Compliance outsourcing: what you can hand over and what stays yours

Loona Järvloo
October 6, 2026

You can outsource almost every compliance task, from KYC checks to first-level alert review, but not the decisions and not the liability. From 10 July 2027, the EU Anti-Money Laundering Regulation says it outright: six tasks "shall not be outsourced under any circumstances", and the obliged entity "shall remain fully liable" for everything its provider does (Article 18, Regulation (EU) 2024/1624).
Outsourcing compliance buys you capacity. It never buys you a defence. The firms that get fined for it are the ones that confused the two.
What is compliance outsourcing?
Compliance outsourcing is paying a service provider to carry out compliance tasks on your behalf, such as onboarding checks, screening review or transaction monitoring, while the regulated firm keeps responsibility for the result. Under the AMLR, the provider is "regarded as part of the obliged entity" (Article 18(2)).
Outsourced KYC is the most common case: a provider collects documents, runs identity and company checks (KYB, UBO verification) and prepares the file, and your team decides.
Three things are often called outsourcing and are not:
- Software. Using third-party software, databases or screening services is not outsourcing, because the provider does not perform the requirement itself (recital 47, AMLR). Buying a KYC platform does not trigger Article 18.
- Reliance. Relying on another regulated firm's customer due diligence is a separate regime with its own rules, limited to identifying the customer and its beneficial owners and the purpose of the relationship, and "the ultimate responsibility" stays with you (Article 48(1), AMLR).
- Independent audit. The AMLR lets you have your controls tested by an external expert when you have no independent audit function (Article 9(2)(b)). That is assurance, not delegated compliance.
Outsourced KYC vs in-house KYC: which should you choose?
Outsourced KYC means a provider's staff review your files. In-house KYC means your own analysts do, usually on KYC software. Buying the software is not outsourcing; handing over the review is.
| Outsourced KYC | In-house KYC on software | |
|---|---|---|
| Who reviews the file | The provider's analysts | Your analysts |
| Who decides and stays liable | You (Article 18(2) and 18(3)(d)) | You |
| Supervisor notified first | Yes, from July 2027 under the AMLR (Article 18(1)); already in Germany | No, software is not outsourcing (recital 47) |
| Best for | Launch before hiring, volume peaks | Steady volume, judgement-heavy files |
Some payment providers also call it outsourced KYC when they onboard your customers under their own licence. That is a regulated partner doing its own due diligence, not you outsourcing yours.
Should you outsource compliance?
Outsource volume, peaks and expertise you need once, such as the licence application or the independent audit. Keep judgement, the MLRO and everything on the Article 18(3) list. A provider is a good answer to a backlog, a launch or a spike in screening alerts. It is a bad answer to a missing MLRO, an unwritten risk assessment or a team that cannot explain its own decisions, because the AMLR keeps all three with you.
What can't you outsource under the AMLR?
Article 18(3), Regulation (EU) 2024/1624 lists six tasks that stay in-house:
| Task that cannot be outsourced | Article 18(3) | What you can still outsource around it |
|---|---|---|
| Proposing and approving the business-wide risk assessment | (a) | Data gathering, drafting support |
| Approving internal policies, procedures and controls | (b) | Drafting, benchmarking |
| Deciding the customer's risk profile | (c) | Collecting the data the risk score uses |
| Deciding to enter a business relationship or carry out an occasional transaction | (d) | Document collection, checks, file preparation |
| Reporting suspicious activity to the FIU | (e) | Alert triage; the filing itself only by another obliged entity of your group in the same Member State |
| Approving the criteria for detecting suspicious or unusual activity | (f) | Tuning proposals, testing |
The pattern is simple: the provider can do the work, you make the call. Recital 48 says the "final decisions" on measures that implement your policies "should always rest with the obliged entity".
From July 2027, Article 18 adds four duties. Notify your supervisor before the provider starts (18(1)); sign a written agreement and run regular controls on the provider (18(4)); never let the arrangement stop the supervisor from retracing what happened (18(5)); and do not outsource to a provider in a high-risk third country unless it is a group entity under group-wide AMLR-grade policies and home-supervisor oversight (18(6)). You must also be able to show you understand "the rationale behind the activities carried out by the service provider" (18(2)). AMLA will publish guidelines on outsourcing by 10 July 2027 (18(8)).
What are the outsourcing rules before July 2027?
The current directive has no general outsourcing article: Article 29, Directive (EU) 2015/849 only says the reliance rules do not apply to outsourcing. The rules today come from sector law, guidelines and national transpositions:
- Banks, PIs and EMIs: outsourcing "cannot result in the delegation of the management body's responsibilities" (EBA/GL/2019/02, paragraph 35). For payment institutions, outsourcing must not "impair materially the quality of the payment institution's internal control" (Article 19(6), Directive (EU) 2015/2366).
- Crypto-asset service providers: outsourcing must not delegate responsibility, and the CASP must keep "the expertise and resources necessary" to supervise the provider (Article 73(1)(a) and (e), Regulation (EU) 2023/1114).
- UK: customer due diligence can be applied through an outsourcing provider only if you "remain liable for any failure" (MLR 2017, regulation 39(7)); firms outsourcing critical or important functions remain "fully responsible" (SYSC 8.1.6 R).
- Germany: you may have a third party carry out your internal safeguards after notifying the supervisor (BaFin for financial firms) in advance, and "the responsibility remains" with you (GwG section 6(7)).
- France: your procedures must provide for informing the ACPR when AML/CFT tasks go to an external provider, and the contract must give the ACPR access (arrêté du 6 janvier 2021, articles 9 and 10).
Can you outsource the MLRO?
Mostly no. The money laundering reporting officer, called compliance officer in the AMLR, is the person who files suspicious transaction reports (Article 69(6), AMLR), and that filing is on the non-outsourceable list.
The EBA allows a bank, PI or EMI to outsource the operational tasks of the AML/CFT compliance officer, but says "strategic decisions in relation to AML/CFT should not be outsourced". It allows the whole function to be outsourced only by a firm with no staff other than its management body (EBA/GL/2022/05, paragraphs 68 and 71). In the UK, the nominated officer must be "an individual in the relevant person's firm" (MLR 2017, regulation 21(3)). Inside a group, the AMLR lets a small, low-risk entity share a compliance officer with another group entity (Article 11(2)).
An interim MLRO on a contract is common between hires. An MLRO-as-a-service who signs reports for a dozen unrelated firms is the arrangement supervisors look at hardest.
What happens when outsourced compliance fails?
The regulator fines you, not the provider. In 2024 the FCA fined CB Payments, Coinbase's UK e-money firm, £3.5 million. The firm had outsourced important functions within its group and "was entitled to outsource these functions but it remained responsible at all times for ensuring that it complied" (FCA final notice, paragraph 4.4).
Worked example: a CASP outsources alert review
A crypto-asset service provider authorised under MiCA hands first-level screening review to a provider. The contract says the provider reads each sanctions, PEP and adverse media hit, closes nothing and recommends one of three outcomes with a written reason. The CASP notifies its supervisor before go-live, samples the provider's recommendations every week and keeps three things in-house: the decision on each customer, the risk profile and every report to the FIU.
That split is right because recommendation and decision are different jobs, and most of the volume is mechanical. On Dotfile, 64% of check decisions are taken automatically, by Dotfile or by customers' own systems through the API, and 36% by a person. Delegating volume is normal. Delegating judgement is what the AMLR forbids. The case decision stays with your team.
Method: Dotfile analysis, October 2026. Check approvals and rejections in customer workspaces on Dotfile over the past year, by who took them; aggregates only.
How to choose a compliance outsourcing provider: checklist
- List the tasks you plan to outsource and check none is on the Article 18(3) list.
- Notify the supervisor before the provider starts.
- Sign a written agreement: scope, your policies applied, audit and access rights for you and the supervisor, sub-outsourcing, exit.
- Keep someone in-house able to understand and challenge the provider's work: your second line (see the three lines of defence).
- Sample its output regularly and report the results to the board.
- Keep every decision, risk profile and report in your own name.
How Dotfile fits
Dotfile is software, which the AMLR does not treat as outsourcing (recital 47). It runs the checks and applies the rules you configure. AI agents can clear the obvious screening false positives with a written reason, under rules your team sets, and send the rest to a reviewer whose decision is logged under their name. The decisions Article 18(3) reserves for you stay inside your team, whether your analysts are in-house or outsourced. Clearing a hit under criteria you approved is applying your rules, not setting them: the rules stay yours. See Autonomy.
FAQ
Is using a KYC provider outsourcing?
Not if you use its software or data and make the decisions yourself (recital 47, AMLR). It becomes outsourcing when the provider carries out a compliance task for you, such as reviewing files.
Who is liable when an outsourced KYC provider makes a mistake?
You are. The obliged entity "shall remain fully liable for any action, whether an act of commission or omission" by the provider (Article 18(2), AMLR).
Do I need to tell the regulator before outsourcing?
From July 2027, yes: the AMLR requires notice before the provider starts (Article 18(1)). Germany already requires prior notice today (GwG section 6(7)); in France, the ACPR must be informed and kept informed of any significant change (arrêté du 6 janvier 2021, article 9).
Can a group company file suspicious activity reports for us?
Only if it is an obliged entity in the same group and the same Member State (Article 18(3)(e)).
Is outsourcing cheaper than hiring?
When the provider's price per file is below your own loaded cost per file: analyst time, plus the tools and the management around it. It never takes the MLRO's salary off the budget. See the cost of a compliance team for the build vs buy maths, and how to build a compliance department for what to keep in-house first.

Ready for Anywhere?
Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.



