Skip to main content
← DossiersIncorporation Architecture

Why the Bank Says No

Reviewed by Ali Gulzari, CPA, EA··9 min read·1,925 words

The entity is formed, the EIN letter is in hand, and the bank application still comes back declined, or worse, sits in review for six weeks and then goes quiet. Nothing about that outcome means the paperwork was wrong. It usually means the file did not answer the questions a financial institution is required to ask, in the order it is required to ask them, before the entity's location or industry ever entered into it.

What the law actually requires the bank to collect

Two federal rules sit underneath every business account opening at a U.S. bank. The Customer Identification Program rule at 31 CFR §1020.220 requires the bank to obtain, at minimum, the entity's name, address, taxpayer identification number, and date of formation, and to verify the identity of the individual opening the account using documentary or non-documentary methods. The Customer Due Diligence rule at 31 CFR §1010.230, often called the beneficial ownership rule, requires the bank to identify and verify beneficial owners under two separate prongs at the time a new account is opened for a legal entity customer: each individual who directly or indirectly owns 25% or more of the equity interests, and a single individual with significant responsibility to control, manage, or direct the entity, sometimes called the control prong.

Those two prongs can point at the same person or at different people. A single-member LLC wholly owned by one foreign individual usually has that person satisfying both prongs at once, which simplifies the form but does not reduce the amount of verification the bank must complete. In February 2026, FinCEN granted covered institutions exceptive relief from re-collecting and re-verifying beneficial ownership information at every subsequent account opening for a customer the bank has already identified, which changes how often the question is repeated for an existing relationship. It does not change what is required the first time.

The documentary set an applicant should expect to produce

Requirements vary by institution, but the file that gets approved on the first pass tends to contain the same core documents regardless of which bank is reviewing it.

DocumentWhat it establishes
Certificate of formation or articles of organization, state-certifiedThe entity exists and is in good standing in its formation state
Operating agreement or bylawsOwnership percentages, management structure, and who has authority to act for the entity
EIN confirmation notice (CP 575) or an EIN verification letter (147C)The taxpayer identification number the bank must record under the CIP rule
Passport for each beneficial owner and for the individual opening the accountIdentity verification for natural persons behind the entity
Proof of foreign residential address, such as a utility bill or national IDAddress verification where the owner has no U.S. address of their own
A written explanation of the business, sometimes called a business narrativeWhat the entity does, who its customers are, and how funds will move through the account

An ITIN is not a federal requirement to open a business account for the entity, because the account is opened in the entity's name using the entity's EIN, not the individual owner's tax number. Some institutions ask for one anyway as an internal risk-management preference, which is a policy choice on their part rather than a legal floor. IRS Form W-7 and its instructions govern ITIN applications for owners who need one for a different reason, such as filing a personal U.S. return.

Why "no U.S. presence" applications get declined on policy, not law

No federal statute prohibits a bank from opening an account for a foreign-owned entity with no U.S. address, no U.S. resident owner, and no U.S. employees. What happens instead is that individual institutions set their own risk appetite within the CIP and CDD framework, and many set it more conservatively than the law strictly requires, because a foreign-owned entity with no U.S. footprint is harder for the bank's own compliance function to monitor and more expensive to service under its Bank Secrecy Act examination obligations. A bank examined under BSA/AML standards is not penalized for declining a marginal account; it is scrutinized for approving one it cannot adequately monitor. That asymmetry pushes many retail branch networks toward a blanket policy against non-resident applicants with no U.S. tie, regardless of how clean the underlying documentation is.

This is a business decision layered on top of the regulatory floor, not a statement that the floor itself forbids the account. It is why the same file, unchanged, can be declined at one institution and approved at another: the underlying law is identical, the institutional risk tolerance is not.

Banks, fintech providers, and payment processors are not the same regulatory animal

A chartered bank holds a bank charter, is a direct member of the Federal Reserve System or otherwise directly regulated, and its deposits are FDIC-insured up to the applicable limit. A fintech or "neobank" product is typically a technology layer on top of a partner bank; the account is legally held at the partner bank, the fintech company is not itself a depository institution, and the CIP and CDD obligations described above are performed by, or on behalf of, the partner bank under its own BSA program even though the applicant experiences the onboarding flow as belonging to the fintech brand. A payment processor or merchant acquirer, by contrast, is not generally holding deposit accounts at all; it is settling card and payment transactions and is separately subject to card network rules and, in many states, money transmitter licensing, and it runs its own onboarding review focused on transaction risk rather than deposit relationship risk.

Chartered bankFintech / neobankPayment processor
Who holds the fundsThe bank itselfA partner bank, under the fintech's brandGenerally not a deposit relationship; funds settle and move through
Deposit insuranceFDIC, subject to limitsPass-through FDIC coverage via the partner bank, subject to conditionsNot applicable
Primary regulatory lensBank Secrecy Act / CIP / CDD as a depository institutionCIP / CDD performed under the partner bank's programCard network rules, state money transmitter licensing, payments compliance
Typical documentation depth for a foreign-owned applicantHighest; often requires in-person or extensive remote verificationModerate; streamlined but still collects the same core CIP/CDD fieldsVariable; often reviews transaction patterns as heavily as entity documents

None of these categories is inherently more "foreign-friendly" than another as a matter of law; the difference in practice comes from each institution's own policy and risk model, which changes over time and by product line. This article describes how the categories function generally. It does not recommend or promise approval from any specific institution or product.

Sanctions screening sits underneath all of it

Separate from the CIP and CDD rules described above, every U.S. financial institution screens applicants and beneficial owners against the sanctions lists maintained by the Treasury Department's Office of Foreign Assets Control, most prominently the Specially Designated Nationals and Blocked Persons list, under the authority collected at 31 CFR Chapter V. This screening happens automatically and is not something an applicant does or requests; it is simply run against the names and, where available, dates of birth and nationalities on the application. A name that produces a false positive against a common name on a sanctioned-persons list, which happens more often with common transliterations of names from some regions than others, can stall a file for additional manual review even where nothing about the applicant is actually connected to the flagged party. Providing complete identity documents, including a full legal name exactly as it appears on a passport and a clear date of birth, reduces the odds of an ambiguous match reaching a human reviewer in the first place.

What happens after the account opens

CIP and CDD are not one-time events even though the initial verification happens once. Financial institutions maintain an ongoing monitoring obligation under their Bank Secrecy Act compliance programs, watching account activity against the profile described in the business narrative at onboarding. A foreign-owned entity that told the bank it would process modest domestic invoicing and then begins receiving large, frequent international wires from jurisdictions never mentioned at opening is likely to trigger enhanced due diligence: a request for supporting documentation on specific transactions, a request for updated beneficial ownership confirmation, or in some cases a temporary hold on funds while the bank resolves the discrepancy. This is not evidence of suspicion about the owner personally; it is the monitoring system doing what CDD requires it to do, comparing observed activity against the expected profile and asking questions when the two diverge. Keeping the bank informed when the nature or volume of the business changes materially, rather than waiting for the bank's monitoring system to notice on its own, generally produces a faster resolution than an unexplained pattern shift does.

What makes a file approvable

A handful of practices consistently separate applications that clear review from ones that stall. The addresses on the formation document, the EIN confirmation notice, and the bank application should match exactly, because a bank's system flags a mismatch automatically and a human reviewer then has to resolve it manually, which is where files sit for weeks. The business narrative should describe, in plain terms, what the company sells, who its customers are, and roughly what volume and currency flow is expected, because CDD review is fundamentally an exercise in whether the account activity the bank observes later matches what it was told to expect at opening. The individual identified as the control-prong beneficial owner should be reachable, meaning a phone number and email that are actually monitored, because verification calls and follow-up document requests go to that contact and an unanswered call is itself a reason for decline. And the ownership chain described in the operating agreement should be the same ownership chain described to every other institution and on every other federal filing, including Form 5472, because inconsistency across filings is treated as a risk signal independent of whether either version is actually wrong.

None of this changes the underlying legal requirement. It changes how quickly and how smoothly a compliant file moves through a process that is, at its core, checking the same three things every time: who owns this, who controls it, and does the activity match the story.

If the first application is declined

A decline is rarely explained in detail, because institutions generally are not required to state the specific reason for a business account decline, and internal risk decisions are not disclosed as a matter of policy at most banks. Reapplying with the identical file at the same institution rarely changes the outcome, since the same policy screen is likely to apply the same way a second time. A more productive response is to treat the decline as information about that institution's particular risk appetite rather than as a verdict on the entity generally, and to review the file for the specific gaps discussed above, an address mismatch, a thin business narrative, or an unreachable beneficial owner, before approaching a different institution. Different banks, fintech providers, and payment processors set their risk tolerance differently for the same underlying regulatory floor, which is why a file that stalls at one can move cleanly through another once the documentation gaps are closed.

This is general information about how customer identification and beneficial ownership rules operate as of the date written. It is not a promise of account approval by any bank, fintech provider, or payment processor, and institutional policies described here are subject to change without notice from this firm.