Skip to main content
Category: Customer Due Diligence

Reliance on Introducers

Also known as: Third Party Reliance, Eligible Introducer Reliance, Introducer Reliance
Simply put

Reliance on introducers refers to an arrangement in which a financial firm accepts a new customer referred by another party (the introducer) and relies, to some extent, on that party having performed customer identity checks. The firm still remains responsible for meeting its own anti-money laundering obligations, so it typically must satisfy itself that the introducer's checks can be trusted. This concept is distinct from simply receiving a business referral, because it involves reliance on due diligence work carried out by someone else.

Formal definition

An arrangement under which an obliged firm relies on a third party (an introducer) that has introduced a customer to the firm, in place of, or as a supplement to, conducting certain customer due diligence measures itself. Regulatory frameworks addressing this concept include the QFCRA AML/CFT Rules (AML/CFTR 3.4.9), which apply where a customer is introduced to a firm by a third party, and the Cayman Islands Anti-Money Laundering Regulations (Regulation 25), under which regulated entities relying on an 'eligible introducer' (EI) are required to conduct third party reliance testing. The precise definitions of who qualifies as an introducer or eligible introducer, the conditions for permissible reliance, and any testing or record-keeping requirements vary by jurisdiction and should be confirmed against the applicable regulation. Reliance arrangements are commonly documented through an introducer agreement setting out the contractual basis of the relationship, though the terminology 'introducer' is also used in adjacent contexts such as the FCA's 'introducer appointed representative' regime (SUP 12), which concerns a distinct authorisation matter and should not be conflated with AML reliance. As a general principle across these regimes, reliance does not transfer ultimate responsibility for compliance away from the relying firm.

Why it matters

Reliance on introducers allows firms to reduce duplication in the customer onboarding process by drawing on due diligence already performed by another party, but it introduces a structural risk: the relying firm typically remains responsible for meeting its own anti-money laundering obligations even though it did not itself carry out all of the underlying identity checks. If the introducer's checks are inadequate, incomplete, or improperly documented, the relying firm may find that it has onboarded a customer without a defensible customer due diligence foundation, and the regulatory consequences generally fall on the relying firm rather than the introducer. This is why frameworks such as the Cayman Islands Anti-Money Laundering Regulations require regulated entities to conduct third party reliance testing when relying on an eligible introducer under Regulation 25.

The concept also matters because it is easily confused with adjacent arrangements that carry different legal implications. A simple business referral, in which one party sends a customer to another and may be paid a fee under an introducer agreement, is not the same as reliance on the referring party's due diligence work. Similarly, the FCA's 'introducer appointed representative' regime under SUP 12 uses the word 'introducer' in a distinct authorisation context that should not be conflated with AML reliance. Compliance teams that blur these categories risk misstating where responsibility lies and misjudging what evidence they must retain.

Because the definition of who qualifies as an introducer or eligible introducer, the conditions for permissible reliance, and the associated testing and record-keeping requirements vary by jurisdiction, firms should treat reliance as an area requiring careful mapping to the specific applicable regulation. Exact conditions and obligations should be confirmed against the relevant regime, such as the QFCRA AML/CFT Rules or the Cayman AMLRs, rather than assumed to be uniform.

Who it's relevant to

AML compliance officers and MLROs
Those responsible for a firm's AML program need to determine whether reliance on an introducer is permitted under their applicable regime, document the arrangement appropriately, and ensure the firm still meets its own obligations. In regimes such as the Cayman AMLRs, they must also design and operate third party reliance testing when relying on an eligible introducer under Regulation 25.
Onboarding and customer due diligence teams
Staff handling new customer intake need to distinguish between a customer introduced with reliance on the introducer's checks and a customer who is merely referred, since the two carry different due diligence and evidence implications. They should confirm what identity checks were performed by the introducer and what the relying firm must still complete or obtain.
Introducers and referring firms
Parties that introduce customers to obliged firms, including those operating under an introducer agreement that sets out the contractual basis for a referral fee, are relevant because the quality and documentation of any due diligence they perform can be relied upon by the receiving firm. Their arrangements should be clearly scoped to reflect whether reliance is intended.
Legal and regulatory advisers
Advisers structuring or reviewing introducer relationships must ensure that AML reliance arrangements are not conflated with adjacent regimes that use similar terminology, such as the FCA's 'introducer appointed representative' regime under SUP 12, which concerns a distinct authorisation matter. They also need to confirm the specific conditions for permissible reliance against the relevant jurisdiction's rules.

Inside Reliance on Introducers

Third-Party Reliance
An arrangement whereby an obliged entity relies on a third party (often an introducer, intermediary, or another regulated firm) to perform certain customer due diligence (CDD) elements, rather than conducting all of those elements itself. The concept is recognised in various forms under the FATF Recommendations and, in the EU, within the AML framework, though the precise conditions differ by regime and should be confirmed against the applicable regulation.
Introducer
A party that introduces or refers customers to an obliged entity and may have already performed identification and verification steps. Whether a firm may rely on an introducer, and to what extent, generally depends on the introducer being a regulated or supervised entity subject to comparable AML/CFT requirements, though the criteria vary by jurisdiction.
Permitted CDD Elements
Reliance typically covers specific CDD measures such as identifying and verifying the customer, identifying beneficial ownership, and understanding the purpose and intended nature of the business relationship. Ongoing monitoring is generally not something that may be delegated through reliance and usually remains with the relying entity, but scope varies by regime.
Retained Responsibility
In many jurisdictions, ultimate responsibility and liability for meeting CDD obligations remains with the relying obliged entity even where reliance is placed on a third party. Reliance shifts the performance of certain tasks, not the accountability for compliance.
Information Availability Requirement
Reliance arrangements generally require that the relying entity be able to obtain, without delay, the relevant CDD information from the third party, and that copies of underlying identification and verification data can be provided upon request. Exact requirements should be confirmed against the applicable regulation.
Third-Party Eligibility Conditions
The third party relied upon typically must be subject to AML/CFT obligations and supervision consistent with applicable standards. Some regimes restrict or prohibit reliance on parties established in higher-risk jurisdictions; scope and eligibility criteria differ across the FATF standards, EU framework, UK Money Laundering Regulations, and US rules.

Common questions

Answers to the questions practitioners most commonly ask about Reliance on Introducers.

Does relying on an introducer or third party transfer AML responsibility away from my firm?
No. In most regimes that permit reliance, the obliged entity that relies on a third party generally retains ultimate responsibility for meeting its customer due diligence obligations. Reliance typically allows a firm to draw on CDD already performed by an eligible third party rather than duplicating it, but it does not outsource or discharge accountability. If the introducer's CDD proves deficient, the relying firm generally remains liable to its regulator. This is a key distinction from outsourcing arrangements and should be confirmed against the applicable regulation, such as the EU AML Directives, the UK Money Laundering Regulations, or the relevant FATF-aligned regime.
Is reliance on introducers the same thing as outsourcing CDD to a service provider?
No, these are conceptually distinct and are often treated differently in regulation. Reliance generally refers to using CDD conducted by an eligible third party (often itself an obliged entity) that has its own independent customer relationship and its own regulatory obligations. Outsourcing or agency arrangements typically involve a provider performing CDD functions on the firm's behalf and under its instruction, where the provider is treated as part of the firm rather than as an independent third party. The distinction affects which party carries obligations and how the arrangement must be documented, and terminology and treatment vary by jurisdiction, so the applicable rules should be checked directly.
What conditions typically must be met before a firm can place reliance on a third party?
Requirements vary by jurisdiction, but reliance regimes generally require that the third party be an eligible category of entity subject to AML supervision and CDD requirements, that the relying firm obtain the necessary CDD information immediately, and that the third party agree to provide underlying documentation on request without delay. Many regimes also restrict or prohibit reliance on parties located in higher-risk jurisdictions or those with inadequate AML regimes. The specific eligibility criteria and any geographic limitations should be confirmed against the applicable instrument, such as the EU AML Directives or the UK Money Laundering Regulations.
What should a written reliance agreement generally cover?
While exact requirements differ by regime, a reliance arrangement is typically documented to establish that the third party will make CDD information available immediately and will forward supporting documentation on request without delay. Firms commonly address the scope of information covered, the timeliness of provision, data protection considerations, and the third party's confirmation of its eligibility and AML compliance. Because the relying firm generally retains responsibility, many firms also address how they will satisfy themselves that the third party's CDD is adequate. The precise contractual obligations should be aligned to the applicable regulation.
How can a firm satisfy itself that an introducer's CDD is adequate before relying on it?
As an operational matter, firms generally perform due diligence on the introducer itself, considering factors such as the introducer's regulatory status, jurisdiction, AML program, and reputation, and may sample or review the CDD provided. Because responsibility typically remains with the relying firm, obtaining CDD information immediately allows the firm to assess its sufficiency rather than accepting it unseen. These are measures to manage and mitigate risk and do not guarantee that the underlying CDD is complete or accurate. The extent of assurance a firm seeks is generally informed by its risk-based approach.
Should a firm apply reliance uniformly across all customer relationships?
Generally no. Reliance is typically applied within a risk-based framework, and many regimes and firms limit or exclude reliance in higher-risk situations, such as those calling for enhanced due diligence. Reliance addresses which party's CDD a firm may draw upon; it does not change the underlying risk assessment or the level of due diligence the customer relationship warrants. Firms commonly reserve the right to conduct their own CDD where risk indicators are present. Any limitations on the use of reliance should be set out in the firm's policies and confirmed against the applicable regulation.

Common misconceptions

Relying on an introducer transfers legal responsibility for CDD to that third party.
In many jurisdictions, the relying obliged entity retains ultimate responsibility and liability for compliance with CDD obligations. Reliance permits another party to perform certain elements but generally does not transfer accountability. The precise allocation should be confirmed against the applicable regime.
Reliance covers the entire AML lifecycle, including ongoing monitoring.
Reliance typically extends only to certain CDD elements such as identification, verification, and identifying beneficial ownership. Ongoing monitoring of the business relationship generally remains with the relying entity and is not usually something that may be delegated through a reliance arrangement.
Reliance and outsourcing are the same thing.
These are distinct concepts. Reliance generally involves depending on CDD already performed by a separate regulated third party acting in its own right, whereas outsourcing typically involves an agent or service provider performing tasks on the firm's behalf under its instruction. The conditions and treatment can differ, and terminology varies by jurisdiction.

Best practices

Confirm that any third party relied upon is subject to AML/CFT obligations and supervision consistent with the requirements of the applicable regime before entering a reliance arrangement, and verify eligibility criteria against the relevant regulation.
Document the reliance arrangement, including which CDD elements the third party performs and which are retained, so that the allocation of responsibilities is clear and auditable.
Establish written assurance that the third party will provide relevant CDD information without delay and can supply copies of identification and verification records upon request.
Retain and periodically test the ability to obtain the underlying data, rather than assuming it will be available, since ultimate responsibility for CDD generally remains with the relying entity.
Assess whether any part of the third party's establishment or the customer relationship involves higher-risk jurisdictions or factors that would make reliance inappropriate under the applicable regime.
Retain ongoing monitoring in-house and apply the firm's own risk-based measures, treating reliance as covering only specified CDD elements rather than the full AML lifecycle.