
For a Fund RC, sample testing is one of the principal tools for assessing whether AML/CFT controls are operating effectively throughout the life of the fund.
The Luxembourg AML framework requires professionals to adopt a risk-based approach, maintain appropriate controls and monitor the ongoing application of customer due diligence measures. RCs are expected to oversee delegated activities and verify that AML/CFT obligations are effectively implemented. Yet one practical question remains largely unanswered.
How should a Fund RC build an annual sample testing strategy?
Should the sample be selected according to the investor's risk rating?
Should it focus on specific events throughout the life of the fund?
Should it explore a particular AML/CFT theme?
Or should it evolve as new risks emerge?
The regulatory framework does not prescribe a single methodology. Perhaps that is intentional. Perhaps the more interesting question is not how many files to review, but what the RC is actually trying to learn from the sample.
1. Why do Fund RCs perform sample testing?
Sample testing forms an integral part of the annual monitoring programme of a Fund RC. Whether performed directly or through the oversight of delegated activities, it remains one of the principal tools for obtaining assurance that AML/CFT controls operate effectively throughout the life of the fund.
The Luxembourg AML/CFT framework requires professionals to adopt a risk-based approach, maintain appropriate policies and procedures, and exercise effective oversight over outsourced or delegated activities where applicable. While these obligations establish the expectation that controls should be monitored, they remain largely silent on a practical question that every Fund RC eventually faces: how should a sample actually be constructed?
In practice, sample testing often becomes synonymous with reviewing a number of investor files selected according to predetermined criteria. Discussions frequently revolve around sample size, risk ratings or percentages of the investor population to be covered. These considerations are undoubtedly important, but they may overlook a more fundamental question.
The purpose of sample testing is not to review files for the sake of reviewing files. It is to obtain reasonable assurance that the controls on which the fund relies continue to operate effectively.
Viewed from this perspective, the selection of files becomes the consequence of a broader reflection rather than its starting point. Before deciding which investors should be included in the sample, the Fund RC may first ask a simpler question:
What am I actually trying to demonstrate?
The answer to that question often shapes how the sample is ultimately constructed, the evidence that is examined and the assurance that may be obtained.
2. Every sample starts with a question
Once the purpose of sample testing has been established, a second observation naturally follows: every sample starts with a question.
This may appear self-evident, yet it offers a different perspective on how sample testing can be approached. Rather than beginning with a population of investor files and deciding which ones to review, the starting point may instead be the question the Fund RC wishes to explore.
That question can take many forms. It may relate to the effectiveness of a particular control, the consistency of a delegated process or the application of the fund's AML/CFT framework in a specific context. In each case, the question gives meaning to the sample rather than the other way around.
Viewed from this perspective, the sample is not an objective in itself. It is simply a means of gathering evidence around a particular aspect of the AML/CFT control framework. Different questions naturally lead to different populations, different selection criteria and, ultimately, different sampling strategies.
This may also explain why no single sampling methodology has emerged as the market standard. Two Fund RCs overseeing comparable funds may legitimately construct their monitoring programmes differently, not because one methodology is necessarily better than another, but because the questions they seek to answer are not identical.
Perhaps this is one of the most interesting characteristics of sample testing. The discussion is less about identifying the "right" sample than about understanding the rationale that led to its construction.
3. Building a sample around the investor lifecycle
One possible way of approaching sample testing is to use the investor lifecycle as the organising principle for the review. Rather than beginning with a particular customer profile or AML/CFT risk, the starting point becomes a specific stage of the relationship between the investor and the fund.
This perspective reflects the fact that AML/CFT obligations accompany the investor throughout the business relationship rather than being confined to the onboarding phase. Initial customer due diligence, investor transfers, trigger events, periodic reviews and, where relevant, the termination of the relationship each give rise to different processes, documentation requirements and control activities. As a result, each stage may also generate different oversight questions for the Fund RC.
A monitoring exercise may therefore focus on a particular point in the investor lifecycle rather than on a cross-section of the investor population. Depending on the question being explored, the review may concentrate on recently onboarded investors, transfers completed during a defined period, or files that have undergone a periodic review following a trigger event.
Viewed in this way, the lifecycle does not dictate how a sample should be constructed. Rather, it provides one possible lens through which the Fund RC may choose to examine the effectiveness of AML/CFT controls at different moments of the relationship.
This also illustrates a broader point. The investor population can be segmented in many different ways depending on the question being explored. The lifecycle represents one possible perspective; others may instead focus on specific AML/CFT risks, delegated controls or emerging issues identified during the course of the year.
4. Building a sample around a specific AML/CFT risk
While the investor lifecycle offers one possible way of structuring a sample testing programme, it is by no means the only perspective available to a Fund RC. Another approach consists of starting with a particular AML/CFT risk rather than a particular stage of the business relationship.
From this perspective, the objective is no longer to observe how controls operate throughout the lifecycle of an investor, but to explore how the AML/CFT framework responds to a specific category of risk, regardless of when it arises.
Unlike lifecycle events, which occur at defined moments during the relationship, risk categories may span the entire investor population. A politically exposed person may be onboarded today or may have been invested in the fund for several years. A trust or nominee arrangement may be identified during onboarding, following a trigger event or as part of a periodic review. Similarly, an investor connected with a higher-risk jurisdiction or exposed to sanctions or proliferation-related risks may appear at any stage of the relationship.
Viewed in this way, the common denominator is no longer the timing of the review but the nature of the risk itself. The sample can then be viewed as a means of exploring how a particular category of risk is identified, assessed, documented and monitored across different situations.
This perspective also illustrates that the same investor population can be analysed through different lenses. A periodic review involving a politically exposed person, for example, could legitimately form part of a lifecycle review or a thematic review focusing on PEP controls. Neither perspective is inherently more relevant than the other; each simply seeks to answer a different oversight question.
As with the investor lifecycle, building a sample around a specific AML/CFT risk represents one possible methodology among many. It reflects a different way of looking at the same population and contributes another perspective to the Fund RC's overall assessment of the effectiveness of the AML/CFT framework.
5. Building a sample around key AML/CFT judgements
The investor lifecycle and the nature of the risk are two possible ways of structuring a sample testing programme. Another perspective consists of focusing on the AML/CFT decisions themselves.
Throughout the life of an investor, numerous decisions are taken that require professional judgement. A customer may be classified as presenting a lower or higher level of risk, enhanced due diligence measures may be applied, a source of wealth assessment may be considered sufficient, or a trigger event may lead to the conclusion that the existing customer due diligence remains appropriate. Each of these decisions reflects the application of the fund's AML/CFT framework to a particular set of circumstances.
From this perspective, the sample is no longer organised around the characteristics of the investor or the stage of the business relationship. Instead, it is built around a particular type of decision. The discussion shifts from the completeness of individual investor files to the consistency of professional judgements reached in comparable situations.
Viewed in this way, the review extends beyond the outcome of the decision itself. It also considers the reasoning supporting that decision, the documentation available to evidence it and the extent to which it remains consistent with the fund's policies, procedures and risk appetite.
This represents yet another way of looking at the same investor population. An investor reviewed as part of a periodic review, for example, may also form part of a sample examining enhanced due diligence decisions or changes in customer risk classification. Once again, the difference lies not in the investor being reviewed, but in the question the Fund RC is seeking to explore.
6. Building a sample around evolving circumstances
The approaches discussed so far all begin with a predefined perspective. A Fund RC may decide to structure a review around the investor lifecycle, a particular AML/CFT risk or a key AML/CFT judgement. In practice, however, sample testing may also be shaped by circumstances that emerge throughout the year.
The context surrounding a fund continues to evolve throughout the year. Regulatory developments, internal findings, changes in the investor base or new business relationships may all provide a different perspective on the areas that deserve closer attention. Likewise, recurring observations identified through management information, KPI or KRI reporting, internal audit recommendations or operational incidents may prompt further exploration of a particular aspect of the AML/CFT framework.
Viewed from this perspective, the sample is no longer defined primarily by the characteristics of the investors being reviewed, but by the context that led the Fund RC to ask a new question. The underlying population may remain unchanged; what evolves is the rationale for examining it.
This also illustrates that a sample testing programme is not necessarily a fixed sequence of predefined reviews. New questions may emerge as the year progresses, leading to additional reviews or to the reconsideration of areas that had not originally attracted particular attention. These additional reviews do not necessarily represent a change in methodology. They simply reflect that the questions considered relevant at the beginning of the year may differ from those that emerge several months later.
As with the approaches discussed previously, this perspective does not seek to establish a preferred methodology. It simply recognises that the circumstances surrounding a fund continue to evolve and that these developments may, in turn, generate new questions worthy of examination.
Conclusion
Perhaps one of the most interesting aspects of sample testing is that it resists standardisation.
Two Fund RCs overseeing comparable funds may legitimately construct their annual monitoring programmes differently. One may organise reviews around the investor lifecycle, another around specific AML/CFT risks, key professional judgements or developments that arise during the year. None of these perspectives is inherently superior to another. Each simply reflects a different way of exploring the effectiveness of the fund's AML/CFT framework.
In that respect, sample testing is less about identifying the perfect sample than about understanding the question that the sample is intended to answer.
Like many areas of AML/CFT, the regulatory framework establishes the principles of oversight while leaving considerable room for professional judgement when determining how assurance is obtained. That flexibility is perhaps one of the strengths of a risk-based approach. It allows Fund RCs to construct monitoring programmes that remain proportionate, explainable and aligned with the particular characteristics of the funds they oversee.
Ultimately, the value of sample testing lies not in the number of files reviewed, but in the quality of the questions being asked.
From reflection to practice
At SableRock, this way of thinking has shaped the development of our AML/CFT sample testing methodology for Fund RCs.
Rather than relying on a single predefined sampling model, our approach allows monitoring campaigns to be structured around different perspectives, including the investor lifecycle, specific AML/CFT risks, key professional judgements and evolving circumstances identified throughout the year.
The objective is not to replace professional judgement, but to provide a structured and documented methodology that helps Fund RCs design, justify and evidence their annual sample testing programme in a manner that remains consistent with the fund's risk profile and oversight objectives.
The objective is not to standardise professional judgement, but to provide a structured framework that supports it.