Sanctions screening is live. Your KYB record isn't.

Banks screen payments in real time but trust business identity in retrospect. Why point-in-time KYB leaves a gap that fraud is built to use.
Kris Singh
August 27, 2026
Sanctions screening is live. Your KYB record isn't.

Every large bank I talk to screens payments against sanctions and watchlists at the moment money moves. That part is live, it is automated, and it works. It is one of the few controls in the stack that runs at transaction speed instead of at review speed.

But screening answers exactly one question: is this name on a list?

It does not tell you that the controlling party of your counterparty changed in March. That an operating license was revoked in a state you don't monitor. That the entity quietly dissolved and re-registered under a similar name. That the person approving this wire stopped being authorized to approve it two reorganizations ago.

Those facts live somewhere else, in a KYB record with a date on it.

So the architecture most institutions are actually running looks like this. The payment is checked in real time. The entity behind the payment is trusted in retrospect. One half of the decision is current; the other half was true the day you ran it and has been decaying ever since.

Fraud uses the second half.

This is not a hypothetical failure mode. In a single year, FinCEN tied $212 billion in suspicious activity to identity, with false records the second-most-reported type behind general fraud. That is not a story about people on sanctions lists. It is a story about identity. And the hardest version of it isn't the entity that was fake at the door. It's the one that was real when you checked and isn't anymore. The paper looks legitimate because the paper is old.

The instinct when a record goes stale is to re-run it. Send the business back through the same verification you ran at underwriting and refresh the file. But that produces a second point-in-time check, a new photograph, taken later, that starts aging the moment it is written. Two snapshots are not a live feed.

What has to change is the shape of the answer, not the frequency of the question. "Verified" needs to stop being a date on a file and start being a state you can query at the moment somebody acts. And the record of who authorized the action needs to be bound to that action rather than logged next to it.

That is the work we are doing with Enigma, whose business identity data sits behind half of the top ten U.S. banks. Enigma keeps the entity picture continuously true. Proof captures a verified human's signature on the specific action, the wire, the invoice, the instruction, so the authorization is bound to what was approved. Neither half is sufficient alone. Together they close the gap between a payment you screened in real time and a counterparty you last confirmed at onboarding.

If you run fraud, risk, or treasury at an institution moving commercial money, you already know which half of that decision is current and which half is not.

Which half do you think the fraud is using?

graphic of envelop on a square

Subscribe to our newsletter

Related Articles