Evergreen
How Beneficial Ownership Fits Into AML Controls
See where ownership data helps an AML program and why it cannot replace customer due diligence, transaction monitoring, escalation, or governance.
In this article
How Ownership Transparency Fits With AML Controls
Beneficial ownership information answers a narrow but important question: which individuals own or control an entity under the definition used by a particular rule?
An anti-money-laundering system has to answer more questions. Who is the customer? Why does the relationship exist? What activity is expected? What actually happened? Which signals require review? What must be reported? Who fixes a broken control?
Ownership transparency is one input into that system. It does not replace customer due diligence, transaction monitoring, investigation, suspicious activity reporting, sanctions controls, testing, governance, or enforcement.
flowchart LR
A["Entity and ownership information"] --> B["Customer due diligence and risk profile"]
B --> C["Transaction monitoring"]
C --> D["Alert review and investigation"]
D --> E["Suspicious activity decision"]
E --> F["Reporting and law-enforcement use"]
G["Governance, staffing, testing, and remediation"] --> B
G --> C
G --> D
G --> E
Corporate reporting and bank due diligence are different controls
The Corporate Transparency Act reporting rule applies to a reporting company. Under the rule verified on July 28, 2026, the reporting-company population generally concerns certain foreign-formed entities registered to do business in the United States. The current 31 CFR 1010.380 defines scope, exemptions, beneficial owners, company applicants, report contents, and timing.
FinCEN's Customer Due Diligence rule applies to covered financial institutions dealing with legal-entity customers. The CDD rule requires written procedures to identify and verify beneficial owners within that framework and supports a customer risk profile and ongoing monitoring.
The terms overlap, but the duties, regulated actors, covered entities, exemptions, data, and operational moments differ. A company exempt from CTA reporting can still be asked for ownership information by a bank. A bank's CDD process does not itself file the company's CTA report.
Customer due diligence builds the expected picture
Customer due diligence connects identity, ownership, business purpose, products, geography, expected activity, and risk.
The institution is trying to understand whom it serves and what normal activity should look like. Ownership information can reveal an individual behind several entities, identify a higher-risk jurisdiction, expose a mismatch with public records, or show that the person presenting the account lacks expected authority.
The information is still point-in-time evidence. It can be incomplete, false, stale, misunderstood, or irrelevant to the actual flow of funds. A good program tests reliability, updates information based on risk, and does not confuse a completed onboarding form with a known customer.
FinCEN changed repetition, not the whole control system
On February 13, 2026, FinCEN issued an exceptive-relief order addressing repeated collection under the CDD rule.
The order allows a covered financial institution to limit identification and verification of a legal-entity customer's beneficial owners to the first account opening, a later point when facts call reliability into question, and situations identified by risk-based ongoing due diligence. FinCEN's updated CDD FAQs explain that using the relief is discretionary.
The relief does not remove ongoing monitoring, suspicious activity obligations, customer-information maintenance, or risk-based review. It changes one repeated account-opening step.
Transaction monitoring asks what happened
Ownership data describes people and entities. Transaction monitoring examines activity.
A monitoring system may compare deposits, withdrawals, wires, counterparties, locations, velocity, cash use, account age, expected behavior, and known risk patterns. Rules or models generate signals. Investigators then decide whether an alert has a reasonable explanation, requires more information, should be escalated, or supports a suspicious activity decision.
That process needs usable data, reasonable scenarios, thresholds, coverage, testing, trained reviewers, enough capacity, and management attention. Knowing an owner does not repair missing transactions or an intentionally constrained monitoring system.
Alert review turns a signal into a judgment
An alert is not a finding of money laundering. It is a prompt for analysis.
The reviewer needs account history, customer context, ownership data, counterparties, related accounts, prior alerts, documentation, adverse information where permitted, and an escalation path. The institution must also manage confidentiality and legal restrictions around suspicious activity reports.
Weak alert review can miss obvious conduct. Overly broad alerting can bury useful signals in volume. The control must balance detection, evidence, capacity, and risk.
Governance decides whether the controls can work
Governance is not the last box on a diagram. It shapes the entire system.
Boards and management allocate funding, set risk appetite, appoint accountable leaders, approve systems, respond to findings, and decide whether growth outpaces control capacity. Independent testing challenges design and operation. Training helps employees recognize and escalate risk. Issue management tracks remediation to evidence rather than promises.
An ownership database can be accurate while the program around it fails. A monitoring engine can be sophisticated while staff cannot review its alerts. A policy can be correct while leaders tolerate exceptions.
What the TD Bank resolution actually showed
Venture Step E048 discussed BOI reporting alongside the October 2024 TD Bank resolution. The case is useful because it shows how several controls can fail together. It should not be used to claim that BOI reporting would have prevented the conduct.
The Justice Department reported that TD Bank entities pleaded guilty and agreed to a criminal resolution totaling about $1.887 billion. DOJ described three money-laundering networks that moved more than $670 million through TD Bank accounts between 2019 and 2023.
FinCEN separately assessed a $1.3 billion civil money penalty. The Office of the Comptroller of the Currency assessed $450 million, imposed a growth restriction, and identified deficiencies involving internal controls, risk management, risk assessment, customer due diligence, customer risk ratings, suspicious activity identification and reporting, governance, staffing, testing, and training. The Federal Reserve announced a separate $123.5 million action and additional remediation requirements.
These were coordinated but distinct legal actions. The amounts should not be casually added and described as one FinCEN fine. Some resolutions include credits and overlapping conduct.
The official records focus on program design, monitoring, reporting, staffing, employee conduct, management knowledge, remediation, and accountability. Ownership information might support parts of an investigation. The public record does not establish that a CTA filing would have stopped the schemes.
Where ownership information adds value
Ownership information can help connect an account to the individuals behind an entity. It can support entity-resolution work across related companies, reveal indirect control, improve customer risk assessment, and give investigators another way to test a customer's explanation.
It can also support law enforcement after a qualifying request and under the CTA access framework. Access, use, re-disclosure, storage, and auditing have legal and security conditions. A beneficial ownership database is not an unrestricted public directory.
Treasury's 2026 National Money Laundering Risk Assessment describes the challenge of identifying people behind foreign shell companies and the role of the tailored CTA implementation. It also notes that large registries can contain inaccurate or fraudulent data. Collection and reliability are separate problems.
A layered system asks each control the right question
Use entity reporting to collect defined ownership and control data for in-scope companies. Use customer due diligence to understand the customer and establish a risk profile. Use transaction monitoring to find activity that departs from rules or expectations. Use alert review and investigation to interpret signals. Use suspicious activity processes to meet reporting duties. Use governance, testing, training, and remediation to keep the system capable.
When one control is treated as the whole solution, gaps become invisible. The better question is not whether beneficial ownership solves money laundering. It is whether the right ownership information reaches the right authorized people, at the right time, inside a system that can act on it.
[[What Beneficial Owner Means Under the Current BOI Rule]] explains the current CTA definition and its scope gate. [[What E048 Got Right and What Changed About BOI Reporting]] preserves the historical episode without turning the TD Bank case into a claim the sources cannot support.
About this page
This systems explainer was developed from E048 and current DOJ, FinCEN, OCC, Federal Reserve, Federal Register, and Treasury sources with AI assistance. It requires AML, banking-law, privacy, legal, source, and founder review before publication. It is general information, not legal, banking, compliance, investigative, or risk-management advice.
Sources
Follow the evidence.
- fincen.gov: boifincen.gov
- fincen.gov: newsroomfincen.gov
- home.treasury.gov: 2026 NMLRAhome.treasury.gov
- youtu.be: fqyzSjGbUloyoutu.be
- justice.gov: td bank pleads guilty bank secrecy act and money laundering conspiracy violations 18bjustice.gov
- federalregister.gov: beneficial ownership information reporting requirement revision and deadline extensionfederalregister.gov
- fincen.gov: fincen assesses record 13 billion penalty against td bankfincen.gov
- federalregister.gov: beneficial ownership information reporting requirementsfederalregister.gov
- ecfr.gov: section 1010ecfr.gov
- congress.gov: PLAW 116publ283congress.gov
- occ.treas.gov: nr occ 2024 116occ.treas.gov
- daltonanderson.ghost.io: boi filing cta what founders need to know nowdaltonanderson.ghost.io
- open.spotify.com: 4q4989dGjvhcgax9VgaN2fopen.spotify.com
- fincen.gov: fincen removes beneficial ownership reporting requirements us companies and usfincen.gov
- federalreserve.gov: enforcement20241010afederalreserve.gov
- fincen.gov: FinCEN Order CCDExceptiveRelieffincen.gov
- fincen.gov: BOI FAQs QA 508Cfincen.gov
- fincen.gov: cdd rule faqsfincen.gov