Blueprint Intelligence / Data Room and DDQ / Firm governance, risk, and compliance, the regulatory layer beyond the operational one

Data Room and DDQ

Firm governance, risk, and compliance, the regulatory layer beyond the operational one

The operational due diligence checklist covers whether a fund's infrastructure actually works. This section covers something adjacent but different: whether the firm can demonstrate it is a properly registered, properly monitored entity under the regulatory obligations that apply to it.


Blueprint's operational due diligence checklist covers the infrastructure layer, cybersecurity, business continuity, a named compliance officer. This section of the DDQ sits next to that but asks a different question: whether the firm can demonstrate active regulatory compliance, meaning anti-money-laundering readiness, sanctions screening, a clean or disclosed regulatory history, and a written code of conduct governing how the firm itself behaves.

ILPA and ILPA DDQ are marks of the Institutional Limited Partners Association. Blueprint is not affiliated with, endorsed by, or certified by ILPA.

AML and KYC, a readiness question ahead of the deadline

The FinCEN investment adviser anti-money-laundering rule carries an effective date deferred to 2028, which means a first-time manager is not yet legally required to have a fully built program. Institutional LPs are not waiting for the deadline to ask about it. A written AML and KYC readiness plan, even one describing a program not yet fully operational, is what this section expects today, and a fund with nothing written down yet is behind the timeline LPs already assume.

What else this section documents

  • OFAC and sanctions screening procedures, required specifically for any LP based in or investing through a regulated jurisdiction.
  • Regulatory history disclosure: any disciplinary actions, SEC inquiries, or other material compliance events, disclosed directly rather than omitted on the theory that nothing came of them.
  • A conflicts of interest policy covering co-investment allocation, cross-fund investing, related-party transactions, and personal investments by firm principals.
  • A personal trading and co-investment policy for the firm's own investment professionals, separate from the fund-level co-investment policy covered elsewhere in this pillar.

The code of conduct, and why bank LPs specifically ask for it

An industry code of conduct covering harassment, discrimination, and workplace violence, including a stated reporting channel, an investigation process, and a non-retaliation commitment, is a specific item bank-affiliated LP compliance teams check as part of their own counterparty review. It is not a symbolic document. A fund without one, asked for it directly by a bank LP's compliance team, has no fallback answer, since this is not a policy most first-time managers think to draft until asked.

A written AML and KYC readiness plan is expected before the FinCEN rule's 2028 effective date, not after it. Institutional LPs are already asking the question the rule will eventually require an answer to.

Check your compliance documentation

Upload your compliance manual, your conflicts of interest policy, or a description of your current regulatory readiness. No signup required for your first result.

One document, PDF or Word. Blueprint reads it to produce this one result and does not keep it afterward.

The Diagnostic is free.

Complete the intake, upload up to 10 documents, and receive your initial readiness snapshot and diligence coverage map. Upgrade when you are ready to build.