FinCEN Ends Beneficial Ownership Reporting (08/28/2026)
- › FinCEN has permanently ended beneficial ownership information reporting for US companies, though parts of the framework still apply.
- › The DOJ has announced priorities signalling renewed focus on white collar and criminal fraud enforcement.
- › American Vision Partners settled data breach litigation for $1.75 million.
- › Azul Vision settled a HIPAA right of access case for $50,000.
- › California SB 253 has an updated compliance timeline that companies need to plan against.
Two enforcement signals point in opposite directions this week, and both are worth planning against. FinCEN has permanently ended beneficial ownership reporting, which removes an obligation, while the Justice Department has named a renewed focus on white collar and criminal fraud, which adds exposure. The net is less filing and more scrutiny.
Top 5 Critical Compliance Alerts
1. FinCEN Permanently Ends Beneficial Ownership Reporting
FinCEN has permanently ended the beneficial ownership information reporting requirement for US companies, though practitioners note that parts of the surrounding framework continue to apply in 2026. We carried the beneficial ownership saga as concluded on August 19, and this is the durable version of that. Harbor Compliance
Operator Note: Confirm what still applies before you retire the process, because the reporting obligation ending is not the same as the underlying records ceasing to matter. The specific risk is a company that built beneficial ownership collection into onboarding, switches it off entirely, and later needs the data for a bank or an acquirer who never stopped asking.
2. The DOJ Signals Renewed White Collar and Fraud Enforcement
The Justice Department has announced priorities pointing to renewed emphasis on white collar and criminal fraud enforcement, following the five priority areas from its National Fraud Enforcement Division that we carried on Wednesday. JD Supra
Operator Note: Two announcements in three days from the same department is a deliberate signal rather than a coincidence of publishing schedules. Read them together and map both against your revenue lines, because the useful output is a short list of where your controls were built for accounting accuracy rather than for fraud detection.
3. Two Eye Care Settlements, Two Very Different Numbers
American Vision Partners settled data breach litigation for $1.75 million, while Azul Vision settled a HIPAA right of access case for $50,000. The gap between them is instructive: one is civil litigation over a breach, the other is a regulator penalising a failure to give a patient their own records. HIPAA Journal
Operator Note: Right of access cases are the cheapest enforcement to avoid and the easiest to trip, because they turn on a request your front desk handled badly rather than on any security control. If you hold patient records, the question is who receives a records request, what the deadline is, and whether anybody has ever tested that path. HIPAA Journal
4. California SB 253 Has an Updated Compliance Timeline
The climate disclosure requirements under California SB 253 have an updated compliance timeline, with specific steps companies should be taking now. The timeline moved, and the underlying obligation did not. JD Supra
Operator Note: Climate disclosure sits with finance and sustainability, and the data collection underneath it usually runs through operational systems that security owns. If your organization is in scope, find out now who is responsible for the integrity of the numbers, because a disclosure regime creates an assurance problem the moment the figures become legally consequential.
5. CMS Gains Exclusion Authority
The Centers for Medicare and Medicaid Services has gained exclusion authority, which healthcare providers should be watching closely. Exclusion is the enforcement tool with the most direct effect on whether an organization can continue operating. JD Supra
Operator Note: A monetary penalty is survivable and exclusion from federal healthcare programs frequently is not, which makes this a change in kind rather than degree. Any provider should know which conduct triggers it and who in the organization can cause it.
Additional Compliance Alerts
Regulatory Updates
- A $250 million HSR warning for corporate dealmakers: Antitrust filing failures priced at a level that reaches the board. JD Supra
- The DOL has proposed a new electronic disclosure safe harbor for group health plans: JD Supra
- The EEOC has proposed rescinding EEO-1 reporting: Another reporting obligation potentially coming off the books. JD Supra
Governance
- The Cloud Security Alliance argues zero trust has lessons for AI watermarking: Cloud Security Alliance
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.