Skip to main content
Category: Customer Due Diligence

Gatekeeper

Also known as: gatekeeper profession, designated non-financial business or profession (in gatekeeper contexts)
Simply put

In financial crime compliance, a 'gatekeeper' is a professional, such as a lawyer, accountant, or company formation agent, whose services can be used to access or move money through the financial system, and who is therefore positioned to help detect or prevent misuse. Because criminals may seek out these professionals to lend legitimacy to transactions or to set up companies and trusts, many countries bring them within anti-money laundering rules. The term is a descriptive, policy-oriented label rather than a single legal definition, and exactly which professionals count and what they must do varies by jurisdiction.

Formal definition

In AML/CFT usage, 'gatekeeper' is a non-statutory, descriptive term for certain non-financial professionals, commonly lawyers and other legal professionals, notaries, accountants and auditors, and trust and company service providers (TCSPs), who by virtue of their functions can facilitate or obstruct access to the financial system, and whose services may be exploited in money laundering or terrorist financing schemes (for example through entity formation, management of client assets, or real estate transactions). Provided as evidence only within general/non-AML sources here, the AML meaning derives from wider policy usage; the precise categories captured, the triggering activities, and the resulting customer due diligence, record-keeping, and suspicious-activity reporting obligations are set by each jurisdiction's framework (such as the EU AML regime, the UK Money Laundering Regulations, or FinCEN rules under the Bank Secrecy Act) and by international standards, and these diverge, so 'gatekeeper' status is not itself a legal test and should not be treated as uniform across regimes. Exact scope, thresholds, and duties must be confirmed against the applicable law and guidance. Note: the AML/FinCrime meaning is not documented in the evidence packet provided, which covers only unrelated commercial and general-dictionary senses of the word.

Why it matters

The gatekeeper concept matters because criminals rarely move illicit funds in isolation, they often need the professional services of lawyers, accountants, notaries, and trust and company service providers to give transactions an appearance of legitimacy, to form corporate vehicles and trusts, or to handle client funds and property transfers. These professionals occupy a position of trust and technical expertise, and that same position can be exploited to obscure beneficial ownership, layer proceeds, or introduce funds into the regulated financial system. Bringing them within AML/CFT frameworks is intended to place a control point at these entry routes so that misuse can be detected, deterred, or reported rather than facilitated unwittingly.

Who it's relevant to

Legal professionals
Lawyers and notaries may fall within AML/CFT obligations when they perform certain triggering activities, such as company or trust formation, managing client money, or handling real estate transactions. The precise scope, and the interaction with legal professional privilege, varies significantly by jurisdiction and should be confirmed against local rules.
Accountants and auditors
Accountants, auditors, and tax advisers are commonly treated as gatekeeper professions where their services can be used to structure transactions or entities. Whether and when they are obliged entities, and what CDD, record-keeping, and reporting duties apply, depends on the applicable national framework.
Trust and company service providers (TCSPs)
TCSPs facilitate the creation and administration of legal entities and arrangements, functions that can be exploited to obscure beneficial ownership. Many regimes bring them within AML/CFT rules, though the categories captured and duties imposed differ across jurisdictions.
Compliance and risk professionals
Those designing AML/CFT programs need to understand which professional services act as entry points to the financial system so they can calibrate risk-based controls. Because gatekeeper status is not a single legal test, program owners should map obligations to the specific regimes and activities that apply to their firm.

Inside Gatekeeper

Covered professions (DNFBPs)
The gatekeeper concept is most often applied to lawyers and notaries, accountants and auditors, and trust and company service providers (TCSPs). Some regimes also treat real estate agents and dealers in high-value goods as gatekeepers for defined activities. Which professions are captured, and for which services, depends on the transposing jurisdiction.
Triggering ('gatekeeper') activities
AML obligations generally attach not to the profession as a whole but to specific activities, such as buying and selling real estate, managing client money or assets, creating or managing companies and other legal arrangements, and acting as or arranging for a nominee. Advisory work outside these defined activities may fall outside scope in many regimes.
Applicable obligations
Where a gatekeeper is an obliged entity for a given activity, obligations typically include customer due diligence (CDD), including identifying beneficial owners, ongoing monitoring, record-keeping, and the filing of suspicious activity or suspicious transaction reports (terminology varies by jurisdiction). The precise obligations derive from the applicable regime rather than a single global rule.
Source instruments
The concept is articulated in the FATF Recommendations (notably Recommendations 22 and 23 and their interpretive notes), which are international standards rather than binding law, and supported by FATF risk-based guidance for legal professionals, accountants, and TCSPs. Binding requirements arise only when transposed into national frameworks such as the EU AML Directives/Regulation, the US BSA and FinCEN rules, or the UK Money Laundering Regulations and POCA.
Professional privilege and confidentiality boundaries
Many regimes provide carve-outs or limitations for information subject to legal professional privilege or professional secrecy, which can affect reporting obligations for lawyers and, in some jurisdictions, other advisers. The scope of any such exemption varies and should be confirmed against local law.

Common questions

Answers to the questions practitioners most commonly ask about Gatekeeper.

Is 'gatekeeper' just another word for any obliged entity, like a bank?
No. In AML usage, 'gatekeeper' generally refers to certain professionals and service providers, commonly lawyers, notaries, accountants, and trust and company service providers (TCSPs), whose services can be used to access or enter the financial and corporate system. The term reflects their position controlling entry points such as company formation, property transactions, or the handling of client funds. Financial institutions like banks are obliged entities but are not typically described as gatekeepers in this sense. The gatekeeper concept is largely descriptive rather than a defined legal category, though it maps closely to the designated non-financial businesses and professions (DNFBPs) addressed in FATF Recommendations 22 and 23. Exact scope varies by jurisdiction and should be confirmed against applicable law.
Does calling someone a 'gatekeeper' mean they have no AML obligations because they aren't a financial institution?
No. The gatekeeper label is often used precisely because these professionals can be subject to AML/CFT obligations when they carry out specified activities. Under the FATF Recommendations (notably 22 and 23) and their implementation in regimes such as the EU AML framework and the UK Money Laundering Regulations, gatekeeper professions may be obliged entities for certain services, for example, forming companies, managing client money, or carrying out real estate transactions. The obligations generally attach to defined triggering activities rather than to the profession as a whole, so scope depends on the service performed and the jurisdiction. Whether and when obligations apply should be verified against the relevant regulation.
Which activities typically bring a gatekeeper professional within the scope of AML obligations?
Coverage is generally activity-based rather than status-based. In many jurisdictions implementing the FATF standards, gatekeeper professionals are captured when they participate in or prepare for specified transactions, such as buying and selling real estate, managing client money or assets, creating or managing legal persons or arrangements, and acting as or arranging for a nominee. Purely advisory work outside these defined activities may fall outside scope in some regimes. Because triggering activities and any thresholds differ by jurisdiction, practitioners should map their service lines against the specific obliged-activity list in the applicable law.
How does legal professional privilege interact with a gatekeeper's reporting obligations?
Many jurisdictions provide a limited exemption or carve-out where legal professionals obtain information in circumstances subject to legal professional privilege or professional secrecy, commonly when ascertaining a client's legal position or acting in litigation. The precise boundaries of this exemption vary significantly between regimes and are frequently litigated, and it generally does not apply where the professional is knowingly involved in facilitating money laundering. Because the interaction between privilege and suspicious activity reporting is jurisdiction-specific and contested, firms should obtain guidance on the exact scope under their applicable rules and any relevant supervisory or professional body guidance.
What customer due diligence should a gatekeeper apply on a risk-based approach?
Where obligations apply, gatekeepers generally perform customer due diligence (CDD), identifying and verifying the client and any beneficial owners, understanding the nature and purpose of the engagement, and conducting ongoing monitoring proportionate to assessed risk. Enhanced due diligence (EDD) may be warranted for higher-risk situations, such as certain PEP relationships, complex ownership structures, or higher-risk jurisdictions. FATF guidance for legal professionals, accountants, and TCSPs describes applying these measures on a risk-sensitive basis. CDD and EDD are measures to detect and mitigate risk, not guarantees against misuse, and specific requirements should be confirmed against local regulation.
How do gatekeeper AML requirements differ across jurisdictions?
The FATF Recommendations are standards rather than binding law, so implementation for gatekeeper professions varies. The EU addresses these professions through its AML Directives and the AML Regulation; the UK covers them under the Money Laundering Regulations alongside the Proceeds of Crime Act; and other regimes implement Recommendations 22 and 23 differently. Divergence commonly arises in which professions are covered, the precise triggering activities, applicable thresholds, the treatment of privilege, and supervisory arrangements. Firms operating across borders should not assume a single global rule and should confirm obligations against each relevant jurisdiction's framework.

Common misconceptions

There is no AML meaning for 'gatekeeper'; it is a general-purpose term.
In financial crime compliance, 'gatekeeper' is a well-established concept referring to DNFBPs, such as lawyers, accountants, and TCSPs, who control access to the financial system. It is reflected in FATF Recommendations 22 and 23 and related FATF risk-based approach guidance.
All services provided by a gatekeeper profession are subject to AML obligations.
Obligations generally attach to specific triggering activities (for example, forming companies, managing client funds, or handling real estate transactions) rather than to the entire practice. Work outside the defined activities may fall out of scope depending on the jurisdiction, and privilege exemptions may further limit obligations.
Gatekeepers are governed by a single, uniform set of global rules.
The FATF Recommendations are international standards, not binding law. The actual obligations, covered activities, thresholds, and privilege carve-outs differ across regimes such as the EU AML framework, the US BSA/FinCEN rules, and the UK regime, so requirements must be confirmed against the applicable jurisdiction.

Best practices

Map which of your firm's activities constitute gatekeeper or triggering activities under the applicable regime, and confirm scope, covered services, and any thresholds against the specific transposing legislation rather than relying on the FATF standards alone.
Apply a risk-based approach to CDD and enhanced due diligence for gatekeeper engagements, with particular attention to identifying and verifying beneficial ownership where you form or manage legal persons and arrangements.
Establish clear internal procedures for identifying, escalating, and reporting suspicious activity, using the reporting mechanism and terminology (SAR/STR) mandated in your jurisdiction, and treat a report as a risk-based disclosure rather than a finding of wrongdoing.
Document how legal professional privilege or professional secrecy is assessed and applied in each matter, so that reporting decisions are defensible and consistent with local exemptions.
Consult the FATF Guidance on the Risk-Based Approach for Legal Professionals, Accountants, and TCSPs alongside sector-specific supervisory guidance to align controls with recognized expectations.
Maintain records of due diligence, monitoring, and decision-making for the retention period required in your jurisdiction, treating these controls as measures to detect and mitigate risk rather than guarantees of prevention.