Beneficial ownership in the US after the BOI rollback: FinCEN points to the bank’s CDD record

Regulatory Analysis By 17 min read

Since August 14, 2026, every company formed in the United States has been permanently exempt from beneficial ownership information (BOI) reporting to the Financial Crimes Enforcement Network (FinCEN), and the foreign companies that still report name no US person. As a control that mitigates the risk of that exemption, FinCEN names a record that banks and other covered financial institutions already keep: the beneficial ownership information they collect from legal entity customers under its 2016 Customer Due Diligence (CDD) Rule, 31 CFR 1010.230. For a company formed in the United States, the bank’s certification file is now the record FinCEN points to, and the one law enforcement can reach on request.

The rule sets a minimum for that file. When a legal entity customer opens an account, the institution identifies each individual who owns 25 percent or more of it, directly or indirectly, and one individual with significant responsibility to control, manage or direct it. The information comes from the person opening the account, who certifies it “to the best of the individual’s knowledge.” The institution verifies the identity of each person named and may rely on the customer’s information about who its owners are, unless it knows facts that would reasonably call that information into question. None of it rests on a check against FinCEN’s own database.

When that work has to be repeated is less settled. As of September 2026, the answer sits in four documents that do not all say the same thing: the regulation, whose text has not been amended since September 28, 2017; a FinCEN order of February 13, 2026 and FinCEN’s CDD Rule FAQs, re-issued on May 6, 2026, which let an institution identify beneficial owners once per customer instead of once per account; and the Federal Financial Institutions Examination Council (FFIEC) BSA/AML Examination Manual, which still describes confirmation each time an account is opened. The revision of the CDD Rule that the Corporate Transparency Act (CTA) requires had not been proposed as of September 18, 2026. Treasury’s regulatory agenda of August 14, 2026 schedules the proposal for March 2027.

What the August 2026 BOI rule changed

FinCEN’s final rule, “Beneficial Ownership Information Reporting Requirement Revision,” took effect on August 14, 2026, the day it was published in the Federal Register. It adopts, with limited changes, the interim final rule of March 26, 2025.

The reporting regulation, 31 CFR 1010.380, now defines a “reporting company” as only an entity formed under the law of a foreign country and registered to do business in a US state or Tribal jurisdiction. Every entity formed in the United States is exempt. Reporting companies do not report any US person as a beneficial owner or company applicant, and US persons do not have to provide that information. A US person who obtained a FinCEN identifier no longer has to update it.

About 15 million reports from domestic companies reached FinCEN before the interim final rule, against about 13,000 from foreign reporting companies by the end of 2025, according to the final rule. Reports have arrived at about 100 a month since the interim final rule, and they list 1.2 beneficial owners on average: about half list one, and a further 25 percent list none, because the company had no non-US beneficial owner to report.

FinCEN is also removing information it already holds. It says privacy, information security and public trust argue for taking out of its BO IT System, as much as practicable, information that would not have been reported had the final rule applied from January 1, 2024, the date the reporting rule took effect. It will delete, in a single pass and working with the National Archives and Records Administration, the information on individuals who reported an identifying document that FinCEN reasonably believes a US person provided, such as a US passport or driver’s license. Individual companies will not receive confirmation of deletions; FinCEN will post a public notice when the process is complete. It does not expect to delete US-person information included in filings made after February 10, 2027. As of September 18, 2026, the deletion had been announced and was not complete.

The record FinCEN points to

In the final rule, FinCEN says that exempting domestic entities returns the tools for addressing their risks to where they stood before the reporting rule. Those tools, it says, include covered institutions’ continuing obligation under the 2016 CDD Rule, which “significantly mitigates” the risks posed by domestic entities and by foreign entities with US-person owners. FinCEN’s questions and answers on the final rule add that the CDD requirement gives covered institutions, “and law enforcement upon request,” valuable information about their legal entity customers, and that it “will serve to mitigate” risks created by exempting domestic companies.

According to the final rule, the reporting rule and the CDD Rule serve different purposes and arise under different legal authorities. The CTA tied them together at one point. Its section 6403(d)(1)(B) directed a revision of the CDD Rule to account for financial institutions’ access to BOI “in order to confirm the beneficial ownership information provided directly to the financial institutions.” In that design, what a customer certified to its bank would be checked against what the company had reported to FinCEN.

As of September 2026, the CDD Rule has not been revised to include that check. Access had not opened by March 2025: the March 2025 version of FinCEN’s small entity compliance guide to the access rule stated that financial institutions did not have access to BOI, that certain institutions would be in the final group given access, and that the access rule created neither a requirement nor a supervisory expectation that banks or other financial institutions access BOI. In August 2026, FinCEN put the question on its list of CDD Rule points it is considering whether to clarify: what it expects of financial institutions’ use of its “still-extant” BO IT System, or confirmation that CDD verification need not involve that system. Whatever FinCEN decides, that system no longer receives filings from US companies.

What a bank still has to collect and verify

The requirement covers legal entity customers: a corporation, limited liability company or other entity created by filing with a Secretary of State, a general partnership, or a similar foreign entity. Limited partnerships and business trusts created by a state filing fall within the definition; sole proprietorships, unincorporated associations and, generally, trusts do not. Companies listed on the NYSE, NYSE American or Nasdaq are excluded, while companies listed on foreign exchanges are not.

25 percent and one control person

A beneficial owner under the CDD Rule is each individual who directly or indirectly owns 25 percent or more of the equity interests of a legal entity customer, plus a single individual with significant responsibility to control, manage or direct it, such as a chief executive officer, chief financial officer, chief operating officer, managing member, general partner, president, vice president or treasurer. FinCEN expects that control person to be a high-level official responsible for how the organization is run. Every legal entity customer therefore has between one and five beneficial owners.

The threshold is 25 percent, not 20 percent, under both the CDD Rule and BOI reporting. It is the regulatory minimum. A lower threshold applies only where an institution sets one on the basis of risk, and on the same basis an institution may identify more than one controller. FinCEN also accepts that an institution may reasonably conclude a lower threshold would not help, and address higher risk by other means, such as enhanced monitoring.

FinCEN’s reference guide comparing BOI reporting with bank collection shows the two records differing in who counts, how many people are listed, what is collected and who vouches for it.

Bank’s record under the CDD RuleBOI report to FinCEN
Ownership25 percent or more of the equity interests, owned directly or indirectlyAt least 25 percent of the ownership interests, owned or controlled
ControlA single individual with significant responsibility to control, manage or direct the customerAny individual who exercises substantial control over the company
Number of beneficial ownersOne to fiveNo maximum
Social Security numberCollected, or another government identification numberNot required
Image of an identity documentNot among the required informationRequired
CertificationBy the individual opening the account, who may or may not be a beneficial owner, “to the best of the individual’s knowledge”By the filer, that the report is “true, correct, and complete”

Identities, not the ownership structure

For each beneficial owner, the institution collects a name, date of birth, address, and a Social Security number or other government identification number, which for a foreign person can be a passport number or similar. It verifies each beneficial owner’s identity under risk-based procedures that contain the elements of its customer identification program, and it may use photocopies of identity documents. The FFIEC manual adds that a bank need not establish the accuracy of every element of identifying information, but must verify enough to form a reasonable belief that it knows each beneficial owner’s true identity.

Nothing in the rule requires the institution to verify the ownership structure. It may rely on the customer’s information about who its beneficial owners are unless it knows facts that would reasonably call that information into question, and it need not independently investigate the customer’s ownership structure.

Indirect holdings still count, which puts arithmetic across entities inside the certification. In FinCEN’s example, Allan owns 30 percent of the customer through Company A and is a beneficial owner. Betty owns 20 percent through Company A and 16⅔ percent through Company B, 36⅔ percent in total, and is a beneficial owner. Carl and Diane each own 16⅔ percent through Company B and are not. The customer works out who crosses the line, and the individual opening the account certifies the result. What the institution verifies is that the people named are who the certification says they are.

FinCEN’s FAQs say a legal entity customer must identify its ultimate beneficial owners, not nominees or “straw men.” Where bank staff know, suspect or have reason to suspect that equity holders are trying to stay under the threshold, the FFIEC manual notes that a suspicious activity report may, depending on the circumstances, be required.

Measured against the fuller record of ownership, control and authority that KYC and KYB compliance systems keep, the regulatory minimum is one controller, up to four 25 percent owners, and identity verification for each. A lower threshold, a second controller or a mapped ownership chain is in the file only if the institution’s own procedures ask for it.

Once per customer: the February 2026 order

Until February 13, 2026, a covered institution had to identify and verify a legal entity customer’s beneficial owners each time that customer opened an account, however little time had passed between openings. FinCEN’s 2018 FAQs let the institution rely on information from an earlier account if the customer confirmed it was still accurate and the confirmation was recorded.

FinCEN’s order FIN-2026-R001, issued February 13, 2026 under 31 U.S.C. 5318(a)(7), grants exceptive relief from that per-account requirement. An institution may limit identification and verification of beneficial owners to three circumstances:

  1. When a legal entity customer first opens an account with it.
  2. Any time afterward, when it knows facts that would reasonably call the earlier information into question.
  3. As needed under its risk-based procedures for ongoing customer due diligence.

In the third circumstance, the institution may rely on information obtained earlier if the customer certifies or confirms, verbally or in writing, that it is up to date and accurate. The institution must keep a record of that certification or confirmation, including a verbal one. If the customer cannot confirm, or the institution knows of facts that call the information into question, it must identify and verify the beneficial owners again.

For an institution that takes the relief, opening another account no longer triggers identification. Knowledge of facts that call the earlier information into question does, and so does the institution’s own ongoing due diligence. By leaving the timing to the institution, the third circumstance turns a per-account step into a question of event-driven ownership refresh.

Using the relief is at the institution’s discretion: it may keep identifying beneficial owners at every account opening. FinCEN may revoke the relief, and the order does not change the rule’s exemptions for certain account types. Because 31 CFR 1010.230(a) makes the beneficial ownership procedures part of the covered institution’s own anti-money laundering program, an election to use the relief, and the procedures for each of the three circumstances, sit in that written program, as part of the institution’s AML program architecture.

On May 6, 2026, FinCEN re-issued its CDD Rule FAQs as one consolidated set, updated to align with the order. A new question, B.1.b, describes the relief, and the answers on new accounts, renewals and multiple accounts were revised.

Four documents, two models

The order and the re-issued FAQs describe identification once per customer. The regulation and the FFIEC manual still describe it once per account.

DocumentDateLater accounts for the same customer
31 CFR 1010.230 (the CDD Rule)Text as of September 16, 2026; last amended September 28, 2017Identification when each new account is opened
FinCEN order FIN-2026-R001Issued February 13, 2026Identification only in the three circumstances, for an institution that elects the relief
FinCEN CDD Rule FAQsConsolidated and re-issued May 6, 2026Aligned with the order (question B.1.b)
FFIEC BSA/AML Examination ManualAs displayed September 18, 2026Reliance on existing records with confirmation at each account opening; examiners sample new accounts

As of September 16, 2026, the regulation requires identification “at the time a new account is opened” and defines “new account” as each account a legal entity customer opens on or after the applicability date. The order grants relief from that requirement without changing its words.

The FFIEC manual’s beneficial ownership overview, as displayed on September 18, 2026, says that when a legal entity customer opens multiple accounts, a bank may rely on existing records provided it confirms, verbally or in writing, that the information is up to date and accurate “at the time each account is opened.” The passage cites FinCEN’s April 2018 FAQs and does not refer to the February 2026 order.

The manual’s examination procedures for beneficial ownership direct examiners to sample new accounts opened for legal entity customers since May 11, 2018. For each account in the sample, examiners test the bank’s regulatory operations and examination evidence on four points: whether the account was opened in accordance with 31 CFR 1010.230, whether identifying information was obtained for each beneficial owner, whether identity was verified within a reasonable time after opening, and whether the required records were kept.

An institution that uses the relief opens later accounts without a fresh certification. For those accounts, what it can show an examiner sampling “new accounts” is the link to the earlier record and its written procedures for the three circumstances.

That earlier record can outlive the account it was taken for. Identifying information must be kept for five years after the account closes, and verification records for five years after they are made. Where an institution relies on beneficial ownership information it already holds when opening a new account, FinCEN says it keeps the original records, any updates and any record of confirmation until five years after the new account closes.

Fintechs build the bank’s record

The CDD Rule binds covered financial institutions, and it binds a fintech directly only if the fintech is one of them. As of September 16, 2026, 31 CFR 1010.605 defines covered financial institutions as banks required to have an anti-money laundering program, broker-dealers registered with the Securities and Exchange Commission (SEC), futures commission merchants and introducing brokers registered with the Commodity Futures Trading Commission (CFTC), and mutual funds. Money services businesses are not on the list.

Because the beneficial ownership procedures belong to the covered institution’s own program, a fintech that collects ownership information for a partner bank is building the bank’s record, under the bank’s procedures. In the allocation of bank-fintech compliance responsibility, the obligation stays with the bank, whichever party collects the data.

Reliance on another party is possible under the rule, but only on a regulated institution. A covered institution may rely on another financial institution to perform the requirements only if the reliance is reasonable, the other institution is subject to an anti-money laundering program rule and regulated by a Federal functional regulator, and it contracts to certify annually that it has implemented its program and will perform the relying institution’s specified procedures. The FFIEC manual lists the Federal functional regulators as the Federal Reserve, the Federal Deposit Insurance Corporation, the National Credit Union Administration, the Office of the Comptroller of the Currency, the SEC and the CFTC. A fintech that none of those agencies regulates falls outside the provision.

The rewrite, now scheduled for March 2027

The February order describes itself as part of FinCEN’s obligation under the CTA to revise the CDD Rule, and FinCEN says it anticipates further changes through rulemaking. Section 6403(d) of the CTA requires a revision that brings the CDD Rule into conformance with the Anti-Money Laundering Act of 2020, accounts for financial institutions’ access to BOI, and reduces burdens that are unnecessary or duplicative.

Under section 6403(d), paragraphs (b) through (j) of 31 CFR 1010.230 are to be rescinded on the revised rule’s effective date; paragraph (a), the requirement to have written procedures, is kept by a rule of construction, as FinCEN’s December 2023 access rule notes. The certification, the verification and reliance standard, the 25 percent threshold and the single control person, the definition of a legal entity customer, the definition of a new account, the retention periods and reliance on another institution all sit in the paragraphs to be rescinded. An onboarding design built around the order may have to change again.

The statute set the timing as “Not later than 1 year after the effective date of the regulations promulgated under section 5336(b)(4).” FinCEN’s reporting rule implementing 31 U.S.C. 5336(b) took effect on January 1, 2024. Treasury’s regulatory agenda published September 22, 2025 listed the proposal, “Revisions to Customer Due Diligence Requirements for Financial Institutions” (RIN 1506-AB60), for May 2026, with comments closing in July 2026. The agenda published August 14, 2026 lists it, still at the proposed rule stage, for March 2027, with comments closing in May 2027. No proposal had been published as of September 18, 2026.

In the final BOI rule, FinCEN wrote that it is “still legally required” to modify the CDD Rule and that, having completed the reporting rule changes, it “can refocus” on it and intends to address the CDD issues commenters raised. The points it is considering whether to clarify include how institutions should reconcile BOI obtained under the CTA with what they collect themselves, and whether reduced BOI collection might mean more CDD obligations for institutions.

Source register

S1. Financial Crimes Enforcement Network — Final rule — Beneficial Ownership Information Reporting Requirement Revision, 91 FR 52508, August 14, 2026. Supports: the scope of BOI reporting from August 14, 2026; the removal of US-person information; FinCEN’s statements on the CDD Rule; filing figures; the reporting rule’s January 1, 2024 effective date.

S2. Financial Crimes Enforcement Network — Questions and answers — Final Rule: Questions and Answers, August 2026. Supports: which companies still report; the deletion process; the CDD requirement as a mitigant, with information available to law enforcement on request; the BOI definition of a beneficial owner.

S3. Financial Crimes Enforcement Network — Order — Exceptive Relief from Requirement to Identify and Verify Beneficial Owners at Each Account Opening, FIN-2026-R001, February 13, 2026. Supports: the per-account requirement before the order; the three circumstances; confirmation and its record; discretion and revocation; the order as part of the CTA revision.

S4. Financial Crimes Enforcement Network — Guidance — CDD Rule FAQs, consolidated and re-issued May 6, 2026. Supports: who is covered; the information collected and who supplies it; the control person; nominees; reliance and indirect ownership; thresholds; verification; legal entity customers and exclusions; retention when relying on existing records; the relief as re-stated.

S5. Electronic Code of Federal Regulations — Regulation — 31 CFR 1010.230, Beneficial ownership requirements for legal entity customers, text as at September 16, 2026, last amended September 28, 2017. Supports: definitions; the certification standard; verification and reliance; the definition of a new account; records and retention; reliance on another institution.

S6. Electronic Code of Federal Regulations — Regulation — 31 CFR 1010.605, Definitions, text as at September 16, 2026. Supports: which institutions are covered financial institutions.

S7. Federal Financial Institutions Examination Council — BSA/AML Examination Manual — Beneficial Ownership Requirements for Legal Entity Customers: Overview, as displayed September 18, 2026. Supports: confirmation at each account opening; the verification standard; suspicious activity reporting where owners avoid the threshold; the list of Federal functional regulators.

S8. Federal Financial Institutions Examination Council — BSA/AML Examination Manual — Beneficial Ownership: Examination Procedures, as displayed September 18, 2026. Supports: examiners’ sampling of new accounts and the tests they apply.

S9. Office of the Law Revision Counsel — United States Code, note to 31 U.S.C. 5311 — Corporate Transparency Act, section 6403(d), Pub. L. 116-283, 134 Stat. 4624, enacted January 1, 2021. Supports: the required revision of the CDD Rule, its purposes and timing, and the rescission of paragraphs (b) through (j).

S10. Financial Crimes Enforcement Network — Final rule — Beneficial Ownership Information Access and Safeguards, 88 FR 88732, December 22, 2023. Supports: the CTA’s retention of 31 CFR 1010.230(a).

S11. Financial Crimes Enforcement Network — Compliance guide — Small Entity Compliance Guide: Beneficial Ownership Information Access and Safeguards Requirements, Version 4.0, March 2025. Supports: financial institutions’ lack of access to BOI, and the absence of any requirement or supervisory expectation to access it.

S12. Financial Crimes Enforcement Network — Reference guide — Notice to Customers: Beneficial Ownership Information Reference Guide, July 2024, with a notice added after March 26, 2025. Supports: the differences between BOI reporting and bank collection in definitions, data collected and certification.

S13. Department of the Treasury — Regulatory agenda — Agenda, 91 FR 53050, August 14, 2026. Supports: the March 2027 proposal date for the CDD Rule revision (RIN 1506-AB60).

S14. Department of the Treasury — Regulatory agenda — Semiannual Agenda, FR Doc. 2025-18332, September 22, 2025. Supports: the earlier May 2026 proposal date for the CDD Rule revision (RIN 1506-AB60).

Related Insights

Continue through related analysis and the systems behind this publication.