Why Financial Institutions May Outsource MSB Due Diligence β and What That Means for Your MSB
Why Canadian financial institutions may use third parties for parts of MSB due diligence, what those reviewers can do, and what MSBs should expect and prepare for.
Key takeaways
- Canadian financial institutions may use external providers to support parts of MSB due diligence, but the exact scope and workflow vary by institution.
- For federally regulated financial institutions, OSFI Guideline B-10 makes clear that using a third party does not transfer accountability for outsourced activities or the risks arising from them.
- An external reviewer may collect documents, verify information, screen parties, analyze risk, or escalate findings depending on the arrangement; not every provider performs every function.
- For an MSB, the practical priority is a current and consistent file: ownership records, FINTRAC registration details, business information, risk assessment, and AML documentation should align.
An MSB submits its onboarding documents or periodic review file to a bank or other financial institution, and then notices that follow-up questions, screening requests, or document requests are coming from a specialist review team or a named third-party provider rather than the institution's usual relationship contact. This can occur when a financial institution uses an external provider to support parts of its due diligence process. It does not, by itself, indicate anything wrong with the MSB's file, and it does not mean the financial institution has handed over the relationship.
This article looks at why a financial institution might use an external party for parts of an MSB due diligence review, what that party's role can involve, what stays with the financial institution regardless of the arrangement, and what an MSB should actually do differently, if anything, when a third party appears in the process.
What Does Outsourced MSB Due Diligence Actually Mean?
At a basic level, the workflow can look something like this: the MSB provides information to the financial institution; some or all of that information is collected, verified, or screened by an external party; findings or open questions are passed back to the financial institution; and the financial institution acts on that information within its own risk framework.
The exact shape of this workflow varies by institution. It helps to separate the distinct activities that can sit anywhere along that chain:
- Collecting information β gathering corporate documents, ownership records, and business descriptions from the MSB.
- Verifying information β confirming that submitted documents are authentic, current, and consistent.
- Screening β checking names against sanctions lists, PEP databases, and adverse-media sources.
- Risk analysis β assessing what the collected and verified information means against the institution's risk appetite.
- Escalation β flagging unresolved questions or higher-risk findings for further review.
- Risk acceptance or relationship decision β how the institution acts on the review within its own governance framework.
Not every external provider performs every one of these functions. Some arrangements cover only document collection or screening; others cover a broader slice of the review.
Why Might a Financial Institution Use a Third Party?
OSFI's Guideline B-10, Third-Party Risk Management, notes that the financial industry has long made use of third-party arrangements to introduce efficiency, drive innovation, manage shifting operational needs, and improve service. This is a general statement about third-party arrangements across federally regulated financial institutions (FRFIs) β it is not a statement specifically about MSB due diligence, and it does not establish that any particular institution outsources this function or does so in a particular way.
Within that general principle, some possible operational reasons an institution might extend to MSB review functions include:
- Specialist expertise a dedicated provider maintains as part of its core business (for example, in sanctions screening or higher-risk sector analysis).
- Operational capacity to manage onboarding or periodic-review volume without building every function in-house.
- Standardized processes that support consistent handling across a portfolio of similar relationships.
- Specialist tools or databases accessed through a provider rather than licensed and operated directly.
These are illustrative possibilities rather than confirmed practices for MSB review specifically β how, or whether, a given institution applies any of them depends on that institution's own operating model and its risk assessment of the arrangement.
Outsourcing the Work Does Not Outsource Accountability
This is the point that matters most to an MSB going through a review involving an external party.
OSFI Guideline B-10 sets out that FRFIs are expected to manage the risks related to all third-party arrangements, and it is explicit that using a third party does not transfer the institution's accountability for the outsourced activity or the risks arising from it. The institution is still expected to govern and oversee the arrangement and understand what the third party is doing on its behalf, including managing subcontractor and concentration risk where relevant.
In practice, this means an external provider may perform review, screening, analysis, or other decision-support activities depending on the arrangement β but the federally regulated financial institution retains accountability for outsourced activities and the risks arising from them. This is the single governing principle behind everything else in this article: whatever workflow you experience, the institution's own accountability does not move with the work.
What an External Reviewer May Ask Your MSB For
The categories of information a reviewer may ask for are broadly similar to what any bank CDD review would cover, whether performed in-house or with external support:
- Corporate and entity information
- Ownership and control information
- FINTRAC registration status, where relevant
- Business model and services offered
- Customer profile and expected activity
- Geographic and payment-corridor exposure
- AML policies and current risk assessment
- Screening and monitoring controls
- Explanations supporting any risk factor that needs clarification
This is a summary rather than a full walkthrough β for the detailed contents of a bank's CDD review of an MSB, including entity structure, ownership, and screening components, see what a bank's CDD review of an MSB involves.
What Changes for the MSB When a Third Party Is Involved?
You may deal with more than one contact. Depending on the institution's process, requests may come through a relationship manager, an internal compliance team, an external reviewer, or some combination of these. Where this happens, it usually reflects the institution's internal workflow rather than anything about your file specifically.
Consistency becomes especially important. When more than one party may be looking at your file, discrepancies that might get smoothed over in a single informal conversation are more likely to surface as a formal follow-up question in a structured, multi-party review.
Follow-up questions do not automatically mean rejection. A request for clarification, additional documents, or an explanation of a screening hit is a normal part of a risk-based review β not a predetermined outcome.
A finding is an input, not necessarily the outcome. What an external reviewer flags feeds into the institution's own process; how it's weighed, and what it means for the relationship, is governed by the institution's own risk framework, as covered above.
What Outsourced Due Diligence Does Not Mean
- It does not mean your MSB has failed a review.
- It does not automatically mean you are the subject of an investigation.
- It does not mean that FINTRAC registration is equivalent to bank approval β registration is a regulatory status; the institution's review is its own customer risk assessment.
- It does not make weak or outdated AML documentation irrelevant β inconsistent or thin documentation can still generate follow-up questions regardless of who is asking them.
- It does not guarantee a faster onboarding or review timeline.
How Should an MSB Prepare for a Third-Party Due Diligence Review?
The following is practical preparation, not a mandatory or universal checklist β actual requirements vary by institution.
- Confirm legal and entity information is current and matches official records.
- Make sure ownership information is clear, complete, and consistent across every document you provide.
- Check that your FINTRAC registration details are accurate and up to date, where applicable.
- Ensure the business model you describe matches what your business actually does.
- Keep your AML risk assessment current and reflective of your actual customer base and activity.
- Make sure your AML policies describe your real operations, not a generic template.
- Prepare clear explanations of customer types, products, transaction flows, and geographic exposure before you are asked.
- Resolve internal contradictions in your file before submitting it.
- Keep a controlled record of what documents and explanations you have already provided, and to whom.
When Due Diligence Questions Reveal a Bigger Compliance Problem
Sometimes repeated difficulty answering basic due diligence questions is less about the review process and more a sign that the underlying AML program, documentation, or risk assessment needs attention. If that's the pattern you're seeing, it may be worth taking the opportunity to strengthen your AML compliance program rather than treating each review as an isolated event.
Where the gaps are more about remediation than fresh program-building β inconsistent records, an outdated risk assessment, or policies that no longer reflect your actual operations β AML advisory support can help get your documentation and compliance position into defensible shape before your next review.
Outsourced Review vs In-House Review: What Actually Matters to the MSB?
IssueIn-House ReviewThird-Party-Supported ReviewWho requests informationInternal teamMay include an external reviewerGoverning standardsInstitution's own frameworkSame framework; institution retains accountabilityFollow-up questionsHandled internallyMay pass through external and internal teamsWhat the MSB must provideAccurate, consistent evidenceSame fundamental requirement
Actual practices vary by institution; this table is illustrative rather than a description of any specific bank's process.
The Bottom Line
The more useful question for an MSB is not whether the person reviewing your file sits inside or outside the financial institution β it's whether your file itself can withstand scrutiny from whoever is looking at it. A third party in the process may change the workflow you experience, but the institution's accountability for the relationship doesn't move with it, and the fundamentals of a strong file don't change either. If your MSB's file consistently generates follow-up questions, that's the signal worth acting on, through a stronger AML program or targeted advisory support.
Frequently Asked Questions
Can a Canadian bank outsource MSB due diligence to a third party?
Federally regulated financial institutions operate under OSFI's Guideline B-10, which recognizes that FRFIs use third-party arrangements generally and sets expectations for managing the associated risk. The guideline does not describe one universal outsourcing model for MSB due diligence specifically β whether and how a given institution involves a third party depends on that institution's own operating model.
How can an MSB find out what role a specific third-party reviewer is playing?
Arrangements between financial institutions and their providers aren't public information, and the tone or content of correspondence from a reviewer won't reliably tell you their scope of authority. If it matters to how you respond, the most direct approach is to ask your institution's relationship contact what the reviewer's role covers and where final decisions are made β institutions vary in how much of this they disclose.
Is outsourced MSB due diligence the same as FINTRAC's third-party determination?
No. FINTRAC's third-party determination concerns identifying whether someone else is instructing your client's transaction or activity β a distinct AML obligation on the MSB itself. Outsourced due diligence refers to a financial institution's own operational choice to use an external party for parts of its customer review process. The two involve different obligations and different parties.
What should an MSB do if it disagrees with a finding raised by a third-party reviewer?
Raise the disagreement in writing through your institution's relationship contact rather than only with the reviewer, and support your position with the underlying documents (corporate records, ownership evidence, transaction data) rather than argument alone. Because the institution retains accountability for the outcome, it is generally the right party to resolve a disputed finding, even where a third party raised it.
Can an MSB prepare for an external due diligence review?
Yes. The most useful preparation is making sure your corporate, ownership, registration, and AML documentation tell a single consistent story before you submit it, and having clear explanations ready for your customer base, transaction flows, and geographic exposure.
Sources
- Office of the Superintendent of Financial Institutions (OSFI), Guideline B-10: Third-Party Risk Management (in force since May 1, 2024)
- FINTRAC, Third-party determination requirements under the PCMLTFA and associated regulations
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.