Skip to main content
Category: Laws and Regulations

Designated Non-Financial Businesses and Professions

Also known as: DNFBPs, Designated Non-Financial Business or Profession, Designated Non-Financial Business and Profession
Simply put

Designated Non-Financial Businesses and Professions (DNFBPs) are certain types of businesses and professionals that are not banks or other financial institutions but are still brought within anti-money laundering rules because their activities can be misused to move or disguise illicit funds. Examples typically include casinos, real estate agents, dealers in precious metals, and law firms. Because they can be exposed to financial crime risk, they are generally subject to AML/CFT obligations in many jurisdictions.

Formal definition

DNFBP is a category defined in the FATF Recommendations to capture specified non-financial sectors and professions that, despite not being financial institutions, are subject to AML/CFT obligations due to their potential exposure to money laundering and terrorist financing risk. Under the FATF standards, the category typically includes casinos (including internet- and ship-based casinos), real estate agents, and dealers in precious metals, among other listed businesses and professions such as lawyers and other legal professionals. The precise scope, thresholds, and applicable obligations are determined by each jurisdiction's implementing framework rather than by a single global rule; for example, in the UAE the AML-CFT Decision defines DNFBPs and enhanced due diligence (EDD) may be required by financial institutions before establishing a business relationship with, or processing transactions for, such entities. Practitioners should confirm the specific definition, covered activities, and monetary thresholds against the applicable local regulation, as these vary by jurisdiction.

Why it matters

DNFBPs matter because money laundering and terrorist financing risk is not confined to banks and other financial institutions. Criminals seeking to place, layer, or integrate illicit funds may turn to sectors such as casinos, real estate, dealers in precious metals, and legal professionals, where high-value transactions, asset conversion, and complex ownership structures can obscure the source or movement of funds. By designating these businesses and professions as obliged entities, AML/CFT frameworks aim to close gaps that would otherwise leave significant channels outside the reach of preventive controls.

The DNFBP category originates in the FATF Recommendations, which are international standards rather than binding law. Each jurisdiction determines the precise scope of covered sectors, the applicable thresholds, and the specific obligations through its own implementing framework, meaning what qualifies as a DNFBP and what such entities must do can diverge from one country to another. For example, in the UAE the AML-CFT Decision defines DNFBPs, and enhanced due diligence may be required before a financial institution establishes a business relationship with, or processes transactions for, such entities. Practitioners should not assume a single global rule applies and should confirm covered activities and thresholds against the relevant local regulation.

For financial institutions, DNFBPs are also relevant as customers. Because certain DNFBP activities may carry elevated risk, some frameworks call for heightened scrutiny when onboarding or transacting with them. Treating a business as a DNFBP is a risk-management and compliance classification, however; it reflects potential exposure to financial crime risk and does not, by itself, indicate that any wrongdoing has occurred.

Who it's relevant to

Casinos and gaming operators
Casinos, including internet- and ship-based casinos where covered by local law, are typically designated within the DNFBP category under FATF-aligned frameworks. They may be subject to customer due diligence, record-keeping, and reporting obligations, with the precise scope and any thresholds determined by the applicable jurisdiction.
Real estate agents and developers
Real estate agents, and in some frameworks real estate developers carrying out transactions involving the buying or selling of real property, are commonly captured as DNFBPs. Because high-value property transactions can be misused to move or disguise illicit funds, these entities may face AML/CFT obligations as defined by local regulation.
Dealers in precious metals and stones
Dealers in precious metals are included among the FATF-defined DNFBP categories. Their exposure arises from the potential to convert or store value in portable, high-worth assets. Covered activities and any transaction thresholds vary by jurisdiction and should be confirmed against the applicable framework.
Legal professionals
Lawyers, law firms, and other legal professionals may be designated as DNFBPs where their activities, such as facilitating transactions or forming legal structures, could be exposed to money laundering or terrorist financing risk. The specific triggering activities and any professional-privilege considerations depend on the local implementing regime.
Compliance and financial crime teams at financial institutions
Banks and other financial institutions must consider DNFBPs as a customer category within their risk-based approach. Under some frameworks, such as the UAE AML-CFT Decision, enhanced due diligence may be required before entering into a business relationship with, or processing transactions for, a DNFBP. Teams should apply the standard set out in the applicable local regulation.
Regulators and supervisory bodies
Authorities responsible for supervising non-financial sectors rely on the DNFBP classification to define which businesses fall within the AML/CFT regime, set covered activities and thresholds, and monitor compliance. The scope of designation and the obligations imposed are determined by each jurisdiction's implementing framework rather than by a single global rule.

Inside DNFBPs

Scope of Covered Sectors
DNFBPs is a category defined in the FATF Recommendations to bring certain non-financial actors within AML/CFT obligations. It typically encompasses casinos, real estate agents, dealers in precious metals and stones, lawyers, notaries and other independent legal professionals, accountants, and trust and company service providers. The precise list and how it is transposed varies by jurisdiction, and some sectors may fall in or out of scope depending on national law.
Activity-Based (Not Status-Based) Triggering
For several DNFBPs, particularly legal professionals and accountants, obligations generally attach only when they engage in specified activities on behalf of a client, such as buying or selling real estate, managing client funds, or creating and administering companies. Advice or services outside these defined activities may fall out of scope, so obligations are frequently transaction- or activity-dependent rather than applying to the professional at all times.
Core AML/CFT Obligations
Where in scope, DNFBPs are generally expected to apply customer due diligence (CDD), keep records, and report suspicious activity, mirroring measures applied to financial institutions. The exact obligations, thresholds, and terminology depend on the implementing regime (for example EU AML Directives, the UK Money Laundering Regulations, or FinCEN rules), which do not treat all DNFBP sectors identically.
Suspicious Activity/Transaction Reporting
In-scope DNFBPs may be required to file suspicious reports to the relevant financial intelligence unit. The report is called a SAR in some jurisdictions and an STR in others; a filing reflects a suspicion or a reporting obligation being triggered and does not itself establish that a crime has occurred.
Interaction with Legal Professional Privilege
For lawyers and notaries, reporting and disclosure obligations are typically qualified by legal professional privilege or professional secrecy, the boundaries of which differ by jurisdiction. This creates carve-outs and exemptions that other DNFBP sectors generally do not benefit from.
Thresholds and Exemptions
Certain DNFBP obligations, such as those for dealers in precious metals and stones or casinos, may apply only above defined monetary thresholds or for particular cash transactions. Exact threshold values vary and should be confirmed against the applicable regulation.

Common questions

Answers to the questions practitioners most commonly ask about DNFBPs.

Are DNFBPs subject to the same AML obligations as banks and other financial institutions?
Not identically. While DNFBPs are brought within the scope of AML/CFT frameworks in many jurisdictions, the FATF Recommendations and national laws generally tailor obligations to the nature and risk of each sector. Core measures such as customer due diligence, record-keeping, and suspicious activity or transaction reporting typically apply, but the way they apply, the applicable thresholds, and the intensity of supervision often differ from those imposed on financial institutions. The precise obligations should be confirmed against the applicable regime, as they vary by jurisdiction and by category of DNFBP.
Does being classified as a DNFBP mean every service or transaction a business provides is covered by AML rules?
No. In many jurisdictions, DNFBP obligations attach only to specified activities or transactions rather than to the business as a whole. For example, obligations for certain professionals may be triggered only when they engage in defined activities on behalf of a client, and some sectors are captured only above particular monetary thresholds. Activities falling outside those defined triggers may be out of scope. Because scope boundaries and thresholds differ between regimes, the specific activities that bring a business within scope should be verified against the applicable regulation.
How does a business determine whether it qualifies as a DNFBP?
A business typically assesses whether the services it provides fall within the categories identified under the applicable AML/CFT framework, and whether the specific activities it undertakes match the defined triggers or thresholds set out in that regime. Because the categories captured, and the activity- or threshold-based triggers, vary by jurisdiction, businesses generally should map their services against the relevant national law or regulation and, where uncertainty exists, confirm their status with the relevant supervisor or through professional advice.
What AML measures should a DNFBP typically implement once it is in scope?
Where a DNFBP is within scope, applicable regimes generally require measures such as customer due diligence, ongoing monitoring, record-keeping, and reporting of suspicious activity or transactions to the relevant authority, often supported by internal policies, controls, and staff training. Many frameworks also expect a risk-based approach, meaning measures are calibrated to assessed risk. The exact set of required measures depends on the jurisdiction and the DNFBP category, and should be confirmed against the applicable regulation.
Who supervises DNFBPs for AML compliance?
Supervision of DNFBPs varies considerably by jurisdiction. In some regimes DNFBPs are overseen by a dedicated government supervisor, while in others certain professions are supervised by self-regulatory bodies or professional associations, and some sectors may be subject to different arrangements again. The identity of the competent supervisor for a given DNFBP category should be confirmed against the applicable national framework.
How should a DNFBP apply a risk-based approach in practice?
A risk-based approach generally involves identifying and assessing the money laundering and terrorist financing risks relevant to the business, its clients, products, delivery channels, and jurisdictions, and then applying measures proportionate to those assessed risks. Higher-risk situations may call for enhanced measures, while lower-risk situations may permit simplified measures where the applicable regime allows. These measures are intended to detect, deter, and manage risk rather than to guarantee prevention, and the acceptable scope of simplified or enhanced measures should be confirmed against the applicable regulation.

Common misconceptions

DNFBPs are subject to the same AML rules everywhere because FATF sets a single global standard.
The FATF Recommendations are standards, not binding law. Each jurisdiction transposes DNFBP obligations through its own instruments, so the list of covered sectors, applicable thresholds, terminology, and specific duties can diverge significantly between regimes.
A lawyer or accountant is always an obliged entity subject to full AML obligations at all times.
For many legal and accounting professionals, obligations are generally activity-based and attach only when they perform specified activities, such as handling client funds or arranging real estate or company formation. Services outside those defined activities may fall out of scope, and privilege or professional secrecy may further limit certain obligations.
When a DNFBP files a suspicious report, it confirms that the client has committed money laundering.
A SAR or STR reflects a suspicion or a triggered reporting obligation. It is a compliance and intelligence tool, not a finding of guilt, and does not by itself establish criminal wrongdoing.

Best practices

Confirm which specific sectors and activities are treated as DNFBPs under your applicable national regime rather than assuming the FATF list applies verbatim, and check the relevant transposing instrument.
For activity-based sectors such as legal and accounting professionals, map the specific triggering activities that bring engagements into scope so that CDD and reporting obligations are applied only where required and consistently.
Verify applicable monetary thresholds and cash-transaction triggers for your sector against the current regulation, and treat any specific figures as values to be confirmed rather than fixed universal amounts.
Implement risk-based CDD, record-keeping, and suspicious-reporting procedures proportionate to the risks of your sector and client base, recognizing that these measures manage and mitigate risk rather than guarantee prevention.
For legal professionals, establish clear internal guidance on where legal professional privilege or professional secrecy limits disclosure, so reporting decisions respect the boundaries defined in your jurisdiction.
Ensure staff understand that filing a SAR or STR reflects suspicion or a reporting obligation, not proof of criminality, and document the basis for reporting decisions accordingly.