01
What AML is for
Money laundering is the process of making the proceeds of crime look legitimate. The classic model has three stages: placement (getting cash or illicit value into the financial system), layering (moving it through transactions and structures to obscure its origin) and integration (bringing it back as apparently clean assets). Terrorist financing works the other way round — the funds may be perfectly legal, but their destination is not. AML/CFT rules exist to make both harder to do and easier to detect.
Investment funds matter because they take in capital from investors in many jurisdictions, often through intermediaries, and move it across borders through long chains of service providers. That makes them useful for layering and integration — and it is why fund managers, administrators and depositaries are obliged entities in their own right, not bystanders.
02
The framework
Global standard. The FATF's 40 Recommendations set the international standard. Countries are evaluated against them, and the FATF's grey and black lists reflect the result — which is why "high-risk third country" lists end up in your onboarding procedure.
European Union. For years the rules came through successive AML Directives, transposed into national law — with the divergences that implies. The 2024 AML package changes the logic: the AML Regulation (AMLR, Regulation (EU) 2024/1624) is a single rulebook that applies directly in every member state from 10 July 2027; AMLD6 (Directive (EU) 2024/1640) covers supervision, financial intelligence units and registers; and AMLA (Regulation (EU) 2024/1620) is the new EU authority, based in Frankfurt, operational since 2025 and due to supervise selected cross-border entities directly from 2028.
National layer. Supervisors apply and enforce the rules (in Luxembourg, the CSSF for the financial sector) and financial intelligence units receive the reports (in Luxembourg, the CRF). Sanctions sit alongside AML with their own legal basis — UN, EU and national measures — and their own logic, covered in chapter 05.
03
Customer due diligence
Customer due diligence (CDD) has four parts, and all four are needed: identify the customer and verify its identity from reliable, independent sources; identify the beneficial owners and take reasonable measures to verify them; understand the purpose and intended nature of the relationship — including, where the risk calls for it, the source of funds and of wealth; and monitor the relationship on an ongoing basis, keeping the information up to date.
The intensity scales with risk. Simplified due diligence fits lower-risk situations — a regulated financial institution in an equivalent jurisdiction, a company listed on a market with disclosure requirements. Enhanced due diligence is mandatory where risk is higher: politically exposed persons, high-risk third countries, complex or unusually large transactions, and patterns with no apparent economic purpose.
A fund may rely on a regulated third party — a distributor, a transfer agent — for parts of CDD. The responsibility does not move with the task: it stays with the obliged entity, and the underlying documents must be obtainable on request, without delay.
04
Beneficial ownership
The beneficial owner is the natural person who ultimately owns or controls the customer. For a company, that means direct or indirect ownership of 25% or more of the shares, voting rights or ownership interest (the AMLR threshold; the directives said "more than 25%"), or control through other means — the right to appoint most of the board, veto rights, a shareholders' agreement. Only when nobody meets either test, after all means have been exhausted, are the senior managing officials recorded instead — with the reason documented.
Trusts and similar arrangements have their own list: settlor, trustee, protector, beneficiaries, and anyone else exercising ultimate control. EU member states keep central registers (in Luxembourg, the RBO); checking the register is required, but it is not a substitute for the obliged entity's own analysis.
For funds, the practical questions are the look-through to investors above the threshold, and what sits behind nominee and omnibus accounts.
05
Sanctions, PEPs and screening
Sanctions are not risk-based. A confirmed match with a designated person or entity must be acted on whatever the risk appetite: assets frozen, no funds or economic resources made available, and the competent authority notified. Which lists apply depends on your nexus — UN and EU lists always, and others (OFAC, OFSI) where there is a US or UK connection. Screening happens at onboarding, at every list update, and on transactions.
Politically exposed persons are individuals entrusted with prominent public functions — heads of state and government, ministers, members of parliament, senior judges, central bank boards, ambassadors, senior officers of the armed forces, board members of state-owned enterprises, heads of international organisations — together with their family members and known close associates. Being a PEP is not an accusation; it is a trigger. It calls for senior management approval, source of wealth and source of funds, enhanced ongoing monitoring, and continued measures for at least twelve months after the person leaves office.
Adverse media and published typologies complete the picture: they are how you learn what the next case looks like before it is yours.
06
Monitoring, reporting and the risk-based approach
Ongoing monitoring means checking that what the customer does is consistent with what you know about it, its business and its risk profile. Typical red flags in a fund: subscriptions paid by a third party, early redemptions with no economic rationale, requests to redeem to a different account or jurisdiction, investors from high-risk countries behind opaque structures, unexplained changes in beneficial ownership.
Reporting. Suspicion — not proof — triggers a report to the financial intelligence unit (an STR or SAR). Telling the customer, or anyone else, that a report has been or may be filed is prohibited: that is tipping-off. Records are kept, typically for five years after the end of the relationship or the transaction.
The risk-based approach ties everything together: a business-wide risk assessment (customers, countries, products, delivery channels, transactions), policies and procedures that follow from it, a designated AML officer with real authority, training, and independent testing. In Luxembourg, the responsable du respect des obligations (RR) and the responsable du contrôle du respect des obligations (RC) carry that responsibility by name.