Business verification
Know your business
What organisations must provide to open and operate a business account, how ownership and control are established, and how ongoing review works.
Last updated 29 August 2026 — Draft for legal review. Jurisdiction-specific wording to be confirmed with local counsel before publication.
Who this applies to
This policy applies to every organisation that holds or applies for a business account, including private and public companies, partnerships, limited liability partnerships, sole traders operating under a business name, associations, charities, trusts and foundations. It applies in addition to the identity verification we perform on the individuals who own or control the organisation.
Verification standards follow the customer due diligence requirements of the Financial Crimes Enforcement Network in the United States, the Money Laundering Regulations 2017 and the Register of Overseas Entities regime in the United Kingdom, national transpositions of the European Anti-Money Laundering Directives in the European Union, and equivalent requirements elsewhere.
Evidence about the organisation
We verify the existence and standing of the organisation from independent sources, and we ask for:
- Full registered legal name and any trading name in use.
- Registration number and country of incorporation or registration.
- Legal form and date of formation.
- Registered office address and the principal place of business, where these differ.
- Constitutional documents — for example a certificate of incorporation, articles of association, a partnership agreement or a trust deed.
- A current extract from the relevant company register, dated within three months.
- The industry in which the organisation operates, selected from a controlled list so that risk can be assessed consistently.
- Tax identifiers required in the market of registration.
- Evidence of the trading address where the registered address is a formation agent or a serviced address.
Beneficial ownership
We identify every beneficial owner and verify their identity to the same standard applied to an individual customer. A beneficial owner is any natural person who ultimately owns or controls the organisation, directly or indirectly. The default threshold is a holding of more than twenty-five per cent of shares or voting rights, and a lower threshold is applied where local law, the ownership structure or the risk assessment requires it.
Declared ownership percentages must account for the whole organisation and total exactly one hundred per cent at submission. Where ownership is held through one or more intermediate entities, the chain must be disclosed up to the natural persons at the top, supported by an ownership chart. Where no natural person meets the threshold, we identify the senior managing official and record the reason.
Nominee arrangements, bearer instruments and undisclosed trusts must be declared. An organisation that cannot or will not evidence its ownership will not be onboarded.
Directors, controllers and authorised users
We identify and verify every director or equivalent officer, every person with significant control however that control arises, and every individual authorised to instruct payments on the account.
Each authorised user is verified individually and holds their own credentials. Shared logins are prohibited. The organisation is responsible for keeping its list of authorised users current, and for removing access promptly when a person leaves or changes role. We may require dual authorisation for payment release above a threshold agreed with the organisation.
Enhanced measures and higher-risk sectors
Enhanced measures apply where the organisation operates in a higher-risk sector, has a complex or opaque structure, is connected to a high-risk third country, has a politically exposed person among its owners or controllers, or presents an unresolved screening or adverse media finding.
Enhanced measures can include evidence of the source of funds and source of wealth, audited financial statements, a business plan or description of the payment flows expected, evidence of licensing where the activity is regulated, and senior management approval before the relationship is opened or continued.
Some sectors are outside our appetite. These include unlicensed money transmission and currency exchange, unlicensed gambling, unregistered charities soliciting cross-border funds, shell entities without demonstrable economic purpose, the manufacture or trade of controlled weapons, and any activity prohibited by applicable sanctions or export control law.
How decisions are made
Business verification cases are decided under a two-reviewer model. The reviewer who prepares a recommendation cannot approve it; a second, independent reviewer must confirm the outcome. Every decision records the reviewer identities, the reason code and the evidence relied on, in an append-only audit record.
Outcomes mirror the individual verification states: approved, pending, more information required, rejected, or held for review. Outbound payment capability is unavailable until the case is approved. Where a hold arises from screening, we are prohibited from explaining it and support cannot provide further detail.
Keeping records current
The organisation must tell us within thirty days of a change to its registered details, its ownership, its controllers, its authorised users or the nature of its activity. We also review each organisation periodically — at least annually for higher-risk organisations, at least every two years for medium risk and at least every three years for lower risk.
A review may ask for refreshed register extracts, a re-confirmation of ownership, or updated evidence about activity. Where a review cannot be completed because information is not provided, the account may be restricted to incoming activity and, if the position is not resolved, closed with notice.
Records, rights and contact
Verification records for an organisation and for the individuals connected to it are retained for at least five years after the end of the relationship. Individuals connected to an organisation retain their personal data rights as described in the Privacy notice, including the right to human review of a decision that materially affects them.
Questions about a business verification case should be raised through support with the case reference shown in the business portal.
