Business due diligence intelligence

Due Diligence
Methodology

How a report is produced, how each finding is graded, and — just as important — what a report does not cover. Every statement below is printed in the report itself, so you can check this page against the document you receive.

What this is

This is an automated, evidence-graded screen of a legal entity from public sources. It is not customer due diligence under your own program, and it is not enhanced due diligence. It is also not a background check on a person: EVULNABLE screens businesses, and does not perform employment, tenant, consumer credit or any other individual screening. It is a starting point that shows its working, and it is designed to be checked rather than trusted.

What is assessed

Ten risk pillars. Every report states on its cover how many were assessed and names those that were not. Today 5 of 10 have a live data source; the other 5 are reported as not assessed, each with a gap recorded — never as a clean result.

Sanctions
ABAC & adverse media
Government ownership & political affiliations
Other adverse media
Financial indicators
Cyber security
ESG
Entity identification
Litigation & regulatory
Group & parent risk

Where web research is enabled, a pillar may be assessed from published sources only: pages EVULNABLE retrieved itself, each fact carrying the page, a verbatim quote checked against it, and the retrieval date. Such a fact is PUBLISHED, never OFFICIAL, and REPORTED unless two independent publications agree, in which case CORROBORATED; never VERIFIED. A pillar resting on published sources only reaches MEDIUM on a single adverse report and HIGH only on corroborated adverse reports; a single article never makes a HIGH. Every such pillar is marked as resting on published sources, and a rating that rests on them says so on the cover. A page tied to the subject by nothing stronger than its name is listed as not attributed and is never a finding.

The right company first

A report about the wrong entity is worse than no report, because it reads as reassurance — a dissolved namesake screens clean by construction.

We match on identifier first: an LEI or a registration number. Where only a name is available, the report lists every candidate found and a person chooses before any screening is scored. Nothing is guessed, and the candidates that were rejected stay in the report with the reason.

How evidence is graded

Every finding carries two marks: where it came from, and how well established it is.

OFFICIALprimary registry, court, gazette or government record
PUBLISHEDcompany disclosure, commercial database or reputable press
OBSERVEDtested directly by EVULNABLE
ESTIMATEDanalyst inference
CLIENTsupplied by the commissioning organization
VERIFIEDPrimary official record read directly by EVULNABLE (court, registry, gazette, sanctions list), or a technical test EVULNABLE ran itself.
CORROBORATEDTwo or more independent published sources agree, or a published source is confirmed by the subject's own statement.
REPORTEDA single published source or a commercial data aggregator; not independently verified by EVULNABLE.
UNVERIFIEDClient statement or analyst inference without documentary evidence.

Any finding graded below Verified should be treated as a lead for enquiry with the subject, not as an established fact. Every finding carries its source and the date it was retrieved.

How the rating is derived

The overall rating is the highest pillar rating, subject to a two-step rule: a single HIGH in pillars 1–2 (sanctions, ABAC) is sufficient on its own; a HIGH elsewhere requires a second pillar at MEDIUM or above, and is otherwise capped at MEDIUM. Pillars with no evidence are excluded from the comparison rather than counted as low, and a screen that assessed nothing is reported as INSUFFICIENT DATA. Where some pillars were assessed and others were not, the result is a lower bound rather than a rating — an unassessed pillar can raise it but never lower it — and is reported as NOT ESTABLISHED, MEDIUM OR HIGHER, or HIGH. Those terms share no word with a complete assessment except HIGH, which means the same in both, so a partial result cannot be mistaken for a full one. Averaging across pillars is deliberately not used, because it allows an unexplained data gap to be read as reassurance. The rating measures the diligence effort warranted, not the probability that the subject has acted improperly.

Where a rating reads NOT ESTABLISHED, the response is to widen coverage now — not to wait and screen the same pillars again. That is why no review date is scheduled for it.

What is not performed

This report does not perform beneficial-ownership verification: the ownership and control structure in section 4 is drawn from public registries and relationship records and is not reconciled against the subject's own declarations, identity documents or a certified ownership chart. It does not review source of funds or source of wealth, which cannot be established from public sources and require documents from the subject. Beneficial-ownership identification and verification is a standard element of customer due diligence under FATF Recommendation 10, not an enhanced one; source of funds and source of wealth are enhanced measures under Recommendation 10 for higher-risk customers, and are mandatory for politically exposed persons under Recommendation 12. All of them remain the commissioning organization's own procedure to complete before this report is relied on for onboarding.

  • Politically exposed person screening. There is no free authoritative global list, so a clean sanctions result is never allowed to imply a clean PEP result.
  • Analyst review. Reports are machine-produced today. Each one says so on its cover and in its method statement, and every page is marked DRAFT until an approval workflow exists.

Sources

Government and open registries read directly — GLEIF, Companies House, SEC EDGAR, and the OFAC, EU and UK sanctions lists — together with live technical checks EVULNABLE runs against the subject's own domain.

Each list's publication date is recorded, and a source that has stopped being updated raises a gap rather than passing silently as current.

What is not in scope

EVULNABLE reads free and openly licensed sources. It does not subscribe to the commercial aggregators — Orbis, LexisNexis, Dow Jones and their equivalents — so anything held only behind those subscriptions is outside what a Screen can see, and the gap register says so rather than leaving the absence unexplained.

Some sources are excluded by their own terms rather than by cost. A register that permits browsing but forbids commercial use of its content is not read at all, at any evidence grade, and appears as a gap naming the official record that would close it. Where a source's licence requires attribution, the report carries it.

No paid databases (Orbis, LexisNexis, Dow Jones) were used. This report complements the commissioning organization's commercial screening and does not replace it; that screening should be run in parallel for audit-trail purposes.

Who processes your data

Producing and delivering a report involves these processors:

AnthropicAI-assisted research proposals
ResendNotification email
StripePayment
CloudflareNetwork edge

Compute and storage are self-hosted. Retention is stated on every report.

This report is a risk-management screen produced from open sources. It is not a legal opinion, not a determination that the subject has acted unlawfully, and not a substitute for the commissioning organization's own customer due diligence procedure.