KYA vs KYC vs KYB

KYC (Know Your Customer) and KYB (Know Your Business) are due-diligence duties that identify and verify the human or legal entity you do business with, largely for anti-money-laundering and counter-terrorist-financing purposes. KYA (Know Your Agent) verifies the autonomous software agent acting for that person or company: what it is, who is accountable for it, what it is allowed to do, and whether it can be revoked.

Short version: KYC/KYB verify the principal. KYA verifies the agent.

What KYC actually is

KYC is not one law; it is the industry name for a set of customer due diligence (CDD) obligations countries impose on financial institutions and other regulated firms.

  • The FATF Recommendations set the global baseline. Recommendation 10 requires firms to identify and verify customers, identify beneficial owners, understand the purpose of the relationship, and conduct ongoing monitoring.
  • In the United States, the FinCEN Customer Due Diligence Rule requires covered financial institutions to identify and verify beneficial owners — any individual owning 25% or more of a legal entity, plus one individual who controls it (31 CFR 1010.230).

KYC answers: Is this customer who they say they are, and what is their risk?

What KYB adds

KYB is the industry label for applying due diligence to a legal entity rather than a natural person. It verifies the company’s registration, its address, its status, and — critically — its beneficial ownership: the people who ultimately own or control it.

KYB is not a separate, formally defined term in the FATF Recommendations; it is shorthand for corporate CDD. The underlying duties (identify the entity; identify beneficial owners; understand control) come from the same Recommendation 10 regime and rules like FinCEN’s.

KYB answers: Is this business legitimate, and who really controls it?

What KYA adds

KYA keeps the discipline of “identify and verify before you trust” but shifts the subject to the agent and the question to “what may it do right now”.

DimensionKYC / KYBKYA
SubjectPerson or legal entitySoftware agent
Core questionWho is the customer?What is the agent, and who is behind it?
AuthorityRelationship-levelPer-action, scoped, time-bound
EvidenceDocuments, registries, screeningCryptographic credentials, attestation, signatures
LifecycleOnboarding + periodic reviewContinuous, with fast revocation
Primary driversAML/CFT regulationAccess control, fraud, accountability, agent governance

An agent introduces dimensions KYC was never built to express:

  1. Delegation. The agent acts on behalf of a principal. That authority must be explicit, scoped, and provable — the subject of new IETF OAuth work for AI agents.
  2. Per-action permission. A verified agent is not thereby allowed to do anything. KYA bounds what it may do, at what limits, for how long.
  3. Machine-verifiable identity. Rather than documents reviewed by a human, agent identity leans on cryptographically verifiable credentials (for example W3C Verifiable Credentials) and workload identity.
  4. Fast revocation. An agent can be compromised or misaligned in seconds. Authority must be withdrawable at the same speed.
  5. Auditability. High-stakes regimes already demand event logs; the EU AI Act’s record-keeping duty for high-risk systems is one example. KYA extends that expectation to agent actions and the authority behind them.

Where the three overlap

The overlap is real, and it matters for compliance teams:

  • The principal is still a KYC/KYB subject. To do KYA you must know who the principal is — which is exactly the KYC/KYB question. KYA does not replace customer due diligence; it depends on it.
  • Agent misuse can be a financial-crime risk. An unverified agent acting for an anonymous principal is an AML/CDD problem, not just a security one.
  • Both need identity assurance levels. NIST SP 800-63 defines assurance levels for people and their authenticators; KYA needs the analogous notion for agents and the software they run.
  • Governance frameworks cover both. ISO/IEC 42001 asks organisations to govern AI systems; agent identity is part of that governance, alongside the AML programme that already governs customers.

How they fit together in practice

A practical sequence for a service that accepts agents:

  1. KYB/KYC the principal — establish the accountable person or entity (existing duties).
  2. Verify the agent — establish a verifiable agent identity, tied to the principal.
  3. Bind authority — issue a scoped, time-bound, revocable credential.
  4. Check per action — is this request within the agent’s current authority?
  5. Log and revoke — record what happened; be able to cut the agent off.

Steps 1 is KYC/KYB. Steps 2–5 are KYA. Together they form one chain of accountability from a verified customer to a specific agent action.

FAQ

Does KYA replace KYC? No. It adds a layer. You still perform customer due diligence on the principal; you now also verify and bound the agent.

Is KYB different from KYC? KYB is the business-entity case of the same due-diligence idea. “KYB” is an industry term for corporate CDD and beneficial-ownership checks; it is not a formally defined FATF term.

Which regulation requires KYA? None names it. Specific obligations (AML CDD; EU AI Act transparency and record-keeping) apply, and KYA is the practice that connects identity, authority, and accountability across them.

Is KYA a vendor category? Partly. Vendors cover pieces (workload identity, verifiable credentials, authorization, agent security). Few cover the whole chain; check which of the five questions each actually answers.

This is an explanation, not legal advice.

Keep reading

Sources

  1. FATF, The FATF Recommendations (Recommendation 10, CDD) — https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html (accessed 2026-10-03)
  2. FinCEN, CDD Final Rule — https://www.fincen.gov/resources/statutes-and-regulations/cdd-final-rule (accessed 2026-10-03)
  3. 31 CFR § 1010.230 (eCFR) — https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-B/section-1010.230 (accessed 2026-10-03)
  4. NIST, SP 800-63-4, Digital Identity Guidelines — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)
  5. European Commission, EU AI Act, Article 50 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 (accessed 2026-10-03)
  6. W3C, Verifiable Credentials Data Model v2.0 — https://www.w3.org/TR/vc-data-model-2.0/ (accessed 2026-10-03)
  7. IETF, draft-oauth-ai-agents-on-behalf-of-user-02 — https://datatracker.ietf.org/doc/html/draft-oauth-ai-agents-on-behalf-of-user-02 (accessed 2026-10-03)
  8. ISO, ISO/IEC 42001:2023 — https://www.iso.org/standard/42001 (accessed 2026-10-03)