What Happened
In late March 2025, the Financial Crimes Enforcement Network (FinCEN) issued a final rule exempting domestic companies and U.S. persons from beneficial ownership reporting under the Corporate Transparency Act (CTA). This rule also directed FinCEN to delete previously submitted information believed to belong to U.S. persons.
The Corporate Transparency Act, enacted in 2021, aimed to create a national beneficial ownership information database to track individuals controlling at least 25% of a company. Banks supported this law to simplify their customer due diligence. However, the database will no longer include domestic ownership information.
Foreign businesses must still disclose information about their foreign owners, but they won't have to report U.S. company applicants.
Timeline
2021: Congress enacts the Corporate Transparency Act as part of the National Defense Authorization Act, overriding a presidential veto. The law requires a national beneficial ownership information database.
2023-2024: The Biden administration implements the CTA reporting requirements. Business groups challenge these requirements in court, arguing they are overly complex and invasive.
March 2025: FinCEN issues an interim final rule exempting U.S. companies and persons from most ownership information reporting requirements.
Late March 2025: FinCEN issues the final rule, making the exemption permanent and ordering deletion of previously submitted U.S. person information.
Which Controls Failed or Were Missing
This situation represents a control failure at the regulatory level. The key gaps include:
No centralized verification source for domestic beneficial ownership. Banks must now independently collect and verify beneficial ownership information for every domestic legal entity customer. There's no federal database to cross-reference, creating a challenge in validating customer information.
Inconsistent data quality across institutions. Each bank's record is unique, and its accuracy depends on how well the institution sources and verifies ownership data. Your sanctions screening and Politically Exposed Person checks rely on the quality of the names you collect. Missing an owner creates a blind spot.
No mechanism for law enforcement to access ownership patterns. The database was designed for law enforcement needs. Without it, investigators lose the ability to identify shell company structures or trace ownership across entities.
What the Relevant Standard Requires
The Bank Secrecy Act and FinCEN's Customer Due Diligence (CDD) Rule still require banks to identify and verify beneficial owners of legal entity customers. This obligation remains unchanged.
Under the CDD Rule, you must:
- Identify beneficial owners who own 25% or more of a legal entity.
- Identify at least one individual with significant responsibility to control, manage, or direct the entity.
- Verify the identity of each beneficial owner using risk-based procedures.
- Maintain records of the information collected.
The CTA directed Treasury to revise the CDD Rule to allow banks to use the beneficial ownership database for compliance. That revision is now uncertain. You're back to building your own record for every customer, with no federal backstop.
The Financial Action Task Force (FATF) requires countries to implement beneficial ownership information regimes. The U.S. exemption puts the country out of step with FATF Recommendation 24, which calls for adequate, accurate, and timely information on beneficial ownership. This matters if you operate across borders or work with correspondent banks in jurisdictions that expect U.S. entities to meet international transparency standards.
Lessons and Action Items for Your Team
Strengthen your internal collection processes immediately. You can't rely on a federal database that doesn't exist. Review your account opening procedures for legal entity customers. Are you asking the right questions? Are you documenting control structures clearly enough to run effective screening? If your process assumes you'll eventually have access to a centralized registry, revise it now.
Invest in data verification tools. You need independent sources to validate what customers tell you. Consider third-party data providers that aggregate corporate registry information, news sources, and litigation records. These won't replace a federal database, but they'll help you spot inconsistencies.
Document your verification methodology. Examiners will want to see how you determined beneficial ownership when there's no authoritative source to check against. Your risk-based procedures need to be defensible. If you accepted a customer's self-certification, document why that was appropriate for that risk profile. If you conducted additional research, show your work.
Prepare for FATF scrutiny if you operate internationally. FATF will likely continue raising concerns about U.S. implementation of beneficial ownership standards in its ongoing mutual evaluation. If you're a U.S. institution with foreign branches or correspondent relationships, expect questions about how you're meeting international transparency expectations when your home country has exempted domestic companies.
Watch for CDD Rule revisions. The CTA directed Treasury to revise the Customer Due Diligence Rule to conform to beneficial ownership database implementation. That revision is now an open question. Stay current on FinCEN guidance. The agency may issue clarifications about what they expect banks to do in the absence of the database.
Escalate shell company red flags faster. Without a federal ownership database, law enforcement has lost a tool for investigating complex ownership structures. That puts more weight on your Suspicious Activity Reports. If you identify potential shell company abuse, structuring through multiple entities, or ownership patterns that suggest money laundering, file your SAR with detailed ownership information. You're now one of the few sources of that intelligence.
The irony is sharp: banks supported the Corporate Transparency Act because it would make their job easier. Now they're left with the compliance burden but none of the infrastructure. You're back to building ownership records one customer at a time, with no way to verify you got it right until something goes wrong.



