FinCEN Ends BOI Reporting: US KYC Burden Shifts to Banks

FinCEN's August 2026 final rule permanently ends CTA beneficial ownership reporting for US entities. Here's what shifts to banks and KYC teams.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·13 min read
Share
FinCEN Ends BOI Reporting: US KYC Burden Shifts to Banks
imageUse this imagedownloadDownload

On August 11, 2026, FinCEN issued the final rule that permanently ends Corporate Transparency Act (CTA) beneficial ownership information (BOI) reporting for US companies and US persons. Publication in the Federal Register on August 14, 2026 made the rule effective immediately. The database of previously reported information from US persons will be deleted. Only foreign entities registered to do business in the United States remain in scope. A four-year policy fight ended in less than a week — and the operational consequences for KYC teams are the opposite of what the headline suggests.

The temptation is to read this as deregulation. It is not. The reporting obligation is what disappeared. The underlying due diligence obligation on covered financial institutions remains untouched. What has changed is where the burden sits. It used to sit, at least in part, on the companies themselves and on a central register FinCEN maintained. It now sits entirely on the KYC and CDD workflows that banks, broker-dealers, mutual funds, and money services businesses have to run when they open an account for a legal entity customer.

What the August 11 Final Rule Actually Does

The rule narrows the scope of the CTA to what was arguably always its original diplomatic purpose: aligning the United States with FATF Recommendation 24 on beneficial ownership transparency for entities operating across borders. Domestic US companies — small LLCs, family holding structures, professional service partnerships, single-member entities used for real estate — are removed from the reporting regime entirely. Only "foreign reporting companies" (non-US entities registered to do business in any US state) still file BOI with FinCEN.

Three practical consequences flow from that narrowing:

  • The BOI database shrinks. Any information previously reported by US persons will be deleted from FinCEN's systems. It cannot be relied upon as a source of truth for onboarding or periodic review.
  • Enforcement of past non-filing is over. Penalties for US persons who missed the original filing window will not be pursued.
  • Foreign-entity filings continue. The subset of reporting companies incorporated outside the US and registered to do business here still owe complete BOI filings and are still exposed to civil and criminal penalties for non-compliance.

The FinCEN CDD Rule of 2016, which sits underneath all of this, does not move. The 25% ownership threshold, the requirement to identify at least one control person, and the certification of beneficial owners at account opening remain in force. Examiners at the OCC, FDIC, Federal Reserve, and FinCEN itself will continue to test beneficial ownership procedures against that 2016 baseline.

Where the Burden Actually Went

Compliance frameworks do not create work; they redistribute it. When the CTA was enacted in 2021, the theory was that a small share of the beneficial ownership verification burden would migrate away from banks and toward a central federal register. A single query to FinCEN would supplement, and in some cases substitute for, work that customer due diligence teams did on their own. That theory is over.

Two structural shifts follow from the August 11 rule.

First, US financial institutions lose a data source they had barely finished integrating. Firms that spent 2024 and 2025 building BOI-query workflows into their onboarding stacks now have to unwind them for domestic customers. The workflow does not disappear — the underlying due diligence obligation is unchanged — but the source it was pulling from has gone dark for every US entity in the client book. Whatever verification signal that query produced has to be replaced with something else: commercial data providers, direct evidence from the customer, or systematic cross-checks against state-level filings.

Second, the asymmetry between US and foreign customers deepens. A US bank opening an account for a Delaware LLC now has less of a public data trail to lean on than for a Cayman Islands entity registered to do business in California. That is the opposite of the risk-weighted approach most KYC programs have been designed around, and it is going to force revisions to enhanced due diligence triggers for domestic entities that were previously assumed to sit inside a paper trail.

Compare this to what is happening on the other side of the Atlantic. The EU spent the same period tightening beneficial ownership rules through AMLD6's UBO registry deadline, the AMLR's move to a "25% or more" threshold that reshapes every KYB engine in Europe, and the AMLA's direct supervision of the largest obliged entities. US and EU firms operating in both markets now sit on either side of a genuine regulatory divergence — and their identity verification stacks have to accommodate both.

The 2016 CDD Rule, Unchanged and Suddenly Louder

Between 2021 and mid-2026, some compliance teams treated the CTA and the FinCEN CDD Rule as overlapping. In practice they were always separate obligations, and the August 11 rule made that separation explicit. A quick reread of what the CDD Rule still requires is worth doing:

Requirement 2016 CDD Rule Effect After August 11, 2026
Identify beneficial owners at ≥25% Required for legal entity customers Unchanged — burden now entirely on the FI
Identify at least one control person Required regardless of ownership Unchanged
Certification form at account opening Required, retained for 5 years Unchanged
Verify beneficial owner identity CIP-consistent (name, DOB, address, ID number) Unchanged
Ongoing monitoring for material changes Required Reinforced by loss of central registry as backstop
Reliance on FinCEN BOI database Available (in theory) No longer available for US persons
Reliance on foreign BOI filings Available Still available, narrower dataset

Read that column on the right. Every "Unchanged" is a task that a bank was doing before the CTA existed, kept doing while the CTA was live, and has to keep doing now that the CTA has effectively been repealed for US entities. The difference is that the FinCEN safety net — thin as it was in practice — has been removed.

The examiners will notice. The FFIEC BSA/AML Examination Manual has never let institutions substitute a FinCEN BOI query for their own beneficial ownership certification and verification. Now that no such database exists for US entities, the "we relied on the register" defence that was never actually available becomes visibly unavailable.

What KYC and CDD Teams Should Do This Quarter

The final rule went effective on publication. There is no phase-in. Action items divide into three tracks: unwind, backfill, and reinforce.

Unwind the BOI-Query Path for US Entities

If your onboarding stack calls the FinCEN BOI database for US reporting companies, that call now returns nothing. Remove it from the workflow, or leave it in place with a clear "no longer authoritative" flag. Do not let a stale query result silently satisfy a CDD step. The related audit trail — proof that you performed the query — is now a proof that you performed a query against an empty dataset, which is worse than not querying at all if a regulator asks what you actually relied on.

Backfill the Signal with Commercial and Public Sources

The information the BOI database was meant to consolidate does not disappear; it is just spread back across the sources it came from. State-level Secretary of State filings, IRS EIN records, commercial UBO data providers (Bureau van Dijk, Dun & Bradstreet, Refinitiv), and the customer's own documented ownership disclosures now have to carry the weight the BOI database was expected to share. Concretely: your KYB workflow needs at least two independent sources of ownership evidence for every US legal entity customer, and the reconciliation between them must be recorded.

This is the same multi-source verification pattern that European firms are being forced to adopt under AMLD6. The compliance operating models are converging, even as the underlying legal frameworks diverge.

Reinforce Ongoing Monitoring

Static BOI data ages badly. Ownership changes, shell company reactivation, and the "synthetic business" attacks that the Federal Reserve warned about in November 2025 all depend on ownership information going stale between reviews. With no central federal register updating in the background, ongoing monitoring is now the primary defence against stale UBO records. That means event-driven review triggers on ownership changes, refresh cycles matched to risk tier, and an escalation path for entities whose ownership diagrams start to look inconsistent across sources.

The perpetual KYC model — verification treated as a continuous process rather than a point-in-time check — was already the direction of travel for European firms under the AMLA's ongoing monitoring guidelines. The August 11 rule pushes US firms in the same direction, even if the legal driver is now "operational necessity" rather than "regulatory requirement."

Foreign Reporting Companies: The Piece That Did Not Change

Non-US entities registered to do business in a US state are still reporting companies under the CTA. They still owe:

  • Full beneficial ownership information filings
  • Company applicant information (for entities registered after January 1, 2024)
  • Updated filings within 30 days of any change in beneficial ownership

Civil penalties of up to $591 per day and criminal penalties of up to $10,000 and two years' imprisonment for willful non-compliance remain on the books for this population. For KYB teams, that means foreign-entity customers are now the one segment where a FinCEN BOI query still returns authoritative data. The workflow bifurcates: US-entity paths query commercial and state sources; foreign-entity paths query FinCEN plus commercial and home-jurisdiction sources.

That bifurcation adds process complexity at exactly the moment when the industry is trying to consolidate KYB workflows into single pipelines. Autonomous AI agents that can route each entity down the correct verification path based on jurisdiction, ownership structure, and risk tier are increasingly the practical response — because the alternative is a manually maintained decision tree that decays with every regulatory update.

The Bigger Picture: Regulatory Divergence Is the New Baseline

Zoom out from the August 11 rule and a pattern is visible. In the space of eighteen months, the US and the EU have moved in opposite directions on beneficial ownership:

  • EU: Central UBO registers strengthened, BORIS interconnection live, 25% threshold reshaped by AMLR, AMLA taking direct supervision, five-year historical ownership data required.
  • US: Central BOI register wound down for the domestic population, obligations concentrated on financial institutions' own CDD processes, foreign-entity filings preserved.

Firms operating across both jurisdictions no longer have the option of a single global KYB playbook. Ownership verification in the EU means multi-source checks that include BORIS, AMLA-compliant CDD workflows, and evidence retained for periodic review by a central supervisor. Ownership verification in the US means multi-source checks that no longer include FinCEN for domestic entities but still include FinCEN for foreign ones. Two operating models, one client. The KYC stack has to reflect that. For the broader picture of that divergence, including Ireland's new national AML strategy and the AMLR timeline, see our analysis of what the FinCEN CTA rollback means for global KYC compliance.

The wider convergence — and this is what makes autonomous compliance interesting — is that both regimes are pushing toward the same operational answer even from opposite starting points. Multi-source verification, ongoing monitoring, event-driven review, and reconciliation across data sources are the common thread. Whether the driver is regulatory (EU) or operational (US), the underlying workflow is the same.

Joinble's AI Agents were built to run that workflow: query the sources appropriate to each entity, reconcile the results, flag inconsistencies, and route only the genuinely ambiguous cases to human reviewers. The August 11 rule does not reduce the volume of that work. It concentrates it, in a jurisdiction where it used to be partially externalized.

What Not to Do

A short list of tempting responses to the final rule that KYC leaders should resist:

  1. Do not tell the business that beneficial ownership requirements have been rolled back. They have not. The reporting obligation on US entities has been rolled back. The due diligence obligation on the FI has not.
  2. Do not remove BOI-related fields from the customer record. They are still required for the certification form and for the CDD Rule's identification requirement.
  3. Do not treat the rule as a signal that ownership verification is a lower priority. It is a signal that ownership verification is now more concentrated in the FI's own process, with less external validation.
  4. Do not assume this is the last word. The CTA has been through three rounds of litigation and two administrations' worth of policy reversals. A future rulemaking could re-expand scope. Systems built with only the current rule in mind will be brittle.

FAQ

Do we still need to collect beneficial ownership information from US legal entity customers?

Yes. The FinCEN CDD Rule of 2016 requires identification of beneficial owners at the 25% ownership threshold and at least one control person, regardless of whether those same individuals were reported to FinCEN under the CTA. Nothing in the August 11 final rule changes the CDD Rule.

What happens to BOI we previously reported for US entities?

FinCEN has stated it will delete previously reported information from US persons and US entities from the BOI database. Firms should not rely on that data for future onboarding or refresh cycles. If your workflow was pulling from BOI as a verification source, treat it as no longer available for US-entity customers.

Are foreign entities still required to file?

Yes. "Foreign reporting companies" — non-US entities registered to do business in any US state — remain in scope. They must file BOI, keep it updated within 30 days of any change, and are exposed to civil and criminal penalties for willful non-compliance. This is the one segment where a FinCEN BOI query still returns authoritative data.

How does this compare to the EU approach?

The EU is tightening. AMLD6's UBO registry provisions, effective July 10, 2026, expand scope, require five-year historical ownership data, and mandate multi-source verification. The AMLR reshapes the ownership threshold to "25% or more" and gives AMLA direct supervisory authority. US firms operating in the EU face both regimes, and their KYB stacks have to reflect the divergence.

Will examiners test our beneficial ownership procedures differently now?

The examination criteria under the FFIEC BSA/AML Examination Manual have not changed. What has changed is the practical evidentiary baseline. Examiners will still expect identification, verification, and certification at the CDD Rule's thresholds. They will not accept "we queried FinCEN" as a substitute for those steps for US entities, because the data is no longer there. Expect more scrutiny of the FI's own multi-source verification process, not less.

Does this affect enhanced due diligence for high-risk customers?

It reinforces it. EDD requirements are unchanged, but the data sources that supported them for US entities have narrowed. Firms that relied on BOI queries as one of the enhanced signals for a high-risk domestic customer now have to replace that signal with commercial data, direct evidence, or more intensive ongoing monitoring. The workload does not decrease; it redistributes.

Emily CarterEmily Carter
Share

Related Articles

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up
Compliance07 Sep, 2026

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up

The EU AMLR's €2,000 gambling threshold takes effect July 2027. Deepfake attacks in iGaming surged 700% in 2026. Here's what operators must do now.

EU AI Act Article 50: Deepfake Rules Live—KYC Impact
Compliance03 Sep, 2026

EU AI Act Article 50: Deepfake Rules Live—KYC Impact

EU AI Act Article 50 entered force on 2 August 2026. Here's what the deepfake disclosure mandate means for KYC compliance and fraud defence.

DORA and KYC: Identity Vendors Are Now ICT Third Parties
Compliance31 Aug, 2026

DORA and KYC: Identity Vendors Are Now ICT Third Parties

DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.