Business due diligence intelligence
How a report is produced, how each finding is graded, and — just as important — what a report does not cover. Every statement below is printed in the report itself, so you can check this page against the document you receive.
This is an automated, evidence-graded screen of a legal entity from public sources. It is not customer due diligence under your own program, and it is not enhanced due diligence. It is also not a background check on a person: EVULNABLE screens businesses, and does not perform employment, tenant, consumer credit or any other individual screening. It is a starting point that shows its working, and it is designed to be checked rather than trusted.
Ten risk pillars. Every report states on its cover how many were assessed and names those that were not. Today 5 of 10 have a live data source; the other 5 are reported as not assessed, each with a gap recorded — never as a clean result.
Where web research is enabled, a pillar may be assessed from published sources only: pages EVULNABLE retrieved itself, each fact carrying the page, a verbatim quote checked against it, and the retrieval date. Such a fact is PUBLISHED, never OFFICIAL, and REPORTED unless two independent publications agree, in which case CORROBORATED; never VERIFIED. A pillar resting on published sources only reaches MEDIUM on a single adverse report and HIGH only on corroborated adverse reports; a single article never makes a HIGH. Every such pillar is marked as resting on published sources, and a rating that rests on them says so on the cover. A page tied to the subject by nothing stronger than its name is listed as not attributed and is never a finding.
A report about the wrong entity is worse than no report, because it reads as reassurance — a dissolved namesake screens clean by construction.
We match on identifier first: an LEI or a registration number. Where only a name is available, the report lists every candidate found and a person chooses before any screening is scored. Nothing is guessed, and the candidates that were rejected stay in the report with the reason.
Every finding carries two marks: where it came from, and how well established it is.
Any finding graded below Verified should be treated as a lead for enquiry with the subject, not as an established fact. Every finding carries its source and the date it was retrieved.
The overall rating is the highest pillar rating, subject to a two-step rule: a single HIGH in pillars 1–2 (sanctions, ABAC) is sufficient on its own; a HIGH elsewhere requires a second pillar at MEDIUM or above, and is otherwise capped at MEDIUM. Pillars with no evidence are excluded from the comparison rather than counted as low, and a screen that assessed nothing is reported as INSUFFICIENT DATA. Where some pillars were assessed and others were not, the result is a lower bound rather than a rating — an unassessed pillar can raise it but never lower it — and is reported as NOT ESTABLISHED, MEDIUM OR HIGHER, or HIGH. Those terms share no word with a complete assessment except HIGH, which means the same in both, so a partial result cannot be mistaken for a full one. Averaging across pillars is deliberately not used, because it allows an unexplained data gap to be read as reassurance. The rating measures the diligence effort warranted, not the probability that the subject has acted improperly.
Where a rating reads NOT ESTABLISHED, the response is to widen coverage now — not to wait and screen the same pillars again. That is why no review date is scheduled for it.
This report does not perform beneficial-ownership verification: the ownership and control structure in section 4 is drawn from public registries and relationship records and is not reconciled against the subject's own declarations, identity documents or a certified ownership chart. It does not review source of funds or source of wealth, which cannot be established from public sources and require documents from the subject. Beneficial-ownership identification and verification is a standard element of customer due diligence under FATF Recommendation 10, not an enhanced one; source of funds and source of wealth are enhanced measures under Recommendation 10 for higher-risk customers, and are mandatory for politically exposed persons under Recommendation 12. All of them remain the commissioning organization's own procedure to complete before this report is relied on for onboarding.
Government and open registries read directly — GLEIF, Companies House, SEC EDGAR, and the OFAC, EU and UK sanctions lists — together with live technical checks EVULNABLE runs against the subject's own domain.
Each list's publication date is recorded, and a source that has stopped being updated raises a gap rather than passing silently as current.
EVULNABLE reads free and openly licensed sources. It does not subscribe to the commercial aggregators — Orbis, LexisNexis, Dow Jones and their equivalents — so anything held only behind those subscriptions is outside what a Screen can see, and the gap register says so rather than leaving the absence unexplained.
Some sources are excluded by their own terms rather than by cost. A register that permits browsing but forbids commercial use of its content is not read at all, at any evidence grade, and appears as a gap naming the official record that would close it. Where a source's licence requires attribution, the report carries it.
No paid databases (Orbis, LexisNexis, Dow Jones) were used. This report complements the commissioning organization's commercial screening and does not replace it; that screening should be run in parallel for audit-trail purposes.
Producing and delivering a report involves these processors:
Compute and storage are self-hosted. Retention is stated on every report.
This report is a risk-management screen produced from open sources. It is not a legal opinion, not a determination that the subject has acted unlawfully, and not a substitute for the commissioning organization's own customer due diligence procedure.