Research

The Identity Dimension of Blocked Cross-Border M&A

Screening authorities, boards, employees and politicians read one acquisition differently. What they ask about the buyer is not what the terms answer.

Author
Published

The postmortem of a failed cross-border acquisition usually starts in the wrong place. The deal team returns to the purchase agreement to look for the fatal flaw. They gather in a conference room to review the variables they know how to control: the price was defensible, the financing was fully committed, the covenants were market standard, and the synergy case had survived diligence. Nothing in the documents explains why the transaction is dead, because the risk that killed it never lived in the documents. Somewhere between announcement and closing, a question was asked that the agreement was never designed to answer. The authorities and stakeholders reviewing the transaction were not asking “what does this deal say.” They were asking “what is this buyer.”

Deal teams are equipped for the first question. It is negotiable, priceable, and carefully papered by sophisticated counsel. The second question is different in kind. It is not negotiated; it is read. And it is read by audiences the buyer never sits across a table from, who use the transaction to assess risks that the purchase agreement cannot resolve.

Scrutiny of what you do, and scrutiny of what you are

A cross-border buyer occupies an unusual double position. It is the examiner, running diligence on the target’s numbers, contracts, and management to price the asset. At the same time, it is the examined, twice over: screening authorities are assessing it as a possible security risk, and the target’s own stakeholders are assessing it as a future owner. The acquirer grades the asset while several rooms of people grade the acquirer.

In transactions involving sensitive assets, multiple markets, or multi-jurisdictional review, this dynamic sharpens. The deal runs through several jurisdictions at once, each with its own review clock and vocabulary of concern. Much of the process is semi-confidential: reasons may never be published, and positions form in rooms the buyer cannot enter. Outcomes may be negotiated rather than simply ruled on. A block or unresolved review in one pivotal jurisdiction can set the global state of the deal, and the public record of it can follow the buyer into the next process.

Two distinctions run through everything that follows. One is that scrutiny can be triggered by what an acquirer does, or by what an acquirer is: its ultimate ownership, its funding, its institutional home, and the state standing behind or beside it. The other is that some constraints can be adjusted inside the transaction, while others are institutional and cannot be negotiated away by redrafting. Terms are exceptionally good at answering conduct questions. They struggle with identity questions, because an identity question is not about what the buyer has agreed to. It is about how much the agreement is worth, given who is signing it.

Identity is written into the statutes

It is tempting to treat all of this as political noise that surrounds an otherwise legal process. The statutes say otherwise: the identity of the acquirer is an express input to review, not a residue around it.

The United Kingdom’s statement on its call-in power under the National Security and Investment Act names three risk factors, and one of them is simply “acquirer risk”, assessed alongside what is being bought and how much control changes hands. The EU’s screening framework, Regulation 2019/452, lets member states weigh whether an investor is directly or indirectly controlled by a third-country government, including through its ownership structure or significant funding, and whether it has a record of activity affecting security or public order. Its adopted replacement, Regulation 2026/1386, tightens the machinery further and applies from January 2028.

In the United States, place of incorporation is not dispositive. Under 31 CFR § 800.224, a U.S.-incorporated entity can be a foreign person if a foreign national, government, or entity exercises or can exercise control over it; 31 CFR § 800.208 defines control by reference to the power, direct or indirect, to determine important matters. Voluntary notices must also disclose the acquiring foreign person’s immediate, intermediate, and ultimate parents under 31 CFR § 800.502. This reflects the legal position as of August 2026. The dates matter, because this is one of the faster-moving areas of law a deal can touch.

Two things follow from this reality. The question “what is this buyer” has statutory addresses, which means it will be asked whether or not the buyer prepares an answer. It need not wait for a formal filing: in the United States, CFIUS’s non-notified team identified the MineOne transaction after a public tip.

The three-part burden of proof

A cross-border acquirer carries a three-part burden of proof: that it is a credible commercial buyer, that it can integrate what it buys, and that the deal is acceptable to regulators.

Each part answers a different reader and addresses a distinct vulnerability. Commercial credibility answers the target’s board and shareholders: is the offer real, is the capital reliable, does the industrial logic hold. Integration capability answers the people inside the target: what happens to the operations, the sites, the teams, after the ink dries. Regulatory acceptability answers the authorities: what could travel through this ownership, and can the state live with it.

The three-part burden of proof in cross-border M&A: three separate cards. A credible commercial buyer, read by the target’s board. Able to integrate what it buys, read by the target’s organization. Acceptable to regulators, read by screening authorities. Carried separately: strength in one does not transfer to another.

The structure would be merely tidy if the three parts converted into one another. They do not. A buyer can be impeccably commercial and still fail the regulatory question, because commercial credibility earns a hearing, not a clearance. An offer at a full premium says nothing about what a security reviewer fears; a strong integration record does not answer a question about ultimate control. Deal teams often discover this asymmetry late, after weeks spent reinforcing the argument they were already winning while the argument they were losing went unaddressed. The three burdens are carried separately or not at all.

One transaction, many readings

Put the burden of proof in front of its audiences and the identity dimension becomes concrete. For each audience around a deal, three questions locate its reading: what does it care about, what does it fear losing, and what constraints is it acting under.

Consider a composite scenario, assembled from recurring situations in which an acquirer whose ultimate ownership runs through two holding layers in a distant institutional system bids for an engineering business. The target’s products sit near, but not inside, the host country’s critical-infrastructure definitions. The screening authority starts at the top of the ownership chain and reads downward: it cares about what could move through this structure in five years, fears an irreversible loss of control over capability, and is constrained to reason about futures rather than track records.

The board reads the same deal from the certainty of close and the premium. It cares about shareholder value and fears losing the only credible offer on the table, constrained by fiduciary duties that make narrative doubts hard to act on. Employees read the investment plan and try to price a promise from an owner whose institutional home they cannot read. Regional politicians read precedent: not this deal alone, but what approving it says about the next one. The acquirer, meanwhile, tells all four rooms the same story, usually the commercial one. It lands in the boardroom, half-lands on the shop floor, and does not touch the authority’s question at all. No one in this picture is misreading. They are reading different objects that happen to share a purchase agreement.

The public record shows the same divergence at full scale. When the UK ordered Nexperia to divest at least 86 percent of Newport Wafer Fab in November 2022, sixteen months after the acquisition had completed, the official notice focused on future capability and access to the South Wales semiconductor cluster. It placed a different governing question at the centre of the transaction than price, financing, or the operational case.

Nippon Steel’s acquisition of U.S. Steel had received all non-U.S. regulatory approvals by May 2024, yet did not close until June 2025. The published presidential order conditioned closing on the execution of a national security agreement. An allied-country buyer still carried an identity question, and the answer was institutional rather than rhetorical.

One structural fact governs the multi-jurisdiction picture. Each jurisdiction is its own stage, with its own procedure under way; the deal itself has a single global state, often set by the slowest and hardest room. Reviews are coupled without being unified: information may move between authorities, postures in one process can shape another, and one unresolved regulator can hold a transaction open. Reading each stage separately while tracking the global state is simply the minimum needed to know where the deal stands.

Why structure alone rarely creates distance

The instinct of a well-advised buyer facing an identity question is structural: insert a local acquisition vehicle, add a holding layer, or route the purchase through a neutral jurisdiction. The record is unkind to this instinct. Authorities read through vehicles as a matter of routine. In 2024, CFIUS’s non-notified process led to an order requiring MineOne, a foreign-owned partnership, to divest a completed U.S. land purchase. A local vehicle or an additional holding layer may change a transaction’s mechanics, but it does not by itself answer the question of control.

What actually gets tested is a set of three questions that a deal team can ask itself before an authority does:

  • Can the feared risk be bounded at the level of specific assets, systems, data, facilities, or rights, rather than vaguely gestured at?
  • Can the buyer’s undertaking be independently verified and monitored by someone other than the buyer?
  • Does the commercial logic survive the constraint: if the only acceptable version of the deal strips out the assets or the control that made it worth doing, is there a deal left to defend?

Where the answers are yes, an identity question can narrow into a manageable one. Where a risk cannot be bounded, assurances tend to expand to fill the space. But a mitigation has to be effective, verifiable, and monitorable. In MineOne, CFIUS concluded that an agreement could not sufficiently address the risks and referred the matter for presidential action. Structure can contain an operational risk; it rarely neutralizes an identity question on its own.

Closing is not the finish line

There is a quieter institutional fact underneath all of this: completing a transaction does not end its exposure. The UK’s Newport order reached an acquisition that had closed sixteen months earlier. In the United States, MineOne was identified through CFIUS’s non-notified process after the transaction had closed. Depending on the regime and the facts, scrutiny can reach a completed transaction.

The protection that clearance gives is real but conditional: it ordinarily holds only on the facts disclosed and the undertakings kept. For a buyer whose identity is under scrutiny, closing transfers the risk; it does not extinguish it. The judgment about what kind of owner this is can continue after the wire settles, with the asset now on the buyer’s side of the ledger.

Four kinds of signal, and why they must not impersonate each other

Around any scrutinized deal, four kinds of signal circulate, and they are easy to confuse. Formal legal triggers are the clearest: filings required, reviews opened, orders issued. Policy concerns sit one step behind them: the worries a government voices about data, supply chains, or capability, shaping review before any of it becomes law. Political narrative is what the deal is made to stand for in legislatures and headlines. Stakeholder perception is quieter still: what boards, employees, and counterparties privately conclude, often without saying so.

These four run on different clocks and different logics, and they do not substitute for one another. A hostile headline is not a filing obligation. A policy concern is not yet a legal trigger, however loudly it is voiced. Board unease can build where no authority has moved, and an authority can move where the press has seen nothing.

Deal teams get into trouble by letting one register impersonate another. Treating a political mood as if it were a binding law can create unnecessary concessions, while dismissing a formal signal because the politics seem quiet can mean missing an actual obligation. Formal variables, policy labels, and political rhetoric are different kinds of fact, and any statement about where a regime currently stands should carry a date, because these regimes move continuously. The practical task is to match the instrument to the signal: legal analysis to a legal trigger, policy engagement to a policy question, and stakeholder work to a perception problem. Counsel, bankers, government-affairs and communications advisers each keep their own instruments; how this reading sits beside their work is mapped in Narrative Architecture, Messaging, PR and IR.

Four signals around a scrutinized deal, formal legal triggers, policy concerns, political narrative and stakeholder perception, each matched to the instrument that answers it, with no single instrument for political narrative, and a struck arc joining the legal-trigger row to the political-narrative row to mark impersonation, one register read as if it were another.

What can be examined from the outside

For a deal team weighing all this, the practical question is what can actually be assessed, and when. The examinable core is whether the account the acquirer gives of itself holds across audiences and jurisdictions. The story told to the board, the undertakings offered to the authority, and the assurances given to employees either describe the same buyer or they do not. Identity accounts fail at sentence level before they fail at strategy level. One document promising “fully independent management” against another projecting “deep integration synergies” is a contradiction an authority will find.

This kind of examination belongs before the narrative is committed: before the same commercial story has been laid in front of four audiences holding four different questions. The question a deal team can borrow today costs nothing to ask. Not “will our terms clear”, but: who, in each room this deal must pass through, is forming a judgment about what we are, and what would actually change that judgment? Terms can change quickly. A reading of identity, once settled, moves on institutional time. The buyers best placed to navigate this scenario are rarely those with the cleanest documents; they are the ones who understood, early, which question they were actually being asked.


Related NPA work

Back to research