FAQ

What is considered “reasonable reliance” on third-party verification?

AUSTRAC expects reporting entities, including AFS licensees, to only rely on third-party verification where they have reasonable grounds to trust the third party’s customer identification procedures and access to the underlying information. The reporting entity retains ultimate responsibility and must assess the reliability, independence, and ongoing suitability of the third party.

Expanded Answer
AUSTRAC permits reliance on third parties for aspects of customer due diligence, but only where the reporting entity can demonstrate that the third party applies equivalent AML/CTF standards and can provide verification data when required. Reasonable reliance requires an informed assessment of the third party’s systems, controls, and regulatory status, not a passive acceptance of their outputs.

In practice, AFS licensees should conduct due diligence on the third party before relying on them. This includes understanding how identity verification is performed, whether the third party is subject to AML/CTF regulation, and whether information can be accessed or reproduced if requested by AUSTRAC. Written agreements should define responsibilities, data access, and escalation processes. Reliance should also be periodically reviewed to ensure ongoing suitability.

Regulatory scrutiny increases where reliance is assumed rather than evidenced, or where the licensee cannot obtain underlying verification records. AUSTRAC assesses whether the reporting entity can demonstrate control and oversight, particularly where failures in customer identification or reporting occur. Weak third-party oversight is a common failure point, as highlighted in AML/CTF for financial planners and five AML questions you must be able to answer.

Why it matters
Improper reliance on third parties can lead to failures in customer identification and reporting, exposing AFS licensees to AUSTRAC enforcement. Responsibility cannot be outsourced, and gaps in third-party controls are treated as failures of the reporting entity.

Practical guidance

  • Assess the third party’s AML/CTF controls, regulatory status, and verification methodology before relying on them
  • Document reliance arrangements, including access to underlying data and responsibilities for compliance
  • Review third-party performance regularly and test whether verification evidence can be retrieved and substantiated

Further reading
AML/CTF for financial planners
Five AML questions you must be able to answer

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?