Gå til hovedinnholdet Gå til menyen
Book a demo

Finding the UBO Is Only the Beginning

A UBO name is one conclusion. Good KYB means understanding the structure behind it, the risks within it, and how that structure changes over time.

Aerial view of eroded rock formations, layer upon layer of blue-grey sediment exposed.

Most corporate KYC processes are built around a satisfying moment: the ownership chain is traced, a name is entered into the UBO field, and the file moves to the next stage. It feels like an answer. In an important sense, it is only the beginning of one.

Knowing the UBO tells a firm who ultimately owns or controls the customer. It does not, on its own, explain how that ownership or control is reached, what sits along the way, or whether the answer will still be true in six months. A UBO result is a conclusion. Good KYB should also be able to show how the firm got there — and whether that conclusion still holds.

Ownership is a structure, not a field

Treating beneficial ownership as a single data point invites a particular kind of blindness. A name in a customer record carries no information about the layers of corporate ownership beneath it, whether the ownership is direct or reached through several intermediate entities, whether control was established through shareholding or through some other arrangement entirely, or what — and who — sits at each level of the chain in between.

That matters because the intermediate layers are not incidental to the UBO conclusion. They are the reasoning behind it. A firm that can state a UBO's name but cannot show the path connecting that person to the customer has not really finished the analysis; it has skipped to the answer. Ownership is not a field in a customer record. It is a structure, and structures change.

Why the chain itself matters

The obvious question is why a firm should care about entities it does not do business with, several layers removed from its actual customer. The answer is that risk does not always sit where the direct relationship is.

Sanctions regimes are the clearest example, without needing to become a sanctions article. Under OFAC's 50 Percent Rule, direct and indirect holdings by blocked persons are aggregated, so an entity can be treated as blocked even though its own name never appears on a sanctions list. Other regimes weigh ownership and control differently, and the details vary by jurisdiction and by list — the general lesson does not. Screening the customer's name is not enough if the relevant risk sits several entities higher in the ownership chain.

The same logic applies beyond sanctions: a change in control at an intermediate holding company, aggregate ownership distributed across several related parties in a way that obscures the true ownership picture, or ownership run through a jurisdiction that meaningfully reduces transparency can all matter well before anything about the direct customer itself has changed.

Complexity is not the same as suspicion

It would be easy, at this point, to slide into treating every layered structure as a warning sign. That would be a mistake, and a common one. Multinational groups, private equity structures, joint ventures and legitimate holding arrangements are routinely complicated for entirely ordinary commercial, tax and regulatory reasons that have nothing to do with concealment. Complexity is not evidence of wrongdoing.

What deserves attention is complexity disproportionate to the apparent commercial purpose of the structure: layers that serve no identifiable function, ownership loops that are hard to reconcile with any legitimate rationale, intermediate entities that resist verification, or a declared ownership picture that does not match the evidence available. Structures like these can be used to obscure beneficial ownership, evade sanctions or launder proceeds of crime — but the trigger for scrutiny is the mismatch between the structure and its apparent purpose, not the structure's existence, and it is not confined to any one jurisdiction or corporate form.

Ownership percentages do not tell the whole story

It is tempting to treat UBO determination as arithmetic — cross a shareholding threshold and the answer follows. Regulatory frameworks including the EU's AMLR do not stop there. Ownership through a shareholding interest is one route to beneficial ownership; control through other means is a separate one, and it can exist without any single person crossing an ownership percentage at all. AMLR recognises control arising through holding a majority of voting rights, the right to appoint or remove a majority of a board, veto rights over key decisions, and rights over profit distribution. Depending on the facts, arrangements such as shareholder agreements, nominee relationships, voting rights, appointment rights, veto rights or family relationships may also be relevant to determining control — none of them automatically decisive on its own, but each capable of concentrating control in ways a shareholding register would not show. Indirect control, reached through intermediate entities in the ownership structure, counts as much as direct control does.

Ownership percentages help answer the question. They do not always answer the whole question, and a firm that only checks the arithmetic can miss control that was deliberately built to sit below the obvious threshold.

What if there is no neat UBO?

Not every structure resolves through the familiar shareholder-threshold calculation. Trusts, foundations and similar arrangements can require beneficial owners to be identified through the roles people occupy — settlor, trustee, protector, beneficiary, and anyone else exercising ultimate control — rather than through share ownership; that is a different mechanism for arriving at an answer, not the absence of one. Certain listed companies or public-law bodies may also fall under specific exemptions or simplified treatment, depending on the applicable framework. And in some corporate structures, after ownership and control have been properly analysed, no natural person may ultimately be identifiable as the beneficial owner. The exact treatment varies by jurisdiction and entity type, and generalising across all of them is a good way to get the detail wrong — the point that matters here is that a structure producing something other than one clean, shareholding-based natural-person UBO is not automatically a failure of the analysis.

That is a different situation from failing to establish an answer that should exist. AMLR is explicit about the distinction: where a beneficial owner genuinely cannot be identified after all possible means of identification have been exhausted, the firm falls back to identifying and verifying the senior managing officials of the entity instead — not because they are deemed to be the beneficial owner, but as a documented substitute step, with a record kept of what was tried and why it did not produce an answer. "There is no identifiable UBO under the applicable framework" and "we could not establish who the UBO is" are not the same conclusion. One can be entirely legitimate. The other may itself warrant additional scrutiny and should never be quietly closed out with a blank field.

A blank UBO field tells you almost nothing. A documented conclusion explaining why no UBO exists, or why one could not ultimately be determined, tells you a great deal — and it is the second version, not the first, that a firm should actually be aiming to produce.

The UBO remains a live risk, not a settled fact

Once identified, a UBO can quietly become a static entry: name recorded, screened once, filed. People and circumstances do not hold still. Someone who is not a politically exposed person today may become one. A sanctions designation can be added after onboarding, not only at it. Adverse information can surface later. Ownership or control at the top of the chain can shift even while the direct customer relationship looks unchanged. Finding the UBO answers who ultimately owns or controls the customer today. It does not answer whether the risk associated with that person is the same tomorrow — which is why the UBO, and the other individuals identified along the way, need to stay connected to the firm's ongoing screening and monitoring, governed by the applicable requirements and the firm's own risk framework, rather than treated as a one-time lookup.

Ownership monitoring has to follow the chain

This has a direct operational consequence: a firm's own direct shareholder can stay exactly the same while ownership two or three layers above it moves. That shift can change the UBO conclusion, the control analysis, sanctions or PEP exposure, geographic risk, or the firm's existing risk classification — without a single field in the direct customer's own record ever being touched. Ownership monitoring has to follow the chain, not just the customer record, or a change with real significance can sit undetected simply because it never reached the layer the firm was actually watching.

None of this means every ownership change triggers the same response. A structural change at an intermediate entity, a new party entering the chain, and a change in an already-identified UBO's personal circumstances call for different degrees of reassessment, proportionate to what has actually moved and what it might mean — from confirming the change and updating the record, through re-screening the newly relevant party, to reassessing the risk classification or escalating to a human reviewer where the change is genuinely material. The response should fit the event, not default to the same procedure regardless of what changed.

Why seeing the structure matters

This is where a visual map of the ownership structure earns its place, and why it is worth more than a nicer-looking file. A flat shareholder list, a registry extract, or a set of disconnected data-provider results can each be individually accurate and still fail to convey how a structure actually holds together. An ownership graph that shows the customer, its direct shareholders, the intermediate entities, the parent companies, and the individuals who ultimately own or control it — across as many layers as the structure actually has — lets the person responsible see how the UBO conclusion was reached, which entities sit on the path, where a risk-relevant person or entity appears, and where the structure is genuinely incomplete or uncertain rather than merely unfamiliar.

Technology should make complex ownership understandable. It should not pretend that every complex structure has a simple automated answer — some structures are complex because the underlying business is, and the map's job is to make that complexity legible, not to flatten it into a false simplicity. A UBO result is more useful when the person responsible for it can actually see, and explain, how the conclusion was reached.

It is also worth noting, briefly, that the same map is not purely a compliance artefact. A parent company's insolvency, an acquisition that changes who controls the relationship, or a restructuring that introduces new decision-makers are facts about the customer's commercial reality as much as they are facts relevant to AML. An accurate ownership picture serves both purposes at once, because it is simply an accurate picture of who the firm is actually dealing with.

Human judgement remains the point of the exercise

None of the technology described here is meant to remove judgement from ownership analysis — the opposite is the goal. Software can collect registry data, calculate ownership paths, connect entities across layers, compare current structures against prior ones, screen relevant parties, monitor for change, and preserve the record of what was found and when. It should not be asked to decide whether a given layer of complexity is commercially logical, whether an unresolved structure is itself a concern, whether enhanced due diligence is warranted, or whether a relationship still sits within the firm's risk appetite. Those remain judgement calls, made by people accountable for them. The purpose of technology here is not to remove judgement from ownership analysis. It is to give judgement better facts to work with.

This is the environment platforms like IQON are built for: connecting corporate and ownership data to an ownership map that shows how a UBO conclusion was reached, to the screening and monitoring that keeps the relevant people and entities current, to the risk classification and workflow that a material change may affect or trigger, and to the record that preserves the reasoning — not to hand down the conclusion itself, and not to make the complexity disappear.

Finding the beneficial owner answers an important question. Understanding how ownership and control reach that person, what risk sits along the path, and whether the answer remains true over time is the work that follows. The goal was never simply to put a name in the UBO field. It is to maintain an ownership picture that a competent person can understand, explain, and act on.

Book a demo

Protected by reCAPTCHA
Privacy - Terms

Thank you

Why IQON

  • Modular platform for onboarding, KYC/AML and reporting

  • Digital onboarding and document signing with eID

  • Continuous AML monitoring

  • Simple, intuitive client reporting across web and mobile

  • Fully white-labelled apps and portals

  • Digitalized processes that improve speed and accuracy

  • Easy, vendor-agnostic integrations