Credit-union compliance teams should not translate FinCEN's new beneficial-ownership reporting relief into a blanket stop-work order. The August 11 final rule changes what U.S. companies and people report to FinCEN under the Corporate Transparency Act; it does not repeal the separate Customer Due Diligence Rule that governs how covered financial institutions identify and verify beneficial owners of legal-entity customers.

FinCEN announced on August 11 that U.S. companies and U.S. persons will be permanently exempt from reporting beneficial ownership information to the agency. The rule also removes update and correction duties for U.S. persons with FinCEN identifiers. FinCEN said it will delete previously reported information from U.S. persons that is now exempt.

Foreign entities that meet the rule's definition of a reporting company remain subject to narrower reporting duties for non-U.S. beneficial owners and company applicants. The final rule becomes effective when published in the Federal Register.

Two rules, two different obligations

The distinction matters because “beneficial ownership reporting” describes two separate processes. The Corporate Transparency Act reporting rule tells certain companies what they must submit to FinCEN's national database. The CDD rule tells covered financial institutions what they must collect and verify about legal-entity customers as part of their own anti-money-laundering programs.

FinCEN addresses the potential confusion directly in the final rule. It says the reporting rule and CDD rule serve different purposes and arise under different legal authorities. FinCEN describes CDD compliance as an important part of a covered institution's AML/CFT program and says the new exemptions should not be read as reducing the value of beneficial-ownership information.

The current CDD rule page still requires covered institutions to identify and verify customers and applicable beneficial owners, understand the nature and purpose of customer relationships, build risk profiles and conduct ongoing monitoring. The ownership test generally covers an individual with 25% or more of a legal entity and one individual who controls it, subject to exclusions and exemptions.

The February relief still defines the operating process

Credit unions did receive separate CDD relief earlier this year—but it was narrower than ending beneficial-owner collection. In February, NCUA explained that FinCEN's exceptive order removed the requirement to identify and verify the owners of an existing business customer every time that customer opens another account.

A credit union may instead limit identification and verification to three circumstances: when the legal entity first opens an account; when facts call previously obtained information into question; and when the credit union's risk-based ongoing due-diligence procedures require it. Other BSA/AML duties, including ongoing monitoring, suspicious-activity reporting and risk-based maintenance of customer information, remain.

That means an instruction such as “U.S. companies no longer report BOI” is accurate for the CTA database but incomplete for frontline, onboarding and compliance operations. A business member may be exempt from filing with FinCEN while the credit union still has to collect and verify ownership information under its CDD procedure.

What credit unions should change now

First, separate the rule references in policy, training and technology. Search procedures, business-account scripts, knowledge bases and vendor rules for language that treats the CTA reporting rule and the CDD rule as interchangeable. Label the source of each requirement so a future change to one does not accidentally switch off the other.

Second, test the business-account workflow. Use one new legal-entity customer, one existing customer opening an additional account and one customer whose ownership information may no longer be reliable. Confirm that the workflow requests information only when the current CDD rule and the credit union's risk-based procedure call for it—and that employees can explain the difference without telling a member to file an obsolete CTA report.

Third, review automated rules and vendor content. Business-onboarding platforms, compliance assistants and employee copilots may contain outdated prompts, links or decision logic. Assign an owner to verify rule citations, update effective dates and retain evidence showing what changed. The same discipline applies to external member content: remove filing instructions that FinCEN now says are obsolete, but do not delete accurate CDD disclosures or certifications.

Fourth, wait for the next CDD action before redesigning the control. FinCEN says it is still legally required to modify the CDD rule and intends to address database access, reconciliation, burden and supervisory-expectation questions in future work. Until that happens, compliance teams should treat proposals and anticipated revisions as planning signals—not current authority.

The practical decision is therefore narrow: update CTA-related communications now, preserve the current CDD control, and document the boundary between them. Credit unions can use the AI vendor due-diligence checklist to test whether compliance systems maintain authoritative rule sources, and the AI acceptable-use policy guide to keep employees from relying on uncited generative-AI answers for regulatory changes.