To check a counterparty before a deal, spend twenty minutes clearing the registry minimum by tax ID — the company-register extract, the tax service's public risk card, arbitration-court cases, bailiff enforcement proceedings and bankruptcy records — and then do the thing almost nobody does: check the company's digital footprint rather than its paperwork, and record your check so it holds up in court. Registries prove a company exists. They don't prove anyone real stands behind it.
That gap is where the money is lost. A hollow shell with clean registries is normal, not exceptional: faking a register entry is cheap, while faking eight years of domain history is not. So this guide isn't built around the usual "step 1 — pull the extract, step 2 — check the courts." It's built around what comes after that: the OSINT layer no aggregator shows you, and the legal fixation that turns your check from a box-ticking exercise into proof of due diligence.
I write from a defensive stance, with one caveat about framing: the job is to see risk before it becomes your loss — not to build a dossier on people. Where that line runs, and why crossing it is dangerous specifically for whoever ordered the check, gets its own section below. The examples use Russian registries because that's where most of my work is, but the digital-footprint and foreign-counterparty methods are jurisdiction-agnostic.
The registry minimum in 20 minutes#
This part is common knowledge, so I won't spread it across ten sections the way competitors do — I compress it into one table, but with current addresses, because half the links in the typical guide already redirect or are dead (more on that below). All you need to start is the counterparty's tax ID (INN).
| What you check | Where (current address) | What you look for |
|---|---|---|
| Registration data | egrul.nalog.ru | status, address, director, shareholders, registration date |
| Summary card + risks | pb.nalog.ru ("Transparent Business") | unreliable-data flags, disqualification, tax regime |
| Litigation | kad.arbitr.ru | claims, amounts, role (plaintiff/defendant), red "Б" = bankruptcy |
| Debts and bailiffs | fssp.gov.ru | open enforcement proceedings |
| Bankruptcy and legal facts | fedresurs.ru, EFRSB | intent-to-bankrupt notices, creditor filings |
| Financial statements | bo.nalog.gov.ru (GIR BO) | revenue, assets, losses — copy signed by the FNS |
| Public procurement | RNP register | register of bad-faith suppliers |
| Disqualification | service.nalog.ru/disqualified.do | bans on holding office; updated daily |
You should also request a document pack from the counterparty itself — charter, the decision or minutes appointing the director, licences, financial statements, proof of resources. But keep the main thing in view: a formal pack isn't enough. In case No. 15658/09 the Presidium of the Supreme Arbitration Court held plainly that a charter, a register extract and a director-appointment order do not prove diligence — what counts is business reputation, solvency, the risk of non-performance and the presence of real resources. I'll come back to that case in the evidence section, because it's the axis of the whole topic.
⚠️ One warning up front: don't demand a copy of the director's passport — that's personal data, and collecting it makes you a data operator with all the obligations that entails under data-protection law. The registry details are enough.
Shell-company signs that were sold to you out of date#
This is where I part ways with the top of the search results. Almost every counterparty-check guide builds its steps on "shell-company signs," some of which have been officially withdrawn. Citing them as an FNS requirement means baking an error into your check policy that the counterparty's lawyer will unpick in a minute.
"A mass director in 5+ companies" — a withdrawn criterion#
The popular rule "director of more than five companies = shell" rested on FNS letters No. ГД-4-14/14126@ and ГД-4-14/14127@ of 03.08.2016 (the "more than 5" threshold for registrations after 01.08.2016; "more than 50" for earlier ones). Both of those letters were cancelled by FNS letter No. КВ-4-14/5543 of 01.04.2020. There is no legal concept of a "mass director" at all.
The wording matters here: the criterion is withdrawn, and you can't cite "more than 5 companies" as an FNS requirement. Using the heuristic as a reason to dig deeper is fine and sensible; building a deal refusal on it, or writing it into policy as a rule, is not. The Western analogue is just as mythologised: the popular "30+ directorships" threshold couldn't be confirmed — Global Witness, in The Companies We Keep, works with orders of hundreds and thousands of companies per person (the Michael Gleissner case: over 1,000 firms), and phrases the red flag as "hundreds of unrelated companies," not "five."
Address "mass registration" is the same story. The popular "5+ legal entities at one address" traces back to FNS order ММВ-7-14/72@, but that point too was removed from the list of grounds in March 2025, with an explicit caveat: a mass address does not always mean bad faith. On the "Transparent Business" front end an address is currently flagged as mass when 10 or more entities are registered there — but that's the front end's own threshold, not a statutory one, and you can't read it as an automatic shell-company marker.
Dead links from other people's instructions#
Half the entry points in the typical guide no longer work — verify that before copying anyone's instructions into your own policy:
service.nalog.ru/mru.do(mass-directors search) → redirects topb.nalog.ru, the "Participation in legal entities" tab.service.nalog.ru/svl.do→ decommissioned 09.06.2023, its function moved to the "Participation restrictions" tab (a three-year bar for anyone who held ≥50% in a debtor struck from the register).service.nalog.ru/addrfind.do(address search) — the entry point behaves inconsistently: sometimes it redirects topb.nalog.ru, sometimes it serves a working form. So it's safer to run address checks directly in "Transparent Business" than via that old link.- Alive and working:
service.nalog.ru/disqualified.do(register of disqualified persons, updated daily) andservice.nalog.ru/disfind.do.
FNS scoring from 2026: the counterparty's tool, not yours#
The most common misconception in recent guides — 2026 ones included — sounds like "the FNS now scores counterparties for you, just check the company in the new service." The mechanics are subtler, and you need to get them right, or you'll go looking for an "assess a counterparty" button that, for you, most likely isn't there.
From 01.01.2026 the legal-entity scoring service moved from experiment to a permanent legal regime: Federal Law No. 254-FZ of 23.07.2025 added Article 6.3 to the Law "On Tax Authorities" No. 943-1, and the methodology is set by FNS order No. ЕД-7-31/1041@ of 05.12.2025 (registered with the Ministry of Justice on 26.12.2025); the prior order ЕД-7-31/181@ lost force.
Why this isn't a quiet check on someone else's company#
By the text of Article 6.3, the extract is produced for a legal entity (or sole proprietor) "at its own request and/or, in cases provided for by federal laws, at the request of another person." So a request by a third party — a counterparty, bank or investor — is expressly allowed by the norm, but with two caveats the whole top of the results swallows.
First: a third-party request works only "in cases provided for by federal laws" — it's a referential norm, and without a specific law enabling a given scenario it doesn't fire for an ordinary commercial check. There's no visible public list of such cases for routine pre-deal vetting, and the mechanism sits most naturally on regulated procedures like public procurement rather than on "let me check a supplier before a one-off deal." The second caveat matters more in practice: this is never a quiet check behind someone's back. When another person requests the extract, the FNS first sends it to the assessed company itself — which gets 5 business days to file a correction request, then another 5 business days for the tax authority to decide — and only then does the extract go to the requester: no sooner than 5 business days (if there was no objection) or 10 business days (if the company filed a correction). Either way the counterparty learns it's being checked and gets to fix the picture.
None of this changes the conclusion for pre-deal work: you don't get a "quietly pull the counterparty's rating" button. The working scheme is therefore this: you ask the counterparty to send their own extract, then verify its authenticity at service.nalog.ru/scoring/ — by QR code or by INN plus a verification code. The service shows the issue date, validity period, score and status, right down to "annulled." The extract itself is free for the company, takes one business day, and is available only through the taxpayer's personal cabinet (lkul.nalog.ru for entities, lkip2.nalog.ru for sole proprietors); the public methodology front end is pb.nalog.ru/grade.html.
The scoring has two stages. Stage 1 is baseline criteria (the company is active, self-standing, with no signs of impending bankruptcy or liquidation); fail even one and stage 2 is not run. Stage 2 covers financial stability, resources and experience, one point per criterion. Some stage-2 criteria are directly relevant to your own vetting: "the founder/director shows no signs of mass registration," "long duration of the entity's existence," "headcount above 50."
57 and 33, not 55 and 31#
A small detail almost the whole top of the results trips over. Most guides, including fresh "2026 breakdowns," give the criteria count as "55 and 31." By the order in force that's wrong: there are 57 criteria for legal entities (stage 1 — items 1–14, stage 2 — 15–57) and 33 for sole proprietors (stage 1 — 1–10, stage 2 — 11–33). I counted the lists by hand in Appendix 1 to order ЕД-7-31/1041@ (the file 16593572_1.docx on the order's page at nalog.gov.ru); the "55/31" pair gets copied around because the lists are followed by notes with their own 1–9 numbering, which is where counters slip. The 57/33 figure does show up in some legal analyses of the methodology, but it hasn't reached the search results for counterparty-check queries yet.
One more thing from the primary source that competitors miss: a request can be filed no more than once a day per template form (clause 3 of Appendix 2). And the real stage-1 criteria give a feel for the bar: no VAT discrepancies above 0.65% of the deduction total over four periods; no tax arrears exceeding both 1% of assets and 3,000 rubles at once.
When registries are clean: the layer aggregators don't see#
Guides tend to stop exactly where it gets interesting: "registries are clean — go ahead." But a shell with clean registries is ordinary. The layer no aggregator holds is the age and history of a company's digital presence. Everything below I checked with live queries (July 2026), and here we get close to what open-source checks on companies and people do as a service.
Domain age and site history#
The first reflex from other guides is "check the domain with whois." On Windows that won't work: there's no whois command in PATH or in System32. The working replacement is RDAP, whois's successor by protocol:
curl -s https://rdap.verisign.com/com/v1/domain/example.com
In the response, look at the events[] array and the entry with eventAction: "registration". For bellingcat.com, RDAP returns 2014-01-26.
Here's the nuance nobody spells out: RDAP shows the current registration date, and it resets on re-registration after a drop. For that same bellingcat.com, RDAP gives 2014 while the Wayback Machine has snapshots from 2006 (a previous owner). Two conclusions follow, both of which break the naive logic: a "fresh domain" is not evidence in itself (honest rebrands happen), and an old domain is no absolution (you can buy one with history). Age only reads in tandem with the site archive:
curl --max-time 90 "https://web.archive.org/cdx/search/cdx?url=example.com&collapse=timestamp:4&limit=20&output=json&fl=timestamp,original,statuscode"
collapse=timestamp:4 gives one snapshot per year (:6 per month). The archive.org API is slow — set a 60–90 second timeout. What to look for: a gap in snapshots plus a change of site topic = a change of owner. For a quick single-date check there's the instant https://archive.org/wayback/available?url=example.com×tamp=2015.
Connected infrastructure#
Next, the web infrastructure around the domain. All free and keyless:
- Certificates and subdomains —
crt.sh:curl "https://crt.sh/?q=%25.example.com&output=json". Returns subdomains and certificate issue dates; often throws 502, so retries are needed. - Scan history —
urlscan.io:curl "https://urlscan.io/api/v1/search/?q=page.domain:example.com". Writepage.domain:specifically, notdomain:— the latter catches sites that merely load resources from the domain and returns noise. - Reverse analytics (what other sites tie to the same owner): the classic
spyonweb.comis dead — DNS doesn't resolve, though "2026" round-ups and even old Bellingcat guides still recommend it. Live alternatives:dnslytics.com/reverse-analytics,osint.sh/analytics,hackertarget.com/reverse-analytics-search.
One more thing about analytics-counter correlation — it has degraded, and you should know that so you don't waste time. Google Analytics UA identifiers were switched off in July 2023; the old UA-XXXXXXX-X correlated by account root, while the new GA4 G- ones are flat — only an exact match catches anything. The current tool is bellingcat/wayback-google-analytics (it pulls UA/GA4/GTM from the archive), but with a ~10-URL limit and an archive.org ban of 5–10 minutes if you exceed it. Correlation by IP/ASN and certificates (the method T.Hunter practises) still works, but it's a technique with caveats, not a reliable sign: it shows something for a company with its own subnets, and proves nothing on mass hosting where one IP holds thousands of sites.
There's a limit worth naming outright rather than dodging: you cannot check someone else's corporate domain in Have I Been Pwned. HIBP only opens domain search after you prove you're authorised to manage the domain (via DNS TXT or a meta tag). So "check the counterparty's domain in HIBP" is impossible — whereas checking whether your own corporate data has leaked is entirely your right.
What Kontur.Focus and SPARK won't show#
Paid aggregators cover the registry layer well and save you hours — but only the registry layer. What they structurally lack: domain age and history, connected web infrastructure, whether the staff is real, physical address checks, foreign structures outside Russia/Belarus/Kazakhstan, behavioural signals in correspondence. As a price anchor: basic annual access to Kontur.Focus for 2026 starts at roughly 28,000–32,000 rubles (with monitoring of a limited number of counterparties), while SPARK doesn't publish prices — always confirm exact figures with the vendor, tariffs get revised yearly. The point is simple: an aggregator is a registry-layer accelerator, not a check. The methodology is the combination "aggregator + OSINT layer + fixation."
OSINT ≠ underground lookups: where the line runs, and why it's your risk#
Here's a line accounting portals pass over in silence, and OSINT search results blur with spam. The difference between legitimate OSINT and "probiv" (underground data lookups) isn't ethics — it's the data source. Legitimate tools query public endpoints: Sherlock, Maigret, WhatsMyName, theHarvester — the same family I covered in the piece on username search and enumeration. "Probiv" bots trade in the contents of leaks and internal databases.
A concrete trap: searching "Sherlock bot" turns up nothing but SEO spam from GitHub orgs (sherlok-probiv-bot, sherlock-tg-probiv and the like) parasitising on the name of the legitimate sherlock-project/sherlock. These are different things, and someone Googling "Sherlock" is very likely to land in the wrong place.
Why this is the client's risk, not just the operator's. Since 11.12.2024, Article 272.1 of the Russian Criminal Code is in force (introduced by law No. 421-FZ of 30.11.2024): up to 4 years for the basic offence, up to 5 for special categories and biometrics, up to 8 years plus a 2-million-ruble fine for cross-border transfer. But set the prison term aside — there's a purely practical argument too: under Article 50 of the Constitution, evidence obtained in breach of the law has no legal force. So "probiv" material won't protect you in the very tax dispute the check was meant for. The lawful route to closed data is a court motion to compel its production from the data operator.
Foreign counterparty: a 2026 map of free registers#
Here other people's instructions fail especially often: they send the reader to entry points that closed two or three years ago. The current map of free access for 2026 looks like this:
- OpenCorporates (140+ jurisdictions) — since 01.08.2023, data only for registered users. Free "Permitted User" status is for journalists, NGOs, academia and personal interest; corporations and financial institutions need a subscription (API from £2,250/year). It has no global beneficial-owner register — it mirrors national registers.
- UK Companies House —
find-and-update.company-information.service.gov.uk, search is free; the PSC register discloses control at a >25% share/votes stake or the right to appoint a majority of the board. - OpenSanctions — sanctions and PEPs; licensed CC-BY-NC 4.0, meaning free for non-commercial use only, with a paid Screening API for commercial use.
- ICIJ Offshore Leaks (
offshoreleaks.icij.org) — Panama/Paradise/Pandora, 810,000+ structures, data through 2020, no account needed. - GLEIF (
search.gleif.org) — the global LEI identifier: Level 1 "who is who," Level 2 "who owns whom." - Hong Kong — the old Cyber Search Centre was replaced by the ICRIS e-Services Portal (
e-services.cr.gov.hk) on 27.12.2023. Only name search is free; company particulars cost HK$22. - China — the official register is GSXT (
gsxt.gov.cn, run by SAMR); the key identifier is the USCC, 18 characters (Unified Social Credit Code). Tianyancha and Qichacha are commercial layers over GSXT. Note: gsxt.gov.cn doesn't always open from outside China (captcha, regional limits), so have a VPN ready and don't count on instant access.
Sanctions: the 50% rule#
A separate layer that Russian-language material reduces to "check the lists." The key thing here is the OFAC 50% rule: an entity owned in aggregate 50% or more, directly or indirectly, by blocked persons is itself considered blocked — even if it isn't on the SDN list. The aggregation is literal: two SDN persons at 25% each means a block. The rule speaks only of ownership, not control.
Fresh and important: on 31.03.2026 OFAC issued the guidance "Sham Transactions and Sanctions Evasion", where the 50% rule is called a "floor, not a ceiling" for due diligence — the emphasis shifted from a formal ownership share to actual control and the beneficial-ownership structure. Check against OFAC Sanctions List Search; bear in mind that the OFAC and EU lists diverge and update on different rhythms.
Fixation: turning a check into evidence#
"Save screenshots" is advice everyone gives. What actually makes a screenshot evidence, and when a notary is required — nobody does. And this is the part the whole check exists for: to show due diligence in a tax dispute.
A self-certified screenshot is admissible evidence; a notary is not mandatory. That's stated directly in clause 55 of the Russian Supreme Court Plenum ruling No. 10 of 23.04.2019: admissible are "printouts of materials posted online (screenshots), made and certified by persons participating in the case, indicating the address of the web page from which the printout was made, as well as the exact time it was obtained."
Mandatory screenshot attributes (FNS letter No. СА-4-7/5589 of 31.03.2016): date and time obtained; the site's name and ownership; details of the person who displayed and printed the material; the software and hardware used. Such printouts are weighed on par with other evidence (Art. 71 of the Arbitration Procedure Code, Art. 67 of the Civil Procedure Code).
Three depth levels by deal size#
"The bigger the deal, the deeper the check" — everyone writes it as self-evident, but it's a direct norm. Clause 16 of FNS letter No. БВ-4-7/3060@ of 10.03.2021 fixes the gradation explicitly: the requirements for choosing a counterparty "cannot be identical" for an ordinary small-sum purchase and for acquiring an expensive asset or a deal carrying disproportionate risk. I verified this word-for-word against the official .doc on the FNS site — no paywall needed.
From that, a working model — three depth levels tied to the deal's size and nature:
- A one-off small-sum deal — the registry minimum from the first table, screenshots with attributes.
- A material sum / expensive asset — plus the OSINT layer (domain, infrastructure), a request for the FNS scoring extract from the counterparty, a resources check.
- A large or disproportionately risky deal — plus the foreign and sanctions layer, notarial preservation of evidence, and for a complex structure — escrow accompaniment of the deal as a way not to hand money over directly.
From the same letter (clause 14) comes a criterion missing from Russian guides: a sign of imprudence is "concluding a deal in breach of internal approval procedures... or contrary to business strategy." That's a direct argument for a written check policy as an internal document: without it you have no "internal procedures" to follow, and no answer to "on what criteria did you choose?"
When you actually need a notary#
Notarial preservation of evidence (Arts. 102–103 of the Fundamentals of Notary Legislation) isn't always needed — only when the content might disappear before trial (a site taken down, a page deleted). It costs noticeably more than a screenshot: a notary fee of 3,000 rubles plus a charge for legal and technical work (around 3,000 rubles per page of the protocol's descriptive part and 100 rubles per attachment), so in practice a website inspection protocol in Moscow runs from ~14,000 rubles — confirm the exact sum with the notary, it depends on volume. In all other cases a self-certified screenshot under clause 55 is enough. The key rule people trip on: the check must be done before the deal — diligence can't be assembled after the fact.
What the director personally risks#
This section is for the people who make decisions, not the ones who prepare the paperwork. The consequences of an unchecked counterparty sit in three layers, and the third one lands personally.
- Tax. Denial of VAT deductions and profit-tax expenses under Art. 54.1 of the Tax Code — if the obligation was performed not by the contracting party but by a "technical" company.
- Deal losses. Money gone, goods undelivered, the account turning out to belong to someone else.
- The director's personal liability. The Supreme Court consistently holds that a director must build a system for vetting counterparties, not check case by case. If there's no system, losses can be recovered from them personally.
That's exactly why a check policy and monitoring aren't bureaucracy for its own sake — they're protection for the director's own wallet. For large and structurally complex deals it's sensible not to rely on your own check alone but to add external control over settlements via escrow.
A check is a process, not a document signed once#
A counterparty who's clean at signing turns into a problem by the third payment — and the check "was done." So a one-off check has to become monitoring. The free circuit:
- Fedresurs (
fedresurs.ru/monitoring) — after login, "add monitoring," alerts on changes. - kad.arbitr.ru — the "electronic guard": subscribe to specific cases with notifications.
- ZACHESTNYIBIZNES — subscribe to changes by INN/OGRN.
- Your own sheet + RSS (the T.Hunter method): Google Sheets as a monitoring hub with conditional formatting.
What to monitor: a change of director, address or shareholders, an unreliable-data flag, a decision on impending strike-off, new claims (especially where the counterparty is the defendant), bankruptcy cases, and appearance in the bad-faith suppliers register.
After signing: the bank-details swap#
The most expensive moment of a deal isn't choosing the counterparty — it's the email "we've changed our bank details." The typical BEC (business email compromise) scenario: the accountant's mailbox is compromised, a quiet forwarding rule is set, and then counterparties get an email about changed details — from the real address, inside the real thread. A registry check is useless here: the entity is real, the contract is real, the account is someone else's.
The control that works: a change of details is confirmed only by a call to a number known in advance — not the number in the email — and that rule is written into the contract and the policy. On your own side, basic operational hygiene helps, the kind I wrote about in the piece on OPSEC: alerts on mailbox logins from a new device and regular audits of forwarding rules.
If the counterparty is a sole proprietor or self-employed#
Three differences that matter for risk. First: a sole proprietor is liable with personal property, so the check shifts to the individual — the FSSP enforcement-proceedings database, EFRSB (personal bankruptcy), the FNP register of movable-property pledges (reestr-zalogov.ru, free and round-the-clock search). Second: self-employed status is checked as of a date — the FNS service by INN and date; the status can be lost, and then the client gets charged personal income tax and contributions with penalties. Third: the self-employed have prohibited activities — a deal from the "forbidden" list collapses the status on its own, which doesn't happen with a sole proprietor.
FAQ#
Can I check a counterparty through the new FNS scoring service?#
Quietly and unilaterally — no. A request by another person is allowed by Art. 6.3 of Law No. 943-1, but only "in cases provided for by federal laws," and with mandatory notice to the company itself: it receives the extract first and can file a correction before you ever see it. For an ordinary pre-deal check the working scheme is to ask the counterparty to send their own extract and verify its authenticity at service.nalog.ru/scoring/. The extract is free, takes one business day, and is available only through the personal cabinet.
How many companies make a director "mass"?#
There's no "more than 5" threshold anymore — the criterion was withdrawn by FNS letter No. КВ-4-14/5543 of 01.04.2020. It's a heuristic for "dig deeper," not a live FNS rule, and you can't cite it as a requirement.
Do I need a notary for a screenshot to count as evidence?#
No. Under clause 55 of Supreme Court Plenum ruling No. 10, a screenshot certified by the party itself is admissible — with the page address and the exact time obtained. A notarial inspection protocol (a 3,000-ruble fee plus a technical-work charge, in practice from ~14,000 rubles) is only needed when the content might disappear before trial.
What documents should I request from the counterparty?#
The charter, the decision or minutes appointing the director, licences, financial statements, proof of resources. Don't demand a copy of the director's passport — that's personal data. And remember: a formal pack isn't enough — in case No. 15658/09 the Presidium of the Supreme Arbitration Court held that a charter, an extract and an appointment order don't prove diligence.
What happens if I don't check a counterparty?#
Three layers of consequences: denial of deductions and expenses under Art. 54.1 of the Tax Code; losses on the deal itself; and the director's personal liability — the Supreme Court holds that a manager must build a vetting system, and where there's none, losses are recovered from them.
Is it legal to "probiv" a counterparty?#
No. "Probiv" means working with the contents of leaks and internal databases, and since 11.12.2024 it falls under Art. 272.1 of the Criminal Code. Legitimate OSINT queries public sources only. "Probiv" data is useless on top of that: obtained in breach of the law, it has no evidentiary force in a dispute.
