Quick Answer: AML outsourcing means delegating the high-volume, judgement-light parts of anti-money-laundering work (alert triage, KYC file build, screening adjudication, remediation) to a specialist team, often offshore, while your institution keeps every decision that carries legal accountability. It is a mainstream, regulator-tolerated practice in 2026, but only under demonstrable oversight: the UK regulator found around 40% of surveyed firms outsource customer due diligence, yet only 36% had full oversight of that provider’s onboarding processes. Outsourcing moves the work. It never moves the liability.
Key Takeaways
- AML outsourcing is legal and common, but oversight is the whole game. The FCA’s July 2026 review of 242 firms found ~40% outsource CDD or EDD, but only 36% could demonstrate full oversight of the third party.
- You delegate work, never judgement. Customer risk-rating, onboarding accept or decline, suspicion determination, and regulatory reporting must stay with the accountable institution in all major regimes.
- The cost gap is real on volume roles. A fully-loaded in-house US KYC or AML analyst runs roughly $115,000 to $127,000 a year once benefits at 30.1% of total compensation and overhead are added.
- The enforcement backdrop is heavy. Global AML, KYC, and sanctions penalties reached $3.8 billion in 2025, and single actions like TD Bank’s ~$3.09 billion resolution show the downside of thin controls.
- South Africa’s jurisdiction risk just cleared. It was removed from the FATF grey list in October 2025 and the EU high-risk list effective 29 January 2026, removing the overlay that previously complicated EU and UK delegation.
- Design the arrangement to fund oversight, not to avoid building it. The regulators reward outsourcing that frees senior capacity for genuine supervision.
What AML Outsourcing Actually Means
AML outsourcing is the practice of having a specialist provider perform defined anti-money-laundering tasks under your institution’s control and brand, rather than staffing every function in-house. It sits alongside the broader shift toward financial services outsourcing, where regulated firms move process-heavy work to dedicated offshore or nearshore teams. In an AML context the delegated work is usually queue-based and evidence-driven: reviewing transaction-monitoring alerts, building and verifying know-your-customer files, adjudicating sanctions and politically-exposed-person screening hits, and running remediation or back-book reviews.
The distinction that matters is between activity and accountability. Every major regulator now says the same thing in slightly different words: operational execution can move outside the institution, and outside the country, but legal responsibility cannot move at all. That single principle shapes every good design decision below, and it is why treating anti-money-laundering as an outsourced BPO function works only when the judgement layer stays home.
What You Can Outsource, and What You Cannot
The commonly delegated functions are the volume tiers, and the regulatory texts support delegating them. In practice that means first-line and second-line alert triage, KYC and customer-due-diligence file build and verification, sanctions and PEP screening adjudication, suspicious-activity-report narrative preparation, ongoing monitoring and periodic-review refresh, and remediation or lookback projects. The FCA confirmed the pattern empirically: roughly 40% of surveyed asset-management and alternatives firms outsource elements of CDD and EDD, typically to fund administrators and compliance providers.
What cannot leave the accountable institution is the set of decisions that constitute judgement. In the United States, the AML Act 2020 (codified at 31 U.S.C. 5318(h)(5)) requires that the AML programme be maintained by persons in the United States, and FinCEN’s April 2026 proposed rule requires a US-based AML/CFT officer while confirming that offshore personnel may still perform certain functions. Critically, sharing a suspicious activity report or its existence with personnel outside the US remains generally prohibited, so offshore teams can prepare investigative work product but the filing itself stays home. In the European Union, Article 18 of Regulation (EU) 2024/1624 lists tasks that cannot be outsourced under any circumstances, including the customer risk-profile decision, the onboarding decision, and reporting to the financial intelligence unit. In the UK, FCA Handbook SYSC 8.1.6 states a firm remains fully responsible for its regulatory obligations and cannot delegate senior-manager responsibility.
The practical design rule is simple to state and hard to game: delegate the work, retain the judgement. Alert triage, evidence gathering, file build, narrative drafting, and quality-assurance sampling can sit offshore. Customer risk-rating, accept-or-decline decisions, suspicion determinations, and regulatory filings stay with the institution.
What Outsourced AML Compliance Costs
The cost case is strongest on high-volume, well-documented, judgement-light work, and it should be modelled on fully-loaded cost rather than headline salary. That distinction is where most in-house budgets understate reality. US Bureau of Labor Statistics data shows wages and salaries account for only 69.9% of total employer compensation, with benefits making up the other 30.1%, implying a multiplier of roughly 1.43 on base salary before you add facilities, technology, recruitment, and management overhead. In the UK, employer National Insurance rose to 15% on earnings above a reduced 5,000-pound threshold, plus a minimum 3% pension contribution.
Applying those sourced multipliers to sourced salary benchmarks gives a defensible in-house baseline, and clarifies which roles are delegable at all.
| Role | In-house fully-loaded cost (annual) | Outsourceable? |
| KYC / AML analyst, L1 (US) | ~$115,000 to $127,000 | Yes, high-volume queue work |
| Transaction-monitoring analyst (US) | ~$115,000 | Yes, L1/L2 triage |
| KYC analyst (UK) | ~£56,800 before facilities and tech | Yes |
| BSA / AML officer (US) | ~$250,000 to $379,000 | No, must be a US-based designated officer |
| MLRO (UK, mid-tier) | ~£195,000 to £300,000 total package | No, non-delegable senior-manager role |

The delegable roles are exactly the ones with the widest cost gap, because they scale with transaction and alert volume. The non-delegable roles are senior and few. That asymmetry is the real economic logic of AML outsourcing: it lets a lean, expensive accountable core sit on top of an elastic, cost-efficient delivery layer. For a fuller treatment of how offshore delivery cost is built up, our analysis of the true cost of offshore support sets out the same fully-loaded method.
Why Demand Is Rising in 2026
The volume and stakes of AML work are both climbing, which is what pushes institutions toward elastic capacity. Enforcement remains severe even where headline totals dipped: global AML, KYC, sanctions, and CDD penalties reached $3.8 billion in 2025, following $4.6 billion in 2024. The single largest recent action, TD Bank’s roughly $3.09 billion multi-agency resolution, included a record $1.3 billion FinCEN penalty and a four-year independent monitorship. In the UK, the FCA fined Starling Bank almost £29 million after it screened customers against only 39 of 3,088 names on the sanctions list for years.
Spending is scaling with the risk. Global financial-crime compliance spend has been benchmarked at $206.1 billion, and the AML solutions market is forecast to grow from $4.05 billion in 2026 to $9.27 billion by 2031 at roughly 18% a year. On the demand side, 83% of fraud and AML leaders expect budget increases in 2026, and 94% plan at least one full-time hire. There is a transatlantic split worth noting: PwC’s EMEA survey found 58% of EMEA institutions expect AML cost increases above 10% driven by the EU AML package, while many US respondents expect costs to fall under the deregulatory FinCEN proposal. A US bank and an EU bank should therefore build very different business cases for the same outsourcing decision. Suspicious-activity-report volumes, meanwhile, keep rising regardless of policy direction, hitting a record 4.1 million filings in 2025.
Why South Africa Works for AML Delivery
South Africa has become a credible AML delivery location, and its jurisdiction risk cleared in the last twelve months, which is the single most material change for anyone who last assessed it in 2023. It was removed from the FATF grey list in October 2025 and from the EU high-risk third-country list effective 29 January 2026. That removal matters directly: EU rules restrict outsourcing AML tasks to high-risk-country providers, and South Africa’s delisting lifts that overlay for both EU-facing and UK-facing work.

The delivery fundamentals are strong. South Africa runs a mature domestic AML regime under the Financial Intelligence Centre, processing over 570,000 suspicious and unusual transaction reports a year across more than 55,000 accountable institutions, so the workforce operates against real regulatory expectations rather than in a vacuum. It ranks 13th of 123 countries for English proficiency, first in Africa. Its global-business-services sector has grown to around 150,000 people, and the US and UK together account for 76.5% of new job creation in the sector, confirming it is already built for US and UK buyers. The GMT+2 timezone gives near-total overlap with London and a useful morning handover to US Eastern hours, which suits an overnight-clearance, morning-review model for alert triage. Our overview of BPO in South Africa covers the wider delivery case, and the South Africa versus Philippines comparison sets it against the traditional offshore default.
One honest caveat: senior AML talent is a scarce skill locally, competing with domestic banks. Model L1 and L2 analyst capacity as scalable and cost-efficient, and model senior investigator and QA-lead capacity as constrained and priced closer to local bank levels.
How to Structure the Arrangement Defensibly
The regulatory case turns entirely on retained oversight, not retained headcount, and the FCA’s 36% full-oversight figure is the number that should govern your build. An arrangement that quietly reduces MLRO or BSA-officer capacity is regulatorily worse than no outsourcing at all. One that funds genuine quality-assurance testing, service-level monitoring, escalation protocols, and periodic review is defensible under SYSC 8.1.6, JMLSG guidance, and EU AMLR Article 18.
The Wolfsberg Group’s monitoring guidance points to the right performance basis. It reframes measurement away from raw alert counts toward precision and recall, judging effectiveness on outcomes rather than throughput. That matters commercially, because an outsourcing arrangement measured on alerts-closed-per-hour is measured on the wrong axis, and a good provider should be held to coverage and quality metrics instead. Firms building AML capacity should also read it alongside their wider data security and compliance posture, since AML work involves highly sensitive customer data. The same model extends naturally to adjacent regulated functions such as banking and financial-services support, fund administration, and loan servicing, and it shares DNA with the AML controls behind iGaming AML compliance.
Frequently Asked Questions
Is AML outsourcing legal? Yes. Outsourcing AML operations is a mainstream, regulator-tolerated practice in the US, UK, and EU. The condition in every regime is that legal accountability stays with the institution. You may delegate the execution of tasks such as alert review and KYC file build, but you remain fully liable for compliance, and you must be able to demonstrate active oversight of the provider.
What AML functions can be outsourced? The high-volume, evidence-driven tiers: transaction-monitoring alert triage, KYC and customer-due-diligence file build and verification, sanctions and PEP screening adjudication, suspicious-activity-report narrative preparation, ongoing monitoring, periodic-review refresh, and remediation or lookback projects. These are judgement-light and scale with volume, which is what makes them suitable to delegate.
What can never be outsourced in AML? The decisions that carry legal accountability: the customer risk-profile decision, the onboarding accept-or-decline decision, the suspicion determination, and the regulatory filing to the financial intelligence unit. In the US you must retain a US-based AML officer and generally cannot share a SAR with offshore staff. In the EU these prohibitions are black-letter under AMLR Article 18. In the UK senior-manager responsibility cannot be delegated.
How much does AML outsourcing save? The saving comes from the fully-loaded cost gap on volume roles. An in-house US KYC or AML analyst costs roughly $115,000 to $127,000 a year once benefits and overhead are added, and a UK KYC analyst around £56,800 before facilities and technology. Offshore delivery of the same queue work removes a substantial share of that cost, though senior and non-delegable roles stay in-house and are not part of the saving.
Does outsourcing AML transfer regulatory liability? No. This is the consistent principle across FinCEN, the FCA, the EU AMLR, and FATF: outsourcing transfers activity, never liability. A provider performing outsourced tasks is treated as part of your institution, and you remain fully responsible for any act or omission connected to that work.
Is South Africa a safe place to outsource AML work? As of 2026, yes, from a jurisdiction standpoint. South Africa was removed from the FATF grey list in October 2025 and from the EU high-risk third-country list effective 29 January 2026, which lifts the restriction that previously complicated EU and UK delegation. It also runs a mature domestic AML regime, ranks first in Africa for English proficiency, and has a large US and UK-facing delivery sector. You still assess local AML law and monitor the arrangement’s own risk.
How do regulators expect me to oversee an outsourced AML provider? Through demonstrable governance: quality-assurance testing of the provider’s output, service-level monitoring against defined metrics, documented escalation procedures, and periodic reviews. The FCA specifically criticised firms that could not explain their provider’s methodology or show that oversight was actually happening. Fund the oversight; do not outsource to avoid building it.
Afrishore builds financial services outsourcing teams for regulated US and UK institutions, including AML and financial-crime process support delivered from South Africa under your oversight and controls. Our teams handle the volume tiers, so your accountable specialists can focus on judgement and supervision. Explore how outsourcing to South Africa fits a compliance-heavy function, and talk to us about a financial services outsourcing team scoped to your regulatory boundaries.



