Blogs
Beneficial ownership untangled: What's required and how APLYiD does the work for you

The AML/CFT Act requires every nonindividual customer to have its ownership traced back to real people who own 25% or more, or who control it. That means following the trail through every shareholder, trust, and holding company until an actual person is named, then risk assessing and verifying that person. APLYiD does this tracing, calculating, and verifying seamlessly, so your team never has to work through an ownership chain by hand.
Who is a beneficial owner?
A beneficial owner is an individual who directly or indirectly owns 25% or more of a customer, or who has effective control of it.
This applies whether that ownership runs through a direct shareholding or through layers of companies, trusts, and intermediaries. In practice, you're never just checking who owns the company in front of you. You're checking who owns the owner, and who owns that owner, until you reach an actual human being. A company can never be the final answer, only a person can be a beneficial owner.
This is where manual AML processes tend to slow down or go wrong, because a shareholding register only ever shows one layer at a time. The AML/CFT Act calls this identifying the ownership and control structure, and it doesn't stop until every individual holding 25% or more at any point in that chain has been identified.
What does control mean if someone owns less than 25%?
Effective control is a separate test from ownership altogether. For a company, control exists through voting power, majority shareholding, board control, or the practical ability to direct the entity's decisions, even without any formal legal right to enforce it. For a trust, the same test extends to anyone who can appoint or remove trustees, amend the trust deed, or otherwise direct how trust property is used, including a beneficiary with a vested interest of more than 25% in the trust property. For partnerships and other structures, the test narrows to control of the governing body or that same practical influence standard.
What this means day to day is that one person can control a business with zero shares in it, simply by being the person everyone actually listens to. It's a judgement call rather than a number on a share register, which is exactly why it trips up manual reviews.
What does the AML/CFT Act actually require you to do?
Every non-individual customer, meaning any company, trust, partnership, incorporated society, or unincorporated body, triggers three linked obligations:
| AML/CFT Act requirement | What it means in practice | Handled in APLYiD by |
|---|---|---|
| Identify ownership and control | Trace the chain until real individuals are named | Automated structure unwrapping workflow |
| Assess ML/FT risk | Risk rate the customer and every person behind it | Risk scoring applied at both entity and individual level |
| Verify each beneficial owner | Every named individual needs the same identity checks as the customer | Digital document and biometric verification, PEP/sanctions screening |
In other words, onboarding "the company" isn't the finish line. Your AML/CFT programme has to keep going until every qualifying individual behind it has been both risk assessed and verified, which in a layered structure can mean checking several people, not just one.
How does APLYiD take this off your plate?
Rather than a compliance officer extracting one company at a time and calculating percentage ownership across multiple layers by hand, APLYiD's workflow unwraps the structure automatically. You enter the customer, and the platform works out who sits behind it, layer by layer, surfacing the individuals who actually need to be verified.
You start by onboarding a nonindividual customer, and APLYiD unwraps the ownership and control structure behind it, checking shareholding percentages and board control at each step until it reaches named individuals. Every person who clears the 25% ownership threshold or meets a control test is surfaced automatically, so nobody has to manually decide whether a 20% stake counts or a majority shareholder without board control still qualifies.
From there, APLYiD moves straight into identity verification for each identified beneficial owner, using electronic document and biometric checks rather than requiring an in-person branch visit. Screening against politically exposed person lists, sanctions lists, and adverse media happens in the same pass. A risk assessment is also applied to both the customer and each beneficial owner individually, matching the AML/CFT Act’s requirement that both be assessed.
Every supporting document and result is retained against the customer file, giving you a complete, audit ready record without anyone needing to assemble it after the fact. The net effect is that the parts of beneficial ownership compliance involving judgement calls, percentage calculations, and cross-referencing multiple registers are handled by the platform, and your team's role shifts from doing the maths to reviewing the outcome.
APLYiD pulls beneficial ownership verification into one workflow; no more chasing constitutions, shareholder agreements and trust deeds by hand. Every document and result is stored against the customer file automatically, so your DIA audit trail builds itself as you go.








