FinCEN cuts BOI reporting, pressures banks
FinCEN ended domestic beneficial ownership reporting, stripping banks of a federal KYC reference and raising the bar for correspondent controls.
FinCEN permanently ended beneficial ownership reporting for domestic companies and U.S. persons under the Corporate Transparency Act, and said it will delete all historical filings from its database for those entities and now-exempt applicants. For banks and other financial institutions, the change removes a centralized verification source and shifts more weight onto internal due diligence, with direct effects on dollar correspondent relationships that serve complex structures across Latin America.
FinCEN has permanently ended beneficial ownership reporting requirements for domestic companies and U.S. persons under the Corporate Transparency Act, and confirmed it will delete all historical filings submitted by those entities and by applicants now exempted. For banks and other financial institutions, the change removes a centralized verification source and shifts more weight onto their own due diligence controls, with direct effects on dollar correspondent relationships that serve complex structures across Latin America.
What changes under FinCEN's final rule?
The final rule narrows reporting obligations to certain foreign entities registered to do business in U.S. jurisdictions that do not qualify for a statutory exemption. According to specialist analyses, those foreign entities must still disclose information about their foreign owners, but not about U.S. applicants. Even a foreign entity wholly owned by U.S. persons could file a report without identifying any owner on the beneficial ownership form.
That reduction also affects the quality of information available to the market. American Banker warned that scaling back the reporting regime removes or shrinks a due diligence tool banks and other financial institutions used to assess client and counterparty risk, especially in dollar transactions involving complex corporate structures.
How does this affect banks and correspondent relationships?
Ending domestic reporting leaves financial institutions without the federal registry as a backstop for verifying ownership in U.S. corporate clients. Global RADAR said banks will now need to rely almost entirely on their own CDD records, transaction monitoring, state records, and foreign registries to establish ownership and control.
The same report described internal CDD files as the "only evidence of ownership" in many cases, with greater operational and evidentiary risk for dollar correspondent relationships that work with complex corporate structures linked to Argentina and Mexico. It also recommended that banks with U.S. exposure brief their boards and audit committees that verification through the FinCEN database is no longer an option, and adjust onboarding procedures and CDD checklists before quarter end to remove dependencies on registry lookups.
Commerce Security Authority said the removal of domestic reporting puts the U.S. out of step with FATF Recommendation 24 and raises expectations for banks that operate cross-border with the U.S., including entities from Argentina and Mexico, to conduct their own due diligence. The same piece noted that the obligation under the Customer Due Diligence Rule to identify and verify beneficial owners remains unchanged, so the BOI registry is now more useful for foreign entities registered in U.S. states than for the bulk of domestic correspondent-bank clients.
What happens with CDD, third parties, and cybersecurity?
FinCEN's rule does not change Customer Due Diligence obligations under the BSA/AML framework, so banks must still identify, verify, and assess the risk of beneficial owners of legal entity customers, even without support from a federal database. FinCrime Central also said the absence of records or the presence of exemptions should not be treated as a low-risk signal, because assessments still rely on internal information, transaction behavior, and jurisdictional indicators.
The debate overlaps with another regulatory track. Secure Systems identified the key frameworks for U.S. financial institutions as the GLBA Safeguards Rule, FFIEC guidance used by examiners at the Federal Reserve, the OCC and the FDIC, and the NYDFS cybersecurity framework for licensed entities in New York, with requirements such as a designated CISO, annual compliance certification, encryption standards, and 72-hour incident reporting. For subsidiaries or branches of Argentine and Mexican entities in the U.S., those standards continue to function as de facto reference points.
Shumaker added that the FDIC proposed a "Synapse rule" in 2024 to require banks to keep accurate beneficial owner records in custody accounts, but the proposal was withdrawn. The same piece said bank-fintech contracts must make clear that responsibility for BSA/AML, fair lending, and safety and soundness cannot be delegated and remains with the bank, along with the need for data access clauses, audit rights, and cybersecurity standards in agreements with third parties located in Latin American jurisdictions.
Why does Mexico appear at the center of the contrast?
ShuftiPro described a regulatory asymmetry between Mexico and the United States. In Mexico, the July 2025 reform to the LFPIORPI and its March 2026 regulatory update lowered the beneficial owner threshold to 25%, required direct identification of the beneficial owner, and imposed continuous automated monitoring, with suspicious transaction reporting within 24 hours.
The same analysis said Mexican entities are moving toward heavily automated KYC and KYB models and ten-year record retention. That local tightening contrasts with the U.S. narrowing of BOI reporting and forces Mexican banks with U.S. correspondent relationships to reconcile different standards, in a setting where the United States is reducing centralized reporting while Mexico is demanding greater traceability of ownership and control.
Sources
- BaaS Enforcement, Synapse Fallout, and Contract Terms ...natlawreview.com· The National Law Review
- Why TPRM is a deal-stopper in 2026whizzc.com· Whizzc
- FinCEN Permanently Repeals Domestic BOI Reportingregtech.com· RegTech
- Banking Cybersecurity Requirements: Regulatory Landscape for Financial Institutionssecuresystems.com· Secure Systems
- Banks Lose Key KYC Tool as U.S. Ownership Reporting Exemptedcommercesecurity.org· Commerce Security Authority
- Compliance Brief - August 12, 2026globalradar.com· Global RADAR
- Beneficial ownership regime's demise removes tool for banksamericanbanker.com· American Banker
- Mexico KYC & AML Compliance 2026: The LFPIORPI Reformshuftipro.com· ShuftiPro
- FinCEN Final Rule Permanently Narrows U.S. Ownership ...fincrimecentral.com· FinCrime Central
- Who Owns the Compliance Failure? Bank-Fintech Liabilityshumaker.com· Shumaker



