The regulations amend the European Union (Anti-Money Laundering: Beneficial Ownership of Corporate Entities) Regulations 2019 and significantly widen who in Ireland can obtain access to a central register that contains information about the beneficial owners of companies.
Ireland last changed its laws in 2023 to restrict public access to the Central Register of Beneficial Ownership (RBO) following a landmark ruling by the EU’s highest court. The Court of Justice of the European Union (CJEU) ruled on 22 November 2022 that the public’s access to information on companies’ beneficial ownership constituted “a serious interference with the fundamental rights to respect for private life and to the protection of personal data”.
The CJEU’s decision prompted the Companies Registration Office Ireland (CRO) to restrict the central register in 2023 to very limited categories of designated persons and competent authorities, which included financial institutions, accountants, auditors, tax advisers, and legal professionals.
However, this highly restrictive approach drew criticism from anti-corruption and transparency advocates, which argued that it created a “veil of secrecy” over company ownership in Ireland, while other EU member states have maintained public access to their registers on transparency grounds following the CJEU ruling.
Statutory Instrument no. 406 of 2026 (17 pages / 251 KB PDF) broadens who can obtain access to the register in Ireland in a move that is expected to increase transparency of the ownership of Irish corporate entities and facilitate due diligence by anybody looking to acquire, invest in or transact with an Irish corporate entity.
What the new regime entails
The list of individuals entitled to access the register has expanded significantly. It now includes senior members of the Irish police (An Garda Síochána), government ministers, staff of the Central Bank of Ireland, relevant competent regulatory authorities, including anti-money laundering (AML) and countering the financing of terrorism (CFT) authorities, as well as the European Public Prosecutor’s Office (EPPO) and the European Anti-Fraud Office (OLAF).
Europol – the EU's law enforcement agency – and Eurojust – the European Union Agency for Criminal Justice Cooperation – will also be granted access to the register “when providing operational support to the competent authorities” in EU member states.
While the register is still not open to the general public, the regulations crucially introduce a “legitimate interest” test. Certain groups, including journalists, civil society organisations, non-governmental organisations (NGOs) and academia, and indeed anyone who can demonstrate a genuine interest in preventing or combatting “money laundering, its predicate offences and terrorist financing”, are now permitted to apply to access the register.
Individuals have to apply for a certificate, which permits them to inspect the following information related to the beneficial owner of an entity:
- the name of each beneficial owner;
- the month and year of birth of each beneficial owner;
- the country of residence and nationality of each beneficial owner of the entity;
- a statement of the nature and extent of the beneficial interest held by each beneficial owner.
Effective from 10 November, the registrar must process applications within 12 working days. Certificates, once issued, are normally valid for up to three years from the date of issue.
The registrar can choose to refuse or revoke a certificate but must document the steps taken to make this decision and provide the applicant with a statement in writing of the reasons for refusal.
Where access is sought to register information regarding a beneficial owner who is a minor, lacks capacity, or is otherwise legally incapable, or where such access would expose a beneficial owner to disproportionate risk of fraud, kidnapping, blackmail, extortion, harassment, violence or intimidation, an assistant registrar must request the person seeking access to provide a written summary of the grounds under which they consider it is in the public interest for the information be disclosed. If these grounds are not furnished or sufficiently substantial, the request will be refused.
Any individual who has been refused certification or whose certification is revoked may appeal the decision to the District Court within 10 working days of receiving notification.
Where a beneficial owner makes a data access request under article 15(1)(c) of the GDPR, the registrar must, in making any disclosure from the retained information:
- not identify journalists, civil society, NGO or academia persons who have inspected the register;
- not disclose the identity of third-country counterparts of EU AML/CFT authorities as long as required to protect their analyses or investigations;
- include information on the function or occupation of persons from the journalist or civil society categories who inspected information relating to that beneficial owner.
Regulation 27 of the 2019 regulations has also been replaced. Now any fee required to pay for access to the register is “limited to what is strictly necessary to cover the costs of ensuring the quality of the information held in the register and of permitting access to inspect the information”.
What this means for businesses
These changes will be particularly relevant for Irish companies and other corporate entities required to file beneficial ownership information with the RBO, as well as beneficial owners whose personal information is recorded on the register. Businesses will be able to inspect the register to determine entities that they are “likely to enter into a transaction with”, which may offer opportunities for preliminary due diligence.
The changes will also be significant for financial institutions, investors, purchasers, lenders, and other AML-regulated entities that typically rely on beneficial ownership information as part of their ongoing customer due diligence obligations related to acquisitions, investments, financing and commercial transactions. Legal, accounting and corporate services advisers will also need to familiarise themselves with the new rules to assist clients with beneficial ownership compliance and verification obligations and to comply with their own AML obligations.
Additional safeguards will protect beneficial owners recorded on the RBO who are minors, lack capacity, are otherwise legally incapable, or face a disproportionate risk of fraud, kidnapping, blackmail, extortion, harassment, violence or intimidation.
However, the legislation notably does not define when a risk is “disproportionate”, leaving the assessment to the registrar or assistant registrar. This may create some uncertainty and limited transparency. In future, the creation of a notification mechanism could allow affected beneficial owners to raise such issues in advance of an access application, but for now businesses will need to be alert to this risk.
From a corporate governance perspective, greater transparency of beneficial ownership in Ireland is expected to encourage companies to ensure their beneficial ownership records remain accurate, up-to-date and reflective of their true ownership structures. This is particularly relevant in instances where senior managing officials are still listed when they have either changed roles or left the entity altogether. Overall, these changes should make due diligence more straightforward for both businesses and their advisers.
Next steps before 10 November
Businesses should consider taking the following steps before the new regime becomes fully operational from 10 November 2026:
- review beneficial ownership records, confirming that they are accurate, complete and up-to- date;
- undertake an RBO compliance audit; and
- prepare for increased scrutiny.