NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Insights11 min read· July 23, 2026

KYC and AML Compliance for External Asset Managers (EAM): The 2026 Playbook

External Asset Managers carry a full compliance burden with a fraction of a bank's resources, and they document the same client three to five times across every custodian bank they use. Here is how a shared, automated compliance layer removes the duplication, satisfies revised art. 37 AMLO-FINMA, and prepares EAMs for the 2026 regulatory shift.

by Wecan

External Asset Managers occupy a difficult position in the compliance landscape. They carry the full weight of anti-money-laundering obligations that apply to any financial intermediary, but they do so with small teams — often one or two people wearing the compliance hat alongside everything else — and they depend entirely on custodian banks to hold client assets and settle transactions. The result is a structural problem the industry rarely names: the same end client is documented three, four, or five times, once for every custodian bank the EAM works with.

This article explains why compliance is uniquely hard for EAMs, what the revised art. 37 AMLO-FINMA on payable-through accounts now requires operationally, and how a shared, automated compliance layer removes the duplicated-KYC tax while preparing the firm for the 2026 regulatory shift toward demonstrable effectiveness.

1. Why compliance is structurally harder for an EAM

A bank runs its compliance function with dozens or hundreds of specialists, a dedicated MLRO office, purpose-built screening infrastructure, and an audit budget to match. An External Asset Manager delivers substantially the same due diligence with none of that scale.

Small teams, full obligations

Since the entry into force of FinIA and the licensing of portfolio managers under FINMA supervision (via a supervisory organisation), EAMs are held to the same substantive AML standard as any other financial intermediary: identify the client, establish the beneficial owner, build a risk profile, screen against sanctions and PEP lists, monitor the relationship on an ongoing basis, and conduct periodic reviews at a cadence set by risk. What differs is the resource base. A firm managing CHF 300–800 million for 150–300 relationships may have one dedicated compliance officer, or none — the managing partner absorbs the role. The obligation does not shrink to fit the team.

Dependence on multiple custodian banks

An EAM does not custody assets. Client portfolios sit at custodian banks — typically three to five of them, because clients arrive with existing banking relationships, because the firm wants counterparty diversification, and because different banks offer different market access and pricing. Each of those banks is itself a financial intermediary with its own AML obligations, its own onboarding forms, its own document standards, and its own view of the same end client.

This is the root of the EAM compliance problem. The client is one person. The KYC file is built many times.

2. Payable-through accounts and revised art. 37 AMLO-FINMA

The regulatory framework has made explicit what was already operational reality. In its partial revision of the Anti-Money Laundering Ordinance-FINMA — consulted on between 12 May and 9 June 2026 — the regulator reinforced the rules on payable-through accounts and sub-accounts. Under revised art. 37 AMLO-FINMA, a financial intermediary may only execute payments on behalf of a counterparty's clients where the counterparty provides the necessary client due-diligence information, including the KYC profile of the end clients.

What this means operationally for an EAM

An EAM instructing a custodian bank to move money for an end client is, in the relevant sense, asking the bank to act for a party the bank does not directly onboard. The bank cannot simply take the instruction on trust. It needs the underlying client due diligence — identity, beneficial owner, source of funds and wealth, risk classification — and it needs to be able to evidence that it holds it.

In practice this converts a soft expectation into a hard gate: no adequate KYC transfer, no smooth execution. If the EAM cannot hand the custodian a complete, current, well-structured due-diligence package, the bank either refuses the account relationship, restricts it, or spends weeks rebuilding the file itself — delaying the client's first trade and eroding the relationship the EAM was hired to protect.

The information the bank actually needs

The bank needs the same core dossier the EAM already holds: certified identification of the contracting party, the beneficial-ownership determination, the client risk profile and its rationale, sanctions and PEP screening results, and the documentary evidence behind each. The problem is never that the EAM lacks this information. The problem is that it lives in the EAM's files in the EAM's format, and every bank wants it in the bank's format, re-attested, on the bank's forms.

3. The duplicated-KYC tax

When a client is onboarded across four custodian banks, the EAM effectively runs the KYC process four times. Documents are re-requested from the client, re-certified, re-keyed into four sets of forms, and re-screened. Every subsequent change — a new address, a renewed passport, a change of beneficial owner, a fresh source-of-wealth attestation — must be propagated to all four banks, on each bank's timeline.

The cost is both financial and relational. Financially, it multiplies analyst hours and cost-per-client by the number of banks. Relationally, it turns the EAM's most valuable clients into the ones asked most often for the same paperwork.

Duplication metric Per bank (manual) Same client across 4 banks (manual) Collect once, share (Wecan Comply)
Document requests to the client 1 full set Up to 4 near-identical sets 1 set, reused
Analyst hours per onboarding 4–7 hours 16–28 hours 3–5 hours total
Elapsed time to first trade 15–21 days 15–21 days per bank, often staggered 2–3 hours once the shared file is live
Cost per client (onboarding) CHF 300–800 CHF 1,200–3,200 CHF 50–150
Propagating one client update 1 update 4 separate updates 1 update, pushed to all

The bottom two rows are where EAMs feel the pain most acutely. A CHF 300–800 onboarding cost is a known quantity; the same cost multiplied by four or five banks, plus the recurring drag of propagating every future change, is the hidden tax that quietly consumes a small team's capacity.

4. What a shared, automated compliance layer changes

The fix is not to work faster inside the duplication — it is to remove the duplication. A shared compliance layer treats the end client's due-diligence file as a single, authoritative, continuously maintained record that the EAM collects once and shares, in each recipient's required form, with every custodian bank connected to the relationship.

Collect once

The client provides documents and information a single time through a secure digital flow. OCR and NLP extract and structure the data; beneficial-ownership chains are constructed automatically from registry data; sanctions and PEP screening runs with contextual scoring that suppresses the industry's flood of false positives. The output is one clean, structured, evidenced dossier.

Share with each bank

That single dossier is then delivered to each custodian bank in the shape the bank needs, with the specific attestations and evidence each institution requires for its own art. 37 AMLO-FINMA obligations. The EAM stops re-keying the same client into four different form sets. The bank receives due diligence it can rely on and evidence, which is precisely what the revised ordinance expects before it executes on the client's behalf.

Keep continuously updated

When a client's circumstances change, the update is entered once and propagated to every connected bank. This is the operating model behind perpetual KYC (pKYC) — continuous, event-driven due diligence that replaces scheduled periodic reviews. Early adopters remove 70–90% of manual periodic-review work, because the file is never allowed to drift out of date in the first place.

5. The numbers for a typical EAM

The metrics that matter to a bank scaling onboarding volume matter differently to an EAM: the constraint is not client count, it is a two-person team documenting each client across several banks. The per-client and per-analyst gains are therefore where the case is made.

Metric Manual Automated (Wecan Comply) Improvement
Standard KYC onboarding (per bank) 15–21 days 2–3 hours −97%
Document collection 5–10 days Under 24h −90%
UBO identification 2–4 hours Minutes −95%
Sanctions/PEP false-positive rate 90–99% 20–25% ≈ −75 pts
Periodic review per file 2–4 hours 20–45 min −70%
Cost per onboarded client (per bank) CHF 300–800 CHF 50–150 ≈ −75%
Clients per analyst per month 15–25 80–120 ~4–5×

Consider a representative firm: 250 relationships, an average of 3 custodian banks per client, and 2 people covering compliance alongside advisory duties. Under the manual model, each new relationship costs 12–21 analyst hours once duplicated across three banks; onboarding a modest 40 new relationships a year consumes the better part of one full-time equivalent purely in re-documentation. Add periodic reviews across the existing book — 250 clients × 3 banks × 2–4 hours — and the two-person team is structurally underwater before it does any actual advising.

A shared layer changes the arithmetic. Collecting once and sharing removes the ×3 multiplier outright; contextual screening cuts false-positive triage by roughly three-quarters; pKYC removes most of the periodic-review load. In practice, the same two people move from firefighting duplication to supervising a maintained, bank-ready book — recovering the equivalent of a full analyst's capacity without hiring one, at a time when a KYC analyst in Switzerland costs CHF 80,000–110,000 per year loaded and takes 6–12 weeks to recruit.

6. Regulatory pressure in 2026

Two shifts make the shared-layer model less a convenience than a necessity for EAMs this year.

From tick-box to demonstrable effectiveness

Supervisors are moving decisively from asking whether controls exist to asking whether they work. The 2026 expectation is demonstrable effectiveness: decisions that are traceable, timely, and evidence-based, applied consistently across the entire book. For a small EAM team, consistency across a portfolio documented manually and separately at several banks is exactly the thing that is hardest to prove. A single authoritative record, with a full audit trail of who collected what, when, and what changed, is what turns an inspection from an anxiety into an export.

Beneficial-ownership transparency: LETA and revised AMLA

From 1 October 2026, the Legal Entities Transparency Act (LETA), alongside the revised Anti-Money Laundering Act, introduces a federal beneficial-ownership register and obliges intermediaries to identify the natural person who ultimately controls a legal entity — regardless of how many layered or offshore structures sit in between — with lowered thresholds and expanded beneficial-ownership capture. EAMs must update their onboarding and KYC procedures accordingly. For firms serving clients with holding companies, trusts, or cross-border structures — which describes a large share of the EAM client base — the manual burden of re-establishing beneficial ownership across every custodian bank is precisely the work that automated, registry-connected UBO resolution is built to absorb.

Regulatory driver (2026) What it demands Manual exposure for an EAM With a shared, automated layer
Revised art. 37 AMLO-FINMA KYC profile of end clients supplied to the executing bank Rebuild the file per bank, on request One authoritative dossier, shared in each bank's format
LETA + revised AMLA Identify ultimate natural-person owner; register beneficial ownership Re-map UBO chains manually, per bank Registry-connected UBO resolution, updated once
Effectiveness over tick-box Traceable, timely, consistent, evidenced decisions Hard to prove across separate files Full audit trail on a single record

7. How Wecan helps EAMs and connects them to custodian banks

Wecan Comply is built for exactly this shape of problem. It gives an External Asset Manager a single, authoritative, continuously maintained due-diligence record for each end client — collected once through a secure digital flow, structured automatically, and screened with contextual scoring that keeps false positives low enough for a small team to handle.

Crucially, Wecan sits between the EAM and its custodian banks. The same maintained record is shared with each connected bank in the form that bank requires, giving the institution the client due-diligence information it now needs under revised art. 37 AMLO-FINMA before it executes on the client's behalf. When a client's circumstances change, the EAM updates once and the change propagates to every connected bank, keeping each dossier current and each relationship inspection-ready.

For a small team carrying a bank-sized obligation, that is the difference between compliance as a permanent bottleneck and compliance as a managed, shared, and defensible process — leaving the firm's people free to do the advisory work they were hired for.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.