
The government is no longer keeping a centralized business ownership database. What it means for banks and fintechs.

Get in touch with SOLO's team.
This past Tuesday, FinCEN issued a final rule that permanently shut down the short-lived government-run business ownership database and almost all of the federal reporting requirements that went with it. U.S. companies and U.S. persons are now fully exempt from reporting their beneficial ownership information (BOI) under the Corporate Transparency Act, a requirement that only went into effect in January 2024. The decision is not merely forward-looking; FinCEN will also delete the U.S. person data it had already collected.
This is a big deal, but for reasons completely separate than most commentators will focus on.
The headlines will track the political nature of the rule’s trajectory: one party’s administration wrote it, the other rolled it back. You’ve seen that movie before. The part of the script that those stories won’t tell is how this rule change affects institutions looking to onboard small business customers.
The requirement for banks to identify and verify the beneficial owners of their business customers comes from the 2016 Customer Due Diligence (CDD) Rule — not the 2021 Corporate Transparency Act that spawned the now-shuttered BOI database. The CDD Rule had always operated independently from the Corporate Transparency Act, and it has survived completely untouched by FinCEN’s most recent rulemaking.
Under the CDD Rule, every time a business opens a bank account, the bank has to collect beneficial ownership information: name, date of birth, address, and an identifying number for every person who owns 25% or more of the entity and anyone who exercises substantial control. The bank then corroborates the identifying information provided for each beneficial owner (typically name, date of birth, address, and SSN or passport number) to ensure that each owner is a real person.
The Corporate Transparency Act’s registry was supposed to supplement, not replace, this process by giving banks an additional database to query. But it never got there. The registry was embroiled in legal battles less than a year after it launched, and banks never got to fully operationalize it. Thus, its elimination changes nothing about the day-to-day reality of how beneficial ownership verification is currently implemented.
That day-to-day reality, for anyone who hasn't had the pleasure, goes something like this: a business owner walks into a bank (or, more likely, fills out an online application) and is handed a certification form. Then the not-so-fun part for the business owner begins. They list their co-owners, providing personal information for each one. Some time passes. The bank verifies the identities of the people listed. Hopefully for the business owner, they get approved for their account a couple days later. But the pain doesn’t end there. The next time they apply for a financial product at a different institution (or even, sometimes, at a different business line within the same institution), the business owner does the exact same thing at the next bank. And the next one. Every new account, every new relationship, the same information, from scratch.
Here's the part that doesn't get enough attention: under the CDD Rule, banks can rely on the customer's own certification for the ownership and control question. They don't need to independently verify that the people listed are actually the beneficial owners. They don't need to pull operating agreements or cap tables. FinCEN's own 2018 FAQ confirmed this. The bank just needs to verify that the individuals named on the form are real people who are who they claim to be.
This means that beneficial ownership verification in the United States is, in practice, a self-reported exercise. A business representative fills out a form, and the bank takes their word for the ownership structure. The identities get checked, but the ownership claims do not.
For most banks, most of the time, this process works out fine. The overwhelming majority of business owners are who they say they are and own what they say they own. But "fine most of the time" rarely cuts it as a risk management standard. The same logic that makes self-certification workable for any individual bank makes it fragile across the system. If a bad actor provides false ownership information at one institution, nothing in the current process prevents them from doing so at the next one. There's no cross-referencing, no network corroboration, no way for Bank B to know that the ownership structure Bank A was given looks completely different from what they're being told.
Set aside the compliance and risk implications for a moment. Think about the experience from the business owner's perspective.
A decade ago, filling out a few extra forms at account opening was an annoyance, but a tolerable one. Banks could get away with it because there weren't many alternatives and business owners didn't have strong expectations around digital onboarding. That's changing fast. Consumer financial services have trained everyone to expect instant, frictionless account opening. The more that expectation bleeds into small business banking, the harder it becomes to justify asking a three-person LLC to hand-certify its ownership structure from scratch at every institution it touches.
The trajectory here is clear: business owners will tolerate this friction less and less over time. The banks that figure out how to reduce it without compromising their compliance obligations will win the relationships. The ones that don't will watch those relationships walk out the door to someone who has.
That's the real significance of the final rule. It's not just that the registry is gone; it's that the federal government looked at the problem of centralized beneficial ownership infrastructure, weighed the costs against the benefits, and concluded that building it for domestic entities was not in the public interest. The Secretary of the Treasury made that determination explicitly. The Attorney General and the Secretary of Homeland Security concurred.
This is a permanent policy decision. And it means that the redundancy, the friction, and the verification gaps in how banks collect and confirm beneficial ownership are not going to be solved by a government database. If they get solved at all, industry has to do it.
The answer is a reliance network: a shared infrastructure that allows banks to furnish verified ownership data into a common framework and query that data when onboarding new business customers. Not a government registry. Not a single centralized database. A network operated by and for the financial institutions that have the compliance obligation in the first place.
This is what we've built at SOLO. The digital business identity product that solves the BOI friction problem (and many others) is called a KYB Certificate. Here’s how it works: John Doe, owner of Acme LLC, applies for a loan from Bank A. Instead of immediately presenting John with a long list of forms to fill out and paperwork to fetch, Bank A pings the SOLO Network to see if a KYB Certificate exists for Acme. If it does — perhaps it had been furnished by Bank B after John had opened a separate account with them a few months prior — Bank A receives the certificate and all of the verification work that comes with it. The piece relevant for our story is the Business Ownership Information BOI data, which instantaneously appears on John’s application pre-filled for him to approve or, if necessary, edit. John’s a whole lot likelier to see that application through to the end when the asks of him plummet to next to nothing.
The kicker is that Bank A can decide to filter its acceptance criteria to only accept certificates where the BOI information had been verified by an independent source.
While third-party verification is not legally required (as mentioned earlier, self-reported ownership is sufficient), Bank A may see it as a useful risk management layer. This is the opinion most of our network members shared when the news broke that the government maintained source would be disappearing. The consensus so far is that many banks will still require third-party business ownership verification for their own risk policies, even if they now bear the cost of sourcing that information instead of being able to rely on a FinCEN maintained list available to everyone.
The government-run BOI database may have gone away, but the opportunity for banks to dramatically reduce business identity verification friction lives on in the form of the SOLO Network. We’re here for anyone who wants to reduce their SMB application friction and doesn’t know where to turn in light of this week’s news. Your current and prospective small business customers with little to no time to spare on form-filling and file-chasing will certainly appreciate it.