Legal Entity: The Only Thing a Contract Can Actually Bind
Surya · 13 min read
Think of a family running a fruit stall. The father owns it, the son runs it, and if a supplier isn't paid, the supplier can walk up to either of them and demand the money personally — their house, their savings, their scooter, all of it is fair game if the debt goes unpaid. There is no separate "fruit stall" that owes the money. There is only the family.
Now think of a company. It can borrow money, own a building, sign a hundred-page loan agreement, get sued, and even go bankrupt — and the people who founded it can, in most cases, walk away having lost only what they invested. Their house is untouched. That's not a technicality. It's because the law treats the company as a distinct "person" in its own right, separate from every human being who owns it, runs it, or works for it.
That distinct, law-recognised "person" is a legal entity. It sounds like dry paperwork. It is actually the single fact that every contract, every loan, every trade, and every regulatory filing quietly depends on — because none of those things can be signed with a family, a brand, or a desk. They can only be signed with an entity the law agrees exists.
What a legal entity actually is
Not a legal entity (a fruit stall, a family business, an unregistered partnership)
- Can't own property or sign contracts in its own name — the humans behind it do that personally
- The owners are personally liable for every rupee it owes, without limit
- It ends the moment the people behind it stop running it — there's nothing left to inherit or hand over
A legal entity (a company, an LLP, a registered trust)
- Owns its own assets and signs its own contracts, in its own name
- Its owners are liable only up to what they invested — the entity absorbs the rest
- It survives changes of ownership, management, or death of a founder — it has what lawyers call perpetual succession
In India, an ordinary partnership formed under the Indian Partnership Act, 1932 sits on the left side of that list: the firm can operate under a shared name and hold property for practical purposes, but the partners remain personally, jointly, and severally liable for the firm's debts — there is no legal wall between the business and the people running it. Register the same business as an LLP under the LLP Act, 2008, instead, and it jumps to the right side: an LLP is a body corporate with its own legal personality, distinct from its partners, who now enjoy limited liability.
The same line was drawn, more famously, on the other side of the world more than a century earlier. In Salomon v A Salomon & Co Ltd (1897), Britain's House of Lords held that even a company owned almost entirely by one man was still a separate legal person from him — his creditors could pursue the company, but not Mr. Salomon personally. That single ruling is the foundation the entire modern idea of a "legal entity" still rests on, in Indian courts as much as English ones.
Why regulators need to know exactly which entity is on the other side
A contract doesn't care who the humans in the room were. It cares which entity signed it. And once you're managing risk across an entire financial system rather than one deal, that distinction stops being a legal footnote and becomes the whole problem.
A bank doesn't just want to know it lent money to "the Ambani group" or "the Adani group." It needs to know precisely which entity within that group borrowed, because different entities in the same business family can have wildly different assets, different debts, and different ability to pay — lumping them together hides exactly the concentration risk a regulator is trying to catch. That's why the Reserve Bank of India's Large Exposures Framework, in force since 2019, puts a hard number on it: a bank's exposure to any single counterparty — or to a group of counterparties connected to each other — is capped at 25% of the bank's own Tier 1 capital. Checking that cap only means something if the system checking it can correctly tell that five small-looking borrowers are, in fact, the same connected group and not five unrelated ones.
RBI didn't invent that 25% figure — it adopted it. The number comes from the Basel Committee on Banking Supervision's own global Large Exposures standard, built in direct response to the 2008 crisis, when supervisors trying to work out who was exposed to whom discovered that the same institution could appear on different banks' books under different names, different spellings, and different levels of its own corporate structure — with no reliable way to confirm two records pointed at the same legal entity. The US and EU's post-crisis reforms — Dodd-Frank in America, the Bank Recovery and Resolution Directive in Europe — went further still, requiring the largest banking groups to file "living wills": resolution plans mapped out entity by entity, so that if the group failed, regulators would know in advance exactly which legal entity held which asset, and could be wound down without freezing the rest.
None of that works if "who's on the other side" is a guess.
The regulator's view: how one wrong match can hide a systemic risk
Everything above explains why a regulator needs entity identity correct in theory. In practice, several regulators have built live, granular monitoring systems that only work if it's correct — and the failure mode when it isn't is worth walking through with real numbers, not just a principle.
Since 2014, the RBI has required Indian banks and financial institutions to report every borrower with aggregate credit exposure of ₹5 crore or more, from every lender, into one system: the Central Repository of Information on Large Credits, or CRILC. The whole point is aggregation across lenders. A borrower owing ₹3 crore to Bank A and ₹4 crore to Bank B looks individually harmless to each bank — comfortably under the ₹5 crore threshold either one would separately worry about. Only when CRILC correctly joins both records to the same underlying legal entity does the real picture appear: ₹7 crore of aggregate exposure, past the threshold RBI actually cares about, and — if repayments have started slipping — a Special Mention Account flag raised system-wide, before either individual lender treats it as anything more than one small, well-behaved account. If Bank A reports the borrower as "X Pvt Ltd" and Bank B reports it under a slightly different registered name, or with a typo in the identifying code, that join never happens. The ₹7 crore exposure is real. The system just never sees it as one number.
The European Central Bank built the same idea, at a larger scale, for the euro area. AnaCredit, its loan-by-loan credit register, has required banks across the currency union to report individual loans above €25,000 since 2018, tagged — wherever an LEI is available for the borrower — by that code specifically, so that a company borrowing from banks in three different countries shows up to supervisors as one exposure, not three unrelated ones sitting in three national datasets that never compare notes.
Neither system is really about legal philosophy at that point. Both are, in effect, one very large join operation, run across every bank in a country or currency union, that only produces a correct answer if the key it's joining on — the entity's true identity — is unambiguous. Get that key wrong, and a systemic risk doesn't fail to exist. It just fails to be visible until after it's already happened.
What is not a legal entity
This is where reference-data systems most often go wrong, because plenty of things look like a party to a trade without actually being one in law.
A branch. Citibank's branch in Mumbai is not a separate legal entity from Citibank, N.A. — it's the same bank, operating locally under a banking license, not a company incorporated in India. Novation can replace your counterparty with a clearinghouse, but it can never make a branch into its own legal person; every contract that branch signs still binds the head office. The same rule holds the other way internationally — a US bank's London branch is not a UK-incorporated company either, and is typically identified for settlement purposes by a branch-level SWIFT/BIC code, which is a routing address, not proof of a separate legal identity.
A desk or a business division. "JPMorgan's FICC desk" or "the derivatives trading desk" cannot own an asset, sign a master agreement, or be sued — it's an internal organisational label inside one legal entity, nothing more. That distinction matters most exactly when it's ignored: in cases of rogue trading, the losses were booked as though a desk or an individual trader were somehow a contained, separate exposure — when in law, every position that trader put on belonged, in full, to the one legal entity employing them.
A fund scheme. In India, a mutual fund is constituted as a trust, and that trust — along with its Asset Management Company — is the legal entity. An individual scheme sitting under it, like a particular equity growth fund, is an accounting sub-division of that trust, not a legal person capable of contracting on its own. Internationally the shape repeats: a UCITS umbrella fund in Europe is typically one legal entity, or one umbrella structure, with individual sub-funds inside it that don't each carry a fully separate legal identity of their own.
The entity code: how a computer tells two "Reliance"s apart
Knowing, in principle, that entities matter is one thing. Building a system that can actually tell two similarly-named entities apart, at machine speed, across every bank and regulator on earth, is a different problem — and it needed its own solution.
That solution is the Legal Entity Identifier, or LEI: a 20-character alphanumeric code, one per legal entity, issued under the ISO 17442 standard by accredited "Local Operating Units" and overseen globally by the GLEIF — the Global Legal Entity Identifier Foundation, set up in 2014 at the G20's request in the same post-crisis push described above. Unlike a company's name, which can be spelled, abbreviated, or translated a dozen different ways across a dozen systems, an LEI is meant to be unambiguous: exactly one code, and the code isn't just a random string — every one of the 20 characters has a job.
- Characters 1–4: which Local Operating Unit issued the code — effectively, which country or registry vouched for this entity
- Characters 5–6: reserved, always "00"
- Characters 7–18: the entity-specific identifier that LOU assigned — the part that's actually unique to this one company
- Characters 19–20: two check digits, calculated from the other 18 the same way a credit card number's final digit is calculated from the rest
That last part is what makes the code self-verifying. Change one digit of an LEI by mistake — a fat-fingered entry, a copy-paste error — and the check digits almost certainly stop matching, so a system can reject it on the spot instead of silently booking a trade against the wrong company.
India adopted the same code rather than inventing its own. The RBI has, since 2017, progressively mandated LEIs — first for large corporate borrowers above a defined exposure threshold, then extended to participants transacting in government securities, money markets, and non-derivative forex and interest-rate derivative markets — precisely so a borrower's exposure across every bank in the system can be added up correctly, using one code instead of guessing from a name.
Europe went a step further and made the code load-bearing for the trade itself. Under MiFID II, an investment firm cannot execute a trade on a trading venue for a legal-entity client that doesn't have an LEI — the rule is blunt enough that the industry just calls it "no LEI, no trade." The EU's EMIR framework and the US's Dodd-Frank Act apply the same logic to derivatives specifically: every OTC derivative reported to a trade repository must carry the LEI of both counterparties, so that regulators trying to answer "who is exposed to whom" — the exact question that went unanswered in 2008 — can finally get a clean answer by machine, instead of by hand, months after the fact.
Why this matters for a Business Analyst
Think of two different books that happen to share the same title
A library that catalogued books by title alone would eventually shelve two unrelated novels under one entry, or lose track of which of five reprints a reader actually borrowed. It works only because every book also carries an ISBN — a unique number, with its own check digit, that doesn't care what the cover says. The title is for humans. The ISBN is for the system.
A company name is a book title. An LEI is its ISBN.
A KYC or counterparty-master system that matches parties by name string — "Reliance Industries" today, "Reliance Industries Ltd." tomorrow, "RIL" from a different desk's feed — will quietly either merge two distinct entities into one exposure record or split one real entity into two, and either error understates or fabricates concentration risk in exactly the report a regulator is going to ask for first. Matching on the LEI instead of the name is what actually keeps a hierarchy — ultimate parent, intermediate holding company, operating subsidiary — untangled across systems that were never built by the same team, using the same naming convention, at the same time.
It's also directly testable, not just conceptually correct. Because an LEI carries a built-in check digit, a QA professional can write a validation test the same way they'd validate an IBAN or a card number — reject anything that doesn't checksum, rather than trusting whatever string a front-office system happened to type into a free-text counterparty field. A reference-data defect here doesn't surface as a crash. It surfaces months later, as a large-exposure report that's wrong in a way nobody notices until an auditor — or a regulator — asks why the same company appears to owe money under two different names.
Lighthouse Insight
A contract has never once been signed by a family, a brand, a desk, or a fund's marketing name. It has only ever been signed by whatever the law is willing to call a person in its own right — and everything downstream of that signature, the exposure limits, the resolution plan, the regulatory filing, depends on getting that one fact correct.
Lehman didn't fail as "Lehman Brothers." It failed as thousands of separately incorporated entities that the industry had spent years treating, informally, as one name. The Legal Entity Identifier exists for exactly one reason: so that mistake is never allowed to happen silently again.
Continue the system
A curated path through the next concept, so one essay becomes a map.