Skip to main content
Category: Beneficial Ownership

Company Service Provider

Also known as: CSP, Corporate Service Provider, Trust and Company Service Provider (TCSP)
Simply put

A Company Service Provider is a business that helps clients set up and run companies, offering services such as forming a company and handling its ongoing administration. Because these services can be misused to hide who really controls or benefits from a company, providers of this kind are typically brought within anti-money laundering rules in many jurisdictions. Note that the abbreviation 'CSP' is also widely used in unrelated technology contexts, so the intended meaning should always be confirmed from the surrounding context.

Formal definition

In the AML/CFT context, a Company Service Provider (also commonly styled Corporate Service Provider, and often overlapping with the term Trust and Company Service Provider, or TCSP) is generally understood as a business that provides company formation and administration services and related support to private and corporate clients. In many regulatory regimes, entities providing such services are designated as obliged entities or otherwise subject to a licensing or supervisory framework; for example, some jurisdictions operate a dedicated CSP regime intended to establish a regulatory framework for the provision of company services aligned with international best practice. The precise scope of covered activities, registration or licensing obligations, and supervisory arrangements varies by jurisdiction and should be confirmed against the applicable local regulation. Practitioners should note that 'CSP' is an ambiguous acronym also used for unrelated technology concepts (such as cloud, communication, or content service providers), and the corporate/company service provider meaning must be distinguished by context.

Why it matters

Company Service Providers occupy a sensitive position in the corporate lifecycle: they help clients form companies and handle ongoing administration, which means they can be the point at which legal structures are created, maintained, and, in some cases, misused. Because company formation and administration services can be exploited to obscure who genuinely controls or benefits from a corporate vehicle, providers of these services are typically brought within anti-money laundering and counter-terrorist financing frameworks in many jurisdictions. Treating CSPs as obliged entities is intended to place customer due diligence, record-keeping, and reporting responsibilities at a structurally important gateway into the financial and corporate system.

The regulatory response to this risk is not uniform. Some jurisdictions operate a dedicated CSP regime, for example, the ADGM CSP Framework is described as intended to establish a robust regulatory regime for the provision of company services aligned with international best practice, while others address CSP-type activity through broader obliged-entity or trust and company service provider (TCSP) categories. The exact scope of covered activities, registration or licensing requirements, and supervisory arrangements varies by jurisdiction and should be confirmed against the applicable local regulation. For compliance professionals, this variation matters when assessing whether a counterparty or service provider is itself supervised, and to what standard.

Who it's relevant to

Company Service Providers and TCSPs
Businesses that offer company formation and administration services need to determine whether they fall within a dedicated CSP regime, a broader TCSP category, or another obliged-entity framework in the jurisdictions where they operate. Because coverage, licensing, and supervisory expectations vary by jurisdiction, providers should confirm their status and obligations against the applicable local regulation rather than assuming a single global standard applies.
AML compliance officers and MLROs
Compliance professionals need to identify when a counterparty, intermediary, or service provider is itself a CSP and whether it is supervised, since this affects how they assess and manage the associated risk. They should also treat the ambiguous 'CSP' acronym with care, confirming the corporate service provider meaning from context to avoid confusion with technology-sector usages.
Financial crime investigators and analysts
Investigators and analysts examining corporate structures may encounter CSPs at the point where companies are formed and administered, which can be relevant when tracing control and beneficial ownership. The presence of a CSP is a structural feature to understand in context and does not, on its own, establish wrongdoing.
Regulators and supervisory bodies
Authorities designing or operating regulatory frameworks for the provision of company services, such as dedicated CSP regimes intended to align with international best practice, are relevant stakeholders, as the scope of covered activities and supervisory arrangements is set at the jurisdictional level.

Inside CSP

Company Formation and Registration Services
The provision of services to form companies or other legal persons, a core activity that typically brings a provider within scope of the trust and company service provider (TCSP) category under regimes such as the FATF Recommendations, the EU AML framework, and the UK Money Laundering Regulations. The precise list of triggering activities may vary by jurisdiction and should be confirmed against the applicable regulation.
Provision of Registered Office or Correspondence Address
Acting as, or arranging for another person to act as, a registered office, business address, correspondence or administrative address for a company, partnership, or other legal person or arrangement. This is commonly listed among the activities that make a provider an obliged entity in many jurisdictions.
Provision of Directors, Secretaries, or Nominee Roles
Acting as, or arranging for another person to act as, a director or secretary of a company, a partner of a partnership, or in a similar position, including nominee arrangements. Such services can obscure the link between legal ownership and beneficial ownership, which is why they attract heightened attention.
Obliged Entity Status and AML/CFT Obligations
Where a CSP falls within scope, it is generally treated as an obliged entity subject to AML/CFT requirements such as customer due diligence (CDD), enhanced due diligence (EDD) in higher-risk situations, ongoing monitoring, record-keeping, and the filing of suspicious activity or suspicious transaction reports (SARs/STRs, terminology varying by jurisdiction). The exact obligations depend on the governing instrument.
Beneficial Ownership Focus
Because CSPs create and administer legal persons and arrangements, a central function is identifying and verifying the beneficial owner(s) as distinct from the legal owner(s) of record, supporting transparency objectives promoted by the FATF standards and reflected in various national and regional frameworks.

Common questions

Answers to the questions practitioners most commonly ask about CSP.

Is a Company Service Provider the same thing as a Trust and Company Service Provider (TCSP)?
Not exactly, though the terms overlap and are sometimes used loosely. The FATF Recommendations and many national regimes refer to "trust and company service providers" (TCSPs) as a combined category of designated non-financial businesses and professions. A Company Service Provider is generally understood to cover the company-formation and corporate-administration side of that category, while trust services (such as acting as or arranging a trustee) form a distinct but often co-regulated activity. Terminology and the precise labelling of these providers vary by jurisdiction, so you should confirm how the applicable regime defines and separates these roles rather than assuming the terms are interchangeable.
Does registering or being licensed as a CSP mean the provider has verified that its client companies are legitimate?
No. Registration, licensing, or supervision as a CSP is a status that brings the provider within the scope of AML/CFT obligations; it is not a certification that any company it forms or administers is legitimate or free of financial crime risk. CSPs are typically obliged entities expected to conduct customer due diligence and manage risk, but those measures are designed to detect, deter, and mitigate misuse rather than to guarantee that a client or a formed entity is legitimate. A provider's regulated status should not be read as a warranty about the underlying companies.
Which specific activities typically bring a business within the definition of a CSP?
In many jurisdictions the defining activities include forming companies or other legal persons, acting as (or arranging for another person to act as) a director or secretary, providing a registered office or business/correspondence address, and acting as (or arranging for) a nominee shareholder. The exact list and wording derive from the applicable regime, so the precise scope, and which incidental services fall in or out, should be confirmed against the relevant national law or regulation rather than assumed to be uniform.
What customer due diligence should a CSP apply when forming a company for a client?
As an obliged entity, a CSP generally applies customer due diligence (CDD) to the client engaging it and takes reasonable measures to identify and verify beneficial ownership of the entity being formed or administered, distinguishing legal ownership from the natural persons who ultimately own or control it. Where higher risk is present (for example, complex ownership structures, higher-risk jurisdictions, or PEP involvement), enhanced due diligence may be required. The specific verification standards, documentary expectations, and thresholds depend on the governing regime and the provider's risk assessment.
How should a CSP handle acting as, or arranging, a nominee director or nominee shareholder?
Providing or arranging nominee arrangements is commonly treated as a higher-risk activity because it can obscure the natural persons who ultimately own or control an entity. A CSP generally needs to look through the nominee arrangement to identify and verify the underlying beneficial owner(s), maintain records of the relationship, and apply risk-based scrutiny to the purpose of the arrangement. Some jurisdictions impose specific disclosure or registration expectations around nominee roles; these requirements should be confirmed against the applicable regime.
When a CSP identifies suspicious activity involving a client entity, what is its reporting obligation?
As an obliged entity, a CSP is typically required to report suspicion of money laundering or terrorist financing to the relevant financial intelligence unit, filed as a suspicious activity report (SAR) or suspicious transaction report (STR) depending on the jurisdiction's terminology. Filing such a report reflects a threshold of suspicion and does not establish that any wrongdoing has occurred. The trigger, form, timing, and any tipping-off restrictions are set by the governing regime and should be confirmed against it.

Common misconceptions

A CSP and a trust service provider are entirely separate regulatory categories.
In many regimes, company service provision and trust service provision are addressed together under a combined 'trust and company service provider' (TCSP) category, though the specific activities captured and the terminology can differ by jurisdiction and should be checked against the applicable regulation.
Providing only a registered office address is too minor an activity to bring a business within AML scope.
Providing a registered office, correspondence, or administrative address is typically listed as one of the activities that can make a provider an obliged entity in many jurisdictions, so it may attract AML/CFT obligations regardless of how limited the service appears.
Using a CSP to arrange nominee directors or shareholders is itself evidence of illicit activity.
Nominee and similar arrangements are lawful services in many contexts. They can obscure the connection between legal and beneficial ownership and therefore warrant scrutiny, but the use of such services does not by itself establish wrongdoing; it is one factor to assess within a risk-based approach.

Best practices

Confirm whether your specific activities fall within the CSP/TCSP definition under the applicable instrument (for example the FATF Recommendations as standards, the EU AML framework, or the UK Money Laundering Regulations), as scope and triggering activities vary by jurisdiction.
Apply customer due diligence to identify and verify beneficial owners as distinct from legal owners of record when forming or administering companies and other legal persons.
Escalate to enhanced due diligence for higher-risk situations, including complex ownership structures, nominee arrangements, or where the link between legal and beneficial ownership is not transparent.
Maintain ongoing monitoring and record-keeping consistent with obliged-entity requirements, and confirm the applicable retention periods against the governing regulation rather than assuming a single global standard.
Establish clear procedures for filing suspicious activity or suspicious transaction reports (SARs/STRs, per local terminology), treating a filing as a report of suspicion rather than a determination of criminality.
Treat controls around registered-office, address, director, secretary, and nominee services as measures to detect, deter, and mitigate financial crime risk, not as guarantees that misuse is prevented.