How a Fund Manager should draft an AML policy

One manager-level framework. A clear assessment of every Fund and every relevant business relationship.

Many Fund Managers still treat the AML policy as a standard one-size-fits-all document in the fund setup file.

Not because AML is ignored. Usually, the opposite is true. KYC documents are collected, investors are screened and the subscription process includes AML checks.

But this keeps coming up in practice: who does the policy actually belong to? The answer is the Fund Manager, not the Fund.

The Fund Manager is responsible for the AML framework and for compliance across the Funds it manages. Each Fund is a product. Its strategy, investors, liquidity, transaction flows and service-provider setup must be assessed within the Fund Manager's business-wide risk assessment.

That sounds like a small distinction. It is not.

If the policy is written as if the Fund is the responsible party, governance becomes unclear. If the policy only looks at investor onboarding, important risks in the wider business are missed. And if the policy is copied from a bank, trust office or asset manager, the procedures may not fit the way the Fund Manager actually works.

Start with the wider risk landscape

Before looking at the Fund Manager's own business, first look at the wider risk assessments and regulatory guidance.

For an EU or Dutch Fund Manager, this includes the European Commission's Supranational Risk Assessment, the Dutch National Risk Assessment, AFM guidance, relevant EBA guidance, FATF standards and the applicable AML and sanctions rules.

Why start there?

Because those sources show which sectors, countries, products, structures and transaction patterns are already seen as higher risk. They give the Fund Manager the context for its own assessment.

The sequence matters though. External risk assessments are the starting point, not the final answer. The Fund Manager still needs to explain what those risks mean for its own business.

Then assess the Fund Manager and each Fund

The business-wide risk assessment sits at Fund Manager level. It should cover the full business model and all Funds, services and relevant relationships within scope.

Within that assessment, each Fund needs a product-level assessment. Look at matters such as:

  •       the investment strategy, asset classes and countries involved;
  •       the liquidity profile and the way transfers, redemptions or early exits work;
  •       the expected investor types and ownership structures;
  •       the distribution model and the use of placement agents, nominees or intermediaries;
  •       the investor-onboarding process and who performs the KYC work;
  •       subscriptions, capital calls, distributions, redemptions and transfers;
  •       the flow of investment, financing, disposal and distribution proceeds;
  •       the banks, brokers, custodians ,depositaries, administrators and other material service providers; and
  •       third-party payments, cross-border payment routes and other features that may create complexity oropacity.
Can several Funds have the same risk profile?

Possibly.

If the investment strategy, liquidity, investor base, service providers, banks, brokers, onboarding process and transaction flows are materially the same, the Fund Manager may be able to use the same product-risk assessment.

That conclusion should be documented. A short comparison is enough if it clearly shows why the differences do not change the risk.

If one of those elements is different, assess the effect. What is different? Does it increase the inherent risk? Which controls apply? What is the residual risk?

The same legal form or the same policy document is not enough to conclude that two Funds have the same risk profile.

Do not stop at the investors

This is the part that is often missed.

The Wwft approach does not only concern investors. The Fund Manager should map all relevant business relationships and decide what the AML framework requires for each relationship.

Depending on the structure, this may include:

  •       investors and prospective investors;
  •       placement agents, distributors, introducers and nominee parties;
  •       advisers, administrators and other outsourced service providers;
  •       banks, brokers, custodians and depositaries;
  •       co-investment parties, financing parties and other contractual counterparties; and
  •      other persons or entities with whom the Fund Manager maintains a relevant ongoing relationship.

Not every relationship will be treated in exactly the same way. A service provider is not automatically a client for every Wwft purpose. But that is precisely why the Fund Manager should record the assessment instead of silently excluding the relationship.

For each relevant relationship, document why it falls inside or outside the client due-diligence approach, which risks it creates and which controls apply. Even where a party is not treated as a client, outsourcing, sanctions, payment-flow or third-party risk may still need to be managed.

Set an expected transaction profile

A risk rating alone is not enough. The Fund Manager also needs to know what normal activity is expected to look like.

For investors, the basic pattern will often be the same. They subscribe or commit capital, meet capital calls and receive distributions or divestment proceeds. For an open-ended Fund, subscriptions and redemptions may be more frequent.

In those cases, a Fund-level reference profile is a practical starting point. It may cover:

  •       the expected commitment or subscription amount;
  •       the timing and frequency of capital calls, distributions, transfers or redemptions;
  •       the bank account and countries from which money will be received and to which it may be returned;
  •       whether third-party payments or changes of bank account are permitted; and
  •       the expected holding period and use of liquidity or exit rights.

But the Fund-level profile is only the starting point.

If a participant funds through another country, uses a nominee or custodian, expects a transfer, has a different redemption pattern or has another relevant feature, record that difference in the individual profile.

The same logic applies to other business relationships that generate transactions. What payments are expected? From which account? For which service? How often? Are third-party payments possible? Not every relationship needs an identical transaction profile, but the Fund Manager should decide where a profile is needed and what normal activity looks like.

Then compare the actual activity with both the common reference profile and the relationship-specific information.

A deviation is an alert. It is not automatically a FIU report.

Investigate the reason, obtain evidence where needed and document the conclusion. If the explanation is credible, the profile can be updated. If it is not, escalate. The profile should never be changed simply to make unexplained activity appear normal.

Connect monitoring to FIU reporting

When an alert is raised, who reviews it? Who asks follow-up questions? Who decides whether the transaction is unusual? Who submits the report? And who acts as backup if that person is unavailable?

The policy should answer those questions before the first alert arrives.

A completed or intended transaction that meets an applicable objective or subjective indicator must be reported to FIU-Nederland without delay after its unusual nature becomes known. An unusual transaction is also broader than a bank transfer. It can be an act or combination of acts that becomes known through the relationship.

Also keep the terminology clear. The Fund Manager reports an unusual transaction. FIU-Nederland decides whether it becomes a suspicious transaction.

An administrator can detect an alert, perform part of the review and prepare information. That does not remove the Fund Manager's responsibility where the Fund Manager is the Wwft-obliged entity.

And do not wait until the first report is needed to register.

The Fund Manager should be registered in the FIU-Nederland reporting portal under the correct reporting group, with an authorised main user and appropriate backup. Keep the Reporting ID, users, authorisations and contact details current. A service provider's registration is not a substitute for the Fund Manager's own registration where the Fund Manager is the reporting entity.

The reporting decision should be documented, including where the conclusion is not to report. FIU reports and related information are confidential. The report, information supplied and FIU acknowledgement must be kept accessibly for five years. Also assess separately whether the matter qualifies as an incident that must be reported to the AFM.

Use clear but separate risk classifications

A simple low, elevated and unacceptable model can work well. But do not put everything into one score.

Product risk, relationship risk and transaction risk are connected, but they are not the same. A lower-risk Fund can still have a higher-risk participant or intermediary. A well-known investor does not remove a product or payment-flow risk.

Low risk. The relationship, structure and expected activity are transparent and do not create material additional AML concerns.

Higher risk. The relationship may be accepted, but additional information, approval, controls or monitoring are needed.

Unacceptable risk. The Fund Manager should not establish or continue the relationship, or should not launch the product in the proposed form, unless the issue can lawfully and demonstrably be resolved.

The purpose is not to create a beautiful matrix. The purpose is to make decisions and escalation steps clear.

So what should the AML policy cover?

In practice, I would expect at least the following areas:

  1. Governance and responsibility. State clearly that the Fund Manager owns the framework. Explain who drafts, approves, operates and reviews it. If work is outsourced, distinguish the outsourced tasks from the responsibility that stays with the Fund Manager.
  2. Business-wide and product-level risk assessment. Translate EU and national risks into the Fund Manager's own assessment. Include a product assessment for every Fund and explain when several Funds may share the same assessment.
  3. All relevant business relationships. Do not limit the policy to investors. Map the other relevant relationships, record whether and how the Wwft approach applies, and include outsourcing, sanctions and third-party risks where relevant.
  4. KYC, risk assessment and expected transaction profiles. Explain what information is required for each type of relationship, when additional information is needed and how risk is assessed as well as how common Fund-level transaction patterns are combined with relationship-specific deviations.
  5. Monitoring, FIU reporting and escalation. Cover screening, alerts, investigations, objective and subjective indicators, reporting decisions, confidentiality, FIU registration and the separate assessment of possible AFM incident reporting.
  6. Recordkeeping, training and review. Document decisions, profiles, alerts, investigations and reports. Set review triggers and make sure the relevant people can recognise unusual activity and know what to do next.

Monitor AMLA developments

The framework will continue to develop.

AMLA has consulted on draft Guidelines for the business-wide risk assessment under Article 10(4) of Regulation (EU)2024/1624. The consultation is closed, but the results and final guidance still need to be monitored.

So the AML policy is not a document to approve once and leave in a folder. Review it when a new Fund is launched, a material service provider changes, a new country or investor type is introduced, payment flows change or new guidance becomes relevant.

Conclusion

An AML policy for an investment-fund business is not a template exercise.

The Fund Manager owns the framework. Each Fund is assessed as a product. Similar Funds may share a product-risk assessment if the comparison supports that conclusion.

But the analysis does not stop with the Funds or their investors.

The Fund Manager should also map its other relevant business relationships, decide which AML measures apply and understand the expected transactions within those relationships.

That is what makes the policy practical: it connects the real structure, the real relationships and the real money flows to clear decisions, monitoring and reporting.

Primary Sources

AFM, Revised Wwft and Sanctions Act Guideline (2024), sections 5.4, 6 and 8.1

Regulation (EU) 2024/1624, including Article 10 and Annex I

AMLA, Consultation on draft Guidelines on business-wide risk assessmentFIU-Nederland, Investment institutions: reporting obligation and indicators

FIU-Nederland, Reporting obligation and registration procedure

Dutch Wwft, including Articles 16, 23 and 34

Drafting note: This article is educational and should not be treated as legal advice or formal regulatory approval.

Contact the KRIF Team

FAQ

Should every investment fund have its own AML policy?

In most cases, yes.

Even if the Fund Manager already has an internal AML framework, the policy should still be checked against the specific fund. The investor base, jurisdictions, subscription process, redemption mechanics, service providers and governance model may differ per fund.

A generic group policy can be a starting point, but it should be clear how it applies to the actual fund.

Can we use the fund administrator’s AML policy?

Not as a full replacement.

If a fund administrator performs KYC checks, its procedures are relevant and should be reviewed. But the Fund Manager should still understand what the administrator does, which checks are performed, how exceptions are escalated and which decisions remain with the Fund Manager.

If a fund administrator is involved, consider creating a periodic control plan to review the administrator’s AML work.

Do we always need to ask for source of wealth?

No.

Source of wealth should not automatically be requested from every investor. It should be linked to the investor risk profile, the fund’s AML risk assessment and the applicable legal requirements.

In higher-risk cases, source of wealth may be necessary. For low-risk investors, asking for it by default may create unnecessary friction and may also raise AVG/GDPR questions around data minimisation.

What is the difference between source of funds and source of wealth?

Source of funds looks at where the money for a specific investment comes from.

Source of wealth looks at how the investor built their overall wealth.

They are related, but not the same. For many fund investors, source of funds may be the first relevant question. Source of wealth usually becomes more relevant in elevated-risk situations, for example with PEPs, complex structures, adverse media or unclear economic background.

Can we copy a bank or trust office AML procedure?

Usually not without major adjustments.

A fund is not a bank, a trust office or automatically comparable to a discretionary asset manager. The investor relationship, transaction flow, product risk and operational model are different.

Copying another institution’s AML procedure can lead to unnecessary investor requests, overcollection of data and controls that do not fit the actual fund risk.

What risk levels should we use?

A practical model is:

Low risk.

Higher risk.

Unacceptable risk.

This is often easier to apply than a complicated five-level matrix. The important point is that the policy clearly explains what each level means, what evidence is required and who approves elevated-risk cases.

Should we start with the fund risk assessment or the EU and national risk assessments?

Start with the wider risk landscape.

Review the EU and national risk assessments first. They show how certain products, sectors, client types, jurisdictions and transaction patterns are viewed at a higher level.

After that, assess the specific fund. This makes the fund-level risk assessment more grounded and easier to defend.

How often should the AML policy be reviewed?

At least periodically, and sooner if something material changes.

Examples include a new investor type, new jurisdiction, change in fund strategy, new administrator, regulatory update, sanctions development or new AMLA guidance.

The review should be documented, even if the conclusion is that no major change is needed.

What should we monitor from AMLA?

Fund Managers should monitor AMLA’s final guidance on business-wide risk assessments, regulatory technical standards and future supervisory methodology.

As the EU AML framework becomes more harmonised, these materials may influence how national supervisors expect AML policies and risk assessments to be structured.

How does AVG/GDPR affect AML documentation?

AML compliance does not mean collecting everything “just in case”.

The AML policy should explain what personal data is collected, why it is needed, who can access it, how long it is retained and when additional information is justified.

This is especially important when requesting sensitive information such as source of wealth, adverse media documentation or detailed ownership information.