What Can Third-Party Verification—and What Can It Not—Confirm?

A third-party check is only as broad as its defined scope. Learn what identity, registry, signature, financial, valuation and technical checks may confirm—and which conclusions still require separate review.

A third-party check can add useful evidence to an asset package. It can compare information with a source, test a document or provide a professional opinion within a defined scope.

It should not be treated as a universal seal of approval. An identity check, registry search, signature validation, audit, valuation and technical assessment answer different questions. None automatically answers all the others.

Key point: A verification result should be read as: who checked what, against which source, using which method, on what date, with what result and limitations. The word verified on its own does not provide enough information.

“Third-party verification” is not one service

The expression may refer to many different activities, including:

  • checking identity evidence;
  • matching company information to an official register;
  • screening names against sanctions or other databases;
  • validating an electronic signature or file integrity;
  • confirming a bank account or payment;
  • reconciling an amount to a ledger or source document;
  • reviewing ownership or a chain of title;
  • auditing financial statements;
  • assessing credit risk;
  • providing a valuation;
  • inspecting an asset; or
  • testing software, data or cybersecurity controls.

Before relying on a result, identify the precise question the provider agreed to address. A narrow automated match is different from an assurance engagement, expert opinion or legal due-diligence review.

Identity verification

An identity provider may compare a person's details, identity document, photograph, biometric information or electronic identity credential. Depending on the process, the result may support a conclusion that the person presenting the evidence corresponds to a particular identity.

That result does not automatically confirm:

  • that the person is authorised to represent a company;
  • that the person owns the asset or right;
  • the identity of every beneficial owner;
  • the truth of statements made by the person;
  • creditworthiness, solvency or source of funds;
  • that the proposed transaction is lawful; or
  • how the person will behave in the future.

The record should identify the provider, the person checked, the method, the result, the date and any expiry or refresh requirement. Avoid replacing this detail with a broad label such as party verified.

Company and registry checks

A company-register search may confirm that specified information appeared in a particular register at a particular time. Depending on the register, this may include a company's name, number, status, registered office, officers, filings, accounts, charges or insolvency information.

The result should not be expanded beyond the register's own scope. It may not establish that:

  • every filed statement is complete, current or factually correct;
  • a person signing a specific contract had authority to do so;
  • the company owns a particular asset;
  • there are no undisclosed liabilities, disputes or competing interests;
  • the company is solvent or able to pay; or
  • a transaction is legally valid or enforceable.

For example, Companies House now performs checks and has enhanced powers to query, annotate and remove information. Its current guidance still explains that the search service is not comprehensive, that occasional inaccuracies may occur and that only basic checks are made when accounts are examined. A search result is therefore useful evidence of what the register showed, not a substitute for all other due diligence.

Use a precise status such as company number and status matched to the Companies House record on [date], rather than company fully verified.

Electronic signature and document-integrity checks

Electronic-signature validation may test the integrity of signed data, the validity and status of a certificate and other elements of the signature process. A cryptographic hash comparison may show that the tested file has not changed since a particular hash was created.

These checks can be valuable for authenticity and provenance, but they do not by themselves prove:

  • that every statement in the document is true;
  • that the document contains the complete agreement;
  • that the signatory understood the document;
  • that the signatory had corporate or legal authority;
  • that required consents or formalities were satisfied;
  • that the agreement is enforceable; or
  • that the asset described in the document exists, is owned or has value.

The European Commission's eSignature guidance describes qualified-signature validation in terms such as data integrity, certificate validity and the qualified status of the certificate. Those are important and specific conclusions; they should not be presented as validation of every legal or factual statement in the signed document.

Document extraction, matching and reconciliation

A reviewer or automated tool may compare a structured field with a supplied document, ledger or data source. The result may confirm, for example, that:

  • a stated date matches the date shown in a contract;
  • a company number matches a registry result;
  • an amount was extracted from a particular invoice;
  • a payment appears in a supplied account record; or
  • a calculated balance reconciles to the supplied inputs under a stated formula.

This improves traceability. It does not necessarily establish that the source itself is authentic, complete, legally correct or current. Nor does it show that all relevant amendments, payments, side letters, disputes or competing records were provided.

Use language such as matched to the supplied contract or reconciled to the records provided as of [date]. Do not convert a source match into an unqualified statement that the underlying fact has been proven.

Ownership and chain-of-title review

A lawyer, registry specialist or other qualified reviewer may examine agreements, assignments, corporate records and official registers to assess ownership or a chain of title.

The conclusion still depends on matters such as:

  • the documents and jurisdictions included in the review;
  • whether originals or reliable copies were available;
  • undisclosed assignments, licences, security interests or disputes;
  • the accuracy and currency of registry information;
  • the legal assumptions and qualifications used; and
  • events occurring after the review date.

An opinion about ownership of one defined right does not automatically confirm its value, transferability, absence of encumbrances or eligibility for a proposed transaction. Record the asset, jurisdiction, review period and qualifications to which the conclusion applies.

KYC, sanctions and AML screening

Customer due-diligence and screening services may identify a customer, seek beneficial-ownership information, compare names against specified lists or flag risk indicators. Results are generally time-sensitive and depend on the identifiers, databases, matching rules and thresholds used.

Such a result does not guarantee that:

  • all beneficial owners or controlling persons have been identified;
  • there is no money-laundering, fraud or sanctions risk;
  • the source of funds or wealth is legitimate;
  • a false positive or false negative has not occurred;
  • circumstances or lists will not change; or
  • the transaction satisfies every applicable legal or regulatory requirement.

The FATF Recommendations describe customer due diligence as part of a wider risk-based framework that also includes beneficial-owner identification, understanding the relationship and ongoing monitoring. A single screening result is not the whole process.

Record the provider, databases or lists used where appropriate, matching result, date, unresolved alerts and whether ongoing monitoring or refresh is required. Do not publish sensitive identity or screening data merely to show that a check occurred.

Financial statements, audits and credit assessments

Audited financial statements can provide assurance about defined historical financial information under the applicable reporting and auditing framework. Different engagements provide different levels of assurance; an audit is not the same as a review, agreed-upon procedures report or compilation.

Even an audit does not automatically confirm:

  • the value or collectability of a specific asset outside the engagement scope;
  • future revenue, cash flow or solvency;
  • that a debtor will pay;
  • the absence of all fraud or error;
  • the legal validity of every underlying contract; or
  • the price a buyer will offer.

The IAASB describes a financial-statement audit as providing reasonable assurance, not an unlimited guarantee. A credit score or risk report is also a model- and date-specific assessment, not a promise of future payment or recovery.

Valuation reports

A valuation may estimate value for a defined asset, purpose and date using specified information, methodology and assumptions. Its usefulness depends on whether its scope fits the decision being considered.

A valuation does not automatically confirm:

  • legal ownership or enforceability;
  • that supplied information is complete;
  • transferability or the absence of restrictions;
  • that a buyer exists;
  • the final transaction price; or
  • future performance or recovery.

IFRS 13, for example, provides a defined framework for fair-value measurement when another IFRS requires or permits it. That accounting measurement concept does not turn every stated claim amount or indicative estimate into fair value.

Record the valuer, asset, purpose, valuation date, standard or methodology, principal assumptions, information relied on, limitations and any permitted reliance or use restrictions.

Technical and security assessments

A technical reviewer may test a particular product, code version, environment, control or dataset using a defined procedure. The report may identify observed vulnerabilities, test results or compliance with specified technical criteria.

It does not necessarily confirm:

  • the absence of every vulnerability;
  • the security of versions or environments that were not tested;
  • future security after the system changes;
  • ownership of the software or training data;
  • compliance with every law, licence or contract;
  • commercial performance or value; or
  • suitability for every intended use.

NIST guidance emphasises that security testing techniques have different benefits and limitations and should be planned and interpreted within an assessment process. Record the tested system and version, environment, date, methodology, exclusions, findings and remediation status.

A useful verification record

For each third-party result, record at least:

  1. Provider — who performed the check and in what role.
  2. Subject — the person, company, document, right, amount, system or asset examined.
  3. Question — the precise matter the check was designed to address.
  4. Scope — included documents, periods, jurisdictions, systems and exclusions.
  5. Sources — registers, documents, databases, records or samples used.
  6. Method — matching, validation, reconciliation, inspection, audit, valuation or another procedure.
  7. Date — when the check was performed and the information cut-off date.
  8. Result — the provider's actual conclusion or status, without broadening it.
  9. Exceptions — mismatches, alerts, qualifications, missing information and unresolved questions.
  10. Limitations — assumptions, reliance restrictions and matters outside the engagement.
  11. Evidence — the report, receipt, reference number or other supporting record.
  12. Refresh status — whether the result expires or needs ongoing monitoring.

This structure allows a reviewer to decide how much weight to give the result. It also preserves the difference between a source-backed fact, a provider's opinion and an unresolved assertion.

Better labels make verification safer

Prefer specific descriptions such as:

  • identity evidence checked by [provider] on [date];
  • company status matched to [register] on [date];
  • electronic signature certificate validated on [date];
  • amount reconciled to the supplied ledger as of [date];
  • ownership opinion obtained for [defined right and jurisdiction];
  • sanctions screening completed against [specified sources] on [date]; or
  • security test completed for [system and version] within the stated scope.

Avoid broad badges such as fully verified, legally verified, risk free, guaranteed authentic, confirmed value or approved for trading unless a competent provider has expressly reached that conclusion within an appropriate and clearly disclosed framework. In many cases, those labels will still be too broad.

What DaDepo does—and does not do

DaDepo can help organise a third-party report alongside the asset documents, record its provider and date, link it to the subject it concerns and display its scope, status and limitations in an Asset Passport.

Unless a service expressly states otherwise, storing or displaying a third-party result does not mean that DaDepo has:

  • performed the underlying verification;
  • appointed, endorsed or supervised the provider;
  • adopted the provider's conclusion as its own;
  • confirmed that the report is complete, current or suitable for a particular purpose;
  • certified identity, authority, ownership, legal validity, compliance, value or transferability; or
  • guaranteed registration, financing, sale, settlement, price, recovery or liquidity.

Users should have authority to provide and share verification material, use appropriate access controls and avoid unnecessary disclosure of personal or confidential information. A prospective counterparty should review the original report, understand its permitted use and limitations, and perform any additional checks required for its own decision.

Important: DaDepo provides technology and information tools. It does not provide legal, financial, investment, tax, accounting, audit, compliance or valuation advice. Verification requirements depend on the asset, provider, transaction, jurisdiction and intended use. Obtain appropriate professional advice where needed.

Verification should narrow uncertainty, not hide it

A well-scoped third-party check can strengthen an evidence package. Its value comes from answering a defined question transparently—not from making every aspect of an asset appear approved.

Keep the provider's conclusion connected to its scope, sources, date, exceptions and limitations. That gives reviewers a clearer basis for deciding what the result supports, what it does not support and which questions remain open.

Further reading