Reliance vs outsourcing — two different AML routes
These are two different legal mechanisms with two different sets of conditions, and firms routinely describe one while operating the other. Reliance under Articles 48 and 49 of Regulation (EU) 2024/1624 means using due diligence another obliged entity has already performed on that customer. Outsourcing under Article 18 means having a provider perform tasks for you. The counterparty differs, the permitted scope differs, the paperwork differs, and the supervisory notification differs. Getting the label wrong is not a drafting problem — it puts a firm inside a regime whose conditions it has not met.
1. Reliance — Articles 48 and 49
Obliged entities may rely on other obliged entities, whether located in a Member State or in a third country, to meet the customer due diligence requirements in Article 20(1), points (a), (b) and (c) — identifying and verifying the customer, identifying beneficial owners and taking reasonable measures to verify their identity, and assessing the purpose and intended nature of the relationship. Article 48(1) sets two conditions:
- the other entity applies the customer due diligence and record-keeping requirements of the Regulation, or equivalent requirements where it resides or is established in a third country; and
- its compliance with AML/CFT requirements is supervised in a manner consistent with Chapter IV of Directive (EU) 2024/1640.
Ultimate responsibility remains with the entity that relies. Article 48(1) says so in terms. And Article 48(2) requires the geographical risk factors in Annexes II and III, plus relevant Commission, AMLA or competent-authority material, to be taken into account when deciding to rely on an entity located in a third country.
That scope limit is the practical heart of the article. An introducer arrangement can lawfully deliver you an identified and verified customer with its ownership structure understood and its purpose assessed. It cannot deliver you a screened customer, an understood line of business, or a monitored relationship. If the commercial description of the arrangement covers those, the arrangement is not reliance — whatever the contract calls it.
2. The five-working-day rule, and the paperwork behind it
Article 49 makes reliance operational rather than nominal. Under Article 49(1) the relying entity must obtain from the entity relied upon all necessary information concerning the Article 20(1)(a) to (c) measures, or concerning the business being introduced. Article 49(2) then requires it to take all necessary steps to ensure that, on request, the entity relied upon provides:
- copies of the information collected to identify the customer;
- all supporting documents or trustworthy sources used to verify the identity of the client and, where relevant, of beneficial owners or persons on whose behalf the customer acts — including data obtained through electronic identification means and relevant trust services under Regulation (EU) No 910/2014; and
- any information collected on the purpose and intended nature of the relationship.
Article 49(3) fixes the clock: that information must be provided without delay and in any case within 5 working days. Article 49(4) requires the conditions for transmitting it to be specified in a written agreement between the obliged entities. An arrangement with no contractual mechanism capable of meeting the deadline is not a workable reliance arrangement, and the gap will surface at the worst moment — when a supervisor, an FIU or a correspondent asks for the underlying verification on a file you did not perform.
Two structural routes soften this inside a group. Article 48(3) allows the Article 48 and 49 requirements to be met through group-wide policies, procedures and controls, provided the relied-upon entity is in the same group, the group applies AML/CFT policies, customer due diligence and record-keeping fully compliant with the Regulation or equivalent third-country rules, and effective implementation is supervised at group level by the home Member State supervisor under Chapter IV of Directive (EU) 2024/1640, or by the third country under its own rules. Where those conditions are met, Article 49(5) lets a group-level internal procedure replace the written agreement.
3. The third-country lines — two different bans
Both mechanisms are cut off at high-risk third countries, and the two cut-offs are worded differently.
Reliance. Article 48(4) prohibits relying on obliged entities established in third countries identified under Section 2 of Chapter III. There is one carve-out: a Union-established obliged entity whose branches and subsidiaries are in those third countries may rely on those branches and subsidiaries, provided all the Article 48(3) group conditions are met.
Outsourcing. Article 18(6) similarly bars outsourcing to service providers residing or established in those third countries unless all three conditions are met: the tasks go solely to a provider that is part of the same group; the group applies fully compliant or equivalent AML/CFT policies, due diligence and record-keeping; and implementation is supervised at group level by the home Member State supervisor under Chapter IV of Directive (EU) 2024/1640.
Both routes therefore narrow to the same practical answer for a high-risk jurisdiction: intra-group only, on group-wide policies, under group-level supervision. What differs is what you get at the end — a customer file someone else built, or a task someone else performs under your own procedures.
4. Outsourcing — Article 18 in its own right
Article 18(1) is permissive and immediately conditional: obliged entities may outsource tasks resulting from the Regulation to service providers, and shall notify the supervisor of the outsourcing before the service provider starts to carry out the outsourced task. That is an ex-ante notification, not a periodic disclosure in an annual return.
Article 18(2) then sets the conceptual frame that explains everything else: when performing these tasks, service providers shall be regarded as part of the obliged entity — including where they consult the central beneficial-ownership registers under Article 10 of Directive (EU) 2024/1640 on the obliged entity’s behalf. The obliged entity remains fully liable for any act or omission connected to the outsourced tasks, and must be able to demonstrate to its supervisor that it understands the rationale behind the provider’s activities, the approach followed, and how those activities mitigate the specific risks the firm is exposed to.
Article 18(3) sets the hard floor. Outsourcing must not materially impair the quality of the firm’s policies and procedures or the controls that test them, and six tasks may not be outsourced under any circumstances:
| Art. 18(3) | Task that can never be outsourced |
|---|---|
| (a) | Proposing and approving the business-wide risk assessment under Article 10(2) |
| (b) | Approving the internal policies, procedures and controls under Article 9 |
| (c) | Deciding the risk profile to be attributed to the customer |
| (d) | Deciding to enter into a business relationship or carry out an occasional transaction |
| (e) | Reporting suspicious activity to the FIU under Article 69, or threshold-based reports under Articles 74 and 80 — except where outsourced to another obliged entity in the same group and the same Member State |
| (f) | Approving the criteria for detecting suspicious or unusual transactions and activities |
Point (e) is the one most often misread. The carve-out is narrow on two axes at once: same group and same Member State. A shared reporting function in another Member State does not qualify, however well governed.
Article 18(4) adds the diligence and contract layer: satisfy yourself the provider is sufficiently qualified before outsourcing; ensure the provider and any sub-outsourcing provider applies your policies and procedures; put the conditions in a written agreement; and perform regular controls on effective implementation, at a frequency set by how critical the task is. Article 18(5) closes the supervisory loop — outsourcing must not materially impair the supervisor’s ability to monitor and retrace the firm’s compliance.
5. Side by side
| Reliance (Articles 48–49) | Outsourcing (Article 18) | |
|---|---|---|
| Counterparty | Another obliged entity, supervised under Chapter IV of Directive (EU) 2024/1640 | Any sufficiently qualified service provider |
| What moves | Due diligence already performed on that customer | Performance of tasks on your behalf, under your policies |
| Scope | Article 20(1)(a), (b) and (c) only | Tasks arising from the Regulation, minus the six in Article 18(3) |
| Status of the counterparty | A separate obliged entity with its own obligations | Regarded as part of the obliged entity under Article 18(2) |
| Key limit | Ultimate responsibility stays with the relying entity | Full liability for acts and omissions stays with the obliged entity |
| Paperwork | Written agreement (Art. 49(4)), or a group internal procedure (Art. 49(5)) | Written agreement (Art. 18(4)), extending to sub-outsourcing |
| Supervisor | No notification duty in the Article | Ex-ante notification before the provider starts |
| Timing duty | Information on request within 5 working days | Regular controls, frequency set by criticality |
6. Three arrangements, three classifications
An identity-verification vendor in the onboarding flow. A payment institution uses a provider to capture documents, run a liveness check and return a verification result. Which rule: the provider is not an obliged entity performing due diligence on its own customer — it performs a task for the firm, so this is Article 18 outsourcing. What the firm does: notify the supervisor before the provider goes live; put the firm’s own procedures into the written agreement and extend them to any sub-processor; keep the risk-profile decision and the onboarding decision in-house under Article 18(3)(c) and (d). Outcome: the vendor may return a verification result, but a rule that auto-approves the customer on that result has outsourced point (d) and is non-compliant however good the vendor is.
An introducer that is a regulated EU credit institution. A bank introduces its corporate clients to an EMI for a payment product and supplies the identification and beneficial-ownership work it already did. Which rule: the counterparty is a supervised obliged entity and what moves is completed due diligence on that customer — Article 48 reliance. What the firm does: confirm the supervision condition, put a written agreement in place under Article 49(4) that can actually deliver the underlying documents in five working days, and run sanctions verification, the business-nature assessment and ongoing monitoring itself, because Article 20(1)(d), (e) and (f) are outside the reliance scope. Outcome: a file that survives a supervisory request, rather than one that points at another institution.
A group AML hub in a third country. A Union EMI wants its parent’s shared services centre, outside the EU, to run alert triage and draft suspicious-activity reports. Which rule: tasks performed for the firm, so Article 18. What the firm does: test Article 18(6) first — if the location is a third country identified under Section 2 of Chapter III, the arrangement is only available intra-group, on fully compliant or equivalent group policies, under group-level home-supervisor supervision. Then test Article 18(3)(e): the FIU reporting itself cannot be outsourced unless the recipient is in the same group and the same Member State, which a third-country hub is not. Outcome: triage and preparation can sit in the hub; the decision to report and the report to the FIU stay with the Union entity.
7. What to do, today
- Classify every existing arrangement as reliance or outsourcing in writing, on the counterparty test: is it another supervised obliged entity passing you its own completed due diligence, or a provider doing work for you?
- List your Article 18(3) tasks and prove they are in-house — particularly the customer risk profile and the onboarding decision, which automated vendor rules quietly absorb.
- Test each reliance agreement against the five-working-day clock by requesting a live file, not by reading the clause.
- Check the supervisor has been notified for every outsourcing, before go-live, and that sub-outsourcing is covered by the written agreement.
- Map the high-risk-third-country exposure in both directions: Article 48(4) for reliance, Article 18(6) for outsourcing.
The Regulation applies from 10 July 2027 (Article 90), and AMLA is to issue guidelines on reliance — including the acceptable conditions, the roles and responsibilities of the entities involved, and supervisory approaches — by 10 July 2027 under Article 50. Firms building introducer or group models now should design to the Articles and leave room for the guidelines, rather than waiting for them.
Can we rely on a provider that is not an obliged entity?
No. Reliance is available only in respect of other obliged entities whose AML/CFT compliance is supervised consistently with Chapter IV of Directive (EU) 2024/1640. A non-obliged provider is an outsourcing question under Article 18.
Does reliance transfer responsibility?
No. Article 48(1) states that ultimate responsibility for meeting the customer due diligence requirements remains with the entity that relies. Outsourcing is no different in substance: Article 18(2) keeps the obliged entity fully liable for acts and omissions connected to the outsourced tasks.
How quickly must the underlying documents arrive?
Without delay and in any case within five working days of the request, under Article 49(3). The conditions for transmitting them must be set out in a written agreement under Article 49(4), or in a group internal procedure where the Article 48(3) conditions are met.
Can we outsource suspicious activity reporting?
Only to another obliged entity belonging to the same group and established in the same Member State. Article 18(3)(e) otherwise prohibits outsourcing the report to the FIU under Article 69 and threshold-based reports under Articles 74 and 80. Alert triage and preparation are not the report.
Does reliance cover sanctions screening?
No. Reliance reaches Article 20(1)(a), (b) and (c) only. The targeted-financial-sanctions verification in point (d), the assessment of the customer’s business in point (e) and ongoing monitoring in point (f) remain with the relying entity.
Do we need to tell our supervisor?
For outsourcing, yes — Article 18(1) requires notification before the service provider starts to carry out the task. Article 48 imposes no equivalent notification for reliance, though the arrangement remains subject to supervision and to the Article 49 documentation duties.
Related: AMLR outsourcing · The customer risk profile · EBA remote onboarding guidelines


