Most of the work is documentary and public-record based, and much of it is slow rather than clever. The value lies in knowing which registers to pull, in which jurisdiction, and in reading them against each other rather than in isolation.
What does a corporate due diligence check actually cover before a deal?
A pre-deal check normally runs across four layers, and a competent one keeps them separate so that a weak finding in one is not quietly offset by a strong finding in another.
Corporate existence and standing. The company is checked at its registry of incorporation: certificate of incorporation, current status, filings history, charges and mortgages, and any striking-off or restoration notices. Where the entity operates through branches, the equivalent local registrations are pulled. A company that is active at home but unregistered where it trades is a common and material finding.
Ownership and control. The share register, the constitutional documents, and any shareholders’ agreement that is disclosed are read together. The question is not only who holds the shares but who can direct the votes, appoint the board, or block a sale. Nominee arrangements, trusts, and layered holding companies are normal in some markets, and the check should describe them rather than treat them as automatically suspicious.
Directors and management. Each director and senior officer is checked for disqualification, bankruptcy, sanctions and litigation exposure in the jurisdictions where they have operated. Resignations clustered around a particular date, or a board that changes entirely shortly before a transaction, are worth a written explanation.
Commercial and regulatory position. Licences, regulated status, material contracts, and known disputes are reviewed. In regulated sectors the check also asks whether the target’s permissions actually cover the activity it is being paid for.
A check of this kind is described in more detail by publications that cover the field, such as The Diligence Review, which treats pre-deal verification as one of its three main subjects. The scope should be agreed in writing before work starts, because an open-ended mandate produces a long report and no decision.
How do I verify that a company and its beneficial owners are who they claim to be?

Verification is a chain, and it is only as strong as its weakest link. The practical sequence is: establish the legal entity, then establish the ownership chain, then establish the natural persons at the end of it, then test each step against an independent source.
Start with the legal entity. Obtain the registration number and the jurisdiction of incorporation directly from the counterparty, then confirm both at the registry rather than through a copy of a certificate the counterparty supplies. Registry extracts, not scanned certificates, are the working document.
Then walk the ownership chain. In jurisdictions with a public beneficial ownership register, the register gives a starting position, but it is a filing by the company and it can be stale or incomplete. Where no public register exists, the chain is built from share registers, annual returns, and corporate filings in each holding jurisdiction. Each layer should be documented with the date it was checked, because ownership changes.
Then identify the natural persons. A beneficial owner is normally a person who ultimately owns or controls a defined percentage of the shares or voting rights, or who exercises control by other means. The definition used should be stated, since thresholds differ between regimes. Where a trust or foundation sits in the chain, the check looks at the trustee, the settlor, the protector and the beneficiaries, not only at the entity.
Finally, test the result. Names are matched against sanctions lists, politically exposed person designations, and disqualification registers, with dates of birth and other identifiers used to reduce false positives. A name match alone is not a finding; an unexplained match is a question.
Two limits are worth stating on the same page as the method. First, no open-source process proves that a person is not a front for someone else. Second, registers in some jurisdictions are accurate as of filing and no more recent. Both limits belong in the report.
What is a reputation audit and what can it find that a database cannot?
A reputation audit is a structured search of open sources about a person or a company, followed by an assessment of what the material actually shows. It is not a database query with a longer output. Databases are good at answering closed questions: is this name on a sanctions list, is this company registered, has this director been disqualified. They are poor at answering the questions that decide deals.
What a reputation audit adds is context and pattern. It looks at local-language media, court reporting, regulatory notices, trade press, and archived material that has been removed from the live web. It reads a lawsuit for what was alleged and what was decided, rather than recording that litigation exists. It notices that a company’s public profile changed at the same time as a change in ownership, or that a director’s earlier ventures share an address, an auditor, or a pattern of short lifespans.
It also handles the negative finding properly. A clean reputation audit does not mean nothing was found; it means the searches were defined, the sources were listed, and the absence of adverse material is reported within those limits. Adverse media screening that returns nothing because the search was run in one language is not a clean result.
Where the audit is used in a dispute or a regulatory context, the standard of the underlying evidence matters. Material that may end up in a filing or a hearing needs a documented chain of custody, and that requirement shapes how the research is collected from the start rather than at the end.
Where the three exercises meet
Pre-deal verification, ownership tracing and reputation work are usually sold as separate services, and in practice they overlap. The ownership chain tells you whose reputation to check. The reputation check tells you which parts of the ownership chain deserve a second look. The corporate record tells you whether the person you are checking was actually in control at the time the events you found took place.
Running them in sequence rather than in parallel is usually a mistake, because each one generates questions for the others. A workable structure is to agree the scope, run the corporate and ownership work first, use its output to define the reputation searches, and then reconcile the two before writing conclusions.
What the output should contain
The deliverable is not a dossier. It is a short set of findings, each tied to a source, with the date the source was checked and a clear statement of what remains unverified. A useful report distinguishes between three things that are often blurred: what the records show, what the records do not cover, and what the researcher infers. Only the first is evidence.
Two practical points follow. First, every finding should be traceable to a document a third party could obtain, or the report should say that it is not. Second, the report should state its own limits: jurisdictions not searched, languages not covered, periods not reviewed. A reader who knows the boundaries can use the report; a reader who does not will treat it as more complete than it is.
None of this removes deal risk. It changes the point at which the risk is identified, which is usually the difference between a price adjustment and a write-off.