The institution remains accountable even when a third party collects or processes due diligence data. Dutch rules require firms to obtain that information without delay and maintain accurate records for ongoing risk assessment. Governance should therefore assign clear ownership for CDD quality, escalation, sanctions screening, and reporting, rather than assuming the provider carries the regulatory burden.
Why Accountability Stays With the Institution
Outsourcing due diligence collection does not outsource regulatory responsibility. The financial institution is still the accountable party for AML compliance because it owns the customer relationship, the risk decision, and the obligation to ensure the due diligence data is complete, timely, and usable for ongoing monitoring.
This matters most when the provider is treated as an input source rather than a control owner. If the institution cannot explain how it validates CDD quality, handles exceptions, or escalates missing information, it has shifted operational work but not the accountability that regulators expect.
What Third-Party Due Diligence Can and Cannot Do
A third-party provider can collect documents, enrich screening, and accelerate onboarding, but it cannot become the legal owner of AML obligations simply by processing the data. The institution still has to decide whether the evidence is sufficient, whether the customer risk profile has changed, and whether sanctions or adverse-media findings require action.
That distinction is important because third-party output can be fragmented, delayed, or context-free. A provider may deliver a data set, but only the institution can determine whether the record supports a defensible file, whether follow-up is needed, and whether the case should be rejected, restricted, or reported.
- EBA AML/CFT Guidance frames the supervisory expectation that firms remain responsible for effective AML/CFT controls even when tasks are delegated.
- FATF Recommendations — AML and KYC Framework remains the clearest baseline for customer due diligence, beneficial ownership, and ongoing monitoring expectations.
Governance Controls That Make Delegation Defensible
The practical test is whether the institution can demonstrate control over quality, timeliness, and escalation. Ownership should sit with the institution for CDD review, sanctions screening decisions, regulatory reporting, and exception handling, even when the provider performs first-pass collection or screening support.
Good governance also requires records that prove what was received, when it was received, what was missing, and who accepted the residual risk. If the provider’s workflow is not mapped into the firm’s own review and approval process, the institution will struggle to prove that the file was current at the point of decision.
- EU Digital Operational Resilience Act (DORA) is useful where third-party dependencies affect oversight, incident handling, and operational resilience.
- SOC 2 Trust Services Criteria (AICPA) can help when a firm needs assurance language around vendor controls, but it does not transfer AML accountability.
Risk and Threat Considerations
Delegating due diligence to a third party can create blind spots if the institution assumes the provider’s process is equivalent to its own control environment. The main risks are stale records, incomplete beneficial ownership data, missed sanctions hits, and weak escalation where the provider flags an issue but no accountable internal owner acts on it.
Failure mechanism: Accountability fails when collection, review, and escalation are split across teams without a clearly owned decision point, or when a vendor delivers data without the firm validating quality and timeliness against its own AML risk model.
Impact: The institution can end up onboarding or retaining customers on the basis of incomplete evidence, missing reporting obligations, or being unable to defend its AML decisions during audit or supervisory review.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | N/A — ICT third-party risk management | Third-party due diligence relies on outsourced ICT and operational dependencies that still require firm oversight. |
| Recommendation — Map vendor due diligence dependencies to third-party risk controls and retain internal ownership of regulatory decisions. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Third-party due diligence is a supplier relationship that needs defined controls and accountability. |
| A.5.15 — Access control | AML case handling depends on controlled access to customer and screening data across internal and external parties. | |
| A.5.33 — Protection of records | AML compliance depends on preserving accurate due diligence records for audit and supervisory review. | |
| Recommendation — Set supplier security obligations and verify that outsourced checks feed your own control decisions. Restrict who can approve, edit, and accept due diligence records in the firm’s workflow. Retain complete due diligence records and approval evidence for the required retention period. | ||
| NIST CSF 2.0 | GV.OV-01 — Oversight of risk management strategy | The institution must oversee third-party AML execution within its own risk management strategy. |
| Recommendation — Keep executive oversight for outsourced AML controls and validate that provider output meets risk expectations. | ||
Practitioner Guidance
What to prioritise: Assign a named internal owner for the full due diligence outcome, not just for vendor management. That owner should control the acceptance criteria for CDD files, escalation thresholds for exceptions, and the handoff into sanctions and ongoing monitoring workflows.
What to verify: Confirm that the provider’s SLA covers timeliness, completeness, and record retention, but treat those terms as support for your control, not as a substitute for it. The most important evidence is an auditable trail showing how the institution reviewed, challenged, and accepted the provider’s output.
Practitioner takeaway: If a third party helps collect AML data, the institution still owns the compliance decision, so governance must prove internal review, not vendor reliance.
Related resources from NHI Mgmt Group
- Who is accountable for PCI SAQ compliance when organisations rely on third-party payment providers?
- Who is accountable for AML compliance when businesses delegate due diligence tasks to third parties?
- How should financial institutions and crypto service providers prepare for DORA when they rely on third party technology vendors for critical functions?
- Who is accountable when financial cybersecurity compliance fails across third-party vendors and internal teams?