Organisations should verify the natural persons who ultimately own or control a company, then confirm that information with reliable, independent sources such as government-issued records. The practical goal is to reduce opacity in ownership structures, improve risk profiling, and support enhanced due diligence for higher-risk customers. Verification should cover identity, control, and beneficial interest, not just the registered company name.
How UBO verification works in practice
Ultimate beneficial ownership checks should establish who ultimately owns, controls, or benefits from a customer, then test that claim against independent evidence. In an African context, that usually means looking beyond the registered company name to the natural persons behind nominees, layered entities, trusts, and cross-border structures. The point is to make ownership explainable, not merely declared.
Verification is stronger when organisations corroborate self-declared ownership with reliable sources, then document where the evidence is direct and where it is inferential. A useful benchmark is to distinguish identity of the person, the control path, and the economic interest, because a customer can be lawful yet still present elevated AML risk if those three are hard to confirm.
For ownership opacity and related secrets and control risks, the same discipline used to reduce hidden access paths in key identity risks and to manage regulatory and audit expectations is useful: opaque structures need evidence, traceability, and documented exceptions, not assumptions.
What evidence is worth trusting
Reliable, independent sources are the core of UBO verification. Organisations should prioritise government-issued or regulator-supervised records where available, then complement them with corporate registries, ownership filings, tax records, trust instruments, board resolutions, or notarised documents when the structure is more complex. The more layers between the customer and the natural person, the more important it becomes to compare multiple sources rather than relying on a single assertion.
Practically, this means verifying whether a person owns the company directly, controls it through voting rights or shareholder agreements, or benefits economically through another arrangement. In higher-risk cases, organisations should also test whether the disclosed owner is acting for someone else, because nominees and front entities can make the registered owner look clean while the real control sits elsewhere. That is why beneficial ownership checks are a control over opacity, not a box-ticking exercise.
When beneficial ownership evidence is weak, the better response is usually enhanced due diligence, not a rushed approval. FATF’s AML and KYC framework remains the clearest external reference for beneficial ownership and customer due diligence, while the EBA AML/CFT Guidance gives a useful example of how supervisors expect firms to handle uncertainty, escalation, and risk-based verification.
In a governance sense, the relevant parallel is the same control logic used in lifecycle management: ownership data must be acquired, validated, reviewed, and refreshed over time. Stale ownership records are a common failure mode even when onboarding was done carefully.
Practitioner judgement for African AML programmes
UBO verification in Africa works best when organisations treat jurisdictional variation as a risk input, not a reason to lower the bar. Registry quality, beneficial ownership disclosure rules, and document reliability vary significantly across markets, so the control should be designed around evidence quality, not around the assumption that every country will provide the same source depth or update frequency.
What to verify: Confirm who owns, controls, and benefits from the entity, then compare that against at least one independent source that is credible for the jurisdiction. If the structure includes trusts, nominee shareholders, or offshore entities, require extra scrutiny and a documented rationale for any unresolved gap.
Decision rule: If the organisation can identify the natural person with confidence, proceed with standard risk scoring; if it cannot, treat the customer as higher risk until the ownership chain is reconciled or the relationship is rejected. The quality of the ownership evidence should influence onboarding, monitoring intensity, and escalation thresholds.
Practitioner takeaway: The objective is not to obtain a perfect ownership tree every time, but to make hidden control materially harder to conceal and materially easier to defend in audit, investigation, and escalation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-1 — Organizational Context | Beneficial ownership verification supports understanding customer context and risk exposure. |
| ID.RA-01 — Asset Risk Assessment | UBO checks are a risk-assessment control for opaque legal entities and control chains. | |
| PR.DS-1 — Data-at-Rest Protection | Ownership records and supporting documents are sensitive due diligence data needing protection. | |
| Recommendation — Document ownership context to inform AML risk decisions and escalation. Assess ownership opacity as a risk factor before accepting the customer. Protect beneficial ownership records and restrict access to due diligence evidence. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Assets | UBO verification depends on maintaining an accurate inventory of entities and controlling persons. |
| 6.1 — Establish an Access Control Policy | AML teams need policy-driven rules for when ownership uncertainty triggers enhanced due diligence. | |
| 8.2 — Audit Log Management | UBO review decisions and source checks need traceable evidence for audit and investigation. | |
| Recommendation — Keep a current inventory of legal entities, owners, and control relationships. Set clear policy thresholds for escalation when ownership cannot be verified. Log ownership verification steps and retain evidence for review and audit. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | UBO verification relies on stronger identity proofing than a self-declared name or document scan. |
| IAL3 — Identity Assurance Level 3 | Higher-risk beneficial ownership cases need stronger proofing and corroboration. | |
| AAL2 — Authenticator Assurance Level 2 | Access to ownership evidence and due diligence workflows should be protected by stronger authentication. | |
| Recommendation — Use higher assurance evidence when confirming the natural persons behind the entity. Apply stronger proofing when the ownership structure or risk profile is complex. Require stronger authentication for staff handling sensitive ownership evidence. | ||
| NIST Zero Trust (SP 800-207) | 5.0 — Zero Trust Architecture Principles | Zero Trust supports verify-explicitly thinking for ownership claims and control relationships. |
| Recommendation — Verify each ownership claim explicitly rather than trusting declarations or structure alone. | ||
Related resources from NHI Mgmt Group
- How should organisations turn AML policy into enforceable operational controls?
- How should organisations connect AML controls to identity governance?
- Why do beneficial ownership controls matter more when AML risk rises?
- How should healthcare organisations strengthen identity controls after CISA expiration?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org