Loading…
Loading…
The Corporate Transparency Act (Section 6403 of the Anti-Money Laundering Act of 2020, Title LXIV of the NDAA FY2021) required FinCEN to (a) collect BOI from reporting companies, and (b) promulgate rules governing who may access that information. The reporting rule was finalized separately (88 FR 76927, November 7, 2023, effective January 1, 2024). This access rule is the complementary instrument — it operationalises the database by specifying the conditions under which submitted BOI can be disclosed.
Six authorized-recipient categories are established:
1. US federal agencies — those engaged in national security, intelligence, or law enforcement activity, upon request using BOI to carry out those activities. 2. State, local, and tribal law enforcement agencies — with a court order, subpoena, or other lawful process in connection with a criminal or civil investigation. 3. Foreign law enforcement, judges, prosecutors, central authorities, and competent authorities — requests must come through an intermediary US federal agency; must relate to law enforcement, national security, or intelligence; and must be made under an international treaty/agreement or be an official request from a trusted foreign country. 4. Financial institutions — using BOI to comply with CDD requirements under applicable law, provided the reporting company consents. 5. Federal functional regulators and other regulatory agencies — assessing financial-institution compliance with CDD requirements in a supervisory capacity. 6. Treasury officers and employees — for tax administration, financial intelligence, or supervisory activities.
Phased implementation: FinCEN planned a staged rollout — beginning in 2024 with a pilot for key federal agencies, then extending to Treasury and agencies with existing BSA MOUs, then broader law enforcement and national-security agencies, then state/local/tribal law enforcement, then foreign-government intermediaries, and finally financial institutions and their regulators.
Data-security obligations: Each authorized recipient category faces tailored security-and-confidentiality requirements, including restrictions on re-disclosure, mandated security standards, and audit/oversight mechanisms enforceable by FinCEN.
companies began populating from January 1, 2024; a registry without clear access rules would have been a compliance burden with no law-enforcement payoff.
purposes, potentially reducing reliance on manual beneficial-ownership verification for covered accounts (31 CFR §1010.230).
participation — limits direct foreign-government access, preserving a US control point over cross-border information sharing consistent with FATF Recommendation 24 implementation policy.
BOSS — Beneficial Ownership Secure System) before broad financial-sector access opened.
interim final rule exempted domestic reporting companies from BOI reporting; with most US entities no longer filing, the database is populated only by foreign reporting companies registered in the US.
use cases (e.g., sanctions screening or fraud detection) in future rulemaking.
exemption) affects the value proposition of the access infrastructure for federal law-enforcement users.
operationally viable for allied-country law-enforcement partners seeking timely BOI data.