Skip to main content
Category: Laws and Regulations

Obligated Entities

Also known as: Obliged Entities, Obliged Entity, Obligated Entity
Simply put

In the anti-money laundering context, an obligated entity is a business that the law requires to carry out AML/CFT measures, such as checking who its customers are, monitoring transactions, and reporting suspicious activity. The term is most closely associated with the EU-style framework, where it identifies the businesses that fall within the scope of these obligations. Note that the same phrase is used in unrelated fields, such as energy management and carbon trading, where it has a different meaning.

Formal definition

In AML/CFT usage, an "obliged entity" (also rendered "obligated entity") is an EU-style term for any business that is legally required to apply AML/CFT measures, including customer due diligence checks, ongoing transaction monitoring, and reporting obligations. The concept defines the scope of persons and firms subject to a jurisdiction's AML framework; entities falling outside the designated categories are generally not subject to these requirements. Which businesses qualify, and the precise obligations imposed, depend on the applicable regime, so scope should be confirmed against the relevant instrument rather than assumed to be uniform across jurisdictions. The term also appears in unrelated regulatory contexts (for example, energy management systems and carbon credit trading schemes), where it carries an entirely distinct meaning and should not be conflated with its AML/CFT sense.

Why it matters

The concept of the obligated entity (also rendered "obliged entity") defines the perimeter of an AML/CFT regime: it determines which businesses are legally required to conduct customer due diligence, monitor transactions on an ongoing basis, and report suspicious activity. Because the regime's obligations attach to designated categories of persons and firms, correctly identifying whether a business falls within scope is a threshold question. A business that qualifies as an obligated entity may be subject to supervision, examination, and enforcement for failing to meet its duties, while a business that falls outside the designated categories is generally not subject to those same requirements.

The term is most closely associated with the EU-style framework, where it is used to identify the businesses within the scope of AML/CFT measures. Which businesses qualify, and the precise obligations imposed on them, depend on the applicable instrument, so firms should confirm their status and duties against the relevant regime rather than assume a uniform standard applies across jurisdictions. Misjudging scope in either direction carries risk: a firm that wrongly treats itself as out of scope may fail to implement required controls, while one that misunderstands the specific obligations attached to its category may build a program that does not align with what the law actually requires.

A further point of caution is that the same phrase appears in entirely unrelated regulatory contexts. In energy management, for example, obligated entities may be required to appoint energy managers for their locations, and under carbon credit trading schemes such as India's, an obligated entity refers to an industrial plant in a notified sector with binding emissions-related obligations. These uses carry a distinct meaning and should not be conflated with the AML/CFT sense of the term.

Who it's relevant to

Compliance officers and MLROs
Those responsible for AML/CFT programs need to determine whether their business falls within the designated categories of obligated entities and, if so, which specific measures, customer due diligence, ongoing monitoring, and reporting, apply under the relevant regime. Because scope and obligations vary by jurisdiction, they should confirm their status against the applicable instrument rather than assume uniformity.
Legal and risk professionals
Advisers assessing whether a client or business is subject to AML/CFT obligations rely on the obligated entity concept to define the regulatory perimeter. They should be careful to distinguish the AML/CFT meaning of the term from its distinct uses in unrelated fields such as energy management and carbon credit trading.
Regulators and supervisors
Bodies that supervise and enforce AML/CFT requirements use the designated categories of obligated entities to identify which businesses fall within their remit. The scope of covered entities is set by the applicable instrument, which shapes the population subject to examination and enforcement.
Newly in-scope businesses
Firms that may have recently come within a designated category need to understand that being classified as an obligated entity generally triggers requirements to apply customer checks, monitor transactions, and report suspicious activity. They should verify the precise obligations attached to their category under the relevant regime.

Inside Obligated Entities

Financial Institutions
Banks, credit institutions, payment service providers, e-money issuers, investment firms, and similar entities are typically classified as obligated entities (also called 'obliged entities' in EU terminology or 'covered financial institutions' under the US Bank Secrecy Act framework). The precise list varies by jurisdiction and is set out in the applicable instrument, such as the EU AML Directives, the US BSA and FinCEN rules, or the UK Money Laundering Regulations.
Designated Non-Financial Businesses and Professions (DNFBPs)
The FATF Recommendations extend AML/CFT obligations beyond financial institutions to certain non-financial actors, typically including casinos, real estate agents, dealers in precious metals and stones, lawyers, notaries, other independent legal professionals, and accountants when they conduct specified activities. The categories captured and the triggering activities differ between jurisdictions.
Source of Obligation
Whether an entity is 'obligated' is defined by the applicable legal or regulatory instrument, not by a single global rule. The FATF Recommendations are international standards rather than binding law, and are implemented differently through the EU AML framework, US BSA/FinCEN rules, the UK MLRs and Proceeds of Crime Act, and other national regimes.
Core Compliance Duties
Once in scope, obligated entities generally must apply customer due diligence (CDD), conduct ongoing monitoring, maintain records, and report suspicious activity (via a SAR, or an STR in many jurisdictions). The specific obligations, thresholds, and mechanics depend on the governing regime.
Scope and Threshold Boundaries
Obligation status may attach only to certain activities, transaction types, or above specified monetary thresholds. Some actors are captured only when performing particular functions (for example, certain legal or accounting activities), and activities outside those functions may fall out of scope. Exact thresholds should be confirmed against the applicable regulation.

Common questions

Answers to the questions practitioners most commonly ask about Obligated Entities.

Are 'obligated entities' the same across every country, so a firm can apply one global list?
No. The concept of an obligated entity (sometimes called an 'obliged entity' in EU terminology or a 'financial institution' and specified non-financial business under other regimes) is defined by each jurisdiction's own framework. The FATF Recommendations set out standards for which sectors should be covered, but they are not binding law, and countries transpose them differently. The EU AML framework, the US Bank Sacrecy Act and FinCEN rules, and the UK Money Laundering Regulations each specify their own categories and scope. A firm operating across borders generally cannot rely on a single global list and should confirm status under each applicable regime.
Does being an obligated entity mean a business is only about banks and financial institutions?
Not necessarily. While banks and other financial institutions are typically core obligated entities, many regimes also bring in designated non-financial businesses and professions, which in various jurisdictions may include certain lawyers, accountants, trust and company service providers, real estate agents, dealers in high-value goods, and casinos, among others. The precise categories and any applicable thresholds or activity-based triggers vary by jurisdiction, so which non-financial actors are in scope should be confirmed against the specific applicable regulation.
How does a business determine whether it qualifies as an obligated entity?
A business generally assesses this by mapping its activities against the categories and any activity or threshold triggers set out in the applicable national framework, rather than assuming coverage based on its industry label alone. Because scope differs between the EU AML framework, the US Bank Secrecy Act and FinCEN rules, the UK Money Laundering Regulations, and other regimes, the assessment should be made under each jurisdiction where the business operates, and exact scope and thresholds should be confirmed against the relevant regulation. Legal advice is often used where status is uncertain.
What core AML obligations typically apply once a business is an obligated entity?
Once in scope, an obligated entity is generally subject to a set of AML/CFT obligations that commonly include customer due diligence, ongoing monitoring, record-keeping, and reporting of suspicious activity to the relevant authority. The specific measures, their scope, and the reporting mechanisms differ by regime, and terminology varies too. The precise obligations, exemptions, and any applicable thresholds should be confirmed against the applicable regulation for each jurisdiction.
How should a group with multiple business lines handle obligated-entity status internally?
A group with multiple business lines may find that only some parts of its operations fall within scope, depending on the activities each line performs and the jurisdiction in which it operates. This generally requires mapping each line and legal entity against the applicable definitions rather than treating the whole group uniformly. Where different regimes apply to different entities in the group, the specific obligations and scope for each should be confirmed against the relevant regulation.
What are the practical implications if a business is unsure whether it is an obligated entity?
Where status is unclear, a business typically treats the question as a matter to resolve before determining its compliance posture, since obligations only attach if it is in scope under the applicable framework. Because coverage and thresholds vary between regimes and can turn on the specific activities performed, businesses commonly document their scoping analysis and confirm the position against the applicable regulation, seeking legal advice where uncertainty remains. Being in scope subjects a business to compliance obligations; it is a regulatory classification and does not itself imply any wrongdoing.

Common misconceptions

There is a single, universal list of obligated entities that applies globally.
There is no single global rule. The FATF Recommendations set international standards, but the categories of obligated (or 'obliged'/'covered') entities are defined and implemented differently across regimes such as the EU AML framework, the US BSA/FinCEN rules, and the UK MLRs, and terminology itself varies by jurisdiction.
Only banks and financial institutions are obligated entities.
Many regimes, consistent with the FATF Recommendations, also designate non-financial businesses and professions (DNFBPs) such as casinos, real estate agents, dealers in precious metals and stones, lawyers, notaries, and accountants, typically when they conduct specified activities. Which categories are captured varies by jurisdiction.
If an entity falls within a designated category, all of its activities are automatically subject to AML obligations.
For several categories, particularly certain legal and accounting professionals, obligations are typically triggered only by defined activities or above specified thresholds. Activities outside those triggers may fall out of scope, and the precise boundaries depend on the applicable regulation.

Best practices

Determine your obligation status by reference to the specific governing instrument in each jurisdiction where you operate (for example, the EU AML framework, US BSA/FinCEN rules, or the UK MLRs) rather than assuming a single global standard applies.
Map which of your specific activities and business lines trigger obligations, paying particular attention to categories where duties attach only to defined activities or above set thresholds, and confirm exact thresholds against the applicable regulation.
Where you operate across multiple jurisdictions, document divergences in scope, terminology (such as obliged versus covered entities, or SAR versus STR), and threshold values so that local requirements are applied correctly rather than harmonized incorrectly.
Implement the core duties applicable to your status, including customer due diligence, ongoing monitoring, recordkeeping, and suspicious activity reporting, calibrated to the requirements of each governing regime.
Reassess obligation status when business activities, products, or jurisdictions change, since new activities may bring previously out-of-scope operations within the definition of an obligated entity.
Track regulatory updates to the categories of obligated entities and their triggering activities, as these are periodically expanded or revised through amendments to national implementing law.