Netherlands Expands Controlled Access to UBO Register, Giving AML and Sanctions Institutions New Routes to Ownership Data
The Dutch Chamber of Commerce (KVK) is expanding controlled access to the Netherlands’ beneficial ownership register for recognised institutions subject to anti-money laundering, counter-terrorist financing and sanctions obligations, giving eligible organisations new ways to obtain certified information about ultimate beneficial owners (UBOs).

The development restores and broadens practical access to UBO information after restrictions on the register. The changes introduce new retrieval channels, including an API and KVK’s website, while access continues to be authorised on a sector-by-sector basis.
The significance for compliance teams, however, extends beyond simply making UBO records easier to obtain. The central issue is whether institutions use the information as evidence within a broader customer-risk assessment rather than treating possession of an official extract as proof that their ownership analysis is complete.
Controlled access replaces unrestricted publication
KVK is not reopening the UBO register to the public. Instead, access is being restored through controlled channels for organisations that can demonstrate that they belong to an eligible category.
Under KVK's framework, organisations must be objectively identifiable through such mechanisms as a supervisory licence, registration or compulsory professional membership.
Consequently, an organisation may fall within the scope of the Dutch Money Laundering and Terrorist Financing (Prevention) Act, or Wwft, without automatically being able to access every UBO record immediately.
KVK's current eligible sectors include civil-law notaries, banks, trust companies, certain licensed life insurers, investment firms, credit providers, payment-service providers, electronic-money institutions and money transaction bureaus. Existing subscribers to KVK's Data Service retain their access.
The authorisation process is being introduced gradually. KVK says it cannot authorise every eligible organisation simultaneously, so sectors are being invited in stages through their sector organisations. Civil-law notaries and banks are among those able to apply under the current rollout.
The practical distinction is important for compliance departments: legal eligibility and actual operational access are not necessarily the same thing.
Certified PDFs are available now, with structured data planned
Since April 2026, KVK has expanded the ways eligible organisations can obtain UBO information. A digitally certified UBO extract can now be requested through the KVK website or through an API connection. Organisations that consult the register regularly are directed toward the API, while occasional users can use the website.
The current API should not, however, be confused with a fully structured ownership-data feed.
At present, the service provides a digitally certified PDF. KVK says a JSON API providing data through structured fields is expected in 2027.
That distinction could be significant for financial institutions and other organisations planning automated onboarding, periodic reviews or transaction-monitoring workflows. Retrieving a document electronically is not the same as receiving ownership information already divided into machine-readable fields.
It is important to understand what the institution is actually receiving before estimating the technical effort required to integrate the information.
A practical implementation would need to establish, among other things, which employees or systems are authorised to retrieve information, how the original extract is preserved, how it is tied to the correct legal entity and when the document was obtained.
The article emphasises that these are operational recommendations rather than new requirements imposed by KVK.
An official extract is evidence — not necessarily proof that the ownership picture is correct
One of the article's central points is that institutions should not assume that certification of a KVK extract means the underlying ownership information has independently been established as correct.
KVK's system places responsibility for providing accurate and complete UBO information on the organisation required to register it. KVK checks whether the required information has been supplied, but it does not itself determine who the beneficial owners of an organisation are.
That creates an important distinction between what the register says and what the institution knows about its customer.
If, for example, a customer's declared ownership structure does not correspond with a newly obtained KVK extract, the discrepancy should not simply be resolved by accepting whichever document is easier to obtain.
Instead, the institution should establish whether the documents concern the same legal entity and relevant date, determine what has caused the difference and seek supporting information where appropriate.
Potential explanations could include a recent ownership change, an incomplete registration or an incorrect understanding of who exercises control. A discrepancy by itself is therefore not proof of money laundering.
The broader compliance objective is to explain the inconsistency using evidence.
This reflects the risk-based approach to customer due diligence under the Wwft. De Nederlandsche Bank's guidance extends due diligence beyond collecting identity and ownership documents to understanding the intended and actual nature of customer relationships and transactions. FATF guidance likewise supports the use of multiple information sources when establishing beneficial ownership.
Access to the register does not eliminate the need for independent customer assessment
The article argues that the value of the expanded access will ultimately depend on how institutions interpret the information.
A registered individual may be the formal UBO, but that fact does not by itself explain the customer's business model, transaction activity or the economic rationale for a particular payment.
Likewise, a complex corporate structure should not automatically be interpreted as evidence of criminality.
The relevant question is how the ownership information fits into the institution's overall understanding of the customer.
A successful API call or PDF download can establish that the institution obtained a record. It does not establish that the institution has understood the ownership structure or determined whether that structure makes sense in light of everything else known about the customer.
Institutions have a duty to report incorrect UBO information
The expanded access also strengthens the connection between ownership-data availability and data quality.
Under KVK's rules, Wwft institutions that have access to UBO information are required to report incorrect or incomplete registered information. The obligation covers, among other things:
a UBO who should be registered but is missing;
a person listed as a UBO who is not actually a UBO;
an incorrect description of the nature of a UBO's interest; and
an incorrect indication of the size of that interest.
KVK describes this process as "reporting back", and treats it as a legal obligation for covered institutions with access.
This means that discovering an inconsistency cannot simply result in a private note being placed in a compliance file.
It is recommended that institutions implementing the new access channels clearly assign responsibility for assessing discrepancies, gathering supporting evidence, submitting required feedback and monitoring unresolved issues.
The article makes clear that this proposed workflow is an operational recommendation, not a newly announced KVK reporting deadline or technical requirement.
UBO discrepancies and suspicious transactions are separate questions
A particularly important distinction concerns the relationship between register corrections and suspicious-transaction reporting.
An inaccurate UBO record does not automatically constitute an unusual transaction.
KVK feedback addresses the accuracy of ownership information. Separately, institutions covered by the Wwft must assess transactions against the applicable indicators for reporting unusual transactions to the Dutch Financial Intelligence Unit, FIU-Netherlands.
The two processes should therefore remain distinct.
As the article puts it in its FAQ:
“Is reporting a discrepancy the same as reporting an unusual transaction?”
The answer is no. A correction to KVK concerns the accuracy of the UBO register, while the Wwft assessment determines whether a transaction should be reported to FIU-Netherlands.
Conversely, the discovery of an ownership discrepancy should not automatically be treated as evidence that an unusual transaction has occurred.
Keeping the assessments separate allows compliance teams to deal with both issues without incorrectly assuming that completion of one reporting obligation resolves the other.
Different users receive different levels of UBO information
Access is also differentiated according to the organisation's status.
KVK describes three access levels, known as UBOB1, UBOB2 and UBOB3, with the amount of information available increasing according to the access level.
Information can include the type and scope of the ownership interest, name, month and year of birth, country of residence and nationality. At the highest access level, additional information can include the date and place of birth, country of birth, residential address and BSN or TIN.
Personal information may also be shielded in certain circumstances, including where a UBO is under 18, under police protection, under guardianship, or faces a relevant security risk following a criminal offence reported to police. For level-one users, shielding can limit the information available to the type and extent of the UBO's interest.
This creates an operational issue for compliance systems.
Information that is unavailable because of an institution's access rights should not be recorded or interpreted as though the customer has failed to provide it.
Distinguish between information that is unavailable to the user and information that is actually absent from the underlying record. Otherwise, systems could create misleading customer profiles or trigger unnecessary requests for clarification.
Trust-register access broadens the ownership picture
The changes also extend beyond companies and other legal entities.
Access to the separate Dutch UBO Register for Trusts has been available since June 2026. KVK says organisations authorised to access the UBO register for companies and other entities also receive access to the trust register without having to undertake a separate authorisation process. Information from the trust register can be downloaded as a PDF.
This matters because trusts and comparable legal arrangements can involve several distinct roles.
KVK's background information identifies roles including the settlor, trustee, beneficiaries and, in some cases, a protector.
For compliance purposes, therefore, identifying the trustee alone may provide an incomplete picture of who benefits from or exercises influence over the arrangement.
The article cautions against treating connected access as though it creates a consolidated ownership map. A company and a trust may form part of the same customer structure while being subject to different registration rules and supported by different documentary evidence.
The appropriate approach is to map the relationships between the entities, identify the evidence supporting each connection and record unresolved questions.
PDF access brings its own integration challenges
The current reliance on certified PDF extracts also means institutions should consider how information will be incorporated into customer files.
A compliance department could preserve the original PDF as source evidence while using a controlled process to capture relevant information in its customer systems.
Where data is entered manually or extracted from documents, information should be checked against the original source to reduce transcription errors.
Even if KVK subsequently provides structured data through its planned JSON service, issues surrounding provenance and interpretation will remain.
The article deliberately stops short of assuming that the future service will contain particular automated-monitoring capabilities or prescribe a specific software architecture.
The real test will be better compliance decisions
The broader conclusion is that easier access to ownership information should not be confused with stronger AML prevention automatically.
The article suggests that institutions should judge the value of the change by asking whether the additional access produces better compliance decisions.
Among the useful management questions are whether ownership reviews are resolving material inconsistencies, whether required feedback is actually being sent to KVK, and whether customer-risk assessments properly reflect the ownership evidence obtained.
These are suggested measures rather than official KVK performance targets.
The underlying message is straightforward: availability, accuracy and interpretation have to work together.
The Netherlands is making UBO information more accessible to authorised AML/CFT and sanctions institutions, but the effectiveness of that information still depends on what institutions do with it.
Key implications for AML and sanctions teams
The changes described in the article can be distilled into several practical points.
First, UBO access is being restored through controlled mechanisms rather than returning to unrestricted public access.
Second, the current delivery model centres on certified PDF extracts obtained through the KVK website or API, with structured JSON delivery planned for 2027.
Third, authorisation is being rolled out by sector, meaning organisations should distinguish between being legally eligible and actually being authorised to retrieve records.
Fourth, a certified register extract should be treated as important evidence but not as an automatic guarantee that the underlying ownership declaration is accurate.
Fifth, institutions subject to the Wwft must report incorrect or incomplete UBO information discovered through their work.
Sixth, reporting an inaccurate UBO record to KVK is fundamentally different from determining whether a transaction is unusual and must be reported to FIU-Netherlands.
Seventh, institutions need to understand the limits of their particular access level, including the consequences of shielded personal information.
Finally, access to the separate trust register gives institutions a wider view of ownership structures, but it does not eliminate the need to understand the relationships between companies, trusts, individuals and other legal arrangements.
In that sense, the KVK development removes an important practical barrier to obtaining beneficial-ownership evidence, but it does not fundamentally change the intellectual task facing compliance teams. The challenge remains to establish who ultimately owns or controls a customer, determine whether the available evidence is consistent and credible, and connect that ownership assessment to the customer's actual activities.
By fLEXI tEAM





Comments