is added indicating the reason for the review.
Decision on the customerAccepted, rejected, or accepted with restrictions; the date of the decision; the grounds; the full name and position of the responsible person.
Documents and copiesConstituent documents, register extracts, powers of attorney for representatives, confirmations of authority. If the documents are in a foreign language — a notarized translation.
Action logThe chronology of all checks, requests, updates, and decisions on the customer, with a binding to dates and executors.

In accordance with Federal Law 115-FZ, the retention period for the file is no less than five years from the moment the relationship with the customer ends. Similar requirements are provided for by the EU AML directives and the FATF Recommendations, although the specific periods depend on the jurisdiction.

The file is updated at every significant event — a change of UBO, a change of jurisdiction, the appearance of a new match in the sanctions lists — and not only within the scheduled review. Each update is recorded as a separate entry indicating the date and grounds.

Which Events Trigger a Repeat AML and KYB

Scheduled review is a necessary but insufficient element of monitoring. Between regular checks (once a year for standard risk, once every six months or more often for high risk), events may occur that drastically change the customer’s risk profile. The compliance system must recognize triggers and launch an unscheduled check.

Changes in the company’s structure. A change of director, founder, or UBO is one of the most significant triggers. A new beneficiary may turn out to be on a sanctions list or be a PEP. Reorganization, merger, division, a change of legal address or jurisdiction — each of these events requires updating the data and recalculating the risk.

Updates of sanctions and PEP lists. International and national lists are updated regularly: the UN, OFAC, the EU, HMT/OFSI, Rosfinmonitoring publish changes at their own pace, sometimes several times a week. If a person or company connected to the customer ends up in an updated list, a repeat screening must happen immediately.

Negative mentions. The appearance of information about the customer, their UBO, or associated persons in the context of court proceedings, criminal investigations, corruption scandals, financial violations, or license revocations.

Anomalies in the customer’s behavior. A sharp increase in operation volumes, the appearance of new counterparties in high-risk jurisdictions, uncharacteristic transactional patterns. In combination with a KYT transaction-monitoring module, such anomalies are identified in the flow rather than in a retrospective analysis.

A request or order from the regulator. An external request from a financial intelligence unit, a tax authority, or a relevant regulator is itself grounds for an unscheduled review of the entire file.

Doubts about the reliability of previously obtained data. If during any interaction with the customer discrepancies are found between previously provided information and current data, Federal Law 115-FZ obliges the organization to update the questionnaire within seven business days.

A reactive approach — a manual check once every six months — leaves a blind spot in which a sanctioned person can operate on the platform for months. The continuous monitoring model (perpetual KYC/KYB), in which the system automatically tracks changes in registers, sanctions lists, and the media, while trigger events generate an alert for the compliance officer, is a more resilient option. With this approach, scheduled review becomes a checkpoint rather than the sole mechanism of updating.

Image

For the implementation of continuous monitoring, the technological infrastructure is critical: API integration with data sources, an event-driven architecture for handling alerts, automatic recalculation of the risk score when a new signal arrives, and the routing of cases to the responsible specialist.

Launch continuous monitoring of counterparties instead of point-in-time checks

The reactive model — a manual check once every six months — leaves a window in which a sanctioned person can operate for months without detection. The NeuroVision AML and KYB modules implement continuous monitoring: at every update of sanctions, PEP, and registry data, the system automatically rescans the base of active customers and sends notifications to the responsible specialist via webhooks. Key lists are updated daily, and the average API response time is under one second.

We will design and connect a monitoring loop to your infrastructure: define the alert triggers, configure the automatic recalculation of the risk score and the routing of cases. Deployment is possible in the cloud, within your perimeter (on-premises), or in a hybrid variant. To assess the volume and choose the optimal architecture, we will need information on the number of counterparties and the current data sources.

Send a request for a pilot project
Conclusion
Compliance for B2B begins with a transparent ownership structure and never ends

A reliable AML and KYB process for corporate customers is a single chain: collecting registration data, disclosing the ownership structure up to the ultimate beneficiary, sanctions and PEP screening of every link, assigning a risk level, recording all decisions in the file. None of these stages works in isolation: skipping the UBO check devalues the screening of the company, and a one-time check at onboarding leaves a blind spot for the entire period of cooperation. Cascading and continuity turn a set of formal procedures into real protection against sanctions, corruption, and reputational risks.

The practical resilience of such a loop is determined by three conditions: formalized triggers and thresholds, automation of routine checks and monitoring, and clear documentation of every decision — from the initial assessment to the unscheduled review. Companies that build in this logic at the start gain a scalable process capable of adapting to changes in sanctions lists, the customer’s structure, and regulatory requirements without a proportional growth of the load on the compliance team.