With the regulatory shift from form to substance, some of the old ways of allocating liability may soon be gone
China released a draft amendment to the Banking Supervision Law, which was out for public consultation from last December. A key highlight is its alignment with the Central Financial Work Conference’s mandate for “look-through” supervision. By extending the regulatory reach, the draft significantly tightens oversight of shareholders and actual controllers.
Identify the controller
Traditional regulation focuses on the corporate entity, targeting financial institutions and their senior executives. In practice, however, a bank’s risk appetite is not always determined by its nominal management. Controlling shareholders can steer operations through board resolutions, key appointments and funding arrangements.
Actual controllers can also exert control via proxy agreements, concerted action, affiliate networks or nominee arrangements.

Senior Partner
Tahota Law Firm
Tel: +86 135 5122 3080
E-mail: fei.xiang@tahota.com
Look-through supervision sees beyond official business registries and shareholding percentages to focus on three questions: who controls the entity; who profits from the transactions; and who actually influences risk-related decisions?
The regulatory focus shifts from the form of equity ownership to the substance of control – and from a single corporate entity to the entire chain of control and benefit.
The draft amendment provides the technical foundation for look-through supervision by enhancing macroprudential management, financial databases, and information sharing mechanisms.
By sharing information across departments, regulators can identify hidden relationships, making it possible to uncover nominee shareholders, complex control structures and closed-loop fund flows.
Link to Company Law
Look-through supervision is not about adding paperwork. Instead, it fundamentally strengthens the civil, administrative and corporate governance responsibilities of both shareholders and actual controllers.
First, the new Company Law broadens the definition of an actual controller, which no longer needs to be a non-shareholder; anyone who directs corporate behaviour through investment ties, agreements or other arrangements is under the definition.Consequently, individuals can no longer evade liability by holding low nominal stakes or hiding behind multi-layered corporate structures and concerted action agreements.
Second, the liability of a “de facto director” is formalised. Article 180 of the new Company Law stipulates that controlling and actual controllers who execute corporate affairs owe the company a duty of loyalty and diligence, even if they do not hold a directorship. Controllers can no longer shift the blame for bad decisions onto the board or management simply by claiming they hold no formal office.
Article 192 of the new law also establishes “shadow instruction liability”. Controlling and actual controllers who instruct directors or senior executives to carry out any act that damages company interests or its shareholders face joint and several liability. This rule can apply retroactively.
This creates a link between look-through identification in financial regulation and look-through accountability under company law. Authorities are responsible for identifying actual control relationships and sources of risk, while company law provides the basis to hold controllers liable.
Chief compliance risks
Opaque ownership structures. Hiding control relationships through nominee arrangements, trust holdings, cross-shareholdings, multi-layered special purpose vehicles or concerted action agreements can distort assessments of shareholder eligibility, affiliation and the true source of capital.
Improper operational interference. Shareholders or actual controllers who interfere in credit extensions, investments, fund allocations and risk management owe a duty of loyalty and diligence if they effectively execute corporate affairs, even if no formal written instructions are issued.
Related-party transactions and siphoning of benefits. Funnelling a financial institution’s resources into a shareholder’s own network via loans, asset transfers or fee payments involving affiliates is a target of look-through supervision.
Inauthentic capital and circular funding. Capital contributions by financial institution shareholders must not only be genuine under company law, but must also come from legitimate, stable and proprietary sources. Funding share acquisitions using financial institution loans, recycling capital through circular injections or illegally withdrawing capital can trigger liabilities under both company law and financial regulations.
Group risk transmission. When actual controllers treat financial institutions as funding platforms for their wider corporate group – demanding they provide guarantees, channel liquidity or absorb distressed assets for affiliates – risks at a single institution can escalate into group-wide or systemic crises.
Compliance advice
To prepare for the incoming look-through regulatory regime, financial institutions should leverage their existing corporate governance and regulatory frameworks to proactively map out relationships between shareholders, actual controllers and related parties. At this stage, they should focus closely on identifying ultimate beneficial owners, concerted action arrangements, funding sources and changes in affiliate networks.
For major credit extensions, guarantees, investments and asset transactions, scrutiny of related-party relationships and conflicts of interest should be strengthened.
If shareholders or actual controllers express views or exert influence on operations, proper records should be kept to ensure that decisions are made independently by authorised bodies in accordance with corporate governance procedures.
Institutions can also define clear boundaries for the conduct of shareholders and actual controllers within their articles of association, shareholder agreements and policies. They should refine mechanisms for recusal from related-party transactions, the declaration of conflicts of interest, and monitoring abnormal fund flows.
At its heart, the logic of look-through supervision is to equalise power and responsibility. Whoever exerts substantive influence over a company’s operations must bear the corresponding liability.
Rather than focusing predominantly on their own actions as they did in the past, businesses must begin to accord an equal, if not greater, amount of attention to the underlying control relationships, beneficial interests and risk allocation.
Xiang Fei is a senior partner at Tahota Law Firm. He can be contacted by phone at +86 135 5122 3080 and by email at fei.xiang@tahota.com

24F, Tahota Centre
299 Longhe Lane West, Tianfu New Area
Chengdu 610000, China
Tel: +86 28 8662 5656




















