Third-party risk assessment is the systematic evaluation of money laundering and terrorist financing exposure created by suppliers, service providers, distributors, and business partners. French regulators expect firms to document third-party due diligence proportionate to inherent risk before establishing relationships. Without structured assessment, compliance teams miss critical exposure and face TRACFIN and ACPR enforcement action.
This template explains why French firms need third-party risk assessment and the regulatory framework governing third-party due diligence and provides an actionable risk matrix for consistent evaluation. For additional guidance, consult the ACPR’s AML-CFT supervision framework and the AMF’s beneficial ownership guidelines.
Why France needs an AML third-party risk template
French financial institutions face three converging pressures regarding third-party risk:
Regulatory intensity
The AutoritĂ© de ContrĂ´le Prudentiel et de RĂ©solution (ACPR) and TRACFIN (Financial Intelligence Unit) expect firms to conduct documented third-party due diligence. France’s AML Directive implementation requires proportionate risk assessment for all material business relationships.
Supply chain vulnerability
Third parties create indirect money laundering pathways: shell company distributors, high-risk service providers, and PEP-affiliated business partners. Without systematic screening, firms unknowingly facilitate sanctions evasion or trade-based money laundering through third parties.
Operational complexity
Compliance teams manage hundreds of third-party relationships across procurement, payments, distribution, and outsourcing. Manual assessment creates inconsistency, missed deadlines, and audit gaps when regulators request evidence.
A structured AML third-party risk template addresses each pressure by embedding risk-based assessment into onboarding workflows, maintaining documented evidence of due diligence, and automating periodic reassessment triggers.
What is third-party AML risk assessment?
Third-party AML risk assessment is a documented evaluation of a business partner’s money laundering and terrorist financing exposure. Assessment covers beneficial ownership transparency, jurisdiction of operation, regulatory status, transaction patterns, and sanctions history. Risk rating informs ongoing monitoring intensity and contract termination decisions.
Effective third-party assessment requires clear risk criteria, documented scoring, evidence retention, and periodic reassessment. Without systematic assessment, firms cannot demonstrate to TRACFIN or ACPR that they applied risk-based due diligence.
French regulatory framework
The AutoritĂ© de ContrĂ´le Prudentiel et de RĂ©solution (ACPR) and TRACFIN (Financial Intelligence Unit) establish expectations for documented third-party due diligence. The ACPR’s guidance on combating money laundering outlines supervisory expectations for third-party risk assessment and AML compliance.
Key requirements:
Beneficial ownership identification
Firms must identify ultimate beneficial owners of third parties and assess ownership opacity.
Sanctions and adverse media screening
Screen third parties against EU sanctions lists and international watchlists at onboarding and periodically (minimum annually).
Risk-based monitoring
High-risk third parties require enhanced due diligence and ongoing transaction monitoring. Low-risk third parties may receive streamlined assessment.
Documentation and audit trail
Retain assessment documentation, screening results, and reassessment evidence for TRACFIN inspection.
AML third-party risk template: Assessment matrix
| Risk Factor | Low-Risk Indicator | Medium-Risk Indicator | High-Risk Indicator |
|---|---|---|---|
| Beneficial ownership | Transparent, EU-registered corporate | Moderate opacity, 2-3 ownership layers | Shell company, bearer shares, PEP-linked |
| Jurisdiction | EU-27 member state | Developed non-EU country | FATF grey list, sanctioned territory |
| Regulatory status | Own AML/KYC compliance obligations | Regulated, but jurisdiction varies | Unregulated or recent regulatory action |
| Business type | Established distributor, professional service provider | SME, variable transaction volume | One-person operation, irregular activity |
| Sanctions/adverse media | Clean screening | Historical match only, resolved | Current sanctions match, ongoing adverse media |
| Transaction patterns | Predictable, aligned with contract | Variable seasonal flows | Erratic volumes, unexplained spikes |
Scoring: 1-2 factors = low risk; 3-4 = medium risk; 5+ = high risk. Reassess annually minimum.
Common third-party assessment challenges
- Fragmented due diligence: Third-party documentation scattered across procurement, finance, and compliance systems with no unified record.
- Shallow beneficial ownership: Firms accept third-party assertions without verification or documentation.
- Missed reassessment deadlines: Annual reassessments not scheduled; third-party risk status becomes stale.
- No screening integration: Sanctions checks performed manually or not at all; TRACFIN watchlist matches missed.
- Inadequate documentation: Assessment decisions lack written rationale; TRACFIN requests expose gaps.
AML third-party risk template: Best practices
Third-party risk assessment should be systematic, proportionate, and risk-based. The AMF’s guidance on risk-based AML approaches provides regulatory expectations for consistent assessment across your organization.
- Document risk criteria and scoring thresholds in writing; communicate to procurement and finance teams.
- Verify beneficial ownership for all material third parties; require documentary evidence for complex structures.
- Screen all third parties at onboarding against EU sanctions and international watchlists; repeat annually minimum.
- Establish reassessment triggers: annual calendar review, material contract changes, sanctions matches, and regulatory updates.
- Retain assessment documentation, screening results, and reassessment evidence for a minimum of six years.
- Integrate third-party due diligence into procurement workflows so compliance reviews occur before relationship establishment.
Systematic third-party assessment prevents regulatory risk
Manual third-party assessments across fragmented systems expose French firms to compliance gaps when TRACFIN or ACPR requests evidence. A centralized compliance platform consolidates third-party profiles with integrated sanctions screening, automated reassessment scheduling, and documented audit trails. Assessment decisions are recorded with supporting evidence; regulatory requests are fulfilled immediately with complete, organized documentation.
Key takeaways
All material third-party relationships require documented AML risk assessment proportionate to inherent risk before engagement. Beneficial ownership must be verified, sanctions screening conducted, and assessment results retained systematically with periodic reassessment triggers.
Frequently asked questions
What third parties require AML risk assessment under French law?
All material business partners, including distributors, service providers, suppliers, outsourcing partners, and intermediaries, require documented AML risk assessment. Material is defined by contract value or transaction volume; firms should establish clear thresholds in their AML policy.
How often should third-party risk assessments be reassessed?
Annual reassessment is the minimum standard for all third parties. High-risk third parties may require quarterly reassessment. Reassessment should also be triggered by material contract changes, sanctions matches, or significant regulatory updates.
What beneficial ownership documentation should be retained for third parties?
Retain ownership verification documents (corporate registration, shareholder registry, beneficial ownership declaration) for all material third parties. For shell companies or complex structures, supplementary documentation evidencing the ultimate beneficial owner is required.
Must TRACFIN be notified if a third party is subject to sanctions listing?
If you discover a third party has been subject to sanctions during the relationship, you must immediately suspend the relationship and report to TRACFIN. Document the discovery date, action taken, and notification date for regulatory compliance.
What is Cascade, and how does it simplify AML/KYC compliance?
Cascade is an end-to-end AML software platform that centralises client data and supports AML/KYC workflows from onboarding through ongoing monitoring and reporting, helping teams standardise processes and maintain audit trails.
Who can benefit from using Cascade?
Cascade software supports organisations with AML/KYC obligations, including financial services firms, fintechs, wealth managers, law firms and corporate service providers.
How does Cascade ensure data security and regulatory compliance?
The Cascade platform provides controlled workflows, activity logging and audit trails to support traceable AML/KYC processes, though compliance depends on your policies and configuration.
How can I get started with Cascade?
Book a demo with Cascade to discuss your AML/KYC requirements and identify how the platform can support your workflows.
Disclaimer: This article is for general information only and based on publicly available sources and regulatory guidance at the time of writing. We have made our best effort to ensure accuracy and relevance to French financial services AML compliance, but ACPR regulations, TRACFIN guidance, and business requirements can change. Always verify key details against current ACPR and TRACFIN publications and consult with a qualified compliance specialist or legal advisor before making compliance or vendor decisions.






































