Compliance

What is KYC reliance?

KYC reliance is a regulatory arrangement that lets one regulated firm use the customer due diligence (CDD) another regulated firm has already done, instead of repeating it. The firm that relies on those checks stays legally responsible if they turn out to be wrong.

For example, a bank may open a deposit account for a customer who already has a brokerage account with its affiliate. Instead of asking for the same documents again, the bank can rely on the broker-dealer's identity checks. The customer gets onboarded faster, but the bank answers to its regulator for the result.

Key facts about KYC reliance:

  • What it is: using another regulated firm's KYC checks instead of repeating them
  • Global standard: FATF Recommendation 17
  • Who stays responsible: always the firm that relies on the checks
  • Who can be relied on: regulated, supervised firms with similar CDD and record-keeping rules
  • What it isn't: outsourcing, where a vendor runs checks under your control, or reusable KYC, where you review shared data and decide yourself

What conditions must be met to rely on another firm's KYC?

The global baseline comes from the Financial Action Task Force (FATF). Recommendation 17 lets countries allow reliance on third parties. It also makes clear that the relying firm keeps the ultimate responsibility for CDD. The recommendation sets four conditions:

  • Get the information right away: the relying firm must collect the core CDD information at the start
  • Secure access to documents: the third party must hand over copies of ID data on request, without delay
  • Check the third party's oversight: the third party must be regulated or supervised, with CDD and record-keeping rules in place
  • Weigh country risk: where the third party is based must factor into the decision

National rules build on these conditions, and the details differ in ways that matter.

How do US, UK, and EU rules on KYC reliance compare?

All three keep responsibility with the relying firm. They differ on who counts as a valid third party.

United States. Under FinCEN's rules, banks can rely on another financial institution for their customer identification program, per 31 CFR 1020.220(a)(6).

A matching rule covers beneficial ownership checks. In both cases, the reliance must be reasonable. The other firm must also have an AML program, be regulated by a "Federal functional regulator," and sign a contract to certify its AML program every year.

That regulator list is short. It covers the Federal Reserve, OCC, FDIC, NCUA, SEC, and CFTC, per 31 CFR 1010.100(r). Fintechs that operate as money transmitters are licensed and examined by states, and no state regulator is on the list. So a partner bank generally can't use this rule to rely on their KYC.

United Kingdom. Regulation 39 of the Money Laundering Regulations 2017 allows reliance on other regulated firms, or on similar firms abroad. The relying firm "remains liable for any failure to apply such measures." It must also be able to get copies of ID data from the third party immediately on request.

European Union. From July 10, 2027, Article 48 of the Anti-Money Laundering Regulation lets regulated firms, called obliged entities, rely on each other. This covers firms in the EU and in non-EU countries with similar standards. Obliged entities include banks, payment institutions, and crypto-asset service providers. Firms in high-risk countries can't be relied on, and responsibility stays with the relying firm.

How is KYC reliance different from outsourcing and reusable KYC?

People often confuse reliance with two other ways to avoid repeat checks. The difference is who runs the checks and who decides:

Feature KYC reliance Outsourcing Reusable KYC
Who runs the checks Another regulated firm, for its own customer A vendor, on your behalf The first firm or its verification provider
Whose rules apply The third party's Yours The first firm's, then yours when you review
Who decides to onboard You, based on the third party's checks You You, after reviewing the shared data

Outsourcing is how identity verification APIs usually work. The vendor runs the checks, but you set the rules. Under Article 18 of the EU regulation, you stay "fully liable" for outsourced tasks. You also can't outsource key decisions, such as setting a customer's risk profile or choosing to take them on.

Reusable KYC moves a customer's verified data from one firm to another. The receiving firm reviews the data and decides for itself. That means it is doing its own CDD with better inputs, not relying on someone else's.

How does Due handle KYC from other platforms?

Due supports reusable KYC, not reliance, through Sumsub KYC Sharing. Per Due's documentation:

  • Import instead of re-verify: users verified on another Sumsub-integrated platform can share their data with a share token
  • Due decides: the shared data becomes a KYC submission that Due reviews, and the result arrives by webhook
  • No overrides: sharing can't replace an existing passed or failed KYC decision
  • Fallback: if Sumsub doesn't allow sharing, the user completes standard KYC

This covers individual users. Business accounts go through Due's standard KYB flow, and KYB sharing uses a separate endpoint.

Book a call to learn more about how Due onboards users.

Sources:

Continue learning

KYC reliance

Category
Read more

Prefunding

Category
Read more

CLABE (Clave Bancaria Estandarizada)

Category
Read more

NUBAN (Nigeria Uniform Bank Account Number)

Category
Read more

OUSD (Open USD)

Category
Read more

Meta transaction

Category
Read more

Gas fees

Category
Read more

Batch payments

Category
Read more

Wallet-as-a-Service (WaaS)

Category
Read more

Wallet screening

Category
Read more

KYT (Know Your Transaction)

Category
Read more

KYB (Know Your Business)

Category
Read more

Settlement finality

Category
Read more

Stablecoin redemption

Category
Read more

E-Money Token (EMT)

Category
Read more

MiCA

Category
Read more

Travel Rule

Category
Read more

CCTP (Cross-Chain Transfer Protocol)

Category
Read more

Stablecoin depeg

Category
Read more

FX risk (currency risk)

Category
Read more

Banking-as-a-Service (BaaS)

Category
Read more

ISO 20022

Category
Read more

Nostro and vostro accounts

Category
Read more

UETR (Unique End-to-End Transaction Reference)

Category
Read more

Stablecoin settlement

Category
Read more

Automatic reconciliation

Category
Read more

Balance reconciliation

Category
Read more

Identity verification API

Category
Read more

Interbank settlement

Category
Read more

Open banking

Category
Read more

FedGlobal ACH

Category
Read more

Ledger API

Category
Read more

Subsidiary ledger

Category
Read more

Cross-chain bridges

Category
Read more
Download Due & Move Money Without Borders