The FinCEN CTA Rollback: What the Elimination of Domestic BOI Reporting Means for Grant Oversight
- Matthew Merkel
- 3 days ago
- 6 min read

Domestic entities and U.S. persons are no longer required to report Beneficial Ownership Information (BOI) under the Corporate Transparency Act (CTA) following a final rule published in press release SB0603 by U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN). Furthermore, FinCEN announced it will permanently purge all previously submitted U.S. beneficial ownership data from its central registry.
The FinCEN rollback primarily provides administrative relief to domestic for-profit entities—including small contractors, vendors, and non-501(c) subrecipients. (Formal 501(c) tax-exempt non-profits and government authorities were already exempt under original statutory exclusions.)
“Today’s action is a victory for common sense and American small businesses,” said Secretary of the Treasury Scott Bessent. “President Trump promised to cut red tape, and this final rule delivers. Treasury is eliminating a burdensome reporting requirement for millions of law-abiding business owners without compromising our national security.” While domestic reporting has ended, foreign entities registered to do business in the U.S. remain subject to BOI disclosure requirements for foreign individuals.
Agencies can still access domestic ownership information through alternative pathways:
Investigative & Public Records: Government agencies can access ownership details through subpoenas, annual reports, and state-level articles of organization (though disclosure rules vary by state).
Mandatory Applicant Disclosures: Pass-Through Entities (PTEs) can require grant subrecipients and contractors to disclose natural-person owners, parent entity hierarchies, and control structures as a mandatory condition of award funding.
Third-Party Cross-Referencing: PTEs can screen applicants against SAM.gov, state ethics records, and public filings to expose hidden shell companies and conflicts of interest.
BOI Reporting Policy Rationale: Weighing Administrative Relief Against Oversight Vulnerabilities
The federal government frames the permanent elimination of domestic BOI reporting and data purge not merely as deregulatory relief, but as a strategic shift toward risk-based enforcement. From the Treasury Department's perspective, universal reporting forced law enforcement and regulatory agencies to process data on more than 32 million low-risk domestic small businesses, diverting critical investigative resources away from high-priority, complex financial crime threats.
By narrowing the scope, Treasury asserts it can better target enforcement on high-risk entities while delivering key operational benefits to legitimate domestic enterprises:
Shift to Risk-Based Enforcement: Concentrates federal analytical resources on high-risk foreign entities and cross-border money laundering rather than broad-brush monitoring of domestic small businesses.
Reduced Compliance Costs: Eliminates millions of collective hours and legal expenses for small contractors, non-profits, and subrecipients.
Mitigation of Legal Liability: Protects small subrecipients without dedicated legal teams from daily civil fines ($500+/day) or criminal penalties caused by inadvertent administrative errors.
Enhanced Data Privacy: Deleting stored Personally Identifiable Information (PII) eliminates risks associated with federal database breaches, leaks, or government overreach.
Industry groups (including the American Institute of Certified Public Accountants and National Federation of Independent Business) noted that small entities faced upfront compliance costs between $500 and $2,500 per entity to interpret complex legal definitions of "substantial control." (By comparison, FinCEN’s own initial estimates placed basic filing costs around $100 per business.
Conversely, oversight coalitions, public integrity groups, and law enforcement associations evaluate the regulatory change through a different risk lens:
Lack of Empirical Cost-Benefit Analysis: Organizations like the Financial Accountability and Corporate Transparency (FACT) Coalition emphasize that Treasury provided no empirical proof that small-business administrative savings outweigh the public cost of undetected grant fraud, double-dipping, and money laundering.1
Impact on Small Businesses: In public comments to FinCEN, the Main Street Alliance argued that transparent ownership reporting levels the playing field for legitimate small businesses by curbing corrupt actors who exploit anonymous shell entities.2
Erosion of Historical Audit Trails: Law enforcement associations argue that purging existing databases actively destroys historical audit trails required to prosecute multi-year procurement fraud.3 4
The Compliance Gap: Executive Directives vs. Grant Integrity Mandates
Though framed as administrative relief for small businesses, FinCEN’s domestic BOI rollback creates operational friction with Executive Order 14395 (Establishing the Task Force to Eliminate Fraud), which demands strict identity verification and enhanced data sharing across public benefit and grant programs.
By purging domestic ownership data, Treasury removes a centralized federal baseline that PTEs could otherwise leverage to screen subrecipients. This creates significant hurdles under 2 CFR § 200.332 (Uniform Guidance), which statutorily mandates that PTEs evaluate subrecipient risk profiles—including financial stability, management structures, and fraud potential—prior to disbursing federal awards.
Foreign vs. Domestic Entities: A Complex Risk Picture
FinCEN’s updated rule restricts reporting companies strictly to foreign-formed entities registered in the U.S. However, watchdogs like Transparency International U.S. and Global Financial Integrity highlight critical carve-outs: foreign entities no longer need to report U.S. company applicants or disclose U.S. persons exercising control over foreign pooled investment vehicles.5 When a U.S. person holds managerial control, foreign elites or illicit actors can still use U.S. nominee managers to shield their equity interests from view.
Furthermore, while concern over foreign bad actors is valid, particularly for homeland security, government audit data demonstrates that the overwhelming majority of grant and public benefit fraud involves domestic entities and U.S. citizens:
Pandemic Program Abuse: Massive grant schemes—such as the $250 million Feeding Our Future case in Minnesota or widespread pandemic relief loan fraud—were executed primarily by domestic actors establishing local LLCs and front companies.
False Claims Act (FCA) Enforcement: Of the record $6.8 billion in FCA recoveries achieved by the Department of Justice in FY 2025, combined domestic healthcare and defense sector cases alone accounted for over $5.7 billion (roughly 84%). The majority of defendants in these civil actions were domestic U.S. corporations, healthcare systems, and local contractors—underscoring that federal fraud exposure is predominantly domestic.6
The Pervasiveness of Domestic Shells: Fraudsters rarely need foreign corporate structures to exploit federal awards; registering a local domestic LLC has historically provided sufficient anonymity to submit false invoices, obscure self-dealing, and violate 2 CFR Part 200 (Uniform Guidance) rules.
Heightened Liability for Pass-Through Entities (PTEs)
It is important to distinguish FinCEN’s statutory role from federal grant administration: FinCEN’s core mandate is anti-money laundering and financial intelligence (pursuant to 31 U.S.C. § 5311 et seq.), whereas federal grant integrity has always fundamentally relied on agency-level procurement controls under the Uniform Guidance (2 CFR Part 200, Subparts D and E).7
Consequently, while FinCEN’s regulatory rollback changes how corporate data is collected at the national financial level, it does not alter a Pass-Through Entity’s legal duties or liability under federal grant rules:
Direct Responsibility: Under 2 CFR § 200.332, state agencies and other Pass-Through Entities (PTEs) remain statutorily responsible for subrecipient compliance. If a subrecipient operates as a fraudulent shell company, the federal awarding agency holds the prime grantee—not the shell entity—primarily liable for fund clawbacks.
False Claims Act (FCA) Exposure: Liability under 31 U.S.C. § 3729 extends to "reckless disregard." Disbursing funds to an unverified shell company without basic due diligence can be classified as reckless disregard. PTEs cannot cite the absence of a federal FinCEN database as a legal defense.
Single Audit Findings: Unaddressed subrecipient fraud leads to severe internal control audit findings (§ 200.303) and cost disallowances, forcing state agencies and other pass-through agencies to repay funds using non-federal operating dollars.
Essential Internal Controls for Pass-Through Entities
Because federal clearinghouses no longer track domestic beneficial ownership centrally, the burden of corporate due diligence shifts directly onto Pass-Through Entities. To maintain compliance and protect public funds, PTEs should consider implementing a five-pillar pre-award internal control framework:
Mandatory Pre-Award BOI Self-Attestations: Require prospective subrecipients and contractors to submit a sworn disclosure identifying every natural person (a living human being, as distinguished from a corporate entity) holding 10% or greater ownership interest or operational control, alongside parent/affiliate hierarchies.
Multi-Layered Registry Cross-Verification: Audit state Secretary of State corporate filings for shell company markers (e.g., entities formed immediately prior to a grant solicitation, commercial mailboxes listed as primary addresses, or shared registered agents among competing bidders). However, because secrecy-friendly states like Delaware, Wyoming, and Nevada do not require LLCs to disclose natural-person beneficial owners, PTEs cannot rely on state registries alone to satisfy 2 CFR § 200.332 risk assessment mandates.
Operational Capacity Verification: Require proof of physical business operations (lease agreements, utility bills, matching W-9 tax IDs, and direct bank verification letters).
Quantitative Pre-Award Risk Scoring: Build risk-assessment matrices under 2 CFR § 200.332 that flag complex holding structures, recent ownership shifts, or foreign management ties for enhanced pre-award review.
Contractual Clawbacks & Special Award Conditions: Insert 2 CFR § 200.208 specific conditions for higher-risk subrecipients—such as cost-reimbursement payment structures and mandatory transaction receipt reviews prior to fund disbursement.
Protect Your Grant Funding with Expert Oversight
Navigating shifting regulatory requirements—from evolving Uniform Guidance mandates to heightened subrecipient risk—demands robust, proactive internal controls. The Vander Weele Group provides turnkey grants monitoring, pre-award subrecipient risk assessments, internal control evaluations, and robust monitoring frameworks designed to safeguard public funds and prevent audit findings.
To strengthen your grant oversight infrastructure or learn how our Guardrails 360™ platform can insulate your agency from risk, contact our team at www.vanderweelegroup.com or email us at info@vanderweelegroup.com.
1 FACT Coalition, FACT Joins Chorus of Opposition to Treasury’s Gutting of Landmark Financial Transparency Law, May 28, 2025
2 Main Street Alliance (MSA) CTA IFR public comment
3 National District Attorneys Association (NDAA) Treasury Rule CTA comment
4 National Narcotic Officers’ Association Coalistion (NNOAC) CTA Letter
5 U.S. Code of Federal Regulations, 31 CFR § 1010.380(a)(2)(iii), Reports of Beneficial Ownership Information
6 U.S. Department of Justice, Fraud Recovery Statistics, October 1, 1982–September 30, 2024
7 Office of Management and Budget, Uniform Guidance, 2 CFR § 200.303 (Internal Controls), § 200.318 (General Procurement Standards), and § 200.332 (Requirements for Pass-Through Entities)




Comments