The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · Wealth management

AMLA 2023: no client file stays current forever

How the 2023 AMLA revision turns beneficial-owner checks and client-data updates into focused, traceable and recurring reviews.

Cellule études getfishnetAnalyse des marchés et acquisition client7 min read

A relationship opened ten years ago may appear thoroughly understood. Then a beneficial owner changes, an intermediate company is added, an activity moves or a document expires. Since 1 January 2023, the revised Anti-Money Laundering Act has brought this weakness into sharper focus: the beneficial owner’s identity must be verified and client data reviewed periodically according to risk. The question is no longer simply, “Did we identify the client at onboarding?” It is, “Can we demonstrate that the information remains current?” This article follows a file as it ages, from the first signal to a remediation decision. It explains why a blanket update campaign wastes resources, how to construct an informative sample, which first engagement can be sold without promising compliance and how a one-off review becomes a recurring discipline. For a specialist partner, the value lies in a method that finds fragile files before an audit or event exposes them. General analysis updated on 7 August 2026. It does not replace legal advice, the financial intermediary’s internal rules or a FINMA decision.

What has the revised AMLA actually required since 1 January 2023?

The revised AMLA requires, in particular, verification of the beneficial owner’s identity and periodic checks that client data remains current. The frequency and extent of review must reflect risk. A financial intermediary must therefore be able to explain its method, the events that trigger review and the audit trail left by each decision.

FINMA explained in November 2022 that verification of the beneficial owner is regulated by law and linked to periodic checks that data is up to date. Its ordinance retains the obligation to set out the arrangements for updating and verifying data in an internal directive. Responsibility is therefore clear: the internal rule must result in observable actions in client files.

An identity-document date alone is not enough. Relevance depends on the relationship: control structure, source of wealth, activities, domicile, mandates, politically exposed person status and unusual transactions. These factors do not all require the same frequency, but each must be linked to a source, date and owner.

The first defensible purchase is not a compliance certificate. It is a sample review: read the directive, select files, compare facts with evidence and produce a prioritised remediation plan. The institution remains responsible for its decisions and for any resulting reports.

Two drivers of reviewBar height illustrates priority, not a universal regulatory frequency.
  • Scheduled cycle1
  • Event detected2
How a file loses reliabilityTime alone does not describe risk; an event can make data obsolete before the scheduled review.
  • Stable factVerified information with its source retained
  • Elapsed timeReview date set by the internal directive
  • EventChange in control, activities or behaviour
  • DecisionRetain, refresh, escalate or close

Why does a blanket document-gathering campaign fail to solve the problem?

A blanket campaign fails because it requests the same documents from everyone without accounting for risk or actual changes. It can produce a large volume of paperwork and very little understanding. A useful update starts with facts that may have changed, verifies control relationships and explains when the next review is due.

Sending every client the same form creates three problems. Straightforward files bear an excessive burden; complex structures may reply without revealing the material change; and the team accumulates documents without knowing which discrepancy requires escalation. Effort should be proportionate and directed towards information that changes the institution’s understanding of the client.

Segmentation combines assigned risk, data age, legal complexity and known events. New management, a shareholder change, a transfer of domicile, an unexplained change in flows or a new business relationship may bring the review forward. A stable, lower-risk file can follow its planned cycle without artificial urgency.

SignalQuestionBounded action
Control changedIs the beneficial owner still correctly established?Reconstruct the control chain
New activityDoes the economic profile still explain the transactions?Update activities and source of funds
Data expiredIs the source still reliable and sufficient?Collect and verify the relevant document
Unexpected behaviourShould risk be reassessed or escalated?Document the analysis and its owner

Which sample reveals the true quality of the control framework?

The most informative sample crosses several categories: higher- and lower-risk clients, recent and older files, individuals and structures, and relationships that have or have not been updated. It does more than look for errors. It tests whether the method selects the right files, whether evidence supports decisions and whether exceptions are handled consistently.

A review starts with the full population and the segmentation logic. It then selects files from each segment, including cases considered straightforward. Every file follows the same evidence chain: expected fact, source checked, discrepancy, decision, approval and next deadline. This tests how well the framework works, not merely how tidy the filing is.

The deliverable can be purchased promptly: a sampling matrix, anonymised findings, gap classification and remediation plan. Price, timing and partner capacity must be agreed before the campaign. If file access or confidentiality cannot be controlled, acquisition stops.

How can the beneficial owner be reconstructed without relying on intuition?

Reconstructing the beneficial owner means tracing persons and rights back to the relevant natural person, then retaining the sources and checks performed. If a level remains opaque, the uncertainty must remain visible. A client declaration belongs in the file, but on its own it is not always sufficient evidence.

The analysis starts with the contracting entity, then traces shareholdings, voting rights, control agreements and other means of influence. The result is compared with internal documentation and reliable information available to the institution. A structure is not suspicious because it has several layers; it is poorly controlled when no one can explain the chain or date its verification.

How to read the diagram. The control chain is explained before a conclusion is reached. A discrepancy becomes an assigned gap, never a concealed assumption.

The engagement remains bounded: it prepares the analysis and evidence but does not replace the compliance function’s decision. Cases that may require reporting or enhanced measures are referred to the responsible person under the institution’s procedure.

How can the beneficial owner be reconstructed without relying on intuition?How can the beneficial owner be reconstructed without relying on intuition?
  1. 1Contracting party
  2. 2Intermediate entities and jurisdictions
  3. 3Ownership, voting or control rights
  4. 4Relevant natural person
  5. 5Audit trail, approval and next review
  6. 6Documented gap and escalation
  7. 7Sources consistent?

What first deliverable can be sold without promising compliance?

The first deliverable may be a review of a bounded sample of files, with a gap map and remediation plan. Its value lies in selection, traceability and prioritisation. It neither certifies the entire portfolio nor guarantees the absence of risk or the outcome of an inspection.

The output separates data shortcomings, inconsistencies in the method and execution failures. It shows which issues can be corrected through document collection, which need specialist analysis and which require an internal decision. Recommendations are ordered by risk and effort so that the most visible task does not displace the most important one.

The review may lead to a second engagement: correct the selected files, revise the directive, deliver targeted training or establish periodic controls. Each subsequent service has its own price and completion criterion. This division turns a diffuse obligation into understandable purchases.

Which accounts form a responsible acquisition pool?

The responsible pool comprises financial intermediaries whose volume, complexity or transformation makes updating difficult: authorised asset managers, trustees, growing firms, institutions integrating a client base or businesses changing systems. Outreach targets professional decision-makers. It does not use end-client lists, sensitive data or suspicions.

Public events can help prioritise accounts: an acquisition, merger, new business line, change in management, IT migration or visible workforce growth. None proves an AMLA deficiency. The message offers to test the resilience of the method following a change without presuming a failure.

The wealth management market page connects this article with authorisation and supervision topics. Professional networks, content, specialist events, email and calls have complementary roles. No channel should circumvent confidentiality rules or turn an obligation into a threat.

How can remediation be managed without creating an endless queue?

Remediation is managed through defined batches, assigned risk, an owner and completion criteria. Every file moves between explicit states: awaiting analysis, information requested, verification under way, decision taken or escalated. The number of documents collected is not evidence of progress if discrepancies remain undecided.

A well-managed queue shows the detection date, missing information, owner, expected decision and next action. Blocked cases do not disappear into an “in progress” category; they appear in a dedicated review. Capacity is adjusted to the actual backlog, not the number of emails sent.

Prioritise remediation by risk and effortThe institution owns the classification and must be able to justify it.
  • Higher risk / lower effortaction: Correct immediately
  • Higher risk / higher effortaction: Escalate and reserve capacity
  • Lower risk / lower effortaction: Process in a controlled batch
  • Lower risk / higher effortaction: Plan and reconfirm priority

When does a one-off review become usefully recurring?

Recurrence becomes useful when it follows the client’s risk calendar and relevant events. It may take the form of a quarterly sample control, annual review or event-triggered intervention. It is legitimate only when each cycle produces a distinct decision and the institution retains ownership of its method.

The partner can maintain quality through a review calendar, event monitoring, controls over closed files and exception tracking. The relationship renews because data changes, not because a subscription was signed without a clear completion point. Recurring revenue is recognised only after a new cycle has been invoiced and paid.

Commercial reporting follows paid diagnostics, conversion time, delivery margin, the proportion of files leading to action and justified renewal. Replies, meetings and downloads remain indicators. No confidential figures are invented to illustrate performance.

What conditions make this acquisition approach acceptable?

This acquisition approach requires a competent partner, appropriate insurance, secure access, confidentiality rules, confirmed capacity and an escalation mechanism. Price, timing and scope must be clear before contact begins. Without these elements, the topic remains at partner-research stage and no campaign is launched.

The authoritative sources used are FINMA, the Anti-Money Laundering Act, the FINMA Anti-Money Laundering Ordinance and published audit points. They describe obligations and expected audit trails. They promise neither compliance nor service prices or an accessible volume of mandates.

How can you check free of charge whether a similar strategy suits your offer?

The complimentary eligibility test examines your acquisition challenge, account pool, initial sample, exchange security and remediation capacity. It does not certify an AMLA framework. It determines whether getfishnet and your team have sufficient alignment to build a tailored strategy.

Editorial provenance

Cellule études getfishnetAnalyse des marchés et acquisition clientPublished Updated

Sources used

  1. FINMA, Ordonnance sur le blanchiment d’argent révisée
  2. FINMA, Points d’audit LBA 2023
  3. Conseil fédéral, Mise en vigueur de la LBA révisée
Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Can a data-update obligation become a clear engagement?

Tell us about your offer, acquisition challenges and capacity. We provide a 100% free eligibility assessment to test the fit and, where appropriate, develop a tailored strategy.

Check my eligibility free
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité