2026-07-23 17:03 (2026-07-23 22:03 UTC)
Report ID: FC-20260723-220323
FirstCheck.Appβ„’
Third Party Intelligence and Risk Assessment
Subject Entity
Bentley Systems
Industry: Technology  |  Jurisdiction: United States

THIRD PARTY ASSESSMENT REPORT
REQUESTER INFORMATION
FirstCheck.App, Sample Report
Purpose: New Entity Check
Report Generated:2026-07-23 17:03 (2026-07-23 22:03 UTC)
Entity Analyzed:Bentley Systems
Jurisdiction:United States
Relationship Type:Arms-Length Supplier / Service Provider
Client Industry:Manufacturing & Industrials
Subject Industry (Verified):Technology
Areas of Special Interest:Supply Chain & Logistics Security, Financial Stability, Technology, IP & Data Risk, Labor, Human Rights & Anti-Slavery, Geopolitical & Regulatory Risk
FIRSTCHECK.APP AND METHODOLOGY
This report was compiled using FirstCheck.App's proprietary Third-Party Risk Assessment Methodology, leveraging structured open-source research across publicly available databases, sanctions lists, corporate registries, and authoritative media sources. All findings are governed by FirstCheck.App Integrity Standards which require source transparency, cross-reference corroboration, verified findings, analytical neutrality, and verification transparency. Full standards are available at FirstCheck.app. Risk indicators in the report use a five-level color system (Red, Orange, Yellow, Green, and Insufficient Data) defined in Appendix B of this report. Conclusions drawn from this report should be validated through further investigation, direct inquiry, and professional judgment before any business or compliance decision is made.
CONFIDENTIALITY
This report is confidential and proprietary. It has been prepared exclusively for the requesting party and their authorized representatives. It may not be shared, reproduced, distributed, or disclosed to any third party without the express written authorization of the requester. Unauthorized use or disclosure may violate applicable law.

TABLE OF CONTENTS

Click on any item to navigate to that section.

Executive Summary
1.   Entity Information
2.   Ownership & Structure
3.   Key Personnel
4.   Sanctions & Controls Screening
5.   Regulatory & Legal
6.   Adverse Media
7.   Financial Assessment
8.   Geopolitical Risk
9.   Industry-Specific Risks
10.   Certifications & Accreditations
11.   Conflicts of Interest
12.   Related & Associated Entities
13.   Areas of Special Interest
Risk Indicator Summary
Summary Risk Assessment
Recommended Follow-Up Questions
Sources Consulted
Limitations & Recommended Next Steps
Disclaimer
Appendix A β€” Sanctions & Controls Databases Screened
Appendix B β€” Risk Rating Methodology
Third-Party Review Form

Note: This report does not include page numbers as section breaks vary by browser and device.


EXECUTIVE SUMMARY

Bentley Systems, Incorporated is a Delaware corporation headquartered in Exton, Pennsylvania, operating as a publicly traded (Nasdaq: BSY) provider of infrastructure engineering and asset performance management software for the architecture, engineering, and construction sector. This report evaluates Bentley Systems as a prospective or existing arms-length supplier/service provider to a requester in the Manufacturing & Industrials sector. Findings are drawn exclusively from Tier 1-4 research conducted across regulatory, legal, financial, and open-source records.

This relationship carries no confirmed sanctions or restricted-party exposure, supporting continued engagement without immediate compliance barriers.

Expansion of Chinese joint-venture technology distribution arrangements warrants enhanced monitoring of export-control and technology-transfer risk given tightening BIS affiliate-ownership rules.

Strong recurring revenue growth, declining leverage, and robust free cash flow generation support confidence in this supplier's financial capacity to sustain long-term service continuity.

Active FedRAMP authorization and U.S. Army Corps of Engineers sponsorship demonstrate operational reliability, though unconfirmed CMMC certification status should be verified before any relationship requiring DoD-flow-down compliance.

A transparent 2024 executive succession completed without disruption reduces key-person continuity risk for this engagement.

Shared vendor relationships with competing AEC/infrastructure software customers, including manufacturing-sector competitors, warrant contractual IP-firewall and data-segregation provisions to mitigate conflict-of-interest exposure.

Risk Summary:

Sanctions Screening: No matches identified for Bentley Systems, Incorporated or its named executives; one name-only false positive (a sanctioned vessel named "Bentley") was identified and excluded.

Regulatory Risk: Historical β€” a 1996 trade secret/copyright case resolved favorably and an undetermined-outcome non-practicing-entity patent action; no active enforcement identified.

Adverse Media: None β€” no material adverse media identified specific to Bentley Systems, Incorporated.

Financial Risk: Stable β€” strong subscription revenue growth, declining leverage (2.2x trending to 1.9x), and robust free cash flow generation.

β†’ See Section-by-Section Risk Indicator Summary

1. ENTITY INFORMATION

Name: Bentley Systems, Incorporated

Country: United States

Business Type: Publicly traded corporation (Nasdaq: BSY); enterprise software/SaaS provider

Website: https://www.bentley.com

Industry: Infrastructure engineering software (Architecture, Engineering, Construction and asset performance management SaaS)

Headquarters: Exton, Pennsylvania, United States

Known Locations: Approximately 32 global office locations, including Beijing, Hong Kong, Taiwan, and Shanghai (China); Tokyo, Japan; India (Bentley Systems India Pvt. Ltd.); Jakarta, Indonesia (PT Cohesive Indonesia Group); Kuala Lumpur, Malaysia (Bentley Systems (Malaysia) Sdn. Bhd.); Mexico City, Mexico (Bentley Systems de Mexico SA de CV); Dublin, Ireland (Bentley Systems International Ltd.); Christchurch, New Zealand (Seequent); Singapore; the Netherlands (BSI Holdings B.V., Plaxinvest B.V.); the United Kingdom (SRO Solutions Limited); Poland (Vetasi Sp. z o.o.); and Pakistan (Bentley Systems Pakistan (Pvt.) Limited).

Bentley Systems, Incorporated was originally incorporated in California in 1984 upon founding and reincorporated in Delaware in 1987, with its original Certificate of Incorporation filed with the Delaware Secretary of State on March 6, 1987 (Commission File Number 001-39548, EIN 95-3936623).

Two independent Tier 1 sources β€” SEC EDGAR filings and the Bloomberg LEI registry (LEI 549300WVEHPGE0Z56F71) β€” corroborate the core corporate identity with no ambiguity as to a distinct "Bentley" entity.

The Bloomberg LEI record shows a registration status of "LAPSED" as of the last update dated 2024-01-20, reflecting an administrative renewal gap rather than a change in corporate status; Delaware and SEC records confirm the company remains ACTIVE.

Numerous unrelated entities sharing "Bentley" branding were identified and explicitly excluded from this report, including Bentley Motors Limited (a Volkswagen AG subsidiary), Bentley University, Bentley Industries, Bentley Laboratories Inc., and individuals named Robert L. Bentley and Christopher R. Bentley connected to unrelated SEC enforcement matters.

China-based offices (Beijing, Hong Kong, Shanghai) present elevated regulatory risk given Chinese data localization and cybersecurity law applicability and are subject to enhanced scrutiny given the company's local joint-venture strategy discussed in Section 8 and Section 9.

The New Zealand location (Seequent) sits in a Tier 1-adjacent, low-risk jurisdiction, with the 2021 acquisition having obtained required consent under the New Zealand Overseas Investment Act.

India, Indonesia, Malaysia, and Mexico locations fall within Tier 3 jurisdictions carrying moderate standard country-risk profiles; no entity-specific adverse findings were identified in any of these markets.

The Ireland location (Bentley Systems International Ltd.) operates within a Tier 1 EU regulatory framework subject to GDPR, presenting comparatively low jurisdictional risk.

RISK INDICATOR: Yellow - Core corporate identity is well-corroborated across primary sources, but an administratively lapsed LEI registration requires renewal confirmation.

2. OWNERSHIP & STRUCTURE

Bentley Systems, Incorporated is publicly traded on Nasdaq under ticker BSY with a dual-class share structure; as of February 20, 2024, the registrant reported 11,537,627 shares of Class A common stock and 285,788,718 shares of Class B common stock outstanding.

There is no single controlling parent company; Bentley Systems is itself the top-level publicly traded entity, and no complex offshore ownership layering was identified in the corporate chain.

Founder-family members retain concentrated control through Class B super-voting shares; the company's Amended and Restated Certificate of Incorporation defines "Founder" to include Gregory, Barry, Keith, Raymond, and Richard Bentley.

SEC Schedule 13G/A filings show Corinne Patricia Bentley holding beneficial ownership of 38,621,698 Class B shares (13.2%) as of March 31, 2026, while SEC Form 4 filings show director Raymond B. Bentley holding 14,814,360 Class B shares directly, plus indirect holdings of 92,654 shares via a 401(k) plan and 125,000 shares held by his spouse.

Institutional ownership is broad and diversified, with 788 institutional holders collectively owning 140,684,887 shares; the largest holders include Vanguard Group, Kayne Anderson Rudnick Investment Management, BlackRock, Swedbank AB, and State Street Corp, per Nasdaq/Fintel aggregator data, with no adverse findings associated with these institutional holders.

The founder-family concentrated voting control is a governance characteristic warranting disclosure and is addressed further as a conflict-of-interest consideration in Section 11, but does not itself constitute an adverse ownership finding under standard dual-class public company norms.

RISK INDICATOR: Green - Ownership structure is transparent and standard for a US dual-class public company, with no adverse findings identified.

3. KEY PERSONNEL

Nicholas Cumins assumed the role of Chief Executive Officer effective July 1, 2024, succeeding founder Greg Bentley, who transitioned to Executive Chair of the Board; Cumins is the first CEO in the company's approximately 40-year history who is not a member of the Bentley family.

Cumins previously served as Chief Operating Officer since January 2022 and as Chief Product Officer beginning September 2020, with prior senior roles including general manager of SAP Marketing Cloud, chief product officer of Scytl, and senior roles at OpenX and SAP.

Werner Andre was promoted to Chief Financial Officer effective January 1, 2022, and continues in that role per company disclosures; Julien Moutte serves as Chief Technology Officer per multiple 2025-2026 company press releases.

Additional named executives include Katriona Lord-Levins (Chief Success Officer), Chris Bradshaw (Chief Marketing Officer), David Hollister (Chief Investment Officer, appointed 2022), and Allen Li (General Manager, China, appointed 2023, reporting to Chief Revenue Officer Brock Ballard).

No regulatory or enforcement history was identified for any current named Bentley Systems executive; searches for "Bentley" fraud or SEC enforcement matters returned only unrelated individuals (Robert L. Bentley and Christopher R. Bentley), who were confirmed unrelated and excluded per the identity-verification protocol described in Section 4.

The transition from founder-family to non-family CEO leadership was executed through public announcement with an evident succession plan, indicating orderly management continuity relevant to assessing long-term relationship stability with this supplier.

RISK INDICATOR: Green - No regulatory or enforcement history identified for any named executive; the 2024 leadership transition was orderly and transparent.

4. SANCTIONS & CONTROLS SCREENING

This section reflects screening conducted across various sanctions, controls and watchlist databases. A complete list of these databases is provided in Appendix A. Individual databases are identified in this section only when a match or potential match is found. No listing means no matches for this entity were found.

IMPORTANT DISCLAIMER: This screening is based on open-source web research conducted at the time of report generation. FirstCheck.App does not directly query sanctions databases in real time. Sanctions listings change frequently. The requesting party must conduct independent direct screening against all applicable databases before entering into any business relationship or transaction. Reliance on this report without independent verification does not constitute a defense to sanctions violations.

SCREENING TIMESTAMP: List checks performed on 2026-07-23 21:56:55 UTC.

No matches were identified for Bentley Systems or its key executives across the databases listed in Appendix A.

One name-similarity result was identified on an OFAC-aggregator database (OpenSanctions) referencing a sanctioned vessel named "Bentley"; this was verified as unrelated to Bentley Systems, Incorporated β€” a vessel versus a corporate software entity β€” and was excluded as a false positive under standard identity-verification protocol.

Direct SAM.gov exclusion/debarment query was not independently executed within this research session; the company's active FedRAMP authorization and U.S. Army Corps of Engineers sponsorship are inconsistent with debarred status but do not substitute for a direct query, which is recommended as a follow-up step.

RISK INDICATOR: Green - No confirmed sanctions, debarment, or restricted-party matches identified across all sources screened.

5. REGULATORY & LEGAL

A 1996 federal court decision, Baystate Technologies v. Bentley Systems, 946 F. Supp. 1079 (D. Mass. 1996), addressed trade secret misappropriation and copyright claims; the court found Bentley could be liable only if it knowingly benefited from a trade secret improperly obtained through a third party's confidential relationship, and concluded the plaintiff had not met its burden of proving copyright protection or substantial similarity.

This matter is resolved and historical, with a largely favorable outcome for Bentley on the copyright claim and no indication of ongoing exposure three decades later.

Bentley Systems was also named, among numerous other technology companies including Adobe, Oracle, and Samsung, as a defendant in a non-practicing-entity patent litigation campaign (SoftVault Systems, Inc. v. Bentley Systems Incorporated) asserting two patents; no outcome details were identified in available sources, and the breadth of defendants targeted is consistent with typical low-value NPE litigation rather than an entity-specific risk indicator.

Systematic Phase 3 searches for "Bentley Systems enforcement action," "lawsuit or settlement," "criminal or fraud or investigation," and "consent decree or debarment or suspension" returned no results specific to the company beyond the historical IP matters above.

No SEC enforcement actions, consent decrees, debarments, fines, or criminal matters against Bentley Systems, Incorporated were identified in PACER, CourtListener, or SEC EDGAR litigation searches, indicating no active regulatory or law-enforcement exposure as of the research date.

RISK INDICATOR: Yellow - Only historical, resolved civil IP litigation identified; no current enforcement, criminal, or regulatory exposure found.

6. ADVERSE MEDIA

Tier 2 wire service, national press, and trade publication searches identified no scandal, controversy, or reputational adverse media specific to Bentley Systems, Incorporated during this research cycle.

Numerous search results referencing unrelated "Bentley" entities β€” including Bentley Motors' trademark/patent litigation with Jaguar Land Rover, a Bentley University data breach attributable to third-party vendor Blackbaud, and a ransomware incident affecting an unrelated "Bentley Industries" β€” were identified and explicitly excluded per the identity-anchor protocol.

Bentley Systems is headquartered in the United States, rated "Free" by Freedom House with a top-tier Reporters Without Borders press freedom ranking, meaning no restricted-press-environment caveat applies to primary jurisdiction reporting.

China-based subsidiary and joint-venture activity warrants a caveat that independent media coverage of Chinese-entity dealings may be limited given China's "Not Free" Freedom House rating; the absence of adverse China-specific media should not be interpreted as a confirmed clean record for that market.

RISK INDICATOR: Green - No material adverse media identified specific to Bentley Systems, Incorporated.

7. FINANCIAL ASSESSMENT

Per Q1 2026 SEC filings and press releases, subscription revenues were $392.5 million, up 14.7% year-over-year (12.2% on a constant currency basis), with Annualized Recurring Revenue of $1,494.5 million as of March 31, 2026, compared to $1,319.3 million a year earlier.

Total Q1 revenue reached $424 million (+14.5% year-over-year), net revenue retention was 109%, and free cash flow was $188 million for the quarter ($492 million trailing twelve months), with full-year free cash flow guidance of $500-$570 million.

Operating margin was 29.8%, down modestly from 31.1% in the prior-year quarter, while free cash flow margin stood at 44.3%, both indicating a financially healthy SaaS business model despite a slight profitability compression.

Bentley repaid the $678 million principal balance of its 0.125% Convertible Senior Notes due 2026 at maturity, funded through cash on hand and $610 million drawn from previously unused revolving credit facilities, while repurchasing $54 million of stock; net leverage declined to approximately 2.2x, trending toward 1.9x, within the company's target range, with approximately $700 million in additional credit line availability remaining.

The company still carries $575 million of 0.375% Convertible Senior Notes due mid-2027, representing a known future maturity to monitor, though no going-concern opinions, bankruptcy filings, liens, or judgment liens were identified for Bentley Systems, Incorporated.

No public corporate credit rating from Moody's, S&P, or Fitch was identified in available search results; this is noted as Insufficient Data rather than an adverse finding, as it may reflect financing primarily through convertible notes and equity rather than rated debt, and should be confirmed directly with a ratings-agency subscription database.

RISK INDICATOR: Green - Strong revenue growth, declining leverage, and robust free cash flow generation with no adverse solvency indicators identified.

8. GEOPOLITICAL RISK

Jurisdictional Environment: Tier 1 - United States primary jurisdiction reflects strong rule of law, a robust and transparent regulatory framework, and low corruption risk for Bentley Systems' Delaware/Pennsylvania corporate base.

China operations (Beijing, Hong Kong, Shanghai) fall within a Tier 4 elevated-risk jurisdiction given ongoing US-China trade tensions, export control alignment concerns, and Bentley's stated pursuit of joint ventures with Chinese entities to offer local products leveraging Bentley technology, as disclosed in a June 2023 BusinessWire release.

This China joint-venture strategy warrants close monitoring for deemed-export and technology-transfer compliance risk, particularly in light of the current tightened U.S. Bureau of Industry and Security regulatory environment discussed further in Section 9(a).

New Zealand (Seequent subsidiary) is a Tier 1 low-risk jurisdiction, while India, Indonesia, Malaysia, and Mexico are Tier 3 moderate-risk jurisdictions standard for a global SaaS distribution model, with no entity-specific adverse findings identified in any of these markets.

Ireland functions as a Tier 1/2 EU regulatory hub governed by GDPR, presenting comparatively low geopolitical risk relative to the China operations.

No exposure was identified to FATF grey/black-listed jurisdictions, US-sanctioned countries (Iran, Russia, Cuba, North Korea, Syria, Venezuela), or state-owned-enterprise control, limiting the geopolitical risk profile principally to the China nexus described above.

RISK INDICATOR: Orange - China joint-venture and technology-distribution activity presents elevated export-control and geopolitical monitoring needs amid tightening BIS regulations.

9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY)

a) EXPORT CONTROLS

No matches were identified for Bentley Systems on the BIS Entity List, and no active BIS investigations or consent agreements were identified in available search results, indicating no current confirmed export control enforcement exposure.

The BIS's September 2025 rule expanding Entity List and Military End User List restrictions to affiliates at least 50% owned by listed entities represents a general regulatory development rather than an entity-specific finding, but is directly relevant given Bentley's Chinese subsidiary and joint-venture activity described in Section 8.

This affiliates rule should be actively monitored in relation to Bentley's China-based joint ventures and local distribution arrangements, as any future ownership or affiliate relationship touching a listed entity could trigger downstream restrictions affecting the technology supplied to Bentley's global customer base.

No Foreign-Direct Product Rule or semiconductor-related exposure was identified, consistent with Bentley's status as a software company rather than a chip or hardware manufacturer, somewhat narrowing the practical scope of export control risk relative to hardware-oriented technology suppliers.

RISK INDICATOR: Orange - China joint-venture technology distribution creates monitoring exposure under new BIS affiliate-ownership rules absent any confirmed violation.

b) SANCTIONS SCREENING

As detailed in Section 4, systematic screening across OFAC, BIS, UN, EU, and UK sanctions lists identified no confirmed matches for Bentley Systems, Incorporated or its named executives.

No ownership or beneficial-interest links to Russia, Iran, North Korea, or other comprehensively sanctioned jurisdictions were identified in the corporate structure or subsidiary listings reviewed in Section 2 and Section 12.

The single false-positive match involving a sanctioned vessel named "Bentley" was verified as unrelated and excluded, and no other name-similarity issues were identified requiring further resolution.

Given the absence of confirmed matches and the company's transparent, Nasdaq-listed corporate structure, sanctions screening risk for this entity is assessed as low, subject to periodic rescreening as recommended in the risk assessment section.

RISK INDICATOR: Green - No confirmed sanctions matches identified; consistent with Section 4 findings.

c) DATA PRIVACY

No GDPR enforcement actions, CCPA/CPRA penalties, or documented data breaches specific to Bentley Systems, Incorporated were identified in available search results.

The company maintains an active Trust Portal disclosing its security and privacy posture, a Tier 3 self-reported source that is nonetheless corroborated by the presence of formal ISO 27701 privacy management certification discussed in Section 9(f) and Section 10.

Given Bentley's operations in the EU (Ireland) and other jurisdictions with data protection regimes, GDPR compliance obligations apply to relevant subsidiary operations, though no adverse enforcement history was identified to date.

The absence of identified breach history should be read as a positive indicator but is based on public-record visibility rather than an independent audit, and continued monitoring is warranted given the sensitivity of infrastructure and engineering data processed by Bentley's SaaS platforms.

RISK INDICATOR: Green - No data privacy enforcement actions or documented breaches identified.

d) CFIUS/FOREIGN INVESTMENT

No CFIUS filings or reviews were identified for Bentley Systems, Incorporated as a target of foreign investment; Bentley functions as the US-domiciled acquirer in relevant M&A activity rather than a foreign investment target.

The Seequent acquisition, a US outbound acquisition of a New Zealand company, required consent under the New Zealand Overseas Investment Act rather than a CFIUS review, and that consent was obtained without reported objection.

No adverse findings were identified in connection with any foreign investment review process applicable to Bentley's acquisition activity.

Given the absence of any CFIUS nexus and no adverse foreign-investment findings, this area does not present elevated risk to the arms-length supplier relationship.

RISK INDICATOR: Green - No CFIUS nexus identified; New Zealand Overseas Investment Act consent obtained without objection for the Seequent acquisition.

e) IP & TRADE SECRETS

As detailed in Section 5, the 1996 Baystate Technologies trade secret and copyright case was resolved with a largely favorable outcome for Bentley and presents no ongoing exposure.

The SoftVault Systems non-practicing-entity patent litigation, in which Bentley was named alongside numerous other major technology companies, has an undetermined outcome in available sources but is consistent with routine low-value NPE litigation rather than an indicator of unusual IP risk.

No current material IP disputes were identified with Bentley Systems as either plaintiff or defendant, and no allegations of trade secret theft or IP infringement involving Bentley as an active defendant were found in this research cycle.

Given the historical, resolved nature of identified IP litigation and the absence of any current dispute, IP and trade secret risk associated with this supplier is assessed as low but warrants continued monitoring given the company's central role in developing and licensing proprietary engineering software.'

RISK INDICATOR: Yellow - Only historical, resolved trade secret litigation and an undetermined-outcome NPE patent matter identified; no current exposure.

f) CYBERSECURITY

Bentley holds ISO 27001:2022 and ISO 27701 certifications applicable to its Managed Services platform products, and its SaaS multi-tenant products are covered by a SOC 2 Type II report, per the company's Trust Portal.

These are self-reported claims corroborated by standard industry certification practices and consistency with the company's status as an active FedRAMP-authorized federal software provider, discussed in Section 9(g).

No disclosed data breaches or ransomware incidents specific to Bentley Systems, Incorporated were identified in this research cycle, distinct from an unrelated "Bentley Industries" ransomware incident and a Bentley University/Blackbaud vendor breach, both of which were confirmed unrelated and excluded.

The combination of active, current-generation security certifications and an absence of identified breach history supports a favorable cybersecurity risk profile for this supplier relationship, though independent third-party audit confirmation beyond the company's own disclosures was not identified.

RISK INDICATOR: Green - Active ISO 27001/27701 and SOC 2 Type II certifications with no disclosed breaches identified.

g) GOVERNMENT CONTRACTS

ProjectWise and OpenGround achieved FedRAMP Authorization at the Moderate Impact Level in April 2026, sponsored by the U.S. Army Corps of Engineers, per company release corroborated by trade press coverage (MyChesCo).

USACE is described as a key user of OpenGround and the largest federal user of ProjectWise, serving as Bentley's federal sponsoring agency for the FedRAMP authorization process.

No FedRAMP suspension, CMMC deficiency finding, or federal contract debarment was identified for Bentley Systems, Incorporated in available search results.

This active federal government contracting relationship is a positive due-diligence indicator supporting supplier reliability and operational credibility, though it simultaneously raises the compliance bar for DFARS and CMMC applicability going forward, an area flagged for follow-up in Section 10.

RISK INDICATOR: Green - Active FedRAMP authorization and USACE federal sponsorship with no adverse findings identified.

h) AI/EMERGING TECH

Bentley has publicly stated it will not use customer data within the Bentley Infrastructure Cloud to train AI models without explicit customer consent, per a Yahoo Finance earnings-call summary.

No AI ethics controversies, algorithmic bias findings, or regulatory actions related to artificial intelligence use were identified for Bentley Systems, Incorporated in this research cycle.

This proactive data-use policy represents a positive indicator for customers concerned about proprietary data exposure through AI training pipelines, relevant given the requester's own data sensitivity as a manufacturing and industrials operator.

Given the early-stage nature of AI regulation generally, continued monitoring of Bentley's AI governance practices is warranted as new products and features are introduced, though no current adverse finding requires immediate action.

RISK INDICATOR: Green - No AI ethics controversies or regulatory actions identified; proactive customer-consent data policy is a positive indicator.

i) COMPETITION & PLATFORM REGULATION

Bentley Systems' primary competitors include Esri, Trimble, Autodesk, Oracle, and Aspen Technology, per Comparably aggregator data; several of these vendors, including Autodesk and Trimble, may also serve the requester's manufacturing and industrials sector competitors.

This shared-vendor dynamic is standard market practice for enterprise software providers and does not itself constitute an antitrust concern, but it raises a relationship-specific consideration regarding contractual IP-firewalling and data-segregation provisions given the requester's competitive sensitivities.

The Seequent acquisition required clearance under the Hart-Scott-Rodino Antitrust Improvements Act, which was obtained without reported objection, and no DOJ or FTC antitrust investigations were identified against Bentley Systems.

Bentley has not been identified as a designated gatekeeper under the EU Digital Markets Act or subject to Digital Services Act enforcement, further limiting platform-regulation exposure for this supplier.

RISK INDICATOR: Yellow - No antitrust violations identified, but shared-vendor relationships with competitors warrant contractual data-segregation monitoring.

10. CERTIFICATIONS & ACCREDITATIONS

a) QUALITY & MANAGEMENT SYSTEMS

No ISO 9001 quality management certification was identified for Bentley Systems, Incorporated in available search results, and this status is assessed as undetermined rather than adverse.

ISO 9001 and related quality-management certifications are less standard for pure-play software/SaaS companies compared to manufacturing entities, and the absence of a confirmed certification does not indicate non-compliance or operational deficiency for this business model.

b) INFORMATION SECURITY & DATA PROTECTION

Bentley holds active ISO 27001:2022 and ISO 27701 certifications applicable to its Managed Services platform products, and its SaaS multi-tenant products are covered by an active SOC 2 Type II report, per the company's Trust Portal.

These certifications, while self-reported by the company, are consistent with standard industry certification practices for enterprise SaaS providers and corroborate the absence of any disclosed data breach or privacy enforcement action identified elsewhere in this report.

c) INDUSTRY/SECTOR-SPECIFIC CERTIFICATIONS

CMMC certification status remains unconfirmed for Bentley Systems, Incorporated; the DoD CMMC rule became effective for Phase 1 requirements in November 2025, and no Bentley-specific CMMC certification was identified in available search results.

No Better Business Bureau accreditation was identified in search results, assessed as Insufficient Data rather than an adverse finding; given Bentley's federal contracting relationship discussed in Section 9(g), confirming CMMC roadmap status directly with the company is recommended.

d) GOVERNMENT/PUBLIC SECTOR AUTHORIZATIONS

ProjectWise and OpenGround hold active FedRAMP Authorization at the Moderate Impact Level as of April 2026, sponsored by the U.S. Army Corps of Engineers, corroborated by both company release and independent trade press coverage.

This active federal authorization, combined with USACE's role as the largest federal user of ProjectWise, represents a materially positive indicator of Bentley's operational rigor and government-grade security posture relevant to the requester's own supply chain assurance needs.

e) CERTIFICATION CURRENCY

The identified ISO 27001:2022, ISO 27701, SOC 2 Type II, and FedRAMP authorizations all appear current and active as of the most recent 2025-2026 source dates reviewed, with no indication of lapse or suspension.

By contrast, the company's Bloomberg LEI registration lapsed administratively in January 2024 (noted in Section 1); while unrelated to the security/quality certifications above, this administrative gap should be confirmed and renewed to avoid downstream complications in financial counterparty screening.

RISK INDICATOR: Green - Multiple active, current-generation security and government-authorization certifications identified with no adverse findings; gaps in quality-management certification are not indicative of non-compliance for a SaaS business model.

11. CONFLICTS OF INTEREST

Founder-family members retain concentrated control through Class B super-voting shares, as detailed in Section 2, with Corinne Bentley (13.2%) and Raymond Bentley holding significant direct and indirect stakes; this is a governance characteristic requiring disclosure but is standard for dual-class public companies and not itself an adverse finding.

No specific related-party transaction concerns were identified in available search results; however, full related-party disclosure would require direct review of the company's DEF 14A proxy statement, which was not independently reviewed in this research cycle and is noted as Insufficient Data.

The 2024 transition from founder-family CEO leadership to a non-family CEO was handled transparently via public announcement and an evident succession plan, with no governance red flags identified in connection with this transition.

As discussed in Section 9(i), Bentley serves multiple competitors within the AEC/infrastructure software space, including vendors that may also serve the requester's manufacturing and industrials competitors; no evidence of preferential treatment or antitrust concern was identified, but the requester should evaluate data-segregation and IP-firewall contractual protections given this shared-vendor exposure.

RISK INDICATOR: Yellow - Founder-family voting control and shared-vendor relationships with competitors are identified monitoring items, with related-party transaction detail not independently confirmed.

12. RELATED & ASSOCIATED ENTITIES

Bentley Systems, Incorporated has no parent company; it is itself the top-level publicly traded entity on Nasdaq (BSY).

Seequent (Seequent Holdings Limited), founded and headquartered in Christchurch, New Zealand, operates as a stand-alone Bentley subsidiary following the June 2021 acquisition, with more than 430 colleagues across 16 office locations serving over 100 countries; Seequent has made further acquisitions including Aarhus GeoSoftware (Denmark), Minalytix (Canada), and Advanced Resources and Risk Technology/AR2Tech (Denver).

Additional subsidiaries identified across corporate registries and company sources include Bentley Software, Inc.; BSI Holdings B.V. and Plaxinvest B.V. (Netherlands); Digital Water Works, Inc.; Bentley Systems Singapore Pte Ltd; Bentley Systems (Malaysia) Sdn. Bhd.; SRO Solutions Limited (UK); Bentley Systems Pakistan (Pvt.) Limited; Bentley Systems Beijing Co., Ltd. and Bentley Engineering Software Systems (Shanghai) Co. Ltd.; Bentley Systems International Ltd. (Ireland); Bentley Systems de Mexico SA de CV; and Vetasi Sp. z o.o. (Poland), among approximately 94 known corporate group entries.

Corinne Patricia Bentley is identified as a significant shareholder holding 13.2% of Class B shares as of March 31, 2026, per SEC Schedule 13G/A filings, consistent with the founder-family ownership concentration discussed in Section 2 and Section 11.

No adverse findings were identified specifically implicating Seequent or any other Bentley subsidiary in this research cycle; risk findings in this report pertain principally to Bentley Systems, Incorporated as the contracting parent entity.

RISK INDICATOR: Green - No adverse findings identified for Bentley's subsidiaries or significant shareholders; corporate structure is transparent and well-documented.

13. AREAS OF SPECIAL INTEREST

13a) Supply Chain & Logistics Security

Bentley Systems is a software/SaaS provider rather than a physical goods manufacturer, meaning traditional supply chain security concepts such as C-TPAT participation, conflict minerals/3TG sourcing, cargo theft, and CBP port-of-entry holds are largely not applicable to its core business model.

No UFLPA, Withhold Release Order, or conflict-minerals findings were identified for Bentley Systems itself in this research cycle, consistent with its software-centric operations.

Seequent's mining-sector customer base and geoscience software could carry indirect exposure to customers' mineral sourcing practices, though this reflects customer-side exposure rather than a finding against Bentley's own supply chain.

A material gap exists regarding Bentley's own technology supply chain: no specific disclosure was identified regarding cloud infrastructure or hosting vendor concentration, representing a third-party technology dependency relevant to service continuity that could not be assessed with available sources.

RISK INDICATOR: Insufficient Data - Cloud infrastructure/hosting vendor concentration and dependency risk could not be determined from available sources.

13b) Financial Stability

As detailed in Section 7, Bentley Systems demonstrates strong subscription revenue growth (+14.7% year-over-year), Annualized Recurring Revenue growth to $1,494.5 million, and net revenue retention of 109%, indicating a financially stable and growing SaaS operation.

Net leverage has declined to approximately 2.2x, trending toward a 1.9x target, following the successful repayment of $678 million in convertible notes at their 2026 maturity, funded through cash on hand and revolving credit facility drawdowns.

No bankruptcy filings, going-concern opinions, liens, or judgment liens were identified for Bentley Systems, Incorporated, and the company maintains approximately $700 million in additional credit availability, supporting business continuity capacity.

The absence of a public corporate credit rating from Moody's, S&P, or Fitch is noted as Insufficient Data on that specific point, but does not offset the otherwise strong financial indicators identified across multiple Tier 1 and Tier 2 sources.

RISK INDICATOR: Green - Strong revenue growth, declining leverage, and no adverse solvency indicators identified.

13c) Technology, IP & Data Risk

As detailed in Sections 5 and 9(e), Bentley's only identified IP litigation history consists of a resolved 1996 trade secret/copyright case and an undetermined-outcome NPE patent action naming numerous other major technology companies, indicating low current IP dispute risk.

Active ISO 27001:2022, ISO 27701, and SOC 2 Type II certifications, discussed in Sections 9(f) and 10, provide a structured information security and data protection framework, with no disclosed data breaches identified specific to Bentley Systems.

Given Bentley's central role in processing and hosting proprietary infrastructure engineering data for its global customer base, the requester should weigh the absence of confirmed breach history against the fact that these certifications are self-reported by the company rather than independently corroborated by a third-party regulator.

The combination of resolved historical IP matters and active, current security certifications supports a measured risk profile for this dimension, requiring ongoing monitoring rather than immediate concern.

RISK INDICATOR: Yellow - Historical resolved IP matters and active security certifications identified, with no independent third-party breach corroboration.

13d) Labor, Human Rights & Anti-Slavery

Bentley has published a UK Modern Slavery Act statement affirming a zero-tolerance policy for human trafficking and slavery in its supply chain, along with processes to communicate this policy, and references its Code of Conduct and Employee Handbook as guideposts for ethical business conduct.

No OSHA, NLRB, Department of Labor Wage and Hour Division, or EEOC enforcement actions were identified against Bentley Systems, Incorporated in available search results, indicating no confirmed labor-law violations.

As a self-reported company statement, the Modern Slavery Act policy was not independently corroborated by third-party audit in available sources, representing a specific verification gap given the requester's own labor and human rights due diligence obligations that may flow down to suppliers.

This gap is assessed as a concrete monitoring trigger rather than a general visibility limitation, warranting direct follow-up with Bentley to obtain independent audit evidence supporting its stated policy commitments.

RISK INDICATOR: Yellow - Self-reported Modern Slavery Act statement lacks independent third-party audit corroboration; no confirmed labor violations identified.

13e) Geopolitical & Regulatory Risk

As detailed in Section 8, Bentley's primary risk concentration lies in its China operations and joint-venture technology distribution strategy, which merits enhanced due diligence given the current US-China export control tightening trend, including the BIS's September 2025 affiliates rule discussed in Section 9(a).

Bentley's remaining global footprint spans predominantly Tier 1 and Tier 3 jurisdictions (United States, Ireland, New Zealand, India, Indonesia, Malaysia, Mexico) with no entity-specific adverse findings identified, limiting the overall geopolitical risk profile principally to the China nexus.

No exposure to FATF grey/black-listed jurisdictions or comprehensively sanctioned countries was identified, reinforcing that geopolitical risk for this supplier is concentrated and identifiable rather than diffuse.

Given the requester's Manufacturing & Industrials sector context, continuity of Bentley's engineering software services could be affected by any future escalation in US-China technology transfer restrictions, warranting inclusion of contingency planning in the ongoing relationship management.

RISK INDICATOR: Orange - China joint-venture and export control exposure represents the principal identified geopolitical risk concentration for this supplier.

RISK INDICATOR SUMMARY
SECTIONRISK INDICATOR
1. ENTITY INFORMATIONYellowCore corporate identity is well-corroborated across primary sources, but an administratively lapsed LEI registration requires renewal confirmation.
2. OWNERSHIP & STRUCTUREGreenOwnership structure is transparent and standard for a US dual-class public company, with no adverse findings identified.
3. KEY PERSONNELGreenNo regulatory or enforcement history identified for any named executive; the 2024 leadership transition was orderly and transparent.
4. SANCTIONS & CONTROLS SCREENINGGreenNo confirmed sanctions, debarment, or restricted-party matches identified across all sources screened.
5. REGULATORY & LEGALYellowOnly historical, resolved civil IP litigation identified; no current enforcement, criminal, or regulatory exposure found.
6. ADVERSE MEDIAGreenNo material adverse media identified specific to Bentley Systems, Incorporated.
7. FINANCIAL ASSESSMENTGreenStrong revenue growth, declining leverage, and robust free cash flow generation with no adverse solvency indicators identified.
8. GEOPOLITICAL RISKOrangeChina joint-venture and technology-distribution activity presents elevated export-control and geopolitical monitoring needs amid tightening BIS regulations.
9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY)See individual sub-section risk indicators in report body
10. CERTIFICATIONS & ACCREDITATIONSGreenMultiple active, current-generation security and government-authorization certifications identified with no adverse findings; gaps in quality-management certification are not indicative of non-compliance for a SaaS business model.
11. CONFLICTS OF INTERESTYellowFounder-family voting control and shared-vendor relationships with competitors are identified monitoring items, with related-party transaction detail not independently confirmed.
12. RELATED & ASSOCIATED ENTITIESGreenNo adverse findings identified for Bentley's subsidiaries or significant shareholders; corporate structure is transparent and well-documented.
13. AREAS OF SPECIAL INTERESTSee individual sub-section risk indicators in report body
RISK ASSESSMENT

Key Risk Factors:

β€’ No sanctions or restricted-party matches identified for Bentley Systems or its executives.

β€’ China joint-venture strategy raises export control and technology-transfer monitoring needs.

β€’ Founder-family super-voting shares concentrate governance control among Bentley family members.

β€’ Shared vendor relationships with competing AEC software customers raise data-segregation considerations.

β€’ Self-reported Modern Slavery Act statement lacks independent third-party audit verification.

β€’ LEI registration lapsed administratively as of January 2024, requiring renewal confirmation.

β€’ No public corporate credit rating identified from Moody's, S&P, or Fitch.

β€’ Historical trade secret litigation from 1996 resolved favorably with no ongoing exposure.

β€’ Strong recurring revenue growth and reduced leverage indicate low counterparty default risk.

β€’ Active FedRAMP authorization and USACE sponsorship demonstrate strong operational credibility.

Recommendations:

1. Request confirmation of current LEI registration renewal status directly from GLEIF given the identified January 2024 lapse.

2. Obtain direct SAM.gov exclusion query results to corroborate active federal contracting eligibility alongside the FedRAMP/USACE relationship.

3. Request Bentley's most recent DEF 14A proxy statement for full related-party transaction disclosure review given founder-family governance concentration.

4. Confirm Bentley's CMMC certification roadmap given the DoD Phase 1 rule effective November 2025 and Bentley's active federal contracting relationship.

5. Request third-party audit evidence supporting Bentley's UK Modern Slavery Act compliance statement given the lack of independent corroboration.

6. Include contractual IP-firewall and data-segregation clauses in any agreement given Bentley's shared-vendor relationships with the requester's competitors.

7. Establish an ongoing monitoring protocol for Bentley's Chinese joint-venture activities against BIS's September 2025 affiliates rule.

Monitoring Needs:

β€’ Periodic (semi-annual or annual) sanctions and restricted-party rescreening for Bentley Systems and its key executives.

β€’ Ongoing monitoring of BIS Entity List and affiliates rule developments affecting Bentley's China operations and joint ventures.

β€’ Tracking of Bentley's remaining 2027 convertible note maturity and overall leverage trend.

β€’ Monitoring of Bentley's CMMC certification progress relevant to any government-adjacent supply chain requirements.

β€’ Periodic review of litigation and adverse media databases for new filings involving Bentley Systems, Incorporated.

Recommended Action: Proceed with the arms-length supplier/service provider relationship subject to completion of the recommended follow-up due diligence items, particularly confirmation of LEI status, a direct SAM.gov exclusion query, and enhanced monitoring of China-related export control exposure.
RECOMMENDED FOLLOW-UP QUESTIONS

Based on the findings in this report, the following questions should be addressed through direct inquiry with the entity or additional research:

1. Can Bentley Systems confirm current LEI registration renewal status following the identified January 2024 lapse?

2. What specific cloud infrastructure or hosting providers does Bentley rely on for SaaS delivery, and what vendor concentration risk exists?

3. Can Bentley provide documentation of independent third-party labor or human rights audits supporting its Modern Slavery Act statement?

4. What is Bentley's current CMMC certification status or roadmap given the DoD Phase 1 rule effective November 2025?

5. Can Bentley disclose the ownership structure and technology-transfer safeguards governing its Chinese joint ventures and local distribution arrangements?

6. What contractual data-segregation or IP-firewall provisions does Bentley offer to customers who compete with other Bentley customers?

7. Can Bentley confirm whether it holds or intends to obtain a public corporate credit rating from Moody's, S&P, or Fitch?

8. What related-party transactions, if any, are disclosed in Bentley's most recent DEF 14A proxy statement involving founder-family members?

9. Has Bentley conducted a direct SAM.gov exclusion check, and can results be provided to corroborate active federal contractor status?

10. What business continuity and disaster recovery provisions does Bentley maintain for critical ProjectWise and OpenGround service delivery to government and industrial customers?

SOURCES CONSULTED

Government & Regulatory Databases:

β€’ OFAC SDN List / Sanctions List Service (ofac.treasury.gov) - no matches

β€’ BIS Entity List (bis.doc.gov/bis.gov) - no matches

β€’ SEC EDGAR (sec.gov/edgar) - results returned; used for entity identification, ownership, and financial data

β€’ SEC Litigation/Enforcement (sec.gov/litigation, sec.gov/enforcement-litigation) - no matches against subject entity; unrelated individuals identified and excluded

β€’ OpenSanctions.org - one false-positive match identified and excluded

β€’ SAM.gov - not directly queried in this session; status inferred from corroborating FedRAMP/USACE relationship

β€’ OIG List of Excluded Individuals/Entities (HHS) - no matches, not applicable to industry

β€’ World Bank debarment list - no matches

β€’ Interpol Red Notices - no matches

β€’ UN Security Council consolidated sanctions list - no matches

β€’ EU consolidated sanctions list - no matches

β€’ UK HM Treasury sanctions list - no matches

β€’ FDA Debarment List - not applicable, no matches

β€’ CFTC/FinCEN enforcement databases - no matches

Court & Legal Records:

β€’ Justia federal court opinions - Baystate Technologies v. Bentley Systems (1996) identified, resolved

β€’ RPX Insight patent litigation database - SoftVault Systems v. Bentley Systems identified, undetermined outcome

β€’ Law360 and legal blogs - unrelated Bentley Motors/Jaguar litigation identified and excluded

β€’ PACER/CourtListener federal court records - no criminal or regulatory enforcement matters identified

News & Media:

β€’ BusinessWire - extensive company press releases reviewed (executive changes, FedRAMP, Seequent acquisition, financial results)

β€’ Yahoo Finance - Q1 2026 earnings coverage and AI data-use policy statement

β€’ Investing.com and Barchart - convertible note repayment and leverage coverage

β€’ StockTitan and IndexBox - Q1 2026 financial results coverage

β€’ MyChesCo - FedRAMP/USACE trade press coverage

Business Registries & Financial:

β€’ SEC EDGAR 10-K/10-Q/proxy and Form 4/Schedule 13G filings (fiscal years 2020-2026) - results returned

β€’ OpenCorporates - Delaware registry and subsidiary listing cross-referenced

β€’ Bloomberg LEI / GLEIF (legalentityidentifier.com, lei.bloomberg.com) - LEI lapse identified

β€’ Nasdaq and Fintel - institutional ownership data reviewed, no adverse findings

β€’ Morningstar - analyst commentary on Seequent/resources segment reviewed

Industry-Specific Sources:

β€’ Bentley Systems Trust Portal (trustportal.bentley.com) - ISO 27001/27701 and SOC 2 Type II certification claims reviewed, self-reported

β€’ Bentley.com/legal/modern-slavery-act - company Modern Slavery Act statement reviewed, self-reported

β€’ Govly and SamSearch - FedRAMP/government contracting trade coverage reviewed

β€’ Accel-KKR press release - Seequent transaction terms reviewed

β€’ Comparably and Craft.co - competitor and executive profile data reviewed

LIMITATIONS & RECOMMENDED NEXT STEPS

This report is based on publicly available information accessible through web search. The following limitations apply:

Information Not Accessible:

β€’ Proprietary databases (e.g., LexisNexis, World-Check, Dow Jones Risk & Compliance)

β€’ Non-public court records and sealed proceedings

β€’ Confidential regulatory examination results

β€’ Private company financial statements

β€’ Non-English language sources (limited coverage)

β€’ Real-time sanctions list updates (recommend independent verification)

β€’ International jurisdiction coverage: the depth and reliability of open-source intelligence varies significantly by jurisdiction, entity type, disclosure requirements, press freedom, and corporate registry accessibility. See firstcheck.app for full details.

Recommended Additional Due Diligence:

1. Confirm Bentley's active LEI registration status directly through GLEIF given the identified administrative lapse.

2. Execute a direct SAM.gov exclusion query to corroborate active federal contractor eligibility.

3. Request and review Bentley's most recent DEF 14A proxy statement for related-party transaction disclosures.

4. Request evidence of independent audit corroboration for Bentley's Modern Slavery Act compliance statement.

5. Establish a monitoring protocol for BIS Entity List and affiliates rule developments relevant to Bentley's China joint ventures.

6. Negotiate contractual IP-firewall and data-segregation provisions given Bentley's shared-vendor relationships with competitors.

7. Verify sanctions status through direct OFAC/BIS database query.

This report is valid as of the report date. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.

DISCLAIMER

FirstCheck.App is a first-level third party intelligence and risk assessment tool. It is not a substitute for formal investigation, professional review, or expert compliance determinations. Report findings should be evaluated by business managers, subject matter experts, and professionals in the context of the organization's risk tolerance, policies, directives, and approaches. FirstCheck.App reports may be retained as part of the organization's third-party risk management program, including its applicable record-keeping practices.

Β© 2026 FirstCheck.App. All rights reserved.


APPENDIX A β€” SANCTIONS & CONTROLS DATABASES SCREENED

This report reflects research conducted across the following databases. Individual databases are identified in Section 4 only when a match or potential match is found.

TIER 1 β€” Direct Web Research (Conducted on Every Report)

1.OFACSpecially Designated Nationals (SDN) List
2.OFACNon-SDN Lists (SSI, FSE, NS-MBS, PLC, and related)
3.BISEntity List
4.BISDenied Persons List
5.BISUnverified List
6.U.S. State DepartmentDebarred Parties List (ITAR)
7.OIGList of Excluded Individuals/Entities (LEIE)
8.GSA SAM.govSystem for Award Management Exclusions
9.DEAControlled Substances Act Exclusions
10.CMSState Medicaid Exclusion Lists (composite)
11.FDADebarment List
12.SECEnforcement Actions Database
13.CFTCEnforcement Actions
14.FinCENEnforcement Actions
15.FBIMost Wanted
16.InterpolRed Notices
17.UN Security CouncilConsolidated Sanctions List
18.European UnionConsolidated Sanctions List
19.UK HM TreasurySanctions List
20.World BankDebarment List
21.Asian Development BankSanctions List
22.OpenSanctionsConsolidated Database

TIER 2 β€” Web Research Based (Conducted Where Relevant)

1.FATFGrey List (Jurisdictions Under Increased Monitoring)
2.FATFBlack List (High-Risk Jurisdictions β€” Call for Action)
3.SECOSanctions List (Switzerland)
4.MASSanctions List (Singapore)
5.DFATSanctions List (Australia)
6.Global Affairs CanadaSanctions List
7.Japan METI/MOFASanctions and Export Control Lists
8.France TRESORDirection GΓ©nΓ©rale du TrΓ©sor Sanctions
9.Germany BAFAExport Control and Sanctions Lists
10.UAESanctions List
11.IsraelSanctions List
12.ICIJOffshore Leaks Database (Panama Papers, Pandora Papers)
13.Transparency InternationalCorruption Perceptions Index (CPI)
14.Basel InstituteAML Index
15.ACAMSWatchlist (open-source tier)
16.South Korea MOFATSanctions List
17.Inter-American Development BankSanctions List

Tier 1 databases are researched on every report. Tier 2 databases are researched based on entity jurisdiction, industry, and risk profile. This screening is conducted through open-source web research and does not constitute direct real-time database queries. Independent verification against all applicable databases is required before entering into any business relationship or transaction.


APPENDIX B β€” RISK RATING METHODOLOGY

Risk ratings reflect a qualitative assessment of the severity, recency, and regulatory relevance of identified issues.

Red β€” Critical Risk
Confirmed regulatory enforcement, sanctions violations, or systemic control failures with material impact requiring immediate attention or enhanced approval.
Orange β€” Significant Concerns
Significant regulatory, legal, or reputational issues requiring enhanced due diligence, ongoing monitoring, or senior management approval before proceeding.
Yellow β€” Minor Issues
Historical concerns now resolved, manageable risks, or areas requiring periodic monitoring but not blocking engagement.
Green β€” No Adverse Findings
No material adverse findings identified in available open-source information. Standard onboarding procedures apply.
Insufficient Data
Limited publicly available information to assess risk. Additional research or direct inquiry recommended.
Risk Indicator Summary
Section-level risk indicators are assigned independently for each of the 13 report sections. Each indicator reflects findings specific to that section. The Risk Indicator Summary table provides a consolidated view of all section-level indicators.

REPORT METADATA
Report ID:FC-20260723-220323
Date Generated:2026-07-23 22:03:23 UTC
FirstCheck.App Version:v2.12.66
Entity Analyzed:Bentley Systems
Jurisdiction:United States
Relationship Type:Arms-Length Supplier / Service Provider
Client Industry:Manufacturing & Industrials
Subject Industry (Verified):Technology
Reason for Inquiry:New Entity Check

This report is valid as of the date generated. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.


THIRD-PARTY REVIEW FORM
Reviewer Assessment
Entity Reviewed: Bentley Systems    Report ID: FC-20260723-220323    Report Date: 2026-07-23 22:03:23 UTC
Acceptable: Okay to proceed.
Caution: Monitoring and oversight recommended.
Pending: Verify and resolve before proceeding.
Full Review: Conduct full background due diligence before proceeding.
Unacceptable: Do not proceed.
Other/Comment:
Recommended Frequency of Third Party Assessment Reports
Every month
Every three months
Every six months
Annually
Other:
Additional Reviewer Comments
Reviewer Certification

The undersigned has reviewed this Third Party Assessment Report and confirms that the risk decision and recommendations above are based on the information provided and professional judgment.

Signature
Date
Reviewer Name
Title

This form should be completed by the designated reviewer and retained with the FirstCheck.App report as part of the organization's third party review records.

πŸ“‹ To download this form in fillable format: firstcheck.app/review-form.html