Skip to main content
Category: Beneficial Ownership

Beneficial Ownership Information Collection

Also known as: BOI, Beneficial Ownership Information Reporting, BOI Reporting
Simply put

Beneficial Ownership Information (BOI) collection refers to the process of gathering data that identifies the true individuals who own or control a business, as opposed to only the names of the company or its legal representatives. In the United States, this collection is administered by FinCEN, though the applicable requirements have been substantially narrowed under a revised rule. Under that rule, U.S. companies are exempt from BOI reporting, and the collection now applies on a voluntary basis to certain individuals.

Formal definition

Beneficial Ownership Information (BOI) collection is the gathering by FinCEN of specified data identifying the true owners and controllers of a business entity, distinct from its legal ownership. Under the revised final rule published in the Federal Register on March 26, 2025, U.S. companies are exempt from BOI reporting requirements and are no longer required to file BOI reports; the collection is characterized as voluntary, requiring individuals to report certain information about themselves to FinCEN in order to receive a FinCEN identifier. The revised rule further contemplates the destruction of previously submitted U.S. business BOI. Practitioners should confirm the current scope, exemptions, and applicable procedures directly against the operative FinCEN rule, as this regime has been materially altered from its original form and the details described here reflect the revised requirement rather than a stable, long-standing standard.

Why it matters

Beneficial ownership transparency is a central pillar of anti-money laundering policy because illicit actors frequently exploit opaque corporate structures to disguise the individuals who ultimately own or control an entity. By distinguishing beneficial ownership, the natural persons who truly own or control a business, from legal ownership, which may reflect only nominee directors, holding companies, or registered agents, BOI collection is intended to help authorities and, in some regimes, obliged entities identify the human beings behind legal persons. This distinction matters operationally: customer due diligence processes have long grappled with the challenge of piercing layered ownership chains, and centralized beneficial ownership data can support that work.

Who it's relevant to

Compliance Officers at Obliged Entities
Compliance professionals who previously relied on, or anticipated relying on, FinCEN's BOI collection as a reference point for verifying customer ownership structures should note that the regime has been substantially narrowed and that U.S. companies are now exempt from reporting. They should confirm the current scope and available data directly against the operative FinCEN rule, as this framework has changed materially from its original form.
U.S. Companies and Small Businesses
Under the revised rule, U.S. companies are exempt from BOI reporting requirements and are no longer required to file BOI reports. Entities that had prepared for or completed filings should be aware that the rule contemplates the destruction of previously submitted U.S. business BOI, and should verify their specific obligations, if any, against the current FinCEN guidance.
Individuals Seeking a FinCEN Identifier
The revised collection is characterized as voluntary and applies to certain individuals who report information about themselves to FinCEN, for instance, to obtain a FinCEN identifier. Such individuals should review FinCEN's current procedures to understand what information is requested and how it is used.
Legal and Regulatory Advisors
Attorneys and regulatory specialists advising clients on corporate transparency obligations should treat the March 26, 2025 revised final rule as the operative reference and avoid presenting the prior, broader reporting requirement as the current standard. Because the regime has been materially altered rather than settled, advisors should confirm scope, exemptions, and applicable procedures against the current rule.

Inside BOI

Identifying Particulars of the Beneficial Owner
Typically includes the natural person's full legal name, date of birth, residential or correspondence address, and nationality. Many regimes also require a national identification number, passport number, or similar identifier. The precise data points required vary by jurisdiction and should be confirmed against the applicable regulation.
Nature and Extent of the Beneficial Interest
Information describing how and to what degree the individual owns or controls the legal entity or arrangement, for example, the percentage of shares or voting rights held, or the nature of control exercised. Ownership thresholds commonly used as an indicator (such as a specified percentage) vary between regimes, and control-based beneficial ownership may exist even where no ownership threshold is met.
Ownership and Control Structure
Documentation of the chain of ownership and control linking the customer to the ultimate beneficial owner, including any intermediate legal entities, nominees, or arrangements. This distinguishes legal ownership (the registered or titular holder) from beneficial ownership (the natural person who ultimately owns or controls).
Verification Evidence
Records used to verify beneficial ownership information, which may include corporate registry extracts, constitutional documents, shareholder registers, or trust deeds. The extent of verification generally depends on the assessed risk and the requirements of the applicable regime; collection and verification are distinct steps.
Senior Managing Official Fallback
Where no natural person can be identified as a beneficial owner through ownership or control after exhausting reasonable measures, many regimes permit or require identification of a senior managing official as a fallback. This is generally treated as a last resort rather than a default.
Source and Currency of Information
The origin of the information (for example, self-declaration by the customer, a central register, or independent sources) and arrangements for keeping it current. Reliance on a central beneficial ownership register, where one exists, does not necessarily discharge an obliged entity's own due diligence obligations, and this varies by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about BOI.

Is beneficial ownership the same as legal ownership?
No. Legal ownership refers to the person or entity in whose name a share, asset, or account is registered, whereas beneficial ownership refers to the natural person(s) who ultimately own or control the entity or on whose behalf a transaction is conducted. A legal owner may hold an interest for another party's benefit, and a beneficial owner may exercise control without appearing on any register. This distinction is central to beneficial ownership collection because obliged entities are generally expected to look through legal and nominee arrangements to identify the ultimate natural persons, and the exact tests for control differ across regimes such as the FATF Recommendations, the EU AML framework, and US FinCEN rules.
Does collecting beneficial ownership information satisfy an entity's full customer due diligence obligation?
Not on its own. Identifying and verifying beneficial owners is one component of customer due diligence, but CDD typically also involves identifying and verifying the customer itself, understanding the nature and intended purpose of the relationship, and conducting ongoing monitoring. Beneficial ownership collection is a discrete step within that broader process, and higher-risk relationships may trigger enhanced due diligence measures that go beyond baseline collection. Treating beneficial ownership data capture as the whole of CDD would leave other required measures unaddressed. Specific obligations should be confirmed against the applicable regime.
What information is typically collected to identify a beneficial owner?
Practices vary by jurisdiction and by the risk profile of the relationship, but obliged entities generally collect identifying details of the natural person, such as name and other identifiers used to distinguish the individual, together with information describing the nature and extent of their ownership or control interest. The precise data elements, and the extent to which they must be independently verified rather than simply recorded, depend on the applicable rules and the entity's own risk-based approach. Exact required fields and verification standards should be confirmed against the relevant regulation and any supervisory guidance.
How should an entity handle a customer with a complex or multi-layered ownership structure?
Where ownership is layered through intermediate entities, trusts, or nominee arrangements, the general expectation is to work through the structure to identify the ultimate natural person(s) who own or control the customer, rather than stopping at an intermediate corporate layer. This may involve applying the applicable control or ownership thresholds at each layer and, where no natural person can be identified through ownership, considering control by other means or the relevant senior managing official test used in some regimes. Complex structures may warrant additional scrutiny under a risk-based approach, but complexity alone is not evidence of wrongdoing.
What should an entity do when collected beneficial ownership information cannot be verified or appears inconsistent with a public register?
A discrepancy between information collected directly and information held in a central register does not by itself establish wrongdoing, but it is generally treated as a matter to be resolved. Depending on the regime, obliged entities may be expected to take reasonable steps to reconcile the difference, and some frameworks impose specific requirements to report discrepancies to the register maintainer. Where verification cannot be completed or concerns persist, an entity may need to consider whether its risk-based measures, escalation procedures, or reporting obligations are engaged. The applicable reporting and reconciliation duties should be confirmed against the relevant rules.
How often should beneficial ownership information be reviewed after onboarding?
Beneficial ownership information is generally treated as part of ongoing monitoring rather than a one-time onboarding exercise, because ownership and control can change over the life of a relationship. Many frameworks expect information to be kept current, with the frequency and depth of review calibrated to the assessed risk of the customer, so that higher-risk relationships are reviewed more closely or more often. There is no single universal review interval; the appropriate cadence depends on the entity's risk-based approach and any specific requirements in the applicable regime, which should be confirmed against that regulation.

Common misconceptions

Beneficial ownership is the same as legal ownership, so collecting the registered shareholder's details is sufficient.
Legal ownership refers to the titular or registered holder, whereas beneficial ownership concerns the natural person who ultimately owns or controls the entity or arrangement. A registered shareholder may hold on behalf of another, and control can arise without any ownership stake. Collecting only the legal owner's details generally does not satisfy beneficial ownership obligations.
There is a single global ownership threshold that defines a beneficial owner.
Ownership percentages used as an indicator of beneficial ownership vary between regimes, and a threshold is only one route to identification. Beneficial ownership can also arise through control exercised by other means. Exact thresholds should be confirmed against the applicable regulation for the relevant jurisdiction.
Consulting a central beneficial ownership register fully discharges the obliged entity's collection obligation.
In many jurisdictions, an obliged entity may consult a central register but is generally still expected to take its own risk-based measures to identify and, where required, verify beneficial owners. Reliance arrangements and the legal status of registers differ by regime and should be checked against applicable rules.

Best practices

Distinguish clearly in records between legal ownership and beneficial ownership, and document the ownership and control chain linking the customer to each identified natural person.
Apply a risk-based approach to the depth of verification, escalating scrutiny where structures are complex, opaque, or involve higher-risk jurisdictions, while confirming the specific data points and thresholds required against the applicable regulation.
Treat identification through ownership and through control as separate routes, and only use a senior managing official as a fallback after documenting that reasonable measures to identify a beneficial owner have been exhausted.
Where a central beneficial ownership register is available, use it as one input but continue to perform your own due diligence rather than relying on it exclusively, in line with the applicable regime.
Establish processes to keep beneficial ownership information current, including triggers to refresh information on material changes in ownership or control and periodic review calibrated to risk.
Retain the underlying verification evidence and a clear record of the source of information, so the basis for each beneficial ownership determination can be reconstructed and evidenced to supervisors.