Dun & Bradstreet
A mockup of Dun & Bradstreet's Simplifying UBO eBook

Guide

Fewer UBO Reporting Requirements Don't Reduce Ownership Risk for Financial Institutions

When FinCEN’s March 2025 interim final rule narrowed Corporate Transparency Act (CTA) beneficial ownership reporting requirements for many U.S. entities, the compliance world noticed. Fewer filings, fewer deadlines, less administrative overhead; for teams that had spent months preparing for a wave of new reporting obligations, it felt like a reprieve.

But the risk that those reporting requirements were designed to address didn't shrink along with the paperwork. If you're a compliance or risk professional at a bank, insurer, or financial services firm, you're still on the hook for understanding who owns and controls the entities you do business with. That part hasn't changed. And in some ways the scaled-back reporting makes that job harder, not easier.

What Happens When Reporting Requirements Change but Compliance Obligations Don't?

It's worth stepping back and remembering why the CTA existed in the first place. The United States had a well-documented gap in beneficial ownership transparency. Opaque corporate structures gave bad actors room to hide, and regulators wanted to close that gap by requiring more entities to file beneficial ownership information (BOI) reports disclosing their ultimate beneficial owners (UBOs).

FinCEN's interim final rule pulled back on those requirements for many domestic entities. But it didn't touch the Customer Due Diligence (CDD) Rule, which still requires covered financial institutions to identify and verify UBOs during onboarding. Anti-money laundering (AML) and counter-terrorist financing (CTF) program expectations haven't been relaxed either. Sanctions screening still demands visibility into who stands behind an entity. And regulators still expect organizations to document how they reached their risk assessments.

So the filing requirement got smaller, but the compliance obligation stayed the same size. That's an important distinction, and it's easy to overlook if you're focused on what you no longer have to submit rather than what you still need to know.

Why Is Beneficial Ownership So Difficult to Trace?

On the surface, identifying a UBO sounds straightforward: find out who owns or controls a business. But anyone who's spent time tracing ownership chains through complex corporate structures knows the reality is a lot more tangled.

Ownership structures can stretch across multiple jurisdictions. They can involve holding companies stacked on top of other holding companies, trusts, investment vehicles, joint ventures, and nominee arrangements that make it genuinely hard to figure out who's pulling the strings. Some of that complexity exists for perfectly legitimate business reasons, and some of it doesn't.

The numbers help put the problem in context. The United Nations Office on Drugs and Crime estimates that somewhere between $800 billion and $2 trillion gets laundered globally each year. Europol has reported that 85% of the EU's most threatening criminal networks use legal business structures to launder criminal proceeds. These aren't edge cases. This is the operating environment that AML compliance teams navigate every day.

And the data doesn't always cooperate. Reporting standards vary by jurisdiction, and beneficial ownership registers update on different schedules. Records can be incomplete, inconsistent, or just plain wrong. When you're trying to build a clear picture of who owns what across borders, you're often stitching together fragments from sources that weren't designed to talk to each other.

The good news is that these dots can be connected. Corporate registries, regulatory filings, sanctions lists, and commercial data sources each hold pieces of the ownership puzzle, and when you layer them together with entity resolution and relationship mapping, complex global structures start to come into focus. It's not something most compliance teams can do manually at scale, but the path from fragmented data to a defensible ownership picture is more practical than it used to be. The guide we've linked at the end of this post walks through how to get there. But connecting the data is only half the challenge; the harder part is turning what you find into action.

How Can Compliance Teams Move from Identifying Risk to Addressing It?

A recent commissioned study conducted by Forrester Consulting on behalf of Dun & Bradstreet found that 71% of organizations struggle to move from identifying risk to treating it effectively. This finding points to a significant execution gap: many organizations can recognize risk, but have difficulty determining the appropriate response.

That same study found that only 11% of organizations can share risk data seamlessly across departments. So not only are teams struggling to act on what they find, they're often working with an incomplete picture because the information they need lives in someone else's system.

For UBO compliance, this is a critical concern. Identifying a beneficial owner is only the starting point. You still need to screen that person against sanctions lists, check for politically exposed persons (PEP) exposure, assess whether the ownership structure raises red flags, and document every step of that process in a way that holds up under regulatory scrutiny. When beneficial ownership data, screening results, and risk assessments sit in disconnected systems, each of those steps gets harder and takes longer. The odds of missing something go up.

The real question isn't just "can we identify UBOs?" It's whether your compliance program treats ownership as a vital thread that connects customer due diligence, sanctions screening, risk assessment, and ongoing monitoring into a coherent whole. Ownership intelligence that sits in one system but doesn't inform decisions across the program creates gaps, and those gaps tend to show up at the worst possible moment: during a regulatory examination, an audit, or after a suspicious activity report you didn't file.

How Do You Keep Beneficial Ownership Records Current?

There's another wrinkle that doesn't get enough attention: ownership structures rarely stay still. A company you cleared at onboarding a year ago might look very different now. Investors change, ownership stakes move, sanctions lists expand, and connections to higher-risk jurisdictions can come to light after the initial review.

None of that shows up if you're only looking at the snapshot you took during onboarding. And yet, a lot of compliance programs still rely on periodic reviews that happen on fixed schedules, regardless of whether anything meaningful has changed in between.

That's why more organizations are moving toward perpetual KYC (pKYC), which replaces those fixed review cycles with ongoing monitoring and event-driven reassessments. Instead of reviewing every customer on the same calendar, compliance teams focus on relationships where something has actually changed. It's a smarter use of limited resources, and it keeps the compliance program closer to what's really happening across the customer portfolio.

But this shift only works if you've got reliable, well-connected data underneath it. Monitoring tools are only as good as the information they're monitoring. And if that information is fragmented, outdated, or hard to trust, even the best monitoring program will have blind spots.

What Won't Change as Beneficial Ownership Regulations Evolve?

If the past few years have taught compliance professionals anything, it's that regulatory requirements can move in unexpected directions. The CTA's scope expanded, then contracted. Different jurisdictions are moving at different speeds on ownership transparency. Privacy regulations in some regions have made access to beneficial ownership data more complicated, not less.

What won't change is the expectation that financial institutions understand who stands behind the entities they do business with. Regulators will keep expecting it, and auditors will keep testing for it. And the consequences of getting it wrong, whether that's fines, reputational damage, or exposure to financial crime, will keep growing.

The organizations that handle this well won't be the ones that react to each regulatory change as it comes. They'll be the ones that build a consistent, repeatable approach to ownership transparency that connects data sources, supports defensible due diligence decisions, and adapts when the rules shift.

Explore the UBO Guide

Dun & Bradstreet has put together a comprehensive guide that covers all of this in more detail: the practical challenges of UBO identification, how to build a risk-based approach to beneficial ownership compliance, and what it takes to move from static reviews to continuous monitoring aligned with FATF recommendations.

Read "Simplifying UBO: The Ultimate Beneficial Ownership Guide for AML & KYC" to dig into the frameworks and strategies that can help strengthen financial firms’ compliance programs.

Download the Guide

There are multiple Contact Forms popups in the page. Only one Contact Form popup could be present on single page. Please reconfigure Contact Forms and refresh the page.