← All articlesAll firms1 June 2026 · 6 min read

Relying on third parties for CDD: what you can and cannot delegate

What Irish designated persons can and cannot delegate when relying on third parties for customer due diligence under the AMLR - and who carries the risk.

A new client arrives at your firm mid-transaction. Their solicitor has "already done the AML". A referring accountant offers to send over the ID documents they collected last year. An introducer promises that everyone on their book is "fully verified".

Can you rely on any of that? Sometimes, yes - AML law has long allowed one regulated firm to rely on customer due diligence performed by another. But reliance is one of the most commonly misused shortcuts in Irish practice, and the AMLR - Regulation (EU) 2024/1624, applying from 10 July 2027 - keeps the core principle that catches firms out: you can borrow the work, but you cannot hand over the responsibility.

Reliance, outsourcing and tools: three different things

Firms often blur three arrangements that the rules treat differently.

ArrangementWhat it isWho does the CDD thinking
RelianceAnother obliged entity (a bank, solicitor, accountant) performed CDD on the client for its own purposes, and you rely on the outcomeThey gathered it; you still own the decision
OutsourcingA provider performs CDD tasks on your behalf, under your instructions and proceduresYou, acting through an agent
ToolingYou use software for identity verification or screening as part of your own processYou, with better equipment

Using an electronic identity verification tool is not "reliance" at all - it is simply how you perform your own CDD, and the AMLR explicitly recognises eIDAS-aligned electronic identification for that purpose. The reliance rules are about leaning on another regulated firm's completed work.

What you can rely on a third party for

Broadly, reliance covers the information-gathering elements of due diligence: identifying the client, verifying their identity, identifying beneficial owners, and gathering information on the purpose and intended nature of the relationship.

For that to be defensible, the third party needs to be the right kind of third party - itself an obliged entity, subject to AML obligations and supervision. A designated person supervised by the Law Society of Ireland, a designated accountancy body, the PSRA, the AMLCU or the Central Bank of Ireland is the sort of firm reliance was designed for. An unregulated introducer is not, whatever assurances they give.

Some of the finer conditions for reliance under the AMLR - and how it will work across borders - will be shaped by AMLA's technical standards, the first drafts of which were submitted to the European Commission around 10 July 2026 and are awaiting adoption. Keep an eye on amla.europa.eu before you rewrite your procedures around reliance.

What you can never delegate

This is the list that matters at inspection:

  • Responsibility. If the third party's CDD was inadequate, that is your problem, not just theirs. Reliance transfers work, never liability.
  • The risk assessment and the decision. Rating the client, deciding whether enhanced measures apply, and deciding to take them on at all are yours alone.
  • Ongoing monitoring. The relationship is yours, so monitoring it is yours.
  • Suspicious transaction reporting. If something looks wrong, your obligation to report to FIU Ireland through goAML - and to Revenue through ROS - is personal to your firm. You cannot assume someone else has reported.
  • Your RBO duties. Obtaining an extract from the Register of Beneficial Ownership before a new business relationship, and reporting discrepancies you find, are duties on you as the designated person entering the relationship.
  • Record-keeping. You must hold, or be able to obtain immediately, the CDD information you relied on. "The other firm has it" is not a file.

What good reliance looks like in practice

A hypothetical: a Cork accountancy practice takes on a company client referred by a Dublin solicitor who completed CDD three months ago for a related transaction. Handled well, the practice would:

  1. Confirm the solicitor's firm is a supervised obliged entity and record that check.
  2. Obtain the identification and verification information immediately - not a promise of it - along with confirmation of when and how it was gathered.
  3. Ensure copies of the underlying documents will be provided on request, and test that this actually happens.
  4. Perform its own risk assessment of the client, its own sanctions screening, and its own RBO extract and comparison.
  5. Record the whole arrangement on the client file: who was relied on, for what, and on what basis.

Handled badly, the file would contain a single email saying "AML done by solicitors". At inspection, that is a missing file.

Should a small firm rely on third parties at all?

Reliance saves the client from producing the same passport twice. But for a small Irish firm the economics are often weaker than they look. You still have to assess the third party, chase the documents, do your own screening, risk-rate the client and monitor the relationship. With modern electronic verification, doing the checks yourself is frequently faster than administering reliance - and it removes an inspection argument entirely.

A sensible middle position: allow reliance in your procedures for defined, genuinely useful cases (for example, within a transaction where another Irish regulated firm is already acting), require the full evidence trail every time, and default to doing your own CDD otherwise.

What to do now

  • Search your current files for clients where you relied on another firm's CDD, and check what evidence you actually hold.
  • Write reliance into your procedures explicitly: who may be relied on, for which elements, and what must be on file.
  • Make the non-delegable list - risk decisions, monitoring, STRs, RBO duties, records - explicit in staff training.
  • Test one reliance arrangement end to end: can you actually get the underlying documents on request, today?
  • Review any introducer relationships and drop any that amount to relying on an unregulated party.
  • Diarise a review of your reliance procedures once AMLA's technical standards are adopted.

Where CompliDesk fits

CompliDesk Ireland keeps every element of the client file - your own checks and anything you relied on - in one evidenced record, built around Regulation (EU) 2024/1624. For the full picture of what changes in July 2027, start with the AMLR explainer.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist