By Steve Lamb – CEO, Kyckr
I went to the European Business Registry Association’s annual conference in Malta this year expecting to talk about incremental changes to company registries. Thanks to a new EU identity initiative, I left thinking about the future of business verification.
Know Your Business is one of the most persistent and expensive problems regulated firms face. At its heart it is an identity problem. Every institution wants the same thing: a fast, accurate understanding of who it is dealing with. Yet achieving it has meant collecting vast amounts of information from customers and verifying it independently, repeatedly. The corporate equivalent of a passport – a single, portable proof of identity – has stayed frustratingly out of reach.
Europe has solved this kind of problem before.
Thirty years ago, sending money across borders was slow and fragmented: banks built and maintained webs of bilateral relationships, and the same information was checked at every step. Then the industry built shared infrastructure: payment schemes, messaging standards, the Single Euro Payments Area (SEPA). Business identity never had that moment. We are still in the KYB equivalent of the pre-SEPA era.

The European Business Wallet may change that. It gives businesses a digital repository for verifiable credentials, proofs of identity and other trust attestations they can present on demand to any counterparty that asks.
It could answer the three questions underpinning all KYB: is this company real, who owns it, and is this person authorised to act for it? Obliged entities would rely on signed, machine-readable credentials instead of manually requesting and reverifying the same documents. Onboarding moves from weeks to near-instant.
The numbers are substantial. Large institutions spend up to $50 million a year on client due diligence, much of it verifying information customers downloaded from the register in the first place. When Kyckr surveyed SME owners several years ago, they expected to open a bank account in two days; the reality is often one to three months. The European Commission estimates broad adoption could unlock at least €150 billion in savings each year. That’s roughly €5,000 for every company in Europe.
Company registers are becoming even more important.
In a wallet-based model, the company register is enshrined as the “authentic source”: the legally binding origin of truth about which companies exist and who may act for them. That is the right direction.
But this raises the stakes considerably. A credential is only ever as good as the register beneath it. If that register is incomplete or out of date, the problem propagates faster, wrapped in a veneer of cryptographic certainty. Garbage in, garbage out, at machine speed.
Not all registers are equal. Legal authority, verification rigour, data quality and access vary widely between jurisdictions, even as institutions tend to treat every register as equally authoritative.
Fortunately, as was clear in Malta, registries from Luxembourg to Bulgaria are moving from librarians to gatekeepers, checking what they are given rather than simply filing it. Malta recently created a compliance unit that risk-scores entities at incorporation, cross-referencing sanctions lists and government databases. Verification may well be moving to the source, instead of being repeated by every institution downstream.
Three questions remain unsolved:
First, what happens when a registry wears two hats? If registries become the default wallet interface and begin packaging KYB profiles directly to relying parties, the market tilts. This is not hypothetical: in a position paper published last month, the DT4C Alliance – whose members include Moody’s, LSEG Risk Intelligence, LexisNexis Risk Solutions and Dun & Bradstreet – pointed to a live legal dispute between the Dutch Chamber of Commerce (KVK) and a B2B information provider. A Dutch appeal court has now referred to the Court of Justice the question of whether a publicly funded register can restrict commercial reuse of its data. The principle stands regardless of who voices it. The moment the authoritative source becomes a competitor in the market built on top of it, scrutiny follows.
Second, what does a credential mean? The danger is mistaking a verified credential for compliance itself. EU AML law rests on the obliged entity carrying full responsibility for risk-based due diligence. A credential confirms identity and formal attributes, but does not screen for sanctions, weigh adverse media, or interpret a chain of ownership. Those are judgements, and judgement cannot be delegated to an issuer.
Third, the wallet does not yet carry time. A director resigns. Ownership changes hands. A name appears on a sanctions list. The wallet answers “is this real and authorised today?” but a credential is a statement about a single moment, and companies do not live in single moments. That gap, between issuance and the next change in a company’s circumstances, is exactly when financial crime tends to occur.
So, what will KYB look like in five years?
Faster and cheaper is the easy prediction.
For routine cases, KYB becomes a simple case of credential exchange. A company presents proof from its wallet, the obliged entity verifies the signature, and a basic business identity check takes mere seconds. The document-gathering that consumes most CDD budgets drops out of the standard path.
What does not drop out is the judgement. A signed credential tells you a company existed, its associated parties, and that its representative was authorised on the date it was issued. It does not tell you whether that is still true, and it never tells you whether this is a counterparty you should transact with. The register still must keep the data accurate. The relying party still must conduct adequate risk assessments.
Crucially, the register does not become less important in this model. It becomes the thing everything else rests on, which is why the important work of the next five years will not be building the wallet ecosystem. That is already under way. It will be raising the quality of what sits underneath it.


