SardineCon SF/2026

Learn More
AML programs4 分で読めます

Designated business groupとは?

SUBSCRIBE

A designated business group is a set of related reporting firms that some regimes allow to share core AML program pieces, such as policies, customer checks, and reporting arrangements, instead of each building fully separate ones. It cuts duplicated work across the group, but only if the governance over who owns each duty is airtight.

What is a designated business group, in plain English?

A designated business group is a mechanism that lets related reporting firms pool parts of their AML program rather than each standing up a fully separate one. Where a regime permits it, entities under common ownership or control can share things like written policies, certain customer due diligence, and elements of their reporting arrangements.

The appeal is obvious: it cuts duplicated work. Instead of five entities in a group each writing their own near-identical policy and running parallel processes, they can build once and apply across the group, which saves cost and improves consistency.

The catch is that sharing does not remove obligations; it just changes where the work is done. A shared setup needs clear governance over which entity owns each duty, because a gap in that split can leave one member technically non-compliant while everyone assumes the shared program has it covered. Shared does not mean automatic.

Shared vs entity-specific

What changes

Handled by the group

Stays with the entity

Policies

A shared AML policy framework built once.

Local tailoring where the entity's risk differs.

Customer checks

Common CDD standards and tooling.

The specific customers each entity onboards.

Reporting

Shared arrangements and infrastructure.

The legal duty to file for that entity's activity.

Accountability

Group-level coordination.

Named ownership of each obligation per member.

What it looks like in practice

In practice

A financial group forms a designated business group so its three regulated subsidiaries can share one policy set and a common monitoring platform. Everyone is pleased with the efficiency, and each subsidiary assumes the group program handles its reporting.

Then a regulator asks who filed for a particular subsidiary's suspicious activity, and the answer is nobody: the shared arrangement covered the infrastructure but the filing duty still sat with the entity, and no one had been named to own it. The efficiency was real, but the unassigned obligation created a direct compliance gap that a clearer split would have closed.

Why the split has to be owned by name

The tradeoff with any shared setup is that it blurs responsibility unless the group is deliberate about ownership. Confirm exactly what is shared versus entity-specific, and put a name against each obligation, because the failure mode here is quiet: a duty falls between the group and the entity, and everyone assumes the other side has it.

That is why a gap in the split can leave one member technically non-compliant while the group believes the shared program covers everything. The efficiency of pooling is worth having, but only if the governance is explicit. Shared does not mean automatic; someone still has to own each obligation by name, and that mapping needs to be documented and testable, not assumed.

What to watch for

  • Unassigned duties. Any obligation that neither the group nor a named entity clearly owns is a gap waiting to be found.
  • Assumption of coverage. Members who assume the shared program handles everything are exactly how filings get missed.
  • Undocumented split. If the shared-versus-entity mapping is not written down, it cannot be tested or defended in an exam.
  • One-size policy. A shared policy that ignores an entity's distinct risk profile can leave that member under-controlled.
  • Stale membership. New acquisitions folded into the group without updating the ownership map inherit the gaps.

Quick questions

What can a designated business group actually share?

Depending on the regime, core AML program pieces like written policies, elements of customer due diligence, and reporting arrangements. The exact scope varies by jurisdiction, so confirm what your regime permits.

Does sharing remove any legal obligations?

No. Sharing changes where the work is done, not who is ultimately responsible. Each entity still carries its own legal duties, and someone has to own each one explicitly.

What is the main risk of this arrangement?

A duty falling between the group and an entity because everyone assumes the other side handles it. That gap can leave one member technically non-compliant while the group believes it is covered.

How do you avoid the coverage gap?

Document exactly what is shared versus entity-specific and put a named owner against every obligation. The mapping should be explicit, current, and testable rather than assumed.

Is this the same as a group-wide AML program?

It is related but narrower. A designated business group is a specific permitted arrangement to share defined program pieces; a group-wide program is the broader concept of coordinating AML across a corporate group.

What happens when the group acquires a new entity?

The ownership map has to be updated to bring the new member into scope explicitly. Folding it in without reassigning duties is how shared arrangements quietly develop compliance gaps.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Designated business groupと併せて知っておきたい用語