AML & Financial Crime – Page 4 – grcsight.com

Suspicious activity vs suspicious transaction

Suspicious activity vs suspicious transaction Suspicious activity and suspicious transaction describe two overlapping but distinct reporting concepts, and the difference is more than naming. A suspicious transaction report is anchored to a completed transaction; a suspicious activity report can cover behaviour, attempted transactions, or a relationship pattern even without one. Most of the time the terms get used interchangeably, which is exactly where the confusion starts. Key takeaways A suspicious transaction report needs a completed transaction; a suspicious activity report can cover behaviour or attempts without one. FATF Recommendation 20 sets the international baseline that most STR-terminology countries built their law around. The US uses SAR terminology under the Bank Secrecy Act, filing with FinCEN using Form 111. The UK uses SAR terminology too, despite following the same FATF standard that produced STR elsewhere, a reminder that naming doesn’t reliably signal scope. Monitoring systems need calibrating to whichever model actually applies locally, not treated as one global rule set. The 2024 TD Bank case, over $3 billion in combined penalties, shows the real cost of a monitoring gap in this area. On this page What each term actually coversWhy the same underlying obligation has two namesThe US SAR modelThe FATF STR model most other countries followWhere the UK sits in this splitWhy the distinction matters for transaction monitoring designA real case that shows what gets missedWhat this means for a global compliance programmeFAQsRead more $5,000 / $2,000 US SAR filing thresholds for most banks vs money services businesses Source: Bank Secrecy Act / FinCEN $3bn+ Combined FinCEN/DOJ penalty against TD Bank in 2024 for suspicious transaction monitoring failures Source: FinCEN / US Department of Justice What each term actually covers A suspicious transaction report is tied to a transaction that actually happened. The filing has to identify the specific transaction and explain what made it suspicious; the trigger is the transaction itself. A suspicious activity report has broader scope: it can cover behaviour, a pattern across a relationship, or even an attempted transaction that never completed, without needing one specific transaction to point to. In practice, this means an activity-based regime can catch things a purely transaction-based one would miss: someone probing account limits without ever moving money, for instance, or a pattern of behaviour that only becomes suspicious once you see it across several interactions rather than one. Why the same underlying obligation has two names The reason there are two names for what’s functionally the same underlying obligation, tell your financial intelligence unit when something looks wrong, comes down to which standard a country built its reporting regime around. FATF’s Recommendation 20 sets the international baseline, requiring financial institutions to report suspicious transactions to their national FIU. Most countries that built their AML law directly around FATF’s standard adopted STR as the formal term. The United States went a different route. Its reporting obligation grew out of the Bank Secrecy Act rather than being drafted straight from FATF’s language, and it settled on “activity” rather than “transaction” as the defining word. The US SAR model Under the US Bank Secrecy Act, financial institutions file SARs with FinCEN using FinCEN Form 111. Thresholds vary by institution type: $5,000 for most depository institutions, $2,000 for money services businesses. Because the obligation is activity-based, a SAR can be filed over a pattern of conduct or an attempted transaction, not only a completed one. FinCEN’s own SAR Stats database tracks filing volumes by institution type, activity category, and geography, giving a rare public window into how many of these reports actually get filed and for what reasons across the US financial system. The FATF STR model most other countries follow Most other jurisdictions built their reporting obligation directly around FATF Recommendation 20’s language and call the resulting document a suspicious transaction report. India is a clear example: STRs are filed under the Prevention of Money Laundering Act 2002 with FIU-IND, using that exact terminology in law. The EU’s Anti-Money Laundering Directives and many Asian jurisdictions follow the same pattern. FATF itself doesn’t mandate a specific threshold or form. Recommendation 20 sets the principle, report promptly when there are reasonable grounds to suspect proceeds of crime or terrorist financing, and leaves the mechanics of implementation to each country. Where the UK sits in this split The UK sits in an interesting middle position. It uses the term SAR, filed with the National Crime Agency under POCA and the Terrorism Act, following US-style terminology. But UK law was still shaped by the same FATF standard as STR-based jurisdictions, and in practice UK guidance treats the obligation broadly enough to cover suspicious activity, not strictly a completed transaction. That’s a useful reminder that the name a jurisdiction uses doesn’t reliably tell you the actual scope of what needs reporting. Firms operating across borders need to check the substance of each jurisdiction’s obligation, not assume from the label alone. Worth knowing. The name a jurisdiction uses for this report doesn’t reliably tell you its actual scope. The UK calls its filing a SAR, following US-style naming, but the underlying obligation was shaped by the same FATF standard that produced STR terminology in most other countries. Why the distinction matters for transaction monitoring design This distinction has a direct, practical consequence for how transaction monitoring gets built. A system designed around US SAR logic generates activity-based alerts, patterns, behaviours, attempted actions, that don’t map cleanly onto a strictly transaction-anchored STR threshold used elsewhere. Applying one global rule set built for one model to a jurisdiction that uses the other risks either over-reporting or under-reporting relative to what local law actually expects. Firms running programmes across multiple countries need alert logic and escalation workflows calibrated to whichever standard actually applies in each jurisdiction, rather than assuming SAR and STR are close enough to treat as one global rule set. A real case that shows what gets missed The 2024 settlement between TD Bank and US authorities is a useful illustration of what falling short on this obligation … Read more

De-risking

De-risking is when a bank or firm exits or refuses whole categories of customers to avoid financial crime risk, rather than managing that risk. It can cut off legitimate customers from banking and push activity into less visible channels, which is why regulators discourage it. Key takeaways De-risking means dropping whole customer groups to avoid risk, not manage it. It often hits money service businesses, charities, and correspondent banking. It can cause financial exclusion and push activity into less visible channels. The number of correspondent banking relationships fell by about 20 percent from 2011 to 2019. The FATF and other regulators discourage wholesale de-risking. The alternative is the risk-based approach: manage risk case by case. On this page What it isWhy firms do itWho is affectedThe problem with itRegulators’ viewVs the risk-based approachAlternativesManaging risk insteadFAQsRead more ~20% Fall in active correspondent banking relationships, 2011 to 2019 Source: Financial Stability Board 2014 Year the FATF issued a statement warning against wholesale de-risking Source: FATF $800B to $2T Laundered worldwide each year that risk controls target Source: UNODC What is de-risking? De-risking is when a firm avoids financial crime risk by cutting off whole groups of customers, rather than assessing and managing each one. Instead of deciding case by case, the firm makes a blanket call to exit or refuse a category. A bank might drop every money service business, or refuse every customer from a certain country, because the group is seen as risky. The individual customer’s own risk is never really weighed. It is often a reaction to cost and fear of penalties. Read more: it is the opposite of the risk-based approach regulators expect. Why firms de-risk Firms de-risk for reasons that are understandable, even where the outcome is criticized. A few pressures drive it. Cost. Managing a high-risk customer well can cost more than the customer earns. Fear of penalties. After large fines, some firms decide whole categories are not worth the risk. Uncertainty. Where the rules feel unclear, exiting can seem safer than judging. Simplicity. A blanket rule is easier to apply than a case-by-case judgment. The logic is defensive, and from inside one firm it can even look responsible. The problem is that it solves one firm’s worry by creating a wider one. Who is affected by de-risking? De-risking tends to hit the same groups, often ones that are legitimate but seen as harder to serve. The impact can be severe. Money service businesses. Remittance firms that many people rely on to send money home. Charities and non-profits. Especially those working in high-risk regions. Correspondent banking. Smaller banks losing access to the global system. Customers from certain countries. Whole nationalities treated as too risky. Cash-intensive and crypto businesses. Seen as harder to monitor. For the people behind these groups, losing banking can mean losing access to the financial system altogether. Turn customer details into a risk rating Enter a few details about a customer and get an indicative risk level, so you can judge the case rather than the category. Try the Customer Risk Calculator → The problem with de-risking De-risking carries costs that reach well beyond the firm making the decision. Two stand out. The first is financial exclusion. When legitimate customers lose banking, they can be cut off from safe, regulated services, which is unfair and harmful. Remittance customers and charities are often the ones who suffer. The second is reduced visibility. When activity is pushed out of the regulated system, it does not stop, it moves to smaller firms or informal channels with weaker controls. That makes the money harder for everyone to see. There is a fairness point too. The customers most often de-risked, remittance users sending money to family, small charities, and businesses in poorer regions, are frequently the ones who can least afford to lose access. A control meant to fight crime can end up punishing the people it should protect. Worth knowing. De-risking can backfire on the whole system. When a bank drops a money service business, that business does not vanish, it moves to a smaller bank or an informal channel with weaker controls. So a decision that lowers one bank’s risk can raise the risk everyone else has to watch. Screen a customer instead of dropping them Run one search across sanctions, PEP, and adverse media data to judge a real customer rather than a category. Try Combined AML Screening → Regulators’ view of de-risking Regulators have been clear that wholesale de-risking is not what the rules intend. They see it as a misreading of the risk-based approach. The FATF issued a statement in 2014 warning that the risk-based approach does not require firms to refuse whole categories of customers, and that de-risking can undermine the goals of financial crime rules. Other regulators have echoed this, urging firms to manage risk rather than avoid it. The message is that declining a category to save effort is not a substitute for judging real risk. De-risking vs the risk-based approach De-risking and the risk-based approach are often confused, but they point in opposite directions. One avoids risk, the other manages it. De-risking Risk-based approach Approach Exit whole categories Assess each customer Basis The group’s perceived risk The customer’s actual risk Effect Excludes and hides activity Keeps activity visible and managed High risk, under the risk-based approach, means more checks, not automatic refusal. Treating high risk as prohibited is where de-risking begins. Alternatives to de-risking There is almost always a middle path between accepting all risk and refusing a whole group. The alternatives focus on managing the risk. Enhanced due diligence. Apply deeper checks to higher-risk customers rather than exiting them. Closer monitoring. Watch higher-risk accounts more carefully. Clear risk appetite. Decide what the firm will accept and manage, and why. Better tools. Use technology to make managing risk affordable at scale. Do this: get an indicative read on your exposure with the AML Risk Assessment before making blanket calls. How to manage risk without de-risking Managing risk instead … Read more

Wildlife trafficking finance

Wildlife trafficking finance Wildlife trafficking finance covers the financial flows, and the laundering of them, behind the illegal trade in endangered species, their parts, and derivatives. FATF’s first global report on the subject, published in 2020, put the value of the illegal wildlife trade at somewhere between $7 billion and $23 billion a year. Most of that money still moves through ordinary banks and trade finance channels, which is exactly why FATF treats it as a mainstream AML problem rather than a niche environmental one. Key takeaways Wildlife trafficking finance covers the money and laundering activity behind the illegal wildlife trade. FATF’s 2020 global report estimated the trade at $7 billion to $23 billion in annual criminal proceeds. Specific trades carry real, sometimes surprising value: pythons for leather alone generate roughly $1 billion a year. Wildlife trafficking is a predicate offence for money laundering in most FATF member jurisdictions. Proceeds get laundered through trade-based laundering, shell companies, and correspondent banking, the same mechanisms used across other financial crime. Network leadership typically stays insulated from the poaching itself while capturing most of the financial benefit. On this page What wildlife trafficking finance actually coversHow big the illegal wildlife trade actually isWhat specific trades look like in dollar termsHow proceeds actually get launderedWhy this is a predicate offence, not just an environmental issueThe three-stage structure FATF describesWho’s involved beyond the poachersWhat this means for a firm’s due diligenceFAQsRead more $7bn-$23bn Estimated annual criminal proceeds from the illegal wildlife trade Source: FATF, 2020 global report $1bn Estimated annual value of the illegal trade in pythons, largely for leather Source: FATF, 2020 What wildlife trafficking finance actually covers Wildlife trafficking finance is the set of financial flows connected to poaching, transporting, and selling illegal wildlife products, along with the laundering activity that disguises where that money actually came from. It covers everything from a local poacher getting paid in cash to a shipment of ivory or pangolin scales being financed and insured through ordinary trade finance instruments. FATF’s interest in the subject isn’t primarily conservation. It’s that this is a large, transnational criminal enterprise whose proceeds move through the same financial system every other kind of laundering does, which makes it squarely an AML problem. How big the illegal wildlife trade actually is FATF’s 2020 report, the organisation’s first global study dedicated to the illegal wildlife trade, estimated the trade generates between $7 billion and $23 billion in criminal proceeds annually. FinCEN’s own 2021 threat analysis, published under a specific statutory requirement in the US Anti-Money Laundering Act of 2020, cited the same $7 billion to $23 billion range and noted that figure represents roughly a quarter of the value of the legal wildlife trade. Estimates at this scale are inherently imprecise, since illegal trade by definition resists accurate measurement, but the range is corroborated across enough independent sources to establish that this isn’t a marginal criminal activity. What specific trades look like in dollar terms FATF’s report breaks the trade down into specific product categories with genuinely surprising dollar values. Queen conch, an edible mollusk, is roughly a $60 million a year trade. Pythons, harvested largely for leather, generate around $1 billion a year. Bigleaf mahogany, a protected timber species, is worth about $33 million a year in illegal trade. Those numbers matter because they show the trade isn’t limited to the iconic species that dominate public attention, elephants, rhinos, tigers. A huge amount of the underlying value sits in less visible categories: timber, reptile leather, shellfish, and other products that rarely make headlines but move real money. Worth knowing. A huge share of illegal wildlife trade value sits outside the iconic species that dominate public attention. Python leather alone is roughly a $1 billion a year trade, more than most people would guess sits in a single reptile product category. How proceeds actually get laundered Wildlife trafficking proceeds get laundered through mechanisms that overlap heavily with other financial crime: trade-based laundering through manipulated invoices and misdescribed cargo, shell company layering to obscure who actually controls a shipment or the proceeds from selling it, and correspondent banking relationships used to move payments across the multiple jurisdictions a trafficking supply chain typically spans. FATF’s report includes a detailed infographic tracing an actual wildlife trafficking supply chain and the payments moving through it, illustrating how ordinary-looking trade payments and banking relationships end up financing and cleaning the proceeds of poaching thousands of miles away. Why this is a predicate offence, not just an environmental issue In most FATF member jurisdictions, wildlife trafficking is itself a predicate offence for money laundering, meaning a bank processing payments connected to it can face laundering exposure even where staff had no direct knowledge of the underlying wildlife crime. That’s a meaningful point for compliance teams who might otherwise treat this as a specialist environmental concern rather than a mainstream financial crime risk with the same BSA, EU AML Directive, and FATF Recommendation 20 implications as any other predicate offence. Environmental crime broadly, not just wildlife trafficking specifically, sits inside FATF’s own designated categories of predicate offences, which is part of why FATF has continued expanding its work in this area beyond the original 2020 wildlife-specific report. The three-stage structure FATF describes FATF describes the money moving through a typical wildlife trafficking operation in three broad stages, similar in structure to conventional money laundering. Proceeds are first collected at the source, often as cash paid to poachers or local traffickers in source countries, frequently in sub-Saharan Africa or South and Southeast Asia. The money then moves through the financial system, layered through trade transactions, cash couriers, or informal transfer mechanisms. Finally, it’s integrated into the legitimate economy through business investments, property, or other assets that give it the appearance of clean origin. This structure is exactly why conventional AML red flags, trade-based laundering indicators, unusual cash intensity, mismatched shipping and invoicing documentation, tend to apply here just as they do to other predicate crimes, even though the underlying offence … Read more

AML Compliance Program

An AML compliance program is the set of policies, controls, and people a firm uses to detect and prevent money laundering. In the United States it must cover five pillars: internal controls, a compliance officer, training, independent testing, and customer due diligence. Key takeaways An AML compliance program is a legal requirement for regulated firms, not an optional policy. US programs rest on five pillars, with customer due diligence added in 2018. A written risk assessment sits underneath and shapes the whole program. A named compliance officer owns the program and answers to the board and regulator. Weak programs are costly: TD Bank paid about $3 billion in 2024 after monitoring gaps. The FATF standard, set in 1989, shapes AML rules in more than 200 jurisdictions. On this page What it isWhy firms need oneThe five pillarsHow to build oneRoles and responsibilitiesLaws and regulatorsCommon weaknessesFAQsRead more $3B Paid by TD Bank in 2024 after AML program failures Source: US Department of Justice 1989 Year the FATF set the standard programs follow Source: FATF $800B to $2T Laundered worldwide each year that programs aim to stop Source: UNODC What is an AML compliance program? An AML compliance program is how a firm turns anti-money laundering rules into daily practice. It brings together the policies, controls, people, and records needed to spot laundering and report it. The program is written down, approved at a senior level, and tested. A regulator expects to see not just a document, but evidence that the controls run and that someone acts on what they find. Every regulated business needs one, from a global bank to a small payments startup. Read more: our step-by-step guide to building an AML program covers the practical setup. Why firms need an AML compliance program Firms need a program for two reasons: the law requires it, and the cost of failure is severe. Regulators can fine a firm, restrict its license, and hold its officers personally responsible. The financial cost is real and growing. In 2024, TD Bank agreed to pay about $3 billion to US authorities after leaving large categories of transactions out of monitoring, which let criminal networks move funds (US Department of Justice, 2024). Beyond fines, a weak program lets the money behind trafficking, fraud, and corruption pass through the firm. That is the harm the rules exist to prevent. Start your AML policy in minutes Answer a short set of questions and generate a tailored AML policy draft you can adapt and keep for your records. Open the AML Policy Generator → The five pillars of an AML compliance program US regulators judge a program against five pillars. The first four come from the Bank Secrecy Act, and the fifth, customer due diligence, was added by FinCEN’s 2018 rule. Internal controls. Written policies and procedures that set how the firm prevents, detects, and reports laundering. A designated compliance officer. A named, senior person, often the BSA or AML officer, who owns the program. Ongoing training. Regular, role-specific training so staff can recognize and escalate warning signs. Independent testing. A periodic audit, run by someone outside the compliance team, that checks the controls actually work. Customer due diligence. Verifying customers, understanding their activity, and identifying beneficial owners. Worth knowing. A written risk assessment is not one of the five pillars, but every examiner expects it, because it justifies the rest of the program. Without a risk assessment, a firm cannot show why its controls are set the way they are, and that gap is one of the most common findings. How to build an AML compliance program Building a program follows a clear order. Each step depends on the one before it. Run a risk assessment. Rate your laundering risk across customers, products, geographies, and channels. Our AML risk assessment gives an indicative starting point. Write the policies. Set out how you handle onboarding, monitoring, reporting, and record-keeping. Appoint a compliance officer. Give a senior person clear authority and direct access to the board. Set up customer due diligence. Define how you verify identity, rate risk, and apply enhanced due diligence. Turn on monitoring and screening. Watch transactions and check names against sanctions and PEP data. Train staff and test the program. Deliver training, then have an independent party audit the controls. Use the tool: screen customers against sanctions, PEP, and adverse media data with Combined AML Screening as part of onboarding. Screen customers as part of onboarding Run one search across sanctions, PEP, and adverse media data and see each result with its source and date. Try Combined AML Screening → Roles and responsibilities A program only works if responsibility is clear. Three groups carry the weight. The board and senior management. They approve the program, fund it, and set the tone. Regulators hold them accountable for its failures. The compliance officer. They run the program day to day, receive internal reports, decide on filings, and report to the board. All staff. Front-line teams apply the checks, spot warning signs, and escalate concerns. Larger firms often describe this split as the three lines of defense. The business is the first line and owns the risk it creates. Compliance is the second line and sets the rules and checks. Internal audit is the third line and tests that both are working. When one of these groups treats the program as someone else’s job, gaps appear. Clear ownership is what regulators look for first. Key laws and regulators A US program must satisfy several laws and the agencies that enforce them. The shape is similar in other countries, because most follow the same global standard. The Bank Secrecy Act (1970). The foundation of US AML law, which sets reporting and record-keeping duties. The USA PATRIOT Act (2001). Expanded customer identification and information-sharing rules. FinCEN. The Treasury bureau that administers the rules and receives reports. What FinCEN does. OFAC. Runs US sanctions programs that screening must respect. The FATF. Sets the 40 Recommendations that shape AML rules in more … Read more

Third-party laundering

Third-party laundering Third-party laundering is money laundering carried out by someone who didn’t commit the crime that generated the proceeds, on behalf of the person who did. It’s the default scenario most money laundering law was originally built to catch: a launderer separate from the criminal, cleaning proceeds that aren’t their own. It sits alongside, and sometimes overlaps with, both self-laundering and professional money laundering. Key takeaways Third-party laundering is laundering carried out by someone who didn’t commit the underlying crime, on behalf of the person who did. Some legal systems historically treated it as the only prosecutable form of laundering, excluding self-laundering entirely. Professional money laundering is a narrower, fee-based subset of third-party laundering. Prosecutors generally need to prove the property was criminal proceeds and that the third party knew or suspected as much, not that the predicate offender was convicted. Common relationships include family members, nominee account holders, and business partners accepting questionable payments. Criminals routinely prefer distancing themselves from their own proceeds, which keeps third-party laundering common even as more laws now cover self-laundering too. On this page What third-party laundering actually meansWhy this was the original default assumption in AML lawThird-party laundering vs self-launderingThird-party laundering vs professional money launderingCommon relationships behind third-party launderingWhat the law requires prosecutors to proveWhere third-party laundering shows up in due diligenceWhy the category still matters even where laws now cover self-laundering tooFAQsRead more What third-party laundering actually means Third-party laundering describes a specific structure: person A commits a crime and generates illicit proceeds; person B, who had no part in that crime, then launders those proceeds for or with A. The “third party” is the launderer, someone outside the original criminal act. That structure covers a huge range of real relationships, from a family member helping move money without asking too many questions, to a specialist criminal network paid specifically to clean large sums for clients they’ve never met in person. Why this was the original default assumption in AML law For much of AML law’s history, third-party laundering wasn’t just one category among several, it was closer to the assumed default. Some legal systems, Italy being the clearest documented example, explicitly excluded the predicate offender from their ordinary laundering offence, meaning only a third party could actually be prosecuted for laundering in the first place. That assumption has shifted. Most modern frameworks, including the UK’s Proceeds of Crime Act 2002, cover both scenarios under the same offence, but the third-party structure remains conceptually distinct and, in raw volume, still describes a huge share of real laundering activity. Third-party laundering vs self-laundering The contrast with self-laundering is straightforward: self-laundering means the predicate offender launders their own proceeds; third-party laundering means someone else does it for them. The two aren’t mutually exclusive within one criminal operation. A person might launder some of their own proceeds directly while also routing larger sums through a third party better positioned to move them. Where a jurisdiction only recently criminalised self-laundering, or still hasn’t, third-party laundering may be the only version of the offence that’s actually prosecutable for a given case, which makes it important to know which category a specific fact pattern actually falls into. Third-party laundering vs professional money laundering Professional money laundering is a narrower, specific type of third-party laundering: laundering offered as a paid service, systematically, to multiple criminal clients, rather than one person helping one associate on a single occasion. Every professional money launderer is, by definition, a third-party launderer. Not every third-party launderer is operating as a professional. The distinction matters for how law enforcement approaches a case. A one-off favour between associates looks and gets investigated differently from a repeat, fee-based laundering operation serving multiple clients across the categories professional money laundering networks are known to use. Common relationships behind third-party laundering Third-party laundering shows up across a wide range of relationships, not just organised professional networks. Family members and close associates moving money without asking direct questions about its source. Nominee account holders and straw men whose names sit on accounts or company registrations controlled by someone else entirely. Business partners who accept payments they should reasonably question but don’t. Each of these involves a different level of knowledge and intent, which matters enormously for prosecution, since most money laundering offences require proving the third party knew or suspected the property was criminal, not simply that they handled it. What the law requires prosecutors to prove Prosecutors generally need to establish two things for a third-party laundering charge: that the property in question really was the proceeds of crime, and that the person handling it knew or suspected as much at the time. Under UK law, for instance, the prosecution doesn’t need a conviction for the predicate offence to proceed with a laundering charge against the third party, only evidence that the property constitutes criminal property under the relevant statutory definition. This is part of why third-party laundering prosecutions can move forward even when the original predicate offender is never caught, tried, or convicted. The laundering charge stands on its own evidentiary footing. Worth knowing. A laundering charge against a third party doesn’t require the original predicate offender to ever be caught, tried, or convicted. Under UK law, the charge stands on its own evidentiary footing once the property is shown to be criminal property. Where third-party laundering shows up in due diligence For a compliance team, third-party laundering risk usually surfaces around account relationships that don’t quite make commercial sense: a customer receiving and immediately forwarding funds with no apparent business reason, an account that primarily exists to receive money from unrelated third parties and pass it on quickly, or a pattern where the same nominal account holder appears across multiple seemingly unconnected structures. None of these alone confirm third-party laundering. They’re the kind of pattern that, combined with a lack of a credible explanation, tends to justify an internal report and closer review. Why the category still matters even where laws now cover self-laundering too … Read more

Proliferation Financing

Proliferation financing is the funding of weapons of mass destruction, such as nuclear, chemical, or biological arms, and the means to deliver them. Firms guard against it mainly through sanctions and screening, since it is tied closely to countries under international restrictions. Key takeaways Proliferation financing funds weapons of mass destruction and their delivery. That means nuclear, chemical, and biological weapons and missiles. It is closely tied to sanctions on countries such as North Korea and Iran. It differs from terrorist financing, which funds terrorism. Firms guard against it through sanctions screening and risk assessment. The FATF now requires firms to assess their proliferation financing risk. On this page What it isThe weapons involvedVs terrorist financingThe role of sanctionsThe FATF and PFHow it worksWhy it mattersHow firms guard against itFAQsRead more 2020 Year the FATF required firms to assess proliferation financing risk Source: FATF 1989 Year the FATF set the global standard for these controls Source: FATF $800B to $2T Laundered worldwide each year, the wider problem PF sits within Source: UNODC What is proliferation financing? Proliferation financing is providing money or services that help spread weapons of mass destruction. It funds the making, buying, or moving of the deadliest weapons and the technology behind them. Unlike most financial crime, the danger here is not the money itself but what it buys. A payment that helps a sanctioned state acquire nuclear technology is the threat, whatever it looks like on a bank statement. It is one of the gravest risks in the financial crime world. Read more: the main defense against it is sanctions screening. The weapons involved Proliferation financing centers on weapons of mass destruction and the means to deliver them. These are the categories of concern. Nuclear weapons. And the materials and technology to build them. Chemical weapons. Toxic agents designed to harm on a large scale. Biological weapons. Diseases and toxins used as weapons. Delivery systems. Missiles and other means to deliver these weapons. Financing any part of this chain, from raw materials to delivery systems, counts. The concern is not just the weapons but everything needed to develop and move them. Proliferation financing vs terrorist financing Proliferation financing and terrorist financing are often mentioned together, but they are not the same. The difference is what the money funds. Terrorist financing funds acts of terrorism and the groups behind them. Proliferation financing funds weapons of mass destruction, usually linked to states rather than terrorist cells. Both are about what money enables rather than where it came from, which sets them apart from ordinary laundering, but the end goals differ. Proliferation financing Terrorist financing Funds Weapons of mass destruction Acts and groups of terrorism Usually linked to Sanctioned states Terrorist organizations Main defense Sanctions screening Screening and monitoring Both differ from laundering, where the money is dirty. Here the money may be clean; the problem is where it is going. Screen against sanctions and watchlists Run one search across sanctions, PEP, and adverse media data to check a customer or counterparty for restricted links. Try Combined AML Screening → The role of sanctions Sanctions are the front line against proliferation financing. Because the threat is tied to specific states and entities, restricting them is the main tool. International bodies such as the UN Security Council, and national regulators, impose sanctions on countries and parties linked to weapons programs. North Korea and Iran have been central to these efforts. For a firm, this means screening against sanctions lists is the key defense: catching a payment to a restricted party is how proliferation financing is stopped in practice. The FATF and proliferation financing The FATF, which sets global AML standards, has steadily strengthened its rules on proliferation financing. Its focus has been on making firms assess and manage the risk. In 2020, the FATF amended its standards to require firms and countries to assess their proliferation financing risk, alongside its longer-standing rules on targeted financial sanctions. This pushed proliferation financing from a niche concern into something every regulated firm is expected to consider, at least enough to judge its own exposure. Worth knowing. What makes proliferation financing hard to catch is that the money can look entirely ordinary. A shipment of dual-use goods, items with both civilian and military uses, might be paid for like any other trade. The risk hides in the details of who is involved and what is being bought, which is why sanctions screening and knowing the customer matter so much. How proliferation financing works Those behind proliferation financing rely on hiding the true purpose and parties of a payment. The methods are built to slip past controls. Front companies. Businesses that disguise who is really behind a deal. Intermediaries. Layers of middlemen that obscure the end user. Dual-use goods. Items with civilian and military uses that look like normal trade. Sanctions evasion. Routing payments to avoid restricted-party checks. The common aim is to make a dangerous transaction look like ordinary business, so it passes without a second look. Why proliferation financing matters Proliferation financing matters because the stakes are as high as they get. The money funds weapons capable of mass casualties, which puts it in a category of its own. For a firm, the risk is being used, even unknowingly, to help fund a weapons program. That carries severe legal and reputational consequences, quite apart from the harm to the wider world. It is one area where getting the controls right is not just about compliance but about a much larger responsibility. It is also an area of rising expectation. Regulators increasingly want to see that a firm has actively considered its proliferation financing risk, rather than simply assumed it has none. How firms guard against it Firms guard against proliferation financing mainly through sanctions discipline and vigilance. A few measures do most of the work. Screen against sanctions. Check customers and payments against sanctions lists. Assess the risk. Judge the firm’s exposure to proliferation financing. Watch trade and dual-use goods. Look closely … Read more

Three Lines of Defense

The three lines of defense is a governance model that divides responsibility for managing risk into three layers: the business that owns risk, the compliance and risk functions that oversee it, and internal audit that independently checks both. In AML, it clarifies who does what. Key takeaways The three lines of defense is a model for organizing risk management. The first line is the business, which owns and manages risk day to day. The second line is compliance and risk, which sets policy and oversees. The third line is internal audit, which independently checks the first two. In AML, it clarifies who is responsible for what. The IIA updated it to the Three Lines Model in 2020. On this page What it isThe three linesThe first lineThe second lineThe third lineIn AMLThe 2020 updateCommon weaknessesFAQsRead more 3 Lines: the business, oversight, and audit Source: IIA Three Lines Model 2020 Year the IIA updated it to the Three Lines Model Source: IIA $3.09B TD Bank penalty after its lines of defense failed, 2024 Source: US Department of Justice What is the three lines of defense? The three lines of defense is a way of organizing who manages risk in a firm. It splits the job into three distinct layers, each with its own role, so responsibility is clear and no single group is left marking its own homework. The model is used across risk and compliance, and it fits anti-money laundering especially well. AML involves many people, from front-line staff to auditors, and the three lines make clear where each fits. It underpins how a firm structures oversight. Read more: it shapes a firm’s AML governance. The three lines Each line has a different job, and together they form a layered defense. If one misses a risk, the next should catch it. First line: the business. The people who take on and manage risk day to day. Second line: oversight. The compliance and risk functions that set the rules and watch the first line. Third line: internal audit. The independent function that checks whether the first two actually work. The word defense captures the idea: each line is a barrier, and layering them makes it far harder for a risk to slip all the way through. The first line of defense The first line is the business itself, the staff who deal with customers and transactions. They own the risk, because they are the ones creating and managing it. In AML terms, the first line is where customers are onboarded, activity is watched, and the initial checks are done. Front-line staff are often the first to see something wrong, which makes their role central. A strong first line stops many risks before they go anywhere. The second line of defense The second line is the compliance and risk functions that oversee the first. They do not deal with customers directly; they set the rules and check the business is following them. This is where the compliance team and the MLRO sit. The second line writes the policies, monitors how well the first line applies them, and provides expertise. It is oversight, not front-line work, and its independence from the business is part of its value. The third line of defense The third line is internal audit, which independently checks the first two. It answers a question the others cannot answer about themselves: is any of this actually working? Internal audit stands apart from both the business and compliance, which is what lets it judge them honestly. In AML, the third line is closely tied to the independent AML audit, testing the whole program and reporting to the board. Its independence is the source of its credibility. Set out roles in your AML policy Generate a tailored AML policy draft that records who owns, oversees, and audits your controls. Open the AML Policy Generator → The three lines in AML Applied to AML, the model maps neatly onto how a program runs. Each line has a clear AML job. First line. Onboards customers, runs initial checks, and watches activity. Second line. Sets AML policy, monitors the first line, and owns the framework. Third line. Independently tests the program and reports to leadership. When the lines work together, a risk missed by the business is caught by compliance, and any gap between them is caught by audit. When they blur, that safety net frays. The 2020 update to the model The model was refreshed a few years ago to reflect how firms actually work. It kept the core idea but broadened it. In 2020, the Institute of Internal Auditors, which developed the framework, updated the old Three Lines of Defense into what it calls the Three Lines Model. The change stressed that risk management is about seizing opportunities as well as defending against threats, and clarified how the roles work together rather than in isolation. Many firms still use the older defense language, and the underlying structure is the same. Worth knowing. The three lines only work if they are genuinely separate. When the same people own the risk, oversee it, and audit it, the model collapses into a single point of failure. The value comes precisely from the independence between the lines, which is why blurring them, often to save cost, tends to be where the model breaks down. Common weaknesses The model is simple, but it fails in familiar ways. A few weaknesses recur. Blurred lines. The first and second lines merging, so oversight is not independent. A weak second line. Compliance without the authority to challenge the business. A toothless third line. Internal audit that is not truly independent or is ignored. Confused ownership. No one clear on which line owns a given risk. Most of these come down to independence, or the lack of it. When each line keeps its distinct role, the model holds; when they merge, it stops being three lines at all. Get an indicative AML risk rating See where your money laundering risk is … Read more

Model risk

Model risk Model risk is the chance that a detection model, such as a transaction monitoring or screening model, performs poorly and produces incorrect or misleading outputs. In AML terms, that usually means missing genuine risk, generating excessive false positives, or both. US regulatory guidance, SR 11-7, frames it as risk that can arise even when a model is technically sound, if it’s poorly understood, poorly implemented, or over-relied upon. Key takeaways Model risk is the chance a detection model performs poorly, even when it’s technically well built. US guidance SR 11-7 (Federal Reserve/OCC, 2011) is the reference framework most AML model risk programmes are built around. SR 11-7 rests on three pillars: sound development, independent validation, and board-level governance. “Effective challenge” means critical, independent review from people who can actually identify a model’s limitations. Common drivers include poor data quality, wrong assumptions at build time, and model drift as real-world behaviour shifts. Similar principles now shape supervisory expectations well beyond the US, including the Bank of England’s SS1/23. On this page What model risk actually isWhere model risk comes fromSR 11-7 and the three pillars of model risk managementWhat “effective challenge” means in practiceModel risk vs model validationManaging model risk in an AML programmeFAQsRead more What model risk actually is Model risk isn’t just the risk that a model has a coding error. It covers any way a model’s design, data, or use can lead to decisions that are wrong, whether that’s a monitoring system missing real laundering activity or a screening tool burying analysts in false positives. Crucially, a model can be technically correct and still create model risk, if the people relying on it don’t understand its limitations or treat its output as more certain than it is. Where model risk comes from Common sources include poor-quality or incomplete input data, assumptions baked in at build time that no longer hold, and model drift, where the real-world behaviour a model was trained or calibrated on gradually shifts without the model being updated to match. SR 11-7 and the three pillars of model risk management SR 11-7, issued jointly by the Federal Reserve and the Office of the Comptroller of the Currency in April 2011, is the reference framework most US model risk programmes are built around, and its influence extends well beyond American banks. It rests on three pillars: sound model development and implementation, effective challenge through independent validation, and governance with clear board-level accountability. Worth knowing. Even a technically accurate model can create material risk if governance is weak or a team places too much trust in its output without independent challenge. SR 11-7 treats that overreliance as a risk in its own right, not just a technical flaw. What “effective challenge” means in practice Effective challenge means critical, objective review by people who didn’t build the model and can genuinely identify its limitations and assumptions, not a rubber-stamp sign-off. It’s the mechanism through which model risk actually gets managed, rather than just documented. Model risk vs model validation Model validation is the practical activity that manages model risk. Model risk is the problem; validation is one of the main tools used to find and reduce it, alongside good governance and ongoing monitoring. Managing model risk in an AML programme A working programme keeps a full inventory of every model in use, assesses risk proportionate to how much weight a model carries in decision-making, and assigns clear governance and validation ownership independent of the team that built or runs the model day to day. Frequently asked questions What is model risk? Model risk is the chance that a detection model performs poorly and produces incorrect or misleading outputs, whether that means missing genuine risk or generating excessive false positives. It can arise even in a technically sound model if it’s poorly understood or over-relied upon. What is SR 11-7? SR 11-7 is supervisory guidance on model risk management issued jointly by the Federal Reserve and the OCC in April 2011. It sets out expectations for model development, independent validation, and governance for US-regulated banks. What does “effective challenge” mean? Effective challenge means critical, independent review of a model by people who didn’t build it and can genuinely identify its limitations and assumptions, rather than a routine sign-off. Is model risk only a US concept? The term originates in US supervisory guidance, but the underlying principles now shape expectations well beyond the US, including frameworks such as the Bank of England’s SS1/23. How is model risk different from model validation? Model risk is the underlying problem: the chance a model performs poorly. Model validation is one of the main tools used to identify and reduce that risk through independent testing. Read more: our ultimate guides, whitepapers and templates Related guides and resources to help you act on what you just read. Model ValidationHow model risk gets managed.Read guide →Machine Learning in AMLWhere model risk is highest.Read guide →Above-the-Line TestingTesting what alerted.Read guide →Below-the-Line TestingTesting what didn’t.Read guide →Independent AML AuditThe wider check.Read guide → Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team Key takeaway: Model risk is the chance that a detection model, such as a transaction monitoring or screening model, performs poorly and produces incorrect or misleading outputs. In AML terms, that usually means missing genuine risk, generating excessive false positives, or both. US regulatory guidance, SR 11-7, frames it as risk that can arise even when a model is technically sound, if it’s poorly understood, poorly implemented, or over-relied upon.

Non-profit organisation abuse

Non-profit organisation abuse Non-profit organisation abuse happens when a charity or similar body is used, knowingly or not, to raise or move funds for terrorism. It’s one of the narrower, more sensitive risks in AML and counter-terrorist financing work, because most charities are entirely legitimate and already heavily scrutinised. FATF’s Recommendation 8 exists specifically to target the small subset of NPOs genuinely at risk, without treating the whole sector as suspect. Key takeaways Non-profit organisation abuse means a charity is used, knowingly or not, to raise or move terrorist funds. FATF identifies three mechanisms: sham charities, exploited legitimate conduits, and clandestine diversion of genuine funds. FATF revised Recommendation 8 on 16 November 2023 to stop countries applying it too broadly. The standard requires a risk-based approach: proportionate measures for genuinely higher-risk NPOs, not blanket restrictions on the whole sector. UN Security Council Resolution 2664 (2022) created a standing humanitarian exemption to stop sanctions freezes from blocking legitimate aid. Red flags focus on fund flows, related-party links and purpose mismatches, not charitable status itself. On this page What non-profit organisation abuse actually looks likeThe three ways FATF says it happensWhy this risk gets treated differently from other AML riskFATF Recommendation 8 and its 2023 revisionWhat a risk-based approach means for charities in practiceWarning signs firms and donors actually look forThe humanitarian exemption problemWhere NPO abuse risk shows up in due diligenceFAQsRead more What non-profit organisation abuse actually looks like Abuse of a non-profit organisation isn’t usually a fake charity invented purely to move terrorist money, though that happens too. More often, it’s a real, functioning charity that gets exploited: a branch office diverting funds, a local partner with undisclosed links to a proscribed group, or donations collected for one purpose and redirected to another. FATF’s definition covers organisations engaged in raising or disbursing funds for charitable, religious, cultural, educational, social or fraternal purposes, or other types of good works. It’s deliberately broad, because the risk shows up across the whole range of the sector, not just in obvious cases. The three ways FATF says it happens FATF’s guidance identifies three distinct mechanisms. First, terrorist organisations posing as legitimate charities from the outset, using the appearance of good works as cover. Second, legitimate NPOs being exploited as conduits, sometimes to move money, sometimes specifically to dodge asset-freezing measures aimed at named individuals or groups. Third, and often the hardest to detect, funds collected for a genuine purpose being clandestinely diverted to a terrorist cause partway through. Each mechanism calls for a different control. Vetting at registration catches the first. Ongoing monitoring of fund flows catches the second and third. Why this risk gets treated differently from other AML risk This is one of the few corners of AML/CFT where FATF has explicitly warned regulators against overreach. Recommendation 8’s own revision history exists largely because countries applied it too bluntly: freezing bank accounts, imposing due diligence smaller charities couldn’t meet, or effectively pushing NPOs out of the banking system altogether. The result, documented repeatedly by FATF and civil society groups, was legitimate charities losing access to banking and donors losing confidence, without a matching gain in actually stopping terrorist financing. A revised Recommendation 8, adopted in November 2023, exists to correct that. FATF Recommendation 8 and its 2023 revision FATF released amendments to Recommendation 8 and its Interpretive Note on 16 November 2023, specifically to address what it called misapplication and misinterpretation of the original standard. The core instruction is explicit: countries must identify which NPOs actually fall within scope, assess their real risk of abuse, and apply focused, proportionate, risk-based measures, not a blanket approach across the whole sector. The updated Best Practices Paper that came with the revision, for the first time, includes examples of bad practice alongside good practice, spelling out specifically how not to implement the standard. Worth knowing. FATF’s updated Best Practices Paper is the first of its kind to include examples of bad practice alongside good practice, spelling out specifically how a country should not implement Recommendation 8. What a risk-based approach means for charities in practice In practice, a risk-based approach means most NPOs face light-touch treatment. A local community group running a food bank doesn’t need the scrutiny an international NPO moving funds into a conflict zone with weak governance and active armed groups requires. Countries are expected to review their entire NPO sector first, then narrow in on the genuinely higher-risk subset, based on factors like where funds are sent, how much cash moves through the organisation, and whether it operates in or near areas with active terrorist activity. Warning signs firms and donors actually look for Firms and donors doing due diligence on an NPO tend to look for a specific set of signals: unclear or shifting statements of charitable purpose, fund flows to jurisdictions with weak governance or active conflict, related parties or trustees with undisclosed links to proscribed organisations, and a mismatch between an NPO’s stated size and the volume of money moving through its accounts. None of these signals confirm abuse on their own. They’re reasons to ask more questions, not reasons to automatically refuse service. The humanitarian exemption problem One genuine tension the sector has raised for years is the risk that strict controls block legitimate humanitarian aid to the places that need it most, often the same conflict zones where sanctioned groups also operate. UN Security Council Resolution 2664, adopted in 2022, introduced a standing humanitarian exemption to asset-freeze provisions across UN sanctions regimes, specifically to stop counter-terrorism measures from accidentally blocking aid delivery. That exemption doesn’t remove the underlying AML/CFT risk. It recognises that a blanket freeze can cause its own kind of harm. Where NPO abuse risk shows up in due diligence For a bank or payment provider, NPO abuse risk usually surfaces during onboarding and ongoing monitoring of any customer registered as a charity or similar not-for-profit entity. Enhanced checks tend to focus on where the organisation actually operates, who controls it, and where … Read more

Alert-to-SAR Conversion Rate

The alert-to-SAR conversion rate is the share of monitoring alerts that end up becoming a suspicious activity report. It is a key measure of how efficient a firm’s transaction monitoring is, because most alerts turn out to be false positives that never lead to a report. Key takeaways The alert-to-SAR conversion rate is the share of alerts that become SARs. It measures how efficient transaction monitoring is. Most alerts are false positives, so the rate is usually low. A very low rate can point to too many poor-quality alerts. It is a diagnostic, not a target to be gamed. Better rules and tuning can raise it without missing real risk. On this page What it isHow it is calculatedWhy it mattersWhat a good rate looks likeThe false positive problemHow to improve itThe balanceUsing it wellFAQsRead more Over 90% Estimated share of monitoring alerts that are false positives Source: Industry estimates $800B to $2T Laundered worldwide each year that monitoring targets Source: UNODC $3.09B TD Bank penalty after monitoring failures, 2024 Source: US Department of Justice What is the alert-to-SAR conversion rate? The alert-to-SAR conversion rate is a simple ratio: of all the alerts a firm’s monitoring system raises, how many end up as a filed suspicious activity report. It measures how often an alert turns out to be worth reporting. Transaction monitoring throws up alerts when activity looks unusual. Most of those alerts, after review, turn out to be innocent. The conversion rate captures how many survive that review and become an actual suspicious activity report. It is one of the most watched metrics in AML operations. Read more: it reflects the quality of a firm’s transaction monitoring. How it is calculated The calculation is straightforward. It is the number of SARs filed divided by the number of alerts generated, over a period, usually shown as a percentage. If a system raises 1,000 alerts in a month and 20 of them lead to a SAR, the conversion rate is 2 percent. The other 980 were reviewed and cleared. Firms track this over time and across different monitoring rules, to see which rules produce useful alerts and which mostly produce noise. Why the conversion rate matters The conversion rate matters because it measures efficiency. Every alert costs an analyst’s time, so a firm wants its alerts to be worth reviewing. A very low conversion rate suggests a system generating far too many poor alerts, drowning analysts in false positives and risking that a real one is missed in the flood. A rate that gives useful signal means the monitoring is better targeted. The metric, in short, tells a firm whether its monitoring is working smart or just working hard. It also has a cost dimension. Reviewing alerts is expensive, so improving the rate can save real money as well as sharpen detection. What a good rate looks like There is no single correct number, which surprises people who want a benchmark. What counts as good depends on the firm, its customers, and its rules. Conversion rates are generally low across the industry, often just a few percent, because monitoring is deliberately cautious and flags far more than turns out to be suspicious. A rate that is extremely low may signal poorly tuned rules, while one that is unusually high may mean the firm is not casting a wide enough net. The right rate is one that balances catching real risk against wasting effort. Get an indicative AML risk rating See where your money laundering risk is concentrated so your monitoring can focus where it counts. Try the AML Risk Assessment → The false positive problem Behind the conversion rate sits the biggest headache in monitoring: false positives. Most alerts are innocent, and each one still has to be reviewed. Industry estimates often put the false positive rate in transaction monitoring above 90 percent, which is why conversion rates are so low. Every false positive consumes time that could go to real risk, and the sheer volume can bury a genuine alert. Reducing false positives, without losing the true hits, is the central challenge the conversion rate helps measure. How to improve the conversion rate Improving the rate means making alerts smarter, not simply making fewer of them. A few approaches help. Tune the rules. Adjust monitoring thresholds so they flag genuine risk, not noise. Use better data. Feed monitoring accurate customer and risk information. Apply smarter tools. Use machine learning to rank alerts by likely risk. Review and learn. Study which rules produce useful alerts and refine them. Do this: keep a clear guide to the warning signs behind good alerts with our Red Flags Checklist. The balance to strike The conversion rate has to be handled with care, because it can be gamed. A firm chasing a higher number could simply raise its thresholds and file more readily, which misses the point. The goal is not a high rate for its own sake; it is monitoring that catches real risk efficiently. Cutting alerts too aggressively to lift the rate can let genuine suspicion through, which is far worse than a few extra false positives. Effectiveness comes first, and efficiency second. Worth knowing. The alert-to-SAR conversion rate is best read as a diagnostic, not a scoreboard. A regulator will be far more concerned that a firm missed a real SAR than that its conversion rate was low. Used well, the metric points to where monitoring can be sharpened; used badly, as a target, it can quietly push a firm toward under-reporting. Using the conversion rate well A firm gets value from the metric by treating it as a guide to improvement, not a goal in itself. A few principles keep it useful. Track it by rule. See which monitoring rules produce useful alerts. Investigate extremes. Look into rates that are unusually high or low. Never sacrifice detection. Keep effectiveness ahead of efficiency. Use it to tune. Let the metric guide better rules over time. Screen a customer behind an alert … Read more