NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Insights11 min read· July 24, 2026

KYC for Trusts, Foundations and Complex Ownership Structures

Trusts, foundations and layered holding chains are the hardest KYC files a bank or EAM will open. Here is how to reach the ultimate natural person, map every role, and keep it current.

by Wecan

Every compliance team has a mental hierarchy of onboarding difficulty. A salaried individual with a single account sits at the easy end. At the hard end sit trusts, private foundations, layered holding chains and nominee arrangements — the files that a UHNW client brings to a private bank or an External Asset Manager and that can take a senior analyst days rather than hours to clear. These structures are not exotic edge cases; they are the normal wrapper for cross-border private wealth, and they concentrate every difficult question in KYC at once: who really owns this, who really controls it, and how do we prove we know.

This article explains why these structures are uniquely hard, what the 2026 regulatory expectation to reach the ultimate natural person actually requires, how to document each role, which patterns should trigger enhanced due diligence, and where automation makes the difference between a defensible file and a fragile one.

1. Why complex structures are the hardest KYC files

A standard onboarding answers one ownership question. A trust or foundation file answers several at once, and the answers interact.

Ownership and control come apart

In a simple company, whoever owns the shares controls the entity and benefits from it. In a trust, those three ideas — legal ownership, control, and economic benefit — are deliberately split across different people. The settlor transfers assets and may retain powers. The trustee holds legal title and administers the assets. A protector may hold veto or appointment rights. The beneficiaries receive economic benefit, sometimes only at the trustee's discretion, sometimes not yet at all. A private foundation distributes the same functions across a founder, a foundation council, and beneficiaries or a defined purpose. KYC cannot pick one of these roles and call it the owner; it has to capture all of them and understand how power actually flows between them.

The look-through problem multiplies

Rarely does the structure stop at one layer. A trust owns a holding company, which owns two intermediate companies in different jurisdictions, which in turn own the operating assets. Somewhere in that chain a nominee shareholder or director may hold on behalf of someone whose name never appears on a certificate. Each layer is a separate legal person in a separate registry with its own documents, its own language, and its own filing conventions. The regulatory obligation is not to stop at the first corporate shareholder — it is to look through every layer until you reach the natural persons at the top. For a five-layer cross-border structure, that is not one KYC file. It is a dozen sub-files that have to reconcile into a single coherent picture.

Discretion, currency and jurisdiction

Discretionary trusts add a further twist: the beneficiaries may be a class ("the settlor's descendants") rather than named individuals, and the person who decides who benefits is the trustee. Foundations can have purposes rather than beneficiaries. Documents arrive from registries that update on very different cadences — some real-time, some annual, some effectively never — so a file that was accurate at onboarding silently decays. This is why complex structures are not just harder to open; they are harder to keep correct.

2. Reaching the ultimate beneficial owner

The organising principle of modern KYC on these files is simple to state and hard to execute: identify the natural person or persons who ultimately own or control the structure, regardless of how many layers sit in between. A corporate shareholder is never an acceptable stopping point. Nor is a trustee company, a nominee, or a foundation council member acting in an administrative capacity.

The 2026 regulatory frame

In Switzerland, the Legal Entities Transparency Act (LETA) and the revised Anti-Money Laundering Act enter force on 1 October 2026, introducing a federal beneficial-ownership register and reinforcing the obligation to identify the ultimate natural-person owner behind legal entities — with lowered capture thresholds and explicit attention to layered and offshore arrangements. In the EU, the single AML Regulation (AMLR) pushes in the same direction: a harmonised, look-through definition of beneficial ownership, tighter treatment of trusts and similar arrangements, and interconnected registers. The two regimes are not identical, but they converge on one demand — the file must name the human beings at the top and evidence why they, and not someone else, are the answer.

From register to verified fact

A crucial nuance for 2026: the register is a starting point, not the finish line. Intermediaries remain obliged to verify beneficial ownership against reliable, independent sources and to resolve discrepancies rather than defer to a self-declared filing. For complex structures this means cross-checking the trust deed, the foundation statutes, the shareholder registers at each layer, and the register entry against one another — and treating any mismatch as something to investigate, not paper over. Our deeper treatment of this workflow lives in automating UBO and beneficial-ownership verification.

3. A role-by-role documentation map

The single most useful discipline for these files is to stop thinking "client" and start thinking "parties." Each structure type has a defined cast, and each member of the cast has to be identified, verified, and — where they are a natural person with ownership or control — treated as a beneficial owner in their own right. The table below maps the common structures to the parties that must be identified and the core evidence for each.

Structure type Parties to identify Documents / evidence
Discretionary trust Settlor, trustee(s), protector, named + class beneficiaries, any UBO with control Trust deed + any deeds of amendment, letter of wishes (where available), trustee incorporation & regulatory status, certified ID of each natural person, source-of-wealth on the settlor
Underlying holding company Registered shareholders, directors, ultimate natural-person owner(s) Certificate of incorporation, up-to-date shareholder register, register extract, directors' IDs, ownership-chain map to the top
Private foundation (e.g. Liechtenstein/Panama) Founder, foundation council members, beneficiaries or defined purpose, protector Foundation statutes + by-laws (regulations), council register, beneficiary schedule, certified IDs, purpose documentation
Nominee arrangement Nominee (shareholder/director) and the beneficial party behind it Nominee agreement / declaration of trust, indemnity, certified ID of the true beneficial party, board resolution appointing the nominee
Multi-layer holding chain Each intermediate entity + the ultimate natural persons Registry extract per layer, cross-border translations, consolidated ownership graph, evidence resolving each layer's control

The second table below turns that structural map into an onboarding workload, which is where the operational problem becomes visible.

Parties per file (typical) Simple company Trust over 2-company chain Foundation over 4-layer chain
Natural persons to identify 1–2 4–7 8–15
Registries / sources to touch 1 3–4 6–10
Distinct documents to collect & verify 3–5 12–20 25–40
Senior-analyst hours (manual) 1–2 h 6–12 h 15–30 h

4. Red flags and enhanced due diligence triggers

Complex structures are legitimate far more often than not — the wrapper is chosen for succession, asset protection, tax neutrality or privacy, not concealment. But the same features that make them legitimate also make them attractive for hiding control, so a defined set of patterns should escalate the file to enhanced due diligence rather than being cleared on first pass.

  • Layering without economic rationale — intermediate entities in jurisdictions with no connection to the client, the assets, or the business, and no coherent reason to exist.
  • Nominee directors or shareholders whose declared role does not match how the entity actually behaves, or who appear across many unrelated structures.
  • Opaque or non-cooperative jurisdictions at any layer, or registries that cannot be verified against an independent source.
  • A discretionary beneficiary class so broad that no natural person can meaningfully be identified as benefiting — combined with unusually large or frequent distributions.
  • Recent restructuring immediately before onboarding, or changes to trustee, protector or council that coincide with an inflow of funds.
  • Mismatch between the register entry, the constitutive documents and what the client declares — the discrepancy itself is the trigger.
  • PEP exposure anywhere in the cast — settlor, protector, council member or beneficiary — which pulls the whole structure into enhanced due diligence.

When triggered, enhanced due diligence typically means corroborating the source of wealth and source of funds with independent evidence, obtaining senior-management sign-off, tightening the review cadence, and documenting the rationale for accepting the relationship in a form an examiner can follow.

5. Where manual review breaks — and where automation helps

The workload table in section 3 explains the failure mode. A single UBO on a layered structure routinely takes a senior analyst two to four hours to establish; a foundation over a four-layer chain can consume the better part of a week across all its parties. Three things make manual review fragile at this scale.

First, registry access. The analyst logs into several national registers, each with a different interface, language and export format, pays per extract, and re-keys the results by hand — every keystroke a chance to introduce an error into a legally significant file. Second, graph construction. Turning a stack of extracts into a correct ownership graph, reconciling percentages across layers, and identifying where control actually sits is judgement work that does not scale by adding hours. Third, keeping current. Because registries update unevenly, a manually built file is accurate only on the day it is built; a change of trustee or a share transfer three layers down may go unnoticed until the next scheduled review — which for a high-risk file may be a year away.

Automation attacks all three. Registry connectivity pulls extracts across jurisdictions without manual logins; the ownership graph is constructed and reconciled automatically, flagging the layers where control is ambiguous for a human to resolve; and continuous, event-driven monitoring — the operating model behind perpetual KYC — watches the connected registries and screening feeds so a change three layers down surfaces as an alert rather than an annual surprise. The analyst stops assembling and re-keying, and starts doing the judgement work that actually requires a human.

Complex-structure metric Manual Automated (Wecan Comply) Improvement
UBO identification per party 2–4 hours Minutes ≈ −95%
Foundation over 4-layer chain (end to end) 15–30 hours 2–4 hours ≈ −85%
Registry extracts re-keyed by hand Every layer Auto-ingested
Detecting a change 3 layers down Next periodic review (≤12 months) Event-driven alert Near real-time
Cost per complex file onboarded CHF 300–800+ CHF 50–150 ≈ −75%
Files a senior analyst clears per month 15–25 80–120 ~4–5×

6. Governance and demonstrable effectiveness

For high-risk files, doing the work is no longer enough; the 2026 supervisory standard is demonstrable effectiveness — the ability to show, on demand, that the right natural persons were identified, that the evidence was independent and current, and that every judgement call has a rationale attached to it. On a complex structure this is exactly where manual processes are weakest, because the reasoning lives in an analyst's head, an email thread, and a spreadsheet that no longer matches the register.

A defensible complex-structure file has three properties. It is traceable: every party, every document, every screening result and every UBO determination carries a record of who established it, from which source, and when. It is current: the ownership graph reflects the state of the registries today, not on the day the file was opened. And it is consistent: the same look-through logic and the same evidentiary bar are applied to every structure in the book, so an examiner sampling ten trust files finds one method, not ten. A single authoritative record with a complete audit trail turns a UHNW inspection from an exercise in reconstruction into an export — which is the practical meaning of governance for these files, whether the institution is a bank or an External Asset Manager carrying the same obligation with a smaller team. The wider economics of this shift are set out in our note on KYC and AML compliance for External Asset Managers.

7. How Wecan Comply handles complex structures

Wecan Comply is built to make these files defensible rather than merely survivable. When a trust, foundation or layered holding chain is onboarded through corporate onboarding, the platform ingests the constitutive documents, connects to the relevant registries across jurisdictions, and constructs the ownership graph automatically — reaching through each layer to the ultimate natural persons and flagging, rather than silently guessing, the points where control is ambiguous and human judgement is required.

Every party in the structure is identified and screened, with contextual scoring that keeps the sanctions and PEP false-positive load manageable, and the enhanced-due-diligence triggers described above are surfaced as part of the file rather than left to the analyst's memory. The whole record — parties, documents, sources, determinations and rationale — is held as a single authoritative dossier with a full audit trail, and continuous monitoring keeps it current so that a change three layers down arrives as an alert, not as a finding at the next review.

For the hardest files a compliance team will ever open, that is the difference between a structure that is a source of anxiety and one that is a maintained, traceable, and demonstrably effective part of the book.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.