A guide to the OSINT tools used in corporate and financial investigations: corporate registries, court databases, sanctions sources, beneficial ownership registers, leaked document databases and blockchain analytics — and where their limits lie.
Open-source intelligence tools for corporate and financial investigation divide into several distinct categories, each covering a different type of information. Understanding what each category covers — and where each systematically falls short — is the starting point for using them effectively. The tools are free or commercially available; the methodology is what makes the difference between a database query and an investigation.
Corporate registries are the foundational data source in any investigation involving companies. They record legal name, registration number, registered address, officer appointments and, in many jurisdictions, beneficial ownership information. Key sources:
Beneficial ownership data — who actually controls or benefits from a legal entity — is among the most valuable and least reliable category of OSINT data. Disclosure requirements and enforcement vary dramatically by jurisdiction:
Primary sanctions data is published directly by issuing authorities and is free:
Court records are among the most valuable and least systematically covered data sources in OSINT. Major tools by jurisdiction:
For investigations involving cryptocurrency — asset tracing through blockchain, sanctions compliance for virtual asset service providers, or source-of-funds analysis — specialist tools apply on-chain analytics to trace transaction flows:
Blockchain data is public and traceable by anyone — the value of these platforms is in entity attribution (connecting wallet addresses to real-world entities) and algorithmic detection of mixing and obfuscation patterns. See Umbragarde's crypto rail case study for how on-chain tracing integrates with conventional OSINT.
The most common failure mode in OSINT-based investigation is mistaking tool access for investigative capability. Having a Companies House login does not make a PSC filing accurate; having Factiva access does not make a clean result meaningful for a high-risk CIS counterparty. What converts tool access into investigative output is methodology: knowing what each source does and does not cover, how to resolve entity ambiguity across jurisdictions, how to bridge gaps between structured sources with OSINT, and how to produce findings that are sourced, corroborated and defensible.
Umbragarde uses these tools as components of structured investigations. If you need access to a tool, these sources will serve you. If you need a finding — a corroborated, sourced, actionable answer to a specific question about a specific person, entity or structure — an enquiry is the starting point.
Corporate investigations draw on corporate registries (Companies House, OpenCorporates, national registries), beneficial ownership registers (UK PSC, ICIJ Offshore Leaks, FinCEN BOSS), court records (PACER, Gazette, CIS court databases), sanctions and PEP databases (OFAC, OFSI, EU consolidated list, commercial platforms), adverse media platforms (Factiva, LexisNexis), and blockchain analytics tools for crypto-related investigations.
Tools provide access to data. A managed investigation applies methodology: knowing which sources cover which jurisdictions, how to resolve entity ambiguity and transliteration variants, how to identify nominees, and how to produce findings that are sourced, corroborated and usable in legal or compliance contexts. Tool access is the starting point; the investigation is what produces a defensible result.
No. Tools are necessary but not sufficient. Enhanced due diligence requires an assessed, sourced analysis produced through a professional process — not a set of database results. UK MLR 2017 requires that EDD is proportionate to the risk: for high-risk counterparties, proportionate means covering the sources where material information actually exists, which requires judgment beyond tool access.
The UK PSC register (Companies House), ICIJ Offshore Leaks database, and OpenOwnership Global Register cover the most accessible public beneficial ownership data. For US entities post-2024, FinCEN BOSS contains Corporate Transparency Act filings but access is restricted. For offshore structures, the ICIJ databases from major leaks are often the only source of beneficial ownership data — formal registry disclosure is limited by design.
One confidential message is enough. We take it from there.
Make a confidential enquiry