The US KYC landscape just shifted. Here’s what banks need to understand
Update, August 2026: Since this piece was first published, FinCEN has finalized the permanent end of beneficial ownership reporting for U.S. persons and companies, and confirmed it will delete previously filed data. This sharpens the argument below rather than changing it: the customer due diligence (CDD) rule was already the fallback source of beneficial ownership data. It is now the only source. The relevant sections have been updated to reflect this.
Four regulatory events between February and August 2026 have redrawn the compliance map.
This means less procedural duplication, higher substantive standards, and hard government deadlines. Together, they demand a fundamentally different approach to Know Your Customer (KYC) identity verification.
Four overlapping regulatory actions; a FinCEN exemptive order, a proposed rule on Anti-Money Laundering (AML) program reform, a pair of executive orders, and FinCEN’s August 2026 final rule permanently ending beneficial ownership reporting — have created a coherent and demanding new framework for US KYC compliance. For compliance officers, and their technology partners, the arc is clear: the era of process-based, box-ticking KYC is ending.
Here’s a breakdown of what changed, what it demands of banks, and what it means for institutions evaluating their data infrastructure.
| Date | Reference | Change | What it means |
|---|---|---|---|
| Feb 2026 | Order FIN-2026-R001 | CDD exemptive relief | FinCEN removed the requirement to re-verify ultimate beneficial owners (UBOs) at each new account opening. Banks verify once at initial onboarding, then only when new risk information warrants a refresh. Less procedural burden, but it raises the stakes on getting the first-touch verification genuinely right. |
| Apr 2026 | NPRM published | Bank Secrecy Act (BSA) program overhaul | FinCEN proposed a fundamental reform of AML/CFT program requirements under the BSA. The central shift: replacing a process-based standard with an effectiveness-based standard. Regulators will no longer ask “did you have a policy?”, they will ask “did your program actually detect financial crime?” |
| May 2026 | Signed 19 May | Two companion executive orders (EOs) | The Fintech Integration EO opens the banking perimeter to non-bank participants. The Integrity EO tightens the compliance standard for everyone inside it, mandating stronger CDD (90 days), Customer Identification Program reform (180 days), and a FinCEN advisory on UBO concealment typologies (60 days). |
| Aug 2026 | Final rule, 11 Aug | CTA reporting permanently ended for domestic entities | NEW — FinCEN made permanent the exemption of U.S. companies and U.S. persons from beneficial ownership reporting under the Corporate Transparency Act, and confirmed it will delete previously filed U.S.-person data. This is a distinct action from the February order above: it removes the federal reporting obligation itself, not just the account-opening re-verification trigger. The 2016 CDD rule, and banks’ own verification obligations under it, are unaffected and now stand as the only domestic source of beneficial ownership evidence. |
Three live deadlines compliance teams need on their radar
The May executive orders embedded concrete, non-negotiable mandates with specific timeframes. These are not guidance. Instead, they are enforceable deadlines.
| Deadline | Milestone | Detail |
| Jul 19, 2026 | FinCEN advisory on UBO typologies | Updated AML typologies covering shell companies, nominee accounts, UBO concealment, funnel structures, and structuring patterns. Banks must update risk typology libraries and assess current UBO controls. |
| Aug 17, 2026 | CDD rule changes | Treasury to propose stronger risk-based CDD; UBO identification named explicitly as a required outcome. This deadline lands alongside the August 11 final rule ending CTA reporting for domestic entities. With no federal BOI database for domestic entities, stronger risk-based CDD is expected to raise the bar on what banks’ own verification and evidence trail must independently demonstrate. |
| Nov 15, 2026 | CIP rule changes | Structural review of how banks verify identity at onboarding. Foreign consular ID cards specifically flagged as a risk under review. Every bank CIP policy requires review; existing accounts may need risk-based re-assessment. |
What “verified” is coming to mean
The April Notice of Proposed Rulemaking (NPRM) represents the most significant reframing of what compliance actually means. Morrison Foerster described it as a shift from “largely technical compliance” to a “more effectiveness-based, risk-driven framework” that elevates enterprise risk assessment. Gibson Dunn notes FinCEN is introducing a two-pronged framework: has an AML/CFT program been established at all, and is it being properly maintained, with the standards for each prong being defined for the first time.
Regulators will no longer ask whether you had a policy. They will ask whether your program actually detected financial crime. That is a fundamentally different evidentiary burden.
That expectation has since hardened rather than softened. On August 11, 2026, FinCEN permanently ended beneficial ownership reporting for U.S. companies and persons under the Corporate Transparency Act, and confirmed it will delete the data it already holds. The FinCEN beneficial ownership information (BOI) database that banks might once have cross-referenced against is being switched off for domestic entities. The 2016 CDD rule is unchanged, which means the cross-referencing this section describes now has to happen entirely inside the bank’s own infrastructure, against authoritative public registries and direct client attestations, with no federal backstop to check against.
In practice, “verified” is migrating toward a definition that encompasses three things:
- confirmed against an authoritative issuing source
- ownership claims cross-referenced to official registries or direct client attestation, since a federal register can no longer be assumed to exist
- and a chain of evidence that is demonstrable and audit-ready
What this demands of banks – and their technology
These four regulatory events do not simply add new tasks to existing workflows. They reshape the underlying logic of what good KYC infrastructure must do.
| Regulatory event | What it demands of banks |
|---|---|
| Feb 2026 — CDD exemptive relief | A robust, documented first-touch CDI profile the bank can rely on indefinitely; a reliable change-detection mechanism to trigger re-verification when ownership shifts. |
| Apr 2026 — NPRM | Ability to demonstrate to examiners that KYC processes produce reliable, evidence-based identity intelligence, not just document collection. Board-approved program documentation tied to data provenance. |
| May 2026 — EO: CDD mandate | Verification of nominal and beneficial owners against authoritative registries and direct client attestation, not self-certification. Registry coverage breadth across client jurisdictions was already a compliance question, not a product differentiator, and as of August 2026 the primary domestic registry, FinCEN’s BOI database, no longer holds data on U.S. persons. Banks’ own evidence chain now has to carry that weight entirely on its own for domestic entities. |
| May 2026 — EO: Fintech integration | Corporate KYC for fintech entities and crypto-native firms, often with novel, opaque, or multi-jurisdictional ownership structures. A FinCEN stablecoin CDD/CIP rulemaking is still outstanding. |
| Aug 2026 — Final rule ending CTA reporting | A documented, audit-ready ownership evidence chain built entirely in-house, sourced from authoritative public registries and direct client outreach, since there is no longer a federal register to lean on for domestic entities. |
The compliance review conversations that are now overdue
The specific areas of review have become more defined than they were six months ago.
Compliance teams should be asking:
- Does our first-touch onboarding meet the substantive standard the CDD rule changes will require?
- Do our AML typology libraries reflect the updated red flags the FinCEN advisory will introduce?
- Are our CIP policies already reviewing the document types likely to be flagged?
- Have we assessed the existing accounts opened on those documents?
- With no FinCEN BOI database to fall back on, where does our beneficial ownership evidence actually come from, and how is it kept current?
On the technology side, the question is equally pointed:
- Can our KYC data infrastructure demonstrate its own effectiveness to an examiner?
- Not just that it collected documents, but that it produced reliable, traceable identity intelligence with a complete audit trail?
The same evidentiary standard is now showing up outside AML entirely. The SEC’s mandatory central clearing requirement for U.S. Treasury transactions requires firms to prove legal-entity accuracy against Financial Industry Regulatory Authority (FINRA) and Depository Trust and Clearing Corporation (DTCC) or Fixed Income Clearing Corporation (FICC) records before a trade can clear. Verification backed by a documented, audit-ready trail is becoming the baseline compliance expects across the business, not a KYC-specific standard.
EC360 and the new regulatory standard
The executive order’s explicit requirement to identify nominal and beneficial owners against authoritative sources is precisely what EC360 automates, and it matters more now that FinCEN’s database can no longer serve as that authoritative source for domestic entities. The effectiveness-based standard introduced by the April NPRM means the quality of the evidence chain, not just the existence of a process, is what regulators will examine.
EC360’s Corporate Digital Identity (CDI) profiles include full data provenance and original source documents. They also include perpetual know your customer (pKYC) and continuous monitoring capability to detect ownership changes and trigger refresh, and a complete audit trail demonstrating when and why re-verification was or was not triggered. This enables the institution to demonstrate effectiveness under examination, built entirely from its own verified evidence rather than a federal register that may no longer be there to check against.
If you would like to discuss how these changes interact with your current onboarding infrastructure, please get in touch with our team.
Discover corporate digital identity from Encompass
what financial institutions need to know now
