UBO Verification: Why entity-level screening isn’t enough
A third party can clear initial screening and still leave important ownership questions unanswered.
Sanctions screening clean. Adverse media clear. Questionnaire complete. By every check the process runs, the relationship is ready to approve.
None of those checks ask who stands behind the entity once approval is signed off. Not the registered name – the person or people who own it, control it, and benefit from it. Compliance teams call this the hardest part of due diligence, and the data supports this: in a review of 25 conversations with compliance leaders on third-party risk, 15 named ownership and affiliation visibility as a significant operational gap: 10 called UBO identification the hardest single piece of the process, ahead of sanctions status, adverse media, and questionnaire review.
This shows up across sectors and company sizes, in teams running mature programs and teams building from scratch. Entity-level screening confirms the entity a compliance team is looking at. It does not, however, trace what sits behind that entity, and that’s where the process runs its course.
What UBO investigation means
Ultimate Beneficial Ownership (UBO) investigation is the process of identifying the individual or individuals who ultimately own or control a third-party entity. The name on a registration document is only the starting point. In practice, this may involve tracing ownership through holding companies, nominee arrangements, and multi-jurisdiction structures until an accountable person is identified, since the registered legal owner and the actual controlling party are frequently different.
Relationship intelligence can support a UBO investigation by surfacing ownership signals, affiliations, connected entities, and publicly documented relationships for further review. It does not independently confirm ultimate beneficial ownership or replace formal ownership verification.
This matters because 10 of the 25 conversations we reviewed specifically named UBO identification as the hardest single piece of information to obtain, ahead of sanctions status, adverse media, and questionnaire responses. Registry data is an important starting point, but its coverage depends on the jurisdiction and applicable disclosure rules.
What entity-level due diligence actually checks
Third-party due diligence typically runs a fixed set of checks against the entity itself: sanctions lists, PEP registers, adverse media, and in some cases a registry-based ownership lookup. This is the baseline of most third-party risk management (TPRM) programs, and for good reason. It runs quickly, automates well, and catches the clearest risk signals. For a broader look at where this baseline commonly runs into trouble, see Third-Party Risk Management: Challenges and Best Practice.
Entity-level checks have a defined scope. They assess the submitted legal entity and their scope stops there. The checks leave open who controls that entity, which other companies share its directors or owners, or whether it’s part of a larger group with its own risk profile. Registry-based ownership data helps here, but coverage varies sharply by jurisdiction. In the calls we reviewed, jurisdiction was the recurring fault line.
One compliance lead described the limit directly: in certain markets, “you cannot know who the shareholders are… the only way to find the shareholders is to ask the third party who their shareholders are.” Another, working across multiple jurisdictions, put it more bluntly: ownership is sometimes “hidden in some kind of nominee entity” in low-disclosure jurisdictions. Twelve of the 25 conversations described their current ownership investigation process as questionnaire-based self-disclosure or manual research, with no system-driven check in place.
Where the gaps actually show up
Three patterns recurred across the calls we reviewed, each pointing to a different failure mode in entity-only screening.
Smaller companies often produce limited public signals. Adverse media and registry checks depend on a company having a public footprint. One compliance officer described getting zero hits on a third party that was simply too small or too new to appear anywhere: no media profile, no web presence, nothing to screen against. A blank result reads as “no risk found.” It often means “no data existed to search.”
Local-language and local-market information doesn’t surface in global databases. In one case, a global screening tool returned nothing on a supplier; a compliance officer’s own ten-minute local-language search turned up material findings the tool had missed entirely. Language and geography came up as a barrier in multiple conversations, particularly for high-risk markets like China, Eastern Europe, and parts of Africa.
Ownership structures span jurisdictions in ways that single-entity checks stop short of following.Multi-jurisdiction ownership chains are common in cross-border third-party relationships, and each jurisdiction along the chain can carry different disclosure standards. Following that chain today means manually cross-referencing separate registries and reconciling names by hand. It is often the same email-and-spreadsheet process described in How to Digitize Your Third-Party Risk Management Program.
When the gap is worth escalating
Compliance teams don’t investigate every third party to the same depth, and they shouldn’t. Across the calls reviewed, escalation to enhanced due diligence (EDD) tracked a consistent set of triggers: high-risk jurisdictions, red flags surfaced during initial screening, high contract value, government-adjacent relationships, and strategically important suppliers or M&A targets.
The pattern worth noting: EDD triggers are usually risk-based and proportional, but the information that justifies escalation, such as an unexpected ownership connection or an affiliate in a sanctioned jurisdiction, is exactly the kind of signal entity-only screening is least likely to surface on its own. Teams end up escalating based on what they happen to find manually, with no consistent view of ownership across their portfolio. Formalizing this, by defining risk tiers up front before any single case arises, is what a structured, risk-based approach is meant to address; our white paper, A practical framework for efficient and defensible TPRM, walks through a five-phase framework for doing that.
Building this into a due diligence workflow
Some AI experts see the EU AI Act not as a burden, but as an opportunity. By building trust in AI among customers and partners, the law could give Germany and Europe a competitive edge. Companies that comply signal that they take social responsibility seriously, boosting their reputations. Put simply, an ethical approach to AI is essential for driving sustainable innovation and preventing misuse.
We’re still at the start of the AI journey. No one can say exactly where it will lead. That’s why the EU has built flexibility into the law. The Act is designed to evolve alongside the technology.
For companies, this means it’s worth investing in digital processes and a centralized platform for AI governance now. The more agile your setup, the better equipped you’ll be to handle what comes next.
