Many Fund Managers still treat the AML policy as a standard one-size-fits-all document in the fund setup file.
Not because AML is ignored. Usually, the opposite is true. KYC documents are collected, investors are screened and the subscription process includes AML checks.
But this keeps coming up in practice: who does the policy actually belong to? The answer is the Fund Manager, not the Fund.
The Fund Manager is responsible for the AML framework and for compliance across the Funds it manages. Each Fund is a product. Its strategy, investors, liquidity, transaction flows and service-provider setup must be assessed within the Fund Manager's business-wide risk assessment.
That sounds like a small distinction. It is not.
If the policy is written as if the Fund is the responsible party, governance becomes unclear. If the policy only looks at investor onboarding, important risks in the wider business are missed. And if the policy is copied from a bank, trust office or asset manager, the procedures may not fit the way the Fund Manager actually works.
Before looking at the Fund Manager's own business, first look at the wider risk assessments and regulatory guidance.
For an EU or Dutch Fund Manager, this includes the European Commission's Supranational Risk Assessment, the Dutch National Risk Assessment, AFM guidance, relevant EBA guidance, FATF standards and the applicable AML and sanctions rules.
Why start there?
Because those sources show which sectors, countries, products, structures and transaction patterns are already seen as higher risk. They give the Fund Manager the context for its own assessment.
The sequence matters though. External risk assessments are the starting point, not the final answer. The Fund Manager still needs to explain what those risks mean for its own business.
The business-wide risk assessment sits at Fund Manager level. It should cover the full business model and all Funds, services and relevant relationships within scope.
Within that assessment, each Fund needs a product-level assessment. Look at matters such as:
Possibly.
If the investment strategy, liquidity, investor base, service providers, banks, brokers, onboarding process and transaction flows are materially the same, the Fund Manager may be able to use the same product-risk assessment.
That conclusion should be documented. A short comparison is enough if it clearly shows why the differences do not change the risk.
If one of those elements is different, assess the effect. What is different? Does it increase the inherent risk? Which controls apply? What is the residual risk?
The same legal form or the same policy document is not enough to conclude that two Funds have the same risk profile.
This is the part that is often missed.
The Wwft approach does not only concern investors. The Fund Manager should map all relevant business relationships and decide what the AML framework requires for each relationship.
Depending on the structure, this may include:
Not every relationship will be treated in exactly the same way. A service provider is not automatically a client for every Wwft purpose. But that is precisely why the Fund Manager should record the assessment instead of silently excluding the relationship.
For each relevant relationship, document why it falls inside or outside the client due-diligence approach, which risks it creates and which controls apply. Even where a party is not treated as a client, outsourcing, sanctions, payment-flow or third-party risk may still need to be managed.
A risk rating alone is not enough. The Fund Manager also needs to know what normal activity is expected to look like.
For investors, the basic pattern will often be the same. They subscribe or commit capital, meet capital calls and receive distributions or divestment proceeds. For an open-ended Fund, subscriptions and redemptions may be more frequent.
In those cases, a Fund-level reference profile is a practical starting point. It may cover:
But the Fund-level profile is only the starting point.
If a participant funds through another country, uses a nominee or custodian, expects a transfer, has a different redemption pattern or has another relevant feature, record that difference in the individual profile.
The same logic applies to other business relationships that generate transactions. What payments are expected? From which account? For which service? How often? Are third-party payments possible? Not every relationship needs an identical transaction profile, but the Fund Manager should decide where a profile is needed and what normal activity looks like.
Then compare the actual activity with both the common reference profile and the relationship-specific information.
A deviation is an alert. It is not automatically a FIU report.
Investigate the reason, obtain evidence where needed and document the conclusion. If the explanation is credible, the profile can be updated. If it is not, escalate. The profile should never be changed simply to make unexplained activity appear normal.
When an alert is raised, who reviews it? Who asks follow-up questions? Who decides whether the transaction is unusual? Who submits the report? And who acts as backup if that person is unavailable?
The policy should answer those questions before the first alert arrives.
A completed or intended transaction that meets an applicable objective or subjective indicator must be reported to FIU-Nederland without delay after its unusual nature becomes known. An unusual transaction is also broader than a bank transfer. It can be an act or combination of acts that becomes known through the relationship.
Also keep the terminology clear. The Fund Manager reports an unusual transaction. FIU-Nederland decides whether it becomes a suspicious transaction.
An administrator can detect an alert, perform part of the review and prepare information. That does not remove the Fund Manager's responsibility where the Fund Manager is the Wwft-obliged entity.
And do not wait until the first report is needed to register.
The Fund Manager should be registered in the FIU-Nederland reporting portal under the correct reporting group, with an authorised main user and appropriate backup. Keep the Reporting ID, users, authorisations and contact details current. A service provider's registration is not a substitute for the Fund Manager's own registration where the Fund Manager is the reporting entity.
The reporting decision should be documented, including where the conclusion is not to report. FIU reports and related information are confidential. The report, information supplied and FIU acknowledgement must be kept accessibly for five years. Also assess separately whether the matter qualifies as an incident that must be reported to the AFM.
A simple low, elevated and unacceptable model can work well. But do not put everything into one score.
Product risk, relationship risk and transaction risk are connected, but they are not the same. A lower-risk Fund can still have a higher-risk participant or intermediary. A well-known investor does not remove a product or payment-flow risk.
Low risk. The relationship, structure and expected activity are transparent and do not create material additional AML concerns.
Higher risk. The relationship may be accepted, but additional information, approval, controls or monitoring are needed.
Unacceptable risk. The Fund Manager should not establish or continue the relationship, or should not launch the product in the proposed form, unless the issue can lawfully and demonstrably be resolved.
The purpose is not to create a beautiful matrix. The purpose is to make decisions and escalation steps clear.
In practice, I would expect at least the following areas:
The framework will continue to develop.
AMLA has consulted on draft Guidelines for the business-wide risk assessment under Article 10(4) of Regulation (EU)2024/1624. The consultation is closed, but the results and final guidance still need to be monitored.
So the AML policy is not a document to approve once and leave in a folder. Review it when a new Fund is launched, a material service provider changes, a new country or investor type is introduced, payment flows change or new guidance becomes relevant.
An AML policy for an investment-fund business is not a template exercise.
The Fund Manager owns the framework. Each Fund is assessed as a product. Similar Funds may share a product-risk assessment if the comparison supports that conclusion.
But the analysis does not stop with the Funds or their investors.
The Fund Manager should also map its other relevant business relationships, decide which AML measures apply and understand the expected transactions within those relationships.
That is what makes the policy practical: it connects the real structure, the real relationships and the real money flows to clear decisions, monitoring and reporting.
AFM, Revised Wwft and Sanctions Act Guideline (2024), sections 5.4, 6 and 8.1
Regulation (EU) 2024/1624, including Article 10 and Annex I
AMLA, Consultation on draft Guidelines on business-wide risk assessmentFIU-Nederland, Investment institutions: reporting obligation and indicators
FIU-Nederland, Reporting obligation and registration procedure
Dutch Wwft, including Articles 16, 23 and 34
Drafting note: This article is educational and should not be treated as legal advice or formal regulatory approval.
In most cases, yes.
Even if the Fund Manager already has an internal AML framework, the policy should still be checked against the specific fund. The investor base, jurisdictions, subscription process, redemption mechanics, service providers and governance model may differ per fund.
A generic group policy can be a starting point, but it should be clear how it applies to the actual fund.
Not as a full replacement.
If a fund administrator performs KYC checks, its procedures are relevant and should be reviewed. But the Fund Manager should still understand what the administrator does, which checks are performed, how exceptions are escalated and which decisions remain with the Fund Manager.
If a fund administrator is involved, consider creating a periodic control plan to review the administrator’s AML work.
No.
Source of wealth should not automatically be requested from every investor. It should be linked to the investor risk profile, the fund’s AML risk assessment and the applicable legal requirements.
In higher-risk cases, source of wealth may be necessary. For low-risk investors, asking for it by default may create unnecessary friction and may also raise AVG/GDPR questions around data minimisation.
Source of funds looks at where the money for a specific investment comes from.
Source of wealth looks at how the investor built their overall wealth.
They are related, but not the same. For many fund investors, source of funds may be the first relevant question. Source of wealth usually becomes more relevant in elevated-risk situations, for example with PEPs, complex structures, adverse media or unclear economic background.
Usually not without major adjustments.
A fund is not a bank, a trust office or automatically comparable to a discretionary asset manager. The investor relationship, transaction flow, product risk and operational model are different.
Copying another institution’s AML procedure can lead to unnecessary investor requests, overcollection of data and controls that do not fit the actual fund risk.
A practical model is:
Low risk.
Higher risk.
Unacceptable risk.
This is often easier to apply than a complicated five-level matrix. The important point is that the policy clearly explains what each level means, what evidence is required and who approves elevated-risk cases.
Start with the wider risk landscape.
Review the EU and national risk assessments first. They show how certain products, sectors, client types, jurisdictions and transaction patterns are viewed at a higher level.
After that, assess the specific fund. This makes the fund-level risk assessment more grounded and easier to defend.
At least periodically, and sooner if something material changes.
Examples include a new investor type, new jurisdiction, change in fund strategy, new administrator, regulatory update, sanctions development or new AMLA guidance.
The review should be documented, even if the conclusion is that no major change is needed.
Fund Managers should monitor AMLA’s final guidance on business-wide risk assessments, regulatory technical standards and future supervisory methodology.
As the EU AML framework becomes more harmonised, these materials may influence how national supervisors expect AML policies and risk assessments to be structured.
AML compliance does not mean collecting everything “just in case”.
The AML policy should explain what personal data is collected, why it is needed, who can access it, how long it is retained and when additional information is justified.
This is especially important when requesting sensitive information such as source of wealth, adverse media documentation or detailed ownership information.