OSINT for KYC and AML Compliance

OSINT for KYC starts where your screening tool stops: the possible match nobody can confirm, the customer with no footprint, the ownership chain that ends in another jurisdiction. We research the open record and hand your analysts a sourced file they can put in front of the MLRO, an auditor or a regulator.

  • Screening hits confirmed or cleared
  • Beneficial ownership mapped
  • Source of wealth corroborated
  • Single files or a steady case flow
Short answer

OSINT for KYC is enhanced due diligence research from public and licensed sources, used when automated screening returns a possible hit, a gap or an opaque ownership structure. Analysts confirm or rule out matches, trace owners through registries, corroborate the customer's source of wealth and review adverse media. Your firm keeps the risk decision; OSINT-S supplies the evidence, with a source for every fact.

When Automated KYC Screening Is Not Enough

Screening tools are built for volume. Cases escalate when a result needs judgment, and each trigger needs a different kind of research.

TriggerWhat it usually meansWhat the OSINT work does
Possible sanctions, PEP or watchlist hitSame or similar name, thin identifiersTies the list entry and the customer to independent identifiers, then confirms or clears the match with reasons
Nothing found at allNew company, unusual name, or a person with no public lifeChecks whether the absence is plausible for the profile, or a sign the identity is constructed
Ownership stops at a holding companyForeign layer, trust or nomineeFollows each layer in its home register and looks for the people who act for the company
Wealth does not fit the profileDeclared story is thin or very largeCorroborates salary, company sales, property and inheritance events from public records
Negative newsAllegation, enforcement or a namesakeConfirms identity, grades the source, finds the outcome

What an OSINT KYC File Covers

Six areas, chosen per case: a false-positive review needs one, a high-risk corporate onboarding often needs all six.

Identity

Match resolution

Dates of birth, nationalities, addresses, roles and photos compared, so a hit is confirmed or cleared on evidence.

Ownership

Beneficial owners and controllers

Shareholders, trusts and nominee signs traced through each layer, and the people who sign, speak and decide for the customer.

Company investigations →
PEPs

Political exposure

Public roles, family members and close associates, the dates of office, and whether the role gives influence over the customer's business.

Wealth

Source of wealth and funds

The customer's account of how they made their money, tested against registries, filings, property records and media.

Media

Adverse media review

National, trade and court reporting in each country involved, read in full rather than keyword-matched.

Exposure

Sanctions through ownership and links

Designated persons who own, control or trade with the customer without appearing on its documents.

Due diligence →

Source of Wealth and Source of Funds From Open Sources

Open sources cannot prove where every dollar came from, but they can show whether the customer's account of their wealth is plausible and consistent with the public record.

Source of wealth is how a customer built their net worth; source of funds is where the money for this relationship comes from. Most evidence comes from the customer. OSINT tests that story against records nobody in the relationship created.

The FATF guidance on politically exposed persons makes the same point. It names publicly available property registers, land registers, asset disclosure registers and company registers as useful sources for verifying source of wealth, and says discrepancies with the customer's declarations could be indicators of money laundering suspicion. It also warns that an asset disclosure form is a self-declaration and may not contain verified information (FATF PEP guidance).

Typically we rebuild the customer's career and business timeline, confirm the sale that produced a liquidity event, match property to dates and prices where registers show them, and flag gaps. Where the trail points to assets the customer did not mention, the case can move into asset tracing.

What FATF and Regulators Say About OSINT in AML

Regulators expect firms to use independent sources for higher-risk customers, and warn that databases alone do not meet the standard.

  • FATF. The PEP guidance under Recommendations 12 and 22 says commercial databases are not required by the FATF Recommendations, are not sufficient for compliance with Recommendation 12, and "should never replace traditional CDD processes" (FATF).
  • United Kingdom. Regulation 33 of the Money Laundering Regulations 2017 lists the cases that need enhanced due diligence, including PEPs, high-risk cases and unusually complex or large transactions. The enhanced measures may include "seeking additional independent, reliable sources to verify information" and taking additional measures to understand the background, ownership and financial situation of the customer (MLR 2017, reg. 33).
  • United States. A joint statement by FinCEN and the federal banking agencies of 21 August 2020 notes that BSA/AML regulations do not define PEPs, that the CDD rule does not require banks to screen for them, and that "not all PEPs are automatically higher risk"; banks must apply a risk-based approach (joint statement).

The common thread is proportion: OSINT is for cases where risk is real and documents do not settle it.

Adverse Media Without the False Positives

Good adverse media review answers three questions for each article: is it our customer, how reliable is the source, and how did the matter end.

QuestionHow we answer it
Is it the same person or company?At least two independent identifiers match, such as date of birth, role, address or registration number
How credible is the source?Court records and regulators first, then established media, then blogs and forums, each labeled
Allegation, charge or finding?We follow the story to its outcome: dropped, settled, acquitted, convicted or still open
Is it relevant to financial crime?Fraud, corruption, sanctions, tax and organized crime are separated from unrelated disputes

You get the findings that matter, not every article that mentions the name.

How an Escalated KYC Case Runs

Five steps, from the trigger your team flagged to a file your MLRO can rely on in the decision.

  1. Send the triggerYou share the screening result, the question and only the customer documents the case needs.
  2. Agree scope and deadlineWe confirm the countries, depth and delivery date and send a fixed quote; for a case flow, we agree terms per file type.
  3. Research independent sourcesRegistries, courts, sanctions and enforcement lists, property and asset records, media and online sources in each relevant country.
  4. Resolve and gradeMatches are confirmed or cleared, discrepancies with the customer's account are listed, and each finding gets a confidence level.
  5. Senior review and deliveryA senior analyst reviews the file before it reaches your team, with sources and captures for your records.

Your Obligations Stay With You

We provide research. The regulated firm keeps its customer due diligence duties, its risk rating, its decision to onboard or exit and any suspicious activity reporting.

  • The decision is yours. We do not set risk ratings, approve customers or decide whether to file a suspicious activity report. Our file is evidence your MLRO or compliance officer weighs.
  • No contact with the customer. We never approach the customer or people around them. In the UK, disclosing that an investigation is being contemplated or carried out, where that is likely to prejudice it, can be a tipping-off offense in the regulated sector (POCA 2002, s.333A).
  • Lawful sources only. No hacking, no fake profiles to see private accounts, no purchased leaked or breached data. Personal data is processed for the AML purpose and kept proportionate, in line with the GDPR and UK GDPR (GDPR).
  • Not identity verification. Document and biometric checks at onboarding belong with your IDV provider; we work on the cases that remain open after it.

Turnaround, Volume and Format for AML Teams

Single match reviews sometimes take a business day; full enhanced due diligence files take from 10 business days to about a month.

A false-positive review on one name can sometimes be closed in one business day. A corporate customer with foreign layers and a source-of-wealth question takes from 10 business days, and complex multi-country structures up to about a month. Urgent files cost 50% more, and if we miss the agreed date, the fee goes down.

Files open with the answer to the trigger, then identity, ownership, PEP status, source of wealth, adverse media and open questions for the customer. Customers that stay high risk after onboarding can be watched on our analyst-reviewed platform, which updates hourly, through OSINT monitoring. Crypto-asset exposure is handled with crypto investigations, one of the OSINT services for regulated firms we run as one team.

OSINT KYC and AML: Specialized Services

Focused versions of kyc and aml for specific subjects, deals and situations.

KYC and AML

Source of wealth checks

Declared wealth tested against registries, filings, property records and media, with a timeline and the gaps your MLRO should ask about.

Read more →
KYC and AML

PEP and adverse media

Screening alerts reviewed by analysts: false positives cleared, PEP relatives and associates found, adverse media graded for relevance and credibility.

Read more →
KYC and AML

Sanctions evasion investigations

Hidden sanctioned owners, 50 Percent Rule tests, intermediaries, transshipment and shipping red flags researched for compliance and legal teams.

Read more →

Send Us the Case Your Screening Could Not Close

Share the trigger, the customer type, the countries involved and your deadline. We reply with a scope, a delivery date and a fixed quote.

OSINT for KYC and AML: FAQ

Our screening tool flagged a new corporate customer's director as a possible match to a sanctioned person with a similar name — can OSINT for KYC confirm or clear the match before we decide on onboarding this week?

Usually yes. We compare the listed person's published identifiers with the director's date of birth, nationality, addresses, roles and photos from registries, filings and media, then confirm or clear the match with the evidence set out. A single-name review like this can sometimes be done in one business day; if identifiers are thin, we say so rather than force a conclusion.

I'm onboarding a wealthy client who says her money comes from selling a family logistics business ten years ago — how can open sources help me corroborate that source of wealth?

We look for the business in company registers and filings, the sale in transaction announcements, trade press and later ownership records, and her role in it over time. We then compare the timing and scale with property holdings and other assets in public registers. The result shows whether her account is consistent with the record, and lists the documents you should still request from her.

Our compliance team wants to use OSINT in AML reviews but our MLRO worries about relying on internet searches — what makes an OSINT file defensible to an auditor or regulator?

Method and audit trail. A defensible file names each source, dates it, keeps a capture and separates verified facts from allegations. Matches rest on several independent identifiers, and each conclusion carries a confidence level. Random search results are not evidence; dated registry extracts, court records and graded media are.

We're a payments company and a merchant's owner has almost no online footprint at all — is a missing digital footprint a red flag, or are we overthinking it?

It depends on the profile. A retired person or a small local trader often has little online presence. A director who claims to run an international e-commerce business and leaves no trace in registries, trade data or professional sources is a different matter. We check whether the absence is plausible, and whether the identity details link to other companies or reused addresses.

Our US bank has a local politician applying for a mortgage — do we have to treat every PEP as high risk and run full enhanced due diligence on them?

Not automatically. US agencies have said not all PEPs are higher risk and that a risk-based approach applies. UK firms are different: regulation 33 lists every PEP among the cases needing enhanced due diligence. Either way, the role, the country, the business and any adverse findings set the depth, and a light OSINT check on role and media shows whether more is warranted.

If your research on our customer finds something suspicious, will you report it to the authorities yourselves or tell the customer what you found?

Neither. We report findings only to you. Your firm decides whether the facts amount to suspicion and whether to file a report, under your own legal obligations. We never contact the customer or their associates, which also protects you from tipping-off risk.

We get around forty escalated KYC cases a month that our team cannot close — can you handle a steady flow, and how do we keep costs predictable?

Yes. We agree a standard file format and fixed quotes per case type, for example a match review, a corporate ownership file and a full enhanced due diligence file with source of wealth. Each case gets a delivery date at intake, and a monthly review of the flow keeps scope in line with what files actually need.