Transaction Monitoring for Investment Advisers: What Changes on January 1, 2028
The 2028 rule never says "transaction monitoring," but the SAR duty requires it. What fund advisers should monitor, who holds the data, and a build plan for 2027.

Short Answer
From January 1, 2028, covered investment advisers must monitor for and report suspicious activity. The rule does not prescribe a transaction monitoring system, but an adviser cannot file SARs on activity it never looks at. For a private fund adviser, monitoring means reviewing every capital movement it can see (subscriptions, capital calls, distributions, redemptions and transfers of interests) against what it knows about the investor, with written rules for what counts as unusual and a recorded decision on every alert.
Key Takeaways
- Ongoing monitoring is part of the customer due diligence element of the 2028 program, and it feeds the SAR obligation.
- Fund monitoring is low volume and high value. Review every capital event against the investor profile rather than buying a bank-style statistical engine.
- The adviser rarely holds the money. Administrators and custodians see the wires, so data access is the first design problem.
- Write the red flags into rules, and document a disposition for every alert, including the ones you close.
- Use 2027 to run monitoring in parallel and test it, so January 2028 is a switch-over, not a launch.
Does the Investment Adviser AML Rule require transaction monitoring?
Not in those words. FinCEN's final rule requires covered registered investment advisers and exempt reporting advisers to maintain a risk-based AML/CFT program that includes appropriate risk-based procedures for ongoing customer due diligence. That element has two parts: understanding the nature and purpose of customer relationships to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious transactions. The rule also requires SAR filing for transactions of $5,000 or more that the adviser knows, suspects or has reason to suspect are suspicious.
Put those together and the requirement is clear even though the phrase "transaction monitoring" never appears. If an examiner asks how you identify reportable activity and the answer is "we would notice," the program is not reasonably designed.
For the wider program, see why RIAs should build for the 2028 rule now and the five pillars of a BSA/AML program.
How is transaction monitoring different for a fund adviser than for a bank?
A retail bank processes millions of card payments, cash deposits and transfers. It needs statistical models and scenario engines because no person could review that volume. A private fund with 150 LPs might see four capital calls and two distributions a year per investor, plus a handful of transfers. That is a few thousand events annually, each one large.
The economics invert. A bank tunes thresholds to keep alert volumes manageable. A fund adviser can afford to look at every capital movement, and should. The risk is not missing one suspicious payment in a million; it is failing to notice that a $2 million call was paid by a company in a third country the investor never mentioned.
Three features of fund structures shape the design:
- Money moves at predictable moments. Capital calls and distributions follow the fund's own schedule, so unexpected activity stands out.
- The adviser usually does not hold the cash. The fund's bank account sits with a custodian, and the administrator processes the wires.
- Relationships are long. A ten-year fund life means the investor at year eight may have different owners, banks and circumstances than at onboarding.
Where does an adviser actually see money move?
Figure 1. The three investor-facing flows an adviser can monitor (subscriptions and capital calls, distributions and redemptions, and secondary transfers) and four red flags to write into rules.
Monitoring for AML purposes focuses on the investor side. Portfolio investments raise their own sanctions and diligence questions, but the money laundering risk the rule targets is illicit money entering or leaving through the fund.
Which red flags should a fund adviser monitor for?
Treasury's 2024 Investment Adviser Risk Assessment found that advisers serve as an entry point into the U.S. market for proceeds of foreign corruption, fraud and tax evasion, and that sanctioned parties and foreign states have used private funds, particularly venture funds, to access technology and services. Translate those findings into concrete scenarios:
| Scenario | Why it matters | What to check |
|---|---|---|
| Payment from an account not in the investor's name | Breaks the link between investor and money; classic layering | Who holds the account, relationship to investor, written reason |
| Capital call paid in several pieces or from several accounts | Can hide the true source | Each paying account against the source of funds on file |
| Payment routed through a high-risk or new jurisdiction | Sanctions and corruption exposure | Banking chain, investor's stated footprint, sanctions screening of banks |
| Early redemption or transfer accepted at a heavy discount | Willingness to lose money can signal a need to clean it | Reason given, buyer identity, timing against any news |
| Distribution requested to a new or third-party account | Common in fraud and in exits by sanctioned parties | Account holder verification, call-back to known contact |
| Secondary transfer to an unknown buyer | New investor entering without onboarding | Full KYC on the transferee before consent |
| Change of ownership in an LP entity | A sanctioned or high-risk party may now control the investor | Updated ownership chart, rescreening, risk re-rating |
| Investor activity inconsistent with stated profile | Wealth may not support the commitment | Source of wealth evidence, EDD if not already done |
The last two scenarios are not payments at all. For a fund, the most important monitoring often happens on investor data rather than wires. That is why ongoing screening and event-driven refresh, covered in our perpetual KYC guide, belong in the same design.
Who has the data, and how do you get it?
Start by mapping every party that touches investor money: the fund administrator, the custodian or fund bank, any placement agent and any feeder fund. For each, record what data they hold (remitting account name and number, originating bank, amount, date) and how the adviser gets it.
The rule lets an adviser delegate parts of its program, including to an administrator, but the adviser remains fully responsible. In practice that means one of two models:
- The administrator monitors and escalates. You agree the scenarios, the administrator applies them and escalates hits, and you receive a periodic report and sample the work. Your agreement must say who decides on a SAR.
- The administrator sends data; the adviser monitors. You receive remittance details for every capital event and review them against the KYC file yourself.
Either works. What fails is the common current state, where the administrator applies its own standard, the adviser never sees the output, and nobody has agreed who files. Our comparison of relying on your fund administrator sets out the questions to settle.
What should happen when an alert fires?
Figure 2. The lifecycle of an alert. Triage and investigation can be prepared by software; the decision is a person's. If a SAR is filed, it is due 30 days after initial detection of facts that may constitute a basis for filing.
- Alert. Generated by a rule, a screening list change or a staff referral. Staff referrals matter: investor relations teams often notice odd requests first.
- Triage. A first-line review closes obvious false positives with a written reason or opens a case.
- Investigate. Pull the KYC file, the payment history and open-source information. Ask the investor where appropriate, without tipping them off about a potential SAR.
- Decide. No further action, enhanced monitoring, a SAR, or exiting the relationship. Exits are complicated in closed-end funds; plan for them in your fund documents.
- Record. Rationale, evidence, dates and the reviewer's name.
FinCEN's October 2025 SAR FAQs confirmed that institutions are not required to document decisions not to file. Most examiners will still ask how a closed alert was resolved. A one-line reason costs little and answers the question. For the filing itself, see the SAR filing guide for RIAs.
What should an adviser build between now and 2028?
| Period | Work | Exit criterion |
|---|---|---|
| Q4 2026 | Map data flows and parties; agree data access with the administrator and custodian | For every capital event, you can see payer name, account and bank |
| Q1 to Q2 2027 | Write scenarios and thresholds from the red flags above; define alert handling and roles | Approved monitoring procedure, versioned |
| Q3 2027 | Run monitoring in parallel on live events; tune with documented changes | Every alert dispositioned with a reason; QA sample passed |
| Q4 2027 | Independent test of the monitoring procedure; train staff; board approval of the program | Findings closed before January 1, 2028 |
Where Verifica fits
Monitoring decisions are only as good as the investor file they are measured against. Verifica maintains that file: verified identity, ownership to natural persons, source of funds evidence, and ongoing sanctions, PEP and adverse media screening through LSEG Risk Intelligence, with any change in an investor's screening status raised for review. When a capital call arrives from an unexpected account, your reviewer can see in one place who the investor is, who owns it and what account it said it would pay from. Verifica is software, not a law firm, and your monitoring rules and decisions stay with your team.
Frequently Asked Questions
Do investment advisers need a transaction monitoring system?
They need a reasonably designed way to identify suspicious activity, because the 2028 rule requires ongoing monitoring and SAR filing. For most private fund advisers that is a documented review of every capital event against the investor profile, not a bank-style statistical engine.
When does the transaction monitoring obligation start?
With the rest of the Investment Adviser AML Rule, on January 1, 2028. Sanctions obligations already apply.
Can the fund administrator do transaction monitoring for the adviser?
Yes, the work can be delegated, but the adviser remains responsible. Agree the scenarios, the escalation route and who decides on SARs in writing, and sample the administrator's work.
What is the SAR threshold for investment advisers?
$5,000. Advisers must report transactions conducted or attempted by, at or through the adviser involving at least $5,000 in funds or other assets where the adviser knows, suspects or has reason to suspect the activity is suspicious.
What are common red flags in private fund transactions?
Payments from accounts not in the investor's name, calls split across several payers, routing through high-risk jurisdictions, early exits at a heavy discount, distributions to new accounts, and transfers to buyers who have not been onboarded.
Sources
- FinCEN, AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers, final rule, 89 Fed. Reg. 72156 (September 4, 2024), and postponement to January 1, 2028.
- U.S. Department of the Treasury, 2024 Investment Adviser Risk Assessment (February 2024).
- FinCEN and federal banking agencies, Frequently Asked Questions Regarding Suspicious Activity Reporting Requirements (October 9, 2025).
- OFAC, A Framework for OFAC Compliance Commitments (May 2019).
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of Verifica, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.



