Cross-border payments run on trust, and the awkward part is that the institutions doing the trusting are often competitors. FATF Recommendation 17 is the rule that makes it possible for one regulated institution to rely on client due diligence that another regulated institution has already performed. It is a narrow provision, but it sits underneath something much larger: the idea that trust between institutions can be codified rather than left to personal relationships.
What the recommendation actually allows
Recommendation 17 permits a regulated institution to rely on the customer due diligence performed by another regulated institution. It is a permission to lean on someone else's work, not a transfer of obligations. The relying institution remains responsible for its own legal duties. This is the distinction that matters most in practice, and it is easy to miss.
What has to be fixed in writing
Reliance only works if the details are agreed before anything flows. In SUPA's protocol, each participant signs one multilateral reliance agreement on joining. It sets out:
- who is responsible for what;
- the data that must accompany each operation, following FATF Recommendation 16 (the travel rule);
- access to KYC documents on request — by SUPA, by another participant, or by a regulator;
- a minimum standard for KYC, KYB and monitoring regardless of jurisdiction;
- the agent layer: principal identification, agent registration, and the tie between an operation and the unit's policy;
- control and consequences: selective audit, limits, suspension, exclusion.
Where reliance stops
Reliance does not transfer legal responsibility, and cross-border reliance is not permitted everywhere. Local-law limits are checked per jurisdiction. That is why the agreement states a minimum standard rather than an assumption that every jurisdiction will accept the same arrangement.
The value of Recommendation 17 is not that it removes work. It is that it gives a lawful basis for many institutions to share one compliance function instead of rebuilding it separately, corridor by corridor.
This article is general information, not legal, tax or financial advice.
In short
- Recommendation 17 lets a regulated institution rely on another's due diligence.
- Responsibility never transfers — each party keeps its own legal duties.
- One multilateral agreement can fix responsibility, data, access and standards.
- Cross-border reliance is not permitted everywhere; local law is checked per jurisdiction.
See how reliance fits the wider architecture at /protocol/.