A Complete Subscription Pack Is Not a Complete CDD File

How funds can build an AMLR-ready CDD file for entity investors, from subscription through ongoing monitoring.

Sep 2, 2026Steward Team1 min read
A Complete Subscription Pack Is Not a Complete CDD File

A Complete Subscription Pack Is Not a Complete CDD File

A fully executed subscription agreement shows that an investor wants to commit capital. It does not, on its own, show that the fund understands who that investor is, who controls it, who is authorised to act for it, why the relationship makes sense or what must happen when the information changes.

That gap is where fund onboarding becomes fragile. A corporate certificate may sit in an administrator's portal, identity documents in an email thread and an ownership chart in a shared drive. The subscription can move forward while the evidence that supports a customer due diligence decision remains fragmented. When a reviewer later asks why the relationship was accepted, the team must reconstruct the answer from documents that were never connected to the decision they were meant to support.

AMLR makes that approach difficult to defend. Article 20 requires customer identification and verification, beneficial-ownership identification and reasonable verification, understanding of ownership and control, assessment of the relationship's purpose and intended nature, sanctions checks, ongoing monitoring, PEP assessment and verification of people acting for the customer. Article 21 is equally direct: if an obliged entity cannot complete the required CDD, it must not establish the relationship or carry out the transaction, subject to the provision's specific rules for existing relationships. The Regulation applies from 10 July 2027. A signed pack should therefore be treated as one source of evidence in a controlled CDD file, not as proof that the file is complete. Regulation (EU) 2024/1624 sets the common baseline.

A CDD file should answer five connected questions

The precise information a fund collects will depend on its risk assessment, investor type and the relationship. But a durable file should make five records easy to find and easy to understand. The point is not to create five new folders. It is to connect the evidence to the compliance question it answers.

1. The investor entity. Record the legal name, form, jurisdiction, registration details and relevant business activity of the customer. For a fund-of-funds, SPV, family office, partnership or corporate investor, this is the starting point for understanding the entity rather than a formality completed from a certificate of incorporation.

2. The people associated with the entity. Capture the people who purport to act for the investor, confirm that they are authorised and identify and verify them. Depending on the facts, the file may also need to capture people on whose behalf or for whose benefit an activity is being conducted. A signature page is useful evidence. It does not by itself demonstrate the full authorisation or identity analysis.

3. Beneficial ownership and control. Show the natural persons who ultimately own or control the investor, the ownership route and the evidence that supports the conclusion. This is where entity onboarding becomes a different discipline from individual KYC. KYB is not simply KYC applied to a company: a trust, nominee, partnership or layered holding chain can make the legal investor only the first step in the analysis.

4. Relationship and payment context. Article 25 requires an obliged entity to understand the purpose and intended nature of the relationship. Where necessary, it must obtain information on the economic rationale, estimated activity, source and destination of funds, and the customer's business activity or occupation. For a fund, that means the commercial context should be understandable from the case: the relevant vehicle, anticipated investment activity and payment route should not be left as disconnected fields in a subscription document. It does not mean applying a blanket information request that ignores the risk-based assessment.

5. The evidence and decision. Keep the source documents, registry results, screening outcomes, risk assessment, reviewer rationale, approvals, conditions and unresolved questions with the case. This is also the record that makes a negative decision intelligible. Article 21 requires records of CDD actions, decisions, supporting documents and justifications, including when a relationship is refused or terminated.

Taken together, these records create something a subscription pack cannot: a demonstrable explanation of what the fund knew, how it tested the information and who decided that the relationship could proceed.

Documents only matter when they support a conclusion

The practical failure mode is rarely a complete absence of documents. More often, the documents are present but the link between document, fact and decision is missing.

This is why an effective workflow separates collection from verification and verification from decision. Each item should be tied to the entity, person, relationship or control path it substantiates. Conflicting registry information, an expired identity document, a missing trust deed, an opaque nominee relationship or a payment route that does not match the expected activity should create a visible exception. The workflow should state what is unresolved, who owns the next action and which decision is blocked until it is resolved.

That discipline matters for investor experience as much as for compliance. If a reviewer can see the precise evidence gap, the fund can ask a focused question rather than send a generic request for the full pack again. Fund-of-funds, offshore trusts and multi-layered SPVs are still complex. The difference is that complexity is handled as a defined review path, not as an email chain that grows with every follow-up.

Acceptance is the start of the CDD lifecycle

An accepted investor is not a completed file with a future expiry date. Article 26 requires ongoing monitoring of the business relationship and customer transactions, with information kept up to date. It sets an outside limit of one year between updates for higher-risk customers subject to enhanced due diligence and five years for other customers, alongside reviews when relevant circumstances change or relevant new facts become known.

For funds, the exact monitoring model must reflect the relationship and applicable obligations. The operating principle is consistent: a change in beneficial ownership, authorised representative, payment instruction, investor risk or sanctions status must be able to reopen the right part of the file. Periodic reviews should not begin by asking a team to find the original evidence again. They should begin with a record that already shows what was verified, when it was verified and what has changed since.

The same applies to screening. A potential match is a case decision, not merely a result in a batch report. The reviewer needs the identity and contextual data collected during CDD, a clear rationale for the disposition and a route to escalate further review. Reducing false positives in AML screening depends on that context. A risk-based periodic review process keeps the record usable after the investor has been admitted.

Turn onboarding into a durable investor record

The right system does not make an investor complete the same commercial form repeatedly. It creates an end-to-end record in which collection, verification, exceptions and decisions remain connected. That lets the fund improve the process without weakening the evidence standard.

In Steward, dynamic onboarding can adapt to investor type, jurisdiction, risk and document status. AI-first document review, KYI and KYB checks, plus sanctions and adverse-media screening within the same workflow, help teams organise the evidence around the questions that matter. Reusable profiles can reduce duplicate collection across funds and vehicles, while case management supports document expiry, ongoing monitoring and periodic reviews after approval. Human reviewers retain ownership of the risk and acceptance decisions, with the supporting evidence and rationale held in the record.

The important shift is conceptual. The subscription pack is an input to the relationship. The CDD file is the fund's living account of why that relationship is understood, accepted and kept under review. Under AMLR, that distinction needs to be operational, not merely documented in a policy.