An offshore company does not usually “control” a domestic banking system merely because its customers can send or receive local currency. Cross-border payments are delivered through a chain of regulated banks, payment institutions, e‑money firms, card acquirers, agents, technical processors and settlement systems. The important investigative question is which entity performs each function, under whose licence, and where the risks ultimately sit.
Map the payment chain before assigning control
Begin with the customer-facing brand, but do not stop there. Identify the contracting entity, licensed payment provider, merchant acquirer, safeguarding bank, correspondent banks, foreign-exchange provider, processor and ultimate settlement system. Record each party’s jurisdiction, regulatory status and role. A brand may own the interface while relying entirely on an unrelated licensed institution for account issuance and movement of funds.
The Bank for International Settlements’ CPMI explanation of correspondent banking describes how several intermediary banks may participate in one cross-border payment chain. That is different from direct membership of an onshore payment system. Analysts should verify whether the offshore-linked business is a direct participant, an indirect participant, an agent, a programme manager or simply a customer of another provider.
Separate ownership, access and operational dependence
Ownership of a processor or payment institution can influence strategy, but legal ownership does not prove day-to-day control of settlement. Access may come through sponsorship agreements, correspondent accounts, agency arrangements or application programming interfaces. Conversely, an onshore licensed entity may depend heavily on an offshore parent for technology, compliance staff, customer acquisition or treasury decisions.
Draw two diagrams: a legal-ownership chart and an operational flow chart. Then compare them with contracts, bank-account names, licence registers, customer terms, settlement instructions and technical documentation. Trider’s analysis of payment institutions and structural risk allocation helps distinguish contractual responsibility from the location of infrastructure.
Test licensing and territorial reach
Do not describe an offshore firm as operating “outside regulation.” It may be licensed in its home jurisdiction, passport services where permitted, act through a local subsidiary or serve only another regulated institution. Check the official register for the exact legal entity and activities. Confirm whether it may hold customer funds, issue e‑money, acquire merchants, execute transfers or provide only technical services.
The regulatory perimeter also depends on where customers and merchants are located. A licence held by one group company does not automatically cover every affiliate or brand. Marketing pages, footer disclosures, account terms and payment descriptors should identify the entity responsible for the service. Inconsistencies are a reason to investigate, not proof of unlawful activity.
Examine safeguarding and third-party dependence
Where a UK payment or e‑money institution receives relevant customer funds, the Financial Conduct Authority’s current safeguarding guidance explains the applicable protection framework. Safeguarding is not the same as deposit protection, and the exact obligations depend on the provider and service.
Map where funds are held, how they are reconciled, who can instruct transfers and what happens if a bank or processor fails. Also test concentration: one sponsor bank, correspondent or cloud provider can become a critical point of failure. Trider’s guide to payment-provider indirect exposure illustrates how foreign providers and settlement partners can transmit operational, legal and liquidity risk into an onshore market.
Review AML, sanctions and transaction visibility
Determine which participant identifies the customer and beneficial owner, screens sanctions, monitors transactions, investigates alerts and files reports. Contractual delegation does not necessarily remove the licensed firm’s responsibility. Request the allocation of duties, escalation routes, audit rights and information-sharing arrangements. Weak data exchange between layers can prevent one participant from seeing the complete customer and transaction picture.
Recent reporting provides practical examples but must be attributed carefully. Malta Media’s report on an onboarding restriction affecting Inpay’s iGaming business shows how access to international payment corridors can remain dependent on supervisory expectations as well as technology and bank connectivity. The report should be checked against the cited regulator’s decision before supporting any entity-specific conclusion.
Measure actual influence
Evidence of material influence may include the power to select settlement banks, set risk rules, approve merchants, control transaction routing, hold encryption keys, manage liquidity or terminate downstream access. Volume concentration and technical indispensability also matter. An offshore-linked provider can be operationally important without owning the onshore infrastructure, while a legal owner may exercise limited operational control.
A defensible report states who owns each entity, who is licensed, who contracts with the customer, who holds funds, who processes data and who settles the payment. It also identifies unresolved gaps and the date of each source. That precise mapping is more useful than claiming that an offshore company broadly “controls” domestic banking rails.