Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · AMLR

Article 18Outsourcing

CELEX 32024R1624 · Read on 2026-08-22

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. Obliged entities may outsource tasks resulting from this Regulation to service providers. The obliged entity shall notify the supervisor of the outsourcing before the service provider starts to carry out the outsourced task.

2. When performing tasks under this Article, service providers shall be regarded as part of the obliged entity, including where they are required to consult the central registers referred to in Article 10 of Directive (EU) 2024/1640 (‘central registers’) for the purposes of carrying out customer due diligence on behalf of the obliged entity.

The obliged entity shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks that are carried out by service providers.

For each outsourced task, the obliged entity shall be able to demonstrate to the supervisor that it understands the rationale behind the activities carried out by the service provider and the approach followed in their implementation, and that such activities mitigate the specific risks to which the obliged entity is exposed.

3. The tasks outsourced pursuant to paragraph 1 of this Article shall not be undertaken in such a way as to impair materially the quality of the obliged entity’s policies and procedures to comply with the requirements of this Regulation and of Regulation (EU) 2023/1113, and of the controls in place to test those policies and procedures. The following tasks shall not be outsourced under any circumstances:

(a)

the proposal and approval of the obliged entity’s business-wide risk assessment pursuant to Article 10(2);

(b)

the approval of the obliged entity’s internal policies, procedures and controls pursuant to Article 9;

(c)

decision on the risk profile to be attributed to the customer;

(d)

the decision to enter into a business relationship or carry out an occasional transaction with a client;

(e)

The article continues in the official text.

Open the article on EUR-Lex

Judgments of the Court of Justice

1 decisions

  • C-562/20Court of Justice of the European Union

    SIA 'Rodl & Partner' v Valsts ieņēmumu dienests

    Reference for a preliminary ruling – Prevention of the use of the financial system for the purpose of money laundering and terrorist financing – Directive (EU) 2015/849 – Article 18(1) and (3) – Annex III, point 3(b) – Risk-based approach – Risk assessment conducted by obliged entities – Identification of risks by Member States and obliged entities – Customer due diligence measures – Enhanced due diligence measures – High-corruption-risk third countries – Article 13(1)(c) and (d) – Evidence and documentation requirements imposed on obliged entities – Article 14(5) – Ongoing customer monitoring imposed on obliged entities – Publication of decisions imposing a sanction.

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit