Financial institutions are ultimately responsible for outsourced anti-money laundering (AML) and countering the financing of terrorism (CFT) control functions.
Such outsourcing of AML/CFT control functions should be considered a material outsourcing, given the criticality of these controls and the access that AML/CFT service providers (ASPs) may have to sensitive customer information. Material outsourcing arrangements are particularly important as they have significant impact on the FIs’ operations, reputation and/or ability to comply with MAS’ laws and regulations.
- inadequate understanding of their ASPs’ practices; and
- lack of oversight and timely ongoing monitoring of ASPs post-appointment.
Stages of the Outsourcing Process
In general, the outsourcing process has three stages:
Stage 1: Due diligence of shortlisted ASPs
The FI performs a thorough due diligence of the potential ASPs. This is crucial in understanding and ensuring that the ASP is suitably competent to support the needs of the FI.
Stage 2: Review contract terms and engagement of ASP
Scope and terms of the engagement are finalised in an outsourcing contract after the FI has decided on a suitable ASP.
Stage 3: Post-engagement monitoring of ASP
The FI monitors and reviews the performance of the ASP in relation to the outsourced control functions, on a periodic basis.
An outsourcing arrangement does not equate to “Reliance on Third Parties” as defined in the AML/CFT MAS Notices.
Whereas, reliance on third parties under paragraph 9 of MAS Notice SFA04-N02 (or the relevant MAS Notices, depending on the type of FIs) is different from an outsourcing arrangement. The third party will perform the control function(s) according to its own AML/CFT policies, procedures and controls. Taking the example of performing CDD measures on a customer, the third party will typically have an existing relationship with the customer that is independent of the relationship to be formed by the customer with the relying FI.
FIs may refer to paragraph 9 of the relevant MAS Guidelines to AML/CFT Notices for more details.
Robust Assessment of ASPs During Stages 1 and 2 is a Crucial First Step
FIs can strengthen their due diligence frameworks by establishing:
Right tone set by the Board and Senior Management – It is crucial to set a formalised outsourcing policy, and for experienced AML/CFT compliance officer(s) to support the assessment of ASPs.
Structured assessment process with defined criteria – The suitability and ability of ASPs must be evaluated. FIs should perform gap analyses to assess if the ASPs’ AML/CFT policies and procedures adhere to MAS’ requirements.
A well-defined outsourcing agreement with clear scope and responsibilities of the ASP – FIs must scrutinise contractual terms to avoid expectations gaps, i.e. significant differences between the scope of outsourced AML/CFT control functions and the FIs’ intended scope of the arrangement. This ensures that key AML/CFT controls are implemented consistently.
Proper documentation of assessments and approvals – FIs should maintain clear basis for the appointment of ASPs. Documentation of due diligence undertaken by FIs will ensure that subsequent periodic reviews can be conducted consistently.
- The FI engaged an ASP to perform several AML/CFT control functions. However, the ASP did not perform certain key AML/CFT controls for an extended period of time, as the actual scope of the outsourcing agreement was narrower than intended by the FI.
- Another FI selected an ASP due to favourable commercial terms offered without a thorough review of the ASP’s AML/CFT practices. As the customer risk assessment framework used by the ASP differed from the FI’s framework, lower ML/TF risk ratings were assigned to some customers; enhanced CDD measures were thus not performed.
Regular Oversight over ASPs is a Necessary Control
- Board and Senior Management’s involvement – There should be effective oversight over outsourcing arrangements at all times. AML/CFT compliance officers’ role is to ensure outsourced control functions are performed as intended.
- Regular monitoring and defined escalation mechanisms – FIs should require ASPs to provide regular management reports on their execution of key AML/CFT control functions and ML/TF risk issues, such as status reports on CDD checks and periodic reviews. Escalation procedures for ASPs to surface pertinent ML/TF issues, such as potential sanction hits and material changes to the ASPs’ processes, should also be established.
- Regular quality assurance reviews – A formalised approach to conduct regular post-appointment reviews of ASPs is essential. This can be conducted through (i) regular sample reviews of ASPs’ work to ensure effective implementation; and/or (ii) regular discussions with ASPs to monitor that performance and control standards are met.
- The FI did not have defined metrics to assess the ASP’s performance of AML/CFT control functions, nor did it require the ASP to regularly provide status reports. As such, the FI was unaware that its ASP missed conducting periodic reviews on some high-risk customers for extended periods.
- Another FI relied on its ASP to escalate pertinent AML/CFT issues of its own accord, without clearly-defined circumstances. As a result, the ASP had dismissed potential positive screening matches, without first escalating to the FI for its consideration.



