AMLR outsourcing — six tasks you can never delegate
Six AML tasks become non-delegable under any circumstances — and one of them is the decision to onboard a customer. Article 18 of Regulation (EU) 2024/1624 lets obliged entities outsource tasks arising from the AMLR, then draws a hard line around a short list that may never leave the entity. It also requires the supervisor to be told before the provider starts, treats the provider as part of the entity, and closes the door on providers in high-risk third countries unless three conditions are met together. For anyone running an outsourced onboarding or monitoring model, this is the provision that decides whether the model survives.
1. The six tasks that can never be outsourced
Article 18(3) is unambiguous in its framing — these “shall not be outsourced under any circumstances“. There is no proportionality release and no supervisory waiver.
| # | Task | Anchor |
|---|---|---|
| 1 | The proposal and approval of the business-wide risk assessment | Article 10(2) |
| 2 | The approval of internal policies, procedures and controls | Article 9 |
| 3 | The decision on the risk profile attributed to the customer | — |
| 4 | The decision to enter into a business relationship or carry out an occasional transaction | — |
| 5 | Reporting to the FIU of suspicious activity, and threshold-based reports | Articles 69, 74, 80 |
| 6 | The approval of the criteria for detecting suspicious or unusual transactions and activities | — |
Items 3 and 4 are the ones that reshape outsourced onboarding. A provider may gather documents, run checks, score against your matrix and present a recommendation — but the attribution of the risk profile and the decision to enter the relationship have to be taken inside the obliged entity. Item 6 does the same for transaction monitoring: a vendor can build, tune and run the model, but approving the criteria that define what counts as suspicious stays in-house.
Item 5 carries the only carve-out in the list, and it is narrow. FIU reporting may be outsourced only where it goes to another obliged entity belonging to the same group and established in the same member state. A group-level reporting hub in another member state does not qualify.
2. Notify first, remain liable throughout
Three structural rules sit around the list. First, the entity must notify the supervisor of the outsourcing before the service provider starts to carry out the task — an ex-ante notification, not a register entry made afterwards. Second, when performing tasks under Article 18, service providers are regarded as part of the obliged entity, including where they consult the central beneficial-ownership registers under Article 10 of Directive (EU) 2024/1640 to carry out due diligence on the entity’s behalf. Third, the obliged entity remains fully liable for any act or omission connected to the outsourced tasks.
Then a knowledge duty that is easy to under-read: for each outsourced task the entity must be able to demonstrate to the supervisor that it understands the rationale behind the activities the provider carries out and the approach followed in their implementation, and that those activities mitigate the specific risks to which the entity is exposed. A black-box arrangement — where the entity can describe the service but not the method — fails this on its face, and it applies per task rather than per contract.
Article 18(3) also sets a quality floor: outsourcing must not be undertaken in a way that materially impairs the quality of the entity’s policies and procedures, or of the controls that test them. And Article 18(5) adds a supervisory-access floor: it must not materially impair the supervisor’s ability to monitor and retrace the entity’s compliance.
Facts: an e-money institution outsources onboarding to a provider that performs identity verification, screening and risk scoring, and auto-approves any customer scoring below a threshold, with exceptions referred back to the institution.
What the rule says: auto-approval means the provider is deciding the risk profile (item 3) and deciding to enter the business relationship (item 4). Both are on the never-outsource list, so the threshold model does not survive as designed.
What the practitioner does: keeps the provider’s work as an assessed recommendation and moves the decision inside the entity — which can be a systematic, automated decision executed on the entity’s own rules and recorded in its own systems, but must be the entity’s decision and evidenced as such. The approval of the scoring criteria comes back in-house at the same time, under item 6.
Outcome: the operating model barely changes; the decision record and the criteria ownership do — and those are what a supervisor inspects.
3. Provider diligence, the written agreement, and sub-outsourcing
Before outsourcing, the entity must assure itself that the provider is sufficiently qualified to carry out the tasks. After outsourcing, it must ensure that the provider and any subsequent sub-outsourcing provider applies the policies and procedures adopted by the obliged entity — the entity’s own framework travels down the chain rather than the provider’s.
The conditions must be laid down in a written agreement, and the entity must perform regular controls to ascertain that the provider is effectively implementing those policies and procedures. The frequency of those controls is not fixed by the Regulation; it is to be determined on the basis of the critical nature of the tasks outsourced. That is a risk-tiering obligation in disguise: to set a defensible frequency you first need a documented view of which outsourced tasks are critical.
4. High-risk third countries: three conditions, all of them
Article 18(6) derogates from the general permission. Obliged entities shall not outsource AMLR tasks to providers residing or established in third countries identified under Section 2 of Chapter III — the high-risk and other identified jurisdictions — unless all of the following are met:
- the entity outsources solely to a provider that is part of the same group;
- the group applies AML/CFT policies and procedures, customer due diligence measures and record-keeping rules fully in compliance with the AMLR, or equivalent rules in third countries; and
- the effective implementation of those requirements is supervised at group level by the home member state supervisor under Chapter IV of Directive (EU) 2024/1640.
The conditions are cumulative, and the first alone rules out every third-party offshore arrangement in an identified jurisdiction. Intragroup captives in those countries remain possible, but only inside a supervised group framework.
The neighbouring articles complete the picture for a group. Article 16 requires compliance functions at group level — a group compliance manager and, where justified by the activities carried out at group level, a group compliance officer, with the decision on the extent of those functions documented — and requires group entities to exchange information where relevant for due diligence and risk management, expressly including the suspicions reported to the FIU under Article 69 together with the underlying analyses, unless the FIU instructs otherwise. Article 17 then handles branches and subsidiaries in third countries with weaker requirements: the parent must ensure they comply with the AMLR or equivalent, and where third-country law does not permit compliance, must take additional measures and inform its home supervisor — with the supervisor empowered, if it judges those measures insufficient, to require the group not to enter into or to terminate business relationships, not to undertake transactions, or to close down its operations in that country.
Facts: a group runs a shared AML operations centre in a third country that appears on the identified-jurisdiction list, serving several EU entities, staffed by a group company.
What the rule says: being intragroup satisfies only the first condition. The group must also apply fully compliant or equivalent policies, due diligence and record-keeping, and that implementation must be supervised at group level by the home member state supervisor under Chapter IV of the Directive.
What the practitioner does: evidences the second and third conditions as a package — a group policy set mapped to the AMLR, and confirmation of the group-level supervisory arrangement — before assuming the centre can keep serving EU entities, and separately checks Article 17 for whether the third country’s law permits compliance at all.
5. What is still to come
By 10 July 2027 AMLA is to issue guidelines addressed to obliged entities on the establishment of outsourcing relationships, including subsequent sub-outsourcing, their governance and the procedures for monitoring the provider’s performance of functions — and in particular those functions to be regarded as critical — on the respective roles and responsibilities of entity and provider, and on supervisory approaches to outsourcing.
Until then the critical-function definition that drives control frequency is the entity’s own to justify. Firms already maintaining a DORA register of information and a CSSF-style outsourcing register have a head start, because the AMLR notification duty and those regimes ask overlapping questions from different angles — see our notes on the DORA register and Circular CSSF 22/806.
6. FAQ
Can we outsource customer onboarding?
Partly. The verification, screening and analysis can be outsourced; the decision on the customer’s risk profile and the decision to enter into the business relationship cannot be, under any circumstances. The provider’s output has to function as a recommendation on which the entity decides and records its decision.
Can a group hub file our suspicious transaction reports?
Only if it is another obliged entity in the same group and established in the same member state. A hub in a different member state does not meet the carve-out in Article 18(3)(e).
Do we have to tell the supervisor before we outsource?
Yes. Article 18(1) requires notification to the supervisor before the service provider starts to carry out the outsourced task.
Does outsourcing transfer any liability?
No. Service providers are regarded as part of the obliged entity when performing these tasks, and the entity remains fully liable for any act or omission connected to them.
How often must we control the provider?
The Regulation sets no fixed frequency — it must be determined on the basis of the critical nature of the tasks outsourced. In practice that means documenting which outsourced tasks are critical before you can defend the cadence. AMLA guidelines on critical functions are due by 10 July 2027.
Can we use a provider in a high-risk third country?
Only where all three conditions in Article 18(6) are met together: the provider is part of the same group, the group applies fully compliant or equivalent policies, due diligence and record-keeping, and implementation is supervised at group level by the home member state supervisor.
7. What to do, today
- Test every outsourced flow against the six. The question is not what the contract allocates but where the decision is actually taken and whether the entity can evidence taking it.
- Fix auto-approval first. Threshold-based automatic onboarding executed by a provider is the most common arrangement that fails items 3 and 4, and it is fixable without changing the vendor.
- Bring the detection criteria back in-house even where the model stays with the vendor. Approving the criteria is item 6.
- Write the “we understand the method” evidence now, per task — the rationale, the approach, and how it mitigates your specific risks. It is a demonstrable duty and nobody produces it well retrospectively.
- Tier your outsourced tasks by criticality and set control frequency off that tier, so the cadence has a stated basis before the AMLA guidelines arrive.
Related: the EU AML package timeline · the DORA register of information · Circular CSSF 22/806 on outsourcing · agents, distributors and liability under PSD2


