Outsourcing and reliance under the AMLR: what may leave the building and what must stay
Article 18 sets hard limits on outsourcing AML tasks; Articles 48 and 49 govern reliance on other obliged entities. Which tasks stay in-house, what contracts must contain and what AMLA's draft Guidelines add.
Cet article n'est pas encore disponible dans cette langue ; l'original anglais est affiché. La traduction suit automatiquement.
Many institutions run parts of their AML programme through group service centres or vendors: identity verification, screening, transaction monitoring, even case handling. The AMLR allows outsourcing, but Article 18 draws lines that some current arrangements cross.
Tasks that cannot be outsourced
The business-wide risk assessment, the compliance functions (compliance manager and compliance officer), the approval of policies and procedures, and decisions on whether a transaction is suspicious and must be reported stay with the obliged entity. A vendor may prepare the analysis; the decision and the report are yours.
Conditions for what can be outsourced
- A written agreement that sets out the tasks, the standards, the right to audit and the supervisor's access.
- The obliged entity remains responsible and must be able to demonstrate control: performance monitoring, incident reporting, exit plans.
- Outsourcing to a provider in a third country requires attention to data protection and to the supervisor's ability to obtain information.
- The supervisor must be informed where national law requires.
Reliance is different from outsourcing
Under Articles 48 and 49 an obliged entity may rely on the customer due diligence performed by another obliged entity, for example a bank relying on the identification done by another bank. Reliance is a relationship between two obliged entities, both subject to the AMLR; outsourcing is a relationship with a service provider acting on your behalf. In both cases the relying or outsourcing entity stays responsible, but the documentation differs: for reliance, the Guidelines on information to be obtained from third parties specify what you must receive and when.
AMLA's draft Guidelines
The Guidelines on outsourcing and on reliance, both in final draft, set expectations on due diligence before entering the arrangement, on concentration risk when many institutions use the same provider, and on the retention of a copy of the customer file by the relying entity.
What to do now
- Inventory every AML task performed by a group entity or vendor and classify it: prohibited, outsourcing, reliance, or mere technology.
- Repaper agreements that lack audit rights or supervisor access.
- Make sure the decision to report a suspicious transaction is demonstrably taken by your own staff.
The dashboard tracks both Guidelines under Governance; the readiness tracker has blocks for outsourcing and third-party reliance.