Skip to main content
Category: Customer Due Diligence

Third-Party Reliance

Also known as: Reliance on Third Parties, Third-Party Reliance for CDD
Simply put

Third-party reliance is an arrangement that generally allows a regulated firm to use customer due diligence (CDD) work already carried out by another qualifying institution, rather than repeating that work itself when onboarding a customer. This can reduce duplication, but the relying firm typically remains responsible for meeting its own obligations. It is distinct from outsourcing or using an agent, because the third party being relied upon is itself an independently regulated entity subject to due diligence requirements.

Formal definition

Third-party reliance refers to a regulatory mechanism under which an obliged entity may rely on customer due diligence measures performed by a qualifying third party, subject to conditions set out in the applicable regime. Under the UK Money Laundering Regulations 2017, regulated entities are permitted to rely on third parties to conduct CDD, while remaining subject to their own compliance obligations; exact conditions and record-availability requirements should be confirmed against the Regulations. The FATF Recommendation 17 standard, which is a standard rather than binding law, frames a reliance arrangement as one in which the third party is itself subject to AML/CFT requirements and supervision, and expressly distinguishes reliance from outsourcing and from the use of an agent. In practice, reliance typically does not transfer ultimate accountability: the relying entity generally retains responsibility for the adequacy of the CDD, and purely formal reliance without genuine substantive involvement of the third party may not be permitted. The precise scope, eligible third parties, permitted CDD elements, and documentation requirements vary by jurisdiction and should be verified against the governing instrument.

Why it matters

Third-party reliance addresses a practical tension in customer due diligence: firms want to avoid duplicating CDD work that another regulated institution has already performed, yet regulators need assurance that due diligence is actually being done to an adequate standard. The mechanism can reduce friction and cost at onboarding, but it does so without transferring the underlying accountability. Under regimes such as the UK Money Laundering Regulations 2017, a relying entity generally remains subject to its own compliance obligations even where it relies on a third party's CDD, meaning that a reliance arrangement is not a way to offload responsibility.

The distinction between reliance, outsourcing, and the use of an agent is more than semantic and carries real compliance consequences. As reflected in the FATF Recommendation 17 standard, a genuine reliance arrangement involves a third party that is itself subject to AML/CFT requirements and supervision. Because the FATF Recommendations are standards rather than binding law, the precise conditions are set by each jurisdiction's implementing instruments, and firms that misclassify an outsourcing or agency relationship as reliance may find they have not met the applicable conditions.

A further point of exposure is that purely formal reliance is generally not sufficient. Guidance in this area indicates that a merely formal reliance on a third party, without substantive involvement, may not be permitted, and that firms may need to secure the third party's genuine involvement through appropriate contractual arrangements. Where a firm relies on inadequate or unavailable CDD, it retains responsibility for the shortfall, so reliance should be treated as a measure to manage duplication rather than a guarantee that CDD obligations have been discharged.

Who it's relevant to

Compliance officers and MLROs at obliged entities
Those responsible for CDD programs need to understand that relying on a third party's work does not discharge their own obligations. They should assess whether the third party qualifies under the applicable regime, whether the arrangement is genuinely reliance rather than outsourcing or agency, and whether they can obtain the necessary CDD information and records. Because conditions vary by jurisdiction, they should confirm requirements against the governing instrument, such as the UK Money Laundering Regulations 2017.
Onboarding and operations teams
Teams handling customer onboarding may use reliance to avoid duplicating CDD already performed by a qualifying institution, reducing friction at account opening. However, they should treat reliance as a measure to manage duplication, not as a guarantee that CDD has been adequately completed, and should ensure that genuine, substantive involvement of the third party underpins any arrangement rather than a purely formal one.
Legal and contracting professionals
Legal advisers structuring reliance arrangements need to distinguish reliance from outsourcing and agency, and may need to secure the third party's genuine involvement through appropriate contractual arrangements. They should also account for record-availability requirements and the fact that ultimate accountability generally remains with the relying entity, verifying exact conditions against the applicable regulation.
Supervisors and auditors
Those reviewing an AML program's reliance on third parties will examine whether the relied-upon party is itself subject to AML/CFT requirements and supervision, whether purely formal reliance has been avoided, and whether the relying entity has retained responsibility for the adequacy of the CDD. They should assess documentation and record-availability against the requirements of the governing regime.

Inside Third-Party Reliance

Reliance on Third Parties for CDD
An arrangement whereby an obliged entity relies on a third party to perform elements of customer due diligence, typically customer identification, verification of identity, and identification of beneficial ownership and the purpose and intended nature of the business relationship, rather than performing those measures itself. The concept is reflected in the FATF Recommendations as a standard and is implemented differently across regimes such as the EU AML framework and the UK Money Laundering Regulations.
Eligible Third Parties
The categories of persons or entities that may be relied upon are generally limited to those themselves subject to AML/CFT obligations and supervision. Under many frameworks these are typically other regulated financial institutions or designated professionals; the precise scope of who qualifies varies by jurisdiction and should be confirmed against the applicable regulation.
Retention of Ultimate Responsibility
A defining feature in most regimes is that the relying entity retains ultimate responsibility for meeting its own CDD obligations. Reliance does not transfer liability; if the third party's due diligence proves inadequate, the relying entity generally remains accountable to its supervisor.
Distinction from Outsourcing/Agency
Third-party reliance is conceptually distinct from outsourcing or agency arrangements. In outsourcing, a service provider performs functions on behalf of the obliged entity under its instruction and control, and the provider is generally treated as part of the entity. Reliance involves depending on CDD already performed by an independent regulated party. Frameworks often treat these differently.
Immediate Access to Information
Frameworks relying on third parties typically require that the relying entity obtain immediately the necessary CDD information from the third party and be able to obtain, without delay and upon request, copies of underlying identification and verification documentation.
Adequacy and Supervision Conditions
Reliance is generally permitted only where the relying entity satisfies itself that the third party is regulated, supervised, and has appropriate CDD and record-keeping measures in place. Additional conditions may apply where the third party is located in a higher-risk jurisdiction, and some regimes restrict or prohibit reliance in such cases.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Reliance.

Does relying on a third party for CDD transfer the compliance responsibility to that third party?
No. This is a common misconception. In most regimes that permit third-party reliance, including under the EU AML framework and the UK Money Laundering Regulations, the obliged entity that relies on the third party generally retains ultimate responsibility for meeting its own customer due diligence obligations. Reliance is a mechanism to avoid duplicating CDD steps already performed, not a transfer or outsourcing of accountability. If the underlying due diligence proves deficient, the relying entity typically remains liable to its supervisor. Exact allocation of responsibility should be confirmed against the applicable regulation.
Is third-party reliance the same thing as outsourcing CDD to an agent or service provider?
No, these are conceptually distinct, though they are frequently conflated. Third-party reliance generally involves relying on CDD already conducted by another regulated entity for its own customer relationship, where that third party remains responsible for the quality of its own work. Outsourcing typically involves engaging an agent or external provider to perform CDD tasks on the obliged entity's behalf, under its instruction and control, where the outsourced party is treated as part of the obliged entity's own processes. Many regimes apply different conditions to each arrangement, and some do not treat outsourcing as reliance at all. The applicable distinction should be checked against the relevant regulation and supervisory guidance.
What information must typically be obtained when relying on a third party?
In many jurisdictions that permit reliance, the relying entity is generally required to obtain immediately the relevant CDD information gathered by the third party, and to ensure that copies of underlying identification and verification documents can be made available on request without delay. The specific data set, timing, and documentation requirements vary by regime, so the precise expectations should be confirmed against the applicable rules and any supervisory guidance.
Which third parties may generally be relied upon, and are there geographic limits?
Reliance is typically permitted only on parties that are themselves subject to AML/CFT obligations and supervision, such as certain regulated financial institutions or designated professionals. Many regimes impose additional conditions where the third party is located in another jurisdiction, often requiring that the third party be subject to requirements and supervision considered broadly equivalent, and some restrict or prohibit reliance on parties in higher-risk jurisdictions. The categories of eligible third parties and any equivalence or geographic restrictions vary by regime and should be verified against the applicable regulation.
Should reliance arrangements be documented, and how?
As a practical matter, obliged entities generally document reliance arrangements to demonstrate to supervisors that the conditions for reliance were met. This may include written agreements or arrangements setting out the third party's obligations to provide CDD information and documents on request, records confirming the third party's regulated and supervised status, and evidence of the information obtained. Documentation practices are an operational control rather than a guarantee of compliance, and specific requirements vary by jurisdiction.
Can reliance be used for higher-risk customers or in place of enhanced due diligence?
Reliance and the level of due diligence required are separate considerations. Even where reliance is permitted, the relying entity generally remains responsible for ensuring the CDD conducted is adequate to the assessed risk, including any enhanced due diligence that applies to higher-risk relationships. Many entities limit or avoid reliance in higher-risk situations because they retain ultimate responsibility and may prefer direct control over the measures applied. Whether reliance is appropriate in a given case should be assessed on a risk-based basis and against the applicable regulatory requirements.

Common misconceptions

Relying on a third party transfers legal responsibility for CDD to that party.
In most regimes the relying entity retains ultimate responsibility for the adequacy of customer due diligence. Reliance is a permitted method of performing CDD, not a mechanism for shifting liability, and supervisors generally hold the relying entity accountable for any deficiencies.
Third-party reliance and outsourcing are the same thing.
They are conceptually and often legally distinct. Outsourcing involves a service provider acting under the entity's instruction and control as an extension of the entity, whereas reliance involves depending on CDD independently performed by another regulated party. Different conditions and treatment typically apply to each.
An entity can rely on any third party that has already checked the customer.
Reliance is generally limited to third parties that are themselves subject to AML/CFT obligations and supervision, and is subject to conditions such as immediate access to information and copies of documentation on request. Reliance on unregulated parties, or in certain higher-risk jurisdictions, may be restricted or prohibited depending on the applicable regime.

Best practices

Confirm that the third party is a regulated and supervised entity eligible to be relied upon under the specific framework that applies to you, and document the basis for that determination.
Establish written arrangements ensuring you can obtain the relevant CDD information immediately and copies of identification and verification documentation without delay upon request.
Verify the precise conditions and eligible categories in the applicable regime, such as the EU AML framework or the UK Money Laundering Regulations, rather than assuming a single uniform standard, and confirm any thresholds or restrictions against the current regulation.
Apply enhanced caution or avoid reliance where the third party operates in a higher-risk jurisdiction, consistent with any restrictions in your applicable regime.
Maintain internal records demonstrating that you retained ultimate responsibility and satisfied yourself of the adequacy of the third party's CDD and record-keeping measures.
Distinguish clearly in policies and contracts between reliance arrangements and outsourcing/agency arrangements, since they carry different obligations and treatment.