Know Your Business (KYB) has several steps: confirm the company exists, understand who controls it, screen it, assess its risk. The first step, confirming the company against an official register, is the one every other step depends on, and the one most often done by hand. For French and Spanish business customers, this page sets out exactly what a registry API can confirm, what it can't, and how to file each check so it holds up in an audit.
Facts as of 10 October 2026. Fuentio's API is opening soon; examples are real recorded answers.
Short answer: for the registry step of KYB, an API like Fuentio confirms, from the official register and with the source and check date, that a French or Spanish company exists, its exact legal name and form, its status, its registered office, its activity (France) and its officers' names and roles. It covers no beneficial owners, no sanctions screening and no risk judgement: those remain separate steps in your KYB process.
What you'll learn
- Where the registry step sits in KYB
- What it confirms for French and Spanish companies
- What it doesn't, and what covers those gaps
- How to automate it without losing auditability
- How to handle the cases that need a person
Where does the registry step sit in KYB?
A typical KYB flow for a business customer:
- Identify the company: get its official identifier and confirm it against the register.
- Understand who's behind it: officers, and the people who ultimately own or control it.
- Screen it: sanctions and other lists your obligations require.
- Assess risk and decide.
Step 1 is factual and repeatable: the same lookup for every customer. That makes it the right step to automate, as long as the answer carries its source. See what KYB is.
What does the registry step confirm?
| KYB question | France (Sirene and RNE) | Spain (BORME) |
|---|---|---|
| Does the company exist? | Yes, by SIREN | Yes, by registry sheet, for companies with an act since 6 October 2025 |
| Exact legal name | Yes | Yes |
| Legal form | Yes, with the ISO 20275 ELF code | Yes, from the name's suffix |
| Status | Active or ceased, with the date | Only from acts that define it (liquidation, extinction, closure); otherwise "unknown" |
| Registered office | Yes | When published in an act |
| Activity | NAF code with NACE equivalent | Not published (corporate purpose as text) |
| Officers | Names and roles | Names and roles from appointment acts |
| Source and check date | On every answer | On every answer, with BOE links |
The important column for compliance is the last row. A KYB file that says "verified" without a source and a date doesn't prove much; one that says "RENAULT, active according to INSEE Sirene via the State's company API, checked on 5 October 2026" does. See provenance on every answer.
What doesn't it confirm?
- Ownership and control. Who ultimately owns or controls the company is a separate KYB step, with its own sources and access rules. No annual accounts and no ratings either: register facts only.
- Sanctions and adverse media screening: separate lists, separate tools.
- That your contact represents the company: officers' names help, but authority to sign needs its own check. See who runs a French company.
- A risk opinion: Fuentio returns register facts, never a score.
Saying this clearly in your KYB policy keeps the registry step from being mistaken for the whole of KYB.
How do you automate it without losing auditability?
- Collect the identifier at onboarding: SIREN for France; for Spain, the exact legal name and province, then the registry sheet.
- Validate it before any call. Check digits catch typos for free.
- Look it up, and show the customer the legal name and address returned, so they confirm it's them.
- Apply simple rules: ceased, in liquidation or extinct goes to review; not found goes to review; everything else continues.
- Store the answer with its provenance: source,
last_verified_at,source_updated_at,stale, request ID. - Re-check at renewal and when events happen (failed payment, returned mail).
For the full pattern, see automating merchant onboarding with a register check.
French and Spanish specifics your KYB policy should mention
- France has two levels. The company (SIREN) and its sites (SIRET) each have a status. A closed site isn't a ceased company. Check the SIREN's status for KYB.
- France has non-public businesses. Individual entrepreneurs can opt out of publication; they're missing from public data, not necessarily from existence.
- Spain has no national status flag. Status comes from registered acts: dissolution, extinction, provisional closure. Without such an act, the honest status is "unknown".
- Spain is keyed on the registry sheet. The tax number (NIF) isn't in the BORME; collect the exact legal name and province, then the sheet.
- Spanish coverage is event-based. Our records hold companies with at least one act since 6 October 2025.
Writing these into your policy prevents the classic errors: rejecting a legitimate sole trader who isn't public, or accepting a Spanish company as "active" because nothing says otherwise. See is a Spanish company still active?.
What a good KYB registry record looks like
For one French business customer, the registry part of your KYB file can be this short:
| Item | Example |
|---|---|
| Identifier | SIREN 441 639 465 |
| Legal name and form | RENAULT, SA nationale à conseil d'administration (ELF 1NF1) |
| Status | Active, as of 2025-12-06 |
| Registered office | Boulogne-Billancourt, 92100 |
| Source | Annuaire des Entreprises (INSEE Sirene, INPI RNE), Licence Ouverte 2.0 |
| Checked | 5 October 2026, not stale |
| Decision | Continue to step 2 |
Seven lines, each traceable to the official source. That's what an auditor wants to see.
Which cases need a person?
- Not found: in France, the business may have opted out of publication; ask for its Sirene situation notice.
- Several candidates for a name: never let the system choose.
- Spanish "unknown" status: normal for an events source, but for a large exposure, order the registry's information note.
- A source outage (
stale: true): retry before deciding.
Routing these to a person isn't a weakness of automation; it's what makes the automated part defensible. See company checks in AML reviews.
Fuentio's API is opening soon. Become an early tester to run the registry step on your own French and Spanish customers before launch.
See what we cover in France and Spain.
Limits. Facts as of 10 October 2026. This page describes the registry step only; your KYB obligations depend on your activity and regulator. Fuentio returns register facts with their source; it doesn't make anyone compliant. Not legal advice.
Frequently asked questions
Is there a KYB API for French and Spanish companies?
For the registry step, yes: Fuentio confirms French and Spanish companies against official registers, with the source and check date on every answer.
Is a registry check enough for the whole of KYB?
No. It covers no beneficial owners and no sanctions screening; those are separate KYB steps with their own sources.
What should I store for a KYB audit?
The identifier, the facts you relied on in their original wording, the source, the check date, whether the answer was stale, and your decision.
Can KYB be fully automated?
The registry step can be, for clear cases. Not-found, ambiguous and stale answers should go to a person.
Sources
- API Recherche d'entreprises, documentation: recherche-entreprises.api.gouv.fr
- BOE, BORME daily gazette: boe.es
- INSEE, definition of the SIREN number: insee.fr
