B2B Sales Strategy

    SDR Outsourcing for Financial Services: The Third Party

    What a bank, broker-dealer, adviser or agency's regulators say about an outside team that speaks for it, the licensed line, and which arrangement survives due diligence.

    What each regulator's text says about a third party that works for the firm, as quoted on this page.
    September 21, 202611 min read
    Share:
    The short answer

    For a regulated financial services firm an outsourced sales team is a third-party relationship: the interagency guidance says a bank's responsibility is undiminished, FINRA treats outsiders doing registrable work as associated persons, the SEC marketing rule makes a paid solicitor an endorsement, and states limit unlicensed pay. What survives is research and an approved message sent by a licensed person.

    Key takeaways

    • The 2023 interagency guidance reaches any business arrangement with another entity and says a bank's use of third parties does not diminish its responsibility; a proposed replacement was opened for comment on 11 September 2026.
    • FINRA Notice 05-48 treats a third party doing registrable work as an associated person of the member, Rule 2040 forbids paying an unregistered person who would need registration, and Rule 3110 supervision extends to outsourced covered activities.
    • For an adviser a paid outside solicitor is an endorsement under the SEC marketing rule, requiring a written agreement, disclosure and oversight; for an agency, Florida's rule allows paying an unlicensed person per referral but never per sale.
    • Per-meeting and per-lead arrangements pay for conversations the firm did not hear; a supervised seat or a research-and-writing arrangement, with a compliance-approved template sent by a licensed person, is what an examiner can see.

    Reviewed and updated September 21, 2026

    A regional bank's treasury services team signs an outsourced sales development contract in the spring. The vendor's reps write to controllers and treasurers in the bank's name and book meetings, and by summer the pipeline looks healthier than it has in years. Then the bank's third-party risk function asks what it asks about every vendor: who did the due diligence, where is the compliance clause, who monitors what these people say, and where are the records. Nobody had thought of a sales vendor as a third-party relationship. The regulators had.

    This guide is for the financial services company selling to businesses, the commercial bank, the insurer or agency writing commercial lines, the broker-dealer or adviser with an institutional practice, deciding whether an outside team may do part of its sales development. The rules that bind the firm's own words are in B2B sales for financial services companies; the fintech vendor's assessability problem is in SDR outsourcing for fintech companies and fintech lead generation; the four arrangements on sale are in SDR outsourcing. What is specific here is the third-party layer: what a regulated firm's regulators say about a third party that speaks for it, the licensed-versus-unlicensed line, and which arrangement survives the firm's own vendor due diligence.

    A sales vendor is a third-party relationship

    For a bank, the governing text is the interagency guidance on third-party relationships that the Federal Reserve, the FDIC and the OCC published in the Federal Register on 9 June 2023. It is broad on purpose: the guidance addresses "any business arrangement" and applies "between a banking organization and another entity, by contract or otherwise". And it removes the excuse in the opening paragraph: "A banking organization's use of third parties does not diminish its responsibility to meet these requirements to the same extent as if its activities were performed by the banking organization in-house." It names the laws that travel with the activity, "including but not limited to those designed to protect consumers (such as fair lending laws and prohibitions against unfair, deceptive or abusive acts or practices)", and it describes the practices "typically considered throughout the third-party risk management life cycle", beginning with oversight and accountability (Federal Register, Interagency Guidance on Third-Party Relationships: Risk Management, read 21 September 2026).

    That guidance is in motion. On 11 September 2026 the FDIC, the Federal Reserve Board, the National Credit Union Administration and the OCC "requested comment on proposed guidance to assist financial institutions with managing risks associated with third-party relationships", intended to help institutions "better align and tailor their third-party risk management practices to the risks of individual third-party relationships"; "When finalized, the federal bank regulatory agencies plan to rescind existing third-party risk management guidance and replace it with the finalized guidance", and "Comments on the proposed guidance are due 60 days after publication in the Federal Register" (OCC News Release 2026-77, read 21 September 2026). The proposal is in the Federal Register of 15 September 2026 (Federal Register, Proposed Third-Party Risk Management Guidance, read 21 September 2026). The 2023 text governs today; a firm signing a sales vendor this autumn will be examined, before long, under its successor.

    For a broker-dealer the equivalent text is older and blunter. FINRA's Notice to Members 05-48, published on 22 July 2005, says that "any parties conducting activities or functions that require registration under NASD rules will be considered associated persons of the member", and that "outsourcing an activity or function to a third party does not relieve members of their ultimate responsibility for compliance with all applicable federal securities laws and regulations and NASD and MSRB rules regarding the outsourced activity or function" (FINRA Notice to Members 05-48, read 21 September 2026). Regulatory Notice 21-29, published on 13 August 2021, reminds firms that the supervisory obligation under Rule 3110 "extends to member firms' outsourcing of certain" covered activities, meaning functions that would need supervision if the firm performed them itself (FINRA Regulatory Notice 21-29, read 21 September 2026). Rule 3110 itself begins: "Each member shall establish and maintain a system to supervise the activities of each associated person that is reasonably designed to achieve compliance with applicable securities laws and regulations, and with applicable FINRA rules" (FINRA Rule 3110, read 21 September 2026).

    Bank, broker-dealer, adviser, agency: the text that reaches an outside vendor Bank: interagency guidance, 2023 Any business arrangement is a third-party relationship; responsibility is undiminished Replacement proposed 11 September 2026 Broker-dealer: FINRA 05-48, 21-29, 3110 Registrable work makes the outsider an associated person; supervision extends out Adviser: SEC marketing rule A paid solicitor is an endorsement: written agreement, disclosure, adviser oversight Agency: state producer licensing Unlicensed referrals paid per referral, never per sale; solicitation stays licensed Four texts, one direction
    What each regulator's text says about a third party that works for the firm, as quoted on this page.

    The licensed and the unlicensed line

    What the outside person may say depends on which kind of firm is speaking.

    For a broker-dealer, FINRA Rule 1210 says "Each person engaged in the investment banking or securities business of a member shall be registered with FINRA as a representative or principal in each category of registration appropriate to his or her functions and responsibilities" (FINRA Rule 1210, read 21 September 2026), and Rule 2040 closes the payment route: "No member or associated person shall, directly or indirectly, pay any compensation, fees, concessions, discounts, commissions or other allowances to: (1) any person that is not registered as a broker-dealer under Section 15(a) of the Exchange Act but, by reason of receipt of any such payments and the activities related thereto, is required to be so registered" (FINRA Rule 2040, read 21 September 2026). Whether a given outreach activity requires registration is a question for the firm's compliance function and counsel; what the texts make plain is that an outside person doing registrable work is inside the firm's perimeter, not outside it.

    For an investment adviser, the SEC's marketing rule, which its press release of 22 December 2020 says "replaces the current advertising and cash solicitation rules" and "will permit the use of testimonials and endorsements, which include traditional referral and solicitation activity, subject to certain conditions" (SEC Press Release 2020-334, read 21 September 2026), treats a paid outside person who recommends the adviser as giving an endorsement. The rule text requires the adviser to have "A written agreement with any person giving a testimonial or endorsement that describes the scope of the agreed-upon activities and the terms of compensation for those activities", and "A reasonable basis for believing that the testimonial or endorsement complies with the requirements of this section" (eCFR, 17 CFR 275.206(4)-1, read 21 September 2026).

    For an insurance agency the line is drawn by the state, and Florida's Department of Financial Services shows how. Its page for general lines agents says an agent may pay an unlicensed person for referrals only under a statute that forbids any fee "which is in any way dependent upon whether the referral results in the purchase of an insurance product", and summarises: "it is OK to pay an unlicensed person for every referral. If you only pay that unlicensed person for referrals that result in the sale of an insurance product, it violates the law." The same page confines a licensed customer representative's authority to solicit new customers to "the agent's office or by phone from that office" (Florida Department of Financial Services, General Lines Agents and Customer Representatives, read 21 September 2026). Other states write their own rules; the point for an agency is that a per-sale fee to an unlicensed setter is the shape a state may forbid.

    Bank

    Outside person may: research a business and send an approved message offering a conversation.

    Stays inside: any statement of a rate, term or credit decision; any consumer product.

    Broker-dealer

    Outside person may: research and drafting under the firm's supervision.

    Stays inside: anything that is securities business, such as recommending or soliciting a transaction.

    Adviser

    Outside person may: give an endorsement under a written agreement with disclosure.

    Stays inside: advice, performance claims, anything beyond the agreed scope.

    Agency

    Outside person may: referrals paid per referral, research, an introduction.

    Stays inside: soliciting, quoting, binding; any fee tied to a sale.

    What an outside person may say for each kind of firm, drawn from the texts on this page; none of it is legal advice.

    The rules every sender inherits

    Two federal rules reach the message whoever sends it. The Federal Trade Commission's CAN-SPAM guide: "The law makes no exception for business-to-business email", and "even if you hire another company to handle your email marketing, you can't contract away your legal responsibility to comply with the law" (FTC, CAN-SPAM Act: A Compliance Guide for Business, read 21 September 2026). The Federal Communications Commission's rules, for a vendor that calls or texts mobile numbers, "require a caller to obtain your oral or written consent before making an autodialed or prerecorded call or text to your wireless number" (FCC, Stop Unwanted Robocalls and Texts, read 21 September 2026). RevenueFlow runs email and LinkedIn only, one message per campaign, no bumps; calling here is the vertical's practice.

    Which arrangement survives vendor due diligence

    Put the regulators' texts beside the four arrangements and the fit sorts itself. The interagency guidance's life cycle begins with oversight and accountability; FINRA's notices require supervision of covered activities and records of what was said; the marketing rule requires a written agreement and adviser oversight of any paid endorsement; a state may forbid a fee tied to a sale. Every one is a requirement about control of what is said and by whom.

    A per-meeting arrangement is paid for a conversation the firm did not hear and cannot show its examiner. A per-lead arrangement is paid for a name, and for an agency may be the fee shape the state forbids. A dedicated seat can be supervised, trained on approved language and recorded, which is what the texts ask, provided the person in it never crosses into registered or licensed work. A research-and-writing arrangement, where the outside team builds the list and drafts one message that the compliance owner approves and a licensed, named person sends, leaves nothing outside the perimeter. That is also how RevenueFlow works for any client: qualification agreed in writing before launch, every template approved by the client, the campaign in the client's name.

    Outside research, approved template, licensed sender, firm keeps the record Outside team: research and a draft Business, titles, public trigger, one message Compliance owner: approves the template No rate, term, recommendation or performance Licensed or registered person: sends In their own name, from the firm's domain Firm: keeps the record, takes the reply Supervised, retained, monitored Nothing is said outside the perimeter
    The path an outside team's work takes inside a regulated firm's perimeter, from research to the licensed sender, with compliance approving the template.

    The relationship manager is the incumbent, and the vendor is a supplement

    The firm's own selling model is a licensed or registered person with a portfolio and a network of referring professionals; that model, its buying committee and its renewal windows are in the B2B sales guide linked above. What the third-party layer adds is a limit: an outside team can widen the top of that person's funnel with research and a first approved message, and nothing else. It cannot hold the credit conversation, quote the policy, recommend the security or give the advice, and under the texts above it should not be paid as if it had. A firm that treats its vendor as a researcher and a drafter, supervised like any other third party, buys something its examiner can see.

    When outsourcing is the wrong play for a financial services company

    It is the wrong play when the firm has no third-party risk process to put the vendor through, because the guidance expects one. It is the wrong play when the vendor's people would do registrable or licensable work, or be paid per sale where the state forbids it. It is the wrong play when nobody inside can approve every template and take every reply, since those are the two places the texts put the firm. It is the wrong play for consumer products, where the consumer rules govern. And it is the wrong play as a per-meeting purchase, because the meeting is a conversation the firm did not hear.

    It fits a firm with a third-party process, a compliance owner with time to approve templates, a licensed person to send and answer, and more businesses than that person can research alone.

    Three openers, each on a fetched fact

    Three illustrative openers follow, each built on a page read on 21 September 2026, each one message to one person, sent once by a licensed or registered person after the compliance owner has approved it. None names a real recipient, states a rate or term, or claims a result, and the firm that speaks in each is invented.

    The first is from a commercial bank's treasury specialist to a company's controller, and it rests on the interagency guidance's expectation that a bank's responsibility is undiminished when a third party does the work: the message names the person who will answer.

    Your company opened a second distribution site this year, per your own announcement, which usually means receivables landing in more than one place. The treasury specialist writing this is the person who would work with you, and every message from our bank comes from a named banker. If a short conversation about how two companies of your size set up cash application would be useful, name a week.
    

    The second is from a commercial lines agency to a business owner, and it rests on the Florida page's rule that an unlicensed person may be paid per referral but never per sale: the licensed agent is the sender.

    The person writing this holds the licence for commercial lines in your state and would be the person handling your account. Your fleet policy renews in the spring on the date your current agent reviews it. We would like to be on the table at that review with a quote, and nothing in this note is one.
    

    The third is from a registered representative at an institutional broker-dealer, and it rests on FINRA Rule 2210's correspondence category: one person, one message, kept on record, no recommendation.

    This note is from one registered person to one finance director, a copy is kept by our firm as our rules require, and it recommends nothing. Your treasurer's post about the cash policy review described a question our institutional desk works on. If a conversation with the registered person who covers your sector would help, we can arrange it at a time that suits you.
    

    Email from a bank's treasury specialist to a company's controller, sent once

    Your company opened a second distribution site this year, per your own announcement, which usually means receivables landing in more than one place. 1

    The treasury specialist writing this is the person who would work with you, and every message from our bank comes from a named banker. If a short conversation about how two companies of your size set up cash application would be useful, name a week. 2

    1. 1A public fact about the company and what it usually means; no product, rate or term is named.
    2. 2The sender is the licensed person inside the perimeter, which is where the guidance puts the bank's responsibility, and the ask carries no claim about results.
    The first illustrative opener with its working parts numbered; the message and the bank are invented.

    What to agree in writing

    The vendor's place in the firm's third-party process: due diligence, contract clauses on compliance and records, monitoring named. The line: research and drafting outside, every regulated act inside, the fee shape checked against the state. The compliance owner who approves every template, and the licensed or registered person who sends and answers. The record of every message, kept by the firm. One message per campaign, no bumps. A financial services company that wants to see a researched list and a single approved message, sent in its own licensed person's name, before contracting for any arrangement can start with a free campaign and count the conversations that begin.

    The Federal Register, OCC, FINRA, SEC, eCFR, Florida Department of Financial Services, FTC and FCC pages were read on their own sites on 21 September 2026. The 2023 interagency guidance is quoted as current text; its proposed replacement was open for comment on the day of reading. Nothing here is legal or compliance advice; whether an activity requires registration or a licence is a question for the firm's own compliance function and counsel.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Is an outsourced SDR vendor a third-party relationship for a bank?
    Yes under the interagency guidance published on 9 June 2023, which addresses any business arrangement between a banking organization and another entity, by contract or otherwise, and says the bank's responsibility is undiminished when a third party performs the activity. A sales vendor goes through the same due diligence, contracting and monitoring as any other vendor, and the agencies proposed replacement guidance on 11 September 2026.
    Can a broker-dealer use an unregistered outside team to book meetings?
    FINRA's Notice to Members 05-48 says parties conducting activities that require registration will be considered associated persons of the member, Rule 1210 requires registration of each person engaged in the firm's securities business, and Rule 2040 forbids paying a person who by reason of the payment and the activity would need to be registered. Whether outreach is registrable is a question for compliance and counsel; the safe rule keeps the outsider to research and drafting under supervision.
    What does the SEC marketing rule say about paying an outside solicitor?
    The rule the SEC adopted on 22 December 2020 replaced the cash solicitation rule and permits testimonials and endorsements, which include traditional referral and solicitation activity, subject to conditions. The text requires a written agreement describing the scope of the activities and the compensation, disclosures at the time of the endorsement, and a reasonable basis for believing the endorsement complies. An outside team paid to recommend an adviser sits inside that regime.
    Which outsourcing model fits a financial services company?
    The one the firm's regulators can see. A per-meeting fee pays for a conversation the firm did not hear, and a per-lead fee may be the sale-linked payment a state forbids for an unlicensed person. A dedicated seat that is supervised, trained on approved language and recorded, or a research-and-writing arrangement whose one message the compliance owner approves and a licensed person sends, keeps every regulated act inside the perimeter.
    SDR OutsourcingFinancial ServicesBankingComplianceB2B Sales
    Byline

    About the author.

    RevenueFlow Team

    B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.

    RevenueFlow Team

    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.