AUSTRAC expects reporting entities, including AFS licensees, to only rely on third-party verification where they have reasonable grounds to trust the third party’s customer identification procedures and access to the underlying information. The reporting entity retains ultimate responsibility and must assess the reliability, independence, and ongoing suitability of the third party.
Expanded Answer
AUSTRAC permits reliance on third parties for aspects of customer due diligence, but only where the reporting entity can demonstrate that the third party applies equivalent AML/CTF standards and can provide verification data when required. Reasonable reliance requires an informed assessment of the third party’s systems, controls, and regulatory status, not a passive acceptance of their outputs.
In practice, AFS licensees should conduct due diligence on the third party before relying on them. This includes understanding how identity verification is performed, whether the third party is subject to AML/CTF regulation, and whether information can be accessed or reproduced if requested by AUSTRAC. Written agreements should define responsibilities, data access, and escalation processes. Reliance should also be periodically reviewed to ensure ongoing suitability.
Regulatory scrutiny increases where reliance is assumed rather than evidenced, or where the licensee cannot obtain underlying verification records. AUSTRAC assesses whether the reporting entity can demonstrate control and oversight, particularly where failures in customer identification or reporting occur. Weak third-party oversight is a common failure point, as highlighted in AML/CTF for financial planners and five AML questions you must be able to answer.
Why it matters
Improper reliance on third parties can lead to failures in customer identification and reporting, exposing AFS licensees to AUSTRAC enforcement. Responsibility cannot be outsourced, and gaps in third-party controls are treated as failures of the reporting entity.
Practical guidance
- Assess the third party’s AML/CTF controls, regulatory status, and verification methodology before relying on them
- Document reliance arrangements, including access to underlying data and responsibilities for compliance
- Review third-party performance regularly and test whether verification evidence can be retrieved and substantiated
Further reading
AML/CTF for financial planners
Five AML questions you must be able to answer