Skip to main content

Know Your Artist (KYA): Checks to Reduce Streaming Fraud

By Gruv Editorial Team
Contributor
Updated on
•
21 min read
Layer KYA checks before access: Identity, Business proof, Sanctions, Payee match, Risk signals, and Manual review.

Quick Answer

Use KYA to connect the legal artist or label, authority over the catalog and the entitled payee before enabling distribution or payouts. Resolve conflicting evidence through a named review and correction process, apply sanctions requirements within their legal scope, and assess PEP risk separately. Continue monitoring after release: identity verification alone cannot stop artificial streams.

Why Music Platforms Use KYA#

Streaming fraud can distort royalty allocations, create payment disputes and expose a distributor to partner action. In a March 2026 guilty plea, DOJ described an operator using AI-generated songs and bot accounts to obtain more than $8 million in royalties. Identity checks can reduce impersonation and account abuse, but a verified person can still manipulate listening activity. Artist onboarding and post-release monitoring must work together.

Know Your Artist (KYA) is an industry term for checking who submits music, what authority they have to distribute it and who is entitled to receive payments. It adapts identity and risk controls to artist and label relationships; it is not a universal legal category. A platform should connect the legal person or entity, artist profile, authorized catalog and approved payee before enabling the relevant capability.

This guide offers an operating model for distributors and music platforms opening artist or label intake. Select controls for your business, markets and payment partners, and have counsel determine which legal duties apply to your role. Bank customer-identification rules, FATF standards and a payout provider’s onboarding requirements do not automatically become direct legal obligations for every music platform.

Before launch, define who can approve draft access, distribution and payouts, what evidence each permission requires and how unresolved cases reach a reviewer. Collecting a flag without a decision owner leaves the account in an ambiguous state. A rights dispute may affect one release, while a compromised payee affects payments; make the restriction fit the issue.

Spotify’s artificial-streaming guidance says detected artificial streams do not earn royalties and that flagrant activity can lead to charges to labels and distributors. The practical response is to verify applicants, review suspicious listening and connect partner adjustments to the affected release and royalty statement. An identity pass alone cannot establish genuine listener intent.

How to choose a KYA model before you expand#

If you are entering a new country or expanding artist/label onboarding, start with a risk-based Know Your Artist (KYA) model from day one. Treat it as an operating decision layer, not legal advice, and keep your approve/hold/reject logic clear enough to explain on one page.

Use four criteria to choose the lightest model you can still defend internally and with Digital Service Providers (DSPs):

Fraud exposure#

Prioritize the capabilities that can be abused: releasing unlicensed catalog, creating linked accounts, redirecting royalties or withdrawing disputed earnings. Track your own intake volume, confirmed incidents and money at risk instead of sizing controls from an unattributed industry loss estimate.

Onboarding friction#

Keep baseline checks practical. Know Your Customer (KYC) helps reduce anonymity, while KYA adds risk handling around artist, label, and payout legitimacy. Apply heavier checks to higher-risk account types or flows instead of sending every applicant to enhanced review by default.

Review capacity#

Only adopt controls your team can run consistently. Before launch, make sure you have a defined queue, clear ownership, and an evidence trail for exceptions. Collecting ID, watchlist, or ownership signals without a defined approve/hold/reject path effectively creates silent approvals.

DSP defensibility#

DSP requests need a retrievable case record. Apple explains that it communicates with distributors about metadata and asset issues. Keep the account, release, evidence reference and decision rationale linked so the team answering a partner question can find the original review.

If you want a deeper dive, read Music Streaming Fraud: How AI Creates Fake Streams and How Platforms Can Fight Back.

Compare three KYA operating models#

A practical rule is to start with risk-tiered KYA, keep baseline KYC for lower-risk intake, and use enhanced due diligence with manual review when risk signals repeat or exposure is clearly higher. The goal is proportional control: lighter checks where risk is lower, stronger checks where risk is higher.

ModelTypical required inputsReview speedFalse-positive riskOps loadKey prosKey consBest forConcrete use-case
Baseline KYC onlyIdentity evidence appropriate to the market and permitted capability; address proof where requiredFast, mostly automatedCan rise if automation is strict and there is no fallbackLowLowest friction, quick startLimited coverage of artist/label/payee legitimacyLower-risk intake and early-stage onboardingIndividual creator onboarding with limited access before broader payout/distribution permissions
Risk-tiered KYACore identity evidence, then entity, authority, tax or payee evidence as applicableFast for clean accounts, slower on triggered reviewsNeeds measured false-positive rates and manual fallback; improvement is not guaranteedMediumBalances conversion speed with stronger controls where neededRequires clear escalation logic and queue ownershipMost launches across mixed artist/label intakeStep up to registration docs or tax ID when auto-verification fails or entity details do not align
Enhanced due diligence with manual reviewIdentity and entity evidence, catalog authority, payee authorization and corroboration of the specific riskDepends on the case and review queue; publish your actual service targetValid users can still be wrongly flagged; measure outcomes and appeal reversalsHighStrongest defensibility in higher-risk casesHighest operational and conversion costHigh-risk segments or repeated abuse signalsRepeated automated failures, mismatched ownership details, or higher-risk corridors that require manual review evidence

1. Baseline KYC only#

Use basic identity checks for lower-risk, limited intake, such as creating a draft artist profile. They are not a complete basis for distribution or withdrawal: confirm catalog authority before release and entitlement to the payee before moving royalties.

The tradeoff is downstream exposure: identity alone does not fully validate artist, label, or payee credibility. Weak onboarding data can later show up as misdirected payments and fraud leakage.

2. Risk-tiered KYA#

This is the middle path for most operators. Start with core identity checks, then escalate only when risk signals justify it.

That means low-risk creators move quickly, while higher-risk or unclear cases trigger added business and tax verification. Because automated checks are probabilistic, keep a manual review path for valid users who fail edge cases.

3. Enhanced due diligence with manual review#

Use this for clearly higher-risk situations, not as your default. Collect broader evidence, review it manually, and gate distribution or payouts until checks are resolved.

This model improves control and auditability, but it slows onboarding and increases queue pressure. Apply it where risk signals are persistent or materially higher.

Related: Sync Royalties Explained: What Platforms Need to Know About Licensing Music for Video.

Five checks to connect an artist, catalog and payee#

Use identity, entity and catalog authority, applicable sanctions checks, payee authorization and contextual risk signals together. The diagram shows the control layers; evidence requirements vary by role and market, and risk signals should be evaluated throughout the process rather than only at the end. A politically exposed person (PEP) is someone entrusted with a prominent public function; screening may also cover family members and close associates.

CheckWhen to useKey requirement
Identity verificationBefore permissions requiring a verified legal partyUse supported identity evidence; document retry and manual fallback for poor quality, expiry or name-format issues
Entity and catalog authorityBefore distribution, especially for labels and managersVerify the legal entity and representative’s authority; retain catalog-specific rights or mandate evidence and territory/term limits
Applicable sanctions and PEP reviewBefore relevant access or payment permissions and when circumstances changeResolve possible sanctions matches under applicable law; assess PEP risk separately without treating political status as a block
Payee authorization and account controlBefore first withdrawal and after beneficiary changesConnect payment entitlement to the verified legal party or an authorized recipient; verify account-holder evidence and require a separate change approval
IP and public-profile contextAs part of routing and ongoing reviewUse conflicting signals to request corroboration; VPN use or absence of a public profile alone is not proof of fraud

Identity verification plus government-issued ID#

Verify the legal person behind the artist profile using a supported identity route. Government ID and live-photo validation may be appropriate under your provider policy, but they are not a universal requirement at every signup. Separate stage names from legal names and record their relationship. Poor images, expired documents or transliteration differences should lead to a supported retry or review path, with biometric collection assessed under applicable privacy rules.

Entity identity and authority over the catalog#

For a label, manager or business account, verify registration, the submitting representative’s authority and applicable tax details. Then establish why that party can distribute each catalog: request an artist agreement, license or documented mandate, including relevant territories, dates and payee instructions. For example, a manager may be a verified person while their mandate excludes royalty collection; approve only the permissions the mandate supports. Government ID proves identity, not copyright ownership.

Sanctions lists and politically exposed person (PEP) checks#

Screen the parties and ownership relevant to your applicable sanctions regime and payment route. OFAC’s 50 Percent Rule can cover entities owned 50% or more in aggregate, directly or indirectly, by blocked persons even without a name on the SDN list. A PEP flag is a different issue: political exposure is not a sanctions designation or evidence of fraud. FATF guidance addresses preventive measures for covered relationships, while the US interagency bank statement emphasizes risk-based treatment. Determine the requirements for your own role and jurisdiction rather than applying an automatic PEP payout block.

Before withdrawal, verify payment entitlement and account control. Connect the payee to the artist, label or authorized rights holder using the contract and account-holder evidence; a stage name need not literally equal a legal bank name. A joint account or third-party recipient needs a documented, policy-permitted authorization path. Use the payout provider’s current document-age and format requirements instead of assuming a universal twelve-month rule. After a beneficiary change, reverify the destination and obtain a second authorized approval before release.

IP address checks plus public-profile corroboration#

Use this as a step-up trigger, not a standalone rejection reason. Unexpected geolocation or cloud-service IP patterns can justify additional controls, and public web or LinkedIn presence can add legitimacy context during triage. On their own, these signals are indicators to investigate, not proof to deny.

Give artists a clear correction route: state the missing evidence, permitted alternative documents, affected permissions and next review date. Preserve the original decision when a correction is accepted so another reviewer can follow the change.

Set step-up rules before onboarding volume grows#

Step-up controls only scale when every trigger has a pre-defined outcome and owner. A common failure mode in Know Your Artist (KYA) is not missing checks, but letting edge cases sit in an undefined middle state.

Define your default routing before volume increases. You can use four internal outcomes you control, for example: approve, conditional approve, manual review, or reject. That is an operating model, not a regulator-mandated taxonomy, but it is more defensible than an open-ended "investigate later."

Review triggers to define up front#

TriggerRecommended routeReason
IP address checks mismatchRoute to conditional approval or manual review if identity, business documents, and payment ownership are otherwise cleanIP address checks are useful for escalation, but too noisy to use alone as a final deny
Payment-owner mismatchDo not auto-activate payout; review legal-name alignment and supporting account-holder evidenceThis signal is directly tied to who controls the money endpoint
Possible sanctions matchHold the affected permission while qualified staff resolve identity, ownership and legal scopeA screening alert is not itself blocked property; actual blocking duties require the applicable legal analysis
PEP alertAssess the facts and any applicable due-diligence requirements separatelyPolitical exposure alone is not a sanctions block or a fraud finding
Weak corroboration in public records databasesUse conditional approval rather than blanket rejection; keep payout and distribution behind a policy gate until corroboration improvesWeak public-record support can reflect incomplete records, not necessarily fraud

IP address checks mismatch#

Treat unexpected geography, proxy/cloud traffic, or claimed-country mismatch as a step-up trigger, not a standalone denial. If identity, business documents, and payment ownership are otherwise clean, route to conditional approval or manual review. IP address checks are useful for escalation, but too noisy to use alone as a final deny.

Payment-owner mismatch#

If the bank or PayPal account holder does not match the vetted person or business, do not auto-activate payout. Name-to-account mismatch should trigger review with legal-name alignment checks and supporting account-holder evidence. This signal is directly tied to who controls the money endpoint.

Sanctions alert and separate PEP assessment#

Route a possible sanctions match promptly to qualified review. Compare identifiers and relevant ownership, then determine the program, jurisdiction and any authorization that applies; retain false-positive clearance evidence. A temporary operational hold is distinct from a legal block. If property must actually be blocked under OFAC rules, OFAC requires reporting within ten business days of blocking. Do not treat a PEP hit or every fuzzy-name alert as that reportable event. Never release legally blocked property solely because an internal reviewer approves the account.

Weak corroboration in public records databases#

If artist or business claims do not line up cleanly with public records databases, use conditional approval rather than blanket rejection. Allow low-risk setup, but keep payout and distribution behind a policy gate until corroboration improves. Weak public-record support can reflect incomplete records, not necessarily fraud.

Make the sequence explicit#

Keep the operator flow fixed: intake checks -> automated risk score -> manual review queue -> decision log -> payout/distribution policy gate. Use automated scoring for routing, not as an unreviewed final decision.

Log the trigger, evidence references, rule and policy version, reviewer, outcome, affected capability and timestamp. Include the next action and due date for a hold. For a corrected or appealed case, append the new decision and its rationale; preserve the original record rather than overwriting it.

Hold hard failures, limit mixed cases#

Hold the affected capability for a confirmed failure under your policy or applicable law. For mixed signals, permit only the defined lower-risk capabilities while the issue is reviewed. For example, an artist with verified identity but unresolved catalog authority may edit a draft profile while distribution stays disabled; a resolved rights review still does not authorize an unverified payee. Track each restriction and release decision separately.

Handle cross-border rollout without breaking legitimate onboarding#

For cross-border rollout, do not force one global Know Your Artist (KYA) standard onto every market. Use a country matrix that shows which checks are reliable and available in each market, and which capabilities stay locked until stronger evidence is in place.

Build country playbooks around real verification conditions#

The World Bank’s 2025 ID4D dataset, drawing on 2024 data, estimates about 800 million people without official ID and at least 2.8 billion without access to a government-recognized digital identity for online transactions. These population figures are not artist-onboarding failure rates. Test the local documents your verification provider supports and define permitted alternative evidence and manual review when remote verification is unavailable.

Maintain a market matrix tied to payout activation#

For each market, record accepted identity routes, entity and representative checks, catalog authority, sanctions scope, payee requirements, tax-document applicability and manual-review triggers. Map each item to signup, draft upload, distribution and payout permissions. Give the matrix an owner, version date and change trigger; do not leave a previously approved account unrestricted when its payee or ownership changes.

Use stricter sequencing in higher-risk corridors#

Recheck current legal restrictions and payment-provider coverage before opening a corridor. FATF’s 19 June 2026 call for action distinguishes high-risk jurisdictions from jurisdictions under increased monitoring; the lists and requested measures are not interchangeable. Have counsel and payment partners identify measures that apply to your role and route. Geography can justify closer review, but does not establish that an artist committed fraud.

Launch narrow, then relax only after stable operating evidence#

Start new markets with narrower capabilities than mature markets. A practical initial release is onboarding with limited catalog setup, while payouts and broader distribution stay behind review until KYA outcomes and exception handling are stable. Keep each exception record tight: applicable country rule, evidence used, approver, and timestamp. This protects legitimate artists from blanket rejection while keeping rollout decisions defensible.

Measure a narrow launch before widening permissions. As an illustrative queue plan, 100 daily applicants with a 10% step-up rate create ten reviews; at twenty minutes each, that is 200 reviewer-minutes a day before appeals and follow-up. If only 120 minutes are available, change staffing or scope and communicate delays; do not silently auto-approve the overflow. Compare completion, appeal overturns, confirmed incidents and review age by verification route.

Build an evidence pack that survives partner and enforcement scrutiny#

If you cannot reconstruct an onboarding decision later, your controls are not defensible. Your evidence pack should let internal reviewers, partners, and enforcement teams follow the same chain of logic from inputs to outcome.

Log the full decision, not just the outcome#

Keep a timestamped decision trail linking account, release and payee to the reviewed evidence and policy version. Record who approved or changed a permission and why. Limit log access, preserve change history and record corrections as new entries. Periodically ask a second reviewer to reconstruct a case from the saved records and identify any missing evidence.

Make partner-facing proof traceable and exportable#

Reference raw evidence in its restricted system rather than copying IDs into every operations tool. A partner-facing export should identify the account, release, review date, policy applied and relevant outcome, with only the necessary supporting information. Verify the requester’s authority and provide sensitive documents through an approved channel. Apple’s distributor relationship makes a retrievable release record useful when metadata or asset issues escalate.

Use enforcement reality as a design input#

Design records as if a fraud case could be reviewed after the fact. On March 19, 2026, the U.S. Attorney's Office for the Southern District of New York announced a guilty plea in a music-streaming fraud case, and DOJ described AI-generated songs, bot-driven streams in the billions, and more than $8 million in fraudulently obtained royalties. Record observable facts, triggered rules, and applied controls, not vague notes.

Minimize sensitive data while preserving proof of control#

Assign retention periods by record type, applicable law, payment-provider contract and dispute needs; do not set a blanket five-year rule for all KYA material. Current 31 CFR 501.601 requires covered transaction records to remain available for at least ten years, and blocked-property records during the block and for at least ten years after unblocking, except as otherwise provided. That does not require every music platform to keep every raw identity image for ten years. Restrict PII and biometrics, retain necessary decision evidence and follow a documented deletion schedule with legal-hold exceptions.

You might also find this useful: How Streaming Platforms Calculate and Pay Artist Royalties: Per-Stream Rates Explained.

Avoid the mistakes that make KYA look strict but fail in production#

KYA fails in production when controls are treated as one-time, identity-light, overly blunt, or ownerless. To keep review defensible without blocking legitimate creators, fix these four patterns early.

Mistake: treating KYA as a one-time checkbox#

Fix: review suspicious post-release activity and changes to ownership, catalog authority and payment details. Preserve the original approval and later review history. Link distributor fraud reports to the affected release and statement, distinguish provisional estimates from adjusted payable royalties and document any hold or reversal under the contract. Give a legitimate artist a route to explain suspicious playlists or marketing they did not authorize.

Mistake: using social proof as legitimacy evidence#

Fix: use social profiles only as triage signals, then require hard identity verification with documentary and non-documentary methods, plus payment-owner evidence. If profile signals and ownership signals conflict, step up review or hold payouts instead of deciding on profile quality alone.

Mistake: over-blocking because triage logic is vague#

Fix: apply a risk-based approach with clear step-up paths. Mixed signals should route to conditional approval, limited distribution, or payout holds where appropriate, rather than default rejection.

Mistake: no ownership model for day-to-day decisions#

Fix: assign explicit decision rights across product, risk ops, and compliance, with a named owner coordinating daily compliance execution. Log who approved, held, rejected, or changed policy so decisions stay consistent and explainable as post-release enforcement issues arise.

Conclusion#

Treat Know Your Artist (KYA) as an operating discipline, not a brand label. The practical question is simple: can you show, case by case, who gets verified before access, what triggers escalation, and what record explains the final decision?

Use risk tiers with explicit permissions. A lower-risk applicant may receive draft access; distribution still requires catalog authority and payout still requires an entitled, verified destination. Send conflicting evidence to a named reviewer rather than automatically assigning every applicant the highest-friction process.

Keep monitoring after approval. Reopen review when listening patterns, ownership, rights or payment details change, and connect partner reports to the affected release and royalty statement. A passed identity check should remain in the history without preventing a later restriction.

Document decisions so another reviewer can reconstruct them. Preserve the evidence references, policy version, approver, time, affected permission and rationale, including corrections and appeals. A status flag alone cannot explain why a payout was released or held.

That is the operating standard that holds up under pressure: verify early, escalate consistently, and keep proof. It can reduce fraud exposure because bad actors face gates before access, and it can help preserve onboarding velocity because not every case gets the same treatment.

Your next move should be concrete. Mark where identity is confirmed, where escalation rules are defined, where ongoing monitoring starts, and where records are stored. Any missing gate is a red flag, especially if access is granted before verification or if decisions are being made without a written trail.

Frequently Asked Questions

What is Know Your Artist (KYA) in a music platform context?

KYA is an industry operating approach for connecting an artist or label to a verified legal party, authorized catalog and entitled payee. Apply the checks before the corresponding distribution or payout permission, then keep monitoring after release. A verified identity does not prove genuine listening or rights ownership.

How is KYA different from standard KYC?

KYA adapts identity and risk checks to music distribution and royalties by adding catalog authority, artist-to-legal-name mapping and payee entitlement. It is not a universal legal category. Bank KYC duties and provider contracts need their own applicability analysis; sanctions and PEP review are separate issues.

Which checks are table stakes before artist or label distribution access?

Before distribution, establish the legal party and its authority over the catalog, with entity and representative evidence where applicable. Before payouts, establish entitlement and control of the destination under your provider policy. Apply relevant sanctions requirements and resolve conflicting signals. Tax ID and biometric evidence depend on the party, market and permitted capability rather than one global signup rule.

Can KYA alone prevent streaming fraud, or do we still need post-release monitoring?

No. Spotify defines an artificial stream as one that does not reflect genuine user listening intent, and undetected artificial activity can still dilute the royalty pool after onboarding is complete. Use KYA to block obvious bad actors up front, but keep post-release monitoring in place for suspicious activity after onboarding.

What should trigger step-up review versus automatic approval?

Use conflicting identity, catalog-authority or payee evidence, suspicious beneficiary changes and relevant sanctions alerts as defined review triggers. Assess PEP risk separately under applicable requirements. VPN use, transliteration or a missing public profile alone should not establish fraud. Each hold needs an owner, affected permission and correction route.

What evidence should we retain to satisfy DSP partner scrutiny and compliance reviews?

Retain the policy version, evidence references, screening resolution, catalog and payee authority, reviewer, affected permission, timestamp and rationale. Keep original and appealed decisions traceable. Set retention by record type and applicable duty; a blanket five-year baseline is insufficient where current OFAC transaction-record rules require at least ten years.

How should KYA policy change when entering higher-risk countries?

Check current restrictions, provider coverage and the available verification routes for each market. Distinguish FATF calls for action from increased monitoring and assess which requirements apply to your role. Use country-specific evidence alternatives and capability gates without treating every artist from that country as fraudulent.

Gruv Editorial Team

Researched and edited by the Gruv editorial team. Gruv builds cross-border billing, payouts, and finance-operations software for global businesses.

Sources

Includes 2 external sources outside the trusted-domain allowlist.

  1. ecfr.gov/current/title-31/subtitle-B/chapter-V/part-5...trusted
  2. fincen.gov/news/news-releases/agencies-issue-statement-...trusted
  3. id4d.worldbank.org/global-datasettrusted
  4. justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilt...trusted
  5. ofac.treasury.gov/faqs/9trusted
  6. ofac.treasury.gov/faqs/402trusted
  7. artists.apple.com/support/1108-get-your-next-release-on-apple-...external
  8. artists.spotify.com/en/artificial-streamingexternal

Educational content only. Not legal, tax, or financial advice.

Related Posts

How Platforms Can Fight Back Against AI Fake Streams in Music
Risk Management23 min read

How Platforms Can Fight Back Against AI Fake Streams in Music

Music streaming fraud is now an operating risk, not a corner case you can clean up later. A recent example is the [Michael Smith case](https://www.justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilty-music-streaming-fraud-aided-artificial-intelligence-0) in the United States. Federal prosecutors said he used bots to fraudulently stream AI-generated songs billions of times and obtain more than $8 million in royalties.

music streaming fraudartificial streamsartist verification
Read
Sync Royalties for Video Platforms and What You Owe for Music Licensing
Foundational Guides22 min read

Sync Royalties for Video Platforms and What You Owe for Music Licensing

Before you ship video features, break the music question into three parts. First, identify the right you need to pair music to picture. Then identify the license fee, which is often paid up front. Finally, ask whether any ongoing royalties could still show up later. That matters more than the deal label, because it is easy to miss obligations when all music spend is treated as one bucket.

music licensingsync royaltieslicensing video media
Read
How Streaming Platforms Calculate and Pay Artist Royalties Per Stream
Deep Dives22 min read

How Streaming Platforms Calculate and Pay Artist Royalties Per Stream

Per-stream headlines are useful for orientation, but they are a bad operating assumption. If your product, pricing, or artist messaging depends on one blended payout number, you are already skipping the part that usually breaks in production: settlement reality.

per streampay artist royaltiesstreaming platform artist
Read