Why Financial Institutions May Outsource MSB Due Diligence β and What That Means for Your MSB
Why a financial institution may use a third party for parts of an MSB due diligence review, what that party's role typically covers, and what stays with the institution regardless.

Key Takeaways
- A financial institution using a third party for parts of MSB due diligence does not transfer the institution's accountability for the relationship (OSFI Guideline B-10).
- Outsourced due diligence is a different concept from FINTRAC's third-party determination requirement.
- FINTRAC registration is not the same as passing a bank's own risk-based due diligence review.
- Follow-up questions from a third-party reviewer are a normal part of risk-based review, not a sign of rejection.
- Consistent, current documentation matters more than who is conducting the review.
An MSB submits its onboarding documents or periodic review file to a bank or other financial institution, and then notices that follow-up questions, screening requests, or document requests are coming from a specialist review team or a named third-party provider rather than the institution's usual relationship contact. This is a common feature of how some financial institutions structure parts of their due diligence process, and it is not, by itself, a sign of anything wrong with the file.
It also does not mean the financial institution has handed over the relationship. This article looks at why a financial institution might use an external party for parts of an MSB due diligence review, what that party's role typically covers, what stays with the financial institution regardless of the arrangement, and what an MSB should actually do differently, if anything, when a third party appears in the process.
What Does Outsourced MSB Due Diligence Actually Mean?
At a basic level, the workflow can look something like this: the MSB provides information to the financial institution; some or all of that information is collected, verified, or screened by an external party; findings or open questions are passed back to the financial institution; and the financial institution decides what happens next in the relationship.
The exact shape of this workflow varies by institution. It helps to separate the distinct activities that can sit anywhere along that chain:
- Collecting information β gathering corporate documents, ownership records, and business descriptions from the MSB.
- Verifying information β confirming that submitted documents are authentic, current, and consistent.
- Screening β checking names against sanctions lists, PEP databases, and adverse-media sources.
- Risk analysis β assessing what the collected and verified information means for the institution's risk appetite.
- Escalation β flagging unresolved questions or higher-risk findings for further review.
- Final risk acceptance or relationship decision β the actual decision on whether, and on what terms, the institution continues the relationship.
Not every external provider performs every one of these functions. Some arrangements cover only document collection or screening; others cover a broader slice of the review. What generally does not move to a third party is the institution's own final decision-making on the relationship.
Why Might a Financial Institution Use a Third Party?
Financial institutions engage third parties for a range of operational reasons. The reasons below are commonly cited in practice, but they will not apply to every institution or every arrangement.
Specialist compliance expertise
Some review functions β sanctions screening logic, adverse-media analysis, or higher-risk sector assessments β benefit from specialist knowledge that a dedicated provider maintains as its core business.
Operational capacity and scalable review workflows
Institutions handling a large or fluctuating volume of MSB and fintech relationships may use external capacity to manage periodic reviews and onboarding volume without building that capacity entirely in-house.
Standardized processes and documentation
A third party built around a defined review methodology can help an institution apply a consistent process across a portfolio of similar relationships.
Access to specialist tools or review resources
Screening databases, verification technology, and document-analysis tools are sometimes accessed through a provider rather than licensed and operated directly.
OSFI's Guideline B-10, Third-Party Risk Management, recognizes that federally regulated financial institutions rely on an expanding range of third-party arrangements, and it directs institutions to assess the risk and criticality of each arrangement so that oversight is proportionate. The guideline does not say that MSB due diligence specifically must, or typically does, involve a third party β it applies to third-party arrangements generally, and how (or whether) a given institution applies it to MSB review functions depends on that institution's own operating model.
Outsourcing the Work Does Not Outsource Accountability
This is the point that matters most to an MSB going through a review involving an external party.
Guideline B-10 is explicit that a financial institution's use of third-party arrangements does not remove its own responsibility for the activity or the risks arising from it. The institution is still expected to govern and oversee the arrangement, understand what the third party is doing, and manage the risk that comes with relying on an outside provider β including, where relevant, subcontractor and concentration risk within that arrangement.
For a practical read of what this means: an external reviewer's findings feed into the financial institution's process, but the institution's own risk framework and decision-makers are still the ones accountable for the relationship. An external reviewer should not automatically be treated as the entity making the final call on whether your MSB is approved, retained, or offboarded β that depends on how the specific institution has structured its arrangement.
What an External Reviewer May Ask Your MSB For
The categories of information a reviewer may ask for are broadly similar to what any bank CDD review would cover, whether performed in-house or with external support:
- Corporate and entity information
- Ownership and control information
- FINTRAC registration status, where relevant
- Business model and services offered
- Customer profile and expected activity
- Geographic and payment-corridor exposure
- AML policies and current risk assessment
- Screening and monitoring controls
- Explanations supporting any risk factor that needs clarification
This is a summary rather than a full walkthrough β for the detailed contents of a bank's CDD review of an MSB, including entity structure, ownership, and screening components, see what a bank's CDD review of an MSB involves.
What Changes for the MSB When a Third Party Is Involved?
You may deal with more than one contact
Depending on the institution's process, requests and correspondence may come through a relationship manager, an internal compliance team, an external reviewer, or some combination of these. This does not always happen, and where it does, it usually reflects the institution's internal workflow rather than anything about your file specifically.
Consistency becomes especially important
When more than one party may be looking at your file, it matters that your corporate information, ownership details, FINTRAC registration record, business description, AML documentation, and stated transaction expectations all tell the same story. Discrepancies that might get smoothed over in a single informal conversation are more likely to surface as a formal follow-up question when a structured, multi-party review process is involved.
Follow-up questions do not automatically mean rejection
A request for clarification, additional documents, or an explanation of a screening hit is a normal part of a risk-based review process. It reflects the review doing its job, not a predetermined outcome.
The reviewer may identify issues, but the institution's process determines what happens next
A finding raised by an external reviewer is an input into the financial institution's own decision process β not, in itself, the decision. How that finding is weighed, and what it means for the relationship, sits with the financial institution.
What Outsourced Due Diligence Does Not Mean
- It does not mean your MSB has failed a review.
- It does not automatically mean you are the subject of an investigation.
- It does not remove the financial institution's own responsibility for the relationship.
- It does not mean that FINTRAC registration is equivalent to bank approval β the two are separate assessments (registration is a regulatory status; the institution's review is its own customer risk assessment).
- It does not make weak or outdated AML documentation irrelevant β inconsistent or thin documentation can still generate follow-up questions regardless of who is asking them.
- It does not guarantee a faster onboarding or review timeline.
How Should an MSB Prepare for a Third-Party Due Diligence Review?
The following is practical preparation, not a mandatory or universal checklist β actual requirements vary by institution.
- Confirm legal and entity information is current and matches official records.
- Make sure ownership information is clear, complete, and consistent across every document you provide.
- Check that your FINTRAC registration details are accurate and up to date, where applicable.
- Ensure the business model you describe matches what your business actually does.
- Keep your AML risk assessment current and reflective of your actual customer base and activity.
- Make sure your AML policies describe your real operations, not a generic template.
- Prepare clear explanations of customer types, products, transaction flows, and geographic exposure before you are asked.
- Resolve internal contradictions in your file before submitting it.
- Keep a controlled record of what documents and explanations you have already provided, and to whom.
When Due Diligence Questions Reveal a Bigger Compliance Problem
Sometimes repeated difficulty answering basic due diligence questions is less about the review process and more a sign that the underlying AML program, documentation, or risk assessment needs attention. If that's the pattern you're seeing, it may be worth taking the opportunity to strengthen your AML compliance program rather than treating each review as an isolated event.
Where the gaps are more about remediation than fresh program-building β inconsistent records, an outdated risk assessment, or policies that no longer reflect your actual operations β AML advisory support can help get your documentation and compliance position into defensible shape before your next review.
Outsourced Review vs In-House Review: What Actually Matters to the MSB?
| Issue | In-House Review | Third-Party-Supported Review |
|---|---|---|
| Who requests information | Internal team | May involve an external reviewer |
| Review standards applied | Institution's own framework | Institution's framework still governs the arrangement |
| Follow-up questions | Handled internally | May pass through external and internal teams |
| Accountability for the outcome | Financial institution | Financial institution retains accountability |
| What the MSB must provide | Accurate, consistent evidence | Same fundamental requirement |
Actual practices vary by institution; this table is illustrative rather than a description of any specific bank's process.
The Bottom Line
For an MSB, the more useful question is not whether the person reviewing your file sits inside or outside the financial institution. It's whether your compliance file β ownership records, business description, risk assessment, and AML controls β is current, consistent, and able to withstand scrutiny from whoever is looking at it.
A third party in the process may change the workflow you experience, but it does not change what actually gets you through the review: accurate ownership information, a business description that matches reality, an up-to-date risk assessment, and AML controls that are operating rather than just documented. If your MSB's file consistently generates follow-up questions, that's usually the signal worth acting on β through a stronger AML program or targeted advisory support β rather than the presence of a third party itself.
Frequently Asked Questions
Can a Canadian bank outsource MSB due diligence to a third party?
Federally regulated financial institutions operate under OSFI's Guideline B-10, which sets expectations for managing risk when they rely on third-party arrangements generally. The guideline doesn't specifically mandate or describe one universal outsourcing model for MSB due diligence β whether and how a given institution uses a third party for this function depends on that institution's own operating model and risk assessment of the arrangement.
Does a third-party CDD provider decide whether my MSB gets a bank account?
Not necessarily. A third party's authority varies by arrangement β some only collect or screen information, while others may also flag risk findings. The institution generally retains accountability for the relationship decision itself. Don't assume the external party you're corresponding with is the one making the final call; that depends on how the specific institution has structured its process.
Is outsourced MSB due diligence the same as FINTRAC's third-party determination?
No. FINTRAC's third-party determination concerns identifying whether someone else is instructing your client's transaction or activity β a distinct AML obligation on the MSB itself. Outsourced due diligence, by contrast, refers to a financial institution's own operational choice to use an external party for parts of its customer review process. The two concepts involve different obligations and different parties.
Does FINTRAC registration mean my MSB should pass a bank's due diligence review?
Not automatically. FINTRAC registration confirms your MSB has met a regulatory registration requirement; it isn't the same as a financial institution's own risk-based assessment of your business as its customer. A financial institution may still request additional information, apply its own risk criteria, or decline a relationship for reasons unrelated to your registration status.
Can an MSB prepare for an external due diligence review?
Yes. The most useful preparation is making sure your corporate, ownership, registration, and AML documentation tell a single consistent story before you submit it, and having clear explanations ready for your customer base, transaction flows, and geographic exposure. Resolving contradictions in advance reduces the likelihood of follow-up questions, regardless of who is conducting the review.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.