← Back to news

AML Screening for Shell Companies: Best Practices

· 6 min read

AML Screening for Shell Companies: Best Practices

Shell companies are legal, common and frequently abused. Here is how to screen them without stalling legitimate onboarding.

Why shell companies matter in AML

A shell company is a registered legal entity with no significant operations, staff or assets of its own. There is nothing inherently unlawful about one: they are used every day for holding intellectual property, ring-fencing liability, structuring investment vehicles and preparing for a merger. The problem is that the same qualities that make them useful for legitimate business — speed of incorporation, minimal disclosure and layered ownership — make them attractive to anyone trying to distance illicit funds from their origin.

For a compliance team, that means shell entities cannot simply be blocked. They have to be understood. The objective of screening is not to decide whether an entity is a shell, but to establish who ultimately controls it, why it exists and whether its activity matches the story it tells at onboarding.

Start with ownership, not paperwork

The single most valuable output of a corporate check is a reliable ultimate beneficial owner (UBO). Registry documents tell you the legal owner; they rarely tell you the natural person behind it. Effective screening walks the chain upwards through every intermediate entity until it reaches individuals, and records the percentage of ownership and control at each step.

Where the chain crosses jurisdictions with limited disclosure, the gap itself is a finding. Document it, escalate it and require the customer to supply a signed ownership declaration supported by corporate documents. An unverifiable UBO is a risk decision, not an administrative delay.

Once individuals are identified, they should be screened exactly as a retail customer would be: sanctions, politically exposed person status, adverse media and watchlists — with continuous rescreening rather than a one-off check at signup.

Red flags worth acting on

Certain patterns repeat across enforcement cases. A registered address shared with dozens of unrelated entities. A company incorporated weeks before a large inbound transfer. Directors who are nominees appearing across many unconnected businesses. Stated activity that does not match the transaction profile — a consultancy receiving bulk commodity payments, for example. Rapid changes of ownership, name or registered agent shortly before onboarding.

None of these alone proves wrongdoing. Together they should raise the entity's risk score and trigger enhanced due diligence rather than an outright refusal.

Enhanced due diligence that is proportionate

Enhanced due diligence should be a defined package, not an open-ended investigation. In practice that means source-of-funds and source-of-wealth evidence, an explanation of the corporate structure's purpose, verification of the operating business behind the entity, and senior sign-off before the relationship is approved.

Set expected activity at that point. A shell entity that has been approved on the basis of a specific commercial rationale should be monitored against that rationale, so a deviation surfaces automatically instead of waiting for an annual review.

Make it repeatable

The difference between a compliance function that scales and one that does not is usually workflow, not effort. Risk scoring rules should be written down and applied consistently, every check should leave an immutable audit trail, and analysts should see corporate data, UBO screening results and document verification in one case file rather than four systems.

Horus Checks brings company registry data, UBO tracing, sanctions and adverse-media screening and document verification into a single automated KYB flow, so low-risk entities clear in minutes and your team spends its time on the cases that genuinely need judgement.

Talk to our team

See how Horus Checks automates KYC, KYB and AML for your onboarding flow.

Contact Us