Why operator identity is a distinct diligence workstream
When an acquisition includes datacenter assets, the standard financial and legal diligence process often treats physical infrastructure as a line item rather than a subject of independent verification. That assumption breaks down quickly when you discover that the facility named in the target's contracts is operated under a subsidiary you have not reviewed, that the network presence described in pitch materials reflects a carrier agreement held by a different legal entity, or that the building itself is leased from a third-party landlord whose ownership chain has not been examined.
Datacenter operator verification is worth treating as its own workstream because the gap between what a company says it operates and what the public record can independently confirm is often significant. A company may describe itself as owning and operating a facility when in practice it holds a wholesale or master-lease agreement, or it may present a multi-building campus as a single asset when each building is held by a different legal entity with its own liabilities and contractual obligations. Catching these distinctions before signing has material consequences for the purchase price, the reps-and-warranties scope, and the post-close integration plan.
Confirming operator identity through network evidence
The most direct independent check on operator identity is the autonomous system record. Any company that genuinely operates its own network infrastructure — running its own routers, holding carrier contracts, and announcing its own IP blocks — will appear in the regional internet registry records as the holder of an autonomous system number. That record names a legal entity, a country of registration, and a contact domain, all of which can be cross-referenced against the name and jurisdiction of your acquisition target.
When the autonomous system record names a different entity than the one you are acquiring, that discrepancy deserves an explanation. Common benign causes include a historical registration that was never updated after a rebranding, a regional subsidiary that holds the network assets separately from the parent, or a managed-services arrangement where a third party operates the network on the target's behalf. Less benign explanations include intercompany arrangements that have not been disclosed, beneficial ownership structures designed to obscure the ultimate operator, or prior ownership by an entity that has since been sanctioned or placed on a restricted-party list.
Beyond the autonomous system record, the IP address blocks announced from a facility provide a second layer of verification. The allocation records for those blocks, maintained by the regional internet registries, name an organization that should match or be clearly traceable to your target. Mismatches between the announced network, the allocation record, and the corporate entity you are acquiring are a reliable indicator that the ownership or operating structure is more complex than the target has represented.
Tracing the ownership chain through corporate registries
Once you have confirmed the operating entity, the next step is tracing its ownership chain upward through corporate registries to identify the ultimate beneficial owner. This matters for two reasons: sanctions exposure and undisclosed liabilities. A datacenter operating entity that looks clean at the subsidiary level may be ultimately controlled by a parent or beneficial owner that appears on a restricted-party list, and liabilities or encumbrances at the parent level can flow down to the asset you are acquiring even if they are not visible in the subsidiary's own records.
The Legal Entity Identifier system, maintained by the Global Legal Entity Identifier Foundation, is the most reliable starting point for international ownership tracing because it is designed for exactly this purpose and covers over three million entities across most major jurisdictions. Each LEI record includes the entity's direct and ultimate parent, and the relationship records are updated on a regular schedule. Not every operating entity will have a LEI, but companies with material financial obligations including datacenter lease and carrier contracts are increasingly required to hold one in jurisdictions that have adopted financial regulatory standards mandating LEI use.
Where LEI records are absent or incomplete, national corporate registries are the next resource. For European targets, the cross-border access to business registers through the BRIS system covers most EU member states. For targets in other jurisdictions, the relevant national registry varies, and in some markets the registry records are not publicly accessible or are maintained only in the local language, which creates a practical gap that may require local counsel to close.
Sanctions screening across the full entity set
Sanctions screening in a datacenter acquisition context is not limited to the target company itself. The screening should cover the operating entity, every entity in the ownership chain up to the ultimate beneficial owner, any named directors and beneficial owners above a threshold ownership percentage, and the counterparties to material contracts including carrier agreements, colocation master leases, and managed-services arrangements. Missing any of these is the most common way that sanctions exposure reaches a deal after close.
The relevant screening lists for a transaction with international datacenter assets typically include the OFAC Specially Designated Nationals list, the BIS Entity List and Denied Persons List, the EU consolidated financial sanctions list, the UN Security Council consolidated list, and the OFSI list for UK-incorporated assets. Many acquirers treat these as parallel lists to run independently, but the most efficient approach is to use a consolidated screening source that aggregates them into a single normalized database, since the same entity often appears across multiple lists and manual de-duplication across five or six separate downloads introduces both redundancy and error risk.
One specific risk pattern that is easy to overlook is the operator that is not itself sanctioned but whose ultimate parent is. This structure is common in markets where state-adjacent entities operate commercial datacenter infrastructure. The subsidiary may have been established specifically to hold assets in a jurisdiction where the parent would face restrictions, and the operating subsidiary's contracts may appear entirely clean until you trace the ownership chain far enough to find the controlling interest.
What to request from the target company
The information requests that yield the most diligence value in a datacenter acquisition are not always the ones that appear in standard infrastructure due diligence checklists. Beyond the expected items such as lease agreements, power capacity documentation, and compliance certificates, the requests that are most likely to surface undisclosed complexity are those that ask the target to identify every legal entity that holds a material contract related to the facility, provide the autonomous system number and the name of the registered holder, identify the counterparties to all carrier interconnect agreements, and explain any discrepancy between the operating entity named in those documents and the entity being acquired.
Asking for the carrier interconnect agreements specifically is valuable because those agreements identify the networks actually present in the building, the entity that holds the cross-connect rights, and the term and termination conditions of those relationships. A facility that markets itself as carrier-neutral but whose interconnect agreements are held by a related party with a different ownership structure than expected is a common source of post-close surprises, particularly if one of the named carriers or the cross-connect counterparty is later identified as a restricted party.