Compliance conversations love acronyms, and three of them get mixed up constantly. KYC verifies a person, KYB verifies a company, and KYT watches the money itself. Confusing them leads to real gaps — like onboarding a corporate client with a personal-identity flow, or assuming an identity check covers transaction risk. This guide separates the three cleanly and shows how they combine into a single defensible program.
KYC: know your customer
KYC answers \"is this person who they claim to be?\" A typical flow collects an ID document, runs a liveness check against the selfie, and screens the name against watchlists and PEP lists. On Arya Crypto, KYC runs through a hosted verification link: you create the request via dashboard or API, the user completes it on their phone, and the signed result — with a downloadable audit report — lands on your webhook. It is a point-in-time event: done once at onboarding and refreshed when risk dictates.
KYB: know your business
KYB answers \"is this company real, and who actually controls it?\" That means registry data, country of incorporation, and — critically — the UBOs (ultimate beneficial owners) and related persons, each screened against international lists. A company can look respectable while one shareholder is sanctioned; KYB exists to catch exactly that. Expect it to consume more effort (and tokens) than KYC: there are simply more people and documents per case.
KYT: know your transaction
KYT answers \"is this money clean — today?\" Rather than a one-time event, it is a continuous discipline: screening deposits and withdrawals against sanctions and risk sources, and monitoring counterparties on a schedule. Identity checks cannot see a wallet that starts receiving mixer output three months after onboarding; KYT can, and alerts you when it happens.
Which ones do you need?
It depends on who you serve and what moves through you:
- Retail exchange or wallet: KYC for users + KYT on deposits and withdrawals.
- B2B services, OTC, payment providers: KYB for corporate clients + KYT on settlement addresses.
- Regulated VASPs: all three — identity at onboarding, corporate due diligence for entities, transaction monitoring for the whole lifetime.
The common mistake is stopping after onboarding. Verification without monitoring is a snapshot; regulators increasingly ask for the film.
One program, one budget
On Arya Crypto all three run from a single token balance: address screening and KYT re-checks cost little per event, KYC costs more per verified person, KYB the most per company — reflecting the real work behind each. One API, one dashboard, one audit trail, so your compliance file reads as one coherent story instead of three disconnected tools.
Where AML fits above all three
KYC, KYB and KYT are controls. AML is the framework they sit inside — the policies, record-keeping, staff training and reporting obligations that your jurisdiction imposes. People often use "AML" and "KYC" interchangeably, which causes real confusion in vendor conversations and in audits.
The practical distinction: AML is what you are required to have. KYC, KYB and KYT are three of the mechanisms by which you satisfy it. A regulator will not ask whether you bought a screening tool; they will ask what your process is, whether it runs consistently, and whether you can evidence it.
How the three combine in a real workflow
They are sequential rather than parallel, and each one depends on the previous.
At onboarding you run KYC on an individual, or KYB if the customer is a company. That establishes identity. Then you screen the wallet addresses that customer actually uses, before crediting a deposit and before releasing a withdrawal. Then, for counterparties you deal with repeatedly, you place those addresses under continuous KYT monitoring so you learn about changes rather than discovering them in an audit.
Skipping a step leaves a specific hole. Screening wallets without KYC means an alert with nobody to contact. KYC without screening means a verified customer whose money you never look at. Neither is a programme.
One token balance, one audit trail
A frequent operational complaint is that compliance means three vendors, three contracts and three invoices. It does not have to.
On Arya Crypto, address screening, KYT monitoring, KYC and KYB all draw from a single token balance. There is no per-seat subscription; tokens are consumed only when a check actually runs, and an abandoned verification is not billed. That means you can mix the four in whatever proportion your business actually needs, and change that mix month to month without renegotiating anything.
It also means one audit trail. When an analyst reviews a flagged case, they see what the automated pipeline saw — which matters when you are reconstructing a decision months later. Current per-action rates are on the pricing page.
A minimum viable compliance stack
If you are starting from nothing, this order gets you defensible fastest.
- Week one: enable KYC at signup and run a handful of real verifications, including a deliberately poor-quality document, so you learn your approval and review rates.
- Week two: screen deposit addresses before crediting, and withdrawal destinations before releasing. Start with conservative thresholds.
- Week three: list your recurring counterparties and put their settlement addresses under monitoring.
- Week four: write the one-page policy — who reviews what, in what timeframe, and when it escalates — and set up an archive for the reports.
Add KYB when you begin onboarding companies rather than individuals. That single change is usually what triggers it.
When KYB specifically becomes necessary
KYB is the control teams delay longest, usually because their first corporate customer arrives before anyone has planned for one.
The trigger is simple: the moment your counterparty is a legal entity rather than a person, individual identity verification stops being sufficient. You now need to know the company exists, where it is registered, who ultimately owns it, and whether any of those owners appear on a sanctions list. A company is a structure people hide behind, which is precisely why KYB exists.
In practice this means collecting registration details and ultimate beneficial owner information, screening the company and each UBO internationally, reviewing the case, and receiving a signed decision on your webhook. You can gather the data through a public form the company completes itself, or submit it manually if you already hold it.
What each check costs relative to the others
The four are priced differently because they cost different amounts to perform, and understanding why helps you budget realistically.
Address and transaction screening is the cheapest per request: it is a lookup against indexed data. Automatic KYT re-runs are cheaper still per cycle, because re-analysis reuses monitoring infrastructure rather than rebuilding the graph. Personal KYC costs more, since it runs document forensics, biometric comparison and liveness analysis on uploaded media. Business KYB costs the most, because it involves company registry checks plus screening for every beneficial owner.
The practical consequence: monitoring a counterparty continuously for a month can cost less than a handful of scattered manual checks over the same period, while giving far better coverage because it leaves no gaps in time.
Mistakes that show up in audits
Verifying identity once and never refreshing it. Documents expire and ownership changes. Most frameworks expect periodic re-verification at an interval driven by customer risk.
Screening deposits but not withdrawals. Deposit screening stops you receiving tainted funds. Withdrawal screening stops you sending funds to a sanctioned address, which is usually the more serious violation.
Running checks without keeping the evidence. A check you cannot produce a record of is, to a regulator, a check you did not run.
Treating a clean result as permanent. Every check is a point-in-time assessment. Only monitoring keeps it current.
Set up the right checks for your business — Pricing · Services · KYT · KYC · KYB · Exchange · Prop