You're building out your third-party risk program, and someone just flagged that your company's outside counsel needs to be assessed for AML compliance. Or you're reviewing a real estate transaction, and the agent handling the deal has no idea what Customer Due Diligence means. These aren't edge cases anymore. They're the compliance gaps that corrupt officials exploit every day.
These questions come up in every MLRO forum, every BSA officer roundtable, and every compliance team meeting where someone's trying to map FATF Recommendation 22 and 23 obligations to actual operational controls. The confusion is understandable. We've spent decades building AML/CFT frameworks for banks and money services businesses. Now we're being told that accountants, lawyers, and real estate agents are gatekeepers too, and they need similar controls.
Here's what you need to know.
Why Focus on Lawyers and Accountants?
You're not suddenly worried. FATF Ministers have long recognized the impact of grand and systemic corruption on economies, and the professionals who help move that money have been in the Standards since the early 2000s. What's changed is enforcement attention.
When a corrupt official steals public funds, they can't just walk into a bank with a duffel bag. They need a lawyer to set up a shell company, an accountant to create invoicing structures that look legitimate, and a real estate agent to quietly acquire luxury assets. These professionals provide legitimacy, access to the financial system, and the skills to layer transactions until the money looks clean.
Most of these professionals operate within the law. But professional enablers exist, and they're effective because their services look routine. A trust and company service provider forming a British Virgin Islands entity isn't inherently suspicious. It becomes suspicious when that entity is owned by a politically exposed person who can't explain the source of funds, but nobody asked.
Required AML/CFT Measures for Professionals
Under FATF Standards, over 205 jurisdictions in the FATF Global Network have agreed to apply AML/CFT measures to designated non-financial businesses and professions (DNFBPs). This includes:
Customer Due Diligence. Lawyers preparing real estate transactions, accountants managing client funds, and trust and company service providers forming entities must identify and verify their clients. This means collecting beneficial ownership information, understanding the purpose of the relationship, and conducting ongoing due diligence.
Enhanced Due Diligence for higher-risk clients. If the client is a politically exposed person or the transaction involves a high-risk jurisdiction, these professionals need to apply enhanced measures: senior management approval, enhanced monitoring, and source of wealth verification.
Suspicious Activity Reporting. When a lawyer sees red flags indicating possible money laundering or corruption, they're required to file reports with their jurisdiction's financial intelligence unit, subject to the same tipping-off prohibitions you follow.
Record-keeping. Transaction records and due diligence documentation must be retained, typically for five years, so investigators can reconstruct the paper trail if corruption is later detected.
The gap isn't the requirements. It's that many jurisdictions haven't implemented supervision and enforcement for these sectors the way they have for banks.
Assessing Compliance of Law and Accounting Firms
You don't know if a law or accounting firm is compliant unless you ask. And you should ask.
When you onboard a law firm as a service provider, your third-party risk assessment should include questions about their AML/CFT Framework. Do they have a designated compliance officer? Do they conduct Customer Due Diligence on their clients? Do they screen for politically exposed persons? Have they filed Suspicious Activity Reports in the past year, and if not, why not?
If the firm looks at you blankly, that's your answer. Many professional services firms, particularly smaller practices, don't have mature AML/CFT frameworks because their local regulators haven't enforced the requirements. That's a risk to you if you're relying on their due diligence to support your own.
Consider a scenario where your bank is financing a commercial real estate acquisition. The buyer's funds are moving through a law firm's client trust account. If that law firm hasn't verified the beneficial owner or the source of funds, you're inheriting that blind spot. Your transaction monitoring might flag the wire as unusual, but by the time you investigate, the deal has closed and the money has moved again.
Information Sharing with Professionals
This is where it gets tricky. You can share information to comply with your own AML obligations, but you can't tip off a subject of investigation.
If you're conducting Enhanced Due Diligence on a politically exposed person and you need the client's lawyer to provide source of wealth documentation, you can request that. If you've already filed a Suspicious Activity Report and you're asking the lawyer to explain transactions that are under investigation, you risk tipping off.
The better approach: build information-sharing protocols into your engagement agreements with outside counsel and other professional service providers. Specify that they're required to provide beneficial ownership information and transaction documentation upon request, and that they'll notify you if they identify red flags in their own due diligence.
Some jurisdictions allow Safe Harbor provisions for information sharing in the context of joint due diligence, but the rules vary. Check with your legal team before you disclose anything related to an active SAR or investigation.
Consequences of Professional Enablers Facilitating Corruption
You inherit the reputational risk, regulatory scrutiny, and potentially the enforcement action.
When corrupt proceeds move through your institution because a lawyer or accountant layered the transactions to look legitimate, regulators will ask why your due diligence didn't catch it. They'll review your third-party risk assessments, your transaction monitoring rules, and your Enhanced Due Diligence procedures for politically exposed persons.
If you can demonstrate that you asked the right questions, collected beneficial ownership information, and escalated red flags appropriately, you're in a defensible position. If you relied entirely on the professional's reputation without verifying their AML controls, you're not.
The worst scenarios involve state capture and systemic corruption, where the professionals enabling the corruption are operating with implicit or explicit protection from enforcement. In those cases, your institution may be the only control standing between corrupt proceeds and the financial system.
Risk-Based Approach to Professional Services
You don't need to treat all lawyers and accountants as high-risk third parties, but you need a risk-based approach that accounts for the services they provide and the jurisdictions where they operate.
A law firm providing employment advice is different from a firm forming offshore entities. An accounting firm preparing tax returns is different from a firm managing client funds or structuring cross-border transactions. Real estate agents in jurisdictions with strong beneficial ownership registries and AML supervision are different from agents in jurisdictions where neither exists.
Your Customer Risk Rating methodology should account for these variables. When a professional service provider has access to your clients, handles funds, or structures transactions, they need enhanced due diligence and ongoing monitoring.
Where to Find More Guidance
Start with the FATF Recommendations, specifically Recommendation 22 (DNFBPs: Customer Due Diligence) and Recommendation 23 (DNFBPs: Other Measures). These lay out the baseline requirements that jurisdictions have agreed to implement.
Then check your own jurisdiction's implementation. In the U.S., that's FinCEN regulations under the Bank Secrecy Act. In the EU, it's the Anti-Money Laundering Directives and national implementing legislation. The gap between what FATF requires and what your local regulators enforce will tell you where the risks are concentrated.
Finally, talk to your peers. The professional enabler problem is operational, not theoretical, and the compliance officers who've dealt with it have frameworks you can adapt. The red flags are knowable. The questions to ask are standard. You just need to ask them before the transaction closes, not after the investigator shows up.



