KYB vs KYC vs Ongoing Monitoring: What Each Covers, and Where the Gaps Are

By Mike North Jun 23, 2026

When you write about the gap between KYC, KYB and ongoing monitoring, any working assumption was the one you’ll find in a lot of vendor content: that “ongoing monitoring” in identity products means periodic sanctions re-screening and not much else.

That isn’t true.ongoing AML monitoring tools may cover sanctions lists, watchlists, PEPs and adverse media, across individuals and legal entities, drawing on thousands of media sources with contextual filtering and refresh cycles that run from a couple of hours to a month depending on the feed. It’s a serious product doing serious work, and broadly the same is true of its main competitors.

So the gap isn’t where I assumed it was. It’s somewhere more interesting, and once you see it you can’t unsee it.

The gap isn’t coverage. It’s the question.

KYC: Is this person who they claim to be?

Document verification, liveness detection, biometric matching, address validation, plus screening against sanctions and PEP lists at signup.

The technology here has become genuinely excellent. A well-built flow verifies an individual in under a minute, and modern liveness detection is good enough that most attackers have moved on to other parts of the funnel.

It answers an identity question, and it answers it properly. What it doesn’t tell you is what that person does, or what they become. That isn’t a criticism. It’s a scope, and the vendors are clear about it.

KYB: a considerably harder problem

KYB asks whether a business is real, and who actually owns and controls it. Most explainers rush past this in a paragraph, which does it a disservice.

The difficulty is structural, and I mean that literally. A person has an identity. A business has a structure, and structures are built by people, occasionally by people who would prefer the structure not be legible.

So a proper KYB check runs through several layers. Entity verification against a corporate registry. Director and officer identification. And beneficial ownership — working out which humans actually sit behind the entity, typically anyone holding twenty-five percent or more, though that threshold moves by jurisdiction and, if we’re being honest, is fairly gameable by anyone sufficiently motivated. FinCEN and the EU’s AML directives take somewhat different positions on where the line sits.

Then there’s the ownership chain. Company A is held by Holding B, registered somewhere with a thin registry, which is owned by two entities in a third country, one of which is a trust. Somewhere at the bottom of that there are people. Finding them is the job.

Registry quality varies enormously, which is the part almost nobody mentions. Some jurisdictions publish beneficial ownership openly. Some publish incorporation and nothing further. Some publish a name, a date, and treat the rest as commercially confidential. A KYB provider is only ever as good as the registries it can reach, and no provider can conjure data a government has declined to collect. OpenCorporates is a useful way to see how uneven the underlying picture actually is.

All of which is to say KYB is hard, the good providers do it well, and it’s worth more than most buyers appreciate.

But here’s the thing about it that I think matters most, and I haven’t seen anyone put it down in writing.

A KYB check is a snapshot of a structure that was specifically designed to be changed.

That’s what corporate structures are for. Companies redomicile. Directors get appointed and resign. Shares transfer. Subsidiaries appear in new jurisdictions. None of that is suspicious behaviour. It’s ordinary corporate life, and it happens constantly.

Which gives a KYB verification a much shorter shelf-life than a KYC verification. A person’s identity is reasonably stable. A company’s structure is not, and almost nobody treats those two facts as different.

Ongoing monitoring: what the phrase actually refers to

Now the term that causes the confusion, and I want to be careful here, because getting it wrong would be both unfair and self-defeating.

When an identity vendor says “ongoing monitoring,” they mean ongoing AML monitoring. And it’s a real product, not a marketing gesture.

Take the clearest example. Some kinks of software continuously update applicant and entity profiles against changes in sanctions lists, watchlists and adverse media worldwide. It covers legal entities as well as individuals. It reads across a very large number of media sources, categorises matches by type, and uses a language model to help analysts triage them.

That is not a thin capability. Any firm with customers it’s accountable for should have something like it running.

Two operational details worth knowing, and they sit in the documentation rather than the marketing. It’s generally an add-on rather than a default. And it typically runs forward from the point you switch it on, so entities approved before you bought it need re-screening to enter the monitoring pool at all.

Neither of those is a trick. Both matter a great deal if you assumed monitoring was included and retrospective, which plenty of buyers do.

So where is the gap?

Here’s where I ended up, having been wrong the first time.

Ongoing AML monitoring is built to answer one question, and it answers it well. Is this customer a financial crime risk?

That is precisely the right question if you’re a bank, a payment processor, an exchange, a lender, a gambling operator. You have customers. Money moves through you on their behalf. If one of them is laundering, that’s your regulatory problem, and you need to know the moment their risk profile shifts.

Now think about a fund.

You don’t have customers. You have portfolio companies. You wire money to them once, you hold the position for seven or eight years, and no money moves through you on their behalf at all.

Your question isn’t whether this entity is a financial crime risk to you. Your question is whether this company has changed in ways that affect your position.

And most of the answers to that question simply aren’t AML signals.

Four things that never produce an AML hit

Run through what actually goes wrong inside a portfolio, and ask which of it would trigger an alert in a monitoring system built for financial crime.

A portfolio company redomiciles from Delaware to the BVI and appoints two new directors. That’s a registry event. It isn’t a sanctions match. It isn’t a PEP hit. Unless a journalist happens to write about it, it isn’t adverse to the media either. It produces no AML signal at all, because there’s nothing criminal about it. It’s simply a fact about a company you own part of, and it may have changed your regulatory position considerably.

The exchange a portfolio company settles through has its principal shareholder designated. Your company is now exposed. But the designation is against an entity that is not your applicant, not your customer, and not a counterparty to any transaction of yours. It’s a second-degree exposure, and it sits outside the perimeter of a system built around your direct relationships.

Eleven fake Telegram channels start impersonating a portfolio company’s support desk and draining its users. Nothing in an AML system touches this. There is no watchlist of impersonators. This isn’t a financial crime by your portfolio company. It’s a financial crime against it, and the whole model is pointed the other way.

A founder is named personally in a civil suit in a jurisdiction whose court filings aren’t in any commercial database. It may surface as adverse media eventually, if a publication picks it up. It may not.

None of these are failures of the AML products. All of them are outside the question those products were built to answer.

The applicant model, and why funds break it

There’s an architectural point underneath this that explains why funds struggle to make identity platforms fit, and it’s worth spelling out.

Look at how these systems are actually constructed. There’s an applicant. The applicant is verified. The applicant is approved, rejected, or held for review. Approved applicants can then be monitored. There are verification levels, workflow builders, approval buttons, rejection statuses.

It’s a funnel. It was designed around onboarding, because onboarding is what the customers of these products do all day.

A fund has no funnel. It has thirty-eight companies it already owns part of and cannot un-own. It didn’t approve of them, it invested in them. And if a signal fires, the relationship doesn’t get terminated, because the position is illiquid and will be held for years regardless.

You can bolt a portfolio onto an applicant-shaped system, and firms do. But you spend the whole time fighting the model, because you’re using an onboarding product to manage a holding.

Four questions, not three tiers

The single most common misunderstanding is that these are escalating levels of rigour. KYC is basic, KYB is thorough, monitoring is the advanced tier. That framing is wrong, and it’s why buyers end up confused about what they’ve bought.

They’re not tiers. They’re different questions, and buying the “highest” one doesn’t get you the others.

KYCKYBOngoing AML monitoringEntity risk intelligence
The questionIs this person real?Is this business real, and who controls it?Has this customer become a financial crime risk?What has changed about this entity?
What it watchesAn individualAn entity and its ownership chainSanctions, PEPs, watchlists, adverse mediaRegistries, officers, counterparties, social channels, media
WhenAt onboardingAt onboardingContinuously, forward from activationContinuously, for as long as you hold the position
Built forCustomersCustomersCustomersEntities you’re exposed to but don’t transact with

Who needs which, and in what combination

Once the questions are separated, this resolves fairly cleanly.

If you onboard individuals at volume, a consumer fintech or an exchange or a marketplace, you need KYC. Go and buy it, it works, and it’ll live faster than you expect.

If you onboard businesses, you need KYB, done properly, with real registry coverage and real beneficial ownership resolution. Harder than it looks and worth paying for.

If you’re accountable for your customers’ financial crime risk, you need ongoing AML monitoring on top of both. In most relevant jurisdictions this isn’t optional — FATF Recommendation 10 expects ongoing due diligence on business relationships, not a single check at the gate.

And if your exposure is to entities you’ve invested in rather than customers you’ve onboarded — a VC fund, a crypto fund, a family office, a corporate development team holding minority stakes — then the first three cover the beginning of the relationship and none of them cover the seven years that follow.

That’s the fourth question. It’s a different product, and most firms don’t know it exists.

Where that leaves the three terms

They aren’t a ladder. That’s the misunderstanding worth correcting, and it’s the reason so many firms believe they’ve bought something they haven’t.

KYC verifies a person. KYB verifies a structure, and does it well, and does it once. Ongoing AML monitoring watches your customers for financial crime risk, comprehensively, using data that is genuinely good.

The question of what has changed about an entity you’re exposed to — its officers, its jurisdiction, its counterparties, its public presence, its ownership — is a fourth thing entirely, and most funds have nothing at all running against it.

We’ve written the long version of why that gap exists here, and mapped the whole vendor landscape here, if you’d rather see where everything sits before deciding anything.

If you’d rather just look at it, Beady AI monitors the entities you’re exposed to continuously — portfolio companies, founders, counterparties — across sanctions, adverse media, corporate registries and impersonation, with every signal linked back to its primary source. Book a session and we’ll run it against your real holdings. It takes about twenty minutes and you’ll know within one whether the fourth question is one you actually have.

Mike North
Ceo and Cofounder of Company Name

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris tincidunt vulputate efficitur. Pellentesque nec massa sed ante pharetra elementum. Phasellus ac ante vitae quam ultricies tincidunt ac vel odio.

Lorem ipsum dolor sit amet

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Lorem ipsum dolor sit amet

    Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Ready to get started?

    Helping you go live in days, not weeks.