A reliance agreement lets one regulated institution rely on client due diligence performed by another. It is the legal heart of any shared-KYC model, and it is also where institutions understandably slow down. The concept is not new — FATF Recommendation 17 recognises reliance between regulated institutions — but the practical question is what to verify before signing. This article offers a checklist, not legal advice; institutions should confirm every point against their own obligations and their supervisor's expectations.

The standard being relied upon

Reliance only makes sense if the performing institution's standard is at least as strong as your own. Check the minimum standard for KYC, KYB and ongoing monitoring that the agreement fixes, and confirm it holds regardless of jurisdiction. A weaker minimum anywhere in the network becomes your risk everywhere.

The data that must travel

Every operation should carry the information needed to reconstruct who is involved. FATF Recommendation 16 — the travel rule — sets the expectation that required originator and beneficiary data accompany a transfer. Confirm what data must be attached to each operation and how it is retained.

Access, audit and consequences

A reliance agreement should define, in writing:

  • Document access — the ability to obtain KYC documents on request, whether from the operator, another participant or a regulator.
  • Selective audit — the right to examine specific relationships rather than accept assurances on trust.
  • Limits and escalation — how over-limit operations become human approval requests rather than silent rejections.
  • Control levers — limits, suspension and, at the end of the ladder, exclusion.

The jurisdictional limit

This is where many programmes stall. Reliance does not transfer legal responsibility. Each institution keeps its own legal duties, and cross-border reliance is not permitted everywhere. Local-law limits must be checked per jurisdiction before any corridor is used. An agreement that is valid in one market may not be usable in another.

In short

  • Reliance rests on FATF Recommendation 17; data obligations sit with Recommendation 16.
  • Verify the minimum KYC/KYB/monitoring standard across the network.
  • Insist on document access, selective audit and a clear consequences ladder.
  • Reliance never transfers legal responsibility.
  • Cross-border reliance is not permitted everywhere — check per jurisdiction.

Review the compliance framework behind reliance at /protocol/.