> ## Content Index
> Fetch the complete content index at: https://www.adriadefense.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# The Counterparty Problem: Why Corporate Intelligence Is Becoming a Security Issue in Europe
- URL: https://www.adriadefense.com/the-counterparty-problem-why-corporate-intelligence-is-becoming-a-security-issue-in-europe/
- Published: 2026-09-23T09:00:38.000Z
- Updated: 2026-09-23T09:00:37.000Z
- Description: Sanctions, opaque ownership and tighter investment screening are reshaping how European companies assess business partners. As commercial risk and national security overlap, knowing the legal entity behind a deal may no longer be enough.
- Author: AdriaDefense Desk
- Tags: Analysis, Foreus, Austria, Vienna, CEE, Cyber Security, Intelligence, Private Intelligence, Foreus Group, Foreus Intelligence

In December 2023, Raiffeisen Bank International announced plans for an unusual transaction involving 28.5 million shares in Austrian construction group STRABAG held by MKAO Rasperia Trading Limited. STRABAG said the proposed multi-step acquisition was subject to several conditions, including a sanctions review. Five months later, RBI abandoned the plan, saying that exchanges with the relevant authorities had failed to provide the "required comfort" needed to proceed and that it had decided, in an abundance of caution, to walk away.

The episode was specific to RBI, STRABAG and the sanctions environment surrounding Russia, but it captured a broader problem facing companies across Europe. The legal identity of a counterparty can be clear while the wider risk surrounding ownership, control and influence remains much harder to assess. For businesses in defense, advanced manufacturing, critical infrastructure and technology, that problem is becoming more consequential as economic security and commercial risk begin to overlap.

A company may know who signs a contract, who appears in the shareholder register and whether the names involved appear on sanctions lists, yet still lack a reliable picture of the network around a transaction. The relevant questions can include who ultimately benefits, which jurisdictions are involved, whether apparently separate parties are connected and whether the commercial purpose matches the counterparty's actual business history. Those questions sit at the point where conventional due diligence increasingly meets corporate intelligence.

### **Where conventional due diligence stops**

The division of labor in a major transaction is well established. Lawyers examine contracts, ownership, litigation and regulatory exposure. Accountants test financial statements and liabilities. Compliance teams screen sanctions, politically exposed persons and adverse media, while investment professionals focus on valuation, management and market prospects. Each discipline can produce a rigorous assessment and still leave gaps because some of the most important questions do not belong neatly to any one category.

A law firm advising on a cross-border acquisition may establish the target company's documented ownership and legal obligations but still need to understand whether an intermediary has a meaningful relationship with one of the parties. In a dispute, counsel may need to determine whether companies registered in different jurisdictions are connected through people, assets or historic business relationships. During an internal investigation, the legal framework may be relatively clear while the factual picture remains incomplete. Who exercised influence, who benefited from a decision and whether assets or relationships extend beyond formal records can all become material to legal strategy.

Corporate intelligence addresses those gaps by connecting information that is often scattered across jurisdictions and sources. Historic directorships, beneficial ownership records, litigation, company filings, public procurement, business relationships and asset information can each appear unremarkable on their own. The analytical task is to establish whether, taken together, they materially change the understanding of a counterparty.

That does not mean treating complexity as evidence of wrongdoing. International businesses legitimately use holding companies, subsidiaries, professional service providers and multiple jurisdictions. Executives sit on several boards and ownership structures change for ordinary commercial reasons. A serious assessment should distinguish that normal complexity from inconsistencies that warrant further scrutiny.

European regulators are increasingly applying a similar logic. The European Commission's sanctions due diligence guidance recommends a risk-based approach covering business partners, transactions and goods rather than relying on list screening alone. For higher-risk cases, it points to beneficial owners and other stakeholders, a counterparty's established business record, ownership changes, intermediaries, banks, end users, shipping routes and whether an end-user certificate can be provided. The Commission also suggests examining whether the transaction itself makes commercial sense for the prospective customer. 

The guidance is aimed at sanctions circumvention, but the principle is broader. Screening can establish whether a name is listed. It cannot necessarily explain why a newly established distributor is buying a technically sophisticated product, whether an unusually large order fits its historical business or how apparently independent participants in a transaction may be connected.

**Stefan Embacher**, CEO of Vienna-based intelligence firm [FOREUS](https://foreusgroup.com/?ref=adriadefense.com), says the distinction lies partly in what conventional checks are designed to establish and what remains outside the formal record.

> *“Traditional due diligence tells you what is documented. Intelligence helps you understand what is actually happening behind it. The decisive information is often not a sanctions hit or a company record, but the connections between people, companies, jurisdictions and interests. Our job is to identify those connections, verify them and give decision-makers a clearer picture of who they are really dealing with.”* 

> **Stefan Embacher, CEO, FOREUS**

---

### **The end-user problem**

The challenge becomes more acute when a transaction involves technology or industrial goods rather than shares or financial assets. A manufacturer may understand its immediate customer reasonably well and still have limited visibility into what happens after the goods leave its control. For defense and dual-use suppliers, that distinction has become one of the central risk questions of Europe's post-2022 security environment.

Siemens confronted an earlier version of the problem in 2017\. The company said four gas turbines delivered in 2016 for a project in Taman, southern Russia, had later been locally modified and moved to Crimea contrary to contractual agreements. Siemens described the transfer as a breach of its contracts and EU rules, pursued legal action and reviewed relevant investments and licensing arrangements in Russia. It also introduced additional controls intended to ensure that future equipment reached the contractually agreed destination.

The case did not suggest that Siemens had failed to identify its immediate customer. It demonstrated a more difficult problem: knowing the buyer and the intended destination does not necessarily guarantee control over what happens further down the chain.

That distinction has become more significant as European export controls and sanctions have expanded while the market for dual-use technology remains global. Precision machine tools, electronics, sensors, semiconductors and other industrial equipment can support legitimate civilian activity while also having applications in military production. Exposure can therefore arise through distributors, intermediaries or re-exporters several transactions removed from the original manufacturer.

Austria provided a particularly relevant example this summer. Authorities disclosed a network involving a Vienna-based company that used entities across Türkiye, the United Arab Emirates, Hong Kong, Belarus, Kyrgyzstan, South Korea, Poland and Lithuania to send specialized metalworking tools and CNC machines to Russian companies. Austrian authorities said falsified end-user certificates were used to disguise the final destination and that evidence indicated more than €3.3 million in industrial goods had been supplied to Russian arms manufacturers since 2022\. 

The case subsequently moved beyond the investigative stage. On August 12, an Austrian court convicted two Belarusian cousins connected to the company of violating export controls after both pleaded guilty. The 28-year-old director received a 21-month prison sentence, 19 months of which were suspended, while the second defendant received a 15-month suspended sentence. According to Reuters, the primary defendant told the court that he had acted on instructions from his father and uncle, who worked at a Russian company.

For European industry, the significance of the case extends beyond the criminal conduct established in court. It demonstrates how corporate entities, supporting documentation and third-country trade routes can be used to obscure the final destination of industrial technology. This is as much a supply-chain intelligence problem as a sanctions problem.

Europe is trying to expand defense production, shorten procurement timelines and bring new companies into strategic supply chains while simultaneously tightening export controls and reducing the risk that sensitive technology reaches hostile end users. The European Union's 21st sanctions package, adopted in July, illustrates the international nature of that challenge: 27 of the newly targeted entities linked to Russia's military-industrial complex or sanctions circumvention were located outside Russia, including in China, Türkiye, Kyrgyzstan, India, Kazakhstan and the UAE. 

The problem also works in the opposite direction. European defense companies are looking for new suppliers, investors, manufacturing partners and additional production capacity. A supplier may pass financial and legal checks while remaining dependent on a third country for a critical component. An investor may be legally acceptable while raising questions about access to intellectual property or production knowledge. A joint-venture partner may have no sanctions exposure but still introduce relationships that a government customer considers problematic. None of these circumstances implies wrongdoing, but each can alter the strategic risk of a deal.

### **When the risk is legal**

The distinction between illegality and strategic exposure is increasingly visible in European investment policy. In June 2026, the European Union adopted Regulation 2026/1386 on foreign investment screening, replacing the framework introduced in 2019\. The new regulation strengthens screening across the Union and requires member states to maintain mechanisms for examining investments that could affect security or public order.

For companies, the importance goes beyond the formal regulatory process. An investor can be unsanctioned and financially credible while still creating questions about access to sensitive technology. A supplier can be profitable and operationally reliable while creating strategic dependency. A transaction can be lawful and economically rational while producing concerns about where intellectual property, data or production know-how may eventually flow.

Those questions are particularly important in defense, where governments frequently occupy several roles at once: regulator, customer, security stakeholder and, in some cases, investor. But the same logic increasingly applies to critical infrastructure, semiconductors, artificial intelligence, telecommunications and other sectors where commercial control can have security consequences.

Law firms are often central to this process because they are among the first external advisers to encounter difficult factual questions in transactions, disputes, sanctions matters and internal investigations. Intelligence work can complement legal analysis by establishing facts that counsel then evaluates within the relevant legal framework. Investigators do not replace legal judgment, but lawyers may need a stronger factual record before they can advise a client on the consequences of a relationship or transaction.

The same principle applies in mergers and acquisitions. Financial statements may support the valuation, contracts may be enforceable and sanctions screening may return no obvious concerns, while unanswered questions remain about beneficial ownership, undisclosed relationships, political exposure or dependence on a particular intermediary. Such findings do not determine whether an investment should proceed. They give an investment committee, board or legal team a better basis for deciding whether additional investigation, contractual protections or conditions are justified.

Demand is increasingly moving upstream, before a dispute or compliance problem has emerged. 

> *“We are seeing a clear shift from reactive investigations to preventive intelligence. Clients increasingly want to understand who is really behind a company, an investor or a business partner before they sign, invest or share sensitive information. In one recent cross-border matter, our analysis identified relationships around a counterparty that were not apparent from the formal corporate structure. Nothing in the initial screening alone would have provided the full picture. That additional intelligence allowed the client to reassess the transaction before exposure occurred.”*

> **Stefan Embacher, CEO, FOREUS, speaking to Adria Defense**

### **More information, not necessarily more certainty**

The growing demand for deeper analysis comes at a time when corporate information has never been easier to obtain. Company registries, court records, procurement databases, sanctions lists, financial filings and commercial intelligence platforms can increasingly be searched across borders. Artificial intelligence can accelerate translation, document review and entity matching. Yet easier access to data does not automatically produce better intelligence; it can also make weak connections easier to discover and easier to overstate.

Two executives appearing together in a photograph may indicate a meaningful relationship or simply attendance at the same conference. Companies sharing an address may belong to the same network or merely use the same law firm or corporate-services provider. A newly created distributor placing an unusually large order can be a warning sign in one context and perfectly ordinary behavior in another. The quality of an assessment therefore depends on verification, context and judgment, with a clear distinction between documented fact, analytical inference and unresolved questions.

That standard matters particularly in defense and security, where both false positives and missed risks can be expensive. An unsupported allegation can damage a company or individual, while an incomplete assessment can expose a manufacturer or investor to regulatory action, sanctions, technology loss or reputational harm. Good intelligence does not require a dramatic conclusion. In many cases, the result may simply be a decision to request further documentation, examine one shareholder or intermediary more closely, restrict access to sensitive information, strengthen contractual protections or monitor a relationship after closing.

The European cases discussed here are different and should not be conflated. RBI and STRABAG showed how sanctions and uncertainty around ownership could complicate a major corporate transaction. Siemens demonstrated the limits of contractual control over the destination of strategically relevant technology. Austria's 2026 export-control case showed how companies and falsified end-user documentation could be used to conceal the destination of industrial equipment. The EU's new investment-screening framework, meanwhile, reflects a wider policy shift in which access to critical technology, ownership and strategic dependency increasingly carry security significance.

For Europe's defense companies, dual-use manufacturers, investors and the law firms advising them, the implication is not that every transaction requires a private intelligence investigation. It is that the definition of counterparty risk is expanding. Establishing the legal name on the contract remains the beginning of due diligence, but in Europe's more contested security environment it is increasingly unlikely to be the end.

---

**Sources:** [STRABAG Newsroom](https://newsroom.strabag.com/en/press-releases/group/2023-12/strabag-se-278-percent-stake-of-mkao-rasperia-trading-limited-in-strabag-se-to-be-transferred-to-raiffeisenbank-international-ag?ref=adriadefense.com), [European Commission: Sanctions Due Diligence Guidance](https://finance.ec.europa.eu/document/download/3c86c9a8-f09e-4092-ab8c-a9e678df1494%5Fen?filename=guidance-eu-operators-russia-sanctions-circumvention%5Fen.pdf&ref=adriadefense.com), [Siemens: Crimea Turbine Case](https://press.siemens.com/global/en/article/update-official-statement-regarding-turbines-crimea?ref=adriadefense.com), [Reuters: Austrian Sanctions-Evasion Case](https://www.reuters.com/business/aerospace-defense/austria-breaks-up-sanctions-evasion-scheme-supplying-russian-arms-industry-2026-08-10/?ref=adriadefense.com), [Reuters via Internazionale: Austrian Court Convictions](https://www.internazionale.it/ultime-notizie-reuters/2026/08/12/austrian-court-convicts-belarusians-over-supplying-russian-arms-industry?ref=adriadefense.com), [European Commission: 21st Sanctions Package](https://finance.ec.europa.eu/news/eu-adopts-21st-package-sanctions-against-russia-2026-07-23%5Fen?ref=adriadefense.com), [EUR-Lex: Regulation (EU) 2026/1386](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1386&ref=adriadefense.com)

**Republication policy:** *This article may be republished in full or in part with clear attribution to Adria Defense and a direct link to the original source. Any edits must preserve the meaning and context of the original reporting.*

**Disclosure:** *FOREUS is a commercial partner of Adria Defense and contributed expert commentary to this article. Adria Defense retained full editorial control over the reporting, analysis and final publication.*