Corporate Intelligence (CORPINT): Intelligence Discipline Guide
Every company is a legal fiction held together by filings. Corporate intelligence reads those filings to establish who is actually in control.
Every company is a legal fiction held together by filings. Corporate intelligence reads those filings to establish who is actually in control.
What Corporate Intelligence is as a discipline
Corporate intelligence is the collection and analysis of information about legal entities: registration, ownership, control, directorships, group structure, licensing, litigation and commercial behaviour. It works from statutory registries, beneficial ownership disclosures, securities filings, court dockets, procurement and tender records, sanctions and enforcement lists, trademark and patent registers, and public commercial data. The objective is to establish what an entity is, who ultimately controls it, what it is connected to, and whether the picture presented to counterparties matches the documentary record.
Sub-methods include entity resolution across jurisdictions and transliterations, ownership graph construction up to ultimate beneficial owners, nominee and shell structure detection, and adverse-media and enforcement screening. Maturity ranges from single-registry lookups, through structured multi-jurisdiction collection, to maintained entity graphs with change monitoring on directors, ownership and status. It underpins due diligence, third-party risk management, sanctions compliance, fraud investigation and asset tracing.
Why it matters
Corporate intelligence answers who is behind an entity and what else they are behind. Contracts are signed with companies, but risk sits with people and structures. It exposes the shell layered between a supplier and a designated party, the director disqualified in another jurisdiction, the ownership change immediately preceding a fraud, and the shared registered address linking a dozen supposedly independent bidders. No other discipline reliably converts a company name into a control structure you can act on.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Registered entity data: incorporation date, status, jurisdiction, registered office, entity type and filing compliance history
- Director, officer and shareholder records over time, including appointments and resignations clustered around significant corporate events
- Beneficial ownership declarations identifying natural persons with significant control, and the specific gaps where none are declared
- Group structure reconstructed from filings: parents, subsidiaries, branches, holding vehicles and cross-border ownership chains
- Registered address reuse and corporate service provider patterns linking nominally unconnected entities to a single formation agent
- Charges, liens, security interests and insolvency filings showing who holds claims over the entity assets
- Litigation, regulatory enforcement, debarment, sanctions designations and adverse media touching the entity, its officers or owners
- Operational corroboration through trademarks, licences, tender awards, job postings and premises consistent or inconsistent with claimed scale
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OpenCorporates — Aggregated registry data across many jurisdictions with officer, address and cross-entity linkage
- Companies House (UK) — Free filings, officers, persons with significant control and charge registers with complete history
- SEC EDGAR — Ownership, control and related-party disclosure for US issuers, including beneficial ownership schedules and proxies
- GLEIF — Legal Entity Identifiers with validated direct and ultimate parent relationships across borders
- OFAC, EU and UK sanctions lists — Designated persons and entities with published ownership and control interpretation guidance
- OpenSanctions — Consolidated sanctions, politically exposed person and watchlist data with entity matching across sources
- OCCRP Aleph and ICIJ Offshore Leaks — Investigative datasets exposing offshore structures, nominee arrangements and intermediary relationships
- Court dockets and insolvency registers — Litigation history, judgments, winding-up petitions and administration proceedings by jurisdiction
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Fix the entity precisely — Resolve to a registration number and jurisdiction rather than a trading name, because name matching alone constantly returns the wrong company.
- Pull the primary record — Retrieve filings from the registry itself: officers, ownership, accounts, charges and status history, each with its filing date.
- Build the ownership graph — Follow shareholdings and control layers upward until you reach natural persons or an opaque jurisdiction, and record exactly where it stops.
- Detect structural signals — Test for nominee directors, mass registered addresses, formation-agent patterns and counterparties incorporated shortly before the transaction.
- Screen and corroborate — Run sanctions, enforcement, litigation and adverse-media checks against every entity and person in the graph, not only the named counterparty.
- Test the operating story — Compare claimed scale against premises, staffing, trademarks, tender awards and filed accounts. Shell entities rarely survive this comparison.
- Monitor for change — Watch for director changes, ownership transfers, address moves and filing defaults, which routinely precede a problem becoming visible.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
- Organized Crime
- Counterfeiting & IP Crime
- Art & Antiquities Trafficking
- Mining & Resource Crime
- Forced Labour & Modern Slavery
- Financial Crime
- Anti-Money Laundering
- Sanctions Evasion
- Economic Espionage
- Supply Chain Security
Operates on these data points
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
- HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Bank Account / IBAN — A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
Related disciplines
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Cryptocurrency Intelligence — Tracing Value on Public Ledgers
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Financial Intelligence — Following Value Through the Financial System
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
Inside the platform: where Corporate Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=CORPINT— Discipline hubsource-catalog.php?disc=CORPINT— Source catalogue filtered to this disciplinesearch.php— Company / Organization profileblockchain.php— Cryptocurrency Address profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Export STIX/MISP
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Fix the entity precisely is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Build the ownership graph turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Monitor for change feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Corporate Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence practitioners use corporate intelligence to establish who actually controls a supplier, a facility or a local partner. The work is registry-based: incorporation records, shareholding, directorships, group structure and licensing, tested for foreign ownership, control or influence. It feeds supply chain assurance, base support contracting, host nation partner vetting and industrial security decisions, and in operational contexts it supports understanding of who owns the port, the fuel depot or the telecommunications operator in an area of interest. Constraint: findings on individuals are personal data with legal protections, and adverse decisions on a contractor require an evidenced, disclosable basis rather than an analyst inference from a registry diagram.
🕵 National intelligence
National services practise corporate intelligence as structured open collection into ownership and control, feeding proliferation, sanctions evasion and strategic dependency requirements. The method is registry triangulation across jurisdictions, since the entity that appears clean in one register is usually documented differently in another. Analysts build ownership chains through nominee layers and offshore vehicles, then test them against procurement, shipping, trade and financial reporting. All-source fusion is what resolves the last layer, because beneficial ownership is frequently only established through sensitive collection or a partner service. Products separate registry fact from assessed control, and handling reflects that the registry layer is releasable while the resolution of the final beneficial owner often is not.
👮 Law enforcement
Investigators use corporate intelligence to establish legal personality, control and criminal liability. Registry documents are obtained as public records or under production order; nominee and formation agent records, bank mandates and trust deeds usually require warrants or mutual legal assistance. Everything is exhibited with retrieval dates and hashes, because registries amend documents in place. The analytic product is the corporate structure chart that shows who controlled the entity at the time of the offence, which is what supports charging a natural person rather than only the company. Corroborate registry data with signatures, addresses, telephone numbers and filings, since registry contents are self-declared and frequently false.
🔍 Private investigation and corporate security
Corporate practitioners are the heaviest users of this discipline, for pre-transaction diligence, counterparty screening, litigation asset tracing and integrity checks on partners and hires. Lawful sources are statutory registries, licensed aggregators, court records, procurement data, media and enquiries the subject consents to. A private actor may not obtain records by pretext or impersonation, may not access bank or tax records, may not run covert surveillance on directors, and must handle personal data on a documented lawful basis. Output is a structured entity profile with sourced findings, red flags graded by materiality, and an explicit statement of what could not be determined.
📰 Journalism and OSINT media
Journalists use corporate records as the backbone of ownership investigations, from hidden control of media outlets to offshore holdings of public officials. The verification standard is document-first: every ownership claim traced to a named filing with a date and, where possible, an image of the document. Corroborate identity carefully, because name matches across jurisdictions are unreliable and misidentifying a person with a common name is the most frequent and most damaging error in this field. Protect sources who supplied non-public records. Give named individuals and companies a specific right of reply with time to respond, and publish denials alongside the findings.
🌍 NGO, humanitarian and human rights
Accountability organisations use corporate intelligence to expose beneficial ownership behind land grabs, extractive concessions, arms brokering and procurement corruption. The practice is document-based and designed for onward use by regulators, courts and investigative partners, so completeness of sourcing matters more than narrative. Do-no-harm requires assessing whether publication endangers local researchers, whistleblowers or communities named in the documents, particularly where the beneficial owner is politically connected. Duty of care covers legal threats, which in this field are routine and well funded, so pre-publication legal review and document preservation in more than one jurisdiction are standard operating practice.
🎓 University and research
Researchers treat corporate registry data as a network dataset for studying ownership concentration, offshore structuring, sanctions evasion and the effectiveness of beneficial ownership transparency. Methodology must address entity resolution explicitly, since matching companies and officers across registries without a common identifier is the central technical problem and the main source of error. Prefer identifier-anchored linkage such as legal entity identifiers where available. Ethics review applies because officer records are personal data, and republication of bulk personal data from registries is restricted in several jurisdictions. Cite the registry, the extraction date and the snapshot used, because registries change continuously and retrospective reproduction is otherwise impossible.
Playbook: working Corporate Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Fix the subject entity precisely
Establish exactly which legal person you are investigating before collecting anything. Capture the registered name, the registration number, the jurisdiction and the registered address, and note trading names, former names and transliterations. Similar names across jurisdictions are the norm rather than the exception, and the whole investigation fails if the wrong entity is picked up at this stage. A good output is an entity identity record with the registration number and at least one corroborating identifier such as a legal entity identifier or a tax number. Stop when the entity can be unambiguously distinguished from every similarly named company.
Phase 2 — Pull the primary registry record
Retrieve the full filing history from the statutory registry rather than a summarised aggregator record: incorporation documents, annual returns, officer appointments and terminations, share allotments and transfers, charges and security, and any strike-off or insolvency actions. Record retrieval dates and hash the documents, since registries amend in place without version history. Note where the registry is self-declared and unverified, which is most of them. A good output is a complete document set with a manifest. Stop when the filing history is continuous with no unexplained gaps between filings.
Phase 3 — Build the ownership and control chain
Work upward from the subject through shareholders to the ultimate beneficial owner, and downward through subsidiaries. Record each link with the evidencing document and date, and mark where the chain passes through a jurisdiction with no public ownership disclosure, since that is where the chain will break. Distinguish legal ownership from control, which may sit with a golden share, a shareholder agreement, a debt instrument or a management contract. A good output is a dated ownership chart where every edge cites a document. Stop when you reach a natural person, a listed entity, or a documented opacity point.
Phase 4 — Resolve the people
Identify the natural persons behind the entity as individuals rather than as names. Use date of birth, nationality, address history, signature comparison and cross-jurisdiction appointment patterns to distinguish people who share a name. Identify professional nominees and formation agents by their appointment volume and their address clustering, since a director holding hundreds of appointments is providing a service rather than managing a business. A good output is a person record per individual with the discriminating evidence recorded. Stop when each named person is distinguished from same-name individuals or the ambiguity is explicitly flagged.
Phase 5 — Map the network around the entity
Expand from the entity to its address, its officers, its agents and its counterparties. Shared registered addresses, shared company secretaries, shared telephone numbers and shared auditors reveal groups that no filing declares. Treat mass-registration addresses correctly: a formation agent address links thousands of unrelated companies and proves nothing on its own. A good output is a network graph with edge types labelled by strength, distinguishing declared relationships from inferred ones. Stop expanding when new nodes stop changing the assessment rather than when the graph stops growing.
Phase 6 — Screen for risk and designation
Screen the entity, its owners, its officers and its close counterparties against sanctions lists, export control lists, politically exposed person data, debarment registers and law enforcement actions. Apply ownership and control rules properly: an entity may be caught by sanctions through aggregate ownership by designated persons even where no single holder is designated and the entity is not itself listed. Record match confidence and the basis for discounting near matches. A good output is a screening record with dispositions. Stop when every match is resolved as confirmed, discounted with a reason, or escalated to compliance.
Phase 7 — Test commercial substance
Determine whether the entity does anything. Compare filed accounts, employee numbers, premises, licences, website age, procurement awards, court appearances and trade records against the activity it claims. A company with substantial declared turnover, no employees, a serviced address and no operational footprint is a conduit, and that finding is often the whole point of the investigation. A good output is a substance assessment listing the indicators found and absent. Stop when the entity can be characterised as operating, dormant, or a probable conduit, with the evidence for that characterisation set out.
Phase 8 — Check litigation and enforcement history
Search court dockets, insolvency records, regulatory enforcement, employment tribunals and arbitration registers for the entity, its group and its officers. Litigation history is the most under-used corporate source, because pleadings frequently contain ownership, financial and relationship detail that appears in no filing. Track officers across their prior companies for a pattern of failed entities, disqualifications and repeat insolvency. A good output is a chronology of legal exposure with document references. Stop when the officer histories and entity histories are covered in each jurisdiction of operation.
Phase 9 — Corroborate across independent sources
Test every material finding against a source the subject does not control. Registry contents are self-declared, so corroborate addresses against property and tenancy records, officers against professional registers and media, activity against customs and procurement data, and financial claims against filed accounts and credit records. Where corroboration fails, that discrepancy is itself a finding. A good output is a corroboration table listing each material claim with its independent support. Stop when the findings that drive the conclusion each have at least one independent source or are flagged as uncorroborated.
Phase 10 — Grade findings and write the profile
Write the product as a structured entity profile: identity, structure, ownership and control, people, substance, risk findings and unresolved questions. Grade each finding by source reliability and materiality, and separate document fact from inference explicitly. State what could not be determined and why, because an honest opacity statement is more useful to a decision maker than a confident guess. A good output is a profile that supports a specific decision and survives legal review. Stop when a reviewer can trace every conclusion to a cited document without asking a question.
Phase 11 — Set monitoring and refresh
Corporate structures change deliberately to defeat point-in-time diligence, so set monitoring on the entity and its key people for new filings, officer changes, share transfers, charges, insolvency events, new designations and adverse media. Define the trigger events that require a full re-assessment rather than a note. Retain the original documents so a later change can be diffed against the baseline. A good output is a watch list with defined triggers and a revision log. Stop monitoring only when the relationship or decision the profile supported has formally ended.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Companies House | Open | United Kingdom statutory registry with filing history, officer records, charges and persons with significant control declarations. | Primary registry source for United Kingdom entities including document images and continuous filing history. |
| SEC EDGAR | Open | Filings by issuers registered in the United States including ownership disclosures, material event reports and annual reports. | Establishes control, related party relationships and group structure for United States listed entities. |
| OpenCorporates | Registration | Aggregated company records from many jurisdictions normalised into a common schema with officer and filing data. | Rapid cross-jurisdiction search for same-name entities and shared officers when the jurisdiction is unknown. |
| GLEIF | Open | Global register of legal entity identifiers including direct and ultimate parent relationship records verified against source documents. | Provides the only widely adopted global identifier for anchoring entity resolution across registries. |
| OpenSanctions | Open | Consolidated sanctions, politically exposed person, debarment and enforcement datasets with cross-source entity resolution. | Screens the entity, owners and officers against designation and enforcement data in a single query. |
| OCCRP Aleph | Registration | Searchable archive combining leaks, registries, court records, procurement data and gazettes assembled for investigative use. | Finds documents and relationships that statutory registries omit, particularly in opaque jurisdictions. |
| OFAC sanctions programmes | Open | United States sanctions designations, general licences and guidance including the fifty percent ownership rule. | Determines whether an undesignated entity is nonetheless blocked through aggregate ownership by designated persons. |
| European Union sanctions and trade policy | Open | European legal instruments, consolidated designation lists and guidance on restrictive measures. | Establishes European designation status and ownership and control interpretation for entities in scope. |
| Bureau of Industry and Security | Open | United States export control lists including the entity list and denied persons list with licensing requirements. | Identifies export control exposure attaching to an entity or its parent regardless of sanctions status. |
| Transparency International | Open | Research and indices on corruption risk, beneficial ownership transparency and procurement integrity by country. | Supplies the jurisdiction risk baseline used when weighting opacity findings in an ownership chain. |
| World Bank debarment data | Open | Listings of firms and individuals debarred or cross-debarred from participating in development finance contracts. | Screens contractors and their affiliates for prior findings of fraud or collusion in procurement. |
| UN Comtrade | Registration | Official bilateral merchandise trade statistics by commodity code as reported by national customs authorities. | Tests whether an entity claimed trading activity is consistent with reported flows in the relevant corridor. |
| Financial Action Task Force | Open | Standard setter publishing recommendations, mutual evaluations and jurisdiction listings on money laundering and beneficial ownership. | Frames the beneficial ownership standard against which registry disclosure quality in a jurisdiction is assessed. |
| Global Investigative Journalism Network | Open | Practitioner resource collection covering corporate research methods and jurisdiction-specific registry guides. | Locates registry access routes and research techniques for jurisdictions outside routine coverage. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Corporate Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Registry document retrieval and archiving scripts — Pull and hash filing images at scale with retrieval timestamps. Limitation: many registries rate limit, charge per document or block automation.
- Entity resolution and record linkage libraries — Match companies and officers across registries lacking common identifiers. Limitation: transliteration and name variation drive both false merges and missed links.
- Graph analysis platforms — Model ownership, officer and address relationships and detect clusters. Limitation: mass-registration addresses create dense false communities unless weighted down.
- Sanctions and adverse media screening engines — Match entities and people against designation and enforcement datasets with fuzzy logic. Limitation: tuning trades false positives against missed near matches, and both are costly.
- Court docket and gazette search systems — Locate litigation, insolvency and official notices naming the entity or its officers. Limitation: coverage and machine readability vary enormously by jurisdiction.
- Document management with hashing and provenance — Holds retrieved filings with retrieval time and integrity records for evidential use. Limitation: only as good as the discipline of the analysts using it.
- Structured note-taking and chronology tools — Maintain the dated ownership chain with a citation per edge. Limitation: manual effort, and the chart drifts from the evidence unless rebuilt from sources.
- Translation and transliteration tooling — Handles non-Latin registry data and name variants during cross-border search. Limitation: machine transliteration produces variants that miss the registry canonical spelling.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Registry data is self-declared and frequently false. The registry proves what was filed, not what is true, and the analytic value lies in comparing the declaration against independent evidence of address, activity, employment and trade.
- A director with hundreds of appointments is a service, not a manager. Identify professional nominees and formation agents early, because treating them as principals sends the whole investigation into a layer that carries no information.
- Distinguish ownership from control at every link. Control can sit in a shareholder agreement, a loan covenant, a golden share or a management contract, none of which appear in the shareholding record you are diagramming.
- Fix identity before building structure. Misidentifying a person with a common name is the most frequent and most damaging error in corporate intelligence, and date of birth plus nationality plus appointment pattern is the minimum discriminating set.
- Absence of substance is a positive finding. Declared turnover with no employees, a serviced address, no premises and no procurement or trade footprint characterises a conduit, and that characterisation is usually the point of the work.
- Read the litigation, not just the filings. Pleadings, insolvency reports and arbitration awards routinely disclose ownership, financing and relationship detail that no statutory filing will ever contain.
- Apply ownership and control sanctions rules by aggregation. An entity with no designated shareholder above the threshold individually may still be blocked when designated holdings are combined, and screening engines frequently miss this.
- Hash and date every document at retrieval. Registries amend in place with no version history, and a superseded filing you preserved is often the strongest single item in the eventual evidence pack.
- Record where the chain breaks and why. A precise opacity statement naming the jurisdiction and the missing disclosure is far more useful to a decision maker than an inferred beneficial owner presented with false confidence.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Corporate Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of investigations that reach a named natural person or a documented opacity point, rather than terminating in an unexplained gap.
- Rate of entity misidentification detected at review, which should approach zero as identity fixing discipline improves.
- Median time from a triggering event, such as a new officer appointment or designation, to a completed reassessment of a monitored entity.
- Share of material findings supported by at least one source independent of the entity own declarations.
- Number of adverse findings later overturned on challenge by the subject, tracked with the reason for each.
- Percentage of screening matches resolved with a documented disposition rather than left pending at case closure.
- Proportion of decisions taken on the profile that were subsequently reversed because of a structural change the monitoring failed to detect.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Name-only matching across jurisdictions and transliterations, which merges unrelated entities and misses the one that actually matters
- Stopping at the registered shareholder when that shareholder is itself a corporate vehicle, so the real controller is never identified
- Treating aggregator snapshots as current, when registry data lags and aggregation lags further, hiding the most recent filings
- Assuming beneficial ownership registers are complete or verified, when many entries are self-declared and never audited
- Reading an offshore structure as proof of wrongdoing rather than as a fact requiring an explanation you should go and obtain
- Ignoring aggregation rules under which combined holdings by designated parties make an entity itself effectively sanctioned
Legal and ethical considerations
Registry data is public, but officer and shareholder records identify individuals and are personal data carrying purpose-limitation and retention obligations. Several jurisdictions have restricted public beneficial ownership access following court rulings, so access may require demonstrated legitimate interest. Due-diligence findings must be handled confidentially and shared only with a lawful basis. Adverse conclusions about named individuals carry defamation risk and should be evidenced with source and date. Sanctions screening itself carries statutory record-keeping duties that must be met independently of the investigation.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Corporate Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 data points, 10 mission domains, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
How do I get past a nominee shareholder?
Lawfully, by triangulation rather than by demanding the answer. Look for the same nominee or agent appearing across other entities and map that portfolio, since the pattern of who they serve is informative. Look for control instruments outside the shareholding record: charges, loan agreements filed as security, shareholder agreements referenced in accounts, and management contracts. Check other jurisdictions where the group files, since disclosure obligations differ. Check litigation, where beneficial ownership is often pleaded. Where none of this resolves it, record a documented opacity point naming the jurisdiction and the missing disclosure, and refer to counsel or law enforcement if compulsion is needed.
Are beneficial ownership registers reliable?
Variable and generally unverified. Most registers accept self-declaration without checking, several have been restricted or closed following litigation over privacy, and thresholds differ so a holder below the local threshold discloses nothing. Treat a register entry as a claim that carries some evidential weight because it was made under a legal duty, not as established fact. The most useful signals are often negative: an entity declaring no person with significant control, or declaring a nominee-like individual, tells you something. Always corroborate against filings, litigation and financial records rather than concluding from the register alone.
How far should a network expansion go?
Until new nodes stop changing the assessment. Expansion by shared address or shared agent grows without limit and produces graphs that look impressive and mean nothing, especially where the address is a formation agent serving thousands of companies. Weight edges by strength: a shared controlling shareholder is strong, a shared director is moderate, a shared registered address at a mass-registration site is close to worthless on its own. Set the stopping rule before you start, and review whether each added layer changed a conclusion. If it did not, the expansion was decoration.
What may a private investigator not do here?
Do not use pretext or impersonation to obtain records from registries, banks, utilities or the entity itself. Do not access bank, tax or telephone records, or commission anyone who will. Do not conduct covert surveillance on directors or their families. Do not use data you know or suspect was unlawfully obtained. Do process personal data on a documented lawful basis with a retention period, since officer information is personal data and diligence reports are routinely disclosed in later litigation. Where the evidence needed requires compulsion, the correct step is referral to counsel or law enforcement, not creative sourcing.
How do I handle registries that amend documents in place?
Treat retrieval as an evidential act. Download the document image rather than the rendered summary, record the exact retrieval time, hash the file and store it unaltered. Re-query on a schedule and diff against your stored copy so amendments are detected rather than discovered by an opponent. When an amendment appears, preserve both versions and treat the change itself as a finding, since retrospective correction of an officer or shareholding record around the time of an event is significant. Never cite a registry document without stating when you retrieved it.
Company records show nothing unusual. Is that a clean result?
Only if you tested for absence as well as presence. A clean registry record in a jurisdiction with no ownership disclosure, no accounts filing and no verification means you have learned almost nothing, and reporting that as clean is misleading. Convert it into a coverage statement: what you checked, what that jurisdiction actually discloses, and what therefore remains unknown. Then apply the substance test, since a conduit is usually clean on paper by design. The finding that matters is often that a materially sized business has no observable operational footprint anywhere.
How do I decide whether sanctions ownership rules are triggered?
Aggregate the holdings of designated persons rather than looking at each separately, and check the threshold applicable to the regime in question. Also assess control independently of ownership, since several regimes catch entities controlled by a designated person regardless of shareholding percentage. Trace through intermediate entities, because ownership is calculated through the chain. Where the analysis is finely balanced or the structure is opaque, the decision belongs to sanctions compliance and counsel, not to the analyst. Document the calculation and the ownership evidence used, since supervisors will ask for it.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- FATF Recommendations 24 and 25 on transparency of beneficial ownership of legal persons and arrangements, which set the international disclosure standard.
- The EU anti-money laundering directives and the UK Money Laundering Regulations 2017, which govern customer due diligence and beneficial ownership verification duties.
- OFAC fifty percent ownership guidance, which governs when an undesignated entity is blocked by aggregate designated ownership.
- ISO 17442, which defines the legal entity identifier used to anchor entity resolution across jurisdictions.
- The UK Data Protection Act 2018 and the EU General Data Protection Regulation, which govern processing of officer and beneficial owner personal data.
- The UN Convention against Corruption, which governs international cooperation on asset recovery and corporate liability for corruption.
- ISO/IEC 27037 on digital evidence handling, which governs preservation of retrieved registry documents for evidential use.
- ICD 203 analytic standards, which govern sourcing transparency and expression of confidence in assessed entity profiles.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Companies House register and filing history — UK Companies House. Statutory United Kingdom registry with document images and control declarations
- EDGAR filings archive — US Securities and Exchange Commission. Ownership, control and material event disclosures for United States issuers
- Global LEI index — Global Legal Entity Identifier Foundation. Verified global entity identifiers with parent relationship records
- OpenSanctions consolidated datasets — OpenSanctions. Sanctions, politically exposed person and debarment data with entity resolution
- Aleph investigative data archive — OCCRP. Searchable archive of registries, leaks, court records and procurement data
- Sanctions programmes and ownership guidance — US Office of Foreign Assets Control. Designation lists and the guidance governing ownership-based blocking
- FATF Recommendations — Financial Action Task Force. International standards on beneficial ownership transparency and due diligence
- Corruption research and indices — Transparency International. Jurisdiction-level corruption and ownership transparency assessments
- Entity List and export control listings — US Bureau of Industry and Security. Export control designations attaching licensing requirements to named entities
- Investigative research guides — Global Investigative Journalism Network. Practitioner guides to corporate registries and cross-border research methods
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: resolves entities across registries, builds ownership graphs and monitors changes in control. Explore the platform, or browse the rest of the library by following any tag above.