Cross-border trust is usually personal. A relationship manager at one bank knows a counterpart's compliance team, and payments move because that familiarity has been built over years. It works, but it does not scale and it does not transfer. The alternative is to codify trust into a rule that every participant signs.
What reliance means
The basis is FATF Recommendation 17: a regulated institution may rely on client due diligence performed by another regulated institution. Reliance is not a loophole — it is a recognised way for institutions to share verified information without each repeating the same work from scratch. The point is to remove duplication without removing accountability.
One agreement instead of hundreds
SUPA's reliance agreement is multilateral: each participant signs one agreement on joining, rather than negotiating hundreds of bilateral arrangements. It fixes who is responsible for what, the data that must accompany each operation under the travel rule (FATF Recommendation 16), access to KYC documents on request by SUPA, another participant or a regulator, and a minimum standard for KYC, KYB and monitoring regardless of jurisdiction.
It also covers the agent layer — principal identification, agent registration and the operation tied to unit policy — and the consequences of failure: selective audit, limits, suspension, exclusion. Because the terms are standardised, a new participant inherits a known position rather than a bespoke one, and every counterpart can see the same baseline.
What reliance does not do
Reliance does not transfer legal responsibility. Each party keeps its own legal duties, and cross-border reliance is not permitted everywhere; local-law limits are checked per jurisdiction before an arrangement is relied upon. Codified trust makes the process predictable and repeatable, but it does not remove the underlying obligations or move them onto someone else.
This article is general information, not legal, tax or financial advice.
In short
- FATF Recommendation 17 permits one institution to rely on another's due diligence.
- One multilateral agreement replaces many informal, non-transferable relationships.
- It standardises data, document access and monitoring expectations.
- Responsibility stays with each party; local-law limits still apply.
Review the compliance architecture at /protocol/.