Content Library
Back
Share

One customer, three regimes: What global organizations need to know after FinCEN’s new UBO rule

Setting a UBO standard when US regulator steps back

One customer three regimes blog hero

On 11 August 2026, FinCEN issued a final rule removing the requirement for US companies and US persons to report beneficial ownership information under the Corporate Transparency Act (CTA). FinCEN is also deleting the information US persons have already filed. 

After taking effect on 14 August, what remains is narrow: only entities formed under foreign law and registered to do business in a US state or Tribal jurisdiction need to report, and even they no longer report US-person beneficial owners or US-person company applicants.

At almost exactly the same moment, Companies House is midway through verifying the identity of roughly six to seven million UK directors and Persons with Significant Control (PSC). Meanwhile, the EU is building interconnected registers with mandated legitimate-interest access ahead of the AMLR’s July 2027 application date.

Three regimes are moving in different directions, with the same customers sitting across all of them. Firms focused on the US and European markets need to reckon with the absence of a common UBO standard.

 

1.  Where the US, UK, and EU now stand

Inline graphic 1 One customer three regimes 1

One nuance that’s worth catching: state-level regimes that borrowed the Corporate Transparency Act (CTA) definitions collapsed with it. New York’s LLC Transparency Act took effect on 1 January 2026 but, because it defines “reporting company” by reference to the federal rules, it now only bites non-US LLCs. The fallback most people assumed existed does not.

2.  Designing the minimum standard

If FinCEN’s announcement broke your UBO KYC process, there are practical steps you can take to reconcile local standards across your global customer base. Rather than getting bogged down in country-by-country standards and creating and maintaining separate policy streams, first start with a global standard, and then enable local uplift from there.  

The design principle for a global standard is straightforward:

Set the group standard at the high-water mark. Permit local uplift. Never permit local downgrade. Treat registers as corroboration, never as source.

That gives you a policy that is jurisdiction-agnostic by construction, and one you can defend to the Financial Conduct Authority (FCA), to the Anti-Money Laundering Authority (AMLA) from 2028, and to a US examiner, without maintaining three parallel operating models.

Inline graphic 2 One customer three regimes 1

Honing in on discrepancies,  in the UK and EU, a discrepancy between what the customer tells you and what the register says triggers a reporting duty. In the US, although there is now no external registry to disagree with, it is still important to capture discrepancies noted by your firm.

3.  Practical considerations

Nothing changed for US financial institutions collecting UBO. The CDD Rule still requires identification of any individual owning 25% or more, plus a control person. What changed is the ability to corroborate what the customer shares based on FinCEN data. 

Re-baseline your reliance model for US entities. With no registry, the US file rests on customer attestation plus documentary evidence. State incorporation filings never carried ownership data. Make that explicit in procedures rather than leaving analysts to discover it at the desk.

Don’t confuse the February relief with a lower standard. FinCEN’s exceptive relief removed re-verification at every new account opening, not the obligation itself. Firms that used account opening as their de facto refresh mechanism now have a gap in their event-driven triggers. Check whether yours was doing quiet work you hadn’t documented.

Preserve what you already hold. FinCEN deleting its copy has no effect on your records. If you collected or received beneficial ownership information (BOI), your retention obligations are unchanged.

Resist a blanket country-risk uplift on the US. It is hard to defend, commercially expensive, and not what the change actually means. The defensible move is to treat verification difficulty as an input to EDD triggers and ownership-chain assurance, not to bump a country score.

Watch the sanctions interaction. OFAC’s 50% rule and the UK’s ownership and control tests both depend on tracing chains. Losing a registry makes chain tracing on US-formed entities harder at precisely the point where the consequences of getting it wrong are strict liability.

Sequence this with Anti-Money Laundering Regulation (AMLR). You need a group UBO standard in place before 10 July 2027 regardless. Do it once. A firm running a separate “US response” project alongside an “AMLR readiness” project is paying twice for one policy.

Implementing a UBO standard for your KYC process 

Implementing a global UBO standard that incorporates local regulatory guidance is critical for sustainable operations in multiple markets. But as a business grows, it becomes challenging to apply these standards consistently when facing increasing volumes of applications and KYC refreshes. Financial crime intelligence and orchestration technology like Alloy can help to automate KYC checks and provide context, and with Alloy’s AI Assistant, firms can remediate open cases much faster. Whether going global for the first time or facing higher growth worldwide, firms that can swiftly and elegantly adapt to regulatory changes can keep pace with their growth goals. 

The divergence is real, but it is primarily a divergence in jurisdiction-level transparency, not in what a regulated firm must know about its customer. That obligation has not moved on either side of the Atlantic. 

Firms that wrote their UBO policy around registers are now rewriting it. Firms that wrote it around evidence are in a better position to pass audits carried out by US, UK, and EU examiners.

Build a compliance program that keeps pace

Alloy helps financial institutions automate identity checks, adapt policies as requirements change, and apply consistent compliance standards across markets.

Explore our compliance solutions or contact us to learn more. 

Related content

Back