Purpose of This Template
This template provides a structured due diligence script for your account opening team when a business applicant's state registration shows recent changes to its registered agent, formation documents, or ownership structure. It's designed to catch fraudsters who exploit state filing processes to create authentic-looking documentation for fraudulent accounts.
The script addresses a specific vulnerability: in most states, anyone can modify a business's registered agent using only publicly available information. The National Association of Secretaries of State confirms that state filing offices typically operate in a "ministerial" capacity with little authority to reject filings. Your account opening process is the control layer that state systems don't provide.
Prerequisites
Before implementing this template, ensure your institution has:
- Access to state business registry data with filing date visibility (not just current records)
- A defined timeline threshold for what constitutes "recent" changes (we recommend 90 days)
- Authority to request additional documentation from business account applicants
- A documented escalation path for suspicious patterns
- Integration capability between your account opening system and state registry lookups
You'll also need buy-in from your account opening team. Recent changes to business records are not inherently fraudulent, so this script requires judgment, not automatic rejection.
The Due Diligence Script
Trigger condition: Business registry shows registered agent change, entity formation, or ownership modification within 90 days of account application.
Step 1: Document the Timeline
- Record the date of the most recent state filing change.
- Record the account application date.
- Calculate the gap in days.
- If the gap is less than 7 days, escalate immediately to fraud review.
- If the gap is 7-90 days, proceed to Step 2.
Step 2: Verify the Applicant's Connection to the Business Ask the applicant:
- "I see your business recently updated its registered agent on [date]. Can you walk me through why that change was necessary?"
- "How long have you been involved with this business?"
- "What prompted you to open an account with us now?"
Listen for vague answers about "routine updates," inability to explain the business's operations, or claims of long-term involvement that contradict recent registry changes.
Step 3: Cross-reference the Registered Agent
- Pull the current registered agent name from state records.
- Compare it to the account applicant's name and provided identification.
- If the registered agent name doesn't match the applicant, ask: "Our records show [name] as the registered agent. What's your relationship to them?"
- Document the explanation.
Step 4: Request Corroborating Documentation For any account where Steps 1-3 raised questions, request at least two of the following:
- IRS Employer Identification Number (EIN) confirmation letter showing issue date
- Operating agreement or corporate bylaws with signatures
- Business license from local jurisdiction
- Utility bill or lease agreement in the business name
- Prior bank statements from another institution (showing account age)
Step 5: Check for Deposit Pressure During the application conversation, note whether the applicant:
- Mentions an incoming payment or check that needs to clear urgently
- Asks about deposit limits or hold policies before the account is approved
- Volunteers that they have a large check to deposit "today" or "this week"
If yes to any of the above, escalate to fraud review before approval.
Step 6: Document and Decide Record your findings in the account opening notes:
- Timeline gap: [X] days
- Applicant explanation: [summary]
- Corroborating documents received: [list]
- Deposit pressure observed: [yes/no]
- Decision: [Approve / Approve with enhanced monitoring / Decline / Escalate]
For approvals with recent registry changes, flag the account for enhanced monitoring of the first three deposits.
Customizing the Template
Adjust the 90-day Threshold based on your risk appetite and customer friction tolerance. Consider:
- 30 days for high-risk business types (check-cashing services, money services businesses)
- 60 days for standard business accounts
- 90 days for accounts requesting immediate large deposit capabilities
Modify the Corroborating Document List to match your existing KYC requirements. Don't duplicate requests. If you already collect EIN letters, focus on documents that establish the timeline of the applicant's involvement with the business.
Integrate State-specific Registry Access. New Jersey's free business search doesn't show modification dates, forcing you to request filing history separately. If your institution operates in multiple states, document which registries provide timeline data and which require manual follow-up.
Define "Deposit Pressure" for Your Team. Not every mention of an incoming payment is suspicious. Calibrate your team's judgment by reviewing past fraud cases where the fraudster mentioned deposits during account opening.
Validation Steps
After implementing this script, track these metrics monthly:
Coverage: What percentage of business account applications triggered the recent-change flag? If it's below 5%, your state registry integration may not be capturing all modification types.
False Positive Rate: Of the accounts that triggered enhanced review, how many were approved and operated normally for 90 days? If this exceeds 80%, consider tightening your threshold or improving interviewer training.
Catch Rate: How many accounts flagged by this process were later confirmed as fraudulent or closed due to suspicious activity within the first 30 days? This is your signal that the control is working.
Time to Decision: Measure the additional time this review adds to account opening. If it's adding more than 24 hours to standard applications, your corroborating document requests may be too broad.
Review the script quarterly with your fraud team. As state filing systems evolve and fraudsters adapt, your trigger conditions and interview questions should evolve too. The goal isn't to block every recent business registration; it's to force fraudsters who hijack legitimate businesses to either slow down or expose themselves through inconsistent explanations.



