Crypto KYB: Verify the Permission, Not Just the Company
A crypto company can legally exist without being permitted to provide the service it claims. Learn how KYB connects entity verification with regulatory status and permission scope.

A crypto business can pass every basic company check and still leave one important question unanswered.
The entity exists.
The directors match.
The beneficial owners have been identified.
Screening produces no obvious issue.
But can this legal entity actually provide the crypto service it claims to provide, in the market where it is providing it?
That question sits between traditional company verification and regulatory due diligence.
For teams onboarding exchanges, custodians and other virtual-asset businesses, crypto KYB cannot stop at proving that the company is real.
It also needs to understand the company's regulatory identity.
A company record and a regulatory permission answer different questions
A corporate registry is designed to tell you about the legal entity.
It can help establish its legal name, registration number, status, address, directors and other available corporate information. Detelio's data coverage brings company-registry, ownership, screening and monitoring inputs into the wider KYB process.
That information is fundamental.
But a regulatory record answers a different question.
It may establish whether a particular entity is registered or authorised, which authority oversees it, which activities fall within its permission and whether that regulatory status remains current.
The distinction becomes especially important when a crypto business operates through a group of companies.
Imagine a brand with:
- a parent company in one jurisdiction
- an operating subsidiary in another
- customers across several markets
- a regulatory permission held by only one entity in the group
Finding a licence or registration somewhere under the same brand does not necessarily resolve the KYB question.
The relevant question is whether the permission matches the entity, activity and jurisdiction actually being reviewed.
That is the gap a stronger crypto KYB process needs to close.
Regulatory identity has five parts
Instead of reducing regulatory information to:
Regulated: Yes
a useful crypto KYB review should connect five pieces of context.
1. Legal entity
Which exact company is the counterparty?
The trading name, group name and regulated legal entity may not be identical.
2. Activity
What does that entity actually do?
Custody, exchange, transfer, execution and other crypto services can carry different regulatory implications.
3. Jurisdiction
Where is that activity being provided?
The country of incorporation is only one part of that picture.
4. Regulatory status
What status does the entity hold under the relevant regime?
Depending on the jurisdiction and circumstances, that may involve authorisation, registration, restrictions, withdrawal or another applicable status.
5. Permission scope
Does that regulatory status actually cover the service being offered?
Together, these five elements provide considerably more useful context than a binary regulatory flag.
Entity → Activity → Jurisdiction → Status → Scope
That is the regulatory identity behind the KYB decision.
MiCA makes this distinction unusually visible
Europe now provides a very practical example.
MiCA allowed eligible crypto-asset service providers operating under national law before 30 December 2024 to benefit from transitional arrangements up to 1 July 2026, although Member States could shorten or decline the grandfathering period. With the maximum transition now over, ESMA has said unauthorised CASPs should stop onboarding new EU clients and take immediate steps to wind down their EU activities in an orderly way. You can read ESMA's June 2026 statement on the end of the MiCA transitional period.
That creates a very concrete KYB question.
It is no longer enough to know that a crypto business previously operated under some national arrangement.
A team evaluating the business needs to understand what status applies now.
ESMA also maintains its central MiCA register. The register contains separate records for authorised crypto-asset service providers and non-compliant entities. ESMA says it is updated weekly, and withdrawn authorisations remain in the register with the date the withdrawal became effective.
That illustrates why regulatory status should be treated as information with context and history.
A compliance team does not merely need to know that someone found a regulatory record.
It needs to understand:
Which entity is on it?
What status does it show?
What does that status cover?
Is it still current?
The regulatory label itself can be misleading
There is another complication.
Terms such as registered, authorised and licensed do not have one universal meaning across crypto regulatory regimes.
The UK currently provides a useful example.
Firms providing in-scope crypto-asset services in the UK must currently be registered with the FCA under the Money Laundering Regulations before they begin trading. Under the forthcoming regime, firms carrying out regulated crypto-asset activities will instead need the relevant authorisation under FSMA. Applications for that authorisation open on 30 September 2026, and the new regime is expected to start on 25 October 2027. The FCA explains the transition in its guidance on MLR registration ahead of the new FSMA crypto-asset regime.
Importantly, an existing MLR registration does not automatically become FSMA authorisation.
The FCA says firms already registered under the MLRs will still need FSMA authorisation where they carry out activities regulated under the new regime. It also states that being registered under the MLRs does not guarantee FSMA authorisation.
So a KYB record that simply says:
FCA registered ✓
may contain a correct fact while still lacking the context needed for the decision.
A stronger review asks:
Registered under which regime?
For which activity?
For which legal entity?
At what point in time?
The objective is not to collect regulatory badges.
It is to understand what the regulatory status means for the business being assessed.
Match the permission to the entity, not the brand
This is where regulatory verification becomes operational.
Suppose an onboarding team receives:
- the customer's legal entity name
- a corporate registry record
- a regulator reference
- a group website displaying a regulatory claim
The job is not simply to collect all four.
The job is to establish whether they describe the same regulatory relationship.
That can require comparing:
- legal name
- company identifier
- regulator identifier
- jurisdiction
- relevant group entity
- stated activities
- permission scope
- current regulatory status
Detelio's crypto KYB workflow is structured around this broader view of the counterparty. It brings legal-entity verification, licensing or registration evidence, operating footprint, ownership, sanctions and PEP screening, wallet exposure and monitoring signals into the same KYB process. Licensing or registration inconsistencies, unclear scope and conflicting operating footprints are among the signals that can trigger review.
The principle is simple:
Do not verify a permission somewhere in the group. Verify the permission relevant to the counterparty in front of you.
Permission also has a lifecycle
There is a temptation to treat regulatory evidence as something collected during onboarding and then archived.
But the underlying facts can move.
An entity may obtain a new authorisation.
A permission may be withdrawn.
A service may move to another group company.
The business may enter another market.
The activity being offered may change.
The regulatory evidence that supported the original decision can therefore become stale even when it was perfectly accurate on the day it was collected.
That is where regulatory identity connects naturally to continuous KYB monitoring.
Detelio's monitoring workflow is designed to detect changes in areas such as company status, ownership, directors, sanctions and other risk-relevant signals, then route material changes into review with the evidence attached.
The same underlying principle applies to regulatory context:
a decision is only as current as the facts supporting it.
The international picture reinforces this.
In its July 2026 update on virtual assets and VASPs, FATF reported continued progress in implementing Recommendation 15, including licensing and registration frameworks, Travel Rule implementation and supervisory activity. But it also found significant remaining gaps in operationalising licensing and registration frameworks, identifying persons or entities conducting VASP activity, and ensuring effective risk-based supervision and enforcement.
For teams assessing crypto businesses across markets, the regulatory picture is therefore not one global database with one universal yes-or-no answer.
Context matters.
Seven questions before approving a crypto counterparty
A practical regulatory-status review should be able to answer seven questions:
- Which exact legal entity are we onboarding?
- What crypto activity does that entity perform?
- Where is that activity being provided?
- Which regulatory regime applies?
- What regulatory status does the entity currently hold?
- Does that status cover the activity being offered?
- What change would cause us to review the relationship again?
These questions do not replace ownership verification, sanctions and PEP screening, wallet-risk checks or broader KYB risk scoring.
They provide regulatory context around those other controls.
Detelio's risk-scoring workflow combines factors such as business data, ownership, geography and screening signals with configurable policy logic, so cases can be assessed and routed according to the risk model rather than one isolated indicator.
And once the decision is made, the evidence behind it needs to remain connected to the case.
A structured KYB audit trail helps preserve verification runs, sources, reviewer actions, decision rationale, timestamps and subsequent changes. That makes the original decision easier to review later without reconstructing it from scattered records.
Verify the entity. Verify the permission.
Corporate verification establishes who the business is.
For crypto counterparties, that may only be the first half of the decision.
The second half is understanding the regulatory identity surrounding that business:
Which entity?
Which activity?
Which jurisdiction?
Which status?
Which scope?
A company can exist without having permission to perform every activity it claims.
A regulatory record can exist without applying to the particular entity being onboarded.
And regulatory status can change after the original decision.
Good crypto KYB connects those facts before deciding what the relationship means for risk.
Verify the entity. Verify the permission.
