Proving the person applying can act for the business
Registration numbers are public, so anyone can type a real company's number. To know the applicant represents the business, verify who they are, check them against the officers the register names, and, where they are not named, ask for evidence of their authority.

Charles Archibong, Co-founder
· 5 min read

Key takeaways
- A registration number is public information; typing a real one proves nothing about the person typing it.
- FATF asks institutions to verify that anyone acting for a customer is authorised, and to verify their identity.
- Check the applicant's verified identity against the officers the register names.
- An applicant who is not a named officer needs authority evidence and a human decision, not an automatic decline.
A valid registration number is not proof that the applicant represents the company because registration numbers are public. They are printed on invoices, websites and letterheads, and anyone can look them up. A registry lookup confirms the company exists; it says nothing about the person who typed the number into your form.
To know the applicant can act for the business, you need three separate answers: who the applicant is (an identity check on them as a person), whether the register names them as an officer, and, if it does not, what authorises them to act. The fraud this article is about lives in the gap between the first answer and the other two.
What does the standard actually ask for?
The FATF Recommendations are specific on this point. When carrying out due diligence, "financial institutions should also be required to verify that any person purporting to act on behalf of the customer is so authorised, and should identify and verify the identity of that person" (FATF Recommendations, updated October 2025 (opens in a new tab), Interpretive Note to Recommendation 10, paragraph 4).
That is two obligations, not one: identify the person, and establish their authority. National rules add their own detail. In the United States, for example, FinCEN's customer due diligence rule requires a covered institution to identify a single individual with significant responsibility to control, manage or direct a legal entity customer, such as a chief executive or other senior officer (31 CFR 1010.230(d)(2) (opens in a new tab)). Requirements differ by jurisdiction, and this article is general information, not legal advice.
How does a real registration number get misused?
Three patterns come up repeatedly for platforms that onboard businesses online:
Borrowing an established company. Someone opens a payment or credit account in the name of a real, well-filed company they have no connection with. The lookup matches, the company looks healthy, and the money flows to accounts the company never controlled.
The departed insider. A former director or employee still knows the company's details and applies after leaving. The register may even still name them if the change was never filed.
The front person. The applicant is real and the company is real, but the applicant is acting for someone who does not want to appear anywhere. This one is about ownership as much as authority, and the key-people work covers it.
In each case, a flow that verifies only the company approves the application.
Three questions to ask about every applicant
Who is this person?
Run a normal individual identity check on the applicant: document or government database verification, a selfie and liveness. Without it, everything that follows compares the register against a name someone typed.
Does the register name them?
Compare the verified identity with the directors, secretaries and other officers the register returns. Compare the verified name, not the typed one. Name matching on registry data needs tolerance for middle names, initials and ordering, and a human should see the borderline cases.
If not, what authorises them?
Plenty of legitimate applicants are not named officers: a finance manager, an operations lead, an accountant instructed by the board. For them, ask for evidence of authority appropriate to your risk, such as a board resolution, a letter of authority signed by a named director, or a power of attorney, and have a person review it. Requiring the named director's own identity check is often the simplest evidence of all.
A decision table
Applicant's identity check | Named by the register? | Authority evidence | Reasonable outcome |
|---|---|---|---|
Passed | Yes, as a director | Not needed | Proceed to ownership and screening checks |
Passed | No | Resolution or letter signed by a named director who has also verified | Review, likely approve |
Passed | No | None provided | Hold and request evidence; do not auto-approve |
Passed | Named, but the register looks out of date | Not needed | Review; confirm current officers |
Failed or abandoned | Any | Any | Do not approve |
Note what the table does not do: it does not decline an honest finance manager automatically. An automatic decline for "not a named officer" pushes legitimate businesses to send their director through the flow for a task the director delegates, and some of them will leave instead.
An illustrative case: the sole trader in Kano
A lender offers working capital to small traders. An applicant in Kano enters a business name registration number, and the lookup returns a valid, active business name registered to one proprietor. The applicant passes their own identity check. Their verified name does not match the proprietor's.
The applicant explains that the business belongs to their older brother, who travels, and that they run the shop day to day. That may well be true. It still means the person asking for credit is not the person the register says owns the business. The reasonable response is to ask the named proprietor to verify their own identity and confirm the arrangement, rather than to approve on the applicant's word or reject a probably genuine family business outright.
How Myaza Trust supports applicant checks
A KYB workflow in Business Verification can include applicant verification: the person filling in the form completes their own identity check inside the same flow, declares their role, and is checked against the officers the register names. The same workflow can require named directors or beneficial owners to complete their own identity checks through personal invite links, and the decision can wait until those checks finish. Company documents such as the certificate of incorporation can be collected and cross-checked against the registry record.
If you already verify the submitter in your own onboarding before they reach the KYB step, you can leave applicant verification off, but make sure that check is recorded against the business. The business verification documentation describes the application layers, and fraud prevention covers related signals such as device reuse across applications.
Checklist before you approve a business
The applicant passed an individual identity check.
Their verified identity was compared with the officers on the register.
If they are not a named officer, you hold authority evidence and a person reviewed it.
If the register's officer list looks stale, you confirmed the current officers.
The approval waits for these results rather than for the registry lookup alone.
Sources

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


