Obliged entity

Who has the duty to identify customers and report to the authority. What concrete obligations the status brings, and why the same concept is named differently in each country in the region.

In short

An obliged entity is a person or an organization on which the anti-money-laundering and counter-terrorism-financing regime imposes its own duties: identifying its customers, keeping evidence of that identification, and reporting to the authority any operations that turn out to be suspicious.

The status isn't chosen or requested: it comes from the activity being carried out. If the activity is among those the rule covers, the duties apply from day one, regardless of the organization's size.

And it's not a status exclusive to banks. Across the region its scope isn't limited to the financial system: the catalogs include notaries, real estate, metals, gaming, and professional services.

What obligations the status brings

The duties vary in detail between countries and match in structure. There are six, and they function as a system, not as a task list.

  • Registering with the authority — signing up with the body that receives the reports, which depending on the country is the financial intelligence unit, the sector regulator, or the tax authority.
  • Appointing a compliance officer — an identified person, with decision-making authority, who answers for how the system works.
  • Identifying and knowing the customer — the core duty, and the one from which the whole KYC process stems. It includes identifying the ultimate beneficial owner when the customer is a company.
  • Applying risk-based due diligence — more scrutiny where the risk is greater, including customers who qualify as PEP.
  • Keeping the documentation — for the period each rule sets, and under conditions that allow a specific operation to be reconstructed years later.
  • Reporting — suspicious operations and, under several regimes, also those that exceed an objective threshold even if they raise no suspicion.

There's an implicit seventh duty that rarely shows up in the lists and is the one that generates the most work: being able to prove the six above. An obliged entity that did everything right and doesn't keep the trail is, in front of an inspection, in the same position as one that did nothing.

The same concept is called something different in each country

This is the part a regional team needs and that almost no page resolves. The figure exists in all four markets; the name, the supervisor, and the scope criteria change.

  • Argentina — the legal term is literally sujeto obligado (obliged entity), and the Financial Information Unit (Unidad de Información Financiera) is the body it registers and reports with. It's the country where the expression entered the everyday language of accounting firms and notary offices.
  • [Mexico](/regulacion/mexico) — the conceptual equivalent is those who carry out vulnerable activities, a catalog defined by the anti-money-laundering law that covers a wide universe outside the financial system. Financial entities answer to their own regulation and a different supervisor.
  • [Colombia](/regulacion/colombia) — the entities supervised by the Financial Superintendence fall under SARLAFT. Real-sector companies that exceed certain thresholds fall under SAGRILAFT, with the Superintendence of Companies as supervisor.
  • [Brazil](/pt/regulacao/brasil) — the pessoas obrigadas (obliged persons) are the individuals and entities covered by Law No. 9,613/1998 and its regulations. They must comply with money-laundering and terrorism-financing prevention duties and report the corresponding operations to COAF, Brazil's Financial Intelligence Unit. Depending on the sector, supervision falls to its specific regulator or directly to COAF, which besides being the FIU oversees sectors that have no regulator of their own.

The map of authorities isn't uniform, and it's worth not implying that it is:

  • Argentina — Sujetos obligados (Obliged entities). Authority: UIF. Evidence focus: registration and reporting to the UIF; record-keeping of the file.
  • Mexico — Quienes realizan Actividades Vulnerables (Those who carry out vulnerable activities). Authority: SAT-SPPLD and UIF. Evidence focus: notices for vulnerable activity; safekeeping of supporting information.
  • Colombia — Entidades vigiladas (SARLAFT) or empresas obligadas (SAGRILAFT), depending on the regime. Authority: Financial Superintendence and Superintendence of Companies, reporting to the UIAF. Evidence focus: documented risk-management system; suspicious operation report.
  • Brazil — Pessoas obrigadas (Obliged persons). Authority: COAF and sector regulators. Evidence focus: customer identification, record-keeping, and reporting of operations.

Four names, one mechanism. Whoever operates across several countries doesn't have to learn four philosophies: they have to know, in each one, three things. Who supervises, from what threshold, and for how long records must be kept.

The status depends on the activity, not the industry or the size

Two frequent misunderstandings get cleared up together.

The first: you don't have to be a financial entity. Across the region, depending on the country, notary offices, real estate agencies, currency exchanges, dealers of metals and precious stones, betting platforms, companies that grant credit without being banks, trust administrators, and virtual asset service providers, among others, are covered.

The second: being an obliged entity implies no suspicion whatsoever. The rule doesn't flag sectors by conduct, it flags them by exposure. An activity gets covered because its operations are a useful channel for moving funds of illicit origin, not because whoever carries it out is under suspicion.

The question that defines the status isn't what an organization does in general terms, but whether it carries out any of the activities its country's rule lists, and from what amount. Two companies in the same industry can be in different situations if one exceeds the threshold and the other doesn't.

Frequently asked questions

By comparing the specific activity it carries out against the list of covered activities in your country's rule, and against the thresholds that rule sets for each one. It doesn't depend on the size of the company or its legal form: it depends on what it does and, for several activities, from what amount. When there's reasonable doubt, the answer isn't assumed — it's checked with an advisor or directly with the supervising body, because the status brings registration and reporting duties that start as soon as the activity begins.

They're the same idea with a different name and a different jurisdiction. Obliged entity is the Argentine regime's term and it names the person or entity the duties fall on. Vulnerable activity is the Mexican term and it names the activity that, when carried out, creates those duties for whoever does it. One names the one who's obliged, the other names the act that obliges, and in practice they describe the same mechanism.

No. The reporting duty covers suspicious operations, which are the ones that don't find a reasonable economic or legal justification in light of the customer's profile. Several regimes also add objective reports above a threshold, which are filed even without any suspicion. What does cover every relationship, with no threshold, is the duty to identify the customer and keep the evidence.

It becomes exposed to its country's sanctions regime. The consequences can include warnings, fines, disqualifications, suspension, or cancellation of authorizations, depending on the jurisdiction, the supervisor, and the type of non-compliance. The sanction doesn't require that laundering actually occurred: failing the identification, record-keeping, or reporting duties can be an infraction on its own.

The exposure doesn't always stop at the organization. In Argentina, Colombia, and Brazil, liability can reach the person appointed as compliance officer directly. In some regimes that personal liability only activates when there's no compliance officer appointed or the appointment is irregular, and it then shifts to the administrators. It's a difference worth checking country by country before assuming the scheme is the same everywhere.

It depends on the country, and the floor is high. In Argentina and Mexico the regulatory standard requires keeping identification evidence for a minimum of ten years. In Brazil the minimum period is five years, extendable by decision of the authority. What almost always gets underestimated isn't the timeframe but the form: it isn't enough to keep the final result, approved or rejected. The rule requires that the record allow the operation to be reconstructed, meaning a supervisor has to be able to follow, step by step, which document was presented, which comparison was made, and what result each control produced. A file that only keeps the verdict meets the timeframe and not the duty.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo