FOR FAMILY OFFICES AND MULTI-FAMILY OFFICES

Could the office prove, four years later, that a client was informed?

An office answers for other people's wealth, across generations, and is expected to show how it answered. The duties are already written into the regimes the office lives under. The proof, almost everywhere, lives in inboxes, shared folders and the memory of whoever handled the matter at the time. Exedra Gate is one closed room where the office's work becomes its own record while it is happening.

A reviewer can confirm, with free standard tools, that the documents are unchanged and existed at the stated moment. The timestamp comes from an independent authority.

THE WORLD AS THE OFFICE MEETS IT

The duties are not vague. They name the artefact.

The recurring question in this segment is not whether an office acted properly. It is which document the office owes, to whom, on what rhythm, and whether that document can still be produced years afterwards. Each entry below is published law with its primary source attached.

Jurisdiction
United Arab Emirates

Showing rules for European Union

The argument on this page does not change with the selection. The citations do.

Every jurisdiction is shown below, grouped and labelled.

European Union

  • Advice

    A suitability statement is owed before the transaction, to a retail client, when advice is given. It has to outline the advice and explain how the recommendation meets that client’s objectives, circumstances, knowledge and experience, attitude to risk, capacity to sustain losses and sustainability preferences. The trigger is the recommendation, not the trade.

    MiFID II, Art. 25(6); Del. Reg. (EU) 2017/565, Art. 54(12)

    Source checked

  • Discretionary mandates

    Under a discretionary mandate the duty is a periodic statement instead. Once every three months by default; at least monthly where the agreement authorises a leveraged portfolio; at least once every twelve months where the client elected transaction-by-transaction reporting. The quarterly statement may be skipped only where the client has online access to up-to-date valuations and the firm has evidence that the client accessed one during the quarter.

    Art. 60(3), Del. Reg. (EU) 2017/565

    Source checked

  • Professional clients

    For professional clients the reporting duty is switched off unless they ask for it in writing, and the firm has to keep a record of that communication. Most of an office’s clients are professional or opted up, which means the recurring artefact is frequently not the report at all. It is the record of who opted in, when, and in what form.

    MiFID II, Art. 29a(2) and 29a(3), inserted by Directive (EU) 2021/338

    Source checked

  • Record-keeping standard

    Records must be kept so that the authority can reconstitute each key stage of the processing of each transaction, and so that it is not possible for the records otherwise to be manipulated or altered. That is a specification for an evidence store, written into a conduct regulation.

    Art. 72, Del. Reg. (EU) 2017/565

    Source checked

  • Anti-money-laundering

    One anti-money-laundering rulebook, every member state. The harmonised regulation applies directly across the Union from 10 July 2027, replacing national transpositions with a single text, supervised by an authority in Frankfurt with a mandate and a calendar.

    Regulation (EU) 2024/1624; AMLA

    Source checked

Switzerland

  • Advice

    The reasons behind a recommendation are documented, with no professional-client switch-off. The Swiss documentation and accountability duty is the strictest of the three jurisdictions on this point, and it does not fall away because the client is sophisticated.

    FinSA, Art. 15

    Source checked

  • Advice

    The file is not kept for its own sake. On request, the client is owed a copy of that documentation and an account of the services provided. The request can arrive years after the advice, and it is answered from the file or not at all.

    FinSA, Art. 16

    Source checked

Austria

  • Beneficial ownership

    Nominee arrangements became comprehensively reportable on 1 October 2025. Whether or not they affect ownership or control, and entities that had been exempt lost the exemption. Beneficial owners are re-checked at least annually and the confirmation is filed within four weeks of the review date; a Compliance-Package runs for twelve months with no automatic renewal. Penalties reach EUR 200,000 for an intentional breach and EUR 100,000 for a grossly negligent one.

    WiEReG, §§ 3, 5, 5a and 15; BGBl. I Nr. 151/2024

    Source checked

United Kingdom

United States

  • Private placement documentation

    Verification is a document review with a date on it. An issuer relying on Rule 506(c) must take reasonable steps to verify that every purchaser is an accredited investor, and each of the safe harbour methods the rule lists is a document review or a written confirmation with a date attached to it.

    17 CFR 230.506(c)(2)(ii), Regulation D under the Securities Act of 1933

    Source checked

  • Books and records for advisers

    The clock runs from the last entry, not from the document. An investment adviser must keep the required books and records in an easily accessible place for not less than five years from the end of the fiscal year in which the last entry was made, the first two of those years in an appropriate office of the adviser.

    17 CFR 275.204-2(e)(1), Investment Advisers Act of 1940

    Source checked

  • Anti-money-laundering records

    Five years, and accessible within a reasonable period. All records a financial institution is required to retain under the Bank Secrecy Act regulations must be kept for five years and stored so as to be accessible within a reasonable period of time.

    31 CFR 1010.430(d)

    Source checked

  • Anti-money-laundering records

    Where no record exists, one has to be made. Where no record of a transaction is made in the ordinary course of business, the institution must prepare one in writing, so the duty is to produce the record and not only to keep whatever happened to exist.

    31 CFR 1010.430(b)

    Source checked

  • Electronic signature and admissibility

    The operative word is "solely". For a transaction in or affecting interstate or foreign commerce, a signature, contract or record may not be denied legal effect, validity or enforceability solely because it is in electronic form.

    15 U.S.C. 7001(a), Electronic Signatures in Global and National Commerce Act

    Source checked

  • Electronic records and retention

    Accuracy, accessibility and reproducibility are the three conditions. Where a law requires a record to be retained, an electronic record meets that requirement if it accurately reflects the information and remains accessible to those entitled to it, for the period the law requires, in a form capable of being accurately reproduced for later reference.

    15 U.S.C. 7001(d)(1)

    Source checked

  • Substantiation on demand

    The substantiation has to exist before the claim is made. An adviser’s advertisement may not include a material statement of fact that the adviser does not have a reasonable basis for believing it will be able to substantiate upon demand by the Commission.

    17 CFR 275.206(4)-1(a)(2), Investment Advisers Act marketing rule

    Source checked

United Arab Emirates, onshore

  • AML record keeping

    The statute states the duty and defers the period. Financial institutions, designated non-financial businesses and professions and virtual asset service providers must retain all records, documents and data relating to transactions and make them immediately available to the competent authorities on request.

    Federal Decree-Law No. (10) of 2025, Article 19(1)(f)

    Source checked

  • AML record keeping

    The five years live in the Executive Regulations. Records, documents, instruments and data for domestic and international transactions and commercial dealings must be retained for not less than five years from completion of the transaction or the end of the business relationship.

    Cabinet Resolution No. (134) of 2025, Article 25(1)

    Source checked

  • AML record keeping

    The clock restarts on the most recent of several triggers. Customer due diligence records, account files, business correspondence and suspicious transaction reports run for not less than five years from the most recent of several triggers, so a later inspection, investigation or final judgment restarts the clock rather than the account closure alone.

    Cabinet Resolution No. (134) of 2025, Article 25(2)

    Source checked

  • AML record keeping

    Holding the documents is not the same as holding them usably. Retained records must be organised so that individual transactions can be reconstructed, so the duty is not merely to hold the documents but to hold them in a form that can be put back together years later.

    Cabinet Resolution No. (134) of 2025, Article 25(3)

    Source checked

  • Electronic transactions and trust services

    An original can be electronic where its integrity is evidenced. Where UAE law requires a document to be submitted or stored in its original form, an electronic document meets that requirement if there is technical evidence confirming the integrity of its information from the moment it was first created in final form, and if it can still present that information whenever it is requested.

    Federal Decree-Law No. (46) of 2021, Article 9

    Source checked

  • Electronic evidence

    Admissible, not presumed. The admissibility of an electronic document, electronic signature or electronic seal as evidence in legal proceedings cannot be denied merely because it is in electronic form.

    Federal Decree-Law No. (46) of 2021, Article 18(1)

    Source checked

  • Electronic signatures

    Equivalence attaches to the qualified tier only. Equivalence to a handwritten signature is attached to the qualified tier only: a Qualified Electronic Signature has the same legal effect as a manual signature where it meets the conditions in the Decree-Law and its Executive Regulations, and a signature below that tier does not carry that equivalence.

    Federal Decree-Law No. (46) of 2021, Article 18(3)

    Source checked

United Arab Emirates, DIFC

  • Data protection

    The duty is to comply and to be able to show it. A controller or processor must establish a programme to demonstrate compliance with the Law, and must implement appropriate technical and organisational measures to demonstrate that processing is performed in accordance with it, so the obligation is not only to comply but to be able to show it.

    Data Protection Law, DIFC Law No. 5 of 2020, Article 14(1) and 14(2)

    Source checked

  • Data protection

    The record of processing is itself a required document. A controller must maintain a written record of the processing activities under its responsibility, which may be in electronic form, covering at least the purposes, the categories of data subjects and personal data, the categories of recipients including those in Third Countries, and where possible the time limits for erasure.

    Data Protection Law, DIFC Law No. 5 of 2020, Article 15(1)

    Source checked

  • AML record keeping

    The duty catches the analysis that led to no report at all. A Relevant Person must maintain sufficient records of transactions to enable individual transactions to be reconstructed, together with the customer due diligence documents, the business correspondence relating to the customer’s account and its own internal findings and analysis on unusual or suspicious business.

    DFSA Rulebook, AML module, Rule 14.4.1(a) and (b)

    Source checked

  • AML record keeping

    Where the record sits is a decision with conditions attached. Where these records are kept outside the DIFC, the firm must take reasonable steps to ensure they are held in a manner consistent with the Rules, ensure they remain easily accessible to it, and ensure that on the DFSA’s request they are immediately available for inspection.

    DFSA Rulebook, AML module, Rule 14.4.3

    Source checked

United Arab Emirates, ADGM

  • Data protection

    The record has to exist and to be handed over on request. Each controller must maintain a record of the processing activities under its responsibility, the record must be in writing including in electronic form, and it must be made available to the Commissioner of Data Protection on request.

    Data Protection Regulations 2021, sections 28(1), 28(3) and 28(4)

    Source checked

  • Data protection

    Ongoing integrity, and a process for testing that it holds. Controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including the ability to ensure the ongoing integrity of processing systems and a process for regularly testing and evaluating whether those measures are effective.

    Data Protection Regulations 2021, sections 30(1)(b) and 30(1)(d)

    Source checked

  • AML record keeping

    The word in the rule is "immediately". A Relevant Person must maintain sufficient records of transactions to enable individual transactions to be reconstructed, and must immediately provide a copy of those records to the Regulator on request.

    ADGM Anti-Money Laundering and Sanctions Rulebook, Rules 4.5.1(b)(ii) and 4.5.2

    Source checked

  • AML record keeping

    The same conditions, from a second regulator in a second jurisdiction. Where these records are kept outside ADGM, the firm must take reasonable steps to ensure they are held consistently with the Rules, keep them easily accessible to itself, and ensure that on the Regulator’s request they are immediately available for inspection.

    ADGM Anti-Money Laundering and Sanctions Rulebook, Rule 4.5.5

    Source checked

  • Electronic records and signatures

    Electronic retention satisfies the enactment only on conditions. Where an ADGM enactment requires a record to be retained, an electronic record satisfies that requirement only if it stays accessible for subsequent reference, keeps its original format or one demonstrably replicating the original information, and retains the information identifying the record’s origin, destination, the parties who sent or received it and the date and time.

    Electronic Transactions Regulations 2021, section 4(1)

    Source checked

Singapore

  • Data protection

    This clock runs the other way: it is a duty to stop. An organisation must cease to retain documents containing personal data, or remove the means of associating that data with particular individuals, as soon as it is reasonable to assume that the collection purpose is no longer served and retention is no longer necessary for legal or business purposes.

    Personal Data Protection Act 2012, section 25

    Source checked

  • Data protection

    Modification is named alongside access. An organisation must make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal of the personal data in its possession or under its control.

    Personal Data Protection Act 2012, section 24

    Source checked

  • Data protection

    A refusal creates a preservation duty. Where an organisation refuses an individual’s request for access to their personal data, it must preserve a complete and accurate copy of that data for not less than the prescribed period.

    Personal Data Protection Act 2012, section 22A(1) and (2)

    Source checked

  • Electronic records and signatures

    Three conditions, and the list is not exhaustive. A legal requirement to retain a document is satisfied electronically only if the information stays accessible for subsequent reference, the record keeps its original format or a format demonstrably representing it accurately, and the information identifying the record’s origin, destination and the date and time it was sent or received is retained as well.

    Electronic Transactions Act 2010, section 9(1)(a) to (c)

    Source checked

Canada

Ledger entries are published in English only, and cite each instrument by its own official name.

The enforcement record behind these rules, statute by statute and figure by figure, is kept on its own page. The risk, sourced.

WHERE THE WEEK GOES

Six situations, named precisely. None of them require anyone to do anything wrong.

Deloitte's family-office study puts administration and compliance at eighteen per cent of European family-office time (Deloitte, Defining the Family Office Landscape, 2024). That share is not one large report. It is a long tail of small, deadline-bound, differently-formatted obligations, each owned by a different person.

The quarter that is assembled by hand

The periodic statement has a fixed content list: holdings and their valuation, cash at open and close, performance, total fees and charges itemised down to management fees and execution costs, the benchmark comparison where one was agreed, dividends and interest received, corporate actions, and the per-transaction detail. The data arrives from several custodians in several shapes. Somebody reconciles it, somebody formats it, and the exercise repeats in ninety days.

The evidence that a client looked

An office that relies on the online-access route to reduce reporting frequency has to hold evidence that the client actually accessed a valuation during the quarter. That evidence is a server log on somebody else's system, retained for somebody else's reasons, and it is discovered to be missing at the moment it is needed rather than before.

The client who says nobody explained the risk

Four years later a decision is disputed and the client states that the downside was never named. The office knows it was named. Knowing is not proving, and the burden of producing the file tends to sit with the office. The adviser who handled the matter may have moved on. The record must not leave with him. The case patterns, with sources.

The switch that has to justify itself

Selling one instrument to buy another triggers a documented analysis of the costs and benefits of the switch, sufficient to demonstrate that the benefits are greater than the costs. It applies to discretionary management as well as to advice (Art. 54(11), Del. Reg. (EU) 2017/565). It is the one document that genuinely straddles a sale and a purchase, and it is the one most often reconstructed afterwards from memory and a spreadsheet.

The confirmation that expires in silence

An Austrian Compliance-Package is valid for twelve months and does not renew itself. The supporting register extracts have to be no older than six weeks when they are filed. Nothing arrives to say the clock has run out; the office finds out through a penalty notice, or through a counterparty's own due diligence.

The office that cannot say what it holds

Client communication sits in an inbox, documents in a shared drive, signatures on a vendor that has changed hands twice, the obligations calendar in one person's head. Nothing is wrong, exactly. It is simply that no single place can answer what the office told which client, when, and on what basis.

WHY THE CURRENT ANSWER FAILS

The systems an office already runs were built to value assets, not to prove conduct.

Consolidation and performance platforms are good at what they were designed for: they aggregate custodians, price positions and produce a view of the portfolio. None of them produces the regulatory artefact. The suitability file, the opt-in record, the switch analysis, the register confirmation and the evidence that a disclosure was received are not portfolio data, so they live outside the portfolio system, in the tools that were nearest to hand when the duty first arrived.

That is how the proof ends up between the systems. Signing in one place, identity in another, the document itself in a third, the covering message in a mailbox, the deadline in a calendar entry nobody inherited. Each tool timestamps in its own way and keeps its records for its own retention period. When the question finally arrives, the answer has to be assembled by hand from five sources, and an assembled reconstruction can be attacked precisely because it was assembled.

The failure is structural, not careless
A file that is complete but scattered fails the same way as a file that is missing. Both answer the question late, both depend on people who were there at the time, and both leave the office arguing about its own records instead of about the matter. The fix is not more diligence from the same people. It is a place where the record is produced by the work rather than after it.
A CLOSED ROOM

The office and its clients speak on the record, and the record writes itself.

On Exedra Gate the office and its principals and clients meet inside the system rather than in an inbox. Identity verification, documents, contracts, signatures, deadlines, reports and multi-language document management run in one flow. Everything that happens becomes proof automatically: sent, opened, read, signed and independently timestamped. Nobody writes the protocol afterwards, because it is a byproduct of the work.

Read against the six situations above: the periodic statement goes out from the room and the room records who received it, who opened it and who read it, per client, with the questions each client sent back. The access the office relies on is the office's own record, not a log on a vendor's server. A decision or an opt-in is signed inside the room and signed at the moment it is made, which is what turns the switch analysis and the opt-in communication from a reconstruction into an entry. Deadlines and duties are carried alongside the artefact that proves each one was met, so a confirmation with a twelve-month life is a dated obligation rather than a silence. And if a mandate ends, the client's records leave with the relationship, complete.

A signature is given on the phone in the client's pocket, wherever he happens to be. The Exedra Gate app is arriving, and will carry the same room onto the device itself.

The record, as it accumulates

An invitation, an identity check, a document, a signature and a document-room access arrive in order, each carrying a fingerprint, thread onto one chain, and close in a final entry carrying an independent timestamp. The same chain continues past that entry: a periodic statement, its opened and read receipts for each recipient, a question answered inside the room, an appointment and its reminder, an obligation met alongside the artefact that proves it, a certified translation beside the original, and finally the exit, where every record leaves with the client.

The evidence pack is the flight recorder.

Nobody thinks about it while the work is going well; then something goes wrong, and it is the only thing that matters. Each engagement closes into one evidence pack: every document, identity check, signature and access, in order, each entry fingerprinted and chained to the one before it. The signature carries a timestamp issued under RFC 3161 by an authority that is not Exedra Gate.

One check, reproducible years later

A document is fingerprinted, the fingerprints are chained and signed, and the record carries a timestamp from an independent authority. Years later, a different reviewer runs the same check with free standard tools and confirms the documents are unchanged and existed at that moment.

The claim is narrow and checkable: a reviewer confirms with free standard tools that the documents are unchanged and existed at that moment, because the timestamp comes from an authority that is not Exedra Gate. Whether a record satisfies a particular legal standard remains a question for counsel; the record's integrity and its date do not depend on anyone's word.
SOVEREIGNTY

One place, and the office decides where that place stands.

A family's affairs do not belong on whichever continent a vendor found convenient. Where four vendors meant four legal bases, four processor agreements and four registers to search on every subject-access request, one place means one. It is deployed where the office's obligations point: as a managed service, as a white-label deployment on a server of the office's choosing, in Germany, in Switzerland, or inside infrastructure the office controls.

Offices rarely fit a template, so custom features are built on request. That is a plain fact about how Exedra Gate works with an office, and such work is quoted and delivered as an engagement rather than configured from a form. Deployment models, stated.

WHAT THE OFFICE KEEPS
  • A workspace per family and per entity, separated at the database
  • Records signed and independently timestamped, checkable years later with free standard tools
  • Residency where the office chooses, as a scoped engagement
  • Custom features as an engagement, not a form
  • Every record on exit, complete
WHAT IT LOOKS LIKE IN PRACTICE

Which parts the office touches, and in what order.

An office does not adopt a platform in one movement. The order below is the order the work already happens in, which is why it is also the order of adoption.

  • FIRST

    The client and entity workspaces. One room per family and per entity, held side by side and switched deliberately. Isolation is enforced in the database rather than in the interface, and the cases that must be refused are tested.

  • THEN

    Identity, once. The people behind each relationship are verified, and the check is an entry in the record with its own date rather than a folder of scans. Ownership above 25% is declared under signature and corroborated where public registers permit.

  • THEN

    Documents and signatures. The document is generated in the room, signed on the phone, and independently timestamped as it is signed. One version, one place, one timestamp, and a certified translation delivered beside the original rather than instead of it.

  • THEN

    Communication that counts as evidence. Statements, disclosures and updates go out from the room and come back with receipts per recipient. Messaging stays inside the room, with a polite email follow-up when a message goes unanswered.

  • THEN

    Obligations and their proof. Each duty carries its deadline and the artefact that answers it, in the calendars the office already uses. An annual confirmation with a twelve-month life stops being a memory problem.

  • WHEN ASKED

    The export. One evidence pack per relationship, in one shape, handed over rather than assembled. The reviewer checks it on his own machine, with free standard tools, without asking Exedra Gate for anything.

The compliance rail is live in production today. The mobile app is arriving and is named as arriving wherever it appears. What runs today, in full.

THE CLOSE

Time will show who was prepared.

The rules are published and the calendars are fixed. The questions arrive on their own schedule, usually about work done years earlier, and they are answered from records or from memory. An office that prepares answers in minutes. Exedra Gate exists for it.

Access is by invitation. A short note on the office and its situation is enough; where there is a fit, the walkthrough happens on a live system.

Exedra Gate is a technology platform, not a broker, dealer, custodian, escrow provider, or investment adviser. It never holds, routes, or settles investor funds, does not recommend offerings to investors, and charges no success-based fees on raises. Records and timestamps attest integrity and existence as of a date, not compliance with any particular regime; that judgment remains with the office and its counsel.

Regulatory references on this page are orientation, not legal advice: see Sources & verification.