Compliance

Beneficial ownership compliance

Identifying a customer's beneficial owners isn't optional under AML law - it's a specific, threshold-based obligation, and how you document meeting it matters as much as whether you did.

Definition

Beneficial ownership compliance - The obligation, under AML/CDD rules, to identify a business customer's ultimate beneficial owners as part of onboarding and ongoing due diligence - and to keep records showing how that identification was made.

Where this obligation comes from

Anti-money-laundering law requires obliged entities - banks, payment institutions, e-money issuers, crypto asset service providers, and others - to know who they're really dealing with. For a corporate customer, that means identifying the natural persons who ultimately own or control it, not just the entity's legal name and registration number. This sits inside the broader CDD/EDD framework as its own specific requirement.

The threshold that defines "beneficial owner"

Under the EU's AMLR, the general test is 25% or more of ownership or control, with a lower threshold available only for sectors the Commission has specifically identified as higher-risk by delegated act. Getting this threshold wrong in either direction is a real compliance risk - missing a genuine beneficial owner, or asserting a stricter legal position than currently exists. See the 25% UBO threshold, explained.

A one-time check isn't the end of the obligation

Ownership can change after onboarding, and the compliance obligation doesn't stop at the first check - it extends to noticing when the picture changes. This is the regulatory rationale behind perpetual KYB and UBO monitoring: not a product feature bolted on, but a direct response to what "ongoing due diligence" actually means.

What a defensible record looks like

If a beneficial-ownership determination is ever questioned - by a regulator, an auditor, or internally - the record needs to show not just a conclusion but how it was reached: which register, what exact percentage, and if the chain didn't fully resolve, exactly why not. A vague "no beneficial owners identified" and a documented "register closed in this jurisdiction, stop reason X" are very different records to have to defend. See how Keizu determines a UBO for how that distinction is made concrete.

Related

AML, CDD and EDD: definitions

Where this obligation sits in the wider framework.

The 25% UBO threshold

The test that defines who counts.

Tools for MLROs

The practitioner's view of this obligation.

How Keizu determines a UBO

What a defensible determination actually requires.

See it work on a real company.

Search the registerExplore coverage