SymplifiedSOLUTIONSBook Consultation
External compliance mandate

AML oversight that works inside your operations

Symplified provides an external AML compliance function for Swiss financial intermediaries that need experienced oversight without building a full internal department. The mandate is designed around your clients, transactions, systems and supervisory framework.

When an external model makes sense

A practical option for a growing or specialised business

The decision should follow the workload, independence needs and risk profile—not simply headcount.

A

Limited internal capacity

The business needs qualified AML oversight, but the volume does not support a dedicated full-time role.

B

New regulated activity

The company is establishing its first control framework or preparing for SRO affiliation and operations.

C

Complex risk exposure

Cross-border clients, payment flows or other higher-risk features require experienced review and escalation.

Coverage

What the engagement can include

The precise allocation is set in writing. This table is a service map, not a one-size-fits-all package.

Control areaTypical external supportExpected evidence
Governance and riskReview the risk assessment, control ownership, escalation paths and management information.Approved framework, responsibilities and periodic reporting.
Client due diligenceAdvise on identification, beneficial ownership, higher-risk reviews and complex onboarding questions.Complete files with recorded rationale and approvals.
Ongoing controlsOversee review schedules, alerts, sanctions processes and remediation follow-up.Review logs, resolved exceptions and tracked actions.
Suspicion handlingSupport internal escalation and the assessment of reporting duties under the agreed governance.Confidential decision records and reporting documentation where applicable.
People and awarenessProvide role-specific training and practical guidance for staff and management.Training materials, attendance and knowledge follow-up.
SRO audit readinessOrganise the compliance file, prepare responsible persons and coordinate responses to findings.Audit index, requested records and remediation plan.
Governance boundary

The provider operates the mandate; the company governs it

External support does not replace the governing body’s oversight. A workable arrangement identifies reserved decisions, access rights, reporting frequency and the internal person responsible for supervising the provider.

Written responsibilities and a clear reporting line
Access to the information and people needed for the work
Defined escalation deadlines and decision authority
Management review of issues, trends and overdue actions
Periodic assessment of whether the mandate remains adequate
Working rhythm

A recurring control cycle, not an annual clean-up

The cadence is agreed according to risk and activity. Each cycle produces a record that management can review and auditors can follow.

Start

Baseline review

Confirm scope, gaps, access and immediate corrective actions.

Routine

Case oversight

Review referrals, exceptions and higher-risk relationships.

Periodic

Control reporting

Present issues, trends, decisions and overdue actions.

Annual

Framework refresh

Update the risk assessment, policies and training plan.

Audit cycle

SRO preparation

Assemble evidence, support interviews and track findings.

Commercial model

A scope based on the work required

Fees depend on the firm’s regulatory status, activities, client population, transaction profile, systems and frequency of support. After a short assessment, Symplified proposes the deliverables, service rhythm and fee in writing.

Request a Mandate Proposal
Important: the applicable SRO regulations and the firm’s specific legal position determine which tasks may be allocated externally and which decisions must remain within the company.
Questions

Before appointing an external AML officer

Is the same mandate suitable for every intermediary?

No. A mandate must reflect the firm’s regulatory category, activities, scale, risk exposure and internal organisation.

Can Symplified support an SRO application as well?

The external function can be coordinated with an SRO application or remediation project. The application and ongoing mandate should nevertheless have separate, clearly stated deliverables.

Who remains responsible for AML compliance?

The company and its governing body retain their legal and supervisory responsibilities. The external provider performs the work allocated under the agreement and reports through the agreed governance.

How quickly can a mandate begin?

Timing depends on the completeness of the existing framework, the availability of records and whether material gaps must be resolved before handover.

Regulatory references: FINMA overview of Swiss AML supervision · fedpol information on MROS. This page describes a service framework and is not a determination that outsourcing is permitted for every firm.

Build an AML mandate around your actual risk.

Tell us how the business operates. We will identify the required coverage, internal responsibilities and implementation priorities.

Speak With Symplified