AMLR Article 18: what you can and cannot outsource to a KYC provider
Article 18 of the AMLR lets you outsource KYC tasks, not the decisions or the liability. The conditions, the six reserved tasks, the recital 47 grey zone, a provider checklist and an outsourcing register.

In short
AMLR outsourcing is governed by Article 18 of the EU Anti-Money Laundering Regulation (AMLR), which applies from 10 July 2027.[1] You may hand tasks to a service provider under a written agreement, after notifying your supervisor and with regular controls, and you "shall remain fully liable" for the result.[1]
- Six tasks can never be outsourced, among them the onboarding decision.[1]
- Buying software or database access is not outsourcing, according to recital 47.[1]
- Where an automated verification service falls is not settled on 2 October 2026.
Most firms that run customer due diligence (CDD) under the AMLR will buy part of it from a know your customer (KYC) provider. Regulation (EU) 2024/1624 allows that, and draws three lines that sales pages tend to blur: who stays liable, which decisions never leave the firm, and when a purchase counts as outsourcing at all. This guide is vendor-neutral until the last section.
Reliance, outsourcing and tools: three arrangements, three sets of rules
The AMLR has two mechanisms for involving someone else in due diligence, and recital 47 describes a third situation that is neither.[1]
Reliance
Rely on another obliged entity
- Only another obliged entity
- Identity, beneficial ownership and purpose only
- Written agreement; copies within 5 working days
- "Ultimate responsibility" stays with you
Articles 48 and 49 AMLR
Outsourcing
A provider performs the task
- A service provider
- Any task except the six reserved ones
- Written agreement, notice to the supervisor, controls
- You "remain fully liable"
Article 18 AMLR
Tool use
You perform the task with a tool
- Software, databases, screening services
- Your staff perform the requirement
- "Not considered to be outsourcing"
- The requirement stays yours
Recital 47 AMLR
Reliance (Articles 48 and 49) is narrow. Article 48(1) lets you rely on "other obliged entities" for identity, beneficial ownership and purpose, not for sanctions checks, the politically exposed person (PEP) determination or ongoing monitoring.[1] A vendor that is not an obliged entity cannot be relied on.[1] A KYC provider therefore fits Article 18, or sits outside both mechanisms as a tool supplier. For the wider regulation, start with AMLR explained.
AMLR outsourcing under Article 18, step by step
Article 18(1)Regulation (EU) 2024/1624
"Obliged entities may outsource tasks resulting from this Regulation to service providers. The obliged entity shall notify the supervisor of the outsourcing before the service provider starts to carry out the outsourced task."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The notice is not an approval. Recital 49 says it "does not imply an acceptance of the outsourcing arrangement".[1]
1Classify the arrangement
The provider performs the requirement itself
Check the provider
It must be sufficiently qualified.
Sign a written agreement
It binds the provider and any sub-outsourcer to your policies.
Notify the supervisor
Before the provider starts.
Control regularly
More often for critical tasks.
Not outsourcing
Recital 47: software, databases or screening services you use yourself.
2Keep the decisions
On both paths, the six reserved tasks stay with the firm.
Article 18 as a sequence.[1]
Before outsourcing, the firm "shall assure itself that the service provider is sufficiently qualified", and it must ensure that the provider and any sub-outsourcing provider apply the firm's own policies and procedures.[1]
Article 18(4)Regulation (EU) 2024/1624
"The conditions for the performance of such tasks shall be laid down in a written agreement between the obliged entity and the service provider. The obliged entity shall perform regular controls to ascertain the effective implementation of such policies and procedures by the service provider."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The frequency of those controls depends on "the critical nature of the tasks outsourced".[1] Article 9 adds that your internal policies must cover outsourcing and be communicated to the service providers involved.[1]
Article 18(2)Regulation (EU) 2024/1624
"The obliged entity shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks that are carried out by service providers."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
Recital 47 explains why: a provider that is not an obliged entity has duties that "arise only from the contract between the parties and not from this Regulation".[1] A contract does not change who answers to the supervisor.
Two more duties follow. For each outsourced task, the firm must show that it "understands the rationale behind the activities carried out by the service provider" and that they mitigate its specific risks.[1] And outsourcing must not materially impair the supervisor's ability "to monitor and retrace the obliged entity's compliance".[1]
The six tasks you can never outsource
Article 18(3) lists tasks that "shall not be outsourced under any circumstances".[1] The right column is our reading of what a provider may still contribute.
| Point | Reserved task, Article 18(3)[1] | A provider can still supply |
|---|---|---|
| (a) | "the proposal and approval of the obliged entity's business-wide risk assessment [...]" | Portfolio data as input |
| (b) | "the approval of the obliged entity's internal policies, procedures and controls [...]" | Checks that apply your policies |
| (c) | "decision on the risk profile to be attributed to the customer" | A proposed rating and its rationale |
| (d) | "the decision to enter into a business relationship or carry out an occasional transaction with a client" | Check results and review queues |
| (e) | "the reporting to FIU of suspicious activities [...] or threshold-based reports [...]" | A draft report that you file |
| (f) | "the approval of the criteria for the detection of suspicious or unusual transactions and activities" | Monitoring on criteria you approved |
FIU is the financial intelligence unit. Point (e) has one exception, for an obliged entity of the same group in the same Member State.[1] Article 76(5) puts a second lock on point (d): an automated decision to accept or refuse a customer needs "meaningful human intervention".[1] Collective investment undertakings without legal personality may outsource points (c), (d) and (e) after supervisor approval.[1]
Everything else may be outsourced, as long as it does not "impair materially the quality" of the firm's policies, procedures and controls.[1] The regulation gives no positive list. By elimination, and this is our inference, that includes collecting identity data, the document or electronic identification (eID) check, register look-ups, PEP and sanctions screening, monitoring against criteria you approved and record storage.
The third-country restriction on providers
Article 18(6) says obliged entities "shall not outsource tasks deriving from the requirements under this Regulation to service providers residing or established in third countries identified pursuant to Section 2 of Chapter III".[1] Those are the countries listed under Articles 29 to 31. The only exception is a provider in the same group, where the group applies AMLR-level policies and the home supervisor oversees them at group level.[1]
Watch out
This is not a general ban on non-EU providers, and not a data-location rule.[1] Whether it reaches a sub-outsourcer or a processing location in a listed country, when the contracting provider is in the EU, is not settled in the text.
Recital 47: when a KYC tool is not outsourcing
For anyone buying verification software, this is the least resolved part of the AMLR outsourcing rules.
Recital 47Regulation (EU) 2024/1624
"Processes or arrangements that contribute to the performance of a requirement under this Regulation, but where the performance of the requirement itself is not carried out by a service provider, such as the use or acquisition of third-party software or the access to databases or screening services by the obliged entity, are not considered to be outsourcing."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The test is who performs the requirement. What follows is interpretation, to be confirmed with counsel.
- Tool use. You license software or query a screening service, and your own staff perform the requirement. The notification and contract rules of Article 18 do not attach on that account.
- Outsourcing. The provider performs the requirement itself, for example its systems or reviewers decide that the document is genuine and the person matches it. The same recital expressly mentions a provider "involved for the purposes of remote customer identification".[1]
- The grey zone. An automated verification service reached by API, with or without review by the provider's staff. No primary text says on which side it falls.
Not yet known
AMLA, the EU Anti-Money Laundering Authority, must issue outsourcing guidelines by 10 July 2027.[1] On 2 October 2026 no consultation on them appears in AMLA's list.[2] Until they exist, the classification is a judgment the firm makes and documents.
- 9 July 2024In forceArticle 18 and recital 47 are final text.
- 2 October 2026No draftNo outsourcing consultation on AMLA's list.
- 10 July 2027AppliesArticle 18 binds. Outsourcing guidelines are due.
The guidance may arrive on the same day as the obligation.[1][2]
When the guidelines come, obliged entities "shall make every effort to comply" with them.[3] The closest benchmark today is the European Banking Authority's guidelines on remote customer onboarding (EBA/GL/2022/15), written under the current directive.[4] AMLA's tracker lists them among the EBA guidelines that apply until AMLA's own instruments on the subject enter into force.[5] Their status after 10 July 2027 is not confirmed.
One thing is settled: the AMLR creates no licence, certification or approval for KYC vendors.[1] Remote identification itself is covered in AMLR identity verification and AMLA's final CDD standards.
Due diligence on a provider: a checklist you can document
Article 18(4) does not say how to check a provider. This list combines the Article 18 duties with the EBA benchmark; two lines are our suggestion.
- Confirm the provider is not established in a country listed under Articles 29 to 31.[1]
- Ask where data is stored and processed, so that supervisors can retrace your compliance.[1]
- List every sub-outsourcer and bind each to your policies.[1]
- Secure audit rights: regular reporting, on-site visits or sample testing.[4]
- Assess staff training, technology fitness and data governance.[4]
- Require notice of any change to the process or the solution.[4]
- Require notice of incidents that affect your customers' data (our suggestion).
- Secure access to unredacted evidence for every case.[1]
- Agree a defined retention period, with limited and logged access.[4]
- Plan the exit: an export of all evidence when the contract ends (our suggestion).
The exit line matters more than it looks. Records are kept for 5 years from the end of the relationship, the occasional transaction or the refusal, and the duty is the firm's.[1] If the contract ends in year two, you still need the evidence in year six. See also AMLR software: what to build, what to buy and what it costs.
What to put in your AMLR outsourcing register
The AMLR does not use the words "outsourcing register". It requires things a register makes easy to prove: the notification, the written agreement, the controls, and your understanding of each task.[1]
| Field | What to record | Basis[1] |
|---|---|---|
| Task | What the provider performs and what stays in-house | Art. 18(3) |
| Classification | Outsourcing, reliance or tool use, with your reasoning | Art. 18, recital 47 |
| Provider | Legal entity, country of establishment, sub-outsourcers | Art. 18(4), (6) |
| Agreement | Date, version, the clause binding the provider to your policies | Art. 18(4) |
| Notification | Date sent to the supervisor; the provider's start date | Art. 18(1) |
| Controls | Frequency and why, last result, open findings | Art. 18(4) |
| Rationale | How the provider works and which risks it mitigates | Art. 18(2) |
| Records | Where evidence sits, how you retrieve it, when it is deleted | Arts. 18(5), 77 |
The fields are our proposal, not a legal template. The AMLR checklist by type of obliged entity has the rest.
How Didit helps: checks and evidence, with the decisions left to you
Didit supplies checks and the evidence of each one. Using it moves none of your liability and none of the six reserved tasks. The AMLR solution page maps each requirement to a check.
That covers identity verification, AML screening against 1,300+ sanctions, PEP and watchlists, business verification and transaction monitoring, built into one flow in the workflow builder with manual review and four-eyes approval.
Data is stored in the EU by default, with in-country processing on Enterprise. Retention is configurable from 1 month to 10 years, with deletion on demand. Didit holds SOC 2 Type 1 and Type 2 and ISO/IEC 27001:2022 (see security and compliance).
Whether your Didit setup is outsourcing or tool use depends on how you configure it and on guidance that does not exist yet, so take that question to counsel. Prices are public: a full KYC check is $0.33, and the rest is on the pricing page. Integration steps are in the AMLR guide in the docs.
Didit provides
- Identity checks by document, digital ID wallet or non-document lookup
- Sanctions, PEP and watchlist screening, re-screened daily
- Company registry data and linked checks on owners
- Monitoring rules, alerts and FIU report preparation
- The evidence of every check, with retention you configure
Stays with you
- The risk assessment and the policies
- The customer's risk profile and the onboarding decision
- Approval of the detection criteria
- Filing reports with the FIU
- The supervisor notification, the controls and the full liability
Buy the checks, keep the decisions
Set up identity verification, screening and monitoring in one workflow, with the evidence of every check ready for your own review.
Key takeaways
- Article 18 allows outsourcing with a written agreement, prior notice to the supervisor and regular controls.
- The obliged entity "shall remain fully liable". No contract changes that.
- Six tasks never leave the firm, including the risk profile, the onboarding decision and FIU reporting.
- AMLA's outsourcing guidelines are due by 10 July 2027 and had no draft on 2 October 2026.
Frequently asked questions
Can you outsource KYC under the AMLR?
Yes, in part. Article 18(1) lets obliged entities outsource tasks to service providers, with a written agreement, prior notice to the supervisor and regular controls. The decisions stay with the firm: the customer's risk profile and the decision to onboard cannot be outsourced.
Does outsourcing KYC transfer liability to the provider?
No. Article 18(2) says the obliged entity "shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks". A contract with the provider does not change who answers to the supervisor.
Which tasks can never be outsourced under Article 18?
Six: the business-wide risk assessment, the approval of internal policies, the customer's risk profile, the decision to onboard or carry out an occasional transaction, reporting to the financial intelligence unit, and the approval of detection criteria. Reporting has one exception, inside a group in the same Member State.
Is using KYC software or a screening database outsourcing?
Not when the firm performs the requirement itself. Recital 47 says the use of third-party software and access to databases or screening services are not considered outsourcing. Where an automated verification service falls is not stated in any primary text on 2 October 2026.
Do I need my supervisor's approval before outsourcing?
No. Article 18(1) requires a notification before the provider starts the task, not an approval. Recital 49 adds that the notification does not imply acceptance of the arrangement.
Can I use a KYC provider based outside the EU?
Yes, unless the provider resides or is established in a third country identified under Articles 29 to 31 of the AMLR. For those countries, outsourcing is allowed only inside the same group and under group-level conditions. Article 18(6) is not a general ban on non-EU providers.
What is the difference between reliance and outsourcing?
Reliance, under Articles 48 and 49, means using due diligence already performed by another obliged entity, and covers only identity, beneficial ownership and purpose. Outsourcing, under Article 18, means a service provider performs a task for you under your policies. In both cases the responsibility stays with you.
When will AMLA publish its outsourcing guidelines?
The deadline in Article 18(8) is 10 July 2027, the day the AMLR starts to apply. On 2 October 2026 no consultation on these guidelines appears in AMLA's list of public consultations. Plan with the text of Article 18 and revisit each classification once they are out.
Sources
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024. Articles 9, 18, 48, 49, 76 and 77; recitals 47 and 49.
- Public consultations, AMLA, read on 2 October 2026.
- Regulation (EU) 2024/1620 (AMLA Regulation), EUR-Lex, Official Journal of 19 June 2024. Article 54.
- Guidelines on the use of remote customer onboarding solutions (EBA/GL/2022/15), European Banking Authority, section 4.5.2.
- Regulatory instruments tracker, AMLA, last update 30 September 2026.
Article 18 lets you buy the work and keeps the responsibility with you. The AMLR solution page shows which checks Didit runs for each requirement and which decisions stay yours.
See what your outsourcing file would hold
Run a verification, open the evidence it produces and judge whether it answers your supervisor's questions.
Related articles
- The EU's EUR 10,000 cash limit from July 2027: who it binds
- AMLR software: what to build, what to buy and what it costs
- AMLR identity verification: eID first, documents as the alternative
- AMLR and the EUDI Wallet: when you must accept it, and what is left
- AMLR for crypto: what crypto-asset service providers must verify
- AMLR checklist by obliged entity, with the article behind every line