{
  "id": "BRD-022",
  "slug": "brd-022",
  "title": "A DUNS number is not a US business registration number",
  "statement": "A DUNS number must not be submitted as the US business registration number.",
  "rationale": "DUNS is a commercial identifier issued by a credit bureau, and the registry checks against tax records — so a DUNS number is nine digits that match nothing. It reaches the field honestly, because procurement and vendor-onboarding systems ask for DUNS constantly and it feels like the same class of thing.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.ein",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "AWS"
  ],
  "applicability": {
    "excludeEntityTypes": [
      "SOLE_PROPRIETOR"
    ]
  },
  "applicabilityText": "Applies when the brand is NOT a sole proprietor.",
  "universal": false,
  "remediation": "Replace it with the EIN from your IRS letter. Keep the DUNS number for the systems that want it — it is simply not what this field verifies against. Done when the value is the nine-digit EIN in hyphenated form.",
  "example": "ein: 12-3456789 — the IRS EIN, not the nine-digit D-U-N-S",
  "notes": "Only the shape is checkable here: an unhyphenated nine-digit US identifier is the DUNS signature, since a real EIN should carry the hyphen (BRD-020). Confirming a value IS a DUNS number needs the D&B register, which is EXTERNAL_DATA and out of reach pre-submission.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/brand/brd-022/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-022.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
