Company / Organization: Data Point Intelligence Guide
Companies are how money, liability and control get organised. Follow the entity and you find the people who preferred not to be named.
Companies are how money, liability and control get organised. Follow the entity and you find the people who preferred not to be named.
Understanding the Company / Organization as an intelligence artifact
A company data point is a legal entity registered with a state authority: a corporation, LLC, partnership, foundation or NGO. Its atomic identity is the registration number in a named jurisdiction, not the trading name, because names are duplicated across registries and change freely while registration numbers do not. Around that key sits the entity's status, incorporation date, registered address, officers, shareholders, filing history and any successor or predecessor entities created through merger, conversion or migration.
Registry quality varies enormously. Some jurisdictions publish full beneficial ownership, dated officer appointments and machine-readable accounts. Others publish only a name and a status, and some publish nothing at all. Nominee directors, corporate officers registered in other jurisdictions and formation agents acting for thousands of entities are deliberate opacity layers. The registered address is frequently a service provider, which makes address clustering a productive rather than a disappointing finding.
Why it matters
Entity research links people to assets, contracts, sanctions exposure and criminal proceeds. It is the backbone of due diligence, supply chain risk and financial crime investigation. A company record connects officers to other directorships, addresses to networks of shells, and filings to auditors, lenders and counterparties. In cyber investigations it also grounds infrastructure: hosting providers, registrars and front companies used to procure services are all legal entities with a public paper trail.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Incorporation date relative to the events under investigation, where an entity created shortly before a transaction is a strong flag.
- Officer and shareholder overlap with other entities, which reveals the controlling network behind superficially unrelated companies.
- Registered address reuse at scale, distinguishing genuine premises from formation agent and virtual office clusters.
- Status changes such as dissolution, strike-off, administration or restoration, which mark stress, abandonment or deliberate liquidation.
- Rapid succession of name changes, which often precedes reputational escape or rebranding after enforcement action.
- Jurisdiction choice and any redomiciliation, which indicates deliberate selection of secrecy, tax or enforcement characteristics.
- Filing regularity and late filing patterns, which are a cheap and reliable proxy for whether an entity is genuinely operating.
- Cross-border ownership chains terminating in secrecy jurisdictions, which mark the point where beneficial ownership becomes deliberately obscured.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OpenCorporates — Aggregated company records across many jurisdictions with officer data and cross-registry linking
- Companies House (UK) — Free full registry with officers, persons of significant control, accounts and complete filing history
- SEC EDGAR — US registrant filings including ownership, subsidiaries, auditors, related party transactions and material events
- GLEIF — Legal Entity Identifier records with verified legal name, address and parent relationship data
- OFAC SDN and EU consolidated lists — Designated entities with aliases, addresses and ownership linkage for sanctions screening
- OCCRP Aleph — Cross-referenced corporate, leak and procurement datasets aimed at investigative research
- ICIJ Offshore Leaks Database — Offshore entity, officer and intermediary records from major leak investigations
- National business registers — Primary source records with authoritative status, filings and officer detail per jurisdiction
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Pin the entity by registration number — Resolve the name to a jurisdiction and registration number before doing anything else, since names collide across and within registries.
- Pull the primary record — Go to the national registry rather than relying solely on aggregators, which can lag on status changes and officer updates.
- Map officers and ownership — Extract every officer, shareholder and beneficial owner with appointment and resignation dates, building a dated control timeline.
- Expand the network — Pivot on each officer, address and agent to enumerate connected entities, then look for the clusters that repeat.
- Screen for exposure — Check the entity, its officers and its owners against sanctions, PEP, enforcement and litigation sources in each relevant jurisdiction.
- Read the filings — Work through accounts, charges, annual returns and material disclosures for counterparties, lenders, auditors and undisclosed relationships.
- Corroborate real activity — Test whether the entity actually operates using premises, employees, web presence, procurement records and trade data.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Collected by these disciplines
- Geospatial Intelligence — Intelligence Derived from Place
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Criminal Intelligence — Intelligence Supporting Criminal Investigation
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
- Logistics Intelligence — Cargo, Freight, and Physical Movement
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Financial Intelligence — Following Value Through the Financial System
- Environmental Intelligence — Environmental Conditions, Damage, and Crime
Investigated in these domains
- Emerging Technology & AI Security
- Organized Crime
- Weapons Trafficking
- Wildlife Trafficking
- Counterfeiting & IP Crime
- Art & Antiquities Trafficking
- Mining & Resource Crime
- Forced Labour & Modern Slavery
- Financial Crime
- Anti-Money Laundering
Pivots to these data points
- Patent — An intellectual property filing granting invention rights.
- Legal Entity Identifier — A 20-character global identifier for a legal entity participating in financial transactions.
- Corporate Filing — A regulatory or corporate filing (SEC, Companies House, court).
- Tax ID / VAT Number — A jurisdiction-issued tax registration number for a person or entity.
Inside the platform: where Company / Organization lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
search.php— Company / Organization profiledatapoint.php?dp=dp_company— Data point hubdomain.php?d=emergingtech— Emerging Technology & AI Security dashboarddomain.php?d=org— Organized Crime dashboarddomain.php?d=weapons— Weapons Trafficking dashboarddomain.php?d=wildlife— Wildlife Trafficking dashboardcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Enrichment Runner
- Enrichment → Local
- Correlate Infrastructure
- Export STIX/MISP
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Pin the entity by registration number is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Map officers and ownership turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Corroborate real activity feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Company / Organization
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence uses entity research for procurement integrity, supply chain assurance and force protection. Before a contract is let, the question is who actually owns and controls the supplier, whether any layer of the ownership chain sits in an adversary jurisdiction or under sanction, and whether the entity has the substance to deliver. In deployed environments, local contractors are vetted through registry records, ownership and litigation history before they are given base access or logistics roles. Products feed contracting officer decisions, supply chain risk registers and counter-intelligence referrals. Constraints are that registry data varies enormously in quality across jurisdictions and that a clean record in a weak registry is an absence of evidence rather than evidence of absence.
🕵 National intelligence
For national intelligence, corporate structures are the mechanism through which sanctioned actors, proliferation networks and intelligence services acquire technology, move money and establish presence. Requirements-driven work traces ownership chains from a front company to a beneficial owner, identifies formation agents and nominee networks that service multiple targets, and monitors incorporation activity in jurisdictions of interest. Registry data is open source, which means findings can usually be shared at low classification while the reason for the interest cannot. Fusion combines registry records with trade data, financial reporting, travel and human sources. Entity resolution across transliterations and jurisdictions is the recurring technical problem, and identifiers rather than names are the solution.
👮 Law enforcement
In law enforcement, company records are documentary evidence with a custodian who can certify them. Registration numbers, dated officer appointments, filed accounts and charge registrations establish who controlled an entity at a given moment, which is the backbone of fraud, money laundering and sanctions evasion cases. Certified copies obtained through the registry's formal process, or through mutual legal assistance for foreign registries, carry evidential weight that a screenshot does not. Officer records also give identity leads: dates of birth, service addresses and correspondence details. Charging decisions on false filing and fraudulent trading rest directly on the filings themselves, so preserve the document, its accession detail and retrieval date.
🔍 Private investigation and corporate security
Entity research is the core of private due diligence, litigation support and asset tracing. A private actor may collect everything a registry publishes, may aggregate it, and may draw conclusions from clustering of addresses, officers and agents. What a private actor may not do is misrepresent itself to obtain non-public records, pretext a registry or a company employee, access data behind an authorisation gate it does not hold, or publish assertions about individuals that the documents do not support. Respect registry licensing for bulk extraction and redistribution. Retain the source records and retrieval dates, because in due diligence the value is in being able to substantiate every assertion later.
📰 Journalism and OSINT media
Corporate records give investigative journalism its documentary spine, because a registry filing is a dated statement attributable to a named person with legal consequences for inaccuracy. Verification means going to the primary registry rather than relying solely on aggregators, which can lag on status and officer changes. Distinguish carefully between what the record says and what you infer from it: a shared registered address usually means a shared formation agent, not a conspiracy. Officer records contain personal data including dates of birth and sometimes home addresses, so redact before publication. Approach named individuals and companies for comment with the specific documents rather than the conclusion.
🌍 NGO, humanitarian and human rights
Human rights, anti-corruption and environmental organisations use company data to connect harms to the entities and people responsible: which company holds the concession, who owns it, which financier is behind it and which jurisdiction shields it. Registry evidence is durable, citable and safe to hold, which makes it ideal for accountability documentation compared with material that endangers sources. Where research names individuals, apply the same care a publisher would: substantiate from documents, redact personal data that is not necessary, and assess the risk to local staff and partners of publishing findings about powerful local actors. Beneficial ownership registers, where they remain public, are the highest-value source.
🎓 University and research
Corporate registry data supports research on ownership networks, tax avoidance, illicit finance, market structure and state capture. Reproducibility depends on citing registration numbers and jurisdictions rather than names, and on pinning the retrieval date, since registers are live and officer histories change. Bulk access is governed by each registry's licence, and several permit research use under conditions that must be documented in the data management plan. Entity resolution across jurisdictions is a methodological contribution in its own right and should be published with its error rates. Where officer-level personal data is analysed, ethics approval and a minimisation plan are usually required even though the source is public.
Playbook: working Company / Organization end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Pin the entity by jurisdiction and number
Resolve the trading name to a registration number in a named jurisdiction before any other step, because names collide within and across registries, change freely, and are used by unrelated entities in different countries. A good output is a canonical entity record keyed on jurisdiction plus registration number with all observed name variants attached. Stop and widen the search if you cannot achieve that resolution, since every downstream finding attributed to the wrong entity is worse than no finding at all.
Phase 2 — Retrieve the primary registry record
Go to the national registry rather than relying solely on aggregators, which lag on status changes, officer updates and strike-off proceedings, and which sometimes retain records the registry has corrected. Capture status, incorporation date, registered address, legal form, and any predecessor or successor entity. A good output is a dated primary record with the retrieval timestamp and the URL or accession reference. Note explicitly where the registry publishes nothing, because a thin record is a jurisdictional characteristic rather than a finding about the company.
Phase 3 — Map officers and ownership with dates
Extract every officer, shareholder, person of significant control and beneficial owner with appointment and resignation dates, building a control timeline rather than a snapshot. Who controlled the entity at the moment of the transaction under investigation is almost always the operative question, and current officers frequently were not there. A good output is a dated control chart. Record where ownership is held by another corporate entity, which is a pointer to the next layer rather than an answer.
Phase 4 — Walk the ownership chain upward
Follow corporate shareholders through each jurisdiction until you reach natural persons or a registry that publishes nothing. Record each hop with its jurisdiction, registration number and the evidence used, and mark clearly where the chain terminates in opacity rather than in an owner. Cross-check against LEI relationship data and group structures disclosed in financial filings. A good output is a chain diagram in which every edge is sourced and every unresolved terminus is labelled as unresolved rather than quietly dropped.
Phase 5 — Expand the network laterally
Pivot on each officer, address, formation agent and email or phone contact to enumerate connected entities, then look for the clusters that repeat. A registered address serving thousands of companies identifies a formation agent, which is normal; the same three individuals appearing across a specific set of entities is a network. A good output is a network with each edge labelled by the shared attribute and its discriminating power, so a reader can distinguish a service provider artefact from a genuine relationship.
Phase 6 — Screen the whole structure for exposure
Check the entity, every officer, every owner and every parent and sibling in the resolved structure against sanctions, PEP, enforcement, debarment and litigation sources in each relevant jurisdiction. Exposure frequently sits at a parent or an affiliate rather than at the entity in front of you, and ownership thresholds in sanctions regimes mean indirect control can be decisive. A good output is a screening record with list versions and dates. Route any hit to compliance and counsel immediately rather than continuing the analysis.
Phase 7 — Read the filings for substance
Work through accounts, annual returns, charge and security registrations, auditor appointments and resignations, and material event disclosures for counterparties, lenders, related party transactions and undisclosed relationships. Auditor resignations, late filings and repeated charge registrations against a small balance sheet are diagnostic. A good output is a filing timeline with the substantive findings extracted per document. Prioritise by filing type rather than reading annual reports end to end, since each type has a defined trigger.
Phase 8 — Test whether the entity actually operates
Look for premises, employees, web presence and its age, procurement and tender records, import and export data, tax registration status, professional licences and physical evidence such as street imagery. A company with a large stated turnover, one officer, a formation agent address and no digital footprint is a finding. A good output is a substance assessment with each indicator and its source, expressed as an evidenced judgement rather than an assertion that the entity is a shell.
Phase 9 — Check litigation and insolvency
Search court dockets, insolvency registers, judgment databases and regulatory enforcement in each relevant jurisdiction, because litigation filings frequently expose contracts, relationships and communications that appear in no registry. Insolvency proceedings produce administrator reports with detailed asset and creditor analysis. A good output is a litigation record with the case reference, status and what it establishes. Mark allegations from pleadings clearly as untested claims rather than as findings.
Phase 10 — Reconcile identifiers across systems
Bind the entity to its LEI, tax registration, stock ticker, procurement supplier identifiers and any sector licence numbers, so that data from financial, trade and regulatory systems can be joined deterministically rather than by name. This is the step that makes a research file reusable. A good output is an identifier table with the source and validation status for each entry. Validate check digits offline where the scheme provides them, which catches transcription errors early.
Phase 11 — Assess and state confidence
For each conclusion, state what the documents show, what you infer and how strongly. Registry data supports strong claims about registration facts and much weaker claims about control in practice, particularly where nominees are used. A good output distinguishes the entity is registered at this address, this address is used by a formation agent serving many entities, and this individual controls the company, which are three very different assertions requiring three different evidential bases.
Phase 12 — Preserve, cite and refresh
Retain the source documents with accession references and retrieval dates, because registers are live and a record you relied on may change or be corrected. Cite by jurisdiction and registration number rather than by name. Set a refresh cadence for any entity in an ongoing relationship, since status changes, new charges and officer resignations are the early signals. A good output is a research file where every assertion can be re-substantiated from retained documents years later without re-running the research.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OpenCorporates | Registration | Aggregated company records across many jurisdictions with officer data, cross-registry linking and structured identifiers. | Fast cross-jurisdiction discovery and officer pivoting before going to primary registries for confirmation. |
| Companies House | Open | UK registry publishing officers, persons of significant control, accounts, charges and the complete filing history free of charge. | Primary source for UK entities, including dated officer changes and beneficial ownership declarations. |
| SEC EDGAR | Open | US registrant filings including subsidiary lists, ownership disclosures, auditors, related party transactions and material events. | Establishes group structure and related party relationships for US-listed entities and their subsidiaries. |
| GLEIF | Open | Open Legal Entity Identifier reference data with verified legal names, addresses and direct and ultimate parent relationships. | Provides machine-readable, openly licensed group structure data to corroborate an ownership chain. |
| OCCRP Aleph | Registration | Aggregated registries, leaks, sanctions lists and documents with entity extraction and cross-dataset search. | Finds an entity or officer across many datasets at once, including material absent from commercial aggregators. |
| ICIJ Offshore Leaks Database | Open | Structured records from multiple offshore leaks naming entities, officers, intermediaries and registered addresses. | Tests whether an entity or its officers appear in offshore structures with named intermediaries. |
| OFAC Sanctions List Search | Open | US designations with aliases, addresses, identifiers and ownership linkage across entities and individuals. | Mandatory screening of the entity, its officers and every layer of the resolved ownership structure. |
| EU and UK consolidated sanctions lists | Open | European and UK designations with entity identifiers, addresses and ownership and control statements. | Jurisdiction-specific screening, since designations and ownership thresholds differ between regimes. |
| CourtListener and RECAP | Open | US federal and state dockets and documents, including filings purchased from PACER and made freely available. | Surfaces litigation exposing contracts, relationships and allegations absent from registry records. |
| Bundesanzeiger | Open | German federal gazette publishing company accounts, corporate notices and statutory announcements. | Primary source for German entity accounts and corporate events, which aggregators cover unevenly. |
| EU Business Registers interconnection | Open | European portal linking national business registers with basic company information across member states. | Identifies the correct national registry and basic status for EU entities before deeper research. |
| EU VIES | Open | European Commission service validating VAT registration numbers and returning the registered name and address. | Independent confirmation that a claimed EU business registration is currently active and matches the entity. |
| System for Award Management | Registration | US federal contractor registration and exclusion records including entity identifiers and debarment status. | Establishes government contracting status and whether an entity is excluded from federal awards. |
| Open Ownership register | Open | Aggregated beneficial ownership data from multiple jurisdictions published in a standard structured format. | Cross-jurisdiction beneficial ownership research where individual national registers are hard to query. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Company / Organization. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Registry APIs — Programmatic access to primary company data with structured filing history. Limitation: coverage and field richness vary enormously between jurisdictions.
- OpenCorporates — Cross-jurisdiction search and officer pivoting at scale. Limitation: derived from scraping, so status changes can lag the primary registry.
- Aleph — Cross-dataset entity search including leaks, registries and sanctions data. Limitation: dataset coverage is uneven and provenance must be checked per source.
- Graph analysis platform — Visualises officer, address and ownership networks to surface repeating clusters. Limitation: visually compelling clusters are frequently formation agent artefacts.
- Sanctions screening engine — Matches entities and individuals against designation lists with versioned snapshots. Limitation: transliteration and alias handling drives both false positives and misses.
- XBRL financial extraction — Parses machine-readable accounts for structured financial analysis across filings. Limitation: tagging quality varies and small entity accounts are often unstructured.
- Document OCR and search — Makes scanned filings and court documents searchable across a large corpus. Limitation: OCR accuracy on poor scans determines whether anything is found at all.
- Entity resolution tooling — Deduplicates entities across datasets using identifiers plus fuzzy name and address matching. Limitation: confident false merges are more damaging than misses.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Enrichment Runner — Walks the indicator set through a chosen provider in time-boxed, cursor-based batches that resume rather than restart.
- Enrichment → Local — Materialises enrichment into the local store so dashboards render from your own database instead of a live third-party call.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Names are not identity. Resolve to jurisdiction plus registration number before anything else, because a name-based conclusion attached to the wrong entity is worse than no conclusion, and it will survive in derived reports long after the error is found.
- Dates of appointment and resignation are the analytic content of an officer record. Who controlled the entity at the moment of the transaction is the operative question, and the current officer list frequently has no overlap with the people who were there.
- A shared registered address usually identifies a formation agent, not a conspiracy. That is still useful, because agents cluster their clients and the agent itself becomes a pivot, but a network diagram built on address alone will be dominated by service provider artefacts.
- A thin registry record is a jurisdictional characteristic, not a finding about the company. State what the registry publishes and what it does not, because readers routinely interpret an empty officer field as concealment when it simply reflects local law.
- Sanctions exposure frequently sits at a parent or a sibling rather than at the entity in front of you, and ownership and control thresholds mean indirect holdings can be decisive. Screen the whole resolved structure, not the counterparty name.
- Auditor resignations, repeated late filings, sudden changes of registered office and a pattern of charge registrations against a small balance sheet are the highest-yield signals in filing history, and they are visible without reading a single set of accounts in full.
- Test substance rather than asserting shell status. Premises, employees, procurement records, trade data, licences and the age of the digital footprint are evidence; a formation agent address alone is not, since a great many legitimate businesses use one.
- Registers are live and your evidence is not. Retain the retrieved document with its accession reference and date, because officer histories are amended, filings are corrected and companies are dissolved, and an unsupported assertion from a changed record cannot be defended.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Company / Organization is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of entity research files keyed on jurisdiction plus registration number rather than on name, which determines whether findings can be safely reused.
- Percentage of ownership chains resolved to natural persons, with unresolved termini explicitly labelled. The unresolved rate is a meaningful measure of jurisdictional opacity in your portfolio.
- Screening coverage across the full resolved structure rather than the immediate counterparty, measured as entities screened per relationship onboarded.
- Time from a material registry event, such as an officer change or a charge registration at a key supplier, to internal awareness. Long lags mean monitoring is nominal.
- Proportion of assertions in delivered due diligence reports supported by a retained source document with a retrieval date, tested by sampling.
- Rate at which findings are later corrected because of entity misidentification, tracked as a quality measure rather than suppressed as an embarrassment.
- Refresh completion for entities in ongoing relationships against the defined cadence, since a clean report ages faster than most risk registers assume.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Identical or near-identical names across jurisdictions cause misattribution, which is the single most common error in entity research.
- Aggregator data is a periodic snapshot and can be materially out of date on status, officers and ownership.
- A shared registered address usually indicates a formation agent rather than a genuine relationship between the tenants.
- Absence of adverse information in low-transparency jurisdictions is not evidence of clean operation, only of limited disclosure.
- Nominee directors and corporate officers deliberately obscure control, so officer lists can be entirely uninformative about real ownership.
- Dissolved entities disappear from some registry interfaces while remaining legally and evidentially significant to the investigation.
Legal and ethical considerations
Corporate registry data is public and lawful to collect, but officer records contain personal data such as names, dates of birth and addresses, which remain subject to data protection rules including purpose limitation and retention. Respect each registry's licensing and reuse terms, particularly for bulk extraction and redistribution. Where findings feed due diligence or adverse media conclusions about named individuals, retain the source records and dates so any assertion can be substantiated, and avoid publishing inferences that the underlying documents do not support.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Company / Organization, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 intelligence disciplines, 10 mission domains, 4 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Is a shared registered address evidence of a shell network?
Usually not by itself. Formation agents, accountants and company service providers register thousands of legitimate companies at their own address, and virtual office services are entirely lawful. What makes an address analytically interesting is the combination: a small, specific set of entities sharing an address plus overlapping officers, coordinated incorporation dates, similar naming patterns and common banking or trading counterparties. Report the address as a pivot into the agent's client base rather than as a finding about the companies, and be explicit in writing about which interpretation the evidence supports.
Should I trust an aggregator or go to the primary registry?
Use aggregators for discovery and primary registries for confirmation. Aggregators are indispensable for cross-jurisdiction search, officer pivoting and finding entities you did not know existed, but they are derived from scraping and can lag on status changes, strike-off proceedings and officer updates, and they occasionally retain records the registry has since corrected. Any assertion that will appear in a report, a filing or a court document should be substantiated from the primary record with a retrieval date. Cite both, and note where they disagree, since divergence is itself sometimes the finding.
How do I handle a jurisdiction that publishes almost nothing?
Say so explicitly, and pivot to the evidence that exists elsewhere. Where a registry publishes only a name and a status, the entity's relationships still surface in counterparty filings, litigation, trade and customs data, procurement records, financial regulator disclosures, property registers, leaked corporate corpora and the LEI relationship data if it participates in financial markets. Absence of information in a weak registry is not evidence about the company. Frame the conclusion around what could and could not be established, because a report that implies concealment from jurisdictional opacity is not defensible.
What does beneficial ownership data actually tell me?
It tells you who the entity declared as its beneficial owners, subject to the declaration thresholds and verification standards of that jurisdiction, which vary from meaningful verification to pure self-declaration with no checking. Thresholds mean holdings below the limit are invisible, and nominee arrangements can satisfy the letter of the requirement while concealing real control. Treat a declaration as a dated statement by a named person with legal consequences for falsity, which is genuinely useful, and corroborate against filings, litigation and financial records rather than treating it as settled fact.
Can I lawfully bulk download registry data?
It depends on the registry's licence, and the terms differ substantially. Several major registries publish bulk data under open licences that permit reuse including commercial reuse; others restrict bulk extraction, prohibit redistribution or require a paid licence, and some enforce technical rate limits that terms of service make it a breach to circumvent. Read the licence before building a pipeline, record which licence you relied on, and remember that officer records are personal data whose bulk processing carries data protection obligations independent of whether the registry permits the download.
How do I connect an entity across jurisdictions reliably?
Use identifiers rather than names wherever one exists: the LEI for financial market participants, tax registrations, stock tickers, procurement supplier numbers and sector licence numbers. Where no shared identifier exists, build the link from multiple corroborating attributes such as the exact registered address, matching officers with dates of birth, disclosed subsidiary lists in a parent's filings and consistent auditors. Record the specific evidence for every cross-jurisdiction link, and rate its strength, because these links are where entity resolution errors concentrate and where they do the most damage downstream.
What are the strongest early warning signals in filing history?
Auditor resignation, particularly where the auditor states a reason, is the strongest single signal. After that: a pattern of late or missed filings, sudden changes of registered office or accounting reference date, repeated registration of charges against a small balance sheet, rapid officer turnover, restatement of previously filed accounts, and a change of company name shortly before or after a significant event. None is conclusive alone, but the combination is diagnostic and all of it is visible from the filing index without reading a full set of accounts.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- FATF Recommendations 24 and 25 set international standards on transparency of beneficial ownership of legal persons and arrangements.
- EU Anti-Money Laundering Directives establish beneficial ownership registers and customer due diligence obligations across member states.
- ISO 17442 defines the Legal Entity Identifier, providing a globally unique code for entities participating in financial transactions.
- Beneficial Ownership Data Standard provides a common structured format for publishing and exchanging ownership data across jurisdictions.
- UK Economic Crime and Corporate Transparency provisions govern identity verification and accuracy obligations for registry filings.
- OECD Common Reporting Standard and country-by-country reporting frameworks shape what multinational entities must disclose about structure.
- Wolfsberg Group guidance sets financial industry expectations for correspondent banking and entity due diligence practice.
- GDPR applies to officer and beneficial owner personal data even where the source register is public, governing purpose limitation and retention.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Companies House register — UK Government. Free primary registry with officers, persons of significant control and full filing history.
- OpenCorporates — OpenCorporates. Cross-jurisdiction aggregation of company records with officer linking.
- EDGAR — US Securities and Exchange Commission. Registrant filings disclosing subsidiaries, ownership and related party transactions.
- Global LEI Index — GLEIF. Openly licensed entity reference data with verified parent relationship records.
- Offshore Leaks Database — International Consortium of Investigative Journalists. Structured offshore entity, officer and intermediary records from multiple leaks.
- Aleph — OCCRP. Cross-dataset search across registries, leaks, sanctions and documents.
- FATF Recommendations — Financial Action Task Force. International standards on beneficial ownership transparency and due diligence.
- Beneficial Ownership Data Standard — Open Ownership. Structured publication format enabling cross-jurisdiction ownership analysis.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: entity resolution across registries with officer, address and ownership network mapping plus continuous sanctions screening. Explore the platform, or browse the rest of the library by following any tag above.