Guide 5 of 5 · Abax Fund Admin · 2026

AML Compliance for VC Funds:
The 2026 Playbook

FinCEN's investment adviser AML rule is now in effect. This guide explains what's required, who's covered, and how to build a compliant program without hiring a compliance team.

!

VC funds are no longer exempt. Starting in 2026, FinCEN regulations require venture capital fund managers to implement formal AML programs — including written policies, LP risk assessments, ongoing monitoring, and suspicious activity reporting procedures. The VC exemption that previously relieved many emerging managers from these obligations is gone.

Background

What changed and why it matters

For most of the history of venture capital, VC fund managers were largely exempt from the anti-money laundering requirements that applied to banks, broker-dealers, and other financial institutions. The rationale was that venture capital — with its small LP bases of sophisticated investors and long investment horizons — posed lower AML risk than high-volume, high-liquidity financial services.

That position has changed. FinCEN's Investment Adviser Rule, which came into effect in 2026, extends formal AML program requirements to investment advisers — including most VC fund managers, regardless of whether they're registered as RIAs or operating as Exempt Reporting Advisers. The rule requires every covered investment adviser to implement a written AML program, conduct customer due diligence on investors, perform LP risk assessments, maintain ongoing monitoring, and have a process for identifying and reporting suspicious activity.

For the vast majority of emerging managers, this is new territory. First-time GPs who launched their first fund in 2022 or 2023 under the old exemption framework are now operating under materially different compliance requirements. Most don't have a compliance officer, a compliance consultant, or a fund administrator that handles AML professionally. This guide is written for them.

Non-compliance is not a theoretical risk. FinCEN enforcement actions against investment advisers are increasing in frequency. "We didn't know about the requirements" is not a defense once regulations are in effect. If your fund hasn't implemented a formal AML program, the time to act is now — not at your next annual review.

Chapter 01

The 5 core requirements of a compliant AML program

A compliant AML program for an investment adviser under the 2026 FinCEN rules has five core components. Each is required — not optional, not aspirational. Here's what each one means in practice for a micro VC fund.

01
Written AML program Required
A formal, documented policy document — typically 5–10 pages — that covers your fund's AML risk profile, the procedures you follow for verifying LP identities, the process for identifying and escalating suspicious activity, and the annual review schedule. It must be approved in writing by senior management (that's you, the GP). This document is the foundation of everything else in your AML program.
02
Customer due diligence (CDD) Required
Enhanced know-your-customer procedures for every LP — applied at onboarding and updated when circumstances change. For individual LPs: government-issued ID verification, address confirmation, and source-of-funds documentation for high-risk investors. For entity LPs (LLCs, trusts, family offices): beneficial ownership identification — who ultimately controls and benefits from the entity — plus the entity's formation documents and source-of-funds attestation where required.
03
LP risk assessment Required
A documented assessment that classifies each LP by AML risk level — low, medium, or high — based on standard risk factors: LP type (domestic individual, domestic entity, foreign individual, foreign entity), source of funds, jurisdiction, and whether any LP is a Politically Exposed Person (PEP). The risk assessment informs how much due diligence you apply to each LP and how frequently you re-screen them. This document must be maintained and updated at least annually.
04
Ongoing monitoring Important
A periodic review of LP accounts and capital activity to identify changes in risk profile or unusual patterns. For most VC funds, this means annual re-screening of your LP base against sanctions lists and PEP databases, plus transaction-level monitoring of capital calls and distributions for activity that doesn't fit the LP's stated profile. This doesn't require sophisticated software — a documented annual review process with your fund administrator's records as the input is sufficient for most micro VC funds.
05
Suspicious Activity Reports (SARs) In practice: rare
A documented process for identifying transactions that may involve money laundering or terrorist financing and reporting them to FinCEN. Most VC fund managers will never actually file a SAR — the LP base of a typical micro VC fund is small and well-known to the GP. But the process for identifying when to file is required, and it must exist in your written AML program. Your fund formation attorney or compliance consultant can provide standard SAR trigger criteria appropriate to a VC fund context.
One additional requirement: your AML program must include an annual independent review of the program's effectiveness. For most emerging managers, this doesn't mean hiring an external auditor — a documented annual review conducted by someone other than the primary compliance point of contact (which can be your compliance consultant or your fund administrator) satisfies this requirement.

Chapter 02

Who is covered — and common misconceptions

The most common misconception among first-time GPs is that the VC Fund Adviser Exemption — which allows many emerging managers to avoid full RIA registration — also exempts them from AML requirements. It does not. AML requirements attach to the investment adviser function, not to the registration status.

Fund manager type AML program required? Notes
Registered Investment Adviser (RIA) ✓ Yes — fully covered Full AML program required. No exemptions.
Exempt Reporting Adviser (ERA) ✓ Yes — generally covered ERA status exempts from RIA registration, not from AML. Most micro VC funds fall here.
Foreign Private Adviser → Depends on structure May have different requirements depending on US nexus and LP base. Consult attorney.
SPV-only operator (no ongoing fund) → Depends on structure Whether AML applies depends on whether you're acting as an investment adviser under the statute. Consult attorney.
Accelerator / scout program → Case-by-case Depends on whether there's a pooled investment vehicle. Not covered if no fund structure.
If you're uncertain whether your fund structure is covered by the new rules, a 30-minute conversation with your fund formation attorney will resolve it. The cost of that conversation is orders of magnitude lower than the cost of being found non-compliant during an examination.

A note on timing

The regulations are in effect now. If your fund launched before the effective date and you haven't implemented an AML program, you're not grandfathered — you're non-compliant. The practical approach: implement the program as quickly as reasonably possible, document the implementation date, and maintain records going forward. A fund that implements an AML program in Q2 2026 and maintains it diligently is in a significantly better position than one that doesn't implement it at all.


Chapter 03

What a compliant AML program looks like

Abstract regulatory requirements are hard to act on. This section describes the concrete documents and processes that constitute a compliant AML program for a micro VC fund — not what the regulation says, but what you actually need to have in place.

The four documents / processes of a compliant AML program Required for compliance
Who produces each — and what it contains
01
Written AML program document
A 5–10 page policy covering: fund's AML risk profile, CDD procedures, LP onboarding checklist, risk classification methodology, SAR trigger criteria, annual review process, and GP approval signature. Drafted once, updated when program changes or annually. Your compliance consultant or fund administrator provides a template; the GP customizes it and signs off.
GP signs / consultant drafts
02
LP onboarding file (per LP)
A file maintained for every LP containing: government ID (for individuals), entity formation documents and beneficial ownership (for entities), source-of-funds attestation where required, AML screening results (sanctions list, PEP check), risk classification (low / medium / high), and the date of initial screening. Maintained and updated by your fund administrator throughout the LP's relationship with the fund.
Fund admin handles
03
LP risk assessment matrix
A master document showing every LP's risk classification with the supporting rationale — LP type, jurisdiction, source of funds, PEP status, and any escalating risk factors. Updated at least annually or whenever an LP's circumstances change. This is the document an examiner would review to assess the quality of your CDD process. Your fund administrator produces this from their LP records.
Fund admin produces
04
Annual AML review record
A brief document — one to two pages — confirming that the annual review has been conducted: all LPs re-screened, written program reviewed and confirmed current, no SARs filed (or SARs filed, as applicable), and the review date. Signed by the GP and the reviewer. This is the primary evidence that your AML program is actually functioning, not just documented.
GP + independent reviewer
Most of the documentation burden sits with your fund administrator, not the GP. A fund administrator who includes AML compliance in their standard service should be maintaining LP onboarding files, producing the risk assessment matrix, conducting annual re-screenings, and providing you with the records you need for the annual review. The GP's primary obligation is to approve the written program and conduct or commission the annual review.

Chapter 04

How your fund administrator fits into AML compliance

The relationship between fund administration and AML compliance is one of the most important and most misunderstood operational decisions for emerging managers. Knowing exactly what your administrator handles — versus what requires a separate engagement — determines how much compliance burden lands on you personally.

Fund administrator handles
  • LP onboarding document collection
  • Identity verification (individuals)
  • Beneficial ownership identification (entities)
  • Sanctions list and PEP screening
  • LP risk classification and documentation
  • LP onboarding file maintenance
  • Annual LP re-screening
  • Risk assessment matrix production
  • Records for annual review
May need compliance consultant for
  • Drafting the written AML program
  • Regulatory interpretation advice
  • SAR filing guidance
  • Annual independent program review
  • High-risk LP determination
  • Foreign investor structuring advice
GP responsibility always
  • Approving the written AML program
  • Final sign-off on high-risk LPs
  • Annual review sign-off
  • Training any employees
  • Ultimate regulatory accountability

The critical question to ask every prospective fund administrator

Before signing with any fund administrator, ask this question directly: "Does your AML service cover the written program, ongoing monitoring, and annual review required under the 2026 FinCEN regulations?"

The answer tells you immediately whether you need a separate compliance consultant. Many fund administrators offer basic KYC document collection — gathering IDs and subscription documents — but stop well short of the documented risk assessment, ongoing monitoring, and annual review process that the new regulations require. The distinction between "we do KYC" and "we maintain a compliant AML program" is significant, and it's a question almost no first-time GP thinks to ask.

Abax includes LP onboarding verification, risk assessment documentation, and ongoing monitoring as part of our standard fund administration service — built to meet the 2026 FinCEN requirements. We also work directly with your compliance consultant if you engage one for the written program or annual review. Ask us specifically what we cover for your fund structure.

The compliance consultant: when you need one and what it costs

Most solo GPs and small emerging manager teams don't need a full-time or ongoing compliance consultant. What you need is a one-time engagement to draft your written AML program — a compliance firm that specializes in investment adviser compliance can produce a fund-specific written program for a one-time fee of approximately

,000–$5,000. That program is then reviewed and updated annually, which is a 1–2 hour exercise if your fund administrator maintains good records throughout the year.

If your fund has a complex LP base — significant foreign LP commitments, entity LPs in multiple jurisdictions, or LPs that include politically exposed persons — the complexity of your written program and ongoing monitoring increases, and a more active compliance relationship may be warranted. Your fund administrator should be able to assess this and advise accordingly.


Chapter 05

Building your AML program without a compliance team

A practical action plan for the solo GP or two-person emerging manager team who needs to implement a compliant AML program without the budget or headcount to hire dedicated compliance staff. This is achievable, and it doesn't require the infrastructure of a large asset manager.

1
Confirm your fund administrator's AML coverage
Before anything else: understand exactly what your fund administrator covers for AML compliance. Ask in writing — "does your service include LP risk assessment documentation, ongoing monitoring, and annual re-screening?" If yes, get it confirmed in your service agreement. If no, you know what you need to source separately. This conversation takes 20 minutes and determines how much additional work you need to do.
Timeline: This week
2
Engage a compliance consultant for the written program
A VC-specialist compliance firm can draft your written AML program in 1–2 weeks. You review and approve it. The GP signs the approval. This is a one-time engagement unless your fund structure changes significantly. Ask your fund administrator or fund formation attorney for a referral to a compliance firm they regularly work with — warm introductions significantly reduce the evaluation time. Cost:
,000–$5,000 one-time.
Cost:
,000–$5,000 one-time
3
Implement standardized LP onboarding checklists
Work with your fund administrator to standardize the document collection process for every new LP. The checklist should be consistent, applied to every LP without exception, and documented. LPs who object to providing standard AML documentation are themselves an AML red flag — your written program should address how to handle this. Your fund administrator should have a standard LP onboarding checklist they use; confirm it meets the new requirements.
Timeline: Before next LP onboarding
4
Calendar the annual AML program review
Set the annual review date now — don't leave it as an undated intention. Pick a consistent date (January is common — shortly after year-end). Your fund administrator provides the updated LP screening records. Your compliance consultant (or you, with their template) reviews the written program for currency. The GP signs the annual review record. If your records are well-maintained, this is a 2–4 hour process, once a year.
Timeline: Calendar immediately
5
Document everything — compliance is a documentation exercise
If you do the right things but don't document them, you can't prove compliance. The examination risk is in the documentation gap, not in the actions. Your fund administrator should be maintaining LP-level records (onboarding files, risk classifications, screening results). Your responsibility is to maintain program-level documents (written program, annual review records, any SAR documentation). Keep these organized and accessible — an examiner who asks for your AML documentation should be able to see it within 24 hours.
Ongoing

Reference

AML/KYC glossary for emerging managers

A reference for the regulatory terminology used in AML compliance — for GPs who are new to this framework and want clear plain-English definitions before working through their compliance setup.

AML
Anti-Money Laundering. The set of laws, regulations, and procedures designed to prevent the use of the financial system to conceal the proceeds of criminal activity. The FinCEN Investment Adviser Rule extends AML obligations to investment advisers including VC fund managers.
KYC
Know Your Customer. The process of verifying the identity of your investors and understanding their financial profile. KYC is the operational implementation of AML requirements — it's what you actually do when you onboard a new LP.
CDD
Customer Due Diligence. The enhanced KYC procedures required under the new FinCEN rules — including beneficial ownership identification for entity investors and source-of-funds documentation for higher-risk investors. Goes beyond basic identity verification.
SAR
Suspicious Activity Report. A report filed with FinCEN when a transaction appears to involve money laundering, terrorist financing, or other financial crimes. Most VC fund managers will never file a SAR, but having a documented process for identifying when to file is required.
PEP
Politically Exposed Person. An individual who holds or has held a prominent public position — senior government official, politician, military leader, or their close family members and associates. PEPs are flagged as higher AML risk and typically require enhanced due diligence and more frequent monitoring.
Beneficial Owner
The individual(s) who ultimately own or control an entity LP. When an LP is an entity (LLC, trust, family office holding company), the AML requirement is to identify the natural persons who ultimately benefit from or control that entity. Under FinCEN's rule, this typically means individuals with 25%+ ownership or effective control.
FinCEN
Financial Crimes Enforcement Network. The bureau of the US Department of the Treasury that collects and analyzes financial data to combat domestic and international money laundering, terrorist financing, and other financial crimes. FinCEN administers the AML regulations that now apply to investment advisers.
ERA
Exempt Reporting Adviser. A fund manager that qualifies for an exemption from full SEC registration as an investment adviser — typically because they manage only VC funds or have less than
50M in AUM. ERA status exempts from registration requirements but does not exempt from AML obligations under the 2026 FinCEN rule.
RIA
Registered Investment Adviser. An investment adviser that has registered with the SEC (or state securities regulators). Both RIAs and ERAs are covered by the 2026 AML requirements — the distinction is in registration status, not AML compliance obligations.
Written Program
The formal written AML program document required under the FinCEN Investment Adviser Rule. A 5–10 page policy that covers the fund's AML risk profile, CDD procedures, monitoring processes, SAR trigger criteria, and annual review schedule. Must be approved in writing by senior management (the GP).

Download the AML program compliance checklist

A one-page reference covering all required elements of a compliant AML program for emerging VC managers — formatted to share with your compliance consultant, fund administrator, or fund formation attorney.

5-requirement compliance checklist LP onboarding document list Annual review template Risk classification guide

Sent. Check your inbox — the checklist will arrive within a few minutes.

No spam. Just the checklist. Unsubscribe anytime.

Unsure if your current setup is compliant?

Abax includes AML/KYC compliance as part of our standard fund administration service. If you're not sure whether your current arrangement covers the 2026 FinCEN requirements, book a 20-minute call and we'll walk through your specific fund structure.

Book a 20-minute call

Need Hands-On Help?

Book a demo and we'll walk you through everything.