On 21 July 2026, FinCEN Director Andrea Gacki told a House subcommittee that the revised beneficial ownership reporting rule is “very close to the finish line.” That sentence gets read as a compliance update. It is really a data announcement. When the final rule lands, the United States will have formally settled on a federal ownership registry that excludes 99.94% of the companies operating inside it — and every institution that needs to know who owns an American company will have to assemble that answer from somewhere else, permanently.
- Nothing changes operationally when the rule drops. The interim final rule has been in force since 26 March 2025. Finalisation converts a provisional position into a durable one.
- The perimeter went from 32,556,929 entities to roughly 20,000. GAO put it at over 99% of previously covered entities exempted, in a report released 29 May 2026.
- The obligation did not move to the states. Most states collect officers, directors and sometimes LLC managers. Four jurisdictions collect shareholder data. That is not beneficial ownership.
- New York’s LLC Transparency Act did not backfill it. It borrows the CTA’s definitions, so it narrowed when the CTA narrowed. It now covers only foreign-formed LLCs.
- The CDD rule is the surviving obligation, not the surviving dataset. Banks still have to identify beneficial owners. They just have to source that themselves.
What was actually said, and what it means
The hearing was a routine FinCEN oversight session before the House Financial Services Subcommittee on National Security, Illicit Finance, and International Financial Institutions. Most of the coverage focused on reporting thresholds — the subcommittee chair noted that institutions file nearly five million suspicious activity reports and over twenty-one million currency transaction reports a year, against an estimated $52 billion annual Bank Secrecy Act compliance cost.
On beneficial ownership, Gacki confirmed the revised rule is imminent but gave no date. That matters less than it sounds. FinCEN said in the March 2025 interim final rule that it intended to issue a final rule “this year” — meaning 2025. It did not. FinCEN officials told GAO in December 2025 that issuance had slipped because of the government shutdown and other factors, and that no revised timeline had been set. Sixteen months into a rule that was meant to be provisional, the provisional position is the operating environment.
What “beneficial owner” means in US law
Everything downstream turns on this definition, and it is narrower than most people assume. Under the CTA and 31 CFR 1010.380, a beneficial owner is a natural person who either:
The two-limb test
Ownership. Directly or indirectly owns or controls at least 25% of the ownership interests of the entity; or
Substantial control. Exercises substantial control over it — which captures senior officers (president, CFO, general counsel, CEO, COO, or anyone performing a similar function regardless of title), anyone with authority to appoint or remove senior officers or a majority of the board, and anyone directing important decisions.
Three consequences follow, and each of them is where KYB programmes leak. An entity can be a legal owner but never a beneficial owner — the test resolves to a human being. A person can be a beneficial owner while holding no equity and no title, purely through the control limb. And a registered officer, director, LLC member or manager is not automatically a beneficial owner: a manager may own nothing, and a 25% owner may appear nowhere in any public filing.
Thresholds also diverge once you leave the federal definition. Washington, DC sets its threshold at 10% and permits an entity, not just an individual, to be recorded as a beneficial owner. The CDD rule uses 25% for the ownership prong but requires only one control person. Many institutions apply a lower internal threshold for higher-risk customers. If your data model hard-codes 25% and “natural person,” it will silently disagree with several of the sources feeding it.
The arithmetic nobody puts in the headline
FinCEN’s September 2022 reporting rule identified 32,556,929 reporting entities once the twenty-three statutory exemptions were applied. The March 2025 interim final rule redefined “reporting company” to mean only entities formed under the law of a foreign country and registered to do business in a US state or tribal jurisdiction. Every entity created in the United States was exempted, and foreign reporting companies were relieved of having to report any US-person beneficial owners at all.
FinCEN’s own paperwork estimate for the new perimeter: about 20,000 entities coming into compliance in year one, plus roughly 5,000 newly registered foreign companies annually. The agency put the change in reporting burden at negative 91.5 million hours and roughly $9 billion a year.
GAO reached the same place from the other direction in GAO-26-107967, released 29 May 2026: the expanded exemption “applies to over 99 percent of entities that previously were required to report.” GAO recommended that Treasury identify actions to address the resulting gap. Treasury disagreed. The recommendation remains open.
Even for what is in the register, you cannot query it
A reasonable follow-up: fine, but there are still roughly 20,000 foreign reporting companies in there, and many of those are exactly the higher-risk entities you want visibility on. Can you use that?
Barely. The BOI Access Rule, effective 20 February 2024, governs who reaches the beneficial ownership IT system and on what terms. Covered financial institutions — banks, securities brokers and dealers, mutual funds, futures commission merchants and introducing brokers — sit at the most restricted tier of authorised recipients, below federal, state, local and tribal agencies. In practice that means:
- Consent-gated. An institution may only request BOI for a reporting company that has consented. No consent, no record.
- One entity at a time. Broad searches are not permitted. You submit identifiers for a specific company and receive a transcript for that company.
- No history. The transcript reflects the current filing, not previously submitted versions.
- No redistribution. Re-disclosure is prohibited outside narrow circumstances, consent documentation must be retained for five years, and misuse carries civil and criminal penalties.
That is a consent-gated point lookup for a customer you have already onboarded. It is not a data source. You cannot use it to screen a counterparty, resolve a corporate structure, detect a pattern across related entities, or enrich a book of business. Access was also phased in gradually — GAO is now on the second of seven statutorily required annual reports auditing FinCEN’s access safeguards. Nothing about the register was ever designed to be queryable in the way a compliance data pipeline needs.
Why the CDD rule does not close the gap
The standard rebuttal is that banks were never going to query the BOI register anyway — they collect beneficial ownership under the 2016 Customer Due Diligence Rule, and that obligation survives untouched. That is true, and it is also the argument Treasury made in the interim final rule itself: the continuing requirement for covered institutions to collect beneficial ownership at account opening “will serve to mitigate certain illicit finance risks.”
GAO tested the argument and found three structural holes in it. They are worth stating precisely, because they define exactly what a data layer has to do.
- Timing. The CDD rule captures ownership at account opening, not at entity formation. It tells you nothing about who originally created the company, or about a structure that was formed and never banked.
- Coverage. Not every transaction runs through a covered financial institution. Real estate, trade finance outside the banking perimeter, professional services and intermediated payments can all move value around an entity that no covered institution ever onboards.
- Queryability. The data sits inside individual institutions, not in a register. It cannot be searched across the economy, cross-referenced between institutions, or used to detect a pattern across a network of related entities.
Meanwhile the CDD obligation itself has been loosened. On 13 February 2026 FinCEN issued exceptive relief (FIN-2026-R001) removing the requirement to re-identify and re-verify beneficial owners at every new account opening. Institutions now do it at first account opening, when facts call previously obtained information into question, and as their own risk-based procedures require. FinCEN was statutorily required under the CTA to propose a revised CDD rule by 1 January 2025 and has not done so.
The adjacent calendar tells the same story. FinCEN's September 2024 rule extending AML programme and suspicious activity reporting obligations to registered investment advisers and exempt reporting advisers was postponed in December 2025 — from 1 January 2026 to 1 January 2028. That matters because Treasury's own 2024 assessment found that SEC-registered advisers to private funds appeared in suspicious activity reports at twice the rate of those that did not advise private funds. The population Treasury identified as elevated-risk now has two more years before programme obligations bite, and the entities they advise were already outside the beneficial ownership perimeter.
The practical effect
The requirement to know beneficial ownership is intact. The infrastructure that was supposed to help you know it is not being built. That difference is now permanent enough to design around.
What US state registries actually give you
Because company formation in the US is a state function, the argument that ownership data has simply devolved to the states comes up constantly. It is worth being precise about what states hold, because the gap between “ownership and control information” and “beneficial ownership” is where most KYB programmes quietly break.
GAO reviewed the five states with the highest corporation and LLC filing volumes — together nearly 40% of all registered corporations and LLCs as of July 2025.
| State | Corporate officers / directors | LLC members / managers | Beneficial owners |
|---|---|---|---|
| California | Collected | Collected | Not collected |
| Delaware | Collected | Not collected | Not collected |
| Florida | Collected | Collected | Not collected |
| New York | Collected | Not collected | Foreign-formed LLCs only |
| Texas | Collected | Collected | Not collected |
Source: GAO-26-107967, May 2026. Delaware collects no member or manager data, but has required registered agents since January 2019 to verify the identity of the person forming an entity and maintain a contact person for it.
Nationally, drawing on a December 2024 National Association of Secretaries of State survey, the picture is consistent: nearly all of the 45 states and DC that require periodic reports collect officer and director names; 30 states require the name and address of LLC members or managers; and only four jurisdictions — three states plus the District of Columbia — collect shareholder information at all.
Six jurisdictions go further and either set an explicit ownership threshold or refer to beneficial owners directly. Alaska requires biennial reporting of anyone holding 5% or more of a corporation’s shares. Arizona requires manager-managed LLCs to disclose managers and any member holding 20% or more. Kansas requires LLCs to report members holding 5% or more of capital. Washington, DC requires the name and address of anyone whose legal or beneficial ownership exceeds 10% or who controls the entity — though DC’s definition allows an entity, not just a natural person, to be a beneficial owner, and sets the threshold at 10% rather than FinCEN’s 25%.
None of this reconciles into a national picture. Different thresholds, different definitions, different filing cycles, different data fields, fifty-one separate systems and no shared search — our state-by-state guide to the official registries sets out what each jurisdiction publishes and how fast it updates. Worth noting: when GAO needed to count US business entities by state, it did not query the states. It used a commercial aggregator of secretary-of-state records. That is the state of the art, and it tells you what the actual solution shape is.
The entities that were never in scope at all
The BOI debate has been conducted almost entirely about LLCs and corporations, because those are the entity types the CTA reaches — it applies to entities created by filing a document with a secretary of state or similar office. That framing quietly excludes two categories that matter disproportionately in fund, holding and wealth structures.
GAO examined partnerships and trusts separately in December 2024 and found that states require registration and ownership information only from certain types, with the required fields varying by state and entity type. General partnerships in many states need not register at all. Trusts are typically creatures of private instrument rather than public filing. GAO reported that law enforcement officials described investigations being halted by an inability to determine beneficial owners using existing methods.
Treasury agreed with GAO's recommendation to monitor suspicious activity report data for partnership and trust risk and fold the analysis into future risk assessments. As of November 2025, GAO recorded that FinCEN had not yet acted on it.
For a data team the practical implication is scoping. If your US entity model handles LLCs and corporations cleanly and treats limited partnerships, statutory trusts and series entities as edge cases, you have built a model that degrades precisely where fund vehicles, holding structures and asset-holding entities live.
The state backstop that did not arrive
The expectation through 2025 was that states would fill the vacuum. They largely have not.
- New York enacted the LLC Transparency Act, effective 1 January 2026 — and then inherited the federal rollback. The Act defines “reporting company” by reference to the CTA and its implementing regulations, so when FinCEN narrowed the definition, New York narrowed with it. Governor Hochul vetoed the decoupling amendment on 19 December 2025, and the Department of State confirmed on 31 December 2025 that the Act reaches only LLCs formed outside the United States. The database is also closed to the public.
- California and Maryland both saw beneficial ownership legislation fail.
- Massachusetts House Bill 3566 remained under legislative study as of September 2025.
One state law, applying to one entity type, formed in one place, feeding a non-public database. That is the entire state-level backstop as of July 2026.
Where the answer comes from when the registry does not have it
Global Database sources company data first-party from official government registries — every US state plus DC, and 400+ registries across 200+ countries. That gives you the entity layer the US does publish (status, officers, directors, filings), the corporate-structure links that resolve a US entity to the group controlling it, and real beneficial ownership from the registries that do publish it — which is frequently where the controlling parent sits. Normalised into one schema, refreshed daily, with sanctions and PEP screening attached to the same record.
We will not claim complete US UBO coverage. The underlying record does not exist — for anyone.How a US ownership picture is actually assembled
If you accept that there is no lookup, the design problem gets clearer. A defensible US ownership picture is built from four layers, three of which are data problems you can solve and one of which is a process problem you cannot.
The layer worth dwelling on is the third. A large share of US entities that matter for risk purposes are subsidiaries, branches or vehicles of groups incorporated somewhere with a functioning beneficial ownership regime. For those, the ownership answer exists — it is just recorded in Companies House, a European register, or an APAC registry rather than in Washington. Resolving the US entity into its group and then reading ownership at the parent is often the difference between an inference and a record. Our guide to which countries publish UBO data maps where that works and where it does not.
The fourth layer is where honesty matters. For a US-formed entity with US owners and no foreign parent, no data provider can give you a verified beneficial owner, because no authority collects one. What you can do is collect it from the customer under the CDD rule, then use registry data to test the answer — does the declared owner appear as an officer or manager anywhere, does the corporate structure support the claim, does anything contradict it. Attestation plus contradiction-testing is a defensible programme. Attestation alone is not.
Which route applies to which entity
Before any of that is useful you have to know which branch an entity sits on, because the four layers do not apply equally. Most programmes treat every US entity the same way, which over-collects on the ones where ownership is retrievable and under-evidences the ones where it is not.
A worked example: tracing one entity
Abstractions are easy to agree with and hard to act on, so here is the same logic run end to end. The structure below is a composite, but every source, restriction and fee in it is real as of July 2026: a logistics operating company formed in Delaware, registered to transact business in Texas, sitting under a Cayman holding company, under a UK parent.
| Step | Source | What you get | What it costs |
|---|---|---|---|
| 1 | Texas Secretary of State | Confirms the entity is registered to transact business, its registered agent, and that its formation jurisdiction is Delaware. No ownership. | Free lookup |
| 2 | Delaware Division of Corporations | Entity name, file number, formation date, registered agent, franchise tax standing. Delaware collects no member or manager data. The US ownership trail ends here. | Free / low fee |
| 3 | Corporate structure data | Resolves the Delaware entity into its group and identifies the immediate parent as a Cayman exempted company. This step is the one that does not exist in any registry. | Commercial data |
| 4 | Cayman beneficial ownership register | A register does exist under the Beneficial Ownership Transparency Act, in force since 31 July 2024 — but it is not public. Access is case-by-case on demonstrated legitimate interest, which expressly includes a business conducting due diligence on a counterparty. | US$75 per search, US$250 annual |
| 5 | UK Companies House PSC register | The Cayman company’s parent is a UK limited company, so the person with significant control is published: name, month and year of birth, nationality and nature of control. | Free and public |
Two things are worth pulling out of that trace. The step that actually breaks the deadlock is step 3, and it is the only one with no registry behind it — group structure is the connective tissue that turns four disconnected records into one answer. And the step that finally yields a named human being is the furthest from the United States.
The direction of travel is not the same everywhere
Since 18 November 2025, UK directors and PSCs must verify their identity with Companies House under the Economic Crime and Corporate Transparency Act, with existing officeholders required to complete verification by 18 November 2026. So the UK is making its published ownership data identity-verified in the same window in which the US is finalising the removal of its own. For a US entity with a UK parent, the strongest evidence in the file will be foreign.
What contradiction-testing actually means
Saying attestation should be tested is easy. What follows is the part that is usually left implicit. None of these findings is proof of anything on its own — each is a prompt to ask a second question before the file is closed.
- The declared owner appears in no filing anywhere. Not an officer, director, member or manager in the formation state or any state of registration. Common and often innocent for a passive owner, but it means you have exactly one uncorroborated source.
- The registered agent address is shared at scale. Thousands of entities at one address is normal for a commercial agent, and also the standard signature of mass formation. What matters is whether the entity has any other footprint.
- Formation date sits close to the approach. An entity created weeks before it sought a banking relationship, with no operating history, deserves the question of what it was created for.
- Officers differ across jurisdictions. The same entity naming one set of people in its formation state and another in the states where it registered as a foreign entity.
- Declared control does not match the structure. The customer names an individual as controlling, but the group data shows the entity wholly owned by a parent whose own control sits elsewhere.
- The chain terminates in a jurisdiction with no accessible register. Not disqualifying — it tells you the ownership assertion cannot be independently corroborated, which is a risk rating input rather than a data gap to be quietly ignored.
What a defensible file contains
The examiner question is not “did you find the beneficial owner.” For a US-formed, US-owned entity there is frequently no source that could have told you. The question is whether your effort was proportionate, documented and repeatable. That is an evidence standard, and it can be written down.
| Capture | Where it comes from | Refresh |
|---|---|---|
| Entity verification | Formation-state registry record: legal name, status, formation date, entity number, registered agent | At onboarding, then on change |
| Registration footprint | Every state where the entity is registered as a foreign entity | Annually or on change |
| Officers and managers | State filings, noting that these are control indicators, not beneficial owners | At each periodic report cycle |
| Group structure | Corporate hierarchy resolving the entity to its ultimate parent and formation jurisdiction | At onboarding, then monitored |
| Ownership at the parent | The parent jurisdiction’s register where one is published or accessible on legitimate interest | On the parent registry’s own cycle |
| Customer attestation | The declaration collected under the CDD rule, with the date and the person who certified it | Per FIN-2026-R001 risk triggers |
| Contradiction log | What you tested the attestation against, what matched, what did not, and what you did about it | Every time the file is touched |
| Screening | Sanctions, PEP and adverse media on the entity and every named individual | Continuous |
One caution on refresh. State data typically only moves when a periodic report is filed, so between filings a record can be up to a year old — and in biennial-reporting states, two. A file that looks current because it was pulled yesterday may rest on a filing from eighteen months ago. Recording the underlying filing date, not just your retrieval date, is the difference between a defensible file and one that only looks defensible.
What to do when the final rule publishes
The rule is not a change event. It is a confirmation event — which makes it the right moment to close out assumptions that have been sitting provisional since March 2025.
- Confirm your policy documents describe the current perimeter, not the 2024 one. Several KYB policies still reference a domestic BOI filing obligation that has not existed for over a year.
- Check whether your onboarding flow still asks customers for a FinCEN identifier or BOI filing confirmation. For US-formed entities that field is now meaningless and creates a false assurance trail.
- Re-scope your foreign reporting company logic. Foreign-formed entities registered in the US must still file within 30 days of registration, and they are the population your BOI-related controls should target.
- Document how you satisfy the CDD rule now that FIN-2026-R001 has removed per-account re-verification. Examiners will want the risk-based trigger logic written down, not inferred.
- Identify which of your US entity population has a foreign parent. That subset has retrievable ownership; the remainder does not. Treating them the same way over-collects on one and under-evidences the other.
- Stress-test any vendor claim of US UBO coverage. Ask which source, for which entity types, and request a live sample on entities you already know — our buyer’s guide to company data APIs sets out the questions worth asking.
The US was upgraded for building this. Then it unbuilt it.
There is one part of this story that almost nobody connects, and it is the part that should worry anyone modelling how long the current position holds.
In March 2024, the Financial Action Task Force published its seventh Enhanced Follow-Up Report on the United States and upgraded the country on Recommendation 24 — transparency and beneficial ownership of legal persons — from Non-Compliant to Largely Compliant. FATF attributed the upgrade to the implementation of the Corporate Transparency Act together with the CDD Rule. Treasury issued a press release describing it as the result of nearly a decade of work to stop the flow of money through anonymous companies.
Twelve months after the upgrade, the reporting obligation that earned it was removed for 99% of the entities it covered. The other pillar FATF credited — the CDD Rule — has since been narrowed by exceptive relief, and the statutorily required revision to it has still not been proposed.
The United States reports back on Recommendation 24 in the fifth round of mutual evaluations, assessed against the 2022 methodology which raised the beneficial ownership standard rather than lowering it. The US already carries Non-Compliant ratings on three Recommendations covering non-financial businesses and professions — lawyers, accountants, real estate agents, and trust and company service providers — which is the exact professional layer through which US shell structures are typically formed.
Two things follow for planning. First, the external pressure to rebuild something is real and comes from a body the US helped found, so a permanent gap is not guaranteed. Second, and more useful: any rebuild would arrive as a new collection mechanism years from populated, and the 2022 methodology now expects multi-source verification rather than a single register. Whatever replaces this will look more like an assembled ownership picture than a lookup. Which is the same thing you have to build today.
The reversal risk, priced honestly
Building around a permanent gap invites the obvious challenge: what if it closes? Three live paths, none of them close to resolution.
| Path | Status as of July 2026 | Direction |
|---|---|---|
| H.R. 425 and S. 4419 | H.R. 425 was reported out of the House Financial Services Committee 26–25 in April 2026; as amended it codifies the foreign-only scope and directs FinCEN to delete domestic data already collected. The Senate companion takes the same approach. | Widens the gap |
| GAO recommendation | Open. Treasury disagreed with the recommendation to identify actions addressing the gap. | Pressure only |
| CTA litigation | The Eleventh Circuit upheld the CTA as a valid exercise of the Commerce Clause; cert petitions remain in play. | Unresolved |
Read together, the probability-weighted answer is that the gap persists and may be written into statute. Even in the reversal scenario, a registry rebuilt from scratch would take years to populate and would still exclude the twenty-three statutory exemption categories. There is no version of the next thirty-six months in which a federal BOI lookup is your primary US ownership source.
Which leaves the working conclusion. US ownership data is an assembly problem, not a retrieval problem, and it will stay that way. The organisations that handle it well are the ones that stopped waiting for the register and started building the assembly. If you are still deciding how to structure that, our comparison of UBO data providers covers who can supply which layer, and on what sourcing.
Get US company data the way your stack needs it
The same registry-sourced dataset, three delivery routes. Query it live through the API for onboarding and verification, with a unified JSON schema across all 51 US jurisdictions. Pull it as a bulk feed refreshed daily via S3, SFTP or direct database sync for analytics, modelling and screening at scale. Or research entity by entity in the online platform for due diligence and investigations.
Built for compliance, risk, onboarding, due diligence and data engineering teams.