Join our Newsletter — 33% off our NHI Course

Who is accountable for AML compliance when Dutch financial institutions rely on third-party due diligence providers?

The institution remains accountable even when a third party collects or processes due diligence data. Dutch rules require firms to obtain that information without delay and maintain accurate records for ongoing risk assessment. Governance should therefore assign clear ownership for CDD quality, escalation, sanctions screening, and reporting, rather than assuming the provider carries the regulatory burden.

Why Accountability Stays With the Institution

Outsourcing due diligence collection does not outsource regulatory responsibility. The financial institution is still the accountable party for AML compliance because it owns the customer relationship, the risk decision, and the obligation to ensure the due diligence data is complete, timely, and usable for ongoing monitoring.

This matters most when the provider is treated as an input source rather than a control owner. If the institution cannot explain how it validates CDD quality, handles exceptions, or escalates missing information, it has shifted operational work but not the accountability that regulators expect.

What Third-Party Due Diligence Can and Cannot Do

A third-party provider can collect documents, enrich screening, and accelerate onboarding, but it cannot become the legal owner of AML obligations simply by processing the data. The institution still has to decide whether the evidence is sufficient, whether the customer risk profile has changed, and whether sanctions or adverse-media findings require action.

That distinction is important because third-party output can be fragmented, delayed, or context-free. A provider may deliver a data set, but only the institution can determine whether the record supports a defensible file, whether follow-up is needed, and whether the case should be rejected, restricted, or reported.

Governance Controls That Make Delegation Defensible

The practical test is whether the institution can demonstrate control over quality, timeliness, and escalation. Ownership should sit with the institution for CDD review, sanctions screening decisions, regulatory reporting, and exception handling, even when the provider performs first-pass collection or screening support.

Good governance also requires records that prove what was received, when it was received, what was missing, and who accepted the residual risk. If the provider’s workflow is not mapped into the firm’s own review and approval process, the institution will struggle to prove that the file was current at the point of decision.

Risk and Threat Considerations

Delegating due diligence to a third party can create blind spots if the institution assumes the provider’s process is equivalent to its own control environment. The main risks are stale records, incomplete beneficial ownership data, missed sanctions hits, and weak escalation where the provider flags an issue but no accountable internal owner acts on it.

Failure mechanism: Accountability fails when collection, review, and escalation are split across teams without a clearly owned decision point, or when a vendor delivers data without the firm validating quality and timeliness against its own AML risk model.

Impact: The institution can end up onboarding or retaining customers on the basis of incomplete evidence, missing reporting obligations, or being unable to defend its AML decisions during audit or supervisory review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
DORA N/A — ICT third-party risk management Third-party due diligence relies on outsourced ICT and operational dependencies that still require firm oversight.
Recommendation — Map vendor due diligence dependencies to third-party risk controls and retain internal ownership of regulatory decisions.
ISO/IEC 27001:2022 A.5.19 — Information security in supplier relationships Third-party due diligence is a supplier relationship that needs defined controls and accountability.
A.5.15 — Access control AML case handling depends on controlled access to customer and screening data across internal and external parties.
A.5.33 — Protection of records AML compliance depends on preserving accurate due diligence records for audit and supervisory review.
Recommendation — Set supplier security obligations and verify that outsourced checks feed your own control decisions. Restrict who can approve, edit, and accept due diligence records in the firm’s workflow. Retain complete due diligence records and approval evidence for the required retention period.
NIST CSF 2.0 GV.OV-01 — Oversight of risk management strategy The institution must oversee third-party AML execution within its own risk management strategy.
Recommendation — Keep executive oversight for outsourced AML controls and validate that provider output meets risk expectations.

Practitioner Guidance

What to prioritise: Assign a named internal owner for the full due diligence outcome, not just for vendor management. That owner should control the acceptance criteria for CDD files, escalation thresholds for exceptions, and the handoff into sanctions and ongoing monitoring workflows.

What to verify: Confirm that the provider’s SLA covers timeliness, completeness, and record retention, but treat those terms as support for your control, not as a substitute for it. The most important evidence is an auditable trail showing how the institution reviewed, challenged, and accepted the provider’s output.

Practitioner takeaway: If a third party helps collect AML data, the institution still owns the compliance decision, so governance must prove internal review, not vendor reliance.