2026-07-24 10:19 (2026-07-24 15:19 UTC)
Report ID: FC-20260724-151948
FirstCheck.Appβ„’
Third Party Intelligence and Risk Assessment
Subject Entity
Bentley Systems
Industry: Technology  |  Jurisdiction: United States (Delaware)

THIRD PARTY ASSESSMENT REPORT
REQUESTER INFORMATION
FirstCheck.App, Sample Report
Purpose: New Entity Check
Report Generated:2026-07-24 10:19 (2026-07-24 15:19 UTC)
Entity Analyzed:Bentley Systems
Jurisdiction:United States (Delaware)
Relationship Type:Joint Venture / Strategic & Licensing Partner
Client Industry:Manufacturing & Industrials
Subject Industry (Verified):Technology
Areas of Special Interest:Environmental Risk & Liabilities, Technology, IP & Data Risk, Supply Chain & Logistics Security, Litigation & Legal Exposure, Defense & Export Controls, Business Continuity & Resilience, Compliance Vulnerability, Geopolitical & Regulatory Risk, Financial Stability, Labor, Human Rights & Anti-Slavery
FIRSTCHECK.APP AND METHODOLOGY
This report was compiled using FirstCheck.App's proprietary Third-Party Risk Assessment Methodology, leveraging structured open-source research across publicly available databases, sanctions lists, corporate registries, and authoritative media sources. All findings are governed by FirstCheck.App Integrity Standards which require source transparency, cross-reference corroboration, verified findings, analytical neutrality, and verification transparency. Full standards are available at FirstCheck.app. Risk indicators in the report use a five-level color system (Red, Orange, Yellow, Green, and Insufficient Data) defined in Appendix B of this report. Conclusions drawn from this report should be validated through further investigation, direct inquiry, and professional judgment before any business or compliance decision is made.
CONFIDENTIALITY
This report is confidential and proprietary. It has been prepared exclusively for the requesting party and their authorized representatives. It may not be shared, reproduced, distributed, or disclosed to any third party without the express written authorization of the requester. Unauthorized use or disclosure may violate applicable law.

TABLE OF CONTENTS

Click on any item to navigate to that section.

Executive Summary
1.   Entity Information
2.   Ownership & Structure
3.   Key Personnel
4.   Sanctions & Controls Screening
5.   Regulatory & Legal
6.   Adverse Media
7.   Financial Assessment
8.   Geopolitical Risk
9.   Industry-Specific Risks
10.   Certifications & Accreditations
11.   Conflicts of Interest
12.   Related & Associated Entities
13.   Areas of Special Interest
Risk Indicator Summary
Summary Risk Assessment
Recommended Follow-Up Questions
Sources Consulted
Limitations & Recommended Next Steps
Disclaimer
Appendix A β€” Sanctions & Controls Databases Screened
Appendix B β€” Risk Rating Methodology
Third-Party Review Form

Note: This report does not include page numbers as section breaks vary by browser and device.


EXECUTIVE SUMMARY

Bentley Systems, Incorporated is a Delaware-incorporated, Pennsylvania-headquartered developer of infrastructure engineering, geospatial modeling, and asset performance management software, publicly traded on the Nasdaq Global Select Market under the ticker symbol BSY, with reported fiscal year 2024 revenue of $1.35 billion generated across 189 countries worldwide. The company maintains development, sales, and operational functions in more than 50 countries, including a regional headquarters in Dublin, Ireland, an Asia headquarters in Beijing, China, and the wholly owned Seequent Limited geoscience modeling software subsidiary headquartered in Christchurch, New Zealand and comprising more than 430 colleagues across 16 office locations, acquired in 2021 for $900 million in cash plus 3,141,342 shares of Class B common stock. This report evaluates Bentley Systems, Incorporated for consideration as a Joint Venture / Strategic & Licensing Partner by a requester operating in the Manufacturing & Industrials sector, a relationship category that entails shared legal, financial, technology-transfer, governance, and reputational exposure substantially broader in scope than a standard vendor, supplier, or licensing arrangement.

This relationship carries no confirmed sanctions, export-control, or restricted-party exposure following screening across OFAC, BIS, UN, EU, and UK Treasury lists, though Bentley's Beijing office and China revenue base elevate technology-diversion risk for shared technology access.

This engagement operates within an environment of escalating US-China export-control tightening on advanced computing items, and Bentley's Tier 4 China jurisdiction presence, combined with company management's public disclosure of separately reported China ARR softness, creates geopolitical exposure for technology-sharing continuity.

This relationship's governance leverage is constrained by Bentley Family voting control of approximately 67.4% of total voting power and controlled-company board exemptions under Nasdaq rules, limiting the requester's ability to influence strategic direction or dispute resolution in a joint venture.

This engagement benefits from Bentley's improved FY2025 operating margin of 20.0%, free cash flow of $520 million, and reduced net debt leverage of 2.1 times following convertible note retirement, supporting confidence in its capacity to meet shared financial obligations.

This relationship faces workforce-continuity monitoring needs given Bentley's documented recurring restructuring pattern, including a $12.6 million Q4 2023 severance charge affecting under five percent of staff and uncorroborated employee-sentiment reports of repeated large-scale layoffs affecting personnel retention.

This engagement carries a favorable reputational baseline, as no material adverse media, securities class action litigation, sanctions matches, or regulatory enforcement actions were identified against Bentley Systems across the government, court, and media sources reviewed for this assessment.

Risk Summary:

Sanctions Screening: No sanctions or restricted-party matches identified for Bentley Systems, Incorporated or its named executives; one name-only false positive (a sanctioned vessel) was identified and resolved as unrelated.

Regulatory Risk: None active; one historical/undetermined-outcome trademark (TTAB) dispute noted, with no SEC, antitrust, or other regulatory enforcement identified.

Adverse Media: Minor; adverse media relates primarily to recurring workforce restructuring, with no material findings on corruption, fraud, or safety.

Financial Risk: Stable, with improving margins, reduced leverage, and strong free cash flow, though public credit rating status is undetermined.

β†’ See Section-by-Section Risk Indicator Summary

1. ENTITY INFORMATION

Name: Bentley Systems, Incorporated

Country: United States

Business Type: Publicly traded enterprise software company (Nasdaq: BSY)

Website: Not specified in the research notes reviewed

Industry: Infrastructure engineering, geospatial modeling, and asset performance management software

Headquarters: Exton, Pennsylvania, United States

Known Locations: Principal offices at 685 Stockton Drive, Exton, Pennsylvania; Bentley Systems International Limited at 2 Park Place, Upper Hatch Street, Dublin 2, Ireland; Asia headquarters at Bentley Engineering Software Systems, Unit 1402-06, Tower 1 China Central Place, Beijing 100022, China; Seequent Limited headquartered in Christchurch, New Zealand with more than 430 colleagues across 16 office locations; development, sales, and other departments in more than 50 countries worldwide.

Bentley Systems, Incorporated was originally incorporated in California in 1984 upon its founding and was subsequently reincorporated in Delaware in 1987, per SEC 10-K filings (Tier 1 source).

The company reported revenue of $1.35 billion for fiscal year 2024, generated across 189 countries, corroborated by both company disclosures and SEC filings (Tier 1/2 sources).

The Beijing, China office represents a Tier 4 jurisdictional risk location relative to the company's Tier 1 US, Irish, and New Zealand facilities; Bentley management disclosed in its Q4 2024 earnings call that year-over-year constant-currency ARR growth of 12% compared with 12.5% growth excluding China, indicating China-specific revenue softness with second-order relevance for any JV partner dependent on stable, geographically diversified revenue performance.

The Dublin, Ireland regional headquarters operates within the EU regulatory regime, including GDPR and EU sanctions frameworks, and presents low incremental jurisdictional risk consistent with other Tier 1 operating locations.

The Seequent subsidiary's New Zealand headquarters and associated global office network are described in company materials as serving over 100 countries and are expected to expand Bentley's presence in mineral-intensive geographies, while Bentley's existing China presence is expected to accelerate Seequent's market expansion, an explicit company-disclosed China growth nexus relevant to combined-entity risk exposure.

RISK INDICATOR: Yellow - Beijing office location and disclosed China revenue softness introduce jurisdiction-specific monitoring considerations despite an otherwise well-documented identification profile.

2. OWNERSHIP & STRUCTURE

Bentley Systems maintains a dual-class share structure in which each share of Class A common stock carries 29 votes and is convertible into one share of Class B common stock; following its IPO, Class A holders held approximately 57.4% of voting power, and the Bentley Control Group held or could control approximately 67.4% of voting power, qualifying the company as a 'controlled company' under Nasdaq Listing Rules.

As of the most recent 2026 proxy statement, the Bentley Family beneficially owned approximately 52% of outstanding Class B common stock in the aggregate after giving effect to conversion of all Class A shares, with approximately 20% held individually by named Bentley family members and approximately 32% held by other Bentley Family members; the eight-member board is led by Gregory S. Bentley as Executive Chairperson and President.

All Class A common stock automatically converts to Class B stock upon a 90% supermajority Class A vote or when the Bentley Family collectively owns less than 20% of issued and outstanding Class B stock on a fully diluted basis, a mechanism that preserves family control unless a substantial ownership threshold is crossed.

This concentrated governance structure carries direct relevance for the proposed Joint Venture / Strategic & Licensing Partner relationship: a minority JV partner should anticipate limited ability to influence Bentley's strategic direction, capital allocation, or dispute-resolution posture through conventional minority-governance mechanisms, given the family's durable voting majority.

Bentley Systems acquired Seequent Limited, a New Zealand geoscience modeling software company, for $900 million in cash plus 3,141,342 shares of Bentley Class B common stock, with the transaction completed in 2021 subject to New Zealand Overseas Investment Act consent and Hart-Scott-Rodino Antitrust clearance; no adverse findings were identified regarding the antitrust clearance process.

Subsidiary-level jurisdictional risk varies materially across the corporate structure: Seequent Limited (New Zealand) and Bentley Systems International Limited (Ireland) operate within Tier 1 rule-of-law jurisdictions with no subsidiary-specific enforcement findings identified, while Bentley Engineering Software Systems (Beijing, China) operates within a Tier 4 jurisdiction carrying elevated corruption-risk and rule-of-law considerations, raising second-order questions regarding data localization requirements, technology-transfer exposure, and applicability of BIS advanced-computing export rules.

No parent company was identified above Bentley Systems, Incorporated, which functions as the ultimate publicly traded parent (Nasdaq: BSY); no undisclosed ultimate beneficial owner beyond the disclosed Bentley Family control group was identified in SEC filings.

RISK INDICATOR: Orange - Concentrated family voting control (~67.4%) and controlled-company board exemptions create structural governance risk materially limiting minority partner influence in JV arrangements.

3. KEY PERSONNEL

Nicholas H. Cumins serves as Chief Executive Officer and a member of the Board of Directors, having joined Bentley Systems in September 2020 as Chief Product Officer, been promoted to Chief Operating Officer in January 2022, and assumed the Chief Executive Officer role effective July 1, 2024, becoming the first non-Bentley-family member to lead the company.

Cumins is a dual French and United States citizen based in France; prior to Bentley, he served as General Manager of SAP Marketing Cloud, Chief Product Officer of Scytl (an online voting platform headquartered in Barcelona), Senior Vice President of Product at OpenX, and held senior roles at SAP across the United States, Germany, and France; no adverse regulatory history was identified for Cumins in Tier 1/2 sources.

Cumins' dual citizenship and France-based residency are noted as a relevant consideration for immigration-status and deemed-export screening in any technology-sharing arrangement, though no PEP connection or adverse finding was identified.

Gregory S. Bentley serves as Executive Chairperson of the Board and President, having transitioned from the Chief Executive Officer role, which he held since 1995, to Executive Chair effective July 1, 2024; as a founding family member, he remains central to governance and strategic direction, and the Bentley Family's continued majority voting control (Section 2) means his influence persists despite the operational leadership transition to Cumins.

Keith A. Bentley, Barry J. Bentley (Ph.D.), and Raymond B. Bentley are co-founders of the company (founded 1984) and continue to serve as Board Directors, having been re-elected per the 2026 proxy vote results; their continued board presence provides institutional continuity but reinforces the concentration of governance authority within the founding family rather than a majority-independent board.

Werner Andre has served as Chief Financial Officer since 2022 and previously served as Chief Accounting Officer from 2020 through March 2024; he joined Bentley in 2015 as Global Corporate Controller, and prior to Bentley served as Assistant Corporate Controller for Rockwood Holdings, Inc. and held roles with PricewaterhouseCoopers from 1995 to 2010; no adverse regulatory history was identified.

David Hollister, formerly Chief Financial Officer, transitioned to the newly created role of Chief Investment Officer effective January 1, 2022; no adverse findings were identified regarding his tenure or transition.

Additional named executives identified through company bios and organizational-chart sources, though not independently corroborated by Tier 1/2 sources beyond factual identification, include David Shaman (Chief Legal Officer and Secretary), Brock Ballard (Chief Revenue Officer), Julien Moutte (Chief Technology Officer), Florence Zheng (Chief People Officer), and Chris Bradshaw (Chief Sustainability and Education Officer); no adverse findings were identified for any of these individuals.

A conflicting-title discrepancy was noted across Tier 4 aggregator sources (GlobalData, Clay.com) regarding the precise dates of Cumins' COO-to-CEO transition; the SEC-sourced primary account is treated as authoritative and confirms the January 2022 to June 2024 COO tenure followed by the July 1, 2024 CEO effective date.

RISK INDICATOR: Yellow - Orderly non-family CEO succession mitigates key-person risk, but continued family board dominance and a foreign-national CEO warrant governance and immigration-status monitoring.

4. SANCTIONS & CONTROLS SCREENING

This section reflects screening conducted across various sanctions, controls and watchlist databases. A complete list of these databases is provided in Appendix A. Individual databases are identified in this section only when a match or potential match is found. No listing means no matches for this entity were found.

IMPORTANT DISCLAIMER: This screening is based on open-source web research conducted at the time of report generation. FirstCheck.App does not directly query sanctions databases in real time. Sanctions listings change frequently. The requesting party must conduct independent direct screening against all applicable databases before entering into any business relationship or transaction. Reliance on this report without independent verification does not constitute a defense to sanctions violations.

SCREENING TIMESTAMP: List checks performed on 2026-07-24 15:09:04 UTC.

No matches were identified for Bentley Systems or its key executives across the databases listed in Appendix A.

A name-similarity result was identified through an aggregator database referencing a sanctioned maritime vessel named 'Bentley' under a Russia-related sanctions program; this result was verified as unrelated to Bentley Systems, Incorporated, given the differing entity type (vessel versus corporation), and is recorded as a resolved false positive rather than a confirmed match.

RISK INDICATOR: Green - No confirmed sanctions or restricted-party matches identified; one name-similarity false positive resolved.

5. REGULATORY & LEGAL

No SEC enforcement actions, consent decrees, or criminal matters were identified against Bentley Systems, Incorporated in SEC EDGAR litigation releases; a search specific to 'Bentley Systems enforcement action SEC' returned no entity-specific results.

No evidence of financial restatement or SEC accounting investigation was identified for Bentley Systems, Incorporated; standard 10-K disclosure checkboxes regarding restatements and SOX 404(b) attestation were not triggered, which reflects a routine disclosure posture rather than an adverse finding.

A trademark dispute, Marchon Officemate Inc. v. Bentley Systems Incorporated Corporation, was identified through a Law360 Trademark Trial and Appeal Board case index; the case details and outcome were not accessible due to subscription paywall restrictions, and the matter's status remains undetermined.

A legal-commentary source (Vondran Legal blog, an uncorroborated Tier 4 source) indicated that a review of federal court dockets found the company does not appear heavily invested in pursuing corporate infringers for copyright infringement, with only one potential instance located of Bentley initiating suit against a third party; this finding should be treated with caution given its single-source, non-independently-verified nature.

No class action securities litigation was identified against Bentley Systems, Incorporated in searches of PSLRA-related law firm announcement services; searches for 'Bentley Systems securities fraud class action' returned only unrelated results concerning 3D Systems Corporation.

No consent decrees, debarment actions, or suspension actions were identified against Bentley Systems, Incorporated in any reviewed source.

RISK INDICATOR: Yellow - One undetermined-outcome trademark dispute and limited-source litigation search represent minor monitoring items absent any confirmed enforcement action.

6. ADVERSE MEDIA

During the fourth quarter of 2023, Bentley Systems recorded a $12.6 million charge for realignment expenses, primarily for severance, affecting under 5% of its workforce, undertaken to reinvest in go-to-market functions and AI product development; this restructuring action was disclosed through a company press release corroborated by BusinessWire distribution and is characterized as resolved and completed.

Tier 4 employee-review aggregators, including Glassdoor and Indeed, contain sentiment describing the company as being in a 'constant state of restructuring' with 'multiple large scale layoffs' over recent years; this characterization is drawn from single-source, uncorroborated employee sentiment data not independently confirmed by Tier 1 or Tier 2 reporting beyond the disclosed Q4 2023 action, and should be treated as a workforce-stability signal warranting further verification rather than a confirmed adverse finding.

No data breach or cybersecurity incident specific to Bentley Systems, Incorporated was identified in Tier 1, 2, or 3 sources; this is distinguished from the unrelated 2020 Blackbaud third-party vendor breach affecting Bentley University, an unaffiliated educational institution excluded from this assessment.

No FCPA, antitrust, or corruption-related adverse media was identified specific to Bentley Systems.

Bentley Systems' 'Autodesk License Upgrade Program,' which targeted owners of discontinued Autodesk perpetual licenses, generated public friction with competitor Autodesk in 2016 according to Architect Magazine, a Tier 2 trade publication; this is characterized as a commercial marketing dispute rather than litigation or a regulatory matter and is noted for competitive-landscape context only.

RISK INDICATOR: Yellow - Recurring restructuring reports, though single-source and uncorroborated beyond the disclosed 2023 action, warrant monitoring for organizational stability.

7. FINANCIAL ASSESSMENT

Annualized Recurring Revenues reached $1,283.3 million as of December 31, 2024, compared with $1,174.8 million as of December 31, 2023, representing 12% constant-currency ARR growth, with a net retention rate of 110% versus 109% in the prior year; ARR further increased to $1,462.1 million as of December 31, 2025, representing 11.5% constant-currency growth with a net retention rate of 109%.

Operating income margin improved from 12.2% in the prior year to 17.6% for FY2024, while net income per diluted share declined from $0.54 to $0.16 and cash flows from operations declined slightly from $87.1 million to $81.6 million; FY2025 results showed further improvement, with operating income margin reaching 20.0%, cash flows from operating activities of $141.6 million, and free cash flow of $520 million, significantly exceeding the company's raised outlook.

Management stated that Bentley entered 2026 'from a position of financial strength,' having reduced net debt leverage to 2.1 times, described as a four-year low, with retirement of 2026 convertible notes in January 2026 reducing the fully diluted share count by approximately 3%; this is a positive forward-looking indicator relevant to assessing Bentley's capacity to meet shared financial obligations in a joint venture structure.

The company disclosed no material account concentration, with no single account or affiliated group representing more than 2.5% of revenues for the year ended December 31, 2019, and reported that 80% of total revenues derived from accounts of more than ten years' standing and 87% from accounts of more than five years' standing, indicating strong customer retention and low concentration risk favorable to partnership continuity.

No public credit rating actions from Moody's, S&P, or Fitch were identified in available search results, and the company does not appear to carry rated public debt, relying primarily on convertible notes and a revolving credit facility; this is recorded as Insufficient Data regarding formal credit rating status rather than a clean finding, and independent confirmation is recommended.

No bankruptcy filings, going-concern opinions, or UCC/tax lien filings were identified for Bentley Systems, Incorporated; the absence of a China-specific revenue breakdown beyond qualitative earnings-call commentary noting ARR growth 'ex-China' as a distinct disclosure item suggests China represents a sufficiently large single-market factor to warrant separate management commentary, functioning as a concentration and geopolitical risk indicator relevant to joint venture planning.

RISK INDICATOR: Green - Financial indicators reflect improving profitability, reduced leverage, and strong free cash flow generation, notwithstanding an undetermined public credit rating status.

8. GEOPOLITICAL RISK

Jurisdictional Environment: Tier 1 - Bentley Systems' primary jurisdiction is the United States (Delaware incorporation, Pennsylvania headquarters), a Tier 1 jurisdiction characterized by strong rule of law and a robust regulatory framework.

Bentley Systems International Limited's Dublin, Ireland regional headquarters and Seequent Limited's Christchurch, New Zealand headquarters both operate within Tier 1 jurisdictions, carrying minimal incremental geopolitical or sanctions risk.

Bentley Engineering Software Systems' Beijing, China office and Asia headquarters operate within a Tier 4 jurisdiction under the applicable risk framework, reflecting weaker enforcement consistency and elevated corruption-risk considerations relative to Tier 1 and Tier 2 jurisdictions; the company has disclosed China as a distinct enough growth and risk factor to break out separately in earnings commentary, as noted in Sections 1 and 7.

Current BIS guidance, dated May 2026, indicates ongoing US export-control tightening around advanced computing items directed at China- and Macau-headquartered entities, reflecting a continued elevated policy trajectory of restriction; this context is directly relevant to any joint venture or licensing arrangement involving shared technology or data access with Bentley given its China office footprint, since Bentley's infrastructure and geospatial software may carry dual-use or sensitive-infrastructure implications in China government-linked projects such as mining and civil infrastructure, consistent with Seequent's stated strategy of leveraging Bentley's China presence for market expansion.

RISK INDICATOR: Orange - China office footprint and Tier 4 jurisdictional classification, combined with escalating US-China export-control tightening, create material geopolitical exposure for technology-sharing arrangements.

9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY)

a) EXPORT CONTROLS

The BIS Entity List identifies foreign parties subject to license requirements for the export, reexport, or in-country transfer of controlled items, with violations subject to criminal penalties and administrative sanctions; no matches were identified for Bentley Systems, Incorporated, its subsidiaries, or named executives on the BIS Entity List, Denied Persons List, Unverified List, or Military End-User List.

No Department of Commerce or BIS investigation, consent agreement, or enforcement action involving Bentley Systems was identified; this finding is based on completed searches against the named Tier 1 sources bis.doc.gov and bis.gov and is therefore recorded as a confirmed no-adverse-findings result rather than an insufficient-data determination.

RISK INDICATOR: Green - Direct queries of Tier 1 export-control databases returned no adverse findings for the entity, its subsidiaries, or named executives.

b) SANCTIONS SCREENING

Sanctions screening results are detailed in Section 4; no confirmed matches were identified for Bentley Systems, Incorporated across OFAC, BIS, UN, EU, or UK Treasury sanctions lists.

One name-similarity false positive, involving a sanctioned maritime vessel named 'Bentley' under a Russia-related program, was identified through an aggregator database and definitively resolved as unrelated to the corporate entity under the false-positive verification protocol.

RISK INDICATOR: Green - No confirmed sanctions matches identified; single name-similarity false positive resolved.

c) DATA PRIVACY

No GDPR enforcement actions, CCPA or CPRA enforcement actions, or cross-border data transfer violations were identified for Bentley Systems, Incorporated in the searches conducted.

Direct queries of European Union Data Protection Authority enforcement registries and the California Attorney General enforcement database were not independently completed beyond general web search, and this area is therefore recorded as Insufficient Data rather than a confirmed clean result; direct query of these registries is recommended given the depth of proprietary data access contemplated in a joint venture relationship.

RISK INDICATOR: Insufficient Data - Absence of adverse findings could not be independently confirmed through direct DPA or state attorney general enforcement database queries.

d) CFIUS/FOREIGN INVESTMENT

The Seequent Limited acquisition required New Zealand Overseas Investment Act consent and Hart-Scott-Rodino Antitrust clearance in the United States; no CFIUS review was specifically identified for this transaction, consistent with its nature as an outbound US acquisition of a New Zealand target rather than an inbound foreign investment into a US business involving critical technology.

No other CFIUS filings or reviews were identified for Bentley Systems, Incorporated in available search results; the absence of CFIUS exposure reduces one category of regulatory-approval risk relevant to future joint venture structuring involving foreign capital or ownership changes.

RISK INDICATOR: Green - No CFIUS review applicability identified and no adverse findings in the one foreign-investment transaction reviewed.

e) IP & TRADE SECRETS

One trademark matter, Marchon Officemate Inc. v. Bentley Systems Incorporated Corporation, was identified before the Trademark Trial and Appeal Board with an undetermined outcome due to paywall-restricted access to case details, as detailed in Section 5.

No trade secret misappropriation litigation was identified against or by Bentley Systems, Incorporated in the sources reviewed; the absence of confirmed trade secret disputes is a favorable indicator for a relationship type in which IP ownership and assignment provisions are of central importance, though the undetermined trademark matter warrants closer review before finalizing IP-sharing terms.

RISK INDICATOR: Yellow - One undetermined-outcome trademark dispute remains unresolved in public records, though no trade secret litigation was identified.

f) CYBERSECURITY

Bentley Systems, Inc. holds an ISO/IEC 27001:2013 Information Security Management System certificate, Certificate Number ISMS-BE-103015.1, issued by A-LIGN Compliance and Security, Inc., a recognized accredited certification body that provides some independent verification weight to the certification.

The certificate document located in research was dated 2021; ISO 27001 certifications typically require a three-year recertification cycle with annual surveillance audits, and a current 2026 certificate was not independently located, rendering certification currency undetermined; no confirmed data breaches were identified for Bentley Systems, Incorporated specifically.

RISK INDICATOR: Yellow - ISO 27001 certification currency is undetermined pending verification of a recertification within the standard three-year cycle.

g) GOVERNMENT CONTRACTS

No FedRAMP authorization, CMMC certification, or DFARS compliance status was confirmed in available searches, and no evidence of debarment or federal contract suspension was identified.

Direct confirmation through the FedRAMP Marketplace was not independently completed during this research; this area is therefore recorded as Insufficient Data rather than a confirmed no-adverse-findings result, and direct query of FedRAMP.gov is recommended if government-contract usage is material to the proposed relationship.

RISK INDICATOR: Insufficient Data - Government-contracting certification status could not be independently confirmed through direct database query.

h) AI/EMERGING TECH

Company commentary describes artificial intelligence as 'our generation's paradigm shift,' with significant investment in AI product development cited as a reinvestment priority in the Q4 2023 realignment charge.

No AI ethics controversies, algorithmic bias findings, or regulatory actions were identified in connection with Bentley Systems' AI initiatives in the sources reviewed.

RISK INDICATOR: Green - No adverse findings identified regarding AI development or deployment practices.

i) COMPETITION & PLATFORM REGULATION

No DOJ or FTC antitrust investigations, nor European Commission competition proceedings, were identified against Bentley Systems, Incorporated in the sources reviewed.

The Seequent acquisition cleared Hart-Scott-Rodino antitrust review without identified complications, corroborated consistently across multiple Tier 2 trade press sources.

RISK INDICATOR: Green - No antitrust or competition-law adverse findings identified, and the one merger reviewed cleared without complication.

10. CERTIFICATIONS & ACCREDITATIONS

a) QUALITY & MANAGEMENT SYSTEMS

Bentley Systems holds an ISO/IEC 27001:2013 Information Security Management System certification, Certificate Number ISMS-BE-103015.1, issued by A-LIGN Compliance and Security, Inc., covering the company's information security management practices.

No ISO 9001 quality management certification or other formal quality-management-system accreditation was identified in the sources reviewed, and this specific certification category is recorded as Insufficient Data rather than a confirmed absence.

b) ENVIRONMENTAL & SUSTAINABILITY CERTIFICATIONS

Bentley Systems references LEED certification for select offices in company website materials, though the specific buildings and certification levels covered were not identified in the sources reviewed.

The company maintains a Global Electronic Recycling Program as disclosed in company sustainability materials; no independent third-party audit or verification of these environmental programs was identified.

c) INDUSTRY-SPECIFIC ACCREDITATIONS

No SOC 2 Type I or Type II attestation was publicly confirmed for Bentley Systems, Incorporated, notwithstanding the company's enterprise SaaS customer base, which would typically warrant such an attestation; this is recorded as Insufficient Data rather than an assumed absence.

No CMMC, FedRAMP, HITRUST, or PCI-DSS certification was confirmed or denied in the sources reviewed, representing a gap in independently verified industry-specific accreditation relevant to any government-contract-adjacent data flows under the proposed relationship.

d) THIRD-PARTY VERIFICATION

A-LIGN Compliance and Security, Inc. serves as the accredited third-party certification body for Bentley's ISO/IEC 27001:2013 certificate, and the certification can be validated by direct contact with A-LIGN.

No Better Business Bureau accreditation was confirmed in the sources reviewed; this is recorded as Insufficient Data.

e) CERTIFICATION CURRENCY

The only located ISO/IEC 27001:2013 certificate document was dated 2021; given the standard three-year recertification cycle with annual surveillance audits applicable to ISO 27001, certification currency in 2026 could not be independently confirmed.

Direct verification with A-LIGN Compliance and Security, Inc. or with Bentley Systems directly is recommended to confirm current certification status before finalizing any data-sharing or system-access provisions under the proposed joint venture or licensing relationship.

RISK INDICATOR: Yellow - ISO 27001 certification currency is undetermined and several industry-relevant certifications (SOC 2, CMMC, FedRAMP, HITRUST, PCI-DSS) remain unconfirmed.

11. CONFLICTS OF INTEREST

Bentley Systems' Board is led by Gregory S. Bentley as Executive Chairperson and President, with founding family members Keith A. Bentley, Barry J. Bentley, and Raymond B. Bentley also serving as directors; because the company qualifies as a 'controlled company' within the meaning of Nasdaq Listing Rules, it is not required to maintain a majority-independent board, a structural governance feature transparently disclosed in SEC filings rather than concealed.

This structural feature carries direct relevance to conflict-of-interest assessment in a joint venture context: minority partners should anticipate that board decisions, including those touching on the JV relationship itself, may be influenced by family-aligned directors whose primary fiduciary alignment runs through concentrated family ownership rather than a fully independent oversight structure.

Multiple Bentley family members hold beneficial ownership through trust structures; for example, Corinne Bentley's 13.2% Class B stake includes shares held in a grantor retained annuity trust and shares held across 19 family trusts for which she serves as trustee, per SEC Schedule 13G/A filings (Tier 1 source); this reflects standard estate-planning structuring rather than an undisclosed conflict, and no adverse findings regarding non-arm's-length transactions were identified.

No undisclosed ownership stakes in competing businesses, including Autodesk, Hexagon, AVEVA, or Dassault Systemes, were identified for Bentley executives or the Bentley Family, and no self-dealing, interlocking directorate, or undisclosed beneficial ownership adverse findings were identified in the sources reviewed.

RISK INDICATOR: Yellow - Transparently disclosed but structurally concentrated family governance creates inherent conflict-of-interest potential requiring monitoring within JV governance design.

12. RELATED & ASSOCIATED ENTITIES

Seequent Limited, headquartered in Christchurch, New Zealand, is a wholly owned subsidiary providing 3D geoscience modeling software, acquired by Bentley Systems in 2021 for $900 million in cash plus 3,141,342 shares of Bentley Class B common stock; the subsidiary operates within a Tier 1 rule-of-law jurisdiction, employs more than 430 colleagues across 16 office locations, and serves over 100 countries, with no subsidiary-specific enforcement actions or adverse findings identified in Tier 1/2 sources.

Bentley Systems International Limited, located in Dublin, Ireland, functions as the company's EMEA regional operating entity; Ireland is a Tier 1 jurisdiction subject to the EU regulatory regime, including GDPR and EU sanctions frameworks, and no subsidiary-specific enforcement findings were identified.

Bentley Engineering Software Systems, located in Beijing, China, functions as the company's Asia regional headquarters; China is assessed as a Tier 4 jurisdiction under the applicable risk framework, and while no entity-specific enforcement action was identified in Tier 1/2 sources, the entity carries elevated structural and geopolitical risk given US-China technology tensions, potential export-control exposure under BIS advanced-computing rules, and questions regarding data localization and technology-transfer safeguards applicable to Bentley's infrastructure and geospatial software capabilities in China-based government-linked projects.

The Bentley Family collectively constitutes the significant shareholder group, beneficially owning approximately 52% of outstanding Class B common stock in the aggregate as of March 31, 2026, per SEC DEF 14A disclosure, with individual family members such as Corinne Bentley (13.2% Class B) separately disclosed via Schedule 13G/A filings.

No third-party joint ventures were identified in the sources reviewed; Seequent and other prior acquisitions operate as wholly owned subsidiaries rather than joint ventures, indicating that the proposed relationship would represent a departure from Bentley's typical wholly-owned-subsidiary growth model and may warrant additional scrutiny of Bentley's institutional experience operating true joint venture structures.

RISK INDICATOR: Yellow - The Beijing-based Asia headquarters subsidiary carries materially elevated jurisdictional risk relative to the Ireland- and New Zealand-based entities, which present minimal incremental exposure.

13. AREAS OF SPECIAL INTEREST

13a) Environmental Risk & Liabilities

No EPA enforcement actions, CERCLA or Superfund involvement, or environmental litigation were identified for Bentley Systems, Incorporated; as a software company without manufacturing facilities, the company carries an inherently low environmental liability profile relative to industrial or manufacturing counterparties.

The company maintains a Global Electronic Recycling Program and references LEED certification for select offices in company sustainability materials; these are company-generated disclosures not independently audited in this research, but no contradictory or adverse environmental finding was identified from any independent source.

RISK INDICATOR: Green - No adverse environmental findings identified, consistent with the low inherent environmental footprint of a software business.

13b) Technology, IP & Data Risk

Bentley Systems holds an ISO/IEC 27001:2013 certification of undetermined current status (Sections 9f, 10e), and one trademark dispute of undetermined outcome (Marchon Officemate, Sections 5 and 9e) remains unresolved in public records; no confirmed data breaches, no FTC privacy enforcement actions, and no trade secret misappropriation litigation were identified.

For a Joint Venture / Strategic & Licensing Partner relationship involving deep access to proprietary data, customer information, and strategic plans, the combination of an unverified current cybersecurity certification and an unresolved trademark matter represents a moderate risk requiring direct verification before finalizing data-sharing and IP-assignment terms; the absence of confirmed breaches or trade secret disputes is a favorable offsetting factor.

RISK INDICATOR: Yellow - Cybersecurity certification currency and one trademark dispute outcome remain undetermined, warranting direct verification before data-sharing terms are finalized.

13c) Supply Chain & Logistics Security

Bentley Systems operates as a software and intellectual-property-centric business with a limited physical supply chain; no conflict-minerals disclosures, C-TPAT participation, or cargo-security findings were identified as applicable to the company's business model.

Given the absence of physical goods movement central to Bentley's core software licensing business, this area carries minimal relevance to the proposed relationship relative to other risk categories, though any hardware components bundled with software offerings were not separately assessed in available sources and would warrant clarification if relevant to the JV scope.

13d) Litigation & Legal Exposure

Over a 10-plus-year lookback, Bentley Systems' identified litigation footprint consists of one Trademark Trial and Appeal Board matter (Marchon Officemate, undetermined outcome) and a reference to a legal-commentary blog's characterization of Bentley's own limited history of initiating infringement suits; no securities class actions and no government investigations or subpoenas were identified.

This pattern suggests Bentley Systems is not a frequent litigant as either plaintiff or defendant relative to industry peers; however, full PACER docket search was not independently completed during this research, and search depth was limited by PACER access constraints, warranting a direct PACER/CourtListener query before this finding is treated as conclusive.

RISK INDICATOR: Yellow - Limited identified litigation footprint is favorable, but incomplete PACER docket access leaves residual visibility gaps requiring direct verification.

13e) Defense & Export Controls

No matches were identified for Bentley Systems, Incorporated, its subsidiaries, or named executives on the BIS Entity List, Denied Persons List, Unverified List, Military End-User List, or OFAC/DDTC sanctions lists, as detailed in Sections 4 and 9a.

No Department of Commerce or BIS investigation, consent agreement, or enforcement action was identified; these findings are based on completed direct queries of Tier 1 named sources and are therefore recorded as confirmed no-adverse-findings results.

RISK INDICATOR: Green - Direct queries of export-control and defense-related restricted-party lists returned no adverse findings.

13f) Business Continuity & Resilience

Bentley Systems recorded a $12.6 million Q4 2023 realignment charge affecting under 5% of its workforce, and Tier 4 employee-sentiment sources reference a pattern of recurring large-scale restructuring across 2023-2024, as detailed in Section 6; this represents a workforce-continuity signal requiring monitoring, though it is not independently corroborated beyond the disclosed action at Tier 1/2 level.

The company's CEO transition, completed in July 2024 with a non-family executive possessing four years of prior internal tenure, represents an orderly and completed succession that mitigates key-person risk to some degree; however, the Bentley Family's continued majority board presence and voting control (Section 2) means founder-level key-person and succession dynamics remain materially relevant to long-term business continuity planning for a joint venture counterparty.

RISK INDICATOR: Yellow - Recurring restructuring signals and continued family governance concentration warrant continuity monitoring despite an orderly CEO succession.

13g) Compliance Vulnerability

Bentley Systems' Code of Conduct states zero tolerance for bribery and corruption, requires observance of all applicable anti-corruption and anti-bribery laws, and requires colleagues to report bribery-related occurrences to a Compliance Committee, with regular anti-bribery and anti-corruption training required; this is a company-generated disclosure describing program design rather than independently audited effectiveness.

No regulatory findings of compliance program failure, and no FCPA, UK Bribery Act, or related enforcement actions, were identified against Bentley Systems, Incorporated in any independent source reviewed, supporting a favorable baseline compliance posture notwithstanding the self-reported nature of the underlying program documentation.

RISK INDICATOR: Green - No independent findings of compliance program failure or anti-corruption enforcement identified, notwithstanding reliance on company-generated program disclosures.

13h) Geopolitical & Regulatory Risk

As detailed in Section 8, Bentley's Beijing office and China revenue exposure sit within a Tier 4 jurisdiction amid escalating US-China export-control tightening on advanced computing items, creating elevated geopolitical risk for any technology-sharing joint venture arrangement.

Company management has separately disclosed China ARR growth softness relative to the balance of the business, reinforcing that China represents a distinct and material geopolitical and commercial risk factor warranting dedicated monitoring within the proposed relationship rather than treatment as a routine international-operations consideration.

RISK INDICATOR: Orange - Tier 4 jurisdictional exposure combined with escalating export-control tightening creates material geopolitical risk for technology-sharing arrangements.

13i) Financial Stability

As detailed in Section 7, Bentley Systems demonstrates improving profitability (FY2025 operating margin of 20.0%), strong free cash flow generation ($520 million in FY2025), and reduced net debt leverage (2.1 times, a four-year low), alongside low customer-concentration risk and strong long-tenure account retention.

No public credit rating status was confirmed, and no bankruptcy, going-concern, or lien indicators were identified; the absence of a confirmed credit rating is recorded as Insufficient Data on that specific point rather than an adverse finding, given the otherwise strong financial indicators disclosed through audited SEC filings.

RISK INDICATOR: Green - Strong and improving financial indicators support stability, notwithstanding an unconfirmed public credit rating status.

13j) Labor, Human Rights & Anti-Slavery

Bentley Systems, Incorporated and its subsidiaries issued a UK Modern Slavery Act Statement for financial year 2024 disclosing steps to ensure modern slavery and human trafficking are not taking place within its organization or supply chains, and the statement notes the company is 'not aware of any situation that would be considered an instance of a labor violation'; this is a self-reported company disclosure and cannot independently establish a clean record on its own.

No NLRB, OSHA, EEOC, or DOL enforcement actions were identified against Bentley Systems, Incorporated in the sources reviewed; however, corroborating searches of these specific databases by entity name were not exhaustively completed, and this finding should be treated as a favorable but incomplete result warranting direct database query before final reliance.

RISK INDICATOR: Yellow - Self-reported labor compliance statement lacks independent corroboration through exhaustive NLRB, OSHA, EEOC, or DOL database queries.

RISK INDICATOR SUMMARY
SECTIONRISK INDICATOR
1. ENTITY INFORMATIONYellowBeijing office location and disclosed China revenue softness introduce jurisdiction-specific monitoring considerations despite an otherwise well-documented identification profile.
2. OWNERSHIP & STRUCTUREOrangeConcentrated family voting control (~67.4%) and controlled-company board exemptions create structural governance risk materially limiting minority partner influence in JV arrangements.
3. KEY PERSONNELYellowOrderly non-family CEO succession mitigates key-person risk, but continued family board dominance and a foreign-national CEO warrant governance and immigration-status monitoring.
4. SANCTIONS & CONTROLS SCREENINGGreenNo confirmed sanctions or restricted-party matches identified; one name-similarity false positive resolved.
5. REGULATORY & LEGALYellowOne undetermined-outcome trademark dispute and limited-source litigation search represent minor monitoring items absent any confirmed enforcement action.
6. ADVERSE MEDIAYellowRecurring restructuring reports, though single-source and uncorroborated beyond the disclosed 2023 action, warrant monitoring for organizational stability.
7. FINANCIAL ASSESSMENTGreenFinancial indicators reflect improving profitability, reduced leverage, and strong free cash flow generation, notwithstanding an undetermined public credit rating status.
8. GEOPOLITICAL RISKOrangeChina office footprint and Tier 4 jurisdictional classification, combined with escalating US-China export-control tightening, create material geopolitical exposure for technology-sharing arrangements.
9. INDUSTRY-SPECIFIC RISKS (TECHNOLOGY)See individual sub-section risk indicators in report body
10. CERTIFICATIONS & ACCREDITATIONSYellowISO 27001 certification currency is undetermined and several industry-relevant certifications (SOC 2, CMMC, FedRAMP, HITRUST, PCI-DSS) remain unconfirmed.
11. CONFLICTS OF INTERESTYellowTransparently disclosed but structurally concentrated family governance creates inherent conflict-of-interest potential requiring monitoring within JV governance design.
12. RELATED & ASSOCIATED ENTITIESYellowThe Beijing-based Asia headquarters subsidiary carries materially elevated jurisdictional risk relative to the Ireland- and New Zealand-based entities, which present minimal incremental exposure.
13. AREAS OF SPECIAL INTERESTSee individual sub-section risk indicators in report body
RISK ASSESSMENT

Key Risk Factors:

β€’ Bentley Family controls approximately 67.4% of voting power, limiting JV governance influence.

β€’ Beijing office and disclosed China ARR softness create technology-diversion and export-control exposure.

β€’ 2023 realignment charge of $12.6 million and layoff reports signal workforce-continuity risk.

β€’ ISO 27001 certificate dated 2021 raises currency concerns for cybersecurity assurance.

β€’ Undetermined-outcome TTAB trademark dispute (Marchon Officemate) remains unresolved in public records.

β€’ Public credit rating status is undetermined, limiting independent financial-stability verification.

β€’ Controlled-company Nasdaq exemption permits a non-majority-independent board, reducing external oversight.

Recommendations:

1. Negotiate explicit minority-protection, veto, and dispute-resolution provisions in any JV agreement to offset Bentley Family's approximately 67.4% voting control.

2. Require current A-LIGN ISO/IEC 27001:2013 recertification documentation before granting Bentley system access to shared data or intellectual property.

3. Commission a dedicated China-exposure assessment covering export control, data localization, and technology-transfer safeguards given the Beijing office footprint and disclosed China ARR softness.

4. Request clarification on the outcome of the Marchon Officemate TTAB trademark dispute before finalizing IP-sharing or co-branding terms.

5. Obtain direct confirmation of Bentley's public credit rating status or audited leverage schedules to independently verify the disclosed 2.1x net debt figure.

6. Monitor workforce attrition and restructuring trends through direct HR data requests given recurring realignment charges reported since 2023.

7. Confirm FedRAMP, SOC 2, and CMMC certification status directly with Bentley if government-contract-adjacent data will flow through the partnership.

Monitoring Needs:

β€’ Ongoing monitoring of BIS Entity List and OFAC SDN List for Bentley Systems and named executives.

β€’ Track quarterly ARR and China-specific revenue commentary for continued softness or acceleration.

β€’ Monitor US-China export control regulatory developments affecting advanced computing and infrastructure software.

β€’ Track workforce restructuring announcements and employee-sentiment indicators for continuity signals.

β€’ Monitor ISO 27001 and other certification renewal cycles for currency lapses.

β€’ Monitor SEC filings for changes in Bentley Family beneficial ownership percentages and board composition.

Recommended Action: Proceed with the proposed Joint Venture / Strategic & Licensing Partner relationship subject to negotiated governance safeguards, verified cybersecurity certification currency, and enhanced monitoring of China-related technology-transfer and export-control exposure.
RECOMMENDED FOLLOW-UP QUESTIONS

Based on the findings in this report, the following questions should be addressed through direct inquiry with the entity or additional research:

1. What was the final outcome of the Marchon Officemate Inc. v. Bentley Systems TTAB trademark dispute?

2. Is Bentley Systems' ISO/IEC 27001:2013 certification (ISMS-BE-103015.1) currently active, and when is the next recertification audit scheduled?

3. What specific technology-transfer, data-localization, or export-control safeguards does Bentley apply to its Beijing office operations and China-linked customer engagements?

4. Does Bentley Systems hold a current SOC 2, FedRAMP, CMMC, or HITRUST attestation relevant to any government-contract-adjacent data flows under the proposed partnership?

5. What is driving the disclosed China ARR growth softness (12% versus 12.5% ex-China), and what is management's outlook for China market stability?

6. What governance, veto, and dispute-resolution rights would the requester hold under a JV structure given Bentley Family's 67.4% voting control and controlled-company board exemption?

7. Can Bentley provide independently verified workforce attrition and turnover data to substantiate or refute employee-sentiment reports of repeated large-scale layoffs?

8. Does Bentley Systems carry a public or private credit rating, and can audited debt-leverage schedules be provided to verify the disclosed 2.1x net debt figure?

9. What IP ownership, assignment, and technology-transfer provisions would govern joint work product under the proposed licensing/JV structure, particularly regarding China-based personnel access?

10. Has Bentley Systems conducted direct compliance verification with EU Data Protection Authorities or the California Attorney General regarding cross-border data transfer practices?

SOURCES CONSULTED

Government & Regulatory Databases:

β€’ SEC EDGAR (sec.gov/edgar) β€” results found (10-Ks, S-1, 424B4, DEF 14A, 8-K, Schedule 13G/A)

β€’ SEC Litigation Releases (sec.gov/litigation) β€” no matches found for Bentley Systems, Incorporated

β€’ OFAC SDN List / Sanctions List Service (ofac.treas.gov) β€” no matches found

β€’ BIS Entity List (bis.doc.gov / bis.gov) β€” no matches found

β€’ SAM.gov exclusions/debarments β€” no matches found

β€’ OIG List of Excluded Individuals/Entities (oig.hhs.gov) β€” not applicable / no matches found

β€’ World Bank debarment list β€” no matches found

β€’ UN Security Council consolidated sanctions list β€” no matches found

β€’ EU consolidated sanctions list β€” no matches found

β€’ UK HM Treasury sanctions list β€” no matches found

β€’ DOL/OFCCP Debarred List β€” no entity-specific match found

β€’ CISA Entity List resource page β€” reference/context only, no adverse finding

Court & Legal Records:

β€’ Law360 (TTAB case index) β€” match found: Marchon Officemate Inc. v. Bentley Systems (paywall-limited access)

β€’ PACER/CourtListener β€” not exhaustively queried; noted as a research limitation

β€’ WIPO Arbitration and Mediation Center β€” results returned pertained to unrelated Bentley Motors Limited and were excluded

News & Media:

β€’ Reuters, Bloomberg, Financial Times, Wall Street Journal, Associated Press, BBC β€” no direct adverse hits found specific to Bentley Systems

β€’ Architect Magazine (Tier 2 trade publication) β€” result found: Autodesk/Bentley licensing friction, 2016

β€’ Glassdoor, Indeed, TheLayoff.com (Tier 4 employee-sentiment aggregators) β€” results found: layoff pattern sentiment, single-source and uncorroborated

Business Registries & Financial:

β€’ SEC EDGAR 10-K/DEF 14A/8-K filings β€” results found; primary financial data source

β€’ StockTitan (SEC filing aggregator) β€” results found, cross-referenced against Tier 1 filings

β€’ Last10k.com β€” results found (Tier 4 aggregator)

β€’ ZoomInfo, Owler, Clay.com, GlobalData, TheOrg, salestools.io β€” results found (Tier 4 aggregators used for structural/identification cross-reference only)

Industry-Specific Sources:

β€’ A-LIGN ISO 27001 Certificate (company-hosted PDF) β€” result found; currency undetermined (2021-dated document)

β€’ CII (Council of Institutional Investors) Dual Class Companies List β€” result found, governance corroboration

β€’ Bentley Systems Code of Conduct, Modern Slavery Statement, Supplier Code of Conduct, ESG Environmental Policy (company-generated) β€” results found

β€’ OpenSanctions.org β€” lead-generation aggregator; one false-positive match identified and resolved

LIMITATIONS & RECOMMENDED NEXT STEPS

This report is based on publicly available information accessible through web search. The following limitations apply:

Information Not Accessible:

β€’ Proprietary databases (e.g., LexisNexis, World-Check, Dow Jones Risk & Compliance)

β€’ Non-public court records and sealed proceedings

β€’ Confidential regulatory examination results

β€’ Private company financial statements

β€’ Non-English language sources (limited coverage)

β€’ Real-time sanctions list updates (recommend independent verification)

β€’ International jurisdiction coverage: the depth and reliability of open-source intelligence varies significantly by jurisdiction, entity type, disclosure requirements, press freedom, and corporate registry accessibility. See firstcheck.app for full details.

Recommended Additional Due Diligence:

1. Commission direct legal counsel review of the Marchon Officemate TTAB trademark matter to confirm current status and any residual IP risk.

2. Request current ISO/IEC 27001 recertification documentation and any SOC 2, CMMC, or FedRAMP attestations directly from Bentley Systems prior to executing data-sharing terms.

3. Conduct a dedicated China-exposure assessment covering export control, data localization, and technology-transfer safeguards applicable to the Beijing office and China customer base.

4. Negotiate governance, veto, and dispute-resolution provisions in the JV agreement to address Bentley Family's controlling voting position and controlled-company board structure.

5. Request audited financial schedules or an independent credit assessment to verify Bentley's disclosed 2.1x net debt leverage and cash flow figures.

6. Perform an exhaustive PACER/CourtListener docket search and direct EU DPA/California AG enforcement-database query to close residual litigation and data-privacy visibility gaps.

7. Verify sanctions status through direct OFAC/BIS database query.

This report is valid as of the report date. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.

DISCLAIMER

FirstCheck.App is a first-level third party intelligence and risk assessment tool. It is not a substitute for formal investigation, professional review, or expert compliance determinations. Report findings should be evaluated by business managers, subject matter experts, and professionals in the context of the organization's risk tolerance, policies, directives, and approaches. FirstCheck.App reports may be retained as part of the organization's third-party risk management program, including its applicable record-keeping practices.

Β© 2026 FirstCheck.App. All rights reserved.


APPENDIX A β€” SANCTIONS & CONTROLS DATABASES SCREENED

This report reflects research conducted across the following databases. Individual databases are identified in Section 4 only when a match or potential match is found.

TIER 1 β€” Direct Web Research (Conducted on Every Report)

1.OFACSpecially Designated Nationals (SDN) List
2.OFACNon-SDN Lists (SSI, FSE, NS-MBS, PLC, and related)
3.BISEntity List
4.BISDenied Persons List
5.BISUnverified List
6.U.S. State DepartmentDebarred Parties List (ITAR)
7.OIGList of Excluded Individuals/Entities (LEIE)
8.GSA SAM.govSystem for Award Management Exclusions
9.DEAControlled Substances Act Exclusions
10.CMSState Medicaid Exclusion Lists (composite)
11.FDADebarment List
12.SECEnforcement Actions Database
13.CFTCEnforcement Actions
14.FinCENEnforcement Actions
15.FBIMost Wanted
16.InterpolRed Notices
17.UN Security CouncilConsolidated Sanctions List
18.European UnionConsolidated Sanctions List
19.UK HM TreasurySanctions List
20.World BankDebarment List
21.Asian Development BankSanctions List
22.OpenSanctionsConsolidated Database

TIER 2 β€” Web Research Based (Conducted Where Relevant)

1.FATFGrey List (Jurisdictions Under Increased Monitoring)
2.FATFBlack List (High-Risk Jurisdictions β€” Call for Action)
3.SECOSanctions List (Switzerland)
4.MASSanctions List (Singapore)
5.DFATSanctions List (Australia)
6.Global Affairs CanadaSanctions List
7.Japan METI/MOFASanctions and Export Control Lists
8.France TRESORDirection GΓ©nΓ©rale du TrΓ©sor Sanctions
9.Germany BAFAExport Control and Sanctions Lists
10.UAESanctions List
11.IsraelSanctions List
12.ICIJOffshore Leaks Database (Panama Papers, Pandora Papers)
13.Transparency InternationalCorruption Perceptions Index (CPI)
14.Basel InstituteAML Index
15.ACAMSWatchlist (open-source tier)
16.South Korea MOFATSanctions List
17.Inter-American Development BankSanctions List

Tier 1 databases are researched on every report. Tier 2 databases are researched based on entity jurisdiction, industry, and risk profile. This screening is conducted through open-source web research and does not constitute direct real-time database queries. Independent verification against all applicable databases is required before entering into any business relationship or transaction.


APPENDIX B β€” RISK RATING METHODOLOGY

Risk ratings reflect a qualitative assessment of the severity, recency, and regulatory relevance of identified issues.

Red β€” Critical Risk
Confirmed regulatory enforcement, sanctions violations, or systemic control failures with material impact requiring immediate attention or enhanced approval.
Orange β€” Significant Concerns
Significant regulatory, legal, or reputational issues requiring enhanced due diligence, ongoing monitoring, or senior management approval before proceeding.
Yellow β€” Minor Issues
Historical concerns now resolved, manageable risks, or areas requiring periodic monitoring but not blocking engagement.
Green β€” No Adverse Findings
No material adverse findings identified in available open-source information. Standard onboarding procedures apply.
Insufficient Data
Limited publicly available information to assess risk. Additional research or direct inquiry recommended.
Risk Indicator Summary
Section-level risk indicators are assigned independently for each of the 13 report sections. Each indicator reflects findings specific to that section. The Risk Indicator Summary table provides a consolidated view of all section-level indicators.

REPORT METADATA
Report ID:FC-20260724-151948
Date Generated:2026-07-24 15:19:48 UTC
FirstCheck.App Version:v2.12.66
Entity Analyzed:Bentley Systems
Jurisdiction:United States (Delaware)
Relationship Type:Joint Venture / Strategic & Licensing Partner
Client Industry:Manufacturing & Industrials
Subject Industry (Verified):Technology
Reason for Inquiry:New Entity Check

This report is valid as of the date generated. Circumstances may change. Periodic re-screening is recommended based on risk indicator and relationship type.


THIRD-PARTY REVIEW FORM
Reviewer Assessment
Entity Reviewed: Bentley Systems    Report ID: FC-20260724-151948    Report Date: 2026-07-24 15:19:48 UTC
Acceptable: Okay to proceed.
Caution: Monitoring and oversight recommended.
Pending: Verify and resolve before proceeding.
Full Review: Conduct full background due diligence before proceeding.
Unacceptable: Do not proceed.
Other/Comment:
Recommended Frequency of Third Party Assessment Reports
Every month
Every three months
Every six months
Annually
Other:
Additional Reviewer Comments
Reviewer Certification

The undersigned has reviewed this Third Party Assessment Report and confirms that the risk decision and recommendations above are based on the information provided and professional judgment.

Signature
Date
Reviewer Name
Title

This form should be completed by the designated reviewer and retained with the FirstCheck.App report as part of the organization's third party review records.

πŸ“‹ To download this form in fillable format: firstcheck.app/review-form.html