2026-09-03 15:11 UTC
Report ID: FC-20260903-151152
FirstCheck.App
Third Party Intelligence and Risk Assessment
Subject Entity
Bentley
Industry: Technology  |  Jurisdiction: US

THIRD PARTY ASSESSMENT REPORT
REQUESTER INFORMATION
FirstCheck.App, Sample Report
Purpose: New Entity Check
Report Generated:2026-09-03 15:11 UTC
Entity Analyzed:Bentley
Jurisdiction:US
Subject Industry (Verified):Technology
Relationship Type:Joint Venture / Strategic & Licensing Partner
Requester:FirstCheck.App
Requester Industry:Manufacturing & Industrials
Requester Jurisdiction:United States
Areas of Special Interest:Anti-Bribery & Corruption, Environmental Risk & Liabilities, Technology, IP & Data Risk, Supply Chain & Logistics Security, Litigation & Legal Exposure, Labor, Human Rights & Anti-Slavery, Reputational & Media Coverage, Financial Stability, Geopolitical & Regulatory Risk, Fraud & Integrity Risk
FIRSTCHECK.APP AND METHODOLOGY
This report was compiled using FirstCheck.App's proprietary Third-Party Risk Assessment Methodology, leveraging structured open-source research across publicly available databases, sanctions lists, corporate registries, and authoritative media sources. All findings are governed by FirstCheck.App Integrity Standards which require source transparency, cross-reference corroboration, verified findings, analytical neutrality, and verification transparency. Full standards are available at FirstCheck.app. Risk indicators in the report use a five-level color system (Red, Orange, Yellow, Green, and Insufficient Data) defined in Appendix B of this report. Conclusions drawn from this report should be validated through further investigation, direct inquiry, and professional judgment before any business or compliance decision is made.
CONFIDENTIALITY
This report is confidential and proprietary. It has been prepared exclusively for the requesting party and their authorized representatives. It may not be shared, reproduced, distributed, or disclosed to any third party without the express written authorization of the requester. Unauthorized use or disclosure may violate applicable law.

TABLE OF CONTENTS

Click on any item to navigate to that section.

Executive Summary
Partnership assessment
1.   Entity Information
2.   Ownership & Structure
3.   Key Personnel
4.   Sanctions & Controls Screening
5.   Regulatory & Legal
6.   Adverse Media
7.   Financial Assessment
8.   Geopolitical Risk
9.   Industry-Specific Risks
10.   Certifications & Accreditations
11.   Conflicts of Interest
12.   Related & Associated Entities
13.   Areas of Special Interest
Risk Indicator Summary
Summary Risk Assessment
Recommended Follow-Up Questions
Sources Consulted
Limitations & Recommended Next Steps
Disclaimer
Appendix A — Sanctions & Controls Databases Screened
Appendix B — Risk Rating Methodology
Third-Party Review Form

Note: This report does not include page numbers as section breaks vary by browser and device.


EXECUTIVE SUMMARY

Bentley Systems, Incorporated is a Delaware-incorporated, Nasdaq-listed (BSY) provider of infrastructure engineering software headquartered in Exton, Pennsylvania, generating over $1 billion in annual revenue across 194 countries with approximately 5,200 employees as of mid-2024. This report evaluates Bentley Systems as a prospective or existing Joint Venture / Strategic and Licensing Partner for a requester in the Manufacturing and Industrials sector. The assessment weighs Bentley's founder-controlled governance, financial profile, geopolitical footprint, and technology-protection practices as they bear on a long-term, shared-exposure partnership arrangement.

• This relationship carries no confirmed sanctions or restricted-party match as of the screening date, but Bentley's unresolved status of temporarily pausing rather than fully exiting Russia operations requires direct, documented verification to avoid inheriting sanctions exposure under evolving OFAC, EU, and UK Russia programs.

• Uncorroborated claims of Bentley offices in Beijing, Hong Kong, and Shanghai and a possible local China joint-venture structure raise deemed-export and technology-diversion risk requiring confirmation before finalizing any shared technology-sharing provisions.

• Siemens AG's dual role as a greater-than-9-percent equity holder and joint-innovation partner, backed by a EUR 100 million program, creates risk that Bentley's technology roadmap may favor a company competing with the requester.

• Bentley's 29-votes-per-share founder-family supervoting structure concentrates strategic and dispute-resolution authority within the Bentley Control Group, materially limiting the requester's negotiating leverage over governance terms in this engagement.

• Unresolved data gaps regarding the CFO, CIO, and CTO roles, combined with uncorroborated reports of indiscriminate 2023-2024 layoffs, elevate key-person and workforce-continuity risk for this long-term partnership.

• Bentley's active 2024 intellectual-property enforcement action in India signals a genuine capability to protect shared technology, partially offsetting the unconfirmed SOC 2 and ISO 27001 certification status relevant to this engagement's data-access requirements.

Risk Summary:

Sanctions Screening: No sanctions or restricted-party matches identified for Bentley Systems or its named executives as of the screening date; one name-similarity hit was investigated and determined unrelated.

Regulatory Risk: None active; historical litigation resolved favorably with one undetermined-status non-practicing-entity patent matter requiring continued monitoring.

Adverse Media: Minor; no material adverse coverage identified in primary or trade media, but uncorroborated employee-sentiment reports of 2023-2024 layoffs warrant monitoring.

Financial Risk: Stable with monitoring items; strong revenue growth and liquidity are offset by an unconfirmed current public credit rating and softening single-source 2026 analyst sentiment.

→ See Section-by-Section Risk Indicator Summary

PARTNERSHIP ASSESSMENT

Partnership View

Bentley Systems presents as a financially strong, technologically capable infrastructure-software leader whose founder-controlled governance and entangled Siemens relationship warrant careful contractual structuring before binding a joint venture or licensing partnership.

What the Partner Brings

• Sustained double-digit ARR growth, reaching $1,405.2 million as of September 30, 2025, with 109-110% net retention indicating durable customer relationships.

• Established global footprint across 194 countries and approximately 5,200 employees, providing broad market access and distribution reach.

• Demonstrated M&A execution capability, including the $911 million Seequent acquisition with clean Hart-Scott-Rodino and New Zealand regulatory clearance.

• Active and successful track record defending and enforcing its core intellectual property, evidenced by the favorable Baystate Technologies (1996) judgment and the 2024 Nakshatech enforcement action.

• Strategic technology alliance with Siemens AG including a EUR 100 million joint innovation program, indicating credible co-development capacity.

• Strong liquidity, evidenced by an $850 million revolving credit facility and a consistent quarterly dividend, with no bankruptcy or going-concern indicators identified.

Partnership Vulnerabilities

• Founder-family supervoting control at 29 votes per Class A share concentrates governance authority, limiting external partner influence over strategic direction.

• Siemens AG's dual role as investor and competitor-adjacent technology partner creates potential divided loyalty in a joint venture touching overlapping industrial-software markets.

• Unconfirmed SOC 2/ISO 27001 certification status and unverified cloud-vendor concentration leave data-security assurances unestablished.

• Unresolved Russia 'pause' status and uncorroborated China footprint claims introduce unresolved sanctions and export-control exposure.

• Uncorroborated reports of indiscriminate 2023-2024 layoffs and unresolved CFO/CIO background gaps raise workforce-stability and key-person continuity questions.

• Absence of a current public credit rating limits independent verification of Bentley's long-term debt-servicing capacity.

Key Uncertainties

• Current Siemens AG ownership percentage and any contractual limitations on Siemens' access to jointly developed technology.

• Bentley's actual current contractual Russia posture and any China local operating or joint-venture structure.

• Current SOC 2 Type II/ISO 27001 certification status and cloud-infrastructure resilience and vendor concentration.

• Status, structure, and liability allocation of the reported Talon Aerolytics acquisition.

• Current board composition and independent-director representation following the July 2024 CEO transition.

• Scale, cause, and resolution status of the 2023-2024 workforce reductions referenced in employee-sentiment platforms.

Trajectory & Alignment

Bentley's trajectory shows continued recurring-revenue growth and expanding AI-enabled product capability, though 2026 analyst sentiment has softened and its acquisitive strategy involving Seequent and the reported Talon Aerolytics transaction continues to add integration and successor-liability complexity. This growth-through-acquisition path can converge with a manufacturing and industrials requester's need for expanding digital-twin and infrastructure-software capability, provided governance and intellectual-property protections are secured contractually rather than assumed from Bentley's public disclosures.

Implication for the Requester

Before proceeding, the requester should secure board representation or veto rights over material strategic decisions, explicit information-barrier provisions addressing the Siemens relationship, documented IP-assignment terms and data-security certifications, a defined exit and buy-out mechanism, and direct verification of Bentley's Russia and China exposure. Absent these protections, the founder-controlled governance structure and unresolved geopolitical and certification gaps warrant a cautious, conditions-precedent approach rather than immediate, unconditional execution.
1. ENTITY INFORMATION

Name: Bentley Systems, Incorporated

Country: United States

Business Type: Publicly traded corporation (Nasdaq: BSY), dual-class share structure, founder/family-influenced governance

Website: www.bentley.com

Industry: Infrastructure engineering software, including architecture-engineering-construction (AEC) design software, industrial digital twin platforms, and asset performance management solutions

Headquarters: Exton, Pennsylvania, United States (685 Stockton Drive, Exton, PA 19341)

Known Locations: Exton, Pennsylvania (global headquarters); Christchurch, New Zealand (headquarters of wholly owned subsidiary Seequent Holdings Limited); Beijing, Hong Kong, and Shanghai, China; India, Indonesia, Malaysia, and Mexico (distribution and technical support presence); and Ireland, cited as the location of Bentley Systems International Ltd., described as an EU/GDPR operations hub. The China, India, Indonesia, Malaysia, Mexico, and Ireland location details derive from a single Tier 4 aggregator compliance sample report and have not been independently corroborated against Bentley's own investor disclosures, state or foreign corporate registries, or other primary sources; these should be treated as leads requiring direct verification rather than confirmed structural findings.

Bentley Systems, Incorporated was originally incorporated in California in 1984 upon its founding and was subsequently reincorporated in Delaware in 1987, where it remains domiciled as a matter of current corporate record per SEC EDGAR filings (Tier 1 source).

The company's Class B common stock trades on Nasdaq under the ticker BSY and is the only class registered under Section 12 of the Exchange Act and publicly traded; each Class B share carries one vote, while the closely held Class A common stock is not publicly traded and carries supervoting rights addressed in Section 2 of this report.

As of the most recent figure identified in company disclosures (mid-2024), Bentley Systems employed approximately 5,200 colleagues and generated annual revenues exceeding $1 billion, with operations and customer relationships spanning 194 countries; this is the most current headcount and revenue-scale figure available and supersedes any earlier company size references.

Bentley Systems is a component of the S&P MidCap 400 index, reflecting its status as an established mid-cap public issuer subject to standard SEC reporting and governance obligations.

Per-location risk observations: the China office locations (Beijing, Hong Kong, Shanghai), if confirmed, warrant elevated jurisdictional risk treatment given export-control and data-localization exposure discussed further in the geopolitical and industry-specific risk sections of this report; the New Zealand location (Seequent) sits within a Tier 1-adjacent, OECD-aligned regulatory environment; and the Ireland location, if confirmed, would fall within a Tier 1/2 EU-regulated jurisdiction subject to GDPR oversight.

RISK INDICATOR: Yellow - Core corporate identity is confirmed through SEC filings, but several international office locations rely solely on an uncorroborated Tier 4 aggregator source and require verification.

2. OWNERSHIP & STRUCTURE

Bentley Systems operates under a dual-class share structure in which Class A common stock carries 29 votes per share, a supervoting ratio that reduces to 11 votes per share only if none of Barry J. Bentley, Gregory S. Bentley, Keith A. Bentley, or Raymond B. Bentley remains an executive officer or director of the company, per SEC EDGAR disclosures (Tier 1 source). Class B common stock, the only publicly traded and listed class, carries one vote per share, meaning public shareholders hold materially disproportionate voting power relative to their economic interest.

SEC prospectus filings define the 'Bentleys' collectively as Barry J. Bentley, Gregory S. Bentley, Keith A. Bentley, Raymond B. Bentley, and Richard P. Bentley, and define the 'Bentley Control Group' as this family group together with certain relatives and permitted transferees acting in concert; this group's aggregate voting power qualifies Bentley Systems as a 'controlled company' under Nasdaq listing rules. This is a lawful, fully disclosed governance structure rather than an adverse finding, but it is a structural characteristic with direct bearing on the joint venture relationship context under evaluation.

For a prospective joint venture or strategic partner, controlled-company status means that ultimate strategic direction, board composition, and dispute-resolution posture rest with a small founding family group irrespective of the breadth of public share ownership. This concentration reduces the practical negotiating leverage available to outside partners seeking governance protections, board representation, or veto rights in joint venture agreements, and it elevates the importance of clearly negotiated contractual dispute-resolution and exit mechanisms rather than reliance on shareholder-level checks.

Siemens AG holds a strategic minority equity position in Bentley Systems that, per Siemens' own investor disclosures (Tier 3, corroborated by multiple Tier 2 trade press sources including ARC Advisory Group, Control Design, and Railway Track & Structures), exceeded 9% of Bentley's common stock following continuous secondary-market investment. The two companies extended a 2016 strategic alliance agreement and increased a joint innovation investment program from an initial EUR 50 million to EUR 100 million, reflecting a deepening technology-development relationship alongside the equity stake.

Siemens' position as simultaneously an equity investor, a joint technology-development partner, and a company with overlapping industrial-software and infrastructure-technology market interests presents a conflict-of-interest consideration directly relevant to the joint venture relationship context. Should the requester compete with Siemens in any relevant vertical, the alliance raises questions regarding information-sharing priorities, technology-transfer sequencing, and whether Bentley's strategic roadmap could be influenced by Siemens' commercial interests in ways not fully visible to other strategic partners.

Bentley Systems' principal operating subsidiary is Seequent Holdings Limited, headquartered in Christchurch, New Zealand, acquired in a transaction valued at approximately $1.05 billion and closed at $911 million in June 2021 following clearance under both the New Zealand Overseas Investment Act and the US Hart-Scott-Rodino Act. Seequent operates as a stand-alone subsidiary with its own chief executive, Graham Grant, reporting into Bentley's Chief Product Officer function, and represents an integrated, low-geopolitical-risk affiliate.

Other named acquisitions include Talon Aerolytics, Inc., reported acquired on December 31, 2025 per a single-source Simply Wall St summary of SEC-derived data that requires corroboration against Bentley's own 8-K filing, and Cohesive, a professional-services affiliate referenced in connection with Maximo-related work in Bentley's Q4 2024 earnings materials. No further detail on the integration structure or liability allocation of Talon Aerolytics was independently confirmed in this research.

No parent company or controlling shareholder was identified above Bentley Systems; the company is the ultimate publicly traded parent within its corporate family, and Siemens AG's minority stake does not constitute control under standard ownership thresholds. Accel-KKR appeared in the research only as a seller-side investor in the Seequent transaction and is not an ongoing Bentley affiliate. For a joint venture counterparty assessment, the combined effect of founder-family supervoting control and a strategically entangled minority investor with competitive overlap should be treated as a compounding governance risk requiring explicit contractual attention rather than two isolated, minor observations.

RISK INDICATOR: Orange - Founder-family supervoting control combined with Siemens' dual investor/technology-partner/competitor relationship constitute significant structural governance and conflict-of-interest concerns material to a joint venture negotiation, though no unlawful conduct is indicated.

3. KEY PERSONNEL

Nicholas H. Cumins has served as Chief Executive Officer of Bentley Systems since July 1, 2024, succeeding longtime CEO Gregory S. Bentley in that role as part of a planned leadership transition disclosed in SEC filings (Tier 1 source). Cumins previously served as Chief Operating Officer from January 2022, with responsibility for global sales, marketing, products, user success, and business operations, and before that as Chief Product Officer from 2020 and general manager of SAP Marketing Cloud from 2018 to 2020; no adverse regulatory history was identified for Cumins individually.

Gregory S. Bentley transitioned to Executive Chair of the Board effective July 2024 after serving as Chief Executive Officer from 2000 to 2024 and as President and Chairman since June 1996. Prior to joining the company in 1991, he founded Devon Systems International, which was sold to SunGard Data Systems in 1987, and he subsequently served as a SunGard director and audit committee member from 1991 to 2005; he holds a B.S. in economics and an M.B.A. from the Wharton School and serves as a trustee of Drexel University. His more than three decades of continuous senior leadership represent a substantial key-person dependency, given that ultimate strategic and voting control remains concentrated in the founding Bentley family under the controlled-company structure described in Section 2.

Keith A. Bentley co-founded the company at its 1984 inception and has served as a director continuously since that date, serving as President from 1984 to 1995 and as Chief Executive Officer from 1984 to 2000 before assuming the role of Chief Technology Officer in 2000, a title he has held in SEC filings since. He holds a B.S. in electrical engineering from the University of Delaware and an M.S. from the University of Florida; no adverse regulatory history was identified.

Werner Andre is named as Chief Financial Officer in multiple 2025 SEC-filed earnings release exhibits (Tier 1 source), but no independent corroboration of his prior professional background, appointment date, or tenure was located in this research, and this is recorded as a data gap requiring direct verification given the financial-stewardship relevance of the CFO role to a joint venture counterparty assessment.

Michael M. Campbell has served as Chief Product Officer since September 2022, with responsibility for product strategy and product development, per Bentley's proxy statement disclosures (Tier 1 source). He previously served as Executive Vice President at PTC Inc., a direct competitor in engineering software, and holds a B.S. in mechanical engineering from Boston University; no adverse regulatory history was identified.

Brock Ballard serves as Chief Revenue Officer, with prior sales leadership roles at Dassault Systemes, Autodesk, and Oce, all of which compete with or adjoin Bentley's core markets, per Bentley's proxy statement disclosures. He holds a B.A. in communication and information sciences from the University of Alabama; his and Campbell's competitor-derived backgrounds are standard industry hiring practice and not themselves adverse findings, but they are relevant to the joint venture context's emphasis on information-handling practices and competitive-intelligence sensitivity in any technology-sharing arrangement.

Julien Moutte is identified in Wikipedia and Craft.co aggregator sources as Chief Technology Officer on the product and engineering side, a title that conflicts with SEC filings identifying Keith A. Bentley as Chief Technology Officer. This discrepancy is flagged as a title conflict likely reflecting organizational evolution over a multi-year period rather than a factual error, and it requires clarification against Bentley's most recent proxy statement or organizational chart before finalizing any joint venture governance mapping.

Ruth Sleeter is reported to have joined as Chief Information Officer in 2025, with prior CIO roles at Axon Enterprise and Sonos, per a single-source GlobalData aggregator record (Tier 4) that has not been independently corroborated; this is recorded as a data gap given the CIO role's direct relevance to the data-security and system-access considerations central to the joint venture relationship context.

David Shaman serves as Chief Legal Officer and Secretary, confirmed through Bentley's SEC 424B4 filing (Tier 1 source) and corroborated by TheOrg aggregator data; no adverse regulatory or litigation history was identified for Shaman individually.

Graham Grant serves as Chief Executive Officer of subsidiary Seequent, having succeeded retiring CEO Shaun Maloney following Bentley's 2021 acquisition of Seequent, per acquisition-related press materials (Tier 2/3 sources); no adverse findings were identified.

Board composition disclosed in 2022-period filings included Gregory Bentley, Keith Bentley, Barry Bentley, and Raymond Bentley from the founding family, together with independent directors Kirk Griswold, Janet Haugen, and Brian Hughes, per a Tier 4 aggregator summary of period disclosures. This composition should be corroborated against Bentley's most current definitive proxy statement, as board membership has likely changed following the July 2024 CEO transition, and confirming current independent-director representation is material to assessing governance balance for a prospective joint venture partner.

Taken together, the executive roster reflects continuity of founder involvement at the board and technology-leadership level alongside a comparatively recent influx of externally recruited functional leaders in sales, product, and information-technology roles. No enforcement action, criminal matter, or civil fraud finding was identified against any named executive in connection with their duties at Bentley Systems; however, the succession-planning implications of Gregory Bentley's and Keith Bentley's long tenures, combined with unresolved data gaps regarding the CFO and CIO and the unresolved CTO title conflict, warrant follow-up verification before the joint venture relationship is finalized.

RISK INDICATOR: Yellow - No adverse regulatory findings were identified against any named executive, but unresolved data gaps in CFO and CIO background verification, an unresolved CTO title conflict across sources, and high key-person dependency tied to founder tenure warrant ongoing monitoring.

4. SANCTIONS & CONTROLS SCREENING

This section reflects screening conducted across various sanctions, controls and watchlist databases. A complete list of these databases is provided in Appendix A. Individual databases are identified in this section only when a match or potential match is found. No listing means no matches for this entity were found.

IMPORTANT DISCLAIMER: This screening is based on open-source web research conducted at the time of report generation. FirstCheck.App does not directly query sanctions databases in real time. Sanctions listings change frequently. The requesting party must conduct independent direct screening against all applicable databases before entering into any business relationship or transaction. Reliance on this report without independent verification does not constitute a defense to sanctions violations.

SCREENING TIMESTAMP: List checks performed on 2026-09-03 14:53:15 UTC.

Screening of Bentley Systems, Incorporated and its named executives across sanctions, export-control, and restricted-party databases identified no confirmed matches indicating sanctions exposure, denied-party designation, debarment, or exclusion status as of the screening date.

One name-only record for "Bentley" tied to a Russia-sanctions-related vessel was identified through an OpenSanctions aggregator search. Upon verification, this record was determined to relate to an unrelated maritime entity bearing no shared address, incorporation date, sector, or personnel with Bentley Systems, Incorporated, and is accordingly documented as a name-similarity finding requiring verification rather than a confirmed sanctions match.

No matches were identified for Bentley or its key executives, including Chief Executive Officer Nicholas H. Cumins, Executive Chair Gregory S. Bentley, Chief Technology Officer Keith A. Bentley, Chief Financial Officer Werner Andre, Chief Product Officer Michael M. Campbell, Chief Revenue Officer Brock Ballard, Chief Legal Officer David Shaman, and Chief Information Officer Ruth Sleeter, across the databases listed in Appendix A.

For the joint venture and strategic partnership context under evaluation, the absence of a confirmed sanctions or restricted-party match at a single point in time should not be treated as a permanent clearance. Bentley Systems has been separately identified by an independent tracker as having paused, rather than exited, its Russia operations, and the entity continues to operate across 194 countries with corresponding exposure to evolving sanctions programs administered by OFAC, the EU, and the UK. Given this operating footprint, periodic re-screening of Bentley Systems, its subsidiaries including Seequent Holdings Limited, and its senior officers throughout the term of any joint venture or licensing relationship is warranted as a standing control rather than a one-time diligence step.

No confirmed beneficial-ownership linkage to a sanctioned party was identified. Siemens AG, which holds a minority equity stake exceeding nine percent in Bentley Systems, carries no sanctions designation and does not approach a controlling ownership threshold that would trigger derivative sanctions exposure for Bentley Systems under applicable ownership-aggregation rules.

RISK INDICATOR: Green - No confirmed sanctions, export-control, or restricted-party matches were identified for Bentley Systems, Incorporated or its named executives across any government list screened as of the screening date.

5. REGULATORY & LEGAL

Bentley Systems, Incorporated is subject primarily to United States federal oversight as a Delaware-incorporated, Pennsylvania-headquartered, Nasdaq-listed issuer. Review of the Securities and Exchange Commission's enforcement and litigation releases identified no enforcement action, restatement, or civil penalty against Bentley Systems itself; the only similarly-named SEC matters located involved unrelated individuals, Robert L. Bentley (2001) and Christopher R. Bentley (2022), with no corporate or personal connection to the subject entity. Review of Department of Justice and SEC Foreign Corrupt Practices Act enforcement records, Federal Trade Commission privacy and competition enforcement records, and Department of Labor, National Labor Relations Board, and Equal Employment Opportunity Commission enforcement records similarly identified no action against Bentley Systems.

The company's own SEC filings disclose two risk factors of direct relevance to a joint venture or strategic-licensing relationship. First, Bentley Systems' Form 10-K acknowledges that regulators may pursue a theory of successor liability for FCPA violations committed by companies or assets it acquires, a standard risk disclosure rather than an admission of wrongdoing, but one that carries specific weight given Bentley's active acquisition strategy, including Seequent Holdings Limited (2021) and Talon Aerolytics, Incorporated (reported December 2025, single-source and requiring corroboration). Second, the company discloses that its software offerings may be subject to United States export controls and economic sanctions laws restricting delivery to certain governments, locations, and persons, and states that its compliance processes cannot guarantee prevention of all violations; no confirmed export-control violation was identified in DOJ, Bureau of Industry and Security, or Treasury records reviewed, and this remains a disclosed forward-looking risk rather than a substantiated finding.

Historical litigation review identified a limited and largely favorable pattern. In Baystate Technologies v. Bentley Systems (D. Mass. 1996), the court entered judgment for Bentley Systems, finding no copyright infringement, no trade secret misappropriation, no Lanham Act violation, no unlawful conversion, no tortious interference, and no unfair trade practices; this matter is resolved and predates the standard ten-year lookback window but remains the most substantive litigation precedent identified for the entity. In 2024, Bentley Systems appeared as plaintiff in Bentley Systems and Anr v. Nakshatech Pvt. Ltd. before an Indian court, enforcing intellectual property rights in its MicroStation design software; this is a positive indicator of the company's willingness and capacity to protect proprietary technology, a factor directly relevant to the requester's own intellectual-property assignment and protection concerns in a licensing structure, though it also confirms that Bentley's technology has been subject to at least one attempted misappropriation.

A separate matter, SoftVault Systems, Inc. v. Bentley Systems Incorporated, named Bentley Systems alongside numerous other large technology companies including Adobe, Oracle, and Samsung in a non-practicing-entity patent assertion; the outcome could not be determined in sources reviewed. This action is assessed as low-specificity, industry-wide non-practicing-entity litigation exposure common across the software sector rather than an entity-specific adverse indicator, though its unresolved status is noted for completeness. No class actions, government investigations, civil investigative demands, consent decrees, injunctions, or arbitration awards were identified against Bentley Systems in the court and regulatory records searched.

On competition and antitrust matters, no Department of Justice Antitrust Division or Federal Trade Commission investigation, and no European Commission competition proceeding, was identified against Bentley Systems. The 2021 Seequent acquisition cleared Hart-Scott-Rodino antitrust review and New Zealand Overseas Investment Act consent without identified complications, a finding corroborated across multiple independent trade-press sources describing the transaction's regulatory clearance conditions. This clearance history is a relevant, though not determinative, positive indicator of the company's capacity to navigate merger-control and competition-law processes, which is pertinent given that formation of a joint venture of sufficient scale with Bentley Systems could itself require notification under Hart-Scott-Rodino or foreign merger-control regimes depending on transaction value and market overlap.

Taken together, the regulatory and legal record shows no confirmed enforcement action, criminal matter, or adverse judgment against Bentley Systems, Incorporated. The rating reflects the combination of resolved historical litigation, an unresolved third-party patent assertion of undetermined status, and standard but non-trivial successor-liability and export-control risk factors that carry elevated relevance specifically because of the requester's proposed joint venture or strategic-licensing relationship, which would create shared exposure to any future acquisition-related liability or export-compliance lapse.

RISK INDICATOR: Yellow - No active enforcement actions were identified against Bentley Systems, but historical litigation, an undetermined-status patent assertion, and standard successor-liability and export-control risk-factor disclosures warrant continued monitoring in a JV context.

6. ADVERSE MEDIA

Searches of international wire services, including Reuters, Bloomberg, the Financial Times, the Wall Street Journal, the Associated Press, and the BBC, identified no material adverse coverage specific to Bentley Systems, Incorporated. Trade and industry press coverage, including Global Construction Review, GIM International, ARC Advisory Group, Control Design, and Railway Track and Structures, was overwhelmingly transactional and neutral-to-positive in tone, concentrated on acquisitions such as Seequent and Talon Aerolytics, the Siemens strategic alliance, and product launches, with no scandal, regulatory criticism, or controversy identified in these Tier 2 sources.

Employee-sentiment platforms, including Glassdoor and Fishbowl, contain multiple reviews describing workforce reductions in 2023 and 2024 as unexpected, with at least one detailed review characterizing certain layoffs as indiscriminate, describing the loss of some higher-performing employees, and raising concerns about the effectiveness of human resources in addressing underperforming or difficult personnel, with an associated effect on employee morale. These are single-source, Tier 4 employee-sentiment claims that have not been corroborated by independent reporting, litigation records, or the company's own restructuring disclosures identified in this research, and are therefore reported as an uncorroborated workforce-sentiment signal rather than a confirmed adverse finding.

This workforce-sentiment signal carries specific relevance to the proposed joint venture and strategic-licensing relationship, independent of its uncorroborated status, because sustained or recurring workforce reductions can affect continuity of the technical and product personnel who would support a long-term partnership, and can compound the key-person dependency risk already inherent in Bentley Systems' founder-controlled governance structure. Corroboration through Bentley Systems' own restructuring-charge disclosures in its Form 10-K footnotes, rather than reliance on anecdotal employee-review commentary, is recommended before this signal is weighted further in the overall risk assessment.

No product recalls, safety alerts, executive personal scandals, environmental, social, or governance activist campaigns, boycotts, or brand-related public controversies were identified against Bentley Systems, Incorporated in the sources reviewed. No adverse media pertaining to bribery, corruption, sanctions evasion, data breach, or discrimination was identified for the subject entity; adverse media results returned for similarly named but unrelated entities, including Bentley Motors Limited, Bentley University, and Bentley Industries, were excluded in accordance with the identity-anchor protocol applied throughout this research.

RISK INDICATOR: Yellow - No material adverse findings were identified in primary or trade media, but uncorroborated employee-sentiment reports of workforce reductions in 2023-2024 warrant monitoring given workforce-stability relevance to the proposed relationship.

7. FINANCIAL ASSESSMENT

Financial data reviewed for Bentley Systems, Incorporated is drawn primarily from the company's own SEC-filed quarterly and annual earnings releases (Tier 1), which show a sustained pattern of double-digit growth through fiscal 2025. Q1 2025 total revenues reached 370.5 million dollars, up 9.7 percent year-over-year (10.9 percent constant currency), with annualized recurring revenue of 1,319.3 million dollars as of March 31, 2025, up from 1,186.5 million dollars a year earlier. By Q3 2025, total revenues had risen to 375.5 million dollars (up 12.0 percent) with ARR of 1,405.2 million dollars as of September 30, 2025, and Q4 2025 total revenues reached 391.6 million dollars, up 11.9 percent, representing the most recent confirmed figures available.

Net retention rates of 109 to 110 percent across 2025 quarters indicate strong existing-customer expansion, a positive indicator of platform stickiness and predictable cash flow that is directly relevant to a prospective joint venture partner's ability to fund co-investment commitments over a multi-year horizon. Operating income margin expanded to 31.1 percent in Q1 2025 versus 27.2 percent a year earlier, though it moderated to 22.5 percent in Q3 2025, reflecting quarter-to-quarter variability in cost structure that should be factored into any joint financial planning. Recurring revenue reached 91 percent of total revenue as of full-year 2024 per CFO commentary, indicating a business model with substantial revenue visibility, a favorable characteristic for long-duration partnership commitments.

Bentley Systems maintains substantial available liquidity, having disclosed an undrawn revolving credit facility of up to 850 million dollars in the context of the 2021 Seequent acquisition, alongside an earlier-disclosed 500 million dollar revolving facility with a 50 million dollar letter-of-credit sub-facility in its FY2020 10-K. No bankruptcy filing, going-concern opinion, negative equity position, or judgment lien was identified against the entity in searches performed. An active quarterly dividend of 0.06 dollars per share was declared in Q2 2024, payable to both Class A and Class B stockholders, indicating positive free cash flow generation and a degree of capital-return discipline consistent with a financially stable counterparty.

A material data gap was identified regarding current credit ratings: a S&P Global Ratings notice titled Bentley Systems Inc. Ratings Withdrawn dates to 2012 and appears to relate to a legacy bank-facility rating predating the company's 2020 initial public offering, and no current public long-term issuer rating from Moody's, S&P, or Fitch was identified in this research. This absence of an independently verified current credit rating is assessed as Insufficient Data on that specific point rather than a negative finding, and should be corroborated directly with Bentley Systems' treasury function before finalizing any JV financial-exposure assessment. Separately, single-source analyst commentary (Simply Wall St, Tier 4, uncorroborated) indicates second-quarter 2026 revenue of 410.7 million dollars and net income of 78.6 million dollars, alongside a reported trend of analysts trimming fair-value estimates amid a softer organic ARR outlook and more cautious 2026 profitability expectations, a forward-looking sentiment shift that, while not itself an adverse finding, is a monitoring item relevant to the durability of Bentley's financial commitments over the life of a long-term joint venture.

RISK INDICATOR: Yellow - Core financial metrics show sustained double-digit revenue and ARR growth with strong liquidity, but an undetermined current credit rating and a documented softening in 2026 analyst sentiment warrant ongoing monitoring for a JV partner's capacity to sustain shared financial obligations.

8. GEOPOLITICAL RISK

Bentley Systems, Incorporated is domiciled in Delaware and headquartered in Exton, Pennsylvania, placing its primary corporate jurisdiction within a stable, rule-of-law-based regulatory environment with robust judicial enforcement, transparent securities regulation, and low inherent political risk. However, the company's own disclosures indicate it generates revenue across 194 countries as of mid-2024, meaning its geopolitical risk profile cannot be assessed solely by reference to its US domicile; a substantial share of its commercial exposure arises from operations, resellers, and end-customers in jurisdictions with materially different sanctions, export-control, and rule-of-law characteristics.

Jurisdictional Environment: Tier 1 - The primary jurisdiction (United States, Delaware/Pennsylvania) is assessed as Tier 1 given its stable institutional framework, mature securities and corporate law regime, and low direct sovereign risk, though this tier assignment applies only to Bentley's corporate domicile and does not extend to the elevated-risk foreign markets discussed below.

The most significant geopolitical finding identified is Bentley Systems' listing on the Yale Chief Executive Leadership Institute-affiliated #LeaveRussia tracker (leave-russia.org, using KSE Institute methodology) in the category of companies "Temporarily Pausing Operations in Russia" - defined by the tracker as curtailing operations while keeping return options open, rather than fully exiting the market. This is a Tier 2 NGO/academic-affiliated source with a transparent, publicly documented methodology, and the finding was not independently corroborated against Bentley's own investor disclosures within this research; the precise current operational and contractual status of Bentley's Russia-linked business (including any residual licensing, distributor, or support relationships) remains undetermined as of the most recent data reviewed.

For a prospective joint venture or strategic licensing partner, an unresolved Russia posture carries second-order sanctions-exposure risk that extends beyond Bentley itself: OFAC, EU, and UK Russia sanctions programs have expanded materially since 2022, and any continuing software licensing, maintenance, or data-services relationship touching Russian end-users could create shared reputational and, in certain structuring scenarios, shared compliance exposure for a JV partner whose brand or technology is co-marketed with Bentley's. This risk is compounded by the software industry's exposure to deemed-export and re-export control issues, given that engineering and infrastructure-design software can carry dual-use classification sensitivities under the Export Administration Regulations; the requester should treat verification of Bentley's current, contractual (not merely reputational) Russia exit or pause status as a pre-condition to JV execution rather than a post-closing monitoring item.

China exposure presents a second material geopolitical consideration. Bentley's own SEC 10-K risk factors acknowledge that operations outside the United States are subject to trade protection measures, sanctions, quotas, embargoes, import and export licensing requirements, and increasingly stringent data-privacy regimes including the Cybersecurity Law and Personal Information Protection Law of the People's Republic of China; separately, single-source aggregator claims (not independently corroborated by Tier 1 or Tier 2 sources in this research) suggest Bentley maintains offices in Beijing, Hong Kong, and Shanghai and may pursue a localized China go-to-market or joint-venture structure. If confirmed, a Bentley-China operating or joint-venture arrangement would raise deemed-export and technology-transfer considerations directly relevant to the requester's own JV due diligence framework, particularly the risk that proprietary technology, source code, or design data shared with Bentley under a strategic partnership could migrate into a China-based development, hosting, or joint-venture channel subject to Chinese state data-access authority.

Bentley's FY2025 10-K further discloses that recent and potential US tariffs, particularly those targeting China, and the possibility of a broader global trade war could increase costs and harm the business, with an attendant risk of retaliatory tariffs from other governments. While Bentley is primarily a software licensor with limited direct hardware trade exposure, its Seequent subsidiary and any hardware-adjacent geoscience tooling could carry incremental tariff-cost exposure that flows through to shared JV cost structures or pricing commitments; this is a disclosed forward-looking risk factor rather than a confirmed adverse event, but it is relevant to financial-stability and shared-obligation planning in a JV context given the cost volatility it implies.

Bentley's New Zealand subsidiary, Seequent Holdings Limited, operates in a Tier 1-adjacent, OECD-aligned jurisdiction with low sanctions and expropriation risk; the acquisition cleared New Zealand's Overseas Investment Act consent process and Hart-Scott-Rodino antitrust review in the United States without identified complications, indicating an orderly, well-regulated integration. A separately claimed Irish entity, Bentley Systems International Ltd., described in single-source aggregator material as a GDPR/EU compliance hub, would similarly sit within a Tier 1/2 EU-regulated environment if confirmed, though this location claim was not independently corroborated in this research and should be verified directly against Bentley's own corporate registry filings or investor disclosures.

No expropriation, nationalization, sovereign-interference, or state-ownership influence was identified with respect to Bentley Systems itself; the company is founder-controlled under a dual-class share structure (see Section 2) rather than state-influenced, which removes one category of geopolitical risk common to entities with government or state-linked shareholders. No presence in comprehensively OFAC-sanctioned jurisdictions (Iran, North Korea, Cuba, Syria) was identified in the sources reviewed, though the breadth of Bentley's 194-country commercial footprint means that layered, jurisdiction-by-jurisdiction sanctions and export-control screening across resellers and end-customers could not be exhaustively verified within the scope of this research and should be treated as an open due-diligence item rather than a confirmed clean result.

In synthesis, the geopolitical risk profile most relevant to the joint venture and strategic-partnership context is not a confirmed sanctions violation or enforcement action, but rather a set of unresolved, evolving exposures - the Russia operational pause and the China export-control and data-localization risk factors chief among them - that could crystallize into shared sanctions, reputational, or technology-transfer liability for the requester if not independently verified before execution. Given the pace at which Russia- and China-related sanctions and export-control regimes have evolved since 2022, the requester should treat Bentley's current Russia posture and any China joint-venture or data-hosting arrangement as items requiring direct, documented confirmation from Bentley (rather than reliance on NGO trackers or aggregator claims) as a condition precedent to any binding JV or licensing commitment.

RISK INDICATOR: Orange - An unresolved Yale/KSE-tracked Russia operations pause combined with disclosed China export-control, data-localization, and tariff exposure constitute elevated geopolitical risk factors requiring direct verification before JV execution.

9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY)

a) EXPORT CONTROLS

No confirmed presence on the BIS Entity List and no active or historical enforcement action by the Department of Commerce or the Bureau of Industry and Security was identified against Bentley Systems, Incorporated in searches performed. Bentley's own SEC Form 10-K (FY2025) discloses standard risk-factor language acknowledging that its software offerings, distributed across 194 countries, are subject to US export controls and economic-sanctions laws restricting delivery to certain locations, governments, and persons, and states that while screening processes exist, the company cannot guarantee they will prevent all violations.

Given the joint-venture relationship context's specific concern with deemed-export risk and unauthorized technology transfer, two disclosed findings elevate monitoring priority rather than confirming a violation. Bentley Systems is listed by the Yale-affiliated #LeaveRussia tracker as temporarily pausing rather than fully withdrawing from Russia operations, a status that remains active and undetermined in precise current form, and the company's 10-K separately discloses China-related data-localization and export-control exposure under the Cybersecurity Law of the People's Republic of China. Neither finding constitutes a confirmed export-control breach, but the unresolved Russia posture and the software's use in engineering environments that may involve controlled technical data warrant direct verification of Bentley's current country-specific operational status and export-compliance program before any technology-sharing arrangement is finalized.

RISK INDICATOR: Yellow - No confirmed export-control violation was identified, but Bentley's unresolved Russia operational status and disclosed China export/data-localization exposure warrant direct verification before any JV technology-sharing arrangement.

b) SANCTIONS SCREENING

Systematic review of the OFAC SDN List, the BIS Entity List, the EU consolidated sanctions list, the UK HM Treasury sanctions list, and the UN Security Council consolidated sanctions list identified no confirmed match for Bentley Systems, Incorporated, consistent with the detailed findings presented in Section 4. A single OpenSanctions aggregator hit involving a Russia-sanctioned vessel bearing the name Bentley was investigated and determined to be a false positive, with no shared address, incorporation date, sector, or personnel connecting it to the subject entity.

No evidence was identified of beneficial ownership by a sanctioned party under the 50-percent-rule test. Siemens AG's minority equity position, disclosed at in excess of 9 percent as of the most recent confirmed disclosure, falls well below any control threshold, and Siemens itself carries no sanctions designation under any list reviewed. This supports a favorable baseline sanctions posture for JV purposes, though the unresolved Russia-pause status identified in subsection (a) should be independently reconciled against current sanctions-program requirements before partnership execution.

RISK INDICATOR: Green - No confirmed sanctions or restricted-party matches were identified for Bentley Systems across the government lists screened.

c) DATA PRIVACY

No GDPR enforcement action, FTC Section 5 privacy-enforcement action, or US state attorney general privacy action was identified against Bentley Systems, Incorporated in searches performed. No disclosed data breach involving Bentley Systems' own systems or customer data was identified; breach-related search results referencing the name Bentley were traced to Bentley University's separate third-party Blackbaud incident and were excluded as unrelated under the identity-anchor protocol.

Bentley's own 10-K risk factors acknowledge increasing regulatory complexity arising from GDPR, China's Personal Information Protection Law, and emerging artificial-intelligence-specific data regulation as compliance-cost and operational risks. Given the joint-venture relationship context's heightened sensitivity to a partner's data-handling practices where deep access to a requester's proprietary data, customer information, and strategic plans would be involved, the absence of any confirmed enforcement action is a positive indicator, but the inability to independently confirm Bentley's current SOC 2 Type II or ISO 27001 certification status, as detailed in Section 10, leaves a material verification gap regarding the technical adequacy of its data-protection controls.

RISK INDICATOR: Yellow - No privacy enforcement action or breach was identified, but the unconfirmed data-security certification status represents a monitoring item given the JV context's data-access sensitivity.

d) CFIUS/FOREIGN INVESTMENT

Bentley Systems is a US-domiciled entity and was not identified as the target of any CFIUS review in searches performed; CFIUS jurisdiction attaches to foreign acquisitions of US businesses and is accordingly not directly applicable to Bentley Systems' own corporate structure. The 2021 acquisition of Seequent Holdings Limited, in which Bentley was the acquirer of a New Zealand-headquartered target, triggered New Zealand's own inbound-investment consent regime under the Overseas Investment Act rather than CFIUS, since the direction of foreign investment ran outward from Bentley rather than inward toward it.

No CFIUS filings, mitigation agreements, or foreign-ownership-control-and-influence determinations involving Bentley Systems as a reviewed party were identified in this research. This subsection is assessed as not applicable to the subject entity's current structure, though the requester should note that any future foreign strategic investment into Bentley itself, or a restructuring involving foreign control, would reintroduce CFIUS considerations relevant to the JV relationship.

e) IP & TRADE SECRETS

Historical litigation review reflects a favorable pattern for Bentley Systems as an intellectual-property holder. In Baystate Technologies v. Bentley Systems (D. Mass. 1996), the court found no copyright infringement, no trade-secret misappropriation, no Lanham Act violation, and no unfair-trade-practices violation, entering judgment in Bentley's favor. More recently, in Bentley Systems and Anr v. Nakshatech Pvt. Ltd. (India, 2024), Bentley appeared as the enforcing plaintiff protecting its MicroStation design software from alleged infringement, indicating an active and current practice of defending its core proprietary technology.

Bentley was also named, alongside numerous unrelated major technology companies including Adobe, Oracle, and Samsung, in a non-practicing-entity patent assertion action, SoftVault Systems, Inc. v. Bentley Systems Incorporated, whose outcome remains undetermined in sources reviewed; this is assessed as low-specificity, industry-wide litigation exposure common across the software sector rather than an entity-specific adverse indicator. For JV purposes, this litigation history is a moderately favorable indicator of institutional discipline in protecting proprietary technology, relevant to confidence in IP-ownership and assignment provisions within any partnership structure, though the certification gap noted in subsection (f) means the technical robustness of Bentley's IP-protection infrastructure has not been independently verified.

RISK INDICATOR: Green - No trade-secret misappropriation or IP wrongdoing by Bentley Systems was identified, and the company's litigation history as an IP holder is favorable.

f) CYBERSECURITY

No confirmed data breach, ransomware incident, or CISA advisory specific to Bentley Systems, Incorporated was identified in searches performed. Breach-related results referencing the name Bentley were traced to unrelated entities, including Bentley University's Blackbaud-linked incident and a separate small company reported as a ransomware victim under the name Bentley Industries, both of which were excluded under the identity-anchor protocol.

No authoritative public source confirmed Bentley Systems' current SOC 2 Type II, ISO 27001, or comparable cybersecurity-management certification status; searches returned only generic explanatory material about the certifications themselves rather than entity-specific confirmation. Given the joint-venture relationship context's explicit emphasis on a partner's cybersecurity posture where deep access to shared systems and proprietary data would be involved, this represents a material visibility gap rather than a confirmed weakness, and should be closed through a direct request for current audit reports and penetration-testing summaries before any system-integration commitments are made.

RISK INDICATOR: Insufficient Data - No cybersecurity incident was identified, but Bentley's current certification and independent audit status could not be confirmed from public sources.

g) GOVERNMENT CONTRACTS

No FedRAMP authorization, CMMC certification, or federal suspension/debarment record was identified for Bentley Systems in searches of SAM.gov and related federal contracting databases. Bentley's core commercial market is private and public infrastructure-engineering software broadly rather than defense-specific government contracting, so the absence of these sector-specific certifications is consistent with its business model rather than indicative of a gap.

No history of contract-performance disputes, false-claims allegations, or government-contract termination-for-default was identified against the company in this research. For JV purposes, this finding provides no basis for flow-down federal-contracting compliance concern under the company's current business scope, though the requester should independently confirm the status of these certifications if any prospective joint venture activity would involve US federal government end-use customers.

RISK INDICATOR: Green - No adverse government-contracting findings were identified, consistent with the company's non-defense commercial focus.

h) AI/EMERGING TECH

No AI-ethics controversy, algorithmic-bias finding, facial-recognition controversy, or regulatory action concerning artificial-intelligence deployment was identified against Bentley Systems in searches performed. The company's 10-K disclosures reference AI-related regulatory complexity as a forward-looking risk factor consistent with broad industry trends, rather than describing any specific incident or enforcement matter.

Bentley's product suite has increasingly incorporated AI-driven design and analytics capabilities across its infrastructure-engineering offerings, and no litigation, regulatory inquiry, or adverse-media finding concerning the deployment of these capabilities was identified. This is assessed as a clean record on the evidence reviewed, though the fast-evolving nature of AI regulation globally, including emerging obligations under frameworks such as the EU AI Act, means this area warrants ongoing monitoring rather than being treated as permanently settled.

RISK INDICATOR: Green - No adverse AI-related controversy, litigation, or enforcement action was identified against Bentley Systems.

i) COMPETITION & PLATFORM REGULATION

No DOJ Antitrust Division investigation, FTC competition-enforcement matter, or European Commission competition proceeding was identified against Bentley Systems, Incorporated in searches performed. The 2021 acquisition of Seequent Holdings Limited cleared Hart-Scott-Rodino antitrust review without identified complications, a finding corroborated consistently across multiple independent trade-press sources reporting the transaction's regulatory-clearance condition.

Bentley is not designated a gatekeeper under the EU Digital Markets Act, nor is it subject to any comparable platform-regulation designation identified in this research. Given the joint-venture relationship context's specific concern with market concentration and competitor-collaboration risk, the presence of Siemens AG as both a greater-than-9-percent equity holder and a joint-technology-development partner in overlapping industrial-software and digital-twin markets is not itself an antitrust violation, but represents a structural relationship the requester should evaluate for information-sharing and market-concentration implications if the requester operates in a vertical where Siemens is also active.

RISK INDICATOR: Green - No antitrust or competition-law enforcement action was identified, though the Siemens equity and technology relationship warrants disclosure review for market-concentration implications.

10. CERTIFICATIONS & ACCREDITATIONS

a) QUALITY & MANAGEMENT SYSTEMS

Searches conducted against ISO certification body registries, accreditation-body public databases, and Bentley Systems' own investor and corporate disclosures did not identify a confirmed ISO 9001 (quality management) or ISO 14001 (environmental management) certification for Bentley Systems, Incorporated. No certificate number, accreditation body listing, or company statement affirmatively confirming or denying current certification under either standard was located in this research pass.

Bentley Systems operates as a global enterprise engineering-software provider rather than a physical manufacturer, so the absence of a confirmed ISO 9001/14001 record is not inherently unusual for the sector and should not be read as a negative indicator on its own. It does, however, leave a residual documentation gap that a prospective joint venture partner would ordinarily expect to close through direct request for current certificates prior to executing a strategic partnership involving shared operational standards.

b) SECURITY & DATA PROTECTION CERTIFICATIONS

No SOC 2 Type II report, ISO 27001 certification, or PCI-DSS attestation could be confirmed for Bentley Systems, Incorporated through public searches. A single third-party product reference (OpenLM licensing-tool documentation) mentioned integration compatibility with Bentley software but did not confirm or reference Bentley's own security-certification status, and no authoritative primary source was identified either affirming or contradicting current certification.

This gap is the most consequential of the certification findings given the joint-venture relationship context, which anticipates the partner having deep access to the requester's systems, proprietary engineering data, and strategic plans. Absent independent confirmation of SOC 2 or ISO 27001 status, the requester cannot rely on public information to assess Bentley's data-security control environment and should treat direct production of current audit reports and certification scope statements as a precondition to any data-sharing arrangement.

c) INDUSTRY-SPECIFIC ACCREDITATIONS

No Better Business Bureau accreditation or rating record was identified for Bentley Systems, Incorporated in this research. Independent confirmation of membership in relevant industry bodies such as buildingSMART International, the Open Geospatial Consortium, or comparable architecture-engineering-construction software standards organizations could not be corroborated through Tier 1 or Tier 2 sources, notwithstanding that such memberships are commonly claimed by vendors in this space.

The absence of independently verified accreditation-body records does not indicate an adverse finding, but it constrains the ability to benchmark Bentley's standing against sector peers through public documentation alone. This should be treated as an open item for direct diligence request rather than a confirmed deficiency, consistent with the broader visibility limitations noted across this section.

d) REGULATORY LICENSES & AUTHORIZATIONS

No FedRAMP authorization or Cybersecurity Maturity Model Certification (CMMC) credential was identified for Bentley Systems in searches of federal contracting-readiness sources, consistent with the company's core commercial focus on private and public infrastructure-engineering software rather than defense-specific government contracting requiring those credentials by default. No PCI-DSS attestation was located, which is relevant primarily if Bentley directly processes payment card data in its subscription billing operations rather than through a third-party payment processor.

These findings are assessed as neutral rather than adverse, since the credentials in question are not baseline requirements for Bentley's disclosed business model. To the extent any joint venture activity would involve US federal government end-customers or payment-card data flows through Bentley-controlled infrastructure, the requester should request specific confirmation of the applicable authorization or attestation before scoping those activities into the partnership.

e) CERTIFICATION CURRENCY

Because no baseline certification status could be affirmatively confirmed for ISO 9001, ISO 14001, ISO 27001, SOC 2, PCI-DSS, CMMC, FedRAMP, or HITRUST, the currency of any such certification (that is, whether a certificate is active, lapsed, suspended, or expired) cannot be assessed from public sources. This is a structural visibility limitation rather than an identified negative finding, reflecting the fact that most certification and audit records of this type are not published in searchable public registries.

Resolution of this gap requires a direct documentary request to Bentley Systems for current certificates, audit report cover letters, and scope statements as part of onboarding due diligence for the proposed joint venture. Until such documentation is obtained and reviewed, the requester should treat Bentley's formal certification posture as unverified rather than assume either compliance or non-compliance.

RISK INDICATOR: Insufficient Data - Public sources did not confirm current certification status for Bentley Systems across quality management, security, or industry-specific accreditation categories, and this reflects a visibility limitation rather than an identified adverse issue.

11. CONFLICTS OF INTEREST

Bentley Systems operates as a Nasdaq-recognized 'controlled company,' with Class A common stock carrying 29 votes per share (reduced to 11 votes per share only if none of the named Bentley family members remains an executive officer or director) held by the collective 'Bentley Control Group' comprising Barry J. Bentley, Gregory S. Bentley, Keith A. Bentley, Raymond P. Bentley, and Richard P. Bentley and their permitted transferees. Multiple members of this family group have simultaneously held founder, executive, and director roles across the company's history, including Gregory S. Bentley's 24-year tenure as CEO before his 2024 transition to Executive Chair and Keith A. Bentley's continuous service as a director since the company's 1984 founding and as CTO since 2000. This concentration of voting control and management authority within a single family group is a disclosed and lawful governance structure, not an adverse finding, but it constitutes a material structural conflict-of-interest consideration for a prospective joint venture partner, since ultimate strategic decision-making authority rests with a small, closely aligned group regardless of the interests of public Class B shareholders or, by extension, of a strategic partner negotiating governance and dispute-resolution terms.

Siemens AG holds a strategic equity position in Bentley Systems exceeding 9 percent as of the last confirmed disclosure, and the two companies operate a joint innovation investment program that was expanded from an initial 50 million euros to 100 million euros under a strategic alliance originally established in 2016. Siemens is simultaneously an equity investor, a joint-technology-development partner in digital-twin and infrastructure-technology integration, and a company with its own overlapping footprint in industrial and infrastructure software markets that may compete with the requester or with other stakeholders in a proposed joint venture. This dual investor-and-competitor-adjacent role creates a structural conflict-of-interest exposure that the requester should specifically address in any information-sharing, technology-access, or exclusivity provisions of a joint venture agreement, since Bentley's strategic alignment with Siemens could influence prioritization of technology roadmaps, data access, or competitive positioning in ways not fully visible to an external partner.

Several senior Bentley executives, including Chief Revenue Officer Brock Ballard (previously a sales leader at Dassault Systemes and a director of sales at Autodesk) and Chief Product Officer Michael M. Campbell (previously an executive vice president at PTC Inc.), held senior commercial roles at direct Bentley competitors before joining the company. This is a routine and common hiring pattern in the enterprise software industry and does not itself constitute an adverse finding, but it is relevant context for the requester's assessment of Bentley's internal information-handling practices and the potential for residual competitive-intelligence sensitivities in personnel who move between competing platforms. No undisclosed beneficial ownership arrangement, self-dealing transaction, or related-party transaction outside the disclosed family-control and Siemens-alliance structures was identified in SEC filings or other sources reviewed in this research.

Taken together, these findings do not establish misconduct but do establish a governance and commercial-relationship profile that the requester should weigh carefully in structuring joint venture voting rights, information barriers, and dispute-resolution mechanisms. The combination of concentrated family control and a strategically entangled minority investor with market overlap represents the type of second-order conflict risk that a joint venture due diligence process is specifically designed to surface, even where no single element rises to the level of a confirmed violation.

RISK INDICATOR: Yellow - Structural governance concentration and a strategic investor's dual commercial role represent disclosed, lawful characteristics requiring ongoing monitoring rather than confirmed misconduct.

12. RELATED & ASSOCIATED ENTITIES

No parent company or controlling holding entity sits above Bentley Systems, Incorporated; the company is the ultimate public parent of its corporate group, with ultimate voting control resting with the Bentley Control Group described in Section 11 rather than with any external corporate parent. This structural independence simplifies certain aspects of counterparty due diligence, since there is no need to screen an upstream parent for sanctions or governance risk, but it also means that the founder-family control group functions as the practical equivalent of a controlling parent for governance purposes.

Siemens AG, headquartered in Germany and listed on the Frankfurt Stock Exchange, is Bentley's most significant outside shareholder, holding a stake exceeding 9 percent as of the last confirmed disclosure identified in this research (2018); the current percentage has not been independently re-verified against Bentley's most recent proxy statement or Schedule 13D/13G filings and should be confirmed directly. As a German, EU-regulated, Tier 1 jurisdiction entity, Siemens itself carries no sanctions designation or adverse regulatory history identified in this research, but its dual role as investor and joint-technology-development partner (see Section 11) means the relationship carries commercial-alignment risk rather than jurisdictional or sanctions risk.

Seequent Holdings Limited, headquartered in Christchurch, New Zealand, has operated as a wholly owned Bentley subsidiary since the transaction closed in June 2021 at a cash consideration of 911 million dollars, following clearance under New Zealand's Overseas Investment Act and Hart-Scott-Rodino antitrust review in the United States. New Zealand is assessed as a Tier 1-adjacent, OECD-aligned jurisdiction with low sanctions and geopolitical risk, and Seequent's integration as a stand-alone subsidiary reporting to Bentley's Chief Product Officer indicates an operationally settled acquisition rather than an unresolved integration risk; because Seequent's geoscience and mining-sector software may involve sensitive subsurface and resource data, any joint venture data-sharing arrangement touching Seequent's product lines should confirm applicable export-control and data-sovereignty treatment specific to that subsidiary.

Talon Aerolytics, Inc. is referenced in a single-source aggregator summary (Simply Wall St, citing SEC-sourced data) as having been acquired by Bentley Systems effective December 31, 2025; this acquisition has not been independently corroborated in this research against Bentley's own 8-K filings or investor disclosures and should be treated as an unverified lead rather than a confirmed transaction. The entity's name suggests a possible aerial-data or drone-analytics business line, which, if confirmed, could introduce dual-use technology and export-control considerations distinct from Bentley's traditional infrastructure-software portfolio; the requester should request direct confirmation of this transaction's existence, structure, and jurisdiction before relying on it in any partnership scoping.

Accel-KKR was identified as a private equity investor on the selling side of the Seequent transaction and is not an ongoing affiliate, subsidiary, or shareholder of Bentley Systems; it is noted here for completeness only and carries no current relationship risk. The Bentley family and associated family trusts hold Class A supervoting shares as disclosed in SEC prospectus filings; these are ownership vehicles rather than operating commercial entities, and their significance lies in reinforcing the governance-concentration analysis set out in Sections 2 and 11 rather than in presenting any independent jurisdictional or operational risk.

No other subsidiaries, joint ventures, or minority-investment relationships were identified in this research beyond those listed above. The overall related-entity profile is assessed as low in confirmed adverse risk, but the unresolved verification items concerning Talon Aerolytics and current Siemens ownership percentage represent concrete monitoring triggers that should be closed out before the requester finalizes any joint venture agreement with Bentley Systems.

RISK INDICATOR: Yellow - No adverse findings were identified for any named related entity, but unresolved single-source claims regarding Bentley's most recent acquisition and current Siemens ownership percentage warrant follow-up verification before JV execution.

13. AREAS OF SPECIAL INTEREST

13a) Financial Stability

Bentley Systems' most recently reported quarterly results, for the fourth quarter of fiscal year 2025, show total revenues of $391.6 million, an increase of 11.9 percent year-over-year (9.7 percent in constant currency), with subscription revenues of $356.6 million, up 13.0 percent, continuing a multi-year trend of double-digit top-line growth driven by recurring subscription revenue now representing over 90 percent of total revenue. The most recently disclosed annual recurring revenue figure, $1,405.2 million as of September 30, 2025 (up from $1,270.7 million a year earlier, a 10.5 percent constant-currency growth rate), together with a net retention rate of 109 percent reported for the same quarter, indicates a stable and expanding subscription base and low customer-attrition risk, both favorable indicators for a prospective joint venture or strategic partner expected to co-fund or share in long-term commercial obligations. Operating income margin also expanded across the periods reviewed, reaching 22.5 percent in Q3 2025 versus 20.5 percent in the prior-year quarter, consistent with improving operating leverage as the subscription mix has grown.

A single-source, uncorroborated Tier 4 analyst summary (Simply Wall St) referencing results characterized as second-quarter fiscal 2026 reports EPS of $0.25 (up from $0.22 a year earlier), revenue of $410.7 million (up 13 percent), net income of $78.6 million (up 12 percent), and a profit margin of 19 percent; the same source notes that sell-side analysts have trimmed fair-value estimates and adopted a more cautious, in some cases neutral, stance amid a softer organic ARR growth outlook for 2026. This figure and characterization could not be independently corroborated against a Tier 1 SEC filing within this research pass and should be treated as a directional signal rather than a confirmed financial statement; it is nonetheless flagged because it represents the most recent forward-looking sentiment identified and marks a discernible, if modest, softening in analyst confidence relative to the strong historical growth trajectory described above. This shift in sentiment is a relevant monitoring trigger for a joint-venture counterparty assessment, given that any moderation in Bentley's organic growth could affect its capacity to fund shared investment commitments over a multi-year partnership horizon.

Liquidity indicators remain strong based on Tier 1 SEC disclosures: the FY2020 10-K disclosed a revolving credit facility with maximum borrowing capacity of $500,000,000 plus a $50,000,000 letter-of-credit sub-facility and a since-repaid $125,000,000 secured term loan, while company disclosures tied to the 2021 Seequent acquisition referenced an undrawn revolving credit facility of up to $850 million available to fund that transaction, indicating the facility was subsequently expanded and that Bentley retained substantial unused borrowing capacity at that time. No bankruptcy filing, receivership, going-concern qualification, negative equity position, tax lien, UCC lien, or judgment lien was identified against Bentley Systems, Incorporated in the sources searched. The company also maintains an active capital-return program, having declared a $0.06 per share quarterly dividend in Q2 2024 payable to both Class A and Class B stockholders, which is consistent with sustained positive free cash flow generation and capital-allocation discipline.

No current public long-term issuer credit rating from Moody's, S&P Global Ratings, or Fitch was identified for Bentley Systems, Incorporated in this research; a 2012-dated S&P Global Ratings notice titled 'Bentley Systems Inc. Ratings Withdrawn' was located but appears to relate to a historical, likely bank-facility-linked rating action predating the company's 2020 initial public offering, and its relevance to the entity's current capital structure is undetermined. This represents a genuine data gap on the entity's current, independently rated creditworthiness rather than a confirmed absence of a rating, and it should be closed through direct inquiry with Bentley or a targeted NRSRO database check before finalizing any joint-venture financial-exposure assessment. Taken together, the entity displays strong, growing recurring revenue, expanding margins, substantial undrawn credit capacity, and no adverse solvency indicators, offset by a recent, still-developing softening in forward analyst sentiment for fiscal 2026 and the absence of a confirmed current public credit rating, warranting continued monitoring rather than escalation.

RISK INDICATOR: Yellow - Financial performance and liquidity indicators are strong with no adverse solvency findings, but a recently emerging, single-source-flagged softening in forward analyst sentiment for 2026 and the absence of a confirmed current public credit rating warrant continued monitoring.

13b) Litigation & Legal Exposure

A ten-year-plus lookback of federal and state court records, PACER/CourtListener searches, and SEC litigation releases identified no class actions, no government investigations or civil investigative demands, no consent decrees or injunctions, and no arbitration awards against Bentley Systems, Incorporated. The most significant historical civil matter identified is Baystate Technologies v. Bentley Systems (D. Mass. 1996), in which the court entered judgment for Bentley on claims of copyright infringement, trade secret misappropriation, Lanham Act violations, unlawful conversion, tortious interference with a business relationship, and unfair trade practices. This matter, while outside the standard ten-year window, is the sole substantive litigation precedent of record and resolved entirely in Bentley's favor, indicating a historically clean defensive litigation record on core intellectual-property claims relevant to a technology-licensing partner.

More recent litigation activity shows Bentley Systems in an IP-enforcement rather than IP-defense posture. In Bentley Systems and Anr v. Nakshatech Pvt. Ltd. (Indian Kanoon court record, 2024), Bentley appears as plaintiff enforcing rights in its MicroStation design-modeling software against an alleged infringer, a matter that remains active as of the most recent record reviewed. This litigation posture is a favorable indicator of the company's willingness and capability to protect proprietary technology, a factor directly relevant to the joint venture context's emphasis on IP ownership, protection, and assignment provisions, though it also confirms that Bentley's technology has been subject to at least one attempted misappropriation in an operating market.

A separate matter, SoftVault Systems, Inc. v. Bentley Systems Incorporated, names Bentley as one of numerous technology-sector defendants (including Adobe, Oracle, and Samsung) in a non-practicing-entity patent assertion; the outcome of this action could not be determined in the sources reviewed. This exposure is assessed as low-specificity and consistent with routine industry-wide NPE patent-assertion activity rather than an entity-specific adverse indicator, since NPE suits of this type are commonly filed against a broad swath of large technology companies without regard to individual conduct. No successor-liability litigation was identified beyond the standard FCPA successor-liability risk-factor disclosure already noted in Bentley's own SEC filings, and no judgment, settlement payment, or adverse verdict against Bentley Systems was identified in any matter reviewed.

From a joint venture risk-weighting perspective, the overall litigation profile supports a conclusion of low legal-exposure intensity: no pattern of serial-defendant or serial-plaintiff conduct was identified, no government enforcement litigation exists, and the entity's two most substantive matters either resolved favorably or reflect Bentley acting to protect its own technology assets. The unresolved NPE matter and the undetermined final status of the Nakshatech proceeding warrant inclusion as monitoring items in ongoing partnership due diligence, particularly given the requester's stated interest in technology-transfer and IP-assignment risk, but neither rises to a level indicating material or imminent legal exposure capable of disrupting a prospective partnership.

RISK INDICATOR: Yellow - Litigation history shows one favorably resolved historical case and two low-materiality pending or undetermined matters (an NPE patent suit and an Indian IP-enforcement action) requiring monitoring but no confirmed adverse judgment against the entity.

13c) Fraud & Integrity Risk

Direct searches of SEC EDGAR full-text search, SEC Administrative Proceedings, and SEC Litigation Releases identified no accounting-fraud enforcement action, no financial restatement, and no PCAOB audit-deficiency finding against Bentley Systems, Incorporated. No False Claims Act or qui tam action was identified in federal court record searches (PACER/CourtListener), and no DOJ or FBI wire, mail, or bank fraud prosecution naming the entity or its executives was located. No insurance fraud, procurement fraud, or bid-rigging finding was identified against the company in any government enforcement database reviewed, and no named executive, including long-tenured founders Gregory S. Bentley and Keith A. Bentley or current CEO Nicholas H. Cumins, carries any identified personal history of fraud-related criminal or civil enforcement connected to their duties at Bentley Systems.

No SEC, CFTC, or OSHA whistleblower complaint referencing Bentley Systems was located in public searches; however, such complaints are frequently filed and maintained under statutory confidentiality provisions, so the absence of a public record constitutes a genuine no-adverse-findings-identified result rather than an affirmative clearance, and this distinction is material for a joint-venture partner that would gain access to the requester's proprietary systems and strategic plans. This integrity profile is corroborated indirectly by the absence of any consent decree, deferred or non-prosecution agreement, or disgorgement order in the SEC and DOJ records reviewed, and by the clean litigation pattern documented in Section 5, where Bentley Systems appears almost exclusively as an IP-enforcing plaintiff rather than as a defendant in matters alleging dishonesty or misrepresentation. The principal residual exposure for the requester is not a documented integrity failure but the standard successor-liability risk factor Bentley discloses in its own 10-K regarding FCPA exposure inherited through future acquisitions, a boilerplate disclosure rather than evidence of misconduct, which should be addressed through acquisition-integration diligence covenants in any JV agreement rather than treated as a current integrity finding.

RISK INDICATOR: Green - Direct queries of SEC enforcement records, DOJ fraud databases, and federal court dockets returned no confirmed fraud, false-claims, or integrity-related enforcement action against Bentley Systems or its named executives.

13d) Geopolitical & Regulatory Risk

The most significant finding in this area concerns Bentley Systems' Russia operations status. The Yale Chief Executive Leadership Institute's #LeaveRussia tracker, developed with the Kyiv School of Economics Institute methodology, categorizes Bentley Systems as a company that is temporarily pausing operations in Russia, meaning it has curtailed activity while preserving optionality to resume, rather than having fully divested or exited. This status is materially different from a confirmed exit and creates an unresolved sanctions-adjacent exposure that requires direct verification before execution of any joint venture or strategic partnership, given the active and evolving nature of US OFAC, EU, and UK Russia-related sanctions programs; no confirmed sanctions violation was identified, but the ambiguity of a paused (rather than terminated) Russia relationship represents a monitorable exposure rather than a settled clean record.

China exposure presents a second material geopolitical vector. Bentley Systems' own SEC 10-K risk-factor disclosures acknowledge that its non-US operations are subject to trade protection measures, sanctions, quotas, embargoes, and import/export licensing requirements, as well as heightened data-privacy compliance obligations under frameworks including the Cybersecurity Law of the People's Republic of China. Single-source aggregator claims referencing a China office presence and a potential local joint-venture distribution strategy in China could not be corroborated against Tier 1 or Tier 2 sources in this research and are flagged as requiring direct verification; if substantiated, such a structure would raise deemed-export, technology-transfer, and data-localization considerations directly relevant to a prospective JV partner's exposure to US export-control and CFIUS-adjacent risk.

Bentley's FY2025 10-K further discloses that recent and potential US tariffs targeting China, and the broader risk of an escalating global trade war including retaliatory tariff measures, could increase costs and adversely affect the business; this is a disclosed forward-looking risk factor rather than a realized adverse event, but it is relevant to continuity-of-performance analysis for a manufacturing-and-industrials-sector counterparty dependent on stable cross-border software delivery and support. No FATF grey-list or black-list jurisdiction operational presence was identified for Bentley Systems' core corporate structure, as its principal jurisdictions of operation and incorporation (United States, New Zealand, and an unconfirmed Ireland presence) are not FATF-listed, and no expropriation, nationalization, or state-ownership influence over Bentley Systems was identified in any source reviewed.

Taken together, these findings support an elevated but not critical risk rating. There is no confirmed sanctions match, enforcement action, or expropriation event, but the unresolved, undetermined-status Russia pause combined with uncorroborated China footprint claims and disclosed tariff/trade-war exposure constitute a pattern of potential, unconfirmed sanctions and trade-compliance exposure that should be resolved through direct diligence questions to Bentley Systems prior to finalizing any joint venture or licensing structure, particularly given the requester's manufacturing-sector obligations around flow-down sanctions compliance and technology-transfer controls.

RISK INDICATOR: Orange - Bentley Systems carries an undetermined, unresolved Russia operational-pause status per the Yale/KSE tracker and uncorroborated China footprint and local-JV claims, representing potential sanctions and export-control exposure without a confirmed violation.

13e) Supply Chain & Logistics Security

Bentley Systems, Incorporated operates as a pure enterprise software provider without a traditional physical manufacturing or logistics supply chain, which substantially narrows the applicability of conventional supply-chain-security due diligence relative to a hardware-producing or distribution-based counterparty. No conflict-minerals exposure under the Dodd-Frank Section 1502 disclosure framework was identified, as the company does not manufacture physical products incorporating tin, tantalum, tungsten, or gold. No Customs-Trade Partnership Against Terrorism (C-TPAT) membership record was identified, and none would ordinarily be expected given Bentley is not a significant physical importer or exporter of goods in the traditional customs sense. No history of cargo theft, counterfeit-goods involvement, product diversion, or U.S. Customs and Border Protection detention or seizure action was identified against Bentley Systems in the sources searched, and this is assessed as a genuine null result reflecting the low inherent physical-supply-chain risk profile of a software business rather than an evidentiary gap.

Notwithstanding the limited relevance of traditional logistics-security concerns, the functional equivalent of supply-chain risk for a software entity of this profile lies in its cloud infrastructure and third-party technology-vendor dependencies, an area of particular salience given the joint-venture relationship context's emphasis on data security and deep third-party access to a partner's systems and proprietary information. This research was unable to independently confirm Bentley Systems' specific cloud-hosting architecture, its degree of concentration in any single hyperscale provider such as AWS, Microsoft Azure, or Google Cloud, or the resilience and redundancy provisions governing that infrastructure; public search returned no authoritative Tier 1 or Tier 2 source addressing this question directly. This represents a material open item for a prospective strategic or joint-venture partner to resolve through direct diligence request, particularly given the relationship context's stated concern with technology-transfer risk, deemed-export exposure, and continuity of service, and it is compounded by the unresolved certification-status gap noted elsewhere in this report regarding SOC 2 Type II and ISO 27001 status. Given the absence of adverse findings on the physical supply-chain dimension but the inability to confirm the technology-vendor concentration and infrastructure-resilience profile most relevant to the requester's sector and relationship type, this area is assessed as Insufficient Data pending direct disclosure from Bentley Systems.

RISK INDICATOR: Insufficient Data - No adverse findings were identified regarding physical logistics or customs matters, but the cloud-infrastructure and technology-vendor concentration data most relevant to the joint-venture data-security context could not be confirmed through the sources searched.

13f) Technology, IP & Data Risk

Bentley Systems' litigation history reflects a generally favorable pattern with respect to intellectual property protection and enforcement. In Baystate Technologies v. Bentley Systems (D. Mass. 1996), the court entered judgment for Bentley, finding no copyright infringement, no trade secret misappropriation, no Lanham Act violation, and no tortious interference; this is a resolved, historical matter with no ongoing exposure. More recently, in Bentley Systems and Anr v. Nakshatech Pvt. Ltd. (India, 2024), Bentley appeared as the enforcing plaintiff protecting its MicroStation design-modeling software against alleged misappropriation, indicating both active IP-protection discipline and the fact that Bentley's core technology has been the target of at least one confirmed attempted-infringement action in a foreign jurisdiction.

A separate non-practicing-entity patent action, SoftVault Systems, Inc. v. Bentley Systems Incorporated, named Bentley alongside numerous unrelated major technology companies (Adobe, Oracle, Samsung); this is assessed as low-specificity, industry-wide NPE litigation exposure rather than an entity-specific adverse indicator, and its outcome remains undetermined in sources reviewed. Taken together, no pattern of serial defendant or plaintiff conduct, no trade secret theft conviction, and no adverse IP judgment against Bentley Systems was identified, which supports a reasonable baseline of confidence in the company's ability to negotiate and honor IP-ownership and assignment provisions within a joint venture structure, subject to the residual technology-leakage risk illustrated by the Nakshatech matter.

On data privacy and cybersecurity, no disclosed data breach, ransomware incident, or CISA alert specific to Bentley Systems, Incorporated was identified in this research; unrelated incidents affecting similarly named entities, including Bentley University and a separate small company called Bentley Industries, were excluded under the identity-anchor protocol and do not reflect on the subject. No FTC Section 5 privacy enforcement action, state attorney general privacy action, or GDPR enforcement action against Bentley Systems was identified. Bentley's own SEC 10-K risk factors acknowledge exposure to increasing regulatory complexity around data privacy and artificial intelligence, including the EU GDPR and China's Personal Information Protection Law, and to more stringent requirements under the Cybersecurity Law of the People's Republic of China where the company delivers software or maintains operations; these are disclosed forward-looking risk factors rather than confirmed violations.

A material and unresolved gap for the purposes of this relationship type is the absence of any independently confirmed SOC 2 Type II or ISO 27001 certification status for Bentley Systems, despite the joint venture relationship context's specific emphasis on data security given anticipated deep partner access to proprietary systems, customer data, and strategic plans. Public searches, including generic explanatory material and unrelated third-party product references, did not surface authoritative confirmation of Bentley's current certification posture in either direction, and cloud-infrastructure vendor concentration (for example, reliance on a specific hyperscale provider) could likewise not be independently corroborated. Combined with the company's own disclosed exposure to deemed-export risk, export control and economic sanctions compliance obligations affecting software delivery to certain jurisdictions, and the unresolved China data-localization and cybersecurity-law exposure noted in Section 8, this certification and infrastructure-visibility gap should be treated as a specific pre-execution due diligence item requiring direct confirmation from Bentley Systems before any technology-sharing or system-access provisions are finalized in a joint venture agreement.

RISK INDICATOR: Yellow - No confirmed data breach, IP theft judgment, or privacy enforcement action against Bentley Systems was identified, but the unconfirmed SOC 2/ISO 27001 certification status and unverified cloud-vendor dependency, combined with disclosed China/PIPL and deemed-export exposure, constitute a concrete monitoring trigger given the depth of system access contemplated in a joint venture relationship.

13g) Reputational & Media Coverage

A twenty-four-month lookback across major international wire services (Reuters, Bloomberg, Financial Times, Wall Street Journal, Associated Press, BBC) identified no material adverse coverage specific to Bentley Systems, Incorporated. Trade press coverage in outlets such as Global Construction Review, GIM International, ARC Advisory Group, Control Design, and RT&S is overwhelmingly transactional and neutral-to-positive, concentrated on acquisitions (including the pending Talon Aerolytics transaction and the completed Seequent acquisition), earnings releases, and product launches. No brand or trademark controversy, executive personal scandal, product recall, safety alert, or ESG activist boycott campaign was identified against the entity in this research.

A more significant, though uncorroborated, signal emerges from employee-sentiment platforms (Glassdoor, Fishbowl, TeamBlind), which are Tier 4 sources not independently verified by any Tier 1 or Tier 2 outlet. Multiple reviewers describe layoffs occurring in 2023 and 2024 as unexpected, with at least one detailed review characterizing the reductions as indiscriminate, affecting exceptional performers, and citing ineffective HR response to underlying morale and toxic-culture concerns. For a joint-venture or strategic-licensing counterparty, sustained negative internal sentiment concerning workforce reductions carries second-order implications for continuity of the technical and commercial personnel likely to be assigned to a partnership, and for the retention of institutional knowledge relevant to any technology-transfer or co-development arrangement. No independent corroboration of the scale, cause, or resolution of these layoffs was located in Bentley's own SEC disclosures (10-K restructuring-charge footnotes were not confirmed in this research pass), and the finding should be treated as a workforce-stability signal warranting direct follow-up rather than a confirmed adverse media event.

RISK INDICATOR: Yellow - No material adverse findings from authoritative media, but uncorroborated employee-sentiment reports of layoffs and morale concerns in 2023-2024 warrant ongoing monitoring.

13h) Environmental Risk & Liabilities

No EPA enforcement action, Superfund or CERCLA site involvement, environmental litigation, or regulatory notice of violation was identified against Bentley Systems, Incorporated in searches of federal environmental enforcement records and court databases. This outcome is consistent with the entity's operating profile as a software and technology-services provider without manufacturing facilities, industrial emissions sources, chemical handling operations, or physical waste streams that typically generate environmental liability exposure. No environmental, health, and safety citation history was located for the New Zealand-based Seequent subsidiary either, which itself operates in software and geoscience data analytics rather than physical extraction or processing.

From a joint-venture risk perspective, the absence of an environmental liability profile substantially reduces the likelihood of shared or successor environmental exposure that might otherwise arise in a partnership involving a manufacturing or industrial counterparty. This is a genuine null result rather than a data-access limitation: the low inherent environmental-risk profile of a software business, combined with the absence of any contrary indicator across EPA, state environmental agency, or litigation searches, supports a clean-record determination for this category rather than an inconclusive one. No ongoing monitoring trigger specific to environmental liability was identified that would require follow-up in the context of the proposed relationship.

RISK INDICATOR: Green - No environmental enforcement, contamination, or litigation history identified, consistent with the entity's non-industrial software business model.

13i) Labor, Human Rights & Anti-Slavery

Bentley Systems, Incorporated has published a Modern Slavery Act Statement covering financial year 2024 in which it states a commitment to good corporate citizenship, asserts a low assessed risk of engaging in modern slavery or human trafficking given the technical and professional nature of its business, and states it is not aware of any situation it considers a labor violation. The statement acknowledges that the company conducts business in countries that may be more vulnerable to human-rights abuses and asserts a zero-tolerance policy supported by internal communication processes. Because this statement is company-generated, it is recorded here only as a factual identification of its existence and content; per sourcing protocol it cannot independently establish a clean labor-rights record and should be corroborated through supplier and country-level human-rights databases prior to relying on it for JV governance purposes.

Independent screening of the US Department of Labor, National Labor Relations Board, Equal Employment Opportunity Commission, and OSHA enforcement records identified no unfair-labor-practice findings, wage-and-hour violations, discrimination enforcement actions, or workplace-safety citations against Bentley Systems. No forced-labor, child-labor, or human-trafficking finding was identified in business-and-human-rights registries reviewed, though the majority of relevant hits in those registries pertained to the unrelated Bentley Motors Limited and Mott MacDonald Bentley Ltd entities and were excluded under the identity-anchor protocol. The most substantive labor-related signal identified in this research is the uncorroborated employee-sentiment reporting of 2023-2024 layoffs discussed in Section 13g, which bears directly on workforce stability and talent-retention considerations material to a joint-venture relationship; this signal, together with the reliance on a self-reported modern slavery statement rather than independently verified supply-chain human-rights auditing, supports a monitoring-level rather than clean-record determination.

RISK INDICATOR: Yellow - No confirmed labor or human-rights enforcement action was identified, but reliance on a self-reported modern slavery statement and uncorroborated layoff/workforce-stability signals warrant continued monitoring.

13j) Anti-Bribery & Corruption

No enforcement action, settlement, deferred prosecution agreement, or non-prosecution agreement involving Bentley Systems, Incorporated was identified in DOJ or SEC records reviewed in connection with the Foreign Corrupt Practices Act. Direct searches of SEC litigation releases and DOJ FCPA enforcement resources returned no entity-specific results, and no UK Serious Fraud Office action under the UK Bribery Act was identified despite that statute's extraterritorial reach being considered given the requester's cross-border joint venture due diligence framework. This is assessed as a genuine no-adverse-findings result rather than a data gap, since named primary enforcement sources were searched directly and returned nothing adverse.

Bentley Systems' own SEC Form 10-K discloses a standard risk factor stating that government authorities may seek to hold the company liable under a successor-liability theory for FCPA violations committed by companies or assets it acquires. This is boilerplate risk-factor language common to acquisitive public companies and does not constitute an admission or evidence of an actual violation; no acquisition-related bribery exposure was substantiated in the underlying record for Seequent Holdings Limited, Talon Aerolytics, Inc., or any other identified acquisition. The disclosure is nonetheless relevant to the joint venture context because Bentley's acquisitive growth strategy, most recently evidenced by the Seequent and Talon Aerolytics transactions, creates recurring integration risk that the requester would inherit indirectly through any shared venture structure.

No politically exposed person connections or improper government-official relationships were identified against Bentley Systems, Incorporated or its named executives in the sources reviewed. This absence of findings carries limited weight, however, because Bentley's core commercial model involves substantial licensing and services engagements with government agencies, public utilities, and state-owned infrastructure operators across 194 countries, a customer base that inherently elevates PEP-interaction exposure beyond what public-source screening can reliably capture. This area is flagged as warranting targeted, non-public due diligence, including a direct request to Bentley Systems for its anti-corruption policy, third-party intermediary due diligence procedures, and any government-contract-specific compliance certifications, rather than reliance on public records alone.

Bentley Systems maintains a Code of Conduct referenced in its governance materials, but the specific content, training cadence, and third-party/agent due diligence procedures of its anti-bribery compliance program could not be independently confirmed through public sources reviewed in this research. This represents a genuine information gap rather than an adverse finding, and is a material open item given the joint venture relationship context's requirement to assess the quality of a partner's own compliance infrastructure before entering into a shared-liability arrangement. The requester is advised to obtain Bentley's current anti-corruption policy, FCPA/UK Bribery Act training records, and third-party intermediary vetting procedures directly as a condition of proceeding, particularly in light of the company's government-adjacent customer base and ongoing acquisition activity.

RISK INDICATOR: Insufficient Data - No FCPA, UK Bribery Act, or related enforcement action was identified against Bentley Systems, but the quality of its anti-corruption compliance program, third-party due diligence procedures, and PEP exposure in government-adjacent markets could not be independently verified through public sources.

RISK INDICATOR SUMMARY
SECTIONRISK INDICATOR
1. ENTITY INFORMATIONYellowCore corporate identity is confirmed through SEC filings, but several international office locations rely solely on an uncorroborated Tier 4 aggregator source and require verification.
2. OWNERSHIP & STRUCTUREOrangeFounder-family supervoting control combined with Siemens' dual investor/technology-partner/competitor relationship constitute significant structural governance and conflict-of-interest concerns material to a joint venture negotiation, though no unlawful conduct is indicated.
3. KEY PERSONNELYellowNo adverse regulatory findings were identified against any named executive, but unresolved data gaps in CFO and CIO background verification, an unresolved CTO title conflict across sources, and high key-person dependency tied to founder tenure warrant ongoing monitoring.
4. SANCTIONS & CONTROLS SCREENINGGreenNo confirmed sanctions, export-control, or restricted-party matches were identified for Bentley Systems, Incorporated or its named executives across any government list screened as of the screening date.
5. REGULATORY & LEGALYellowNo active enforcement actions were identified against Bentley Systems, but historical litigation, an undetermined-status patent assertion, and standard successor-liability and export-control risk-factor disclosures warrant continued monitoring in a JV context.
6. ADVERSE MEDIAYellowNo material adverse findings were identified in primary or trade media, but uncorroborated employee-sentiment reports of workforce reductions in 2023-2024 warrant monitoring given workforce-stability relevance to the proposed relationship.
7. FINANCIAL ASSESSMENTYellowCore financial metrics show sustained double-digit revenue and ARR growth with strong liquidity, but an undetermined current credit rating and a documented softening in 2026 analyst sentiment warrant ongoing monitoring for a JV partner's capacity to sustain shared financial obligations.
8. GEOPOLITICAL RISKOrangeAn unresolved Yale/KSE-tracked Russia operations pause combined with disclosed China export-control, data-localization, and tariff exposure constitute elevated geopolitical risk factors requiring direct verification before JV execution.
9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY)See individual sub-section risk indicators in report body
10. CERTIFICATIONS & ACCREDITATIONSInsufficient DataPublic sources did not confirm current certification status for Bentley Systems across quality management, security, or industry-specific accreditation categories, and this reflects a visibility limitation rather than an identified adverse issue.
11. CONFLICTS OF INTERESTYellowStructural governance concentration and a strategic investor's dual commercial role represent disclosed, lawful characteristics requiring ongoing monitoring rather than confirmed misconduct.
12. RELATED & ASSOCIATED ENTITIESYellowNo adverse findings were identified for any named related entity, but unresolved single-source claims regarding Bentley's most recent acquisition and current Siemens ownership percentage warrant follow-up verification before JV execution.
13. AREAS OF SPECIAL INTERESTSee individual sub-section risk indicators in report body
RISK ASSESSMENT

Key Risk Factors:

• Bentley's unresolved 'temporarily pausing' Russia status creates potential inherited sanctions exposure through any co-marketed licensing relationship.

• Uncorroborated China office and local joint-venture claims raise deemed-export and technology-diversion risk to shared intellectual property.

• Siemens' 9%+ equity stake and EUR 100 million joint R&D program create competitive-alignment conflict risk in overlapping markets.

• Bentley's 29-vote Class A supervoting structure concentrates governance control, limiting requester leverage over JV dispute resolution.

• Unconfirmed SOC 2/ISO 27001 certification status prevents verification of data-security controls before granting system access.

• Uncorroborated 2023-2024 layoff reports signal potential workforce-continuity risk affecting technical personnel supporting the partnership.

• Absence of a current public credit rating limits independent verification of Bentley's long-term debt-servicing capacity.

Recommendations:

1. Obtain direct written confirmation from Bentley Systems of its current, contractual Russia operational status before executing any JV agreement, given the Yale/KSE 'pausing' classification.

2. Request documentary confirmation of Bentley's China office locations and any local joint-venture or data-hosting structure to assess deemed-export and technology-transfer exposure.

3. Negotiate explicit information-barrier and technology-roadmap-priority provisions addressing Siemens AG's dual role as equity holder and overlapping-market technology partner.

4. Secure contractual governance protections, including board representation and binding dispute-resolution mechanisms, to offset the Bentley Control Group's 29-vote supervoting authority.

5. Require production of current SOC 2 Type II and/or ISO 27001 audit reports and cloud-vendor concentration disclosures before granting system or data access.

6. Request Bentley's 10-K restructuring-charge footnotes or internal workforce data to corroborate or refute Glassdoor/Fishbowl reports of indiscriminate 2023-2024 layoffs.

7. Obtain Bentley's current anti-corruption policy, FCPA/UK Bribery Act training records, and third-party intermediary due diligence procedures given its government-adjacent customer base.

Monitoring Needs:

• Periodic re-screening of Bentley Systems, Seequent Holdings Limited, and senior officers against OFAC, EU, and UK sanctions lists throughout the JV term.

• Ongoing tracking of Bentley's Russia operational status via the Yale/KSE tracker and direct inquiry to Bentley management.

• Quarterly review of Bentley's ARR growth, net retention rate, and analyst sentiment for early financial-stability warning signals.

• Monitoring of the reported Talon Aerolytics acquisition for confirmation, structure, and integration status.

• Monitoring of current Siemens AG ownership percentage via Schedule 13D/13G filings.

• Tracking of Bentley's board composition and independent-director representation following the July 2024 CEO transition.

Recommended Action: Proceed with the joint venture relationship only after Bentley Systems provides direct verification of its Russia operational status, China footprint, and cybersecurity certification posture, and after negotiating governance, IP-protection, and exit safeguards commensurate with its founder-controlled structure.
RECOMMENDED FOLLOW-UP QUESTIONS

Based on the findings in this report, the following questions should be addressed through direct inquiry with the entity or additional research:

1. What is Bentley Systems' current, contractual status regarding Russia operations, including any residual licensing, distributor, or support relationships?

2. Does Bentley Systems maintain offices in Beijing, Hong Kong, and Shanghai, and does it operate or plan any local joint-venture or data-hosting structure in China?

3. What is Bentley Systems' current SOC 2 Type II and/or ISO 27001 certification status, and can current audit reports be produced for review?

4. What cloud infrastructure providers does Bentley Systems rely on, and what is the degree of vendor concentration and redundancy in that architecture?

5. Can Bentley Systems corroborate the scale, cause, and resolution of the 2023-2024 workforce reductions referenced in employee-sentiment platforms?

6. What is Bentley Systems' current Siemens AG ownership percentage, and what information-sharing or exclusivity limitations apply under the strategic alliance?

7. What is the current status, structure, and jurisdictional scope of the reported Talon Aerolytics acquisition?

8. What specific anti-corruption compliance program elements, including third-party intermediary due diligence and training cadence, does Bentley Systems maintain?

9. What is Bentley Systems' current board composition and independent-director representation following the July 2024 CEO transition?

10. Does Bentley Systems carry a current public credit rating, and if not, what internal liquidity metrics can be provided to support long-term JV financial commitments?

SOURCES CONSULTED

Government & Regulatory Databases:

• SEC EDGAR (10-K, 10-Q, 8-K, DEF 14A, S-1, 424B4) - results found

• SEC Litigation Releases - no results for subject entity; unrelated individuals named Bentley excluded

• OFAC SDN List - no matches identified

• BIS Entity List - no matches identified

• SAM.gov exclusions/debarments - no matches identified

• OIG List of Excluded Individuals/Entities - no matches identified

• World Bank debarment list - no matches identified

• Interpol - no matches identified

• UN Security Council consolidated sanctions list - no matches identified

• EU consolidated sanctions list - no matches identified

• UK HM Treasury sanctions list - no matches identified

• S&P Global Ratings regulatory notice - result found (historical 2012 rating withdrawal)

Court & Legal Records:

• Justia - Baystate Technologies v. Bentley Systems (D. Mass. 1996) - result found

• Indian Kanoon - Bentley Systems and Anr v. Nakshatech Pvt. Ltd. (2024) - result found

• PACER/CourtListener federal court records - no enforcement or criminal results identified

News & Media:

• Reuters, Bloomberg, Financial Times, Wall Street Journal, Associated Press, BBC - no material adverse results identified

• Businesswire, Global Construction Review, GIM International, ARC Advisory Group, Control Design, Railway Track and Structures - results found (transactional/positive coverage)

• Yale SOM #LeaveRussia tracker (KSE Institute methodology) - result found (Russia operations pause status)

• Glassdoor, Fishbowl, TeamBlind - results found (uncorroborated employee-sentiment reports)

Business Registries & Financial:

• SEC EDGAR filings - results found

• Bentley Systems Investor Relations earnings releases - results found

• Simply Wall St - results found (single-source, uncorroborated 2026 figures)

• Craft.co, Comparably, TheOrg, GlobalData, Clay.com aggregators - results found, partially corroborated against SEC filings

Industry-Specific Sources:

• OpenSanctions - result found (determined false positive)

• firstcheck.app compliance sample report - result found (uncorroborated single-source aggregator claims)

• business-humanrights.org and UK Modern Slavery Statement Registry - results found (predominantly unrelated entities excluded)

• Bentley Systems Modern Slavery Act Statement (company website) - result found (company-generated)

LIMITATIONS & RECOMMENDED NEXT STEPS

This report is based on publicly available information accessible through web search. The following limitations apply:

Information Not Accessible:

• Proprietary databases (e.g., LexisNexis, World-Check, Dow Jones Risk & Compliance)

• Non-public court records and sealed proceedings

• Confidential regulatory examination results

• Private company financial statements

• Non-English language sources (limited coverage)

• Real-time sanctions list updates (recommend independent verification)

• International jurisdiction coverage: the depth and reliability of open-source intelligence varies significantly by jurisdiction, entity type, disclosure requirements, press freedom, and corporate registry accessibility. See firstcheck.app for full details.

Recommended Additional Due Diligence:

1. Obtain direct written confirmation from Bentley Systems of its current Russia operational status and any residual contractual relationships before proceeding further.

2. Request documentary verification of Bentley's China office locations and any local joint-venture, hosting, or data-localization arrangements.

3. Require production of current SOC 2 Type II/ISO 27001 certification documentation and cloud-vendor concentration disclosures.

4. Negotiate governance, dispute-resolution, and IP-assignment protections in the JV agreement addressing the Bentley Control Group's supervoting authority and the Siemens strategic-alliance conflict.

5. Corroborate the 2023-2024 workforce-reduction reports through Bentley's 10-K restructuring disclosures or direct management inquiry.

6. Confirm the status, structure, and integration plan of the reported Talon Aerolytics acquisition and the current Siemens ownership percentage.

7. Verify sanctions status through direct OFAC/BIS database query.

This report is valid as of the report date. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.

DISCLAIMER

FirstCheck.App is a first-level third party intelligence and risk assessment tool. It is not a substitute for formal investigation, professional review, or expert compliance determinations. Report findings should be evaluated by business managers, subject matter experts, and professionals in the context of the organization's risk tolerance, policies, directives, and approaches. FirstCheck.App reports may be retained as part of the organization's third-party risk management program, including its applicable record-keeping practices.

© 2026 FirstCheck.App. All rights reserved.


APPENDIX A — SANCTIONS & CONTROLS DATABASES SCREENED

This report reflects research conducted across the following databases. Individual databases are identified in Section 4 only when a match or potential match is found.

TIER 1 — Direct Web Research (Conducted on Every Report)

1.OFACSpecially Designated Nationals (SDN) List
2.OFACNon-SDN Lists (SSI, FSE, NS-MBS, PLC, and related)
3.BISEntity List
4.BISDenied Persons List
5.BISUnverified List
6.U.S. State DepartmentDebarred Parties List (ITAR)
7.OIGList of Excluded Individuals/Entities (LEIE)
8.GSA SAM.govSystem for Award Management Exclusions
9.DEAControlled Substances Act Exclusions
10.CMSState Medicaid Exclusion Lists (composite)
11.FDADebarment List
12.SECEnforcement Actions Database
13.CFTCEnforcement Actions
14.FinCENEnforcement Actions
15.FBIMost Wanted
16.InterpolRed Notices
17.UN Security CouncilConsolidated Sanctions List
18.European UnionConsolidated Sanctions List
19.UK HM TreasurySanctions List
20.World BankDebarment List
21.Asian Development BankSanctions List
22.OpenSanctionsConsolidated Database

TIER 2 — Web Research Based (Conducted Where Relevant)

1.FATFGrey List (Jurisdictions Under Increased Monitoring)
2.FATFBlack List (High-Risk Jurisdictions — Call for Action)
3.SECOSanctions List (Switzerland)
4.MASSanctions List (Singapore)
5.DFATSanctions List (Australia)
6.Global Affairs CanadaSanctions List
7.Japan METI/MOFASanctions and Export Control Lists
8.France TRESORDirection Générale du Trésor Sanctions
9.Germany BAFAExport Control and Sanctions Lists
10.UAESanctions List
11.IsraelSanctions List
12.ICIJOffshore Leaks Database (Panama Papers, Pandora Papers)
13.Transparency InternationalCorruption Perceptions Index (CPI)
14.Basel InstituteAML Index
15.ACAMSWatchlist (open-source tier)
16.South Korea MOFATSanctions List
17.Inter-American Development BankSanctions List

Tier 1 databases are researched on every report. Tier 2 databases are researched based on entity jurisdiction, industry, and risk profile. This screening is conducted through open-source web research and does not constitute direct real-time database queries. Independent verification against all applicable databases is required before entering into any business relationship or transaction.


APPENDIX B — RISK RATING METHODOLOGY

Risk ratings reflect a qualitative assessment of the severity, recency, and regulatory relevance of identified issues.

Red — Critical Risk
Confirmed regulatory enforcement, sanctions violations, or systemic control failures with material impact requiring immediate attention or enhanced approval.
Orange — Significant Concerns
Significant regulatory, legal, or reputational issues requiring enhanced due diligence, ongoing monitoring, or senior management approval before proceeding.
Yellow — Minor Issues
Historical concerns now resolved, manageable risks, or areas requiring periodic monitoring but not blocking engagement.
Green — No Adverse Findings
No material adverse findings identified in available open-source information. Standard onboarding procedures apply.
Insufficient Data
Limited publicly available information to assess risk. Additional research or direct inquiry recommended.
Risk Indicator Summary
Section-level risk indicators are assigned independently for each of the 13 report sections. Each indicator reflects findings specific to that section. The Risk Indicator Summary table provides a consolidated view of all section-level indicators.

REPORT METADATA
Report ID:FC-20260903-151152
Date Generated:2026-09-03 15:11:52 UTC
FirstCheck.App Version:v2.12.102
Entity Analyzed:Bentley
Jurisdiction:US
Subject Industry (Verified):Technology
Relationship Type:Joint Venture / Strategic & Licensing Partner
Requester:FirstCheck.App
Requester Industry:Manufacturing & Industrials
Requester Jurisdiction:United States
Reason for Inquiry:New Entity Check

This report is valid as of the date generated. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.


THIRD-PARTY REVIEW FORM
Reviewer Assessment
Entity Reviewed: Bentley    Requester: FirstCheck.App    Report ID: FC-20260903-151152    Report Date: 2026-09-03 15:11:52 UTC
Acceptable: Okay to proceed.
Caution: Monitoring and oversight recommended.
Pending: Verify and resolve before proceeding.
Full Review: Conduct full background due diligence before proceeding.
Unacceptable: Do not proceed.
Other/Comment:
Recommended Frequency of Third Party Assessment Reports
Every month
Every three months
Every six months
Annually
Other:
Additional Reviewer Comments
Reviewer Certification

The undersigned has reviewed this Third Party Assessment Report and confirms that the risk decision and recommendations above are based on the information provided and professional judgment.

Signature
Date
Reviewer Name
Title

This form should be completed by the designated reviewer and retained with the FirstCheck.App report as part of the organization's third party review records.

📋 To download this form in fillable format: firstcheck.app/review-form.html