Match resolution
Dates of birth, nationalities, addresses, roles and photos compared, so a hit is confirmed or cleared on evidence.
OSINT for KYC starts where your screening tool stops: the possible match nobody can confirm, the customer with no footprint, the ownership chain that ends in another jurisdiction. We research the open record and hand your analysts a sourced file they can put in front of the MLRO, an auditor or a regulator.
OSINT for KYC is enhanced due diligence research from public and licensed sources, used when automated screening returns a possible hit, a gap or an opaque ownership structure. Analysts confirm or rule out matches, trace owners through registries, corroborate the customer's source of wealth and review adverse media. Your firm keeps the risk decision; OSINT-S supplies the evidence, with a source for every fact.
Screening tools are built for volume. Cases escalate when a result needs judgment, and each trigger needs a different kind of research.
| Trigger | What it usually means | What the OSINT work does |
|---|---|---|
| Possible sanctions, PEP or watchlist hit | Same or similar name, thin identifiers | Ties the list entry and the customer to independent identifiers, then confirms or clears the match with reasons |
| Nothing found at all | New company, unusual name, or a person with no public life | Checks whether the absence is plausible for the profile, or a sign the identity is constructed |
| Ownership stops at a holding company | Foreign layer, trust or nominee | Follows each layer in its home register and looks for the people who act for the company |
| Wealth does not fit the profile | Declared story is thin or very large | Corroborates salary, company sales, property and inheritance events from public records |
| Negative news | Allegation, enforcement or a namesake | Confirms identity, grades the source, finds the outcome |
Six areas, chosen per case: a false-positive review needs one, a high-risk corporate onboarding often needs all six.
Dates of birth, nationalities, addresses, roles and photos compared, so a hit is confirmed or cleared on evidence.
Shareholders, trusts and nominee signs traced through each layer, and the people who sign, speak and decide for the customer.
Company investigations →Public roles, family members and close associates, the dates of office, and whether the role gives influence over the customer's business.
The customer's account of how they made their money, tested against registries, filings, property records and media.
National, trade and court reporting in each country involved, read in full rather than keyword-matched.
Designated persons who own, control or trade with the customer without appearing on its documents.
Due diligence →Open sources cannot prove where every dollar came from, but they can show whether the customer's account of their wealth is plausible and consistent with the public record.
Source of wealth is how a customer built their net worth; source of funds is where the money for this relationship comes from. Most evidence comes from the customer. OSINT tests that story against records nobody in the relationship created.
The FATF guidance on politically exposed persons makes the same point. It names publicly available property registers, land registers, asset disclosure registers and company registers as useful sources for verifying source of wealth, and says discrepancies with the customer's declarations could be indicators of money laundering suspicion. It also warns that an asset disclosure form is a self-declaration and may not contain verified information (FATF PEP guidance).
Typically we rebuild the customer's career and business timeline, confirm the sale that produced a liquidity event, match property to dates and prices where registers show them, and flag gaps. Where the trail points to assets the customer did not mention, the case can move into asset tracing.
Regulators expect firms to use independent sources for higher-risk customers, and warn that databases alone do not meet the standard.
The common thread is proportion: OSINT is for cases where risk is real and documents do not settle it.
Good adverse media review answers three questions for each article: is it our customer, how reliable is the source, and how did the matter end.
| Question | How we answer it |
|---|---|
| Is it the same person or company? | At least two independent identifiers match, such as date of birth, role, address or registration number |
| How credible is the source? | Court records and regulators first, then established media, then blogs and forums, each labeled |
| Allegation, charge or finding? | We follow the story to its outcome: dropped, settled, acquitted, convicted or still open |
| Is it relevant to financial crime? | Fraud, corruption, sanctions, tax and organized crime are separated from unrelated disputes |
You get the findings that matter, not every article that mentions the name.
Five steps, from the trigger your team flagged to a file your MLRO can rely on in the decision.
We provide research. The regulated firm keeps its customer due diligence duties, its risk rating, its decision to onboard or exit and any suspicious activity reporting.
Single match reviews sometimes take a business day; full enhanced due diligence files take from 10 business days to about a month.
A false-positive review on one name can sometimes be closed in one business day. A corporate customer with foreign layers and a source-of-wealth question takes from 10 business days, and complex multi-country structures up to about a month. Urgent files cost 50% more, and if we miss the agreed date, the fee goes down.
Files open with the answer to the trigger, then identity, ownership, PEP status, source of wealth, adverse media and open questions for the customer. Customers that stay high risk after onboarding can be watched on our analyst-reviewed platform, which updates hourly, through OSINT monitoring. Crypto-asset exposure is handled with crypto investigations, one of the OSINT services for regulated firms we run as one team.
Focused versions of kyc and aml for specific subjects, deals and situations.
Declared wealth tested against registries, filings, property records and media, with a timeline and the gaps your MLRO should ask about.
Read more →Screening alerts reviewed by analysts: false positives cleared, PEP relatives and associates found, adverse media graded for relevance and credibility.
Read more →Hidden sanctioned owners, 50 Percent Rule tests, intermediaries, transshipment and shipping red flags researched for compliance and legal teams.
Read more →Share the trigger, the customer type, the countries involved and your deadline. We reply with a scope, a delivery date and a fixed quote.
Usually yes. We compare the listed person's published identifiers with the director's date of birth, nationality, addresses, roles and photos from registries, filings and media, then confirm or clear the match with the evidence set out. A single-name review like this can sometimes be done in one business day; if identifiers are thin, we say so rather than force a conclusion.
We look for the business in company registers and filings, the sale in transaction announcements, trade press and later ownership records, and her role in it over time. We then compare the timing and scale with property holdings and other assets in public registers. The result shows whether her account is consistent with the record, and lists the documents you should still request from her.
Method and audit trail. A defensible file names each source, dates it, keeps a capture and separates verified facts from allegations. Matches rest on several independent identifiers, and each conclusion carries a confidence level. Random search results are not evidence; dated registry extracts, court records and graded media are.
It depends on the profile. A retired person or a small local trader often has little online presence. A director who claims to run an international e-commerce business and leaves no trace in registries, trade data or professional sources is a different matter. We check whether the absence is plausible, and whether the identity details link to other companies or reused addresses.
Not automatically. US agencies have said not all PEPs are higher risk and that a risk-based approach applies. UK firms are different: regulation 33 lists every PEP among the cases needing enhanced due diligence. Either way, the role, the country, the business and any adverse findings set the depth, and a light OSINT check on role and media shows whether more is warranted.
Neither. We report findings only to you. Your firm decides whether the facts amount to suspicion and whether to file a report, under your own legal obligations. We never contact the customer or their associates, which also protects you from tipping-off risk.
Yes. We agree a standard file format and fixed quotes per case type, for example a match review, a corporate ownership file and a full enhanced due diligence file with source of wealth. Each case gets a delivery date at intake, and a monthly review of the flow keeps scope in line with what files actually need.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.