European asset managers are generally subject to more stringent anti-money laundering (AML) regimes than their U.S. counterparts. However, U.S. asset managers might still need to comply with EU or UK AML requirements due to a European nexus—be it overseas operations or fund vehicles in the EU.
Additionally, the U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) recently published a Final Rule on AML and counter-terrorist financing (CTF) that will bring SEC-regulated advisers and exempt reporting advisers (ERA) within the scope of the U.S. customer due diligence framework set out under the Bank Secrecy Act (BSA) effective January 1, 2028.
Even for U.S. investment managers not currently subject to a formal AML regime, an increasing number of U.S. managers adopt AML programs that are somewhat aligned with the European regime. This is as a result of:
The need to identify beneficial owners of transaction counterparties and investors to ensure compliance with OFAC and other sanctions regimes
Client expectations—such as institutional investors with heightened compliance expectations
Maintaining a consistent global approach to AML where also operating in jurisdictions with mandatory AML rules for asset managers (such as the UK and EU);
Affiliation with a regulated entity (such as a broker-dealer); and/or
The desire to understand and manage reputational and financial risks associated with entering into business relationships with persons who may be subject to media controversy and/or legal or regulatory sanctions.
This move toward greater global alignment on AML regulations for asset managers will see U.S. firms increasingly contend with AML obligations that are much closer to the European rules. Because of this, there has never been a better time for U.S. managers to become familiar with European AML requirements.
Applying European AML to private transactions
1. Who do they cover?
One of the key differences between the U.S. AML regime and European AML regimes is the types of entities within scope.
In the U.S., AML-related rules and requirements are most notably codified in the federal BSA and administered by FinCEN. These requirements apply to “financial institutions,” which include banks, broker-dealers, and money services businesses. Notably, several types of private asset managers—including investment advisers, private investment funds, and real estate firms—currently do not fall within the BSA's existing “financial institution” definition.
However, this is about to change—FinCEN's new Final Rule, which is set to take effect on January 1, 2028, will expand the definition of “financial institution” to registered investment advisers and exempt reporting advisers.
European AML requirements apply to a broad range of entities, including credit and financial institutions, estate agents, certain professional advisers, and investment advisers. This means that advisers not subject to U.S. AML rules may still fall within EU or UK regimes if they operate or have dealings in those jurisdictions—for example, through Luxembourg entities in their fund structures, or by using a European AIFM.
The rules governing these obligations are changing. The EU's regime has historically been built on successive Anti-Money Laundering Directives, but as of June 2024, a directly applicable Single Rulebook (Regulation EU 2024/1624) now sits above the 6th AML directive as the primary compliance instrument– setting CDD obligations and AMl controls that will apply uniformly across all EU member states from July 10, 2027, without national transposition. The 6AMLD remains in force but governs supervisory architecture rather than substantive compliance standards. Overseeing both is the Anti-Money Laundering Authority (AMLA), which became operational in July 2025.
For U.S. fund managers with a European nexus, this shift provides clarity: rather than navigating a patchwork of nationally transposed rules that varied by member state, the Single Rulebook creates one uniform set of AML standards across the EU, making compliance obligations easier to understand and plan for.
2. Risk-based approach
Any firm subject to the EU or UK AML frameworks must take a risk-based approach to AML compliance. The core principles of a risk-based approach are also reflected under the BSA for the U.S. regime. The EU rules do not require compliance with a one-size-fits-all program; instead, they require firms to design AML policies, procedures, and internal controls that fit their own specific needs and risk exposure.
Regulators expect that there will be some differences between firms' approaches to AML, but they require that each firm's AML policy be documented clearly and applied consistently.
When looking specifically at private transaction investing, it is typical to apply risk weighting to the transaction to determine the extent of the compliance due diligence needed. This will include a documented analysis of:
The nature and complexity of the transaction
The jurisdiction of the counterparties, asset, or other key parties
The relevant industry
Whether there are any politically exposed persons (PEP) in the structure
Results of background screening checks
It's worth remembering that an initial risk rating is not static. It can be revised based on further information collected during the due diligence process.
A key point also to note is that risk rating isn't a formula. Each transaction needs to be reviewed within the broader context of the transaction, applying experience, legal knowledge, and commercial sensibility. Too rigid an approach can result in important risk factors being missed, or in excessively burdensome KYC requests.

3. KYC
The UK and EU regimes require managers to carry out customer due diligence (CDD) or, informally, know your customer (KYC). This is broadly equivalent to the U.S. framework's Customer Identification Program (CIP), one of the five pillars of U.S. AML.
One of the key current differences between the EU/UK regime and the U.S. is that “customer” includes transaction counterparties with respect to private investments, not just the funds and/or investors of an asset manager.
These rules therefore specifically require the identification and verification of transaction counterparties and their ultimate beneficial owners (UBOs) by way of carrying out KYC on those persons (and source of funds).
KYC may be simplified, standard, or enhanced (the last of which is often referred to as enhanced due diligence, or EDD). Entities may conduct simplified KYC in circumstances with relatively low AML risk, such as when dealing with a regulated financial institution or companies listed on a recognized stock exchange. Conversely, entities are expected to conduct EDD in circumstances with higher AML risk, such as transactions with PEP exposure and/or in higher-risk geographies and industries. Standard KYC should apply in all other cases.
Turning then to the process of collecting KYC information. Another of the key differences between the U.S. and European approaches is the approach used to identify UBOs. U.S. managers can generally adopt a lighter-touch approach, often relying on customer self-declaration or bespoke beneficial ownership forms. The European approach, however, is more granular and prescriptive under the regulations, and there are restrictions on relying on third-party databases and/or self-declarations to establish ownership. UBOs are therefore identified through the collection of certified structure charts and the collection of various corporate and ownership documents (such as cap tables and shareholder registers) up the customer's chain of control to the ultimate UBOs who are individuals. Collecting identity documents and proof of address (often certified) for UBOs and/or key managers and directors is also mandatory in most cases.
Having identified key persons connected with a transaction counterparty through the KYC process, those parties are then typically screened against global sanctions lists, PEP watchlists, and financial crime databases. This helps inform the risk profile of the transaction—are the screens clear or are there further hits?—and ensures the transaction is compliant with applicable sanctions and other legal and regulatory regimes.
To the extent there are higher risk factors connected with the transaction or the counterparty, further work is then typically undertaken as part of a more comprehensive EDD program.
4. Ongoing monitoring
The U.S., UK, and EU frameworks agree that AML due diligence is not a one-and-done exercise. An effective AML program involves risk-based ongoing monitoring to ensure that suspicious activities and/or material changes to a customer's risk profile are promptly flagged and escalated for further handling, and that CDD materials are kept updated by way of periodic refresher KYC exercises.
With staffing changes and investment teams focused elsewhere, keeping up to date with monitoring and refresher checks can get deprioritized. However, with audits on the rise, asset managers subject to EU/UK rules need to ensure they have a clear system in place to monitor their private transactions during the lifetime of the investment. For a closer look at the key steps asset managers should take, see Investment KYC: managing the need for ongoing monitoring.
This is the third entry in Carta Law's series, Private Markets Compliance: The Operational Framework. Read the next entry here.

DISCLOSURE: This publication contains general information only and neither eShares, Inc. dba Carta, Inc. (“Carta”) nor Carta Law is, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication does not give rise to any lawyer-client relationship, is not a substitute for such professional advice or services and nor should it be used as a basis for any decision or action that may affect your business or interests. Before making any decision or taking any action that may affect your business or interests, you should consult a qualified professional advisor. Carta does not assume any liability for reliance on the information provided herein. © 2026 eShares, Inc. dba Carta, Inc. All rights reserved. Reproduction prohibited.


