Skip to content
Normfin

Which AML obligations belong to your custodian, and which ones are yours

Your custodian’s anti-money-laundering program and your own advisory firm’s are two separate obligations, running under two different sections of the same underlying law, and FinCEN said so in writing when an adviser asked, during the rulemaking, to be allowed to rely on the custodian’s program instead of building its own.

Why this looks like double coverage, and where that reading breaks

Most advisory firms with no direct custody use a broker-dealer or a bank as their qualified custodian, and that custodian has carried its own Bank Secrecy Act anti-money-laundering obligation for two decades already: 31 CFR 1023.210 for a broker-dealer custodian, 31 CFR 1020.210 for a bank one. Both of those programs already require the same five things FinCEN’s new rule for investment advisers requires: written policies and internal controls, independent testing, a designated compliance officer, ongoing training, and risk-based customer due diligence. Seeing the same five-item shape on both sides is exactly what makes “surely this is already covered” feel reasonable. It is also exactly where the reasoning breaks: two programs sharing the same shape are still two separate programs, built for two separate legal relationships, examined against two separate sets of customers.

The exact question FinCEN was asked, and its exact answer

During the comment period on the new adviser rule, more than one commenter asked FinCEN directly to let an adviser rely on another financial institution’s AML measures instead of building its own, naming the custodian relationship specifically. One commenter “requested that FinCEN expressly permit an investment adviser’s AML/CFT program to contractually rely on diligence conducted by another covered financial institution.” FinCEN’s final rule answered in the same paragraph: “Regarding certain suggestions that FinCEN permit advisers to expressly rely on diligence or AML/CFT measures by other financial institutions, service providers, or other intermediaries, FinCEN declines to do so” (89 FR 72156, p. 72189, September 4, 2024). The same passage continues: when an adviser delegates part of its program’s operation to a service provider, “the adviser will remain responsible for overall compliance with these requirements.” That is not a general policy statement about outsourcing. It is a direct answer to the exact question this page is titled after.

Same five pillars, two separate programs, side by side

Program elementYour custodian’s obligation (31 CFR 1023.210 or 1020.210)Your own obligation (31 CFR 1032.210, effective January 1, 2028)
Written policies, procedures, controlsCovers the custodian’s own accountholders and its own transaction flow across every client it custodies for, not any one advisory relationship in particularMust be built around YOUR firm’s own advisory customers and the risk factors YOUR own Form ADV discloses, something the custodian’s program was never designed to see
Independent testingTests whether the custodian’s own program works. Tells you nothing about whether your firm’s program, if you have not built one, exists at allA separate test of a program only your firm can build, since the custodian has no advisory-side program to test on your behalf
Designated compliance officerReports up through the custodian’s own management chain, with no visibility into or authority over your firm’s advisory bookMust be your own designated person, one FinCEN expects to be “knowledgeable and competent regarding AML/CFT requirements” for YOUR business, not the custodian’s
Ongoing trainingTrains custodian staff on custodian-side risks: account opening, funds movement, its own customer baseMust train YOUR employees on YOUR firm’s own advisory risks, something a custodian’s training program was never built to cover
Risk-based customer due diligenceKeyed to the custodial account relationship the custodian itself holdsKeyed to the advisory relationship and the specific risk factors your own filing discloses (private funds, wrap fee programs, foreign regulator ties, paid solicitors), none of which a custodian’s CDD process is built to capture

What you can delegate, and what never moves

FinCEN’s final rule does allow an adviser to delegate the implementation and day-to-day operation of parts of its program to a third party, and that third party can include a custodian in practice, though the rule’s own delegation discussion is written around service providers and fund administrators generally, not custodians specifically: “FinCEN will permit an investment adviser to delegate contractually the implementation and operation of some or all aspects of its AML/CFT program to a third-party provider” (89 FR 72156, p. 72188). What does not move with that delegation is responsibility. The same passage is explicit that the adviser “will remain fully responsible and legally liable for, and be required to demonstrate to examiners, the program’s compliance with AML/CFT requirements” (p. 72189). A certification from a service provider that it “has a satisfactory anti-money laundering program” is not, on its own, enough; FinCEN’s rule treats that kind of certification as one input into the adviser’s own periodic oversight, not a substitute for having a program at all.

When the custodian is a related person, the assumption gets stronger, and the answer does not change

1,154 firms in the current roster (see the calculated number above) report that a RELATED person, not an independent third party, holds their clients’ assets. That is the case where “surely they already cover this” is hardest to argue with on the surface: the entity holding the assets is not a stranger you hired, it is your own affiliate. FinCEN’s rule does not carve out an exception for that either. An adviser in this position still needs its own program, and that program additionally has to describe, in writing, the division of AML/CFT responsibilities between the adviser and its related custodian, since FinCEN’s refusal to let one institution’s measures substitute for another’s applies to a related person exactly the same way it applies to an unrelated one.

FAQ

Is this the same question as “does my custodian handle AML for my RIA”? Yes, same underlying question. The existing short page on this site (/use-cases/does-my-custodian-already-handle-aml-for-me) gives the one-paragraph answer with the headline quote. This page is the itemized version: the actual CFR sections on both sides, the side-by-side table, and what specifically can and cannot be handed off. Can I point to my custodian’s own AML program during an exam? You can cite it as part of the overall picture, and FinCEN’s rule text treats a service provider’s certification as something you can factor into your own periodic oversight. It is not, on its own, a substitute for having your own written program, your own designated officer, your own training, and your own testing. My custodian is an affiliate of my firm. Does that change anything? No. FinCEN’s rule does not exempt a related-person custodian from this analysis; if anything, your own written program needs to be more explicit about where your firm’s responsibilities end and your affiliate’s begin, precisely because the two entities are close enough that the line is easy to blur informally. Where do these citations come from? Every quote above is from the Federal Register text of the final rule itself, page-cited. See Sources below. Is this legal advice? No. This is independent research reading the Federal Register text against a firm’s own public Form ADV data. It does not replace counsel and makes no promise about any specific firm’s compliance status. Whether your own firm is in scope, and which risk factors apply to it, is what the checker at normfin.com reads off the SEC’s own adviser roster.

Sources (primary, dated)

- Financial Crimes Enforcement Network, “Anti-Money Laundering/Countering the Financing of Terrorism Program and Suspicious Activity Report Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers,” 89 FR 72156 to 72278, published September 4, 2024, RIN 1506-AB58, 31 CFR Parts 1010 and 1032. https://www.federalregister.gov/documents/2024/09/04/2024-19260/ - Custodian-reliance refusal, verified verbatim against the full text on 2026-08-23: “Regarding certain suggestions that FinCEN permit advisers to expressly rely on diligence or AML/CFT measures by other financial institutions, service providers, or other intermediaries, FinCEN declines to do so,” printed page 72189. - Delegation permitted, responsibility does not transfer: “FinCEN will permit an investment adviser to delegate contractually the implementation and operation of some or all aspects of its AML/CFT program to a third-party provider,” printed page 72188, and “the adviser will remain fully responsible and legally liable for... the program’s compliance,” printed page 72189. - 31 CFR 1023.210, Anti-money laundering program requirements for brokers or dealers in securities, current text via Cornell Law’s Legal Information Institute (law.cornell.edu/cfr/text/31/1023.210), read 2026-08-23. Five elements: policies/procedures/ controls, independent testing, a designated individual, ongoing training, risk-based CDD. - 31 CFR 1020.210, Anti-money laundering program requirements for banks, same structure, confirmed 2026-08-23. - SEC investment adviser public roster, sec.gov/help/foiadocsinvafoiahtm.html, roster dated 2026-08-03 per ~/Code/normfin/data/meta.json, filtered per ~/Code/normfin/scripts/build-data.ts. Custody cross-tab computed 2026-08-23, method and code shown above. - staged/praxtrust/seo/aio-queries.txt, AI Overview measurement dated 2026-08-20, for the seed query’s AIO status only (see “AI Overview risk” above for what this does and does not cover).

Published by Neige AI, Inc., last reviewed August 25, 2026. See the method and sources.

This page is independent research, not legal advice. It quotes FinCEN’s own rulemaking with pinpoint citations. Verify anything load-bearing against the Federal Register text itself before acting on it.