Skip to main content
Category: AML and KYC

Ultimate Beneficial Owner

Also known as: UBO, Ultimate Beneficial Ownership
Simply put

An Ultimate Beneficial Owner (UBO) is the actual person who ultimately owns or controls a company or other legal entity, even when that ownership is held indirectly through layers of other businesses. Identifying the UBO answers the question of which real individual is truly behind a customer that is itself an organization rather than a person.

Formal definition

A UBO is the natural person who ultimately owns or controls a legal entity, such as a corporation or partnership, through direct or indirect ownership or through the exercise of effective control. Some sources describe the UBO as sitting at the top of the ownership chain, typically holding a significant stake (for example, 25% or more) or otherwise exercising effective control, though applicable ownership thresholds and control criteria vary by jurisdiction and regulatory framework and should be confirmed against the governing rules. In transaction contexts, a UBO may also be characterized as the ultimate beneficiary when an institution initiates a transaction.

Why it matters

Identifying the Ultimate Beneficial Owner addresses a core problem in Know Your Customer (KYC) and anti-money laundering compliance: when a customer is a legal entity rather than a natural person, the institution needs to know which real individual ultimately owns or controls that entity. Without this visibility, layered ownership structures can obscure who is actually behind an account or transaction, which undermines the ability to assess risk, screen against sanctions and watchlists, and detect illicit activity.

For payment processors, acquirers, and merchant risk teams, UBO identification is part of due diligence when onboarding business customers and merchants. Understanding who ultimately controls an entity helps institutions evaluate whether a relationship carries elevated risk and helps satisfy regulatory obligations tied to customer identification. The specific ownership thresholds and control criteria that trigger UBO identification vary by jurisdiction and regulatory framework, so institutions should confirm requirements against the governing rules rather than assuming a single universal standard.

Because UBO determination depends on tracing ownership and control through potentially multiple layers of intermediate entities, it is an area where incomplete or outdated information can create compliance gaps. UBO identification is intended to reduce the risk that a legal entity is used to conceal the identity of the person truly behind it, though it does not by itself eliminate financial crime risk and must be combined with broader due diligence and monitoring controls.

Who it's relevant to

Compliance and KYC Teams
Compliance officers and KYC analysts use UBO identification to determine which natural person ultimately owns or controls a legal-entity customer, supporting customer due diligence and screening. Because applicable ownership thresholds and control criteria vary by jurisdiction and regulatory framework, these teams should confirm the specific requirements that govern their obligations.
Acquirers and Payment Processors
When onboarding business customers and merchants that are legal entities rather than individuals, acquirers and processors rely on UBO determination to understand who is truly behind the relationship. This helps inform risk assessment during onboarding and ongoing due diligence.
Merchant Risk Teams
Merchant risk teams use UBO information as part of evaluating whether a business relationship carries elevated risk, particularly where ownership is held indirectly through layers of other entities that could otherwise obscure the controlling individual.
Financial Institutions Initiating Transactions
In transaction contexts, an institution may need to identify the UBO as the ultimate beneficiary when it initiates a transaction, connecting the transaction to the natural person who ultimately benefits from or controls the entity involved.

Inside UBO

Beneficial Ownership Identity
The natural person or persons who ultimately own or control a legal entity, as distinct from nominee directors, intermediary holding companies, or registered agents whose names may appear on incorporation documents.
Ownership Threshold
A defined percentage of ownership or voting rights above which an individual is treated as a beneficial owner. Thresholds vary by jurisdiction and program, so the applicable figure should be confirmed against the governing regulation or network rule rather than assumed.
Control Test
An assessment of who exercises effective control over an entity through means other than direct equity, such as senior management authority, contractual arrangements, or the right to appoint or remove directors, capturing individuals who fall below an ownership threshold but still direct the entity.
Verification Evidence
Documentation and data used to establish and confirm UBO identity, which may include corporate registry records, ownership structure charts, and identity documents. The sufficiency of evidence depends on the applicable due diligence program and risk rating.
Ownership Structure Mapping
The layered representation of how ownership and control pass through intermediate entities to reach natural persons, used to see through complex or multi-jurisdictional structures to the ultimate individuals.
Merchant Onboarding Context
In payments, UBO identification is a component of Know Your Customer and merchant due diligence performed by acquirers and payment processors when boarding a merchant, supporting anti-money-laundering and merchant risk objectives. Note that AML and KYC obligations are governed by applicable law and network rules, not by PCI DSS.

Common questions

Answers to the questions practitioners most commonly ask about UBO.

Is identifying the Ultimate Beneficial Owner (UBO) a PCI DSS requirement?
No. UBO identification is a concept rooted in anti-money-laundering (AML) and know-your-customer (KYC) obligations, not in PCI DSS. PCI DSS governs the protection of cardholder data and sensitive authentication data, not the identification of the natural persons who ultimately own or control a merchant or entity. Acquirers and payment processors may perform UBO due diligence to satisfy AML/KYC and card brand onboarding obligations, but these are separate frameworks from PCI DSS. You should confirm the specific obligations against your applicable regulatory regime and network rules rather than treating UBO checks as a PCI DSS control.
Does the UBO simply mean the majority shareholder or the person listed as the company's legal owner?
Not necessarily. The UBO refers to the natural person or persons who ultimately own or control an entity, which is not always the same as the registered legal owner or a single majority shareholder. Ownership may be held indirectly through layered corporate structures, nominee arrangements, or trusts, and control can be exercised through means other than direct shareholding. Definitions and ownership or control thresholds vary by jurisdiction and by the applicable AML framework, so the UBO must be determined by tracing ownership and control rather than by reading a single ownership label.
When onboarding a new merchant, when should UBO identification be performed?
UBO identification is typically performed as part of the KYC and due diligence steps during merchant onboarding, before the merchant is enabled to process transactions, and may be revisited during periodic reviews or when a material change in ownership or control occurs. The precise timing, documentation, and refresh cadence depend on the applicable AML regulations, the acquirer's or processor's risk-based policies, and card brand onboarding rules. Confirm the requirements against your governing regime rather than assuming a fixed schedule.
What information is generally collected to verify a UBO?
The information collected commonly includes the natural person's identifying details and evidence sufficient to establish and verify their ownership or control of the entity, along with documentation of the ownership or control chain where structures are layered. The exact data elements, verification methods, and acceptable evidence are defined by the applicable AML/KYC regime and internal risk policy, and they vary by jurisdiction and entity type. Note that any such personal data should be handled under applicable privacy and data protection obligations, which are separate from PCI DSS scope.
How does UBO due diligence relate to a merchant's fraud and risk profile?
UBO due diligence can help acquirers and processors understand who ultimately controls a merchant, which may inform onboarding decisions and ongoing risk monitoring. It is intended to support AML/KYC objectives and may help identify certain higher-risk relationships, but it is not a fraud detection control for individual transactions and does not by itself prevent fraud. Transaction-level fraud risks such as card-not-present fraud, account takeover, or transaction laundering require separate monitoring and controls. UBO checks and transaction fraud controls address different risks and should be treated as complementary rather than interchangeable.
What should be done when the ownership structure is too complex to identify a UBO?
When layered ownership, nominee arrangements, or opaque structures make a UBO difficult to determine, the applicable AML/KYC framework and internal risk policy generally define escalation and enhanced due diligence steps, which may include obtaining additional documentation, applying a defined fallback approach to identify controlling persons, or declining or restricting the relationship. Because the required treatment of unresolved or high-risk cases varies by jurisdiction, regulator, and network rules, confirm the specific procedures against your governing regime rather than applying a single fixed rule.

Common misconceptions

The UBO is whoever is listed as director or registered agent on the incorporation documents.
Directors, nominees, and registered agents may not be the ultimate beneficial owners. The UBO is the natural person who ultimately owns or controls the entity, which may require looking through nominee arrangements and layered structures to identify individuals rather than relying on the names on formation records.
Identifying the UBO is a PCI DSS requirement for merchant boarding.
UBO identification is part of KYC and AML due diligence obligations governed by applicable law and card network rules, which are separate from PCI DSS. PCI DSS addresses the protection of cardholder data and does not itself define beneficial ownership obligations.
A single ownership percentage threshold applies everywhere.
Thresholds and control tests differ by jurisdiction and program, and both an ownership test and a control test may apply. The applicable threshold and criteria should be confirmed against the current governing regulation or network rule rather than assuming a fixed figure.

Best practices

Map the full ownership and control structure to natural persons, applying both the ownership threshold and the control test rather than stopping at the first layer of directors or registered agents.
Confirm the applicable ownership threshold and control criteria against the current governing regulation and card network rules for each jurisdiction, since these vary and change over time.
Collect and retain verification evidence proportionate to the merchant's risk rating, and document the basis for how each identified UBO was determined.
Treat UBO identification as part of KYC and AML due diligence during merchant onboarding, keeping it distinct from PCI DSS cardholder data protection obligations.
Establish periodic review and refresh of UBO information so that changes in ownership or control are captured after initial boarding.
Escalate structures that cannot be resolved to identifiable natural persons for enhanced due diligence rather than boarding on incomplete ownership information.