U.S. Beneficial Ownership Information Reporting Begins

FinCEN’s Compliance Guide provides an exemption qualification checklist.

Reporting Timelines and Requirements

First, you only must file an initial report once. There are no annual reporting requirements. Filing deadlines vary based on when a company was created or registered with the relevant secretary of state.

  • Before Jan. 1, 2024, => Deadline of Jan. 1, 2025
  • Between Jan. 1, 2024, and Jan. 1, 2025, => You have 90 calendar days after receiving notice of the company’s creation or registration to file.
  • On or after Jan. 1, 2025, => Deadline is 30 calendar days from the company’s creation or registration.

While there is no annual filing requirement, filing updates are necessary within 30 days of any changes. Ownership activity subject to change reporting includes registering a new business name, a change in beneficial owners, or a beneficial owner’s name, address, or unique identifying number previously provided.

What Do You Need to Report?

Beneficial ownership reporting must identify the following data.

At the company level, it must report:

  • Company name, both legal and trade (if applicable)
  • Company physical address (no post office boxes)
  • Jurisdiction of formation or registration
  • Taxpayer Identification Number

For each beneficial owner, the following must be reported:

  • Name
  • Date of birth
  • Address
  • Driver’s license, passport, or other acceptable identification

Depending on the situation, there also may be reporting requirements about the company applicant. This is generally a person involved in the creation or registration of the company. The same four pieces of data as for a beneficial owner would need to be provided.

As a general rule, a beneficial owner is someone who controls the company or owns 25 percent or more.

The full definition and all exemptions to whom constitutes a beneficial owner or company applicant can be found here.

No financial information or details about the business operations are required.

How and Where to File

You have the option to file online or via PDF. Filing online can be done through the Beneficial Ownership Information (BOI) E-Filing System on the FinCEN site.

There is no cost to file.

Conclusion and Cautions

While the reporting is simple, the requirements should not be taken lightly. Failure to report could result in civil penalties of up to $500 per day and criminal charges of up to two years imprisonment and a fine of up to $10,000.

The message is this: Don’t wait – and don’t forget to file!

Deepfakes and Social Engineering: The New Face of CEO and CFO Fraud

Hong Kong-based multinational firm that lost $25 million after being duped by a deepfake impersonation of their CFO. Using a realistic video call, the scammer instructed an employee to transfer the funds to a supposedly urgent business acquisition in China. Unfortunately, the employee was unaware of the deepfake and fell victim to the elaborate scam.

In another instance, a cybercriminal impersonated the CFO of a prominent financial institution using a deepfake audio recording. The fraudulent call, which sounded identical to the CFO’s voice, instructed an employee to disclose sensitive client information. Believing it was a legitimate request from the CFO, the employee complied, unintentionally compromising confidential data and exposing the organization to regulatory penalties and lawsuits.

Mitigating the Threat

Organizations must implement robust cybersecurity measures and employee training initiatives to deal with the rising threat of CEO and CFO fraud facilitated by deepfakes and social engineering. Below are some strategies to consider:

  • Employee education and awareness: Companies can hold regular training sessions to educate employees about the dangers of social engineering tactics and how to identify suspicious communications, including deepfake content. They also can encourage vigilance and emphasize the importance of verifying requests, especially those involving financial transactions or sensitive information.
  • Multi-factor authentication (MFA): Businesses are implementing MFA protocols for financial transactions and accessing sensitive data. By requiring multiple verification forms, such as passwords, biometrics or one-time codes, MFA adds an extra layer of security that can help hinder unauthorized access, even if credentials are compromised.
  • Strict verification procedures and zero-trust policy: Organizations can establish strict verification procedures for any requests involving changes to payment instructions or the disclosure of sensitive information. Employees must verify such requests through multiple channels, such as phone calls or in-person meetings.
  • Advanced detection technologies: Companies also might invest in advanced detection technologies capable of identifying deepfake content and other forms of manipulated media. These tools use AI algorithms to analyze multimedia content for signs of tampering or manipulation, helping organizations identify potential threats before they escalate.

As deepfake technology advances, these scams will likely become even more sophisticated and challenging to detect. As Gartner predicts, by 2026, identity verification and authentication solutions such as face biometrics could become unreliable due to AI-generated deepfakes. Therefore, it is crucial to acknowledge the broader implications of deepfakes and social engineering. Regulatory bodies, technology companies, and other concerned institutions must collaborate to develop comprehensive frameworks that address the ethical use of AI, establish clear guidelines for deepfake technology, and enhance overall cybersecurity resilience.

Conclusion

As deepfakes and social engineering tactics continue to evolve, the threat of CEO and CFO fraud is a real challenge for organizations of all sizes. Sophisticated technology and deceptive practices have made it easier than ever for cybercriminals to impersonate executives and manipulate employees into unknowingly facilitating fraudulent activities. Organizations must adopt proactive approaches to mitigate the risks associated with deep fake-enabled fraud and to safeguard their assets and reputations in an increasingly digital landscape.

Optimizing Your Business’ Performance with Capacity Management

Municipal Bond Outlook for 2024

Averting a Government Shutdown, and Reinforcing Air Travel Infrastructure, Weather Alert Systems and National Defense Initiatives

Understanding How Variances Vary

How to be Your Tax Pro’s Favorite Client this Tax Season

New Email Deliverability Rules: Reaching Gmail and Yahoo Subscribers in 2024

Gmail and Yahoo are implementing stricter email deliverability rules to combat spam and protect user inboxes. This announcement was made by both Google and Yahoo on Oct. 3, 2023, indicating a united effort to enhance email security.

Initially intended for bulk senders (marketers, businesses, and individuals) sending more than 5,000 emails a day, it also applies to senders who send regular emails to their subscribers and meet criteria as per the updated Google Email Sender Guidelines.

Although it may sound strict, there is nothing to worry about. By understanding the rules and adopting best practices, you can ensure your messages land safely in your subscribers’ inboxes.

Key Rules to Remember

  • Domain Authentication is Paramount – Implement security protocols, including Domain Keys Identified Mail (DKIM), Sender Policy Framework (SPF), and Domain-based Message Authentication, Reporting and Conformance (DMARC) to verify your sending domain and prevent spoofing. DKIM digitally signs emails for verification. SPF confirms that sending domain authorization prevents spammers from impersonating and sending messages from your domain, while DMARC specifies the handling of unauthenticated emails. Basically, these protocols confirm your sending domain as legitimate and not from a malicious email spammer or phisher. Although these protocols have been previously considered best practices, many senders have unknowingly or knowingly bypassed them. Some have ignored them, considering them challenging to deploy. Hence, the step to enforce them as mandatory requirements.
  • One-Click Unsubscribe is Mandatory – Make it easy for subscribers to opt out with a clear and accessible unsubscribe link in every email. The unsubscribe requests must be honored within 2 days. You can add an unsubscribe button to the header, whereby recipients can unsubscribe easily instead of marking an email as spam. This will ensure email deliverability is not harmed. Allowing easy unsubscribe also offers the benefit of having an email list of quality subscribers.
  • Maintain a Low Spam Complaint Rate – Keep your spam complaints below 0.3 percent (ideally, this should be below 0.1 percent) to avoid landing in the spam folder or getting blacklisted. Failing to comply with the spam complaint threshold could put the sending domain under review, restricting your email reach.

Beyond the Rules: Deliverability Best Practices

  • Clean and Permission-Based Email Lists – Send only to subscribers who have opted-in, and keep your list clean by removing inactive users and bounced addresses.
  • Personalization and Segmentation – Tailor your emails to individual preferences and segment your list based on demographics, interests, or engagement levels.
  • Mobile-Friendly Design – Ensure your emails are optimized for mobile devices, as most users check their email on smartphones.
  • Subject Line Optimization – Craft compelling and relevant subject lines that invite users to open your emails.
  • Craft High-Quality and Engaging Content – Provide relevant and valuable information to maintain audience interest and avoid being marked as spam.
  • Avoid Spammy Tactics – Avoid excessive images, ALL CAPS text, and misleading content.
  • Engagement and Reputation – Encourage engagement by asking questions, including social media links, and providing valuable content. Positive user interactions improve the sender’s reputation.

Consequences of Ignoring the Rules

Failing to adhere to the new rules can have severe consequences, including:

  • Emails Landing in Spam Folders – Your messages may never reach your intended audience.
  • Domain or IP Blacklisting – Repeated violations can lead to your domain or IP address being blocked by email providers.
  • Decreased Sender Reputation – This can negatively impact your future deliverability rates, affecting domain reputation and overall business performance.

Adapting to the New Landscape

Although these requirements may seem overwhelming, they represent an opportunity to improve your email marketing practices and build stronger relationships with your subscribers. By prioritizing sender authentication, clear communication, and valuable content, you can ensure your emails reach the right inboxes and achieve your marketing goals.

Remember, staying informed about email deliverability best practices and adapting to evolving regulations is crucial for successful email marketing in today’s landscape.

Your February Financial To-Do List

Consumer Reports. On this site, you’ll find all the good stuff: cars, home and garden supplies, appliances, electronics, and more.

These are just a few of the items you can put on your financial to-do list. All it takes is carving out some time and getting started. Once you get going, you’ll probably make more progress than you ever dreamed.

Sources

https://www.consumerreports.org/personal-finance/february-financial-to-do-list/

Defining Materiality in Accounting