FaSQUAL: The BSIA-led Vetting Passport for the UK Security Industry Powered by Neotas Read More →
Generate AI-Powered Audit-Ready Due Diligence Reports instantly. Learn More →
Perpetual Due Diligence for Fund Managers

Perpetual Due Diligence for Fund Managers

Monitoring Portfolio Companies, Counterparties and Service Providers Between Reviews

Quick answer

Perpetual due diligence for fund managers is continuous, trigger-based monitoring of the portfolio companies, deal counterparties, co-investors and fund service providers a manager depends on, with an investigation and a recorded decision each time a defined risk event occurs.

It applies the logic of perpetual KYC to relationships beyond the investor file. Typical triggers include sanctions designations, ownership and key-person changes, enforcement actions, litigation and credible adverse media. The output is an audit trail that answers SEC examiners, CIMA-mandated auditors and LPs.

Key takeaways

  • Cayman’s new CIMA AML Rule and Sanctions Rule came into force on 18 September 2026. Under them, outsourcing an AML function does not transfer accountability, and the independent AML audit must cover third-party relationships and outsourcing.[1]
  • The SEC’s amended Regulation S-P requires written policies for overseeing service providers that access customer information. Larger advisers had to comply from 3 December 2025 and smaller advisers from 3 June 2026.[2]
  • EY found that 58% of surveyed asset managers still run KYC reviews on a fixed 1, 3 or 5-year cycle, and 42% outsource onboarding and KYC to third parties (EY, 2024).[3]
  • FinCEN has postponed its investment adviser AML/CFT rule to 1 January 2028. Investor KYC obligations are on a horizon, but third-party and portfolio exposures exist today.[4]
  • A calendar review records what was true on the review date. Perpetual due diligence records what changed since, and what the firm did about it.

What is perpetual due diligence for fund managers?

Perpetual due diligence is the practice of keeping risk assessments on a fund’s external relationships current between scheduled reviews. Instead of waiting 12 or 36 months to look again, the manager monitors each relationship continuously and opens a review when a defined event occurs.

The mechanism is the same one banks call perpetual KYC (pKYC): event-driven review instead of calendar review. The difference is scope. Perpetual KYC is usually discussed for investors and customers. Perpetual due diligence covers the relationships that carry a fund manager’s investment, operational and reputational risk after the subscription documents are signed.

Definition
Trigger event: a change in a counterparty’s ownership, management, legal, regulatory, sanctions or media profile that is material enough to require a documented reassessment before the next scheduled review.

Investor KYC is one of four monitoring duties

Most perpetual KYC content stops at the investor. For a fund manager, investors are often the best-documented relationship, because a fund administrator already holds the file. The less-watched exposures sit elsewhere.

Relationship Who usually watches it What goes wrong between reviews
Investors and LPs Fund administrator, investor services Change of UBO, PEP status or sanctions exposure after onboarding
Portfolio companies and management teams Deal team, board representatives Executive misconduct, litigation, regulatory action, a sanctioned customer or supplier
Deal counterparties and co-investors Often nobody after closing A co-investor’s backer is designated, or a seller faces fraud allegations post-close
Fund service providers and delegates Operations, procured once and renewed Administrator, placement agent or distributor faces enforcement, ownership change or a data breach

The fourth row carries most of the live regulatory weight in 2026. The second and third rows carry most of the reputational weight. An LP rarely reads about a fund manager because an investor’s KYC file aged. It reads about one because a portfolio company CEO was charged, or because a placement agent was sanctioned.

For the investment-stage view of these relationships, our investment due diligence checklist covers pre-commitment checks. This guide covers what happens after the deal closes.

Why calendar-based reviews miss risk between cycles

A fixed review cycle creates a blind window. A high-risk relationship on a 12-month cycle can carry an undetected sanctions designation for up to 11 months. A low-risk service provider on a 3-year cycle can change owners twice before anyone looks.

The industry still leans on that model. In EY’s 2024 survey of global asset managers, 58% ran reviews on the traditional 1, 3 or 5-year cycle, and only 17% were purely event-driven.[3] IQ-EQ’s 2026 survey of more than 50 private markets fund managers found 48% still manage KYC through email and spreadsheets.[5]

Outsourcing moves the work, not the accountability

EY found 42% of asset managers outsource onboarding and KYC to third-party vendors.[3] IQ-EQ found 87% of larger managers use outsourced or hybrid KYC models.[5]

Each of those arrangements creates a service provider the manager now has to oversee. A firm that outsourced investor KYC to reduce work has, in regulatory terms, added a relationship that needs its own ongoing due diligence. Cayman’s 2026 rules say this outright.

Exposure check: if your third-party review schedule was set before Regulation S-P’s amendments and CIMA’s 2026 rules, it was designed for a different set of obligations. A 30-minute review with a Neotas analyst will map which relationships fall outside your current cycle. Book a programme review.

Which regulations require ongoing due diligence from fund managers in 2026?

Four obligations are live now and fall directly on the manager’s third-party and portfolio relationships. Two more are dated horizons. The table separates what a rule requires from what is good practice.

Rule Date What it asks of the manager Status
CIMA AML Rule and Sanctions Rule (Cayman) In force 18 Sep 2026 Ongoing monitoring and sanctions screening; oversight of outsourced AML functions; independent AML audit covering third-party relationships and outsourcing Live
SEC Regulation S-P amendments (17 CFR 248.30) 3 Dec 2025 (larger); 3 Jun 2026 (smaller) Written policies for due diligence on and monitoring of service providers with customer information access; 72-hour breach notice from those providers Live
AIFMD II (Directive (EU) 2024/927) Transposition 16 Apr 2026 Stricter delegation and substance expectations for AIFMs overseeing delegates Live (EU)
UK MLR 2017 as amended by SI 2026/621 Most provisions 30 Jun 2026 Ongoing monitoring under Reg 28(11); narrower bright-line EDD triggers, so more depends on documented judgement Live (UK)
EU AMLR (Regulation (EU) 2024/1624) Applies 10 Jul 2027 Directly applicable CDD and ongoing monitoring rules across the EU Horizon
FinCEN investment adviser AML/CFT rule (31 CFR 1032.210) Postponed to 1 Jan 2028 AML/CFT programme and SAR filing for RIAs and ERAs; FinCEN has said it intends to revisit the rule’s substance Horizon

Regulatory summaries are Neotas’ reading of published rules and law-firm guidance as of October 2026. They are not legal advice. Confirm scope for your fund structures with counsel.

United States: Regulation S-P is the clearest live trigger

For an SEC-registered adviser, Regulation S-P’s amended safeguards rule is the most concrete reason to formalise third-party monitoring now. Every adviser had to comply by 3 June 2026. The SEC’s Division of Examinations listed vendor oversight under Regulation S-P and S-ID, and operational resiliency, among its FY2026 priorities.[6]

One point is often misread. The SEC’s 2022 proposal on outsourcing by investment advisers was withdrawn on 12 June 2025. There is no standalone SEC outsourcing rule. The obligation comes through Regulation S-P, the adviser’s fiduciary duty and examination expectations.

The Corporate Transparency Act changed in the same period, in the opposite direction. FinCEN’s interim final rule of 21 March 2025 exempts US-formed companies and US persons from beneficial ownership reporting. Fewer filings mean ownership checks on US counterparties now depend more on independent investigation than on a registry.

Cayman: the trigger most US managers overlook

Many US sponsors run Cayman vehicles. CIMA’s AML Rule and Sanctions Rule apply to CIMA-registered funds, managers and advisers, and they took effect on 18 September 2026. Law-firm guidance on the rules states that outsourcing does not transfer accountability.[1] The independent AML audit has to examine third-party relationships and outsourcing, so the evidence of oversight is now something an auditor will ask to see.

UK and EU: portfolio monitoring already has a basis

The UK’s JMLSG guidance for private equity (Part II, Sector 13) says a private equity firm must conduct ongoing monitoring of its AML “customers”, which in some structures include portfolio companies. It accepts that board-level oversight can contribute to that duty.[7] In the EU, AIFMD II puts more weight on how an AIFM selects and supervises delegates.

Neotas, rated in the Chartis FCC50

See what your last review missed

Name up to five portfolio companies or service providers. A Neotas analyst runs them through OSINT, sanctions, adverse media and ownership checks and returns a sample ongoing due diligence report with its full audit trail.

Request a sample monitoring report

What trigger events should prompt an out-of-cycle review?

A trigger list only works if it is tied to relationship type. A data breach at a fund administrator matters for Regulation S-P. The same event at a portfolio company is a value and reputation issue. The matrix below is Neotas’ working taxonomy, built from the regulatory obligations above.

Trigger event Portfolio company Counterparty / co-investor Administrator / delegate Placement agent / distributor
Sanctions designation (direct or via 50% ownership) Escalate Escalate Escalate Escalate
Change in UBO or controlling shareholder Review Escalate Review Escalate
Key person departure, arrest or charge Escalate Review Review Escalate
Regulatory enforcement or licence action Escalate Review Escalate Escalate
Material litigation or insolvency signals Review Review Escalate Review
Credible adverse media (fraud, bribery, ML, labour, ESG) Escalate Review Review Escalate
Data breach or cyber incident Review Note Escalate Review
New PEP connection Review Escalate Note Escalate
Move into a higher-risk jurisdiction Review Review Review Escalate

Escalate = analyst investigation and a documented decision within a set timeframe. Review = relationship owner reassesses the risk rating. Note = log against the file and consider at the next scheduled review.

Placement agents score high on most rows because they act in the manager’s name with investors, often across jurisdictions where the manager has no staff. Their risk is closer to an agent’s than a vendor’s.

How should a fund manager tier its third-party monitoring?

Tier by consequence, not by contract value. A low-fee distributor in a high-risk market can expose the manager more than a large technology vendor. Five factors decide most tiers:

1
Acts in your name
Placement agents, distributors and finders speak to investors for you. Misconduct lands on the manager.
2
Holds investor or fund data
Administrators, transfer agents and technology vendors with customer information fall under Regulation S-P service provider oversight.
3
Performs a regulated function you delegated
Outsourced AML, depositary and portfolio management delegation carry CIMA and AIFMD II accountability.
4
Ownership opacity and jurisdiction
Layered holding structures, nominee directors and operations in higher-risk jurisdictions raise the tier.
5
Value and visibility
Large positions and publicly visible portfolio companies carry more reputational exposure for the fund.
Tier Monitoring Scheduled review On trigger
Critical Continuous: sanctions, adverse media in local languages, ownership, litigation Annual enhanced review Analyst investigation, documented decision
Significant Continuous sanctions and adverse media Every 2 years Owner reassessment; escalate if confirmed
Standard Continuous sanctions screening Every 3 years Owner reassessment

Review frequencies are Neotas’ recommended starting point, not regulatory minimums. Set yours in your written risk methodology. Our enhanced due diligence checklist includes a monitoring-frequency-by-risk table you can adapt.

When does screening need investigation?

Screening tells you a name matched a list or an article. Investigation tells you whether it matters. Fund relationships produce three kinds of risk that database screening alone tends to miss.

  • Hidden ownership. Sanctions exposure through a 50%-owned entity, or a co-investor’s backer sitting two layers up, does not appear as a direct list match. Ownership has to be traced through registries and open sources.
  • Local-language media. The first report of a regulatory raid on a portfolio company in Brazil or Indonesia is usually in Portuguese or Bahasa, in regional outlets that many commercial adverse media feeds index late or not at all.
  • Behavioural signals. Court filings, social media activity and changes in corporate filings show conduct that never reaches a watchlist.

This is where most programmes stall. They switch on continuous screening, alerts arrive, and nobody has the time or the method to resolve them. Unresolved alerts are worse than none, because an examiner can see the firm knew and did nothing.

What an ongoing due diligence report should contain

An ongoing due diligence report records what changed in a relationship and what the firm decided. At minimum it should hold the trigger and its source, the checks run, the findings with links to evidence, the analyst’s assessment, the risk rating before and after, the decision and its owner, and the date. That record is what CIMA’s independent auditor and an SEC examiner will ask for.

Our guide to adverse media screening covers why one-off screening and ongoing monitoring produce different results.

The Neotas Perpetual Due Diligence Maturity Model

Use these five levels to place your current programme. Each level scores two things: how many relationship types are covered, and what happens when something changes.

Level Coverage Response to change
1. Calendar Investors only, at onboarding and fixed intervals Found at the next review, if at all
2. Screened Investors and some counterparties rescreened automatically Alerts generated, inconsistently resolved
3. Mapped All four relationship types inventoried and tiered Defined trigger taxonomy and owners
4. Investigated Critical and significant tiers monitored continuously Escalations go to analyst-led, multilingual investigation
5. Evidenced Whole relationship portfolio, on one dashboard Every alert, finding and decision in an audit trail, mapped to the obligation it satisfies

Our experience is that firms tend to overrate their level by one step. Continuous screening of investors feels like Level 4. Without a tiered inventory of portfolio companies and service providers, it is Level 2.

Important: moving from Level 2 to Level 3 is mostly internal work: an inventory, a tiering method and named owners. Moving from Level 3 to Level 5 is where most firms need outside intelligence capacity, because alert volume rises faster than in-house analyst time.

Common mistakes in fund manager third-party monitoring

  1. Treating the administrator’s KYC file as the whole programme. It covers investors. It says nothing about the administrator itself, your delegates or your portfolio.
  2. Relying on questionnaires for service provider oversight. A provider’s own answers describe its controls. They will not tell you about the enforcement action in its parent company’s home market.
  3. Stopping diligence at closing. Pre-deal checks on management teams are thorough at most sponsors. Post-close monitoring of the same people is often nobody’s job.
  4. Screening the entity, not its owners and officers. Many material events attach to a director or a beneficial owner, not the company name.
  5. Generating alerts without a resolution method. An unworked alert queue is evidence of a known, unaddressed risk.

Who owns perpetual due diligence: CCO, GC, COO and deal team

Each role meets this problem from a different direction. The programme works when each one knows which trigger is theirs.

Chief Compliance Officer

Your exposure is the exam or audit request: show Regulation S-P service provider oversight, show the CIMA outsourcing file. You need tiering logic and decision records, not just a vendor list.

General Counsel

Your exposure is the sanctions or enforcement event attached to a counterparty you contracted with. OFAC liability is strict, so the question is how fast you knew and what you did.

Chief Operating Officer

Your exposure is a critical provider failing or changing hands with no tested fallback. Ownership-change triggers on administrators and delegates belong on your dashboard.

Deal and portfolio teams

Your exposure is the portfolio company headline that reaches LPs before it reaches you. Key-person and adverse media triggers on management teams protect value and the next fundraise.

How Neotas supports perpetual due diligence

Neotas combines automated monitoring with analyst investigation, so alerts end in decisions. Each capability below maps to a problem described earlier.

Problem Neotas capability
Blind windows between reviews Continuous monitoring across connected data sources, with custom alerting
Different risk across relationship types Configurable risk models and dashboards by tier
Hidden ownership, local-language media OSINT and social media intelligence, premium data sources and search in 30+ languages
Alerts that need judgement Expert analyst team and enhanced due diligence reports
“Show me” from an examiner, auditor or LP Full audit trail of every check, finding and decision

Investment firms already use this approach. Coller Capital works with Neotas on OSINT-based ESG due diligence at the initial investment stage and for ongoing monitoring of the portfolio. Read how OSINT supports ESG due diligence for investors.

For the wider programme design, see our guide to third-party risk management and the TPRM lifecycle.

Ready for the next audit or exam request?

Score your programme against the Perpetual Due Diligence Maturity Model

If your third-party oversight still relies on questionnaires, onboarding checks and annual reviews, a 30-minute readiness assessment with a Neotas specialist will show where your portfolio companies and service providers sit outside your cycle, and what CIMA, Regulation S-P or AIFMD II evidence you are missing.

Practical guides for fund compliance, legal and operations teams managing portfolio, counterparty and service provider risk.

Investment Due Diligence Checklist

The pre-commitment checks investors and managers run on funds, managers and service providers, including operational due diligence and the ILPA DDQ.

Private Equity Due Diligence Checklist

Buy-side checks on targets and management teams before closing, which set the baseline that post-close monitoring then tracks.

Enhanced Due Diligence Services

Analyst-led investigation for investment and operational due diligence on fund managers, portfolio companies and service providers.

Adverse Media Screening: What It Misses

Why keyword screening misses material media, and how ongoing adverse media monitoring differs from a one-off check.

Third-Party Risk Management Framework

How to structure risk tiering, due diligence depth by tier and governance for a third-party programme.

OSINT Due Diligence for Investors

How open-source intelligence exposes management and ownership risk that registry data and questionnaires do not show.

Vendor Due Diligence

Due diligence on suppliers and service providers, from onboarding checks to the evidence a regulator expects to see.

Enhanced Due Diligence Checklist

EDD steps and an ongoing monitoring plan with review frequency by risk level and common trigger events.

Frequently asked questions: perpetual due diligence for fund managers

Answers based on regulatory sources and People Also Ask data for ongoing due diligence and perpetual KYC queries in US and UK search results.

What is the difference between perpetual KYC and perpetual due diligence?▾
Perpetual KYC applies event-driven review to customers and investors. Perpetual due diligence applies the same event-driven review to the other relationships a fund manager depends on: portfolio companies, deal counterparties, co-investors and fund service providers. Both replace fixed review dates with continuous monitoring and trigger-based reassessment.
How often should a fund manager review its service providers?▾
Frequency should follow risk tier. A common starting point is annual enhanced review for critical providers, every two years for significant providers and every three years for standard ones, with continuous sanctions and adverse media monitoring in between. No single regulator sets these intervals; document your chosen frequencies in your risk methodology.
Does outsourcing KYC to a fund administrator transfer compliance responsibility?▾
No. Under Cayman’s CIMA AML Rule, in force since 18 September 2026, outsourcing an AML function does not transfer accountability, and the independent AML audit must cover outsourcing and third-party relationships. The manager must oversee and evidence the administrator’s performance, not just the investor files it holds.
What does Regulation S-P require for service provider oversight?▾
The amended Regulation S-P requires SEC-registered advisers to keep written policies for due diligence on and monitoring of service providers with access to customer information, and to require those providers to report breaches within 72 hours. Larger advisers complied from 3 December 2025, smaller advisers from 3 June 2026.
When does the FinCEN investment adviser AML rule take effect?▾
FinCEN postponed the rule’s effective date from 1 January 2026 to 1 January 2028, in a final rule published on 2 January 2026. FinCEN has said it intends to revisit the rule’s substance and scope before then, so registered and exempt reporting advisers should expect the final requirements to change.
What is an ongoing due diligence report?▾
An ongoing due diligence report records a change in an existing relationship and the firm’s response. It should include the trigger and its source, the checks performed, findings with evidence, the analyst’s assessment, the risk rating before and after, the decision, its owner and the date. It forms the audit trail regulators and auditors review.
Do UK private equity firms have to monitor portfolio companies?▾
JMLSG Part II Sector 13 says a private equity firm must conduct ongoing monitoring of its AML customers, which can include portfolio companies, on a risk-sensitive basis. It accepts board-level oversight as part of that. Many firms add independent media and sanctions monitoring because board reporting rarely surfaces allegations against management.
What is the difference between adverse media screening and adverse media monitoring?▾
Adverse media screening is a one-off search at a point in time, usually at onboarding. Adverse media monitoring runs continuously and alerts when new negative coverage appears. For fund relationships, monitoring needs to cover owners and officers as well as the entity, and local-language sources where the counterparty operates.

Sources

[1] Cayman Islands Monetary Authority, AML Rule and Sanctions Rule, in force 18 September 2026; summarised in Walkers, “Cayman Islands new AML Rule and new Sanctions Rule: Practical Guide for Investment Funds”, August 2026.

[2] US SEC, Regulation S-P amendments (17 CFR 248.30), adopted May 2024; compliance dates 3 December 2025 and 3 June 2026.

[3] EY, “Asset management institutional client onboarding survey”, February 2024.

[4] Federal Register, FR Doc. 2025-24184, 2 January 2026.

[5] IQ-EQ, “KYC in private markets: Challenges, friction and the case for change”, March 2026 (updated June 2026).

[6] US SEC Division of Examinations, Fiscal Year 2026 Examination Priorities, November 2025.

[7] JMLSG Guidance Part II, Sector 13: Private equity, paras 13.78 to 13.79.

This article is for information only and does not constitute legal or regulatory advice.


Share:

Picture of Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.

A detailed guide to TPRM and a downloadable checklist to implement the TPRM Framework in 2026

Book a Demo

Explore Neotas Enhanced Due Diligence