All posts
5 min readOpenKYC Team

KYC vs KYB vs KYA: A Field Guide to Identity Acronyms

kyckybkya

Compliance loves an acronym, and the "know your" family keeps growing. KYC, KYB, KYA, KYT: they sound interchangeable, but each one answers a different question about a different kind of actor. This guide sorts out who gets verified under each label, who demands it, and why all of them are converging on the same underlying problem: proving things about an entity without starting from zero every time.

KYC: know your customer

KYC is the original. It means verifying the identity of an individual customer before, and while, doing business with them. In practice that's document checks, liveness or selfie matching, sanctions and PEP screening, and ongoing monitoring for the life of the relationship.

The legal roots are anti-money-laundering law. In the United States, KYC obligations grew out of the Bank Secrecy Act and were sharpened by the USA PATRIOT Act's customer identification program rules. In the EU, a series of Anti-Money Laundering Directives pushed the same requirements across member states, and the new AML package centralizes supervision further. Most other jurisdictions follow the FATF recommendations, which is why KYC looks broadly similar worldwide.

KYC applies whenever a regulated entity (a bank, broker, exchange, payment institution, increasingly even a gambling operator or marketplace) onboards a natural person. The regulators are financial supervisors and financial intelligence units: FinCEN in the US, national competent authorities in the EU, the FCA in the UK, and their equivalents elsewhere.

KYB: know your business

KYB applies the same logic to companies. When your customer is a legal entity rather than a person, you have to verify that the entity exists, that it is in good standing, and (the hard part) who actually owns and controls it.

That last step is beneficial ownership verification. Shell structures exist precisely to obscure who is behind a company, so regulators require identifying the ultimate beneficial owners (UBOs), typically anyone holding above a threshold such as 25 percent of ownership or control. Once UBOs are identified, each one effectively goes through KYC, so every KYB check contains several KYC checks inside it.

Governments have responded with UBO registries: the EU mandated beneficial ownership registers under its AML directives, and the US introduced beneficial ownership reporting under the Corporate Transparency Act, though its scope has shifted over time. Registries help, but coverage, accuracy, and cross-border access remain uneven, which is why KYB is still slower and more expensive than KYC. Onboarding a business customer can take days or weeks of document collection, registry lookups, and back-and-forth.

KYA: know your agent

KYA is the newest member of the family, and the acronym is genuinely contested. In some compliance contexts it has long meant "know your applicant," essentially KYC at the application stage. But the meaning gaining momentum now is know your agent: verifying AI agents that act on behalf of users.

The driver is agentic commerce. AI agents are beginning to browse, negotiate, and pay on behalf of people, and major payment networks announced agentic payment initiatives in 2025 to support exactly this. The moment an autonomous agent shows up at a checkout or an API with someone's money, a counterparty has to answer new questions: Is this agent legitimate? Who is the human or business behind it? Was it actually authorized for this transaction, within what limits?

No regulator mandates KYA yet: this is an emerging practice, not settled law. But the structural need is the same as KYC and KYB: bind an actor to a verified identity and a defined mandate. We go deeper on this in Know Your Agent: Why AI Agents Need Identity Verification.

KYT, briefly

Know your transaction shifts the lens from the actor to the activity. KYT means monitoring transactions for patterns consistent with money laundering, sanctions evasion, or fraud: unusual volumes, structuring, exposure to flagged wallets. It complements rather than replaces the others: KYC tells you who the customer is, KYT tells you whether their behavior still matches that picture. Most transaction-monitoring obligations come from the same AML frameworks that mandate KYC.

Where they all break down

Strip away the acronyms and the failure mode is identical across the family:

  • Repetition. Every regulated entity verifies the same person, company, or (soon) agent from scratch, because verifications don't transfer between organizations.
  • Cost. Each check has a direct price, and the abandonment caused by slow onboarding costs more. KYB multiplies this, since one business check fans out into many individual checks.
  • Staleness. A verification is a snapshot. The customer's passport expires, the company's ownership changes, and everyone's records drift out of date independently.
  • Data sprawl. Dozens of companies end up holding copies of the same passports and registry extracts: dozens of breach targets storing identical sensitive data.

The industry has spent years optimizing each silo (faster document OCR, better registry APIs) without touching the structural problem: the verification result is trapped inside whoever performed it.

One pattern underneath: issuer, holder, verifier

This is where verifiable credentials change the picture. The W3C Verifiable Credentials model has three roles: an issuer attests to facts, a holder keeps the signed credential in a wallet they control, and a verifier checks the cryptographic signature without calling the issuer back.

The crucial point is that the pattern doesn't care what kind of entity the holder is:

  • A person holds a KYC credential issued by a certified identity verification provider.
  • A company holds a KYB credential attesting to its registration and verified UBO structure.
  • An AI agent holds a credential derived from its principal's verified identity, scoped to a specific mandate.

Same data model, same cryptography, same trust framework: three acronyms collapse into one architecture. A verifier onboarding a business can check the company credential and the UBO credentials in one flow; a merchant facing an agent can check the agent's credential and trace it to a verified human. The full mechanics of the reusable model are in What Is Reusable KYC?.

That convergence matters because the acronym list will keep growing. Whatever entity needs verifying next, the issuer-holder-verifier pattern already accommodates it, which is more than can be said for another generation of siloed checks.

Where OpenKYC fits

OpenKYC is building a reusable KYC marketplace on open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, and reuse it everywhere, whether the credential describes a person, a business, or eventually an agent, and earn every time it's used. Join the waitlist at openkyc.org.

Verify once. Use everywhere. Earn every time.

OpenKYC is building the reusable KYC marketplace on open identity standards. Be first in line.

Join the waitlist