Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Compliance Strategy

FinCEN Just Permanently Ended BOI Reporting for US Companies. Here's What Your Compliance Program Needs to Update Before Q4.

FinCEN's August 14, 2026 final rule permanently exempts all domestic US entities from Corporate Transparency Act beneficial ownership reporting. Here's what compliance programs need to change — and what the exemption doesn't touch.

By Rebecca Leung · September 2, 2026 ·
Table of Contents

TL;DR

  • On August 14, 2026, FinCEN’s final rule permanently exempted all domestic US entities from Corporate Transparency Act beneficial ownership reporting
  • Foreign entities registered in any US state still must file — the exemption is not blanket
  • The CDD rule (what banks collect from entity customers) is completely separate and unchanged
  • Compliance programs need to update regulatory inventory, policies, and bank partner questionnaire responses
  • BSA/AML obligations — SARs, CTRs, CIP, ongoing monitoring — are entirely unaffected

Three years of Corporate Transparency Act compliance work just became irrelevant for most domestic US businesses — but the compliance program updates that creates are deceptively easy to miss.

On August 11, 2026, FinCEN announced a final rule that became effective August 14, 2026, permanently exempting domestic US entities from the CTA’s beneficial ownership information reporting requirements. All entities created under US law — corporations, LLCs, limited partnerships, and the like — are now permanently exempt from filing BOI with FinCEN. US-person beneficial owners are also exempt from providing their information, and the FinCEN identifier program no longer applies to them.

The rule closes a chapter that started with CTA enactment in January 2021 and included an extended enforcement saga involving court injunctions, deadline extensions, and multiple interim rules. For many compliance teams, this has been an active compliance tracking item for years. That item is now closed — for domestic entities.

But “closed” isn’t the same as “done.” A regulatory change that eliminates a compliance obligation still requires compliance program updates. This is the part that generates findings.


Who’s Exempted and Who Isn’t

The scope of the exemption matters because it’s easy to overgeneralize.

Permanently exempted: All entities created under the law of any US state, territory, or tribal jurisdiction. This covers the vast majority of domestic operating entities — the LLC that is your company, the subsidiaries incorporated in Delaware, the operating partnerships organized under state law.

Still required to file: Foreign entities that have registered to do business in any US state or tribal jurisdiction. The rule defines “reporting company” going forward as only those entities formed under the law of a foreign country that have registered in the US. If your organizational structure includes foreign-registered entities — a parent company incorporated in the Cayman Islands, a subsidiary organized under UK law that registered to do business in New York — those entities may still have BOI filing obligations.

The FinCEN BOI resource page has the current guidance for entities evaluating their filing status.

Before you close out your CTA compliance tracking entirely, the first step is confirming which entities in your structure are domestic and which are foreign-registered. This is especially relevant for:

  • Fintechs with offshore holding structures (common in venture-backed companies)
  • BaaS or embedded finance platforms organized under foreign law
  • Companies with foreign subsidiaries that do business in US markets
  • Investment funds or SPVs registered in offshore jurisdictions that operate in the US

The CDD Rule: The Most Important Thing This Exemption Doesn’t Change

Before we get to what compliance programs need to update, there’s one critical distinction that’s already generating confusion in the market.

The Corporate Transparency Act BOI exemption affects one thing: whether your company must file beneficial ownership information with FinCEN.

It does not affect the Customer Due Diligence (CDD) rule at 31 CFR 1010.230.

The CDD rule requires banks, credit unions, broker-dealers, mutual funds, futures commission merchants, and introducing brokers — all “covered financial institutions” — to collect and verify beneficial ownership information from their legal-entity customers when opening accounts. That obligation has nothing to do with the CTA and isn’t changed by this rule.

If you’re a covered financial institution, you still have to:

  • Collect beneficial ownership information from entity customers at account opening
  • Verify that information under your CIP procedures
  • Update that information when it changes
  • Maintain records in accordance with BSA record-retention requirements

The logic is simple: the CTA created a government database of BO information. The CDD rule created a bank-level collection requirement. They’re parallel regulatory regimes that happen to involve the same subject matter. Eliminating one doesn’t touch the other.

FinCEN’s enforcement track record on CDD violations makes clear that BO collection failures remain a serious AML risk area regardless of CTA changes. Don’t let the BOI exemption news create misunderstanding in your BSA team about their ongoing CDD obligations.


What Your Compliance Program Actually Needs to Change

This is the practical work. Most of it is documentation and regulatory change tracking — lower-stakes than the CTA compliance itself, but still necessary to avoid the policy-reality gap that generates examination findings.

1. Update Your Regulatory Inventory

If your compliance program maintains a regulatory inventory or compliance obligation register, the CTA obligation for domestic entities should be marked as no longer applicable — with the basis for that determination (FinCEN final rule effective August 14, 2026) and the date documented.

This is the first place an examiner or auditor will look if they’re assessing whether your program tracked the change. The regulatory change management framework provides the documentation standard — a new rule, rule change, or rule rescission should be tracked from announcement through program update with dates and approvals at each step.

2. Update Your Compliance Calendar

Remove any future CTA BOI filing dates from your compliance calendar for domestic entities. If you have foreign-registered entities that still need to file, those dates stay — separately documented by entity with the basis for ongoing obligation noted.

3. Revise Compliance Policies and Procedures

If your compliance manual includes a CTA/BOI section — particularly if it describes filing procedures, record-retention requirements, or escalation paths for CTA compliance — that section needs updating. The policy should reflect the current state: exempt for domestic entities as of August 14, 2026; still applicable for any foreign-registered entities in the structure.

This is one of the most commonly missed compliance program updates. The regulation changes, the team knows it changed, but nobody updates the written policy. Six months later, an examiner or auditor reads the policy and asks why it still describes an obligation you don’t have.

4. Review Bank Partner Questionnaire Responses

If your bank partner’s vendor due diligence questionnaire includes questions about CTA compliance — and many do, because sponsor banks are required to assess their fintech partners’ regulatory compliance posture — your responses may need updating. A representation that “the company is in compliance with CTA beneficial ownership reporting requirements” should be updated to reflect that the obligation no longer applies to domestic entities, and when that determination was made.

This matters because inaccurate regulatory representations in bank partner questionnaires can become MRA-level findings if the inaccuracy is material and the bank’s examiner identifies it.

5. Remove CTA-Specific Controls from Ongoing Monitoring

If your compliance monitoring program includes periodic checks of CTA filing status — upcoming deadlines, beneficial owner changes that trigger updated filings — those controls are no longer needed for domestic entities. Remove them from your monitoring plan (with documentation of the removal and why), or they’ll generate false-positive alerts and consume compliance capacity unnecessarily.

6. Confirm FinCEN Database Deletion is Administrative

FinCEN has stated it will undertake a one-time administrative process to remove previously reported domestic company information from the BOI database. No action is required from reporting companies to trigger this deletion — you don’t need to file a withdrawal or request deletion.

Document this in your records: you don’t need to take any action on previously submitted filings, and the database cleanup is FinCEN’s responsibility.


What This Doesn’t Change

It’s worth being explicit, because the BOI exemption news is big enough to generate some confused internal questions.

Unchanged: BSA/AML reporting. Suspicious Activity Reports, Currency Transaction Reports, and all other BSA reporting obligations remain fully in force. The BOI exemption has no relationship to SAR or CTR filing requirements.

Unchanged: KYC and Customer Identification Program. Your CIP procedures for new and existing customers remain applicable. The CTA change doesn’t affect how you onboard or verify customer identities.

Unchanged: OFAC/sanctions screening. Sanctions obligations aren’t touched by the CTA rule.

Unchanged: State-level beneficial ownership disclosures. Some states have their own BO disclosure requirements independent of the CTA. The FinCEN rule doesn’t affect those.

Unchanged: Entity-level governance records. The operating agreements, shareholder records, and internal governance documents that capture beneficial ownership at the entity level are internal records. They’re not FinCEN filings, and the rule doesn’t change any obligation to maintain them.


So What? The Compliance Team’s Q4 Checklist

The immediate task is confirming that the change is documented, the relevant policies are updated, and any ongoing compliance calendar items are accurate. For most domestic fintech compliance programs, this is a four-step process:

  1. Confirm entity structure: Identify any foreign-registered entities that still have CTA filing obligations. Document findings.
  2. Update regulatory inventory: Mark domestic CTA obligations as no longer applicable with supporting basis.
  3. Revise written policies: Update or retire CTA sections of the compliance manual.
  4. Audit open items: Check that bank partner questionnaires, monitoring checklists, and compliance calendars reflect current state.

The Issues Management Tracker includes a regulatory change tracking module that logs rule changes from announcement through policy update — with the sign-off trail examiners and auditors look for when assessing whether your program stays current with the regulatory environment.


For authoritative current guidance, the FinCEN BOI information page has the final rule, updated FAQs, and entity-type guidance for companies evaluating their filing status under the new framework. For analysis of the final rule’s scope, National Law Review’s coverage and Mayer Brown’s breakdown of the permanent exemption’s mechanics are useful primary source supplements.

The rule change is significant. The compliance program work to respond to it is straightforward — but it still has to happen, and it has to be documented.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Did FinCEN permanently end BOI reporting for US companies?
Yes. On August 14, 2026, FinCEN's final rule became effective, permanently exempting domestic US entities from beneficial ownership information (BOI) reporting requirements under the Corporate Transparency Act. US-person beneficial owners and company applicants are also exempted. Only foreign entities that have registered to do business in any US state or tribal jurisdiction are still required to file.
Does the FinCEN BOI exemption affect the CDD rule — banks' obligation to collect BO from customers?
No. The Corporate Transparency Act BOI exemption is entirely separate from the Customer Due Diligence (CDD) rule at 31 CFR 1010.230. The CDD rule requires banks and other covered financial institutions to collect and verify beneficial ownership information from their legal-entity customers when opening accounts. That obligation is unchanged. The August 2026 exemption only affects whether a company itself must report to FinCEN — not what banks must collect from their customers.
Do foreign entities operating in the US still need to file BOI with FinCEN?
Yes. The August 2026 rule exempts companies created under US law, but foreign entities that have registered to do business in any US state or tribal jurisdiction still have BOI filing obligations. If your organization has foreign-registered subsidiaries or affiliates that do business in the US, you need to evaluate each entity separately — the exemption is not blanket.
What happens to BOI information already submitted to FinCEN by domestic companies?
FinCEN has announced a one-time process to remove, as practicable, information from the BOI database that would not have been required under the final rule — including information associated with domestic reporting companies and information reasonably identified as having been provided by or concerning US persons. No action is required to request deletion; FinCEN is handling this administratively.
What compliance program updates are needed in response to the BOI exemption?
For most domestic fintechs and financial services companies, the required updates include: removing CTA compliance obligations from your regulatory inventory and compliance calendar; updating your compliance manual or policy documentation to reflect the exemption; confirming the status of any foreign-registered entities in your structure; updating bank partner questionnaire responses where BOI representations appear; and documenting the change through your regulatory change management process with supporting evidence.
Are SARs, CTRs, and other BSA obligations affected?
No. Suspicious Activity Reports, Currency Transaction Reports, Customer Identification Program requirements, and all other Bank Secrecy Act obligations remain fully in force. The BOI exemption is narrowly scoped to CTA reporting — it does not affect any other BSA or AML requirement.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

◆ Keep reading

Related posts.

Compliance Strategy

DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.

The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.

Sep 9, 2026

Compliance Strategy

FinCEN's Scam Center Alert: What BSA Officers Need to Do with FIN-2026-Alert005

FinCEN's September 3, 2026 alert identified nearly $13 billion in suspected illicit activity tied to overseas scam centers running pig butchering, romance baiting, and cryptocurrency confidence schemes. Here's what the red flags are, who needs to file SARs, and how to update your transaction monitoring program.

Sep 6, 2026

Compliance Strategy

H.R. 10184 Would Cut the Maximum CFPB Penalty to $50,120 Per Day and Move Supervision to $30 Billion. What the CFPB Reform Act Means for Your Compliance Program.

The Consumer Financial Protection Accountability and Reform Act of 2026, introduced August 31, proposes to raise the CFPB supervision threshold to $30B, slash maximum daily penalties, narrow the UDAAP 'abusive' standard, and subject the bureau to congressional appropriations. Here's what it means for your compliance program — and what to watch regardless of whether it passes.

Sep 5, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.