One Constellation
White Paper

Cross-Border AML for Fund Administrators: MAS, HKMA and CSSF Compared

A fund administrator operating in Singapore, Hong Kong and Luxembourg answers to three supervisors whose requirements descend from the same FATF standards but diverge in the places that shape operations. This paper maps where they align, where they genuinely differ, and how to build one control spine rather than three programmes.

Published: September 2026 Section: White Papers Read time: ~13 minutes
Executive Summary
All three regimes descend from the FATF Recommendations, so the architecture is common: risk-based approach, CDD with beneficial ownership, enhanced measures for higher risk, ongoing monitoring, suspicious reporting, record keeping and independent audit. The divergence is in thresholds, PEP treatment, reporting channel and supervisory reporting. The operating answer is a single control spine calibrated per entity — not three parallel programmes, which is how firms end up with three different standards of file and no consolidated view of an investor who appears in all three.

Fund administration is structurally cross-border. A manager in one jurisdiction, a fund domiciled in another, investors in a dozen more, and an administrator regulated in each place it operates. The AML obligation attaches in each of those places, to the same underlying investors.

Most firms handle this by running programmes locally. It works until someone asks a question that spans them — which is precisely what harmonised supervisory reporting now does.

What Is Genuinely Common

More than firms expect. All three supervisors require:

  • A documented, current enterprise-wide risk assessment covering customers, jurisdictions, products and delivery channels.
  • CDD with identification and verification, and identification of beneficial owners with reasonable measures to verify.
  • Enhanced due diligence for higher-risk relationships, including PEPs.
  • Ongoing monitoring proportionate to assessed risk.
  • Suspicious transaction reporting to the national FIU.
  • Record keeping, commonly five years, and independent audit of the programme.

A control designed to satisfy the strictest of the three will generally satisfy the others. That is the basis of the single-spine approach.

Where They Diverge — PEPs

This is the most consequential divergence and the most frequently mishandled.

FATF Recommendation 12 makes enhanced measures mandatory for foreign PEPs but permits a risk-sensitive approach for domestic and international-organisation PEPs. The MAS Notices do not replicate that split — the same enhanced measures apply to domestic, foreign and international-organisation PEPs, and to their family members and close associates.

A group that configures its platform centrally to the FATF minimum is therefore under-compliant on its Singapore book by construction. The detail is in PEP categories and RCAs.

Where They Diverge — Reporting Channel

Each jurisdiction has its own FIU and its own submission route:

  • Singapore — the Suspicious Transaction Reporting Office, part of the Commercial Affairs Department, via its SONAR platform.
  • Hong Kong — the Joint Financial Intelligence Unit.
  • Luxembourg — the Cellule de Renseignement Financier.

The internal process — escalation to the MLRO, the decision, the no-tipping-off constraint, the record of reports not filed — is common. Only the submission differs. Building three separate case workflows to accommodate three submission formats is a common and avoidable mistake.

Where They Diverge — Supervisory Reporting

The newest and fastest-moving divergence. The CSSF now collects AML/CFT risk data using AMLA templates, submitted through eDesk, as part of the move toward harmonised European supervision. That means Luxembourg entities must produce structured risk-distribution and alert-outcome data on a defined cadence, comparable against peers across the Union.

Singapore and Hong Kong supervise on-site and through their own returns rather than a common European dataset. The operational consequence is that the Luxembourg entity has a data-production requirement the others do not — and satisfying it from spreadsheets does not scale.

The Fund-Specific Problem

Everything above assumes you can say who the customer is. In fund administration that is genuinely difficult:

  • Is the customer the fund, the manager, or the investor? Frequently all three are relationships with different obligations.
  • Investors may be nominees, feeders or platforms, with the natural person several layers removed.
  • The same underlying investor may appear across multiple funds administered by the same entity, in different jurisdictions.

If that investor is rated high risk in one fund and standard in another, the firm has two problems: an indefensible aggregate position, and an EDD obligation it may be discharging in one place and not the other. Resolving ownership once and holding one rating per natural person is the only tractable approach — see UBO discovery.

Designing the Single Spine

Four principles:

  1. Build to the strictest standard, calibrate down deliberately. Apply MAS-level PEP treatment everywhere unless a documented decision says otherwise. Uplift is cheap; retrofit is not.
  2. One investor record, many relationships. The natural person is resolved once; fund relationships attach to that record.
  3. Common case workflow, per-jurisdiction output. One escalation and decision process; the submission format varies at the last step.
  4. Entity-level parameters, group-level model. Thresholds and obligations differ per entity; the risk model and data structure do not.

Group Policy and the Home/Host Problem

Each of the three regimes expects a group-level AML policy extended to branches and subsidiaries, with a defined approach where local requirements differ. The MAS Notices set this out explicitly for Singapore-incorporated institutions.

The general principle is straightforward: apply the higher standard. Where the host jurisdiction’s requirement is stricter, follow it; where the group standard is stricter, apply the group standard. The difficulty arises when a local requirement actively conflicts rather than merely differing — data protection or secrecy rules that restrict what can be shared with the group being the usual example.

Those cases need to be identified, documented, and escalated rather than resolved informally by a local team. A supervisor asking how group policy applies in a restricted jurisdiction expects a considered answer with a record, not an admission that the local office decided for itself.

Practically, maintain a divergence register: every place where local practice departs from group standard, why, who approved it, and when it was last reviewed. It is a short document that answers a long line of questioning.

Reliance, Outsourcing and Delegation

Fund administration runs on delegation — to transfer agents, distributors, and other administrators — and every one of those arrangements raises the same question: who performed the due diligence, and can you evidence it?

All three regimes permit reliance on third parties within limits, and all three keep the obligation with the relying firm. The recurring failures are consistent:

  • Records not obtainable without delay. Reliance requires that you can get the underlying CDD documentation promptly. An arrangement where the distributor holds everything and responds in weeks does not meet that test.
  • No assurance activity. A contractual commitment with no sampling, no testing and no periodic review produces no evidence that the delegate actually did the work.
  • Chains of reliance. Where a distributor itself relies on a sub-distributor, the chain frequently breaks. Map it, and know where it terminates in an entity that actually performed identification.
  • Standard mismatch. A delegate applying its own home standard may be below yours — particularly on PEP treatment, where the FATF-minimum versus MAS divergence bites directly.

For a cross-border administrator this is usually the largest practical exposure in the programme, precisely because it sits outside the systems you control.

What Good Looks Like Under Inspection

An inspector in any of the three jurisdictions should be able to take an investor file and see: how the ownership chain was resolved and when; why the risk rating is what it is; what enhanced measures were applied and who approved them; what monitoring has run since; and what was decided on any alert, with reasoning.

They should not be able to tell from the quality of that file which jurisdiction it was created in. Where they can, the firm has three programmes rather than one — and the weakest of them sets the group’s reputational exposure.

One Control Spine, Three Supervisors

Resolve ownership once, hold one rating per investor across funds and jurisdictions, and produce the file each of MAS, the HKMA and the CSSF expects — from a single workflow.

MAS Requirements → HKMA Requirements EU Framework All White Papers
Scroll to Top