Zenoo
Learn/KYC vs KYB vs KYT: what they are and how…
Guide

KYC vs KYB vs KYT: what they are and how they stack

A precise disambiguation of KYC, KYB, and KYT: one-line definitions, a genuine three-way comparison table with data sources and governing laws, and the stacking model that shows a business customer needs all three at once.

Last reviewed 27 July 202614 min read
In shortThe answer, first

KYC, KYB, and KYT are three related but distinct compliance checks. KYC verifies that an individual is who they claim to be, KYB verifies a legal entity and the real people who own or control it, and KYT monitors the money moving through a relationship for behaviour that does not fit. They are not alternatives to choose between: they stack across the customer lifecycle.

Key facts
  • KYC (know your customer) answers "who is this person?" and applies to a natural person at onboarding, then on refresh.
  • KYB (know your business) answers "what is this entity and who really controls it?" It is a superset of KYC, not a synonym for it.
  • KYT (know your transaction) answers "what is this customer doing with their money?" and runs continuously, never as a one-off check.
  • A single business customer commonly needs all three: KYB on the entity, KYC on its ultimate beneficial owners and directors, and KYT on its activity.
  • The threshold that usually triggers UBO identification is ownership or control of 25 percent or more.
  • The three are converging into one continuous, event-driven risk view as perpetual KYC and perpetual KYB spread.

KYC, KYB, and KYT in one minute

Searchers conflate these three constantly, and the confusion causes real programme design mistakes. Here is each one in a single line.

KYC (know your customer) verifies that an individual is who they claim to be, and understands the risk they pose, before and during a business relationship. The subject is a natural person, and the core question is "who is this?".

KYB (know your business) verifies that a company legally exists, understands its structure, and identifies the real humans who ultimately own or control it. The subject is a legal entity plus the people behind it, and the core question is "what is this business and who really controls it?".

KYT (know your transaction) monitors the frequency, amount, timing, counterparties, and flow of funds across a relationship, and screens transactions against sanctions and watchlists at the point of payment. The subject is transactions, and the core question is "what are they doing?".

The single most useful thing to understand is that the three are not options to pick between. They stack. KYC and KYB are mostly onboarding checks that answer "who is this?", while KYT runs continuously and answers "what are they doing?". For the mechanism behind each, this page links out to the dedicated guides: what is KYC verification and what is KYB.

What is KYC?

KYC is the regulated process of confirming that an individual customer is who they claim to be. Under the FATF standard, the operative obligation is customer due diligence (CDD) in Recommendation 10: identify the customer and verify their identity from reliable, independent sources; identify and verify beneficial owners where relevant; understand the purpose of the relationship; and conduct ongoing due diligence.

In practice, KYC means collecting identifying data, verifying an ID document, matching a live selfie to it with a liveness check, screening against sanctions, politically exposed person (PEP), and adverse-media lists, and then scoring risk. In the US, FinCEN's Customer Identification Program rule requires at minimum four data points before an account opens: full legal name, date of birth, address, and a government ID number. The subject of KYC is always a natural person. For the full step-by-step mechanism, see the KYC verification guide rather than repeating it here.

What is KYB?

KYB is the equivalent discipline for a legal entity: verifying that a company legally exists, understanding its structure, and identifying the real humans who ultimately own or control it. A KYB check typically covers confirming legal existence and good standing against a company registry, capturing directors and officers, mapping the ownership tree to find ultimate beneficial owners (UBOs), then running KYC-style identity checks plus sanctions, PEP, and adverse-media screening on those UBOs and directors.

Because a KYB check ends by looping back into KYC on the humans it uncovers, onboarding a company needs both: KYB on the entity plus KYC on the individuals behind it. For the KYB workflow in production, see the KYB use case.

Common misconception
KYB is not just KYC for companies
"KYB is simply KYC applied to a business instead of a person."
A company has no face and no passport. The hard part of KYB is the ownership tree: a UBO can sit several layers up through holding companies, trusts, and cross-border entities, and control can exist without equity, for example through voting rights or a controlling agreement. Under the EU Anti-Money Laundering Regulation, control has to be assessed separately from ownership, and national beneficial-ownership registers can no longer be relied on as a standalone verification source. So KYB adds an entity-resolution and graph problem that plain KYC does not have, then loops into KYC on the humans it finds.

UBOs and the 25 percent threshold

The threshold that usually triggers UBO identification is ownership or control of 25 percent or more. The US CDD rule sets it at 25 percent, and the incoming EU Anti-Money Laundering Regulation standardises it as "25 percent or more", so exactly 25 percent now counts, from 10 July 2027.

Under the EU rules, control must be assessed independently of ownership, and firms can no longer treat a register lookup as verification in itself. The verification burden shifts back onto the firm, which has to resolve the ownership graph across multiple data sources rather than trusting a single registry entry.

What is KYT?

KYT is the continuous monitoring and screening of transactional behaviour across a relationship: analysing the frequency, amount, timing, counterparties, and flow of funds to spot activity that does not fit the customer's expected profile, and screening transactions and counterparties against sanctions and watchlists at the point of payment. Unlike KYC and KYB, which are mostly onboarding checks about identity, KYT is an ongoing check about conduct.

Its roots are in traditional AML transaction monitoring, a long-standing obligation. US institutions must monitor for and report suspicious activity under the Bank Secrecy Act, and both FATF Recommendation 10 and UK Money Laundering Regulations 2017 Regulation 28(11) require ongoing scrutiny of transactions throughout a relationship to ensure they are consistent with what the firm knows about the customer. See the transaction monitoring and ongoing monitoring use cases for the workflow.

The term "KYT" itself rose to prominence in crypto. Blockchain transactions do not fit legacy bank monitoring systems, so a crypto-native form of transaction monitoring grew up around on-chain analytics: tracing the flow of funds between wallets, scoring wallet risk, and detecting laundering patterns. The regulatory anchor here is the FATF travel rule, the application of Recommendation 16 to virtual-asset transfers. It requires virtual-asset service providers (VASPs) to collect, verify, and transmit originator and beneficiary information for transfers above the FATF-recommended de minimis threshold of USD or EUR 1,000. So KYT is best understood as transaction monitoring, with a crypto-native branch defined by on-chain analytics and travel-rule data exchange.

Common misconception
KYT is not a one-off check
"Transaction monitoring is a box we tick once at onboarding."
KYC and KYB largely happen at the front door, with refresh cycles. KYT never stops while the relationship is live. Treating transaction monitoring as a task completed at onboarding is a common and serious design error: the point of KYT is to catch behaviour that changes long after the account is opened.

How KYC, KYB, and KYT stack

The three are layers, not alternatives. The clearest way to see this is by who you are onboarding.

When you onboard an individual, you run KYC on the person, then KYT on their activity from then on. When you onboard a business, you run KYB on the entity, KYC on each UBO and director the KYB step uncovers, then KYT on the entity's activity from then on. A single business customer therefore commonly needs all three at once.

  1. 1Worked example, onboarding a payments company. Start with KYB: confirm the entity exists and is in good standing against the company registry, capture its directors and officers, and map the ownership tree.
  2. 2Resolve the humans. The ownership graph surfaces, say, two ultimate beneficial owners and three directors. Run KYC on each of those five people: verify identity, screen against sanctions, PEP, and adverse-media lists, and score their risk.
  3. 3Turn on monitoring. Once the company is live, run KYT continuously across its payments: watch the frequency, amount, timing, and counterparties of its flows, and screen transactions at the point of payment.
  4. 4Keep it current. As perpetual KYC and perpetual KYB spread, the identity checks re-run on triggers, a new director, a change of control, a fresh adverse-media hit, rather than on a fixed calendar. The three layers converge into one continuous risk view.
Three layers on one customer
KYC, KYB and KYT do not compete. They stack: KYB on the entity, KYC on its people, KYT across everything, converging into one live risk view.
One business customer
A payments company being onboarded
KYB · on the entity
At onboarding: registry, legal structure, and the ownership tree.
KYC · on the humans it surfaces
UBOUBODirectorDirectorDirector
Each person: identity, sanctions, PEP and adverse media.
KYT · on the activity
Runs continuously for the life of the relationship. Never a gate; it never stops.
OnboardingKeep it current → life of the relationship

KYC vs KYB vs KYT compared

This side-by-side is the fastest way to keep the three straight. Each column is a distinct check; read across a row to see how they differ on the same dimension.

DimensionKYCKYBKYT
What it verifiesAn individual's identity and riskA legal entity, its structure, and its UBOsTransactional behaviour and flow of funds
SubjectA natural personA company or legal arrangement, plus its UBOs and directorsTransactions and counterparties
Core questionWho is this person?What is this business and who really controls it?What is this customer doing with their money?
When it appliesOnboarding, then refreshOnboarding, then refresh, increasingly continuousContinuously, for the life of the relationship
Key data sourcesID documents, biometrics, electronic identity data, sanctions, PEP, and adverse-media listsCompany registries, UBO registers, ownership-graph data, plus KYC sources for the humansInternal transaction data, on-chain analytics for crypto, sanctions and watchlist screening at the point of payment
Main regulationsFATF Recommendation 10; US CIP rule; UK MLR 2017; EU AMLR (from 2027)FATF Recommendation 10 (beneficial ownership); US CDD rule (25 percent); EU AMLR UBO rules (from 2027)BSA suspicious-activity monitoring; FATF Recommendation 10 ongoing monitoring and Recommendation 16 travel rule; UK MLR 2017 Regulation 28(11)
Typical toolsIDV and biometric vendors, liveness, screeningCompany-data and KYB vendors, UBO resolution, registry lookupsTransaction-monitoring engines, crypto analytics, travel-rule messaging

The laws behind each check

All three trace back to the same global standard, then diverge into instrument-specific rules. Kept here at comparison depth, with the dedicated pillars for detail.

The shared anchor. FATF Recommendation 10 sits behind all three: it sets the four customer due diligence obligations (identify and verify the customer, identify the beneficial owner, understand the relationship, and monitor it) and the standing duty of ongoing monitoring that KYT delivers.

KYC. In the US, the CIP rule mandates the minimum data points collected at account opening. In the UK, the Money Laundering Regulations 2017 set the CDD obligations. In the EU, the Anti-Money Laundering Regulation harmonises CDD across member states from 10 July 2027.

KYB. The FinCEN CDD rule (2018) still requires covered institutions to collect beneficial-ownership information at a 25 percent threshold when a legal entity opens an account. The EU Anti-Money Laundering Regulation standardises the UBO threshold at 25 percent or more, requires control to be assessed independently of ownership, and bars register-only verification, all from 10 July 2027.

KYT. The Bank Secrecy Act requires US institutions to monitor for and report suspicious activity. FATF Recommendation 10 and UK MLR 2017 Regulation 28(11) require ongoing scrutiny of transactions. For crypto, the FATF travel rule (Recommendation 16 applied to virtual assets) requires VASPs to exchange originator and beneficiary data above the USD or EUR 1,000 threshold.

Where we are now (2025 to 2026)

Three shifts are reshaping how firms run the stack right now.

KYB is being reshaped in opposite directions across the Atlantic. In the EU, the Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) creates a harmonised UBO framework applying directly across all 27 member states from 10 July 2027. It standardises the threshold as 25 percent or more, requires control to be assessed independently of ownership, and, critically, means national UBO registers can no longer be a standalone verification source. In the US the direction is the reverse: a March 2025 interim final rule removed the requirement for US companies and US persons to report beneficial ownership under the Corporate Transparency Act, narrowing "reporting company" to foreign entities registered to do business in the US. The FinCEN CDD rule for financial institutions stays active, so the verification burden pushes back onto firms.

The KYT travel rule is scaling fast, but enforcement lags. FATF's 2025 targeted update reports the number of jurisdictions with travel-rule legislation in force rose to 85 in 2025 from 65 in 2024, roughly 73 percent of assessed jurisdictions, with a further 14 in progress. Later reporting puts adoption at about 83 percent but only around 40 percent actively enforcing it. The gap between having a law and supervising it produces the "sunrise problem": a compliant VASP must still exchange travel-rule data with counterparts in jurisdictions that are only partly compliant. These percentages move with each FATF update, so treat them as of the 2025 targeted update.

The whole stack is moving from periodic to continuous. The industry term is perpetual KYC (pKYC), and it now extends to perpetual KYB: event-driven re-verification when something changes, such as a new director, a change of control, or a new adverse-media hit, rather than a fixed calendar review. That pulls KYC and KYB conceptually closer to KYT's always-on posture.

How AI helps, and how it attacks

AI helps at each layer, differently. On KYC it drives document-forgery detection, face match plus liveness, and risk tiering. On KYB the highest-value use is entity and ownership-graph resolution, cross-referencing multiple registries to build the UBO tree and find people manual research misses. On KYT machine learning triages transaction alerts so analysts spend time on genuine anomalies rather than noise, which matters because rule-based monitoring is notoriously false-positive heavy.

The same technology attacks all three. Synthetic identities and deepfakes at onboarding hit KYC and the KYC leg of KYB hardest; see the synthetic identity fraud and deepfake detection pillars for the figures. KYB is attacked through opacity: shell companies, nominee directors, and layered cross-border ownership hide the real UBO. KYT is attacked through structuring and obfuscation: in crypto, mixers, chain-hopping, and peel chains break the flow of funds that KYT tries to trace.

AI as the threat

The honest takeaway: no single vendor stays ahead of every attack vector across identity, ownership, and transactions at once. That is precisely why layered, swappable controls matter, so one vendor's blind spot is covered by another.

What the future looks like

Several directions look settled enough to plan around.

One continuous lifecycle, not three gates. As perpetual KYC and perpetual KYB spread and meet always-on KYT, the neat "onboarding versus monitoring" split blurs into a single, event-driven risk view. The KYB verification burden shifts to firms. With the US Corporate Transparency Act rollback and the EU rules barring register-only verification, independent multi-source UBO resolution becomes standard practice rather than a nice-to-have from 2027. Travel-rule interoperability matures. Expect the sunrise problem to narrow as more jurisdictions enforce, not just legislate, and messaging networks interconnect, though full global coverage remains some way off. Regulatory divergence persists. The EU centralises under its single rulebook and the Anti-Money Laundering Authority, operational since 1 July 2025, while the US stays fragmented, so cross-border firms will run jurisdiction-specific KYB and KYT policies for the foreseeable future.

Key takeaways
  • KYC (know your customer) answers "who is this person?" and applies to a natural person at onboarding, then on refresh.
  • KYB (know your business) answers "what is this entity and who really controls it?" It is a superset of KYC, not a synonym for it.
  • KYT (know your transaction) answers "what is this customer doing with their money?" and runs continuously, never as a one-off check.
  • A single business customer commonly needs all three: KYB on the entity, KYC on its ultimate beneficial owners and directors, and KYT on its activity.
  • The threshold that usually triggers UBO identification is ownership or control of 25 percent or more.
  • The three are converging into one continuous, event-driven risk view as perpetual KYC and perpetual KYB spread.

Frequently asked questions

What is the difference between KYC, KYB, and KYT?

KYC verifies that an individual is who they claim to be. KYB verifies a legal entity, its structure, and the real people who ultimately own or control it. KYT monitors the transactions moving through a relationship for behaviour that does not fit. KYC and KYB are mostly onboarding checks about identity; KYT is a continuous check about conduct. They are not alternatives, they stack.

Is KYB the same as KYC for businesses?

No. A company has no face and no passport. The hard part of KYB is resolving the ownership tree to find the ultimate beneficial owners, who can sit several layers up through holding companies, trusts, and cross-border entities, and control can exist without equity. KYB adds an entity-resolution and graph problem that plain KYC does not have, then loops into KYC on the humans it uncovers.

Does a business customer need both KYC and KYB?

Yes, and usually KYT as well. Onboarding a business means running KYB on the entity, then KYC on each ultimate beneficial owner and director the KYB step uncovers, then KYT continuously on the entity's activity. A single business customer therefore commonly needs all three at once.

What is know your transaction (KYT)?

KYT is the continuous monitoring and screening of transactional behaviour across a relationship: analysing the frequency, amount, timing, counterparties, and flow of funds to spot activity that does not fit the customer's expected profile, and screening transactions at the point of payment. Its roots are in traditional AML transaction monitoring, and the term rose to prominence in crypto through on-chain analytics.

Is KYT the same as transaction monitoring?

KYT is best understood as transaction monitoring, with a crypto-native branch defined by on-chain analytics and travel-rule data exchange. The underlying obligation, ongoing scrutiny of transactions throughout a relationship, is long-standing under the Bank Secrecy Act and FATF Recommendation 10. The "KYT" label became common in crypto because blockchain transactions do not fit legacy bank monitoring systems.

What is a UBO and what ownership percentage triggers KYB checks?

A UBO is an ultimate beneficial owner, the real human who ultimately owns or controls a company. The threshold that usually triggers UBO identification is ownership or control of 25 percent or more. The US CDD rule sets it at 25 percent, and the EU Anti-Money Laundering Regulation standardises it as 25 percent or more, so exactly 25 percent counts, from 10 July 2027.

What is the FATF travel rule?

The FATF travel rule is the application of Recommendation 16 to virtual-asset transfers. It requires virtual-asset service providers to collect, verify, and transmit originator and beneficiary information for transfers above the FATF-recommended de minimis threshold of USD or EUR 1,000. It is the main regulatory anchor for the crypto branch of KYT.

Do KYC, KYB, and KYT ever run at the same time?

Yes. A single business customer commonly needs all three at once: KYB on the company, KYC on its beneficial owners and directors, and KYT running continuously across its payments. As perpetual KYC and perpetual KYB spread, the identity checks re-run on triggers rather than on a fixed calendar, so the three layers increasingly operate as one continuous risk view.

Which regulations require KYC, KYB, and KYT?

All three trace back to FATF Recommendation 10. KYC is delivered through the US CIP rule, UK MLR 2017, and the EU AMLR from 2027. KYB rests on the FinCEN CDD rule (25 percent) and the EU AMLR UBO rules from 2027. KYT rests on Bank Secrecy Act suspicious-activity monitoring, FATF Recommendation 10 ongoing monitoring and Recommendation 16 travel rule, and UK MLR 2017 Regulation 28(11).
ZenooWhere this fits, honestly

Running all three checks usually means integrating a KYC vendor, a KYB and company-data vendor, and a transaction-monitoring or KYT vendor separately. Zenoo orchestrates KYC, KYB, and ongoing monitoring or KYT across best-of-breed vendors behind one integration and one audit trail: your vendors plus Zenoo, not instead of them. It does not itself verify a passport, resolve ownership from primary registries, provide sanctions data, or run blockchain analytics; specialist providers in the Marketplace do that. It routes each check to the right provider, fails over when one is down, and writes the KYB decision, each UBO's KYC, and every monitoring event to a single immutable record spanning 32 audit event types across 8 categories (Zenoo, metrics registry). The average institution already uses about 4.7 verification providers (Zenoo, metrics registry); the AI layer accelerates the manual work on top, with a KYB Researcher that compiles a 50-plus-field dossier in under 60 seconds against a manual 2 to 4 hours (Zenoo, metrics registry).

Sources

Last reviewed 27 July 2026. Every statistic is traceable to a named source.
  1. 01FATF Recommendation 10, customer due diligence and ongoing monitoring
  2. 02FinCEN Customer Identification Program (CIP) rule FAQs
  3. 03FinCEN CDD Final Rule (2018), beneficial ownership at 25 percent
  4. 04FinCEN removes beneficial-ownership reporting for US companies and US persons (March 2025)
  5. 05Baker McKenzie, EU new UBO rules come into force (Regulation (EU) 2024/1624, from 10 July 2027)
  6. 06FATF 2025 Targeted Update on Virtual Assets and VASPs (travel-rule adoption)
  7. 07Sumsub, what is the FATF travel rule (Recommendation 16, USD/EUR 1,000 threshold)
  8. 08Chainalysis, transaction monitoring and the crypto KYT branch
  9. 09FFIEC BSA/AML manual, suspicious-activity monitoring
  10. 10LexisNexis, UK Money Laundering Regulations 2017 ongoing monitoring (Regulation 28(11))
  11. 11Alloy, KYC KYB KYT: know your K-Y terminology (register exemplar)
  12. 12Fenergo, KYC vs KYB: what's the difference?
Was this helpful?
Share