FinCEN Ends Beneficial Ownership Reporting: What Accounting Firms and CFOs Must Assess Now
The Treasury Department's Financial Crimes Enforcement Network has issued a final rule permanently eliminating the requirement for US companies and US persons to report beneficial ownership information under the Corporate Transparency Act. The rule also directs FinCEN to delete previously submitted data it believes relates to US persons. For accounting firms, auditors, and CFOs who spent the past several years building CTA compliance workflows, this is a material change to the regulatory landscape and one that demands an immediate review of client obligations.
What the Corporate Transparency Act Required
The CTA was enacted as part of the National Defense Authorization Act of 2021. Its core purpose was to pierce the veil of anonymous shell companies by requiring individuals with a beneficial ownership interest in entities such as limited liability companies to disclose personal identifying information to FinCEN. The stated policy rationale was deterring money laundering, tax fraud, drug trafficking, and terrorism financing.
The reporting burden that triggered the rollback
The rule affected millions of small and mid-sized businesses. Compliance required gathering and submitting personal data on beneficial owners, defined broadly, and in many cases on company applicants, the individuals who physically filed formation documents. That scope triggered a wave of legal challenges and sustained industry opposition, including formal objections from the American Institute of CPAs. A series of court rulings created enforcement uncertainty, and the Treasury issued an interim rule in March 2025 suspending fines and penalties against domestic businesses while the litigation landscape settled. The final rule now makes that suspension permanent and goes further.
What the Final Rule Actually Does
The rule is effective upon publication in the Federal Register. It is not a phased rollback. Accounting teams should treat it as operative now and update client-facing guidance accordingly.
Key provisions firms must record
The final rule does several distinct things, and conflating them will create errors in client advice:
- Permanent exemption for US companies and US persons: The interim rule issued in March 2025, which suspended enforcement against domestic businesses, is now codified as a permanent exemption. US companies no longer have any BOI reporting obligation to FinCEN under the CTA.
- FinCEN ID holders released from update obligations: US persons who obtained FinCEN IDs are no longer required to update or correct the information they originally submitted to obtain those IDs. Firms that advised clients to register for FinCEN IDs as a compliance step should confirm no further action is required on those files.
- Foreign company applicant reporting eliminated: Foreign entities that are reporting companies no longer need to report US person company applicants, the individuals who helped those foreign entities register to do business in the United States. This is a targeted but meaningful change for firms advising inbound foreign groups.
- Foreign pooled investment vehicles exempted on US-person control: Foreign pooled investment vehicles registered in the US are now exempt from reporting BOI for a US person in control of the vehicle. This has direct relevance for fund administrators and asset managers serving cross-border structures.
- Active data deletion by FinCEN: FinCEN will delete information it reasonably believes relates to a US person, including company applicants, beneficial owners, and FinCEN ID recipients. The determination is made by reference to linked identity documents such as US passports or US driver's licences. This deletion is not optional or client-initiated; FinCEN will act on its own assessment.
What remains in scope: foreign entities
The exemption is not universal. Foreign entities that qualify as reporting companies under the CTA retain their BOI reporting obligations for foreign individuals. Accounting firms advising multinational clients, foreign subsidiaries operating in the US, or inbound investment structures must maintain a clear separation in their compliance tracking between US-entity and foreign-entity obligations. The rule does not extinguish foreign-person BOI requirements; it carves out US persons from within those structures.
AML and Compliance Implications for Accounting Firms
The permanent elimination of BOI reporting for US entities changes the compliance posture of a significant portion of most firms' client books. But it does not reduce the overall AML risk environment. Several downstream considerations require active attention.
Client file reviews and engagement letter updates
Firms that built CTA compliance into engagement letters, retainer scopes, or annual compliance calendars need to update those documents. Clients who were charged for BOI filing services may raise questions about ongoing fees tied to obligations that no longer exist. Clear, timely communication will prevent disputes.
At the same time, firms should not simply close CTA compliance files without a structured review. The residual foreign-entity obligations mean that some client structures, particularly those involving foreign parent companies or cross-border fund vehicles registered in the US, still carry live BOI requirements. A blanket assumption that all CTA obligations have ended is a compliance error waiting to happen.
Crypto accounting software and AML data workflows
For firms using crypto accounting software to manage digital asset clients, the BOI rollback intersects with broader AML data hygiene questions. Many crypto-native entities, DAOs structured as LLCs, tokenised fund vehicles, and cross-border DeFi operators, were among the entities most exposed to CTA obligations given their often complex or opaque ownership structures. With US-entity obligations now gone, the immediate compliance pressure on those structures shifts. But the underlying AML risk profile of crypto entities has not changed, and regulators in other jurisdictions, including the FATF, continue to push for disclosure standards that exceed what the CTA ever required. Firms relying on digital asset accounting software to track entity-level compliance data should ensure their AML tagging reflects the new US posture without inadvertently dropping monitoring flags that remain relevant under other frameworks.
The intersection of this rollback with ongoing global AML developments is worth watching closely. As discussed in our coverage of the FATF DeFi Report 2026 and the COSI test implications for your firm, international standards continue to evolve toward greater beneficial ownership transparency for DeFi protocols and crypto intermediaries, even as the US domestic framework contracts. A firm advising a crypto client with both US and non-US touchpoints now needs to maintain a split compliance view.
Sanctions and enforcement risk does not move with BOI
Accounting firms should be careful not to read the BOI rollback as a general softening of financial crimes enforcement. OFAC sanctions remain fully operative, and enforcement actions against crypto-linked entities continue. Our recent analysis of OFAC sanctions against Shelbit and Aban Tether illustrates that the enforcement environment for illicit finance through digital assets is, if anything, intensifying. The CTA rollback removes one data-collection mechanism; it does not remove the underlying legal risk of transacting with sanctioned parties or facilitating money laundering.
Tax and Accounting Treatment Considerations
The BOI rule itself is not a tax provision, but its removal has accounting implications that CFOs and their advisers should address.
Deferred compliance costs and accrual reversals
Entities that accrued costs for anticipated BOI compliance filings, legal reviews, or system upgrades in their financial statements may need to revisit those accruals. If the obligation no longer exists, a liability that was provisioned in prior periods may need to be reversed. The accounting treatment will depend on the specific nature of the accrual and the reporting period, but finance teams should flag this for review with their auditors.
Internal controls and documentation
For publicly listed entities or those subject to SOX-style internal control requirements, the removal of a previously documented compliance obligation is itself a change that needs to be captured in control documentation. The control that existed to ensure BOI filings were completed on time is now redundant for US entities. Leaving it in place without updating the control matrix creates audit noise. Removing it without documentation creates a gap. The right answer is a documented, dated control update that references the final rule and its Federal Register effective date.
Foreign subsidiary BOI: transfer pricing and group reporting
For multinational groups with foreign subsidiaries that remain subject to BOI reporting, the group-level compliance function should confirm that the foreign entity obligations are tracked separately and that country-by-country reporting processes, where relevant, are not inadvertently affected by assumptions about the US rollback applying group-wide. Transfer pricing documentation that references ownership structures may also need a review note confirming the current regulatory position.
What Accounting Firms Should Do This Week
The rule is effective on Federal Register publication. The following steps should be on the immediate agenda for any firm with CTA-related client exposure:
Immediate action checklist
- Identify all clients for whom CTA BOI filings were completed or were in progress. Separate US entities from foreign entities.
- For US entity clients: confirm the exemption applies, update engagement letters and compliance calendars, and communicate clearly that the obligation is permanently removed.
- For foreign entity clients: confirm residual obligations for foreign-person BOI reporting remain live and that compliance workflows are not accidentally wound down.
- Review any accrued compliance costs in client or firm financial statements and assess whether reversals are needed.
- Update internal controls documentation to reflect the removal of the BOI filing control for US entities.
- For crypto-native clients: assess whether the entity's AML data profile in your digital asset accounting software still captures all relevant non-CTA compliance flags, including OFAC screening, FATF guidance, and any applicable state-level requirements.
- Monitor FinCEN.gov for updated guidance materials, which FinCEN has confirmed it will publish to reflect the final rule. The agency has also issued a separate FAQ set alongside the final rule.
Frequently Asked Questions
Does this final rule affect crypto entities specifically?
The rule applies to all US companies and US persons subject to the CTA, including crypto-native entities structured as LLCs, DAOs, or other domestic legal forms. The exemption is not sector-specific. However, foreign crypto entities operating or registered in the US still carry BOI obligations for their foreign beneficial owners.
If a client already submitted BOI data, what happens to it?
FinCEN has confirmed it will delete information it reasonably believes is linked to a US person, using identity document markers such as US passports or driver's licences. This deletion is FinCEN-initiated. Clients do not need to file a deletion request, but firms should confirm with individual clients that their specific data profile meets FinCEN's criteria for deletion.
Are there any remaining BOI obligations for US companies under any other federal rule?
The final rule removes the CTA-based obligation. Other AML obligations, including Bank Secrecy Act requirements, OFAC screening, and sector-specific know-your-customer rules, remain fully in force. The BOI rollback is CTA-specific and does not alter those parallel frameworks.
How should firms update their crypto bookkeeping software or compliance systems?
Any compliance module or workflow tied to CTA BOI deadlines for US entities should be deactivated or archived, with documentation of the reason. AML monitoring flags tied to ownership transparency for crypto entities should be reviewed to ensure they reflect the current regulatory position in each relevant jurisdiction, not just the US, since international standards continue to apply.
Does this change the audit risk profile for clients who previously failed to file?
For US entities, the permanent exemption and the suspension of fines and penalties that preceded it effectively resolve prior non-compliance risk under the CTA. However, firms should obtain and retain a copy of the final rule for each affected client file. If any client faces a separate legal proceeding that referenced their CTA non-compliance, that is a matter for legal counsel, not just accounting review.
Source: Accounting Today
