- Spotlight
- Aug 21, 2026
Precise, Confident, and Wrong: The Trouble With KYB Risk Scores
In this article, Stanislav Tyrnov, Head of KYB at Sumsub, discusses how business verification risk scoring can be improved by evaluating a company's ownership structure and transaction activity.

Business risk scoring sounds simple enough. You take the information you have about a company, assign values to different risk factors, and turn them into a score.
The problem is that the company itself is only part of the picture.
A business doesn’t operate in isolation. Behind a legal entity are its beneficial owners, directors, investors, subsidiaries, parent companies, and other connected parties. Its risk profile can also change as it starts operating in new markets, changes ownership, or begins moving money in ways that don’t match its expected activity.
That means a useful business risk score cannot be a static assessment of a registration record. It has to reflect the bigger network around a company and what that company actually does over time.
This is also where regulation is heading. The EU’s new Anti-Money Laundering Regulation takes a risk-based approach that considers not just the customer, but also beneficial owners, their reputation, behavior, and jurisdictions, as well as transaction-related risk factors. It also requires ongoing monitoring of business relationships and transactions.
For compliance teams, the direction is clear, but the difficult part is making it work well.
A company’s risk is not contained in its registration record
The first layer of business risk scoring is relatively familiar: a company’s identity, registration status, jurisdiction, and industry can all provide useful signals.
Some of these factors are straightforward to assess, such as corporate registries, which can establish whether an entity exists and provide information about its activities and ownership. Geographic and industry risks can then be incorporated into the assessment.
There can be certain complications with that part, particularly when information comes from different registries. Company classifications and industry codes aren’t globally standardized, and the same business activity can be represented differently across jurisdictions. However, these are largely data and normalization challenges, and can be solved with the right sources and processes.
The harder question is what happens when the information that matters most is not about the company itself.
Consider a business with a relatively clean registration record but a complicated ownership structure. One of its beneficial owners might be associated with another company that has sanctions exposure or significant adverse media. An affiliated entity may operate in a high-risk jurisdiction. A director could be connected to several other companies with troubling risk profiles.
None of this necessarily means the business is illegitimate, but it changes the context in which its risk should be assessed. A company is a network, not just a name in a registry.
That’s why ownership and control information cannot simply be collected during onboarding and then filed away. They need to feed into the risk assessment.
The FATF has similarly emphasized the importance of thorough risk assessment around legal persons and the risks arising from foreign legal structures and ownership arrangements.
Reputation is where automated scoring gets messy
Reputational risk is even harder to quantify.
On paper, the process sounds easy: search for adverse media, identify negative stories, and increase the risk score when something relevant appears. In practice, anyone who has worked with adverse media screening knows how quickly this can fall apart.
A company name can appear in an article without the company itself being involved in wrongdoing, or a technology provider can be mentioned in a story about fraud because its technology was used to prevent that fraud. A common corporate name can generate matches to completely unrelated organizations.
A simple keyword match isn’t able to reliably distinguish between these situations.
The same applies to geography. A regulatory action or criminal case in one jurisdiction does not automatically carry the same significance in another. Local context, the credibility of the source, the age of the information, and the company's actual involvement all matter.
This is one area where AI agents have a practical role to play, since machines can process large amounts of public information much faster than a human analyst can.
An intelligent system can assess an article in context, determine if the company is actually involved, distinguish relevant allegations from incidental mentions, and surface the information that deserves human attention.
The important word is context.
A risk score that treats every negative keyword as evidence of risk is detrimental, automated noise.
Transactions can change the risk picture
A business that looked low risk 6 months ago may behave differently today. Its transaction volumes may change. It may suddenly start sending funds to new jurisdictions, and its activity will then no longer resemble the business model it declared during onboarding.
That is why transaction monitoring can’t be completely separate from KYB risk scoring.
Transaction data provides evidence of how a business actually behaves. If that evidence changes the assessment of the relationship, the risk score should be able to reflect it.
The EU AMLR explicitly states that ongoing monitoring should be linked to the customer's business activity and risk profile, and that reviews should be triggered by material changes. That includes changes in transaction jurisdictions, transaction value or volume, products and services, and beneficial ownership.
This creates a much more useful feedback loop in the end:
Who is the company? Who controls it? Who is it connected to? What is happening around it? And does its actual behavior match what we expected?
The score should bring these signals together rather than treat them as separate compliance exercises.
Risk scoring depends on connected data
The information needed to assess a company is usually scattered across different systems. KYB data lives on one platform, KYC information on another, transaction monitoring elsewhere, while adverse media and sanctions screening generate their own alerts.
A compliance analyst can connect those dots manually, but that does not scale well. The result is often a risk score that appears precise but is based on an incomplete picture.
A better approach is to make the calculation transparent and connected to other operational decisions. Compliance teams should be able to see which factors contributed to a score, trace those factors back to their sources, and understand what changed.
If a company's risk exceeds a defined threshold, it could trigger enhanced due diligence, a review by a compliance analyst, additional information requests, transaction restrictions, or other actions as defined by the organization's policies.
Otherwise, the score is just another number in a dashboard.
What should a modern KYB risk-scoring system actually do?
The technology doesn’t need to be complicated to cover the full risk picture.
At a minimum, organizations should look for a system that can connect KYB and KYC onboarding with information about ownership and control, instead of treating the company and its associated people as completely separate entities.
Building further on that, it should be able to assess risk across the company's network of relevant entities and individuals, incorporate transaction monitoring, and detect behavioral indicators of fraud.
It should also be capable of intelligent adverse-media and AML alert assessment, where context matters, and provide transparent calculation steps so that compliance teams can understand why a certain score was produced.
Finally, the score needs to connect to the systems where decisions are actually made. If a risk score cannot trigger an operational action, it’s difficult to turn risk assessment into risk management.
This is the direction of Sumsub's own approach to company risk scoring: combining company information, ownership and control structures, associated-party risk, transaction and behavioral signals, and ongoing monitoring into a single assessment.
Business risk scoring should not answer only, “How risky is this company?”
It should answer, “How risky is this business relationship, given who this company is connected to, how those connections behave, and what the company is actually doing?”
That’s a much harder question, and a much more useful one when building an effective business verification risk scoring system.
Relevant articles
- spotlight
- Jul 9, 2026

- spotlight
- Jul 7, 2026
Hello there, I’m Alex. I was a fraudster for most of my life. I pulled off schemes worth millions of pounds, and there are scams I’m even proud of—pi…

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


