CySEC AML · Chapter 6 · Topic 12 of 14

Can a firm rely on a third party for CDD?

Which parts of CDD another regulated firm can perform, who qualifies as a third party, what the relying firm must check first, and why responsibility never moves.

By the ExamPass CY editorial teamLast reviewed 5 min read

Tested inAML · Ch 6

Short answer

Yes, for part of CDD. A firm may rely on a qualifying third party to identify and verify the customer and the beneficial owner and to obtain information on the purpose of the relationship, but ultimate responsibility stays with the relying firm. The third party must be a regulated firm or professional, or a similar institution that applies EU-standard CDD and record keeping and is supervised for it. Third parties in high-risk third countries are excluded, and outsourcing under which the provider counts as part of the firm is not reliance.

Reliance at a glance

What can be relied onIdentifying and verifying the customer and the beneficial owner, and information on the purpose and intended nature of the relationship
What cannotOngoing monitoring stays with the firm, and so does ultimate responsibility for all CDD
Who qualifiesCredit and financial institutions, auditors, external accountants, tax advisers, independent legal professionals and trust and company service providers, or other institutions in the EEA or a third country that apply CDD and record keeping consistent with the EU AML Directive and are supervised accordingly
When (CySEC rules)At the start of the relationship or occasional transaction, to verify identity; later updates come from the customer's own directors and beneficial owners
High-risk third countriesNo reliance, except on an EU firm's branch or majority-owned subsidiary that fully follows group-wide policies and has been exempted by the supervisor
Information and copiesThe CDD information is obtained from the third party immediately; copies of identification and verification data must be available immediately on request
CySEC's conditionsCheck the third party's registration and AML supervision, perform CDD on it, sign an agreement setting out each side's duties, keep a separate file, and obtain the AML Compliance Officer's approval
Outsourcing and agencyNot reliance where, under the contract, the provider or agent counts as part of the firm

Source: Law 188(I)/2007, Article 67; CySEC Directive, paragraph 25.

What can be handed to a third party?

Reliance covers the first three CDD measures: identifying and verifying the customer, identifying and verifying the beneficial owner, and assessing the purpose and intended nature of the relationship. Ongoing monitoring is not on the list; the firm that owns the relationship keeps watching it. Whatever is relied on, the relying firm remains ultimately responsible if the CDD turns out to be deficient.

Terms used in this note

Third party (reliance)
An obliged entity, or another supervised institution applying EU-standard CDD, whose CDD work a firm may rely on for a new customer.
Certified true copy
A copy confirmed as matching the original document by someone who has seen the original.
Outsourcing
Contracting a service provider to perform a function on the firm's behalf, so that the provider acts as part of the firm.

Who counts as a third party?

A third party is a credit or financial institution, an auditor, external accountant, tax adviser, independent legal professional or trust and company service provider covered by AML rules, or another institution or person in the EEA or a third country that applies CDD and record-keeping measures consistent with the EU AML Directive and is supervised in a way consistent with it.

Third parties based in high-risk third countries are off limits. The competent supervisor may exempt an EU obliged entity's branch or majority-owned subsidiary based there, if it fully complies with the group's policies and procedures. Within a group, supervisors may also accept that the firm meets the reliance conditions through its group programme, if the group applies EU-standard CDD, record keeping and AML programmes and is supervised at group level.

What must a firm do before relying on someone?

The law requires the firm to obtain the necessary CDD information from the third party immediately, and to make sure that copies of the identification and verification data, including electronic identification data, will be provided immediately on request. Under CySEC's rules those copies must be certified as true copies of the original documents collected during CDD.

CySEC adds practical steps. The firm confirms that the third party is professionally registered and supervised for AML purposes where it operates, carries out CDD on the third party itself before any business is introduced, signs an agreement that sets out each side's obligations, and keeps a separate file for each third party. Starting the cooperation, and accepting the third party's verified data, both need the AML Compliance Officer's approval.

CySEC also limits when reliance can be used: only at the start of a relationship or occasional transaction, to verify the customer's identity. Information needed later, to update the economic profile or look into unusual transactions, comes from the people who control and manage the customer, such as its directors and beneficial owners.

Is outsourcing the same as reliance?

No. When a firm outsources CDD work, or uses an agent, under a contract that makes the provider effectively part of the firm, the reliance rules do not apply: the provider's work is treated as the firm's own, and the firm's own procedures and oversight govern it.

How to think about it

Reliance moves the work, never the responsibility. Which measures? Only the first three. Who? A supervised firm applying EU-standard CDD, never one in a high-risk third country unless it is an exempted EU group entity. How? Vet the third party first, sign an agreement, get the AML Compliance Officer's approval and make sure certified copies will arrive the moment you ask.

Common mistakes

  1. Believing responsibility passes to the third party. Ultimate responsibility always stays with the relying firm.

  2. Relying on a third party for ongoing monitoring. Only identification, verification and the purpose of the relationship can be relied on.

  3. Relying on any regulated firm abroad. Third parties in high-risk third countries are excluded, save exempted EU group branches or subsidiaries.

  4. Waiting weeks for the documents. Certified copies must be available immediately on request.

  5. Treating outsourcing as reliance. Where, under the contract, the provider or agent counts as part of the firm, the reliance rules do not apply.

Practise this topic

Test what you just read

The Chapter 6 pack has 152 exam-style questions, 7 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 18 free Chapter 6 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error