Beneficial ownership verification sits at the heart of any credible AML programme. It is also, consistently, one of the weakest points in how firms actually implement that programme. Regulatory action in the UK and internationally continues to identify the same failures, and those failures are not primarily technological or resource-related. They reflect a set of persistent conceptual and procedural errors that firms continue to make despite clear regulatory expectations and abundant published guidance.
Understanding why the problem persists matters as much as knowing what the right answer looks like, because firms that correct their procedures without understanding the underlying failure are likely to find those failures recurring in a different form.
Why the same firms keep failing
The most common failure mode is conflating verification with identification. Many compliance teams treat the retrieval of a Companies House filing or a self-declaration from a customer as verification of beneficial ownership. It is neither. Identifying a claimed ultimate beneficial owner (UBO) is the starting point; verification requires independent corroboration that the claimed ownership structure is accurate, current and not designed to obscure the true controlling interest.
A second persistent problem is threshold-based thinking. The regulatory threshold of 25% ownership as the trigger for UBO identification has been widely misread as a definitional rule rather than a minimum starting point. Firms that stop their analysis at the 25% threshold, and do not look beyond it at whether a person in fact exercises significant influence or control through mechanisms other than direct shareholding, are routinely missing the beneficial owner that matters. Complex structures involving nominees, discretionary trusts, chains of holding companies and contractual arrangements can obscure control entirely while sitting within the letter of a threshold-based approach.
A third failure is the treatment of UBO identification as a one-time exercise. Customer due diligence is an ongoing obligation, and UBO structures change. The amendment to the Money Laundering Regulations requiring review of persons with significant control (PSCs) as part of ongoing monitoring was introduced precisely because regulators recognised that static UBO identification at onboarding was not capturing changes in ownership and control during the life of a business relationship. Firms that maintain a UBO record from onboarding without a systematic trigger-and-review process are operating with a structural gap.
The corporate structure problem
Nominated or professional shareholders, complex intermediate holding structures, and cross-jurisdictional ownership chains are not unusual in commercial practice, and they are not inherently suspicious. However, they do require proportionate analytical effort to work through, and that effort is inconsistent across firms and even within firms.
The practical challenge for compliance teams is that the correct approach, which involves identifying the natural persons who ultimately own or control each layer of a corporate structure, requires time and judgement that varies significantly with the complexity of the structure. A flat structure with two shareholders is straightforward. A structure involving four intermediate holding companies in three jurisdictions, one of which is a trust administered by a professional trustee, is not, and cannot be treated by the same process as the first.
Firms that have not built this distinction into their CDD processes, with different procedures or escalation thresholds for complex structures, will consistently underperform on UBO identification for the cases where it matters most.
Practical steps that make a difference
The firms that perform well on UBO identification have generally done three things that their peers have not. They have trained their compliance teams and relationship managers specifically on what UBO verification means in practice, with worked examples covering common structure types, rather than relying on generic AML training that covers the regulatory obligation at a conceptual level without equipping staff to apply it.
They have built structured UBO verification into their file documentation requirements, so that every CDD file records not just who the claimed UBO is, but what evidence was obtained, what independent verification was performed, and what residual uncertainty remains. Files that contain only a name and a percentage shareholding without the underlying verification work are systematically insufficient and will not withstand regulatory scrutiny.
And they have established clear event-driven review triggers for UBO status, so that changes in corporate ownership, changes in the nature of the business relationship, and changes in risk profile generate an automatic prompt to revisit the UBO assessment rather than relying on periodic review cycles alone.
The Companies House identity verification regime now entering active enforcement under the Economic Crime and Corporate Transparency Act 2023 (ECCTA) will, over time, improve the reliability of Companies House data as a source. During the transition period, however, firms should not assume that Companies House records reflect current reality.