Circular N°62 from the Unidad de Análisis Financiero updated the operational expectations for asset managers and wealth managers in Chile. Eighteen months on, we’ve taken three Chilean managers through their first inspection on the back of it. None received a finding. None had to explain themselves.
This is what we learned. It’s the implementation we wish someone had handed us when N°62 first dropped.
What N°62 actually changed
The headline change was a tightening of the operational expectations around continuous monitoring and beneficial-ownership verification. The deeper change was a shift in posture: where previous circulars asked managers to demonstrate their AML programme on inspection, N°62 expects managers to operate it continuously and produce evidence on demand.
In practice, that means three things had to be in place by inspection day:
- A PEP and sanctions screening process that re-runs continuously, not just at onboarding
- A beneficial-ownership map for each investor, traceable to source documents
- An evidence trail that an inspector can request, retrieve and audit without IT involvement
It’s the third point that catches most managers out. The technical controls are usually there. The evidence retrieval is what crumbles.
The five controls that actually mattered
Across three inspections, the same five controls came up every time. If you have all five in production, the rest of N°62 is a paperwork exercise.
1. Continuous re-screening of every active investor
Onboarding-only screening is no longer sufficient. Every active investor must be re-screened on a documented cadence (we run daily delta scans, weekly full scans). Crucially, the re-screen log itself is what the inspector wants to see — not the absence of hits.
We use an override hierarchy: two providers (we use Sumsub plus OpenSanctions) plus a manual review queue. Hits that match across both providers are an automatic case. Single-provider hits go to manual review with a 24-hour SLA.
2. Beneficial-ownership mapping with source provenance
For every investor, the beneficial-ownership tree must be traceable to a source document. We capture the document, the timestamp, the operator who recorded it, and the version of the screening rules that was active at the time.
This sounds heavy. It is. But it’s also the single hardest thing to retro-fit, so we strongly recommend doing it from day one.
3. Suspicious operations registry with reason codes
Every investor interaction that triggered an internal review goes into the registry — even if the review concluded “no action required.” Inspectors want to see the reasoning, not just the outcome. We use a fixed reason-code taxonomy (12 codes covering the common patterns) plus a free-text annotation field.
The control isn’t “did you flag suspicious activity.” The control is “can you produce the reasoning behind every interaction that someone might later consider suspicious.”
4. Operator-attribution on every regulatory-relevant action
This is the boring one that catches everyone. Every action that has regulatory implications — opening an account, changing risk profile, processing a transfer above threshold — must be attributable to a named operator with a timestamp. Not “the system did it.” A person did it; the system recorded that they did.
If your platform was designed without this in mind, fixing it after the fact is genuinely hard. We’ve seen managers spend $300k retro-fitting operator attribution to systems that were never designed for it.
5. Single-pane evidence retrieval
The retrieval test is the one most managers fail. Inspector asks for “all interactions with investor X over the last two years, including the screening history and operator attribution for every action.” The answer must be a single query, not a coordinated dance across three systems.
Our implementation uses a unified audit log indexed by investor. Every relevant event from the PMS, the onboarding flow and the case-management tool flows into it. The retrieval query takes about 800ms.
What we’d skip
A few things appear prominently in N°62 guidance that, in our experience, the inspectors care less about than expected:
- Risk-rating models. Inspectors care that you have one and it’s documented. They don’t care which one.
- Transaction monitoring rules. They care that the rules exist and trigger; they care less about the specific thresholds.
- Quarterly compliance reports to the board. They want to see them; they don’t read them in detail.
We’re not suggesting you skip these — you can’t. But if you’re prioritising, the five controls above earn their seat first.
The build vs buy question
Three of the five controls are well-served by good vendor tooling. Continuous screening, evidence retrieval and the operations registry are commodity capabilities at this point.
The other two — beneficial-ownership mapping with source provenance, and operator attribution — usually need to be built into your specific platform. Not because the patterns are exotic, but because they touch every system in your stack and bolt-on solutions tend to leave gaps.
Our onboard module ships with all five built in for managers running on our platform. For managers running their own platforms, the System Integration team usually has the better answer.
Carmen Riquelme leads compliance engagements at finnerve. If you’re preparing for a UAF inspection or want a second pair of eyes on your N°62 readiness, start a conversation.