Who really controls
the companies you depend on?

Equity Chain Mapping is a recursive investigative method that resolves ownership, control, and influence across an opaque corporate network, then follows the dependencies running the other way. It is the know-your-customer, anti-money-laundering, and due diligence tradecraft that regulated firms use every day, formalised as a repeatable cycle, pointed at a different question, and scaled to networks built across jurisdictions to resist exactly this kind of scrutiny. Not is this counterparty compliant, but who is actually behind this capability. That lineage is not borrowed theory: it is the discipline the whole team works in.
A company at the centre of two chains. Control edges run upward through holding companies, marketing shells, funding vehicles and unknown entities to ultimate beneficial owners. Reliance edges run downward through disclosed vendors, cloud and hosting, sub-processors, code libraries and fourth- and fifth-tier dependencies.
The Problem

Ownership is hidden by design

Attribution is not a fact you can look up. Where it matters most, it is the thing someone has paid to obscure. Any method that starts by naming the party you are worried about is defeated before it begins, so this one starts with the company, the contract, or the capability in front of you, and lets the party emerge as the result.
Privacy jurisdictions
Ownership routed through jurisdictions that do not publish it. Most use of these structures is entirely legitimate, which is precisely what makes them useful cover for the minority that is not.
Interposed shells
A marketing entity placed over an operating entity, which sits over a funding lineage. Each layer is a decision to spend money on concealment.
Undisclosed sub-processors
A disclosed vendor in front of an undisclosed one. The contract names a party you can check; the work is performed by a party you cannot see.
Positions below disclosure thresholds
Stakes deliberately sized below the level at which they must be reported, and influence exercised through terms rather than through equity.
Method

A Few Moves, Repeated at Every Node

The power of the method is not in any one step. It is that the whole cycle runs again against every entity, investor, and supplier it surfaces.
The equity chain mapping cycle: entity resolution, then ownership and control, then adjacency, then derogatory checks, closed by recursion, with a criticality gate deciding which nodes get another pass.
Every supplier, investor, and affiliate surfaced becomes a new node, and the whole cycle runs again against it. Concealment is layered by design, so a single-layer inquiry is defeated by interposing a single additional entity.

01

Entity resolution
Establish which of the similarly named firms is actually the one in question, and identify the corporate family it belongs to. Most errors downstream begin as errors here.

02

Ownership and control
Validate the beneficial owner and the parties exercising control. Ownership, control, and influence are kept distinct throughout. They frequently do not sit with the same party.

03

Adjacency
Follow the people and the money outward to other entities, funders, suppliers, and affiliates. Relationships that were never disclosed are found here rather than declared.

04

Derogatory checks
Sanctions, political exposure, litigation, regulatory enforcement, intellectual property, and adverse media, run against every entity and every person surfaced, not only the subject.

05

Recursion
For every supplier, investor, or affiliate identified, the entire process repeats. Concealment is layered by design, so a single-layer inquiry is defeated by interposing a single additional entity.

06

Criticality gating
A dependency graph has no natural edge, so something has to decide what is worth another pass. A node earns one on what it would cost you if it failed or turned: how much of the capability runs through it, how quickly it could be replaced, what it can reach, and what it decides on your behalf. Each pass re-ranks the graph and the ranking directs the next. Prioritization decides where to look; the looking changes the priorities.
The Equity Axis

Ownership is the first question, not the last

Most reviews treat beneficial ownership as the destination, something to arrive at once everything else has been catalogued. That order is backwards, because ownership is what makes every other judgment computable.
Consider a dependency on a single supplier. If that supplier is an ordinary commercial actor, the dependency is a sourcing problem: second-source it, hold inventory, negotiate terms. If the same supplier is controlled by a party with an interest in your failure, the identical dependency is a material risk to the business. Nothing about the dependency changed. Only its meaning changed, and its meaning is a function of who is behind it.
So the method starts from the capability, the contract, or the counterparty in front of you and resolves ownership backward until a real party emerges. That makes it agnostic to who the party turns out to be, and it turns the tactics used to stay hidden into the evidence trail that surfaces them: layered structures, jurisdictional arbitrage, substance disguised as marketing.
One named company resolved downward into the parties behind it: an operating entity and an interposed marketing shell, then holding companies in two privacy jurisdictions and a nominee director, then two funding vehicles and one entity that cannot be resolved, and finally two named beneficial owners. A third party controls the operating entity through board terms and veto rights while holding just 4%, below the disclosure threshold, so it never appears in the ownership chain at all.
One named company, resolved into the holding companies, funding vehicles, and individuals behind it. Illustrative: the shape is representative of real work, the entities are not real.
The Reliance Axis

Dependency is transitive in a way ownership is not

Ownership is a command relationship. Dependency is an exposure relationship, and exposure travels. A customer sitting three layers above an embedded sub-processor inherits all of its risk while having no relationship with it, no contract with it, and frequently no idea it exists. Risk propagates downstream automatically, and the parties carrying it are usually the last to see it.
This is why decisive control can be reached through the dependency graph rather than through equity. Nobody needs to own the systems you rely on if they can sit inside them as a sub-processor. Ownership is resolved first because it is what makes the rest computable, not because it is the only route to control.
The measure that matters here is concentration against substitutability. A single opaque node making a core decision for everyone downstream of it is a chokepoint even when its ownership is entirely clean. Clean ownership is not a guarantee, it is a snapshot. Mapping that exposure draws on a different evidence base than corporate registries: integration and partner disclosures, data-processing agreements and sub-processor lists, SOC 2 reports, software bills of materials, breach notices, and procurement records. A sub-processor that should appear in a mandated disclosure and does not is itself the finding.
A supply chain graph showing one source domain connected outward to more than a hundred third-party domains and hosts.
SCVue maps the reliance axis for software and applications, capturing the providers an application actually loads. Explore SCVue.
Know your vendor is becoming a regulatory obligation
Rules are catching up with this exposure. For defined categories of transaction, organizations are now expected to run risk-based procedures that verify who a vendor actually is rather than taking the contracting name at face value. That is a narrower obligation than filing an ownership structure, but it points the same way: know-your-vendor, not merely know-your-customer. Organizations that already understand who sits beneath their vendors will find compliance a reporting exercise. Organizations that do not will find it an investigation.
Principles

What Separates This from Screening

The method descends from compliance screening. Three things make it something else.
It is not a checklist
A checklist has a defined end. An investigation ends where the evidence ends, and where each answer changes the next question. The same list of sources, run without judgment, produces a file rather than a finding.
Absence is a question
What is not found matters as much as what is. A network of the size, age, and activity level in front of you should generate a certain volume of standard accountability events: disputes, filings, enforcement, coverage. Where a comparable peer group generates them and this network generates none, that is a reason to look harder at it. It is not, by itself, a conclusion about it: most quiet networks are quiet because nothing is happening.
Privacy is not obfuscation
There are entirely legitimate reasons to hold assets through a privacy jurisdiction, and treating every such structure as suspicious produces noise and unfair conclusions. The method distinguishes legitimate use from deliberate ownership obfuscation, and says which it believes it is looking at.
Deliverable

What You Receive

The work product is an equity chain map: a network of entities, people, and funding vehicles, with control and investment edges drawn, dissolved entities marked, and sanctioned or politically exposed connections flagged. It begins from a single company or capability and resolves an apparent single identity into its actual structure.
It comes with something equally important: a clear statement of where the open trail ends. Lawfully obtained, commercially available information takes an analyst to a boundary, and past that boundary the value is a short, prioritized list of exactly which nodes matter: the discovery requests worth making, the subpoena targets worth naming, the counterparties worth a direct question, the relationships worth putting under monitoring.
This yields indicators, not proof. It is a force multiplier, not a verdict, and it is presented that way. Findings are given with their provenance and their confidence attached, so they can be weighed rather than simply believed.
Applications

Where It Gets Used

The tradecraft does not change between engagements. Only the client and the deliverable do.
Transactions
Who is actually behind the counterparty, the co-investor, or the acquisition target, and what comes with them.
Litigation support
Structure resolved before discovery, so requests are aimed at the entities that hold the answers rather than the ones named on the pleadings.
Enhanced diligence on individuals
Ultra-high-net-worth individuals, founders, directors, and investors, mapped through the vehicles they hold assets and influence through.
Supplier and vendor networks
Multi-tier supplier bases resolved past the tier where conventional vendor review stops, including the sub-processors nobody contracted with directly.
Capital and investor screening
Funding lineages traced through venture, private equity, and fund structures, including capital that enters several rounds and several layers down.
Complex investigations
Any matter where the decisive question is who really owns, controls, or influences a network that has been built not to answer it.

Two Chains, One Question

Equity Chain Mapping resolves control upward. SCVue maps reliance downward. Together they answer the question that sits underneath every supplier decision, every investment, and every dispute: who really controls the capabilities we depend on, and what comes with them?