/ Blog center
Crypto

Crypto KYB: Verify the Permission, Not Just the Company

A crypto company can legally exist without being permitted to provide the service it claims. Learn how KYB connects entity verification with regulatory status and permission scope.

Gasan Rasulov
August 11, 2026

A crypto business can pass every basic company check and still leave one important question unanswered.

The entity exists.

The directors match.

The beneficial owners have been identified.

Screening produces no obvious issue.

But can this legal entity actually provide the crypto service it claims to provide, in the market where it is providing it?

That question sits between traditional company verification and regulatory due diligence.

For teams onboarding exchanges, custodians and other virtual-asset businesses, crypto KYB cannot stop at proving that the company is real.

It also needs to understand the company's regulatory identity.

A company record and a regulatory permission answer different questions

A corporate registry is designed to tell you about the legal entity.

It can help establish its legal name, registration number, status, address, directors and other available corporate information. Detelio's data coverage brings company-registry, ownership, screening and monitoring inputs into the wider KYB process.

That information is fundamental.

But a regulatory record answers a different question.

It may establish whether a particular entity is registered or authorised, which authority oversees it, which activities fall within its permission and whether that regulatory status remains current.

The distinction becomes especially important when a crypto business operates through a group of companies.

Imagine a brand with:

  • a parent company in one jurisdiction
  • an operating subsidiary in another
  • customers across several markets
  • a regulatory permission held by only one entity in the group

Finding a licence or registration somewhere under the same brand does not necessarily resolve the KYB question.

The relevant question is whether the permission matches the entity, activity and jurisdiction actually being reviewed.

That is the gap a stronger crypto KYB process needs to close.

Regulatory identity has five parts

Instead of reducing regulatory information to:

Regulated: Yes

a useful crypto KYB review should connect five pieces of context.

1. Legal entity

Which exact company is the counterparty?

The trading name, group name and regulated legal entity may not be identical.

2. Activity

What does that entity actually do?

Custody, exchange, transfer, execution and other crypto services can carry different regulatory implications.

3. Jurisdiction

Where is that activity being provided?

The country of incorporation is only one part of that picture.

4. Regulatory status

What status does the entity hold under the relevant regime?

Depending on the jurisdiction and circumstances, that may involve authorisation, registration, restrictions, withdrawal or another applicable status.

5. Permission scope

Does that regulatory status actually cover the service being offered?

Together, these five elements provide considerably more useful context than a binary regulatory flag.

Entity → Activity → Jurisdiction → Status → Scope

That is the regulatory identity behind the KYB decision.

MiCA makes this distinction unusually visible

Europe now provides a very practical example.

MiCA allowed eligible crypto-asset service providers operating under national law before 30 December 2024 to benefit from transitional arrangements up to 1 July 2026, although Member States could shorten or decline the grandfathering period. With the maximum transition now over, ESMA has said unauthorised CASPs should stop onboarding new EU clients and take immediate steps to wind down their EU activities in an orderly way. You can read ESMA's June 2026 statement on the end of the MiCA transitional period.

That creates a very concrete KYB question.

It is no longer enough to know that a crypto business previously operated under some national arrangement.

A team evaluating the business needs to understand what status applies now.

ESMA also maintains its central MiCA register. The register contains separate records for authorised crypto-asset service providers and non-compliant entities. ESMA says it is updated weekly, and withdrawn authorisations remain in the register with the date the withdrawal became effective.

That illustrates why regulatory status should be treated as information with context and history.

A compliance team does not merely need to know that someone found a regulatory record.

It needs to understand:

Which entity is on it?

What status does it show?

What does that status cover?

Is it still current?

The regulatory label itself can be misleading

There is another complication.

Terms such as registered, authorised and licensed do not have one universal meaning across crypto regulatory regimes.

The UK currently provides a useful example.

Firms providing in-scope crypto-asset services in the UK must currently be registered with the FCA under the Money Laundering Regulations before they begin trading. Under the forthcoming regime, firms carrying out regulated crypto-asset activities will instead need the relevant authorisation under FSMA. Applications for that authorisation open on 30 September 2026, and the new regime is expected to start on 25 October 2027. The FCA explains the transition in its guidance on MLR registration ahead of the new FSMA crypto-asset regime.

Importantly, an existing MLR registration does not automatically become FSMA authorisation.

The FCA says firms already registered under the MLRs will still need FSMA authorisation where they carry out activities regulated under the new regime. It also states that being registered under the MLRs does not guarantee FSMA authorisation.

So a KYB record that simply says:

FCA registered ✓

may contain a correct fact while still lacking the context needed for the decision.

A stronger review asks:

Registered under which regime?

For which activity?

For which legal entity?

At what point in time?

The objective is not to collect regulatory badges.

It is to understand what the regulatory status means for the business being assessed.

Match the permission to the entity, not the brand

This is where regulatory verification becomes operational.

Suppose an onboarding team receives:

  • the customer's legal entity name
  • a corporate registry record
  • a regulator reference
  • a group website displaying a regulatory claim

The job is not simply to collect all four.

The job is to establish whether they describe the same regulatory relationship.

That can require comparing:

  • legal name
  • company identifier
  • regulator identifier
  • jurisdiction
  • relevant group entity
  • stated activities
  • permission scope
  • current regulatory status

Detelio's crypto KYB workflow is structured around this broader view of the counterparty. It brings legal-entity verification, licensing or registration evidence, operating footprint, ownership, sanctions and PEP screening, wallet exposure and monitoring signals into the same KYB process. Licensing or registration inconsistencies, unclear scope and conflicting operating footprints are among the signals that can trigger review.

The principle is simple:

Do not verify a permission somewhere in the group. Verify the permission relevant to the counterparty in front of you.

Permission also has a lifecycle

There is a temptation to treat regulatory evidence as something collected during onboarding and then archived.

But the underlying facts can move.

An entity may obtain a new authorisation.

A permission may be withdrawn.

A service may move to another group company.

The business may enter another market.

The activity being offered may change.

The regulatory evidence that supported the original decision can therefore become stale even when it was perfectly accurate on the day it was collected.

That is where regulatory identity connects naturally to continuous KYB monitoring.

Detelio's monitoring workflow is designed to detect changes in areas such as company status, ownership, directors, sanctions and other risk-relevant signals, then route material changes into review with the evidence attached.

The same underlying principle applies to regulatory context:

a decision is only as current as the facts supporting it.

The international picture reinforces this.

In its July 2026 update on virtual assets and VASPs, FATF reported continued progress in implementing Recommendation 15, including licensing and registration frameworks, Travel Rule implementation and supervisory activity. But it also found significant remaining gaps in operationalising licensing and registration frameworks, identifying persons or entities conducting VASP activity, and ensuring effective risk-based supervision and enforcement.

For teams assessing crypto businesses across markets, the regulatory picture is therefore not one global database with one universal yes-or-no answer.

Context matters.

Seven questions before approving a crypto counterparty

A practical regulatory-status review should be able to answer seven questions:

  1. Which exact legal entity are we onboarding?
  2. What crypto activity does that entity perform?
  3. Where is that activity being provided?
  4. Which regulatory regime applies?
  5. What regulatory status does the entity currently hold?
  6. Does that status cover the activity being offered?
  7. What change would cause us to review the relationship again?

These questions do not replace ownership verification, sanctions and PEP screening, wallet-risk checks or broader KYB risk scoring.

They provide regulatory context around those other controls.

Detelio's risk-scoring workflow combines factors such as business data, ownership, geography and screening signals with configurable policy logic, so cases can be assessed and routed according to the risk model rather than one isolated indicator.

And once the decision is made, the evidence behind it needs to remain connected to the case.

A structured KYB audit trail helps preserve verification runs, sources, reviewer actions, decision rationale, timestamps and subsequent changes. That makes the original decision easier to review later without reconstructing it from scattered records.

Verify the entity. Verify the permission.

Corporate verification establishes who the business is.

For crypto counterparties, that may only be the first half of the decision.

The second half is understanding the regulatory identity surrounding that business:

Which entity?

Which activity?

Which jurisdiction?

Which status?

Which scope?

A company can exist without having permission to perform every activity it claims.

A regulatory record can exist without applying to the particular entity being onboarded.

And regulatory status can change after the original decision.

Good crypto KYB connects those facts before deciding what the relationship means for risk.

Verify the entity. Verify the permission.

The answers to questions you might have

Common FAQs

Quick answers regarding the topic above

What is crypto KYB?

Expand section details

Crypto KYB is the process of verifying a crypto business and evaluating the information needed to make a risk-based counterparty decision. It typically builds on standard legal-entity, ownership and screening checks and may also involve regulatory status, licensing or registration evidence, operating jurisdiction and wallet-exposure considerations depending on the relationship and risk profile. Detelio's crypto KYB solution combines entity and UBO verification with licensing evidence, screening, wallet-risk signals, decisioning and ongoing monitoring.

Is company registration enough to verify a crypto business?

Expand section details

Not necessarily. Company registration helps establish the legal existence and identity of the business. It does not by itself establish that the entity is authorised or registered to provide a particular regulated crypto service. The relevant activity, jurisdiction, regulatory regime, status and permission scope may need to be assessed separately.

What should teams check when verifying crypto regulatory status?

Expand section details

Teams should understand which legal entity holds the regulatory status, which authority issued it, which regime applies, what activities or services it covers, where it applies, and whether the status remains current. The exact requirements depend on the jurisdiction, activity and nature of the relationship.

Why monitor a crypto business after onboarding?

Expand section details

Because facts supporting the original decision can change. Ownership, directors, corporate status, sanctions exposure, operating footprint and other risk signals can move after onboarding. Continuous KYB monitoring helps teams identify material changes and route them into review rather than relying indefinitely on the original onboarding snapshot.

Paper airplane icon representing sending an invitation or dispatching a report.

Get new posts occasionally

Practical KYB notes and updates, sent sparingly

Thanks, you’re subscribed.
Something went wrong. Please try again.
Verify crypto counterparties with the regulatory context attached
Detelio brings entity information, ownership context, regulatory evidence, risk signals, reviewer decisions and monitoring into one structured KYB workflow.
Request a demo