Skip to main content
Sanctions Ownership Tracing TemplateSanctions Lists & Screening
5 min readFor Sanctions Analysts

Sanctions Ownership Tracing Template

If you're still relying on point-in-time name checks to clear counterparties, you're missing the networks that matter. This template provides a structured process for tracing indirect ownership and beneficial control, revealing exposures that sit beneath disclosure thresholds and across borders.

Purpose of the Template

Use this template to investigate ownership structures beyond the 25% beneficial ownership threshold. It's designed for sanctions analysts who need to:

  • Trace ownership chains across multiple jurisdictions
  • Document indirect exposures not visible in registry searches
  • Build an evidence file demonstrating reasonable inquiry
  • Monitor relationships that evolve after onboarding

The template organizes your investigation into four phases: data gathering, relationship mapping, risk signal identification, and ongoing monitoring triggers.

Prerequisites

Before starting, ensure you have:

Data Access:

  • Corporate registry access in your counterparty's jurisdiction
  • Cross-border ownership data
  • Sanctions list feeds that update daily
  • Transaction routing details showing intermediaries

Internal Coordination:

  • Ownership records from your KYC files
  • Payment routing data from your operations team
  • Relationship intelligence from account managers

Technical Capability:

  • A method to visualize multi-layered ownership, even if it's a spreadsheet with parent-child columns
  • A system that flags changes in ownership structures

You don't need advanced analytics to start. You need connected data and a process for asking the right questions.

The Template

Phase 1: Initial Counterparty Profile

Counterparty Legal Name:
Jurisdiction of Incorporation:
Registered Address:
Date of Onboarding:
Business Relationship Type: (supplier / customer / correspondent / other)

Direct Ownership (>25% Disclosed):

  • Shareholder 1: Name, jurisdiction, % stake
  • Shareholder 2: Name, jurisdiction, % stake
  • (Continue for all disclosed owners)

Directors and Officers:

  • List names and any cross-appointments to other entities

Source of Ownership Data:
(Corporate registry / KYC documentation / Third-party provider)

Phase 2: Indirect Ownership Tracing

For each disclosed shareholder that is a corporate entity, repeat this section:

Parent Entity Name:
Jurisdiction:
Its Disclosed Owners (>25%):

Trace Depth: How many layers up did you go before reaching natural persons or hitting a data wall?

Ownership Structures Below 25%:
Document any stakes between 10-24% that, when combined, could represent control:

  • Entity: % stake, jurisdiction
  • Entity: % stake, jurisdiction
  • Combined Influence Assessment: Do these sub-threshold stakes suggest coordinated control?

Jurisdictions in the Ownership Chain:
List every jurisdiction that appears. Flag any that are:

  • Subject to FATF concerns
  • Known for opaque corporate registers
  • Jurisdictions where your data provider has limited coverage

Phase 3: Risk Signal Identification

Move from data collection to analysis. Document any patterns suggesting hidden relationships or circumvention:

Shared Infrastructure:

  • Do multiple entities in the ownership chain share a registered address?
  • Do the same directors appear across seemingly unrelated companies?
  • Are there common signatories or authorized representatives?

Ownership Fragmentation:

  • Are there multiple entities each holding stakes just below 25%?
  • Is ownership split across family members or related parties suggesting coordinated control?

Intermediary Complexity:

  • How many layers sit between your counterparty and the ultimate beneficial owners?
  • Are there holding companies in the chain with no clear operational purpose?

Transaction Routing:

  • Do payments pass through intermediaries before reaching your counterparty?
  • Can you identify every entity in the payment chain?

Cross-Border Red Flags:

  • Does the ownership chain pass through jurisdictions with weaker disclosure requirements?
  • Are there gaps where you cannot verify the next layer up?

Phase 4: Monitoring Triggers

A counterparty that's clear today can look very different in six months. Set specific triggers to prompt a refresh:

Ownership Change Events:

  • New shareholder disclosed (any %)
  • Change in director or officer
  • Corporate restructuring or merger involving the counterparty or any parent entity

Sanctions List Updates:

  • Weekly check: Has any entity or person in the ownership chain been added to a sanctions list?
  • Quarterly check: Re-run name screening on all disclosed and traced owners

Jurisdiction Risk Changes:

  • FATF adds a jurisdiction in the ownership chain to its Grey List or Black List
  • New sanctions regime targets the counterparty's sector or region

Behavioral Triggers:

  • Payment routing changes (new intermediaries)
  • Counterparty changes its registered address or jurisdiction
  • Transaction patterns shift in ways inconsistent with stated business

Review Frequency:
High-risk relationships: Monthly
Medium-risk: Quarterly
Standard: Semi-annual

Customization Options

For High-Value or High-Risk Counterparties:
Extend Phase 2 to trace ownership beyond the first corporate layer, even when you hit the 25% threshold. If a disclosed owner is owned by another entity, keep going until you reach natural persons or a jurisdiction where you cannot obtain reliable data.

For Correspondent Banking Relationships:
Add a section in Phase 3 for nested account structures. Document whether your correspondent maintains accounts for other financial institutions, and whether you have visibility into those downstream relationships.

For Supply Chain Contexts:
In Phase 3, add a subsection for sub-suppliers. If your counterparty sources from or distributes through third parties, document what you know about those relationships and whether sanctions risk could enter through that route.

For Jurisdictions with Strong UBO Registries:
If you're working in the EU or UK where beneficial ownership registers are centralized, streamline Phase 2, but still document when ownership crosses into jurisdictions without equivalent transparency.

Validation Steps

Before filing this template as complete:

  1. Can You Draw the Ownership Chart? If you cannot visualize the relationships documented, you haven't traced far enough.

  2. Have You Documented Every Data Gap? Where you cannot verify the next layer, note it explicitly. "Unable to verify shareholders of [Entity Name] due to limited registry access in [Jurisdiction]" is a defensible statement. Silence is not.

  3. Did You Check the Directors? The same individuals appearing as directors across multiple entities in your counterparty's network is a signal worth noting, even if no single entity is sanctioned.

  4. Are Your Monitoring Triggers Specific? "Monitor regularly" is not a trigger. "Re-screen all traced entities within 24 hours of OFAC list update" is.

  5. Can You Defend This to a Regulator? Regulatory expectations are shifting from tick-box compliance towards demonstrating a deeper understanding of evolving risks. If an examiner asks how you identified indirect exposure, this template is your evidence that you looked beyond the name on the contract.

This isn't a one-time checklist. Treat it as a living file that gets updated when ownership changes, sanctions lists expand, or your counterparty's risk profile shifts. The goal is not to document every possible connection; it's to show you asked the right questions and followed the answers where they led.

You Might Also Like