A pension fund in Luxembourg wants to invest 200 million euros in your firm's flagship fund. Clean money, respected institution, a referral from an existing client. Your sales team is thrilled. Then compliance opens the file and finds that one of the fund's ultimate beneficial owners traces back through three holding companies to an individual who appeared on a sanctions list last month. The account freezes. The deal collapses. And if you had processed that subscription without spotting the link, your firm could face a seven-figure fine and a public enforcement action.
This is the world of anti-money laundering (AML), know your customer (KYC), and sanctions compliance. It is where "routine" onboarding turns into a minefield, and where getting it wrong costs more than any single mandate is worth.
Three duties sit at the core of financial crime compliance. Every regulator, in every jurisdiction, builds on them.
AML (Anti-Money Laundering): the set of rules requiring firms to detect and prevent the movement of criminal proceeds through the financial system. Money laundering is the process of making illegally obtained money look legitimate.
KYC (Know Your Customer): the requirement to verify who your client actually is, understand their source of wealth, and assess the risk they pose before and during the relationship.
Sanctions screening: checking clients, their owners, and their transactions against government lists of prohibited persons, entities, and countries.
These are not paperwork exercises. They are the specific triggers behind most large fines in asset management.
You cannot comply with laws you cannot name. The key bodies and frameworks for 2026:
A common myth: "We do not handle cash, so AML does not really apply to us." Wrong. Asset managers accept large subscriptions, deal with layered fund structures, onboard entities from many jurisdictions, and move money on redemption. That is precisely the machinery launderers exploit. Regulators treat you as a gatekeeper.
Return to the Luxembourg pension fund. Here is what compliance actually does.
CDD (Customer Due Diligence) means identifying the client and verifying that identity with reliable documents. For an institution, that means incorporation documents, regulatory licenses, and authorized signatories. Straightforward for a well-known pension fund.
This is where most firms stumble. A beneficial owner is the natural person who ultimately owns or controls the client, typically defined as holding more than 25 percent of ownership or voting rights (the common EU threshold). You must pierce through every holding company, trust, and nominee arrangement until you reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.Voir la définition complète → a human being.
Our pension fund invests through a feeder fund, which is owned by a holding company, which has several corporate investors. Each layer must be unwound. If a 25 percent-plus owner turns out to be sanctioned, the deal is dead.
A PEP (Politically Exposed Person) is someone entrusted with a prominent public function, such as a minister, a senior judge, or a state-owned enterprise executive, plus their close family and associates. PEPs are not prohibited, but they require Enhanced Due Diligence (EDD): deeper checks on source of wealth and senior sign-off, because they carry higher corruption risk.
Every identified party, the fund, the feeder, the holding company, and every beneficial owner, is run against OFAC, EU, UK, and UN lists. Screening is not one-time. You rescreen continuously, because lists change. The individual in our scenario was added last month; a firm screening only at onboarding, and never again, would have missed it.
The client gets a risk score (low, medium, high) that dictates how often you review the file and how closely you watch transactions. A high-risk client might be reviewed annually; a low-risk one every three years.
If activity looks suspicious (an unexplained source of funds, a redemption routed to an unrelated third party, a sudden change in behavior), you file a Suspicious Activity Report (SAR), called a Suspicious Transaction Report in some jurisdictions. In the US this goes to FinCEN; in the UK, to the National Crime Agency.
Two rules matter enormously:
1. You must file promptly. Failing to report is itself an offense.
2. You must not "tip off" the client. Telling the client they are under a SAR is a criminal offense in most jurisdictions.
Enforcement is real and large. A few well-established patterns:
Vérification des acquis
1. In the opening scenario, a respected Luxembourg pension fund's subscription is frozen despite being 'clean money' from a reputable institution. What core principle does this illustrate?
2. What is the fundamental distinction between AML and KYC obligations?
3. Why does the lesson describe onboarding as potentially 'a minefield' rather than a paperwork exercise?
4. Select ALL correct answers about the role of FATF in financial crime compliance.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers describing what sanctions screening involves.
Sélectionnez toutes les réponses correctes.
Regulators do not expect you to catch every criminal. They expect a risk-based approach: allocate more scrutiny where risk is higher, and document your reasoning. A defensible program has:
The old model reviewed clients on fixed calendars. The direction of travel in 2026 is perpetual KYC (pKYC): continuous, event-driven monitoring where a change in ownership, a news event, or a new sanctions listing automatically triggers a review. It is more effective and increasingly expected by supervisors.