[ ← Back to Sequenxa Intelligence ]

Sequenxa Intelligence · Intelligence brief

[ Due Diligence ]

Executive due diligence is not a deeper background check

Three LLCs with bank accounts, no employees, and no operations were enough to place overseas workers inside more than 100 U.S. companies. The screening wasn't wrong. It was pointed at the wrong object. Here is what executive due diligence examines that a record search structurally cannot.

R.J. FinneganPublished August 2, 2026Updated July 27, 202610 min read
 Executive due diligence is not a deeper background check

Three limited liability companies. Bank accounts to match. No employees, no operations, no purpose except to make overseas workers look like they were affiliated with legitimate American businesses.


That was the machinery. On April 15, 2026, the Justice Department announced sentences for the two U.S. nationals who built it. Court documents describe more than 80 stolen American identities used to place North Korean IT workers into remote jobs at over 100 U.S. companies, many of them Fortune 500. Victim companies absorbed at least $3 million in legal fees and network remediation. One overseas participant reached technical data controlled under the International Traffic in Arms Regulations, sitting on a laptop issued by a California defense contractor.


Most of those companies ran checks. The checks came back clean.


Here is what that actually means. The screening wasn't defective. It was aimed at the wrong object. It examined individuals as presented, against records that said those individuals were fine, while the exposure lived one layer out: in the entities vouching for them, the addresses receiving their equipment, and the accounts collecting their pay.


That gap is the whole subject of executive due diligence, and it is not the same subject as a longer background check.


What background screening is built to do


Background screening verifies an individual's documented history against indexed sources: criminal records in specified jurisdictions, employment and education confirmations, credit files, and watchlist matches. It answers whether the record of a named person contains adverse findings that a searchable database has captured.


That is a real product with a real ceiling. It is also the correct starting point for most hiring decisions, and I want to be clear that nothing below is an argument against running one.


The ceiling shows up when the decision stops being about a job and starts being about trust. We covered the record-level limits in when public records search is not enough on its own and the category distinction in why a background check is not the same as corporate intelligence. This piece is about a narrower thing: what changes when the subject is an executive, a counterparty, or an advisor, and the question is not their history but your exposure.


What executive due diligence is actually trying to find


Executive due diligence evaluates the exposure an organization takes on by extending trust, authority, or proximity to a specific person. It examines the entities they control, the counterparties they introduce, the advisors who vouch for them, and whether their presented legitimacy holds up against independent sources.


The distinction is the unit of analysis. Screening studies the person. Diligence studies the perimeter around the person, because that is where consequential exposure usually sits.


An honest executive with a clean record can still bring a counterparty you should not be sitting across from. A verified résumé tells you nothing about who owns the entity that person just recommended you fund. Those are different questions, and no amount of additional record depth converts one into the other.


The records layer moved in 2025, and most programs did not move with it


This is the part I think decision-makers are still underweighting, and it is a specific, dated, documented change rather than a general trend.



In March 2025, the Financial Crimes Enforcement Network issued an interim final rule that redefined "reporting company" under the Corporate Transparency Act to cover only entities formed under foreign law and registered to do business in the United States. Every entity created in the U.S., along with its beneficial owners, was exempted from reporting beneficial ownership information.


In May 2026, the Government Accountability Office put a number on the scope. The exemption applies to over 99 percent of entities that had previously been required to report. GAO also found that Treasury has not identified actions to address the resulting gap, and Treasury disagreed with GAO's recommendation that it should. The recommendation remains open.


GAO's assessment of the substitute is the sentence worth reading twice. Most states do collect ownership and control information through entity filings, such as names of corporate officers and directors or LLC managers and members. But those individuals may not be the beneficial owners and may not exercise substantial control, and states vary in how much they collect. GAO also cited Treasury's 2026 National Money Laundering Risk Assessment, which documented cases of U.S.-based shell companies used to launder proceeds from drug trafficking, cybercrime, and fraud.

So: the federal registry that would answer "who actually controls this entity" does not cover the overwhelming majority of American entities, and the state filings that remain were never designed to answer that question.


If your diligence process assumes an entity search resolves control, that assumption is now wrong in most U.S. cases, and it went wrong quietly.


Legitimacy has become cheap to manufacture


Set the DOJ case next to the records picture and the shape of the problem gets clear.


Hopana Tech LLC. Tony WKJ LLC. Independent Lab LLC. Registered entities, financial accounts, corresponding web domains that the FBI later seized. Every artifact a verification process typically asks for, produced deliberately, for a few hundred thousand dollars in facilitation fees.


A registered entity is a receipt, not a finding. Anyone can buy the receipt.


The identity side is moving in the same direction. Palo Alto's Unit 42 analyzed more than 750 major incidents across over 50 countries for its 2026 Global Incident Response Report and found identity weaknesses played a material role in roughly 89 percent of investigations, with 65 percent of initial access driven by identity-based techniques including social engineering. Unit 42 specifically flags synthetic identities and hyper-personalized social engineering as areas where AI has lowered the cost of a convincing impersonation.


We wrote about the operational version of this in contractor access is an identity intelligence problem and what identity verification services actually validate. The executive version is worse in one specific way: nobody re-verifies a person who has already been introduced by someone credible.


The introduction is the credential nobody examines


Think about how access to a senior decision-maker actually happens. Not through an application. Through a warm introduction from someone already trusted.


That introduction is the credential. It carries the vouching person's reputation, and it usually skips every process the organization built for strangers. The advisor who brings the counterparty, the board member who brings the advisor, the family office contact who brings the deal: each hop transfers trust without transferring any verification.

It is a bit like a building where everyone badges in at the front desk except the people who arrive with someone who already has a badge. The control exists. It just doesn't apply to the pathway most visitors actually use.


The systems version of this failure is already well documented. Verizon's 2026 Data Breach Investigations Report found third-party involvement in 48 percent of breaches, up 60 percent from the prior year's dataset, and that only 23 percent of third-party organizations fully remediated missing multi-factor authentication on cloud accounts. Unit 42 recorded attacks involving third-party SaaS applications rising 3.8 times since 2022.


Those numbers describe inherited technical trust. We treated that lane directly in when vendor access becomes adversary access and vendor due diligence is not executive due diligence. What I am pointing at here is the human-relationship equivalent, which has less monitoring and no equivalent of a questionnaire.


Records verification and intelligence-led review compared

Background screening

Executive due diligence

Unit of analysis

The named individual

The trust perimeter around the individual

Primary sources

Indexed databases, court records, credential verifications

Records plus corporate filings, regulatory actions, source-based inquiry, relationship mapping

What it confirms

Whether adverse findings exist in searched jurisdictions

Whether presented legitimacy holds up against independent evidence

Blind spot

Unindexed exposure, entity control, associative risk

Nothing is guaranteed; scope is defined by the decision

Time posture

Point in time

Reviewable and updatable as the relationship changes

Output

A report of findings

An assessment of exposure tied to a specific decision


Neither column replaces the other. Screening filters candidates out of a pool, which is a genuinely useful thing to do and cheap relative to what it prevents. Diligence assesses a decision you are about to make. Ordering more screening when what you needed was an assessment is the most common version of this mistake, and it usually comes with a paper trail showing the organization did something.


Signs a situation has outgrown standard screening

  1. The counterparty was introduced rather than sourced, and no one has verified the introducer's basis for vouching.

  2. Entity ownership resolves to another entity, a nominee, or a jurisdiction that does not publish control information.

  3. The presented track record is verifiable only through sources the subject controls, such as their own website, their own references, or press they placed.

  4. The individual will receive authority, system access, or signature capacity that exceeds what a records check can justify.

  5. Timelines are compressed by the counterparty rather than by your own process, and the compression is framed as a condition of the opportunity.

  6. Advisors, intermediaries, or affiliated firms appear in the deal structure without independent verification of their standing.

  7. The decision creates exposure you cannot unwind cheaply, including regulatory inheritance, clawback risk, or reputational association.


Any one of these is a reason to widen scope. Two or more together is a reason to stop and get an assessment before the decision closes.


What to ask before extending trust, proximity, or access

  • Who controls the entities on the other side of this, and what independent source confirms it?

  • Who introduced this person, what is that person's actual stake, and would they put the vouching in writing?

  • What in the presented record can I verify without using a source the subject provided?

  • What authority or access does this decision grant, and what is the worst realistic use of it?

  • If this relationship goes wrong in eighteen months, what will the file show about what we checked and why we accepted the risk?

  • What would I need to see to change my mind, and have I actually looked for it?

That last one is the one people skip. Most diligence failures I have reviewed were not information failures. The information existed. Nobody went looking because the introduction had already resolved the question emotionally.


When to escalate


Escalate to a confidential review when the exposure is structural rather than historical: entity control that public records cannot resolve, counterparties whose legitimacy rests on self-supplied evidence, or leadership decisions where the organization inherits regulatory and reputational risk from the person it is about to trust.


What a private intelligence agency actually does covers the methodology side, including what this kind of work cannot reach. Sealed matters stay sealed. Anyone promising otherwise is selling something they do not have.


Frequently asked questions


What is the difference between a background check and due diligence?


A background check verifies an individual's documented history against indexed databases in specified jurisdictions. Due diligence assesses the exposure created by a specific decision, including entity ownership, counterparty relationships, regulatory history, and whether presented legitimacy survives independent verification. The check produces findings. The diligence produces an assessment.


What does executive due diligence cover that screening does not?


Entity control and beneficial ownership, undisclosed affiliations and associative risk, the standing of advisors and intermediaries, regulatory and enforcement history across jurisdictions, and consistency between the reputation a subject presents and what independent sources support.


Does the FinCEN beneficial ownership exemption affect due diligence?


Yes. Since the March 2025 interim final rule, entities created in the United States and their beneficial owners are exempt from reporting beneficial ownership information to FinCEN. GAO reported in May 2026 that the exemption covers over 99 percent of previously reporting entities. Determining who controls a U.S. entity now requires investigative work rather than a registry lookup.


Is executive due diligence legal?


Structured due diligence using public records, corporate filings, regulatory databases, and lawful source-based inquiry is legal and routine in regulated hiring, investment, and appointment contexts. Jurisdictional rules govern what can be collected and how it can be used in a decision, which is why scope and documentation matter as much as findings.


How long does executive due diligence take?


Scope determines duration. A focused review of entity control and counterparty standing can resolve in days. Multi-jurisdiction work involving foreign corporate structures, regulatory history, and source-based inquiry takes longer, and compressed timelines are themselves a finding worth noting.


References

Author and review

R.J. Finnegan

R.J. is special agent under Sequenxa Intelligence Agency. With a deep understanding of behavior analytics mixed in with cyber and technical warfare, R.J. brings a unique perspective to the intelligence community.

Content type: Intelligence brief. Last updated July 27, 2026. Read Sequenxa's research methodology and publication boundaries.

Provenance

Sources cited in this brief

Related entity pages

Executive Due Diligence vs Background Screening | Sequenxa