← All articles
Strategy8 minOctober 2026

Outsourced AML Compliance for Emerging Managers: What You Can Hand Off and What You Cannot

Delegation is allowed, transfer of responsibility is not. Three operating models, what to check before relying on your administrator, and the oversight file that proves it works.

RS
Rodolfo SantosReal Estate Compliance Attorney & Co-Founder, Verifica
Outsourced AML Compliance for Emerging Managers: What You Can Hand Off and What You Cannot

Short Answer

Emerging managers can outsource most of the AML work (document collection, verification, screening, alert triage, training and independent testing) to an administrator, a compliance consultant or a software platform. They cannot outsource the responsibility. Under FinCEN's Investment Adviser AML Rule, effective January 1, 2028, an adviser that delegates parts of its program remains fully responsible and legally liable for compliance. The practical answer for most first and second funds is a fractional AML officer who owns the decisions, supported by an administrator or a platform that does the volume work, with a written oversight file that proves the arrangement works.

Key Takeaways

  • Delegation is permitted. Transfer of responsibility is not.
  • Six things stay in-house: legal responsibility, the approved program, a designated officer, acceptance of high-risk investors, SAR decisions and oversight of providers.
  • The fund administrator's KYC is built for its own obligations and jurisdiction. Check that it also meets yours.
  • Oversight must be evidenced: agreement, data access, quarterly sampling, an issue log and an annual provider review.
  • Outsourcing that cannot produce a complete investor file on request is a deficiency waiting to be found.

Why do emerging managers outsource AML compliance?

A first-time fund typically has two to five partners, a CFO who may also be the chief compliance officer, and no compliance staff. It raises from a mix of institutions, family offices and individuals, often across several countries, and closes in waves. The AML workload is spiky, specialist and, until 2028, partly voluntary for U.S. advisers.

Hiring a full-time AML officer for that profile rarely makes sense. The alternative most managers reach for is the fund administrator, which already collects subscription documents and usually runs some KYC. Others hire a compliance consultancy for policies and testing. A growing number use software that runs the checks while a part-time officer makes the decisions.

All three are legitimate. The mistakes come from assuming that buying a service means the obligation has moved with it.


What does the rule say about delegating AML work?

FinCEN's final rule for investment advisers allows an adviser to delegate the implementation and operation of aspects of its AML/CFT program to a third party, such as a fund administrator. FinCEN was explicit that the adviser remains fully responsible and legally liable for the program's compliance, and must be able to demonstrate to examiners that it is effective. Examination authority for advisers sits with the SEC.

The rule also requires the adviser to designate the person or persons responsible for implementing and monitoring the program. That person needs real authority, independence from the deal team on AML questions, access to information and enough time and resources. Many smaller advisers use a part-time or outsourced professional in this role. If you do, make sure the appointment, the scope and the escalation route are written down, and that the person can actually stop an investor from being admitted.


What can you outsource, and what must stay with the adviser?

Responsibilities that stay with the adviser compared with tasks a provider can run, and the oversight evidence required

Figure 1. What stays with the adviser, what a provider can run, and the oversight evidence that links the two.

The left side of the diagram is about decisions and accountability. The right side is about work. A provider can collect and verify documents, screen names, map ownership, triage alerts, deliver training and perform the independent test. It cannot own your risk appetite, decide to accept a foreign PEP, or decide whether to file a SAR on your behalf without your designated officer's involvement.

The bar at the bottom is what most emerging managers lack. Oversight is itself a program requirement. Without evidence of it, an outsourced function looks to an examiner like no function at all.


Which operating model fits an emerging manager?

Three AML operating models: build in-house, administrator plus fractional officer, platform plus fractional officer

Figure 2. Three operating models. All three keep the adviser as legal owner of the program; they differ in who does the work and how much oversight they require.

Build in-houseAdministrator plus fractional officerPlatform plus fractional officer
Who runs the checksYour analysts and toolsAdministrator's onboarding teamSoftware, reviewed by your officer
Who decidesYour AML officerYour fractional officer, on administrator escalationsYour fractional officer
Visibility of the fileFullDepends on the agreement and portal accessFull, in your own system
Oversight burdenLow (internal)High: sampling another firm's workMedium: QA on software output
Fixed costHighestLow to mediumLow to medium
FitsLarge, multi-fund managersFirst funds with a strong administratorLean teams with many LPs or frequent closes

Many managers combine models: the administrator handles subscription processing, a platform holds the KYC record and screening, and a fractional officer reviews and decides. That is fine as long as there is one system of record for each investor and everyone knows which one it is.


What should you check before relying on your fund administrator?

Administrators do valuable work, but their KYC is designed around their own obligations. A Cayman or Luxembourg administrator applies local rules, and its file may not answer the questions your U.S. program will ask in 2028. Before relying on it, confirm:

  • Whose standard applies. Does the administrator's procedure meet your written risk methodology, including your EDD triggers and ownership thresholds?
  • Access. Can you see every investor's complete file, including screening hits and how they were cleared, without filing a request each time?
  • Escalation. Which issues come to you, how fast, and who decides?
  • Ongoing screening. Are investors and their owners rescreened when lists change, or only at onboarding?
  • SARs. How will suspected activity be handled, and how will the adviser's own filing obligation be met?
  • Exit. If you change administrator, do the KYC records come with you in a usable form?

Our comparison on relying on your fund administrator for KYC sets these questions out in more detail.


How do you choose an outsourced AML provider?

Ask every provider, whether consultancy, administrator or software vendor, the same questions:

  1. Which tasks do you perform, and which decisions remain ours? Put it in the agreement.
  2. What screening data do you use, and how often is it updated?
  3. Can we export a complete, timestamped file for any investor at any time?
  4. Who on your side does the work, and what are their qualifications?
  5. What is your own security posture? Ask for a SOC 2 Type II report or equivalent.
  6. How do you handle a true sanctions match or a suspicion of money laundering, and how fast do we hear about it?
  7. What happens to our data if we leave?

Be wary of any provider whose answer to the first question is "we take care of compliance." Under the rule, they cannot.


What should the oversight file contain?

  • The service agreement, with scope, decision rights, service levels and data access.
  • Initial due diligence on the provider and the reason you chose them.
  • Quarterly sample reviews: pick investor files at random, score them against your methodology, record findings.
  • An issue log, with each finding, the provider's response and the date it was closed.
  • An annual review of the provider, approved by the designated officer and reported to senior management.

This file is what you show an examiner. It is also what you show an institutional LP's operational due diligence team, who increasingly ask how emerging managers handle AML before they commit. For what examiners request, see surviving an SEC AML examination.


What should an emerging manager do before 2028?

  1. Now. Appoint the designated AML officer, even part-time, and write the risk methodology.
  2. Before the next close. Choose the operating model and put the provider agreements in place with the decision rights written down.
  3. Within six months. Bring every existing investor's file to the methodology's standard, starting with the highest risk.
  4. During 2027. Run two quarters of oversight sampling, then commission the independent test so findings are closed before January 1, 2028.

Where Verifica fits

Verifica supports the platform model. It runs collection, identity and document verification, ownership mapping and sanctions, PEP and adverse media screening through LSEG Risk Intelligence, and keeps each investor's file in one place that your officer controls and can export at any time. It works alongside your administrator rather than replacing it, and gives your fractional officer the queue, the evidence and the audit trail to make and record decisions. Verifica is software, not a law firm or an outsourced compliance officer: your program, your risk decisions and your sign-off stay with your team.


Frequently Asked Questions

Can an investment adviser outsource its AML program?

It can delegate the implementation and operation of parts of the program to third parties, but under FinCEN's rule it remains fully responsible and legally liable for compliance and must be able to show the program works.

Can the AML compliance officer be outsourced?

Many smaller advisers use a part-time or outsourced professional as the designated person. The adviser must give that person real authority, access and resources, and document the appointment and escalation routes.

Is the fund administrator's KYC enough for the adviser?

Not automatically. The administrator works to its own obligations and jurisdiction. Confirm that its procedures meet your methodology, that you can access every file, and that escalation and SAR responsibilities are agreed.

What does AML oversight of a provider look like?

A written agreement with decision rights, initial due diligence, quarterly sample reviews of investor files, an issue log and an annual provider review approved by the AML officer.

When do emerging managers need an AML program?

Covered SEC-registered advisers and exempt reporting advisers must comply from January 1, 2028. Sanctions obligations apply now, and many LPs and banks already expect documented AML controls.


Sources

  1. FinCEN, AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers, final rule, 89 Fed. Reg. 72156 (September 4, 2024), including the discussion of delegation to third parties, and postponement to January 1, 2028.
  2. U.S. Department of the Treasury, 2024 Investment Adviser Risk Assessment.
  3. OFAC, A Framework for OFAC Compliance Commitments (May 2019), on outsourcing and testing.
Rodolfo Santos

Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.

See a full check run
on a real file.

Identity, documents, and screening in one engine, start to report.

Request a demo