FIND. RANK. FIX. PROVE.
Third-party risk · Enhanced due diligence report EDD-EXAMPLEHOLDI-LT-20260905 Draft — not yet reviewed or released
SPECIMEN - NOT A REAL ASSESSMENT. Example Holdings UAB does not exist. Every company, identifier, address and finding below is fabricated to show the shape of a delivered report. It is not a screen of any real organization and must not be relied on for any purpose.
Subject of report

Example Holdings UAB

UAB · LT · LEI EXAMPLE0000000000000 · Registry no. 000000000 · Vilnius, Lithuania
Report ID
EDD-EXAMPLEHOLDI-LT-20260905
Prepared by
EVULNABLE Third-Party Risk — open-source enhanced due diligence
Screening date
5 September 2026 (UTC) — all sources retrieved on this date unless stated
Jurisdictions
LT · ES · NL
Screening scope
Entity; parent and group relationships as published by the LEI register; the supplied domain. Key individuals are not screened in the mechanical layer.
Method
3 of 10 pillars assessed — not assessed: ABAC & adverse media, Government ownership & political affiliations, Other adverse media, Financial indicators, ESG, Litigation & regulatory, Group & parent risk · machine-only, not analyst-reviewed · Free public sources only; official records priced in section 11. · Retention period: not yet set. · full statement in §13
Basis
Open-source research only; the subject has not been contacted. Every finding carries an evidence label and a confidence grade — see §1 and §13.
Overall risk
MEDIUM  Standard onboarding, conditional on closing the required gaps below. · confidence: reported · full rationale in §1
Next review
4 March 2027 (180-day cadence) or on trigger event — see §12

CONFIDENTIAL — Prepared for the sole use of the commissioning organization's compliance function. Findings rely on public and open-source records and have not been put to the subject. Allegations are reported as allegations. This report is not legal advice and does not establish wrongdoing by any party.

1 Executive Summary

Risk assigned MEDIUM Confidence: reported

1 pillar(s) carry a rating below. 7 fact(s) were recorded from 3 source(s).

Nothing in this report establishes wrongdoing by the subject.

Cyber security — MEDIUM, verified. Dmarc policy: p=none; Spf record: v=spf1 include:spf.protection.outlook.com -all; Domain created: 2001-06-12

Confidence grades used in this report
VERIFIEDPrimary official record read directly by EVULNABLE (court, registry, gazette, sanctions list), or a technical test EVULNABLE ran itself.CORROBORATEDTwo or more independent published sources agree, or a published source is confirmed by the subject's own statement.REPORTEDA single published source or a commercial data aggregator; not independently verified by EVULNABLE.UNVERIFIEDClient statement or analyst inference without documentary evidence.

Any finding graded below Verified should be treated as a lead for enquiry with the subject, not as an established fact.

2 Entity Resolution & Identification

More than one organization matched the request. The table records how each candidate was identified and disposed of, so that the counterparty is matched on identifier rather than name. Identified by its Legal Entity Identifier. A similarly named Spanish company was considered and rejected: it is dissolved and carries a different registration number.

CandidateIdentifiersJurisdictionStatusDisposition
Example Holdings UAB LEI EXAMPLE0000000000000 LT ACTIVE Subject of this report
Example Holdings SL Registry no. B00000000 ES DISSOLVED Not selected — dissolved namesake, profiled in §10
Why identifier-based matching mattersName-only screening can return a namesake — often a dissolved one that reads as low-risk on stale accounts. Any screening or vendor-master process should key the counterparty to the identifier above and check registry status before scoring.

3 Entity Profile

Evidence labels used in this report
OFFICIALprimary registry, court, gazette or government recordPUBLISHEDcompany disclosure, commercial database or reputable pressOBSERVEDtested directly by EVULNABLEESTIMATEDanalyst inferenceCLIENTsupplied by the commissioning organization
Legal name
Example Holdings UAB  PUBLISHED REPORTED
GLEIF LEI record · retrieved 2026-09-05
Incorporated on
1998-04-02  PUBLISHED REPORTED
GLEIF LEI record · retrieved 2026-09-05
Parent
Example Group BV  PUBLISHED REPORTED
GLEIF LEI record · retrieved 2026-09-05

4 Ownership & Control Structure

FromRelationshipToSharePeriodEvidence
Example Group BVOwnsExample Holdings UAB?F-004

No parent or group relationship was recorded.

Gaps recorded here and stated in full in §11: G-002.

Beneficial ownership is not reconstructed in the mechanical layer. Percentages shown as "?" were not obtainable from the sources used.

5 Key Findings by Risk Pillar

Alert status reflects inherent risk to the commissioning organization given the available evidence; the confidence column states how well that evidence is established. A HIGH status with Reported confidence means "significant if true, and not yet tested with the subject".

#Risk pillarAlert statusConfidenceSummary
1 Sanctions LOW VERIFIED Ofac sdn screen: no match
2 ABAC & adverse media NOT ASSESSED Not assessed — no evidence recorded for this pillar.
3 Government ownership & political affiliations NOT ASSESSED Not assessed — no evidence recorded for this pillar.
4 Other adverse media NOT ASSESSED Not assessed — no evidence recorded for this pillar. See G-003 in §11.
5 Financial indicators NOT ASSESSED Not assessed — no evidence recorded for this pillar.
6 Cyber security MEDIUM VERIFIED Dmarc policy: p=none; Spf record: v=spf1 include:spf.protection.outlook.com -all; Domain created: 2001-06-12
7 ESG NOT ASSESSED Not assessed — no evidence recorded for this pillar.
8 Entity identification LOW REPORTED Legal name: Example Holdings UAB; Incorporated on: 1998-04-02; Parent: Example Group BV
9 Litigation & regulatory NOT ASSESSED Not assessed — no evidence recorded for this pillar.
10 Group & parent risk NOT ASSESSED Not assessed — no evidence recorded for this pillar. See G-002 in §11.
How the overall rating was derivedThe overall rating is the highest pillar rating, subject to a two-step rule: a single HIGH in pillars 1–2 (sanctions, ABAC) is sufficient on its own; a HIGH elsewhere requires a second pillar at MEDIUM or above, and is otherwise capped at MEDIUM. Pillars with no evidence are excluded from the comparison rather than counted as low, and a screen that assessed nothing is reported as INSUFFICIENT DATA. Where some pillars were assessed and others were not, the result is a lower bound rather than a rating — an unassessed pillar can raise it but never lower it — and is reported as NOT ESTABLISHED, MEDIUM OR HIGHER, or HIGH. Those terms share no word with a complete assessment except HIGH, which means the same in both, so a partial result cannot be mistaken for a full one. Averaging across pillars is deliberately not used, because it allows an unexplained data gap to be read as reassurance. The rating measures the diligence effort warranted, not the probability that the subject has acted improperly.

6 Detailed Risk Analysis by Domain

6.1 Sanctions  LOW

Ofac sdn screen: no matchOBSERVEDVERIFIED
OFAC SDN list · retrieved 2026-09-05 · F-003

6.2 ABAC & adverse media  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

6.3 Government ownership & political affiliations  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

6.4 Other adverse media  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

Gaps recorded here and stated in full in §11: G-003.

6.5 Financial indicators  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

6.6 Cyber security  MEDIUM

Dmarc policy: p=noneOBSERVEDVERIFIED

Published but not enforced. Mail spoofing this domain would still be delivered.

Live DNS check by EVULNABLE against example.com · retrieved 2026-09-05 · F-005
Spf record: v=spf1 include:spf.protection.outlook.com -allOBSERVEDVERIFIED
Live DNS check by EVULNABLE against example.com · retrieved 2026-09-05 · F-006
Domain created: 2001-06-12OBSERVEDVERIFIED

Gaps recorded here and stated in full in §11: G-001.

6.7 ESG  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

6.8 Entity identification  LOW

Legal name: Example Holdings UABPUBLISHEDREPORTED
GLEIF LEI record · retrieved 2026-09-05 · F-001
Incorporated on: 1998-04-02PUBLISHEDREPORTED
GLEIF LEI record · retrieved 2026-09-05 · F-002
Parent: Example Group BVPUBLISHEDREPORTED
GLEIF LEI record · retrieved 2026-09-05 · F-004

6.9 Litigation & regulatory  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

6.10 Group & parent risk  NOT ASSESSED

Not assessed in the mechanical layer — no evidence recorded. "No data found" is a gap, never a clear.

Gaps recorded here and stated in full in §11: G-002.

7 Chronology of Material Events

DateEventEvidence
1998-04-02Incorporated on: 1998-04-02PUBLISHED F-002
2001-06-12Domain created: 2001-06-12OBSERVED F-007
2026-09-05This report; all sources retrieved on this date unless stated

8 Related Entities Screened

EntityIdentifiersJurisdictionRoleStatus
Example Group BVLEI NOTAREALLEI000000000NLParentACTIVE

8A Key Individuals

Key individuals are not identified or screened in the mechanical layer. Directors, owners and executives are a research-layer task and are listed as a gap where a pillar depends on them.

9 Jurisdiction & Sector Context

Not assessed in the mechanical layer. Country and sector context is narrative drawn from the research layer and is reviewed by an analyst before release.

10 Name-Collision Entities

Unrelated organizations that share the subject's name and can be returned by name-based screening or persist in vendor records. Profiled so that the commissioning organization can identify and correct any record that carries their identifiers.

EntityIdentifiersJurisdictionStatusLink to subject
Example Holdings SLRegistry no. B00000000ESDISSOLVEDNot evidenced

11 Data-Gap Register

This Screen is produced from free public sources and buys no record on the client's behalf, which is what keeps its price where it is. Every gap below names the official record that would close it, the register's published fee and turnaround, and whether EVULNABLE has confirmed that a third party may obtain it, so the client decides what is spent.

Items marked ● are required before onboarding; ○ are recommended.

IDGapWhere to obtainEffort
G-001Cyber security
The domain was supplied by the requester and has not been corroborated against the company's own filings.
Confirm the domain against the subject's registry filings or its published correspondence.minutes
G-002Group & parent risk
Only the immediate parent is recorded. No wider group structure was established from a free source.
A certified registry extract for the parent.hours
G-003Other adverse media
Adverse media has not been assessed. Nothing was searched for, so nothing was found -- this is not a clean result.
A media review in the subject's own language.hours

12 Recommendations & Next Review

Disposition

Standard onboarding, conditional on closing the required gaps below. This is a risk-management judgment based on open-source material, not a determination that the subject has acted unlawfully. Two elements of your own due diligence are outside this report: verification of beneficial ownership, and review of source of funds and source of wealth. The subject should be given the opportunity to respond, and the rating revisited on the basis of that response.

Pre-onboarding (required)

  1. Close gap G-001 (Cyber security) — Confirm the domain against the subject's registry filings or its published correspondence.

Ongoing monitoring

Review cadence: 180 days while rated MEDIUM. Trigger events for immediate re-review: any new sanctions designation touching the subject's jurisdictions; any litigation or regulatory action; change of control, parent or director; new investigative reporting; a change in registry status.

13 Methodology, Sources & Limitations

Method statement

Coverage
3 of 10 pillars assessed. Assessed: Sanctions, Cyber security, Entity identification. Not assessed: ABAC & adverse media, Government ownership & political affiliations, Other adverse media, Financial indicators, ESG, Litigation & regulatory, Group & parent risk. An unassessed pillar is a gap, never a clear; the rating on the cover is bounded accordingly.
Screened
5 September 2026; every source carries its own retrieval date in the table below.
Review
Machine-only. No analyst has reviewed this document; it is a draft until an approval workflow exists.
AI assistance
No AI-assisted research was run on this case.
Paid records
This Screen is produced from free public sources and buys no record on the client's behalf, which is what keeps its price where it is. Every gap below names the official record that would close it, the register's published fee and turnaround, and whether EVULNABLE has confirmed that a third party may obtain it, so the client decides what is spent.
What this Screen did
Candidates considered at resolution2 (see section 2)
Pillars assessed3 of 10
Gaps recorded3
Retention
Retention period: not yet set.
Standing
This report is a risk-management screen produced from open sources. It is not a legal opinion, not a determination that the subject has acted unlawfully, and not a substitute for the commissioning organization's own customer due diligence procedure.

Approach

Open-source due diligence performed by EVULNABLE's mechanical screening layer on 5 September 2026. Entity resolution was performed first — identifier before name, registry status before scoring — then pillar-by-pillar screening of the confirmed subject. Every fact carries an evidence label, a confidence grade and a retrieval date. No paid databases (Orbis, LexisNexis, Dow Jones) were used. This report complements the commissioning organization's commercial screening and does not replace it; that screening should be run in parallel for audit-trail purposes.

Sanctions list coverage

Screened against the three primary government lists published for direct download: the US Treasury OFAC SDN list, the EU consolidated financial sanctions list and the UK OFSI consolidated list. PEP status, the smaller national regimes and cross-script name matching are not covered by this screen and are recorded as gaps where relevant.

Sources consulted

SourceTypeUsed forRetrieved
GLEIF LEI recordPUBLISHED
registry
Entity identification2026-09-05
OFAC SDN listOBSERVED
sanctions_db
Sanctions2026-09-05
Live DNS check by EVULNABLE against example.comOBSERVED
dns
Cyber security2026-09-05

Not performed

This report does not perform beneficial-ownership verification: the ownership and control structure in section 4 is drawn from public registries and relationship records and is not reconciled against the subject's own declarations, identity documents or a certified ownership chart. It does not review source of funds or source of wealth, which cannot be established from public sources and require documents from the subject. Beneficial-ownership identification and verification is a standard element of customer due diligence under FATF Recommendation 10, not an enhanced one; source of funds and source of wealth are enhanced measures under Recommendation 10 for higher-risk customers, and are mandatory for politically exposed persons under Recommendation 12. All of them remain the commissioning organization's own procedure to complete before this report is relied on for onboarding.

Limitations

This is a desk-based, open-source assessment produced by an automated screen. Facts graded REPORTED come from a single source or a commercial aggregator and were not certified. Pillars the mechanical layer cannot assess are reported as gaps, not as clear. The subject was not contacted and has not had the opportunity to comment to EVULNABLE. Findings graded below Verified should be treated as leads for enquiry. Nothing in this report constitutes legal advice or a finding of unlawful conduct by any person or entity.

Confidence-grade summary

PillarGradeBasisWhat would raise it
SanctionsVERIFIED1 fact(s): OFAC SDN list
Other adverse mediano evidence recordedA media review in the subject's own language.
Cyber securityVERIFIED3 fact(s): Live DNS check by EVULNABLE against example.com, Live DNS/RDAP check by EVULNABLE against example.comConfirm the domain against the subject's registry filings or its published correspondence.
Entity identificationREPORTED3 fact(s): GLEIF LEI record
Group & parent riskno evidence recordedA certified registry extract for the parent.
Report ID
EDD-EXAMPLEHOLDI-LT-20260905
Prepared by
EVULNABLE Third-Party Risk — open-source enhanced due diligence
Screening date
5 September 2026 (UTC)
Overall risk
MEDIUM Standard onboarding, conditional on closing the required gaps below.
Next review
4 March 2027

FIND. RANK. FIX. PROVE. · Confidential — for the commissioning organization's compliance function only · 5 September 2026 · DRAFT