Skip to main content
All Insights

Who Owns This Company? Treasury Apparently Doesn't Care

GovIntegrityAugust 13, 2026
Who Owns This Company? Treasury Apparently Doesn't Care

This week, the Treasury Department made permanent one of the most consequential rollbacks in recent fraud-prevention history. On Tuesday, FinCEN issued a final rule permanently exempting American companies and individuals from reporting who owns them, and announced it will delete the ownership data those companies already filed.

Treasury Secretary Scott Bessent framed the move as regulatory relief, calling it a win for common sense and small business owners. The Small Business Administration estimates the exemption will save businesses $6.7 billion in compliance costs over the next decade. FinCEN’s own figure puts the ongoing savings at roughly $9 billion a year.

But what’s the cost of not knowing who's behind a company? Shell companies have concealed Iranian government control of a Manhattan skyscraper for decades, laundered cartel drug proceeds, and served as the paperwork behind billions in fraudulent PPP loans.

For nearly twenty years, the Iranian government hid its ownership of 650 Fifth Avenue behind a chain of shell entities running through the Alavi Foundation, Assa Corporation, and state-owned Bank Melli, funneling rent from a 36-story Manhattan office tower back to Tehran until federal prosecutors finally forced its forfeiture. The Sinaloa Cartel used a network of Wyoming-incorporated shell companies to launder more than $16 million in drug proceeds in 2023 alone, moving the money into U.S. bank accounts to buy aircraft and vehicles before wiring it south. And hundreds of companies registered to a single Sheridan, Wyoming storefront collected tens of millions of dollars in Paycheck Protection Program loans, some tied to outright fraud indictments, others simply invisible to anyone trying to determine who actually stood behind them.

It’s true that the Corporate Transparency Act created a new federal filing requirement for millions of small businesses that pose no meaningful financial-crime risk. And it’s true that the rollout was confusing, and the government could have done far more to streamline compliance for legitimate businesses instead of burying them under it. Fixing the implementation of the law was necessary, eliminating its value entirely is reckless.

Why is beneficial ownership information necessary?

Beneficial ownership addresses one of the most basic questions in fraud prevention. Who is actually behind this company?

I wrote last year about the corporate opacity baked into Wyoming law. An LLC can be formed there remotely, cheaply, and in minutes, while disclosing almost nothing about the people behind it. A registered agent can list its own address as the official home of hundreds or thousands of companies, and Wyoming entities have turned up in drug trafficking cases, money laundering schemes, cybercrime networks, and pandemic fraud. One storefront in Sheridan WY alone has served as the registered address for hundreds of thousands of companies, some linked to suspected North Korean financial and cyber operations.

Wyoming is not an outlier so much as a preview. The Corporate Transparency Act was supposed to solve this problem nationally, requiring companies to tell FinCEN who actually owned or controlled them rather than leaving investigators dependent on whatever scraps individual states chose to collect. Treasury has now abandoned that approach for domestic companies entirely.

Treasury itself identified this vulnerability. The 2020 National Strategy for Combating Terrorist and Other Illicit Financing named the lack of a beneficial ownership requirement at the time of company formation as the single most significant vulnerability in the American financial system, ahead of everything else on the list. More than two million corporations and LLCs are formed in the United States every year, and the Strategy described investigators chasing ownership through layered corporate structures the way you’d peel apart a set of nesting dolls, each entity unwound revealing another one underneath. The government spent years documenting
the gap it just decided to reopen.

The timing of the rollback comes just three months after GAO examined Treasury’s original 2025 exemption and warned that state requirements vary too widely to fill the gap. GAO recommended Treasury figure out how to close it, but Treasury disagreed with the recommendation and three months later, it made the exemption permanent. And now it plans to erase the ownership data already on file.

Treasury’s position is that law enforcement has other ways to identify the people behind domestic companies. This is generally true, the Secretaries of State collect this information, but they do so through a patchwork of highly variable requirements, and some—like Wyoming—require no transparency at all. Treasury has not said which sources it believes will provide the transparency the CTA was intended to provide.

Inspectors general told the agency that identifying beneficial owners from existing federal, state, and commercial records is often difficult, and that opaque ownership structures create risk across procurement, grants, and eligibility programs government-wide. The United States does have enormous amounts of corporate data, scattered across state registries, IRS records, SAM filings, bank records, and commercial databases, much of it self-reported, some of it identifying officers or registered agents rather than actual owners, none of it connected. Investigators are left reconstructing corporate identity after the fraud has already happened, which is exactly why the CTA was passed to begin with.

Treasury’s clever sleight of hand

Jim Richards, one of the nation’s most knowledgeable financial crime experts, has spent the better part of a decade tracking beneficial ownership policy in more granular detail than almost anyone in the field. His read on this final rule is characteristically direct: Treasury’s arguments are, in his words, bullshit. Richards points out that the CTA instructed Treasury to minimize the burdens on reporting companies associated with collecting their ownership information. FinCEN is now citing that same language to justify this rule, arguing that exempting 99 percent of reporting companies satisfies Congress’s instruction to minimize their burden.

That argument doesn’t hold up. Minimizing a burden means making an existing obligation less costly to comply with. FinCEN didn’t do that. It redefined which companies count as “reporting companies” in the first place, then declared the burden minimized because the newly excluded companies no longer have one. The obligation itself didn’t get easier, it just stopped applying to almost everyone who used to have it.

Richards also flags the deeper problem hiding underneath that maneuver. The CTA lets the Treasury Secretary exempt specific classes of entities from reporting. FinCEN’s position is that “domestic reporting companies,” all 32 million of them, qualify as an exemptible class. But foreign reporting companies are just as much a “class of entities” under that same logic. If the Secretary can exempt one class down to nothing, there’s no statutory reason he couldn’t do the same to the other, and effectively repeal an act of Congress through the definitions section rather than through Congress itself. That is how a reporting regime that took years to legislate can be unwound in an afternoon by redefining a word.

Corporate identity is program integrity infrastructure

Across government, agencies have started taking identity seriously for people applying for benefits, verifying that an applicant exists and that the person submitting the application is who they claim to be. That progress rarely extends to the companies receiving government money, even though corporations have identities too. An LLC can get an EIN, open bank accounts, sign contracts, receive federal payments, and apply for loans, building every outward marker of a legitimate enterprise, while the humans behind it stay invisible.

Fraud networks understand the value of that gap well. A shell company inserts a layer between the perpetrator and the transaction, and stacking multiple LLCs, registered agents, nominee owners, and jurisdictions turns that gap into a maze investigators have to navigate one entity at a time. That structure is useful for laundering money and for defrauding government. Shell companies provided ready-made vehicles for fraudulent PPP and EIDL loans during the pandemic, and they continue to provide these vehicles for disaster loans and grants and a slew of everyday government grant and loan programs.

In procurement, opaque ownership can hide relationships between
supposedly competing bidders. In grant programs, it can mask affiliated organizations. In health care, it can conceal that a network of nominally independent providers traces back to the same people.

Beneficial ownership is more than an anti-money-laundering issue, it is program-integrity infrastructure. Treasury has dismantled the federal government’s clearest version of it with nothing to replace it.

Treasury owes the country an answer

I don’t mean to argue here that the Corporate Transparency Act was well designed. But the intention was well-placed and if filing separately with FinCEN was too cumbersome for millions of small businesses, the fix was to redesign the collection mechanism, not eliminate the data.

States already collect information when companies form. The IRS issues EINs. Banks run customer due diligence. Businesses seeking federal contracts register in SAM. A modern system would connect those existing processes instead of asking legitimate owners to file the same information yet again, and it would aim higher than the CTA did. The original database relied on companies reporting their own ownership, and a criminal willing to set up a fraudulent company is usually just as willing to lie about who owns it. The real goal should have been a system that can verify whether a company exists, who controls it, who benefits from it, and whether the same people are running dozens of apparently unrelated entities. Treasury chose not to build that system and it deleted the one it already had started building.

This is familiar pattern. It is easy to create an identity and move money, and expensive and mostly fruitless to reconstruct what happened after the money is gone. Fragmented data systems persist because piecing the fragments together after the fact is politically easier than fixing the fragmentation itself.

When a fraud-prevention control creates friction for legitimate users,
the instinct in Washington is almost always to remove the control
rather than redesign it.

Small businesses are right to expect government to minimize unnecessary compliance costs, and taxpayers are equally entitled to expect government to know who it is doing business with and who ultimately receives public money. Both goals are achievable at once. What should be unacceptable is eliminating one of the government’s few mechanisms for identifying the people behind American companies without even trying to put in place something better to take its place.

In May, GAO told Treasury that exempting American companies from beneficial ownership reporting had created a gap that criminals could exploit and asked Treasury to determine how to close it. Treasury just decided to punt. Make no mistake, this is not a victory over a burdensome regulation. Treasury owes the country the answer it dodged three months ago. If beneficial ownership reporting is gone, how exactly will the government know who is behind a company?

Until there’s a real answer, this decision simply restores a vulnerability criminals have learned to exploit.


Article first posted on GovIntegrity.