20 July 2026
AFM [NLD] ¦ Why Fund Managers must Treat Compliance as a Frontline Defence Against Financial Crime
Establishment of effective compliance and internal audit functions
The Dutch Authority for the Financial Markets (AFM) has identified important weaknesses in the way UCITS and alternative investment fund managers (AIFMs) organise compliance and internal audit. Although most managers meet the formal legal requirements, the quality and effectiveness of their control functions vary considerably.
The findings have direct significance for anti-money laundering (AML) and counter-terrorist financing (CTF) controls. They also highlight a broader point: effective financial crime compliance depends not only on written policies, but on clear accountability, independent challenge, timely escalation and documented follow-up.
Money laundering controls must be tailored to the business
Fund managers are exposed to a range of financial crime risks. These may arise through investors, intermediaries, distributors, service providers, portfolio companies, transactions and cross-border structures. The underlying predicate offenses may include fraud, corruption, tax crimes, sanctions evasion, market abuse, theft and other forms of serious criminal conduct.
A generic compliance manual cannot adequately address these risks. The relevant controls should reflect the manager’s investment strategy, investor base, distribution model, jurisdictions, use of intermediaries, outsourcing arrangements and transaction profile. A manager investing in private assets through complex holding structures may face different risks from a manager offering liquid funds to retail investors through multiple distributors.
The supervisory findings indicate that some compliance frameworks remain too general or are no longer up to date. A list of applicable legislation is not a substitute for an organisation-specific assessment of risk. Policies and procedures should explain how risks are identified, which controls address them, who performs those controls and how weaknesses are escalated.
This is particularly important for suspicious transaction monitoring and customer due diligence (CDD). A control framework should make clear how the manager identifies beneficial owners, assesses investor risk, detects unusual activity, handles higher-risk relationships and determines when information must be escalated for further investigation or reporting. It should also address how information from distributors, administrators and other outsourced providers is obtained and challenged.
The compliance cycle must connect risk, monitoring and remediation
A strong compliance function operates through a connected cycle. The risk assessment informs the compliance agenda. The agenda informs the monitoring plan. Monitoring produces findings. Findings are reported to management, assigned to responsible owners and followed through to completion. Lessons from incidents and overdue actions should then influence future monitoring.
Supervisory observations indicate that these elements are not always aligned. Compliance agendas may not correspond with planned monitoring, while reports may fail to identify whether the activities in the monitoring plan were completed. Findings may be reported without being incorporated into later planning.
This creates a serious risk in the financial crime context. A weakness in customer due diligence, sanctions screening or transaction monitoring may be identified, but unless it is assigned, tracked and tested again, the underlying exposure can remain unresolved. The existence of a finding does not demonstrate effective control. The organisation must be able to show what caused the weakness, what corrective action was taken, who owns it, when it was due and whether the action actually reduced the risk.
Root cause analysis is particularly valuable. Repeated failures may indicate inadequate systems, unclear procedures, insufficient training, weak data quality or excessive reliance on third parties. Treating each failure as an isolated incident can prevent management from identifying a broader control problem.
Outsourcing does not transfer responsibility
Outsourcing can provide access to specialist expertise, but it does not transfer regulatory responsibility.
A service provider’s standard template may be a useful starting point, but it must be adapted to the manager’s specific activities and risks. The manager should understand what the provider does, what information it uses, how exceptions are handled and how quickly issues are escalated. It should also have enough internal expertise to challenge the provider’s conclusions.
Limited contractual hours or minimal physical presence may restrict the ability of an outsourced activity to identify emerging risks. This is particularly relevant where the provider depends heavily on information supplied by operational teams, administrators or distributors. If information is incomplete or delayed, the compliance function may be unable to detect suspicious behaviour or assess whether a potential predicate offense is linked to a relationship or transaction.
The manager must retain the ability to set priorities, increase resources and respond to incidents. A service provider should not determine the scope of compliance solely through a fixed annual arrangement that cannot adapt to changes in the risk profile.
The first and second lines must not be confused
The compliance function belongs primarily to the second line of defence. Its role is to advise, monitor, test and challenge the first line, rather than routinely performing the operational controls it is expected to oversee.
The supervisory findings identify situations in which compliance personnel perform first-line AML activities, such as operational customer checks or drafting procedures that the business itself should implement. Smaller organisations may face genuine capacity constraints, but combining responsibilities creates a risk that the compliance function will later assess its own work.
The distinction should therefore be documented in practical terms. The organisation should identify who performs customer due diligence, who approves higher-risk relationships, who reviews alerts, who investigates unusual activity, who decides on escalation and who independently tests the process. Where one person performs more than one role, compensating controls and independent review should be established.
This separation also matters when assessing the source of funds and source of wealth. Operational staff may collect and assess information as part of onboarding, while compliance should independently monitor whether the process is applied consistently and whether higher-risk cases receive appropriate scrutiny.
Financial crime compliance requires independent reporting
Compliance findings should be recorded in separate reports, rather than appearing only in general board minutes. Board discussions are important, but minutes alone may not provide a complete record of the risks identified, the monitoring performed, the deficiencies found or the remedial measures agreed.
Independent reporting should cover more than confirmed incidents. It should also address emerging risks, control weaknesses, overdue actions, monitoring results, training gaps and changes in the profile of investors or transactions. A high threshold for board reporting can cause significant warning signs to remain outside senior management’s view.
The board should receive enough information to challenge the effectiveness of AML and broader integrity controls. That includes understanding whether identified weaknesses relate to isolated errors or systemic problems, whether staffing and technology are adequate and whether management has accepted any residual risk.
A standing compliance item on the board agenda can support regular oversight, provided that it leads to substantive review rather than a formal update with no challenge or decisions.
The predicate offense cannot be treated as an afterthought
AML frameworks often focus heavily on customer identification and screening, while giving less attention to the criminal conduct that may generate or explain suspicious assets. This can weaken the quality of investigations.
Fund managers should consider the predicate offenses most relevant to their activities and markets. Fraud and corruption risks may be material in private equity and infrastructure investments. Tax crimes and misappropriation may arise in cross-border structures. Sanctions evasion and trade-based laundering may be relevant where investments involve high-risk jurisdictions or complex supply chains. Market abuse can also generate illicit proceeds or conceal the origin of funds.
Understanding these risks improves the quality of red-flag analysis. Unusual ownership structures, unexplained wealth, rapid movement of capital, inconsistent investment rationales, pressure to bypass controls or transactions involving opaque intermediaries should be assessed in context. The purpose is not merely to identify technical breaches, but to determine whether activity may be connected to criminal proceeds or an underlying offense.
Where suspicion arises, the investigation should be documented clearly. The file should explain the facts considered, the information obtained, the rationale for the conclusion and any decision to escalate or report. This supports consistent decision-making and enables independent review.
Proportionality must be demonstrated, not asserted
Proportionality can be appropriate, but size or assets under management alone do not establish that a reduced control structure is adequate.
A proper assessment should consider the nature, size and complexity of the organisation, including its investment activities, jurisdictions, investor profile, outsourcing model, distribution channels, technology and financial crime exposure. It should explain why the chosen structure is suitable and what safeguards address the resulting risks.
For example, a small manager with a complex cross-border investor base and extensive reliance on external administrators may face greater AML risk than a larger manager with a simpler operating model. Conversely, a small, narrowly focused manager may be able to use a proportionate structure if it can demonstrate adequate expertise, independence and oversight.
The same principle applies to internal audit. If the function is outsourced or provided by a group entity, the manager should explain how independence, competence, internal ownership and effective challenge are maintained.
Internal audit must test whether controls work in practice
Compliance monitoring and internal audit are related but distinct. Compliance focuses on adherence to laws, regulations, policies and standards of conduct. Internal audit provides broader independent assurance on the design and operation of procedures and controls.
For financial crime, internal audit should not simply confirm that policies exist. It should test whether controls work in practice. This may include reviewing the quality of customer files, beneficial ownership determinations, risk classifications, enhanced due diligence, sanctions controls, alert handling, suspicious activity escalation, record keeping, training and oversight of outsourced providers.
Audit plans should explain how priorities were selected and how risks were weighted. Without a clear methodology, audits may focus on convenient or routine topics while failing to address material exposure. The plan should also take account of previous findings, regulatory changes, incidents, control failures and changes to the manager’s operating model.
Where a third party performs the audit, the manager must retain sufficient internal knowledge to challenge the work. An internal owner should understand the methodology, assess the findings and ensure that recommendations address root causes rather than merely correcting individual errors.
Follow-up is part of assurance
An audit recommendation has limited value if nobody establishes whether it was implemented effectively. Reports should identify the responsible owner, the deadline, the action required and the evidence needed to close the finding. Delays should be explained, approved at the appropriate level and reported where they create material residual risk.
Follow-up should also test outcomes. Closing a recommendation because a policy was updated does not demonstrate that staff are applying it correctly or that the control has reduced the identified risk. In an AML context, remediation may require sample testing, review of subsequent cases, system validation or independent confirmation that escalation thresholds are operating as intended.
The board should receive transparent information about open, overdue and repeatedly delayed findings. This enables it to assess whether management is addressing weaknesses promptly and whether additional resources or restrictions are necessary.
What fund managers should do next
The supervisory message is clear. Effective compliance and internal audit require more than formal appointments and documented policies. Fund managers should ensure that their control functions are properly embedded, adequately resourced and able to operate independently.
The immediate priority should be a structured review of the compliance and internal audit framework. That review should test whether documentation is current and tailored, whether AML responsibilities are clearly allocated, whether predicate offense risks are reflected in monitoring, whether outsourced activities are effectively controlled and whether findings are consistently followed through to completion.
Fund managers should also revisit every proportionality decision. The relevant question is not whether a function can technically be combined or outsourced, but whether the resulting structure provides reliable, independent and risk-based assurance.
A mature control environment gives management a clear view of where financial crime risks arise, how controls respond to them and whether weaknesses are being corrected. That is the standard against which fund managers should assess their arrangements.