GLEIF LEI (Golden Copy): Intelligence Source Guide
The Legal Entity Identifier is a 20-character global code for a legally distinct organisation, and GLEIF publishes the complete file several times a day under a public domain licence. Its parent data means accounting consolidation, not ownership.
The Legal Entity Identifier is a 20-character global code for a legally distinct organisation, and GLEIF publishes the complete file several times a day under a public domain licence. Its parent data means accounting consolidation, not ownership.
At a glance
| Source | GLEIF LEI (Golden Copy) |
|---|---|
| Category | Corporate, Ownership & Legal Records › Beneficial Ownership & Legal Entities |
| Homepage | https://www.gleif.org/ |
| Machine interface | https://api.gleif.org/api/v1/lei-records |
| Format | JSON |
| Access | Open — no account required |
| Disciplines | Corporate Intelligence, Financial Intelligence |
| Mission domains | Financial Crime, Anti-Money Laundering |
Global Legal Entity Identifier records. — as catalogued in the platform’s own source registry.
The Global Legal Entity Identifier Foundation is a not-for-profit established in 2014 at the direction of the Financial Stability Board with G20 backing, headquartered in Basel and overseen by a regulatory oversight committee of public authorities. It does not issue identifiers itself. Accredited Local Operating Units register entities, verify their details against an authoritative local source such as a company register, and issue an LEI under ISO 17442: a 20-character alphanumeric code with a check digit, opaque by design apart from a prefix identifying the issuing unit. GLEIF consolidates every LEI record from every issuer into the Golden Copy, published multiple times each day in XML, CSV and JSON, free to anyone, with no registration. The record has two levels. Level 1 answers who is who: legal name, legal and headquarters addresses, jurisdiction, legal form, the local business register and the entity's number in it, entity status, and the full registration lifecycle including who issued it, when it was last updated, when it next falls due for renewal, and how well the data was corroborated. Level 2 answers who owns whom, in a specific and limited sense: the entity's direct and ultimate accounting consolidating parents, published as separate relationship records, with structured exception records where no parent is reported and a reason why.
Every corporate investigation runs into the same problem: the same company appears in a sanctions list, a trade record, a court filing and a payments message under four different name spellings and no common key. LEI is the only globally scoped, freely published, regulator-backed answer to that problem. Its analytical job is not to tell you something new about an entity; it is to let you assert that two records describe the same entity, and to do so with a corroboration level attached. That is the foundation on which everything else in corporate and financial intelligence is built — resolve identity first, then analyse. The second job is jurisdictional grounding: because the record carries the registration authority and the entity's number in the local register, an LEI is a bridge from the financial world to the primary company register, which is where documents, filings and directors live. The third is structure, with a hard caveat. Level 2 tells you which entity consolidates this one in its financial statements under applicable accounting standards. That is not beneficial ownership, not control in the AML sense, and not the shareholder register. Treating it as ownership is the single most common and most consequential error made with this dataset, and it produces group structures that are confidently wrong.
Who publishes it, and why that matters
GLEIF is a public-interest foundation created by regulators, funded principally through fees paid by registrants to their issuing units, a portion of which supports the central infrastructure. That model has unusual implications. There is no commercial incentive to withhold data, which is why the entire dataset is published under a public domain dedication rather than licensed — GLEIF's mission is adoption, and free redistribution serves it. There is also no commercial incentive to grow coverage beyond where regulation drives it, which is why the population is dominated by entities that were required to obtain an identifier rather than entities that matter. Data quality is a shared responsibility between GLEIF, which measures and publishes quality metrics, and the issuing units, which do the verification against local registers of wildly varying reliability. GLEIF publishes quality assessments and operates a public challenge mechanism for incorrect records, which is a genuinely good governance arrangement and is also an admission that errors reach production. Institutional longevity is strong: this is infrastructure mandated by the G20 and embedded in financial regulation across major jurisdictions, so the risk of it disappearing is lower than for almost anything else in this catalogue.
Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.
What a record actually contains
The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.
| Field | Type | What it means | Pivot value |
|---|---|---|---|
LEI |
string | The 20-character ISO 17442 identifier. Characters one to four identify the issuing unit, the final two are a check digit computed under a standard modulus scheme, and the remainder is opaque. Validate the check digit on ingest; malformed LEIs in third-party data are common. | The universal join key across regulatory reporting, securities data, payments messages and sanctions records. |
entity.legalName |
string | The legal name as recorded in the authoritative local source, in its own script and transliteration conventions. It is the registered name, not the trading name, brand or common shorthand. | Company register lookup, sanctions and adverse media name matching — with the understanding that legal names rarely match how an entity is described elsewhere. |
entity.legalAddress / headquartersAddress |
string | Registered address and operating headquarters, which frequently differ. A registered address at a company formation agent is a structural fact, not an error, and is analytically informative. | Address clustering to identify formation agents and nominee service providers, and to spot registered-office concentration. |
entity.jurisdiction |
string | The legal jurisdiction of formation as an ISO 3166 code, including subdivision where the register is subnational. This is where the entity exists in law, not where it operates. | Jurisdictional risk assessment, applicable company law, and the correct primary register to query next. |
entity.registeredAt / registeredAs |
string | The registration authority, identified by a code from GLEIF's maintained authority list, and the entity's identifier within that authority — the company number. This is the bridge to primary documents. | Direct lookup in the national company register, where filings, directors, accounts and charges live. |
entity.legalForm.id |
string | The entity's legal form as an ISO 20275 code from GLEIF's Entity Legal Forms list, which distinguishes a limited company from a partnership, trust, fund or branch across hundreds of jurisdiction-specific forms. | Structural analysis: legal form determines disclosure obligations, liability structure and whether beneficial ownership rules even apply. |
entity.status |
enum | Whether the entity is ACTIVE or INACTIVE as a legal person. Distinct from registration status, and the two disagree far more often than they should. | Dissolution and liquidation research; an inactive entity still transacting is a finding. |
registration.status |
enum | The lifecycle state of the LEI itself: ISSUED, LAPSED, MERGED, RETIRED, ANNULLED, DUPLICATE and pending states, among others. LAPSED means the registrant did not renew, not that the company ceased to exist. | Data currency assessment; a lapsed record's contents are as stale as its last update date and nothing more. |
registration.nextRenewalDate |
timestamp | When annual re-verification falls due. Past this date without an update, the record has not been re-checked against the local register by anyone. | Freshness gating; the single most useful field for deciding whether to trust the rest of the record. |
registration.lastUpdateDate |
timestamp | When the record was last changed. This is the true age of the data, and it is the field to display next to any name or address you present to a user. | Change detection across Golden Copy versions; identifying entities whose details were amended and when. |
registration.corroborationLevel |
enum | How the issuing unit verified the record: fully corroborated against an authoritative source, partially corroborated, or supplied by the entity with no independent check. This is the quality field and it is routinely ignored. | Confidence weighting; entity-supplied-only records should not be treated as register-grade evidence. |
registration.managingLou |
string | The issuing unit responsible for the record. Issuers vary in rigour and in the jurisdictions they cover, so this is a meaningful quality covariate. | Systematic quality analysis; identifying whether a data problem is entity-specific or issuer-wide. |
relationship parent records |
array | Direct and ultimate accounting consolidating parents, published as separate relationship records with their own validity periods and validation status. Accounting consolidation, not ownership or control. | Group structure reconstruction — as a starting hypothesis to be tested against filings, never as an ownership finding. |
reporting exceptions |
enum | Where no parent is reported, a structured reason: no parent exists, the parent is a natural person, the parent does not consolidate, or the information is not public. The exception is often more informative than a relationship would have been. | Identifying entities whose ultimate owner is an individual, which routes the investigation to beneficial ownership registers rather than to corporate filings. |
Coverage — and what is not in it
Global in jurisdictional scope and highly selective in population. Well over two million LEIs have been issued across more than two hundred jurisdictions, but the population is shaped almost entirely by regulation: entities obtain identifiers because a rule requires one to trade derivatives, report securities transactions, settle in certain markets or send certain payment messages. The result is excellent coverage of banks, funds, insurers, listed companies, large corporates and their financing vehicles, and near-zero coverage of ordinary private companies with no market activity. Do not expect a small trading company, a shell without financial market exposure, or a private holding structure to have one. Geographically, coverage concentrates where the regulatory mandates bite hardest — the European Union, the United Kingdom, the United States and major Asian financial centres — with much thinner coverage elsewhere, including jurisdictions of high investigative interest. Level 2 relationship coverage is thinner still: a substantial share of records carry a reporting exception rather than a parent, and fund relationship structures were added later and are unevenly populated. The Golden Copy is republished several times each day, so the data is genuinely current; the individual record, however, is only as current as its last renewal, and a large minority of all LEIs are lapsed at any moment.
Known blind spots
Absence of evidence here is not evidence of absence. These are the conditions under which GLEIF LEI (Golden Copy) will not show you something that is nevertheless real:
- Absence of an LEI means nothing about an entity's existence, size or importance. The population is regulation-driven, so a private company with no financial market activity will not have one, and treating LEI absence as a red flag inverts the meaning of the data.
- Level 2 records accounting consolidation, not ownership or control. An entity can be wholly owned and report no parent because the owner does not consolidate it, and an entity can report a parent that holds no shares at all under some accounting frameworks.
- Where the ultimate parent is a natural person, the record contains an exception and no name. This is by design and it means the dataset is structurally silent on exactly the ownership question most investigations are asking.
- Lapsed records are not corrected, only frozen. A lapsed LEI's name, address and status reflect the last renewal, which may be years old, and nothing in the record signals that the underlying facts have changed.
- Verification quality is bounded by the local register. In jurisdictions where company registration involves no verification of the underlying facts, a fully corroborated LEI faithfully reproduces an unverified local record, and the corroboration level does not distinguish this case.
- Branches and subsidiaries are inconsistently represented. Some groups register every operating entity, others register only what regulation requires, so counting LEIs per group measures compliance behaviour rather than corporate structure.
- The dataset contains no financial data, no directors, no shareholders and no filings. It is an identity and relationship layer, and every substantive question requires leaving it for a primary register or a commercial source.
- Name matching against LEI records fails in predictable ways: legal names carry suffixes and punctuation that trading names do not, non-Latin scripts are transliterated inconsistently between issuers, and the same group's entities differ by a word.
- Historical structure is hard to reconstruct. Relationship records carry validity periods but the published file is a current view, so tracking how a group's structure changed requires you to have archived the daily files yourself.
Write the blind spot into the product. A statement that something “was not observed in GLEIF LEI (Golden Copy)” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.
Access, licensing and what you may do with it
Access model: Open — no account required
There are two access routes and you should use both for different purposes. The Golden Copy files are the bulk route: complete concatenated files of all LEI records, all relationship records and all reporting exceptions, published several times a day in XML, CSV and JSON, downloadable without an account. Take these if you need the whole population, if you are building a resolution layer, or if you want to diff releases to detect change. The REST API is the targeted route: a JSON:API interface at the published endpoint, no authentication, supporting lookup by LEI and filtered search across the record fields with paged results. Use it for enrichment of specific entities and for interactive work. There is also a public search interface for human use, and separately published mapping files linking LEIs to securities identifiers, bank identifier codes and market identifier codes, which are the practical bridges into securities and payments data. GLEIF publishes data quality reports and operates a public mechanism for challenging incorrect records; if your work surfaces an error, submitting it is both good practice and the only way the dataset improves.
Licence
GLEIF publishes LEI data under a public domain dedication, free of charge and without restriction on use, redistribution or commercial exploitation. This is unusual and it is deliberate: the foundation's objective is universal adoption, and licensing friction works against it. In practice you may ingest the full Golden Copy, redistribute it, build products on it and resell services derived from it without a licence negotiation. Attribution is not legally required and is nonetheless good practice, because a user who knows a record came from the LEI system knows what it does and does not assert. Two cautions remain. The mapping files that link LEIs to other identifier systems may involve rights held by the bodies that maintain those other identifiers, so check the terms on each mapping file rather than assuming the underlying public domain dedication extends to them. And the absence of licence restrictions is not an absence of data protection obligations: records concerning sole traders and similar entities can constitute personal data in some jurisdictions, and address fields may relate to individuals.
Rate limits and fair use
The API enforces a request rate cap and returns an HTTP 429 when you exceed it; treat that as a hard signal to back off rather than something to work around with parallel clients. Paged responses have a server-imposed maximum page size, so retrieving large result sets through the API means many requests. The correct architecture is to stop trying: if you need more than a few thousand records, take the Golden Copy bulk file instead. It is complete, it is republished several times daily, and pulling it once is cheaper for both parties than a hundred thousand API calls. Reserve the API for interactive lookups and for enriching specific entities as they arise, cache aggressively given that the underlying record changes at most on renewal, and identify your client honestly in the user agent.
Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.
Collecting it
How GLEIF LEI (Golden Copy) is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.
| Method | Format | Cadence | Notes |
|---|---|---|---|
| Golden Copy bulk download | JSON | published several times daily; pull once or twice a day | The complete LEI record population. The correct primary collection method for anyone building a resolution layer. Available in XML, CSV and JSON; pick the one your pipeline parses natively rather than converting. |
| Relationship and exception files | XML | with each Golden Copy publication | Level 2 parent relationships and reporting exceptions ship as separate files. Ingest both — the exceptions carry as much analytical signal as the relationships, particularly the natural-person exception. |
| REST API lookup | JSON | on demand | Targeted retrieval by LEI or filtered search, no authentication. Appropriate for enrichment of individual entities during analysis; inappropriate as a bulk collection method. |
| Identifier mapping files | CSV | per publication schedule | Published mappings from LEI to securities, bank and market identifiers. These are the bridge from entity identity into securities holdings, payments messaging and venue data. |
| Daily delta capture | JSONL | daily | Diff successive Golden Copy releases and store the changes. GLEIF publishes current state, not history, so if you want to know when an entity changed its name or its parent, you must build that record yourself from the moment you start collecting. |
| Data quality report retrieval | HTML | monthly | GLEIF's published quality assessments tell you which issuers and which fields are weak. Use them to set confidence weights rather than treating all records as equivalent. |
Ingesting it into the platform
Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.
- Register the source and its cadence — Add GLEIF in sources.php as a multiple-times-daily bulk source with a public domain licence recorded, and configure collect.php and cron.php to take the Golden Copy on a schedule that matches how quickly you need name changes to propagate.
- Validate identifiers on entry — Check the ISO 17442 check digit on every LEI at ingest.php, including LEIs arriving from third-party sources rather than from GLEIF. Malformed and transposed identifiers are common in externally supplied data and silently create phantom entities.
- Create the entity with its register bridge and currency metadata — Populate org-profile.php with the legal name, jurisdiction, legal form and the registration authority and local company number, so every LEI-derived entity carries a pointer to its primary register. Carry last update date, next renewal date, registration status and corroboration level onto the entity record itself rather than into a metadata blob: these four fields decide whether a downstream analyst should believe the name and address, and they must be visible wherever those are displayed.
- Load relationships as accounting edges, not ownership edges — Ingest Level 2 records into link-analysis.php with an edge type that says accounting consolidation explicitly. Never label them as ownership in the graph; the label is what analysts will read and it will be read literally.
- Ingest reporting exceptions as findings — Load exception records as facts about the entity, particularly the natural-person exception, which is an actionable routing signal telling you the investigation should move to beneficial ownership sources rather than corporate filings.
- Apply identifier mappings — Load the published mappings so that securities identifiers, bank identifier codes and market identifiers resolve to the same entity object, which is what allows financial-crime.php and sanctions.php work to join across payment, trade and securities data.
- Reconcile against sanctions and ownership sources — Run resolve-everything.php to match LEI entities against sanctions lists, beneficial ownership registers and corporate datasets, keeping each source's assertion distinct rather than merging them into a single blended record.
- Persist the change history — Write daily deltas into a versioned store so that name changes, address changes, status transitions and parent changes are queryable over time in timeline.php. GLEIF gives you current state; the history is yours to build and it is where much of the analytical value ends up.
Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.
How it is wrong, and how to tell
Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.
As identity infrastructure this is among the best sources in this catalogue, and it is important to be precise about what that means. The identifier itself is excellent: globally unique, check-digit protected, never reused, and stable across an entity's life including through renaming. The registration lifecycle is transparent, with the issuer, the update dates and the corroboration level all published, so you can assess an individual record's reliability rather than trusting the dataset as a whole. Quality is actively measured and published, and there is a public route for reporting errors. The limits are structural rather than defects. Verification is only as strong as the local register the issuer checked against, and some registers verify nothing. Lapsed records — a large minority of the population at any time — are frozen rather than corrected. Level 2 coverage is partial and its semantics are narrower than almost every user assumes. And the corroboration level field, which is the honest quality signal, is ignored by most implementations. The practical assessment: trust the identifier absolutely, trust the name and address as of the last update date, treat the parent relationships as accounting facts requiring corroboration, and never infer anything from absence.
Characteristic false positives
- Accounting parent read as owner. The most damaging error with this dataset produces group structures that look authoritative, appear in link charts, and are wrong wherever consolidation and ownership diverge — which is precisely in the complex structures worth investigating.
- Lapsed record read as current. Nothing in the name or address fields indicates staleness; only the registration status and renewal date do, and an interface that displays the former without the latter will present years-old data as fact.
- Absence of an LEI read as a negative finding. Most companies in the world do not have one and never will, so 'no LEI' is a statement about regulatory scope, not about legitimacy.
- Name matching producing false identity. Legal names differ from trading names, transliteration of non-Latin scripts is inconsistent between issuers, and large groups contain many similarly named entities — fuzzy matching without the jurisdiction and company number produces confident mismatches.
- Registered address treated as location. A registered office at a formation agent tells you about the service provider, not about where the business operates, and geolocating LEI addresses produces clusters on corporate service providers.
- Entity status and registration status conflated. An entity can be legally dissolved while its LEI still shows as issued, and an active company can have a lapsed LEI; treating either field as a proxy for the other misclassifies both directions.
- Duplicate and merged records treated as separate entities. The lifecycle statuses that mark a record as superseded exist for a reason, and ingesting the whole file without honouring them creates duplicate entities in your graph.
- Entity-supplied-only records treated as register-verified. The corroboration level distinguishes these and it is routinely dropped during ingest, at which point unverified self-assertions become indistinguishable from register-checked facts.
None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.
Ageing
The identifier never ages: an LEI is permanent, is not reused, and survives the entity's renaming, restructuring and dissolution — which is precisely what makes it useful as a join key across time. The record contents age on an annual cycle enforced by renewal, and this is the crucial mechanic to internalise. If the next renewal date has passed and the registration status is lapsed, nobody has checked this record against the local register since the last update date, and the name, address and status are assertions of unknown current validity. A large minority of the population sits in that condition at any moment. Relationship records age faster than entity records because group structures change with every acquisition and reorganisation, and because a parent relationship is only updated when someone reports it. A stale usage looks like a compliance screening built on entity names harvested from lapsed records, or a group structure chart drawn from relationship data that predates a major restructuring. Detect it by displaying the last update date next to every name in your interface and by refusing to let a record older than one renewal cycle drive an automated decision without re-verification against the primary register.
What this source feeds
A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.
Collected by these intelligence disciplines
Serves these mission domains
Yields these data points
How each sector uses GLEIF LEI (Golden Copy)
The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.
🎖 Military and defence
Relevance is in defence industrial base and supply chain assurance rather than in operations. Where you need to establish that a supplier, sub-tier vendor or joint venture partner is the entity you think it is, and to connect it to a corporate group and a jurisdiction, the LEI is the identity anchor that makes the assessment repeatable rather than a name-matching exercise. It is particularly useful for counterparty screening in procurement, where the same corporate group appears under many names across many contracts. The limits are severe for this use: coverage is regulation-driven, so a small specialist component supplier will usually have no LEI at all, and the accounting parent relationships will not reveal the control structures that matter for foreign ownership assessment. Use it as the identity layer beneath a supply chain analysis, and expect the substantive answers to come from national registers, ownership disclosures and contract records.
🕵 National intelligence
For financial intelligence and economic analysis, this is the free, global entity resolution layer that makes cross-source correlation feasible at all. The specific analytic uses are joining sanctions designations to market participants, tracing a group's registered footprint across jurisdictions, identifying which entities in a structure exist for financial market access rather than operations, and using the natural-person reporting exception as a routing signal toward beneficial ownership work. The record's registration authority and local company number are what let you cross from a financial identifier into a jurisdiction's primary register, which is the step most analyses skip and where the documents actually are. Treat the parent relationships with discipline: they describe consolidation for accounting purposes and are not evidence of control, and an assessment that presents them as ownership will be defensible only until someone reads the specification.
👮 Law enforcement
In financial crime investigations the LEI is a case-management asset before it is an analytical one: it gives you a stable, unambiguous identifier for a corporate entity that will survive name changes, transliteration disputes and the passage of time, which matters enormously across a multi-year case. The registration authority and company number take you directly to the primary register for the certified documents you will need for evidence. Two practical points. First, an entity's LEI record is not evidence in itself — it is a third-party assertion, and where a corporate fact matters you obtain a certified extract from the register. Second, absence is not suspicious: the majority of companies have no LEI, and a report treating that as an indicator will not survive cross-examination. Use the natural-person reporting exception as a lead: it tells you an ultimate owner is an individual and that the beneficial ownership question is live.
🔍 Private investigation and corporate security
For due diligence and corporate investigation this is the free starting point that a surprising number of practitioners skip. It gives you the correct legal name, the jurisdiction, the legal form, the registered address and — the useful part — the company number in the local register, which is what you actually need to order documents. It also lets you spot a formation agent address, identify entities in a group that were registered purely for market access, and see when a record was last verified. The disciplined workflow is to use LEI for identity and immediately leave it for the primary register. Do not present the Level 2 relationships to a client as an ownership chart; they are accounting relationships, partial in coverage, and a client acting on a wrong structure has a claim against you. And remember that the population skews to financial market participants, so the private companies most due diligence concerns will often not appear.
📰 Journalism and OSINT media
For investigative journalism the LEI is a corroboration and disambiguation tool rather than a story source. When a company appears in leaked documents, a contract or a sanctions listing, the LEI record establishes the exact legal entity, its jurisdiction and its number in the national register, which is how you avoid the recurring error of confusing similarly named companies in different countries. The reporting exceptions are quietly interesting: an entity whose ultimate parent is recorded as a natural person, with no name given, is a legitimate line of enquiry rather than a dead end. The public domain licence means you can publish extracts and build interactives without clearance, which is rare and worth exploiting. Be careful in how you describe parent relationships to readers — 'consolidates for accounting purposes' and 'owns' are not the same claim, and the second is the one that gets corrected.
🌍 NGO, humanitarian and human rights
Anti-corruption, tax justice and environmental accountability organisations use this as the free identity spine that makes cross-border corporate research possible without a commercial data subscription. It is the practical bridge between a company named in a procurement record and its entry in a national register, and between an entity in one country's disclosure regime and the same entity in another's. For campaigning on beneficial ownership transparency, the dataset is also evidence in itself: the volume of records where the ultimate parent is reported as a natural person with no further detail is a direct, quantified illustration of the gap that beneficial ownership registers exist to fill. The constraint to communicate internally is coverage — the entities most relevant to extractives, land and supply chain work frequently have no LEI, and building a methodology that assumes one exists will fail in exactly the jurisdictions of most interest.
🎓 University and research
For research in finance, economics, corporate governance and network science, the Golden Copy is an unusually clean public dataset: a complete population with a stable identifier, published under a public domain dedication, updated multiple times daily, with explicit quality metadata. It supports work on corporate group structure, cross-border financial integration, regulatory compliance behaviour and identifier adoption itself. The methodological requirements are specific. The population is regulation-selected, so any inference about firms in general requires modelling that selection. Level 2 relationships are accounting consolidation and partial, so network analyses built on them describe reported consolidation structure rather than ownership networks and should say so in the methods section. And because GLEIF publishes current state rather than history, longitudinal work requires archived daily files — start collecting before you need them, because you cannot recover the past afterwards.
Playbook: working GLEIF LEI (Golden Copy) end to end
A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.
Phase 1 — Decide whether identity or substance is the question
This source resolves who an entity is. It does not tell you what it did, who owns it, or whether it matters. If your question is substantive, plan the workflow so that LEI is step one of five, and budget the effort for the primary register work that follows rather than hoping the LEI record will suffice.
Phase 2 — Take the bulk file, not the API
If you are doing anything more than occasional lookups, ingest the Golden Copy. It is complete, free, published several times a day and cheaper for everyone than paginating through the API. Reserve the API for interactive enrichment during analysis.
Phase 3 — Validate every identifier at the boundary
Check the ISO 17442 check digit on all LEIs entering your system from any source. Third-party data contains transposed and truncated identifiers, and a malformed LEI that passes into your graph creates an entity that does not exist and will never be reconciled.
Phase 4 — Establish record currency before believing anything
For each entity, read the registration status, last update date and next renewal date together. A lapsed record is a snapshot of unknown age. Set a policy for what your organisation does with lapsed records — re-verify, flag, or exclude — and apply it consistently rather than case by case.
Phase 5 — Cross to the primary register immediately
Take the registration authority code and the local company number and go to the national register. That is where directors, filings, accounts, charges and dissolution records live. An investigation that stays inside the LEI dataset has stopped at the index.
Phase 6 — Read the Level 2 semantics before drawing a chart
Establish, in writing, that the relationships you are about to visualise are accounting consolidation under applicable standards. Then decide whether that answers your question. For sanctions ownership tests, control assessments and beneficial ownership work it does not, and proceeding anyway is how confidently wrong structure charts get produced.
Phase 7 — Mine the reporting exceptions deliberately
Query for entities whose parent reporting exception indicates a natural person or non-public information. These are not gaps; they are signposts telling you the ownership question is live and where to take it next, and they are ignored by almost everyone.
Phase 8 — Bridge into securities and payments data
Apply the published identifier mappings to connect entities to securities identifiers, bank identifier codes and market identifiers. This is what allows a corporate entity to be joined against trade reporting, holdings data and payment messaging, and it is the step that turns identity resolution into financial intelligence.
Phase 9 — Reconcile against sanctions and ownership sources
Match your LEI population against sanctions lists and beneficial ownership registers, keeping each source's assertions separate. Disagreements between an LEI record and a sanctions list entry — different names, different addresses, different jurisdictions for the same entity — are frequently the most informative output of the whole exercise.
Phase 10 — Build and keep the change history
Diff successive Golden Copy releases and persist the deltas. Name changes, address changes, status transitions and parent changes are individually mundane and collectively revealing, and GLEIF publishes only current state, so nobody will reconstruct this for you later.
Phase 11 — Weight by corroboration and issuer
Carry the corroboration level and the issuing unit into your confidence model. Entity-supplied-only records and issuers with weaker published quality metrics should not carry the same weight as register-corroborated records from strong issuers, and treating them equally quietly degrades everything downstream.
Phase 12 — Report errors back
Where your primary register work shows an LEI record is wrong, use the public challenge mechanism. This costs minutes, improves shared infrastructure that you depend on, and is the only reason the dataset gets better.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
What to pair it with
No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.
| Source | Relationship | What it adds |
|---|---|---|
| OpenCorporates | extends | Aggregated company register data across jurisdictions with officers and filing history, covering the vast population of companies that have no LEI at all. |
| OpenSanctions | extends | Consolidated sanctions, PEP and watchlist data with entity resolution, and the natural next join once an LEI has given you a stable identity. |
| Open Ownership | extends | Beneficial ownership data and the data standard for it, which addresses precisely the question the LEI reporting exceptions leave open when the ultimate parent is a natural person. |
| Companies House | prerequisite | An example of the primary register that an LEI's registration authority and company number point to; the source of certified documents, directors and filings that the LEI record only indexes. |
| SEC EDGAR | extends | Filings for United States registrants, including group structure exhibits and ownership disclosures that let you test whether an accounting parent relationship reflects control. |
| SWIFT | corroborates | Maintains the bank identifier code system that GLEIF publishes a mapping to, which is the bridge from entity identity into payments messaging. |
| ICIJ Offshore Leaks Database | extends | Leaked offshore entity and intermediary records covering structures that by design never appear in a regulated identifier system. |
| OCCRP Aleph | extends | Cross-source search across registers, leaks and documents, useful for testing whether an LEI-identified entity appears in investigative material. |
| Financial Stability Board | prerequisite | The body that mandated the LEI system, and the source for understanding why the population looks the way it does and where the mandates are heading. |
Legal, ethical and operational constraints
Legally this is one of the least encumbered sources available: the data is published under a public domain dedication, may be redistributed and commercialised freely, and concerns legal entities rather than individuals in the great majority of cases. Three qualifications matter. First, records for sole traders, individual partners and similar structures can constitute personal data in jurisdictions where the natural person and the legal entity are not cleanly separated, and address fields may relate to individuals' homes; a bulk ingest therefore still requires a data protection position even though the source is public domain. Second, the identifier mappings to other systems may carry rights belonging to the maintainers of those other identifier schemes, and those terms are separate from GLEIF's dedication. Third, and most consequentially in practice, the legal risk is in interpretation rather than in access: presenting accounting consolidation relationships as ownership in a due diligence report, a sanctions ownership analysis or a client deliverable creates a liability that no licence protects you from. The professional standard is to describe what the field means, not what your audience wishes it meant.
Operational security
Bulk retrieval of the Golden Copy reveals nothing about your interests — you are taking the entire population, and everyone else who does the same takes the same file. That is a genuine operational advantage and a reason to prefer bulk collection over targeted lookups in sensitive work. The API is the opposite: each query names a specific entity or search term, and those queries are visible to the operator in logs, so a pattern of lookups against a particular corporate group is a legible statement of investigative interest to anyone with access to them. Where the fact of your interest is sensitive, take the bulk file and query locally; this is also the faster and cheaper architecture, so there is no trade-off to manage. Downstream, be aware that LEIs in a published report identify entities with a precision that name-based reporting does not, which is usually desirable and occasionally reveals more about the scope of your enquiry than intended.
Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.
Is it earning its place?
Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether GLEIF LEI (Golden Copy) is contributing anything, and they are worth baselining now so the answer is available later.
- Proportion of entities in your working set successfully resolved to an LEI, tracked per jurisdiction, as the honest measure of how far this identity layer actually reaches into your problem space.
- Share of LEI-derived entities in your store whose registration is currently lapsed, which is the direct measure of how much of your entity data is unverified and frozen.
- Rate at which LEI-derived legal names and addresses disagree with the primary register when you check them, sampled periodically, as the empirical basis for how much you should trust the record without checking.
- Number of investigations routed to beneficial ownership work by the natural-person reporting exception, as a measure of whether you are using the exceptions or discarding them.
- Coverage of the identifier mappings applied in your pipeline, since an unmapped LEI cannot join to securities or payments data and the identity layer is doing only half its job.
- Volume of change events captured in your own delta history per period, which is the asset GLEIF does not provide and whose value compounds the earlier you start.
- Count of data quality challenges submitted where your primary register work found an error, as an indicator that your organisation is maintaining the infrastructure it depends on rather than only consuming it.
Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Level 2 is accounting consolidation. Say the words out loud before every structure chart, because the field will be read as ownership by everyone downstream unless the label prevents it.
- Display the last update date next to every name you show a user. A name without its currency is an assertion of unknown age presented as a fact, and lapsed records are a large minority of the population.
- Use the registration authority and company number, not the name. The company number in the local register is the durable link to documents; the legal name is a matching hazard with suffixes, punctuation and transliteration variance.
- Reporting exceptions are findings. A natural-person exception is the dataset telling you exactly where the ownership question lives, and it is discarded by almost every implementation that ingests this data.
- Never infer from absence. Most companies have no LEI and never will, so treating absence as a risk indicator produces alerts on ordinary businesses and misses everything the mandates do not touch.
- Take the bulk file for anything at scale. Paginating the API to reconstruct a dataset that is published complete several times a day is slow, rude and unnecessary — and it also broadcasts your interests.
- Keep your own history. GLEIF publishes current state; the change record is the analytically valuable artefact and it only exists if you started building it before you needed it.
- Carry the corroboration level through to your confidence model. Entity-supplied-only records are self-assertions, and flattening them into the same trust tier as register-verified records is a silent quality regression.
- Report errors back through the challenge mechanism. This is shared infrastructure funded by registrants and used by everyone, and consumers who never correct it are the reason it is imperfect.
Questions analysts actually ask
Does the LEI parent field tell me who owns a company?
No. It records the direct and ultimate parents that consolidate the entity in their financial statements under applicable accounting standards. That frequently coincides with ownership and frequently does not, especially in the structures worth investigating. For ownership and control you need beneficial ownership registers, filings and shareholder records.
Why does a company I am investigating have no LEI?
Because it was never required to obtain one. The population is driven by financial market regulation, so entities without derivatives, securities reporting or certain settlement and payment obligations simply do not appear. Absence carries no information about legitimacy, size or activity.
What does a lapsed LEI mean?
That the registrant did not renew, so nobody has re-verified the record against the local register since its last update. The entity may well still exist and trade. The practical implication is that the name, address and status are of unknown current validity and should be re-checked before they support any decision.
Can I use this data commercially?
Yes. LEI data is published under a public domain dedication with no restriction on redistribution or commercial use. Check the terms on the identifier mapping files separately, since those may involve rights held by the maintainers of the other identifier systems.
Should I use the API or the bulk files?
Bulk files for anything at scale, API for interactive lookups. The complete population is published several times a day, so paginating the API to rebuild it is slower, subject to rate limiting, and reveals which entities you are interested in.
How do I get from an LEI to actual company documents?
Use the registration authority code and the entity's identifier in that authority — its company number — to query the national register directly. That is where filings, directors, accounts and charges are, and the LEI record's main practical value is providing that pointer reliably.
How reliable is the corroboration level?
It is a genuine and useful signal, distinguishing records verified against an authoritative source from those the entity simply supplied. Its limit is that it describes the verification act, not the underlying register's rigour: a fully corroborated record from a jurisdiction that verifies nothing is faithfully reproducing an unverified fact.
Can I reconstruct how a corporate group changed over time?
Only from files you archived yourself. GLEIF publishes current state, and relationship records carry validity periods but the historical series is not provided. Start capturing daily deltas now if longitudinal structure matters to your work; the past is not recoverable.
What is the vLEI?
A verifiable credential form of the LEI, designed to let an organisation and its authorised representatives prove identity cryptographically in digital transactions. It is a separate ecosystem with its own issuers and governance, and it is worth tracking if your work involves digital identity assurance rather than bulk entity data.
Standards, formats and interoperability
What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:
- ISO 17442 defines the Legal Entity Identifier itself, including its structure and the check digit scheme that every ingest pipeline should validate against.
- ISO 20275 defines the Entity Legal Forms code list, which is what makes legal form comparable across hundreds of jurisdiction-specific company types.
- ISO 3166 country and subdivision codes carry jurisdiction and address geography, allowing LEI records to join to the rest of the platform's geography without normalisation guesswork.
- ISO 20022 financial messaging carries the LEI in payment and securities messages, which is the mechanism by which entity identity travels with a transaction.
- The GLEIF Registration Authorities List maps the registration authority codes to the world's business registers, and is the reference you need to turn a code into a queryable primary source.
- MiFID II and MiFIR in Europe, and derivative and swap reporting rules in the United States and elsewhere, are the regulatory mandates that populate the dataset and explain its coverage bias.
- The published mappings to securities identifiers, bank identifier codes and market identifier codes are the interoperability layer between entity identity and market data.
- The platform exports LEI-derived entities and relationships in STIX 2.1, MISP, CSV, JSON and JSONL, with the accounting-consolidation semantics preserved on the relationship type rather than flattened to ownership.
References
Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- GLEIF — Global Legal Entity Identifier Foundation. The foundation: Golden Copy downloads, format specifications, data quality reports, the registration authorities list and the entity legal forms list.
- GLEIF API — LEI records — GLEIF. The public JSON:API endpoint for targeted lookup and filtered search, with no authentication required.
- GLEIF Search — GLEIF. The human-facing search interface. The fastest way to check a single entity and to see how a record is structured before you write code against it.
- Financial Stability Board — FSB. The body that mandated the global LEI system, and the source for understanding the regulatory drivers that shape coverage.
- OpenCorporates — OpenCorporates. Company register aggregation covering the very large population of entities that have no LEI, and the natural complement for corporate research.
- OpenSanctions — OpenSanctions. Consolidated sanctions and PEP data with entity resolution, the standard next join once identity is established.
- Open Ownership — Open Ownership. Beneficial ownership data and standard, addressing the ownership question that LEI Level 2 explicitly does not answer.
- SEC EDGAR — United States Securities and Exchange Commission. Filings including subsidiary lists and ownership disclosures, useful for testing whether an accounting parent reflects actual control.
- Companies House — United Kingdom Government. A primary register of the kind an LEI record points to, and a reference example of what the registration authority and company number unlock.
- SWIFT — SWIFT. Maintainer of the bank identifier code system that GLEIF publishes a mapping to, the bridge from entity identity into payments.
- ICIJ Offshore Leaks Database — International Consortium of Investigative Journalists. Offshore entity records covering the structures that a regulated identifier system is designed never to see.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this source: it ingests the full Golden Copy on a daily cadence, validates every identifier's check digit at the boundary, carries renewal date and corroboration level onto the entity record so staleness is visible wherever a name is displayed, labels Level 2 edges as accounting consolidation rather than ownership, and builds the change history that GLEIF itself does not publish.. Browse the full source catalogue, or follow any tag above into the rest of the library.