[{"data":1,"prerenderedAt":813},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb":3,"resources-category-virtual-account-requirements-kyc-kyb":728},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":698,"categoryType":6,"compare":6,"contributors":6,"date":699,"description":700,"extension":701,"faq":702,"howto":6,"isBlog":718,"isChangelog":718,"meta":719,"navigation":721,"path":722,"pillar":718,"products":6,"rawbody":723,"role":6,"seo":724,"seoTitle":725,"stem":726,"thumbnail":6,"updated":6,"__hash__":727},"content\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb.md","Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes",null,{"type":8,"value":9,"toc":680},"minimark",[10,14,17,22,38,42,51,67,76,80,83,139,147,151,154,275,293,297,300,338,346,353,358,382,386,389,402,413,417,425,464,467,471,474,513,529,533,536,542,547,564,570,575,637,640,644,647,662,666,675],[11,12,13],"p",{},"To open a virtual account, the account holder first passes KYC (for individuals) or KYB (for businesses). Then the provider and its bank review the account itself: what it's for, the industry code, expected revenue, who owns the business, and where the money comes from, backed by documents like bank statements or tax returns. Plan for two reviews, not one.",[11,15,16],{},"Most delays come from treating the second review like a formality. It isn't.",[18,19,21],"h2",{"id":20},"key-takeaways","Key takeaways",[23,24,25,29,32,35],"ul",{},[26,27,28],"li",{},"KYC or KYB approves the customer. The virtual account then gets its own review, with its own fields and documents.",[26,30,31],{},"The bank wants to know what money will flow through the account and where it comes from.",[26,33,34],{},"You collect documents and answer information requests. The provider reviews. The bank has the final say.",[26,36,37],{},"Most rejections are mismatches or silence: a wrong industry code, stale documents, an unanswered request.",[18,39,41],{"id":40},"why-do-virtual-accounts-require-kyc-and-kyb","Why do virtual accounts require KYC and KYB?",[11,43,44,45,50],{},"A named virtual account is a set of bank details issued in your customer's name, so the bank behind it needs to know who that customer is and what the account is for. US anti-money laundering rules require exactly that. The provider runs the process for you, but it can't skip it. (New to how these accounts route into a master account? Start with ",[46,47,49],"a",{"href":48},"\u002Fresources\u002Fmore\u002Fwhat-is-a-virtual-account","what is a virtual account",".)",[11,52,53,54,60,61,66],{},"Two FinCEN rules do most of the work. The customer identification program (CIP) rule requires banks to collect, at minimum, a customer's name, date of birth for individuals, address, and identification number, and to verify identity (",[46,55,59],{"href":56,"rel":57},"https:\u002F\u002Fwww.fdic.gov\u002Fnews\u002Finactive-financial-institution-letters\u002F2024\u002Fcollecting-identifying-information-required-under-customer",[58],"nofollow","FDIC summary","). The customer due diligence (",[46,62,65],{"href":63,"rel":64},"https:\u002F\u002Fwww.fincen.gov\u002Fresources\u002Fstatutes-and-regulations\u002Fcdd-final-rule",[58],"CDD",") rule adds beneficial owners: each person who owns 25% or more of a legal entity, plus one person who controls it, such as a CEO or managing member. It also requires understanding the nature and purpose of the relationship and monitoring it over time. That's where the account purpose and revenue fields come from.",[11,68,69,70,75],{},"One recent change: in February 2026, FinCEN ",[46,71,74],{"href":72,"rel":73},"https:\u002F\u002Fwww.fincen.gov\u002Fnews\u002Fnews-releases\u002Ffincen-issues-exceptive-relief-streamline-customer-due-diligence-requirements",[58],"granted relief"," from re-verifying beneficial owners each time an existing legal entity customer opens a new account. Verification still happens at the first account, when earlier information looks unreliable, and under risk-based procedures. Providers and banks can still ask for more under their own policies, and how any of this applies to your platform is a question for counsel.",[18,77,79],{"id":78},"what-is-the-difference-between-kyc-and-kyb-and-which-documents-are-typical","What is the difference between KYC and KYB, and which documents are typical?",[11,81,82],{},"KYC (know your customer) verifies an individual: name, date of birth, address, government ID, and often a selfie. KYB (know your business) verifies a company: that it legally exists, where it's registered, and which people own or control it. For a business, KYB includes KYC on each beneficial owner.",[84,85,86,102],"table",{},[87,88,89],"thead",{},[90,91,92,96,99],"tr",{},[93,94,95],"th",{},"Check",[93,97,98],{},"Who it covers",[93,100,101],{},"Typical documents",[103,104,105,117,128],"tbody",{},[90,106,107,111,114],{},[108,109,110],"td",{},"KYC",[108,112,113],{},"Individuals, and every owner of a business",[108,115,116],{},"Government ID (passport, ID card, or driver's license), proof of address under 90 days old, selfie, tax ID",[90,118,119,122,125],{},[108,120,121],{},"KYB",[108,123,124],{},"Businesses",[108,126,127],{},"Articles of organization or certificate of incorporation (all pages), share register showing owners and percentages, proof of business address under 90 days old",[90,129,130,133,136],{},[108,131,132],{},"Account review",[108,134,135],{},"The virtual account itself",[108,137,138],{},"Account purpose, industry code, revenue band, source of funds and source of wealth documents",[11,140,141,142,146],{},"The third row is what most teams miss. BlindPay's ",[46,143,145],{"href":144},"\u002Fdocs\u002Fkb\u002Fkyb-documents","KYB document list"," states it directly: virtual account requests go through a separate evaluation with their own documentation, on top of KYB.",[18,148,150],{"id":149},"what-does-the-bank-review-on-top-of-kyb","What does the bank review on top of KYB?",[11,152,153],{},"The bank reviews the expected activity of the account: why it exists, what business it serves, how much money will move, and where that money comes from. Deposits that later don't fit that baseline are what trigger holds.",[84,155,156,172],{},[87,157,158],{},[90,159,160,163,166,169],{},[93,161,162],{},"Field or document",[93,164,165],{},"Individual (sole proprietor)",[93,167,168],{},"Business",[93,170,171],{},"Why the bank asks",[103,173,174,187,200,212,224,236,250,263],{},[90,175,176,179,182,184],{},[108,177,178],{},"Account purpose",[108,180,181],{},"Required",[108,183,181],{},[108,185,186],{},"Sets the expected use, such as collecting client payments or treasury",[90,188,189,192,195,197],{},[108,190,191],{},"Industry code (NAICS)",[108,193,194],{},"No",[108,196,181],{},[108,198,199],{},"Must match the activity in the incorporation documents",[90,201,202,205,207,209],{},[108,203,204],{},"Business type and description",[108,206,194],{},[108,208,181],{},[108,210,211],{},"Confirms the legal structure and what the company sells",[90,213,214,217,219,221],{},[108,215,216],{},"Estimated annual revenue",[108,218,194],{},[108,220,181],{},[108,222,223],{},"Gives a volume baseline for monitoring",[90,225,226,229,231,233],{},[108,227,228],{},"Source of wealth",[108,230,181],{},[108,232,181],{},[108,234,235],{},"How the owners built their wealth: earnings, prior ventures, investments",[90,237,238,241,244,247],{},[108,239,240],{},"Source of funds documents",[108,242,243],{},"A supporting document with the request: service agreement, salary slip, or bank statement",[108,245,246],{},"Bank statements, financials, tax returns, contracts, or invoices",[108,248,249],{},"Proves where the money flowing into the account comes from",[90,251,252,255,257,260],{},[108,253,254],{},"Owners, percentages, and titles",[108,256,194],{},[108,258,259],{},"At least one owner",[108,261,262],{},"Identifies who benefits from and controls the account",[90,264,265,268,270,272],{},[108,266,267],{},"Publicly traded flag",[108,269,194],{},[108,271,181],{},[108,273,274],{},"Listed companies carry a different risk profile",[11,276,277,278,282,283,287,288,292],{},"Source of funds and source of wealth sound alike. They aren't. Source of funds is where ",[279,280,281],"em",{},"this money"," comes from (client payments, operating revenue, investment capital). Source of wealth is how the business or its owners got their money in the first place. Accepted documents for each are in BlindPay's ",[46,284,286],{"href":285},"\u002Fdocs\u002Fkb\u002Fvirtual-accounts","virtual account requirements"," and ",[46,289,291],{"href":290},"\u002Fdocs\u002Fkb\u002Fsource-of-funds","source of funds guide",".",[18,294,296],{"id":295},"who-is-responsible-for-compliance-you-the-provider-or-the-bank","Who is responsible for compliance: you, the provider, or the bank?",[11,298,299],{},"All three, for different parts. You know your customer and collect their information. The provider verifies identities, reviews each account, and monitors transactions. The bank makes the final call on every account and can ask for more.",[84,301,302,312],{},[87,303,304],{},[90,305,306,309],{},[93,307,308],{},"Party",[93,310,311],{},"What it owns",[103,313,314,322,330],{},[90,315,316,319],{},[108,317,318],{},"You (the platform)",[108,320,321],{},"Collecting accurate customer data and documents, getting terms accepted, answering information requests on time, and keeping each account's money tied to that customer",[90,323,324,327],{},[108,325,326],{},"The provider",[108,328,329],{},"KYC and KYB review, the compliance review of each virtual account, transaction monitoring, and holds",[90,331,332,335],{},[108,333,334],{},"The bank",[108,336,337],{},"Final approval, extra document requests, and the right to reject an application",[11,339,340,341,345],{},"One line is worth reading twice. At BlindPay, information requests go to your team, not to your customer: collecting the documents is your job as the partner (",[46,342,344],{"href":343},"\u002Fdocs\u002Fkb\u002Finformation-requests","information requests","). If your customer doesn't reply, you're the one holding the deadline.",[11,347,348,349,292],{},"The other line is about whose money it is. A virtual account should only receive money that belongs to the customer it was issued to. Using one customer's account to collect for that customer's own clients, who were never onboarded, is called nesting, and it gets accounts frozen. BlindPay's rule and quick test are in ",[46,350,352],{"href":351},"\u002Fdocs\u002Fkb\u002Fnested-payments","nested payments",[354,355,357],"h3",{"id":356},"compliance-questions-to-ask-your-virtual-account-provider","Compliance questions to ask your virtual account provider",[359,360,361,364,367,370,373,376,379],"ol",{},[26,362,363],{},"Which fields and documents does the bank require beyond KYB, per account type?",[26,365,366],{},"Does the API reject incomplete account requests up front, or does manual review find the gaps?",[26,368,369],{},"Who contacts my customer when compliance or the bank needs something?",[26,371,372],{},"How long do I have to answer a request on a customer, and on a held deposit?",[26,374,375],{},"Does the SLA restart when the bank asks for more documents?",[26,377,378],{},"Which sectors trigger enhanced due diligence?",[26,380,381],{},"Where exactly is the line on nesting for my business model?",[18,383,385],{"id":384},"what-ongoing-monitoring-applies-after-approval","What ongoing monitoring applies after approval?",[11,387,388],{},"Approval is not the end. Every deposit gets checked against what the customer declared, so expect transaction monitoring, sanctions screening on the parties involved, and periodic reviews of the customer file.",[11,390,391,392,396,397,401],{},"At BlindPay, a deposit flagged by transaction monitoring lands ",[393,394,395],"code",{},"on_hold",". If compliance can't clear it internally, you get a request for the relationship between sender and customer, the purpose of the payment, and its expected outcome. If that request isn't answered within 24 hours, the deposit may be returned to the sender (",[46,398,400],{"href":399},"\u002Fdocs\u002Fkb\u002Fon-hold-transactions","on-hold transactions",").",[11,403,404,405,408,409,412],{},"Customer files get revisited too. A request on an approved customer can run without pausing them (",[393,406,407],{},"approved_rfi","), while a blocking request (",[393,410,411],{},"compliance_request",") stops payins and payouts until you respond. Either way you have 27 days, with reminders on days 7 and 17. A blocking request that's still unanswered on day 27 rejects the customer automatically.",[18,414,416],{"id":415},"what-gets-an-application-rejected-or-delayed","What gets an application rejected or delayed?",[11,418,419,420,424],{},"Mismatches and silence cause most of it: one document contradicts another, a document is stale, or a request goes unanswered. BlindPay publishes its ",[46,421,423],{"href":422},"\u002Fdocs\u002Fkb\u002Frejection-reasons","rejection reasons",", and the fixable ones repeat:",[23,426,427,434,440,446,452,458],{},[26,428,429,433],{},[430,431,432],"strong",{},"Industry code mismatch."," The NAICS code on the customer doesn't match the activity in the articles of incorporation.",[26,435,436,439],{},[430,437,438],{},"Stale proof of address."," Older than 90 days, cropped, or not in the entity's name.",[26,441,442,445],{},[430,443,444],{},"ID problems."," Expired, issued more than 10 years ago, blurry, or a photo of a screen.",[26,447,448,451],{},[430,449,450],{},"Partial documents."," Page one of the articles of organization instead of all pages.",[26,453,454,457],{},[430,455,456],{},"No response to a request."," The 27-day window ran out.",[26,459,460,463],{},[430,461,462],{},"Nesting."," The account would collect money for parties nobody verified.",[11,465,466],{},"Delays have one extra cause: when the bank asks for more documents during its review, the SLA clock restarts from the day you submit them. Companies in higher-risk sectors, including money services, fintech, and digital assets, should also expect enhanced due diligence and more document requests.",[18,468,470],{"id":469},"how-can-automation-cut-onboarding-time","How can automation cut onboarding time?",[11,472,473],{},"Automation removes the back-and-forth, not the review. Collect the account review fields during onboarding so the request goes in complete, and catch bad files before a human sees them. The sequence that avoids rework:",[359,475,476,479,482,485,488,491,494,500,506],{},[26,477,478],{},"Have your customer accept the provider's terms of service.",[26,480,481],{},"Create the customer with full KYC or KYB data, including every owner with their ownership percentage and title.",[26,483,484],{},"Wait for approval. At BlindPay, automated KYC can finish in about 60 seconds, and KYB is a manual review of 3 hours to 1 business day.",[26,486,487],{},"Fill in the account review fields: purpose, industry code, revenue band, source of wealth.",[26,489,490],{},"Upload source of funds documents, plus the supporting document if the customer is a sole proprietor.",[26,492,493],{},"Link the wallet where deposits settle.",[26,495,496,497,401],{},"Request the virtual account. It enters compliance review (",[393,498,499],{},"pending_review",[26,501,502,503,401],{},"Compliance approves and sends it to the bank (",[393,504,505],{},"verifying",[26,507,508,509,512],{},"The bank approves (",[393,510,511],{},"approved","), the account details are issued, and you share them with payers.",[11,514,515,516,519,520,524,525,292],{},"Two features help at steps 4 and 5. BlindPay's API rejects an account request with ",[393,517,518],{},"missing_required_fields",", naming each blank field, so validation can happen in your form instead of a review queue. And a document analysis endpoint returns a low, medium, or high approval rate for a file, so you can ask for a better scan before it's submitted (",[46,521,523],{"href":522},"\u002Fdocs\u002Fkb\u002Fkyc","KYC requirements","). For the broader picture of software running these checks, see ",[46,526,528],{"href":527},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","compliance agents in fintech",[18,530,532],{"id":531},"what-does-a-real-application-look-like","What does a real application look like?",[11,534,535],{},"Here's an illustrative example. The company, names, and dates are made up. The fields and stages are real.",[11,537,538,541],{},[430,539,540],{},"Harbor Code LLC"," is a US software studio that builds apps for US clients and wants a virtual account for incoming ACH and wire payments, settled to USDC. It has two owners, both US residents: Ana owns 60% and is managing member, and Ben owns 40%.",[11,543,544],{},[430,545,546],{},"What it fills in:",[23,548,549,552,555,558,561],{},[26,550,551],{},"Business type: LLC. Industry code: 541511 (custom computer programming services), which matches its articles of organization.",[26,553,554],{},"Business description: \"Custom mobile and web app development for US small businesses.\"",[26,556,557],{},"Account purpose: collecting client payments. Estimated annual revenue: the band that covers its prior-year revenue.",[26,559,560],{},"Source of wealth: business profits. Publicly traded: no.",[26,562,563],{},"Owners: Ana (60%, managing member) and Ben (40%), each with an SSN as tax ID.",[11,565,566,569],{},[430,567,568],{},"What it uploads:"," all pages of the articles of organization, an operating agreement showing the 60\u002F40 split, a utility bill for the office dated last month, ID and proof of residence for both owners, the last 3 months of business bank statements, and two signed client contracts.",[11,571,572],{},[430,573,574],{},"Illustrative timeline:",[84,576,577,587],{},[87,578,579],{},[90,580,581,584],{},[93,582,583],{},"Day",[93,585,586],{},"What happens",[103,588,589,597,607,618,626],{},[90,590,591,594],{},[108,592,593],{},"Monday",[108,595,596],{},"Customer created. KYB enters manual review",[90,598,599,602],{},[108,600,601],{},"Tuesday",[108,603,604,605],{},"KYB approved. Account request submitted, ",[393,606,499],{},[90,608,609,612],{},[108,610,611],{},"Wednesday",[108,613,614,615,617],{},"Compliance approves, ",[393,616,505],{}," (bank review begins on a 3 to 5 business day SLA)",[90,619,620,623],{},[108,621,622],{},"Following Monday",[108,624,625],{},"The bank asks for a signed copy of one client contract. Harbor uploads it the same day and the SLA clock restarts",[90,627,628,631],{},[108,629,630],{},"Following Thursday",[108,632,633,634,636],{},"Bank approves, ",[393,635,511],{},". Routing and account numbers are issued",[11,638,639],{},"Ten days, end to end, and the restart after one unsigned contract added about three of them. An industry code like \"financial services\" would have been worse: a mismatch with the articles is a listed rejection reason.",[18,641,643],{"id":642},"where-does-blindpay-fit","Where does BlindPay fit?",[11,645,646],{},"BlindPay issues US virtual accounts in your customer's own name. They receive ACH, wire, and SWIFT, depending on account type, and deposits settle as USDC or USDT to a wallet you link. Each account costs $1.50 per month and goes through compliance review, then bank review, with SLAs of 24 hours or 3 to 5 business days by account type.",[11,648,649,650,654,655,657,658,292],{},"The requirements are public: ",[46,651,653],{"href":652},"\u002Fdocs\u002Fvirtual-accounts-create","create a virtual account"," lists the required fields, and the ",[46,656,286],{"href":285}," list the documents. Development instances approve accounts instantly, so you can build onboarding before any real review. If you're still deciding whether a virtual account fits next to your existing bank, see ",[46,659,661],{"href":660},"\u002Fresources\u002Fmore\u002Fcan-a-virtual-account-replace-a-bank-account","can a virtual account replace a bank account",[18,663,665],{"id":664},"what-to-do-next","What to do next",[11,667,668,669,671,672,674],{},"Take the field table above and add every row to your onboarding form today, marked required by customer type. Then create a test customer on a development instance and request an account with ",[46,670,653],{"href":652},". If the API returns ",[393,673,518],{},", your form is missing something.",[11,676,677],{},[279,678,679],{},"This article is for general information only and is not legal, tax, or financial advice.",{"title":681,"searchDepth":682,"depth":682,"links":683},"",2,[684,685,686,687,688,692,693,694,695,696,697],{"id":20,"depth":682,"text":21},{"id":40,"depth":682,"text":41},{"id":78,"depth":682,"text":79},{"id":149,"depth":682,"text":150},{"id":295,"depth":682,"text":296,"children":689},[690],{"id":356,"depth":691,"text":357},3,{"id":384,"depth":682,"text":385},{"id":415,"depth":682,"text":416},{"id":469,"depth":682,"text":470},{"id":531,"depth":682,"text":532},{"id":642,"depth":682,"text":643},{"id":664,"depth":682,"text":665},"compliance","2026-08-14","What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.","md",[703,706,709,712,715],{"q":704,"a":705},"What documents do I need to open a virtual account?","A business needs its KYB documents first: formation documents, a share register showing beneficial owners, proof of address, and ID for each owner. The account review then adds source of funds evidence, such as the last 3 months of bank statements, financial statements, tax returns, or client contracts. Individuals need ID, proof of address, and documents like tax returns or bank statements.",{"q":707,"a":708},"How long does virtual account approval take?","It happens in two stages. Identity checks come first: automated KYC for an individual can finish in about a minute, and manual KYB usually takes 3 hours to 1 business day. The account review follows. At BlindPay its SLA is 24 hours or 3 to 5 business days depending on the account type, and the clock restarts if the bank asks for more documents.",{"q":710,"a":711},"Is KYB enough to open a virtual account for a business?","Usually not. KYB proves the company exists and who owns it. The account review asks a different question: what money will flow through this account, and where does it come from? Expect to give an account purpose, an industry code, an expected revenue band, and source of funds and source of wealth, with supporting documents.",{"q":713,"a":714},"Can a sole proprietor open a virtual account?","Often yes, with extra paperwork. At BlindPay an individual customer needs approved KYC, an account purpose, and a source of wealth on file, plus one supporting document sent with the account request: a master service agreement, a salary slip, or a bank statement. The document should show the income the account will receive.",{"q":716,"a":717},"Why was my virtual account application rejected?","The common reasons are fixable: an industry code that doesn't match the incorporation documents, an expired ID, a proof of address older than 90 days, or an information request that nobody answered in time. Others are not, such as a structure where the account would collect money for clients the provider never verified. Ask the provider for the reason code before reapplying.",false,{"author":720},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","---\ntitle: \"Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes\"\nseoTitle: \"Virtual account requirements: KYC, KYB, and documents\"\ndescription: \"What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.\"\ndate: \"2026-08-14\"\ncategory: \"compliance\"\nauthor: \"BlindPay Team\"\nfaq:\n  - q: \"What documents do I need to open a virtual account?\"\n    a: \"A business needs its KYB documents first: formation documents, a share register showing beneficial owners, proof of address, and ID for each owner. The account review then adds source of funds evidence, such as the last 3 months of bank statements, financial statements, tax returns, or client contracts. Individuals need ID, proof of address, and documents like tax returns or bank statements.\"\n  - q: \"How long does virtual account approval take?\"\n    a: \"It happens in two stages. Identity checks come first: automated KYC for an individual can finish in about a minute, and manual KYB usually takes 3 hours to 1 business day. The account review follows. At BlindPay its SLA is 24 hours or 3 to 5 business days depending on the account type, and the clock restarts if the bank asks for more documents.\"\n  - q: \"Is KYB enough to open a virtual account for a business?\"\n    a: \"Usually not. KYB proves the company exists and who owns it. The account review asks a different question: what money will flow through this account, and where does it come from? Expect to give an account purpose, an industry code, an expected revenue band, and source of funds and source of wealth, with supporting documents.\"\n  - q: \"Can a sole proprietor open a virtual account?\"\n    a: \"Often yes, with extra paperwork. At BlindPay an individual customer needs approved KYC, an account purpose, and a source of wealth on file, plus one supporting document sent with the account request: a master service agreement, a salary slip, or a bank statement. The document should show the income the account will receive.\"\n  - q: \"Why was my virtual account application rejected?\"\n    a: \"The common reasons are fixable: an industry code that doesn't match the incorporation documents, an expired ID, a proof of address older than 90 days, or an information request that nobody answered in time. Others are not, such as a structure where the account would collect money for clients the provider never verified. Ask the provider for the reason code before reapplying.\"\n---\n\nTo open a virtual account, the account holder first passes KYC (for individuals) or KYB (for businesses). Then the provider and its bank review the account itself: what it's for, the industry code, expected revenue, who owns the business, and where the money comes from, backed by documents like bank statements or tax returns. Plan for two reviews, not one.\n\nMost delays come from treating the second review like a formality. It isn't.\n\n## Key takeaways\n\n- KYC or KYB approves the customer. The virtual account then gets its own review, with its own fields and documents.\n- The bank wants to know what money will flow through the account and where it comes from.\n- You collect documents and answer information requests. The provider reviews. The bank has the final say.\n- Most rejections are mismatches or silence: a wrong industry code, stale documents, an unanswered request.\n\n## Why do virtual accounts require KYC and KYB?\n\nA named virtual account is a set of bank details issued in your customer's name, so the bank behind it needs to know who that customer is and what the account is for. US anti-money laundering rules require exactly that. The provider runs the process for you, but it can't skip it. (New to how these accounts route into a master account? Start with [what is a virtual account](\u002Fresources\u002Fmore\u002Fwhat-is-a-virtual-account).)\n\nTwo FinCEN rules do most of the work. The customer identification program (CIP) rule requires banks to collect, at minimum, a customer's name, date of birth for individuals, address, and identification number, and to verify identity ([FDIC summary](https:\u002F\u002Fwww.fdic.gov\u002Fnews\u002Finactive-financial-institution-letters\u002F2024\u002Fcollecting-identifying-information-required-under-customer)). The customer due diligence ([CDD](https:\u002F\u002Fwww.fincen.gov\u002Fresources\u002Fstatutes-and-regulations\u002Fcdd-final-rule)) rule adds beneficial owners: each person who owns 25% or more of a legal entity, plus one person who controls it, such as a CEO or managing member. It also requires understanding the nature and purpose of the relationship and monitoring it over time. That's where the account purpose and revenue fields come from.\n\nOne recent change: in February 2026, FinCEN [granted relief](https:\u002F\u002Fwww.fincen.gov\u002Fnews\u002Fnews-releases\u002Ffincen-issues-exceptive-relief-streamline-customer-due-diligence-requirements) from re-verifying beneficial owners each time an existing legal entity customer opens a new account. Verification still happens at the first account, when earlier information looks unreliable, and under risk-based procedures. Providers and banks can still ask for more under their own policies, and how any of this applies to your platform is a question for counsel.\n\n## What is the difference between KYC and KYB, and which documents are typical?\n\nKYC (know your customer) verifies an individual: name, date of birth, address, government ID, and often a selfie. KYB (know your business) verifies a company: that it legally exists, where it's registered, and which people own or control it. For a business, KYB includes KYC on each beneficial owner.\n\n| Check | Who it covers | Typical documents |\n| --- | --- | --- |\n| KYC | Individuals, and every owner of a business | Government ID (passport, ID card, or driver's license), proof of address under 90 days old, selfie, tax ID |\n| KYB | Businesses | Articles of organization or certificate of incorporation (all pages), share register showing owners and percentages, proof of business address under 90 days old |\n| Account review | The virtual account itself | Account purpose, industry code, revenue band, source of funds and source of wealth documents |\n\nThe third row is what most teams miss. BlindPay's [KYB document list](\u002Fdocs\u002Fkb\u002Fkyb-documents) states it directly: virtual account requests go through a separate evaluation with their own documentation, on top of KYB.\n\n## What does the bank review on top of KYB?\n\nThe bank reviews the expected activity of the account: why it exists, what business it serves, how much money will move, and where that money comes from. Deposits that later don't fit that baseline are what trigger holds.\n\n| Field or document | Individual (sole proprietor) | Business | Why the bank asks |\n| --- | --- | --- | --- |\n| Account purpose | Required | Required | Sets the expected use, such as collecting client payments or treasury |\n| Industry code (NAICS) | No | Required | Must match the activity in the incorporation documents |\n| Business type and description | No | Required | Confirms the legal structure and what the company sells |\n| Estimated annual revenue | No | Required | Gives a volume baseline for monitoring |\n| Source of wealth | Required | Required | How the owners built their wealth: earnings, prior ventures, investments |\n| Source of funds documents | A supporting document with the request: service agreement, salary slip, or bank statement | Bank statements, financials, tax returns, contracts, or invoices | Proves where the money flowing into the account comes from |\n| Owners, percentages, and titles | No | At least one owner | Identifies who benefits from and controls the account |\n| Publicly traded flag | No | Required | Listed companies carry a different risk profile |\n\nSource of funds and source of wealth sound alike. They aren't. Source of funds is where *this money* comes from (client payments, operating revenue, investment capital). Source of wealth is how the business or its owners got their money in the first place. Accepted documents for each are in BlindPay's [virtual account requirements](\u002Fdocs\u002Fkb\u002Fvirtual-accounts) and [source of funds guide](\u002Fdocs\u002Fkb\u002Fsource-of-funds).\n\n## Who is responsible for compliance: you, the provider, or the bank?\n\nAll three, for different parts. You know your customer and collect their information. The provider verifies identities, reviews each account, and monitors transactions. The bank makes the final call on every account and can ask for more.\n\n| Party | What it owns |\n| --- | --- |\n| You (the platform) | Collecting accurate customer data and documents, getting terms accepted, answering information requests on time, and keeping each account's money tied to that customer |\n| The provider | KYC and KYB review, the compliance review of each virtual account, transaction monitoring, and holds |\n| The bank | Final approval, extra document requests, and the right to reject an application |\n\nOne line is worth reading twice. At BlindPay, information requests go to your team, not to your customer: collecting the documents is your job as the partner ([information requests](\u002Fdocs\u002Fkb\u002Finformation-requests)). If your customer doesn't reply, you're the one holding the deadline.\n\nThe other line is about whose money it is. A virtual account should only receive money that belongs to the customer it was issued to. Using one customer's account to collect for that customer's own clients, who were never onboarded, is called nesting, and it gets accounts frozen. BlindPay's rule and quick test are in [nested payments](\u002Fdocs\u002Fkb\u002Fnested-payments).\n\n### Compliance questions to ask your virtual account provider\n\n1. Which fields and documents does the bank require beyond KYB, per account type?\n2. Does the API reject incomplete account requests up front, or does manual review find the gaps?\n3. Who contacts my customer when compliance or the bank needs something?\n4. How long do I have to answer a request on a customer, and on a held deposit?\n5. Does the SLA restart when the bank asks for more documents?\n6. Which sectors trigger enhanced due diligence?\n7. Where exactly is the line on nesting for my business model?\n\n## What ongoing monitoring applies after approval?\n\nApproval is not the end. Every deposit gets checked against what the customer declared, so expect transaction monitoring, sanctions screening on the parties involved, and periodic reviews of the customer file.\n\nAt BlindPay, a deposit flagged by transaction monitoring lands `on_hold`. If compliance can't clear it internally, you get a request for the relationship between sender and customer, the purpose of the payment, and its expected outcome. If that request isn't answered within 24 hours, the deposit may be returned to the sender ([on-hold transactions](\u002Fdocs\u002Fkb\u002Fon-hold-transactions)).\n\nCustomer files get revisited too. A request on an approved customer can run without pausing them (`approved_rfi`), while a blocking request (`compliance_request`) stops payins and payouts until you respond. Either way you have 27 days, with reminders on days 7 and 17. A blocking request that's still unanswered on day 27 rejects the customer automatically.\n\n## What gets an application rejected or delayed?\n\nMismatches and silence cause most of it: one document contradicts another, a document is stale, or a request goes unanswered. BlindPay publishes its [rejection reasons](\u002Fdocs\u002Fkb\u002Frejection-reasons), and the fixable ones repeat:\n\n- **Industry code mismatch.** The NAICS code on the customer doesn't match the activity in the articles of incorporation.\n- **Stale proof of address.** Older than 90 days, cropped, or not in the entity's name.\n- **ID problems.** Expired, issued more than 10 years ago, blurry, or a photo of a screen.\n- **Partial documents.** Page one of the articles of organization instead of all pages.\n- **No response to a request.** The 27-day window ran out.\n- **Nesting.** The account would collect money for parties nobody verified.\n\nDelays have one extra cause: when the bank asks for more documents during its review, the SLA clock restarts from the day you submit them. Companies in higher-risk sectors, including money services, fintech, and digital assets, should also expect enhanced due diligence and more document requests.\n\n## How can automation cut onboarding time?\n\nAutomation removes the back-and-forth, not the review. Collect the account review fields during onboarding so the request goes in complete, and catch bad files before a human sees them. The sequence that avoids rework:\n\n1. Have your customer accept the provider's terms of service.\n2. Create the customer with full KYC or KYB data, including every owner with their ownership percentage and title.\n3. Wait for approval. At BlindPay, automated KYC can finish in about 60 seconds, and KYB is a manual review of 3 hours to 1 business day.\n4. Fill in the account review fields: purpose, industry code, revenue band, source of wealth.\n5. Upload source of funds documents, plus the supporting document if the customer is a sole proprietor.\n6. Link the wallet where deposits settle.\n7. Request the virtual account. It enters compliance review (`pending_review`).\n8. Compliance approves and sends it to the bank (`verifying`).\n9. The bank approves (`approved`), the account details are issued, and you share them with payers.\n\nTwo features help at steps 4 and 5. BlindPay's API rejects an account request with `missing_required_fields`, naming each blank field, so validation can happen in your form instead of a review queue. And a document analysis endpoint returns a low, medium, or high approval rate for a file, so you can ask for a better scan before it's submitted ([KYC requirements](\u002Fdocs\u002Fkb\u002Fkyc)). For the broader picture of software running these checks, see [compliance agents in fintech](\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech).\n\n## What does a real application look like?\n\nHere's an illustrative example. The company, names, and dates are made up. The fields and stages are real.\n\n**Harbor Code LLC** is a US software studio that builds apps for US clients and wants a virtual account for incoming ACH and wire payments, settled to USDC. It has two owners, both US residents: Ana owns 60% and is managing member, and Ben owns 40%.\n\n**What it fills in:**\n\n- Business type: LLC. Industry code: 541511 (custom computer programming services), which matches its articles of organization.\n- Business description: \"Custom mobile and web app development for US small businesses.\"\n- Account purpose: collecting client payments. Estimated annual revenue: the band that covers its prior-year revenue.\n- Source of wealth: business profits. Publicly traded: no.\n- Owners: Ana (60%, managing member) and Ben (40%), each with an SSN as tax ID.\n\n**What it uploads:** all pages of the articles of organization, an operating agreement showing the 60\u002F40 split, a utility bill for the office dated last month, ID and proof of residence for both owners, the last 3 months of business bank statements, and two signed client contracts.\n\n**Illustrative timeline:**\n\n| Day | What happens |\n| --- | --- |\n| Monday | Customer created. KYB enters manual review |\n| Tuesday | KYB approved. Account request submitted, `pending_review` |\n| Wednesday | Compliance approves, `verifying` (bank review begins on a 3 to 5 business day SLA) |\n| Following Monday | The bank asks for a signed copy of one client contract. Harbor uploads it the same day and the SLA clock restarts |\n| Following Thursday | Bank approves, `approved`. Routing and account numbers are issued |\n\nTen days, end to end, and the restart after one unsigned contract added about three of them. An industry code like \"financial services\" would have been worse: a mismatch with the articles is a listed rejection reason.\n\n## Where does BlindPay fit?\n\nBlindPay issues US virtual accounts in your customer's own name. They receive ACH, wire, and SWIFT, depending on account type, and deposits settle as USDC or USDT to a wallet you link. Each account costs $1.50 per month and goes through compliance review, then bank review, with SLAs of 24 hours or 3 to 5 business days by account type.\n\nThe requirements are public: [create a virtual account](\u002Fdocs\u002Fvirtual-accounts-create) lists the required fields, and the [virtual account requirements](\u002Fdocs\u002Fkb\u002Fvirtual-accounts) list the documents. Development instances approve accounts instantly, so you can build onboarding before any real review. If you're still deciding whether a virtual account fits next to your existing bank, see [can a virtual account replace a bank account](\u002Fresources\u002Fmore\u002Fcan-a-virtual-account-replace-a-bank-account).\n\n## What to do next\n\nTake the field table above and add every row to your onboarding form today, marked required by customer type. Then create a test customer on a development instance and request an account with [create a virtual account](\u002Fdocs\u002Fvirtual-accounts-create). If the API returns `missing_required_fields`, your form is missing something.\n\n*This article is for general information only and is not legal, tax, or financial advice.*\n",{"title":5,"description":700},"Virtual account requirements: KYC, KYB, and documents","resources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","VmfqMwlwhB4bEMtusVV8ClKVt4PkokqwDlNbTcD0HWM",[729,733,737,741,745,749,753,757,761,765,769,773,777,781,785,786,789,793,797,801,805,809],{"path":730,"title":731,"description":732},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","Are stablecoin payments reversible? Finality, custody, and fraud explained","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",{"path":734,"title":735,"description":736},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Automated KYC\u002FKYB vs. manual onboarding: what actually changes","A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",{"path":738,"title":739,"description":740},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","Compliance agents for cross-border stablecoin payments: a global regulatory guide","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",{"path":742,"title":743,"description":744},"\u002Fresources\u002Fmore\u002Fcrypto-wallet-compliance-checklist","Crypto wallet compliance checklist: KYC, KYT, and Travel Rule","The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.",{"path":746,"title":747,"description":748},"\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins","Do merchants need a license to accept stablecoin payments? KYC, KYB, and compliance explained","Usually no: the license sits with the provider that moves the funds. What merchants still owe on KYB, sanctions, tax, and records in the US, EU, Brazil.",{"path":750,"title":751,"description":752},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","How to automate KYC and KYB for stablecoin payments","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",{"path":754,"title":755,"description":756},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","How to choose an automated risk monitoring vendor for a fintech startup","A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",{"path":758,"title":759,"description":760},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA stablecoin rules explained for payment companies","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",{"path":762,"title":763,"description":764},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","PSAV in Brazil: the Central Bank's virtual asset license explained","PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",{"path":766,"title":767,"description":768},"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","Real-time transaction monitoring for cross-border stablecoin payments","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.",{"path":770,"title":771,"description":772},"\u002Fresources\u002Fmore\u002Fstablecoin-card-issuing-compliance","Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained","What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.",{"path":774,"title":775,"description":776},"\u002Fresources\u002Fmore\u002Fstablecoin-off-ramp-limits","Stablecoin off-ramp limits: per-transaction, daily, and monthly caps explained","Why off-ramps cap how much you can convert per transaction, day, and month, how the caps map to KYC and KYB tiers, and the documents that raise them.",{"path":778,"title":779,"description":780},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan","Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",{"path":782,"title":783,"description":784},"\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses","The GENIUS Act explained for businesses that use stablecoins","What the GENIUS Act means if your business sends, receives, or holds stablecoins: who it regulates, the dates that matter, and what to do before 2027.",{"path":722,"title":5,"description":700},{"path":527,"title":787,"description":788},"What are compliance agents in fintech? How they work and what they do for payments","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",{"path":790,"title":791,"description":792},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","What is KYB? Know Your Business verification explained","KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",{"path":794,"title":795,"description":796},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","What is a VASP? Virtual asset service provider explained","A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",{"path":798,"title":799,"description":800},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","What is automated risk monitoring in fintech?","A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",{"path":802,"title":803,"description":804},"\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps","What is the travel rule for stablecoin off-ramps? Thresholds, data, and failed checks","The travel rule makes off-ramps pass sender and receiver data with transfers. Thresholds by country, required data, and what happens when checks fail.",{"path":806,"title":807,"description":808},"\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds","An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.",{"path":810,"title":811,"description":812},"\u002Fresources\u002Fmore\u002Fsource-of-funds-crypto-off-ramps","Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof","Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.",1790867715609]