Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/Asset & Wealth Management: how the sector works/Regulation, major laws and compliance/AML, KYC and the sanctions regime you can't ignore
4/5+150 XP

Regulation, major laws and compliance

10The regulatory map: who actually governs an asset manager+15011The investment company and advisers acts in practice+15012MiFID II and UCITS: how Europe reshaped the business+15013AML, KYC and the sanctions regime you can't ignore+15014Building the compliance function that keeps you licensed+150

AML, KYC and the sanctions regime you can't ignore

The account that looked routine

A pension fund in Luxembourg wants to invest 200 million euros in your firm's flagship fund. Clean money, respected institution, a referral from an existing client. Your sales team is thrilled. Then compliance opens the file and finds that one of the fund's ultimate beneficial owners traces back through three holding companies to an individual who appeared on a sanctions list last month. The account freezes. The deal collapses. And if you had processed that subscription without spotting the link, your firm could face a seven-figure fine and a public enforcement action.

This is the world of anti-money laundering (AML), know your customer (KYC), and sanctions compliance. It is where "routine" onboarding turns into a minefield, and where getting it wrong costs more than any single mandate is worth.

The three obligations that anchor everything

Three duties sit at the core of financial crime compliance. Every regulator, in every jurisdiction, builds on them.

AML (Anti-Money Laundering): the set of rules requiring firms to detect and prevent the movement of criminal proceeds through the financial system. Money laundering is the process of making illegally obtained money look legitimate.

KYC (Know Your Customer): the requirement to verify who your client actually is, understand their source of wealth, and assess the risk they pose before and during the relationship.

Sanctions screening: checking clients, their owners, and their transactions against government lists of prohibited persons, entities, and countries.

These are not paperwork exercises. They are the specific triggers behind most large fines in asset management.

Who makes the rules

You cannot comply with laws you cannot name. The key bodies and frameworks for 2026:

  • FATF (Financial Action Task Force): the global standard-setter. It issues 40 Recommendations that most countries translate into national law. FATF also publishes a "grey list" and "black list" of high-risk jurisdictions. Read the standards directly at the FATF website.
  • United States: the Bank Secrecy Act (BSA) is the foundational AML statute, enforced by FinCEN (Financial Crimes Enforcement Network). Sanctions are administered by OFAC (Office of Foreign Assets Control), part of the Treasury.
  • European Union: historically a series of AML Directives (the sixth, 6AMLD, being the most recent). Crucially, the EU is now standing up a single supervisor, AMLA (the Anti-Money Laundering Authority), based in Frankfurt, which is expected to begin direct supervision of high-risk firms from 2028 under a new AML Regulation that harmonizes rules across member states.
  • United Kingdom: the Money Laundering Regulations, with the FCA (Financial Conduct Authority) as supervisor and OFSI (Office of Financial Sanctions Implementation) handling sanctions.

Why asset managers are squarely in scope

A common myth: "We do not handle cash, so AML does not really apply to us." Wrong. Asset managers accept large subscriptions, deal with layered fund structures, onboard entities from many jurisdictions, and move money on redemption. That is precisely the machinery launderers exploit. Regulators treat you as a gatekeeper.

Onboarding the institutional client, step by step

Return to the Luxembourg pension fund. Here is what compliance actually does.

Step 1: customer due diligence (CDD)

CDD (Customer Due Diligence) means identifying the client and verifying that identity with reliable documents. For an institution, that means incorporation documents, regulatory licenses, and authorized signatories. Straightforward for a well-known pension fund.

Step 2: Beneficial ownership

This is where most firms stumble. A beneficial owner is the natural person who ultimately owns or controls the client, typically defined as holding more than 25 percent of ownership or voting rights (the common EU threshold). You must pierce through every holding company, trust, and nominee arrangement until you reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.View full definition → a human being.

Our pension fund invests through a feeder fund, which is owned by a holding company, which has several corporate investors. Each layer must be unwound. If a 25 percent-plus owner turns out to be sanctioned, the deal is dead.

Step 3: PEP screening

A PEP (Politically Exposed Person) is someone entrusted with a prominent public function, such as a minister, a senior judge, or a state-owned enterprise executive, plus their close family and associates. PEPs are not prohibited, but they require Enhanced Due Diligence (EDD): deeper checks on source of wealth and senior sign-off, because they carry higher corruption risk.

Step 4: Sanctions screening

Every identified party, the fund, the feeder, the holding company, and every beneficial owner, is run against OFAC, EU, UK, and UN lists. Screening is not one-time. You rescreen continuously, because lists change. The individual in our scenario was added last month; a firm screening only at onboarding, and never again, would have missed it.

Step 5: Risk rating and ongoing monitoring

The client gets a risk score (low, medium, high) that dictates how often you review the file and how closely you watch transactions. A high-risk client might be reviewed annually; a low-risk one every three years.

When something looks wrong: the SAR

If activity looks suspicious (an unexplained source of funds, a redemption routed to an unrelated third party, a sudden change in behavior), you file a Suspicious Activity Report (SAR), called a Suspicious Transaction Report in some jurisdictions. In the US this goes to FinCEN; in the UK, to the National Crime Agency.

Two rules matter enormously:

1. You must file promptly. Failing to report is itself an offense.

2. You must not "tip off" the client. Telling the client they are under a SAR is a criminal offense in most jurisdictions.

What actually triggers fines and frozen assets

Enforcement is real and large. A few well-established patterns:

  • Sanctions violations are strict liability under OFAC. You do not need intent. Processing a transaction for a sanctioned party, even by accident, can trigger penalties. This is why screening rigor matters so much.
  • Systemic KYC and AML failures draw the biggest fines. Regulators have levied penalties in the hundreds of millions, and in some banking cases billions of dollars, for weak controls, poor monitoring, and ignored red flags. The pattern is consistent: the failure to have working systems is punished as harshly as the underlying crime.
  • Frozen assets: if funds are linked to a sanctioned party, you must freeze them and report, not return them. Getting this wrong in either direction creates liability.

Knowledge check

1. In the opening scenario, a respected Luxembourg pension fund's subscription is frozen despite being 'clean money' from a reputable institution. What core principle does this illustrate?

2. What is the fundamental distinction between AML and KYC obligations?

3. Why does the lesson describe onboarding as potentially 'a minefield' rather than a paperwork exercise?

MULTIPLE CHOICE

4. Select ALL correct answers about the role of FATF in financial crime compliance.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL correct answers describing what sanctions screening involves.

Select all the correct answers.

Building a defensible program

Regulators do not expect you to catch every criminal. They expect a risk-based approach: allocate more scrutiny where risk is higher, and document your reasoning. A defensible program has:

  • A named accountable person. In the UK this is the MLRO (Money Laundering Reporting Officer). US and EU firms designate a compliance officer with clear authority.
  • Written policies mapped to real laws, not generic templates.
  • Screening tools that are calibrated. Set thresholds too loose and you miss hits; too tight and you drown analysts in false positives. Tuning the fuzzy-matching logic (so "Mohammed" also flags "Muhammad") is a genuine operational discipline.
  • Training and audit trails. If it is not documented, to a regulator it did not happen.

The perpetual-KYC shift

The old model reviewed clients on fixed calendars. The direction of travel in 2026 is perpetual KYC (pKYC): continuous, event-driven monitoring where a change in ownership, a news event, or a new sanctions listing automatically triggers a review. It is more effective and increasingly expected by supervisors.

Key Takeaways

  • AML, KYC, and sanctions screening are the three pillars, and asset managers are treated as gatekeepers despite not handling cash. Subscriptions and redemptions are the exposure.
  • Beneficial ownership is where deals die. You must unwind every layer to reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.View full definition → a real person and screen each one; the common threshold is more than 25 percent ownership or control.
  • Sanctions violations are often strict liability. Intent is irrelevant under OFAC, so continuous rescreening (not one-time checks) is non-negotiable.
  • The biggest fines punish weak systems, not just crimes. A documented, risk-based program with a named accountable officer and calibrated screening is your defense.
  • File SARs promptly and never tip off the client. Both the failure to report and the disclosure of a report are criminal offenses.

Previous

MiFID II and UCITS: how Europe reshaped the business

Next

Building the compliance function that keeps you licensed