Source of funds and source of wealth differ, and regulators treat them differently. Here's what the FCA, FinCEN and FATF require, and what documentation counts.
Table of contents
- Source of funds and source of wealth are different questions, and conflating them is the most common failure in enhanced due diligence.
- Source of funds verification confirms where the specific money in a transaction came from; source of wealth explains how the customer's overall net worth was accumulated.
- FATF Recommendation 10 requires establishing source of funds and wealth for higher-risk customers, the FCA expects it under its enhanced due diligence rules, and FinCEN frames it through risk-based customer due diligence.
- What counts as evidence is specific: payslips, sale-of-asset documents, an inheritance grant, business-distribution records, or, for crypto, blockchain provenance.
- Source of funds is the most common driver of gambling and private-banking AML fines, because firms let large sums flow without establishing origin.
- The defensible standard is documented, risk-proportionate evidence, kept current, not a one-time tick box at onboarding.
Source of funds verification establishes and evidences where the specific money in a transaction originated, such as salary, a property sale, or inheritance. It is distinct from source of wealth, which explains how a customer's total net worth was built, and is a core enhanced-due-diligence measure for higher-risk customers.
TL;DR
The single most common mistake in this area is treating source of funds and source of wealth as the same thing. They are not. Source of funds verification establishes where the specific money in a transaction came from, the £50,000 that just landed. Source of wealth explains how the customer accumulated their overall net worth. Regulators expect both for higher-risk customers, and they expect evidence, not assertions.
FATF Recommendation 10 requires establishing source of funds and wealth for enhanced due diligence, the FCA expects it for higher-risk relationships, and FinCEN frames it through risk-based customer due diligence. What counts as evidence is concrete: payslips, a property-sale contract, an inheritance grant, business distributions, or blockchain provenance for crypto. This guide separates the two concepts, sets out the regulatory expectations, lists the documentation that counts, explains the triggers, covers crypto, and describes the audit trail that holds up.
11 min read. Last updated 30 September 2026.
What is the difference between source of funds and source of wealth?
The distinction is the whole game. Source of funds is the immediate origin of the specific money in question: the salary payment, the proceeds of a sale, the transfer from another account that funded this transaction. Source of wealth is the bigger story: how the customer came to have the assets they hold at all, their career, business ownership, investments, or inheritance over time.
A customer can have a clean source of funds for a single deposit while their overall source of wealth remains unexplained, and vice versa. For higher-risk customers, enhanced due diligence requires both, because money laundering hides in the gap between them: clean-looking funds drawn from an unexplained fortune. Establishing one and assuming the other is exactly the shortcut regulators penalise. The broader enhanced-due-diligence process this sits within is covered in our enhanced due diligence workflows guide.
What do the FCA, FinCEN and FATF require?
The three frameworks align in substance. FATF Recommendation 10 requires institutions, when applying enhanced due diligence to higher-risk customers, to take reasonable measures to establish the source of funds and source of wealth. The UK's FCA, under the Money Laundering Regulations and its systems-and-controls expectations, requires enhanced scrutiny including establishing source of funds and wealth for higher-risk relationships, and has repeatedly enforced against firms that did not. FinCEN does not use a single prescriptive source-of-funds rule, but its risk-based customer due diligence expectations and the BSA require institutions to understand the nature and purpose of relationships and to scrutinise higher-risk activity, which in practice means establishing origin of funds where risk warrants.
The common thread is risk-proportionate and evidenced. None of the regulators wants source-of-funds checks on every low-risk customer, and all of them expect rigorous, documented checks where risk is elevated, by customer type, geography, product, or transaction size. The failure mode they punish is letting large or unusual sums move without establishing where they came from.
What documentation actually counts as evidence?
Source of funds verification is only as good as the evidence behind it, and assertions do not count. The documentation that does, depending on the stated origin, includes a recent payslip or employment contract for salary, a signed contract and completion statement for a property or asset sale, a grant of probate or solicitor's letter for an inheritance, dividend vouchers or company accounts for business distributions, and bank statements showing the funds' path. For investment gains, brokerage statements; for a loan, the loan agreement.
The principle is corroboration: the customer states an origin, and you obtain independent documentation that supports it, proportionate to the risk and the amount. A single screenshot or a verbal explanation is not evidence. For very high-risk or very large sums, expect to layer multiple corroborating documents. And the documents must actually establish the chain, a bank statement showing money arriving does not explain where it came from before that, which is the gap weak checks leave open.
When is source-of-funds work triggered?
Source of funds verification is risk-based, so the question is when it switches on. The standard triggers are: a customer assessed as higher-risk at onboarding (a PEP, a high-risk jurisdiction, a complex structure); a transaction that is large or unusual relative to the customer's known profile; activity inconsistent with the stated purpose of the relationship; and any red flag from monitoring, sanctions, or adverse media. In gambling, deposit velocity and affordability signals are common triggers; in private banking, the sheer size of sums.
Crucially, the trigger can fire after onboarding, not just at the start. A customer who was low-risk can become high-risk through their behaviour, and that should prompt source-of-funds scrutiny then, not at the next scheduled review. Treating source of funds as a perpetual, trigger-driven obligation rather than an onboarding step is the model regulators increasingly expect, the same logic as perpetual KYC.
How does crypto change source-of-funds checks?
Crypto adds a layer that fiat does not have: on-chain provenance. For a customer funding an account with crypto, source of funds verification can and should examine where the assets came from on the blockchain, whether they trace to an exchange, a mixer, a sanctioned address, or illicit-source funds, using blockchain analytics alongside the customer's explanation. This is where on-chain analytics and identity verification meet, as covered in our crypto compliance software comparison.
The challenge is that on-chain provenance establishes the path of the tokens but not always the real-world origin of the value, and a customer can have clean-looking on-chain funds bought with unexplained fiat. So crypto source-of-funds checks combines blockchain provenance with the same real-world evidence as fiat: how did the customer acquire the means to buy the crypto. Done well, the on-chain view actually strengthens the check, because the transaction history is transparent in a way bank-to-bank transfers are not.
What audit trail does a regulator expect?
When a regulator reviews source-of-funds work, it wants to reconstruct your judgement. The audit trail should show, per relevant customer or transaction: what triggered the source-of-funds requirement, the customer's stated origin, the corroborating documents obtained and how they were verified, the analyst's assessment and any escalation, and the date. For source of wealth, the broader rationale for how the customer's net worth is explained.
The firms that fail examinations are those whose files assert a source of funds without evidence, or show a single document that does not actually establish origin, or cannot show why a large transaction was allowed. The firms that pass can produce the corroboration and the reasoning. As with the rest of enhanced due diligence, source of funds is judged on the defensibility of the documented decision, not on whether a box was ticked, which connects to the AML compliance software layer that should capture it.
When is light-touch source of funds enough?
Source of funds verification is risk-based, which means it is not required at full intensity for everyone, and over-applying it is its own problem. For genuinely low-risk customers conducting normal, expected activity within their profile, demanding full source-of-funds documentation adds friction and collects sensitive financial data you must then protect, without a proportionate risk basis.
The defensible approach is to reserve rigorous source-of-funds checks for the higher-risk triggers, large or unusual transactions, elevated-risk customers, and red flags, and to apply proportionate, lighter checks elsewhere, with the risk assessment documented either way. The mistake is not light-touch checks on low-risk customers; it is failing to escalate when a trigger fires, or applying heavy checks indiscriminately and drowning in data. Match the depth to the risk. To pressure-test your triggers and evidence standards, book a review.
The bottom line
Source of funds verification fails when it is confused with source of wealth, reduced to an unevidenced assertion, or treated as a one-time onboarding tick box. The FCA, FinCEN, and FATF all expect the same thing for higher-risk customers: establish where the specific money came from and how the customer's wealth was built, with corroborating evidence proportionate to the risk, kept current.
Separate the two questions, document the corroboration, treat the obligation as trigger-driven rather than calendar-bound, and use on-chain provenance to strengthen crypto checks. Do that, and the source-of-funds file becomes a defence rather than the gap an examiner walks through.
Book a source-of-funds review, or see how it works.
Related resources
- Enhanced due diligence workflows
- Perpetual KYC vs periodic KYC
- PEP screening in 2026
- AML compliance software in 2026
- Crypto compliance software: a 2026 comparison
- KYC software
- How it works
Cited sources
- FATF Recommendations (Recommendation 10, customer due diligence): https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
- Financial Conduct Authority, financial crime and enhanced due diligence: https://www.fca.org.uk/firms/financial-crime
- FinCEN, Bank Secrecy Act and customer due diligence: https://www.fincen.gov/
- EU Anti-Money Laundering framework (AMLA): https://www.amla.europa.eu/about-amla_en
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.