Indirect ownership exists when a person controls a company through one or more intermediary entities rather than holding shares directly. Tracing indirect ownership is essential in UBO analysis because the true controlling individual may sit several layers away from the legal entity being onboarded.
How Indirect Ownership Is Traced
Indirect ownership is usually traced by moving from the onboarded legal entity outward through each intermediary company, holding company, trust, or nominee arrangement until the natural person or persons who ultimately control the structure are identified. The practical task is less about a single share register and more about reconstructing control across several layers of corporate separation.
That tracing process is central to UBO analysis because control can survive even when no single entity appears to hold a majority stake on the surface. Where thresholds, voting rights, board appointment rights, or contractual control differ from simple share percentage, the investigator has to evaluate the whole control path, not just the final holding.
Why Indirect Ownership Matters in UBO Work
Indirect ownership is important because it is one of the main ways beneficial ownership can be obscured without being hidden completely. A person may influence or control a target entity through subsidiaries, layered vehicles, or cross-holdings even when their name never appears on the immediate cap table.
For compliance and financial-crime teams, that matters because the question is not only who owns shares, but who can actually direct the entity, benefit from it, or influence its decisions. FATF’s customer due diligence and beneficial ownership expectations make this kind of tracing a core part of beneficial ownership analysis under the FATF Recommendations.
Indirect ownership also affects how confident an organisation can be in onboarding, risk scoring, sanctions screening, and escalation decisions. If the ownership chain is incomplete, the institution may misidentify the true controller, which undermines the entire purpose of UBO review.
Common Structures and Calculation Challenges
The most common structures include parent-subsidiary chains, layered holding companies, nominee arrangements, and ownership spread across multiple entities that together create control. In practice, an analyst often has to combine percentage ownership, voting control, and governance rights to decide whether a person is an indirect owner, a controller, or both.
Complexity increases when the same person influences the entity through more than one path. A single individual may hold partial stakes through multiple companies, and those interests may need to be aggregated if the applicable rule set treats parallel paths as cumulative control.
Another challenge is that indirect ownership is jurisdiction-sensitive. Different regimes can treat control thresholds, look-through requirements, and documentation standards differently, so the ownership chain that is sufficient in one context may be incomplete in another.
Risk and Threat Considerations
Indirect ownership creates exposure when it is not fully traced, because concealed control can be used to evade sanctions, launder proceeds, mask conflicts of interest, or place higher-risk parties behind apparently legitimate entities. The risk is greatest when onboarding decisions rely on incomplete corporate documentation or when layered structures are accepted without validating the natural persons behind them.
Failure mechanism: The ownership chain is broken at one or more intermediary entities, leaving the true controller undisclosed or misclassified, which can defeat due diligence, screening, and accountability checks.
Impact: Organisations can onboard the wrong counterparty risk, miss reporting obligations, or maintain business relationships with entities whose real control structure would have changed the decision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
DORA, NIS2 and PCI DSS v4.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | ART. 18 — Third-Party ICT Risk Management | Indirect ownership can hide counterparty control behind layered entities. |
| Recommendation — Verify controlling persons through layered ownership before onboarding critical third parties. | ||
| NIS2 | Article 21 — Cybersecurity Risk Management Measures | Ownership opacity is a governance and dependency risk that affects trust decisions. |
| Recommendation — Document look-through ownership checks as part of supplier and counterpart risk controls. | ||
| PCI DSS v4.0 | 3.2 — Sensitive Authentication Data, Storage and Retention | Entity control opacity can affect merchant and service-provider accountability around sensitive data handling. |
| Recommendation — Validate ownership and control of service providers before granting access to payment data. | ||
Practitioner Guidance
What to watch for: Treat indirect ownership as a control-analysis problem, not just a document-collection exercise. If the structure includes multiple layers, cross-holdings, nominees, or inconsistent voting rights, the investigator should assume the first visible owner may not be the true decision-maker.
Governance implication: Ownership reviews need a documented method for look-through analysis, escalation when evidence is incomplete, and clear ownership of the final UBO determination. Incomplete chain tracing should trigger exception handling rather than silent acceptance.
When the ownership path is genuinely hard to reconstruct, the safest posture is to preserve the uncertainty and escalate it, rather than overstate confidence in a simplified ownership diagram.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org