Click on any item to navigate to that section.
Note: This report does not include page numbers as section breaks vary by browser and device.
Bentley Systems, Incorporated is a publicly traded (Nasdaq: BSY) US enterprise software company headquartered in Exton, Pennsylvania, providing infrastructure engineering and asset-lifecycle software with a reported presence across 189 countries as of fiscal year 2025 company disclosures. This report evaluates Bentley Systems, Incorporated as a prospective or existing arms-length supplier or service provider to a requester in the Professional Services sector. Findings are drawn from sanctions, regulatory, adverse media, financial, geopolitical, and industry-specific due diligence sections completed in this report.
• Engagement with this entity presents minimal immediate sanctions exposure, as comprehensive screening across OFAC, BIS, UN, EU, and UK HM Treasury lists identified no matches for the supplier or its executives.
• This relationship requires ongoing export-control monitoring, since a confirmed China office operates within a rapidly escalating US Bureau of Industry and Security enforcement environment that could affect technology delivery.
• This engagement carries elevated geopolitical monitoring needs given confirmed declining China revenue and an unverified Pakistani subsidiary registration, both contributing to an Orange-rated risk factor for continuity planning.
• This relationship benefits from a financially stable counterparty showing sustained double-digit revenue growth, though recurring 2023-2024 workforce reductions and a trailing 33% share-price decline warrant continued financial monitoring.
• Service continuity should be monitored following the July 2024 transition to the first non-family Chief Executive Officer, alongside recurring employee-reported restructuring, though no financial distress indicators were confirmed.
• This relationship should account for Siemens AG's dual role as minority shareholder and strategic technology partner, and for the likelihood of concurrent service to the requester's competitors, when negotiating protective contract terms.
Risk Summary:
Sanctions Screening: No sanctions matches identified across OFAC, BIS, UN, EU, and UK HM Treasury screening as of the review date.
Regulatory Risk: None identified at the enforcement level; a historical, unresolved-status patent litigation matter is noted as ordinary-course industry exposure.
Adverse Media: Minor - recurring employee-sourced reports of 2023-2024 workforce restructuring; no scandal, fraud, or criminal coverage identified in Tier 1/2 media.
Financial Risk: Stable with monitoring items - sustained revenue and operating-income growth offset by an unresolved public credit-rating status and recent share-price volatility.
→ See Section-by-Section Risk Indicator Summary
Name: Bentley Systems, Incorporated
Country: United States
Business Type: Publicly traded corporation (Nasdaq-listed enterprise software company)
Website: https://www.bentley.com
Industry: Prepackaged software, specifically infrastructure engineering and asset-lifecycle software (SIC code 7372)
Headquarters: 685 Stockton Drive, Exton, Pennsylvania 19341, United States
Known Locations: Development, sales, and support operations spanning 45 countries as of the most recent company disclosure, with reported revenue generation across 189 countries in FY2025; a regional headquarters for the United Kingdom and EMEA opened in the City of London in 2024; identified subsidiary or registered entities include Seequent Holdings Limited (New Zealand), BSI Holdings B.V. and Plaxinvest B.V. (Netherlands), Bentley Systems Singapore Pte Ltd (Singapore), Bentley Systems (Malaysia) Sdn. Bhd. (Malaysia), SRO Solutions Limited (United Kingdom), Bentley Systems Pakistan (Pvt.) Limited (Pakistan), Bentley Software, Inc. and Digital Water Works, Inc. (Delaware), and an office presence in Beijing, China.
Bentley Systems, Incorporated was incorporated in Delaware (company number 2119446 per OpenCorporates, a Tier 4 aggregator) and is confirmed as an active SEC filer under CIK 0001031308, with EIN 95-3936623 and a business address of 685 Stockton Drive, Exton, PA 19341 per SEC EDGAR, a Tier 1 primary source. The company's stock trades on Nasdaq under the ticker BSY, representing its Class B common stock, and its SEC filer status is active based on filings through 2026.
The business was founded in 1984 and formally incorporated in Delaware in 1987 according to the company's own SEC Form 10-K disclosure; these two dates are not contradictory, with 1984 marking the founding of the business and 1987 the date of Delaware incorporation.
Due diligence research identified multiple unrelated entities sharing the Bentley name, including Bentley Motors Limited, a UK luxury automobile manufacturer owned by Volkswagen Group, Bentley University in Massachusetts, Bentley Laboratories, Inc., and an unrelated ransomware-victim entity referred to as Bentley Industries. Material specific to these unrelated entities, including Bentley Motors' modern slavery and ESG disclosures, was identified in research but excluded from this report as pertaining to a different legal entity than Bentley Systems, Incorporated.
Bentley Systems maintains an office presence in Beijing, China, and the company's FY2024 Form 10-K discloses a decline in China subscription revenues within an otherwise growing Asia-Pacific region. China is assessed as an elevated-risk jurisdiction under standard geopolitical and export-control frameworks, and this operational presence is a material factor addressed further in the Geopolitical Risk and Industry-Specific Risk sections of this report, particularly regarding US export-control exposure for a US-headquartered technology company.
A Bentley Systems Pakistan (Pvt.) Limited entity was identified through a Tier 4 corporate registry aggregator among approximately 94 related entities listed for the Bentley corporate family, and this entity's active operating status could not be independently corroborated against a primary Pakistani corporate registry within this research. Pakistan presents moderate governance and corruption-risk considerations, and this subsidiary's status should be verified directly with Bentley Systems or through Pakistan's corporate registry before being relied upon for jurisdiction-specific decision-making.
Bentley Systems is a publicly traded company on Nasdaq under the ticker BSY and is not controlled by any single parent company, sitting at the top of its own corporate structure. Ownership operates through a dual-class-like share structure in which Class A Common Stock carries twenty-nine votes per share, materially concentrating voting control among Class A holders relative to the broader Class B public float.
The founding Bentley family, comprising Gregory, Barry, Keith, Raymond, and Richard Bentley, retains concentrated voting control through this super-voting structure, holding shares both directly and through a network of family trusts. A SEC Schedule 13G/A filing identifies a reporting person, Corinne Patricia Bentley, holding shares through a grantor retained annuity trust and 19 family trusts representing 13.2% of the Class B common stock class as of March 31, 2026, illustrating the scale and complexity of family-trust-based ownership.
The company's amended and restated certificate of incorporation prohibits stockholder action by written consent unless the Bentley family ceases to hold a majority of voting power, an entrenchment mechanism confirming that family control is a structural, legally embedded feature of governance rather than an incidental outcome of share ownership. This structure is lawful and fully disclosed but represents a governance concentration factor that a counterparty should weigh when assessing decision-making independence, particularly regarding strategic decisions such as the family's 2024 rejection of reported acquisition interest.
Siemens AG holds a significant minority equity stake in Bentley Systems, with figures reported across different periods ranging from approximately 9% to 14% of outstanding shares; the most recent secondary-source figures place the holding above 9% as of the most recent reporting reviewed, though the precise current percentage requires verification against Bentley's most recent Schedule 13D/13G filings. Beyond its shareholding, Siemens maintains a strategic commercial alliance with Bentley encompassing joint innovation investment initially valued at 50 million euros and later expanded to 100 million euros per Siemens's own press disclosures.
This dual role, Siemens as both a significant minority shareholder and an active strategic technology and commercial partner, constitutes a structural relationship of note for a prospective counterparty, since Siemens is itself a major global industrial and infrastructure technology firm operating in markets adjacent to, and in some respects competitive with, entities the requester or its competitors may also engage. In 2020, reports indicated Siemens was evaluating a full acquisition of Bentley Systems that did not proceed to completion, and single-source 2024 reporting indicated the Bentley family declined acquisition interest from Schneider Electric in favor of retaining independence.
Bentley Systems' subsidiary structure includes Seequent Holdings Limited, a New Zealand-headquartered subsurface-modeling software company acquired in June 2021 for approximately 900 million dollars in cash plus stock consideration, which operates as a semi-autonomous business unit under its own leadership. The company's acquisition history is extensive, with more than 120 acquisitions completed over four decades and between six and thirteen acquisitions completed annually during the 2020-2022 period alone, creating an ongoing integration and legal-inheritance risk profile across a large number of historically independent entities, though no specific adverse subsidiary-level findings were identified in this research.
No subsidiary of Bentley Systems was identified as located in an OFAC-comprehensively-sanctioned or FATF grey- or black-listed jurisdiction such as Iran, Russia, North Korea, Syria, or Cuba. Subsidiary presence identified in China and Pakistan through Tier 4 aggregator data represents a geopolitical and regulatory risk factor requiring direct primary-source verification, addressed further in the Geopolitical Risk and Industry-Specific Risk sections of this report.
Nicholas Cumins assumed the role of Chief Executive Officer effective July 1, 2024, succeeding Greg Bentley, marking the first time in the company's roughly forty-year history that a non-Bentley-family member has held the chief executive position. Cumins previously served as Bentley's Chief Operating Officer from January 2022 and as Chief Product Officer from September 2020, prior to which he held product-leadership roles at SAP as General Manager of Marketing Cloud, at Scytl, an online-voting platform, as Chief Product Officer, and at OpenX as Senior Vice President of Product.
Cumins holds dual French and United States citizenship and is based in France, a jurisdictional detail relevant to any cross-border executive-liability or export-control personnel-screening considerations the requester may apply. No adverse regulatory, litigation, or sanctions history was identified for Cumins in the sources reviewed, including SEC EDGAR litigation releases and court-record searches conducted under his name.
Greg (Gregory) Bentley, co-founder and former Chief Executive Officer since 1995, transitioned to the role of Executive Chair of the Board effective July 1, 2024, retaining a senior governance position notwithstanding the CEO transition to a non-family executive. Fellow co-founders Keith A. Bentley, Barry J. Bentley, and Raymond B. Bentley continue to serve as directors according to multiple secondary sources, though this detail is single-corroborated and would benefit from direct confirmation against the company's most recent proxy statement.
Corinne Patricia Bentley is identified in a Schedule 13G/A filing with the SEC as a beneficial-ownership reporting person, holding shares through a grantor retained annuity trust and 19 family trusts, as detailed in the Ownership and Structure section above; her role reflects the broader pattern of family-trust-based governance and ownership rather than an operational executive function. This filing is a Tier 1 primary source and confirms the scale of family beneficial ownership disclosed to the SEC.
Brock Ballard, identified in secondary reporting in a risk-oversight capacity, was reported to have conducted an insider stock sale in May 2025 disclosed via SEC Form 4; this activity is consistent with routine, disclosed insider trading and carries no adverse indication on its own. No enforcement action or regulatory finding was associated with this individual in the sources reviewed.
Across all named executives and directors reviewed, no regulatory enforcement history, sanctions-list match, or adverse litigation finding was identified through searches of SEC EDGAR litigation releases, federal court records, and named-individual sanctions screening. The concentration of continuing family governance roles alongside the 2024 transition to a professional, non-family Chief Executive Officer represents a notable but lawful evolution in leadership structure that should be monitored for its effect on strategic continuity and decision-making independence relevant to long-term supplier-relationship stability.
This section reflects screening conducted across various sanctions, controls and watchlist databases. A complete list of these databases is provided in Appendix A. Individual databases are identified in this section only when a match or potential match is found. No listing means no matches for this entity were found.
IMPORTANT DISCLAIMER: This screening is based on open-source web research conducted at the time of report generation. FirstCheck.App does not directly query sanctions databases in real time. Sanctions listings change frequently. The requesting party must conduct independent direct screening against all applicable databases before entering into any business relationship or transaction. Reliance on this report without independent verification does not constitute a defense to sanctions violations.
SCREENING TIMESTAMP: List checks performed on 2026-09-03 17:17:36 UTC.
No matches were identified for Bentley Systems, Incorporated or its key executives across the databases listed in Appendix A.
A name-only reference to "Bentley" surfaced during screening of the OpenSanctions.org aggregator, tied to a vessel designated under a Russia-related sanctions program (Sponsors and accomplices of Russian armed aggression against Ukraine). This reference was reviewed under the False Positive Prevention protocol and excluded as unrelated to the subject entity: the listed subject is a maritime vessel, not a corporation, and no corroborating identity details (registration number, address, officer names) linked it to Bentley Systems, Incorporated.
No matches were identified for any named subsidiary of Bentley Systems, Incorporated, including Seequent Holdings Limited, Power Line Systems, BSI Holdings B.V., Bentley Systems Singapore Pte Ltd, Bentley Systems (Malaysia) Sdn. Bhd., or Bentley Systems Pakistan (Pvt.) Limited, across the same screening sources.
No matches were identified for named current executives and directors, including Nicholas Cumins, Gregory Bentley, Keith A. Bentley, Barry J. Bentley, Raymond B. Bentley, or Corinne Patricia Bentley, on any restricted-party, debarment, or sanctions list reviewed.
Searches of SEC EDGAR litigation releases and enforcement actions, the DOJ Antitrust Division, the FTC, the Delaware Attorney General, and general Pennsylvania regulatory sources did not identify any enforcement action, consent order, or investigation naming Bentley Systems, Incorporated. Bentley's own SEC filings state that the company is subject from time to time to ordinary-course legal proceedings and claims but does not believe it has any material litigation pending against it; this disclosure carries elevated reliability relative to ordinary company-sourced material because it is made under securities-fraud liability standards in a Tier 1 SEC filing, though as a company-generated statement it is not treated as a substitute for independent verification.
Bentley Systems has been named as a defendant in non-practicing-entity (patent-assertion) litigation, most notably in connection with patents asserted by SoftVault Systems, Inc. against multiple technology companies including Adobe, AVG Technologies, F-Secure, Kony, and Oracle, per the RPX Insight litigation database. This matter is single-source, uncorroborated by primary docket records, and its current status (resolved, settled, or dismissed) could not be determined within available sources; it is characterized as ordinary-course industry exposure typical of software vendors rather than an indicator of wrongdoing by Bentley.
A Tier 4 legal-marketing source (Vondran Legal) indicates Bentley Systems has been involved in federal court intellectual property litigation spanning copyright, trademark, and patent matters, and separately engages in routine software license-compliance enforcement against end users, a standard industry practice rather than a regulatory finding. No confirmed securities class action naming Bentley Systems, Incorporated specifically was identified; a search result referencing a 2026 securities case was determined to pertain to an unrelated issuer, York Space Systems, and was excluded.
No matches were identified for Bentley Systems, Incorporated on the SEC EDGAR enforcement docket, CFTC or FinCEN enforcement lists, or the World Bank debarment list. No bankruptcy, insolvency proceeding, or going-concern qualification was identified in connection with the entity. The overall regulatory and legal record reflects a company with no confirmed enforcement history, tempered by an unresolved-status patent matter and a structural limitation in that direct access to Pennsylvania and Delaware state-level enforcement databases and full PACER docket text was not available within this research session.
Searches of Reuters, Bloomberg, the Financial Times, the Wall Street Journal, the Associated Press, and the BBC did not identify coverage of scandal, fraud, criminal conduct, or major controversy involving Bentley Systems, Incorporated. No discrimination lawsuit, harassment class action, whistleblower-retaliation matter, or workplace-safety scandal was identified in adverse media searches conducted for the named entity.
Employee-generated review platforms, including Glassdoor, Indeed, and CareerBliss, contain recurring references to workforce reductions in 2023 and 2024, with one reviewer characterizing the layoffs as unexpected and another describing the company as being in a constant state of restructuring in connection with efforts to increase perceived shareholder value ahead of a public listing. These sources are Tier 4 and uncorroborated by Tier 1 or Tier 2 reporting with specific headcount figures, and are treated as indicative of employee sentiment rather than as confirmed adverse events.
Overall employee sentiment nonetheless registers as net positive, with Bentley Systems holding an aggregate employee rating of 4.0 out of 5 stars across 1,430 Glassdoor reviews, above the 3.6-star average reported for information-technology sector employers generally. Workforce reduction activity also has a documented historical precedent, with the company reporting the addition of 350 employees and the layoff of approximately 100 employees during the 2009 financial downturn, indicating a longstanding pattern of periodic workforce recalibration rather than a novel distress signal.
No adverse media identified regarding cybersecurity incidents, data breaches, or ransomware events specific to Bentley Systems, Incorporated; unrelated coverage of a 2025 ransomware incident affecting an entity named Bentley Industries and a Blackbaud-related data-breach notification affecting Bentley University were identified in search results and excluded as pertaining to different, unrelated entities under the identity-anchor protocol applied throughout this research. The recurring restructuring narrative from employee-sourced media is cross-referenced with the financial and operational-continuity assessment elsewhere in this report and does not independently constitute a compliance or legal adverse finding.
Per Bentley Systems' FY2024 Form 10-K (SEC EDGAR, Tier 1), the company reported total revenues of $1,353.1 million, a 10.1% increase driven primarily by subscription revenue growth, with operating income of $302.2 million, up from $230.5 million in the prior year. Net income before income taxes was $293.1 million, with a $58.7 million tax provision recorded for the period.
Revenue is diversified across four sectors: Public Works/Utilities (59% of sector-attributable annual recurring revenue), Resources (27%), Industrial (9%), and Commercial/Facilities (5%), per the FY2024 10-K. Regionally, Americas revenue grew 10.2%, EMEA grew 9.9%, and APAC grew 10.6%, although the same filing discloses a decline in China subscription revenues within the APAC growth figure.
The most recent aggregate revenue figure identified, per company reporting for FY2025, is $1.5 billion generated across 189 countries; this figure supersedes the FY2024 total and earlier country-count references and should be treated as the current baseline. This represents continued top-line growth consistent with the trajectory shown in the FY2024 SEC filing.
Credit-rating visibility is limited: S&P Global Ratings maintains a page referencing 'Bentley Systems Inc. Ratings Withdrawn,' but substantive detail did not resolve in the sources reviewed, leaving the status undetermined and requiring direct verification via the S&P Global subscription platform. No Moody's or Fitch rating was identified in searches conducted, which is a research limitation rather than an adverse finding given that many software issuers do not maintain widely publicized public agency ratings.
Debt disclosures identified include a historical revolving credit facility of up to $500,000,000 plus $50,000,000 letter-of-credit and bridge-loan sub-facilities, per the FY2020 10-K; a single Tier 4 source describes the company as having reduced long-term debt without corroborated figures, which requires independent verification. No bankruptcy, insolvency, going-concern qualification, UCC lien, tax lien, or judgment lien was identified for Bentley Systems, Incorporated in searches conducted.
As of mid-2026, Bentley Systems' stock price was approximately $31.62 with a market capitalization of approximately $9.6 billion and trailing-twelve-month revenue of approximately $1.56 billion, per aggregator sources (Google Finance, TradingView); these are the most current figures identified and supersede earlier valuation data. A single-source aggregator (TradingView, Tier 4) reported a trailing one-year share-price decline of approximately 33.19% despite modest short-term gains, a time-sensitive figure that should be re-verified at the time of report finalization.
Recurring workforce reductions in 2023-2024 are referenced across multiple Tier 4 employee-review aggregators (Glassdoor, Indeed, CareerBliss), described by reviewers as part of a pattern of restructuring; this is not corroborated by Tier 1 or Tier 2 sources with specific headcount figures and does not itself constitute a compliance or legal adverse finding. Combined with the trailing-year share-price decline, this pattern is a continuity-monitoring item relevant to the requester's supplier-stability assessment rather than an indicator of financial distress.
Overall, the financial profile reflects a well-capitalized, profitable, and growing public company with no going-concern, insolvency, or payment-default indicators identified in Tier 1 SEC filings. Monitoring items -- an unconfirmed public credit rating, recurring workforce restructuring, and recent equity volatility -- should be tracked but do not, on the evidence reviewed, currently indicate elevated financial risk material to business continuity of the supplier relationship.
Jurisdictional Environment: Tier 1 - Bentley Systems' primary jurisdiction, the United States (Delaware incorporation, Pennsylvania headquarters), is classified Tier 1, reflecting strong rule of law, a robust securities and corporate regulatory framework, and low corruption risk.
The company's other principal operating jurisdictions identified in Tier 1/2 sources -- the United Kingdom, where a new regional headquarters opened in the City of London in 2024 per company press release, and New Zealand, home to the Seequent subsidiary acquired in 2021 -- are likewise assessed as Tier 1, low-risk jurisdictions with no elevated geopolitical exposure identified.
China presents the most significant identified geopolitical risk factor for Bentley. The FY2024 10-K (SEC EDGAR, Tier 1) discloses a decline in China subscription revenues even as the broader APAC region grew 10.6%, and China is assessed as a substantially higher-tier jurisdiction reflecting governance and enforcement concerns and an active, escalating US Bureau of Industry and Security (BIS) export-control environment targeting China-based advanced-computing and technology-transfer activity.
A Pakistani subsidiary, Bentley Systems Pakistan (Pvt.) Limited, was identified through a Tier 4 corporate-registry aggregator (OpenCorporates) but has not been independently verified as an active, as opposed to dormant or legacy, operating entity. Pakistan presents moderate-to-significant governance and corruption concerns under standard jurisdictional frameworks, and this exposure should be corroborated through direct primary-registry verification before being weighted materially in the requester's risk assessment.
No indicators were identified of Bentley Systems operations concentrated in, or ownership by, any OFAC-comprehensively-sanctioned jurisdiction (Iran, North Korea, Syria, Cuba, or Russia), and no FATF grey- or black-listed jurisdiction was identified as a primary or material operating base for the subject entity.
Siemens AG, a large minority shareholder of Bentley Systems historically reported at levels between approximately 9% and 14%, is a private German industrial company rather than a state-owned or state-controlled enterprise; no evidence was identified of foreign-government control or influence over Bentley's governance through this relationship.
In aggregate, Bentley Systems' geopolitical risk profile is low-to-moderate, anchored by its predominant Tier 1 US, UK, and New Zealand operations, with China and Pakistan exposures constituting discrete monitoring items. For a Professional Services requester evaluating service-delivery continuity, the principal geopolitical concern is the intersection of Bentley's China presence with the tightening US export-control regime, which could affect Bentley's own compliance posture and, by extension, continuity of technology delivery.
a) EXPORT CONTROLS
Direct searches of the BIS Entity List, Denied Persons List, Unverified List, and Military End-User List, together with Federal Register BIS addition notices from 2023 through 2025, returned no matches for Bentley Systems, Incorporated, its named subsidiaries, or named executives. No active or recent Department of Commerce or BIS investigation, consent agreement, or enforcement action involving Bentley Systems was identified in searches conducted against these named sources.
Given Bentley's confirmed China office and subscription-revenue presence disclosed in the FY2024 10-K, the ongoing tightening of US export controls on advanced-computing and technology-transfer activity linked to China constitutes a live and escalating compliance environment that Bentley, as a US entity, must navigate under its own Export Administration Regulations obligations. This is properly characterized as a monitoring item rather than a confirmed adverse finding, and the requester should request documentation of Bentley's export-control compliance program as it relates to any technology, source code, or data flows touching its China operations.
b) SANCTIONS SCREENING
Comprehensive named-source screening documented in Section 4, covering the OFAC SDN List, the BIS Entity List, and the UN, EU, and UK HM Treasury consolidated sanctions lists, returned no confirmed match for Bentley Systems, Incorporated, its subsidiaries, or named executives. A name-only 'Bentley' match identified on OpenSanctions.org was excluded under the applicable false-positive-prevention protocol, as it corresponds to a sanctioned vessel under a Russia-related program and shares no corroborating corporate identity details with the subject entity.
No indication was identified of 50%-or-greater ownership or control of Bentley Systems by any OFAC-designated or otherwise sanctioned party, and Siemens AG's minority shareholding carries no identified sanctions nexus. No additional sanctions exposure was identified through the foreign subsidiary jurisdictions reviewed, including the Netherlands, Singapore, Malaysia, and the United Kingdom, though the Pakistani subsidiary's operational status remains unverified as noted in Section 8.
c) DATA PRIVACY
No GDPR enforcement action, CCPA/CPRA enforcement action, or confirmed data-breach notification specific to Bentley Systems, Incorporated was identified in searches of relevant regulatory guidance and breach-disclosure-adjacent sources. Search results referencing a 'Bentley' data-breach response connected to the third-party Blackbaud vendor incident were determined to pertain to the unrelated Bentley University and were excluded under the entity-identity anchor applied throughout this research.
As a global SaaS provider processing client engineering and infrastructure data across 189 countries as of FY2025 company reporting, Bentley is subject to a broad range of data-protection regimes, including GDPR and various US state privacy statutes. The absence of identified enforcement history is a positive indicator, though it should be corroborated through direct review of Bentley's data-processing agreements and privacy policy given the scale and sensitivity of client data processed on its infrastructure platforms.
d) CFIUS/FOREIGN INVESTMENT
Siemens AG's minority equity stake in Bentley Systems, reported at levels ranging from approximately 9% to 14% depending on the reporting date across Tier 3 sources, has not been identified as having triggered a CFIUS review or a public foreign-ownership-control-or-influence finding. Reporting from September 2020 indicated Siemens was weighing a full acquisition of Bentley Systems, but no such transaction was completed.
Separate single-source Tier 4 reporting references 2024 takeover speculation involving Schneider Electric, after which the Bentley family is reported to have elected to retain independence; this account requires corroboration, and no CFIUS filing was identified as having occurred in connection with either episode. The recurring pattern of acquisition interest from foreign industrial technology companies is a structural feature relevant to the requester's long-term continuity planning, as a future change of control could alter Bentley's strategic priorities or commercial terms.
e) IP & TRADE SECRETS
Bentley Systems was named as a defendant in patent-assertion litigation brought by SoftVault Systems, Inc., a non-practicing entity that asserted US patents 6,249,868 and 6,594,765 against multiple technology companies, including Adobe, AVG Technologies, F-Secure, Kony, and Oracle, per the RPX Insight litigation database (Tier 4 legal aggregator). This pattern is consistent with routine non-practicing-entity litigation common across the software industry and does not indicate wrongdoing by Bentley; the matter's current status is undetermined and the finding is single-source, without corroborated docket-level detail.
A Tier 4 legal-marketing source (Vondran Legal) indicates Bentley Systems has been involved in federal court intellectual-property litigation spanning copyright, trademark, and patent matters, and separately issues routine software-license-compliance enforcement letters to end-users, a standard practice among enterprise software vendors protecting licensing revenue. No trade-secret misappropriation claims, whether as plaintiff or defendant, were identified against or by Bentley Systems in the sources reviewed.
f) CYBERSECURITY
No confirmed data breach, ransomware incident, or major cybersecurity incident specific to Bentley Systems, Incorporated was identified through searches of SEC 8-K filings, breach-notification-adjacent sources, and general and trade media. A 2025 ransomware incident affecting an entity named 'Bentley Industries' was identified during research and confirmed to be unrelated to the subject entity, and was excluded under the entity-identity anchor applied throughout this report.
A Tier 4 aggregator claimed Bentley Systems holds an ISO/IEC 27001:2013 Information Security Management System certification under a specific certificate number purportedly issued by A-LIGN Compliance and Security, Inc.; this claim is single-source, originating from an unverified compliance-report-generation site, and could not be corroborated against a certification-body registry or Bentley's own security disclosures. Given the volume of client engineering and infrastructure data Bentley processes, the requester should request direct confirmation of current information-security certifications and any incident-history attestations as part of onboarding or contract-renewal due diligence.
g) GOVERNMENT CONTRACTS
Carahsoft is authorized to carry the full Bentley Systems software portfolio across multiple US federal contract vehicles, including NASA SEWP V, OMNIA Partners, the National Cooperative Purchasing Alliance (NCPA), and Bentley's own General Services Administration Multiple Award Schedule (GSA MAS) contract, confirming active federal government contracting relationships. No suspension, debarment, or SAM.gov exclusion was identified for Bentley Systems, consistent with the clean screening result reported in Section 4.
No FedRAMP authorization was confirmed for Bentley Systems in searches of the FedRAMP Marketplace and related GSA program pages, and no CMMC certification level was confirmed. The absence of an affirmative listing does not establish non-authorization but is a research limitation that should be resolved through direct verification with GSA or Bentley for any engagement involving US federal government end-use of Bentley's software.
h) AI/EMERGING TECH
No AI ethics controversies, algorithmic-bias findings, or regulatory actions were identified in connection with Bentley Systems' AI-enabled digital-twin and infrastructure-monitoring product lines, including the iTwin Platform, across the trade press, regulatory, and litigation sources reviewed.
As Bentley continues to integrate generative and predictive AI capabilities into its infrastructure engineering software, the absence of current adverse findings should be treated as a point-in-time result rather than a permanent clearance. The requester should monitor the evolving EU AI Act and emerging US state-level AI regulations for future applicability to Bentley's AI-enabled offerings, given the company's reported 189-country footprint as of FY2025.
i) COMPETITION & PLATFORM REGULATION
No DOJ or FTC antitrust investigation or enforcement action, and no European Commission competition-law proceeding, was identified against Bentley Systems, Incorporated. Historical 2020 trade commentary speculated that a hypothetical Autodesk acquisition of Bentley or of competitor PTC would warrant FTC scrutiny given Autodesk's market position, but this was speculative industry commentary and no such transaction occurred.
Bentley and Autodesk are recognized direct competitors in the architecture, engineering, and construction and infrastructure software space; this competitive landscape is relevant to the conflict-of-interest analysis addressed elsewhere in this report regarding Bentley's likely concurrent service to competitors of the requester. No EU Digital Markets Act or Digital Services Act gatekeeper designation applies to Bentley, as these platform-regulation regimes target large consumer-facing digital platforms rather than enterprise infrastructure-engineering software vendors.
a) QUALITY & MANAGEMENT SYSTEMS
No independently confirmed ISO 9001 (quality management), ISO 45001 (occupational health and safety), ISO 14001 (environmental management), or ISO 22301 (business continuity) certification was identified for Bentley Systems, Incorporated across the Tier 1 and Tier 2 sources reviewed, including SEC filings, company press releases, and general searches of certification-body registries. This absence should not be read as non-compliance; enterprise software and SaaS providers frequently do not pursue manufacturing-oriented quality certifications such as ISO 9001 or occupational-safety certifications such as ISO 45001, given an operating model centered on software development and cloud service delivery rather than physical production.
No business-continuity certification such as ISO 22301, or an equivalent formal accreditation, was identified, which is a relevant gap given the operational-continuity considerations raised elsewhere in this report in connection with recurring workforce restructuring activity noted in adverse media findings. Direct verification with Bentley's own compliance or trust-center resources is recommended before this absence is treated as either a positive or negative indicator.
b) INFORMATION SECURITY
A Tier 4 compliance-report aggregator (firstcheck.app) referenced a specific ISO/IEC 27001:2013 Information Security Management System certificate, citing Certificate Number ISMS-BE-103015.1 issued by A-LIGN Compliance and Security, Inc. This claim is single-source, originates from an automated aggregator rather than a certification-body registry or Bentley's own published security documentation, and could not be corroborated within this research; its status is therefore assessed as undetermined pending direct verification.
No SOC 2 Type I or Type II attestation was independently confirmed through Tier 1 or Tier 2 sources for Bentley Systems, Incorporated. Given that Bentley operates cloud-based platforms including the iTwin Platform and Bentley Infrastructure Cloud, the absence of a confirmed, current SOC 2 attestation is a material gap for a requester conducting technology-vendor risk assessment and should be the subject of a direct information request to Bentley.
c) INDUSTRY-SPECIFIC CERTIFICATIONS
No PCI-DSS attestation, CMMC (Cybersecurity Maturity Model Certification) level designation, FedRAMP authorization, HIPAA compliance attestation, or HITRUST CSF certification was confirmed for Bentley Systems, Incorporated in the sources reviewed, including GSA.gov's FedRAMP marketplace listings and general regulatory searches. Bentley's confirmed participation in US federal contract vehicles, including its GSA MAS Schedule, NASA SEWP V, OMNIA Partners, and the National Cooperative Purchasing Alliance via reseller Carahsoft Technology Corporation, indicates established government-sector engagement, but the absence of a confirmed FedRAMP authorization means any cloud offerings sold into federal accounts may rely on deployment or authorization models not identified in this research.
The lack of a confirmed CMMC designation is a relevant gap should Bentley's software be positioned for use in Department of Defense-adjacent programs, though no evidence was identified indicating an active DoD contract requiring such certification. This category should be revisited directly with Bentley if the requester's use case involves regulated data categories such as protected health information, payment card data, or controlled unclassified information.
d) PROFESSIONAL ACCREDITATIONS & MEMBERSHIPS
No Better Business Bureau accreditation or rating was identified for Bentley Systems, Incorporated in searches conducted. Bentley maintains a confirmed reseller and government-contracting channel relationship with Carahsoft Technology Corporation, through which its software portfolio is made available across multiple federal contract vehicles, indicating an established position within recognized public-sector procurement channels.
No memberships in recognized software-industry standards bodies or trade associations were confirmed through Tier 1 or Tier 2 sources within the scope of this research. Bentley's participation in industry groups relevant to the architecture, engineering, and construction technology sector, if any, was not independently verified and would require direct confirmation from the company.
e) CERTIFICATION CURRENCY
Given the absence of confirmable primary-source certification data across the categories reviewed above, no certification referenced in this report can be affirmatively classified as currently active with confidence. The ISO/IEC 27001:2013 claim remains flagged as undetermined pending direct verification with the named certification body, A-LIGN Compliance and Security, Inc., or with Bentley's own security documentation.
This gap is assessed as a research and visibility limitation rather than an adverse finding, since software companies are not universally required to publicly disclose certification status, and Bentley's own website trust center was not directly reviewed in full during this research session. A direct information request to Bentley regarding current ISO 27001, SOC 2, FedRAMP, and CMMC status is recommended as a follow-up action prior to any decision reliant on certification currency.
No evidence identified of self-dealing by Bentley Systems' management, executives, or controlling family shareholders in the sources reviewed, including SEC EDGAR filings, company disclosures, and general litigation and media searches. No non-arm's-length related-party transactions were identified in this research; a full related-party-transaction review would require direct examination of Bentley's proxy statement (DEF 14A) related-party disclosures, which were referenced but not retrieved in full text during this research session, and this is noted as a limitation.
Bentley Systems retains a concentrated-control governance structure in which Class A common stock carries twenty-nine votes per share, and the amended and restated certificate of incorporation prohibits stockholder action by written consent unless the Bentley Family ceases to own a majority of outstanding voting power. This is a disclosed, lawful governance mechanism rather than a violation, but it entrenches family control and limits the influence of minority shareholders or arm's-length counterparties over strategic decision-making.
The July 2024 transition of Nicholas Cumins to Chief Executive Officer, the first non-family CEO in the company's history, occurred alongside co-founder Greg Bentley's move to Executive Chair of the Board, with other Bentley family members continuing to serve as directors. This governance configuration should be monitored by the requester as an indicator of the degree to which strategic decisions remain subject to family influence notwithstanding day-to-day operational leadership by a non-family executive.
Siemens AG occupies a dual position as a significant minority shareholder, reported at levels ranging from approximately 9 percent to 14 percent across different reporting dates, and as a strategic commercial and technology alliance partner engaged in a joint innovation-investment program initially valued at 50 million euros and later expanded to 100 million euros per Siemens press materials. This combination of equity ownership and commercial alliance is a structural conflict-of-interest consideration relevant to any requester that separately transacts with Siemens or Siemens-affiliated infrastructure technology providers.
Reporting indicates that Siemens weighed a full acquisition of Bentley Systems in September 2020 and that Schneider Electric-related takeover speculation arose in 2024, with the Bentley family electing in both instances to retain independence; this later item is single-source and requires corroboration. The family's retained voting control means that such strategic decisions, including whether to entertain acquisition or partnership proposals, rest substantially with family interests rather than with the broader shareholder base or arm's-length commercial counterparties.
Bentley Systems supplies infrastructure engineering software broadly across the architecture, engineering, and construction sector, and its own disclosure that approximately 80 percent of 2018 and 2019 total revenues derived from accounts of more than ten years' standing indicates a broad, entrenched customer base likely spanning multiple firms that compete with one another and, potentially, with the requester. This is a standard characteristic of a horizontal enterprise software vendor and does not itself indicate impropriety, but it warrants contractual attention to data segregation, intellectual property protection, and non-preferential-treatment terms within the specific supplier relationship.
No evidence of antitrust violation or unlawful preferential treatment favoring one customer over another was identified in the sources reviewed, and no confirmed conflict-of-interest violation was identified with respect to Bentley Systems' management, ownership, or commercial relationships. The considerations identified above are structural and disclosed rather than concealed, and are appropriately addressed through standard arm's-length contractual safeguards rather than through avoidance of the relationship.
Bentley Systems, Incorporated has no controlling parent company; it is itself the publicly traded, top-level entity within its corporate structure, listed on Nasdaq under the ticker BSY. Siemens AG holds a large minority equity stake but does not exercise control over Bentley's governance, and no other entity was identified as holding a controlling interest.
Bentley Systems completed its acquisition of Seequent Holdings Limited, a New Zealand-headquartered 3D geological and geophysical modeling software provider, in June 2021 for approximately 883.3 million dollars in cash, net of cash acquired, plus 3,141,342 shares of Class B common stock, per the company's SEC filings. Seequent operates as a semi-autonomous business unit, marketed as the Bentley Subsurface Company, with its own chief executive reporting into Bentley's broader product organization.
Bentley Systems acquired Power Line Systems in January 2022 for approximately 695.97 million dollars in cash, net of cash acquired, per SEC filings. The company disclosed completing six, thirteen, and six acquisitions respectively in fiscal years 2022, 2021, and 2020, for aggregate purchase prices of approximately 765.1 million, 1,269.8 million, and 102.1 million dollars, reflecting a consistent pattern of active, frequent acquisition activity.
Bentley Systems states it has completed more than 120 acquisitions over its four-decade history, a pattern that creates ongoing integration and legal-inheritance risk across a large number of absorbed entities. No specific adverse finding was identified against any individual acquired subsidiary in the sources reviewed, but the sheer volume of historical acquisitions is a structural factor relevant to comprehensive third-party risk visibility.
OpenCorporates, a Tier 4 aggregator, lists approximately 94 related entities associated with Bentley Systems, including BSI Holdings B.V. and Plaxinvest B.V. in the Netherlands, Bentley Software, Inc. and Digital Water Works, Inc. in Delaware, Bentley Systems Singapore Pte Ltd, Bentley Systems (Malaysia) Sdn. Bhd., SRO Solutions Limited in the United Kingdom, and Bentley Systems Pakistan (Pvt.) Limited. These entries were not independently verified against primary foreign corporate registries and are flagged as requiring direct corroboration before reliance, particularly given the presence of registrations in Pakistan, a jurisdiction carrying elevated governance and corruption risk under standard jurisdictional-tier frameworks.
Bentley Systems maintains a material strategic commercial alliance with Siemens AG involving joint innovation investment, initially valued at 50 million euros and subsequently expanded to 100 million euros per Siemens press materials; this alliance is not structured as a formal joint-venture entity but represents a significant ongoing commercial affiliation. This dual shareholder-and-alliance-partner relationship is addressed further in the Conflicts of Interest section of this report.
Significant shareholders identified at or approaching the 10 percent threshold include members of the Bentley family, whose aggregate holdings are distributed across a grantor retained annuity trust and 19 family trusts, with one reporting person's disclosed holdings representing 13.2 percent of the Class B common stock class as of March 31, 2026 per SEC Schedule 13G/A. Siemens AG has been reported at ownership levels ranging from approximately 9 percent to 14 percent across different reporting dates in Tier 2 and Tier 3 sources, and current verification through the most recent Schedule 13G or 13D filing is recommended given the inconsistency across reporting periods.
Overall, the entity-structure review identified no controlling foreign or sanctioned-jurisdiction parent and no confirmed adverse finding attached to any specific subsidiary or affiliate. The breadth of unverified international subsidiary registrations, combined with unconfirmed operational presence in Pakistan and confirmed but declining revenue exposure in China, represents a monitoring item for the requester's jurisdictional and supply-chain risk review rather than a confirmed adverse finding.
13a) Financial Stability
Bentley Systems reported total revenues of $1,353.1 million for fiscal year 2024, a 10.1% year-over-year increase driven primarily by subscription revenue growth, with operating income rising to $302.2 million from $230.5 million in the prior year, per the company's SEC 10-K filing (Tier 1 source). More recent aggregated reporting for fiscal year 2025 indicates revenue of approximately $1.5 billion across 189 countries; this later figure supersedes the FY2024 total and should be treated as the current baseline for financial-capacity assessment. As of mid-2026, the company's trailing-twelve-month revenue was reported at approximately $1.56 billion, with a market capitalization of approximately $9.6 billion and a share price near $31.62 (Tier 4, TradingView/Google Finance aggregation), figures that require re-verification at the time of report finalization given their time-sensitivity.
No bankruptcy, insolvency, going-concern qualification, tax lien, judgment lien, or UCC lien filing was identified against Bentley Systems, Incorporated in the searches conducted, and the company's own 10-K legal-proceedings disclosure does not indicate material litigation exposure that would threaten solvency. Credit-rating visibility is limited: an S&P Global Ratings webpage referencing 'Bentley Systems Inc. Ratings Withdrawn' was identified but substantive detail did not resolve during this research, and no active Moody's or Fitch rating was located; this status is undetermined pending direct verification through the S&P Global subscription platform and does not itself indicate credit deterioration. The company's most recently confirmed credit facility on record is a $500 million revolving credit facility with $50 million letter-of-credit and bridge-loan sub-facilities, disclosed in the FY2020 10-K; no more current facility figures or covenant-violation disclosures were identified in this research, which is a data gap rather than an adverse finding.
A recurring theme in employee-generated reviews (Glassdoor, Indeed, CareerBliss; Tier 4, uncorroborated by primary financial disclosures) references multiple large-scale workforce reductions in 2023 and 2024, occurring against a backdrop of continued revenue and operating-income growth per Tier 1 filings. Bentley Systems' overall Glassdoor employee rating of 4.0 out of 5 stars, in line with the broader IT industry average, suggests these reductions have not produced a broadly negative internal sentiment pattern, though the layoffs coincide with a reported -33.19% decline in BSY share price over the trailing twelve months as of the mid-2026 data point reviewed. For a supplier relationship of the type under review, recurring restructuring activity combined with share-price volatility warrants ongoing monitoring of business-continuity capacity, even though no Tier 1 or Tier 2 source corroborates specific layoff figures or connects the reductions to financial distress.
13b) Geopolitical & Regulatory Risk
Bentley Systems' principal jurisdictions of operation include the United States (headquarters, Exton, Pennsylvania), the United Kingdom (a new regional headquarters opened in the City of London in 2024), and New Zealand (Seequent subsidiary), all of which are assessed as Tier 1, low-risk jurisdictions under standard governance and rule-of-law frameworks. The company's FY2024 10-K discloses that its Asia-Pacific segment grew 10.6% overall, driven by expansion in Australia, Southeast Asia, and India, but notes that China specifically experienced a decline in subscription revenues; this is a Tier 1-sourced, revenue-trend disclosure rather than a compliance finding, but it confirms an active China operating presence that carries independent geopolitical weight. China is assessed under the standard jurisdictional framework as a higher-risk operating environment given governance and enforcement opacity and the currently escalating US Bureau of Industry and Security export-control posture toward China-linked advanced-computing and technology-transfer activity.
No evidence was identified that Bentley Systems, its subsidiaries, or its named executives appear on the BIS Entity List, the Denied Persons List, the Unverified List, or the Military End-User List, and no active or historic Department of Commerce or BIS enforcement action against the company was located in Federal Register or agency-database searches. Nonetheless, because US export-control jurisdiction attaches to Bentley as a US person/entity regardless of the location of any given counterparty or subsidiary, the confirmed China office presence represents a live, escalating compliance environment that the requester should treat as a forward-looking monitoring item rather than a resolved matter, particularly to the extent any product, data, or technology-sharing arrangement with Bentley touches its China operations.
A Tier 4 corporate-registry aggregator (OpenCorporates) lists a Bentley Systems Pakistan (Pvt.) Limited entity among approximately 94 related entities, a jurisdiction presenting moderate-to-significant governance and corruption concerns; this presence has not been independently corroborated as an active (versus dormant or legacy) operation through a primary Pakistani registry source, and should be verified directly before being treated as a material operating risk. No indicators were identified of Bentley Systems ownership by, or concentrated operations in, any OFAC-comprehensively-sanctioned jurisdiction (Iran, North Korea, Syria, Cuba, or Russia), and no FATF grey- or black-listed jurisdiction was identified as a primary or material operating base for the company.
Siemens AG, a German industrial group and Bentley's largest disclosed minority shareholder (historically reported in a range of approximately 9% to 14% depending on the filing date), is a privately controlled European industrial company rather than a state-owned enterprise, and no evidence of foreign-government control or influence over Bentley's governance was identified. Reported September 2020 discussions of a possible full Siemens acquisition of Bentley did not result in a completed transaction, and 2024 takeover speculation involving Schneider Electric reportedly ended with the Bentley family electing to retain independence (Tier 4, single-source, requiring corroboration); no CFIUS filing or review was identified as having occurred in connection with either matter.
13c) Supply Chain & Logistics Security
Bentley Systems operates as a software licensing and SaaS delivery business rather than a manufacturer or physical-goods importer, and this business model materially narrows the applicability of conventional supply-chain security frameworks. Searches conducted against the Customs-Trade Partnership Against Terrorism (C-TPAT) program, Dodd-Frank Section 1502 conflict-minerals (3TG) disclosure requirements, and the Uyghur Forced Labor Prevention Act (UFLPA)/US Customs and Border Protection forced-labor enforcement actions returned no matches or applicability for Bentley Systems, Incorporated, consistent with the absence of a physical goods import/export supply chain requiring such screening. This is a structural characteristic of the entity's operating model rather than a gap in compliance posture, and it should be distinguished explicitly from the unrelated Bentley Motors automotive manufacturer, which would carry materially different conflict-minerals and physical supply-chain exposure.
The most relevant supply-chain dependency for a software and SaaS provider of Bentley's profile is not physical component sourcing but cloud-infrastructure and hosting-provider dependency supporting platforms such as the iTwin Platform and the Bentley Infrastructure Cloud. No specific adverse finding regarding cloud-vendor concentration, hosting-provider outage history, or infrastructure-redundancy failure was identified in this research, but no primary-source confirmation of the company's cloud-provider diversification or business-continuity architecture was located either. Given the requester's stated interest in continuity of service and single-source dependency risk, this is an appropriate follow-up inquiry to direct to Bentley Systems directly, as the available public record does not address it in sufficient detail to reach a conclusion either way.
Bentley's Modern Slavery Act statement, published on its own corporate website (bentley.com, Tier 3, company-generated), states a zero-tolerance policy toward human trafficking and slavery in its supply chain, references compliance training for affected departments, and describes a reporting channel through the company's Compliance Committee. This disclosure was reviewed only to confirm its existence and general content, not as independent verification of implementation effectiveness, and no third-party audit, NGO report, or regulatory finding corroborating or contradicting the statement's substance was identified. As with the cloud-dependency point above, the low inherent labor-supply-chain risk profile of a software company somewhat limits the practical significance of this category relative to the physical-goods supply chains more commonly scrutinized under UFLPA and conflict-minerals frameworks.
13d) Technology, IP & Data Risk
Searches of the HHS breach-notification portal, SEC 8-K disclosure filings, and state Attorney General data-breach notification registries did not identify any confirmed data-breach event or regulatory data-privacy enforcement action attributable to Bentley Systems, Incorporated. No Federal Trade Commission privacy enforcement action, and no GDPR or CCPA/CPRA enforcement action, was identified against the entity. Search results referencing a data-breach response by Blackbaud, a third-party vendor, were traced to Bentley University, an unrelated educational institution, and were excluded from this assessment under the entity-identity anchoring protocol applied throughout this research.
On the intellectual-property side, RPX Insight litigation database records (Tier 4 legal aggregator) indicate that Bentley Systems was named as a defendant in patent-assertion litigation brought by SoftVault Systems, Inc., a non-practicing entity that asserted patents 6,249,868 and 6,594,765 against multiple technology companies including Adobe, AVG Technologies, F-Secure, Kony, and Oracle. This matter is characteristic of routine non-practicing-entity ('patent troll') litigation common across the software industry, and its current docket status could not be independently corroborated beyond the single-source aggregator; it is treated as resolved or of undetermined status rather than an active, material exposure. A separate Tier 4 legal-marketing commentary (Vondran Legal) notes that Bentley Systems has, on occasion, issued software license-compliance enforcement letters to end-users, a standard software-industry audit practice that does not constitute an adverse regulatory or litigation finding.
No trade secret misappropriation claims, either as plaintiff or defendant, were identified against Bentley Systems in court records or legal-aggregator searches conducted. No confirmed CVE (Common Vulnerabilities and Exposures) history specific to Bentley's iTwin Platform or Bentley Infrastructure Cloud products was located in this research, and the company's claimed ISO/IEC 27001:2013 certification (Certificate Number ISMS-BE-103015.1, per a single Tier 4 compliance-aggregator source) could not be corroborated against a certification-body registry or Bentley's own security trust documentation, and should be treated as unverified pending direct confirmation. Given the entity's role as a supplier of infrastructure-engineering and geospatial software with underlying data-hosting and digital-twin functionality, the requester should independently request evidence of current SOC 2 attestation, ISO 27001 certification, and cloud-hosting redundancy arrangements as a condition of any arms-length engagement, since none of these could be affirmatively confirmed from primary sources within this review.
13e) Labor, Human Rights & Anti-Slavery
Bentley Systems maintains a published Modern Slavery Act statement (bentley.com, confirmed as pertaining to the subject entity and not to the unrelated Bentley Motors Limited) in which the company states it maintains a zero-tolerance policy toward human trafficking and slavery in its supply chain, has provided compliance training to affected departments, and requires that any suspected violation be reported to Bentley's internal Compliance Committee. This is a Tier 3, company-generated disclosure used here to confirm the existence and general content of the policy rather than as independent verification of implementation effectiveness; no third-party audit or NGO assessment of Bentley's modern-slavery compliance program was identified. Given Bentley's business model as a software licensing and SaaS provider with limited physical manufacturing or raw-material sourcing, the inherent forced-labor and human-trafficking risk profile in its own supply chain is assessed as structurally low relative to hardware-manufacturing or extractive-industry counterparties.
Searches of OSHA enforcement records did not identify any willful-violation citations or workplace-fatality investigations involving Bentley Systems, consistent with a predominantly office-based, software-industry workforce with limited physical-hazard exposure. No National Labor Relations Board unfair-labor-practice findings or union-organizing controversies were identified, and no Department of Labor Wage and Hour Division enforcement action was located in the sources reviewed. No Equal Employment Opportunity Commission enforcement action or discrimination class action was identified against the entity in court-record or regulatory-database searches conducted.
Employee-generated review content on Glassdoor, Indeed, and CareerBliss (Tier 4, uncorroborated aggregator sources) references recurring workforce restructuring activity in 2023 and 2024, described by reviewers as a pattern of large-scale layoffs occurring in a company described as being in 'a constant state of restructuring.' This commentary is relevant to operational-continuity considerations addressed elsewhere in this report but does not, on its own, constitute a labor-law or human-rights compliance finding, and no wrongful-termination litigation, mass-layoff notification violation (WARN Act), or related enforcement action was identified to corroborate or elevate this workforce-reduction pattern into an adverse legal finding. No indicators of child labor, forced labor, or human-trafficking exposure were identified in Bentley's own operations or disclosed supply chain, and the California Transparency in Supply Chains Act and UFLPA screening conducted returned no adverse matches, consistent with the entity's non-manufacturing business model.
| SECTION | RISK INDICATOR |
|---|---|
| 1. ENTITY INFORMATION | GreenEntity identity, registration, and headquarters location are confirmed through SEC EDGAR primary filings corroborated by registry data, with no material identification ambiguity affecting the named subject. |
| 2. OWNERSHIP & STRUCTURE | YellowConcentrated founder-family voting control and Siemens' overlapping shareholder and strategic-partner role are disclosed, lawful governance features that warrant ongoing monitoring rather than reflecting any identified violation. |
| 3. KEY PERSONNEL | GreenNo adverse regulatory, sanctions, or litigation findings were identified for any named executive or director in the sources reviewed. |
| 4. SANCTIONS & CONTROLS SCREENING | GreenSystematic screening against OFAC, BIS, SAM.gov, UN, EU, UK HM Treasury, and related named sources returned no confirmed matches for Bentley Systems, Incorporated or its key executives. |
| 5. REGULATORY & LEGAL | YellowNo material adverse enforcement, antitrust, or securities action was identified, but ordinary-course patent-infringement exposure of undetermined status and structural limits on state-level regulator database access warrant continued monitoring. |
| 6. ADVERSE MEDIA | YellowNo scandal, fraud, or criminal-conduct coverage was identified in Tier 1/2 media, but recurring employee-sourced reporting of workforce reductions across 2023 and 2024 warrants monitoring for operational continuity purposes. |
| 7. FINANCIAL ASSESSMENT | YellowFinancial fundamentals show sustained revenue and operating-income growth with no adverse liquidity or insolvency findings, but recurring workforce reductions, an unresolved public credit-rating status, and recent share-price volatility warrant ongoing monitoring for a supplier-continuity assessment. |
| 8. GEOPOLITICAL RISK | YellowThe primary US jurisdiction presents low geopolitical risk, but identified and unverified operational exposure in China and Pakistan, respectively, together with an active US export-control environment, warrant ongoing monitoring. |
| 9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY) | See individual sub-section risk indicators in report body |
| 10. CERTIFICATIONS & ACCREDITATIONS | Insufficient DataCertification status across quality, security, and industry-specific frameworks could not be confirmed through Tier 1 or Tier 2 sources, reflecting a visibility limitation rather than a confirmed adverse finding. |
| 11. CONFLICTS OF INTEREST | YellowDisclosed governance concentration through Bentley family super-voting control and Siemens AG's dual role as shareholder and strategic alliance partner present lawful but structurally relevant conflict-of-interest considerations requiring monitoring, with no confirmed violation identified. |
| 12. RELATED & ASSOCIATED ENTITIES | YellowUnverified international subsidiary registrations in higher-risk jurisdictions, including Pakistan and China, identified only through a Tier 4 aggregator warrant monitoring, though no adverse or sanctioned-entity finding was identified. |
| 13. AREAS OF SPECIAL INTEREST | See individual sub-section risk indicators in report body |
Key Risk Factors:
• Confirmed China office presence sits within an escalating US export-control enforcement environment.
• Unverified Pakistani subsidiary registration lacks primary-source corroboration of active operating status.
• Founder family retains concentrated 29-votes-per-share control limiting minority and counterparty influence.
• Siemens AG holds a dual role as minority shareholder and strategic commercial alliance partner.
• Recurring 2023-2024 workforce reductions are reported across multiple employee-review platforms.
• Trailing twelve-month share price declined approximately 33% despite continued revenue growth.
• Public credit rating status is listed as withdrawn by S&P with no substantive detail confirmed.
• ISO 27001 and SOC 2 security certification claims remain single-source and unverified.
• Ordinary-course, non-practicing-entity patent litigation carries an unresolved current status.
• Bentley Systems likely supplies direct competitors of the requester within the AEC and professional-services sector.
• FedRAMP and CMMC certification status remain unconfirmed despite active federal contract vehicles.
• No sanctions, export-control, or restricted-party matches were identified across named databases screened.
Recommendations:
1. Request direct confirmation from Bentley Systems of active operating status for its Pakistani subsidiary through Pakistan's primary corporate registry.
2. Obtain documentation of Bentley's export-control compliance program covering its China office and any related technology or data flows.
3. Request current SOC 2 Type II attestation and ISO/IEC 27001 certification documentation directly from Bentley to corroborate unverified third-party claims.
4. Verify Bentley's current public credit rating status directly with S&P Global given the ambiguous Ratings Withdrawn listing.
5. Incorporate contractual data-segregation, IP-protection, and non-preferential-treatment clauses given Bentley's likely concurrent service to competitors.
6. Confirm FedRAMP and CMMC certification status directly with Bentley or GSA if any federal end-use is contemplated.
7. Request Bentley's most recent proxy statement (DEF 14A) to review related-party transaction disclosures in full.
8. Monitor Siemens AG's current equity stake via Bentley's most recent Schedule 13D or 13G filings given reporting inconsistencies across periods.
Monitoring Needs:
• Ongoing tracking of Bentley's China subscription revenue trend and any BIS export-control enforcement developments.
• Periodic review of workforce-reduction reporting and its correlation with service-delivery continuity.
• Monitoring of BSY share price and market capitalization for material deterioration signals.
• Tracking of any future change-of-control developments involving Siemens AG, Schneider Electric, or other potential acquirers.
• Periodic re-screening against OFAC, BIS, and other sanctions lists given evolving Russia- and China-related programs.
• Monitoring of Bentley family governance dynamics following the 2024 non-family CEO appointment.
Based on the findings in this report, the following questions should be addressed through direct inquiry with the entity or additional research:
1. Can Bentley Systems provide primary-source confirmation that Bentley Systems Pakistan (Pvt.) Limited is an active, operating entity rather than a dormant or legacy registration?
2. What export-control compliance controls does Bentley maintain over technology, source code, or data accessible to or processed by its China office?
3. Can Bentley provide current, verifiable SOC 2 Type II and ISO/IEC 27001 certification documentation, including certificate numbers traceable to the issuing body?
4. What is Bentley's current public credit rating status, and what explains S&P Global's Ratings Withdrawn listing?
5. What cloud-hosting providers support the iTwin Platform and Bentley Infrastructure Cloud, and what redundancy exists against single-source dependency?
6. What specific headcount figures and business rationale underlie the 2023-2024 workforce reductions referenced in employee reviews?
7. What is Siemens AG's current confirmed equity percentage in Bentley Systems per the most recent Schedule 13D or 13G filing?
8. Does Bentley maintain FedRAMP authorization or CMMC certification for any offering relevant to the requester's federal or regulated engagements?
9. What contractual data-segregation and confidentiality safeguards does Bentley apply given its concurrent service to the requester's direct competitors?
10. What is the current resolution status of the SoftVault Systems patent-assertion litigation naming Bentley Systems as a defendant?
Government & Regulatory Databases:
• SEC EDGAR (sec.gov) - 10-K filings, Schedule 13G/A, Form 4 - results found
• OFAC Sanctions List Search/SDN List - no matches found
• BIS Entity List / Federal Register notices - no matches found
• SAM.gov exclusions and debarments - no matches found
• GSA.gov FedRAMP Marketplace - no Bentley-specific authorization confirmed
• Delaware Division of Corporations - registration confirmed, partial detail
• UN, EU, and UK HM Treasury consolidated sanctions lists - no matches found (limited direct query)
• OpenSanctions.org aggregator - name-only vessel match identified and excluded as false positive
Court & Legal Records:
• RPX Insight litigation database - SoftVault Systems patent-assertion litigation found
• Vondran Legal - intellectual property litigation commentary found
• Law360 and Justia - unrelated 'Bentley' entity litigation found and excluded
• PACER/CourtListener federal court records - no material adverse litigation identified (limited access)
News & Media:
• Reuters, Bloomberg, Financial Times, Wall Street Journal, Associated Press, BBC - no adverse coverage found
• Wikipedia, TradingView, Google Finance, PitchBook, Investing.com, Yahoo Finance, BusinessWire, Nasdaq.com, citybiz - corporate facts found
• Geospatial World and Siemens press office (press.siemens.com) - Siemens equity stake reporting found
• Glassdoor, Indeed, CareerBliss, Blind - employee workforce and layoff sentiment found
Business Registries & Financial:
• OpenCorporates - Delaware registration and subsidiary list found (Tier 4, uncorroborated)
• D&B, Simply Wall St, Forbes Advisor, Fintel, Last10K, StockTitan, MarketBeat, WallStreetZen - ownership and financial data found
• S&P Global Ratings - Ratings Withdrawn listing identified, substantive detail unresolved
Industry-Specific Sources:
• AEC Magazine - competitive landscape commentary found
• Carahsoft - GSA and federal contract vehicle confirmation found
• Sustainalytics ESG Risk Rating - rating page identified, controversy detail unresolved
• Bentley.com Modern Slavery Act statement - found (company-generated, Tier 3)
• firstcheck.app - unverified ISO 27001 certification claim flagged as unconfirmed
This report is based on publicly available information accessible through web search. The following limitations apply:
Information Not Accessible:
• Proprietary databases (e.g., LexisNexis, World-Check, Dow Jones Risk & Compliance)
• Non-public court records and sealed proceedings
• Confidential regulatory examination results
• Private company financial statements
• Non-English language sources (limited coverage)
• Real-time sanctions list updates (recommend independent verification)
• International jurisdiction coverage: the depth and reliability of open-source intelligence varies significantly by jurisdiction, entity type, disclosure requirements, press freedom, and corporate registry accessibility. See firstcheck.app for full details.
Recommended Additional Due Diligence:
1. Request direct primary-source verification of Bentley Systems Pakistan (Pvt.) Limited's active operating status before weighting Pakistan jurisdictional exposure.
2. Request Bentley's export-control compliance documentation covering its China office as part of contract onboarding.
3. Request current SOC 2 and ISO 27001 certification evidence directly from Bentley prior to finalizing any data-sensitive engagement.
4. Incorporate competitor data-segregation and IP-protection clauses into the supplier agreement given Bentley's broad AEC-sector customer base.
5. Establish a periodic re-screening cadence covering financial health, workforce stability, and governance developments.
6. Verify Bentley's current credit rating status directly with S&P Global to resolve the Ratings Withdrawn ambiguity.
7. Verify sanctions status through direct OFAC/BIS database query.
This report is valid as of the report date. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.
FirstCheck.App is a first-level third party intelligence and risk assessment tool. It is not a substitute for formal investigation, professional review, or expert compliance determinations. Report findings should be evaluated by business managers, subject matter experts, and professionals in the context of the organization's risk tolerance, policies, directives, and approaches. FirstCheck.App reports may be retained as part of the organization's third-party risk management program, including its applicable record-keeping practices.
© 2026 FirstCheck.App. All rights reserved.
This report reflects research conducted across the following databases. Individual databases are identified in Section 4 only when a match or potential match is found.
TIER 1 — Direct Web Research (Conducted on Every Report)
| 1. | OFAC | Specially Designated Nationals (SDN) List |
| 2. | OFAC | Non-SDN Lists (SSI, FSE, NS-MBS, PLC, and related) |
| 3. | BIS | Entity List |
| 4. | BIS | Denied Persons List |
| 5. | BIS | Unverified List |
| 6. | U.S. State Department | Debarred Parties List (ITAR) |
| 7. | OIG | List of Excluded Individuals/Entities (LEIE) |
| 8. | GSA SAM.gov | System for Award Management Exclusions |
| 9. | DEA | Controlled Substances Act Exclusions |
| 10. | CMS | State Medicaid Exclusion Lists (composite) |
| 11. | FDA | Debarment List |
| 12. | SEC | Enforcement Actions Database |
| 13. | CFTC | Enforcement Actions |
| 14. | FinCEN | Enforcement Actions |
| 15. | FBI | Most Wanted |
| 16. | Interpol | Red Notices |
| 17. | UN Security Council | Consolidated Sanctions List |
| 18. | European Union | Consolidated Sanctions List |
| 19. | UK HM Treasury | Sanctions List |
| 20. | World Bank | Debarment List |
| 21. | Asian Development Bank | Sanctions List |
| 22. | OpenSanctions | Consolidated Database |
TIER 2 — Web Research Based (Conducted Where Relevant)
| 1. | FATF | Grey List (Jurisdictions Under Increased Monitoring) |
| 2. | FATF | Black List (High-Risk Jurisdictions — Call for Action) |
| 3. | SECO | Sanctions List (Switzerland) |
| 4. | MAS | Sanctions List (Singapore) |
| 5. | DFAT | Sanctions List (Australia) |
| 6. | Global Affairs Canada | Sanctions List |
| 7. | Japan METI/MOFA | Sanctions and Export Control Lists |
| 8. | France TRESOR | Direction Générale du Trésor Sanctions |
| 9. | Germany BAFA | Export Control and Sanctions Lists |
| 10. | UAE | Sanctions List |
| 11. | Israel | Sanctions List |
| 12. | ICIJ | Offshore Leaks Database (Panama Papers, Pandora Papers) |
| 13. | Transparency International | Corruption Perceptions Index (CPI) |
| 14. | Basel Institute | AML Index |
| 15. | ACAMS | Watchlist (open-source tier) |
| 16. | South Korea MOFAT | Sanctions List |
| 17. | Inter-American Development Bank | Sanctions List |
Tier 1 databases are researched on every report. Tier 2 databases are researched based on entity jurisdiction, industry, and risk profile. This screening is conducted through open-source web research and does not constitute direct real-time database queries. Independent verification against all applicable databases is required before entering into any business relationship or transaction.
Risk ratings reflect a qualitative assessment of the severity, recency, and regulatory relevance of identified issues.
| Report ID: | FC-20260903-173024 |
| Date Generated: | 2026-09-03 17:30:24 UTC |
| FirstCheck.App Version: | v2.12.102 |
| Entity Analyzed: | Bentley |
| Jurisdiction: | US |
| Subject Industry (Verified): | Technology |
| Relationship Type: | Arms-Length Supplier / Service Provider |
| Requester: | FirstCheck.App |
| Requester Industry: | Professional Services |
| Requester Jurisdiction: | United States |
| Reason for Inquiry: | New Entity Check |
This report is valid as of the date generated. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.
The undersigned has reviewed this Third Party Assessment Report and confirms that the risk decision and recommendations above are based on the information provided and professional judgment.
This form should be completed by the designated reviewer and retained with the FirstCheck.App report as part of the organization's third party review records.
📋 To download this form in fillable format: firstcheck.app/review-form.html