Third-party and partner due diligence: the control framework
Outsourcing payment flows, distribution or onboarding to partners does not outsource the regulatory obligation. Firms remain responsible for the financial crime risks introduced by third-party relationships, and the FCA expects a proportionate control framework.
Third-party and partner relationships are one of the most complex areas of financial crime risk management. A firm that distributes its products through agents, relies on third parties for onboarding, or routes payments through a partner's infrastructure absorbs the financial crime risk that comes with those relationships, regardless of what the contract says.
The MLR 2017 and the FCA's Financial Crime Guide both make clear that reliance on a third party to conduct CDD does not transfer the regulatory obligation: the firm remains responsible for the adequacy of the checks. The same principle applies to the financial crime risk introduced by the third party's own customer base and activity.
The three categories of third-party risk
Third-party financial crime risk arises in three main forms. The first is CDD reliance: a firm uses a third party to conduct customer identification and verification on its behalf. The second is distribution risk: a firm's products are sold through agents or intermediaries whose own AML controls may be inadequate. The third is flow risk: a third party routes payments or processes transactions on behalf of the firm, introducing counterparties and jurisdictions that the firm has not directly assessed.
Each category requires a different control response. CDD reliance needs a documented due-diligence assessment of the third party's CDD quality before reliance is placed, and a process for obtaining the records on request. Distribution risk needs an agent or distributor oversight programme that monitors sales patterns and customer quality. Flow risk needs a correspondent or partner due-diligence programme that assesses the AML controls of the routing party.
What the due-diligence programme looks like
The Wolfsberg Correspondent Banking Principles and the JMLSG Guidance on outsourcing both describe what a partner due-diligence programme should cover: the partner's ownership and management, its regulatory status and compliance history, the quality of its AML programme, its jurisdiction risk profile, and the nature and volume of the business being introduced.
Due diligence at onboarding is necessary but not sufficient. Partners need to be re-assessed periodically and when material changes occur, including changes of ownership, significant growth, or adverse regulatory findings. A partner that passed due diligence three years ago and has since tripled in size, changed its product mix, or received a supervisory finding may no longer meet the firm's standards.
Monitoring the flow
Once a partner relationship is established, the firm needs to monitor the flow of business being introduced or processed through it. A partner whose customer base begins to show elevated levels of suspicious activity, whose transaction patterns shift materially, or whose customers start failing screening more frequently is a signal that should trigger a review of the relationship.
Transaction monitoring rules need to be applied to third-party-originated flows in the same way as direct customer flows. A firm that has a transaction monitoring gap for one distribution channel or payment rail is not managing its third-party risk; it has simply shifted it off-screen.
Contractual protections and exit
Contracts with partners should include the right to audit, the obligation to report suspicious activity to the firm, the right to terminate if AML standards are not maintained, and a requirement to cooperate with regulatory inquiries. These are not standard commercial terms and need to be negotiated specifically.
The firm also needs a clear exit process for situations where a partner's risk profile deteriorates. A relationship that cannot be exited quickly without disrupting the business creates the wrong incentive: if exiting a partner is painful enough, the business may delay or avoid it even when the risk signals are clear. The FCA expects that firms have planned for exit, not just entry.
Common weaknesses
The most common weaknesses in third-party financial crime risk management are: due diligence that is completed at onboarding but never refreshed; monitoring that does not cover third-party-originated flows; and contracts that lack adequate AML obligations or audit rights.
A second pattern is that partner due diligence is owned by a procurement or commercial team rather than by the financial crime or compliance function. Where the team assessing a partner does not have the financial crime expertise to evaluate the adequacy of its AML programme, the due diligence exercise is largely procedural rather than substantive.
Try the tool
The Partner Control Map designs a control framework for your specific third-party or partner payment flow, assigning ownership and identifying gaps based on your relationship structure.
Map controls for your partner relationshipsSources
- JJMLSG · JMLSG Guidance
- FFCA · FCG
- MMLR · MLR 2017
- WWolfsberg · Wolfsberg Correspondent Banking Principles