
When a shareholder sits outside the EU, run the ownership and control tests together, verify every ultimate beneficial owner against government-grade identity standards, screen all named individuals against sanctions and PEP lists, and document each step. Skip any of these four, and your eligibility file or audit trail has a hole in it. Escalate immediately if you find veto rights, opaque ownership chains, or nominee arrangements.
TL;DR:
- Running ownership and control tests together and verifying every ultimate beneficial owner against government standards is essential to maintain a complete audit trail.
- Non‑EU shareholders should be scrutinized through legal identifiers, sanctions screening, ownership mapping, and governance rights, with increased focus on control rights through shareholder agreements.
- Documents like statutes, shareholder agreements, and registry extracts must be collected upfront to prove ownership, with identity verification extending to certified IDs and shareholder meeting minutes.
- Enhanced due diligence is mandatory when layered ownership, nominee arrangements, or governance rights don’t match economic interest, requiring source-of-funds and transaction history reviews.
- Regular re-verification and automated triggers are necessary to detect share transfers, changes in control, or material asset shifts, ensuring ongoing compliance in volatile ownership structures.
Table of Contents
- Quick Checklist: Ordered Actions to Run First
- How Do You Apply the Dual Ownership and Control Test?
- What Documents Prove Non-EU Shareholder Ownership?
- When Does a Shareholder Check Require Enhanced Due Diligence?
- How Often Should You Re-Verify Non-EU Shareholders?
- How Does Non-EU Control Affect EU Grant Eligibility?
- Where Fintech Infrastructure Fits Into Verification Workflows
- What the Industry Gets Wrong About Non-EU Shareholder Checks
- Sources
Quick Checklist: Ordered Actions to Run First
Start with the paper trail, not the phone calls. A compliance officer working a non‑EU shareholder file gets the most value from a fixed sequence, run in this order every time:
- Pull legal identifiers first. Get the company’s registration number, current statutes, and the most recent shareholder list on file with the relevant registry.
- Screen immediately. Run sanctions and PEP checks on every listed shareholder and every named ultimate beneficial owner (UBO) before you do anything else. This is fast, cheap, and catches the worst-case scenarios early.
- Map ownership to natural persons. Trace every intermediate holding company, trust, or nominee structure until you reach a real person or a documented dead end.
- Check for governance rights that ownership percentages hide. Look for veto powers, board appointment rights, or contractual control clauses.
- Assign a preliminary risk rating. Decide whether standard due diligence is sufficient or whether the file needs enhanced due diligence (EDD).
A few things trip up teams at this stage:
- Shareholder lists go stale fast, especially for companies that raised a funding round or restructured in the past year.
- A “clean” ownership percentage can mask control through a shareholders’ agreement that never shows up in the registry extract.
- Screening only the top-line shareholder and missing a UBO buried three layers down is the single most common gap auditors flag.
Not every shareholder needs the same intensity of scrutiny. The scope of checks should scale with risk, jurisdiction, and company type rather than applying uniform depth to every name on the list, according to LexisNexis guidance on corporate client due diligence.
How Do You Apply the Dual Ownership and Control Test?
Ownership percentage alone will mislead you. The EU’s approach, and increasingly Lithuanian regulatory practice, requires two separate tests run in parallel: an ownership test and a control test. They frequently produce different answers, and both must be recorded in your determination file.
The ownership test is arithmetic. Multiply the ownership percentage across each layer of the chain:
- A non‑EU parent company owns a majority stake of a holding company, which in turn owns a significant portion of the Lithuanian operating entity. The combined effective non‑EU ownership stake exceeds the ownership threshold that governs UBO determination under the EU’s Anti-Money Laundering Regulation, which shifted wording to “25% or more” and made this calculation an audit point, per analysis of the AMLR UBO threshold.
The control test is qualitative, and it is where most verification failures happen. You are looking for:
- Veto rights over budget approval, strategic decisions, or new financing.
- Board appointment or removal power, even without matching economic ownership.
- Contractual decision-making authority written into a shareholders’ agreement, side letter, or voting trust.
Here is the case that catches teams off guard: a non‑EU investor holding only 15% of the shares, well under any ownership threshold, can still hold a veto right over major decisions written into the shareholders’ agreement. That veto makes the entity non‑EU controlled regardless of what the cap table shows, because EU Ownership and Control Assessment guidance treats negative control as equivalent to positive control for eligibility purposes. If your ownership and control tests point in different directions, record both outcomes and explain the reasoning. When neither test identifies a natural person as UBO, the fallback is to name the senior managing official, a step the same EU guidance spells out explicitly.
What Documents Prove Non-EU Shareholder Ownership?
Requesting the right documents up front saves weeks of back-and-forth later. Build your evidence request around what each document is meant to prove, not just what looks official.
Core corporate documents to request:
- Statutes or articles of association, to confirm the legal structure and any class-based voting rights.
- Shareholders’ agreements, which is where veto rights and negative control usually live.
- Share ledgers and transfer histories, to confirm the current shareholder list matches recorded transactions.
- Minutes of shareholders’ meetings and board minutes, which often reveal governance arrangements the statutes don’t mention.
- Proxy authorizations, since a proxy holder can exercise voting rights on behalf of an absent shareholder.
Registry and identity evidence to cross-check:
- National register extracts, which in Lithuania means pulling data through Registrų centras’ shareholder list submission process.
- UBO register entries, checked against the corporate filing to catch discrepancies.
- Certified identification documents for every named UBO, not just the primary contact.
Lithuanian company law itself sets baseline requirements for what a share register must contain, including names, personal identification numbers, addresses or company codes, share counts, and payment dates, under the national rules on share accounting in closed joint-stock companies. That statutory baseline is your floor, not your ceiling. If a shareholder’s documentation meets the legal minimum but leaves the control question unanswered, ask for the shareholders’ agreement anyway. For a full document checklist tailored to account opening, Demivolt’s guide on required KYC documents walks through what companies typically submit and why each item matters.
When Does a Shareholder Check Require Enhanced Due Diligence?
Sanctions and PEP screening belongs at the start of the process, not the end. Run every listed shareholder and every named UBO against the EU consolidated sanctions list, UN and OFAC lists, and a current PEP database before you invest time in deeper ownership mapping.
Certain patterns should trigger enhanced due diligence (EDD) automatically:
- Layered ownership structures built through multiple jurisdictions with no obvious commercial rationale.
- Nominee shareholder arrangements, where the registered holder is not the economic beneficiary.
- Governance rights that don’t match economic interest, such as a small shareholder with outsized board control.
When EDD triggers, the file should expand to cover source-of-funds documentation, a review of transaction history, and a stronger identity check than the standard tier requires. AMLR’s dual-assessment requirement means you cannot substitute a strong ownership finding for a weak control finding, or vice versa. Both tracks need independent evidence, and both need to be logged with a clear record of what was checked and when, so the determination survives an audit request months or years later.
How Often Should You Re-Verify Non-EU Shareholders?
Verification isn’t a one-time event. It has a cadence, and it has triggers that override the cadence entirely.
- Standard-risk shareholders: re-verify annually, aligned with your regular AML review cycle.
- High-risk shareholders: re-verify annually at minimum, and more frequently if the risk rating or jurisdiction warrants it.
- Event-triggered rechecks, regardless of schedule, whenever a share transfer occurs, a director changes, or material assets move between entities.
Event-driven monitoring needs to be automatic, not something a compliance officer remembers to do manually. A share transfer that isn’t flagged the week it happens is a gap in your audit trail the moment a regulator asks about it. Registry subscriptions and automated screening feeds cut the manual burden considerably, catching changes as they’re filed rather than waiting for the next scheduled review. For the recordkeeping side of this, practical guidance on audit-ready documentation retention covers how long to keep evidence and how to index it so an auditor can trace a determination back to its source documents without a scavenger hunt.
How Does Non-EU Control Affect EU Grant Eligibility?
Some EU funding calls, particularly in Horizon Europe and the European Defence Fund, restrict participation based on ownership and control rather than nationality alone. If your ownership and control tests flag a non‑EU controlling interest, that finding can determine whether your organization is eligible to participate at all.
The Ownership Control Assessment (OCA) process requires participants to submit a formal ownership control declaration along with supporting evidence. Expect EU services to request the same document set covered earlier: statutes, shareholders’ agreements, minutes, and identification of intermediate and ultimate owners.
If the assessment finds non‑EU control, participation isn’t automatically closed off. A guarantee, approved by a competent national authority, can preserve eligibility by addressing the security or strategic concerns the restriction is meant to catch. Build your proposal timeline around this reality:
- Run the OCA internally before submission, not after a reviewer flags it.
- Have your ownership control declaration and supporting documents ready before the call deadline, not assembled under pressure afterward.
- If a guarantee looks necessary, start that conversation with the national authority early. Guarantee approval takes time you won’t have if you wait for a rejection notice.
Background on how EU authorities assess control in cross-border holding structures is covered in a guide to EU holding company frameworks, useful reading if your ownership chain runs through a holding entity for tax or structural reasons.
Where Fintech Infrastructure Fits Into Verification Workflows
The bottlenecks in most non‑EU shareholder files are mundane: incomplete document sets, registry extracts that take weeks to arrive from another jurisdiction, and identity checks that don’t meet the assurance level an auditor expects. None of that requires a legal breakthrough to fix. It requires better infrastructure around the workflow.

Government-grade eID verification, paired with a regulated business account, closes a lot of that gap. A dedicated IBAN under a regulated framework means the payment rail itself carries a documented compliance trail, which matters when a shareholder’s funds need to be traced as part of source-of-funds evidence during EDD. Demivolt operates as a regulated European fintech platform, offering dedicated IBAN accounts, SEPA and SWIFT payment processing, and compliance controls built for cross-border business relationships, exactly the kind of structure that keeps a shareholder verification file consistent with how the money actually moves. For a broader view of why this matters beyond a single verification exercise, Demivolt’s guide on EU banking compliance covers the regulatory direction driving these standards higher.
What the Industry Gets Wrong About Non-EU Shareholder Checks
Most compliance teams treat non‑EU shareholder verification as a documentation exercise: collect the paperwork, check the box, move on. That’s backwards. The paperwork is evidence for a judgment call, not a substitute for one. The real work is the control test, and it’s the part teams consistently underinvest in because it doesn’t reduce to a percentage on a spreadsheet.

The AMLR’s shift to a mandatory dual assessment should have settled this argument, but plenty of firms are still running ownership calculations and treating the control question as a formality. That’s the gap that gets flagged in an audit, not the ownership math. If you take one thing from this playbook, prioritize the shareholders’ agreement over the cap table. A clean ownership percentage tells you nothing about who actually controls a decision when it matters.
The other place conventional advice falls short is treating verification as a one-time gate at onboarding. Ownership structures shift quietly, through share transfers, board reshuffles, financing rounds, and a file that was accurate in January can be wrong by June. Build the recheck triggers into your process now, before a regulator or grant reviewer finds the gap for you.
— dd
Sources
Self-declared shareholder lists are no longer sufficient on their own. Institutional compliance increasingly expects identity verification that meets a recognized assurance standard, not a scanned passport emailed as an attachment.
Three source categories build an audit-ready file:
- Ownership and Control Assessment — EU Funding & Tenders Portal
- Guidance on participation in EU calls with ownership and control restrictions — European Commission (PDF)
Pro Tip: Build a reconciliation log every time a KYB provider’s data conflicts with a national registry extract. Auditors care less about the discrepancy itself and more about whether you noticed it and wrote down how you resolved it.
The workflow that holds up under audit runs registry data and eIDAS-grade identity checks side by side, then treats any mismatch as a required investigation rather than a rounding error. Demivolt’s guide to digital identity in banking covers how eIDAS-based verification fits into a broader onboarding workflow, and the same logic applies directly to shareholder checks.