The Investment Adviser AML Rule Moved to 2028. Here's Why U.S. RIAs Should Build Now Anyway
The two-year delay is not a reprieve. A practical build plan for RIAs and exempt reporting advisers ahead of January 1, 2028.
Rodolfo Santos
Real Estate Compliance Attorney & Co-Founder, VeriKYC

A Two-Year Delay Is Not a Two-Year Vacation
On December 31, 2025, FinCEN issued a final rule moving the effective date of the Investment Adviser AML Rule from January 1, 2026 to January 1, 2028. For thousands of registered investment advisers and exempt reporting advisers who had spent the previous year building compliance programs against a fast-approaching deadline, the announcement landed as relief.
It should not have. The delay changed the calendar. It did not change the destination.
The substance of the rule remains intact. Covered investment advisers will still be classified as "financial institutions" under the Bank Secrecy Act. They will still be required to establish risk-based AML/CFT programs, file suspicious activity reports, comply with recordkeeping and Travel Rule obligations, and respond to information requests under Section 314(a). FinCEN has stated its intention to review and potentially tailor the rule's scope during the extended period, but tailoring is not repeal, and the direction of travel in U.S. financial regulation has been consistent for two decades.
More importantly, the delay does not suspend the underlying risk. An adviser that onboards a limited partner whose capital originates from a sanctioned party has a problem in 2026 that has nothing to do with whether the IA AML Rule is technically in effect. Sanctions obligations under OFAC apply to every U.S. person regardless of BSA status. Fraud exposure, reputational harm, and limited partner side-letter representations about AML controls are all live today.
This article lays out what the rule actually requires, what the intervening period should be used for, and how to build a program that will not need rebuilding when FinCEN finalizes its review.
What the Rule Requires
The IA AML Rule extends the core BSA framework to covered advisers. The obligations fall into five broad categories.
A written, risk-based AML/CFT program
The program must be reasonably designed to prevent the adviser from being used to facilitate money laundering or terrorist financing. "Reasonably designed" is doing a lot of work in that sentence. It means the program must reflect the adviser's actual business: its investor base, its strategies, its geographic footprint, and the channels through which capital arrives.
A venture firm raising from domestic institutional LPs and a multi-strategy fund accepting subscriptions from offshore feeder vehicles have materially different risk profiles. A program that does not distinguish between them is a template, and examiners recognize templates on sight.
The program must be approved in writing by the adviser's board of directors or equivalent governing body, a governance step that is frequently overlooked and trivially easy for an examiner to check.
Suspicious activity reporting
Covered advisers must file SARs for transactions involving at least $5,000 that the adviser knows, suspects, or has reason to suspect involve funds derived from illegal activity, are designed to evade BSA requirements, have no apparent lawful purpose, or involve use of the adviser to facilitate criminal activity.
SAR obligations carry a strict confidentiality requirement. An adviser cannot notify the subject that a report has been filed. Building an internal escalation process that preserves confidentiality while allowing genuine investigation is one of the harder design problems in the whole framework.
Recordkeeping and the Travel Rule
Advisers must comply with recordkeeping requirements for transmittals of funds, including the Travel Rule obligation to pass specified originator and beneficiary information along the payment chain for transmittals of $3,000 or more.
Information sharing
Section 314(a) requires financial institutions to search their records in response to law enforcement requests routed through FinCEN. Section 314(b) permits voluntary information sharing between institutions with safe harbor protection. Both require infrastructure: the ability to search investor records comprehensively and quickly is not something most advisers currently possess.
The program pillars
The AML program itself must include internal policies and procedures, a designated AML compliance officer, ongoing employee training, independent testing of the program, and risk-based procedures for conducting ongoing customer due diligence.
Note what is not in the final rule as adopted: a full customer identification program requirement. FinCEN and the SEC jointly proposed a CIP rule for investment advisers in 2024, and that rulemaking remains pending. Advisers should assume a CIP obligation is coming and design their investor onboarding accordingly, rather than building a program that will need a second implementation phase.
Who Is Covered, and Who Is Not
The rule as adopted applies to investment advisers registered with the SEC and to exempt reporting advisers. It does not apply to state-registered advisers, to advisers that report no assets under management on Form ADV, or to advisers that do not have a place of business in the United States and meet certain conditions.
The inclusion of exempt reporting advisers was, and remains, the most contentious element. ERAs, principally venture capital fund advisers and private fund advisers below the $150 million threshold, are by definition smaller and less resourced. Requiring them to stand up full BSA programs was a significant expansion of the regulatory perimeter, and it is the aspect of the rule FinCEN has most clearly signaled it may revisit.
There are also carve-outs worth understanding. The rule permits an adviser to exclude from its program certain advisory activity, including advice to mutual funds and to bank- and trust-company-sponsored collective investment funds, on the theory that those vehicles have their own AML obligations. And an adviser may delegate implementation of its program to a third party (an administrator, for example) while retaining full responsibility for compliance.
That last point deserves emphasis. Delegation is not transfer. An adviser whose fund administrator performs investor onboarding remains responsible for whether that onboarding meets BSA standards. If the administrator's process is inadequate, the adviser is deficient. Oversight of delegated functions is itself a program requirement, and it is where a substantial number of advisers will be found wanting.
Why the SEC Still Matters in 2026
Some advisers have concluded that with the IA AML Rule pushed to 2028, AML is off the examination agenda. That reading is too convenient.
The SEC's 2026 examination priorities explicitly confirm that compliance with the adopted IA AML rules is not a focus for investment advisers, given the extended date. But the same document maintains AML as a priority for broker-dealers and certain registered investment companies, examining whether firms appropriately tailor programs to their business model, conduct adequate independent testing, establish customer identification procedures, verify beneficial owners of legal entity customers, file SARs when required, and screen against OFAC sanctions lists.
For advisers, three exposures remain fully live in 2026:
Sanctions compliance. OFAC obligations do not derive from the BSA. Every U.S. person is prohibited from transacting with blocked persons, and the prohibition is strict liability. An adviser with no sanctions screening at all is exposed today.
Fiduciary duty and compliance program adequacy. Rule 206(4)-7 requires advisers to adopt policies reasonably designed to prevent violations of the Advisers Act. Where an adviser has told investors, in a private placement memorandum or a side letter, that it performs AML diligence, failing to do so is a compliance program failure regardless of BSA status.
Investor and counterparty expectations. Institutional LPs, banks providing subscription lines, and fund administrators increasingly require documented AML controls as a condition of doing business. The commercial deadline often precedes the regulatory one.
How to Use the Extended Runway
The advisers who will be in the best position on January 1, 2028 are not those who start in mid-2027. They are those who use the intervening period to build deliberately rather than under deadline pressure.
Complete a real risk assessment
The risk assessment is the foundation of everything else, and it is the document examiners read first. It should identify, for the adviser's actual business: investor types and their risk characteristics; geographic exposure, including the jurisdictions from which capital originates and where portfolio investments sit; product and strategy risks; distribution channels, including placement agents and intermediaries; and the specific ways in which the adviser could plausibly be used to launder money.
That last element is where most risk assessments fail. They catalogue risk factors without ever articulating a threat model. An assessment that cannot answer "how would a bad actor actually use us?" has not done its job.
Fix the data problem before the process problem
Most advisers discover, when they begin building, that they cannot answer basic questions about their existing investor base. Who are the beneficial owners of the LP entities in Fund II? Which investors were onboarded before the current subscription document was adopted? Where are the identity documents for investors who came in through a feeder?
Remediation of legacy investor records takes far longer than anyone estimates. Starting that work in 2026 rather than 2027 is the single most valuable use of the delay.
Design for the CIP rule you do not yet have
The joint FinCEN-SEC CIP proposal would require advisers to establish procedures for verifying the identity of each customer sufficient to form a reasonable belief that they know the customer's true identity. Building an onboarding process now that collects and verifies identity documents, screens against sanctions and PEP lists, and resolves beneficial ownership for entity investors means the eventual CIP rule is a documentation exercise rather than a rebuild.
Choose your operating model
There are three viable models. Build internally, which suits large advisers with existing compliance infrastructure. Delegate to an administrator, which suits advisers whose administrator has genuine BSA capability, and requires real oversight. Or adopt a compliance platform that handles verification, screening, ownership resolution, and audit trail generation while keeping decisions with the adviser's own compliance function.
For most mid-sized advisers, the third model is the pragmatic answer. It avoids the cost of internal build and the oversight burden of full delegation, while producing exactly the artifact examiners want: a complete, timestamped, reviewable record of what was checked, by whom, and when.
What the Rule Might Look Like in Its Final Form
FinCEN has been explicit that it intends to tailor the rule to the diverse business models and risk profiles within the adviser sector. Reasonable predictions:
The ERA scope is the most likely element to narrow. A venture firm advising three funds with two dozen institutional LPs presents a materially different risk profile than a global multi-strategy manager, and the industry comment record on this point was substantial.
Sequencing with the CIP rulemaking is likely. FinCEN acknowledged commenter concerns about timing, and a coordinated effective date for the AML program requirement and the CIP requirement would be the sensible outcome.
Some form of tiering or proportionality is plausible: reduced obligations for advisers below a size threshold, or for advisers whose investor base consists entirely of institutional accredited investors already subject to their own AML regimes.
What is not plausible is repeal. The Anti-Money Laundering Act of 2020 directed Treasury toward exactly this expansion, the investment adviser sector has been identified as a gap in U.S. AML coverage in successive Treasury risk assessments, and the international standard-setting environment expects coverage.
Conclusion: Build the Thing You Will Need Anyway
The best argument for building now is not regulatory. It is that every component of an IA AML program is something a well-run adviser should have regardless.
Knowing who your investors actually are is not a compliance nicety. It is basic operational hygiene, and its absence surfaces at the worst possible moments: during a subscription line negotiation, in a due diligence questionnaire from a prospective institutional LP, or when a name in your investor register appears in a news story.
Being able to produce, on demand, a complete record of the verification performed on any investor is not bureaucratic overhead. It is the difference between a two-week examination and a six-month one.
Screening every investor and every beneficial owner against sanctions lists at onboarding and on an ongoing basis is not optional in 2026. It is already required, by a body of law entirely separate from the rule that was delayed.
January 1, 2028 will arrive faster than it currently appears. The advisers who treat the delay as breathing room rather than a reprieve will spend that morning confirming that their program works. The ones who treated it as a reprieve will spend it explaining why they have not started.
Rodolfo Santos
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of VeriKYC, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.