FOR SOVEREIGN WEALTH FUNDS AND STATE-OWNED INVESTORS

Three examiners, one record. The owner, the auditor, the host country.

A sovereign investor is the most examined participant in any private transaction. Its governance standard demands documented dealing with third parties and an annual audit. Host countries screen it precisely because it is state-controlled. Its counterparties open enhanced files on its people because the law tells them to. Every one of those examinations is answered from records, years after the deal team has dispersed. Exedra Gate is the rail on which that record is produced by the work itself, in a deployment scoped to where the fund's mandate says it must stand.

A reviewer can confirm, with free standard tools, that the documents are unchanged and existed at the stated moment. The timestamp comes from an independent authority.

THE WORLD AS A SOVEREIGN INVESTOR MEETS IT

A voluntary standard, binding laws, and screening aimed at exactly this reader.

The Santiago Principles are voluntary and self-assessed; the funds that adhere to them declare their own implementation and review it themselves. Everything else below is law, and most of it belongs to someone other than the fund: the host country, the counterparty, the data-protection regime of wherever the deal file happens to sit. Each entry carries its primary source. Host countries screen the investment because of who the investor is, and where the deal file sits is regulated from both ends.

Jurisdiction
United Arab Emirates

Showing rules for European Union

The argument on this page does not change with the selection. The citations do.

Every jurisdiction is shown below, grouped and labelled.

European Union

  • Investment screening

    The Union rewrote its screening regulation, and the successor is adopted. The Union adopted a successor foreign-investment screening regulation on 17 June 2026, replacing the 2019 framework. A filing wants the ownership chain to the ultimate owner, the governance rights and the funding of the specific investment, reproducible as filed.

    Regulation (EU) 2026/1386

    Source checked

  • Where the deal file sits

    Where the deal file sits is regulated from both ends. Personal data of EU-resident founders, directors and signatories may leave the Union only under the transfer chapter, and providers of data processing services in the Union must take measures against third-country governmental access to the non-personal data they hold. The fund’s regulated counterparties add their own layer: EU financial entities carry ICT third-party risk obligations for every vendor in their chain, applicable since 17 January 2025.

    GDPR, Arts. 44 to 50; Data Act, Art. 32; DORA

    Source checked

Germany

  • Investment screening

    Germany reviews acquisitions under its foreign trade law. A filing is a documentation event: the control chain, the governance, the funding of the specific investment, assembled and reproducible.

    AWG/AWV, sections 55 ff.

    Source checked

Switzerland

  • Investment screening

    Switzerland’s screening act is adopted and not yet in force. The Investment Screening Act was adopted by Parliament on 19 December 2025, introducing an approval requirement for state-controlled foreign investors in particularly critical sectors, with entry into force foreseen for 2027 and the ordinance consultation opened on 12 June 2026.

    Investitionsprüfgesetz (SECO, Investitionsprüfung)

    Source checked

  • Where the deal file sits

    Switzerland imposes its own cross-border conditions. Personal data leaving Switzerland travels under the Federal Act on Data Protection’s own transfer conditions rather than the Union’s, which is why where the deal file sits is regulated from both ends.

    FADP, Arts. 16 and 17

    Source checked

United Kingdom

United States

  • Anti-money-laundering records

    Five years, and accessible within a reasonable period. All records a financial institution is required to retain under the Bank Secrecy Act regulations must be kept for five years and stored so as to be accessible within a reasonable period of time.

    31 CFR 1010.430(d)

    Source checked

  • Sanctions record duties

    Ten years, and it reaches parties that are not banks. Every person engaging in a transaction subject to the sanctions regulations must keep a full and accurate record of it, available for examination for at least ten years after the transaction, whether or not the transaction was licensed.

    31 CFR 501.601, Reporting, Procedures and Penalties Regulations

    Source checked

  • Screening aimed at who the investor is

    Some filings are mandatory rather than voluntary. A declaration to the Committee on Foreign Investment in the United States is mandatory where a foreign person in which a foreign state holds a substantial interest acquires a substantial interest in a TID U.S. business, and separately where the transaction involves critical technologies for which a U.S. regulatory authorization would be required to export to the person concerned.

    31 CFR 800.401(a) to (c)

    Source checked

  • Electronic signature and admissibility

    The operative word is "solely". For a transaction in or affecting interstate or foreign commerce, a signature, contract or record may not be denied legal effect, validity or enforceability solely because it is in electronic form.

    15 U.S.C. 7001(a), Electronic Signatures in Global and National Commerce Act

    Source checked

United Arab Emirates, DIFC

  • Data protection

    The duty is to comply and to be able to show it. A controller or processor must establish a programme to demonstrate compliance with the Law, and must implement appropriate technical and organisational measures to demonstrate that processing is performed in accordance with it, so the obligation is not only to comply but to be able to show it.

    Data Protection Law, DIFC Law No. 5 of 2020, Article 14(1) and 14(2)

    Source checked

  • Data protection

    The record of processing is itself a required document. A controller must maintain a written record of the processing activities under its responsibility, which may be in electronic form, covering at least the purposes, the categories of data subjects and personal data, the categories of recipients including those in Third Countries, and where possible the time limits for erasure.

    Data Protection Law, DIFC Law No. 5 of 2020, Article 15(1)

    Source checked

  • AML record keeping

    Where the record sits is a decision with conditions attached. Where these records are kept outside the DIFC, the firm must take reasonable steps to ensure they are held in a manner consistent with the Rules, ensure they remain easily accessible to it, and ensure that on the DFSA’s request they are immediately available for inspection.

    DFSA Rulebook, AML module, Rule 14.4.3

    Source checked

United Arab Emirates, ADGM

  • Data protection

    The record has to exist and to be handed over on request. Each controller must maintain a record of the processing activities under its responsibility, the record must be in writing including in electronic form, and it must be made available to the Commissioner of Data Protection on request.

    Data Protection Regulations 2021, sections 28(1), 28(3) and 28(4)

    Source checked

  • AML record keeping

    The same conditions, from a second regulator in a second jurisdiction. Where these records are kept outside ADGM, the firm must take reasonable steps to ensure they are held consistently with the Rules, keep them easily accessible to itself, and ensure that on the Regulator’s request they are immediately available for inspection.

    ADGM Anti-Money Laundering and Sanctions Rulebook, Rule 4.5.5

    Source checked

Canada

  • Securities regulation structure

    There is no federal securities regulator to answer to. Canada has no federal securities regulator: the Supreme Court of Canada held in 2011 that the proposed federal Securities Act as then drafted was not valid under the general trade and commerce power, so an issuer answers to provincial and territorial regulators rather than to a national one.

    Reference re Securities Act, 2011 SCC 66, paragraph 134

    Source checked

Regimes that belong to no one country

These regimes are not the law of any one country, so there is nothing here for a reader to select. They reach this sector whichever jurisdiction is chosen above, and they are shown to every reader.

  • Host-country compliance

    Multilateral regimes

    Host-country compliance is part of the fund’s own standard. Operations and activities in host countries are to be conducted in compliance with all applicable regulatory and disclosure requirements of the countries in which the fund operates. A per-jurisdiction duty, answered per jurisdiction, with proof.

    Santiago Principles, GAPP 15

    Source checked

  • Dealing with third parties

    Multilateral regimes

    Dealing with third parties follows clear rules and procedures. The selection of an operational vendor is itself a governed act, on economic and financial grounds, under procedures the fund can show.

    GAPP 14

    Source checked

  • Audit

    Multilateral regimes

    The operations and the statements are audited every year. The fund’s operations and financial statements are audited annually to recognised standards.

    GAPP 12

    Source checked

  • Audit

    Multilateral regimes

    The risk framework has to include the reporting and the audit function. A risk framework that must include reliable information and timely reporting systems and an independent audit function.

    GAPP 22

    Source checked

  • Audit

    Multilateral regimes

    The implementation of the principles themselves is reviewed on a rhythm. A voluntary standard with a review cycle attached, which is what makes adherence a dated record rather than a statement.

    GAPP 24

    Source checked

  • Politically exposed persons

    Multilateral regimes

    The fund’s people are enhanced-diligence subjects by definition. The international standard names senior executives of state-owned corporations as politically exposed persons; a counterparty’s institution must obtain senior management approval for the relationship, establish source of wealth and source of funds, and monitor it on an enhanced, ongoing basis. Both sides carry that file for the life of the relationship.

    FATF Recommendation 12

    Source checked

Ledger entries are published in English only, and cite each instrument by its own official name.

The architecture, as one state has built it

Norwegian law and practice, shown as an example rather than as a duty. Comparable architecture exists elsewhere under each fund’s own statute.

  • GOVERNED SOURCING

    A governed vendor selection is a documented one. Norges Bank Investment Management’s published sourcing policy is what that looks like in practice: written contracts, due diligence approved by executive management before outsourcing, and written records of procurement processes maintained under archiving requirements (NBIM, sourcing and service provider management).

  • NORWAY

    The worked example: a fund whose record is examined by statute. Norway’s Government Pension Fund is managed under its own act (Act No. 123 of 21 December 2005); the management mandate requires fair-value reporting to international standards, with unlisted real estate valued at least annually by an appointed, certified independent valuation firm (GPFG management mandate); and the state auditor, answerable to parliament, audits how it is all done (Riksrevisjonen).

WHERE IT GOES WRONG

Five situations, named precisely. Every one is a request for a record the fund must already hold.

The screening filing that wants the whole chain

A screened transaction asks for the ownership and control chain to the ultimate owner, the governance evidence, the funding of the specific investment, and it asks in more than one jurisdiction at once, each with its own format and clock. The answer exists, scattered across counsel, managers and prior filings. Assembling it under deadline is the failure mode; reproducing exactly what was filed, years later, is the second one.

The enhanced-diligence file that never closes

Every counterparty institution opens a politically-exposed-person file on the fund's people, and the fund answers the same questions about identity, source of wealth and control, deal after deal, bank after bank. Each answer is produced fresh because the last one lives in someone else's system, attested by nobody, dated by a mailbox.

The co-investment examined a decade later

An unlisted position is valued annually, folded into audited statements, and open to a performance audit by a supreme audit institution. The examination lands on the transaction record: what was signed, in which version, on which date, on whose authority. The deal team that knows the answers from memory is three reorganisations away.

The vendor selection that is itself audited

Dealing with third parties follows clear rules and procedures, and the procurement record is kept under archiving requirements. A fund must be able to show how the tool that holds its deal record was chosen, what controls it supplies, and that the arrangement is reviewed. A vendor that cannot document its own workings puts a finding in the fund's audit, not its own.

The deal file in the wrong jurisdiction

The data room for a European transaction fills with personal data that is not free to travel, under transfer rules that belong to the counterparty's law, not the fund's choice. A generic cloud deal room in a third country turns every upload into a transfer question. The residency requirement arrives from the fund's own cloud and data law and from its regulated counterparties, and it arrives after the room is already full.

WHY THE CURRENT ANSWER FAILS

Everyone else's records are attested by everyone else.

A sovereign direct deal produces records in the manager's system, the counsel's document tool, the bank's onboarding platform, a signing vendor and a data room, each in its own jurisdiction, each with its own clock, each attested by the party that produced it. The fund's duties cut across all of them: the audit, the screening file, the host-country disclosure and the procurement record are questions about ordering and consistency between systems that were never designed to agree.

What is actually missing
Not another portal. A record of the fund's own acts, produced as they happened, dated by someone other than the fund or its vendor, held where the fund's law wants it held, and exportable in one shape when any of the three examiners asks.
A CLOSED ROOM

The record of the fund's own acts, produced by the work.

On Exedra Gate the fund's deal team, its counsel and its counterparties work inside one system rather than around it. Identity files, the data room, versioned transaction documents, signatures, approvals and deadlines run in one flow, and each step becomes an entry as it happens: sent, opened, read, signed and independently timestamped issued under RFC 3161. Nobody writes the protocol afterwards.

Set against the five situations above: the control-chain documents behind a screening filing are signed versions with dates, reproducible as filed. The identity and source-of-funds documentation that counterparties keep asking for exists once, current, with a record of exactly what was shared with whom and when. The transaction record that an auditor examines a decade later is a chain of dated entries, not a reconstruction. And the fund's own vendor file on Exedra Gate writes itself: the platform's workings are documented, its every material action is logged on the same rail it sells, and the usage record itself is signed and independently timestamped.

The boundary is stated, not implied. Exedra Gate introduces no transactions, recommends nothing to anyone, arranges nothing, holds and moves nothing. It is infrastructure for the deals the fund already has, chosen the way a fund chooses any operational vendor: on documented grounds, under its own procedures. The Santiago Principles are the fund's voluntary standard, and adherence to them is the fund's own declaration; no forum, authority or standard-setter certifies this platform or anything done on it.

One check, reproducible years later

A document is fingerprinted, the fingerprints are chained and signed, and the record carries a timestamp from an independent authority. Years later, a different reviewer runs the same check with free standard tools and confirms the documents are unchanged and existed at that moment.

The claim is narrow and checkable: a reviewer confirms with free standard tools that the documents are unchanged and existed at that moment, because the timestamp comes from an authority that is not Exedra Gate. Whether a record satisfies a particular legal standard remains a question for counsel; the record's integrity and its date do not depend on anyone's word.
SOVEREIGNTY

Deployment is decided by the mandate, and scoped as an engagement.

For this reader, deployment is part of the requirement, and it is treated that way: a dedicated, single-tenant deployment is scoped, quoted and delivered as an implementation engagement, with residency in the jurisdiction the engagement specifies, never configured from a self-serve setting. The transfer rules of the GDPR and the FADP, and the provider duties of the Data Act on third-country governmental access, are inputs to that scoping conversation, not questions deferred to a vendor's terms.

The record stays the fund's in the strongest sense: it exports in standard formats, in one shape, and is checked on the fund's own machine with free tools. A vendor questionnaire, an ICT third-party review or an exit is answered from the same property. Deployment mechanics, the export and the verification are described once, for every sector: how the rail is deployed.

WHAT IT LOOKS LIKE IN PRACTICE

Which parts the fund touches, and in what order.

  • FIRST

    A scoping engagement, not a checkout. Jurisdiction, residency, naming and integration are decided before anything runs; the outcome is a scoped, quoted implementation engagement for a dedicated single-tenant deployment.

  • THEN

    A workspace per transaction. Each deal is its own room with its own clocks, its own document versions and its own counterparty list, held beside the others.

  • THEN

    The standing files. Identity, control-chain and governance documentation kept current once, versioned and signed, with a dated record of every disclosure to every counterparty instead of a fresh assembly each time.

  • THEN

    Contracts and signatures. Generated in the room, signed on the phone and independently timestamped as they are signed, with who opened what recorded alongside them. Approvals that need two people get two keys, and the record shows both.

  • WHEN ASKED

    The export. One evidence pack per transaction, in one shape, handed to an auditor, a screening authority's request or the owner's review rather than assembled for them, and checked on their own machine with free standard tools.

The compliance rail is live in production today. The mobile app is arriving and is named as arriving wherever it appears. What runs today, in full.

THE CLOSE

The examiners are patient. The record has to be older than the question.

The audit is annual, the screening regimes are new and expanding, and the questions land on records years after the people who made them have moved on. A fund that prepares answers from the record. Exedra Gate exists for it.

Access is by invitation. A short note on the mandate and the deployment requirements is enough; where there is a fit, the walkthrough happens on a live system, using the fund's own scenario.

Exedra Gate is a technology platform, not a broker, dealer, custodian, escrow provider, or investment adviser. It never holds, routes, or settles investor funds, does not recommend, introduce or arrange investments for anyone, and charges no success-based fees. For sovereign and state-owned investors it is deal-preparation and evidence infrastructure only. The Santiago Principles are a voluntary, self-assessed standard of their adherents; nothing here implies that any forum, authority or standard-setter supervises, certifies or endorses Exedra Gate. Records and timestamps attest integrity and existence as of a date, not compliance with any particular regime; that judgment remains with the fund and its counsel.

Regulatory references on this page are orientation, not legal advice: see Sources & verification.