Cross-boundary KYC/KYB often requires banks to verify corporate identities, trace complex ownership structures, identify ultimate beneficial owners, conduct compliance screening, and document onboarding recommendations across fragmented systems and data sources. D&B MCP can connect these steps through an AI agent, while compliance teams retain responsibility for reviewing findings and making final decisions.
What Did a Traditional Cross-Boundary KYC/KYB Process Involve?
Before introducing an MCP-enabled workflow, a team may typically need to complete the following tasks during a cross-boundary corporate customer KYC/KYB review:
Collect customer-submitted documents: These included the business license, articles of association, shareholder register, and management list. The completeness of the information depended on the customer’s level of cooperation.
Search external data sources: Corporate registration information and ownership relationships were often dispersed across different platforms, while companies incorporated outside the relevant jurisdiction sometimes required verification through additional channels.
Manually compare customer-submitted information with external data: The team checked each item reported by the customer against information obtained externally. Any inconsistency or missing information required a manual decision on how it should be handled.
Map the complete ownership chain: Cross-boundary companies often had multi-layered holding structures. Analysts had to review corporate annual reports and shareholder registers layer by layer and prepare a complete ownership structure diagram, with the workload increasing significantly for deeper structures.
Conduct compliance risk screening: The team separately checked United Nations, OFAC, and European Union sanctions lists, as well as the terrorist list issued by the Ministry of Public Security of the People’s Republic of China, PEP information, and other risk information. Fuzzy matches, such as variations in name spelling, still required human judgement.
Form a compliance opinion with reference to regulatory requirements: With reference to requirements such as the Anti-Money Laundering Law of the People’s Republic of China, the Measures for the Administration of Customer Due Diligence and the Preservation of Customer Identity Information and Transaction Records by Financial Institutions (Order No. 11 [2025] of the People’s Bank of China, the National Financial Regulatory Administration, and the China Securities Regulatory Commission), and the FATF Recommendations, the team prepared an initial onboarding recommendation and proposed risk rating for compliance review.
Compile and retain records: Due diligence conclusions, verification evidence, and supplementary verification items had to be documented in full to support subsequent audit traceability and regulatory reporting.
How Does D&B MCP Connect Corporate Data with AI Agents?
Built on the standard Model Context Protocol, D&B MCP makes corporate information, ownership structure, management information, and other data capabilities available to AI agents. Compliance professionals can describe the task in natural language. The agent can then call the relevant data capabilities according to a predefined workflow, pass context between tools, and connect corporate searches, presentation of customer-submitted information, cross-verification, compliance risk screening, and preparation of an initial onboarding recommendation. Key calls are recorded to support subsequent review and traceability.
A Six-Step Cross-Boundary KYC/KYB Workflow
Match the Corporate Entity and Map Its Ownership Structure
After receiving the company's basic information, the system confirms the target entity and retrieves its registration details, management list, and ownership chain in one workflow, reducing repeated searches across systems.
An anonymized ownership map tracing five layers to the global ultimate parent and identifying two UBOs and one indirect beneficial ownership interest.
Use Customer-Submitted KYC/KYB Information as the Verification Baseline
The system uses the customer's onboarding information and supporting documents as the starting point for verification. These include registration details, management and shareholder information, and the UBO declaration.
An anonymized view of customer-submitted onboarding information and supporting documents.
Cross-Verify Customer Information and Recommend Follow-Up Actions
The system compares the information provided by the customer with D&B's independent data. It confirms matching details and explains any inconsistencies, together with suggested verification steps. It also flags missing information, such as UBO, management, or financial data, and provides additional insights on areas including corporate family structure and credit rating.

An anonymized comparison table highlighting matches, differences, missing disclosures, and recommended actions.For each inconsistency or undisclosed item, the system can suggest an appropriate follow-up action, such as using the registration date shown on the business license or requesting confirmation and identity verification from the customer. This helps teams apply a more consistent verification approach without determining every next step from scratch.
Identify Entities and Individuals for AML/CFT and Sanctions Screening
Using customer submissions and D&B data, the system identifies all parties requiring AML/CFT and sanctions screening: the company, parent company, shareholders at each level, management, and UBOs.
An anonymized list of entities and individuals identified for AML/CFT and sanctions screening.These parties are screened together against United Nations, OFAC SDN, and European Union sanctions lists, the terrorist list issued by the Ministry of Public Security of the People’s Republic of China, PEP information, and high-risk countries and regions. The system handles initial matching and risk flags; compliance professionals make the final determination.
Support Human Review of Potential Watchlist Matches
The system compares the screening subject with the watchlist record field by field, showing a similarity score and specific differences. It provides structured, explainable evidence, while final authority remains with compliance professionals.
An anonymized side-by-side comparison showing similarity and difference indicators for a potential watchlist match.Generate an Initial KYC Summary and Onboarding Recommendation
Using the verification and screening results, the system applies predefined rules to draft a structured onboarding recommendation covering risk rating, CDD or EDD approach, account type, ongoing monitoring cycle, regulatory basis, and supplementary verification items for review and recordkeeping.

An anonymized initial KYC summary and onboarding recommendation based on the verification and screening results.
How Does D&B MCP Link KYC/KYB Findings to Regulatory Requirements?
The system can link specific verification findings with relevant regulatory requirements and prepare a structured draft compliance opinion for review. For example:
Risk rating and due diligence approach: For a low to medium risk customer, the draft can explain the assessment based on factors such as its cross-boundary profile and indirect beneficial ownership. It can also reference the relevant requirements, including the Measures for the Administration of Customer Due Diligence and the Preservation of Customer Identity Information and Transaction Records by Financial Institutions (Order No. 11 [2025]), to support the proposed CDD or EDD approach. The compliance team makes the final decision.
Potential AML/CFT matches: The system can flag applicable suspicious transaction reporting and internal handling requirements. Where human analysis confirms a suspicious transaction, it can prompt timely reporting under the applicable rules, no later than five working days; cases involving designated terrorist organizations or individuals are handled under the relevant requirements. Applicable sanctions obligations, including OFAC requirements, can also be highlighted.
Complex cross-boundary ownership: FATF Recommendations 10, 12, 24, and 25 can be referenced to support ownership verification, PEP assessment, transparency and beneficial ownership checks, and the proposed ongoing monitoring cycle.
Forward-looking EU requirements: The same logic can incorporate the EU AML Package, including the AMLR’s 25% ownership-interest threshold and the need to consider control exercised through other means. Lower thresholds may later apply to certain high-risk legal entities. As the AMLR will mainly apply from 2027, it is currently more relevant to rule configuration and forward planning; actual application depends on jurisdiction, effective dates, and the institution’s internal policies.
How Does the D&B MCP-Enabled KYC/KYB Workflow Connect End to End?
Customer information becomes the verification baseline: Submitted information flows directly into cross-verification without manual re-entry.
Verification findings trigger follow-up actions: Differences and missing disclosures are paired with suggested verification steps.
Ownership findings feed into screening: Identified corporate shareholders and individual UBOs move directly into AML/CFT screening.
Screening decisions inform the recommendation: Human decisions on potential matches influence the customer’s risk rating and onboarding recommendation.
Regulatory rationale is connected: The draft compliance opinion links findings to relevant requirements and supplementary verification items.
Recorded calls support ongoing review: Institutions can support audit review and schedule periodic ownership and risk-screening checks.
If your institution is exploring ways to improve cross-boundary KYC/KYB workflows, learn more about our integrated solutions for Financial Institutions: https://www.dnb.com.hk/solution/financial-institution-solutions
Find out more D&B's MCP-enabled data capabilities: https://www.dnb.com.hk/products-services/products/data-blocks