AML & Financial Crime – Page 6 – grcsight.com

Record Keeping

Record keeping is the anti-money laundering duty to retain records of customer checks and transactions. Most regimes require these to be kept for at least five years, so activity can be traced by investigators and a firm can prove it met its obligations. Key takeaways Record keeping is the AML duty to retain records of checks and transactions. It covers identity records, transactions, risk assessments, and reports. Most regimes require records to be kept for at least five years. The rule comes from the FATF standard and national law. Records give investigators an audit trail and prove compliance. Poor record keeping is a common and avoidable examination finding. On this page What it isWhy records matterWhat to keepHow longFormat and storageRecords and investigationsCommon failuresDoing it wellFAQsRead more 5 years Minimum record retention under the global AML standard Source: FATF Recommendation 11 1970 Year the US Bank Secrecy Act introduced record-keeping duties Source: FinCEN $800B to $2T Laundered worldwide each year that records help trace Source: UNODC What is record keeping in AML? Record keeping is the duty to hold on to evidence of the checks and transactions a firm handles. It means keeping who a customer is, what they did, and what the firm did about it, in a form that can be found later. It is one of the quieter parts of an AML program, easy to overlook next to screening or monitoring, but it is where the whole system leaves a trail. Without records, there is no proof anything was checked. The duty runs across every regulated firm. Read more: it is one of the obligations inside an AML compliance program. Why records matter Records matter for two reasons: they help catch criminals, and they protect the firm. Both come down to having evidence when it is needed. For investigators, records are the trail that money leaves. When law enforcement follows a suspect, the account records, transaction histories, and identity checks held by firms are often what let them build a case. For the firm, records are the proof that it did its job, which is exactly what a regulator asks to see. A firm with good records can answer questions. A firm without them cannot, whatever it actually did. What records to keep The rules cover a defined set of records, spanning the customer relationship from start to finish. Each supports a different part of the trail. Identity records. The evidence gathered during customer due diligence, such as documents and checks. Transaction records. Details of the transactions a customer made. Risk assessments. How the firm judged the risk of a customer or its business. Reports. Copies of any suspicious activity report filed and the reasoning behind it. Correspondence. Relevant communications about the account or activity. Together these let someone reconstruct not just what a customer did, but what the firm knew and decided. How long to keep records Most regimes settle on a minimum of five years, and that figure is remarkably consistent worldwide. The clock usually starts when the relationship ends or the transaction takes place. The global standard-setter, the FATF, calls for records to be kept for at least five years in its Recommendation 11, and national laws follow it. In the US, the Bank Secrecy Act requires a five-year retention period, and the EU applies a similar rule. Some records may need to be kept longer if an investigation is open. Set out record keeping in your AML policy Generate a tailored AML policy draft that records your controls, checks, and retention approach. Open the AML Policy Generator → Format and storage The rules care less about the exact format than about whether records can be found and read. Two qualities matter most. Retrievable. Records must be produced promptly when a regulator or investigator asks. Readable. They must be complete and legible, not fragments no one can interpret. Records can be kept on paper or, far more often now, electronically. What matters is that a firm can retrieve a specific customer’s history quickly, rather than searching through disorganized files while an examiner waits. Record keeping and investigations Records come into their own when something goes wrong. An investigation, whether by the firm or by law enforcement, runs on the evidence that was kept. When a suspicious pattern emerges, investigators look back through the records to understand it: who the customer is, where the money came from, and where it went. Good records make that possible; missing ones can stall a case entirely. This is why the duty exists in the first place, to keep the trail intact for the day it is needed. Worth knowing. Record keeping is often where a firm’s compliance is truly tested. A program can screen and monitor well, but if it cannot produce the records to prove it, a regulator has no way to confirm the work was done. In practice, weak record keeping can turn a firm that did the right thing into one that cannot show it, which amounts to the same finding. Common record-keeping failures Record-keeping failures tend to be mundane rather than dramatic, which is what makes them so common. A few recur. Gaps. Records missing for some customers or periods. Early destruction. Records deleted before the retention period ends. Poor retrieval. Records that exist but cannot be found quickly. Incomplete files. Records that capture part of the story but not the decision behind it. None of these is hard to avoid, which is exactly why regulators take a dim view of them. How firms do record keeping well Doing record keeping well is a matter of discipline more than technology. A few habits keep a firm on solid ground. Define what to keep. Set a clear policy on records and retention periods. Store it well. Keep records secure, organized, and easy to retrieve. Hold for the full period. Do not destroy records early, and extend where needed. Test retrieval. Check that a specific record can actually be found on request. Get an indicative … Read more

Financial Crime Compliance (FCC)

Financial crime compliance (FCC) is how a firm manages its whole financial crime risk in one function. It brings together anti-money laundering, sanctions, anti-fraud, and anti-bribery controls, so the firm can detect and prevent crime across the board rather than in silos. Key takeaways Financial crime compliance (FCC) is the umbrella function above AML. It covers AML, sanctions, fraud, bribery, and terrorist financing. AML is one part of FCC, not the whole of it. FCC runs risk assessment, screening, monitoring, reporting, and investigations. Firms increasingly merge fraud and AML teams, because criminals cross between them. Weak FCC is costly: TD Bank paid about $3 billion in 2024. On this page What it isWhat FCC coversFCC vs AMLWhat an FCC function doesThe FCC frameworkBuilding the functionRoles in FCCChallenges and trendsFAQsRead more $800B to $2T Laundered worldwide each year, one part of financial crime Source: UNODC ~$300B Laundered in the United States each year Source: US Department of the Treasury $3B Paid by TD Bank in 2024 after control failures Source: US Department of Justice What is financial crime compliance (FCC)? Financial crime compliance is how a firm manages every kind of financial crime risk in one place. It pulls anti-money laundering, sanctions, fraud, and bribery controls into a single function. The idea is to stop treating each crime as a separate problem. Many schemes cross between them, so a joined-up function catches what siloed teams miss. FCC is broader than AML alone. Read more: it is the operating layer above financial crime as a whole. What FCC covers FCC covers the full range of financial crime a firm can face. Each area has its own controls, but they share tools and data. Anti-money laundering. Stopping criminals disguising dirty money. See money laundering. Sanctions. Making sure the firm does not deal with restricted parties or countries. Anti-fraud. Preventing deception that takes money from the firm or its customers. Anti-bribery and corruption. Stopping improper payments and abuse of position. Counter-terrorist financing. Cutting off funds to terrorists. See CTF. Market abuse. Preventing insider dealing and market manipulation. Screen a name across financial crime risks Run one search across sanctions, PEP, and adverse media data to check a person or company before you deal with them. Try Combined AML Screening → FCC vs AML: how they differ FCC and AML are often used loosely, but they are not the same. AML is one part of FCC. AML deals specifically with money laundering. FCC is the wider function that also handles sanctions, fraud, bribery, and more. A firm can have a strong AML program and still have gaps in fraud or sanctions if FCC is not joined up. AML FCC Scope Money laundering All financial crime Includes CDD, monitoring, SARs AML plus sanctions, fraud, bribery Aim Stop dirty money Manage the whole crime picture Placing AML inside FCC lets a firm share data and staff across crime types, which is where the efficiency comes from. What an FCC function does An FCC function runs a set of connected activities across all the crime types it covers. The core work is consistent. Risk assessment. Rate the firm’s exposure across money laundering, sanctions, fraud, and bribery. Screening. Check customers and payments against sanctions and PEP data. Monitoring. Watch transactions and behavior for signs of crime. Investigations. Look into alerts and decide whether to escalate or report. Reporting. File suspicious activity reports and meet regulatory duties. Do this: weigh the geographic side of your exposure with our Country Risk Checker. The FCC framework A sound FCC function rests on a clear framework, so the pieces work together rather than in isolation. The framework has a few layers. Governance. Senior ownership, clear roles, and board oversight of financial crime risk. Risk assessment. A firm-wide view that covers every crime type, not just laundering. Controls. Screening, monitoring, and due diligence shared across crime types. Reporting and record-keeping. Timely reports and evidence that controls ran. Assurance. Independent testing that checks the whole function works. Worth knowing. The biggest gain from a combined FCC function is not saving money, it is seeing the whole picture. Fraud and money laundering are usually the same crime viewed from two ends, so a firm that runs them separately keeps handing each team half a case and wondering why neither can close it. How to build a financial crime compliance function Standing up an FCC function follows a clear path. The order matters, because each step rests on the one before it. Set the scope. Decide which crime types the function will cover, from AML to fraud to sanctions. Run one risk assessment. Build a firm-wide view across all of those crime types, not just laundering. Name an owner. Give a senior person clear responsibility for the whole function. Share the controls. Use common screening and monitoring across crime types rather than duplicating them. Test the function. Have an independent party check that the pieces work together. Bringing the crime types together is the point. A firm that runs sanctions, fraud, and AML on separate systems, with separate data, spends more and sees less. Read more: the AML piece is covered in our guide to building an AML program, which an FCC function extends to other crimes. Start with a financial crime risk read See where your money laundering and financial crime risk is concentrated across customers, products, and markets. Try the AML Risk Assessment → Roles in FCC FCC brings together several roles under one function. A common way to organize them is the three lines of defense. First line. The business, which owns the risk it creates and applies front-line checks. Second line. Compliance, including the MLRO and FCC team, which sets rules and reviews alerts. Third line. Internal audit, which tests that the first two lines work. Analysts and investigators sit mostly in the second line, working alerts and building cases. Clear ownership across the lines is what keeps the function effective, since a gap between the business and compliance is where most … Read more

Money Laundering Reporting Officer (MLRO)

A money laundering reporting officer (MLRO) is the senior person responsible for a firm’s anti-money laundering compliance. The MLRO receives internal reports of suspicion, decides whether to file with the authorities, and answers to the regulator. The role is required for regulated firms in the UK. Key takeaways The MLRO is the named person accountable for a firm’s AML program. The role is a legal requirement for regulated firms in the UK under the 2017 rules. The MLRO receives internal reports and decides whether to file a suspicious activity report. The US equivalent is the BSA or AML compliance officer. The role needs seniority, independence, and direct access to the board. The UK receives hundreds of thousands of suspicious activity reports each year. On this page What it isIs it required?What an MLRO doesMLRO vs BSA officerWho can be oneThe MLRO and SARsChallenges and liabilityFAQsRead more Hundreds of thousands Suspicious activity reports filed in the UK each year Source: UK National Crime Agency $3B Paid by TD Bank in 2024 after AML failures Source: US Department of Justice 1989 Year the FATF set the standard MLROs work within Source: FATF What is a money laundering reporting officer (MLRO)? A money laundering reporting officer is the senior individual a regulated firm names to lead its anti-money laundering effort. The MLRO is the point where suspicion turns into action, deciding whether an internal concern becomes a formal report. The title is most common in the UK and other jurisdictions that follow its model. The person carries real accountability, not just a job description, and the regulator can hold them responsible for failures. The role sits at the top of the AML compliance program. Read more: our guide to filing a suspicious activity report covers the process the MLRO oversees. Is an MLRO legally required? In the UK, yes. The Money Laundering Regulations 2017 require most regulated firms to appoint an MLRO, sometimes alongside a nominated officer who receives internal reports. Other countries have equivalents under different names. The United States requires a designated BSA or AML compliance officer under the Bank Secrecy Act, and the concept appears across FATF-aligned regimes. The exact title matters less than the function. Every regulated firm needs a named, senior person who owns AML compliance and can be held to account. Start your AML policy in minutes Answer a short set of questions and generate a tailored AML policy draft your MLRO can adapt and keep on file. Open the AML Policy Generator → What does an MLRO do? The MLRO holds a broad remit that runs from daily oversight to formal reporting. The core duties are consistent across firms. Receive internal reports. Staff escalate concerns to the MLRO, who assesses each one. Decide on filings. The MLRO judges whether a concern meets the threshold for a suspicious activity report and files it. Own the program. They maintain policies, oversee customer due diligence, and keep the risk assessment current. Lead training. They make sure staff can recognize and escalate warning signs. Report to the board. They give senior management a clear view of AML risk and issues. Liaise with regulators. They act as the firm’s main AML contact for the authorities. Use the tool: give your team a shared reference for warning signs with our red flags checklist. Give your team a shared reference Use our red flags checklist so front-line staff know which warning signs to escalate to the MLRO. Open the Red Flags Checklist → MLRO vs BSA officer vs compliance officer The same role carries different names across countries, which causes confusion. The table lines them up. Term Where used Notes MLRO UK and aligned regimes Owns AML compliance and reporting decisions Nominated officer UK Receives internal reports; often the same person as the MLRO BSA or AML officer United States Designated under the Bank Secrecy Act as a program pillar Compliance officer General Broader role that may include AML among other duties A small firm may combine these into one person. A large bank may split them across a team, with the MLRO at the top. Who can be a money laundering reporting officer? Not just anyone can hold the role. Regulators expect the person to have the standing and independence to act on difficult decisions. Seniority. Enough authority to challenge the business and be heard by the board. Independence. Freedom to file a report even when it is commercially inconvenient. Knowledge. A sound grasp of AML law, the firm’s risks, and its customers. Time and resources. The capacity to do the job properly, not as an afterthought. Worth knowing. The hardest part of the MLRO role is not spotting suspicion, it is independence. The person who decides to file a report is often the same person under pressure to keep a profitable client. Regulators look closely at whether the MLRO can act without fear of being overruled, which is why board access matters so much. The MLRO and suspicious activity reports Filing suspicious activity reports is the MLRO’s most visible duty. The process follows a clear path. A concern is raised. A staff member notices a warning sign and escalates it internally. The MLRO reviews it. They gather context and judge whether suspicion is reasonable. A report is filed. If the threshold is met, the MLRO files with the financial intelligence unit. Records are kept. The firm documents the decision, whether or not it reported. The scale is large. The UK receives hundreds of thousands of suspicious activity reports each year (UK National Crime Agency), and each one starts with a decision like this. Challenges and personal liability The MLRO role carries pressure that other compliance jobs do not. The person can be held personally responsible for failures, which raises the stakes of every decision. Common challenges include high alert volumes, thin resources, and tension between compliance and commercial goals. A firm that under-supports its MLRO is exposing both the person and itself. The most common pressures on an MLRO include: … Read more

Cash-Intensive Business

A cash-intensive business is one that handles large amounts of cash as part of its normal trade, such as restaurants, car washes, and casinos. These businesses carry higher money laundering risk, because dirty cash can be mixed with real takings and reported as revenue. Key takeaways A cash-intensive business handles a lot of cash in its everyday trade. Examples include restaurants, bars, car washes, laundromats, and casinos. They are higher risk because dirty cash can be mixed with real income. In the US, cash transactions of $10,000 or more trigger a report. Not all cash is suspicious, which makes these customers hard to judge. Firms apply extra checks and monitoring to cash-intensive customers. On this page What it isExamplesWhy it is a riskHow laundering happensRed flagsHow firms handle themLegitimate vs suspiciousReporting and thresholdsFAQsRead more $10,000 US cash transaction reporting threshold Source: Bank Secrecy Act $800B to $2T Laundered worldwide each year, much of it starting as cash Source: UNODC $3B Paid by TD Bank in 2024 after monitoring failures Source: US Department of Justice What is a cash-intensive business? A cash-intensive business is one where a large share of sales comes in as physical cash. Handling cash is normal and legal for these businesses, which is exactly what makes them useful to launderers. The concern is not the cash itself, but how hard it is to tell clean takings from dirty ones. A business that already deals in cash gives criminal money an easy place to blend in. These businesses sit high on most risk assessments. Read more: the tactic of blending cash is a classic money laundering example. Examples of cash-intensive businesses Cash-intensive businesses appear across many sectors. What they share is a high volume of cash sales. Food and drink. Restaurants, cafes, bars, and takeaways. Personal services. Hair and nail salons, barbers, and spas. Vehicle services. Car washes, parking, and taxis. Retail. Convenience stores, markets, and vending operations. Laundromats. The classic example that gave laundering its name. Gambling. Casinos and betting shops, where chips and cash change hands. Being cash-intensive does not make a business criminal. It simply raises the level of care a firm should take. Why cash-intensive businesses are a risk The risk comes down to one thing: cash is hard to trace. A physical banknote carries no record of where it came from, so dirty and clean cash look identical once mixed. A launderer can run criminal cash through a cash business, add it to the real takings, and deposit the total as revenue. The bank sees a cash deposit that fits a cash business, and the money is now in the system with a clean story. This is the placement stage of laundering in action, the point where dirty cash first enters the financial system. For a criminal, a cash business is not only a hiding place. It is a machine that produces a clean explanation for money that has none, which is what makes these customers worth extra attention. Know the warning signs before they cost you Use our red flags checklist to review cash-intensive customers for the signs of laundering. Open the Red Flags Checklist → How laundering happens through cash businesses Laundering through a cash business follows a simple pattern. The business becomes a front, or a partial front, for criminal money. Mixing. Dirty cash is added to genuine takings and reported as sales. Over-reporting. A business claims more sales than it really makes to justify extra cash. Front companies. A business exists mainly to wash money, with little real trade. Structuring. Deposits are kept just below reporting limits to avoid a report. See structuring. Because each deposit can look normal, the pattern only shows up when someone compares the cash against what the business should realistically take. Red flags in cash-intensive businesses Certain patterns raise concern in a cash business. None is proof, but each is worth a closer look. Cash deposits that are too large for the size or location of the business. Deposits kept just under the reporting threshold. Sales that do not match the number of customers or the trading hours. Little or no normal business spending, such as suppliers or wages. Reluctance to explain the source of the cash. Frequent round-number deposits with no clear pattern of trade. Rate a cash business customer Enter a few details about a customer and get an indicative money laundering risk level to guide your checks. Try the Customer Risk Calculator → How firms handle cash-intensive customers Firms do not refuse cash businesses, but they treat them with extra care. The approach follows the risk-based method. Understand the business. Learn what it does and how much cash is normal for it. Apply deeper checks. Use enhanced due diligence where the risk is higher. Set expectations. Record the expected level of cash activity at onboarding. Monitor against them. Flag deposits that break from the expected pattern. Use the tool: get an indicative read on your exposure to higher-risk customers with the AML Risk Assessment. Worth knowing. The hard part is that a busy restaurant and a laundering front can look identical on a bank statement. The difference is context, whether the cash matches the size, location, and type of business. That is why firms compare a customer against what similar businesses actually take, rather than judging the cash alone. Legitimate cash vs suspicious cash It is worth saying plainly: most cash businesses are honest. Cash remains a normal way to trade in many sectors and communities. The goal is not to treat cash as guilty, but to tell ordinary cash activity apart from the unusual. A firm that over-reacts to all cash risks cutting off legitimate customers, which is a form of de-risking regulators discourage. A practical way to hold both truths is to build a picture of what is normal for each customer at the start, then watch for departures from it. A salon that suddenly banks three times its usual cash is worth a question. The same amount, … Read more

Proceeds of Crime

Proceeds of crime are the money or property that someone gains from criminal activity. They are what money laundering exists to disguise, and what authorities try to trace, freeze, and recover. In short, proceeds of crime are the profit a crime produces. Key takeaways Proceeds of crime are the money or property gained from criminal activity. They are the result of a predicate offense, the underlying crime. They can be direct, such as stolen cash, or indirect, such as assets bought with it. Money laundering exists to disguise the origin of these proceeds. Authorities can trace, freeze, and confiscate proceeds of crime. In the UK, the Proceeds of Crime Act 2002 is the main law. On this page What they areDirect and indirectVs predicate offenseTracing and recoveryThe lawWhy it mattersLink to launderingHow firms handle itFAQsRead more 2002 Year the UK Proceeds of Crime Act was passed Source: UK Proceeds of Crime Act 2002 14 years Maximum UK prison sentence for money laundering Source: UK Proceeds of Crime Act 2002 $800B to $2T Criminal proceeds laundered worldwide each year Source: UNODC What are proceeds of crime? Proceeds of crime are whatever someone gains from breaking the law. Usually that means money, but it also covers property, goods, and any asset bought with criminal funds. The term is central to both AML and law enforcement. Money laundering exists to disguise these proceeds, and much of the work of tracing and seizing assets is aimed at taking them back. They are the output of an underlying crime. Read more: that underlying crime is the predicate offense. Direct and indirect proceeds Proceeds of crime come in two forms, and the law reaches both. The distinction is about how closely the asset is tied to the crime. Direct proceeds. What comes straight from the crime, such as cash from a robbery or a fraud. Indirect proceeds. What is later bought or gained with that money, such as a house, a car, or an investment. This matters because criminals rarely keep dirty money as cash. They convert it into other assets, and the law follows the value through each change, so a home bought with fraud money is still proceeds of crime. Proceeds of crime vs predicate offense Proceeds of crime and predicate offense are two halves of the same story, and mixing them up is common. The difference is simple once seen. A predicate offense is the crime. The proceeds of crime are the money or property it produces. The crime is the cause, and the proceeds are the effect. Fraud is the predicate offense; the money taken is the proceeds of crime. Predicate offense Proceeds of crime What it is The underlying crime The money or property gained Example Bribery The bribe money and what it buys Role The cause The result Put simply, the predicate offense is what was done, and the proceeds of crime are what was gained. Screen a customer against watchlists Run one search across sanctions, PEP, and adverse media data to check a customer or counterparty. Try Combined AML Screening → Tracing and recovery A major goal of the fight against financial crime is taking proceeds back. Depriving criminals of their profit is often more effective than any fine. Trace. Follow the money through accounts and assets to find where it went. Freeze. Stop the assets from being moved or spent while a case proceeds. Confiscate. Take the proceeds through a court order once the case is made. Recover. Return value to victims or the state where possible. This is why following the money matters so much. Even when a criminal cannot be jailed, taking their proceeds removes the reward that made the crime worthwhile. The law on proceeds of crime Most countries have laws aimed squarely at criminal proceeds. The best-known example gives its name to the whole idea. In the UK, the Proceeds of Crime Act 2002, often called POCA, is the main law. It sets out the money laundering offenses, with a maximum sentence of 14 years, and gives authorities powers to confiscate criminal assets. Other countries have their own asset-recovery laws built on the same principle: crime should not pay. Worth knowing. The idea behind proceeds-of-crime laws is deceptively powerful. By targeting the money rather than only the person, authorities can act even when a conviction for the original crime is hard to secure. Some regimes allow civil recovery of assets that are clearly criminal in origin, without needing a criminal conviction at all. Why proceeds of crime matter Proceeds of crime matter because they are the point of most financial crime. Criminals commit predicate offenses to make money, and that money is the proceeds. For the AML system, the proceeds are the target. Every check, every report, and every seizure is ultimately about stopping criminals from keeping and using them. For a firm, the risk is handling these proceeds unknowingly, which is what its controls exist to prevent. There is a simple logic underneath it all. Crime is committed for profit, so removing the profit strikes at the motive, which is why proceeds-of-crime laws sit at the center of the response to financial crime. How they connect to laundering Proceeds of crime and money laundering are inseparable. One is the money, the other is the effort to clean it. Laundering exists precisely because proceeds of crime are dangerous to hold in their raw form. Dirty cash cannot be spent or banked openly, so criminals launder it to make it look legitimate. Handling those proceeds, knowing what they are, is itself a money laundering offense. How firms handle proceeds of crime A firm’s whole AML effort is, at heart, about keeping proceeds of crime out. A few principles guide how they do it. Know the customer. Understand where a customer’s money comes from. Watch the money. Monitor for activity that suggests criminal funds. Report suspicion. File a report when funds may be proceeds of crime. Do not tip off. Avoid alerting a customer that … Read more

Customer Risk Rating

Customer risk rating is how a firm scores the money laundering risk of a single customer. The rating, usually low, medium, or high, decides how much due diligence to apply and how closely to monitor the relationship. It puts the risk-based approach into practice at the customer level. Key takeaways Customer risk rating scores the laundering risk of one customer. The rating drives how deep the checks and how close the monitoring should be. Common factors are identity, occupation, PEP status, geography, product, and behavior. Ratings are usually low, medium, or high, each with its own treatment. Ratings should be dynamic, updated as behavior and circumstances change. It applies the risk-based approach to individual relationships. On this page What it isWhy firms rate customersThe risk factorsHow it worksWhat each level meansRating examplesDynamic ratingCommon mistakesFAQsRead more 2012 Year the FATF made the risk-based approach central Source: FATF $800B to $2T Laundered worldwide each year that ratings help catch Source: UNODC $3B Paid by TD Bank in 2024 after control gaps Source: US Department of Justice What is customer risk rating? Customer risk rating is the score a firm gives a single customer to show how much money laundering risk they carry. It is worked out at onboarding and kept up to date through the relationship. The score is not a judgment of character. It is a measure of exposure, based on factors such as who the customer is, what they do, and where they operate. The rating then sets the level of scrutiny. Read more: it applies the firm-wide AML risk assessment to one relationship. Why firms rate customer risk Firms rate customer risk to spend effort where it is needed. Treating every customer the same wastes attention on low-risk relationships and under-watches dangerous ones. The rating is the engine of the risk-based approach. It decides how much customer due diligence to apply, whether enhanced due diligence is needed, and how often to review the relationship. It also creates a record. If a regulator asks why a customer was treated a certain way, the rating and its reasoning are the answer. The alternative is worse for everyone. Without a rating, a firm either over-checks harmless customers, which frustrates them and wastes staff time, or under-checks risky ones, which is how laundering slips through. Turn customer details into a risk rating Enter a few details about a customer and get an indicative money laundering risk level to guide your due diligence. Try the Customer Risk Calculator → Customer risk factors A rating combines several factors, not one. Each can push the score up or down, and they are weighed together. Identity and ownership. How clearly the customer and any beneficial owner can be identified. Occupation and business. Whether the customer works in a higher-risk sector, such as a cash-intensive business. PEP status. Whether the customer is a politically exposed person or a close associate. Geography. Whether the customer or their funds touch a high-risk country. Products used. Whether the products favor anonymity or fast movement of funds. Expected behavior. The size, frequency, and type of activity the customer is likely to run. Worth knowing. A single high-risk factor should not automatically make a customer high risk, and a pile of low-risk factors should not bury one serious red flag. Rating well means weighing factors together, which is why a purely mechanical score, with no room for judgment, tends to produce both false alarms and blind spots. How customer risk rating works Rating a customer follows a clear sequence. It turns information into a score and a treatment. Collect information. Gather identity, ownership, occupation, and expected activity. Screen the customer. Check against sanctions, PEP, and adverse media data. Score the factors. Rate each factor, then combine them into an overall level. Apply the treatment. Set the due diligence and monitoring the level requires. Record the reasoning. Document how the rating was reached. Use the tool: screen a customer as part of this step with Combined AML Screening. What each rating level means The rating level decides how the firm treats the customer. The three common bands map to three levels of effort. Rating Due diligence Monitoring Low Simplified checks Lighter, periodic review Medium Full customer due diligence Standard ongoing monitoring High Enhanced due diligence and sign-off Closer, more frequent monitoring High risk means more scrutiny, not automatic refusal. Declining whole groups of customers to avoid effort is de-risking, which regulators discourage, because it pushes activity into channels no one is watching. Examples of customer risk levels A few short examples show how the factors combine into a rating. None is a hard rule, because context always changes the picture. Low risk. A salaried local customer using everyday products, based in a low-risk country, whose identity is clear and whose activity is small and predictable. Medium risk. A small business with moderate cash takings and customers in several countries, where ownership is clear but the activity is varied. High risk. A customer who is, or is closely linked to, a politically exposed person, where the source of wealth needs checking. High risk. A cash-intensive business based in, or trading heavily with, a high-risk country, where funds are harder to trace. The rating is a starting point, not a verdict on the customer. A high rating means closer checks and monitoring, while a low rating still calls for ongoing awareness in case behavior changes. Applied consistently, these levels make a firm’s decisions explainable. If one customer faces deeper checks than another, the rating and its factors show exactly why. Screen a customer as you rate them Run one search across sanctions, PEP, and adverse media data to feed real signals into the rating. Try Combined AML Screening → Dynamic risk rating A rating is not fixed at onboarding. Customers change, and their risk changes with them, so the score should move too. A rating should be reviewed on a schedule tied to its level, and re-checked whenever something shifts. A change in behavior, a … Read more

Counter-Terrorist Financing (CTF)

Counter-terrorist financing (CTF) is the set of laws and controls that stop money from reaching terrorists. It sits alongside anti-money laundering, but it is harder to catch, because terrorist funds are often small and can come from legal sources. It is also called combating the financing of terrorism (CFT). Key takeaways Counter-terrorist financing (CTF) aims to cut off funding for terrorism. It is often paired with AML as AML/CFT, but the two are not the same. Terrorist funds can be small and legally sourced, which makes them hard to spot. The 9/11 attacks cost an estimated $400,000 to $500,000 to carry out. The FATF added terrorist financing to its mandate in 2001. Core controls are screening against terrorist and sanctions lists, monitoring, and reporting. On this page What it isCTF vs AMLHow it worksControls and obligationsLaws and bodiesWarning signsWhy it is hardHow firms strengthen CTFFAQsRead more $400k to $500k Estimated cost of carrying out the 9/11 attacks Source: 9/11 Commission, 2004 2001 Year the FATF added terrorist financing to its mandate Source: FATF 40 FATF Recommendations now covering money laundering and terrorist financing Source: FATF What is counter-terrorist financing (CTF)? Counter-terrorist financing is everything done to stop money from reaching people and groups that carry out terrorism. It combines laws, sanctions, and checks inside banks and other firms. The goal is different from most financial crime work. CTF is not mainly about the size of the money, it is about where the money is going and who will use it. The term is used alongside anti-money laundering so often that the pair is written as AML/CFT. Read more: CTF is the response to terrorist financing, which is the activity it targets. CTF vs AML: how they differ CTF and AML use many of the same tools, but they chase different problems. The difference is in the direction of the money. Money laundering hides the source of dirty money. Terrorist financing hides the destination and purpose of money that may be perfectly clean. A donation to a front charity can be legal at the source and still fund an attack. AML CTF Focus Where money came from Where money is going Source of funds Usually illegal Often legal Amounts Often large Often small Main signal Hidden origin Suspicious destination or link Because the sums can be small and clean, CTF leans harder on who is involved, not just how the money moves. Screen a name against terrorist and sanctions lists Run one search across sanctions, PEP, and adverse media data to check a person or company before you deal with them. Try Combined AML Screening → How terrorist financing works Terrorist financing raises and moves money for violent ends. It draws on a mix of sources, some criminal and some entirely legal. Legitimate sources. Salaries, small businesses, and donations, sometimes through front charities. Criminal sources. Fraud, extortion, kidnapping, smuggling, and the drug trade. Moving the money. Bank transfers, cash couriers, informal value transfer, and cryptocurrency. Using the money. Buying weapons, paying operatives, and covering travel and logistics. Worth knowing. The hardest truth in CTF is that many attacks are cheap. When a plot costs a few thousand dollars and the money comes from a legal job, no transaction looks unusual on its own. That is why screening against known individuals and networks matters as much as watching amounts. CTF controls and obligations Firms meet their CTF duties with a familiar set of controls, tuned toward people and links rather than amounts. The core steps are consistent. Screen names. Check customers against terrorist lists and sanctions lists at onboarding and over time. Monitor activity. Watch for links to high-risk regions and patterns tied to known networks. Assess geographic risk. Weigh exposure to conflict zones and high-risk countries. Report suspicion. File a suspicious activity report when a link or pattern looks wrong. Do this: weigh a customer’s or payment’s geographic exposure with our Country Risk Checker. Key CTF laws and bodies CTF rules come from a layered set of international and national sources. Most trace back to the same global standard. The FATF. Added terrorist financing to its mandate in 2001 and now covers it in the 40 Recommendations. UN sanctions. The Security Council maintains lists of terrorist individuals and groups that firms must screen against. OFAC. Runs US programs targeting terrorists, including specially designated global terrorist lists. National law. The US, UK, and EU each criminalize terrorist financing and require screening and reporting. Read more: for how one sanctions rule works in practice, see the OFAC 50 percent rule. Warning signs of terrorist financing Terrorist financing rarely announces itself, but a few patterns raise concern. None is proof on its own, and each has to be read against what the firm knows about the customer. Transfers to or from conflict zones or high-risk regions with no clear reason. Many small transfers that gather into a single destination. Funds moving through a charity or non-profit with unclear activities. Activity that does not match the customer’s known profile or income. Links, by name or address, to individuals or groups on terrorist lists. Context is what turns a pattern into a concern. A single transfer to a high-risk region is normal for many businesses and families, so a firm weighs these signs together rather than acting on one alone. Read more: the same discipline of checking names sits behind a good sanctions check. Weigh a customer’s terrorist financing risk Get an indicative read on where your money laundering and terrorist financing risk is concentrated across markets. Try the AML Risk Assessment → Why CTF is hard CTF is harder than most financial crime control for two reasons that reinforce each other. The money is small, and its source is often legal. A large laundering scheme leaves a trail of unusual movement. A terrorist plot funded by a salary and a small transfer leaves almost none. The signal is not the amount, it is the connection to a person, place, or network of concern. That … Read more

Stages of Money Laundering

The three stages of money laundering are placement, layering, and integration. Placement puts dirty cash into the financial system, layering moves it through transfers to hide the trail, and integration returns it as clean-looking income. Each stage gives firms a different chance to catch it. Key takeaways Money laundering usually runs through three stages in order. Placement is the riskiest stage for the criminal, because raw cash is easiest to trace. Layering uses transfers, shell companies, and conversions to break the trail. Integration returns the funds as apparently legal income. In modern, digital laundering the stages often blur or happen at once. Firms map controls to each stage, from onboarding checks to transaction monitoring. On this page The three stagesPlacementLayeringIntegrationA worked exampleDo all three happen?Why it mattersDetecting each stageFAQsRead more $800B to $2T Laundered worldwide each year across the three stages Source: UNODC Under 1% Of illicit flows are seized or frozen Source: UNODC, 2011 1989 Year the FATF set the global standard firms follow Source: FATF What are the three stages of money laundering? The three stages of money laundering are placement, layering, and integration. The model has been used by investigators and the Financial Action Task Force for decades, because it describes how almost every scheme works. Each stage puts more distance between the money and the crime that produced it. Placement is where dirty money enters the system, layering is where its trail gets hidden, and integration is where it comes back looking clean. Knowing the stages is practical, not academic. Each one shows up differently in a customer’s activity, so each gives a firm a separate chance to notice and report. Read more: see real money laundering examples mapped to these stages. Stage 1: Placement Placement is the first step, where criminal cash enters the financial system. This is the riskiest stage for the launderer, because physical cash is the hardest thing to explain and the easiest to trace. Common placement methods include depositing cash in small amounts, running it through a cash-heavy business, buying assets, or moving it to a country with weaker controls. Structuring. Breaking cash into deposits below the reporting limit. How structuring works. Cash-intensive businesses. Mixing dirty cash with real takings from a laundromat, bar, or car wash. Currency smuggling. Physically carrying cash across a border to a place with looser rules. Asset purchases. Buying chips, cards, or goods with cash to convert it into something else. Because placement handles raw cash, it is where good customer checks and cash-reporting rules catch the most. See where your money laundering risk sits Answer a few questions about your customers, products, and markets to get an indicative risk rating in minutes. Try the AML Risk Assessment → Stage 2: Layering Layering is the middle stage, where the money moves through a chain of transactions to hide its source. The point is to create so many steps that following the trail becomes slow and expensive. This is usually the most complex stage. It can involve dozens of transfers across countries, companies, and asset types. Wire transfers. Sending funds between accounts and across borders, often in round numbers. Shell companies. Passing money through paper firms that issue fake invoices. See how shell companies are used. Conversions. Switching between cash, securities, and cryptocurrency to break the paper trail. Round-tripping. Sending money out and cycling it back through related parties. Worth knowing. Layering is designed to defeat a single reviewer looking at a single account. It is beaten by network analysis, where a firm links accounts, devices, and counterparties together, which is why modern monitoring looks at relationships, not just individual transactions. Stage 3: Integration Integration is the final stage, where the laundered money returns to the criminal as apparently legal wealth. By now the funds look like business income, investment returns, or the proceeds of a sale. Integration is the hardest stage to detect, because the money already appears clean. The warning signs are about mismatch, not movement. Property sales. Selling real estate bought earlier so the proceeds look like a normal transaction. Business revenue. Recording dirty funds as earnings from a front company. Investment returns. Presenting laundered money as gains from securities or a fund. Loan repayments. Paying yourself back through a controlled company to disguise the source. At this stage the best signal is wealth that does not match a customer’s known profile. Use the tool: check a counterparty with Combined AML Screening before a large transaction. Spot the warning signs early Use our red flags checklist to review onboarding and transactions for the signs of placement, layering, and integration. Open the Red Flags Checklist → A worked example across all three stages A simple example ties the stages together. Picture cash from drug sales that a group wants to spend openly. Placement. The group deposits the cash in small amounts across several accounts and a cash-heavy shop it controls. Layering. The funds move through wire transfers to a shell company abroad, get converted to cryptocurrency, then swapped back. Integration. The shell company buys an apartment, sells it a year later, and the group holds the sale proceeds as clean money. Each step alone can look ordinary. The scheme only becomes visible when someone connects the deposits, the transfers, and the property sale. Do all three stages always happen? No. The three-stage model is a guide, not a rule, and real cases do not always follow it neatly. Some schemes skip a stage, and digital methods often collapse the stages into one fast sequence. A single crypto transaction can place, layer, and integrate value in minutes. That speed is one reason regulators now focus on transaction monitoring and real-time screening rather than treating the stages as separate events. Why the three stages matter to compliance teams The three-stage model is more than a description. It gives a compliance team a shared language for where risk sits and which control should catch it. That makes it useful in three practical ways. It maps each stage … Read more

Anti-Bribery and Corruption (ABC)

Anti-bribery and corruption (ABC) is the set of laws and controls that stop firms and people from paying or taking bribes, or abusing power for private gain. It is a core part of financial crime compliance, backed by laws such as the US FCPA and the UK Bribery Act. Key takeaways Anti-bribery and corruption (ABC) stops improper payments and abuse of power. Bribery is offering value to influence a decision; corruption is the wider abuse of trusted power. Key laws include the US FCPA (1977) and the UK Bribery Act (2010). The World Economic Forum has estimated the global cost of corruption at about $2.6 trillion. Third parties, agents, and gifts are common ways bribery enters a business. ABC sits inside a firm’s wider financial crime compliance function. On this page What it isBribery vs corruptionWhy it is financial crimeKey lawsABC controlsThird-party riskRed flagsManaging the riskFAQsRead more $2.6T Estimated global cost of corruption, about 5 percent of GDP Source: World Economic Forum >$1T Estimated bribes paid worldwide each year Source: World Bank 1977 Year the US Foreign Corrupt Practices Act was enacted Source: US FCPA What is anti-bribery and corruption? Anti-bribery and corruption is everything a firm does to stop bribery and the abuse of entrusted power. It combines laws, policies, and checks that keep improper payments out of the business. The goal is both legal and practical. Bribery and corruption distort markets, raise costs, and expose a firm to heavy penalties, so ABC protects the firm as well as the public. It is one strand of financial crime work, alongside anti-money laundering and sanctions. Read more: ABC sits within a firm’s wider financial crime compliance function. Bribery vs corruption: the difference Bribery and corruption are linked but not the same. The difference is one of scope. Bribery is offering, giving, or taking something of value to improperly influence a decision. Corruption is broader: the abuse of entrusted power for private gain, which includes bribery but also embezzlement, fraud, and favoritism. Bribery Corruption What it is An improper payment or inducement Abuse of entrusted power for gain Scope A specific act A broad category of conduct Includes Cash, gifts, favors Bribery, embezzlement, favoritism In short, every bribe is corruption, but not all corruption is bribery. Why ABC is part of financial crime Bribery and corruption are financial crimes because they move money illegally and often feed other crimes. The proceeds frequently need laundering, which ties ABC to anti-money laundering work. A corrupt official who takes a bribe has to hide and use that money, which is where money laundering begins. Corruption is also a common predicate offense, the underlying crime that produces dirty funds. The scale is large. The World Economic Forum has estimated the global cost of corruption at about $2.6 trillion, roughly 5 percent of global GDP, and the World Bank has estimated that more than $1 trillion is paid in bribes each year. Check a country’s corruption risk Look up a country against corruption and financial crime data to see its risk profile before you take on exposure. Try the Country Risk Checker → Key anti-bribery laws A handful of laws set the global standard for ABC. Two carry the most weight for international firms. US Foreign Corrupt Practices Act (1977). Bans bribery of foreign officials and requires accurate books and records. UK Bribery Act (2010). Broader than the FCPA, it covers bribery of anyone, bans facilitation payments, and creates a corporate offense of failing to prevent bribery. OECD Anti-Bribery Convention (1997). Commits member countries to criminalize bribery of foreign officials. Local laws. Most countries have their own anti-bribery and anti-corruption statutes. These laws reach across borders. A firm can be prosecuted in one country for conduct that happened in another, which is why global firms apply the strictest standard everywhere. Worth knowing. One nuance trips up global firms. Small facilitation payments, made to speed up routine government action, are technically allowed under the US FCPA but banned outright under the UK Bribery Act. A firm operating in both places has to apply the stricter rule, which in practice means treating all such payments as off-limits. What ABC controls look like A working ABC program has a familiar set of controls, tuned toward payments, third parties, and gifts. The core parts are consistent. Risk assessment. Identify where bribery risk is highest, by country, sector, and third party. Policies. Clear rules on gifts, hospitality, donations, and facilitation payments. Third-party due diligence. Check agents, distributors, and partners before engaging them. Training. Help staff recognize and refuse improper payments. Whistleblowing. A safe channel to report concerns. Monitoring and audit. Review payments and books for signs of bribery. Use the tool: screen a partner for adverse media and sanctions links with Combined AML Screening before you engage them. Third-party and facilitation payment risk Most bribery does not happen directly. It flows through third parties, which is where the greatest ABC risk sits. Agents, distributors, consultants, and local partners can pay bribes on a firm’s behalf, and the firm can still be liable. Careful due diligence on who these parties are, and how they operate, is the main defense. Facilitation payments, small sums to speed up routine services, are a related trap. Even where they are technically legal, they are hard to control and easy to abuse, so many firms ban them entirely. Red flags of bribery and corruption A few patterns point to bribery risk. None is proof, but each warrants a closer look. A third party that demands unusually high fees or commissions. Payments to a country different from where the work is done. A partner recommended by the government official awarding the contract. Vague invoices for consulting or success fees with no clear deliverable. Reluctance to agree to anti-bribery terms in a contract. Gifts or hospitality that are lavish or badly timed around a decision. Screen a third party before you engage Run one search across sanctions, PEP, and adverse media data to check an agent, distributor, or … Read more

Financial Crime

Financial crime is any illegal act that uses money or the financial system for gain. It covers money laundering, fraud, bribery and corruption, sanctions evasion, tax evasion, and market abuse. Regulated firms are legally required to detect and prevent it. Key takeaways Financial crime is the umbrella term for crimes involving money and financial systems. Main types include money laundering, fraud, bribery, sanctions evasion, and tax evasion. Money laundering is one type of financial crime, not the whole thing. The UNODC estimates $800 billion to $2 trillion is laundered each year, a large part of the total. Firms manage the risk through financial crime compliance, screening, and monitoring. Failure brings fines, criminal liability, and lost banking access. On this page What it isMain typesVs money launderingWhat it costsCompliance (FCC)How firms reduce riskFAQsRead more $800B to $2T Laundered globally each year, one part of financial crime Source: UNODC ~$300B Laundered in the United States each year Source: US Department of the Treasury 1989 Year the FATF was founded to counter financial crime Source: FATF What is financial crime? Financial crime is any illegal act that uses money or the financial system to make or move illicit gains. It is a broad category that holds several distinct offenses under one heading. Regulated firms have legal duties to prevent it, which is why banks run large compliance teams. Financial crime hurts more than its direct victims: it funds organized crime, drains public money, and weakens trust in the financial system. Read more: the most common type is covered in money laundering explained. The main types of financial crime Financial crime splits into several types, and most firms face more than one. Each has its own controls, but they share tools like screening and monitoring. Money laundering. Disguising the criminal origin of funds. Learn more. Fraud. Deception to take money or assets. Learn more. Bribery and corruption. Paying for improper advantage or abusing power. Sanctions evasion. Dealing with restricted parties or countries. Learn more. Terrorist financing. Funding terrorist acts or groups. Learn more. Tax evasion. Illegally avoiding tax owed. Market abuse. Insider dealing and market manipulation. Use the tool: look up a country’s risk profile with the Country Risk Checker before you take on exposure. Check a country’s financial crime risk Look up a country against FATF, EU, and corruption data to see its risk profile before you take on exposure. Try the Country Risk Checker → Financial crime vs money laundering Money laundering is one type of financial crime. Financial crime is the wider group that laundering belongs to. Fraud, bribery, and tax evasion often produce dirty money in the first place. Laundering is the step that hides where that money came from. All of them count as financial crime. Worth knowing. Fraud creates the loss, and laundering conceals the gain. The same criminal group often runs both, which is why firms that treat fraud and AML as separate teams tend to miss cases that cross between them. What financial crime costs Financial crime carries a heavy price, for economies and for firms. The scale is hard to measure, but the estimates are large. The UNODC estimates $800 billion to $2 trillion is laundered each year, 2 to 5 percent of global GDP (UNODC). The US Department of the Treasury estimates roughly $300 billion is laundered inside the United States annually. On top of that sit the fines: TD Bank paid about $3 billion to US authorities in 2024 over Bank Secrecy Act failures (US Department of Justice, 2024). Spot financial crime red flags early Use our red flags checklist to review onboarding and transactions for the warning signs of laundering and fraud. Open the Red Flags Checklist → What is financial crime compliance? Financial crime compliance, often shortened to FCC, is how a firm manages its financial crime risk. It brings AML, sanctions, anti-fraud, and anti-bribery controls under one function. A typical FCC setup runs on four things: A risk assessment that rates where the firm’s exposure is highest. Screening of customers and payments against sanctions and PEP data. Transaction monitoring that flags unusual activity. Reporting of suspicion to the authorities. The same controls that stop laundering also catch sanctions breaches and fraud, which is why firms combine them. How firms reduce financial crime risk Firms cut financial crime risk with a few core controls, applied in proportion to the threat. The goal is to catch problems early and keep evidence. Know the customer. Verify identity and rate the risk. Screen names. Check against sanctions and PEP data. Confirm ownership. For business customers, find the beneficial owner behind the company. Monitor and report. Watch transactions and report anything suspicious. No single control catches everything, so firms layer them. A screening result is a first check, and a human review still decides the outcome. Screen a name across watchlists, free Run one search across sanctions, PEP, and adverse media data to check a person or company before you deal with them. Try Combined AML Screening → Frequently asked questions What is financial crime? Financial crime is any illegal act that uses money or the financial system for gain. It includes money laundering, fraud, bribery and corruption, sanctions evasion, tax evasion, and market abuse. Regulated firms such as banks are legally required to detect and prevent it, which is why they run dedicated compliance teams. What are the types of financial crime? The main types are money laundering, fraud, bribery and corruption, sanctions evasion, terrorist financing, tax evasion, and market abuse. Cyber-enabled theft and insider dealing also fall under the term. Most firms face several at once and manage them through a single financial crime compliance function. What is the difference between financial crime and money laundering? Money laundering is one type of financial crime. Financial crime is the wider category that also covers fraud, bribery, sanctions evasion, and tax evasion. Many of those crimes produce illegal money, and laundering is the separate step that hides where that money came from. What are … Read more