AML Evidence Index Template for Irish Fund Administrators

AML Evidence Index Template for Irish Fund Administrators image

Building a compliant AML evidence index: A practical framework for Irish funds

Irish fund administrators face mounting regulatory scrutiny from the Central Bank of Ireland. Recent CBI enforcement bulletins require robust, documented AML controls. This guide shows you how to build an AML evidence index template for Ireland, a centralized register that organizes and demonstrates compliance across customer due diligence, ongoing monitoring, and third-party oversight. Learn how to structure, maintain, and audit evidence to meet CBI expectations and reduce regulatory risk.

What is an AML evidence index for fund administrators?

An AML evidence index is a centralized register that catalogs all supporting documentation and evidence of your fund’s AML controls in operation. Rather than a checklist of what you should do, an evidence index documents what you have actually done.

For Irish fund administrators, this includes:

  • Customer due diligence records: identity verification documents, beneficial owner forms, risk assessments, and source-of-funds evidence
  • Ongoing monitoring logs: transaction review notes, screening results (PEP, sanctions, adverse media), and monitoring alerts
  • Third-party oversight files: outsourcing agreements, service-level agreements (SLAs) with AML vendors, oversight testing results, and KPI reports
  • Governance and training records: MLRO appointment documentation, staff AML training records, and board-level compliance reporting
  • Remediation and incident files: suspicious activity reports (SARs), investigation outcomes, breaches, and corrective actions

The CBI does not require a specific format, but inspectors will ask to see evidence that your fund has identified risks, implemented controls, and monitored their effectiveness. An evidence index provides this proof in an audit-ready format.

Why an AML evidence index matters for Irish fund administrators

The Central Bank of Ireland’s supervisory reviews of Irish funds and fund management companies have repeatedly identified recurring AML/CFT gaps, as set out in its 2026 Regulatory & Supervisory Outlook Report and its earlier Anti-Money Laundering Bulletin on Funds and Fund Management Companies (November 2021). Its findings include:

Documentation gaps between policy and practice.

The CBI found that firms often have AML policies in place but cannot evidence that procedures were actually followed, citing “ineffective CDD control frameworks” and a lack of “comprehensive assurance testing programmes.” Without an index, the evidence needed to demonstrate compliance scatters across email, vendors, and storage, making it hard to produce during a review.

Inadequate outsourcing oversight.

The CBI’s Anti-Money Laundering Bulletin on Funds and Fund Management Companies found that outsourced service providers (OSPs) were “not subject to regular and comprehensive due diligence reviews,” with “insufficient oversight of technological solutions utilized by OSPs” for PEP screening, financial sanctions screening, and transaction monitoring, and a “lack of available MI and Key Performance Indicators (KPIs).” This remains an active CBI supervisory focus into 2025 and 2026.

Weak governance and escalation trails.

The CBI expects the Compliance Officer/MLRO to keep the Board informed on AML/CFT matters, with meaningful board-level discussion and challenge. Its review found firms failing to deliver the expected annual Compliance Officer report to the Board and board minutes that “did not always reflect adequate discussion and challenge in relation to AML/CFT/FS matters”. An evidence index documents this governance chain.

Reduced operational friction.

An organized index helps your team locate files quickly and respond to regulatory requests efficiently.

Regulatory framework: What the CBI expects

Under the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010–2021, Irish fund administrators must maintain comprehensive records of AML/CFT activities.

Key CBI expectations:

Board and senior management must evidence effective governance and AML/CFT oversight. The MLRO should have appropriate authority, resources, and escalation paths.

Formalized outsourcing arrangements must clearly define responsibilities and deliverables. Firms should conduct regular assurance testing, track KPIs, and document monitoring of ESPs’ technological solutions.

Customer risk assessments should be documented on each file, tailored to the fund’s risk profile and reflecting investor jurisdiction reach.

Ongoing monitoring should be proportionate to risk, with documented procedures for alert handling, investigation, and escalation.

Suspicious activity reporting (SAR) procedures should be documented, and where a SAR is filed, evidence of the MLRO’s decision-making process and submission must be retained.

Practical framework: Building your AML evidence index

Step 1: Establish governance and index ownership

Assign a compliance officer or senior analyst to own the evidence index. This individual should report to the MLRO and work with operations, fund management, and external service providers to source evidence. Define the scope: which fund entities does the index cover? Which AML activities are in scope (CDD, ongoing monitoring, STR handling, third-party oversight)?

Document the governance decision in a brief memorandum (for your file) that confirms board-level awareness and the MLRO’s oversight role.

Step 2: Define evidence categories and retention rules

Organize evidence by control area. Use the matrix below as a starting template:

Evidence categoryWhat to retainRetention periodStorage location
Customer Due Diligence (CDD)Identity documents (marked “original sighted”), beneficial owner forms, risk assessments, source of funds, address verification6 years post-closureSecure repository (encrypted file server or compliant document management system)
Enhanced Due Diligence (EDD)PEP screening reports, adverse media searches, source-of-wealth documentation, transaction pattern analysis6 years post-closureSecure repository
Ongoing MonitoringTransaction monitoring logs, screening results (PEP, sanctions rescreening), monitoring alert investigation notes, MLRO review sign-offs6 years post-transactionAudit trail / system logs
Third-Party OversightESA due diligence review, SLA execution, annual assurance testing reports, KPI dashboards, remediation notices6 yearsSeparate vendor governance file
SAR SubmissionsCompleted internal SAR form, decision log (date, MLRO sign-off, submission reference), and goAML portal confirmation6 yearsSecure SAR register
Training and CompetenceTraining attendance records, completion certificates, role-specific training schedulesDuring employment + 2 yearsHR/Compliance records
Board ReportingMinutes confirming AML/CFT framework oversight, risk updates, breach notifications6 yearsBoard secretary or compliance

Step 3: Create an index register

Build a master register (spreadsheet or specialist compliance software) that logs every piece of evidence. At a minimum, include:

  • File Reference (e.g., CDD_2024_Q1_001)
  • Control Area (CDD, ongoing monitoring, SAR, training, etc.)
  • Description (e.g., “Identity verification and CDD for XYZ Fund LP subscription”)
  • Date Completed (when the control was performed)
  • Evidence Stored (file path or system location)
  • Retention Expiry (calculated end date)
  • Status (Current, Archive, Destroyed)

Step 4: Integrate with outsourced service providers

If your fund outsources AML services (CDD screening, transaction monitoring, PEP screening), ensure your ESPs provide evidence reports in a standardized format and on a regular schedule. Request:

  • Monthly or quarterly screening result summaries with pass/fail counts
  • Documented escalation procedures for alerts and unusual activity
  • Annual independent audit reports confirming control effectiveness
  • SLA compliance dashboards showing onboarding turnaround, false positive rates, and remediation responsiveness

Store these reports in your evidence index under the third-party oversight category.

Step 5: Conduct quarterly index reviews

Schedule reviews with the MLRO each quarter to:

  • Identify missing or outdated documentation
  • Verify that retention periods are being met and archive/destruction procedures are followed
  • Test sample files to confirm evidence quality and completeness
  • Report findings to senior management or the board

Document the review in a compliance memorandum.

AML evidence index template: Key evidence categories

Evidence categoryWhat to retainRetention periodStorage location
Customer Due Diligence (CDD)Identity documents, beneficial owner forms, risk assessments, source of funds, address verification6 years post-closureSecure repository (encrypted file server)
Enhanced Due Diligence (EDD)PEP screening reports, adverse media searches, source-of-wealth documentation6 years post-closureSecure repository
Ongoing MonitoringTransaction monitoring logs, screening results, alert investigation notes, MLRO sign-offs6 years post-transactionAudit trail / system logs
Third-Party OversightESP due diligence review, SLA execution, assurance testing reports, KPI dashboards6 yearsVendor governance file
SAR SubmissionsInternal SAR form, decision log, MLRO sign-off, submission reference6 yearsSecure SAR register
Training and CompetenceTraining attendance records, completion certificatesDuring employment + 2 yearsHR / Compliance records
Board ReportingMinutes on AML/CFT oversight, risk updates, breach notifications6 yearsBoard records

Best practices for evidence index management

Automate where possible.

Export compliance reports from vendors or transaction monitoring systems directly to your index repository rather than manual file movement.

Use consistent file naming.

Apply standardized naming (e.g., “CDD_FundA_2024_OriginalSighted_PDF”) so files are easily located during regulatory review.

Maintain segregation of duties.

A compliance analyst should populate the index; the MLRO should review samples to verify accuracy.

Document gaps and remediation.

If evidence is missing, record the gap, reason, and remediation date. Do not backfill or recreate evidence.

Test the index periodically.

Simulate a CBI inspection: pull files using only the index as a guide and verify all referenced documentation is retrievable and complete.

Common mistakes in evidence index implementation

Quantity over quality.

Storing many files without critical documents (identity verification, risk assessment, and source of funds) does not demonstrate compliance.

Missing outsourced controls.

Funds often retain their own CDD evidence but lack visibility into screening evidence managed by third-party vendors. Your index should cross-reference vendor reports.

Inconsistent retention.

Records destroyed at the 6-year mark without confirming SARs, investigations, or disputes are fully resolved may breach regulatory expectations.

MLRO lacks access.

If the index is managed by operations only, the MLRO cannot rapidly retrieve files during monitoring reviews or investigations.

No audit trail for the index.

Static spreadsheets lack version control. Your index should be managed in read-only shared storage with change logs.

FAQs

How should we handle evidence when CDD is outsourced to a third party?

Keep a copy of the ESP’s CDD report and document your review for completeness. Your fund remains accountable to the CBI for CDD quality, so retain evidence of your oversight of the ESP, including any requests for additional documentation and acceptance sign-offs.

Do we retain evidence for inactive customer relationships?

Yes. Under Irish AML law, retain records for six years from the end of the relationship. Calculate expiry dates in your index and only destroy records after confirming no SARs, disputes, or regulatory queries apply.

What evidence demonstrates ongoing monitoring is working?

Document your monitoring methodology, sample transaction reports with alerts investigated, MLRO sign-offs, rescreening records (PEP/sanctions), and any transactions that escalated to SAR filing. This chain proves monitoring is continuous, not one-time.

How often should we audit the evidence index?

Conduct quarterly reviews with the MLRO to identify missing documentation, verify retention dates, and spot-check file retrievability. The CBI expects continuous governance; regular reviews document this.

What’s the best way to implement an AML evidence index template in Ireland?

Start by defining scope (fund entities and AML activities covered), then organize evidence by control area using the matrix in this guide. Assign a compliance officer to own the index, set up storage locations, and conduct quarterly reviews with the MLRO to identify gaps.

What if we discover missing evidence during inspection?

Do not recreate evidence; this constitutes falsification. Document the gap, reason, and remediation plan. Report to the MLRO and senior management. The CBI focuses on systemic remediation, not isolated missing files.

Explore Cascade’s compliance workflow capabilities

Building and maintaining an AML evidence index template in Ireland requires coordination across multiple teams and vendors. Many compliance officers struggle to collect evidence on time, organize it consistently, and prove to the MLRO that controls are operating effectively.

Cascade’s AML Software (SaaS Platform) helps streamline compliance workflows across onboarding, screening, alert handling, reporting, and analytics.

Schedule a demo with our compliance team.

Disclaimer

This article is for general information purposes only and is based on publicly available sources as of publication. It is not legal, regulatory, or compliance advice and should not substitute for professional counsel specific to your fund’s structure, risk profile, and jurisdiction. Requirements for AML evidence management vary by fund domiciliation, investor base, and regulatory perimeter. Irish fund administrators should consult with their MLRO, legal team, or external counsel to tailor this framework to their actual operations. The examples and matrices provided are illustrative only and do not guarantee regulatory compliance or immunity from CBI supervisory action. Your fund remains responsible for ensuring its AML/CFT framework is documented, operating effectively, and independently tested. Cascade does not provide legal or compliance advice and does not represent that using Cascade’s platform guarantees regulatory compliance or satisfies CBI expectations; compliance accountability remains with your fund, MLRO, and board.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade