Customer Due Diligence Requirements for Financial Institutions

Federal RegisterMay 11, 2016

Ask Donna

What actually matters in this document.

Text

DEPARTMENT OF THE TREASURY

Financial Crimes Enforcement Network

31 CFR Parts 1010, 1020, 1023, 1024, and 1026

RIN 1506-AB25

Customer Due Diligence Requirements for Financial Institutions

AGENCY:

Financial Crimes Enforcement Network (FinCEN), Treasury.

ACTION:

Final rules.

SUMMARY:

FinCEN is issuing final rules under the Bank Secrecy Act to clarify and strengthen customer due diligence requirements for: Banks; brokers or dealers in securities; mutual funds; and futures commission merchants and introducing brokers in commodities. The rules contain explicit customer due diligence requirements and include a new requirement to identify and verify the identity of beneficial owners of legal entity customers, subject to certain exclusions and exemptions.

DATES:

The final rules are effective July 11, 2016.

Applicability Date:

Covered financial institutions must comply with these rules by May 11, 2018.

FOR FURTHER INFORMATION CONTACT:

FinCEN Resource Center at 1-800-767-2825. Email inquiries can be sent to

frc@fincen.gov

.

SUPPLEMENTARY INFORMATION:

I. Executive Summary

A. Purpose of This Regulatory Action

Covered financial institutions are not presently required to know the identity of the individuals who own or control their legal entity customers (also known as beneficial owners). This enables criminals, kleptocrats, and others looking to hide ill-gotten proceeds to access the financial system anonymously. The beneficial ownership requirement will address this weakness and provide information that will assist law enforcement in financial investigations, help prevent evasion of targeted financial sanctions, improve the ability of financial institutions to assess risk, facilitate tax compliance, and advance U.S. compliance with international standards and commitments.

FinCEN believes that there are four core elements of customer due diligence (CDD), and that they should be explicit requirements in the anti-money laundering (AML) program for all covered financial institutions, in order to ensure clarity and consistency across sectors: (1) Customer identification and verification, (2) beneficial ownership identification and verification, (3) understanding the nature and purpose of customer relationships to develop a customer risk profile, and (4) ongoing monitoring for reporting suspicious transactions and, on a risk-basis, maintaining and updating customer information. The first is already an AML program requirement and the second will be required by this final rule. The third and fourth elements are already implicitly required for covered financial institutions to comply with their suspicious activity reporting requirements. The AML program rules for all covered financial institutions are being amended by the final rule in order to include the third and fourth elements as explicit requirements.

FinCEN has the legal authority for this action in the Bank Secrecy Act (BSA), which authorizes FinCEN to impose AML program requirements on all financial institutions

1

and to require financial institutions to maintain procedures to ensure compliance with the BSA and its implementing regulations or to guard against money laundering.

2

1

31 U.S.C. 5318(h)(2).

2

31 U.S.C. 5318(a)(2).

B. Summary of the Major Provisions of the Rulemaking

1. Beneficial Ownership

Beginning on the Applicability Date, covered financial institutions

3

must identify and verify the identity of the beneficial owners of all legal entity customers (other than those that are excluded) at the time a new account is opened (other than accounts that are exempted). The financial institution may comply either by obtaining the required information on a standard certification form (Certification Form (Appendix A)) or by any other means that comply with the substantive requirements of this obligation. The financial institution may rely on the beneficial ownership information supplied by the customer, provided that it has no knowledge of facts that would reasonably call into question the reliability of the information. The identification and verification procedures for beneficial owners are very similar to those for individual customers under a financial institution's customer identification program (CIP),

4

except that for beneficial owners, the institution may rely on copies of identity documents. Financial institutions are required to maintain records of the beneficial ownership information they obtain, and may rely on another financial institution for the performance of these requirements, in each case to the same extent as under their CIP rule.

3

The term “covered financial institution” refers to: (i) Banks; (ii) brokers or dealers in securities; (iii) mutual funds; and (iv) futures commission merchants and introducing brokers in commodities.

4

31 CFR 1020.220, 1023.220, 1024.220, 1026.220.

The terms used for the purposes of this final rule, including account, beneficial ownership, legal entity customer, excluded legal entities, new account, and covered financial institution, are set forth in the final rule.

Financial institutions should use beneficial ownership information as they use other information they gather regarding customers (

e.g.,

through compliance with CIP requirements), including for compliance with the Office of Foreign Assets Control (OFAC) regulations, and the currency transaction reporting (CTR) aggregation requirements.

2. Anti-Money Laundering Program Rule Amendments

The AML program requirement for each category of covered financial institutions is being amended to explicitly include risk-based procedures for conducting ongoing customer due diligence, to include understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile.

A customer risk profile refers to the information gathered about a customer at account opening used to develop a baseline against which customer activity is assessed for suspicious activity reporting. This may include self-evident information such as the type of customer or type of account, service, or product. The profile may, but need not, include a system of risk ratings or categories of customers.

In addition, customer due diligence also includes conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information. For these purposes, customer information shall include information regarding the beneficial owners of legal entity customers (as defined in § 1010.230). The first clause of paragraph (ii) sets forth the requirement that financial institutions conduct monitoring to identify and report suspicious transactions. Because this includes transactions that are not of the sort the customer would be normally expected to engage, the customer risk profile information is used (among other sources) to identify such transactions. This information may be integrated into the financial institution's automated monitoring system, and may be used

after a potentially suspicious transaction has been identified, as one means of determining whether or not the identified activity is suspicious.

When a financial institution detects information (including a change in beneficial ownership information) about the customer in the course of its normal monitoring that is relevant to assessing or reevaluating the risk posed by the customer, it must update the customer information, including beneficial ownership information. Such information could include,

e.g.,

a significant and unexplained change in the customer's activity, such as executing cross-border wire transfers for no apparent reason or a significant change in the volume of activity without explanation. It could also include information indicating a possible change in the customer's beneficial ownership, because such information could also be relevant to assessing the risk posed by the customer. This applies to all legal entity customers, including those existing on the Applicability Date.

This provision does not impose a categorical requirement that financial institutions must update customer information, including beneficial ownership information, on a continuous or periodic basis. Rather, the updating requirement is event-driven, and occurs as a result of normal monitoring.

C. Costs and Benefits

This is a significant regulatory action pursuant to Executive Order 12866 (“E.O. 12866”) because it is likely to result in a final rule that may have an annual effect on the economy of $100 million or more. Accordingly, FinCEN published for comment on December 24, 2015 a preliminary Regulatory Impact Assessment (RIA) for the proposed rule (80 FR 80308), which provided a quantitative estimate of the costs to the private sector for which adequate data are available and a qualitative discussion of both the costs and benefits for which data are not available. As a result of the comments submitted, FinCEN revised the preliminary RIA to include additional cost estimates

5

and is publishing with this final rule a final RIA. The annualized quantified costs (under low cost scenarios) are estimated to be $153 million (at a seven percent discount rate) and $148 million (at a three percent discount rate). The annualized quantified costs (under high cost scenarios) are estimated to be $287 million (at a seven percent discount rate) and $282 million (at a three percent discount rate). Because the benefits of the rule cannot be quantified, FinCEN has utilized a breakeven analysis to determine how large the final rule's benefits would have to be in order to justify its estimated costs. The RIA uses Treasury's estimate of $300 billion in illicit proceeds generated annually in the United States due to financial crimes, to determine the minimum level of effectiveness that the final rule would need to achieve for the benefits to equal the costs. Based on this analysis, using the upper bound of our cost assessment, FinCEN has concluded that the final rule would only have to reduce illicit activity by 0.6 percent to yield a positive net benefit. The Treasury Department believes that the final rule will reduce illicit activity by a greater amount than this.

5

In the final RIA, we estimate that 10-year quantifiable costs range from $1.15 billion to $2.15 billion in present value using a seven percent discount rate, and from $1.3 billion to $2.5 billion using a three percent discount rate.

II. Background

A. The Bank Secrecy Act

FinCEN exercises regulatory functions primarily under the Currency and Foreign Transactions Reporting Act of 1970, as amended by the USA PATRIOT Act of 2001 (PATRIOT Act) and other legislation, which legislative framework is commonly referred to as the “Bank Secrecy Act” (BSA).

6

The BSA authorizes the Secretary of the Treasury (Secretary) to require financial institutions to keep records and file reports that “have a high degree of usefulness in criminal, tax, or regulatory investigations or proceedings, or in the conduct of intelligence or counterintelligence activities, including analysis, to protect against international terrorism.”

7

6

The BSA is codified at 12 U.S.C. 1829b, 12 U.S.C. 1951-1959, 18 U.S.C. 1956, 1957, and 1960, and 31 U.S.C. 5311-5314 and 5316-5332 and notes thereto, with implementing regulations at 31 CFR chapter X.

See

31 CFR 1010.100(e).

7

31 U.S.C. 5311.

The Secretary has delegated to the Director of FinCEN the authority to implement, administer, and enforce compliance with the BSA and associated regulations.

8

FinCEN is authorized to impose anti-money laundering (AML) program requirements on financial institutions,

9

as well as to require financial institutions to maintain procedures to ensure compliance with the BSA and the regulations promulgated thereunder or to guard against money laundering.

10

8

Treasury Order 180-01 (July 1, 2014).

9

31 U.S.C. 5318(h)(2).

10

31 U.S.C. 5318(a)(2).

B. The Importance of Customer Due Diligence

FinCEN, after consultation with the staffs of the Federal functional regulators and the Department of Justice, has determined that more explicit rules for covered financial institutions with respect to customer due diligence (CDD) are necessary to clarify and strengthen CDD within the BSA regime, which in turn will enhance financial transparency and help to safeguard the financial system against illicit use. Requiring financial institutions to perform effective CDD so that they understand who their customers are and what type of transactions they conduct is a critical aspect of combating all forms of illicit financial activity, from terrorist financing and sanctions evasion to more traditional financial crimes, including money laundering, fraud, and tax evasion. For FinCEN, the key elements of CDD include: (i) Identifying and verifying the identity of customers; (ii) identifying and verifying the identity of beneficial owners of legal entity customers (

i.e.,

the natural persons who own or control legal entities); (iii) understanding the nature and purpose of customer relationships; and (iv) conducting ongoing monitoring. Collectively, these elements comprise the minimum standard of CDD, which FinCEN believes is fundamental to an effective AML program.

Clarifying and strengthening CDD requirements for U.S. financial institutions, including with respect to the identification of beneficial owners, advance the purposes of the BSA by:

(1) Enhancing the availability to law enforcement, as well as to the Federal functional regulators and self-regulatory organizations (SROs), of beneficial ownership information about legal entity customers obtained by U.S. financial institutions, which assists law enforcement financial investigations and a variety of regulatory examinations and investigations;

(2) Increasing the ability of financial institutions, law enforcement, and the intelligence community to identify the assets and accounts of terrorist organizations, corrupt actors, money launderers, drug kingpins, proliferators of weapons of mass destruction, and other national security threats, which strengthens compliance with sanctions programs designed to undercut financing and support for such persons;

(3) Helping financial institutions assess and mitigate risk, and comply with all existing legal requirements, including the BSA and related authorities;

(4) Facilitating reporting and investigations in support of tax compliance, and advancing commitments made to foreign counterparts in connection with the provisions commonly known as the Foreign Account Tax Compliance Act (FATCA);

11

11

Officially the Hiring Incentives to Restore Employment Act of 2010, Public Law 111-147, 124 Stat. 71, Section 501(a).

(5) Promoting consistency in implementing and enforcing CDD regulatory expectations across and within financial sectors; and

(6) Advancing Treasury's broad strategy to enhance financial transparency of legal entities.

1. Assisting Financial Investigations by Law Enforcement

The abuse of legal entities to disguise involvement in illicit financial activity is a longstanding vulnerability that facilitates crime, threatens national security, and jeopardizes the integrity of the financial system. Criminals have exploited the anonymity that use of legal entities can provide to engage in money laundering, corruption, fraud, terrorist financing, and sanctions evasion, among other financial crimes.

There are numerous examples that Treasury has tracked as a part of its National Money Laundering Risk Assessment and Terrorist Financing Risk Assessment.

12

For example, in 2013, prosecutors in New York indicted 34 alleged members of Russian-American organized crime groups, charging that they participated in a range of racketeering activities. One of the constituent racketeering enterprises was alleged to have moved millions of dollars in unlawful gambling proceeds through a network of shell companies

13

in Cyprus and the United States.

14

In 2011, Federal prosecutors indicted 13 individuals for their alleged unlawful takeover and looting of a publicly-held mortgage company. Some of these defendants allegedly used the assets of the company to acquire shell companies, while other defendants are alleged to have further obscured the ownership of these companies through complex legal structures involving other shell companies.

15

In 2006, prosecutors indicted a number of individuals for their roles in supporting a long-running nationwide drug trafficking organization. The proceeds generated by this trafficking organization were laundered through numerous shell and shelf

16

corporations created to provide apparently legitimate fronts for this income. These legal entities were further used to open accounts at financial institutions and hold title to property.

17

Other examples cited by law enforcement officials include major drug trafficking organizations using shell companies to launder drug proceeds.

18

In 2011, a World Bank report highlighted how corrupt actors consistently abuse legal entities to conceal the proceeds of corruption, which the report estimates to aggregate at least $40 billion per year in illicit activity.

19

Other criminals also make aggressive use of front companies,

20

which may also conduct legitimate business activity, to disguise the deposit, withdrawal, or transfer of illicit proceeds that are intermingled with legitimate funds.

12

U.S. Dep't of the Treasury,

National Money Laundering Risk Assessment

(2015),

available at http://www.treasury.gov/resource-center/terrorist-illicit-finance/Documents/National%20Money%20Laundering%20Risk%20Assessment%20%E2%80%93%2006-12-2015.pdf

; U.S. Dep't of the Treasury,

National Terrorist Financing Risk Assessment

(2015),

available at http://www.treasury.gov/resource-center/terrorist-illicit-finance/Documents/National%20Terrorist%20Financing%20Risk%20Assessment%20%E2%80%93%2006-12-2015.pdf

.

13

A shell company is a legal entity that has been registered with a state but has no physical operations or assets. Shell companies can serve legitimate purposes, such as holding financial assets or other property, but can also be used to conceal the source, ownership, or control of illegal proceeds. U.S. Dep't of the Treasury,

National Money Laundering Risk Assessment

at 43.

14

Id.

at 20.

15

Id.

16

A shelf corporation is a legal entity that has been registered with a state but not yet used for any purpose; it has instead been kept on the “shelf” for a buyer who does not want to go through the process of creating a new legal entity.

Id.

17

Id.

at 44.

18

Combating Transnational Organized Crime: International Money Laundering as a Threat to Our Financial System, Before the Subcommittee on Crime, Terrorism, and Homeland Security, H. Comm. on the Judiciary, 112th Cong.

(February 8, 2012) (statement of Jennifer Shasky Calvery as Chief, Asset Forfeiture and Money Laundering Section, Criminal Division of the U.S. Department of Justice).

19

The Puppet Masters: How the Corrupt Use Legal Structures to Hide Stolen Assets and What to Do About It,

The International Bank for Reconstruction and Development/The World Bank (2011).

20

A front company is a legitimate business that combines illicit proceeds with earnings from its legitimate operations, thereby obscuring the source of the illegitimate funds.

See

U.S. Dep't of the Treasury,

National Money Laundering Risk Assessment

at 43.

Strong CDD practices that include identifying and verifying the identity of the natural persons who own or control a legal entity—

i.e.,

the beneficial owners—help defend against these abuses in a variety of ways. The collection of beneficial ownership information by financial institutions can provide law enforcement with key details about suspected criminals who use legal structures to conceal their illicit activity and assets. Moreover, requiring legal entities seeking access to financial institutions to disclose identifying information, such as the name, date of birth, and Social Security number of natural persons who own or control them, will make such entities more transparent, and thus less attractive to criminals and those who assist them. Even if an illicit actor tries to thwart such transparency by providing false beneficial ownership information to a financial institution, law enforcement has advised FinCEN that such information can still be useful in demonstrating unlawful intent and in generating leads to identify additional evidence or co-conspirators.

2. Advancing Counterterrorism and Broader National Security Interests

As noted, criminals often abuse legal entities to evade sanctions or other targeted financial measures designed to combat terrorism and other national security threats. The success of such targeted financial measures depends, in part, on the ability of financial institutions, law enforcement, and intelligence agencies to identify a target's assets and accounts. These measures are thwarted when legal entities are abused to obfuscate ownership interests. Effective CDD helps prevent such abuses by requiring the collection of critical information, including beneficial ownership information, which may be helpful in implementing sanctions or other similar measures.

3. Improving a Financial Institution's Ability To Assess and Mitigate Risk

Explicit CDD requirements would also enable financial institutions to assess and mitigate risk more effectively in connection with existing legal requirements. It is through CDD that financial institutions are able to understand the risks associated with their customers, to monitor accounts more effectively, and to evaluate activity to determine whether it is unusual or suspicious, as required under suspicious activity reporting obligations.

21

Further, in the event that a financial institution files a suspicious activity report (SAR), information gathered through CDD in many instances can enhance SARs, which in turn can help law enforcement, intelligence, national security, and tax authorities investigate and pursue illicit financing activity.

21

See, e.g.,

31 CFR 1020.320.

4. Facilitating Tax Compliance

Customer due diligence also facilitates tax reporting, investigations and compliance. For example, information held by banks and other financial institutions about the beneficial ownership of companies can be used to assist law enforcement in identifying the true owners of assets and their true tax liabilities. The United States has long been a global leader in establishing and promoting the adoption of international standards for transparency and information exchange to combat cross-border tax evasion and other financial crimes. Strengthening CDD is an important part of that effort, and it will dovetail with other efforts to create greater transparency, some of which are longstanding, such as the United States' commitments to exchanging information with other jurisdictions under its tax treaties and tax information exchange agreements, and others of which are new, such as the information reporting requirements under FATCA.

22

FATCA requires foreign financial institutions to identify U.S. account holders, including legal entities with substantial U.S. ownership, and to report certain information about those accounts to the Internal Revenue Service (IRS).

23

The United States has negotiated with foreign governments to enter into intergovernmental agreements that facilitate the effective implementation of these requirements. These agreements allow foreign financial institutions to rely on existing AML practices in a number of circumstances, including, in the case of the intergovernmental agreements, for purposes of determining whether certain legal entity customers are controlled by U.S. persons. Pursuant to many of these agreements, the United States has committed to pursuing equivalent levels of reciprocal automatic information exchange with respect to collecting and reporting to the authorities of the FATCA partner jurisdiction information on the U.S. financial accounts of residents of that jurisdiction. A general requirement for U.S. financial institutions to obtain beneficial ownership information for AML purposes advances this commitment, and puts the United States in a better position to work with foreign governments to combat offshore tax evasion and other financial crimes.

22

Hiring Incentives to Restore Employment Act of 2010, Public Law 111-147, Section 501(a).

23

See generally

Internal Revenue Service, “Regulations Relating to Information Reporting by Foreign Financial Institutions and Withholding on Certain Payments to Foreign Financial Institutions and Other Foreign Entities,” RIN 1545-BK68 (January 28, 2013),

available at http://www.irs.gov/PUP/businesses/corporations/TD9610.pdf

. For further updates on FATCA regulations, see

http://www.irs.gov/Businesses/Corporations/Foreign-Account-Tax-Compliance-Act-(FATCA)

.

5. Promoting Clear and Consistent Expectations and Practices

Customer due diligence is universally recognized as fundamental to mitigating illicit finance risk, even though not all financial institutions use the specific term “customer due diligence” to describe their practices. While Treasury understands from its outreach to the private sector that financial institutions broadly accept this principle and implement CDD practices in some form under a risk-based approach, financial institutions have expressed disparate views about what precise activities CDD entails. At public hearings held after the closing of the comment period to the Advance Notice of Proposed Rulemaking (ANPRM),

24

discussed below, financial institutions described widely divergent CDD practices, especially with respect to identifying and verifying the identities of beneficial owners outside of limited circumstances prescribed by statute.

25

For example, during one of these hearings, FinCEN learned that some financial institutions already obtain beneficial ownership information in all circumstances, while others obtain this information only for certain categories of customers or following a triggering event. Institutions also identified a range of practices, from varied percentage of ownership thresholds, to the extent of information collected (

e.g.,

only the name of the beneficial owner(s) versus collection of additional information, such as addresses, etc.).

26

24

Financial Crimes Enforcement Network (FinCEN), “Customer Due Diligence Requirements for Financial Institutions,” 77 FR 13046 (March 5, 2012).

25

See, e.g.,

FinCEN,

Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence

(October 5, 2012),

available at http://www.fincen.gov/whatsnew/html/20121130NYC.html

. (“Participants expressed varied views as to whether, how and in what circumstances, financial institutions obtain beneficial ownership information.”).

26

Id.

FinCEN believes that this disparity adversely affects efforts to mitigate risk and can promote an uneven playing field across and within financial sectors. Financial institutions have noted that unclear CDD expectations can result in inconsistent regulatory examinations, potentially causing them to devote their limited resources to managing derivative legal risk rather than fundamental illicit finance risk. Private sector representatives have also noted that inconsistent expectations can effectively discourage best practices, because financial institutions with robust compliance procedures may believe that they risk losing customers to other institutions with more lax procedures. Greater consistency across the financial system addresses this competitive inequality.

Providing a consolidated and clear CDD framework will help address these issues. As part of this framework, expressly stating CDD requirements in these regulations with respect to (i) understanding the nature and purpose of customer relationships and (ii) conducting ongoing monitoring will facilitate more consistent implementation, examination, supervision and enforcement of these expectations. With respect to the beneficial ownership requirement, requiring all covered financial institutions to identify and verify the identities of beneficial owners in the same manner and pursuant to the same definition also promotes consistency across industry. Requiring covered financial institutions to operate under one clear CDD framework will promote a more level playing field across and within financial sectors.

6. Advancing Treasury's Broad Strategy To Enhance Financial Transparency of Legal Entities

Finally, clarifying and strengthening CDD is an important component of Treasury's broader three-part strategy to enhance financial transparency of legal entities. Other key elements of this strategy include: (i) Increasing the transparency of U.S. legal entities through the collection of beneficial ownership information at the time of the legal entity's formation and (ii) facilitating global implementation of international standards regarding CDD and beneficial ownership of legal entities.

This final rule thus complements the Administration's ongoing work with Congress to facilitate adoption of legislation that would require the collection of beneficial ownership information at the time that legal entities are formed in the United States. This final rule also advances Treasury's ongoing work with the Group of Twenty Finance Ministers and Central Bank Governors (G-20), the Financial Action Task Force (FATF), the Global Forum on Transparency and Exchange of Information for Tax Purposes, and other global partners, who have emphasized the importance of improving CDD practices and requiring the disclosure of beneficial ownership information at the time of company formation or transfer. Moreover, this proposal furthers the

United States' Group of Eight (G-8) commitment as set forth in the United States G-8 Action Plan for Transparency of Company Ownership and Control, published on June 18, 2013.

27

This Action Plan is in line with principles agreed to by the G-8, which the Administration noted “are crucial to preventing the misuse of companies by illicit actors.”

28

It is also found in the U.S. Action Plan to Implement the G-20 High Level Principles on Beneficial Ownership, published on October 16, 2015.

29

While these elements are all proceeding independently, together they make up a comprehensive approach to promoting financial transparency of legal entities.

27

United States G-8 Action Plan for Transparency of Company Ownership and Control,

available at http://www.whitehouse.gov/the-press-office/2013/06/18/united-states-g-8-action-plan-transparency-company-ownership-and-control.

28

White House Fact Sheet: U.S. National Action Plan on Preventing the Misuse of Companies and Legal Arrangements (June 18, 2013),

available at http://www.whitehouse.gov/the-press-office/2013/06/18/fact-sheet-us-national-action-plan-preventing-misuse-companies-and-legal.

29

U.S. Action Plan to Implement the G-20 High Level Principles on Beneficial Ownership,

available at https://www.whitehouse.gov/blog/2015/10/16/us-action-plan-implement-g-20-high-level-principles-beneficial-ownership.

C. The Advance Notice and Notice of Proposed Rulemaking

FinCEN initiated this rulemaking process in March 2012 by issuing an ANPRM that described FinCEN's potential proposal for codifying explicit CDD requirements, including customer identification and verification, understanding the nature and purpose of accounts, ongoing monitoring, and obtaining and verifying beneficial ownership information.

30

FinCEN received 90 comments, mostly from banks, credit unions, securities and futures firms, mutual funds, casinos, and money services businesses. In general, these commenters raised concerns about the potential costs and practical challenges associated with a categorical requirement to obtain beneficial ownership information. They also expressed concerns with respect to FinCEN's articulation of the other components of CDD (understanding the nature and purpose of customer relationships and ongoing monitoring), asserting that, contrary to FinCEN's stated intention, these would in part be new requirements rather than an explicit codification of pre-existing obligations. To better understand and address these concerns, Treasury held five public hearings from July to December 2012 in Washington, DC, Chicago, New York, Los Angeles and Miami.

31

At these meetings, participants expressed their views on the ANPRM and offered specific recommendations about how best to balance the benefits with the practical burdens associated with obtaining beneficial ownership information. These discussions were critical in the development of the Notice of Proposed Rulemaking (NPRM) issued on August 4, 2014 (79 FR 45151).

30

Two years prior to that, in March 2010, FinCEN, along with several other agencies, published

Joint Guidance on Obtaining and Retaining Beneficial Ownership Information,

FIN-2010-G001 (March 5, 2010). Industry reaction to this guidance is one reason that FinCEN sought to further clarify CDD requirements by making them explicit within FinCEN's regulations.

31

Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence

(July 31, 2012),

available at http://www.regulations.gov/#!documentDetail;D=FINCEN-2012-0001-0094; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence

(September 28, 2012),

available at http://www.fincen.gov/whatsnew/html/20121130CHI.html; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence

(October 5, 2012),

available at http://www.fincen.gov/whatsnew/html/20121130NYC.html; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence

(October 29, 2012),

available at http://www.fincen.gov/whatsnew/html/20121130LA.html; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence

(December 3, 2012),

available at http://www.fincen.gov/whatsnew/pdf/SummaryofHearing-MiamiDec3.pdf

.

The NPRM proposed a new requirement for covered financial institutions to identify the natural person or persons who are beneficial owners of legal entity customers opening new accounts, subject to certain exemptions, and to verify the identity of the natural person(s) identified. As proposed, a covered financial institution would satisfy this requirement at the time a new account is opened by obtaining information on a standard certification form directly from the individual opening the new account on behalf of the legal entity customer, and by verifying the identity of the natural person(s) identified consistent with existing customer identification program (CIP) procedures for verifying the identity of customers who are natural persons. The NPRM thus sought to facilitate this proposed new requirement by leveraging the CIP procedures that have been required of all covered financial institutions since 2003. The NPRM also proposed that the AML program requirements for all types of covered financial institutions be amended to include appropriate risk-based procedures for conducting ongoing due diligence, to include: (i) Understanding the nature and purpose of customer relationships in order to develop a customer risk profile; and (ii) conducting ongoing monitoring to maintain and update customer information and to identify and report suspicious transactions. FinCEN viewed this part of the rulemaking as not imposing new requirements, but rather making explicit the activities that covered financial institutions are already expected to undertake, based on guidance and supervisory expectations, in order to satisfy their existing obligations to detect and report suspicious activities.

D. Summary of Comments

In response to the NPRM, FinCEN received 141 comments from financial institutions, trade associations, Federal and State agencies, non-governmental organizations, members of Congress, and other individuals. The great majority of the private sector commenters, which were primarily banks, credit unions, and their trade associations, asserted that the proposed beneficial ownership requirement would be very burdensome to implement and require more than the proposed 12 months, would be far more expensive than estimated by FinCEN, and would not achieve the proposal's expressed goals.

The commenters addressed many aspects of the proposed beneficial ownership requirement, including the use of the proposed certification form; the extent to which a covered financial institution may rely on the information provided by the customer; the meaning of verification and the extent to which it would be required; the application of the requirement to existing customers; the extent to which the information would need to be updated; and the definitions of beneficial ownership and legal entity customer and the proposed exclusions from those definitions.

Commenters raised a number of questions regarding the proposed certification form, including whether beneficial owner information must be obtained through the certification form or could be obtained by other means; whether the certification form should be an official government form; and who is authorized to sign the certification form on behalf of the customer. Many urged FinCEN to treat the receipt of the certification form as a “safe harbor,” similar to the treatment of the certification used for compliance with the foreign shell bank regulation.

32

Commenters submitted several other comments and suggestions regarding the information to be included in the certification form.

32

31 CFR 1010.630(b).

Many commenters sought clarification regarding the verification requirement

and the extent to which a financial institution may rely on the information submitted by its customer. Financial institutions also pointed out that there would be difficulties with adopting “identical” procedures to those used for verifying the identity of individual customers as done for CIP. Moreover, many commenters noted the practical difficulties resulting from the fact that there is no authoritative source for beneficial ownership information of legal entities, as there is no requirement for U.S. States to collect this information at the time a company is formed. Commenters also sought guidance regarding how they should utilize the beneficial ownership information once collected and how its availability would impact compliance with other obligations.

While many private sector commenters noted that the proposed definition of beneficial owner was an improvement over the definition discussed in the ANPRM, some sought greater clarity about the meaning of “indirect” ownership and guidance regarding how the percentage of ownership held indirectly should be measured in specific situations, as well as clarification of the meaning of “equity interest.” They also suggested eliminating any reference to using a 10 percent threshold on a risk basis, so as to reduce the likelihood of examiners requiring a threshold lower than the 25 percent specified in the proposed rule. On the other hand, non-governmental organizations and many individuals asserted that the proposed 25 percent ownership threshold is too high and that it should be lowered to 10 percent (or eliminated entirely) in the final rule.

A number of commenters urged clarification of the proposed definition of “legal entity customer,” and many urged expansion of the proposed exclusions from the definition to include, for example, accounts opened to participate in employee benefit plans subject to the Employee Retirement Income Security Act of 1974 (ERISA) and accounts for foreign publicly traded companies, regulated financial institutions, and governmental entities. Many commenters also noted difficulties in applying the proposed exclusion for nonprofits and urged FinCEN to simplify it. Commenters also sought clarification regarding whether beneficial ownership would need to be obtained each time a legal entity customer opens a new account after the rule's compliance deadline, and to what extent the information would need to be updated. Some commenters also sought to exempt from the beneficial ownership requirement certain categories of financial products that they contended presented a low risk of money laundering.

Many comments also addressed the proposed amendments to the AML program rules, including urging FinCEN to clarify the proposed requirement to understand the nature and purpose of the customer relationship and the meaning of “customer risk profile” and of the proposed requirement to conduct ongoing monitoring to update customer information, separate from monitoring to detect and report suspicious activity. Some commenters representing the securities and futures industries asserted that, contrary to assumptions in the NPRM, these are not in fact existing requirements in those industries, and that such requirements would be burdensome and of little utility. Some commenters also questioned statements in the preamble that the proposed requirements would not reduce or limit the due diligence expectations of the Federal functional regulators or their regulatory discretion, asserting that such an approach would undermine the clarity and consistency that FinCEN is seeking to provide by the proposed rules. Finally, a great majority of the comments stated that the proposed 12-month implementation period following issuance of a final rule would not be adequate to implement the necessary modifications to their data systems, customer on-boarding procedures, employee training, and other requirements, and sought a period of at least 18-24 months.

Based on the comments addressing the potential cost of implementing the requirement, FinCEN conducted outreach to a number of the financial institution commenters to obtain additional information regarding the anticipated costs of implementing the proposed requirements. As a result of the limited information received from these discussions, Treasury prepared a preliminary Regulatory Impact Assessment (RIA) that was made available for comment on December 24, 2015 (80 FR 80308). FinCEN received 38 comments on this preliminary assessment; a summary of the comments we received and the final RIA is included in the Regulatory Analysis section of this preamble.

All of the substantive comments received on the NPRM, FinCEN's response, and resulting modifications to the final rule are discussed in detail in the following Section-by-Section Analysis. However, we first address certain general comments.

E. General Comments

Regulatory deference.

Commenters raised a number of general comments regarding this rulemaking. Several commenters took issue with the following statement in the NPRM (which we reiterate here as modified for this final rule).

33

33

The original statement can be found at 79 FR 45152 (Aug. 4, 2014).

Nothing in this final rule is intended to lower, reduce, or limit the due diligence expectations of the Federal functional regulators or in any way limit their existing regulatory discretion. To clarify this point, the final rule incorporates the CDD elements on nature and purpose and ongoing monitoring into FinCEN's existing AML program requirements, which generally provide that an AML program is adequate if, among other things, the program complies with the regulation of its Federal functional regulator (or, where applicable, self-regulatory organization (SRO)) governing such programs.

34

In addition, the Treasury Department intends for the requirements contained in the customer due diligence and beneficial ownership final rules to be consistent with, and not to supersede, any regulations, guidance or authority of any Federal banking agency, the Securities and Exchange Commission (SEC), the Commodity Futures Trading Commission (CFTC), or of any SRO relating to customer identification, including with respect to the verification of the identities of legal entity customers.

34

See, e.g.,

31 CFR 1020.210, which currently provides that a financial institution regulated by a Federal functional regulator that is not subject to the regulations of a self-regulatory organization shall be deemed to satisfy the requirements of 31 U.S.C. 5318(h)(1) if it implements and maintains an anti-money laundering program that complies with

the regulation of its Federal functional regulator governing such programs.

(emphasis added).

These commenters contended, among other things, that these statements were unduly deferential to the Federal functional regulators, and would serve to undermine rather than promote clear and consistent CDD standards across financial sectors. They accordingly urged FinCEN to strike this language from the final rulemaking.

FinCEN appreciates the concerns about uneven and inconsistent application of CDD standards that underlie these comments, but nevertheless believes that these statements are an important articulation of FinCEN's understanding of what it is—and is not—accomplishing by this rulemaking. At their core, these statements in the NPRM and this final rule preamble articulate the nature of the relationship of FinCEN's rulemaking authority with that of the Federal functional regulators

35

—that is, as with

all BSA rulemakings, FinCEN determines the appropriate minimum regulatory standards that should apply across an industry. From that baseline, the Federal functional regulators have authority to establish AML program requirements in addition to those established by FinCEN that they determine are necessary and appropriate to address risk or vulnerabilities specific to the financial institutions they regulate. This is particularly true within the context of separate but related concerns that exist for these institutions beyond the strict scope of AML, such as in the area of safety and soundness. These statements simply reflect this basic reality of the existing regulatory framework. Furthermore, as we have maintained throughout this rulemaking process, one of our overarching goals was to clarify and harmonize expectations while at the same time minimizing disruption to the greatest extent possible. Accordingly, we believe that it is critical to make clear—especially with respect to the changes to the AML program rules—that these standards simply articulate current practices pursuant to existing standards and expectations, in order to facilitate implementation and minimize the burden on financial institutions. We believe that leveraging the experience accrued from interpretation of and compliance with prior regulations and guidance that have already been issued in this space will be a net benefit to financial institutions. As FinCEN explained in the proposal, these requirements represent a floor, not a ceiling, and, consistent with the risk-based approach, financial institutions may do more in circumstances of heightened risk, as well as to mitigate risks generally.

35

Where appropriate, working closely with Federal functional regulators may involve

consulting with the applicable SROs in the securities and futures/commodities industries.

Compliance Deadline.

Most commenters strongly opposed FinCEN's proposal for a compliance deadline of one year from the date the final rule is issued, identifying a wide range of changes to systems and processes that would be required in order to implement the rule. Many of these commenters requested that FinCEN provide financial institutions two years to implement the final rule. Based on the well-founded, detailed explanations put forth by these commenters of the difficulties that would arise from a one-year implementation period, FinCEN is extending the period for implementation to two years from the date this final rule is issued (the Applicability Date).

III. Section-by-Section Analysis

Section 1010.230 Beneficial Ownership Requirements for Legal Entity Customers

Section 1010.230(a) In general.

As proposed, this paragraph delineated in broad terms the scope of the beneficial ownership obligation—

i.e.,

that covered financial institutions are required to establish and maintain written procedures reasonably designed to identify and verify the identities of beneficial owners of legal entity customers. There were no significant objections to this general formulation, and we are adopting it as proposed, with the addition that the procedures adopted will be included in the institution's AML program.

Several commenters questioned the efficacy of having financial institutions collect beneficial ownership information, contending that State government offices responsible for the formation and registration of legal entities and/or the IRS would be better suited to collect this information due to their roles in the company formation process. Although FinCEN supports the collection of beneficial ownership information in these other circumstances as well, it does not believe that such collection would replace the independent obligation of financial institutions to collect this information. As described above, we view this rulemaking as but one part of Treasury's comprehensive strategy to enhance financial transparency in the U.S. financial system and worldwide, and we believe the beneficial ownership requirement for financial institutions would be necessary even if these other measures were already in place. One of the principal rationales for this new requirement is that financial institutions should know who their customers are to help them more effectively mitigate risks. This requirement is therefore separate from a policy objective of requiring States to obtain beneficial ownership information from the legal entities they create at the time of formation and upon specified circumstances thereafter (although none currently have such requirements). Presently, corporate laws and regulations differ from State to State, and from FinCEN's regulations, but generally do not require information regarding beneficial ownership. Thus, the information that will be provided under FinCEN's regulations will significantly augment information presently available to law enforcement from State authorities, thereby improving the overall investigative, regulatory, and prosecutorial processes.

In the NPRM, FinCEN proposed that the beneficial ownership requirement would apply only with respect to legal entity customers that open new accounts going forward from the date of implementation, noting that many commenters to the ANPRM viewed a retroactive requirement to obtain beneficial ownership information for all existing accounts as extremely burdensome. We received comments reflecting a wide range of views on this subject. The vast majority of commenters who addressed this issue reiterated this objection to retroactive application of the beneficial ownership obligation. A few commenters, however, urged FinCEN to require covered financial institutions to collect beneficial ownership information on existing accounts on a categorical basis, while some others thought that financial institutions should collect this information retroactively for all higher risk customers.

We decline to impose a categorical, retroactive requirement. Based on our understanding of the significant changes to processes and systems that will be required to implement this requirement simply on a prospective basis, we believe that retroactive application would be unduly burdensome. As we noted in the proposal, the absence of a categorical mandate to apply the requirement retroactively would not preclude financial institutions from deciding that collecting beneficial ownership information on some customers on a risk basis during the course of monitoring may be appropriate for their institution. In our assessment, we have concluded that financial institutions should obtain beneficial ownership information from customers existing on the Applicability Date when, in the course of their normal monitoring, the financial institution detects information relevant to assessing or reevaluating the risk of such customer (as more fully described in the sections below addressing the amended AML program requirements).

Section 1010.230(b) Identification and Verification.

In the NPRM, FinCEN proposed that covered financial institutions be required to develop customer due diligence procedures that enabled institutions to (1) identify the beneficial owner(s) of legal entity customers by collecting a mandatory certification form provided by the individual opening the account on behalf of the legal entity customer; and (2) verify the identity of the identified beneficial owner(s) according to risk-based procedures that are, at a minimum, identical to the institutions' CIP procedures required for verifying

the identity of customers that are individuals.

Section 1010.230(b)(1).

The NPRM proposed to require the use of a standard certification form (Certification Form) in order to, among other purposes, promote consistent practices and regulatory expectations, reduce compliance burden, and provide a uniform customer experience across much of the U.S. financial system. To facilitate institutions' abilities to rely upon the Certification Form, the proposed Certification Form included a section that required the individual opening the account on behalf of a legal entity customer to certify that the information provided on the form is true and accurate to the best of his or her knowledge. Commenters raised a number of issues regarding this proposed requirement. Some commenters asked whether the Certification Form must be used to obtain the information, whether the Certification Form should be an official government form, and what individuals representing the customer would be authorized to provide the Certification Form. Several commenters urged a variety of changes to the fields on the Certification Form in order to conform it more closely to current CIP requirements, to otherwise facilitate use of the form, and to promote other regulatory goals. Some commenters also urged FinCEN to provide a safe harbor to institutions that use the model Certification Form adopted in the final rule akin to, for example, the safe harbor provided for foreign bank certifications.

36

36

31 CFR 1010.630(b).

The comments FinCEN received related to the Certification Form varied widely. Some commenters urged FinCEN to make the Certification Form an official U.S. Government document, with the certification made under the penalty of perjury (rather than only to the best of the knowledge of the certifying party), and a few commenters thought that the Certification Form should be notarized. However, many commenters requested that the proposed Certification Form be permissive rather than mandatory, and that financial institutions be permitted to obtain the information through their standard account opening process without utilizing the Certification Form. A few commenters thought that the person opening the account should be required to have actual personal knowledge of the information provided on the Certification Form, or that the certification should take the form of a resolution ratified or adopted by the legal entity's board or governing body. These commenters thought that a Certification Form without attestation requirements more substantial than those in the proposal would reduce accountability for false representations on the Certification Form.

As noted above, a primary reason that FinCEN proposed the Form was to balance the benefits and burdens of this new requirement to the financial institution and its customers with the benefits to law enforcement and regulatory authorities. We also note that in the case of many legal entities that are small businesses, the natural person opening the account will often be one of the beneficial owners, who would have direct knowledge of the beneficial ownership information of the legal entity customer. FinCEN understands that many institutions obtain and maintain customer data electronically rather than in paper form to the greatest extent possible, and that mandating the use and retention of a specific form would require significant technological and operational changes that could be costly and challenging to implement for some financial institutions. We have therefore amended the final rule to permit, but not require, financial institutions to use the Certification Form to collect beneficial ownership information. Accordingly, in the final rule, § 1010.230(b)(1) is revised to state that covered financial institutions must identify the beneficial owner(s) of each legal entity customer at the time a new account is opened, unless the customer is otherwise excluded or the account is exempted. A covered financial institution may accomplish this either by obtaining certification in the form of appendix A of the section from the individual opening the account on behalf of the legal entity customer, or by obtaining from the individual the information required by the form by another means, provided the individual certifies, to the best of the individual's knowledge, the accuracy of the information.

37

37

This revision will also require a corresponding change to the Recordkeeping subsection, described in greater detail below.

Thus, covered financial institutions can satisfy this requirement through (1) the use of FinCEN's Certification Form; (2) the use of the financial institution's own forms, so long as they meet the requirements of § 1010.230(b)(1); or (3) any other means that satisfy the substantive requirements of § 1010.230(b)(1). These records may be retained electronically and incorporated into existing databases as a part of financial institutions' overall management of customer files, and covered financial institutions will have flexibility in integrating the beneficial ownership information requirement into existing systems and processes. The certification of accuracy by the individual submitting the information may be obtained without use of the Certification Form in the same way the financial institution obtains other information from its customers in connection with its account opening procedures. FinCEN expects that such flexibility will facilitate the implementation of the beneficial ownership requirement—some commenters noted that giving financial institutions flexibility in integrating this requirement would substantially reduce resource outlays to change customer onboarding processes and to train front-line employees. In addition, to facilitate use of the Certification Form by those institutions that choose to utilize it, FinCEN will also make an electronic version available, although it will not be an official U.S. Government form.

Some commenters asked that FinCEN clarify who an appropriate individual to certify the identity of the beneficial owners to the financial institution would be, whether by signing the Certification Form or otherwise providing the beneficial ownership information in accordance with this paragraph; some commenters also questioned whether the individual opening an account could be a low-level employee without knowledge of the entity's owners. In this regard, FinCEN declines to impose specific account-opening procedures on financial institutions, and believes that financial institutions should be able to integrate this new requirement into their institution's existing procedures with little disruption. FinCEN understands that financial institutions generally have long-standing policies and procedures, based on sound business practices and prudential considerations, governing the documentation required to open an account for a legal entity; these typically include resolutions authorizing the entity to open an account at the institution and identifying the authorized signatories. Such resolutions are typically certified by an appropriate individual,

e.g.,

the secretary or other officer of a corporation, a member or manager of an LLC, or partner of a partnership. It would be appropriate for the same individual to certify the identity of the beneficial owners. Such an individual would typically have at least some familiarity with the entity's owners and with individuals with responsibility to control or manage the

entity, but may not have personal knowledge of individuals having an indirect ownership interest through, for example, intermediate legal entities or contractual arrangements with nominal owners, and would have to rely on others for any such information. Therefore, while FinCEN anticipates that the certifying individual would generally be able to provide accurate beneficial ownership information, it is appropriate that it be provided to the best of such person's knowledge, rather than without qualification. Accordingly, FinCEN declines to require a heightened knowledge threshold, or notarization, or board approval requirement for the certification requirement, as some commenters suggested, as any such requirement would increase the amount of time to open an account, without commensurate benefit, and would be inconsistent with FinCEN's goal of integrating this requirement into existing financial institution onboarding procedures to the greatest extent possible.

38

FinCEN thus believes that the certification requirement as described in the final rule provides the appropriate level of accountability given the circumstances.

39

38

FinCEN notes that in cases where the individual signing the documentation to open the account (and identifying the legal entity's beneficial owners) does not deliver such documentation to the financial institution, it may be appropriate that the individual's signature be notarized.

39

FinCEN also understands that in cases where a newly formed legal entity opens a financial institution account in order to commence business, the beneficial owner(s) would typically open the account in person and be the signatories on the account, and could readily certify their status as beneficial owners at that time.

Some commenters urged FinCEN to permit financial institutions to rely upon alternative sources, such as previously collected customer information in their databases, or the IRS Form W-8BEN, to satisfy the certification requirement. FinCEN recognizes that this could facilitate financial institutions' ability to obtain this information. However, to be of greatest use, FinCEN believes that beneficial ownership information must be, at the time of account opening, both (1) current, and (2) certified by an individual authorized by the customer to open accounts at financial institutions to be accurate to the best of his or her knowledge. Furthermore, because FinCEN's definition of beneficial ownership does not align precisely with, for example, the IRS's definition in its Form W-8BEN, permitting reliance in some circumstances upon other agencies' forms would be at odds with FinCEN's goal of consistent beneficial ownership standards within and across industries for purposes of CDD. Thus, FinCEN declines to permit reliance solely upon previously gathered alternate sources of beneficial ownership information.

Several commenters raised specific questions regarding the information in the proposed Certification Form. FinCEN agrees with the suggestions made by several commenters that the title of the person with significant management responsibility, as well as of the person submitting the Certification Form or supplying the information, should be included and has made these changes to the Form. We have also added fields on the Certification Form in which to identify the type of legal entity, and to note its address. Other commenters noted that the address fields as laid out in the proposed Certification Form, along with the description of the address requirement in the general instructions section, were not congruent with CIP's address requirements, and accordingly asked FinCEN to confirm that the CIP rules' address requirements remained applicable. As described in greater detail below, covered financial institutions' procedures for identifying and verifying beneficial owners must contain all the elements of the applicable CIP rule, including the address, date of birth, and Taxpayer Identification Number requirements as set forth therein. Accordingly, FinCEN has revised the Certification Form to clarify this point, and notes that this information will be required whether or not the Certification Form is used. We have also amended item “a” of the Certification Form to clarify that the name of the certifying party should be that of a

natural

person authorized to open the account (and not of the legal entity itself). FinCEN also agrees with the suggestion made by a number of commenters that the Certification Form state that the information in the Certification Form is required by Federal regulation in order to explain to customers why this new requirement has been put in place; the Form has been edited appropriately.

Several commenters sought clarification as to whether a financial institution must identify and verify a legal entity customer's beneficial owners each time it opens a new account at the institution after the rule's compliance deadline, or whether the requirement applies only the first time it opens a new account at such institution. FinCEN has concluded that, while it is not requiring periodic updating of the beneficial ownership information of all legal entity customers at specified intervals, the opening of a new account is a relatively convenient and otherwise appropriate occasion to obtain current information regarding a customer's beneficial owners. Accordingly, FinCEN has added to the final rule as § 1010.230(g) a definition for “new account”.

One commenter urged FinCEN to mandate the use of the Legal Entity Identifier (LEI), a global standardized unique identifier for legal entities engaged in financial transactions, on the proposed Certification Form. This commenter noted that including such a requirement would further the goals of transparency and financial stability. FinCEN understands that the LEI was developed principally to aggregate data from across markets, products, and regions, giving global regulators a means to quickly identify parties to financial transactions, in order to enhance regulators' ability to understand systemic risks to the financial system and act accordingly. Although this is an important and laudable purpose, FinCEN does not believe that mandating the LEI's inclusion on the beneficial ownership Certification Form would further this goal substantially. We believe that the overwhelming majority of legal entities subject to this requirement will be smaller or non-financial entities that would not be typical applicants for LEIs in the first instance, and that the costs of mandating its use solely for the purposes of the Certification Form would not be outweighed by the benefit. FinCEN also understands that the authorized bodies that assign LEIs do not require the beneficial owner to be a natural person, use a 50 (rather than 25) percent threshold, and do not verify the identities of beneficial owners of legal entities, thereby rendering the LEI's utility as a possible proxy or alternative source of verification minimal. For these reasons, FinCEN declines to mandate the use of the LEI. We do, however, recognize that covered financial institutions may find such information useful for enterprise-wide risk management or other purposes, and have accordingly included an optional LEI field on the Certification Form.

Several commenters urged FinCEN to adopt an express safe harbor in the final rule deeming those financial institutions that use the Certification Form compliant with the beneficial ownership requirement. A few commenters recommended that FinCEN model such an express safe harbor on the safe harbor for foreign bank certifications found in § 1010.630. Other commenters opposed the notion of a safe harbor, contending that the Certification Form should serve as the

starting point for financial institutions' risk-based due diligence into a legal entity's beneficial ownership. As discussed in greater detail below, we have included in § 1010.230(b)(2) of the final rule a description of the extent to which financial institutions can rely upon the beneficial ownership information provided by the person opening the account. We decline, however, to include in the final rule a blanket safe harbor triggered by the use and collection of the standard Certification Form.

FinCEN believes that there are a number of factors present in the context of foreign bank certifications (but absent here) that make a blanket safe harbor appropriate in that context. The foreign bank certification was used to satisfy several obligations arising under Sections 313 and 319(b) of the USA PATRIOT Act, including not only for the foreign bank to certify facts such as its status and in certain cases its owners, but also to set forth its agreement not to provide banking services to foreign shell banks and to appoint a U.S. process agent. Moreover the foreign bank official was required to certify that the information in the document was true and correct, whereas the beneficial ownership information is to be provided to the best of the knowledge of the customer's agent. In addition, the population of legal entities subject to the final rule is exponentially larger than that of foreign banks with U.S. correspondent accounts, and the proposed certification in the proposed rule does not include affirmative obligations. We believe that the provision inserted into § 1010.230(b)(2) of the final rule describing the extent to which the financial institution may rely on the information provided by the customer strikes the right balance between the need to minimize burden upon covered financial institutions and the risk of abuse of legal entities for illicit purposes.

A few commenters raised concerns that the collection of sensitive personal information of beneficial owners would impinge upon their privacy and increase their vulnerability to identity theft. FinCEN recognizes the critical importance of protecting individuals' privacy interests, as well as the serious threat posed by cyberattacks and identity theft, particularly with respect to the personal information held at financial institutions. These concerns, while valid and significant, are insufficient to justify elimination of the requirement. From both the privacy and identity-theft perspectives, the incremental impact upon the vast majority of beneficial owners will be slight, because, pursuant to CIP requirements, they already have to provide the same sensitive personal information to financial institutions to open individual accounts and access the U.S. financial system. We note that financial institutions are expected to protect this information just as they do CIP information, as well as comply with all applicable Federal and State privacy laws, including, but not limited to, the Right to Financial Privacy Act

40

and the Gramm-Leach-Bliley Act.

41

40

12 U.S.C. 3401

et seq.

41

15 U.S.C. 6801

et seq.

Section 1010.230(b)(2).

With respect to verification of identity, we proposed that verification meant that financial institutions were required to verify the

identity

of the individual identified as a beneficial owner (

i.e.,

to verify the individual's existence), and not his or her

status

as a beneficial owner. We proposed that this verification be done via risk-based procedures that are identical to the institutions' CIP procedures required for verifying the identity of customers that are individuals, to facilitate financial institutions' implementation of the requirement through leveraging existing procedures and systems.

Many commenters sought clarification of the meaning of the verification requirement in proposed § 1010.230(b)(2) and the means by which it may be accomplished. Some pointed out the potential confusion between two statements in the NPRM discussing the distinction between verifying the identity of the beneficial owner and verifying the status.

42

In order to resolve any potential confusion regarding the beneficial ownership identification and verification obligation of financial institutions, FinCEN is revising § 1010.230(b)(2) in the final rule to clarify that a covered financial institution may rely on the information supplied by the legal entity customer regarding the identity of its beneficial owner or owners, provided that it has no knowledge of facts that would reasonably call into question the reliability of such information. FinCEN anticipates that, in the overwhelming majority of cases, a covered financial institution should be able to rely on the accuracy of the beneficial owner or owners identified by the legal entity customer, absent the institution's knowledge to the contrary. FinCEN recognizes the necessity for permitting reliance on the identification supplied by the legal entity customer, considering the fact the customer is generally the best source of this information, and that there is generally no other source of beneficial ownership information available to covered financial institutions, aside from the legal entity itself.

42

FinCEN stated that “[i] n light of these considerations, FinCEN is not proposing that financial institutions verify the

status

of a beneficial owner. Financial institutions may rely on the beneficial ownership information provided by the customer on the standard certification form.” On the other hand, the proposal also states that its procedures for verifying beneficial ownership “should enable the financial institution to form a reasonable belief that it knows the true identity of the beneficial owner of each legal entity customer.” (79 FR 45162)

Several commenters sought clarification of the requirement as described in the NPRM in proposed § 1010.230(b)(2) that beneficial ownership information procedures be, at a minimum, “identical” to the existing CIP procedures for verifying the identity of individual customers. Some commenters noted that it would be infeasible to simply replicate, without modification, existing CIP procedures for individual customers to implement the beneficial ownership verification requirement. They noted, for example, that because the beneficial owners will in many cases not be physically present at the financial institution at account opening, an institution using documentary verification may not have access to the documents listed in the relevant paragraph of the CIP rule, and therefore may need to rely on a photocopy or other reproduction of such document. Commenters also noted that some current procedures for non-documentary verification of individual customers could not be applied to non-consenting beneficial owners, because of limitations on the use of credit reports imposed by the Fair Credit Reporting Act.

43

43

15 U.S.C. 1681

et seq.

FinCEN agrees that it would be impracticable for covered financial institutions to implement the beneficial ownership verification requirement with procedures that are identical to the institution's existing CIP rule procedures for individual customers. Accordingly, § 1010.230(b)(2) has been amended to require that at a minimum, these procedures must contain the elements

44

required for verifying the identity of customers that are individuals under paragraph (a)(2) of

the applicable CIP rule,

45

but are not required to be identical. In addition, the final rule clarifies that in the case of documentary verification, the financial institution may use photocopies or other reproductions of the documents listed in paragraph (a)(2)(ii)(A)(

1

)

46

of the applicable CIP rule.

44

The clause “in the covered financial institution's Customer Identification Program procedures” in the proposed rule text have been deleted, because, for the reasons described above, the verification procedures for beneficial owners of legal entity customers may be different from the procedures in the covered financial institution's CIP that apply to individual customers.

45

Paragraph (a)(2) of each of the CIP rules requires that the relevant financial institution's CIP includes risk-based procedures to verify the identity of each customer, to the extent reasonable and practicable. The elements of such program must include identifying the customer, verifying the customer's identity (through documents or non-documentary methods), and procedures for circumstances where the institution cannot form a reasonable belief that it knows the true identity of the individual.

46

Relevant documentation may include unexpired government-issued identification evidencing nationality or residence and bearing a photograph or similar safeguard, such as a driver's license or passport.

See, e.g.,

31 CFR 1020.220(a)(2)(ii)(A)(

1

).

Because the risk-based verification procedures must contain the same elements as required by the applicable CIP rule to verify the identity of individual customers, verification must be completed within a reasonable time after the account is opened. In addition, the beneficial ownership identification procedures must address situations in which the financial institution cannot form a reasonable belief that it knows the true identity of the beneficial owner of a legal entity customer after following the required procedures.

47

It remains the case that covered financial institutions may generally rely on government-issued identification as verification of an individual's identity, absent obvious indications of fraud.

48

FinCEN notes that such reliance is also generally appropriate in the case of photocopies or other reproductions obtained pursuant to § 1010.230(b)(2). However, given the vulnerabilities inherent in the reproduction process, covered financial institutions should conduct their own risk-based analyses of the types of photocopies or reproductions that they will accept in accordance with this section, so that such reliance is reasonable. For example, a covered financial institution could determine that it will not accept reproductions below a certain optical resolution, or that it will not accept reproductions transmitted via facsimile, or that it will only accept digital reproductions transmitted in certain file formats. As with CIP, covered financial institutions are not required to maintain these copies or reproductions, but only a description of any document upon which the financial institution relied to verify the identity of the beneficial owner. We note, however, that although covered financial institutions are not required to maintain these reproductions, they are not prohibited from keeping them in a manner consistent with all other applicable laws or regulations.

47

Under the CIP rules, a financial institution's CIP must include procedures for responding to circumstances in which the financial institution cannot form a reasonable belief that it knows the true identity of a customer. These procedures should describe: (A) When the institution should not open an account; (B) The terms under which a customer may use an account while the institution attempts to verify the customer's identity; (C) When it should close an account, after attempts to verify a customer's identity have failed; and (D) When it should file a Suspicious Activity Report in accordance with applicable law and regulation.

See, e.g.,

31 CFR 1020.220(a)(2)(iii).

48

See, e.g.,

Customer Identification Programs for Banks, Savings Associations, Credit Unions and Certain Non-Federally Regulated Banks, 68 FR 25090, 25099 (May 9, 2003).

Some commenters urged FinCEN to permit covered financial institutions to take a risk-based, rather than categorical, approach to the identification and verification requirements. Among the objections lodged against a categorical requirement were that: Conducting CIP procedures on non-present beneficial owners would be too difficult; the benefit of a categorical requirement was outweighed by the costs; and expanding the number of natural persons subject to CIP procedures would increase costs, particularly for institutions that rely upon vendors that charge on a

per capita

basis for CIP. FinCEN believes that categorical application of this requirement across covered financial institutions will reduce illicit actors' opportunities to slip into the financial system by masking their legal entities with markers indicative of a low risk profile. As to concerns about costs and difficulties, we believe that the above-described changes and clarifications made to this paragraph have given financial institutions greater flexibility in determining how to implement the identification and verification requirements, thereby reducing their impact. As described above, because financial institutions will in most instances be able to rely upon the information provided by the customer, FinCEN believes that financial institutions generally will not expend substantially greater resources by collecting and verifying the information in all cases (subject to permitted exemptions) than by engaging in a risk analysis to determine whether the beneficial ownership information should be collected and verified. We recognize that financial institutions that pay for systems and technology costs associated with CIP procedures on a

per capita

basis will face increased costs from identifying and verifying the identities of additional natural persons. However, we believe that the benefits of collecting this information, as described at greater length above and below, outweigh these additional costs. FinCEN accordingly declines to alter the categorical nature of the requirement for the final rule.

Several commenters questioned the utility of collecting this information in the absence of an authoritative centralized resource against which to verify beneficial ownership status. They contended that the limited benefit of this information would not outweigh the costs imposed by the requirement. Law enforcement commenters, however, identified significant benefits to the collection of beneficial ownership information, regardless of financial institutions' ability to verify ownership status. They noted that the identities of verified natural persons linked to legal entities of interest had significant value in law enforcement investigations, whether or not those natural persons are the actual beneficial owners, since at a minimum they may have information that can aid law enforcement in identifying the true beneficial owner(s). Furthermore, false beneficial ownership information is of significant use to prosecutors in demonstrating consciousness of guilt, as well as for impeachment purposes at trial. And law enforcement also noted the likely deterrent effect that a categorical collection and verification requirement would have on illicit actors, by making it more difficult for them to maintain anonymity while opening accounts. For these reasons, FinCEN rejects the notion that this requirement is of limited value.

A few commenters requested that FinCEN eliminate the verification requirement entirely, contending that verification of the identities of non-present beneficial owners would be too difficult and burdensome, especially for smaller institutions. As described above, we are aware of the challenges associated with verifying the identities of non-present individuals and have accordingly made changes to simplify the process for financial institutions, which we expect will reduce the burden. Importantly, collecting beneficial ownership information without verifying the existence of the named person would substantially diminish the value of the information, and we therefore decline to eliminate the verification requirement.

Some commenters asked FinCEN to clarify what we expect financial institutions to do with the beneficial ownership information that they collect and verify. FinCEN generally expects

beneficial ownership information to be treated like CIP and related information, and accordingly used to ensure that covered financial institutions comply with other requirements. For example, the Office of Foreign Assets Control (OFAC) requires covered financial institutions to block accounts (or other property and interests in property) of, among others, persons appearing on the Specially Designated Nationals and Blocked Persons List (SDN List), which includes any entity that is 50 percent or more owned, in the aggregate, by one or more blocked persons, regardless of whether the entity is formally listed on the SDN List.

49

Therefore, institutions should use beneficial ownership information to help ensure that they do not open or maintain an account, or otherwise engage in prohibited transactions or dealings involving individuals or entities subject to OFAC-administered sanctions. Covered financial institutions should also develop risk-based procedures to determine whether and/or when additional screening of these names through, for example, negative media search programs, would be appropriate.

49

See generally

31 CFR part 500;

see also, e.g.,

31 CFR 590.406 (Ukraine-related sanctions regulations); Office of Foreign Assets Control,

Frequently Asked Questions, available at http://www.treasury.gov/resource-center/faqs/Sanctions/Pages/faq_general.aspx#50_percent

.

With respect to aggregation of transactions for Currency Transaction Reporting (CTR) purposes, FinCEN expects covered financial institutions to apply existing procedures consistent with CTR regulations and applicable FinCEN guidance from 2001 and 2012.

50

Thus, while financial institutions should generally recognize the distinctness of the corporate form and not categorically impute the activities or transactions of a legal entity customer to a beneficial owner, they must aggregate multiple currency transactions if the financial institution has knowledge that these transactions are by or on behalf of any person and result in either cash in or cash out totaling more than $10,000 during any one business day.

51

While the requirement to identify the beneficial owners of legal entity customers does not modify this existing CTR aggregation requirement, the beneficial ownership identification may provide financial institutions with information they did not previously have, in order to determine when transactions are “by or on behalf of” the same person. Thus, if a financial institution determines that a legal entity customer or customers are not being operated independently from each other or from their primary owner—

e.g.,

the institution determines that legal entities under common ownership have common employees and are repeatedly used to pay each other's expenses or the personal expenses of their primary owner—then the financial institution may determine that aggregating the transactions of a legal entity or entities and their primary owner would be appropriate.

52

Under such circumstances, if a financial institution were aware that a beneficial owner made a $5,000 cash deposit into his personal account, and later the same business day, he made a $6,000 cash deposit into the account of a legal entity not being operated as an independent entity, the institution would be required to aggregate those transactions and file a CTR.

53

And to the extent that the financial institution determined that such transactions had no other apparent purpose than to avoid triggering a CTR filing, the financial institution would need to consider whether filing a SAR about the transactions would be appropriate.

50

See

31 CFR 1010.313; FinCEN,

Currency Transaction Report Aggregation for Businesses with Common Ownership

FIN-2012-G001, (Mar. 16, 2012) (FIN-2012-G001); FinCEN,

Currency Transaction Reporting: Aggregation,

FinCEN Ruling 2001-2, (Aug. 23, 2001).

51

31 CFR 1010.313.

52

In general, such aggregation would only be appropriate in cases where an individual owns all or substantially all of the legal entity's equity interests. It is only in such cases that a transaction by a legal entity could be considered “by or on behalf of” the owner of the entity (or vice versa).

53

See

FIN-2012-G001 at 2.

A few commenters asked FinCEN to provide guidance as to how beneficial ownership information should be incorporated into processes for information sharing pursuant to USA PATRIOT Act Section 314(a); one of these commenters asked FinCEN to declare such information

per se

outside of the scope of Section 314(a). FinCEN does not expect the information obtained pursuant to the beneficial ownership requirement to add additional requirements with respect to Section 314(a) for financial institutions. The rule implementing Section 314(a), set forth at 31 CFR 1010.520, does not authorize the reporting of beneficial ownership information associated with an account or transaction matching a named subject. Under that rule, financial institutions need only search their records for account or transactions matching a named subject, and report to FinCEN whether such a match exists using the identifying information that FinCEN provides.

Section 1010.230(c) Account.

See discussion below under “Legal entity customer.”

Section 1010.230(d) Beneficial Owner.

In the NPRM, we proposed two prongs for the definition of beneficial owner: Each individual, if any, who directly or indirectly owned 25 percent of the equity interests of a legal entity customer (the ownership prong); and a single individual with significant responsibility to control, manage, or direct a legal entity customer, including an executive officer or senior manager or any other individual who regularly performs similar functions (the control prong). We noted that the number of beneficial owners identified would vary from legal entity customer to legal entity customer due to the ownership prong—there could be as few as zero and as many as four individuals who satisfy this prong. All legal entities, however, would be required to identify one beneficial owner under the control prong. We further noted that financial institutions had the discretion to identify additional beneficial owners as appropriate based on risk.

Thus, in practice, the number of beneficial owners identified will vary based on the circumstances. For example:

• Mr. and Mrs. Smith each hold a 50 percent equity interest in “Mom & Pop, LLC.” Mrs. Smith is President of Mom & Pop, LLC and Mr. Smith is its Vice President. Mom & Pop, LLC is required to provide the personal information of both Mr. & Mrs. Smith under the ownership prong. Under the control prong, Mom & Pop, LLC is also required to provide the personal information of one individual with significant responsibility to control Mom & Pop, LLC; this individual could be either Mr. or Mrs. Smith, or a third person who otherwise satisfies the definition. Thus, in this scenario, Mom & Pop, LLC would be required to identify at least two, but up to three distinct individuals—both Mr. & Mrs. Smith under the ownership prong, and either Mr. or Mrs. Smith under the control prong, or both Mr. & Mrs. Smith under the ownership prong, and a third person with significant responsibility under the control prong.

• Acme, Inc. is a closely-held private corporation. John Roe holds a 35 percent equity stake; no other person holds a 25 percent or higher equity stake. Jane Doe is the President and Chief Executive Officer. Acme, Inc. would be required to provide John Roe's beneficial ownership information under the ownership prong, as well as Jane Doe's (or that of another control person) under the control prong.

• Quentin, Inc. is owned by the five Quentin siblings, each of whom holds a 20 percent equity stake. Its President is Benton Quentin, the eldest sibling, who

is the only individual at Quentin, Inc. with significant management responsibility. Quentin, Inc. would be required to provide Benton Quentin's beneficial ownership information under the control prong, but no other beneficial ownership information under the ownership prong, because no sibling has a 25 percent stake or greater.

One commenter raised a concern that this obligation would effectively require financial institutions to monitor the equity interests and management team of legal entity customers on an ongoing basis and continually update this information. FinCEN notes that it would be impracticable for financial institutions to conduct this type of inquiry, and emphasizes that this obligation should be considered a snapshot, not a continuous obligation. As discussed more fully in the Section-by-Section Analysis addressing the amendments to the AML program rules, FinCEN does expect financial institutions to update this information based on risk, generally triggered by a financial institution learning through its normal monitoring of facts relevant to assessing the risk posed by the customer.

The Ownership Prong.

Commenters raised a number of points regarding the ownership prong. Several commenters speculated on FinCEN's intention with respect to this requirement. FinCEN confirms here that by the phrase “directly or indirectly,” it intends that the financial institution's customer identify its ultimate beneficial owner or owners as defined in the rule and not their nominees or “straw men.” In addition, as described in § 1010.230(b)(2), financial institutions may rely on information provided by the customer to identify and verify the beneficial owner.

Many commenters supported FinCEN's decision in the proposal to set the minimum threshold for equity holdings constituting ownership at 25 percent. Some of these commenters requested that FinCEN affirm this threshold as the regulatory expectation, notwithstanding our remarks in the proposal that financial institutions, after their own assessment of risk, could determine that a lower threshold percentage might be warranted. A few commenters, however, urged FinCEN to lower this threshold to 10 percent, contending that the higher threshold would be too easy to evade and is inconsistent with international AML norms and requirements of FATCA, and that the burden of a lower threshold would be minimal because some financial institutions as a matter of practice already collect beneficial ownership information at thresholds lower than 25 percent.

FinCEN has considered all of the arguments in favor of lowering the ownership threshold to 10 percent, and we decline to make this change in the final rule. Although it is true that some financial institutions already collect beneficial ownership information at a threshold lower than 25 percent in some cases, we do not believe that this practice is widely established enough to justify its categorical imposition for all legal entity customers across all covered financial institutions. As some proponents of the 10 percent threshold noted, this lower threshold would make it more difficult for illicit actors to structure ownership interests to evade the reporting threshold. However, it would also require financial institutions to identify and verify as many as eleven beneficial owners (including the control prong). In FinCEN's assessment, the incremental benefit of this approach does not outweigh the burdens associated with having to collect and verify the identities of more than twice as many beneficial owners in some circumstances. Furthermore, the proposed 25 percent threshold is consistent with that of many foreign jurisdictions (including EU member states) and with the FATF standard, which in turn is used to define the controlling persons of an entity in the intergovernmental agreements that the United States has entered into with more than 110 other jurisdictions in order to enforce the requirements of FATCA. FinCEN continues to believe that a 25 percent threshold strikes the appropriate balance between the benefit of identifying key natural persons who have substantial ownership interests in the legal entity and the costs associated with implementing this information-collection requirement.

We reiterate that the 25 percent threshold is the baseline regulatory benchmark, but that covered financial institutions may establish a lower percentage threshold for beneficial ownership (

i.e.,

one that regards owners of less than 25 percent of equity interests as beneficial owners) based on their own assessment of risk in appropriate circumstances. As a general matter, FinCEN does not expect covered financial institutions' compliance with this regulatory requirement to be assessed against a lower threshold. Nevertheless, consistent with the risk-based approach, FinCEN anticipates that some financial institutions may determine that they should identify and verify beneficial owners at a lower threshold in some circumstances; we believe that making this clear in the note accompanying the regulatory text will aid them in doing so with respect to their customers.

Some commenters urged FinCEN to include in the ownership prong a “fallback provision” to require the collection of beneficial ownership information for at least one individual with a significant equity stake in the legal entity, even if no beneficial owner meets the minimum ownership threshold. Such a provision was initially discussed in the ANPRM for this rulemaking but not included in the NPRM in response to concerns expressed by numerous commenters that the approach was impracticable. As we noted in the NPRM, commenters questioned the feasibility of engaging in a comparative analysis of every owner to determine the individual who “has at least as great an equity interest in the entity as any other individual.” Agreeing with that assessment, we removed this provision, and we do not believe that any benefit from its reintroduction would outweigh the difficulties that customers and front-line employees would face in implementing it. Although we have declined to include this provision in the final rule, financial institutions may determine, pursuant to a risk-based approach for their institutions, that certain higher risk circumstances may warrant the collection of beneficial ownership information for at least one natural person under the ownership prong even if no beneficial owner meets the 25 percent threshold.

One commenter requested that FinCEN clarify whether covered financial institutions had an obligation to determine whether equity holders of a legal entity managed or structured their holdings to evade the 25 percent threshold for reporting. FinCEN notes that in most cases it would be impracticable for front-line employees to conduct this type of inquiry. Thus, FinCEN expects that financial institutions will generally be able to rely upon information about equity ownership provided by the person opening the account, and not to affirmatively investigate whether equity holders are attempting to avoid the reporting threshold. However, financial institution staff who know, suspect, or have reason to suspect that such behavior is occurring may, depending on the circumstances, be required to file a SAR.

A few commenters sought clarification of the definition of “equity interests” provided in the proposal—to wit, an ownership interest in a business entity—contending that although the proposed definition provided a great

deal of latitude and flexibility, it might also cause confusion due to its broad sweep. Thus, commenters requested greater clarification and guidance in the form of examples or additional commentary, to assist customers in understanding and complying with the requirements of the regulation as well as employees in their determinations as to which types of ownership interests are subject to this prong. FinCEN appreciates that some financial institutions may find it challenging in some circumstances to determine whether a particular ownership interest qualifies as an “equity interest.” However, as we noted in the proposal, we deliberately avoided the use of more technical terms of art associated with the exercise of control through ownership; we did so in part based on the preferences expressed by many members of industry. The above-mentioned commenters urged FinCEN to avoid creating a definition using technical and complex legal terms that would also be difficult for customers and front-line employees to understand and apply. Beyond the general examples provided in the proposal, however, we are reluctant to provide additional narrower examples that could be construed to limit a definition that we intend to be broadly applicable, particularly in light of the diversity of types of legal entities formed within the United States and abroad. By the same token, we also decline to provide a formal guidance document listing the types of documents that front-line employees should rely upon to demonstrate the existence of an equity interest over the triggering threshold. We reiterate that it is generally the responsibility of the legal entity customer (and its personnel) to make this determination and to identify the beneficial owners, and not front-line employees at the financial institution, unless the employees have reason to question the accuracy of the information presented.

Some commenters noted that while they approved of FinCEN's general approach to determining indirect ownership of legal entity customers—

i.e.,

that FinCEN does not expect financial institutions or customers to undertake analyses to determine whether an individual is a beneficial owner under the definition—they nevertheless thought that FinCEN should provide additional guidance and examples of how legal entity customers should calculate ownership interests when natural persons have indirect equity interests. As an initial matter, as described above, we emphasize that FinCEN expects that financial institutions will generally be able to rely on the representations of the customer when it identifies its beneficial owners. We also note that it would not be unreasonable to expect that a legal entity that has a complex structure would have personnel who necessarily have a general understanding of the ownership interests of the natural persons behind it for operational, management, accounting, and other purposes.

Commenters also sought clarification regarding various scenarios where 25 percent or greater equity interests of a legal entity customer are held in such a manner that the interest is not ultimately owned, directly or indirectly, by any individual. This could occur, for example, where a 25 percent or greater ownership interest is held by an entity excluded from the legal entity customer definition under paragraph (e)(2) or by a trust. FinCEN notes that the exclusions in the proposed rule include any entity organized under the laws of the United States or of any State at least 51 percent of whose common stock or analogous equity interests are held by an entity listed on a U.S stock exchange. FinCEN believes that this should address the overwhelming majority of situations where an excluded entity is a 25 percent or more shareholder. In addition, in the relatively unusual situations where an excluded entity holds a 25 percent or greater equity interest that is not covered by the above-mentioned exclusion, FinCEN notes that covered financial institutions are not required under the ownership prong to identify and verify the identities of a natural person behind these entities; this is because the definition of “beneficial owner” under the ownership prong refers to “[e]ach individual,

if any,

. . .”, and in such a case there would not be any individual who is the ultimate owner of such interest. On the other hand, where 25 percent or more of the equity interests of a legal entity customer are owned by a trust (other than a statutory trust), covered financial institutions would satisfy the ownership prong of the beneficial ownership requirement by collecting and verifying the identity of the trustee, and FinCEN has amended the definition consistent with this. For clarity, FinCEN notes that in any such case the legal entity customer would nonetheless be required to identify an individual under the control prong.

The Control Prong.

Commenters also raised a variety of points regarding this element.

A few commenters requested that we narrow or eliminate the control prong, contending that it would be difficult to identify a control person under such a wide-ranging definition. We disagree. FinCEN proposed a broad definition to give legal entities a wide range of options from which to choose. Accordingly, the breadth of the definition will facilitate, rather than hinder, financial institutions' ability to collect this information—because legal entity customers are required to provide information on only one control person who satisfies the definition, legal entities should be able to readily identify at least one natural person within their management structure who has significant management responsibility, consistent with the multiple examples of positions provided. Furthermore, there may be legal entities for which there are no natural persons who satisfy the ownership prong; without the control prong, this would create a loophole for legal entities seeking to obscure their beneficial ownership information. Requiring the identification and verification of, at a minimum, one control person ensures that financial institutions will have a record of at least one natural person associated with the legal entity, which will benefit law enforcement and regulatory investigations for reasons described previously.

A few commenters requested that FinCEN provide additional information about the types of persons who would satisfy the control prong, contending that a level of detail similar to the explanations provided for the ownership prong would be helpful for implementation. We believe that such additional explanation is unnecessary. In contrast with the variety of possible complicated scenarios that a financial institution might encounter when trying to determine beneficial ownership under the ownership prong, the control prong provides for a straightforward test: The legal entity customer must provide identifying information for one person with significant managerial control. It further provides as examples a number of common, well-understood senior job titles, such as President, Chief Executive Officer, and others. Taken together, FinCEN believes that these clauses provide ample information for legal entity customers to easily identify a natural person that satisfies the definition of control person.

A few commenters requested that FinCEN expand the reach of the control prong by, among other things, including within it the concept of “effective control,” and proposing a variety of changes to mandate the identification of additional natural persons under this

prong, from all persons who exercise executive management and leadership, to all senior officials and all those who exercise effective control over a legal entity. FinCEN declines to make any of these changes to the control prong. While we recognize that our definition does not encapsulate all possible concepts of control, including effective control, we believe that our definition strikes the appropriate balance between including sufficiently senior leadership positions and practicability. As one of the proponents of including effective control conceded, effective control can be “difficult to determine.” We sought in our proposal to provide an easily administrable definition to facilitate collection of this information for both legal entities and financial institutions. As to the identification of additional natural persons, we believe that the challenges associated with identifying and verifying additional natural persons outweigh any incremental benefit of the information.

Section 1010.230(e) Legal Entity Customer.

As proposed, this paragraph defined the term “legal entity customer” and delineated a series of exclusions from this definition.

Section 1010.230(e)(1).

In the proposed rule, we to defined “legal entity customer” to mean a corporation, limited liability company, partnership or other similar business entity (whether formed under the laws of a state or of the United States or a foreign jurisdiction) that opens a new account. Many commenters raised questions about what entities and other businesses would be covered and requested that the proposed definition be clarified, particularly the meaning of “other similar business entity.” Some commenters urged us to include other business forms, such as unincorporated associations and sole proprietorships, within the definition of legal entity customer.

We agree that covered institutions would benefit from a revised definition that further clarifies the entities that fall within the definition of “legal entity customer.” Thus, for the purposes of the final rule, we state that a legal entity customer means a corporation, limited liability company, or other entity that is created by the filing of a public document with a Secretary of State or similar office, a general partnership, and any similar entity formed under the laws of a foreign jurisdiction, that opens an account. This means that “legal entity customer” would include, in addition to corporations and limited liability companies, limited partnerships, business trusts that are created by a filing with a state office, any other entity created in this manner, and general partnerships. (It would also include similar entities formed under the laws of other countries.) It would not include, for example, sole proprietorships or unincorporated associations even though such businesses may file with the Secretary of State in order to, for example, register a trade name or establish a tax account. This is because neither a sole proprietorship nor an unincorporated association is an entity with legal existence separate from the associated individual or individuals that in effect creates a shield permitting an individual to obscure his or her identity.

54

The definition of “legal entity customer” also does not include natural persons opening accounts on their own behalf. In the final rule, we remove the reference to a “new” account to eliminate redundancies with other paragraphs of this provision, and because this account status is not a relevant characteristic for defining a legal entity customer.

54

FinCEN notes that this is consistent with the CIP rules, which include as a customer “an individual who opens a new account for . . . (B) an entity that is not a legal person, such as a civic club.” In such a case, the individual opening the account, rather than the civic club, is the customer.

See, e.g.,

31 CFR 1020.100(c)(1)(ii)(B).

Trusts

The definition would also not include trusts (other than statutory trusts created by a filing with a Secretary of State or similar office). This is because, unlike the legal entities that are subject to the final rule, a trust is a contractual arrangement between the person who provides the funds or other assets and specifies the terms (

i.e.,

the grantor or settlor) and the person with control over the assets (

i.e.,

the trustee), for the benefit of those named in the trust deed (

i.e.,

the beneficiaries). Formation of a trust does not generally require any action by the state. As FinCEN noted in the NPRM, identifying a “beneficial owner” from among these parties, based on the definition in the proposed or final rule, would not be possible.

FinCEN emphasizes that this does not and should not supersede existing obligations and practices regarding trusts generally. The preamble to each of the CIP rules notes that, while financial institutions are not required to look through a trust to its beneficiaries, they “may need to take additional steps to verify the identity of a customer that is not an individual, such as obtaining information about persons with control over the account.”

55

Moreover, as FinCEN noted in the proposal, it is our understanding that where trusts are direct customers of financial institutions, financial institutions generally also identify and verify the identity of trustees, because trustees will necessarily be signatories on trust accounts (which in turn provides a ready source of information for law enforcement in the event of an investigation). Furthermore, under supervisory guidance for banks, “in certain circumstances involving revocable trusts, the bank may need to gather information about the settlor, grantor, trustee, or other persons with the authority to direct the trustee, and who thus have authority or control over the account, in order to establish the true identity of the customer.”

56

We reiterate our understanding that, consistent with existing obligations, financial institutions are already taking a risk-based approach to collecting information with respect to various persons associated with trusts in order to know their customer,

57

and that we expect financial institutions to continue these practices as part of their overall efforts to safeguard against money laundering and terrorist financing.

58

55

See, e.g.,

“Customer Identification Programs for Broker-Dealers,” 68 FR at 25116 n.32. (May 9, 2003).

56

Federal Financial Institutions Examination Council,

Bank Secrecy Act/Anti-Money Laundering Examination Manual

281 (2014) (FFIEC Manual).

57

FinCEN also understands that in order to engage in the business of acting as a trustee, it is necessary for a trust company to be Federally- or State-chartered. Such entities are subject to BSA obligations, which reduces the AML risk of such trusts.

58

Also not covered by the final rule are accounts in the name of a deceased individual opened by a court-appointed representative of the deceased's estate.

“Account” Definition

FinCEN also notes that a legal entity customer is defined as one that opens an account, but that the NPRM did not define the term “account.” Several commenters requested that FinCEN provide a definition for this term and suggested using the definition from the CIP rules. In order to maintain consistency with the CIP rules, FinCEN is adding to the final rule the definition of the term “account” that is found in the CIP rules,

59

which by its terms excludes an account opened for the purpose of participating in an employee benefit plan established under the Employee Retirement Income Security Act of 1974. This added provision is not only consistent with CIP but also appropriate for the final rule, inasmuch as accounts established to enable

employees to participate in retirement plans established under ERISA are of extremely low money laundering risk.

59

See, e.g.,

31 CFR 1020.100(a)(2) (for banks); 1023.100(a)(2) (for brokers or dealers in securities); 1024.100(a)(2) (for mutual funds); and 1026.100(a)(2) (for futures commission merchants or introducing brokers in commodities).

In this regard, commenters requested that FinCEN broaden the exemption for ERISA plans to include other non-ERISA retirement plans, based on their low risk of money laundering, FinCEN notes that in the case of such non-ERISA plans, the customer would generally either be the trust established to maintain the assets, or the employer that contracts with the financial institution to establish the account, and not the underlying participants in or beneficiaries of the account.

60

Accordingly, in the case where the customer would be the employer and such employer is a legal entity, the financial institution would be required to obtain the beneficial owners of the legal entity employer (unless such employer is otherwise excluded from the definition of legal entity customer). We address other requests for exemptions from the beneficial ownership requirement in the discussion of § 1010.230(h) below.

60

See

FinCEN

et al., Interagency Interpretive Guidance on Customer Identification Program Requirements under Section 326 of the USA PATRIOT Act, FAQs: Final CIP Rule

6 April 28, 2005, page 6,

available at http://www.fincen.gov/statutes_regs/guidance/pdf/faqsfinalciprule.pdf

.

Paragraph (c) of § 1010.230 of the final rule will accordingly read as set out in the regulatory text at the end of this document.

Section 1010.230(e)(2).

The NPRM proposed ten exclusions from the legal entity customer definition. The first two categories are also for the most part excluded from the requirements of the CIP rules. The final rule adopts all of those proposed exclusions, except as discussed below under the heading, Charities and Nonprofit Entities. The final rule also adds a number of other exclusions in response to comments. All of the exclusions are a result of an assessment of the risks and determination that beneficial ownership information need not be obtained at account opening, because the information is generally available from other credible sources:

A financial institution regulated by a Federal functional regulator or a bank regulated by a State bank regulator

—1010.230(e)(2)(i)

These entities are excluded because they are subject to Federal or State regulation and information regarding their beneficial ownership and management is available from the relevant Federal or State agencies.

A person described in § 1020.315(b)(2) through (5) of this chapter

— § 1010.230(e)(2)(ii)

This includes the following:

•

A department or agency of the United States, of any State, or of any political subdivision of a State.

FinCEN has determined that this category is appropriate for exclusion because such entities have no equity owners and information regarding their management is readily available from public sources.

•

Any entity established under the laws of the United States, of any State, or of any political subdivision of any State, or under an interstate compact between two or more States, that exercises governmental authority on behalf of the United States or of any such State or political subdivision.

This category is also appropriate for exclusion due to the amount of ownership and management information that is publicly available about such entities.

•

Any entity (other than a bank) whose common stock or analogous equity interests are listed on the New York, American

,

61

or NASDAQ stock exchange.

This exclusion is appropriate because such entities are required to publicly disclose the beneficial owners of five percent or more of each class of the issuer's voting securities in periodic filings with the SEC, to the extent the information is known to the issuer or can be ascertained from public filings.

62

In addition, beneficial owners of these issuers' securities may be subject to additional reporting requirements.

63

61

Currently called NYSE MKT.

62

See, e.g.,

Item 12 of Form 10-K and Item 403 of Regulation S-K.

63

See

Securities Exchange Act section 13(d) and Rules 13d-1 to 13d-102; Securities Exchange Act § 16(a) and Rules 16a-1 through 16a-13.

•

Any entity organized under the laws of the United States or of any State at least 51 percent of whose common stock or analogous equity interests are held by a listed entity.

Because such subsidiaries of listed entities are controlled by their parent listed entity, information regarding control and management is publicly available.

An issuer of a class of securities registered under section 12 of the Securities Exchange Act of 1934 or that is required to file reports under section 15(d) of that Act

64

—§ 1010.230(e)(2)(iii)

64

See

Securities Exchange Act section 16(a) and Rules 16a-1 through 16a-13 and Item 403 of Regulation S-K.

These issuers are excluded because they are required to publicly disclose the beneficial owners of five percent or more of each class of the issuer's voting securities in periodic filings with the SEC, to the extent the information is known to the issuer or can be ascertained from public filings.

65

In addition, beneficial owners of the issuer's securities may be subject to additional reporting requirements.

66

65

See, e.g.,

Item 12 of Form 10-K and Item 403 of Regulation S-K.

66

See

Securities Exchange Act section 13(d) and Rules 13d-1 to 13d-102; Securities Exchange Act § 16(a) and Rules 16a-1 through 16a-13.

An investment company, as defined in Section 3 of the Investment Company Act of 1940, that is registered with the SEC under that Act

—§ 1010.230(e)(2)(iv)

An investment adviser, as defined in section 202(a)(11) of the Investment Advisers Act of 1940, that is registered with the SEC under that Act

—§ 1010.230(e)(2)(v)

These entities are excluded because registered investment companies and registered investment advisers already publicly report beneficial ownership in their filings with the SEC.

67

67

See, e.g.,

Item 17 of Form N-1A and Schedule A to Part 1A of Form ADV.

An exchange or clearing agency, as defined in section 3 of the Securities Exchange Act of 1934, that is registered under section 6 or 17A of that Act

—§ 1010.230(e)(2)(vi)

Any other entity registered with the SEC under the Securities and Exchange Act of 1934

—§ 1010.230(e)(2)(vii)

These entities are excluded because the SEC registration process requires disclosure and regular updating of information about beneficial owners of those entities, as well as senior management and other control persons.

A registered entity, commodity pool operator, commodity trading advisor, retail foreign exchange dealer, swap dealer, or major swap participant, each as defined in section 1a of the Commodity Exchange Act, that is registered with the CFTC

—§ 1010.230(e)(2)(viii)

These entities are excluded because the CFTC registration process requires disclosure and regular updating of information about beneficial owners of those entities, as well as senior management and other control persons.

A public accounting firm registered under section 102 of the Sarbanes-Oxley Act

—§ 1010.230(e)(2)(ix)

Such firms are those that audit publicly traded companies and SEC-registered broker-dealers. These firms are required to register with the Public Company Accounting Oversight Board

(PCAOB), a nonprofit corporation established by Congress to oversee the audits of publicly traded companies, and are required to file annual and special reports with the PCAOB. In addition, States require public accounting firms to register and to file annual reports identifying their members (

e.g.,

partners, members, or shareholders).

68

Such information is often available online.

68

See, e.g.,

New York State Education Law, Article 149, Section 7408.3.

Many commenters also urged that the proposed exclusions from the legal entity customer definition be expanded or clarified in certain respects. These include, among others, exclusions for accounts for employee benefit plans (addressed above), additional entities regulated by the United States or States of the United States, foreign governments and agencies, foreign financial institutions, and nonprofits. Commenters also sought clarity on how certain types of entities and relationships should be treated.

Additional Regulated Entities

A bank holding company, as defined in section 2 of the Bank Holding Company Act of 1956 (12 U.S.C. 1841), or savings and loan holding company, as defined in section 10(n) of the Home Owners' Loan Act (12 U.S.C. 1467a(n))

—§ 1010.230(e)(2)(x)

At the suggestion of several commenters, bank holding companies, which include financial holding companies, have been excluded from the beneficial ownership requirement in the final rule because the Federal Reserve Board maintains beneficial ownership information on all of these companies. Savings and loan holding companies are excluded for the same reason.

A pooled investment vehicle that is operated or advised by a financial institution excluded under this paragraph

—§ 1010.230(e)(2)(xi)

In response to several commenters who noted that beneficial ownership information would be available regarding the operator or adviser of such pooled vehicles, FinCEN has determined that the pooled vehicle should also be excluded from this requirement.

An insurance company that is regulated by a State

—§ 1010.230(e)(2)(xii)

A few commenters sought exclusion of insurance companies from the definition of legal entity customer, with the requested exclusions ranging in scope from all insurance companies subject to an AML program requirement and all insurance companies regulated by a State of the United States, to those insurance companies that own or control an SEC registered broker-dealer or SEC registered investment adviser. We address these proposals in turn.

The commenters who proposed to exclude all insurance companies subject to an AML program requirement and all State-regulated insurance companies did not directly proffer a rationale for their request. We presume that the commenters believe that insurance companies subject to an AML program requirement and to State regulation present a lower risk profile, and should therefore be excluded. As to insurance companies subject to an AML program requirement, such status alone does not require insurance companies to disclose beneficial ownership information to their supervisors. Accordingly, an exclusion on that basis would not be warranted. With respect to insurance companies regulated by a State of the United States, these companies must disclose and regularly update their beneficial owners, as well the identities of senior management and other control persons. For insurance firms that are a part of a publicly traded group, such disclosures would also be found in annual SEC filings. All State-regulated insurance companies are required to file an Annual Statement with their State regulators, identifying senior management, directors, and trustees. Schedule Y of this Statement shows the firm's corporate structure, including direct and indirect parents and subsidiaries of the insurer. Form B, an annual registration statement filed with state regulators, shows the executive officers, directors, and controlling shareholders of insurance companies. In the case of mutual insurance companies, which do not issue equity and are instead owned as a whole by their policyholders, Form B nevertheless shows their executive officers and directors. For these reasons, we believe an exclusion for State-regulated insurance companies is appropriate, and we have accordingly added to the final rule an exclusion for an insurance company that is regulated by a State as paragraph (e)(2)(xii).

69

69

Because “State” is defined in 31 CFR 1010.100(vv), we have not included “of the United States” in the rule text.

Some commenters also sought an exclusion for insurance companies that own or control an SEC registered broker-dealer or SEC registered investment adviser, noting that their registration with the SEC results in the disclosure of all individuals and entities in the indirect chain of ownership of the broker-dealer or adviser with an ownership interest of 25 percent or more. FinCEN understands that in the vast majority of cases, an insurance company that owns or controls a registered broker-dealer or investment advisor would also be regulated by a State. Accordingly, FinCEN believes that this additional exclusion would be redundant.

A financial market utility designated by the Financial Stability Oversight Council under Title VIII of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010

—§ 1010.230(e)(2)(xiii)

One commenter requested that FinCEN exclude designated financial market utilities from the definition of legal entity customer, noting that such entities are already subject to extensive regulation. FinCEN understands that entities designated as financial market utilities by the Financial Stability Oversight Council pursuant to Title VIII of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 are subject to extensive supervision and oversight by their Federal functional regulators, including the disclosure of beneficial ownership information. Accordingly, FinCEN believes that it is appropriate to exclude them from the definition.

Excluded Foreign Entities

A foreign financial institution established in a jurisdiction where the regulator of such institution maintains beneficial ownership information regarding such institution

—§ 1010.230(e)(2)(xiv)

Numerous commenters urged FinCEN to broaden the proposed exemptions for regulated financial institutions and publicly traded companies in the United States to include their counterparts outside of the United States. With regard to regulated foreign financial institutions, some commenters noted that in the rules implementing section 312 of the USA PATRIOT Act, even in the case of foreign banks subject to enhanced due diligence, a U.S. bank need obtain ownership information only if such foreign banks are not publicly traded,

70

and that it would be inconsistent to impose a more burdensome requirement in the case of correspondent accounts for foreign banks (and arguably other foreign financial institutions) that are not subject to enhanced due diligence. FinCEN agrees with this analysis and has broadened the exclusions to the

definition of legal entity customer in the final rule to include foreign financial institutions established in jurisdictions where the regulator of such institution maintains beneficial ownership information regarding such institution. As with other exclusions described above, FinCEN has determined that it is appropriate to exclude these entities, because information regarding their beneficial ownership and management is available from the relevant foreign regulator.

70

31 CFR 1010.610(b)(3).

A non-U.S. governmental department, agency or political subdivision that engages only in governmental rather than commercial activities

—§ 1010.230(e)(2)(xv)

Commenters also requested that certain departments, agencies, and political subdivisions of non-U.S. governments, as well as State-owned enterprises and supranational organizations, should also be exempt from the beneficial ownership requirement. The commenters pointed out that no such customers would have beneficial owners under the ownership prong, and any individual identified under the control prong would in most cases not be in the United States, which would make verification of identity more difficult. We agree that certain departments, agencies, and political subdivisions of non-U.S. governments—specifically, those that engage only in governmental (and not commercial) activities—should not fall within the definition of legal entity customer, and should therefore be excluded from the requirement. Although this delineation between governmental and commercial activities arises out of well-recognized principles of sovereign immunity, FinCEN does not expect front-line employees of covered financial institutions to engage in any type of legal analysis to determine the applicability of this exclusion. Rather, FinCEN expects covered financial institutions to rely upon the representations of such customers, absent knowledge to the contrary.

Some commenters also requested an exclusion for supranational organizations. FinCEN is not aware of a well-established, widely accepted definition of this term that could serve to clearly notify such entities of their eligibility to be excluded from this requirement. Because of the administrative challenges associated with determining such eligibility in the absence of a clear line, FinCEN declines to include such an exclusion in the final rule. We recognize that many such organizations would generally lack equity interests (and accordingly, equity stakes); thus, as in the case of other legal entities lacking such interests, financial institutions would be expected to collect beneficial ownership information under the control prong only.

Any legal entity only to the extent that it opens a private banking account subject to 31 CFR 1010.620

—§ 1010.230(e)(2)(xvi)

A number of commenters requested that FinCEN clarify the treatment of beneficial owners of private banking accounts for non-U.S. persons that are subject to FinCEN's private banking account rule,

71

which requires financial institutions maintaining such accounts to ascertain the identity of all beneficial owners of such accounts, but utilizes a different definition.

72

Because covered financial institutions have established a process for complying with the private banking account regulation, FinCEN has determined that it is appropriate to exclude such legal entity customers from the beneficial ownership requirement only when they establish such accounts.

71

31 CFR 1010.620.

72

31 CFR 1010.605(a).

Nonexcluded Pooled Investment Vehicles

In the proposal, FinCEN sought comment on the approach that it should take towards pooled investment vehicles that are operated or advised by financial institutions that are not proposed to be excluded from the definition of legal entity customer,

i.e.,

whether they should also be excluded from this requirement, or, if such vehicles are not excluded, whether covered financial institutions should be required to identify beneficial owners of such vehicles only under the control prong of the beneficial ownership definition. We noted that such entities often have ownership interests that fluctuate, and that identifying beneficial owners of these entities based on a percentage ownership threshold accordingly might create unreasonable operational challenges to collect information that would only be accurate for a limited period of time.

Some commenters requested that FinCEN exclude such pooled investment vehicles from the beneficial ownership requirement for several reasons, including the logistical difficulties of maintaining the information and possible limited duration of the accuracy of the information noted above. The commenters requested that, if such vehicles are not excluded, then FinCEN should require those financial institutions to collect beneficial ownership information of such entities under the control prong only. FinCEN agrees that, because of the limited utility and difficulty of collecting beneficial ownership information under the ownership prong, in the case of pooled investment vehicles whose operators or advisers are not excluded from this definition, such as non-U.S. managed mutual funds, hedge funds, and private equity funds, financial institutions would be required to collect beneficial ownership information under the control prong only (

e.g.,

an individual with significant responsibility to control, manage, or direct the operator, adviser, or general partner of the vehicle). This treatment of nonexcluded pooled investment vehicles is reflected in the final rule in § 1010.230(e)(3)(i).

Intermediated Account Relationships

In the NPRM, we proposed that if an intermediary is the customer, and the financial institution has no CIP obligation with respect to the intermediary's underlying clients pursuant to existing guidance, a financial institution should treat the intermediary, and not the intermediary's underlying clients, as its legal entity customer. Thus, existing guidance issued jointly by Treasury or FinCEN and any of the Federal functional regulators for broker-dealers, mutual funds, and the futures industry related to intermediated relationships would apply.

73

Commenters from the securities, mutual fund, and futures industries strongly supported this approach. FinCEN confirms that this principle will apply in interpreting the final rule, as follows: To the extent that

existing guidance provides that, for purposes of the CIP rules, a financial institution shall treat an intermediary (and not the intermediary's customers) as its customer, the financial institution should treat the intermediary as its customer for purposes of this final rule. FinCEN also confirms that other guidance issued jointly by FinCEN and one or more Federal functional regulators relating to the application of the CIP rule will apply to this final rule, to the extent relevant.

74

73

See, e.g.,

Guidance from the Staffs of the Department of the Treasury and the U.S. Securities and Exchange Commission,

Questions and Answers Regarding the Mutual Fund Customer Identification Rule,

August 11, 2003,

available at https://www.sec.gov/divisions/investment/guidance/qamutualfund.htm.;

Guidance from the Staffs of the Department of the Treasury and the U.S. Securities and Exchange Commission,

Question and Answer Regarding the Broker-Dealer Customer Identification Program Rule

(31 CFR 103.122) (October 1, 2003),

available at http://www.fincen.gov/statutes_regs/guidance/html/20031001.html;

Guidance from the Staffs of the Department of the Treasury and the U.S. Commodity Futures Trading Commission,

Frequently Asked Question regarding Customer Identification Programs for Futures Commission Merchants and Introducing Brokers

(31 CFR 103.123),

available at http://www.fincen.gov/statutes_regs/guidance/html/futures_omnibus_account_qa_final.html;

FinCEN,

Application of the Regulations Requiring Special Due Diligence Programs for Certain Foreign Accounts to the Securities and Futures Industries,

FIN-2006-G009 (May 10, 2006),

available at http://www.fincen.gov/statutes_regs/guidance/html/312securities_futures_guidance.html.

74

See, e.g.,

FinCEN,

Application of the Customer Identification Program Rule to Future Commission Merchants Operating as Executing and Clearing Brokers in Give-Up Arrangements,

FIN-2007-G001 (April 20, 2007),

available at http://www.fincen.gov/statutes_regs/guidance/html/cftc_fincen_guidance.html;

“

FAQs: Final CIP Rule

”.

One commenter representing the legal profession requested that escrow accounts established by lawyers to keep their clients' funds in trust be given the same treatment, due to lawyers' professional obligations to maintain client confidentiality under State law and codes of professional conduct. This commenter proposed that in the case of such accounts, only the lawyers and law firms establishing these accounts would be deemed legal entity customers from which beneficial ownership information would be collected. FinCEN understands that many attorneys maintain client trust or escrow accounts containing funds from multiple clients and other third parties in a single account. Funds flow in and out of these accounts during the normal course of business, and while these movements may not be as frequent as those found in, for example, pooled accounts in the securities and futures industries, they nevertheless create significant operational challenges to collecting this information with reference to the relevant clients and third parties. As in the case of nonexcluded pooled investment vehicles, FinCEN believes that it would be unreasonable to impose such collection obligations for information that would likely be accurate only for a limited period of time. FinCEN also understands that State bar associations impose extensive recordkeeping requirements upon attorneys with respect to such accounts, generally including, among other things, records tracking each deposit and withdrawal, including the source of funds, recipient of funds, and purpose of payment; copies of statements to clients or other persons showing disbursements to them or on their behalf; and bank statements and deposit receipts.

75

For these reasons, FinCEN believes that attorney escrow and client trust accounts should be treated like other intermediated accounts described above, and we accordingly deem such escrow accounts intermediated accounts for purposes of the beneficial ownership requirement.

75

See, e.g.,

22 N.Y.C.R.R. Part 1200, Rule 1.15; California State Bar Rule of Professional Conduct 4-100.

Charities and Nonprofit Entities

In the NPRM, we proposed an exclusion from the definition of “legal entity customer” for charities and nonprofit entities that are described in sections 501(c), 527, or 4947(a)(1) of the Internal Revenue Code of 1986, which have not been denied tax exempt status, and which are required to and have filed the most recently due annual information return with the Internal Revenue Service.

Commenters raised a number of issues with this proposed exemption. These include the fact that, in order to qualify for the exemption, the financial institution would effectively need to verify each of the following:

1. That the customer qualifies for an exemption under one of the three listed sections of the Internal Revenue Code, which would likely require that the financial institution review the entity's IRS documentation;

2. That the exemption has not been revoked;

3. That the entity is required to file an annual information return; and

4. That the entity has in fact filed such return.

Commenters expressed concerns that these steps to verify a charitable organization's eligibility for the exemption would be unduly burdensome and difficult for frontline staff to administer. Several commenters asked whether the financial institution could utilize the IRS's search tool that enables taxpayers to confirm the tax exempt status of organizations, “EO Select Check,” in order to verify the necessary information; others noted that, while this Web site confirms the tax exempt status of organizations, it does not confirm that the organization has filed its most recently due return. Moreover, up-to-date information, particularly regarding a recently formed organization, may not be available. Commenters noted further that, unless these issues can be addressed in a way that would facilitate the use of the exclusion, it would in many cases be simpler to ignore the exclusion and obtain the beneficial ownership information.

FinCEN has considered the comments addressing this proposed exclusion and agrees that as proposed the exclusion would in many cases be difficult to administer. Rather than limiting its treatment of this category to entities that are exempt from Federal tax and requiring proof of such exemption, FinCEN has determined that it would be simpler, as well as more efficient and more logical, to exclude all nonprofit entities (whether or not tax-exempt) from the ownership prong of the requirement, particularly considering the fact that nonprofit entities do not have ownership interests, and require only that they identify an individual with significant responsibility to control, manage, or direct the customer. Accordingly, the final rule eliminates this proposed exclusion and instead includes as a type of legal entity customer, subject only to the control prong of the beneficial owner definition, any legal entity that is established as a nonprofit corporation or similar entity and has filed its organizational documents with the appropriate State authority as necessary.

For purposes of this provision, a nonprofit corporation or similar entity would include, among others, charitable, nonprofit, not-for-profit, nonstock, public benefit or similar corporations. Such an organization could establish that it is a qualifying entity by providing a certified copy of its certificate of incorporation or a certificate of good standing from the appropriate State authority, which may already be required for a legal entity to open an account with a financial institution under its CIP.

76

FinCEN also believes that identifying and verifying an individual under the control prong is not an onerous requirement, and understands from its outreach that in the cases of many nonprofits such an individual is already identified to the financial institution as a signatory. FinCEN also notes that as a general matter, small local community organizations, such as Scout Troops and youth sports leagues, are unincorporated associations rather than legal entities and therefore not subject to the beneficial ownership requirement.

76

See, e.g.,

31 CFR 1020.220(a)(2)(ii)(A)(

2

).

Other Proposed Exclusions

A few commenters requested that we expand the list of exclusions to include all types of entities currently exempt from CTR reporting requirements. Although some of the exclusions to the definition of legal entity customer correspond to entities exempt from CTR

reporting requirements,

77

we decline to extend these exclusions to include all of the CTR exemptions. The CTR and beneficial ownership requirements serve different purposes, and the principal underlying justification for many of the CTR exemptions—that the requirement is not feasible or appropriate for cash-intensive low-risk businesses—does not apply here. FinCEN has considered all the CTR exemptions and has included those that are logical in the context of the beneficial ownership requirement, for the reasons articulated above.

77

See

31 CFR 1010.230(e)(2)(i), which includes certain persons exempt from CTR reporting.

Some commenters also requested that FinCEN exclude other “low-risk” entities from the definition of legal entity customer. We have considered all commenters' requests for exclusions to the definition and have incorporated only those that we have determined are appropriate in this context.

Section 1010.230(f) Covered Financial Institution.

As proposed, this paragraph defined covered financial institution through incorporation by reference of the definition set forth in § 1010.605(e)(1), thereby subjecting to this requirement those financial institutions already covered by CIP requirements. FinCEN noted in the proposal that it viewed the exercise of its discretion to limit the initial application of this requirement to these institutions as appropriate, because it is logical to minimize disruption and burden to the extent possible by commencing implementation with institutions already equipped to leverage CIP procedures.

There were no significant objections to limiting the scope of this requirement in this manner, and we are accordingly adopting this definition as proposed. We note generally that FinCEN received comments from institutions not subject to CIP (nor therefore to the proposal), urging us to engage in dialogue before determining whether to expand the beneficial ownership and CDD requirements to their industries. FinCEN agrees that thoughtful engagement with all stakeholders is an essential component of the rulemaking process, and will continue to engage in outreach to inform our policy decisions and any future rulemakings. As we noted in the proposal, comments and discussions with these institutions during the course of this rulemaking have led us to believe that extending CDD requirements in the future to these, and potentially other types of financial institutions, may ultimately promote a more consistent, reliable, and effective AML regulatory structure across the financial system.

A few commenters requested that FinCEN exclude smaller financial institutions from the scope of coverage, contending principally that such institutions generally presented a lower risk profile and that implementation of the beneficial ownership requirement would be unduly burdensome. We decline to categorically exclude smaller institutions from the definition of covered financial institution. As we have noted, both in the proposal and above, one of the animating purposes of this rulemaking is to promote clear and consistent expectations across and within financial sectors, in order to promote a more level playing field when it comes to AML/CFT compliance. Uniform application of the beneficial ownership requirement would prevent the “competitive disadvantage” (cited by one commenter seeking this exclusion) that would result if prospective customers were not required “to complete the same form at . . . competitor financial institutions.” And even though some smaller institutions might be lower risk, size alone should not be a determinative factor for a risk assessment, making it an inappropriate basis for a categorical exclusion. Indeed, a blanket size-based exclusion would provide a clear roadmap for illicit actors seeking an easy entry point into the financial system. Finally, FinCEN appreciates the concerns raised about the burden of implementation expressed by commenters and, as described at length above, has made numerous changes to the proposal to reduce the burden upon financial institutions. We reiterate that, as with CIP, financial institutions are expected to implement procedures for collecting beneficial ownership information “appropriate for [their] size and type of business.”

78

78

31 CFR 1020.220(a)(1); 31 CFR 1023.220(a)(1); 31 CFR 1024.220(a)(1); 31 CFR 1026.220(a)(1).

Section 1010.230(g) New account.

See discussion above under “Identification and Verification.”

Section 1010.230(h) Exemptions.

In the final rule, this paragraph exempts covered financial institutions from the beneficial ownership requirement with respect to opening accounts for legal entity customers for certain specific activities and within certain limitations for the reasons described below.

Private Label Retail Credit Accounts Established at the Point-of-Sale

One commenter requested that FinCEN exempt point-of-sale retail credit accounts provided to small to mid-size business customers, including commercial private label and co-branded credit cards and installment loans, from the scope of coverage of the beneficial ownership requirement. This commenter noted that such accounts presented a lower risk of money laundering due in large part to limitations on the use of those cards inherent in these customer relationships. For example, because private label credit cards can be used only to purchase goods or services at the specified retailer at which they are issued, they would not be an attractive vehicle to launder illicit proceeds. That these accounts can only be used for domestic transactions, and generally have lower credit limits, are additional factors that mitigate the risk of these accounts. FinCEN has learned that legal entities without an established and verifiable credit history that seek such accounts are generally required to provide a personal guarantee by a natural person whose identity and credit history are verified. We agree that these characteristics and limitations associated with private label credit card accounts that are used exclusively within issuing retailers' networks, significantly decrease these accounts' susceptibility to abuse by money launderers and terrorist financers. Thus, covered financial institutions are exempt from the beneficial ownership requirement with respect to private label credit card accounts to the limited extent that they are established at the point-of-sale to obtain credit products, including commercial private label credit cards, solely for the purchase of retail goods and/or services at the issuing retailer and have a credit limit of no more than $50,000.

In contrast, credit cards that are co-branded with major credit card associations do not possess the same limitations and characteristics that would protect them from abuse. For example, co-branded credit cards can be used at any outlet or ATM that accepts those associations' cards. FinCEN therefore believes that covered financial institutions should obtain and verify beneficial ownership information with respect to opening accounts for legal entities involving such co-branded cards.

Additional Exemptions

During the comment period to the RIA, several commenters sought to exempt certain limited purpose activities from the scope of the beneficial ownership requirement, principally on the grounds that such accounts had an extremely low risk profile for money laundering because of

inherent structural limitations to the accounts and the purposes for which such accounts are established.

Accounts Established for the Purchase and Financing of Postage

One such commenter was a limited purpose banking entity whose primary business is to facilitate the purchase and financing of postage. This commenter noted that all the accounts at its institution exist solely for small businesses, governments, and nonprofit organizations to prepay postage and earn interest (in the form of additional postage), or to finance postage through an unsecured revolving line of credit. Clients of this institution cannot use these accounts to purchase merchandise, deposit or withdraw cash, write checks, or transfer funds. FinCEN agrees that these types of accounts present a low risk of money laundering, both because of the purpose for which such accounts are established, as well as the characteristics of these accounts described above. Accordingly, covered financial institutions are exempt from the beneficial ownership requirement with respect to accounts solely used to finance the purchase of postage and for which payments are remitted directly by the financial institution to the provider of the postage products.

Commercial Accounts To Finance Insurance Premiums

Several commenters representing the commercial insurance premium finance industry submitted a joint letter outlining the expected impact of the beneficial ownership requirement on their industry, and the structural characteristics of these financial products that make them a low risk of money laundering. They noted that borrowers seeking funds to finance premiums for property and casualty insurance do not receive these proceeds directly; instead, the funds are remitted directly to an insurance company, either directly or through an insurance agent or broker. As with the limited purpose postage accounts described above, customers of premium finance companies cannot use these accounts to purchase merchandise, deposit or withdraw cash, write checks, or transfer funds. FinCEN agrees that these types of accounts present a low risk of money laundering, both because of the purpose for which such accounts are established, as well as the characteristics of these accounts that make them a poor vehicle for money laundering. For these reasons, covered financial institutions are exempt from the beneficial ownership requirement with respect to accounts solely used to finance insurance premiums and for which payments are remitted directly by the financial institution to the insurance provider or broker.

Accounts To Finance the Purchase or Lease of Equipment

One commenter representing a bank that primarily provides financial products for small business equipment leasing sought to exclude this activity from the beneficial ownership requirement with the same basic rationale put forth by the commenters representing the commercial insurance premium finance industry. Because FinCEN understands that these financial products have similar structural characteristics that limit their utility as vehicles for money laundering, covered financial institutions are exempt from the beneficial ownership requirement with respect to accounts solely used to finance the purchase or leasing of equipment and for which payments are remitted directly by the financial institution to the vendor or lessor of this equipment.

Section 1010.230(h)(2) Limitations on Exemptions.

These three exemptions are subject to further limitations to mitigate the remaining limited money laundering risks associated with them, as follows:

• The exemptions identified in paragraphs (h)(1)(ii) through (iv) do not apply to transaction accounts through which a legal entity customer can make payments to, or receive payments from, third parties.

• If there is the possibility of a cash refund on the account activity identified in paragraphs (h)(1)(ii) through (iv), then beneficial ownership of the legal entity customer must be identified and verified by the financial institution as required by this section, either at the time of initial remittance, or at the time such refund occurs.

The first limitation reflects the additional structural limitation described in our discussion of these account types that makes them a low risk of money laundering, and therefore a necessary characteristic to qualify for these exclusions. The second limitation serves to mitigate the principal money laundering vulnerability in some of these accounts—to wit, the possibility of a cash refund—by requiring the identification and verification of beneficial ownership information when the initial remittance is made or when a refund actually occurs. Based upon the submissions from commenters, as well as subsequent inquiry into these financial products, FinCEN understands that most of these exempted accounts would not be affected by such limitation. Furthermore, this requirement has been drafted to give covered financial institutions flexibility in implementing this provision. Although this limitation applies broadly to accounts where there is the possibility of a refund, as a practical matter, beneficial ownership information must only be collected when such a refund actually occurs. Thus, covered financial institutions that offer such products do not have to change their onboarding systems, and FinCEN believes that in most cases, they will not have to collect this information.

Section 1010.230(i) Recordkeeping.

In the NPRM, we proposed a recordkeeping requirement identical to the requirement for CIP, in order to leverage existing standards and processes to facilitate financial institutions' implementation of this requirement. Thus, under the proposal, a financial institution must have procedures for maintaining a record of all information obtained in connection with identifying and verifying beneficial owners, including retention of the Certification Form and a record of any other related identifying information reviewed or collected, for a period of five years after the date the account is closed. Furthermore, we proposed that a financial institution must also retain records for a period of five years after such record is made, including a description of every document relied on for verification, any non-documentary methods and results of measures undertaken for verification, as well as the resolution of any substant

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.