Regulatory Perimeter: Financial Institutions, DNFBPs and Gatekeepers

The regulatory perimeter defines which activities and persons are subject to particular duties. A bank, securities intermediary, payment provider, trust company, lawyer and estate agent can participate in the same transaction while facing different AML/CFT requirements. The bank must understand the customer's business and counterparties without assuming that another professional's involvement makes a transaction safe.

FATF's financial-institution definition is activity-based. Its designated non-financial businesses and professions (DNFBPs) include specified casino, real-estate, precious-metals and stones, legal/accounting and trust/company-service activities. Recommendations 22 and 23 attach measures to defined situations; they do not impose identical duties on every professional service in every country.

National implementation establishes the binding perimeter, thresholds, exemptions, supervisors and reporting rules. Legal professional privilege and secrecy require careful treatment: privileged advice is not equivalent to all information handled by a lawyer. A bank should escalate uncertain disclosure questions through legal channels rather than assume either universal access or universal immunity.

Regulatory authorisation for one activity does not automatically cover another. A technology platform may provide account information, initiate payments, hold funds or offer a virtual-asset service, each with a different analysis. Start with what it actually does, who contracts with customers and who controls funds.

Regulatory Perimeter: Financial Institutions, DNFBPs and Gatekeepers — operating model

Regulatory Perimeter: Financial Institutions, DNFBPs and Gatekeepers — decision flow

Several perimeters can apply to one service

Regulatory perimeter analysis should name the regime being considered. Permission to provide a financial service, AML/CFT obligations, prudential requirements, customer protection, sanctions, data protection and tax reporting can have different scopes. A business may be registered for one purpose without being authorised for another. A bank should not describe a customer as simply regulated or unregulated without explaining the relevant activity, legal entity, jurisdiction and obligation. That broad label can hide the exact issue the institution needs to resolve.

Consider a technology company that provides software to merchants and later adds a facility for receiving and distributing customer money. The original software activity and the new funds-handling activity may require different analysis. The company may use a licensed partner, operate under an exemption, need its own permission or be subject to another arrangement under local law. The bank should examine contracts, account control, funds flow and actual operation. A sales presentation saying that the business is a technology provider does not settle the changed activity.

AML/CFT scope is also not identical to financial-services authorisation. National rules may impose duties on particular professions or activities without making them banks. FATF standards identify financial-institution activities and designated non-financial businesses and professions, while national implementation creates binding local requirements. A bank should understand both levels and avoid importing a foreign threshold, exemption or professional rule into a different jurisdiction. A proposed rule also needs to be distinguished from one that has commenced.

The useful output is an activity-to-obligation assessment. It identifies the facts, applicable framework, source date, competent authority, permissions or exemptions, reporting entity and unresolved questions. It also identifies the bank's own customer and control responsibilities. Even when a customer's activity is lawfully authorised, the bank still assesses financial-crime risk through evidence. Conversely, an uncertain classification should prompt appropriate inquiry and legal escalation rather than an unsupported accusation that the business is criminal.

Describe the activity before assigning the label

An activity inventory begins with what the business does for customers. Identify who offers the service, who signs the contract, who receives instructions, who controls funds or assets, who executes transactions and who records ownership. Describe settlement, refunds, custody, advice and ancillary services. These facts are more reliable for perimeter analysis than an industry code alone. A single company can perform several activities, and a group can allocate them among different legal entities.

The inventory should include ordinary and exceptional paths. A platform may usually pass instructions to a bank but hold funds temporarily during failed settlement. A professional firm may usually provide advice but operate a client account for a transaction. A marketplace may usually settle merchants directly but retain balances for refunds or disputes. An exceptional path can create material legal and financial-crime implications even when it represents a small share of volume. The assessment should not examine only the advertised standard flow.

Money and information should be mapped separately. A company may access account data without controlling money. Another may instruct transfers without holding the balance. A custodian may safeguard an asset without choosing investments. A bank may hold an omnibus account while the intermediary maintains the subledger. Each arrangement creates different visibility and responsibility. A diagram with one arrow labelled service can obscure those distinctions and lead to an incorrect assumption about who performs due diligence or reporting.

Evidence should support the description. Contracts, terms, account mandates, product demonstrations, settlement files and system permissions can establish how the service operates. Marketing material is useful context but may omit limitations or future features. If the actual product differs from the legal assessment's assumptions, the assessment needs review. The bank should record material changes and decision triggers so that a once-correct classification does not become stale as the customer's business expands.

Legal entities, brands and professional roles

A brand is not necessarily the legal entity providing the service. A platform can use one entity for software, another for regulated payment activity and a third for customer support. A professional network can contain separately owned local firms. A group licence may not cover every affiliate. The bank should identify the contracting entity, account holder and relevant operating entities and connect them to the permission or registration actually relied upon. Matching only a trading name can produce false confidence.

Professional roles also differ. A lawyer may advise on a dispute, manage transaction money or assist with company formation. An accountant may audit accounts, prepare tax returns or participate in a client transaction. A trust company may provide registered-office services, act as trustee or administer assets. The relevant duties depend on the activity and national framework. Treating every service performed by a professional as identical AML-regulated activity overstates scope and can confuse legitimate privilege or confidentiality boundaries.

The bank should distinguish its customer from the customer's clients. A law firm's operating account may pay staff and rent. A client account may aggregate money held for others under a particular arrangement. A company-service provider may pay formation fees on behalf of several clients. Those uses need different understanding of purpose, control and transaction transparency. The customer's professional status does not remove the bank's need to understand the account, while the exact treatment of underlying parties depends on applicable obligations and the actual legal model.

The assessment should identify accountable individuals as well as entities. Authorised signatories, controllers, trustees, directors and beneficial owners are not interchangeable. A person can influence transactions without owning the company, and a director can have a governance role without being the economic beneficiary. Recording roles accurately supports both perimeter analysis and customer due diligence. Where information is uncertain, the bank should preserve the uncertainty and seek appropriate evidence instead of assigning a convenient role to complete a form.

Financial-institution activities and bank relationships

FATF's financial-institution definition is based on activities rather than one universal list of company titles. Banking, lending, certain payment and transfer services, investment and asset administration, custody and other specified financial activities can fall within that framework. National law determines the binding treatment, permissions and supervision. A bank should therefore ask what the customer does, for whom and in which jurisdiction, rather than assume that a familiar business name establishes the relevant category.

Bank relationships with these businesses can create indirect exposure. A payment institution may use an account to collect and distribute funds for many customers. A lender may receive repayments and fund borrowers. An investment intermediary may use settlement accounts connected to client assets. The bank should understand expected activity, access, counterparties and the service purpose. It should not assume that another institution's AML programme makes all transactions safe or that the bank must automatically perform identical due diligence on every external customer.

Registration and supervision can inform the assessment. They may help establish legal status, responsible authority and the framework governing the customer's conduct. They do not prove that controls are effective or that a particular transaction is legitimate. The bank should consider the customer's actual operation, transparency and risk. Where the relationship provides access to the bank's services for others, agreements and monitoring should address the relevant service scope and changes in underlying activity.

An account classification should reflect the real use. Calling a customer a normal business account when it operates as a payment intermediary can weaken monitoring and expected-activity assumptions. Calling every technology business a financial institution can also misclassify services that do not perform the relevant activity. The review should be factual, proportionate and dated, with legal escalation for uncertainty. The decision record should explain why the selected account and control model fits the service that will actually use it.

Mapping activities and responsibilities

Create an activity inventory covering customer contracts, flow of funds, custody, advice, execution, settlement and beneficial ownership services. Map each activity to its operating legal entity, jurisdiction, licence or registration and competent authority. Record the source and date of verification and distinguish a pending application from current permission.

A DNFBP customer can create concentrated exposure. A law firm client account or trust-company relationship may aggregate funds for underlying clients. Understand account purpose, access, ownership, expected transactions and applicable transparency obligations. The customer's own AML duties do not remove the bank's CDD and monitoring responsibilities.

When another professional supplies identity or ownership information, distinguish information collection from permitted third-party reliance. Reliance has its own eligibility and evidence conditions. An accountant's letter may support a factual inquiry, but it is not automatically an authorised reliance arrangement or proof that all underlying funds are legitimate.

Perimeter changes require impact analysis. A new local rule may bring a sector into scope on a future date or apply only to defined transactions. Record adoption, commencement and transition arrangements separately. Do not turn a consultation proposal into an already effective customer requirement.

Regulatory Perimeter: Financial Institutions, DNFBPs and Gatekeepers — control architecture

Casinos and gambling-related banking exposure

FATF identifies casinos within the DNFBP framework in specified circumstances, while national law determines the local perimeter, thresholds and duties. The bank should not treat all gambling-related businesses as one identical category. A casino operator, online service, payment processor, software supplier, agent and hospitality business can have different roles and permissions. The bank should identify the actual operator, customer-facing activity, funds handling and relevant jurisdictions before deciding which framework applies.

Transaction understanding is essential. Casino-related accounts can show customer deposits, withdrawals, winnings, supplier costs, merchant settlement and transfers among operating entities. A rapid withdrawal may have a legitimate explanation, while activity inconsistent with the service or lacking meaningful play can warrant further inquiry. The bank should examine the account's purpose and available evidence rather than infer laundering from the industry label alone. Cash, online channels and agent arrangements may create different visibility and risks.

Permissions need to be checked for scope. A licence may identify the operator, permitted activity, location or conditions, and a cross-border online service may require more than one analysis. The bank should not assume that a licence in one jurisdiction authorises every customer market or payment arrangement. Equally, absence from an irrelevant register does not establish illegality. The reviewer should locate the appropriate source, understand its limits and escalate unresolved questions through the bank's legal and compliance process.

Monitoring should connect expected activity with the real flows. An operating account receiving large numbers of individual customer payments may need a different profile from an account used only for premises expenses. Refunds, reversals and merchant settlements need meaningful transaction classification. If the bank relies on operator information to explain a pattern, it should preserve the source and corroboration. The customer decision should reflect both regulatory status and observed conduct, with separate analysis of any local reporting threshold.

Real-estate services and transaction participation

The FATF DNFBP framework covers specified real-estate-agent involvement in buying and selling property. National implementation can define scope differently or add other duties. A bank should distinguish agents, developers, property managers, mortgage brokers, lawyers and escrow providers according to actual activities. A business that collects rent is not necessarily performing the same activity as one arranging a sale, and a professional holding purchase money may create a separate funds-handling question.

Property transactions often involve several parties whose roles need careful mapping. The buyer, seller, beneficial owners of corporate vehicles, agent, conveyancing professional, lender and recipient account can all be relevant. The bank should identify which party is its customer and what it can observe. It should not assume that an agent's due diligence replaces its own obligations or that a lawyer's involvement validates the economic purpose. Each professional may have a different role and access to different evidence.

The funds path can reveal questions that the property description alone does not answer. Purchase money may arrive from a third party, move through a professional client account, be returned after a failed transaction or be redirected to another beneficiary. These events can be legitimate but need explanation where material. The bank should compare contracts, ownership, loan arrangements and payment instructions as appropriate, preserving differences between stated purpose and observed movement. A property address does not establish the source of funds.

Customer treatment should remain proportionate to the evidence. A complex ownership chain or overseas buyer can require additional inquiry without establishing crime. A failure to resolve a material source or ownership concern may affect the bank's decision under its framework. The bank should record the actual issue and supporting facts rather than use a broad property-risk label as the explanation. Where reporting is considered, the narrative should explain the specific concern and the bank's limited position in the transaction.

Precious metals, stones and cash-related scope

Dealers in precious metals and precious stones appear in the FATF DNFBP framework for specified transactions, including the relevant cash-threshold context. Local rules determine binding scope and can differ in thresholds or treatment. The bank should identify whether the customer buys, sells, brokers, manufactures, recycles, stores or transports goods and whether it handles funds for others. Those distinctions affect both perimeter analysis and understanding of expected banking activity.

The economic features matter. High value in small physical volume, variable grading, international trade and resale markets can create transparency challenges. Those features are vulnerabilities to assess, not proof that a dealer is suspicious. Legitimate businesses may have large settlement amounts, seasonal inventory purchases or payments to specialist suppliers. The bank should understand the business model, supporting trade evidence and the relation between receipts, purchases and stock rather than treat every large payment as anomalous.

Cash activity should be assessed in the relevant context. A dealer may accept cash, bank transfers or other payment methods, with different visibility and applicable duties. Splitting transactions can have commercial explanations or raise concerns when evidence suggests avoidance or concealment. The bank should distinguish a threshold used for a specific customer duty from its own reporting assessment. A transfer exceeding an amount is not automatically a suspicious-activity report, and a transfer below an amount is not automatically low risk.

Trade evidence can be difficult to interpret. An invoice describes a claim about goods and value; it does not by itself establish authenticity, quality or delivery. Where material, the bank may need other evidence available through its process, such as counterparties, shipment records, business history or independent corroboration. The assessment should identify limitations, especially where the bank cannot verify grading or physical goods. It should avoid presenting a commercial discrepancy as a proved criminal valuation without specialist support.

Legal and accounting professionals: activity and privilege

Specified legal and accounting activities fall within the FATF DNFBP framework, including certain client transactions and services. The framework does not make every professional task identical. National law determines binding duties and the treatment of professional secrecy and legal professional privilege. A bank should therefore identify the service actually performed and escalate uncertain disclosure questions to legal. It should not assume that every document held by a lawyer is privileged or that professional status creates unlimited access to client material.

An accountant's role can range from routine bookkeeping to assisting a client with a transaction or structure. A lawyer can provide advice, represent a party, manage transaction funds or participate in establishing an entity. The bank should identify which activity explains the account and transactions. A professional operating account paying salaries and rent differs from an account that receives and distributes money for clients. The account purpose and control model should reflect the actual service rather than the firm's broad profession label.

Professional letters can support inquiry but need careful interpretation. A statement that documents were reviewed may not establish the exact fact the bank needs. A confirmation of company existence does not prove beneficial ownership or source of funds. An accountant's explanation of revenue may require supporting records if material discrepancies remain. The bank should understand the letter's scope, source, date and limitations and should not convert it automatically into a permitted third-party reliance arrangement.

Privilege and confidentiality need practical handling. The bank can explain the factual information it requires through an approved route, while the professional may identify information that cannot be disclosed under the relevant framework. Legal should determine whether an alternative source, narrowed request or other lawful route can resolve the issue. An unresolved material gap should remain visible in the customer assessment. Neither a blanket demand for all files nor a blanket acceptance of professional secrecy is an adequate substitute for a scoped decision.

Trust and company service providers

Trust and company service providers can participate in formation, administration, registered-office arrangements, directorship, trusteeship or nominee-related services within the relevant framework. The precise duties depend on activity and national implementation. A bank should identify which services the customer offers, who controls entities or arrangements, who gives instructions and whether funds or assets are handled. A company formation business and a professional trustee may both be described as service providers while creating very different banking exposure.

The bank should distinguish legal form from economic control. A registered office can be an administrative address shared by many unrelated companies. A director can be appointed for a defined service without owning the company. A trustee holds a role in an arrangement with beneficiaries and other relevant parties. A nominee label does not resolve who exercises control or receives benefit. The due-diligence process should record the actual roles and evidence, with uncertainty escalated instead of replaced by a convenient ownership assumption.

Account purpose is central. An operating account receiving service fees differs from an account used to hold funds for several client companies or trust arrangements. The bank should understand expected counterparties, access and movement, including whether clients can instruct transactions indirectly. The customer's own AML obligations may be relevant to confidence and service scope, but they do not remove the bank's responsibility to assess its customer and the account activity under applicable rules.

The bank should examine changes in service scope. A provider that initially offers only administrative addresses may later arrange banking, hold funds or administer assets. That expansion can alter perimeter analysis, expected activity and the bank's control needs. The institution should identify review triggers through contracts, periodic inquiry, observed transactions and product changes. A long-standing relationship should not continue under an outdated classification merely because the customer has used the same company name for years.

Information collection, outsourcing and reliance

These three arrangements should be named accurately. Information collection means obtaining evidence from a source and assessing it. Outsourcing means another party performs a task under an agreed operating arrangement. Third-party reliance is a specific framework for using another party's customer-due-diligence work where permitted and subject to applicable conditions. A bank should not describe every professional letter or vendor service as reliance. The distinction determines the evidence, responsibilities and safeguards the institution needs.

When collecting information, the bank evaluates source reliability and relevance. A registry extract, professional confirmation or customer document may establish some facts but not others. When outsourcing a process, the bank needs requirements, oversight, access to records and evidence of performance. When using permitted reliance, it must assess eligibility and the required ability to obtain information and supporting records. The precise legal conditions need local analysis; a commercial relationship alone does not create permission to rely.

The bank should document the arrangement before allowing staff to use it as a control shortcut. Identify the provider, services, entities, countries, records available, timing, exceptions and responsible owner. Test whether supporting evidence can actually be obtained when needed. A statement that the provider has checked everyone is insufficient if the bank cannot establish what was checked or access the information required by its framework. The arrangement should remain reviewable after staff or provider changes.

Failure handling is part of the design. If a provider does not respond, supplies inconsistent evidence or changes its service, the bank should identify the affected customers and decide the appropriate response. It may need further inquiry, direct collection, revised service scope or another authorised measure. The response should be proportionate to the actual gap. A provider's regulated status can inform the assessment, but it is not a permanent guarantee that every supplied record is accurate or every transaction legitimate.

Client money, pooled accounts and underlying visibility

The phrase client money does not describe one universal legal model. A professional firm, payment intermediary, marketplace or investment service may hold funds for others under different arrangements. The bank should identify the account holder, legal basis, beneficiaries or underlying users, instruction rights, segregation and reconciliation. The exact legal ownership and protection of funds need jurisdiction-specific analysis. A bank should not infer those rights solely from an account nickname or a statement that money is safeguarded.

Pooled accounts can create visibility limits. The bank may see aggregate deposits and withdrawals while the intermediary's subledger identifies individual users. The control design should understand how the bank obtains relevant information, what identifiers connect external records and how exceptions are handled. A large aggregate transfer can represent many legitimate small transactions, while a small transfer can concern a material risk. Monitoring should reflect the actual arrangement rather than compare the account mechanically with an ordinary single-business operating account.

Access rights deserve examination. Determine who can initiate payments, alter beneficiary details, approve refunds or move balances between internal records. A professional's employees, agents or clients may have different permissions. Changes in those rights can alter the risk even if the account holder remains the same. The bank should preserve the expected model and investigate material divergence through appropriate inquiry. It should avoid assuming that formal account ownership alone describes everyone who can use the relationship.

Records should support reconstruction. Where the bank receives an underlying-user schedule, it should understand its source, period, identifiers and reconciliation to bank activity. A spreadsheet provided after a concern arises may be useful but should not be treated as an authoritative ledger without assessment. The bank should record what it can and cannot verify. Transparency obligations and access decisions remain subject to the applicable legal framework; the account's pooled nature neither removes all duties nor creates unlimited access to every client's confidential information.

Perimeter testing and boundary cases

Test a platform that changes from technical messaging to holding customer funds, a professional offering company formation alongside advice, and a customer operating through multiple jurisdictions. The expected result should identify which activity changed, which authority or duty is relevant and who must approve the response.

Review official registers and activity restrictions rather than trusting a licence number in a sales presentation. Absence from one register may require further inquiry into the relevant regime; it does not automatically prove illegal activity if a different authorisation or exemption applies.

Maintain a legal-interpretation record for uncertain classifications and revisit it when facts change. The bank's acceptance decision should reflect both regulatory status and actual risk. A properly authorised customer can still present serious financial-crime concerns.

Regulatory Perimeter: Financial Institutions, DNFBPs and Gatekeepers — evidence map

Fictional case: the formation agent's blanket assurance

Meridian Formation Services is fictional. It opens an account to receive company-formation fees and pay administrative costs. Its application says it does not handle client investment or trading funds. Six months later, the bank observes large receipts from unrelated individuals and transfers to newly formed companies. Meridian explains that it now helps clients establish operating balances and supplies a letter stating that every client has passed its checks. The bank needs to assess changed activity, account purpose and evidence rather than accept the letter as a complete answer.

The reviewer first maps the original and current services. Who receives client instructions? Who controls the money while it is held? Which companies receive the transfers, and what role does Meridian play in their formation or administration? The bank compares contracts, mandates, invoices and transaction records. It should distinguish fee income from client money and identify whether the new activity is covered by the customer's permission, registration or other lawful basis under the relevant jurisdiction.

The letter may provide useful information, but the bank should examine its scope. It may confirm that Meridian collected identity documents without explaining ownership, source of funds or the purpose of each transfer. It may cover only some clients or use criteria different from the bank's applicable requirements. The bank should not convert it into a permitted reliance arrangement merely because the author is a professional intermediary. Eligibility, conditions and access to supporting records need the appropriate local assessment.

The investigation should also test legitimate explanations. New companies may need capital, and a service provider may lawfully assist with administration. The question is whether the observed flow and transparency fit the claimed model. Unrelated third-party funding, unclear instructions or inconsistent beneficiary ownership may require further inquiry. The bank should record the specific gaps and corroboration, not conclude that company formation itself is suspicious. A regulatory-status question and a suspicious-activity assessment can proceed separately.

The account decision may require a revised service scope, additional evidence, a different account model or another authorised response. The institution should identify the legal and policy basis for any limitation and its effect on legitimate clients. If the local reporting threshold is met, the report should explain the observed conduct and unresolved concern. It should not state that every formed company is criminal merely because the intermediary's new activity exceeded the bank's original understanding.

The learner should produce two outputs: a revised activity-to-obligation map and a factual investigation assessment. Identify which evidence resolves the perimeter question and which evidence supports or weakens suspicion. Explain why a professional assurance can contribute to the analysis while failing to replace the bank's own responsibilities. The case tests changed service scope and the distinction between collecting information and legally permitted reliance.

Fictional case: property money through a professional account

A fictional law firm operates a client account used for property completions. The bank sees a large transfer from a person who is not the named buyer, followed by a request to return the money to a different account after the purchase fails. The firm says that the arrangement is ordinary client business and that the underlying file is confidential. The bank should understand the transaction and applicable evidence requirements without assuming either that the lawyer's involvement makes it safe or that confidentiality can be ignored.

The bank identifies its customer, the account model, the stated buyer, the source account and the proposed return beneficiary. It asks through an approved route for the factual explanation necessary to understand the payment. The third-party contribution may be a gift, loan, company funding arrangement or another legitimate source. The changed return destination may also have a lawful explanation. The investigator records those possibilities and the evidence needed to distinguish them from concealment or misuse of the account.

Legal should assess any claim of privilege or professional secrecy in the relevant jurisdiction and context. The bank need not assume that transaction facts and legal advice have identical protection, but it also should not demand indiscriminate disclosure of the whole professional file. A narrowed request, alternative factual confirmation or other lawful source may resolve the issue. The record should identify what information was obtained, what remains unavailable and the effect of that limitation on the bank's assessment.

Payment treatment requires a separate decision. A request to return funds does not mean the bank should redirect them without verifying the instruction and applicable account arrangements. The bank should consider the actual ownership, authority, scheme rules, contract and any relevant restrictions through its approved process. If the funds are subject to a valid restraint or sanctions duty, that framework governs the action. A suspicion report, by itself, is not a universal authority to move or freeze money.

The customer assessment should remain specific. A well-supported explanation and verified return instruction may resolve the concern. Contradictory accounts of the third-party source, unexplained beneficiary changes or evidence of a broader pattern may sustain it. The investigator should explain the facts and limits rather than rely on the property value or professional category. A client account's legitimate purpose does not remove the need to understand unusual movement within it.

The exercise asks the learner to separate four questions: the firm's local professional duties, the bank's CDD and monitoring responsibilities, the protection of particular information and the authority for the payment action. Identify the appropriate owners and records for each. A strong answer avoids universal claims about privilege and preserves the distinction between a confidentiality limitation and an automatic exemption from financial-crime controls.

Fictional case: a dealer, a trade invoice and third-party settlement

A fictional precious-metals dealer uses a business account for stock purchases and sales. Its profile describes payments from established commercial customers. The bank observes receipts from several unrelated individuals, followed by an overseas supplier payment. The dealer supplies an invoice for refined metal and says it accepted the individual payments on behalf of a business buyer. The bank should examine the commercial explanation, payment arrangement and relevant local scope without treating the sector as a verdict.

The reviewer identifies the actual activity: purchase, resale, brokerage, storage or another service. It distinguishes cash transactions from bank transfers and determines which local obligations and thresholds are relevant to the customer. The bank's own investigation is separate from those customer duties. A threshold associated with a dealer's specified transaction does not automatically determine whether the bank must file a SAR or STR, and staying below a threshold does not establish that activity is legitimate.

The commercial evidence needs reconciliation. Does the invoice identify the claimed buyer, goods, quantity, date and settlement terms? Do the individual receipts reconcile to the amount due? Why are third parties funding the buyer? Is that arrangement consistent with the customer's ordinary business? The investigator should identify discrepancies and plausible explanations. It should not claim expertise in grading or physical authenticity that the bank does not possess. Where specialist evidence is needed, its source and limitations should be recorded.

The supplier relationship also matters. The bank can verify the payment record and obtain available business evidence, but a valid-looking invoice does not prove delivery or lawful source. Conversely, an overseas supplier or high-value commodity payment can be ordinary trade. The assessment should explain the specific concern, such as inconsistent parties or unsupported settlement arrangements, instead of presenting international trade as inherently suspicious. The bank should preserve relevant uncertainty about goods it cannot inspect.

A proportionate response may involve additional inquiry, updated expected activity or specialist review under the bank's framework. If the explanation is corroborated, the bank can record why the unusual receipts are understood. If material inconsistencies remain and the local threshold is met, the reporting assessment should identify those facts and their significance. Customer action, reporting and any payment restriction should retain separate owners and legal or contractual bases.

The learner should write a short evidence plan and a balanced assessment. Identify at least one fact that would weaken the concern and one that would strengthen it. Explain why the invoice, licence or industry category is insufficient alone. The case tests the ability to connect perimeter scope, trade evidence and bank judgement without substituting an amount threshold or sector label for analysis.

Fictional case: the platform that begins holding balances

ClearMarket is a fictional platform that initially provides software connecting merchants to a licensed payment partner. The bank's original assessment records that ClearMarket does not hold customer funds or control settlement accounts. A later release introduces stored balances, manual refunds and transfers among users. The product is still advertised under the same brand. The bank observes changed account activity and learns that the partner contract covers only the earlier payment flow. The service needs reassessment before the old classification is treated as current.

The activity review follows implemented capability. Who holds the balance, who owes the user money, who can instruct a transfer and who maintains the ledger? Which entity contracts with the user, and which entity is the bank's account holder? Manual exception handling should be included because staff may move funds outside the automated path. The bank should compare the current system, contracts and funds flow with the assumptions in the original legal assessment.

The permission question requires the relevant jurisdiction's analysis. A partner's authorisation may not cover the platform's new activity, and a pending application should not be represented as current permission. An exemption may have conditions that the new model no longer meets. The bank should document the source, facts and unresolved issues and use its approved legal and compliance route. It should not infer that all balance features fall under one identical regime in every country.

The financial-crime review is distinct but connected. Stored balances and user transfers can alter visibility, account purpose and monitoring needs. The bank may see only aggregated movement while the platform's ledger records underlying users. Requirements should identify the information needed to understand relevant transactions, how it is obtained and what happens when records conflict or are unavailable. A statement that the partner performs AML does not explain the new model's coverage.

The institution should determine an authorised response to the changed activity, considering both permission and operational risk. It may need to limit the new feature, obtain further evidence, revise the account model or take another proportionate step under the applicable framework. The decision should consider legitimate users and funds already held without allowing commercial pressure to settle the legal question. Any separate suspicion assessment should be based on conduct and evidence, not merely the existence of a product change.

The exercise asks learners to draw the original and changed money and instruction paths. Mark which assumptions no longer hold and which owner must resolve each issue. Propose launch and post-launch tests that would have detected the change. The case demonstrates why regulatory perimeter is an ongoing factual assessment rather than a permanent label attached to a customer name.

Fictional case: a professional refuses all information

A fictional trust administrator tells the bank that professional confidentiality prevents it from identifying any underlying party connected to a pooled account. The bank's records show payments for several arrangements but do not explain who gives instructions or benefits from the transactions. The administrator supplies a registration certificate and asks the bank to accept its internal checks. The bank should assess the relevant information requirements, claimed restriction and account model through a scoped legal process.

The reviewer first separates the requested facts. Account control, contracting entity, trustee role, beneficiary information and legal advice are different categories. The bank should identify what it needs under its applicable framework and why. The administrator should identify the specific basis and scope of any confidentiality restriction. Broad statements on either side are insufficient. Legal can assess whether the restriction applies, whether an alternative source is available or whether a narrowed request can meet the requirement.

The registration certificate establishes only what the relevant source confirms. It may identify the administrator and permitted activity, but it does not automatically prove the underlying parties' identity or the legitimacy of each payment. The bank should not treat registration as a substitute for transparency. It should also avoid asserting that the administrator is unlawful merely because one document does not answer every question. Permission, confidentiality and customer-risk evidence remain distinct assessments.

If a material information gap cannot be resolved, the bank should identify the resulting limitation and decide the appropriate response under its framework. The decision may affect service scope, account use or continuation, with legal and customer consequences assessed. It should not silently accept a model that prevents required controls, nor impose an unsupported blanket restriction on every arrangement. The institution should record the actual facts, attempted resolution and accountable decision.

The investigation may also reveal suspicious conduct, but refusal alone needs context. A genuine legal restriction differs from inconsistent explanations, concealment or a refusal to provide information that is lawfully available. The bank should assess the combined evidence and local reporting threshold. If it files, the report should explain the facts and limitations rather than claim that professional confidentiality proves criminal intent. Reporting is not a substitute for resolving the account's permissible operating model.

The learner should draft a narrowed information request and an escalation note. Identify the exact facts sought, the legal question, alternative evidence and the consequences of unresolved uncertainty. The answer should demonstrate respectful, accountable handling of professional boundaries while preserving the bank's own duties. It should not rely on universal access, universal immunity or the customer's registration certificate as an all-purpose solution.

Worked gatekeeper case

A fictional company-formation agent holds an operating account and asks the bank to accept its declaration that every underlying business has been checked. Determine the account's purpose, the agent's services, relevant licence or registration, ownership evidence and transaction visibility. Then decide whether any permitted reliance arrangement exists.

Explain why the label professional intermediary alone establishes neither exemption from bank CDD nor automatic eligibility for reliance. Identify what remains uncertain and the evidence needed to resolve it.

Laboratory: build an activity-to-obligation matrix

Provide a fictional business with software services, company formation, payment instructions and a proposed client-balance feature. Ask learners to identify each activity, operating entity, jurisdiction, customer contract, funds control and relevant framework. The matrix should include current, proposed and exceptional paths. It should distinguish an adopted future rule from a consultation and identify the date and source of each material interpretation. A list of industry names is not an adequate matrix.

For each activity, record the permission or exemption relied upon, its scope and the evidence supporting it. Identify the relevant supervisor or competent authority where appropriate, without inventing a universal authority for every country. Record local reporting and CDD responsibilities separately from broader financial-services authorisation. The matrix should also identify the bank's own customer, account purpose and control dependencies. These fields prevent the customer's obligations being mistaken for a replacement for the bank's duties.

Add decision triggers. A change in funds custody, instruction rights, customer market, partner contract or service feature may require reassessment. A licence restriction or expired registration may also matter. Learners should identify who notices the change, who interprets it and who approves the operating response. The expected output is a live governance record that delivery teams can use, rather than a one-time legal memo disconnected from product and transaction monitoring.

Close the exercise by selecting two uncertain classifications and proposing the evidence needed to resolve them. An unresolved question should have an owner, interim treatment and review route. The answer should avoid presenting uncertainty as a confirmed breach or ignoring it because a commercial launch is imminent. The matrix is useful when it makes facts, obligations and decisions traceable through the actual service.

Laboratory: test a reliance claim

A fictional onboarding team receives a professional letter saying that a customer's owners have been checked. Learners should identify whether the bank is collecting information, outsourcing work or considering permitted third-party reliance. They should examine the letter's scope, source, date, subjects and records available. The exercise provides a local policy extract defining the relevant reliance conditions so that learners apply a stated framework rather than inventing a global rule.

The team should test access to supporting information through a safe agreed process. Can the provider identify the parties and explain the checks performed? Can the bank obtain the records required by the supplied framework? What happens when information is inconsistent or the provider is unavailable? A successful ordinary response does not prove that the exception path works. The learner should identify responsibilities and preserve the evidence of the test without using real customer data unnecessarily.

The assessment should distinguish eligible arrangement from reliable outcome. Even a permitted reliance relationship needs the conditions and oversight required by the applicable framework. A provider may make an error or its evidence may become stale. The bank should identify review triggers and failure handling. Conversely, a letter that does not meet reliance conditions can still supply useful factual information if assessed appropriately. The categories should not force an all-or-nothing treatment of every professional source.

The output is a scoped decision with the evidence obtained, limitations, accountable owner and required follow-up. Explain why a provider's status alone is insufficient and why the bank should not call routine document collection reliance. This laboratory tests practical classification and the ability to preserve responsibilities when another professional participates in the customer process.

Laboratory: challenge register verification

Give learners four fictional register results. One matches the customer's legal entity but covers a different activity. Another concerns an affiliate with a similar name. A third shows a pending application. A fourth shows an exemption whose conditions depend on the funds flow. Learners should compare each result with the actual service facts and decide what it establishes, what it does not establish and which question needs further evidence or legal interpretation.

The verification record should include the source, search date, identifiers, status, scope and conditions. Screenshots should preserve enough context to understand the result later. A copied licence number without the matched entity or activity is insufficient. The learner should also identify whether the source is current and authoritative for the particular question. A commercial directory can help locate information but should not automatically replace an official record or a scoped legal assessment.

Next, introduce a product change that alters custody or customer market. Learners should explain which earlier verifications need review and why. A valid permission can remain valid while no longer covering the proposed activity. The bank should not treat the changed service as automatically unlawful, but it should not rely on an irrelevant earlier check. The decision needs current facts, the applicable framework and an accountable approval route.

The final exercise asks for a customer-facing factual request and an internal escalation note. The request should seek the relevant evidence without asserting an unproven breach. The internal note should identify material uncertainty and permitted interim treatment. A strong answer is precise about scope and avoids both blind acceptance of a register entry and automatic rejection because the first search did not resolve every issue.

Governance for perimeter changes

Legal owns interpretation of statutory scope; compliance translates duties into policy; business owners provide the actual service facts; technology implements required records and controls; operations execute them. Keep this chain visible so a product's marketing description does not become the legal classification by default.

Before launch, review the contracts and funds flow against the perimeter assessment. Test that customer disclosures, due diligence and reporting ownership align with the approved activity. When the service expands, rerun the assessment before the operational model outgrows its authorisation.

The useful output is a dated activity-to-obligation map with accountable owners, not an undifferentiated list of regulated industries.

Regulatory Perimeter: Financial Institutions, DNFBPs and Gatekeepers — governance map

Official registers and the scope of verification

Register checks should identify the correct entity and the correct regime. A licence number in a proposal can belong to an affiliate, a former company or a different activity. The bank should compare legal name, identifiers, status, scope, conditions and relevant dates through the appropriate official source. Where the register is not definitive for a question, the reviewer should document that limitation and seek the approved additional evidence. A screenshot without the query, date and entity match provides weak historical proof.

Permissions can be conditional or limited. The relevant framework may restrict activity, customer type, geography or service arrangement. A pending application is not the same as an effective permission. A registration may concern AML supervision rather than broader authorisation. An exemption may have conditions that depend on the actual funds flow or scale. The bank should understand which facts support the customer's position and which changes would require reassessment.

Absence from a register should be interpreted carefully. The wrong authority, a different legal name, an exemption or another applicable regime may explain it. The reviewer should not infer illegality immediately, but neither should they accept an unsupported explanation indefinitely. Record the unresolved issue, its risk significance and the legal or compliance route for resolution. The account decision should identify whether the activity can proceed under the bank's framework while classification remains uncertain.

Verification needs maintenance. A customer's permission can be withdrawn, restricted, expanded or transferred. A product can outgrow the original scope. The bank should identify relevant review triggers and reliable sources for updates. The frequency and method should reflect risk and applicable duties rather than a universal schedule invented for every sector. The useful record connects current status to actual activity and preserves the earlier assessment when historical transactions are later reviewed.

Technology platforms and changing control of funds

A platform's legal and financial-crime character can change as its features evolve. Providing messaging, accessing data, initiating payments, receiving funds, holding balances, converting assets and administering investments are different activities. A bank should examine each function and the operating entity. A technology label does not make every function unregulated, while use of sophisticated software does not automatically make the provider a financial institution. The analysis should follow facts, contracts and applicable rules.

Control of funds can be distributed. A bank may hold the account while a platform controls instructions and maintains user balances. A partner may execute payments while another entity markets the service. A merchant may receive settlement only after a platform deducts fees or reserves. The bank needs a clear account of these roles and their dependencies. One contractual statement that a partner handles regulation does not identify every participant's actual obligations or the bank's own control exposure.

Exceptional features can be material. Refunds, chargebacks, failed settlement, dormant balances, emergency withdrawals and manual corrections may use different paths from ordinary payments. Those paths should be included in perimeter and financial-crime review. A platform that normally never holds money may retain it during a failed transaction. A service that normally uses a partner may execute a manual payment directly. The bank should identify whether such changes are within the approved model and who authorises them.

Change governance should connect legal assessment to delivery. Requirements should reflect approved roles, records and controls, and acceptance tests should examine the actual funds flow. A feature flag can activate a new service without changing the customer-facing brand. The launch decision should therefore check implemented capability, not only marketing descriptions. After release, the bank should compare observed activity with the assessed model and investigate material differences before they become an entrenched unreviewed service.

Cross-border activities and conflicting classifications

A business can have customers, operating entities, accounts and service providers in several countries. The bank should identify where the relevant activity occurs and which legal framework applies to each participant. Incorporation in one jurisdiction does not necessarily settle permission to serve customers elsewhere. An overseas licence does not automatically provide local authorisation, and a local exemption may not extend to another market. These questions require scoped legal analysis rather than a single global classification.

The activity map should connect jurisdiction to facts. Identify the contracting entity, customer location where relevant, service delivery, funds control and account location. Distinguish direct service from a partner arrangement. Record assumptions about cross-border operation and the evidence supporting them. If the bank cannot determine a material fact, the uncertainty should remain visible in the assessment. A customer's declaration that it operates globally is not enough to establish every required permission or duty.

Conflicting classifications need escalation. One jurisdiction may treat an activity as a financial service while another uses a different category or exemption. The bank should not resolve the conflict by selecting the least burdensome label. Legal and compliance should identify the applicable obligations and the operating model needed to meet them. Technology should preserve jurisdiction-specific records and routing where required, while business owners ensure that customer contracts and actual service match the approved analysis.

The bank's risk assessment also remains distinct from perimeter legality. A service may be lawfully structured yet provide poor transparency about underlying users or transactions. Another may have a clear low-risk operating model but an unresolved permission question. The institution should address both dimensions and explain the basis for its decision. Combining them into one unexplained score can hide whether the problem concerns authority, customer evidence, transaction behaviour or an operational control limitation.

Perimeter concepts for bank delivery teams

Authorisation. Permission under a particular legal regime to perform specified activities. The bank should identify the entity, scope, conditions and effective status. It should not assume that the word authorisation covers every service, country or affiliate associated with a brand.

Registration. Entry in a register for a defined purpose. It may be relevant to AML supervision or another framework without being equivalent to all financial-services permissions. Read the source and local law rather than infer the meaning from the presence of a number.

Exemption. A legal provision excluding specified persons or activities from a requirement when its conditions are met. The assessment should identify those conditions and the facts supporting them. A change in scale, service or funds control may require review of continued eligibility.

Operating entity. The legal person actually performing the relevant function. It can differ from the brand, group parent, account holder or software owner. Mapping the operating entity prevents permissions and responsibilities being attributed to the wrong participant.

Account purpose. The intended use of the bank relationship, supported by the customer's business and funds flow. An operating-expense account, pooled client account and settlement account can require different understanding. The purpose should be updated when material activity changes.

Underlying party. A person or entity whose activity or funds sit behind an intermediary relationship. The bank's treatment depends on the actual legal model and applicable obligations. Do not assume either automatic direct-customer status or complete irrelevance merely because an intermediary appears in the chain.

Professional privilege. A protection whose scope depends on the relevant legal framework and context. It is distinct from a broad profession label and from every duty of confidentiality. Uncertain requests should be assessed through legal rather than resolved by an operational assumption.

Reliance. A specific permitted arrangement for using another party's due-diligence work under applicable conditions. It differs from obtaining a letter or outsourcing a task. Record eligibility, required information access, responsibilities and failure handling.

Service expansion. A change in what a business actually does, such as adding custody, user transfers or company administration. It can alter the perimeter and the bank's risk model without changing the customer's name. Contracts, capabilities and observed flows should inform reassessment.

Residual uncertainty. A material question not resolved by available evidence. It should have an owner, impact assessment and approved treatment. It is not a reason to invent a classification, ignore the issue indefinitely or automatically accuse the customer of wrongdoing.

Effective dates and controlled implementation

Perimeter change should be recorded as a sequence of legal and operational events. A consultation proposes a possible change. Adoption establishes an approved text. Publication, commencement, transition and enforcement arrangements may have different dates. Guidance may clarify implementation without creating a new statutory duty. The bank should identify the status of the source and the date relevant to each requirement rather than treat the first public announcement as the moment every customer must comply.

Consider a fictional jurisdiction that adopts a rule bringing a defined service into scope from a future date. The bank needs an impact assessment before that date, but it should not tell customers that the future obligation already applies. It can plan data collection, contracts, systems and training under its own approved programme while keeping current and target requirements distinct. If the implementation timetable changes, the bank should update affected requirements and communications rather than leave obsolete dates embedded in forms or rejection rules.

The rule register should identify the covered activity, entities, jurisdiction, source, effective date, transition conditions and interpretation owner. Product requirements should reference that record. Testing should cover current and future configurations, boundary dates and any permitted exceptions. Historical records should preserve the rule version used at the time, so a later reviewer does not apply today's classification retrospectively without considering the relevant law. A date field alone is insufficient if staff cannot understand what changed and why.

Implementation closure should include communication and ongoing maintenance. Operations needs to know which customers require review and what evidence resolves the requirement. Customer-facing teams need accurate explanations and lawful alternatives where appropriate. Technology needs a controlled activation decision rather than a release that accidentally enforces a draft. Legal and compliance should revisit the source when final rules or guidance arrive. The process should connect horizon scanning to specific operating changes, avoiding both premature obligations and late recognition of an effective duty.

References and further reading

Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.

  • FATF Recommendations, updated June 2026 — relevant anchors: 17 on permitted third-party reliance, 22, 23, 26 and 28; FATF Glossary financial institution and DNFBP definitions. These are international standards; local law determines the binding activity perimeter, thresholds, professional protections and authorisation requirements.