US Kills BOI Reporting: What KYC Teams Must Know

FinCEN permanently removed US beneficial ownership reporting on August 14, 2026. KYC obligations remain — and the EU is moving in the opposite direction.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·9 min read
Share
US Kills BOI Reporting: What KYC Teams Must Know
imageUse this imagedownloadDownload

On August 11, 2026, the U.S. Treasury's Financial Crimes Enforcement Network issued a final rule that permanently removes the requirement for U.S. companies and U.S. persons to report beneficial ownership information under the Corporate Transparency Act. The rule took effect on August 14. FinCEN has also announced it will delete previously submitted data from U.S. persons from its Beneficial Ownership Secure System database.

The headline writes itself as a deregulatory victory. It is not that simple — and for compliance teams at financial institutions, the operational reality is considerably more nuanced than the press release suggests.

What the Final Rule Actually Does

The Corporate Transparency Act, enacted in 2021, required tens of millions of U.S. business entities to file beneficial ownership information with FinCEN, naming the natural persons who ultimately own or control them. The goal was to close the shell-company loophole that had long made the United States one of the easiest jurisdictions in the world to hide illicit wealth behind a registered entity.

The August 11 final rule strips that requirement for:

  • All U.S. domestic companies (LLCs, corporations, partnerships registered in any U.S. state)
  • U.S. persons who are beneficial owners of any reporting company

What remains in force:

  • Foreign entities registered to do business in the U.S. still must file beneficial ownership information, but only for foreign individuals — U.S. persons are carved out even in foreign-registered entities.
  • The 30-day reporting window for newly registered foreign entities remains unchanged, creating a strict intake-timing obligation for financial institutions onboarding foreign corporate clients.
  • FinCEN's deletion of previously reported U.S.-person data means any compliance team that relied on the Beneficial Ownership Secure System as a corroboration source has lost access to that data permanently.

What Has Not Changed

This is where many compliance teams risk serious error. The FinCEN CTA rollback is being described in financial media as an end to beneficial ownership compliance in the United States. It is not.

The beneficial ownership due diligence obligation for financial institutions has never lived in the Corporate Transparency Act. It lives in the 2016 Customer Due Diligence Final Rule — a separate, permanent regulation that requires banks, credit unions, broker-dealers, mutual funds, and futures commission merchants to collect and verify beneficial ownership information for legal entity customers at onboarding, and to maintain and update it on an ongoing basis.

That rule has not been touched. The 25% ownership threshold, the control prong, the obligation to re-verify on risk triggers — all remain unchanged. The FinCEN announcement says nothing about the CDD Rule because it cannot: the two frameworks are independent legal instruments. Truth Technologies, a specialist in AML compliance data, noted bluntly: "FinCEN Just Ended CTA Beneficial Ownership Reporting. Your AML/KYC Program's Due Diligence Obligation Did Not End With It."

For financial institutions, the practical consequence is precise: your KYC intake still asks who owns 25% or more of a corporate client. Your compliance program still requires verification. What changed is that you can no longer use the BOSS database to corroborate what a U.S. entity declares — because that database is being emptied.

The EU Is Moving in the Opposite Direction

The contrast with European regulatory trajectory could hardly be sharper.

On July 10, 2026 — five weeks before the FinCEN rule — EU Member States reached the transposition deadline for AMLD6's beneficial ownership registry provisions. Those provisions extend UBO verification requirements significantly beyond AMLD5: five-year historical ownership data, mandatory cross-border verification through BORIS (the EU's Beneficial Ownership Registers Interconnection System), and coverage of non-EU entities with EU nexus, including offshore structures holding EU real estate. The full implications for KYC teams are set out in our analysis of AMLD6's UBO registry requirements and what July 10 means for compliance programs.

On August 13, 2026 — the day before the FinCEN rule took effect — Ireland published its first National Anti-Money Laundering Strategy. Ireland's 2026 National Risk Assessment rated the crypto-assets sector as presenting a "very significant" risk for money laundering and terrorist financing, and the strategy mandates enhanced verification on transfers involving private crypto wallets and stricter due diligence on international digital asset firms. Ireland, as the EU's dominant fintech domicile, sets a tone that other Member States observe.

Looking further ahead, the EU's Anti-Money Laundering Regulation (AMLR), applying from mid-2027, will extend UBO verification requirements to new obliged entity categories and introduce harmonized thresholds across the bloc. The implications for KYB workflows are covered in our analysis of KYB under the AMLR and the 25% UBO threshold trap.

The Compliance Complexity Is the Problem

Financial institutions operating on both sides of the Atlantic now face a structural divergence in beneficial ownership requirements. The U.S. is dismantling its public registry. The EU is building one, making it interconnected, and extending its reach to offshore structures. Two clients in the same industry, doing structurally identical things, now face materially different documentary burdens depending on where their holding structure is domiciled.

This complexity is manageable only if compliance programs are built to track regulatory state rather than assume it. A team that builds its KYB process around a specific regulatory trigger faces repeated rework as that trigger changes jurisdiction by jurisdiction. A team that builds around a data model — who owns what, in what proportion, since when — and then applies the relevant rule set dynamically has a program that absorbs regulatory change without requiring manual redesign.

That architecture is what Joinble's AI Agents apply to ongoing monitoring. Rather than running a static KYB check at onboarding and re-triggering it only on client request, the agent layer tracks regulatory change, maps it against the client portfolio, and flags entities — or ownership percentages, or verification sources — that are affected. The FinCEN CTA rollback is not a compliance reset in that model. It is a data source change that the system processes, adjusting verification workflows for U.S. entities while leaving EU-facing UBO protocols intact.

What Financial Institutions Should Do Now

Action Priority Why
Audit your verification source mix for U.S. entities High BOSS database data for U.S. persons is being deleted
Confirm CDD Rule procedures are unchanged in your policies High They are — but document it explicitly, given the media noise
Update intake procedures for foreign entities registered in the U.S. High 30-day reporting window and requirements remain in force
Map client portfolios against AMLD6 and AMLR exposure High EU tightening affects EU-nexus clients regardless of U.S. deregulation
Brief senior leadership on the regulatory divergence Medium Divergence creates headline risk; management should not be surprised
Review BORIS access for EU-facing KYB workflows Medium Cross-border register queries are now required for EU entities

Why the "End of BOI" Framing Is Dangerous

Compliance teams do not set regulatory policy, but they absorb the consequences of how it is communicated. The "US kills BOI reporting" framing that has circulated since August 11 is technically accurate as a description of the CTA change. It is operationally dangerous if compliance teams — or their business partners — conclude from it that beneficial ownership verification is optional in the United States.

It is not. The CDD Rule is in force. In the enforcement environment of 2026, where AML penalties are at record levels globally, a compliance function that reduces its beneficial ownership verification rigor in response to a rule change it misread will be in a difficult position at its next examination.

The purpose of a compliance function is to know which rules apply, in what jurisdiction, to which clients. That task just became more complex, not less. Programs built around perpetual monitoring and continuous regulatory tracking — rather than annual policy review cycles — are the ones positioned to absorb this kind of change without operational disruption.

FAQ

Does the FinCEN CTA final rule eliminate my bank's obligation to verify beneficial owners?

No. The Corporate Transparency Act reporting obligation is separate from the 2016 CDD Final Rule. Banks, credit unions, broker-dealers, and other covered financial institutions remain required to collect and verify beneficial ownership information for legal entity customers under the CDD Rule, which has not been changed.

What happens to beneficial ownership data previously filed by U.S. companies?

FinCEN has announced that previously submitted beneficial ownership information for U.S. persons will be deleted from the Beneficial Ownership Secure System database. Financial institutions that relied on BOSS as a verification source need to identify alternative corroboration methods for U.S. entities.

Do foreign companies operating in the U.S. still need to file BOI reports?

Yes. Foreign entities registered to do business in the U.S. remain subject to BOI reporting requirements and must report the beneficial ownership information of foreign individuals within 30 days of registration. The exemption applies to U.S. companies and U.S. persons only.

How does the FinCEN rule interact with EU beneficial ownership requirements?

The two frameworks are entirely independent. EU entities and entities with EU nexus remain subject to AMLD6 UBO requirements regardless of U.S. deregulation. International firms must maintain two distinct compliance postures calibrated to each jurisdiction.

What should compliance teams do to fill the verification gap left by the BOSS database?

Financial institutions should audit their current verification source mix and identify alternative data sources for U.S. entity beneficial ownership corroboration. Third-party KYB data providers, state-level registry filings, and enhanced client questionnaires are the primary substitutes. Document the methodology change in your compliance program.

Is Ireland's new AML strategy relevant to non-Irish businesses?

Yes, particularly for crypto-asset service providers with Irish customers or partners. Ireland's strategy mandates enhanced due diligence for transactions involving private crypto wallets and international digital asset firms. Any CASP serving Irish customers should review its procedures against these requirements.

Emily CarterEmily Carter
Share

Related Articles

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up
Compliance07 Sep, 2026

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up

The EU AMLR's €2,000 gambling threshold takes effect July 2027. Deepfake attacks in iGaming surged 700% in 2026. Here's what operators must do now.

EU AI Act Article 50: Deepfake Rules Live—KYC Impact
Compliance03 Sep, 2026

EU AI Act Article 50: Deepfake Rules Live—KYC Impact

EU AI Act Article 50 entered force on 2 August 2026. Here's what the deepfake disclosure mandate means for KYC compliance and fraud defence.

DORA and KYC: Identity Vendors Are Now ICT Third Parties
Compliance31 Aug, 2026

DORA and KYC: Identity Vendors Are Now ICT Third Parties

DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.