Getting Source of Funds and Source of Wealth Right

Stephanie Mangani

9/18/20264 min read

photo of white staircase
photo of white staircase

This article is the first in a series of four focusing on the practical Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) challenges faced by Maltese subject persons. We start with one of the most fundamental principles in AML/CFT compliance: Customer Due Diligence (CDD) is not a tick-box exercise.

Customer Due Diligence involves identifying and verifying a customer through reliable, independent documentation. At its most basic level, this includes verifying a customer's identity and residential address using government-issued identification documents, such as an identity card or passport, and proof of address obtained from reliable and independent sources, such as a regulated credit institution or utility provider.

However, CDD extends far beyond basic identification and verification requirements. Over the years, regulatory expectations have become increasingly stringent, particularly concerning the establishment and assessment of Source of Funds (SoF) and Source of Wealth (SoW). While both concepts must be understood for all customers, it is essential to recognise the distinction between them.

Source of Funds refers to the origin of the specific funds involved in a transaction or business relationship. Source of Wealth, on the other hand, relates to the origin of a customer's total accumulated wealth and net worth.

For example, consider a customer making a EUR 20,000 investment through an investment services provider. If the funds originate from an inheritance recently received, the inheritance represents the Source of Funds for that transaction. If the same individual has accumulated an overall net worth of approximately EUR 200,000 through employment income earned over a 25-year career, this employment income constitutes the Source of Wealth.

In line with the Risk-Based Approach, the Financial Intelligence Analysis Unit (FIAU) expects subject persons to tailor their CDD measures according to the level of risk presented by the customer. The higher the risk, the greater the expectation that firms will obtain and retain comprehensive supporting evidence and conduct more in-depth assessments.

Taking the example above, if the customer is identified as a Politically Exposed Person (PEP), the customer would automatically be classified as high risk. Consequently, the investment services provider would be expected to obtain satisfactory evidence supporting both the Source of Funds and the Source of Wealth. This may include documentation relating to the inheritance, such as a will, grant of probate, or inheritance distribution statement, together with supporting evidence of historical employment income, including payslips, employment contracts, tax documentation, or other records that explain the accumulation of the individual's overall wealth.

Importantly, collecting information and supporting documentation is only one part of the process. Firms are required not merely to gather documents, but to critically assess and challenge the information provided.

For example, if a customer declares a net worth exceeding EUR 1 million, yet the supporting documentation obtained consists only of payslips that would not reasonably support such wealth accumulation, further enquiries are necessary. Additional sources of wealth may exist, such as business ownership, rental income, inheritance, investment returns, or the disposal of assets. The firm must understand and document these factors before being satisfied that the customer's declared financial position is credible and adequately supported.

In practice, deficiencies relating to Source of Funds and Source of Wealth assessments remain among the most common weaknesses identified within subject persons. Frequently, organisations focus on obtaining documentation while overlooking the equally important requirement to assess its adequacy, credibility, and consistency.

Firms should ensure that any document reviewed contains sufficient evidentiary value. For example, documents should clearly identify the customer, be appropriately dated, and originate from reliable and verifiable sources. Furthermore, the assessment performed by the firm should be clearly documented. Compliance teams and front-office personnel alike must understand that obtaining a document does not automatically conclude the due diligence process.

The review of documentation against information previously disclosed by the customer may identify inconsistencies, gaps, or unanswered questions. Such matters should be satisfactorily resolved before onboarding a customer or approving a transaction. Unexplained wealth, unusual transaction patterns, reluctance to provide information, or the provision of inconsistent explanations may all represent indicators requiring enhanced scrutiny from a Financial Crime Compliance (FCC) perspective and, where appropriate, consideration of an internal Suspicious Activity Report (SAR).

To meet regulatory expectations, Maltese subject persons should:

  • Conduct a comprehensive risk assessment of the customer.

  • Apply a proportionate level of CDD based on the customer's risk rating.

  • Obtain and retain appropriate Source of Funds and Source of Wealth evidence.

  • Critically assess the information and documentation received.

  • Clearly document the rationale and outcomes of the assessment.

  • Perform ongoing monitoring throughout the business relationship.

  • Escalate and investigate inconsistencies or potential red flags where necessary.

Finally, subject persons should periodically review their AML/CFT framework and control environment, particularly following regulatory updates, changes in guidance, or findings arising from supervisory inspections. Regular reviews help ensure continued alignment with legal obligations, and industry best practice.

How We Can Help

Navigating Source of Funds and Source of Wealth requirements can be challenging, particularly as regulatory expectations continue to evolve and supervisory scrutiny increases. At MS Squared Compliance we assist subject persons in designing and enhancing their AML/CFT frameworks, developing practical procedures and guidance, conducting independent file reviews, and assessing the effectiveness of existing controls.

We also support firms in developing or performing risk assessments, remediating regulatory findings, delivering tailored staff training, and providing independent challenge to complex customer onboarding and transaction monitoring cases.

By leveraging specialist expertise, organisations can strengthen their compliance framework, improve the quality of their customer due diligence processes, and demonstrate a robust, risk-based approach that meets both regulatory expectations and industry best practices.

Email

stephanie.mangani@mssquaredcompliance.com

© 2026 MS Squared Compliance. All rights reserved.