SDR Outsourcing for Financial Services: The Third Party
What a bank, broker-dealer, adviser or agency's regulators say about an outside team that speaks for it, the licensed line, and which arrangement survives due diligence.

For a regulated financial services firm an outsourced sales team is a third-party relationship: the interagency guidance says a bank's responsibility is undiminished, FINRA treats outsiders doing registrable work as associated persons, the SEC marketing rule makes a paid solicitor an endorsement, and states limit unlicensed pay. What survives is research and an approved message sent by a licensed person.
Key takeaways
- The 2023 interagency guidance reaches any business arrangement with another entity and says a bank's use of third parties does not diminish its responsibility; a proposed replacement was opened for comment on 11 September 2026.
- FINRA Notice 05-48 treats a third party doing registrable work as an associated person of the member, Rule 2040 forbids paying an unregistered person who would need registration, and Rule 3110 supervision extends to outsourced covered activities.
- For an adviser a paid outside solicitor is an endorsement under the SEC marketing rule, requiring a written agreement, disclosure and oversight; for an agency, Florida's rule allows paying an unlicensed person per referral but never per sale.
- Per-meeting and per-lead arrangements pay for conversations the firm did not hear; a supervised seat or a research-and-writing arrangement, with a compliance-approved template sent by a licensed person, is what an examiner can see.
Reviewed and updated September 21, 2026
A regional bank's treasury services team signs an outsourced sales development contract in the spring. The vendor's reps write to controllers and treasurers in the bank's name and book meetings, and by summer the pipeline looks healthier than it has in years. Then the bank's third-party risk function asks what it asks about every vendor: who did the due diligence, where is the compliance clause, who monitors what these people say, and where are the records. Nobody had thought of a sales vendor as a third-party relationship. The regulators had.
This guide is for the financial services company selling to businesses, the commercial bank, the insurer or agency writing commercial lines, the broker-dealer or adviser with an institutional practice, deciding whether an outside team may do part of its sales development. The rules that bind the firm's own words are in B2B sales for financial services companies; the fintech vendor's assessability problem is in SDR outsourcing for fintech companies and fintech lead generation; the four arrangements on sale are in SDR outsourcing. What is specific here is the third-party layer: what a regulated firm's regulators say about a third party that speaks for it, the licensed-versus-unlicensed line, and which arrangement survives the firm's own vendor due diligence.
A sales vendor is a third-party relationship
For a bank, the governing text is the interagency guidance on third-party relationships that the Federal Reserve, the FDIC and the OCC published in the Federal Register on 9 June 2023. It is broad on purpose: the guidance addresses "any business arrangement" and applies "between a banking organization and another entity, by contract or otherwise". And it removes the excuse in the opening paragraph: "A banking organization's use of third parties does not diminish its responsibility to meet these requirements to the same extent as if its activities were performed by the banking organization in-house." It names the laws that travel with the activity, "including but not limited to those designed to protect consumers (such as fair lending laws and prohibitions against unfair, deceptive or abusive acts or practices)", and it describes the practices "typically considered throughout the third-party risk management life cycle", beginning with oversight and accountability (Federal Register, Interagency Guidance on Third-Party Relationships: Risk Management, read 21 September 2026).
That guidance is in motion. On 11 September 2026 the FDIC, the Federal Reserve Board, the National Credit Union Administration and the OCC "requested comment on proposed guidance to assist financial institutions with managing risks associated with third-party relationships", intended to help institutions "better align and tailor their third-party risk management practices to the risks of individual third-party relationships"; "When finalized, the federal bank regulatory agencies plan to rescind existing third-party risk management guidance and replace it with the finalized guidance", and "Comments on the proposed guidance are due 60 days after publication in the Federal Register" (OCC News Release 2026-77, read 21 September 2026). The proposal is in the Federal Register of 15 September 2026 (Federal Register, Proposed Third-Party Risk Management Guidance, read 21 September 2026). The 2023 text governs today; a firm signing a sales vendor this autumn will be examined, before long, under its successor.
For a broker-dealer the equivalent text is older and blunter. FINRA's Notice to Members 05-48, published on 22 July 2005, says that "any parties conducting activities or functions that require registration under NASD rules will be considered associated persons of the member", and that "outsourcing an activity or function to a third party does not relieve members of their ultimate responsibility for compliance with all applicable federal securities laws and regulations and NASD and MSRB rules regarding the outsourced activity or function" (FINRA Notice to Members 05-48, read 21 September 2026). Regulatory Notice 21-29, published on 13 August 2021, reminds firms that the supervisory obligation under Rule 3110 "extends to member firms' outsourcing of certain" covered activities, meaning functions that would need supervision if the firm performed them itself (FINRA Regulatory Notice 21-29, read 21 September 2026). Rule 3110 itself begins: "Each member shall establish and maintain a system to supervise the activities of each associated person that is reasonably designed to achieve compliance with applicable securities laws and regulations, and with applicable FINRA rules" (FINRA Rule 3110, read 21 September 2026).
The licensed and the unlicensed line
What the outside person may say depends on which kind of firm is speaking.
For a broker-dealer, FINRA Rule 1210 says "Each person engaged in the investment banking or securities business of a member shall be registered with FINRA as a representative or principal in each category of registration appropriate to his or her functions and responsibilities" (FINRA Rule 1210, read 21 September 2026), and Rule 2040 closes the payment route: "No member or associated person shall, directly or indirectly, pay any compensation, fees, concessions, discounts, commissions or other allowances to: (1) any person that is not registered as a broker-dealer under Section 15(a) of the Exchange Act but, by reason of receipt of any such payments and the activities related thereto, is required to be so registered" (FINRA Rule 2040, read 21 September 2026). Whether a given outreach activity requires registration is a question for the firm's compliance function and counsel; what the texts make plain is that an outside person doing registrable work is inside the firm's perimeter, not outside it.
For an investment adviser, the SEC's marketing rule, which its press release of 22 December 2020 says "replaces the current advertising and cash solicitation rules" and "will permit the use of testimonials and endorsements, which include traditional referral and solicitation activity, subject to certain conditions" (SEC Press Release 2020-334, read 21 September 2026), treats a paid outside person who recommends the adviser as giving an endorsement. The rule text requires the adviser to have "A written agreement with any person giving a testimonial or endorsement that describes the scope of the agreed-upon activities and the terms of compensation for those activities", and "A reasonable basis for believing that the testimonial or endorsement complies with the requirements of this section" (eCFR, 17 CFR 275.206(4)-1, read 21 September 2026).
For an insurance agency the line is drawn by the state, and Florida's Department of Financial Services shows how. Its page for general lines agents says an agent may pay an unlicensed person for referrals only under a statute that forbids any fee "which is in any way dependent upon whether the referral results in the purchase of an insurance product", and summarises: "it is OK to pay an unlicensed person for every referral. If you only pay that unlicensed person for referrals that result in the sale of an insurance product, it violates the law." The same page confines a licensed customer representative's authority to solicit new customers to "the agent's office or by phone from that office" (Florida Department of Financial Services, General Lines Agents and Customer Representatives, read 21 September 2026). Other states write their own rules; the point for an agency is that a per-sale fee to an unlicensed setter is the shape a state may forbid.
Bank
Outside person may: research a business and send an approved message offering a conversation.
Stays inside: any statement of a rate, term or credit decision; any consumer product.
Broker-dealer
Outside person may: research and drafting under the firm's supervision.
Stays inside: anything that is securities business, such as recommending or soliciting a transaction.
Adviser
Outside person may: give an endorsement under a written agreement with disclosure.
Stays inside: advice, performance claims, anything beyond the agreed scope.
Agency
Outside person may: referrals paid per referral, research, an introduction.
Stays inside: soliciting, quoting, binding; any fee tied to a sale.
The rules every sender inherits
Two federal rules reach the message whoever sends it. The Federal Trade Commission's CAN-SPAM guide: "The law makes no exception for business-to-business email", and "even if you hire another company to handle your email marketing, you can't contract away your legal responsibility to comply with the law" (FTC, CAN-SPAM Act: A Compliance Guide for Business, read 21 September 2026). The Federal Communications Commission's rules, for a vendor that calls or texts mobile numbers, "require a caller to obtain your oral or written consent before making an autodialed or prerecorded call or text to your wireless number" (FCC, Stop Unwanted Robocalls and Texts, read 21 September 2026). RevenueFlow runs email and LinkedIn only, one message per campaign, no bumps; calling here is the vertical's practice.
Which arrangement survives vendor due diligence
Put the regulators' texts beside the four arrangements and the fit sorts itself. The interagency guidance's life cycle begins with oversight and accountability; FINRA's notices require supervision of covered activities and records of what was said; the marketing rule requires a written agreement and adviser oversight of any paid endorsement; a state may forbid a fee tied to a sale. Every one is a requirement about control of what is said and by whom.
A per-meeting arrangement is paid for a conversation the firm did not hear and cannot show its examiner. A per-lead arrangement is paid for a name, and for an agency may be the fee shape the state forbids. A dedicated seat can be supervised, trained on approved language and recorded, which is what the texts ask, provided the person in it never crosses into registered or licensed work. A research-and-writing arrangement, where the outside team builds the list and drafts one message that the compliance owner approves and a licensed, named person sends, leaves nothing outside the perimeter. That is also how RevenueFlow works for any client: qualification agreed in writing before launch, every template approved by the client, the campaign in the client's name.
The relationship manager is the incumbent, and the vendor is a supplement
The firm's own selling model is a licensed or registered person with a portfolio and a network of referring professionals; that model, its buying committee and its renewal windows are in the B2B sales guide linked above. What the third-party layer adds is a limit: an outside team can widen the top of that person's funnel with research and a first approved message, and nothing else. It cannot hold the credit conversation, quote the policy, recommend the security or give the advice, and under the texts above it should not be paid as if it had. A firm that treats its vendor as a researcher and a drafter, supervised like any other third party, buys something its examiner can see.
When outsourcing is the wrong play for a financial services company
It is the wrong play when the firm has no third-party risk process to put the vendor through, because the guidance expects one. It is the wrong play when the vendor's people would do registrable or licensable work, or be paid per sale where the state forbids it. It is the wrong play when nobody inside can approve every template and take every reply, since those are the two places the texts put the firm. It is the wrong play for consumer products, where the consumer rules govern. And it is the wrong play as a per-meeting purchase, because the meeting is a conversation the firm did not hear.
It fits a firm with a third-party process, a compliance owner with time to approve templates, a licensed person to send and answer, and more businesses than that person can research alone.
Three openers, each on a fetched fact
Three illustrative openers follow, each built on a page read on 21 September 2026, each one message to one person, sent once by a licensed or registered person after the compliance owner has approved it. None names a real recipient, states a rate or term, or claims a result, and the firm that speaks in each is invented.
The first is from a commercial bank's treasury specialist to a company's controller, and it rests on the interagency guidance's expectation that a bank's responsibility is undiminished when a third party does the work: the message names the person who will answer.
Your company opened a second distribution site this year, per your own announcement, which usually means receivables landing in more than one place. The treasury specialist writing this is the person who would work with you, and every message from our bank comes from a named banker. If a short conversation about how two companies of your size set up cash application would be useful, name a week.
The second is from a commercial lines agency to a business owner, and it rests on the Florida page's rule that an unlicensed person may be paid per referral but never per sale: the licensed agent is the sender.
The person writing this holds the licence for commercial lines in your state and would be the person handling your account. Your fleet policy renews in the spring on the date your current agent reviews it. We would like to be on the table at that review with a quote, and nothing in this note is one.
The third is from a registered representative at an institutional broker-dealer, and it rests on FINRA Rule 2210's correspondence category: one person, one message, kept on record, no recommendation.
This note is from one registered person to one finance director, a copy is kept by our firm as our rules require, and it recommends nothing. Your treasurer's post about the cash policy review described a question our institutional desk works on. If a conversation with the registered person who covers your sector would help, we can arrange it at a time that suits you.
Email from a bank's treasury specialist to a company's controller, sent once
Your company opened a second distribution site this year, per your own announcement, which usually means receivables landing in more than one place. 1
The treasury specialist writing this is the person who would work with you, and every message from our bank comes from a named banker. If a short conversation about how two companies of your size set up cash application would be useful, name a week. 2
- 1A public fact about the company and what it usually means; no product, rate or term is named.
- 2The sender is the licensed person inside the perimeter, which is where the guidance puts the bank's responsibility, and the ask carries no claim about results.
What to agree in writing
The vendor's place in the firm's third-party process: due diligence, contract clauses on compliance and records, monitoring named. The line: research and drafting outside, every regulated act inside, the fee shape checked against the state. The compliance owner who approves every template, and the licensed or registered person who sends and answers. The record of every message, kept by the firm. One message per campaign, no bumps. A financial services company that wants to see a researched list and a single approved message, sent in its own licensed person's name, before contracting for any arrangement can start with a free campaign and count the conversations that begin.
The Federal Register, OCC, FINRA, SEC, eCFR, Florida Department of Financial Services, FTC and FCC pages were read on their own sites on 21 September 2026. The 2023 interagency guidance is quoted as current text; its proposed replacement was open for comment on the day of reading. Nothing here is legal or compliance advice; whether an activity requires registration or a licence is a question for the firm's own compliance function and counsel.
Frequently asked questions.
Frequently asked questions- Is an outsourced SDR vendor a third-party relationship for a bank?
- Yes under the interagency guidance published on 9 June 2023, which addresses any business arrangement between a banking organization and another entity, by contract or otherwise, and says the bank's responsibility is undiminished when a third party performs the activity. A sales vendor goes through the same due diligence, contracting and monitoring as any other vendor, and the agencies proposed replacement guidance on 11 September 2026.
- Can a broker-dealer use an unregistered outside team to book meetings?
- FINRA's Notice to Members 05-48 says parties conducting activities that require registration will be considered associated persons of the member, Rule 1210 requires registration of each person engaged in the firm's securities business, and Rule 2040 forbids paying a person who by reason of the payment and the activity would need to be registered. Whether outreach is registrable is a question for compliance and counsel; the safe rule keeps the outsider to research and drafting under supervision.
- What does the SEC marketing rule say about paying an outside solicitor?
- The rule the SEC adopted on 22 December 2020 replaced the cash solicitation rule and permits testimonials and endorsements, which include traditional referral and solicitation activity, subject to conditions. The text requires a written agreement describing the scope of the activities and the compensation, disclosures at the time of the endorsement, and a reasonable basis for believing the endorsement complies. An outside team paid to recommend an adviser sits inside that regime.
- Which outsourcing model fits a financial services company?
- The one the firm's regulators can see. A per-meeting fee pays for a conversation the firm did not hear, and a per-lead fee may be the sale-linked payment a state forbids for an unlicensed person. A dedicated seat that is supervised, trained on approved language and recorded, or a research-and-writing arrangement whose one message the compliance owner approves and a licensed person sends, keeps every regulated act inside the perimeter.
About the author.
B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.
RevenueFlow Team
Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
LinkedIn Outreach for Banks: A Regulated Message
How a bank's relationship managers use LinkedIn to reach business owners: what the FFIEC guidance, FINRA's notices and LinkedIn's own rules require, and where to stop.
SDR Outsourcing for Business Brokers: The Fee Timing
Whether a success-fee brokerage should rent sales development at all: the fee timing, the texts that limit what an outside person may say about value, and who signs.
LinkedIn Lead Generation for Financial Services Firms
A LinkedIn message from a regulated firm is a communication the rulebook already defines, and the definition turns on how many people receive it within thirty days.
SDR Outsourcing for Logistics Companies: The Brokerage Line
What an outside sales development team may do in a freight company's name, the calling and email rules it inherits, and which arrangement survives a bid-shaped market.
Cold Calling for PPC Agencies: What You Can See First
A paid media prospect is partly readable before the call and has already been told by the platform what to do when a stranger rings about its ads.
Cold Calling for Chemical Companies: Who Picks Up
A chemical cold call rarely arrives first. It reaches a formulator who has already been comparing suppliers on a screen, for one of three published reasons.