AML Third-Party Risk Template for France

AML Third-Party Risk Template for France

Third-party risk assessment is the systematic evaluation of money laundering and terrorist financing exposure created by suppliers, service providers, distributors, and business partners. French regulators expect firms to document third-party due diligence proportionate to inherent risk before establishing relationships. Without structured assessment, compliance teams miss critical exposure and face TRACFIN and ACPR enforcement action.

This template explains why French firms need third-party risk assessment and the regulatory framework governing third-party due diligence and provides an actionable risk matrix for consistent evaluation. For additional guidance, consult the ACPR’s AML-CFT supervision framework and the AMF’s beneficial ownership guidelines.

Why France needs an AML third-party risk template

French financial institutions face three converging pressures regarding third-party risk:

Regulatory intensity

The AutoritĂ© de ContrĂ´le Prudentiel et de RĂ©solution (ACPR) and TRACFIN (Financial Intelligence Unit) expect firms to conduct documented third-party due diligence. France’s AML Directive implementation requires proportionate risk assessment for all material business relationships.

Supply chain vulnerability

Third parties create indirect money laundering pathways: shell company distributors, high-risk service providers, and PEP-affiliated business partners. Without systematic screening, firms unknowingly facilitate sanctions evasion or trade-based money laundering through third parties.

Operational complexity

Compliance teams manage hundreds of third-party relationships across procurement, payments, distribution, and outsourcing. Manual assessment creates inconsistency, missed deadlines, and audit gaps when regulators request evidence.

A structured AML third-party risk template addresses each pressure by embedding risk-based assessment into onboarding workflows, maintaining documented evidence of due diligence, and automating periodic reassessment triggers.

What is third-party AML risk assessment?

Third-party AML risk assessment is a documented evaluation of a business partner’s money laundering and terrorist financing exposure. Assessment covers beneficial ownership transparency, jurisdiction of operation, regulatory status, transaction patterns, and sanctions history. Risk rating informs ongoing monitoring intensity and contract termination decisions.

Effective third-party assessment requires clear risk criteria, documented scoring, evidence retention, and periodic reassessment. Without systematic assessment, firms cannot demonstrate to TRACFIN or ACPR that they applied risk-based due diligence.

French regulatory framework

The AutoritĂ© de ContrĂ´le Prudentiel et de RĂ©solution (ACPR) and TRACFIN (Financial Intelligence Unit) establish expectations for documented third-party due diligence. The ACPR’s guidance on combating money laundering outlines supervisory expectations for third-party risk assessment and AML compliance.

Key requirements:

Beneficial ownership identification

Firms must identify ultimate beneficial owners of third parties and assess ownership opacity.

Sanctions and adverse media screening

Screen third parties against EU sanctions lists and international watchlists at onboarding and periodically (minimum annually).

Risk-based monitoring

High-risk third parties require enhanced due diligence and ongoing transaction monitoring. Low-risk third parties may receive streamlined assessment.

Documentation and audit trail

Retain assessment documentation, screening results, and reassessment evidence for TRACFIN inspection.

AML third-party risk template: Assessment matrix

Risk FactorLow-Risk IndicatorMedium-Risk IndicatorHigh-Risk Indicator
Beneficial ownershipTransparent, EU-registered corporateModerate opacity, 2-3 ownership layersShell company, bearer shares, PEP-linked
JurisdictionEU-27 member stateDeveloped non-EU countryFATF grey list, sanctioned territory
Regulatory statusOwn AML/KYC compliance obligationsRegulated, but jurisdiction variesUnregulated or recent regulatory action
Business typeEstablished distributor, professional service providerSME, variable transaction volumeOne-person operation, irregular activity
Sanctions/adverse mediaClean screeningHistorical match only, resolvedCurrent sanctions match, ongoing adverse media
Transaction patternsPredictable, aligned with contractVariable seasonal flowsErratic volumes, unexplained spikes

Scoring: 1-2 factors = low risk; 3-4 = medium risk; 5+ = high risk. Reassess annually minimum.

Common third-party assessment challenges

  • Fragmented due diligence: Third-party documentation scattered across procurement, finance, and compliance systems with no unified record.
  • Shallow beneficial ownership: Firms accept third-party assertions without verification or documentation.
  • Missed reassessment deadlines: Annual reassessments not scheduled; third-party risk status becomes stale.
  • No screening integration: Sanctions checks performed manually or not at all; TRACFIN watchlist matches missed.
  • Inadequate documentation: Assessment decisions lack written rationale; TRACFIN requests expose gaps.

AML third-party risk template: Best practices

Third-party risk assessment should be systematic, proportionate, and risk-based. The AMF’s guidance on risk-based AML approaches provides regulatory expectations for consistent assessment across your organization.

  • Document risk criteria and scoring thresholds in writing; communicate to procurement and finance teams.
  • Verify beneficial ownership for all material third parties; require documentary evidence for complex structures.
  • Screen all third parties at onboarding against EU sanctions and international watchlists; repeat annually minimum.
  • Establish reassessment triggers: annual calendar review, material contract changes, sanctions matches, and regulatory updates.
  • Retain assessment documentation, screening results, and reassessment evidence for a minimum of six years.
  • Integrate third-party due diligence into procurement workflows so compliance reviews occur before relationship establishment.

Systematic third-party assessment prevents regulatory risk

Manual third-party assessments across fragmented systems expose French firms to compliance gaps when TRACFIN or ACPR requests evidence. A centralized compliance platform consolidates third-party profiles with integrated sanctions screening, automated reassessment scheduling, and documented audit trails. Assessment decisions are recorded with supporting evidence; regulatory requests are fulfilled immediately with complete, organized documentation.

Key takeaways

All material third-party relationships require documented AML risk assessment proportionate to inherent risk before engagement. Beneficial ownership must be verified, sanctions screening conducted, and assessment results retained systematically with periodic reassessment triggers.

Frequently asked questions

What third parties require AML risk assessment under French law?

All material business partners, including distributors, service providers, suppliers, outsourcing partners, and intermediaries, require documented AML risk assessment. Material is defined by contract value or transaction volume; firms should establish clear thresholds in their AML policy.

How often should third-party risk assessments be reassessed?

Annual reassessment is the minimum standard for all third parties. High-risk third parties may require quarterly reassessment. Reassessment should also be triggered by material contract changes, sanctions matches, or significant regulatory updates.

What beneficial ownership documentation should be retained for third parties?

Retain ownership verification documents (corporate registration, shareholder registry, beneficial ownership declaration) for all material third parties. For shell companies or complex structures, supplementary documentation evidencing the ultimate beneficial owner is required.

Must TRACFIN be notified if a third party is subject to sanctions listing?

If you discover a third party has been subject to sanctions during the relationship, you must immediately suspend the relationship and report to TRACFIN. Document the discovery date, action taken, and notification date for regulatory compliance.

What is Cascade, and how does it simplify AML/KYC compliance?

Cascade is an end-to-end AML software platform that centralises client data and supports AML/KYC workflows from onboarding through ongoing monitoring and reporting, helping teams standardise processes and maintain audit trails.

Who can benefit from using Cascade?

Cascade software supports organisations with AML/KYC obligations, including financial services firms, fintechs, wealth managers, law firms and corporate service providers.

How does Cascade ensure data security and regulatory compliance?

The Cascade platform provides controlled workflows, activity logging and audit trails to support traceable AML/KYC processes, though compliance depends on your policies and configuration.

How can I get started with Cascade?

Book a demo with Cascade to discuss your AML/KYC requirements and identify how the platform can support your workflows.

Disclaimer: This article is for general information only and based on publicly available sources and regulatory guidance at the time of writing. We have made our best effort to ensure accuracy and relevance to French financial services AML compliance, but ACPR regulations, TRACFIN guidance, and business requirements can change. Always verify key details against current ACPR and TRACFIN publications and consult with a qualified compliance specialist or legal advisor before making compliance or vendor decisions.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade