Where the Chain Actually Runs

What private markets means, for readers who don't work in it day to day

"Private markets" covers investment activity that sits outside public exchanges: private equity, private credit, infrastructure, real assets, and secondaries. The common thread is structural, not sectoral. Capital moves from investors (limited partners, LPs) into a fund, managed by a general partner (GP), which then deploys that capital into portfolio companies, often through one or more special purpose vehicles (SPVs) layered in between for tax, liability, or jurisdictional reasons. A private markets structure may contain natural persons, companies, partnerships, trusts, contractual arrangements, and assets, and each layer must be classified correctly before its ownership, control, and CDD consequences can be determined. That classification step, not an assumption that every layer is a legal entity in the same sense, is where an investigation actually starts.

Why this sector specifically, and why now

The FCA's own review of 242 asset management and alternatives firms, published 22 July 2026, found that firms active in private markets within its sample were more likely to exhibit characteristics associated with heightened financial crime risk: complex ownership structures, higher-risk customers, and international fund flows [1]. The FCA was explicit that exposure isn't uniform across the sector and not every finding applies to every firm, a caveat worth stating plainly rather than smoothing into a flatter "private markets is riskier" claim. What the review also found is a set of documented control gaps sitting behind that elevated exposure: incomplete risk assessments, unverified beneficial ownership in layered structures, and outsourced due diligence with no real oversight behind it. Just over a fifth of all 242 firms had no business-wide risk assessment (BWRA) at all, or an incomplete one, and 18% of private markets firms specifically said their BWRA didn't address private markets risk [1]. Separately, 29% of firms had no formal transaction monitoring process in place [1]. Not every one of these figures shares the same denominator, some describe the full 242-firm sample, others describe only the private-markets subset within it, worth keeping that distinction in mind rather than reading every percentage as directly comparable. This guide exists because that combination, genuinely elevated risk in a meaningful share of the sample plus documented control gaps, is exactly the situation an investigation handbook is built for.

Who this guide is for

Practitioners doing the actual work: compliance analysts and MLROs at asset management and alternatives firms, fund administrators handling outsourced CDD/EDD, and anyone reviewing a fund structure who needs to work out where their due diligence obligation actually stops, not just what the regulation says in the abstract. It assumes the reader already knows what a BWRA or PEP is, this isn't an introductory glossary guide, it's the next step: given a real structure, what do you actually do.

What this guide teaches

Not "what did the FCA find", that's one search away and every law firm briefing already covers it. This guide teaches the investigation itself: given a fund's real ownership chain, LP to fund to GP to SPV to portfolio company to underlying assets, where does the CDD obligation start, where does it genuinely need to extend, when does a PEP or high-risk investor sitting one layer removed from the LP of record still trigger enhanced due diligence, and what does "adequate measures to establish source of wealth" actually look like in a fund-of-funds structure where the direct relationship is with a manager, not the underlying investor. Two worked scenarios carry that reasoning in full, the remaining investigation points (outsourcing oversight, sanctions exposure, subscription and redemption anomalies, related-party transactions, introducer risk) are covered as Risk/Signal/Response patterns below rather than full scenarios.

Applicability, stated plainly

This guide applies to firms and individuals assessing financial crime risk in private market fund structures under the UK's Money Laundering Regulations 2017 (MLRs) regime. It does not cover US or EU private fund AML obligations, those are materially different regimes. It does not replace a firm's own legal advice on a specific structure, it teaches the investigative reasoning, not a compliance sign-off.

How to use this guide

Read the ten investigation-point cards and the ownership-chain diagram first, then the composite case that shows how several of them converge in one file. Then work each scenario, make your call, and read why, both for the answer you picked and for the reasoning behind the correct one. Do not skip ahead.

Ten Investigation Points

Ten patterns, ten cards

Most private markets financial crime misses trace back to one of these ten shapes. Learn to recognise them before the scenarios test two of them in depth.

đŸ§©
The Layered Structure
Complex, cross-jurisdiction ownership that obscures the ultimate beneficial owner.
Risk
Illicit fund movement, sanctions evasion, concealment of origin.
Signal
Over 30% of customers using complex ownership structures is the FCA's own private-markets benchmark.
Response
Reasonable measures under Regulation 28(3A)/(4), documented, not assumed satisfied by GP-level verification alone.
🙈
The Outsourced Blind Spot
CDD/EDD delegated to a fund administrator with no real oversight.
Risk
The firm remains fully liable under Regulation 28/33 regardless of outsourcing.
Signal
40% outsource CDD/EDD; only 36% of those have full oversight (FCA figure).
Response
A documented third-party oversight process, not a one-time onboarding check.
💰
The Missing Source of Wealth
A high-risk or PEP-linked investor with no source of wealth or source of funds verification.
Risk
A Regulation 35(5)(b) breach.
Signal
The FCA found some firms didn't verify source of wealth for high-risk customers.
Response
Adequate measures to establish both source of wealth and source of funds, named separately, not one combined check.
đŸ—‚ïž
The Stale Risk Assessment
A BWRA that hasn't been reviewed against a changing book of business, or that doesn't address private markets risk specifically.
Risk
A Regulation 18/18A breach, informal risk management.
Signal
18% of private markets firms say their BWRA doesn't cover private markets risk at all.
Response
A documented review cycle, not a one-time document.
đŸ€
The Borrowed Check
Relying on an introducer's or placement agent's own due diligence instead of the firm's own.
Risk
Regulation 39 permits reliance on another UK relevant person or a qualifying third-country person, and separately addresses agents and outsourcing under Reg 39(7), but the relevant person remains liable for any failure to apply the required measures [6].
Signal
A file that documents "introducer already checked" with nothing behind it.
Response
Confirm a genuine Regulation 39 arrangement actually exists and meets its conditions before treating any third-party check as satisfying the firm's own obligation.
đŸš«
The Quiet Sanctions Gap
A designated person's interest sitting behind an SPV layer that ownership-chain screening never reached.
Risk
Sanctions exposure hiding exactly where the beneficial ownership gap sits.
Signal
Screening stopped at the customer or fund level, never reached the SPV or portfolio-company layer.
Response
Apply the UK sanctions ownership and control tests independently across the structure; don't treat the MLR beneficial ownership analysis as a substitute, the two frameworks use different tests.
🔄
The Unexplained Redemption
Subscription or redemption activity that doesn't match the investor's stated profile or the fund's normal capital-call rhythm.
Risk
The Regulation 28(11) ongoing monitoring obligation, scrutiny of transactions to ensure consistency with the firm's knowledge of the customer.
Signal
A capital movement that doesn't fit the investor's declared profile or the fund's normal rhythm.
Response
Build redemption-pattern review into ongoing monitoring as an operational application of that duty, not just an onboarding-stage check.
🔗
The Related-Party Transaction
A portfolio company transacting with an entity affiliated to the GP or a co-investor, on terms that aren't clearly arm's length.
Risk
Layering and self-dealing risk that structured ownership checks alone won't surface, since every entity involved may individually pass CDD.
Signal
A vendor, service provider, or counterparty at portfolio-company level shares an owner or director with the GP.
Response
A related-party lens applied specifically at the portfolio-company transaction level, not assumed to be covered by fund-level onboarding.
🏩
The Institutional Assumption
Treating an investor as lower risk purely because it presents as an institution, rather than an individual.
Risk
Institutional framing isn't a substitute for the actual PEP or beneficial-ownership determination, the outcome turns on whether the Regulation 5(3) effective-entitlement threshold is actually met, not on how the investor presents.
Signal
A sovereign wealth vehicle, pension fund, or fund-of-funds treated as automatically lower risk with no threshold analysis performed.
Response
The exposure must be considered within the firm's documented risk assessment; genuine statutory exceptions exist (a listed-company exemption, simplified measures where low risk is properly established), so this is a "don't assume, determine" rule, not a blanket one.
📌
The One-Time File
A BWRA or customer risk assessment completed once at onboarding and never revisited as the fund's book of business changes.
Risk
Regulations 18 and 18A require the BWRA to reflect the risks the firm is actually exposed to; a stale assessment risks becoming inadequate under that general standard, not a fixed review-cycle rule.
Signal
No date, owner, or trigger anywhere in the file for when the assessment gets revisited.
Response
A documented review cycle is strong operational practice, the FCA's own good-practice example described exactly this, though it isn't itself the text of the law.
The Investigation Points

The ownership chain, and where the questions actually sit

Regulation 28(3A) and 28(4) of the MLRs 2017 directly require a firm to understand the ownership and control structure of a legal person, trust, or similar arrangement, and to identify and take reasonable measures to verify the beneficial owner, including that beneficial owner's own ownership and control structure where it is itself a legal person or trust [2]. That's the statutory basis for walking the whole chain, not just the first layer.

Layer 1 · Limited Partner (LP)
Who is the customer, and what CDD do they require?
The LP is usually the direct customer. Fund-of-funds and nominee LPs add a layer before this question is even fully answered.
Layer 2 · Fund
The vehicle itself, not automatically the person who needs identifying
The fund is usually a legal person or arrangement, not a natural person. Its own ownership and control structure is what needs establishing under Regulation 28(3A).
Layer 3 · General Partner (GP)
Where operational control actually sits
The GP manages the fund day to day. Understand who controls the GP itself, and whether it is independently regulated or relying on the firm's own oversight.
Layer 4 · Special Purpose Vehicle (SPV)
Offshore layering, the point beneficial ownership most often goes quiet
SPVs exist for tax, liability, or jurisdictional reasons, not automatically to conceal, but each one is a fresh layer Regulation 28(4) requires tracing through.
Layer 5 · Portfolio Company
Related-party transactions and sanctions exposure surface here
Co-investors, affiliated entities, and designated persons can all sit at this layer, screened independently of the fund-level CDD already done above.
Layer 6 · Underlying Assets
Source of wealth versus source of funds
Where the capital actually originated, not just where it's currently invested, has to be evidenced separately from the transaction's source of funds.
Illustrative, Not a Real Enforcement Matter

Composite case: Northbridge Meridian Capital

This is a composite case, built to show how several of the investigation points above converge in a single file. It is not a real, named enforcement matter, see below for why.

Northbridge Meridian Capital, a mid-sized UK private equity manager, onboards a new limited partner, Wexford Continental Holdings, ahead of a fund closing. Wexford is wholly owned by a Jersey trust structure with two co-settlors, one of whom sits on the board of a state-owned sovereign development fund. The onboarding analyst confirms Wexford's own incorporation and its immediate Jersey parent, then stops there, the file records only "beneficial owner: Jersey trust," with no further detail obtained.

Eight months later, the fund's principal portfolio company enters a services contract with a vendor that turns out to be majority-owned by a director of the GP itself, a related-party transaction that never surfaced because Northbridge's ownership-chain checks were scoped to the LP side of the structure only, never extending to the portfolio-company side. Meanwhile the outsourced fund administrator, engaged for ongoing CDD refresh, has no documented process for escalating a change in an investor's declared circumstances, so the sovereign-fund board seat, disclosed voluntarily by Wexford's own investor-relations team a year after onboarding, sits unreviewed in the file until a routine periodic review finally raises it.

Three of the investigation points above converge in this one file: The Layered Structure (the Jersey trust chain stopped short of the actual beneficial owner), The Related-Party Transaction (the portfolio-company vendor contract), and The Outsourced Blind Spot (the administrator's missed escalation). None of the three would have looked serious reviewed alone; together they describe exactly the kind of file this guide is built to teach an analyst to read.

Why a composite case, not a real one

No genuine, on-point UK enforcement action against a private markets firm specifically for beneficial-ownership or ownership-chain failure was found during research for this guide. The closest candidate, the FCA's final notice against ADM Investor Services International, covers PEP, EDD, and source-of-wealth failures, but the firm is an investment brokerage, not a private markets fund manager, so citing it as a private-markets precedent would misrepresent what the source actually establishes.

Scenario 01 · Upstream beneficial ownership
Verifying the Customer's Own Upstream Ownership
The Layered Structure

A relevant person is onboarding a corporate limited partner (LP) as its customer, ahead of that LP's investment into a private equity fund. The LP itself is wholly owned by a Luxembourg holding company, which is in turn owned by a Cayman company. The onboarding file describes the Cayman company's own owner only as "a corporate entity," with no further ownership or control information obtained.

⚖️
What does the firm's CDD obligation require at this point? Make the call
🏦
Scenario 02 · PEP exposure in a fund-of-funds structure
Two Variants, the Same Threshold
The Institutional Assumption

A fund-of-funds limited partnership is the relevant person's direct customer, subscribing as an LP into the underlying fund. The fund-of-funds' own manager is a separate entity and acts only as manager, it is not itself the customer. One of the fund-of-funds' own underlying investors is closely associated with a sovereign wealth entity and meets the PEP definition. Two variants below change only the underlying investor's effective entitlement, once traced through the whole structure.

Variant A: 30% effective entitlement

After tracing every intermediate interest, dilution, aggregation, voting arrangement, and relevant constitutional right through the fund-of-funds structure, the PEP is ultimately and indirectly entitled to 30% of the capital or profits of the customer limited partnership.

⚖️
Does enhanced due diligence apply? Make the call

Variant B: 8% interest, no control rights

The same PEP instead holds 8% of the customer's capital, profits, and voting rights, no rights or arrangements satisfying Regulation 5(3)(b) where applicable, and doesn't otherwise exercise ultimate control over the partnership's management.

⚖️
Does enhanced due diligence apply? Make the call

Why both variants, not one scenario: the wrong lesson to teach here is "any PEP connection anywhere in a fund-of-funds structure triggers EDD." The right lesson is that the trigger depends on whether the underlying investor's effective entitlement, properly traced through the whole structure, actually meets the statutory beneficial-ownership test, and that the consequence differs materially depending on which side of that line the fact pattern falls. A single scenario asserting the look-through rule as universal would have taught an overstatement.

Screening an LP, GP, or an underlying investor? Run a free sanctions, PEP, and adverse media check before proceeding, no account required.
Screen an individual →
Knowledge Check
Five questions. How well do you read the ownership chain and the beneficial-ownership thresholds?
1. Under Regulation 28(3A)/(4), when a firm's customer's beneficial owner is itself a legal person or trust, what must the firm do?
2. What does Regulation 5(3) require for an individual to count as a partnership's beneficial owner?
3. After tracing dilution through every layer of a fund-of-funds structure, a PEP's effective entitlement in the customer partnership comes to 22%. What follows?
4. Under Regulation 28(9), can a firm satisfy its beneficial-ownership verification obligation by relying solely on a Companies House PSC filing?
5. What is the FCA's 22 July 2026 findings publication?
0/5
Frequently Asked

FAQ

Does this guide apply to funds regulated outside the UK?
No. It's built specifically around the UK's MLRs 2017 regime. US and EU private fund AML obligations are materially different regimes and aren't covered here, consistent with this site's standing rule against blending jurisdictions.
What's the difference between a fund's "investors" generally and its legal beneficial owners?
Every LP is an investor, but only those meeting the statutory threshold (Regulation 5 for partnerships, Regulation 6 for trusts) count as beneficial owners for CDD purposes. The two categories overlap but aren't identical, an investor below the threshold is still an investor, just not one that triggers the beneficial-ownership-specific obligations.
Is 25% always the exact line, or can a smaller stake still matter?
25% (partnerships) is the statutory beneficial-ownership threshold under Regulation 5(3). A smaller stake doesn't trigger the automatic beneficial-ownership route, but it can still feed into a firm's broader risk assessment under Regulation 33(1)(a), which operates independently and isn't capped by that threshold.
Why does this guide use a composite case study instead of a real enforcement action?
No UK enforcement action specifically against a private markets fund manager for beneficial-ownership or ownership-chain failure was found during sourcing. The closest candidate, an FCA final notice against a brokerage, was deliberately not used, citing it as private-markets precedent would misrepresent what it actually is.
How is source of wealth different from source of funds?
Regulation 35(5)(b) names them separately. Source of wealth is the overall origin of a person's total assets and how they built their wealth generally. Source of funds is narrower, specifically where the money involved in this relationship or transaction came from. EDD requires adequate measures to establish both, not one as a substitute for the other.
What should a firm do if it genuinely can't identify a beneficial owner after real effort?
Regulation 28(6)/(7) allows treating the senior person responsible for managing a body corporate customer as its beneficial owner, but only where the firm has exhausted all possible means and either failed or isn't satisfied the individual identified is correct, and Regulation 28(8) requires every step taken to be recorded in writing. It's a documented last resort, not a shortcut.
Does outsourcing CDD to a fund administrator reduce the firm's own liability?
No. Regulation 39 permits relying on another UK relevant person or an equivalent third-country party under specific conditions, but the relevant person remains liable for any failure to apply the required measures regardless of what a third party did or didn't do.
Quick Reference

At a glance

Ten investigation points, the risk that makes each one look routine, the signal that actually gives it away, and the response that fits.

đŸ§©
The Layered Structure
Complex, cross-jurisdiction ownership that obscures the ultimate beneficial owner.
Risk
Illicit fund movement, sanctions evasion, concealment of origin.
Signal
Over 30% of customers using complex ownership structures is the FCA's own benchmark.
Response
Reasonable measures under Reg 28(3A)/(4), documented, not assumed.
🙈
The Outsourced Blind Spot
CDD/EDD delegated to a fund administrator with no real oversight.
Risk
The firm remains fully liable under Reg 28/33 regardless of outsourcing.
Signal
40% outsource CDD/EDD; only 36% of those have full oversight.
Response
A documented third-party oversight process, not a one-time check.
💰
The Missing Source of Wealth
A high-risk or PEP-linked investor with no source of wealth or source of funds verification.
Risk
A Regulation 35(5)(b) breach.
Signal
Some firms don't verify source of wealth for high-risk customers.
Response
Adequate measures for both source of wealth and source of funds, named separately.
đŸ—‚ïž
The Stale Risk Assessment
A BWRA never reviewed against a changing book of business, or that doesn't address private markets risk.
Risk
A Regulation 18/18A breach, informal risk management.
Signal
18% of private markets firms say their BWRA doesn't cover private markets risk.
Response
A documented review cycle, not a one-time document.
đŸ€
The Borrowed Check
Relying on an introducer's or placement agent's own due diligence instead of the firm's own.
Risk
The relevant person remains liable for any failure to apply the required measures.
Signal
A file that documents "introducer already checked" with nothing behind it.
Response
Confirm a genuine Regulation 39 arrangement exists before relying on it.
đŸš«
The Quiet Sanctions Gap
A designated person's interest sitting behind an SPV layer that ownership-chain screening never reached.
Risk
Sanctions exposure hiding exactly where the beneficial ownership gap sits.
Signal
Screening stopped at the customer or fund level.
Response
Run sanctions ownership and control tests independently, not as a substitute for the MLR analysis.
🔄
The Unexplained Redemption
Subscription or redemption activity that doesn't match the investor's stated profile or capital-call rhythm.
Risk
The Regulation 28(11) ongoing monitoring obligation.
Signal
A capital movement that doesn't fit the investor's declared profile.
Response
Build redemption-pattern review into ongoing monitoring.
🔗
The Related-Party Transaction
A portfolio company transacting with a GP-affiliated entity or co-investor on non-arm's-length terms.
Risk
Layering and self-dealing risk that structured ownership checks alone won't surface.
Signal
A portfolio-company counterparty shares an owner or director with the GP.
Response
A related-party lens at the portfolio-company transaction level, not assumed covered.
🏩
The Institutional Assumption
Treating an investor as lower risk purely because it presents as an institution.
Risk
The outcome turns on whether the Reg 5(3) threshold is met, not on how the investor presents.
Signal
A sovereign wealth vehicle or fund-of-funds treated as lower risk with no threshold analysis performed.
Response
Determine, don't assume; genuine statutory exceptions exist but aren't automatic.
📌
The One-Time File
A BWRA or customer risk assessment completed once at onboarding and never revisited.
Risk
A stale assessment risks becoming inadequate under Reg 18/18A's general standard.
Signal
No date, owner, or trigger anywhere in the file for revisiting the assessment.
Response
A documented review cycle, strong practice though not itself the text of the law.
Reading the Chain

The FCA's findings name the risk. The chain is where you actually find it.

Walking a real fund's ownership chain, LP to fund to GP to SPV to portfolio company to underlying assets, and knowing at which layer each question actually belongs, is the skill this guide is built to teach. FinCrimeRadar's screening tool checks any individual or entity against live sanctions, PEP, and adverse media data, free, no signup required.

Verifying an LP, GP, or underlying investor? Free. No account needed. Check them against live sanctions, PEP, and adverse media data.
Screen an individual →
Verification

Sources

Each numbered claim above is checked against the specific source below it. The composite case study and its investigation points are illustrative, not sourced facts, the guide's own text says which.

  1. Financial Conduct Authority, Asset management and alternative firms: financial crime controls, 22 July 2026. fca.org.uk/publications/good-and-poor-practice/asset-management-alternative-firms-financial-crime-controls
  2. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), Regulation 28. legislation.gov.uk/uksi/2017/692/regulation/28
  3. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), Regulation 5. legislation.gov.uk/uksi/2017/692/regulation/5
  4. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), Regulation 35. legislation.gov.uk/uksi/2017/692/regulation/35
  5. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), Regulation 33. legislation.gov.uk/uksi/2017/692/regulation/33
  6. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), Regulation 39. legislation.gov.uk/uksi/2017/692/regulation/39
  7. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692), Regulation 40. legislation.gov.uk/uksi/2017/692/regulation/40