Reliance on Third Parties, Introducers and Outsourced CDD

A bank may receive customers through an introducer, rely on another regulated party's customer due diligence, or outsource identification work. These arrangements are different. An introduction supplies a lead. Third-party reliance uses qualifying CDD performed by a party with its own customer relationship. Outsourcing means a service provider performs work for the bank under the bank's procedures and control.

FATF Recommendation 17 permits countries to allow reliance on specified elements of Recommendation 10, subject to conditions. The relying institution retains ultimate responsibility. It obtains necessary CDD information immediately, takes adequate steps to ensure supporting documents are available on request without delay, checks the third party's regulation and CDD/recordkeeping measures, and considers country risk. National law may limit eligibility or impose additional conditions.

The Interpretive Note explicitly distinguishes outsourcing and agency from Recommendation 17 reliance. A vendor's verification API response is therefore not automatically a legally permitted reliance arrangement. A commercial contract, a bank logo on a certificate or the fact that an introducer knows the customer does not establish eligibility.

Reliance does not replace the bank's own understanding of customer risk or its ongoing monitoring. Determine which tasks the arrangement covers, which remain internal, who resolves discrepancies and how information stays current. Evidence should remain retrievable after termination, insolvency or a change of provider.

Reliance on Third Parties, Introducers and Outsourced CDD — operating model

Reliance on Third Parties, Introducers and Outsourced CDD — decision flow

Classify the arrangement before approving the customer

The same external firm can perform several roles. It may introduce a prospect, collect documents as an agent, provide a digital verification service and have its own independent regulated relationship with the customer. Those activities should not be grouped under a generic partner field. The bank needs to know which role supports each task and what responsibility it retains. Classification determines eligibility assessment, contract terms, operating instructions, evidence requirements and oversight. A commercial partnership can contain both outsourced work and a separately permitted reliance arrangement, but each component needs its own basis.

An introducer primarily connects the prospect to the bank. Familiarity with the prospect, a professional title or a referral payment does not demonstrate completion of the bank's CDD. The bank assesses the introduction's credibility and obtains the information needed for its own service. If an introducer also collects evidence, determine whether it does so under the bank's procedures or under an eligible reliance arrangement. A statement that checks are complete should be interpreted against the defined task, not treated as a universal acceptance certificate. Missing scope creates uncertainty precisely where the bank needs a defensible decision.

Outsourcing delegates work within the bank's control framework. A provider may operate document checks, perform screening triage or maintain an onboarding service. The bank defines the required procedure, data quality, escalation and evidence. It needs enough oversight to determine whether the work achieves the required outcome. Reliance is different: the bank uses qualifying CDD performed by another party under the permitted framework. The distinction is not whether technology or people perform the task. An automated service can be outsourced, while reliance may involve records collected through a human process. The actual legal and operating relationship matters.

Scope the due diligence elements precisely

Identity, beneficial ownership, purpose and nature of the relationship, risk assessment and ongoing monitoring are related but distinct. A provider that verifies a person's document has not necessarily established who controls a corporate customer. A professional who knows a company's owners may not understand the proposed banking activity. Information collected for a different service may omit attributes material to the bank. The arrangement should specify which elements it covers and which remain internal. Avoid the phrase CDD complete unless the receiving workflow can determine what that status actually establishes.

The bank should evaluate whether the information fits the proposed customer and service. A low-complexity individual account and a corporate treasury relationship need different context. A historical file can be relevant but stale. A provider's record may show a beneficial owner who has since sold the company. The bank needs a route to identify changes and contradictory evidence, not just a one-time transfer. Ongoing monitoring remains connected to the bank's own activity and customer knowledge. A reliance arrangement should not be used to outsource judgement about every subsequent unusual transaction by implication.

Screening outputs also require careful interpretation. A clear name-screening result does not establish identity or ownership, and a potential match does not establish a prohibition. The bank should know which parties, lists, identifiers and dates were used, and which decisions the provider made. Some work may need to follow the bank's own sanctions or customer-risk policy rather than the provider's scope. Record those boundaries. A third party can support the decision chain, but its score or certificate should not collapse separate legal questions into one approval flag.

Legal permission and commercial assurance are different

Assess eligibility under the framework applying to the bank entity. Relevant considerations can include the third party's status, regulation or supervision, CDD and recordkeeping measures, location and the particular activity. National rules may permit only certain types of reliance and impose additional conditions. A firm's appearance on a regulatory register is useful evidence of status, but the register entry alone may not establish that the proposed arrangement qualifies. Check the actual regulated entity, permissions, scope and current status rather than relying on a brand or group name.

The US customer-identification example has its own conditions. FFIEC's CIP discussion addresses specified reliance on another financial institution, including the applicable relationship, regulation, reasonable reliance and contractual certification conditions. That is a US banking rule context, not an automatic permission for a global bank to rely on any identity vendor. A bank using a service provider outside that specific framework needs the appropriate outsourcing and CIP control analysis. The institution should not import a convenient term from one regime to avoid assessing the arrangement under another. FFIEC Customer Identification Program.

A contract should reflect the approved arrangement and operational dependencies. Define covered tasks, evidence access, lawful disclosure, quality review, incident notification, subcontracting, termination and record retention. Where law requires immediate information or prompt document availability, a commercial service target should not dilute the requirement. The bank should test whether the promised process works. An indemnity can allocate some commercial consequences, but it does not transfer the bank's own regulatory responsibility. Nor does an audit report establish that every customer file contains the information needed for a particular decision.

Risk assessment remains the bank's judgement

Consider the customer separately from the provider. A highly reputable institution can introduce a customer whose purpose or ownership is unclear. A small provider can have a well-controlled process for a defined low-complexity service. Provider risk influences the arrangement and oversight; customer risk influences the due diligence and relationship decision. Combining both into one partner score can hide those differences. Record the source facts, the provider assessment, the customer assessment and the bank's final decision with appropriate owners. The evidence should explain why the arrangement is suitable for this population.

Discrepancies need a controlled route. A provider says a company has one owner while an independent record indicates another. The bank should establish whether the difference reflects timing, ownership type, a data error or an unresolved concern. It should not choose whichever answer allows faster onboarding. Preserve the competing information and resolution. Where required CDD cannot be completed, follow the applicable local response, which may involve not establishing or continuing the relationship and considering reporting. Missing information is not automatically suspicion, but it is not resolved by assigning a low-risk label.

Customer communications should support legitimate information gathering. Explain what information is needed and why through approved, truthful wording. Avoid unnecessarily duplicating requests when reliable information can be used lawfully, but do not promise that the bank will never ask questions because another institution checked the customer. Changes in service, ownership or activity can create new needs. An accessible escalation route helps customers with unusual documents or complex structures provide appropriate evidence. Proportionate treatment improves control accuracy as well as customer experience.

Evidence must survive the commercial relationship

The bank needs to understand where relevant information and documents reside, who can obtain them and what happens if the provider changes systems or stops trading. A portal link that expires after termination is not a durable evidence arrangement. Record retrieval should include context: the customer, version, date, source and decision it supported. Secure transfer and access controls protect the information, while retention and holds follow the applicable record class and legal framework. Retaining all documents indefinitely is not the only way to ensure an effective arrangement.

Test exit before it becomes urgent. Select migrated and older customers, request evidence through the agreed route and examine whether it matches the original decision. Consider licence changes, insolvency, subcontractor failure and a provider refusing cooperation. Establish how new onboarding can be suspended or rerouted and how existing populations will be reassessed where necessary. The bank should know which controls depend on the provider and what work remains after the contract ends. Commercial termination should not silently delete the ability to explain earlier customer decisions.

The practical standard is clear classification, suitable scope, current eligibility, reliable information and demonstrated retrieval. A bank that can explain those elements can use external support without surrendering judgement. A bank that holds only a partner approval flag has neither adequate operating visibility nor a strong evidence chain. The remaining sections examine the details needed to build, test and govern an arrangement in real banking workflows.

Operating a reliance arrangement

Before accepting reliance, legal and compliance establish whether the counterparty and activity qualify in the relevant jurisdiction. Due diligence covers regulatory status, CDD scope, document quality, ownership verification, geographic exposure, retrieval arrangements and the provider's ability to comply with requests. Verify status from an appropriate official register rather than a marketing page.

At onboarding receive the required identifying information and ownership context. Information and documentary copies have different timing requirements under the FATF baseline; a contract promising documents eventually does not satisfy the need for prompt access. Record the source and date, then assess whether the information is sufficient for this customer's actual risk.

Outsourcing requires a different control design. Specify the bank's process, permitted data sources, rejection rules, staff competence, access controls, subcontracting conditions and quality monitoring. A vendor may confirm an identity while missing a beneficial owner or overlooking a mismatch; the bank must detect those failures in its workflow.

Introducer incentives can create biased evidence. Separate sales commission from acceptance authority and test whether the customer profile matches the service sought. If the bank cannot complete required CDD, apply local restrictions and consider reporting. Do not describe a missing file as low risk just because the intermediary has a good reputation.

Reliance on Third Parties, Introducers and Outsourced CDD — control architecture

Build an arrangement inventory, not just a supplier list

The inventory should identify the contracting entity, providing entity, arrangement type, customer population, covered tasks and jurisdictions. A group vendor may supply a platform globally while different subsidiaries use it for different purposes. One entity may outsource document checks; another may use the provider only for data enrichment. The contract owner should identify those differences. A supplier master entry usually describes commercial payment and contact details, not the full control arrangement. Programme oversight needs a record linked to the actual customer workflows that depend on the provider.

Record who approved the classification and what evidence supports it. A proposal can evolve from simple referral to delegated collection or reliance as services expand. Changes should trigger reassessment rather than inherit the first approved label. If a new subcontractor performs a material task, identify the task and whether the arrangement permits it. The bank may need additional legal, privacy, security or control assessment. The governing record should show the current scope and its history, so a reviewer can determine which arrangement supported an earlier onboarding decision.

Map responsibilities at task level. Identify who obtains information, verifies it, assesses discrepancies, approves the customer, updates changes and provides records. A single responsibility matrix row called onboarding can obscure major gaps. For example, the provider may verify a director's identity while neither party identifies who ultimately owns the customer. Or both parties may assume the other screens newly added owners. The operating model should expose those gaps before release. The objective is not to allocate every conceivable activity to the provider, but to ensure that necessary work has a clear owner.

Verify provider eligibility and its continuing relevance

Use reliable evidence for the provider's legal identity and status. A trading name may cover several entities with different permissions. Check which entity actually performs the work and holds the customer relationship where relevant. Preserve the register or authoritative source details used, with the date and material limitations. A screenshot of a logo or a marketing claim is weak evidence. Where reliance eligibility depends on particular regulatory or supervisory conditions, the legal and compliance assessment should explain how the proposed counterparty satisfies them.

Review the provider's CDD and recordkeeping arrangements to the extent relevant to the approved framework. Understand customer types, verification sources, beneficial-ownership treatment, quality control, retrieval and incident handling. A favourable general audit opinion may not cover the service, time period or customer population proposed. Ask which controls were examined and what limitations or exceptions existed. The bank should not transform a third party's assurance report into a conclusion about a different workflow. Additional testing may be necessary to establish that the actual records are usable.

Status can change. Licence restrictions, enforcement findings, mergers, new processing locations or material subcontractors can affect the arrangement. Define how changes are identified and assessed. A review frequency can help, but relevant events may require action sooner. Record who decides whether to suspend new reliance, require direct CDD or reassess existing customers. The bank should distinguish a manageable provider issue from a failure that undermines an eligibility condition or evidence access. The response should be tied to the actual risk and legal framework, not a generic vendor traffic-light rating.

Information handover at onboarding

Define the receiving data contract. It should identify necessary customer information, covered CDD elements, verification context, relevant dates and provenance. A provider can return structurally valid data while omitting the meaning the bank needs. An owner field might refer to legal ownership rather than beneficial ownership. A verified status might mean that a document was scanned, not that authenticity and identity matching were assessed. The bank should understand and document those semantics. Staff and systems need to know what the result establishes and what remains unresolved.

The receiving workflow should check completeness against the applicable scope, not against whatever fields the provider happens to supply. An individual record and a legal-person record can require different information. A trust or similar arrangement introduces roles and powers that cannot be represented reliably by a single shareholder percentage. Missing mandatory information should create an exception with a named reviewer. Optional or irrelevant fields should not create unnecessary barriers. The requirements should distinguish genuine omissions from cases where a field is not applicable under the approved procedure.

Preserve both source information and the bank's interpretation. Normalising addresses or names can support screening, but investigators may need the original spelling and document context. Ownership calculations can require interpretation of chains or control rather than direct percentages. The bank should retain the evidence behind material transformations. A customer acceptance decision should not depend on an opaque score without a route to review the underlying information. Where automated summaries are used, preserve sources and uncertainty so a convenient narrative does not replace the actual evidence.

Documentary retrieval is an operating capability

Identify the route for requesting supporting documents and the responsible contact or service. Define how the request is authenticated, how information is transferred lawfully and securely, and how exceptions are escalated. The applicable obligation may require access without delay; do not turn that into an arbitrary longer period merely because it suits the contract. Test realistic requests, including older files, customers whose relationship has ended and records held by a subcontractor. A provider prepared in advance can demonstrate a process that ordinary operational requests do not receive.

Check content as well as speed. A quickly returned document may relate to the wrong customer, be incomplete or post-date the original decision. It may show identity but not the ownership evidence used. The bank should reconcile the returned material to its customer identifier, source date, covered task and decision. Where a discrepancy exists, preserve the request and result and assess whether it affects the customer's CDD or the wider arrangement. Repeated retrieval defects can indicate that the provider's controls do not support the intended reliance population.

Retrieval should survive change. A migration may move records to an archive not connected to the customer portal. A provider acquisition can alter access rights or contacts. A contract exit can remove login access even though records remain physically stored. Establish an agreed continuity route and test it before termination. The bank may choose to retain appropriate copies through controlled processes where lawful and suitable, but that choice still needs retention, access and purpose controls. Evidence availability should not depend on goodwill from a salesperson after the commercial relationship ends.

Outsourced CDD needs bank-controlled procedures

For outsourced work, define the procedure and expected decisions in sufficient detail for the service. Specify accepted sources, verification methods, discrepancy handling, rejection or escalation rules and the evidence produced. The provider should not silently substitute its own lower standard for commercial convenience. Changes to its workflow may affect the bank's controls even if the API remains technically compatible. Require relevant change notification and assessment. A software update that changes what verified means can undermine a customer decision without changing any field names.

Quality review should include accepted, rejected and exception cases. Accepted cases reveal whether weak evidence passes. Rejected cases reveal avoidable customer barriers or inappropriate rules. Exceptions reveal whether staff escalate uncertainty consistently and whether the bank responds promptly. Include different document types, languages and customer populations actually supported. A high average success rate can conceal poor performance for a specific group. The bank should understand those limitations and provide proportionate alternatives where necessary, rather than treat every failed automated check as evidence of misconduct.

Distinguish operational error from fraud and from a reporting question. A wrong date entered by a provider may require correction and control review. A deliberately altered identity document may require investigation. Neither automatically establishes a particular reporting obligation without the applicable assessment. The provider's staff need clear routes to supply facts and preserve evidence. The bank retains responsibility for its own relationship and reporting decisions. A service agreement should not ask an unqualified vendor analyst to make legal conclusions beyond the approved role.

Introducers and incentives

Introducers can understand a customer's commercial context and help obtain information. They can also be motivated by referral fees or relationship pressure. The bank should separate introduction from acceptance authority and identify conflicts relevant to the arrangement. A referral carrying an urgent request to bypass ownership questions deserves examination. That does not mean every paid introduction is improper. The control asks whether the evidence is independent enough, whether the proposed service is coherent and whether the bank can make its own decision without relying on sales assurances.

Fee structures can influence behaviour. A payment triggered only by successful account opening may encourage incomplete disclosure. A bonus for rapid onboarding can discourage escalation. The bank should understand those incentives and design oversight proportionately. Monitor referral quality, repeated missing information, exception patterns and customer outcomes rather than only conversion rate. Compare populations by introducer where meaningful, while avoiding unsupported conclusions from small samples. A poor-quality pattern can justify stronger review or suspension of referrals; it does not itself prove that the customers are criminal.

Customer information obtained through an introducer should carry source and confidence. An introducer's statement about expected turnover is not the same as independently evidenced financial information. A claimed business purpose should be tested against the service and available facts. Where a customer cannot provide a standard document, staff should consider approved alternatives directly rather than allowing the introducer to invent or reinterpret evidence. The bank should have a route for customers to communicate without the intermediary if conflicts or inaccurate information emerge.

Ongoing changes and event-driven review

The arrangement should explain how material customer changes are recognised and shared where lawful. Ownership, control, address, service purpose and expected activity can change after onboarding. The provider may learn information through its own relationship that the bank does not yet know. Determine whether the arrangement includes relevant notification and how the bank assesses it. Do not assume that because initial information was suitable, it remains suitable indefinitely. Conversely, avoid collecting irrelevant updates simply because the provider can supply them; purpose and proportionality still matter.

The bank's own transaction monitoring and customer contact can reveal inconsistencies with the third-party file. A company presented as a local retailer may begin receiving large cross-border transfers from unrelated parties. The bank should assess the activity using its available facts and obtain further information through the appropriate route. It should not send every alert back to the provider as though the provider owns the bank's reporting decision. The investigation can identify a customer issue, a stale file or a weakness affecting the wider reliance population. Those outcomes need separate owners.

Reassessment can be targeted. If one provider's beneficial-ownership process is defective, identify which legal-person records and periods are affected. A blanket review of every introduced individual may be unnecessary, while sampling only new customers can miss the historical exposure. Define the population, method, evidence and escalation. Where reliable records cannot be obtained, assess the appropriate response under local law and policy. The bank should preserve why it chose direct CDD, restrictions, suspension or another permitted action, rather than record only that the partner rating changed.

Reusing evidence within a financial group

A shared group customer record can reduce unnecessary duplication, but its existence does not determine the legal character of the arrangement. Establish whether the receiving entity is using information within an approved group process, outsourcing work or relying on another entity under the relevant framework. Identify the service, customer relationship, local requirements and information permissions. The receiving bank still needs enough context for its own decision. A customer approved for a savings account at one subsidiary may seek a substantially different corporate or cross-border service elsewhere. The earlier file can be useful without being sufficient.

Group procedures should preserve which entity collected the evidence, when it was obtained and what checks it supported. A global verified field can erase those distinctions. If information is updated centrally, local entities need to understand whether the change affects their decisions and whether they can use it for the intended purpose. Access controls and reporting confidentiality remain relevant even when information moves within the same corporate family. Group membership should support governed cooperation rather than serve as an unexplained exemption from evidence and responsibility.

Test a second-entity application using an older shared record. The receiving workflow should identify relevant stale or missing information and provide a controlled route to obtain it. It should also avoid requesting information unnecessarily where reliable current evidence can be used lawfully. Test a group entity leaving the perimeter, because the arrangement and access rights may change. Preserve historical source identifiers and decisions. A service that works only while every company remains on the same platform may not support the bank's continuing record and investigation needs after a disposal.

Digital identity evidence and the wider CDD decision

A digital identity check can support identification and verification, but its output needs an understood assurance basis and operating context. The bank should know what evidence was assessed, which identity was linked and what limitations apply to the service. A high confidence score about one individual's identity does not establish the beneficial ownership of a company or the purpose of its proposed account. Treat digital capability as part of the relevant task rather than a shortcut around the other due-diligence questions.

Review the customer route when an automated method cannot assess a legitimate record. The bank can provide an approved alternative or a trained review process where appropriate. Staff should not invent missing facts to force a pass, while the system should not equate technical failure with criminal suspicion. Preserve the original result and subsequent evidence. Quality testing should examine both unsupported acceptance and unnecessary rejection for the populations the bank intends to serve. This makes automation accountable to the control outcome and customer decision, instead of allowing a vendor threshold to define the entire service.

Exit, insolvency and assurance

Before exit, reconcile customer populations, open requests, evidence holdings, retention obligations and pending issues. Determine what access remains necessary and what should end. A provider may hold information about several bank entities with different conditions, so one global deletion instruction can be inappropriate. Records management, legal, privacy and control owners should agree the plan. Test exports for content, readability, metadata and linkage, not only file counts. A folder containing thousands of documents without customer relationships is not a usable investigation archive.

If the provider becomes insolvent or unresponsive, use the agreed contingency arrangements and assess the actual control impact. Identify which required information is already held, which documents remain accessible and which customer decisions depend on unavailable evidence. Prioritise the affected population appropriately. Commercial recovery efforts do not replace the programme response. Senior management needs the exposure, options and constraints, including where continued services cannot be supported under the applicable framework. A contractual right that cannot be exercised is a limitation, even if the contract is well drafted.

Independent assurance should test the arrangement's defining conditions and operating results. Verify classification, current eligibility where relevant, immediate information handover, document retrieval, quality, change handling and exit readiness. Inspect material exceptions and rejected cases rather than only successful onboarding. State limitations in access or evidence. The conclusion should explain what the bank can demonstrate about its customer decisions and external dependencies. A mature arrangement combines external capability with internal accountability and evidence, rather than using outsourcing or reliance terminology to distance the bank from its own responsibilities.

Retrieval and quality tests

Select approved and rejected cases, request supporting evidence without advance preparation and compare it with the information used for the original decision. Check retrieval speed against the applicable obligation, content completeness, tampering controls, lawful transfer and survival after termination.

Test a provider outage, revoked licence, subcontractor change and contradictory ownership record. Each should have an owner and a route to suspend affected onboarding or reassess reliance where necessary. A provider scorecard should measure evidence defects and unresolved discrepancies alongside service availability.

Avoid treating group membership as a blanket exemption. Recommendation 17 contains specific group conditions and competent-authority discretion. Confirm the national treatment and group safeguards rather than assuming that an affiliated company automatically qualifies.

Reliance on Third Parties, Introducers and Outsourced CDD — evidence map

The arrangement object should drive the workflow

Create a governed arrangement record with its own identifier rather than burying the classification in a contract attachment. Record the relying or delegating bank entity, provider entity, approved role, tasks, customer scope, jurisdiction, effective dates and responsible owners. Link the approval and eligibility evidence. Distinguish a supplier's general availability from permission to use it for a particular CDD task. A provider may remain active for document scanning after its approval for a different arrangement has ended. One supplier-active flag cannot safely express those differences.

The customer workflow should reference the arrangement version used. If a task falls outside the approved scope, route it to the bank's direct process or an authorised alternative rather than silently extending the arrangement. Test a provider approved for individuals receiving a company application, a contract limited to one bank entity receiving another's request and an expired arrangement used during a retry. The expected result should preserve the application and identify the missing authority. The system should not merely reject a message and lose the prospective customer's work.

Material changes should produce impact events. An eligibility restriction, subcontractor change, new processing country or retrieval failure may affect specific tasks or populations. The workflow should identify affected active applications and existing records. Preserve the original approval and later reassessment. The bank needs to know which customers were accepted before and after the change and which require review. Updating a current arrangement record without history leaves that question unanswered and makes an eventual lookback unnecessarily difficult.

Separate provider results from bank decisions

A provider-result object should preserve the returned status, source fields, method, date, evidence references and relevant limitations. A bank-decision object should record the task outcome, applicable rule or policy, reviewer, rationale and exceptions. This separation prevents a vendor's confidence score from being mistaken for the bank's legal acceptance decision. It also allows the bank to correct its interpretation without altering the original provider response. A result that is technically valid can still be insufficient for the proposed customer or service.

Define statuses carefully. Document-present, authenticity-checked, identity-matched and customer-approved describe different outcomes. An API returning passed should have an agreed meaning that staff can inspect. If a score depends on unavailable or low-quality evidence, surface that condition. When a provider changes its scoring method, determine whether the bank's decision thresholds or procedures remain suitable. Do not accept a backwards-compatible schema as proof that the control meaning is unchanged. Semantic changes can be material even when every software test for field presence succeeds.

Beneficial-ownership results need relationship detail. Preserve persons, entities, ownership or control type, chain links, source and effective dates. A flat list of names may omit why each person is relevant and how indirect ownership was considered. The bank's review should identify unresolved ownership, contradictions and any local treatment applied. A provider confirming a director's identity does not establish that all beneficial owners have been identified. Acceptance tests should include direct ownership, layered ownership, control without a simple percentage and an updated chain after a sale.

Data contracts and exception handling

Define mandatory data by task and customer type. The receiving service should distinguish missing, not applicable, unknown and withheld under a relevant constraint. Treating all four as blank can hide important differences. For example, no ownership information supplied is not equivalent to no natural person meeting a particular ownership test where the relevant framework permits another identification route. The system should require enough context for an authorised reviewer to decide the next step. Default values such as zero ownership or verified unknown can make incomplete files look complete.

Retain source identifiers through normalisation and migration. Provider and bank identifiers should link to the customer, document and task without relying on a display name. Duplicate requests and retries need idempotent handling so one check does not create inconsistent results or multiple customer records. Test events received out of order, corrected information and a provider reusing an identifier. The receiving workflow should preserve chronology and detect ambiguity. Successful transport establishes that a message arrived; it does not establish that it belongs to the intended customer.

Exception queues need actionable context. A record rejected for an unrecognised document type should identify the customer, task, returned evidence and responsible reviewer. An error queue accessible only to engineers can delay required due diligence without business visibility. Conversely, unrestricted error logs can leak personal data or document content. Define appropriate operational views and escalation. Measure unresolved exceptions and affected customer populations, not just API availability. A service can have excellent uptime while repeatedly supplying information the bank cannot use.

Retrieval tests must be unpredictable and representative

Choose samples across provider, time, customer type, arrangement and processing route. Include accepted, rejected, corrected and migrated files, and records connected to terminated relationships. Request evidence through the normal process without allowing special advance preparation of the selected files. Compare the returned material with the information used for the original bank decision. Record request time, response time, completeness, customer linkage and any discrepancy. The timing standard should follow the applicable obligation and approved arrangement, rather than an arbitrary benchmark invented for the test.

Test failure rather than assume cooperation. Simulate a portal outage, unavailable contact, lost archive link and a provider response that contains the wrong customer's evidence. Confirm escalation and appropriate handling of new applications or existing review tasks. A contract clause granting access is not enough if nobody knows how to exercise it during an incident. The bank should understand what it can continue safely and what requires suspension or a direct process. Preserve the distinction between a temporary technical interruption and a structural inability to provide records.

Test lawful transfer and permitted use. A document may be retrievable technically but subject to restrictions affecting the receiving entity, purpose or location. The approved route should identify those conditions and necessary safeguards. The bank should not encourage staff to use personal email or a different portal account to bypass a limitation. If an alternative such as controlled local access is appropriate, test whether it can support the actual decision. An arrangement requiring evidence the bank cannot lawfully access may need a different operating model rather than a more forceful contract demand.

Quality testing for outsourced work

Define a test population reflecting the service the bank actually uses. Include relevant languages, document formats, customer groups, channels and risk situations. Test genuine inconsistencies and legitimate variations. A different transliteration, changed surname or alternative identity evidence may need review rather than automatic rejection. A tampered document or mismatch should not pass merely because all expected fields are present. The expected outcome should be agreed before testing with the appropriate control specialists. Avoid using the vendor's own output as the answer key for validating that output.

Investigate error patterns by population and cause. A high overall pass rate can conceal weak performance for legal persons or particular documents. A high manual-review rate can reflect good caution or poor automation; inspect the evidence before drawing a conclusion. The bank should identify whether defects arise from provider procedure, data transmission, bank interpretation or customer information. Assign the repair accordingly. Retraining provider staff will not fix a bank mapping that treats a non-applicable field as a missing mandatory item.

Preserve both false acceptance and unnecessary rejection findings. False acceptance can expose the bank to inadequate CDD. Unnecessary rejection can deny legitimate customers access and conceal a process that does not support the bank's intended population. Quality oversight should examine both. Where the provider cannot support a relevant population adequately, define a proportionate alternative or revise service scope. Do not hide the limitation through repeated manual overrides without measuring their frequency, authority and results. A growing exception route can become the real operating process without suitable governance.

Introducer controls and customer independence

The introducer record should identify the actual referring party, fee arrangement, relevant relationships and approved service scope. Customer applications should preserve the introducer source without allowing the introducer to approve the bank decision. Test a referral containing incomplete ownership information, an urgent override request and a changed beneficiary or contact. Confirm that the bank can contact the customer through an authorised route and resolve discrepancies independently. An introducer's familiarity can support context, but it should not prevent direct enquiry where necessary.

Monitor patterns that can reveal incentives undermining evidence. Repeated incomplete referrals, unusually high exception rates, identical customer narratives and attempts to split applications across channels deserve contextual review. A metric should identify the population and sample size; one problematic file does not establish that every referral is defective. Oversight should connect complaints and investigation findings to the introducer arrangement where relevant. If suspension is appropriate, the system should prevent new referrals through alternate identifiers and provide an approved route for customers already in progress.

Staff should understand that arrangement classifications cannot be changed informally to bypass controls. A relationship manager should not relabel an introduction as reliance because the provider declines further documents. A provider's sales representative should not expand the bank-approved task scope through an email. Changes require the responsible legal, compliance and contract assessment. Test who can edit the governing fields and whether approvals are preserved. An audit history that records only the final label cannot explain why the bank accepted a file under an arrangement later found unsuitable.

Exit acceptance and secure evidence continuity

Before terminating access, reconcile the affected customer inventory and the evidence needed under the bank's arrangements. Define export scope, formats, identifiers, metadata, encryption and receiving access. Test readability and linkage after import, not only transfer checksums. A valid archive containing unlabelled images can be technically intact and operationally unusable. Verify that open requests, holds and unresolved discrepancies remain visible. The exit plan should identify which records are retained where and which access or copies should be removed under the applicable requirements.

Use a realistic termination rehearsal. Remove ordinary portal access, change the primary contact and request a record through the agreed continuity route. Test the bank's ability to demonstrate an earlier customer decision without relying on the provider's production screen. Include insolvency or unresponsive-provider scenarios where commercially plausible. The bank should know which information it already holds, which dependencies remain and what action follows if access fails. Commercial penalties and indemnities can matter, but they do not restore a lost evidence chain or make an unsupported CDD decision defensible.

Final release and assurance evidence should connect classification, approval, workflow, records and customer outcomes. Show that the arrangement is used only within its approved scope, that required information reaches the bank, that documentary access works and that exceptions have authorised handling. Demonstrate quality across relevant populations and continuity through changes or exit. State limitations rather than using a provider certificate to imply more assurance than it contains. The architecture succeeds when external work strengthens the bank's own control decisions while responsibility and evidence remain clear.

Worked introducer case

A fictional introducer sends a customer name and a statement that identity checks are complete. The bank has no ownership information and the introducer is unwilling to provide underlying records. The first task is to classify the arrangement. If it is merely an introduction, the bank performs its own CDD. If permitted reliance is proposed, the eligibility and evidence conditions must still be met.

Identify what must be obtained immediately, what documentary retrieval must be demonstrable, and which ongoing obligations remain with the bank. A referral fee does not change the answer.

Review question: what exactly did the provider do?

A strong review follows a real task rather than relying on the arrangement's name. Identify the customer, bank entity, provider entity, information source, method, result and decision. Ask whether the provider acted under its own qualifying relationship or the bank's procedures, and which due-diligence elements were covered. If the team cannot explain those points, further contractual wording alone may not establish suitability. The workflow needs a classification and scope that staff can actually apply. Review the implementation against the approval so commercial changes do not silently expand the arrangement.

For an introduction, verify that the receiving process performs the bank's required work. For outsourced tasks, compare the work with the bank-approved procedure and inspect quality and exceptions. For permitted reliance, verify the relevant conditions and information access under the applicable framework. Avoid importing one category's controls into another without analysis. A successful document-scanning service does not establish reliance eligibility, while an eligible reliance arrangement does not automatically establish that a particular customer file is current and sufficient for the bank's proposed service.

Review question: can the bank retrieve the evidence it used?

Request a representative historical file through the normal route. Compare the returned information with the original bank decision, including identifiers, dates and covered tasks. Check completeness and relevance as well as response speed. A document created after the decision may support a current review but cannot automatically establish what was known originally. A quickly supplied file for a similarly named customer is a serious linkage failure. Preserve the request and discrepancy, assess the affected population and assign the response to the appropriate owner.

Repeat the test with ordinary access removed or a primary contact unavailable. Determine whether termination, migration or provider failure changes the result. The bank should have a controlled route for records it needs under its arrangements and retention obligations. Technical retrieval must also be lawful for the receiving entity and purpose. A route requiring staff to bypass restrictions through personal accounts is unsuitable. If evidence cannot be accessed adequately, senior management needs the limitation and the permitted alternatives, not only reassurance that the contract grants a right.

Review question: who resolves contradictory ownership?

A provider identifies one owner while the customer supplies a newer structure showing another. The workflow should preserve both sources and route the difference to an authorised reviewer. Determine whether the discrepancy reflects timing, direct versus indirect ownership, control, a data error or an unresolved concern. The bank's decision should state how the information was resolved and which further work remains. Do not let a provider score automatically override better evidence, or let a commercial sponsor choose the answer that avoids delay.

The resulting assessment can require current CDD, targeted provider remediation and potentially further investigation. These are separate outcomes. Missing or stale information is not automatically proof of crime. It also cannot be dismissed simply because the provider is reputable. The bank needs sufficient understanding for its own service under the applicable framework. Customer enquiries should be focused and proportionate, with appropriate alternatives where standard evidence is unavailable. Preserve the reasoning so future reviewers can assess the actual facts rather than infer that a green partner status resolved every concern.

Review question: what would make the arrangement stop being suitable?

Identify the events that could undermine eligibility, quality or evidence access. Examples include a relevant licence restriction, changed task scope, unavailable records, material subcontracting or persistent unresolved defects. Define who receives the event, who assesses it and how affected applications or existing populations are identified. A provider score dropping from green to amber is not a complete operating response. The bank may need direct CDD, suspended use of particular tasks, targeted review or another lawful measure depending on the actual conditions.

Test whether those decisions reach the workflow. A suspended arrangement should not remain usable through an old channel or a retry with a stale cached approval. Customers already in progress need an authorised route rather than disappearing into a technical error queue. Existing records may require review without indiscriminate re-onboarding of unaffected populations. The final assurance should demonstrate that classification, task results, bank decisions, evidence access and change responses operate together. That chain is the practical expression of retaining responsibility while using external capability.

Requirements and release evidence

Store arrangement type as a governed field, with the approved counterparty, covered CDD elements, jurisdiction and effective dates. Keep vendor scores separate from the bank's acceptance decision. The workflow should block completion when required information is absent and route discrepancies to a named reviewer.

Acceptance testing should prove that evidence can be retrieved for migrated customers and that vendor termination does not delete the bank's access to legally retained records. Contract owners and technology teams should agree export formats, access continuity and secure deletion only after retention obligations and holds expire.

The decisive question is whether the bank can support its own customer decision using admissible, current and accessible evidence. A successful API call alone proves only that a system returned a response.

Reliance on Third Parties, Introducers and Outsourced CDD — governance map

Alder Bank's business-account channel

Alder Bank is fictional. It plans to expand small-business accounts through three external relationships. Bridge introduces prospects and receives a referral fee. Identify provides document and identity checks under Alder's procedures. Anchor is a regulated institution with its own independent customer relationships; Alder proposes a defined reliance arrangement where local legal and compliance assessment permits it. The three names appear in one commercial programme, but their roles differ. The case assumes that relevant national eligibility conditions are separately assessed; it does not assert that every regulated institution qualifies for reliance everywhere.

The commercial dashboard groups all three channels under partner-approved. A business manager believes a green status means the bank can activate the account. The control team asks what the status establishes. For Bridge it means the prospect submitted a contact form. For Identify it means a document-processing task completed. For Anchor it means a defined information package was supplied under the approved arrangement. None is automatically identical to Alder's final customer decision. The first design repair is to classify each task and separate external results from the bank's acceptance workflow.

The introducer's certificate is not reliance

Bridge introduces Larch Components, a company seeking an operating account for supplier payments. The referral includes the director's name and a letter stating that Bridge knows the business well. Ownership details are absent. Bridge's account manager asks Alder to activate quickly because the customer has a payroll deadline. Alder's relationship team explains the information required for its service and follows the direct CDD process. It does not relabel the referral as reliance because Bridge is unwilling to provide more detail. A commercial certificate and an urgent need do not establish the arrangement's legal or evidential basis.

The company provides its registration identifier and ownership documents through an approved route. The first structure chart lists a holding company without the relevant natural-person information. Staff ask focused questions about the chain and control rather than requesting every imaginable document. The resulting evidence identifies the relevant owners and explains the business. The customer is not considered suspicious merely because the first submission was incomplete. The bank records the information and decision, while the referral-quality issue is linked to Bridge's oversight record. Customer acceptance and introducer performance are separate outcomes.

Bridge later sends several applications with nearly identical expected-turnover descriptions. Quality review finds that its sales staff use a standard template without checking the actual service. Some customers have legitimate businesses with different activity. The bank corrects the affected profiles and reviews the referral process. It considers the incentive to maximise approved applications and revises the introduction instructions. The evidence does not establish that every referred customer is dishonest. The control response should improve information quality and identify genuinely unresolved cases, rather than impose a blanket adverse label on the entire channel.

The identity vendor passes the wrong task

Identify processes the Larch director's identity evidence. Its response includes document-present, authenticity-checked and identity-matched results. Alder's adapter collapses those into CDD complete. A separate ownership task remains open, but the activation workflow checks only the collapsed status. In a controlled test, the account can therefore activate after a successful director check without completion of the required company due diligence. The API returns correct task results; the bank's interpretation is wrong. Requiring the vendor to improve uptime would not address this defect.

The team separates task results and the bank decision. Account activation now checks the required customer-specific tasks under the approved procedure. The source response remains preserved for review. A test with a legitimate individual account confirms that unnecessary corporate ownership tasks are not imposed. A legal-person test verifies that director identity does not substitute for beneficial-ownership understanding. A trust-like structure, where supported by the bank's service, tests whether relevant roles and powers can be represented. The acceptance criteria follow the actual population rather than a universal checklist generated from the vendor's field set.

Testing also reveals unnecessary rejection of customers whose names use a different transliteration between records. The provider result appropriately indicates a mismatch requiring review, but the bank adapter treats every mismatch as final rejection. Alder adds an authorised review path with evidence and rationale. The bank still addresses genuine inconsistencies and altered documents. It does not assume that every automated failure proves impersonation. This repair improves both customer treatment and control accuracy. Quality oversight therefore measures inappropriate acceptance and avoidable rejection, not only how quickly applications pass through the system.

A permitted reliance file becomes stale

Anchor supplies information for Cedar Wholesale under the separately approved reliance arrangement. Alder receives the necessary information for the covered tasks and assesses suitability for its proposed service. The file records ownership as of a specified date and identifies supporting documents available through Anchor. Three months later, Alder's customer contact reveals that a shareholder sold the business shortly before account opening. Anchor's record had not yet been updated. The problem is not solved by pointing to the arrangement's eligibility approval. The bank needs to assess the actual customer information and its continuing relevance.

Alder preserves the original information, obtains the current ownership context and evaluates whether the discrepancy affects its relationship decision. Anchor investigates why the change was not reflected. The bank considers whether other records accepted during the relevant period need targeted review. It does not assume that all Anchor customers are affected or that the sale itself is suspicious. The review separates a stale-data issue, provider process weakness and any unresolved customer concern. Appropriate local reporting assessment remains with the bank's responsible function where the available facts warrant it.

The contract did not specify how changes learned through Anchor's own relationship would be handled. Alder and Anchor agree an appropriately scoped process subject to applicable information-sharing rules. The bank also retains its own event-driven reviews based on its activity and contact. It does not outsource all continuing customer understanding by implication. The revised arrangement identifies covered information, recipients, purpose, timing and exception handling. The bank tests whether a change reaches an active customer-review task, rather than merely entering a provider inbox that no bank team monitors.

The retrieval test changes the assurance conclusion

Alder's independent reviewer selects twenty-four fictional records across the three channels, including older, rejected, corrected and migrated cases. The records are requested through the normal process without advance preparation. Bridge cannot provide identity evidence for several referrals because it never performed that work; those are assessed as introduction records, not failed reliance files. Identify returns the expected task evidence, but two images cannot be linked to the original task identifier. Anchor returns most supporting records promptly, while a migrated corporate file lacks the ownership evidence referenced in the original package.

The reviewer examines meaning rather than assigning one pass percentage to all providers. Bridge's scope requires better information quality but does not create a documentary reliance obligation it never accepted. Identify's linkage defect affects the bank's evidence chain for a defined population. Anchor's missing material affects retrieval and possibly the supporting CDD for relevant customers. Each issue has a different owner and response. A single supplier score would obscure those distinctions. The conclusion records what was demonstrated, which files remain unresolved and which broader populations require assessment.

The missing Anchor record is traced to an archive migration. The production portal stores current customer data, while older attachments reside under a different identifier in an archive. The contract promises retrieval, but the normal request process does not reach that archive. Alder requires a tested route and assesses whether the information originally used remains reliable. The repair includes identifier mapping, access continuity and representative retrieval tests. An assurance report that merely repeats the contractual promise would not establish the operating capability. The bank needs evidence that ordinary requests can reach the relevant records.

Provider change tests the exit plan

Identify is acquired by another service company and proposes moving processing to a new subcontractor. Alder reviews task quality, permitted data use, locations, access and the contract's change conditions. The acquisition is not automatically a reason to terminate the service, but it can change dependencies and risk. The bank pauses deployment of the new workflow until its approved assessment and tests are complete. Existing work continues only within the suitable authorised arrangement. The change process preserves which customer tasks were performed under each version and which populations require further attention.

The exit rehearsal removes Alder's ordinary portal access and requests an older task through the agreed continuity route. The first attempt fails because the new provider contact does not recognise the inherited arrangement. The contract owner resolves the route and retests. The bank also validates a controlled export containing customer links, task dates, source identifiers and relevant evidence. It checks readability after import and confirms treatment of open issues and retention conditions. Counting files alone would miss broken links and make the archive unsuitable for future investigation or authority requests.

What the bank can now defend

Alder's final programme record distinguishes introduction, outsourced work and permitted reliance, with task scope and approved entity conditions. It separates provider results from bank decisions, preserves source and current information, provides discrepancy handling and demonstrates record retrieval. Quality measures include evidence defects, unnecessary rejection, unresolved exceptions and affected populations. Commercial conversion and uptime remain useful measures but do not stand in for CDD effectiveness. The responsible managers can explain the specific value external parties provide and the responsibilities Alder continues to exercise.

The case does not teach that external support is inherently weak. The providers improve capacity and specialist capability when their roles and evidence are understood. The failure arose from imprecise classification, overbroad approval statuses and untested retrieval assumptions. Repairing those points produces a better customer process and a stronger control chain. A defensible arrangement is one the bank can explain at task and customer level, including what an external result establishes, what it does not establish and how uncertainty reaches an authorised decision maker.

References and further reading

Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.