# Customer Due Diligence Requirements for Financial Institutions

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2016-10567

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** May 11, 2016
- **Citation:** 81 FR 29398

## Text

DEPARTMENT OF THE TREASURY
Financial Crimes Enforcement Network
31 CFR Parts 1010, 1020, 1023, 1024, and 1026
RIN 1506-AB25
Customer Due Diligence Requirements for Financial Institutions

AGENCY:

Financial Crimes Enforcement Network (FinCEN), Treasury.

ACTION:

Final rules.

SUMMARY:

FinCEN is issuing final rules under the Bank Secrecy Act to clarify and strengthen customer due diligence requirements for: Banks; brokers or dealers in securities; mutual funds; and futures commission merchants and introducing brokers in commodities. The rules contain explicit customer due diligence requirements and include a new requirement to identify and verify the identity of beneficial owners of legal entity customers, subject to certain exclusions and exemptions.

DATES:

The final rules are effective July 11, 2016.

Applicability Date:
Covered financial institutions must comply with these rules by May 11, 2018.

FOR FURTHER INFORMATION CONTACT:

FinCEN Resource Center at 1-800-767-2825. Email inquiries can be sent to
frc@fincen.gov
.

SUPPLEMENTARY INFORMATION:

I. Executive Summary

A. Purpose of This Regulatory Action

Covered financial institutions are not presently required to know the identity of the individuals who own or control their legal entity customers (also known as beneficial owners). This enables criminals, kleptocrats, and others looking to hide ill-gotten proceeds to access the financial system anonymously. The beneficial ownership requirement will address this weakness and provide information that will assist law enforcement in financial investigations, help prevent evasion of targeted financial sanctions, improve the ability of financial institutions to assess risk, facilitate tax compliance, and advance U.S. compliance with international standards and commitments.

FinCEN believes that there are four core elements of customer due diligence (CDD), and that they should be explicit requirements in the anti-money laundering (AML) program for all covered financial institutions, in order to ensure clarity and consistency across sectors: (1) Customer identification and verification, (2) beneficial ownership identification and verification, (3) understanding the nature and purpose of customer relationships to develop a customer risk profile, and (4) ongoing monitoring for reporting suspicious transactions and, on a risk-basis, maintaining and updating customer information. The first is already an AML program requirement and the second will be required by this final rule. The third and fourth elements are already implicitly required for covered financial institutions to comply with their suspicious activity reporting requirements. The AML program rules for all covered financial institutions are being amended by the final rule in order to include the third and fourth elements as explicit requirements.

FinCEN has the legal authority for this action in the Bank Secrecy Act (BSA), which authorizes FinCEN to impose AML program requirements on all financial institutions
1

and to require financial institutions to maintain procedures to ensure compliance with the BSA and its implementing regulations or to guard against money laundering.
2

1
31 U.S.C. 5318(h)(2).

2
31 U.S.C. 5318(a)(2).

B. Summary of the Major Provisions of the Rulemaking

1. Beneficial Ownership

Beginning on the Applicability Date, covered financial institutions
3

must identify and verify the identity of the beneficial owners of all legal entity customers (other than those that are excluded) at the time a new account is opened (other than accounts that are exempted). The financial institution may comply either by obtaining the required information on a standard certification form (Certification Form (Appendix A)) or by any other means that comply with the substantive requirements of this obligation. The financial institution may rely on the beneficial ownership information supplied by the customer, provided that it has no knowledge of facts that would reasonably call into question the reliability of the information. The identification and verification procedures for beneficial owners are very similar to those for individual customers under a financial institution's customer identification program (CIP),
4

except that for beneficial owners, the institution may rely on copies of identity documents. Financial institutions are required to maintain records of the beneficial ownership information they obtain, and may rely on another financial institution for the performance of these requirements, in each case to the same extent as under their CIP rule.

3
The term “covered financial institution” refers to: (i) Banks; (ii) brokers or dealers in securities; (iii) mutual funds; and (iv) futures commission merchants and introducing brokers in commodities.

4
31 CFR 1020.220, 1023.220, 1024.220, 1026.220.

The terms used for the purposes of this final rule, including account, beneficial ownership, legal entity customer, excluded legal entities, new account, and covered financial institution, are set forth in the final rule.

Financial institutions should use beneficial ownership information as they use other information they gather regarding customers (
e.g.,
through compliance with CIP requirements), including for compliance with the Office of Foreign Assets Control (OFAC) regulations, and the currency transaction reporting (CTR) aggregation requirements.

2. Anti-Money Laundering Program Rule Amendments

The AML program requirement for each category of covered financial institutions is being amended to explicitly include risk-based procedures for conducting ongoing customer due diligence, to include understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile.

A customer risk profile refers to the information gathered about a customer at account opening used to develop a baseline against which customer activity is assessed for suspicious activity reporting. This may include self-evident information such as the type of customer or type of account, service, or product. The profile may, but need not, include a system of risk ratings or categories of customers.

In addition, customer due diligence also includes conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information. For these purposes, customer information shall include information regarding the beneficial owners of legal entity customers (as defined in § 1010.230). The first clause of paragraph (ii) sets forth the requirement that financial institutions conduct monitoring to identify and report suspicious transactions. Because this includes transactions that are not of the sort the customer would be normally expected to engage, the customer risk profile information is used (among other sources) to identify such transactions. This information may be integrated into the financial institution's automated monitoring system, and may be used

after a potentially suspicious transaction has been identified, as one means of determining whether or not the identified activity is suspicious.

When a financial institution detects information (including a change in beneficial ownership information) about the customer in the course of its normal monitoring that is relevant to assessing or reevaluating the risk posed by the customer, it must update the customer information, including beneficial ownership information. Such information could include,
e.g.,
a significant and unexplained change in the customer's activity, such as executing cross-border wire transfers for no apparent reason or a significant change in the volume of activity without explanation. It could also include information indicating a possible change in the customer's beneficial ownership, because such information could also be relevant to assessing the risk posed by the customer. This applies to all legal entity customers, including those existing on the Applicability Date.

This provision does not impose a categorical requirement that financial institutions must update customer information, including beneficial ownership information, on a continuous or periodic basis. Rather, the updating requirement is event-driven, and occurs as a result of normal monitoring.

C. Costs and Benefits

This is a significant regulatory action pursuant to Executive Order 12866 (“E.O. 12866”) because it is likely to result in a final rule that may have an annual effect on the economy of $100 million or more. Accordingly, FinCEN published for comment on December 24, 2015 a preliminary Regulatory Impact Assessment (RIA) for the proposed rule (80 FR 80308), which provided a quantitative estimate of the costs to the private sector for which adequate data are available and a qualitative discussion of both the costs and benefits for which data are not available. As a result of the comments submitted, FinCEN revised the preliminary RIA to include additional cost estimates
5

and is publishing with this final rule a final RIA. The annualized quantified costs (under low cost scenarios) are estimated to be $153 million (at a seven percent discount rate) and $148 million (at a three percent discount rate). The annualized quantified costs (under high cost scenarios) are estimated to be $287 million (at a seven percent discount rate) and $282 million (at a three percent discount rate). Because the benefits of the rule cannot be quantified, FinCEN has utilized a breakeven analysis to determine how large the final rule's benefits would have to be in order to justify its estimated costs. The RIA uses Treasury's estimate of $300 billion in illicit proceeds generated annually in the United States due to financial crimes, to determine the minimum level of effectiveness that the final rule would need to achieve for the benefits to equal the costs. Based on this analysis, using the upper bound of our cost assessment, FinCEN has concluded that the final rule would only have to reduce illicit activity by 0.6 percent to yield a positive net benefit. The Treasury Department believes that the final rule will reduce illicit activity by a greater amount than this.

5
In the final RIA, we estimate that 10-year quantifiable costs range from $1.15 billion to $2.15 billion in present value using a seven percent discount rate, and from $1.3 billion to $2.5 billion using a three percent discount rate.

II. Background

A. The Bank Secrecy Act

FinCEN exercises regulatory functions primarily under the Currency and Foreign Transactions Reporting Act of 1970, as amended by the USA PATRIOT Act of 2001 (PATRIOT Act) and other legislation, which legislative framework is commonly referred to as the “Bank Secrecy Act” (BSA).
6

The BSA authorizes the Secretary of the Treasury (Secretary) to require financial institutions to keep records and file reports that “have a high degree of usefulness in criminal, tax, or regulatory investigations or proceedings, or in the conduct of intelligence or counterintelligence activities, including analysis, to protect against international terrorism.”
7

6
The BSA is codified at 12 U.S.C. 1829b, 12 U.S.C. 1951-1959, 18 U.S.C. 1956, 1957, and 1960, and 31 U.S.C. 5311-5314 and 5316-5332 and notes thereto, with implementing regulations at 31 CFR chapter X.
See
31 CFR 1010.100(e).

7
31 U.S.C. 5311.

The Secretary has delegated to the Director of FinCEN the authority to implement, administer, and enforce compliance with the BSA and associated regulations.
8

FinCEN is authorized to impose anti-money laundering (AML) program requirements on financial institutions,
9

as well as to require financial institutions to maintain procedures to ensure compliance with the BSA and the regulations promulgated thereunder or to guard against money laundering.
10

8
Treasury Order 180-01 (July 1, 2014).

9
31 U.S.C. 5318(h)(2).

10
31 U.S.C. 5318(a)(2).

B. The Importance of Customer Due Diligence

FinCEN, after consultation with the staffs of the Federal functional regulators and the Department of Justice, has determined that more explicit rules for covered financial institutions with respect to customer due diligence (CDD) are necessary to clarify and strengthen CDD within the BSA regime, which in turn will enhance financial transparency and help to safeguard the financial system against illicit use. Requiring financial institutions to perform effective CDD so that they understand who their customers are and what type of transactions they conduct is a critical aspect of combating all forms of illicit financial activity, from terrorist financing and sanctions evasion to more traditional financial crimes, including money laundering, fraud, and tax evasion. For FinCEN, the key elements of CDD include: (i) Identifying and verifying the identity of customers; (ii) identifying and verifying the identity of beneficial owners of legal entity customers (
i.e.,
the natural persons who own or control legal entities); (iii) understanding the nature and purpose of customer relationships; and (iv) conducting ongoing monitoring. Collectively, these elements comprise the minimum standard of CDD, which FinCEN believes is fundamental to an effective AML program.

Clarifying and strengthening CDD requirements for U.S. financial institutions, including with respect to the identification of beneficial owners, advance the purposes of the BSA by:

(1) Enhancing the availability to law enforcement, as well as to the Federal functional regulators and self-regulatory organizations (SROs), of beneficial ownership information about legal entity customers obtained by U.S. financial institutions, which assists law enforcement financial investigations and a variety of regulatory examinations and investigations;

(2) Increasing the ability of financial institutions, law enforcement, and the intelligence community to identify the assets and accounts of terrorist organizations, corrupt actors, money launderers, drug kingpins, proliferators of weapons of mass destruction, and other national security threats, which strengthens compliance with sanctions programs designed to undercut financing and support for such persons;

(3) Helping financial institutions assess and mitigate risk, and comply with all existing legal requirements, including the BSA and related authorities;

(4) Facilitating reporting and investigations in support of tax compliance, and advancing commitments made to foreign counterparts in connection with the provisions commonly known as the Foreign Account Tax Compliance Act (FATCA);
11

11
Officially the Hiring Incentives to Restore Employment Act of 2010, Public Law 111-147, 124 Stat. 71, Section 501(a).

(5) Promoting consistency in implementing and enforcing CDD regulatory expectations across and within financial sectors; and

(6) Advancing Treasury's broad strategy to enhance financial transparency of legal entities.

1. Assisting Financial Investigations by Law Enforcement

The abuse of legal entities to disguise involvement in illicit financial activity is a longstanding vulnerability that facilitates crime, threatens national security, and jeopardizes the integrity of the financial system. Criminals have exploited the anonymity that use of legal entities can provide to engage in money laundering, corruption, fraud, terrorist financing, and sanctions evasion, among other financial crimes.

There are numerous examples that Treasury has tracked as a part of its National Money Laundering Risk Assessment and Terrorist Financing Risk Assessment.
12

For example, in 2013, prosecutors in New York indicted 34 alleged members of Russian-American organized crime groups, charging that they participated in a range of racketeering activities. One of the constituent racketeering enterprises was alleged to have moved millions of dollars in unlawful gambling proceeds through a network of shell companies
13

in Cyprus and the United States.
14

In 2011, Federal prosecutors indicted 13 individuals for their alleged unlawful takeover and looting of a publicly-held mortgage company. Some of these defendants allegedly used the assets of the company to acquire shell companies, while other defendants are alleged to have further obscured the ownership of these companies through complex legal structures involving other shell companies.
15

In 2006, prosecutors indicted a number of individuals for their roles in supporting a long-running nationwide drug trafficking organization. The proceeds generated by this trafficking organization were laundered through numerous shell and shelf
16

corporations created to provide apparently legitimate fronts for this income. These legal entities were further used to open accounts at financial institutions and hold title to property.
17

Other examples cited by law enforcement officials include major drug trafficking organizations using shell companies to launder drug proceeds.
18

In 2011, a World Bank report highlighted how corrupt actors consistently abuse legal entities to conceal the proceeds of corruption, which the report estimates to aggregate at least $40 billion per year in illicit activity.
19

Other criminals also make aggressive use of front companies,
20

which may also conduct legitimate business activity, to disguise the deposit, withdrawal, or transfer of illicit proceeds that are intermingled with legitimate funds.

12
U.S. Dep't of the Treasury,
National Money Laundering Risk Assessment
(2015),
available at http://www.treasury.gov/resource-center/terrorist-illicit-finance/Documents/National%20Money%20Laundering%20Risk%20Assessment%20%E2%80%93%2006-12-2015.pdf
; U.S. Dep't of the Treasury,
National Terrorist Financing Risk Assessment
(2015),
available at http://www.treasury.gov/resource-center/terrorist-illicit-finance/Documents/National%20Terrorist%20Financing%20Risk%20Assessment%20%E2%80%93%2006-12-2015.pdf
.

13
A shell company is a legal entity that has been registered with a state but has no physical operations or assets. Shell companies can serve legitimate purposes, such as holding financial assets or other property, but can also be used to conceal the source, ownership, or control of illegal proceeds. U.S. Dep't of the Treasury,
National Money Laundering Risk Assessment
at 43.

14

Id.
at 20.

15

Id.

16
A shelf corporation is a legal entity that has been registered with a state but not yet used for any purpose; it has instead been kept on the “shelf” for a buyer who does not want to go through the process of creating a new legal entity.
Id.

17

Id.
at 44.

18

Combating Transnational Organized Crime: International Money Laundering as a Threat to Our Financial System, Before the Subcommittee on Crime, Terrorism, and Homeland Security, H. Comm. on the Judiciary, 112th Cong.
(February 8, 2012) (statement of Jennifer Shasky Calvery as Chief, Asset Forfeiture and Money Laundering Section, Criminal Division of the U.S. Department of Justice).

19

The Puppet Masters: How the Corrupt Use Legal Structures to Hide Stolen Assets and What to Do About It,
The International Bank for Reconstruction and Development/The World Bank (2011).

20
A front company is a legitimate business that combines illicit proceeds with earnings from its legitimate operations, thereby obscuring the source of the illegitimate funds.
See
U.S. Dep't of the Treasury,
National Money Laundering Risk Assessment
at 43.

Strong CDD practices that include identifying and verifying the identity of the natural persons who own or control a legal entity—
i.e.,
the beneficial owners—help defend against these abuses in a variety of ways. The collection of beneficial ownership information by financial institutions can provide law enforcement with key details about suspected criminals who use legal structures to conceal their illicit activity and assets. Moreover, requiring legal entities seeking access to financial institutions to disclose identifying information, such as the name, date of birth, and Social Security number of natural persons who own or control them, will make such entities more transparent, and thus less attractive to criminals and those who assist them. Even if an illicit actor tries to thwart such transparency by providing false beneficial ownership information to a financial institution, law enforcement has advised FinCEN that such information can still be useful in demonstrating unlawful intent and in generating leads to identify additional evidence or co-conspirators.

2. Advancing Counterterrorism and Broader National Security Interests

As noted, criminals often abuse legal entities to evade sanctions or other targeted financial measures designed to combat terrorism and other national security threats. The success of such targeted financial measures depends, in part, on the ability of financial institutions, law enforcement, and intelligence agencies to identify a target's assets and accounts. These measures are thwarted when legal entities are abused to obfuscate ownership interests. Effective CDD helps prevent such abuses by requiring the collection of critical information, including beneficial ownership information, which may be helpful in implementing sanctions or other similar measures.

3. Improving a Financial Institution's Ability To Assess and Mitigate Risk

Explicit CDD requirements would also enable financial institutions to assess and mitigate risk more effectively in connection with existing legal requirements. It is through CDD that financial institutions are able to understand the risks associated with their customers, to monitor accounts more effectively, and to evaluate activity to determine whether it is unusual or suspicious, as required under suspicious activity reporting obligations.
21

Further, in the event that a financial institution files a suspicious activity report (SAR), information gathered through CDD in many instances can enhance SARs, which in turn can help law enforcement, intelligence, national security, and tax authorities investigate and pursue illicit financing activity.

21

See, e.g.,
31 CFR 1020.320.

4. Facilitating Tax Compliance

Customer due diligence also facilitates tax reporting, investigations and compliance. For example, information held by banks and other financial institutions about the beneficial ownership of companies can be used to assist law enforcement in identifying the true owners of assets and their true tax liabilities. The United States has long been a global leader in establishing and promoting the adoption of international standards for transparency and information exchange to combat cross-border tax evasion and other financial crimes. Strengthening CDD is an important part of that effort, and it will dovetail with other efforts to create greater transparency, some of which are longstanding, such as the United States' commitments to exchanging information with other jurisdictions under its tax treaties and tax information exchange agreements, and others of which are new, such as the information reporting requirements under FATCA.
22

FATCA requires foreign financial institutions to identify U.S. account holders, including legal entities with substantial U.S. ownership, and to report certain information about those accounts to the Internal Revenue Service (IRS).
23

The United States has negotiated with foreign governments to enter into intergovernmental agreements that facilitate the effective implementation of these requirements. These agreements allow foreign financial institutions to rely on existing AML practices in a number of circumstances, including, in the case of the intergovernmental agreements, for purposes of determining whether certain legal entity customers are controlled by U.S. persons. Pursuant to many of these agreements, the United States has committed to pursuing equivalent levels of reciprocal automatic information exchange with respect to collecting and reporting to the authorities of the FATCA partner jurisdiction information on the U.S. financial accounts of residents of that jurisdiction. A general requirement for U.S. financial institutions to obtain beneficial ownership information for AML purposes advances this commitment, and puts the United States in a better position to work with foreign governments to combat offshore tax evasion and other financial crimes.

22
Hiring Incentives to Restore Employment Act of 2010, Public Law 111-147, Section 501(a).

23

See generally
Internal Revenue Service, “Regulations Relating to Information Reporting by Foreign Financial Institutions and Withholding on Certain Payments to Foreign Financial Institutions and Other Foreign Entities,” RIN 1545-BK68 (January 28, 2013),
available at http://www.irs.gov/PUP/businesses/corporations/TD9610.pdf
. For further updates on FATCA regulations, see
http://www.irs.gov/Businesses/Corporations/Foreign-Account-Tax-Compliance-Act-(FATCA)
.

5. Promoting Clear and Consistent Expectations and Practices

Customer due diligence is universally recognized as fundamental to mitigating illicit finance risk, even though not all financial institutions use the specific term “customer due diligence” to describe their practices. While Treasury understands from its outreach to the private sector that financial institutions broadly accept this principle and implement CDD practices in some form under a risk-based approach, financial institutions have expressed disparate views about what precise activities CDD entails. At public hearings held after the closing of the comment period to the Advance Notice of Proposed Rulemaking (ANPRM),
24

discussed below, financial institutions described widely divergent CDD practices, especially with respect to identifying and verifying the identities of beneficial owners outside of limited circumstances prescribed by statute.
25

For example, during one of these hearings, FinCEN learned that some financial institutions already obtain beneficial ownership information in all circumstances, while others obtain this information only for certain categories of customers or following a triggering event. Institutions also identified a range of practices, from varied percentage of ownership thresholds, to the extent of information collected (
e.g.,
only the name of the beneficial owner(s) versus collection of additional information, such as addresses, etc.).
26

24
Financial Crimes Enforcement Network (FinCEN), “Customer Due Diligence Requirements for Financial Institutions,” 77 FR 13046 (March 5, 2012).

25

See, e.g.,
FinCEN,
Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence
(October 5, 2012),
available at http://www.fincen.gov/whatsnew/html/20121130NYC.html
. (“Participants expressed varied views as to whether, how and in what circumstances, financial institutions obtain beneficial ownership information.”).

26

Id.

FinCEN believes that this disparity adversely affects efforts to mitigate risk and can promote an uneven playing field across and within financial sectors. Financial institutions have noted that unclear CDD expectations can result in inconsistent regulatory examinations, potentially causing them to devote their limited resources to managing derivative legal risk rather than fundamental illicit finance risk. Private sector representatives have also noted that inconsistent expectations can effectively discourage best practices, because financial institutions with robust compliance procedures may believe that they risk losing customers to other institutions with more lax procedures. Greater consistency across the financial system addresses this competitive inequality.

Providing a consolidated and clear CDD framework will help address these issues. As part of this framework, expressly stating CDD requirements in these regulations with respect to (i) understanding the nature and purpose of customer relationships and (ii) conducting ongoing monitoring will facilitate more consistent implementation, examination, supervision and enforcement of these expectations. With respect to the beneficial ownership requirement, requiring all covered financial institutions to identify and verify the identities of beneficial owners in the same manner and pursuant to the same definition also promotes consistency across industry. Requiring covered financial institutions to operate under one clear CDD framework will promote a more level playing field across and within financial sectors.

6. Advancing Treasury's Broad Strategy To Enhance Financial Transparency of Legal Entities

Finally, clarifying and strengthening CDD is an important component of Treasury's broader three-part strategy to enhance financial transparency of legal entities. Other key elements of this strategy include: (i) Increasing the transparency of U.S. legal entities through the collection of beneficial ownership information at the time of the legal entity's formation and (ii) facilitating global implementation of international standards regarding CDD and beneficial ownership of legal entities.

This final rule thus complements the Administration's ongoing work with Congress to facilitate adoption of legislation that would require the collection of beneficial ownership information at the time that legal entities are formed in the United States. This final rule also advances Treasury's ongoing work with the Group of Twenty Finance Ministers and Central Bank Governors (G-20), the Financial Action Task Force (FATF), the Global Forum on Transparency and Exchange of Information for Tax Purposes, and other global partners, who have emphasized the importance of improving CDD practices and requiring the disclosure of beneficial ownership information at the time of company formation or transfer. Moreover, this proposal furthers the

United States' Group of Eight (G-8) commitment as set forth in the United States G-8 Action Plan for Transparency of Company Ownership and Control, published on June 18, 2013.
27

This Action Plan is in line with principles agreed to by the G-8, which the Administration noted “are crucial to preventing the misuse of companies by illicit actors.”
28

It is also found in the U.S. Action Plan to Implement the G-20 High Level Principles on Beneficial Ownership, published on October 16, 2015.
29

While these elements are all proceeding independently, together they make up a comprehensive approach to promoting financial transparency of legal entities.

27
United States G-8 Action Plan for Transparency of Company Ownership and Control,
available at http://www.whitehouse.gov/the-press-office/2013/06/18/united-states-g-8-action-plan-transparency-company-ownership-and-control.

28
White House Fact Sheet: U.S. National Action Plan on Preventing the Misuse of Companies and Legal Arrangements (June 18, 2013),
available at http://www.whitehouse.gov/the-press-office/2013/06/18/fact-sheet-us-national-action-plan-preventing-misuse-companies-and-legal.

29
U.S. Action Plan to Implement the G-20 High Level Principles on Beneficial Ownership,
available at https://www.whitehouse.gov/blog/2015/10/16/us-action-plan-implement-g-20-high-level-principles-beneficial-ownership.

C. The Advance Notice and Notice of Proposed Rulemaking

FinCEN initiated this rulemaking process in March 2012 by issuing an ANPRM that described FinCEN's potential proposal for codifying explicit CDD requirements, including customer identification and verification, understanding the nature and purpose of accounts, ongoing monitoring, and obtaining and verifying beneficial ownership information.
30

FinCEN received 90 comments, mostly from banks, credit unions, securities and futures firms, mutual funds, casinos, and money services businesses. In general, these commenters raised concerns about the potential costs and practical challenges associated with a categorical requirement to obtain beneficial ownership information. They also expressed concerns with respect to FinCEN's articulation of the other components of CDD (understanding the nature and purpose of customer relationships and ongoing monitoring), asserting that, contrary to FinCEN's stated intention, these would in part be new requirements rather than an explicit codification of pre-existing obligations. To better understand and address these concerns, Treasury held five public hearings from July to December 2012 in Washington, DC, Chicago, New York, Los Angeles and Miami.
31

At these meetings, participants expressed their views on the ANPRM and offered specific recommendations about how best to balance the benefits with the practical burdens associated with obtaining beneficial ownership information. These discussions were critical in the development of the Notice of Proposed Rulemaking (NPRM) issued on August 4, 2014 (79 FR 45151).

30
Two years prior to that, in March 2010, FinCEN, along with several other agencies, published
Joint Guidance on Obtaining and Retaining Beneficial Ownership Information,
FIN-2010-G001 (March 5, 2010). Industry reaction to this guidance is one reason that FinCEN sought to further clarify CDD requirements by making them explicit within FinCEN's regulations.

31

Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence
(July 31, 2012),
available at http://www.regulations.gov/#!documentDetail;D=FINCEN-2012-0001-0094; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence
(September 28, 2012),
available at http://www.fincen.gov/whatsnew/html/20121130CHI.html; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence
(October 5, 2012),
available at http://www.fincen.gov/whatsnew/html/20121130NYC.html; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence
(October 29, 2012),
available at http://www.fincen.gov/whatsnew/html/20121130LA.html; Summary of Public Hearing: Advance Notice of Proposed Rulemaking on Customer Due Diligence
(December 3, 2012),
available at http://www.fincen.gov/whatsnew/pdf/SummaryofHearing-MiamiDec3.pdf
.

The NPRM proposed a new requirement for covered financial institutions to identify the natural person or persons who are beneficial owners of legal entity customers opening new accounts, subject to certain exemptions, and to verify the identity of the natural person(s) identified. As proposed, a covered financial institution would satisfy this requirement at the time a new account is opened by obtaining information on a standard certification form directly from the individual opening the new account on behalf of the legal entity customer, and by verifying the identity of the natural person(s) identified consistent with existing customer identification program (CIP) procedures for verifying the identity of customers who are natural persons. The NPRM thus sought to facilitate this proposed new requirement by leveraging the CIP procedures that have been required of all covered financial institutions since 2003. The NPRM also proposed that the AML program requirements for all types of covered financial institutions be amended to include appropriate risk-based procedures for conducting ongoing due diligence, to include: (i) Understanding the nature and purpose of customer relationships in order to develop a customer risk profile; and (ii) conducting ongoing monitoring to maintain and update customer information and to identify and report suspicious transactions. FinCEN viewed this part of the rulemaking as not imposing new requirements, but rather making explicit the activities that covered financial institutions are already expected to undertake, based on guidance and supervisory expectations, in order to satisfy their existing obligations to detect and report suspicious activities.

D. Summary of Comments

In response to the NPRM, FinCEN received 141 comments from financial institutions, trade associations, Federal and State agencies, non-governmental organizations, members of Congress, and other individuals. The great majority of the private sector commenters, which were primarily banks, credit unions, and their trade associations, asserted that the proposed beneficial ownership requirement would be very burdensome to implement and require more than the proposed 12 months, would be far more expensive than estimated by FinCEN, and would not achieve the proposal's expressed goals.

The commenters addressed many aspects of the proposed beneficial ownership requirement, including the use of the proposed certification form; the extent to which a covered financial institution may rely on the information provided by the customer; the meaning of verification and the extent to which it would be required; the application of the requirement to existing customers; the extent to which the information would need to be updated; and the definitions of beneficial ownership and legal entity customer and the proposed exclusions from those definitions.

Commenters raised a number of questions regarding the proposed certification form, including whether beneficial owner information must be obtained through the certification form or could be obtained by other means; whether the certification form should be an official government form; and who is authorized to sign the certification form on behalf of the customer. Many urged FinCEN to treat the receipt of the certification form as a “safe harbor,” similar to the treatment of the certification used for compliance with the foreign shell bank regulation.
32

Commenters submitted several other comments and suggestions regarding the information to be included in the certification form.

32
31 CFR 1010.630(b).

Many commenters sought clarification regarding the verification requirement

and the extent to which a financial institution may rely on the information submitted by its customer. Financial institutions also pointed out that there would be difficulties with adopting “identical” procedures to those used for verifying the identity of individual customers as done for CIP. Moreover, many commenters noted the practical difficulties resulting from the fact that there is no authoritative source for beneficial ownership information of legal entities, as there is no requirement for U.S. States to collect this information at the time a company is formed. Commenters also sought guidance regarding how they should utilize the beneficial ownership information once collected and how its availability would impact compliance with other obligations.

While many private sector commenters noted that the proposed definition of beneficial owner was an improvement over the definition discussed in the ANPRM, some sought greater clarity about the meaning of “indirect” ownership and guidance regarding how the percentage of ownership held indirectly should be measured in specific situations, as well as clarification of the meaning of “equity interest.” They also suggested eliminating any reference to using a 10 percent threshold on a risk basis, so as to reduce the likelihood of examiners requiring a threshold lower than the 25 percent specified in the proposed rule. On the other hand, non-governmental organizations and many individuals asserted that the proposed 25 percent ownership threshold is too high and that it should be lowered to 10 percent (or eliminated entirely) in the final rule.

A number of commenters urged clarification of the proposed definition of “legal entity customer,” and many urged expansion of the proposed exclusions from the definition to include, for example, accounts opened to participate in employee benefit plans subject to the Employee Retirement Income Security Act of 1974 (ERISA) and accounts for foreign publicly traded companies, regulated financial institutions, and governmental entities. Many commenters also noted difficulties in applying the proposed exclusion for nonprofits and urged FinCEN to simplify it. Commenters also sought clarification regarding whether beneficial ownership would need to be obtained each time a legal entity customer opens a new account after the rule's compliance deadline, and to what extent the information would need to be updated. Some commenters also sought to exempt from the beneficial ownership requirement certain categories of financial products that they contended presented a low risk of money laundering.

Many comments also addressed the proposed amendments to the AML program rules, including urging FinCEN to clarify the proposed requirement to understand the nature and purpose of the customer relationship and the meaning of “customer risk profile” and of the proposed requirement to conduct ongoing monitoring to update customer information, separate from monitoring to detect and report suspicious activity. Some commenters representing the securities and futures industries asserted that, contrary to assumptions in the NPRM, these are not in fact existing requirements in those industries, and that such requirements would be burdensome and of little utility. Some commenters also questioned statements in the preamble that the proposed requirements would not reduce or limit the due diligence expectations of the Federal functional regulators or their regulatory discretion, asserting that such an approach would undermine the clarity and consistency that FinCEN is seeking to provide by the proposed rules. Finally, a great majority of the comments stated that the proposed 12-month implementation period following issuance of a final rule would not be adequate to implement the necessary modifications to their data systems, customer on-boarding procedures, employee training, and other requirements, and sought a period of at least 18-24 months.

Based on the comments addressing the potential cost of implementing the requirement, FinCEN conducted outreach to a number of the financial institution commenters to obtain additional information regarding the anticipated costs of implementing the proposed requirements. As a result of the limited information received from these discussions, Treasury prepared a preliminary Regulatory Impact Assessment (RIA) that was made available for comment on December 24, 2015 (80 FR 80308). FinCEN received 38 comments on this preliminary assessment; a summary of the comments we received and the final RIA is included in the Regulatory Analysis section of this preamble.

All of the substantive comments received on the NPRM, FinCEN's response, and resulting modifications to the final rule are discussed in detail in the following Section-by-Section Analysis. However, we first address certain general comments.

E. General Comments

Regulatory deference.
Commenters raised a number of general comments regarding this rulemaking. Several commenters took issue with the following statement in the NPRM (which we reiterate here as modified for this final rule).
33

33
The original statement can be found at 79 FR 45152 (Aug. 4, 2014).

Nothing in this final rule is intended to lower, reduce, or limit the due diligence expectations of the Federal functional regulators or in any way limit their existing regulatory discretion. To clarify this point, the final rule incorporates the CDD elements on nature and purpose and ongoing monitoring into FinCEN's existing AML program requirements, which generally provide that an AML program is adequate if, among other things, the program complies with the regulation of its Federal functional regulator (or, where applicable, self-regulatory organization (SRO)) governing such programs.
34

In addition, the Treasury Department intends for the requirements contained in the customer due diligence and beneficial ownership final rules to be consistent with, and not to supersede, any regulations, guidance or authority of any Federal banking agency, the Securities and Exchange Commission (SEC), the Commodity Futures Trading Commission (CFTC), or of any SRO relating to customer identification, including with respect to the verification of the identities of legal entity customers.

34

See, e.g.,
31 CFR 1020.210, which currently provides that a financial institution regulated by a Federal functional regulator that is not subject to the regulations of a self-regulatory organization shall be deemed to satisfy the requirements of 31 U.S.C. 5318(h)(1) if it implements and maintains an anti-money laundering program that complies with
the regulation of its Federal functional regulator governing such programs.
(emphasis added).

These commenters contended, among other things, that these statements were unduly deferential to the Federal functional regulators, and would serve to undermine rather than promote clear and consistent CDD standards across financial sectors. They accordingly urged FinCEN to strike this language from the final rulemaking.

FinCEN appreciates the concerns about uneven and inconsistent application of CDD standards that underlie these comments, but nevertheless believes that these statements are an important articulation of FinCEN's understanding of what it is—and is not—accomplishing by this rulemaking. At their core, these statements in the NPRM and this final rule preamble articulate the nature of the relationship of FinCEN's rulemaking authority with that of the Federal functional regulators
35

—that is, as with

all BSA rulemakings, FinCEN determines the appropriate minimum regulatory standards that should apply across an industry. From that baseline, the Federal functional regulators have authority to establish AML program requirements in addition to those established by FinCEN that they determine are necessary and appropriate to address risk or vulnerabilities specific to the financial institutions they regulate. This is particularly true within the context of separate but related concerns that exist for these institutions beyond the strict scope of AML, such as in the area of safety and soundness. These statements simply reflect this basic reality of the existing regulatory framework. Furthermore, as we have maintained throughout this rulemaking process, one of our overarching goals was to clarify and harmonize expectations while at the same time minimizing disruption to the greatest extent possible. Accordingly, we believe that it is critical to make clear—especially with respect to the changes to the AML program rules—that these standards simply articulate current practices pursuant to existing standards and expectations, in order to facilitate implementation and minimize the burden on financial institutions. We believe that leveraging the experience accrued from interpretation of and compliance with prior regulations and guidance that have already been issued in this space will be a net benefit to financial institutions. As FinCEN explained in the proposal, these requirements represent a floor, not a ceiling, and, consistent with the risk-based approach, financial institutions may do more in circumstances of heightened risk, as well as to mitigate risks generally.

35
Where appropriate, working closely with Federal functional regulators may involve

consulting with the applicable SROs in the securities and futures/commodities industries.

Compliance Deadline.
Most commenters strongly opposed FinCEN's proposal for a compliance deadline of one year from the date the final rule is issued, identifying a wide range of changes to systems and processes that would be required in order to implement the rule. Many of these commenters requested that FinCEN provide financial institutions two years to implement the final rule. Based on the well-founded, detailed explanations put forth by these commenters of the difficulties that would arise from a one-year implementation period, FinCEN is extending the period for implementation to two years from the date this final rule is issued (the Applicability Date).

III. Section-by-Section Analysis

Section 1010.230 Beneficial Ownership Requirements for Legal Entity Customers

Section 1010.230(a) In general.
As proposed, this paragraph delineated in broad terms the scope of the beneficial ownership obligation—
i.e.,
that covered financial institutions are required to establish and maintain written procedures reasonably designed to identify and verify the identities of beneficial owners of legal entity customers. There were no significant objections to this general formulation, and we are adopting it as proposed, with the addition that the procedures adopted will be included in the institution's AML program.

Several commenters questioned the efficacy of having financial institutions collect beneficial ownership information, contending that State government offices responsible for the formation and registration of legal entities and/or the IRS would be better suited to collect this information due to their roles in the company formation process. Although FinCEN supports the collection of beneficial ownership information in these other circumstances as well, it does not believe that such collection would replace the independent obligation of financial institutions to collect this information. As described above, we view this rulemaking as but one part of Treasury's comprehensive strategy to enhance financial transparency in the U.S. financial system and worldwide, and we believe the beneficial ownership requirement for financial institutions would be necessary even if these other measures were already in place. One of the principal rationales for this new requirement is that financial institutions should know who their customers are to help them more effectively mitigate risks. This requirement is therefore separate from a policy objective of requiring States to obtain beneficial ownership information from the legal entities they create at the time of formation and upon specified circumstances thereafter (although none currently have such requirements). Presently, corporate laws and regulations differ from State to State, and from FinCEN's regulations, but generally do not require information regarding beneficial ownership. Thus, the information that will be provided under FinCEN's regulations will significantly augment information presently available to law enforcement from State authorities, thereby improving the overall investigative, regulatory, and prosecutorial processes.

In the NPRM, FinCEN proposed that the beneficial ownership requirement would apply only with respect to legal entity customers that open new accounts going forward from the date of implementation, noting that many commenters to the ANPRM viewed a retroactive requirement to obtain beneficial ownership information for all existing accounts as extremely burdensome. We received comments reflecting a wide range of views on this subject. The vast majority of commenters who addressed this issue reiterated this objection to retroactive application of the beneficial ownership obligation. A few commenters, however, urged FinCEN to require covered financial institutions to collect beneficial ownership information on existing accounts on a categorical basis, while some others thought that financial institutions should collect this information retroactively for all higher risk customers.

We decline to impose a categorical, retroactive requirement. Based on our understanding of the significant changes to processes and systems that will be required to implement this requirement simply on a prospective basis, we believe that retroactive application would be unduly burdensome. As we noted in the proposal, the absence of a categorical mandate to apply the requirement retroactively would not preclude financial institutions from deciding that collecting beneficial ownership information on some customers on a risk basis during the course of monitoring may be appropriate for their institution. In our assessment, we have concluded that financial institutions should obtain beneficial ownership information from customers existing on the Applicability Date when, in the course of their normal monitoring, the financial institution detects information relevant to assessing or reevaluating the risk of such customer (as more fully described in the sections below addressing the amended AML program requirements).

Section 1010.230(b) Identification and Verification.
In the NPRM, FinCEN proposed that covered financial institutions be required to develop customer due diligence procedures that enabled institutions to (1) identify the beneficial owner(s) of legal entity customers by collecting a mandatory certification form provided by the individual opening the account on behalf of the legal entity customer; and (2) verify the identity of the identified beneficial owner(s) according to risk-based procedures that are, at a minimum, identical to the institutions' CIP procedures required for verifying

the identity of customers that are individuals.

Section 1010.230(b)(1).
The NPRM proposed to require the use of a standard certification form (Certification Form) in order to, among other purposes, promote consistent practices and regulatory expectations, reduce compliance burden, and provide a uniform customer experience across much of the U.S. financial system. To facilitate institutions' abilities to rely upon the Certification Form, the proposed Certification Form included a section that required the individual opening the account on behalf of a legal entity customer to certify that the information provided on the form is true and accurate to the best of his or her knowledge. Commenters raised a number of issues regarding this proposed requirement. Some commenters asked whether the Certification Form must be used to obtain the information, whether the Certification Form should be an official government form, and what individuals representing the customer would be authorized to provide the Certification Form. Several commenters urged a variety of changes to the fields on the Certification Form in order to conform it more closely to current CIP requirements, to otherwise facilitate use of the form, and to promote other regulatory goals. Some commenters also urged FinCEN to provide a safe harbor to institutions that use the model Certification Form adopted in the final rule akin to, for example, the safe harbor provided for foreign bank certifications.
36

36
31 CFR 1010.630(b).

The comments FinCEN received related to the Certification Form varied widely. Some commenters urged FinCEN to make the Certification Form an official U.S. Government document, with the certification made under the penalty of perjury (rather than only to the best of the knowledge of the certifying party), and a few commenters thought that the Certification Form should be notarized. However, many commenters requested that the proposed Certification Form be permissive rather than mandatory, and that financial institutions be permitted to obtain the information through their standard account opening process without utilizing the Certification Form. A few commenters thought that the person opening the account should be required to have actual personal knowledge of the information provided on the Certification Form, or that the certification should take the form of a resolution ratified or adopted by the legal entity's board or governing body. These commenters thought that a Certification Form without attestation requirements more substantial than those in the proposal would reduce accountability for false representations on the Certification Form.

As noted above, a primary reason that FinCEN proposed the Form was to balance the benefits and burdens of this new requirement to the financial institution and its customers with the benefits to law enforcement and regulatory authorities. We also note that in the case of many legal entities that are small businesses, the natural person opening the account will often be one of the beneficial owners, who would have direct knowledge of the beneficial ownership information of the legal entity customer. FinCEN understands that many institutions obtain and maintain customer data electronically rather than in paper form to the greatest extent possible, and that mandating the use and retention of a specific form would require significant technological and operational changes that could be costly and challenging to implement for some financial institutions. We have therefore amended the final rule to permit, but not require, financial institutions to use the Certification Form to collect beneficial ownership information. Accordingly, in the final rule, § 1010.230(b)(1) is revised to state that covered financial institutions must identify the beneficial owner(s) of each legal entity customer at the time a new account is opened, unless the customer is otherwise excluded or the account is exempted. A covered financial institution may accomplish this either by obtaining certification in the form of appendix A of the section from the individual opening the account on behalf of the legal entity customer, or by obtaining from the individual the information required by the form by another means, provided the individual certifies, to the best of the individual's knowledge, the accuracy of the information.
37

37
This revision will also require a corresponding change to the Recordkeeping subsection, described in greater detail below.

Thus, covered financial institutions can satisfy this requirement through (1) the use of FinCEN's Certification Form; (2) the use of the financial institution's own forms, so long as they meet the requirements of § 1010.230(b)(1); or (3) any other means that satisfy the substantive requirements of § 1010.230(b)(1). These records may be retained electronically and incorporated into existing databases as a part of financial institutions' overall management of customer files, and covered financial institutions will have flexibility in integrating the beneficial ownership information requirement into existing systems and processes. The certification of accuracy by the individual submitting the information may be obtained without use of the Certification Form in the same way the financial institution obtains other information from its customers in connection with its account opening procedures. FinCEN expects that such flexibility will facilitate the implementation of the beneficial ownership requirement—some commenters noted that giving financial institutions flexibility in integrating this requirement would substantially reduce resource outlays to change customer onboarding processes and to train front-line employees. In addition, to facilitate use of the Certification Form by those institutions that choose to utilize it, FinCEN will also make an electronic version available, although it will not be an official U.S. Government form.

Some commenters asked that FinCEN clarify who an appropriate individual to certify the identity of the beneficial owners to the financial institution would be, whether by signing the Certification Form or otherwise providing the beneficial ownership information in accordance with this paragraph; some commenters also questioned whether the individual opening an account could be a low-level employee without knowledge of the entity's owners. In this regard, FinCEN declines to impose specific account-opening procedures on financial institutions, and believes that financial institutions should be able to integrate this new requirement into their institution's existing procedures with little disruption. FinCEN understands that financial institutions generally have long-standing policies and procedures, based on sound business practices and prudential considerations, governing the documentation required to open an account for a legal entity; these typically include resolutions authorizing the entity to open an account at the institution and identifying the authorized signatories. Such resolutions are typically certified by an appropriate individual,
e.g.,
the secretary or other officer of a corporation, a member or manager of an LLC, or partner of a partnership. It would be appropriate for the same individual to certify the identity of the beneficial owners. Such an individual would typically have at least some familiarity with the entity's owners and with individuals with responsibility to control or manage the

entity, but may not have personal knowledge of individuals having an indirect ownership interest through, for example, intermediate legal entities or contractual arrangements with nominal owners, and would have to rely on others for any such information. Therefore, while FinCEN anticipates that the certifying individual would generally be able to provide accurate beneficial ownership information, it is appropriate that it be provided to the best of such person's knowledge, rather than without qualification. Accordingly, FinCEN declines to require a heightened knowledge threshold, or notarization, or board approval requirement for the certification requirement, as some commenters suggested, as any such requirement would increase the amount of time to open an account, without commensurate benefit, and would be inconsistent with FinCEN's goal of integrating this requirement into existing financial institution onboarding procedures to the greatest extent possible.
38

FinCEN thus believes that the certification requirement as described in the final rule provides the appropriate level of accountability given the circumstances.
39

38
FinCEN notes that in cases where the individual signing the documentation to open the account (and identifying the legal entity's beneficial owners) does not deliver such documentation to the financial institution, it may be appropriate that the individual's signature be notarized.

39
FinCEN also understands that in cases where a newly formed legal entity opens a financial institution account in order to commence business, the beneficial owner(s) would typically open the account in person and be the signatories on the account, and could readily certify their status as beneficial owners at that time.

Some commenters urged FinCEN to permit financial institutions to rely upon alternative sources, such as previously collected customer information in their databases, or the IRS Form W-8BEN, to satisfy the certification requirement. FinCEN recognizes that this could facilitate financial institutions' ability to obtain this information. However, to be of greatest use, FinCEN believes that beneficial ownership information must be, at the time of account opening, both (1) current, and (2) certified by an individual authorized by the customer to open accounts at financial institutions to be accurate to the best of his or her knowledge. Furthermore, because FinCEN's definition of beneficial ownership does not align precisely with, for example, the IRS's definition in its Form W-8BEN, permitting reliance in some circumstances upon other agencies' forms would be at odds with FinCEN's goal of consistent beneficial ownership standards within and across industries for purposes of CDD. Thus, FinCEN declines to permit reliance solely upon previously gathered alternate sources of beneficial ownership information.

Several commenters raised specific questions regarding the information in the proposed Certification Form. FinCEN agrees with the suggestions made by several commenters that the title of the person with significant management responsibility, as well as of the person submitting the Certification Form or supplying the information, should be included and has made these changes to the Form. We have also added fields on the Certification Form in which to identify the type of legal entity, and to note its address. Other commenters noted that the address fields as laid out in the proposed Certification Form, along with the description of the address requirement in the general instructions section, were not congruent with CIP's address requirements, and accordingly asked FinCEN to confirm that the CIP rules' address requirements remained applicable. As described in greater detail below, covered financial institutions' procedures for identifying and verifying beneficial owners must contain all the elements of the applicable CIP rule, including the address, date of birth, and Taxpayer Identification Number requirements as set forth therein. Accordingly, FinCEN has revised the Certification Form to clarify this point, and notes that this information will be required whether or not the Certification Form is used. We have also amended item “a” of the Certification Form to clarify that the name of the certifying party should be that of a
natural
person authorized to open the account (and not of the legal entity itself). FinCEN also agrees with the suggestion made by a number of commenters that the Certification Form state that the information in the Certification Form is required by Federal regulation in order to explain to customers why this new requirement has been put in place; the Form has been edited appropriately.

Several commenters sought clarification as to whether a financial institution must identify and verify a legal entity customer's beneficial owners each time it opens a new account at the institution after the rule's compliance deadline, or whether the requirement applies only the first time it opens a new account at such institution. FinCEN has concluded that, while it is not requiring periodic updating of the beneficial ownership information of all legal entity customers at specified intervals, the opening of a new account is a relatively convenient and otherwise appropriate occasion to obtain current information regarding a customer's beneficial owners. Accordingly, FinCEN has added to the final rule as § 1010.230(g) a definition for “new account”.

One commenter urged FinCEN to mandate the use of the Legal Entity Identifier (LEI), a global standardized unique identifier for legal entities engaged in financial transactions, on the proposed Certification Form. This commenter noted that including such a requirement would further the goals of transparency and financial stability. FinCEN understands that the LEI was developed principally to aggregate data from across markets, products, and regions, giving global regulators a means to quickly identify parties to financial transactions, in order to enhance regulators' ability to understand systemic risks to the financial system and act accordingly. Although this is an important and laudable purpose, FinCEN does not believe that mandating the LEI's inclusion on the beneficial ownership Certification Form would further this goal substantially. We believe that the overwhelming majority of legal entities subject to this requirement will be smaller or non-financial entities that would not be typical applicants for LEIs in the first instance, and that the costs of mandating its use solely for the purposes of the Certification Form would not be outweighed by the benefit. FinCEN also understands that the authorized bodies that assign LEIs do not require the beneficial owner to be a natural person, use a 50 (rather than 25) percent threshold, and do not verify the identities of beneficial owners of legal entities, thereby rendering the LEI's utility as a possible proxy or alternative source of verification minimal. For these reasons, FinCEN declines to mandate the use of the LEI. We do, however, recognize that covered financial institutions may find such information useful for enterprise-wide risk management or other purposes, and have accordingly included an optional LEI field on the Certification Form.

Several commenters urged FinCEN to adopt an express safe harbor in the final rule deeming those financial institutions that use the Certification Form compliant with the beneficial ownership requirement. A few commenters recommended that FinCEN model such an express safe harbor on the safe harbor for foreign bank certifications found in § 1010.630. Other commenters opposed the notion of a safe harbor, contending that the Certification Form should serve as the

starting point for financial institutions' risk-based due diligence into a legal entity's beneficial ownership. As discussed in greater detail below, we have included in § 1010.230(b)(2) of the final rule a description of the extent to which financial institutions can rely upon the beneficial ownership information provided by the person opening the account. We decline, however, to include in the final rule a blanket safe harbor triggered by the use and collection of the standard Certification Form.

FinCEN believes that there are a number of factors present in the context of foreign bank certifications (but absent here) that make a blanket safe harbor appropriate in that context. The foreign bank certification was used to satisfy several obligations arising under Sections 313 and 319(b) of the USA PATRIOT Act, including not only for the foreign bank to certify facts such as its status and in certain cases its owners, but also to set forth its agreement not to provide banking services to foreign shell banks and to appoint a U.S. process agent. Moreover the foreign bank official was required to certify that the information in the document was true and correct, whereas the beneficial ownership information is to be provided to the best of the knowledge of the customer's agent. In addition, the population of legal entities subject to the final rule is exponentially larger than that of foreign banks with U.S. correspondent accounts, and the proposed certification in the proposed rule does not include affirmative obligations. We believe that the provision inserted into § 1010.230(b)(2) of the final rule describing the extent to which the financial institution may rely on the information provided by the customer strikes the right balance between the need to minimize burden upon covered financial institutions and the risk of abuse of legal entities for illicit purposes.

A few commenters raised concerns that the collection of sensitive personal information of beneficial owners would impinge upon their privacy and increase their vulnerability to identity theft. FinCEN recognizes the critical importance of protecting individuals' privacy interests, as well as the serious threat posed by cyberattacks and identity theft, particularly with respect to the personal information held at financial institutions. These concerns, while valid and significant, are insufficient to justify elimination of the requirement. From both the privacy and identity-theft perspectives, the incremental impact upon the vast majority of beneficial owners will be slight, because, pursuant to CIP requirements, they already have to provide the same sensitive personal information to financial institutions to open individual accounts and access the U.S. financial system. We note that financial institutions are expected to protect this information just as they do CIP information, as well as comply with all applicable Federal and State privacy laws, including, but not limited to, the Right to Financial Privacy Act
40

and the Gramm-Leach-Bliley Act.
41

40
12 U.S.C. 3401
et seq.

41
15 U.S.C. 6801
et seq.

Section 1010.230(b)(2).
With respect to verification of identity, we proposed that verification meant that financial institutions were required to verify the
identity
of the individual identified as a beneficial owner (
i.e.,
to verify the individual's existence), and not his or her
status
as a beneficial owner. We proposed that this verification be done via risk-based procedures that are identical to the institutions' CIP procedures required for verifying the identity of customers that are individuals, to facilitate financial institutions' implementation of the requirement through leveraging existing procedures and systems.

Many commenters sought clarification of the meaning of the verification requirement in proposed § 1010.230(b)(2) and the means by which it may be accomplished. Some pointed out the potential confusion between two statements in the NPRM discussing the distinction between verifying the identity of the beneficial owner and verifying the status.
42

In order to resolve any potential confusion regarding the beneficial ownership identification and verification obligation of financial institutions, FinCEN is revising § 1010.230(b)(2) in the final rule to clarify that a covered financial institution may rely on the information supplied by the legal entity customer regarding the identity of its beneficial owner or owners, provided that it has no knowledge of facts that would reasonably call into question the reliability of such information. FinCEN anticipates that, in the overwhelming majority of cases, a covered financial institution should be able to rely on the accuracy of the beneficial owner or owners identified by the legal entity customer, absent the institution's knowledge to the contrary. FinCEN recognizes the necessity for permitting reliance on the identification supplied by the legal entity customer, considering the fact the customer is generally the best source of this information, and that there is generally no other source of beneficial ownership information available to covered financial institutions, aside from the legal entity itself.

42
FinCEN stated that “[i] n light of these considerations, FinCEN is not proposing that financial institutions verify the
status
of a beneficial owner. Financial institutions may rely on the beneficial ownership information provided by the customer on the standard certification form.” On the other hand, the proposal also states that its procedures for verifying beneficial ownership “should enable the financial institution to form a reasonable belief that it knows the true identity of the beneficial owner of each legal entity customer.” (79 FR 45162)

Several commenters sought clarification of the requirement as described in the NPRM in proposed § 1010.230(b)(2) that beneficial ownership information procedures be, at a minimum, “identical” to the existing CIP procedures for verifying the identity of individual customers. Some commenters noted that it would be infeasible to simply replicate, without modification, existing CIP procedures for individual customers to implement the beneficial ownership verification requirement. They noted, for example, that because the beneficial owners will in many cases not be physically present at the financial institution at account opening, an institution using documentary verification may not have access to the documents listed in the relevant paragraph of the CIP rule, and therefore may need to rely on a photocopy or other reproduction of such document. Commenters also noted that some current procedures for non-documentary verification of individual customers could not be applied to non-consenting beneficial owners, because of limitations on the use of credit reports imposed by the Fair Credit Reporting Act.
43

43
15 U.S.C. 1681
et seq.

FinCEN agrees that it would be impracticable for covered financial institutions to implement the beneficial ownership verification requirement with procedures that are identical to the institution's existing CIP rule procedures for individual customers. Accordingly, § 1010.230(b)(2) has been amended to require that at a minimum, these procedures must contain the elements
44

required for verifying the identity of customers that are individuals under paragraph (a)(2) of

the applicable CIP rule,
45

but are not required to be identical. In addition, the final rule clarifies that in the case of documentary verification, the financial institution may use photocopies or other reproductions of the documents listed in paragraph (a)(2)(ii)(A)(
1
)
46

of the applicable CIP rule.

44
The clause “in the covered financial institution's Customer Identification Program procedures” in the proposed rule text have been deleted, because, for the reasons described above, the verification procedures for beneficial owners of legal entity customers may be different from the procedures in the covered financial institution's CIP that apply to individual customers.

45
Paragraph (a)(2) of each of the CIP rules requires that the relevant financial institution's CIP includes risk-based procedures to verify the identity of each customer, to the extent reasonable and practicable. The elements of such program must include identifying the customer, verifying the customer's identity (through documents or non-documentary methods), and procedures for circumstances where the institution cannot form a reasonable belief that it knows the true identity of the individual.

46
Relevant documentation may include unexpired government-issued identification evidencing nationality or residence and bearing a photograph or similar safeguard, such as a driver's license or passport.
See, e.g.,
31 CFR 1020.220(a)(2)(ii)(A)(
1
).

Because the risk-based verification procedures must contain the same elements as required by the applicable CIP rule to verify the identity of individual customers, verification must be completed within a reasonable time after the account is opened. In addition, the beneficial ownership identification procedures must address situations in which the financial institution cannot form a reasonable belief that it knows the true identity of the beneficial owner of a legal entity customer after following the required procedures.
47

It remains the case that covered financial institutions may generally rely on government-issued identification as verification of an individual's identity, absent obvious indications of fraud.
48

FinCEN notes that such reliance is also generally appropriate in the case of photocopies or other reproductions obtained pursuant to § 1010.230(b)(2). However, given the vulnerabilities inherent in the reproduction process, covered financial institutions should conduct their own risk-based analyses of the types of photocopies or reproductions that they will accept in accordance with this section, so that such reliance is reasonable. For example, a covered financial institution could determine that it will not accept reproductions below a certain optical resolution, or that it will not accept reproductions transmitted via facsimile, or that it will only accept digital reproductions transmitted in certain file formats. As with CIP, covered financial institutions are not required to maintain these copies or reproductions, but only a description of any document upon which the financial institution relied to verify the identity of the beneficial owner. We note, however, that although covered financial institutions are not required to maintain these reproductions, they are not prohibited from keeping them in a manner consistent with all other applicable laws or regulations.

47
Under the CIP rules, a financial institution's CIP must include procedures for responding to circumstances in which the financial institution cannot form a reasonable belief that it knows the true identity of a customer. These procedures should describe: (A) When the institution should not open an account; (B) The terms under which a customer may use an account while the institution attempts to verify the customer's identity; (C) When it should close an account, after attempts to verify a customer's identity have failed; and (D) When it should file a Suspicious Activity Report in accordance with applicable law and regulation.
See, e.g.,
31 CFR 1020.220(a)(2)(iii).

48

See, e.g.,
Customer Identification Programs for Banks, Savings Associations, Credit Unions and Certain Non-Federally Regulated Banks, 68 FR 25090, 25099 (May 9, 2003).

Some commenters urged FinCEN to permit covered financial institutions to take a risk-based, rather than categorical, approach to the identification and verification requirements. Among the objections lodged against a categorical requirement were that: Conducting CIP procedures on non-present beneficial owners would be too difficult; the benefit of a categorical requirement was outweighed by the costs; and expanding the number of natural persons subject to CIP procedures would increase costs, particularly for institutions that rely upon vendors that charge on a
per capita
basis for CIP. FinCEN believes that categorical application of this requirement across covered financial institutions will reduce illicit actors' opportunities to slip into the financial system by masking their legal entities with markers indicative of a low risk profile. As to concerns about costs and difficulties, we believe that the above-described changes and clarifications made to this paragraph have given financial institutions greater flexibility in determining how to implement the identification and verification requirements, thereby reducing their impact. As described above, because financial institutions will in most instances be able to rely upon the information provided by the customer, FinCEN believes that financial institutions generally will not expend substantially greater resources by collecting and verifying the information in all cases (subject to permitted exemptions) than by engaging in a risk analysis to determine whether the beneficial ownership information should be collected and verified. We recognize that financial institutions that pay for systems and technology costs associated with CIP procedures on a
per capita
basis will face increased costs from identifying and verifying the identities of additional natural persons. However, we believe that the benefits of collecting this information, as described at greater length above and below, outweigh these additional costs. FinCEN accordingly declines to alter the categorical nature of the requirement for the final rule.

Several commenters questioned the utility of collecting this information in the absence of an authoritative centralized resource against which to verify beneficial ownership status. They contended that the limited benefit of this information would not outweigh the costs imposed by the requirement. Law enforcement commenters, however, identified significant benefits to the collection of beneficial ownership information, regardless of financial institutions' ability to verify ownership status. They noted that the identities of verified natural persons linked to legal entities of interest had significant value in law enforcement investigations, whether or not those natural persons are the actual beneficial owners, since at a minimum they may have information that can aid law enforcement in identifying the true beneficial owner(s). Furthermore, false beneficial ownership information is of significant use to prosecutors in demonstrating consciousness of guilt, as well as for impeachment purposes at trial. And law enforcement also noted the likely deterrent effect that a categorical collection and verification requirement would have on illicit actors, by making it more difficult for them to maintain anonymity while opening accounts. For these reasons, FinCEN rejects the notion that this requirement is of limited value.

A few commenters requested that FinCEN eliminate the verification requirement entirely, contending that verification of the identities of non-present beneficial owners would be too difficult and burdensome, especially for smaller institutions. As described above, we are aware of the challenges associated with verifying the identities of non-present individuals and have accordingly made changes to simplify the process for financial institutions, which we expect will reduce the burden. Importantly, collecting beneficial ownership information without verifying the existence of the named person would substantially diminish the value of the information, and we therefore decline to eliminate the verification requirement.

Some commenters asked FinCEN to clarify what we expect financial institutions to do with the beneficial ownership information that they collect and verify. FinCEN generally expects

beneficial ownership information to be treated like CIP and related information, and accordingly used to ensure that covered financial institutions comply with other requirements. For example, the Office of Foreign Assets Control (OFAC) requires covered financial institutions to block accounts (or other property and interests in property) of, among others, persons appearing on the Specially Designated Nationals and Blocked Persons List (SDN List), which includes any entity that is 50 percent or more owned, in the aggregate, by one or more blocked persons, regardless of whether the entity is formally listed on the SDN List.
49

Therefore, institutions should use beneficial ownership information to help ensure that they do not open or maintain an account, or otherwise engage in prohibited transactions or dealings involving individuals or entities subject to OFAC-administered sanctions. Covered financial institutions should also develop risk-based procedures to determine whether and/or when additional screening of these names through, for example, negative media search programs, would be appropriate.

49

See generally
31 CFR part 500;
see also, e.g.,
31 CFR 590.406 (Ukraine-related sanctions regulations); Office of Foreign Assets Control,
Frequently Asked Questions, available at http://www.treasury.gov/resource-center/faqs/Sanctions/Pages/faq_general.aspx#50_percent
.

With respect to aggregation of transactions for Currency Transaction Reporting (CTR) purposes, FinCEN expects covered financial institutions to apply existing procedures consistent with CTR regulations and applicable FinCEN guidance from 2001 and 2012.
50

Thus, while financial institutions should generally recognize the distinctness of the corporate form and not categorically impute the activities or transactions of a legal entity customer to a beneficial owner, they must aggregate multiple currency transactions if the financial institution has knowledge that these transactions are by or on behalf of any person and result in either cash in or cash out totaling more than $10,000 during any one business day.
51

While the requirement to identify the beneficial owners of legal entity customers does not modify this existing CTR aggregation requirement, the beneficial ownership identification may provide financial institutions with information they did not previously have, in order to determine when transactions are “by or on behalf of” the same person. Thus, if a financial institution determines that a legal entity customer or customers are not being operated independently from each other or from their primary owner—
e.g.,
the institution determines that legal entities under common ownership have common employees and are repeatedly used to pay each other's expenses or the personal expenses of their primary owner—then the financial institution may determine that aggregating the transactions of a legal entity or entities and their primary owner would be appropriate.
52

Under such circumstances, if a financial institution were aware that a beneficial owner made a $5,000 cash deposit into his personal account, and later the same business day, he made a $6,000 cash deposit into the account of a legal entity not being operated as an independent entity, the institution would be required to aggregate those transactions and file a CTR.
53

And to the extent that the financial institution determined that such transactions had no other apparent purpose than to avoid triggering a CTR filing, the financial institution would need to consider whether filing a SAR about the transactions would be appropriate.

50

See
31 CFR 1010.313; FinCEN,
Currency Transaction Report Aggregation for Businesses with Common Ownership
FIN-2012-G001, (Mar. 16, 2012) (FIN-2012-G001); FinCEN,
Currency Transaction Reporting: Aggregation,
FinCEN Ruling 2001-2, (Aug. 23, 2001).

51
31 CFR 1010.313.

52
In general, such aggregation would only be appropriate in cases where an individual owns all or substantially all of the legal entity's equity interests. It is only in such cases that a transaction by a legal entity could be considered “by or on behalf of” the owner of the entity (or vice versa).

53

See
FIN-2012-G001 at 2.

A few commenters asked FinCEN to provide guidance as to how beneficial ownership information should be incorporated into processes for information sharing pursuant to USA PATRIOT Act Section 314(a); one of these commenters asked FinCEN to declare such information
per se
outside of the scope of Section 314(a). FinCEN does not expect the information obtained pursuant to the beneficial ownership requirement to add additional requirements with respect to Section 314(a) for financial institutions. The rule implementing Section 314(a), set forth at 31 CFR 1010.520, does not authorize the reporting of beneficial ownership information associated with an account or transaction matching a named subject. Under that rule, financial institutions need only search their records for account or transactions matching a named subject, and report to FinCEN whether such a match exists using the identifying information that FinCEN provides.

Section 1010.230(c) Account.
See discussion below under “Legal entity customer.”

Section 1010.230(d) Beneficial Owner.
In the NPRM, we proposed two prongs for the definition of beneficial owner: Each individual, if any, who directly or indirectly owned 25 percent of the equity interests of a legal entity customer (the ownership prong); and a single individual with significant responsibility to control, manage, or direct a legal entity customer, including an executive officer or senior manager or any other individual who regularly performs similar functions (the control prong). We noted that the number of beneficial owners identified would vary from legal entity customer to legal entity customer due to the ownership prong—there could be as few as zero and as many as four individuals who satisfy this prong. All legal entities, however, would be required to identify one beneficial owner under the control prong. We further noted that financial institutions had the discretion to identify additional beneficial owners as appropriate based on risk.

Thus, in practice, the number of beneficial owners identified will vary based on the circumstances. For example:

• Mr. and Mrs. Smith each hold a 50 percent equity interest in “Mom & Pop, LLC.” Mrs. Smith is President of Mom & Pop, LLC and Mr. Smith is its Vice President. Mom & Pop, LLC is required to provide the personal information of both Mr. & Mrs. Smith under the ownership prong. Under the control prong, Mom & Pop, LLC is also required to provide the personal information of one individual with significant responsibility to control Mom & Pop, LLC; this individual could be either Mr. or Mrs. Smith, or a third person who otherwise satisfies the definition. Thus, in this scenario, Mom & Pop, LLC would be required to identify at least two, but up to three distinct individuals—both Mr. & Mrs. Smith under the ownership prong, and either Mr. or Mrs. Smith under the control prong, or both Mr. & Mrs. Smith under the ownership prong, and a third person with significant responsibility under the control prong.

• Acme, Inc. is a closely-held private corporation. John Roe holds a 35 percent equity stake; no other person holds a 25 percent or higher equity stake. Jane Doe is the President and Chief Executive Officer. Acme, Inc. would be required to provide John Roe's beneficial ownership information under the ownership prong, as well as Jane Doe's (or that of another control person) under the control prong.

• Quentin, Inc. is owned by the five Quentin siblings, each of whom holds a 20 percent equity stake. Its President is Benton Quentin, the eldest sibling, who

is the only individual at Quentin, Inc. with significant management responsibility. Quentin, Inc. would be required to provide Benton Quentin's beneficial ownership information under the control prong, but no other beneficial ownership information under the ownership prong, because no sibling has a 25 percent stake or greater.

One commenter raised a concern that this obligation would effectively require financial institutions to monitor the equity interests and management team of legal entity customers on an ongoing basis and continually update this information. FinCEN notes that it would be impracticable for financial institutions to conduct this type of inquiry, and emphasizes that this obligation should be considered a snapshot, not a continuous obligation. As discussed more fully in the Section-by-Section Analysis addressing the amendments to the AML program rules, FinCEN does expect financial institutions to update this information based on risk, generally triggered by a financial institution learning through its normal monitoring of facts relevant to assessing the risk posed by the customer.

The Ownership Prong.
Commenters raised a number of points regarding the ownership prong. Several commenters speculated on FinCEN's intention with respect to this requirement. FinCEN confirms here that by the phrase “directly or indirectly,” it intends that the financial institution's customer identify its ultimate beneficial owner or owners as defined in the rule and not their nominees or “straw men.” In addition, as described in § 1010.230(b)(2), financial institutions may rely on information provided by the customer to identify and verify the beneficial owner.

Many commenters supported FinCEN's decision in the proposal to set the minimum threshold for equity holdings constituting ownership at 25 percent. Some of these commenters requested that FinCEN affirm this threshold as the regulatory expectation, notwithstanding our remarks in the proposal that financial institutions, after their own assessment of risk, could determine that a lower threshold percentage might be warranted. A few commenters, however, urged FinCEN to lower this threshold to 10 percent, contending that the higher threshold would be too easy to evade and is inconsistent with international AML norms and requirements of FATCA, and that the burden of a lower threshold would be minimal because some financial institutions as a matter of practice already collect beneficial ownership information at thresholds lower than 25 percent.

FinCEN has considered all of the arguments in favor of lowering the ownership threshold to 10 percent, and we decline to make this change in the final rule. Although it is true that some financial institutions already collect beneficial ownership information at a threshold lower than 25 percent in some cases, we do not believe that this practice is widely established enough to justify its categorical imposition for all legal entity customers across all covered financial institutions. As some proponents of the 10 percent threshold noted, this lower threshold would make it more difficult for illicit actors to structure ownership interests to evade the reporting threshold. However, it would also require financial institutions to identify and verify as many as eleven beneficial owners (including the control prong). In FinCEN's assessment, the incremental benefit of this approach does not outweigh the burdens associated with having to collect and verify the identities of more than twice as many beneficial owners in some circumstances. Furthermore, the proposed 25 percent threshold is consistent with that of many foreign jurisdictions (including EU member states) and with the FATF standard, which in turn is used to define the controlling persons of an entity in the intergovernmental agreements that the United States has entered into with more than 110 other jurisdictions in order to enforce the requirements of FATCA. FinCEN continues to believe that a 25 percent threshold strikes the appropriate balance between the benefit of identifying key natural persons who have substantial ownership interests in the legal entity and the costs associated with implementing this information-collection requirement.

We reiterate that the 25 percent threshold is the baseline regulatory benchmark, but that covered financial institutions may establish a lower percentage threshold for beneficial ownership (
i.e.,
one that regards owners of less than 25 percent of equity interests as beneficial owners) based on their own assessment of risk in appropriate circumstances. As a general matter, FinCEN does not expect covered financial institutions' compliance with this regulatory requirement to be assessed against a lower threshold. Nevertheless, consistent with the risk-based approach, FinCEN anticipates that some financial institutions may determine that they should identify and verify beneficial owners at a lower threshold in some circumstances; we believe that making this clear in the note accompanying the regulatory text will aid them in doing so with respect to their customers.

Some commenters urged FinCEN to include in the ownership prong a “fallback provision” to require the collection of beneficial ownership information for at least one individual with a significant equity stake in the legal entity, even if no beneficial owner meets the minimum ownership threshold. Such a provision was initially discussed in the ANPRM for this rulemaking but not included in the NPRM in response to concerns expressed by numerous commenters that the approach was impracticable. As we noted in the NPRM, commenters questioned the feasibility of engaging in a comparative analysis of every owner to determine the individual who “has at least as great an equity interest in the entity as any other individual.” Agreeing with that assessment, we removed this provision, and we do not believe that any benefit from its reintroduction would outweigh the difficulties that customers and front-line employees would face in implementing it. Although we have declined to include this provision in the final rule, financial institutions may determine, pursuant to a risk-based approach for their institutions, that certain higher risk circumstances may warrant the collection of beneficial ownership information for at least one natural person under the ownership prong even if no beneficial owner meets the 25 percent threshold.

One commenter requested that FinCEN clarify whether covered financial institutions had an obligation to determine whether equity holders of a legal entity managed or structured their holdings to evade the 25 percent threshold for reporting. FinCEN notes that in most cases it would be impracticable for front-line employees to conduct this type of inquiry. Thus, FinCEN expects that financial institutions will generally be able to rely upon information about equity ownership provided by the person opening the account, and not to affirmatively investigate whether equity holders are attempting to avoid the reporting threshold. However, financial institution staff who know, suspect, or have reason to suspect that such behavior is occurring may, depending on the circumstances, be required to file a SAR.

A few commenters sought clarification of the definition of “equity interests” provided in the proposal—to wit, an ownership interest in a business entity—contending that although the proposed definition provided a great

deal of latitude and flexibility, it might also cause confusion due to its broad sweep. Thus, commenters requested greater clarification and guidance in the form of examples or additional commentary, to assist customers in understanding and complying with the requirements of the regulation as well as employees in their determinations as to which types of ownership interests are subject to this prong. FinCEN appreciates that some financial institutions may find it challenging in some circumstances to determine whether a particular ownership interest qualifies as an “equity interest.” However, as we noted in the proposal, we deliberately avoided the use of more technical terms of art associated with the exercise of control through ownership; we did so in part based on the preferences expressed by many members of industry. The above-mentioned commenters urged FinCEN to avoid creating a definition using technical and complex legal terms that would also be difficult for customers and front-line employees to understand and apply. Beyond the general examples provided in the proposal, however, we are reluctant to provide additional narrower examples that could be construed to limit a definition that we intend to be broadly applicable, particularly in light of the diversity of types of legal entities formed within the United States and abroad. By the same token, we also decline to provide a formal guidance document listing the types of documents that front-line employees should rely upon to demonstrate the existence of an equity interest over the triggering threshold. We reiterate that it is generally the responsibility of the legal entity customer (and its personnel) to make this determination and to identify the beneficial owners, and not front-line employees at the financial institution, unless the employees have reason to question the accuracy of the information presented.

Some commenters noted that while they approved of FinCEN's general approach to determining indirect ownership of legal entity customers—
i.e.,
that FinCEN does not expect financial institutions or customers to undertake analyses to determine whether an individual is a beneficial owner under the definition—they nevertheless thought that FinCEN should provide additional guidance and examples of how legal entity customers should calculate ownership interests when natural persons have indirect equity interests. As an initial matter, as described above, we emphasize that FinCEN expects that financial institutions will generally be able to rely on the representations of the customer when it identifies its beneficial owners. We also note that it would not be unreasonable to expect that a legal entity that has a complex structure would have personnel who necessarily have a general understanding of the ownership interests of the natural persons behind it for operational, management, accounting, and other purposes.

Commenters also sought clarification regarding various scenarios where 25 percent or greater equity interests of a legal entity customer are held in such a manner that the interest is not ultimately owned, directly or indirectly, by any individual. This could occur, for example, where a 25 percent or greater ownership interest is held by an entity excluded from the legal entity customer definition under paragraph (e)(2) or by a trust. FinCEN notes that the exclusions in the proposed rule include any entity organized under the laws of the United States or of any State at least 51 percent of whose common stock or analogous equity interests are held by an entity listed on a U.S stock exchange. FinCEN believes that this should address the overwhelming majority of situations where an excluded entity is a 25 percent or more shareholder. In addition, in the relatively unusual situations where an excluded entity holds a 25 percent or greater equity interest that is not covered by the above-mentioned exclusion, FinCEN notes that covered financial institutions are not required under the ownership prong to identify and verify the identities of a natural person behind these entities; this is because the definition of “beneficial owner” under the ownership prong refers to “[e]ach individual,
if any,
. . .”, and in such a case there would not be any individual who is the ultimate owner of such interest. On the other hand, where 25 percent or more of the equity interests of a legal entity customer are owned by a trust (other than a statutory trust), covered financial institutions would satisfy the ownership prong of the beneficial ownership requirement by collecting and verifying the identity of the trustee, and FinCEN has amended the definition consistent with this. For clarity, FinCEN notes that in any such case the legal entity customer would nonetheless be required to identify an individual under the control prong.

The Control Prong.
Commenters also raised a variety of points regarding this element.

A few commenters requested that we narrow or eliminate the control prong, contending that it would be difficult to identify a control person under such a wide-ranging definition. We disagree. FinCEN proposed a broad definition to give legal entities a wide range of options from which to choose. Accordingly, the breadth of the definition will facilitate, rather than hinder, financial institutions' ability to collect this information—because legal entity customers are required to provide information on only one control person who satisfies the definition, legal entities should be able to readily identify at least one natural person within their management structure who has significant management responsibility, consistent with the multiple examples of positions provided. Furthermore, there may be legal entities for which there are no natural persons who satisfy the ownership prong; without the control prong, this would create a loophole for legal entities seeking to obscure their beneficial ownership information. Requiring the identification and verification of, at a minimum, one control person ensures that financial institutions will have a record of at least one natural person associated with the legal entity, which will benefit law enforcement and regulatory investigations for reasons described previously.

A few commenters requested that FinCEN provide additional information about the types of persons who would satisfy the control prong, contending that a level of detail similar to the explanations provided for the ownership prong would be helpful for implementation. We believe that such additional explanation is unnecessary. In contrast with the variety of possible complicated scenarios that a financial institution might encounter when trying to determine beneficial ownership under the ownership prong, the control prong provides for a straightforward test: The legal entity customer must provide identifying information for one person with significant managerial control. It further provides as examples a number of common, well-understood senior job titles, such as President, Chief Executive Officer, and others. Taken together, FinCEN believes that these clauses provide ample information for legal entity customers to easily identify a natural person that satisfies the definition of control person.

A few commenters requested that FinCEN expand the reach of the control prong by, among other things, including within it the concept of “effective control,” and proposing a variety of changes to mandate the identification of additional natural persons under this

prong, from all persons who exercise executive management and leadership, to all senior officials and all those who exercise effective control over a legal entity. FinCEN declines to make any of these changes to the control prong. While we recognize that our definition does not encapsulate all possible concepts of control, including effective control, we believe that our definition strikes the appropriate balance between including sufficiently senior leadership positions and practicability. As one of the proponents of including effective control conceded, effective control can be “difficult to determine.” We sought in our proposal to provide an easily administrable definition to facilitate collection of this information for both legal entities and financial institutions. As to the identification of additional natural persons, we believe that the challenges associated with identifying and verifying additional natural persons outweigh any incremental benefit of the information.

Section 1010.230(e) Legal Entity Customer.
As proposed, this paragraph defined the term “legal entity customer” and delineated a series of exclusions from this definition.

Section 1010.230(e)(1).
In the proposed rule, we to defined “legal entity customer” to mean a corporation, limited liability company, partnership or other similar business entity (whether formed under the laws of a state or of the United States or a foreign jurisdiction) that opens a new account. Many commenters raised questions about what entities and other businesses would be covered and requested that the proposed definition be clarified, particularly the meaning of “other similar business entity.” Some commenters urged us to include other business forms, such as unincorporated associations and sole proprietorships, within the definition of legal entity customer.

We agree that covered institutions would benefit from a revised definition that further clarifies the entities that fall within the definition of “legal entity customer.” Thus, for the purposes of the final rule, we state that a legal entity customer means a corporation, limited liability company, or other entity that is created by the filing of a public document with a Secretary of State or similar office, a general partnership, and any similar entity formed under the laws of a foreign jurisdiction, that opens an account. This means that “legal entity customer” would include, in addition to corporations and limited liability companies, limited partnerships, business trusts that are created by a filing with a state office, any other entity created in this manner, and general partnerships. (It would also include similar entities formed under the laws of other countries.) It would not include, for example, sole proprietorships or unincorporated associations even though such businesses may file with the Secretary of State in order to, for example, register a trade name or establish a tax account. This is because neither a sole proprietorship nor an unincorporated association is an entity with legal existence separate from the associated individual or individuals that in effect creates a shield permitting an individual to obscure his or her identity.
54

The definition of “legal entity customer” also does not include natural persons opening accounts on their own behalf. In the final rule, we remove the reference to a “new” account to eliminate redundancies with other paragraphs of this provision, and because this account status is not a relevant characteristic for defining a legal entity customer.

54
FinCEN notes that this is consistent with the CIP rules, which include as a customer “an individual who opens a new account for . . . (B) an entity that is not a legal person, such as a civic club.” In such a case, the individual opening the account, rather than the civic club, is the customer.
See, e.g.,
31 CFR 1020.100(c)(1)(ii)(B).

Trusts

The definition would also not include trusts (other than statutory trusts created by a filing with a Secretary of State or similar office). This is because, unlike the legal entities that are subject to the final rule, a trust is a contractual arrangement between the person who provides the funds or other assets and specifies the terms (
i.e.,
the grantor or settlor) and the person with control over the assets (
i.e.,
the trustee), for the benefit of those named in the trust deed (
i.e.,
the beneficiaries). Formation of a trust does not generally require any action by the state. As FinCEN noted in the NPRM, identifying a “beneficial owner” from among these parties, based on the definition in the proposed or final rule, would not be possible.

FinCEN emphasizes that this does not and should not supersede existing obligations and practices regarding trusts generally. The preamble to each of the CIP rules notes that, while financial institutions are not required to look through a trust to its beneficiaries, they “may need to take additional steps to verify the identity of a customer that is not an individual, such as obtaining information about persons with control over the account.”
55

Moreover, as FinCEN noted in the proposal, it is our understanding that where trusts are direct customers of financial institutions, financial institutions generally also identify and verify the identity of trustees, because trustees will necessarily be signatories on trust accounts (which in turn provides a ready source of information for law enforcement in the event of an investigation). Furthermore, under supervisory guidance for banks, “in certain circumstances involving revocable trusts, the bank may need to gather information about the settlor, grantor, trustee, or other persons with the authority to direct the trustee, and who thus have authority or control over the account, in order to establish the true identity of the customer.”
56

We reiterate our understanding that, consistent with existing obligations, financial institutions are already taking a risk-based approach to collecting information with respect to various persons associated with trusts in order to know their customer,
57

and that we expect financial institutions to continue these practices as part of their overall efforts to safeguard against money laundering and terrorist financing.
58

55

See, e.g.,
“Customer Identification Programs for Broker-Dealers,” 68 FR at 25116 n.32. (May 9, 2003).

56
Federal Financial Institutions Examination Council,
Bank Secrecy Act/Anti-Money Laundering Examination Manual
281 (2014) (FFIEC Manual).

57
FinCEN also understands that in order to engage in the business of acting as a trustee, it is necessary for a trust company to be Federally- or State-chartered. Such entities are subject to BSA obligations, which reduces the AML risk of such trusts.

58
Also not covered by the final rule are accounts in the name of a deceased individual opened by a court-appointed representative of the deceased's estate.

“Account” Definition

FinCEN also notes that a legal entity customer is defined as one that opens an account, but that the NPRM did not define the term “account.” Several commenters requested that FinCEN provide a definition for this term and suggested using the definition from the CIP rules. In order to maintain consistency with the CIP rules, FinCEN is adding to the final rule the definition of the term “account” that is found in the CIP rules,
59

which by its terms excludes an account opened for the purpose of participating in an employee benefit plan established under the Employee Retirement Income Security Act of 1974. This added provision is not only consistent with CIP but also appropriate for the final rule, inasmuch as accounts established to enable

employees to participate in retirement plans established under ERISA are of extremely low money laundering risk.

59

See, e.g.,
31 CFR 1020.100(a)(2) (for banks); 1023.100(a)(2) (for brokers or dealers in securities); 1024.100(a)(2) (for mutual funds); and 1026.100(a)(2) (for futures commission merchants or introducing brokers in commodities).

In this regard, commenters requested that FinCEN broaden the exemption for ERISA plans to include other non-ERISA retirement plans, based on their low risk of money laundering, FinCEN notes that in the case of such non-ERISA plans, the customer would generally either be the trust established to maintain the assets, or the employer that contracts with the financial institution to establish the account, and not the underlying participants in or beneficiaries of the account.
60

Accordingly, in the case where the customer would be the employer and such employer is a legal entity, the financial institution would be required to obtain the beneficial owners of the legal entity employer (unless such employer is otherwise excluded from the definition of legal entity customer). We address other requests for exemptions from the beneficial ownership requirement in the discussion of § 1010.230(h) below.

60

See
FinCEN
et al., Interagency Interpretive Guidance on Customer Identification Program Requirements under Section 326 of the USA PATRIOT Act, FAQs: Final CIP Rule
6 April 28, 2005, page 6,
available at http://www.fincen.gov/statutes_regs/guidance/pdf/faqsfinalciprule.pdf
.

Paragraph (c) of § 1010.230 of the final rule will accordingly read as set out in the regulatory text at the end of this document.

Section 1010.230(e)(2).
The NPRM proposed ten exclusions from the legal entity customer definition. The first two categories are also for the most part excluded from the requirements of the CIP rules. The final rule adopts all of those proposed exclusions, except as discussed below under the heading, Charities and Nonprofit Entities. The final rule also adds a number of other exclusions in response to comments. All of the exclusions are a result of an assessment of the risks and determination that beneficial ownership information need not be obtained at account opening, because the information is generally available from other credible sources:

A financial institution regulated by a Federal functional regulator or a bank regulated by a State bank regulator
—1010.230(e)(2)(i)

These entities are excluded because they are subject to Federal or State regulation and information regarding their beneficial ownership and management is available from the relevant Federal or State agencies.

A person described in § 1020.315(b)(2) through (5) of this chapter
— § 1010.230(e)(2)(ii)

This includes the following:

•
A department or agency of the United States, of any State, or of any political subdivision of a State.
FinCEN has determined that this category is appropriate for exclusion because such entities have no equity owners and information regarding their management is readily available from public sources.

•
Any entity established under the laws of the United States, of any State, or of any political subdivision of any State, or under an interstate compact between two or more States, that exercises governmental authority on behalf of the United States or of any such State or political subdivision.
This category is also appropriate for exclusion due to the amount of ownership and management information that is publicly available about such entities.

•
Any entity (other than a bank) whose common stock or analogous equity interests are listed on the New York, American
,
61

or NASDAQ stock exchange.
This exclusion is appropriate because such entities are required to publicly disclose the beneficial owners of five percent or more of each class of the issuer's voting securities in periodic filings with the SEC, to the extent the information is known to the issuer or can be ascertained from public filings.
62

In addition, beneficial owners of these issuers' securities may be subject to additional reporting requirements.
63

61
Currently called NYSE MKT.

62

See, e.g.,
Item 12 of Form 10-K and Item 403 of Regulation S-K.

63

See
Securities Exchange Act section 13(d) and Rules 13d-1 to 13d-102; Securities Exchange Act § 16(a) and Rules 16a-1 through 16a-13.

•
Any entity organized under the laws of the United States or of any State at least 51 percent of whose common stock or analogous equity interests are held by a listed entity.
Because such subsidiaries of listed entities are controlled by their parent listed entity, information regarding control and management is publicly available.

An issuer of a class of securities registered under section 12 of the Securities Exchange Act of 1934 or that is required to file reports under section 15(d) of that Act

64

—§ 1010.230(e)(2)(iii)

64

See
Securities Exchange Act section 16(a) and Rules 16a-1 through 16a-13 and Item 403 of Regulation S-K.

These issuers are excluded because they are required to publicly disclose the beneficial owners of five percent or more of each class of the issuer's voting securities in periodic filings with the SEC, to the extent the information is known to the issuer or can be ascertained from public filings.
65

In addition, beneficial owners of t

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2016-10567. Public record. Not legal advice.
