A company may sign a contract, receive an investment or hold an asset, but a legal entity cannot make decisions by itself. Natural persons ultimately benefit from its activity or exercise control over it. Identifying those people is the purpose of an ultimate beneficial owner check.

The question becomes difficult when ownership passes through holding companies, nominees, trusts or several jurisdictions. A registry may show the immediate shareholder without revealing who stands at the end of the chain. That gap can conceal sanctions exposure, conflicts of interest, financial crime or undisclosed influence.

Key takeaways

  • An ultimate beneficial owner, or UBO, is the natural person who ultimately owns or controls a customer or legal entity, or on whose behalf a transaction is conducted.
  • A UBO check maps direct and indirect ownership, examines control beyond shareholding, verifies the people identified and records the supporting evidence.
  • An ownership threshold is a starting point. It does not replace analysis of voting rights, contractual powers and other forms of effective control.

What does UBO mean?

The Financial Action Task Force defines a beneficial owner as the natural person or persons who ultimately own or control a customer, or on whose behalf a transaction is conducted. FATF sets international standards; it is not a regulator and does not create one global threshold.

“Ultimate” matters. The direct shareholder may be another company, partnership or trust. The investigation must continue through each relevant layer until it reaches one or more natural persons. A company can therefore be an intermediate owner, but not the final UBO under the FATF approach.

Ownership is only one route. Control may also arise from voting arrangements, appointment rights, trust powers or contractual influence. A director is not automatically a UBO simply because they run the business.

UBO, shareholder and person with significant control

These terms overlap, but they are not interchangeable.

A shareholder is the registered holder of shares and may be a person or legal entity. A UBO is the natural person at the end of the ownership or control chain.

In the United Kingdom, the separate person with significant control regime covers more than 25% of shares or voting rights, board appointment rights and other significant influence or control. A PSC register is useful evidence, but it does not replace an AML or sanctions assessment.

Why UBO checks matter

Ownership determines whose interests may shape a company’s decisions. An unidentified controller can expose a transaction to sanctions, bribery, money laundering, fraud, tax, regulatory or reputational risk. It can also hide a conflict between a counterparty and an employee, public official, competitor or other participant in the deal.

The legal duty to identify UBOs depends on the jurisdiction, sector and transaction. Banks and other obliged firms commonly conduct UBO checks as part of customer due diligence. Buyers and investors use the same analysis to understand who may benefit from a partnership or acquisition.

For suppliers, distributors and intermediaries, ownership analysis should sit within broader third-party due diligence, not as a standalone database search.

How to identify an ultimate beneficial owner

1. Verify the legal entity

Confirm the company’s registered name, number, status, jurisdiction and address. Collect current incorporation documents, shareholder registers and official filings. Record the date because ownership can change.

2. Map direct ownership

List each direct shareholder, percentage interest and voting rights. If a shareholder is another entity, obtain evidence for it rather than accepting the customer’s chart without verification.

3. Trace indirect ownership

Continue through each material layer until the chain reaches natural persons. Multiply ownership at every level to calculate indirect interests, combining them where several routes lead to the same person.

4. Test control beyond shares

Review voting agreements, board appointment rights, vetoes, nominee arrangements and trust documents. A person can exercise effective control without crossing an ownership threshold.

5. Verify the people identified

Confirm each person’s identity and screen them against the rules relevant to the engagement. This may include sanctions, politically exposed person status, adverse media and other risk indicators. Where the review supports onboarding or AML controls, KYC and compliance due diligence should connect the ownership map with these findings.

6. Resolve gaps and document the conclusion

Compare filings, declarations and independent sources. Investigate inconsistent percentages, unexplained entities and recent transfers. If no natural person is identified through ownership or control, FATF guidance calls for regulated firms to record the relevant senior managing official. That is a customer-due-diligence fallback, not a UBO by default.

Why the 25% rule is not enough

More than 25% is a common threshold in UK AML and PSC tests, but it does not answer every ownership question. Thresholds differ by jurisdiction and legal purpose, while control may exist below them.

Suppose Anna owns 40% of Holding B, which owns 60% of Target C. Her indirect interest in Target C is 24%: 40% multiplied by 60%. She falls below 25%, but voting agreements, board rights or another ownership route may still give her control or increase her combined interest.

Sanctions analysis follows different rules. UK guidance generally examines ownership above 50% and separate control tests, including whether an entity’s affairs may follow a designated person’s wishes. Passing a 25% UBO check is not a sanctions safe harbour.

The practical rule is simple: calculate ownership, test control and apply the correct legal test for the decision being made.

Common UBO red flags

Complexity is not evidence of misconduct. Holding companies, trusts and nominees can serve lawful purposes. Risk rises when the structure lacks a clear rationale or the evidence does not support the explanation.

Warning signs include:

  • ownership declarations that conflict with official filings;
  • repeated use of nominees without a documented business reason;
  • rapid transfers before onboarding, investment or a major payment;
  • shareholders registered in several secrecy-oriented jurisdictions;
  • identical addresses, directors or contact details across apparently unrelated entities;
  • circular ownership or percentages that do not reconcile;
  • unexplained control rights held by a minority investor;
  • links to sanctioned or politically exposed persons; and
  • reluctance to provide current ownership records.

A wider corporate due diligence review can test these indicators against litigation, regulatory, financial and reputational evidence.

How to monitor beneficial ownership

A UBO result is accurate only for the evidence and date recorded. Companies issue and transfer shares, restructure groups, appoint new controllers and move between jurisdictions. Risk status can also change when a person becomes sanctioned, politically exposed or linked to new allegations.

Set monitoring frequency according to risk. Require counterparties to disclose material changes and refresh the assessment after ownership transfers, mergers, new jurisdictions or adverse information. Keep sources, dates, calculations, limitations and the approval decision in the case file.

Automated alerts can surface a change, but they do not verify its meaning. An analyst must determine whether the match concerns the correct person or entity and whether it changes the original risk decision.

Ownership must be verified, not assumed

An effective UBO check does more than copy a name from a declaration. It establishes the ownership chain, identifies natural persons, examines control, applies the relevant legal tests and records how the conclusion was reached.

For straightforward structures, reliable corporate records may resolve the question. Layered, cross-border or contested ownership requires deeper source work. If a counterparty or transaction needs an independent ownership assessment, contact Molfar Intelligence.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.