# Know Your Business When an AI Agent Runs the Company Checks

> Markdown mirror for AI agents, generated 2026-09-07 from the live page.
> Canonical: https://agenticrail.nz/spec/know-your-business/
> Site context: https://agenticrail.nz/llms.txt

**Document type** Controls Note — Evidence Brief

**Subject** Business verification — company search, registration, directors, persons with significant control and beneficial ownership — where an autonomous agent performs the register lookups and also records that it performed them

**Published by** TUARA KURI LIMITED — trading as AgenticRail, Hokianga, Aotearoa New Zealand

**Date** 2026-09-07

**Version** 1.0

**Status** Published — open for citation

**Related** [Customer due diligence](https://agenticrail.nz/spec/customer-due-diligence/) · [Segregation of duties](https://agenticrail.nz/spec/segregation-of-duties/) · [Completeness specification](https://agenticrail.nz/spec/completeness/)

# Know Your Business When an AI Agent Runs the Company Checks

Know your business is not a principle. It is a list. The regulation names the items: the company's name, its registration number, its registered office and principal place of business, the law it is subject to, its constitution, the full names of its directors, the ownership and control structure, and the beneficial owner behind it. Every one of those is a lookup, and an autonomous agent can run all of them in any order it likes. **The regulation also says when they have to happen, and that is the part an agent cannot report on itself.** This note sets out the enumerated checklist, the timing rule that sits over it, and what a refused step has to leave behind to count as evidence that the list was worked in the required order.

## 1. Scope

This note concerns **business verification**: due diligence on a company rather than on a natural person. It is commonly called KYB, know your business, and sometimes corporate KYC, entity verification or business verification. The work consists of querying a companies register and the records attached to it.

The same lookups are run in two different situations that people usually keep apart: **onboarding a corporate customer**, and **third-party due diligence** — vetting a supplier, vendor, contractor, intermediary or agent before engaging them or paying them. The checks do not change between those cases. The company register does not know or care what the company is to you. Whether the resulting duty is a money-laundering duty, a sanctions duty, an anti-bribery duty or a plain contractual one depends on the relationship, but the sequence of lookups is the same sequence, and so is the evidence problem — because the evidence problem is about ordering, not about which rule the ordering serves.

The operative wording throughout is taken from the **United Kingdom** instruments, because that is where the enumerated list and the timing rule are both written down plainly and can be read by anyone. Equivalent obligations exist in other jurisdictions and differ in detail. Naming a duty is not a claim that this product satisfies it.

## 2. The Checklist Is Enumerated, Not Implied

Regulation 28 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 sets out what customer due diligence measures consist of. Where the customer is a company, **the regulation lists the items** rather than leaving them to judgement.

Regulation 28(3) provides that where the customer is a body corporate, the relevant person *must obtain and verify*:

- the name of the body corporate;
- its company number or other registration number;
- the address of its registered office, and if different, its principal place of business;

and *must take reasonable measures to determine and verify*:

- the law to which the body corporate is subject, and its constitution, whether set out in its articles of association or other governing documents;
- the full names of the board of directors, or if there is no board, the members of the equivalent management body, and the senior persons responsible for the operations of the body corporate.

Regulation 28(3A) adds that where the customer is a legal person, trust, company, foundation or similar arrangement, the relevant person must take reasonable measures to *understand the ownership and control structure*. Regulation 28(4) requires the relevant person to identify the beneficial owner and take reasonable measures to verify their identity *so that the relevant person is satisfied that it knows who the beneficial owner is*.

**Two qualifications, because the list is narrower than a summary of it would suggest.** Regulation 28(5) provides that paragraphs (3)(b), (3A) and (4) *do not apply where the customer is a company which is listed on a regulated market*. And where the relevant person has exhausted all possible means of identifying the beneficial owner of a body corporate and either has not succeeded or is not satisfied that the individual identified is in fact the beneficial owner, regulation 28(6) and (7) permit it to treat the senior person responsible for managing the body corporate as the beneficial owner — on condition, under (8), that it keeps written records of all the actions it took. **Note what that condition is: a record of a search that did not find what it was looking for.** The obligation survives the failure and attaches to the attempt.

In the United Kingdom the statutory answer to the control question is the **register of people with significant control**, created by Part 21A of the Companies Act 2006. Section 790C(2) defines a person with significant control as an individual meeting one or more of the specified conditions in Part 1 of Schedule 1A.

This matters for a reason that has nothing to do with AI: **an enumerated list is auditable in a way a principle is not.** A supervisor does not have to argue about whether enough was done. The items are named, and either the record shows each one or it does not.

## 3. The Timing Rule Sits Over the Whole List

Regulation 30 is titled *Timing of verification*. Paragraph (2) provides that a relevant person must comply with the requirement to verify the identity of the customer, any person purporting to act on behalf of the customer and any beneficial owner of the customer **before the establishment of a business relationship or the carrying out of the transaction**.

That rule is expressed as subject to paragraphs (3) and (4), and there are therefore two exceptions, not one.

Paragraph (3) permits verification to be completed *during* establishment, provided that it is completed as soon as practicable after contact is first established, that this is necessary not to interrupt the normal conduct of business, and that there is little risk of money laundering and terrorist financing.

Paragraph (4) permits a credit institution or financial institution to verify a customer opening an account *after* the account has been opened — but only **“provided that there are adequate safeguards in place to ensure that no transactions are carried out by or on behalf of the customer before verification has been completed”**.

Read that second exception closely, because it is the clearest statement in the instrument of what is actually being asked for. The permission is not to skip the check. **The permission is conditional on being able to establish a negative fact about ordering** — that nothing happened in the interval. A record of the transactions that did occur cannot demonstrate the absence of one that did not. Paragraph (3) has the same shape in softer form: relying on it means being able to say what had and had not happened at the point the relationship was established.

Neither exception is a relaxation of the list. Both are narrow permissions whose conditions are themselves assertions about sequence, made after the fact, about a process that has already run.

So the obligation has two parts and they fail differently. The list can be evidenced by outputs: here is the registration number we obtained, here are the directors we found. **The ordering cannot.** An output does not carry the time it was produced relative to a decision made elsewhere in the system.

## 4. The Failure Shape — the agent runs the lookups and writes the record

An autonomous agent doing KYB will typically hold tools that map closely onto the enumerated list: a company search, a company profile fetch, an officers and PSC query, an insolvency or sanctions screen, a jurisdiction lookup. It selects which to call and in what order, receives the results, and produces a summary of what it did.

Three properties of that arrangement are worth stating plainly.

**The agent chooses the order.** Nothing in a tool-calling loop obliges it to run the beneficial ownership query before it recommends onboarding. It may. It usually will. Nothing in the record distinguishes the run where it did from the run where it did not.

**A skipped step writes nothing.** This is the property that makes an audit log the wrong shape of evidence for this obligation. A log reports what it contains. There is no entry for the query that was never issued, and no entry recording that no entry was made. A run with six lookups and a run with four look like two runs, one of which needed less work.

**The agent writes the account of its own process.** The summary saying *company verified, directors checked, PSC clear* is generated by the same system whose ordering is in question. It is a claim about a sequence, produced by the party that chose the sequence.

None of this asserts that agents are unreliable. The problem is structural and would exist if the agent were perfect: **a correct run and an incorrect run produce records of the same shape, so the record cannot be used to tell them apart.**

## 5. What Has To Be True For the Record To Answer the Question

Four properties, and the fourth is the one usually missing.

- **Coverage.** Every item on the enumerated list appears, or its absence is itself recorded.
- **Ordering.** The record establishes the sequence, not merely the set.
- **Non-bypassability.** A step taken out of order fails rather than proceeding, so that compliance is a property of the run rather than of the reporting afterwards.
- **Independence of the record.** The account of what happened is not written by the party whose conduct is in question.

A conventional audit trail supplies the first and part of the second, and cannot supply the third or the fourth at all. That is not a criticism of logging. It is what logging is: a description of events, written by the system that had them.

## 6. Who Already Owes This Duty

Regulation 8(1) applies the obligations to persons *acting in the course of business carried on by them in the United Kingdom* who are listed in regulation 8(2) and who do not fall within the exclusions in regulation 15. The regulation 8(2) list is: credit institutions; financial institutions; auditors, insolvency practitioners, external accountants and tax advisers; independent legal professionals; trust or company service providers; estate agents and letting agents; high value dealers; casinos; art market participants; cryptoasset exchange providers; and custodian wallet providers.

That population already runs company searches, already pulls officers and PSC records, and already has to be able to say when it did so. **The duty is not created by automating the work. Automating it changes what evidence exists that the duty was discharged.**

The same lookups performed on a supplier or a contractor sit under different obligations again — sanctions exposure, anti-bribery expectations, and the ordinary contractual duty to know who you have engaged. The evidence problem is identical, because the evidence problem is about ordering, not about which rule the ordering serves.

## 7. The Instrument, and a Test Anyone Can Run

AgenticRail is a hosted enforcement gate. A caller declares its step order in advance, and each step is submitted to the gate before it runs. A step presented out of the declared order is refused, and the refusal is signed and chained exactly as an allowed step is. **The result is that an omission becomes an artifact rather than a silence.**

A KYB sequence declared to the gate might look like this:

```
company_search → company_profile → jurisdiction_check → officers_psc → screen_sanctions → record_result
```

An attempt to run `record_result` before `officers_psc` does not proceed. It returns a denial naming the step that was expected instead, and that denial is written into the chain. Anyone holding the resulting report can see both what ran and what was refused, in order, and can verify each receipt offline against published Ed25519 keys without contacting us.

The demo lane is open and needs no key. **Use your own sequence identifier** — the demo lane is shared, sealing is permanent, and a fixed identifier copied from a page is an identifier every other reader is also using.

```
curl -s https://api.agenticrail.nz/v1/evaluate \
 -H 'content-type: application/json' \
 -d '{
 "sequence_id": "kyb-CHANGE-THIS-TO-YOUR-OWN",
 "step": "company_search",
 "function": "company_search",
 "action_type": "VALIDATE_INPUT",
 "step_order": ["company_search","company_profile","jurisdiction_check",
 "officers_psc","screen_sanctions","record_result"],
 "nonce": "REPLACE-WITH-A-UUID",
 "ts_ms": 0
 }'
```

Then submit `record_result` out of order and read what comes back. The report for any `demo-` sequence can be fetched with no key at [report.agenticrail.nz/report](https://report.agenticrail.nz/report).

## 8. A Deliberate Boundary — what this does not do

Stated in full rather than summarised, because a control note that overstates its instrument is worse than none.

- **It performs no checks.** AgenticRail holds no company register, no PSC or officers data, no beneficial ownership data, and no sanctions, insolvency or exclusions lists. It runs no lookup of any kind and has no view of whether a search returned the right company.
- **It does not determine who a beneficial owner is.** That is a finding made by the caller, from sources the caller chose. The gate records that a step named for it ran at a particular point in a declared order.
- **It enforces order, not correctness within a step.** A step that ran in the right position but returned a wrong answer is an allowed step with a signed receipt.
- **It enforces the order you declared, and has no opinion on whether that order is the right one.** A declared sequence that omits a check the regulation requires will be enforced exactly as declared. Choosing the order is the caller's judgement and remains the caller's responsibility; the gate holds the caller to it and evidences which order ran.
- **It returns a verdict; it does not execute anything and cannot physically stop your code.** The gate is called before a step runs and answers ALLOW or DENY. A caller that proceeds after a DENY has not defeated the record — the signed denial stands, and stands against it — but the gate did not prevent the action and does not claim to.
- **It enforces one agent's declared sequence, not handovers between several agents.** The published receipt schema v3 names multi-agent failure classes and the surfaces that would emit them are specified and not deployed. Nothing here should be read as evidence that they are.
- **It is hosted only.** There is no self-hosted or air-gapped distribution.
- **The timestamp is signed but self-asserted.** The caller supplies `ts_ms`; the signature means it cannot be altered afterwards without breaking verification, not that the time is true. It is bounded by a 300 second freshness rule against the gate's own clock. RFC 3161 timestamping is the known remedy and is not built.
- **Demo lane receipts are world-readable and are deleted after thirty days.** Anything placed in `attestation` on a demo sequence can be read by anyone, and its report needs no key. Record-keeping obligations under these Regulations run to years. The demo lane is for evaluation, not for evidence you intend to rely on, and retention for any other lane is a matter for the service terms rather than anything implied by this page.
- **No certification is claimed.** AgenticRail holds no SOC 2, no ISO 27001 and no ISO 42001. Nothing on this page asserts that using it satisfies any regulatory obligation, and naming a duty here is not a claim to discharge it.
- **The signing keys are held by the operator, and the second copy is also ours.** The gate is independent of the agent, which can neither instruct it nor edit its output. It is *not* independent of AgenticRail. Receipts of a sealed sequence are copied to a separate write-once store, which narrows the tamper surface, but that store is operated by us and is not an independent custodian — no such custodian is engaged today. Independent custody is a deployment term, not something this page claims. Stated because a limit disclosed is worth more than a limit discovered.

## 9. References

- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, [regulation 28](https://www.legislation.gov.uk/uksi/2017/692/regulation/28) — customer due diligence measures, including the enumerated body corporate items at (3), the ownership and control structure at (3A) and the beneficial owner at (4).
- The same Regulations, [regulation 30](https://www.legislation.gov.uk/uksi/2017/692/regulation/30) — timing of verification, the before-the-relationship rule at (2) and the narrow exception at (3).
- The same Regulations, [regulation 8](https://www.legislation.gov.uk/uksi/2017/692/regulation/8) — the relevant persons to whom the obligations apply.
- Companies Act 2006, [section 790C](https://www.legislation.gov.uk/ukpga/2006/46/section/790C) and Part 21A — people with significant control, with the specified conditions at Schedule 1A Part 1.
- [Customer due diligence when an AI agent runs the checks](https://agenticrail.nz/spec/customer-due-diligence/) — the same evidence problem where the customer is a natural person.
- [Segregation of duties](https://agenticrail.nz/spec/segregation-of-duties/) — why the party doing the work cannot be the party certifying it was permitted.
- [Integration documentation](https://agenticrail.nz/docs/) and the [product specification](https://agenticrail.nz/product/).

Every clause quoted or paraphrased above was read from the instrument at legislation.gov.uk and is linked so it can be checked. Where wording is quoted it is marked as such; where it is compressed, the citation points at the provision so the reader can see what was left out.
