01
Checking a Ukrainian company
What is an EDRPOU number?
An EDRPOU number is the eight-digit identifier assigned to every legal entity registered in Ukraine, issued under the Unified State Register of Enterprises and Organisations of Ukraine. It is the equivalent of a company registration number and is the only reliable way to identify a Ukrainian company, because company names are frequently duplicated, transliterated inconsistently, and changed. Always ask a Ukrainian counterparty for its EDRPOU rather than relying on the trading name.
How do I check if a Ukrainian company is real?
Start with the EDRPOU number and look the entity up in Ukraine's Unified State Register (EDR), which records legal status, registered address, directors and declared beneficial owners. Confirm the entity is active rather than in liquidation or bankruptcy, check the Minjust bankruptcy register, and check the company's filing history with the tax authority. Registration confirms legal existence only. It says nothing about whether the company can actually perform. The full evidence sequence is set out in our Ukraine counterparty verification guide.
How do I find the ultimate beneficial owner of a Ukrainian company?
Ukraine's Unified State Register requires companies to declare their ultimate beneficial owners, so the declared UBO is the starting point. It is not the finishing point. Declared ownership is self-reported, and Ukrainian corporate structures have been reshaped by de-oligarchisation, wartime nationalisations and transfers from sanctioned individuals to nominees. Establishing real control means traversing the ownership chain across current and historical records, including foreign layers, and testing declared owners against sanctions and political-exposure data.
Can I trust Ukraine's beneficial ownership register?
It is genuinely useful and has improved substantially since the 2014 reforms, but it should be treated as a declaration rather than a verified fact. Ownership data is self-reported, and residual Russian-connected ownership exposure has not been fully cleansed from the Ukrainian corporate landscape. Use the register as the first layer of evidence and corroborate it against historical filings, related-party structures, procurement behaviour and sanctions data before relying on it for a decision.
What is Prozorro and is its data reliable for supplier vetting?
Prozorro is Ukraine's public electronic procurement system, and its published tender and award data is one of the most useful open sources on Ukrainian company behaviour: who bid, who won, at what value, and how often. The data itself is reliable as a record of what happened in the system. What it does not tell you is whether an award reflects genuine capacity, whether contracts were performed, or whether a bidding pattern indicates collusion. It operates under Ukrainian procurement law as amended under martial law, with separate thresholds for defence-related and critical infrastructure procurement.
How do I check if a Ukrainian company or person is sanctioned?
Screen the entity and every declared beneficial owner against the EU consolidated list, US OFAC SDN, UK FCDO and UN Security Council lists, and separately against Ukraine's own NACP sanctions registry, which lists designations under Ukrainian law that do not appear on EU or US lists. Screen names in both Ukrainian and transliterated forms, since a single Ukrainian name can be romanised several ways. Free screening within an 18-source configured coverage model is available at s1.salientone.eu; current source health is published separately.
Why is name matching so difficult for Ukrainian entities?
A single Ukrainian name can appear in Cyrillic, in several competing Latin transliterations, in a legacy Russian-derived romanisation, and in an abbreviated legal form, all referring to the same entity. Company names are also widely duplicated. Exact-string screening therefore produces both false negatives, where a designated party is missed because the spelling differs, and false positives, where unrelated entities share a common name. Reliable matching needs fuzzy, phonetic and transliteration-aware comparison, anchored on the EDRPOU identifier wherever one exists.
How do I check whether a Ukrainian company is in litigation or insolvent?
Ukraine publishes court decisions in the Unified State Register of Court Decisions, which allows a company's litigation history to be reconstructed, and the Ministry of Justice maintains a bankruptcy register. Tax and social-contribution debt is recorded by the State Tax Service. Together these give a reasonable picture of financial distress and dispute exposure. Court decisions require careful interpretation because machine translation can mistake party roles.
How do I verify that a Ukrainian site or facility actually exists and is operating?
The public record cannot settle this. A registered address proves a filing, not a functioning plant. Verification means someone going to the coordinates and establishing what is physically there: whether the facility exists, its visible condition, whether it is operating, how accessible it is, and its exposure to power, transport and infrastructure disruption. In a conflict environment a desk-based questionnaire is structurally inadequate for this, and mine contamination makes unstructured site visits unsafe.
Can a Ukrainian supplier near the front line still perform?
Sometimes, and proximity alone does not answer it. What matters is the specific exposure: distance from the contact line, whether the facility sits in occupied or contested territory, its dependence on grid power, the state of transport links, workforce availability given conscription, and the terms of any war-risk insurance. These are assessable, but they need current geographic data and local enquiry rather than a national-level risk rating.
02
Sanctions and export controls
Does screening a name against sanctions lists make me compliant?
No. List screening is a necessary first step and a common point of failure, because it only catches parties that have been designated by name. It does not catch exposure held through an ownership chain, entities controlled by designated persons without being listed themselves, circumvention structures, or secondary effects. Sanctions compliance requires ownership and control analysis on top of screening. A match is also only a candidate for review, never a determination of identity.
What counts as sanctioned ownership or control under EU rules?
Under EU practice, an entity is caught where a designated person holds more than 50% of the proprietary rights or a majority interest, and separately where a designated person exercises control regardless of shareholding. Control can arise through board appointment rights, veto rights, or the ability to direct the entity in practice. This is why a screening hit rate of zero on the entity itself is not sufficient: the analysis has to run through the ownership chain to the ultimate beneficial owner.
What changed in the EU's twentieth and twenty-first Russia sanctions packages?
The twentieth package of 23 April 2026 tightened measures across energy, the military-industrial complex, trade, financial services and crypto assets. Council Regulation (EU) 2026/506 also introduced Article 5sa on specified unconsented uses of EU-owned intellectual property and trade secrets in Russia. The twenty-first package of 23 July 2026 added 218 individual listings, extended transaction bans to thirty-three Russian financial institutions and fourteen crypto-service platforms, and placed fifty-one more entities under tighter dual-use export restrictions. For Ukraine-exposed companies, ownership, intermediary and end-use analysis therefore matters beyond list screening.
Do dual-use export controls apply to reconstruction goods?
Frequently, yes, and this is routinely underestimated. Regulation (EU) 2021/821 is operationally salient well beyond defence: semiconductors, software with cryptographic functions, industrial machinery, components applicable to unmanned aerial vehicles, telecommunications equipment and surveillance technology all arise in reconstruction and resilience projects. A dual-use posture calibrated for peacetime commercial supply generally needs re-examining before deploying the same goods into Ukraine.
03
Reconstruction and procurement
How large is Ukraine's reconstruction financing and where does it come from?
The World Bank's successive Rapid Damage and Needs Assessments place recovery costs above $480 billion. Financing is multilayered: the EU Ukraine Facility provides EUR 50 billion through 2027, alongside EBRD, EIB, IFC and World Bank co-financing across energy, transport, housing, municipal infrastructure and industrial recovery, bilateral G7 instruments, and blended-finance vehicles. Tenders are published through Prozorro and through the development finance institutions' own procurement portals.
Do development finance institution procurement rules align with Ukrainian law?
Not always, and the gaps matter. Projects backed by development finance institutions run under their own frameworks, such as the EBRD Procurement Policies and Rules or the World Bank Procurement Regulations, which do not always align with each other or with Ukrainian domestic procurement requirements. Companies entering through DFI-backed or EU Facility-funded projects therefore face a doubled compliance layer: IFC Performance Standards, the EBRD Environmental and Social Policy and the EU procurement framework at project level, on top of their own corporate compliance.
What are the practical obstacles to operating in Ukraine beyond security?
Four recur. Payments and currency: National Bank of Ukraine capital controls, foreign-exchange restrictions, unpredictable settlement timelines and hryvnia convertibility constraints. Labour: conscription removing working-age men, internally displaced workforces and forced-labour indicators in informal chains. Insurance: expensive war-risk cover, narrowed coverage and multiplied exclusions. Dispute resolution: martial law affects court operation, judgment enforceability and arbitration. Each of these is an operational constraint that shapes whether a contract can actually be performed.
04
CSDDD and supply-chain due diligence
Who is in scope of the CSDDD and when does it apply?
The Corporate Sustainability Due Diligence Directive applies directly to EU companies with more than 5,000 employees and EUR 1.5 billion worldwide turnover, and to non-EU companies with EUR 1.5 billion of EU turnover. National transposition is due by 26 July 2028, application begins 26 July 2029, and first disclosures follow from 1 January 2030. Penalties are capped at 3% of net worldwide turnover. Companies below the thresholds are still affected in practice, because in-scope customers push the requirements down their supply chains.
Is withdrawing from Ukraine the safe compliance option?
No, and treating it as the default is one of the more common errors. The CSDDD does not endorse withdrawal as uniformly compliant, and disengagement may itself produce adverse human rights impacts that the framework expects a company to weigh. What is defensible is a documented, principled decision, reached through a process that can be shown afterwards. Disengagement needs documenting as carefully as engagement.
Are standard ESG questionnaires enough for suppliers in a conflict environment?
No. Standard human rights and environmental due diligence questionnaires assume a supplier that can answer accurately and a verification route that can test the answers. In a conflict-affected market both assumptions weaken: self-reported responses cannot be corroborated at distance, and the risks that matter, such as frontline proximity, grid dependence, mine contamination and conscription-driven labour shortages, do not appear on a standard form. Due diligence has to be calibrated to the environment rather than transplanted into it.
Why do sanctions, CSDDD and dual-use controls need handling together?
Because they converge on the same decision. Most compliance functions staff them as three separate workstreams, but in a Ukraine-relevant value chain they meet at a single supplier-onboarding decision, a single procurement bid, or a single financing arrangement. Assessed separately, each workstream can clear a counterparty that the combined picture would not. The practical response is one integrated view per counterparty rather than three parallel files.
05
Working with Salient One
What does Salient One actually do?
Salient One is a partner-led security and risk advisory firm based in Kyiv. We help international companies, investors, NGOs and institutions operate safely and effectively in Ukraine. Strategy, intelligence, operations and market-entry services support that core work.
Is Salient One a law firm or a compliance advisory?
No. Salient One provides strategy, intelligence, security-risk and operational advice. It does not directly provide regulated physical-security, legal, tax, accounting, investment, sanctions, export-control, engineering, valuation or insurance services. Where specialist services are required, their role is explicit in the scope; vetted, appropriately licensed Ukrainian security providers can be coordinated where needed.
What is Ukraine 1?
Ukraine 1 is Salient One's working environment for resolving Ukrainian companies, people, records and relationships into source-traceable evidence. It connects fragmented records while preserving the source, date and limits of what can be established, covering entity resolution across names and transliterations, an ownership and relationship graph, and Kyiv-based research where open sources are insufficient. It is active infrastructure under development, not a finished product or an unrestricted self-service platform.
What is the [S/1] platform and what is free?
[S/1] is Salient One's global risk-intelligence platform at s1.salientone.eu. Sanctions and political-exposure screening within an 18-source configured coverage model, country risk scorecards for 250 countries and territories, the global risk map and the source freshness directory are free to use. Source availability is published separately. Additional enabled workflows include intelligence reports, ownership and network mapping, UBO chains, batch screening, watchlist monitoring, case management with an audit trail, and a REST API.
Where does Salient One's data come from?
From official and open sources, each carrying its own provenance. For Ukraine these include the EDR company registry, Prozorro procurement, the Unified State Register of Court Decisions, NACP asset declarations and the NAZK register, State Tax Service filings and debt records, the Ministry of Justice bankruptcy register, OpenSanctions and GDELT adverse media. Globally, [S/1] draws on 18 sanctions and debarment registries and official country indicators from the World Bank, Transparency International, the EC Joint Research Centre, FATF, ILO and others. Every material fact carries its source and its date.
How does an engagement with Salient One begin?
By writing to [email protected] with your objective, context, timing and the support you need. A decision, partnership, initiative or recurring local operating need is enough to begin. For a counterparty or site assessment, names, EDRPOU identifiers, coordinates or relevant documents are useful if available. We propose a focused assessment, defined project or ongoing advisory scope, with deliverables, responsibilities, timing and fees agreed before work starts. Assessments also state sources, confidence and limitations.
Who does Salient One work with?
International companies, investors, NGOs, institutions, advisory firms and project teams working in Ukraine. Commercial assignments may involve market entry, investment, partner selection or local execution. Humanitarian and institutional work can include country analysis, partnership strategy, operating-risk reviews, continuity planning and local coordination.