State of M&A Data Rooms — Q2 2026 Read the report →

KYC Due Diligence (2026): The Beneficial-Ownership 25% Test + LP-Onboarding Pack

Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.

Last updated: August 2026

I'm Sean Yu, co-founder of Peony, a virtual data room company. Before Peony I spent my career on the deal side, and KYC is the part of a transaction that people underestimate until it stalls a close. Everyone plans for the financial and legal diligence — the earnings quality, the contracts, the reps. Almost nobody plans for the moment the fund administrator, the bank, or the buyer's counsel says "we can't proceed until the KYC file is complete," and suddenly a raise or a signing is waiting on a proof-of-address document from an investor who is traveling. KYC due diligence is the identity-and-integrity layer that sits underneath the commercial deal: not "is this business worth it," but "who exactly am I dealing with, who really owns and controls them, and is their money clean." It is a legal requirement for banks and, increasingly, for funds; and it is a document-collection problem that lands squarely on whoever is running the room.

The named test at the center of this post is the beneficial-ownership 25% rule. Under the FinCEN Customer Due Diligence Rule at 31 CFR 1010.230, you must identify every individual who owns 25% or more of a legal entity, plus one individual who controls it — which means the answer to "who is the beneficial owner" is anywhere from one to five real people, once you unwrap the holding companies and trusts to the humans behind them. That single rule is why KYC is never just "send me your company's name," and why the ownership chart is the artifact that most often holds up a deal. I run Peony, a data room used by 6,800+ customers, and this guide maps what KYC due diligence is, the four elements and the escalation to enhanced due diligence, the fast-moving 2026 regulatory map across the US, EU, and UK, and the part almost no one writes about honestly — how KYC actually works when you are the one onboarding investors into a fund or KYC-ing a counterparty in a deal — with the tooling framed for what it is: the collection and evidence layer, not the screening engine.

Quick answer: KYC due diligence is the anti-money-laundering identity review — verify who a customer or counterparty is, identify the individuals who beneficially own (25%+ equity) or control the entity, screen those people against sanctions and PEP lists, and establish source of funds. In the U.S. its substance is the FinCEN CDD Rule (31 CFR 1010.230): four elements — identify the customer, identify beneficial owners, understand the relationship, monitor ongoing. Standard CDD escalates to enhanced due diligence for PEPs, high-risk jurisdictions, and opaque structures. The 2026 map moved fast: the FinCEN investment-adviser AML rule is delayed to January 1, 2028; the CTA's government BOI registry was rolled back for U.S. companies (final rule effective Aug 14, 2026); the EU's AMLR applies 10 July 2027; and the UK's MLR amendment took effect 30 June 2026. For a fund, KYC is a per-investor document chase; the room is where you collect and evidence it, not where you screen.

Peony data room organized for KYC collection — per-investor folders holding IDs, proof of address, beneficial-ownership charts, and source-of-funds evidence behind NDA and watermark gates


Why is KYC due diligence different in 2026?

KYC due diligence is different in 2026 because the question of who has to run it is being reset on both sides of the Atlantic at once — the U.S. deferred one major expansion while rolling back a registry, and the EU and UK tightened their rules — so the regime you plan around depends heavily on where you and your investors sit and on the exact date.

Three moving pieces define the moment. First, in the United States, FinCEN's Investment Adviser AML Rule — finalized in 2024 to extend anti-money-laundering programs to many registered investment advisers and exempt reporting advisers — had its effective date pushed from January 1, 2026 to January 1, 2028 in a final rule that gives FinCEN time to tailor the requirements to different adviser business models. The obligation is deferred, not gone. Second, the Corporate Transparency Act's beneficial-ownership registry — the separate FinCEN filing that companies were briefly required to make — was rolled back for domestic entities: an interim final rule in March 2025 exempted U.S. companies, and Treasury announced a final rule, effective August 14, 2026, that permanently removes the BOI reporting requirement for U.S. companies and U.S. persons, leaving only certain foreign reporting companies in scope (and even those need not report U.S. persons as owners). Third, across the Atlantic, the EU AML package and a fresh UK amendment pulled in the opposite direction, harmonizing and tightening customer due diligence on 2026-2027 timelines.

Here is the distinction that trips people up, so I will state it plainly: the CTA registry rollback did not switch off KYC. The Corporate Transparency Act's BOI filing was a report to a government database. A financial institution's duty to collect beneficial ownership from its own customers under the CDD Rule (31 CFR 1010.230) is a different obligation, and it is unchanged — banks still identify the humans behind their legal-entity customers. So a founder who read that "BOI reporting is dead" and concluded their bank would stop asking for ownership information has conflated two separate things. The registry got smaller; the KYC obligation on regulated institutions did not.

The rest of this guide is the practitioner version: what KYC due diligence actually is, the four elements and the beneficial-ownership test, when it escalates, the full 2026 map with dates, and how the whole thing plays out when you are the one onboarding investors or KYC-ing a counterparty — because that is where the abstract rules become a document chase you have to run.

What is KYC due diligence, and how do CDD, EDD, and KYB fit together?

KYC due diligence is the umbrella term for verifying who you are dealing with for anti-money-laundering purposes, and underneath it sit three related terms that a lot of guides use loosely: CDD (customer due diligence) is the baseline process, EDD (enhanced due diligence) is the deeper version for higher-risk cases, and KYB (know your business) is CDD applied to an entity rather than a person.

Think of it as one process at three intensities and two subject types:

  • CDD — the baseline. For a normal-risk customer, you identify and verify them, identify the beneficial owners behind any entity, understand what the relationship is for, and monitor it over time. This is the default, defined in the U.S. by the FinCEN CDD Rule.
  • EDD — the escalation. For a higher-risk customer (a politically exposed person, a high-risk jurisdiction, an opaque structure), you do more: additional identification, corroborated source of funds and source of wealth, senior-management sign-off, and closer monitoring. EDD is not a different process; it is CDD turned up.
  • SDD — the relaxation. Where a regulator permits and the risk is demonstrably low, simplified due diligence allows lighter measures. It is the mirror image of EDD.
  • KYB — the entity case. When the customer is a company rather than a human, you run "know your business": confirm the entity legally exists and is in good standing, then unwrap its ownership and control to the natural persons and run KYC on each of them. KYB contains KYC — you have not finished KYB until you have KYC'd the beneficial owners it reveals.

The reason this matters for funds and deals is that you almost never face a lone individual. Your LP or your counterparty is usually an entity — a trust, an LLC, a fund-of-funds, a holding company — so the everyday reality is KYB: get the formation documents, build the ownership chart down to real people, and KYC those people. The single most common failure is stopping at the first level — recording "HoldCo owns 60%" and never pushing through HoldCo to the humans. The beneficial-ownership rule exists precisely to force that unwrap.

What are the four elements of customer due diligence and the beneficial-ownership test?

The FinCEN Customer Due Diligence Rule breaks KYC into four core elements, and they are the cleanest checklist for what a compliant program must contain. Per FinCEN's own framing of the rule:

  1. Customer identification and verification. Collect and verify the customer's identifying details — name, date of birth or formation, address, and an identifying number. For banks this was already the Customer Identification Program (CIP) requirement; the CDD Rule keeps it as element one.
  2. Beneficial ownership identification and verification. For a legal-entity customer, identify and verify the natural persons behind it under the 25% equity test and the control prong (below).
  3. Understanding the nature and purpose of the relationship. Enough to build a customer risk profile and know what normal looks like for that customer, so abnormal activity is visible.
  4. Ongoing monitoring. Risk-based procedures to monitor for suspicious activity and to keep customer information — including beneficial ownership — current.

The one that generates the most work is element two, the beneficial-ownership test in 31 CFR 1010.230. It has two prongs:

  • The equity prong captures each individual who directly or indirectly owns 25% or more of the entity's equity. Depending on the cap table, that is zero to four people — four owners at 25% each is the arithmetic maximum.
  • The control prong captures one individual with significant responsibility to control, manage, or direct the entity — a CEO, CFO, managing member, or general partner. Exactly one control person is always named, even for a widely-held entity with no 25% owner.

So the answer to "who is the beneficial owner" ranges from one (a widely-held entity: just the control person) to five (four 25%-owners plus a separate control person). The word indirectly is where the effort lives: you unwrap holding companies, trusts, and funds until you reach natural persons, and if a trust holds 25%+, the trustee is the beneficial owner. Getting the unwrap right — not just the top-level shareholder — is where most first-pass KYC errors are found and corrected.

CDD vs EDD: what triggers the escalation?

The escalation from standard CDD to enhanced due diligence is risk-based, not mechanical — you turn up the intensity when the customer, product, geography, or transaction pattern signals higher money-laundering or sanctions risk. This is the heart of the FATF risk-based approach built into Recommendation 10, and the common triggers are well established:

TriggerWhy it escalatesWhat EDD adds
Politically exposed person (PEP)Senior public officials, their family, and close associates carry heightened corruption/bribery risk (FATF Rec 12)Senior-management approval, source-of-wealth inquiry, closer ongoing monitoring
High-risk / sanctioned jurisdictionGeography raises exposure to sanctions and weak AML controlsAdditional verification, deeper transaction rationale
Opaque / multi-layered ownershipStructure obscures who is really behind the entityFull unwrap to natural persons, understand the rationale for the layers
Large / complex / structured transactionsNo clear economic purpose is a classic laundering signalCorroborate source of funds, document the purpose
High-risk sectorCash-intensive or certain money-services businessesHeightened scrutiny and monitoring frequency

EDD is not a separate workflow — it is CDD done deeper: more identification, independently corroborated source of funds and source of wealth, an understanding of why a structure exists, escalation to senior management, and more frequent monitoring. FATF's guidance is explicit that even PEP status is handled on a risk basis: a domestic or international-organization PEP assessed as low-risk does not automatically require the full EDD battery, though the classic conservative posture treats PEPs as high-risk by default.

For a fund manager, the everyday EDD case is concrete: an LP that is a PEP, a sovereign or state-linked investor, or an entity in a higher-risk jurisdiction. Those subscriptions need source-of-wealth corroboration and a senior sign-off, not just an ID and a formation document — and they are the files that take longest to clear, so flag them early in a raise rather than discovering the EDD requirement at the closing. The screening that identifies a PEP or a sanctions hit in the first place runs on dedicated screening platforms; the depth of that screening and the OFAC 50% rule are covered in our third-party due diligence guide, which owns the counterparty-and-sanctions lane.

What is the 2026 regulatory map for KYC?

The 2026 KYC map spans four regimes moving on different clocks, so here it is with the verified as-of dates — treat these as as of August 2026 and confirm the current position before relying on them, because this area has moved unusually fast.

  • US — FinCEN CDD Rule (in force). 31 CFR 1010.230 has required covered financial institutions to run the four-element CDD process, including collecting 25% beneficial ownership, since 2018. This is the durable baseline and it did not change in 2026.
  • US — Corporate Transparency Act BOI registry (rolled back). The CTA's separate government BOI filing was exempted for domestic companies by a March 2025 interim final rule, and Treasury announced a final rule, effective August 14, 2026, permanently removing BOI reporting for U.S. companies and U.S. persons; only certain foreign reporting companies remain in scope, and they need not report U.S. persons. This is a registry change — it does not switch off a bank's own CDD collection.
  • US — Investment Adviser AML Rule (delayed to 2028). The 2024 rule extending AML programs to many advisers had its effective date pushed to January 1, 2028 by final rule, with FinCEN reaffirming intent to bring a tailored version into force. Advisers are not yet under a standalone federal mandate, but the direction is clear.
  • EU — AML package (applies 10 July 2027). Regulation (EU) 2024/1624 (the AMLR) becomes directly applicable across all 27 member states on 10 July 2027, with the Sixth AML Directive (Directive (EU) 2024/1640, AMLD6) transposed by the same date. The AMLR confirms a 25%-or-more UBO threshold, aligned with the U.S. line. The new Anti-Money Laundering Authority (AMLA) in Frankfurt became operational on 1 July 2025.
  • UK — MLR 2017 amendment (in force 30 June 2026). The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621) were made 9 June 2026, with most provisions in force from 30 June 2026 — sharpening CDD expectations, adjusting thresholds to sterling, expanding trust registration, and adjusting the EDD triggers, with certain cryptoasset provisions phased in through 2027.
  • Global — FATF standards. Underneath all of the above, the FATF Recommendations set the international baseline: Recommendation 10 (CDD, interpretive note updated June 2025), Recommendation 12 (PEPs), and the risk-based approach that every regime implements.

The through-line: the mechanics are converging — verify the customer, unwrap ownership to 25% beneficial owners, screen for sanctions and PEPs, monitor on an ongoing basis — even as the filing details and thresholds differ by jurisdiction. A fund raising across the U.S. and EU can largely reuse one beneficial-ownership chart, because both use the 25% line.

How does KYC work in fundraising: the LP-onboarding pack?

This is the section almost no one writes about honestly, so it is worth the detail: when you raise a fund, you are the one running KYC — on your investors. Every LP that subscribes has to be onboarded with an identity-and-AML file, and while your fund administrator often owns the formal review, the collection lands on your team. The pack varies by domicile and administrator, but its shape is consistent across the market (Carta's fund-operations guidance describes the same core set).

For an individual LP, the pack is typically:

  • Government-issued photo ID
  • Proof of address (recent utility bill or bank statement)
  • Tax form — a W-9 for U.S. persons, or the relevant W-8 series for non-U.S. persons
  • Accredited-investor or qualified-purchaser evidence, where the offering requires it
  • Source-of-funds explanation — and for larger or higher-risk commitments, source-of-wealth support

For an entity LP — a trust, corporation, LLC, pension, fund-of-funds, or sovereign vehicle — add the KYB layer:

  • Formation documents (certificate of incorporation or formation, operating or partnership agreement)
  • Evidence of authority for the signatory
  • A beneficial-ownership chart unwrapping the entity to the natural persons who own 25%+ or control it
  • IDs and proof of address for those beneficial owners
  • Entity tax forms and the same source-of-funds/wealth support

The subscription agreement itself carries the investor representations — accreditation, AML, sanctions, ERISA status — and higher-risk investors (PEPs, state-linked entities, higher-risk jurisdictions) trigger the EDD deep-dive: source-of-wealth corroboration and senior sign-off.

Now the operational truth. This is a document chase across many investors at once, each at a different stage of completeness, and you cannot close an LP until their file is done. In practice that means one investor is missing a proof of address, another sent a W-8 when they needed a W-9, a third has not returned the beneficial-ownership chart, and you are tracking all of it while also negotiating side letters and chasing wires. Run on email, this is where sensitive personal data — passports, IDs, ownership charts — ends up scattered across inboxes with no record of who saw what. Run in a data room with per-investor file requests, it becomes a dashboard: each LP gets a private folder and a checklist, you see who is missing what at a glance, and the whole pack stays gated and audited. That is the specific problem the VC fund data room checklist and the seed-round data room guides build around — and it is the mirror image of LP operational due diligence, where the LP is the one running diligence on your operations.

How does KYC work in an M&A deal?

In an M&A deal, KYC runs on the counterparties — usually lighter than a bank's customer onboarding, and usually driven by the advisers and financing parties rather than a direct mandate on the principals, but present in almost every process. Several forces put it there:

  • Know your buyer. A seller wants to confirm the buyer is a legitimate, funded entity — not a sanctioned or straw party — before opening a data room and certainly before signing. Opening a room to an unverified acquirer is a basic hygiene failure.
  • Know the target's owners. A buyer, symmetrically, needs to confirm who really owns and controls the target — a beneficial-ownership question that overlaps directly with KYC and feeds the reps in the purchase agreement.
  • The advisers and lenders bring hard requirements. The investment bank, the escrow agent, and the lender are regulated or contractually obligated to KYC the parties they deal with, so their onboarding pulls beneficial-ownership charts, IDs, and source-of-funds into the process whether or not the principals would have asked.
  • Regulated targets add change-of-control KYC. Where the target is a bank, broker-dealer, or licensed operator, a change-of-control filing can require identifying the new ultimate beneficial owners to a regulator.

The practical output is that a deal room usually needs a KYC folder: entity formation documents, an ownership chart to natural persons, signatory authority, and the sanctions representations that live in the purchase agreement. In Peony, that folder sits behind the same NDA gate as the rest of diligence with per-party permissions, so the KYC evidence is in the room but only the parties who need it can see it. For the broader counterparty-and-sanctions-screening discipline — the exposure map, OFAC, the screening stack — see third-party due diligence; for the full deal sequence around it, the M&A due diligence process guide and financial due diligence.

What is ongoing monitoring and perpetual KYC?

KYC does not end at onboarding — ongoing monitoring is the fourth CDD element and a core part of the risk-based approach, and perpetual KYC (pKYC) is the modern, event-driven way of doing it. The obligation is to watch the relationship for activity inconsistent with the customer's risk profile, file suspicious-activity reports where required, and keep customer information — including beneficial ownership — current after the account is open.

The traditional model refreshes each customer on a periodic cycle keyed to risk — commonly annually for high-risk customers, every two to three years for medium risk, and less often for low risk, though there is no single universal interval and each firm sets its own risk-based schedule. Perpetual KYC replaces that calendar sweep with trigger-based updates: instead of re-reviewing everyone on a timer, the system re-checks a specific customer when something material changes — a new beneficial owner appears, a sanctions or PEP alert fires, an address or activity pattern shifts, or an ID expires (ComplyAdvantage describes the same event-driven model). It trades periodic bulk reviews for continuous, targeted ones.

For a fund or a deal team, the version is lighter than a bank's, but the principle holds: an LP's KYC file is not frozen at subscription. If a beneficial owner changes, an investor becomes a PEP, or the fund reopens for a new close, the file needs refreshing. The practical enabler is keeping the identity documents and the audit trail in one durable place rather than in the email thread that onboarded the investor two years ago — that is what turns a refresh into a quick update instead of a full re-collection.

What are the common KYC due diligence mistakes?

The recurring KYC failures are less about not knowing the rules and more about how the collection is run in practice. The ones I see most often:

  • Stopping the ownership unwrap at the first level. Recording "HoldCo owns 60%" and never pushing through to the natural persons behind HoldCo. The 25% test is about indirect ownership — the unwrap to real people is the whole point.
  • Confusing the CTA registry rollback with the end of KYC. As covered above, the U.S. BOI registry was rolled back for domestic companies, but a bank's own duty to collect beneficial ownership under the CDD Rule is unchanged. Two different obligations.
  • Discovering EDD at the closing. Not flagging PEPs, sovereign investors, or high-risk-jurisdiction LPs early, then scrambling for source-of-wealth corroboration and senior sign-off at the last minute. EDD files take longest — identify them first.
  • Collecting sensitive identity documents over email. Passports, IDs, and ownership charts scattered across inboxes with no record of who accessed them is both an operational mess and a data-protection exposure.
  • Treating a KYC platform and a data room as substitutes. They do different jobs — the platform verifies and screens; the room collects, gates, and evidences. Skipping either leaves a gap.
  • Letting the file go stale. Freezing KYC at onboarding and never refreshing when a beneficial owner changes or a fund reopens.
  • Assuming source of funds equals source of wealth. Source of funds is where this particular money came from; source of wealth is how the person accumulated their assets overall. Higher-risk cases need both.

How do you run KYC collection in the data room?

You run KYC collection in a data room by giving each investor or counterparty a private, permissioned space to submit their documents, gating the whole exchange behind an NDA, watermarking the sensitive personal files, and keeping an exportable audit trail — so the collection is organized, walled, and evidenced rather than scattered across email. Here is the workflow, and then the honest scope.

The workflow, in Peony:

  1. One room, per-party file requests. Create a room for the raise or deal and issue each LP or counterparty a checklist of exactly what they owe — ID, proof of address, W-8/W-9, beneficial-ownership chart, source-of-funds. Each party uploads into their own folder.
  2. Granular per-investor permissions. Wall each investor's identity documents off from every other investor, so one LP can never see another LP's passport. This is the feature that makes multi-party KYC collection safe.
  3. NDA gating. Gate the room behind a Simple NDA (Business plan) or Advanced NDA with countersigning (Data Room plan) so terms are accepted before anything opens.
  4. Dynamic watermarking. Stamp every page of a sensitive document with the viewer's identity, so a leaked ID is traceable.
  5. Audit trail. Keep an exportable record of who uploaded and viewed each file — the evidence your administrator, bank, and counsel will later ask for.

Now the honest segmentation, because this is where a lot of marketing overreaches. Peony is the collection and evidence layer, not a screening engine. The room gathers the documents, gates them, watermarks them, and logs the chain of access. It does not run sanctions, PEP, or adverse-media screening — that runs on a dedicated screening platform or through your fund administrator's onboarding stack, and you should use one. And a bank or fintech onboarding thousands of customers a month needs enterprise KYC-operations software — case management, automated re-screening, regulator reporting — which is a different product category entirely; a data room is the wrong tool for that job. Where Peony fits is the fund raise and the deal: collecting IDs and ownership charts from a defined set of investors or counterparties, keeping each party's documents walled and watermarked, and producing the audit trail. That runs on the Data Room plan at $52 per admin per month (billed annually; unlimited documents, rooms, and storage; dynamic watermarking; granular permissions; Advanced NDA countersigning), or the Business plan at $30 for lighter needs; viewers are always free, so onboarding 30 or 200 investors adds nothing to the bill, and the free plan ($0, 50 documents, no credit card) is enough to collect a first handful of files. Peony serves 6,800+ customers running exactly this kind of gated, multi-party collection — and across 334 M&A transactions on the Peony platform, the deals that move fastest are the ones where the KYC folder was populated early rather than assembled at the closing.

Sources