Reliance lets one regulated institution use due diligence performed by another. FATF Recommendation 17 is the basis, and it is the heart of SUPA's multilateral agreement. For developers, reliance raises a concrete design question: which data actually needs to move between institutions, and which must not.
Reliance does not move responsibility
The first thing to encode is a boundary, not a field list. Reliance does not transfer legal responsibility. Each party keeps its own legal duties, and cross-border reliance is not permitted everywhere; local-law limits are checked per jurisdiction. An integration that assumes otherwise will be wrong in some corridors. This is where reliance agreements do the work that code alone cannot: they fix responsibility, the data that must accompany operations, and a minimum standard for KYC, KYB and monitoring regardless of jurisdiction.
What must accompany an operation
The multilateral reliance agreement each participant signs fixes what travels with each operation. Two standards shape the data: due-diligence information under Recommendation 17, and the information that must accompany a transfer under Recommendation 16, the travel rule.
In practice, a developer distinguishes three categories:
- data transmitted with the operation
- data retrievable on request — for example, KYC documents accessible to SUPA, another participant or a regulator
- data that must not move at all, because local rules restrict it
Translate rules into constraints
The useful output of a reliance design is a set of API constraints: required fields validated at instruction time; an explicit access path for documents rather than copying them into every message; and a record of which fields were shared with which counterparty. Data minimisation is a compliance property, so the default should be the minimum the check requires. The safe default is narrow: transmit what a check requires, make the rest retrievable through a controlled path, and treat any widening of sharing as a deliberate decision rather than a side effect of a schema change.
In short
- Reliance uses another institution's due diligence but does not transfer responsibility.
- Cross-border reliance has local-law limits; check them per jurisdiction.
- Separate transmitted data, retrievable data and data that must not move.
- Enforce the difference in validation and access, not in documentation.
This is general information, not legal, tax or financial advice. Read the developer material: developers.