Third-Party AML Due Diligence: How Banks Should Evaluate Vendors

How banks evaluate AML vendors under OCC and FFIEC third-party risk rules, including residual BSA risk for processors, screening, BPO, and model vendors.
Chrisjan Wüst, Co-Founder & CTO of Sphinx
Chrisjan Wüst

TL;DR: Third-party AML due diligence is how a bank assesses vendors that sit inside its BSA program — processors, screening providers, case-management SaaS, BPO shops, and model vendors — without transferring legal responsibility. OCC Bulletin 2023-17 and the FFIEC BSA/AML manual still leave residual BSA risk with the bank. The LexisNexis True Cost of Financial Crime Compliance study found 79% of mid- and large-sized institutions in the U.S. and Canada reported higher outsourcing costs, which makes the residual-risk question harder to ignore, not easier to delegate.

What Banks Are Actually Buying

Third-party AML due diligence is the bank's assessment of any vendor whose product or people touch customer identification, screening, monitoring, case work, or SAR-related functions. The relationship is a business arrangement under the 2023 interagency third-party risk guidance, whether the bank pays a SaaS invoice, a per-alert BPO fee, or a processor for ACH rails. Experience with the vendor is not a substitute for diligence scoped to the activity.

This is BSA vendor management, not sponsor-bank oversight of a fintech product. Bank-fintech partnership compliance oversight covers deposit and payment programs delivered through a partner. The vendors here sit behind the bank's own BSA program: screening engines, monitoring platforms, case-management SaaS, independent-testing consultants, alert-review BPO, and processors that generate the feeds those systems consume.

The FFIEC BSA/AML manual chapter on third-party payment processors is blunt. Processors generally are not subject to BSA/AML requirements, so some are more exposed to money laundering, fraud, and OFAC-prohibited activity. The bank that holds the account, files the SAR, and sits the exam cannot treat a SOC 2 as a BSA program.

Five vendor classes show up in most BSA inventories, and they do not share one risk profile:

Vendor type Where residual BSA risk concentrates
Payment and core processors Feeds, merchant or originator opacity, return rates, OFAC hits the bank never sees in time
Screening vendors List coverage, match logic, name-variation handling, data latency, false-negative rate
Case-management SaaS Audit trail completeness, access control, SAR confidentiality, evidence retention
BPO and alert-review shops Disposition quality, SAR confidentiality, staffing, fourth-party subcontractors
Model and detection vendors Methodology opacity, local configuration, coverage gaps, independent validation rights

A core provider that also sells consulting is two relationships, not one. The Ncontracts 2025 Third-Party Risk Management Survey found that 64% of financial institutions already assign risk ratings at the product or service level rather than at the vendor level. That split is the right unit of analysis for AML tools: screening is not the same activity as a cybersecurity workshop sold by the same company.

Residual Risk Does Not Move With the Contract

Diagram showing BSA residual risk remaining with the bank after work is contracted to a vendor
Outsourcing the work does not outsource the BSA obligation. Residual risk stays with the bank.

The 2023 interagency guidance states that use of third parties does not diminish a banking organization's responsibility to perform activities in a safe and sound manner and in compliance with financial-crimes laws. Residual BSA risk is what remains after the vendor's controls, the contract, and the bank's compensating procedures are in place. Examiners test that remainder, not the vendor's marketing deck.

The same principle shows up in correspondent banking due diligence: the respondent's program does not become the correspondent's program. Vendor diligence is the analog inside operations. A screening miss, an unmonitored payment type, or a BPO disposition that rubber-stamps a true match still belongs to the bank that filed — or failed to file — the SAR.

Federal Reserve outsourcing guidance has long flagged SAR-related functions as more complex to outsource because of confidentiality. A BPO that drafts narratives, recommends filings, or works inside the case system sits inside that perimeter. The bank still has to keep the filing decision, limit access, and be able to pull the work back if the vendor fails or is acquired.

Demand for that outsourcing is not slowing. The LexisNexis True Cost of Financial Crime Compliance study, conducted with Forrester, reported that 78% of surveyed institutions were looking to outsource some compliance activities in the coming years, and that financial crime compliance costs in the U.S. and Canada had reached $61 billion. Outsourcing does not shrink the BSA program. It relocates execution while concentrating residual risk in a smaller set of vendor relationships the BSA officer still has to explain.

Capacity on the bank side is thin. The same Ncontracts survey found that 73% of institutions have two or fewer full-time employees managing vendor risk, even though more than half oversee 300 or more vendors, and 66% feel pressure to enhance their TPRM programs. Questionnaire factories that treat a screening engine the same as a landscaping contractor are a predictable result of that ratio. BSA vendors need a different file.

On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed replacing the 2023 guidance with a more explicitly risk-tailored framework: align oversight with reasonably assessed risk, and stop treating every third party as inherently higher-risk. That is not permission to skip BSA vendors. Screening, monitoring, case work, and processing remain higher-risk because a failure produces BSA and OFAC harm, not a late invoice. The bank still has to identify those activities and document why residual risk is acceptable.

What Diligence Has to Prove

Sound diligence answers four questions in writing: can this vendor perform the BSA activity as specified, can the bank see enough to monitor it, can the bank exit without a BSA gap, and what residual risk remains after all of that. Shared assessments, SOC 2 reports, and industry certifications can feed the file. They do not close it. The 2023 guidance expects the bank to evaluate collaborative diligence against its own performance criteria and to document limitations when the vendor will not share what the bank asked for.

Start with the activity, not the legal entity. Map every BSA control the vendor touches: CIP data, KYB and beneficial-ownership checks if the vendor onboards businesses, list screening, transaction monitoring, case documentation, independent testing, or SAR drafting. Then risk-rate that activity. A vendor with production access to customer data and the ability to suppress alerts is a different residual-risk problem from a vendor that only hosts a ticketing UI.

For processors, that FFIEC chapter is still the practical checklist. Confirm the business, owners, and merchant or originator mix. Review how the processor diligences those clients. Contract for timely access to merchant lists, return rates, and transaction detail. Treat unauthorized returns as BSA and fraud signals, not only as credit events.

For screening vendors, the file needs list sources and refresh cadence, match methodology, transliteration and aka handling, how the vendor treats weak or truncated names, and what a "cleared" alert actually means in the product. Ask who owns false-negative testing. A vendor that will only demonstrate true-positive examples is selling recall theater. The bank still has to evidence that the configuration matches its customer base, products, and geographies — the same local-configuration problem that AML model validation requirements put on the institution rather than on the vendor's generic white paper.

For case-management SaaS, the BSA residual risk is evidentiary. Who can change a disposition after it is closed. Whether the audit log captures the data the analyst saw, not only the button they clicked. How SAR drafts, narratives, and supporting documents are segregated and retained. Whether the vendor's subprocessors — hosting, AI features, offshore support — sit inside the same confidentiality perimeter. A SaaS outage that locks the bank out of open cases is an operational event and a BSA continuity event at the same time.

For BPO, diligence is about people, process, and fourth parties. Sample dispositions, not policies. Review training on the bank's own typology and risk assessment, not a generic AML certificate. Confirm that SAR-related work stays inside a named, screened population with no unsupervised subcontracting. Set quality thresholds the bank can test independently, and keep the filing decision on the bank's side of the wall. A BPO that "owns" SARs on paper has created a control the BSA statute does not recognize.

For model vendors, demand enough methodology to support conceptual soundness, plus the right to validate configuration, data coverage, and outcomes on the bank's population. Vendor validation of a default ruleset is not the bank's validation. Coverage testing — whether every relevant transaction type actually reaches the engine — is still the bank's job even when the vendor hosts the model.

Contract terms that actually reduce residual risk look specific. Right to audit, including sample-level review of dispositions and configurations. Notice and consent for subcontractors. Data-return and destruction on exit, with a parallel run long enough to retune the next tool. SLAs tied to list-refresh lag, alert aging, and completeness of feeds, not only uptime. Incident notice short enough that an OFAC miss is not discovered in the next exam. If the vendor will not accept those terms, the limitation belongs in the residual-risk memo the board or designated committee sees, not in an email the BSA officer hopes nobody asks about.

Ongoing monitoring is where files go stale. Refresh risk ratings when the vendor ships an AI feature, moves processing offshore, changes list sources, or absorbs another platform. Re-test a sample of screening clears and BPO dispositions on a cycle tied to residual risk, not to the procurement calendar. Independent testing should cover the vendor-supported systems in the BSA program, because the FFIEC treats those IT sources and processes as the bank's controls, not a vendor footnote.

Where Sphinx Fits

Sphinx is itself a third party that works inside existing case systems, screening queues, and onboarding workflows. Agents review alerts and cases with an Interpretable Agentic Framework so each disposition carries the data used and the reasoning applied, which is the audit artifact residual-risk reviews are supposed to produce. Sphinx Frontline is the BPO form of that model: capacity without transferring the filing decision or burying SAR work in an uninspectable subcontracting chain. Banks that diligence Sphinx the way they diligence any other BSA vendor — activity mapping, sample review, subcontracting, exit — are doing the program correctly.

Frequently Asked Questions

What is third-party AML due diligence?

Third-party AML due diligence is a bank's risk-based review of vendors that perform or support BSA activities such as processing, screening, monitoring, case management, BPO alert review, or model operation. The review covers the vendor's ability to perform the activity, comply with applicable law, and give the bank enough visibility to monitor residual BSA risk. The bank keeps legal responsibility for the BSA program regardless of the contract.

Does outsourcing AML work transfer BSA responsibility to the vendor?

No. OCC Bulletin 2023-17 and the 2023 interagency third-party risk guidance state that using a third party does not diminish the banking organization's responsibility to perform activities in a safe and sound manner and in compliance with financial-crimes laws. Residual BSA risk stays with the bank, including SAR confidentiality when BPO or SaaS vendors touch case files.

How is this different from bank-fintech partnership oversight?

Bank-fintech partnership oversight covers programs where a fintech delivers deposit or payment products through a sponsor bank. Third-party AML due diligence covers vendors that operate inside the bank's own BSA program — processors, screening and monitoring tools, case-management SaaS, BPO, and model vendors. A bank can have both, and they require different files, contracts, and residual-risk memos.

What should banks review for screening and case-management vendors?

For screening vendors, review list sources, refresh cadence, match logic, name-variation handling, and how false-negative testing is performed on the bank's own customer base. For case-management SaaS, review audit-log completeness, access control, SAR confidentiality, subprocessor chains, and whether an outage would freeze open investigations. Configuration and coverage remain the bank's evidence burden in both cases.

How often should third-party AML due diligence be refreshed?

Refresh on a cycle tied to residual risk, and whenever the vendor changes activity, geography, subcontractors, data sources, or detection logic. The 2023 interagency guidance expects a complete inventory and periodic risk assessments so the bank can tell whether risks have changed. A questionnaire completed at procurement and filed for three years is not ongoing monitoring of a BSA-critical vendor.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.