Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should compliance teams verify ultimate beneficial owners…
Identity Beyond IAM

How should compliance teams verify ultimate beneficial owners before onboarding a business relationship?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Start with the legal entity, then trace direct and indirect ownership until the natural persons who ultimately control or benefit from the business are identified. Verify the claimed UBOs against reliable documents and independent sources, then apply enhanced due diligence where risk is elevated. The goal is to understand who truly controls the entity before any relationship begins.

How UBO verification should work in practice

UBO verification is a traceability exercise, not a form check. Compliance teams should start with the legal entity, then follow each ownership layer through nominees, holding companies, trusts, and other control arrangements until the natural persons at the end of the chain are identified and validated. In practice, that means reconciling the ownership story across corporate records, registry data, and independent evidence before onboarding proceeds.

Verification also needs to distinguish ownership from control. A person may be a UBO because they hold a qualifying ownership percentage, because they exercise control through voting rights or governance rights, or because the entity is structured so that control is not captured by simple equity thresholds. That is why a narrow share register review is usually insufficient on its own.

When ownership is layered or opaque, the team should document the full chain of reasoning, not just the final name. A defensible file shows how each intermediate entity was resolved, what source supported it, and where the review relied on corroboration rather than self-attestation. For operational guidance on ownership tracing, lifecycle thinking, and control validation, the NHI Lifecycle Management Guide and Ultimate Guide to NHIs, Regulatory and Audit Perspectives provide a useful governance lens.

Evidence, red flags, and when enhanced due diligence is needed

Verification should rely on reliable documents and independent sources that can stand up to audit. Good evidence typically includes incorporation records, shareholder registers, constitutional documents, trust deeds where relevant, regulator filings, and credible open-source or commercial verification where appropriate. The point is to confirm the claimed UBOs against external reality, not to treat the customer-provided structure chart as sufficient proof.

Enhanced due diligence should be triggered when the structure is unusually complex, when ownership sits behind multiple layers or foreign entities, when the customer is a PEP or otherwise high risk, or when there are inconsistencies between declared control and documentary evidence. A mismatch between the stated business purpose and the ownership profile is another warning sign, especially if it suggests concealment, nominee arrangements, or unexplained intermediary entities.

Compliance teams should also be careful with timing. If a relationship begins before ownership is reasonably understood, later remediation can be costly and may miss the earliest opportunity to stop a problematic onboarding decision. A useful comparison point is the FATF’s Recommendations on beneficial ownership and customer due diligence, which frame beneficial ownership as part of knowing who is really behind the customer. For broader control design, ISO/IEC 27002:2022 Information Security Controls and SOC 2 Trust Services Criteria both support disciplined evidence handling, access governance, and third-party risk review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 42001:2023 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
ISO/IEC 42001:2023AI Management SystemNot selected.

Practitioner Guidance

What to verify: Require a full ownership chain that reaches natural persons, then test whether the same people appear consistently across registry data, filings, and supporting documents. If the answer depends on one self-declared document with no independent corroboration, treat the result as incomplete.

Decision rule: If ownership or control cannot be resolved with reasonable confidence before onboarding, pause the relationship and escalate to enhanced due diligence. If the structure is simple and evidence is aligned, document the basis for acceptance and keep the file auditable.

Practitioner takeaway: The key judgment is not whether a name is attached to the entity, but whether the team can defend who ultimately controls or benefits from it before any business is allowed to begin.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org