AML & Financial Crime – Page 7 – grcsight.com

Compliance Officer

A compliance officer is the person responsible for making sure a firm follows the laws and regulations that apply to it. In financial services, that includes anti-money laundering, sanctions, and conduct rules. The role overlaps with, but is broader than, the money laundering reporting officer. Key takeaways A compliance officer keeps a firm on the right side of the rules that apply to it. In finance, the role centers on anti-money laundering, sanctions, and conduct. It is broader than the MLRO, which is focused on money laundering. The role needs independence and a direct line to the board. A senior version is the Chief Compliance Officer, who leads the function. Regulators increasingly hold compliance officers personally accountable. On this page What it isWhat they doOfficer vs MLROIn financial servicesSkills neededWhere the role sitsThe Chief Compliance OfficerChallengesFAQsRead more 1989 Year the FATF set the standard compliance officers work within Source: FATF $3B Paid by TD Bank in 2024 after compliance failures Source: US Department of Justice $800B to $2T Laundered worldwide each year that compliance aims to stop Source: UNODC What is a compliance officer? A compliance officer is the person a firm relies on to follow the rules that govern it. They translate laws and regulations into practices the firm can actually run, and they check that it does. The role exists in many industries, but it is especially central in financial services, where the rules are dense and the penalties for breaking them are severe. At its heart, the job is about keeping the firm and its people out of trouble. Read more: in AML, the closely related role is the money laundering reporting officer. What does a compliance officer do? A compliance officer carries a broad remit that runs from writing rules to catching problems. The core duties are consistent across firms. Know the rules. Track the laws and regulations that apply to the firm. Write policies. Turn those rules into clear internal procedures. Advise the business. Guide teams on how to stay compliant. Monitor and test. Check that controls work and spot gaps. Handle reporting. Report issues to leadership and to regulators. Train staff. Build awareness of the rules across the firm. The exact mix depends on the firm, but the thread is the same: prevent, detect, and correct compliance failures. Compliance officer vs MLRO vs BSA officer These roles overlap, which causes confusion. The difference is scope and, in some places, a legal title. A compliance officer covers all the rules that apply to a firm. An MLRO, the UK term, is focused specifically on anti-money laundering. The BSA officer is the US equivalent of the MLRO, designated under the Bank Secrecy Act. Role Scope Where used Compliance officer All applicable rules General MLRO Anti-money laundering UK and aligned regimes BSA or AML officer Anti-money laundering United States In a small firm, one person may hold all of these at once. In a large bank, they are separate roles within a wider team. Start your compliance policy in minutes Generate a tailored AML policy draft that sets out roles and controls, ready for your compliance officer to adapt. Open the AML Policy Generator → The compliance officer in financial services In a bank or payment firm, compliance work leans heavily on financial crime. That is where the biggest risks and the biggest penalties sit. The compliance officer oversees anti-money laundering, sanctions screening, and conduct rules, often alongside a dedicated MLRO. They make sure the firm knows its customers, watches transactions, and reports suspicion, and they answer to the regulator when asked. The stakes are shown by enforcement. In 2024, TD Bank agreed to about $3 billion after compliance and monitoring failures (US Department of Justice, 2024). Give your compliance team a screening tool Run one search across sanctions, PEP, and adverse media data as part of your compliance checks. Try Combined AML Screening → Skills a compliance officer needs The role calls for a mix of knowledge and character. Technical skill alone is not enough. Knowledge of the rules. A sound grasp of the laws that apply to the firm. Judgment. The ability to weigh risk and make a call. Communication. Explaining rules clearly to the business. Independence. The nerve to challenge the business and say no. Attention to detail. Spotting the gap that others miss. Worth knowing. The quiet strength of a good compliance officer is the ability to say no and be heard. If the role reports to the very business it polices, or can be overruled without a record, it becomes decorative. Regulators look for genuine independence and a direct line to the board. Where the compliance role sits For compliance to work, it has to be independent of the business it checks. Structure is what protects that independence. In the common three lines of defense model, compliance is the second line: separate from the business, which is the first line, and from internal audit, which is the third. A strong compliance officer reports high in the firm, often with a direct line to the board, so they cannot simply be overruled. The Chief Compliance Officer In larger firms, the compliance function is led by a Chief Compliance Officer, or CCO. The CCO sits at the top of the compliance structure. The CCO sets the firm’s compliance strategy, owns the relationship with regulators, and reports to senior management and the board. Beneath them sits a team that may include the MLRO, sanctions specialists, and compliance analysts. The role carries real weight and real accountability. Get an indicative AML risk rating See where your money laundering risk is concentrated so your compliance function can focus where it matters. Try the AML Risk Assessment → Challenges and accountability The compliance role has grown harder as rules multiply and regulators pursue individuals. The pressure is real. Common challenges include heavy workloads, tension between compliance and commercial goals, and the risk of personal liability. In the UK, the Senior Managers and Certification Regime ties named individuals … Read more

Entity Resolution

Entity resolution is the process of working out whether different records refer to the same real-world person or company. In AML, it makes screening and customer checks more accurate by linking related records and separating different ones, cutting confusion and false matches. Key takeaways Entity resolution decides whether records refer to the same entity. It links related records and separates genuinely different ones. It makes screening and customer checks far more accurate. It helps cut false positives in screening. It often uses machine learning and fuzzy matching. Name variations and poor data quality make it challenging. On this page What it isHow it worksWhy it mattersEntity resolution and false positivesAnd machine learningThe challengesWhere it is usedDoing it wellFAQsRead more Over 90% Estimated share of screening alerts that are false positives Source: Industry estimates $800B to $2T Laundered worldwide each year that accurate screening targets Source: UNODC 1989 Year the FATF set the global screening standard Source: FATF What is entity resolution? Entity resolution is the job of figuring out when different records are really about the same person or company. Data about a customer often arrives in many forms, spelled differently, entered separately, or held in different systems, and entity resolution ties those threads together. The reverse matters too: it separates records that look similar but are actually different people. Getting both right, linking the same and splitting the different, is what makes downstream checks reliable. It is a quiet but vital part of good screening. Read more: it improves the accuracy of transaction monitoring and screening. How entity resolution works Entity resolution works by comparing records and judging how likely they are to describe the same entity. The process handles the messiness of real-world data. Matching. Comparing names, addresses, dates, and other details across records. Fuzzy matching. Allowing for spelling variations, typos, and different formats. Scoring. Judging how strongly records point to the same entity. Linking. Joining records that belong together into a single view. The hard part is that real data is messy. The same person may appear as different spellings, and different people may share a name, so the process weighs many clues rather than looking for an exact match. Why entity resolution matters in AML Entity resolution matters because AML depends on knowing who you are dealing with. If records are fragmented or confused, checks fall apart. Without good entity resolution, a firm might treat one risky customer as several harmless-looking ones, missing the full picture, or waste time treating separate people as the same. Screening a name is only useful if the firm can tell whether a hit really matches its customer. Accurate resolution underpins reliable screening, monitoring, and a true view of risk. Entity resolution and false positives One of the biggest payoffs of good entity resolution is fewer false positives. This connects directly to the alert-to-SAR conversion rate. Screening throws up huge numbers of false positives, often over 90 percent of alerts by industry estimates, in part because systems cannot tell whether a name match is really the same person. Better entity resolution means the system can rule out coincidental name matches and confirm genuine ones, cutting the noise. Fewer false positives means analysts spend their time on real risk rather than clearing confusion. Screen a customer against watchlists Run one search across sanctions, PEP, and adverse media data to check a customer accurately. Try Combined AML Screening → Entity resolution and machine learning Entity resolution increasingly relies on machine learning, which is well suited to the task. The problem is one of pattern and probability, which is what such tools do well. Machine learning can weigh many pieces of information at once, learn which combinations reliably indicate a match, and handle the variety of real data better than rigid rules. It can spot that two records with different spellings and slightly different details are almost certainly the same person, or that a close name match is a different one. This makes resolution more accurate and less manual, though human judgment still matters for hard cases. The challenges of entity resolution Entity resolution is hard, and a few problems make it so. They all come back to the messiness of real information. Name variations. Different spellings, transliterations, and formats of the same name. Poor data quality. Incomplete, outdated, or inconsistent records. Shared names. Different people who genuinely share a common name. Deliberate obfuscation. Criminals varying their details to avoid being linked. That last point matters in AML: bad actors actively try to defeat entity resolution, which is why it needs to be resilient to more than honest error. Worth knowing. Entity resolution is one of those unglamorous capabilities that quietly determines whether everything else works. The best screening rules and sharpest analysts are wasted if the firm cannot tell whether a match is really its customer. Investing in resolving entities well often does more to improve real detection, and cut wasted effort, than adding yet more screening rules on top of a shaky foundation. Where entity resolution is used Entity resolution runs behind many parts of a compliance program. Its uses share the need for an accurate view of who is who. Screening. Telling whether a sanctions or PEP hit really matches a customer. Customer due diligence. Building a single, accurate view of each customer. Monitoring. Seeing a customer’s full activity across accounts and records. Networks. Linking related parties to reveal hidden connections. Do this: keep a clear guide to the warning signs behind good alerts with our Red Flags Checklist. Doing entity resolution well Doing entity resolution well is about good data and good judgment together. A few priorities matter most. Improve data quality. Feed the process complete and accurate records. Use capable tools. Apply fuzzy matching and machine learning to the variety of data. Keep humans in the loop. Have people review hard or high-stakes cases. Tune over time. Refine the matching as you learn what works. Get an indicative AML risk rating See where your money laundering risk is … Read more

Anti-Money Laundering (AML)

Anti-money laundering (AML) is the set of laws, rules, and checks that stop criminals from disguising illegal money as legitimate funds. Banks and other regulated firms run AML programs to verify customers, monitor transactions, and report suspicious activity to the authorities. Key takeaways AML is the framework of laws and controls that detects and prevents money laundering. An AML program covers risk assessment, customer checks, monitoring, reporting, and training. AML and KYC are linked: KYC is the customer-identity part of a wider AML program. US rules come from the Bank Secrecy Act, FinCEN, and OFAC; the FATF sets the global standard. AML failures are expensive: TD Bank paid about $3 billion to US authorities in 2024. Core AML checks include sanctions, PEP, and adverse media screening plus customer risk rating. On this page What it isAML vs KYCWhat a program includesLaws and regulatorsWhat an AML check involvesWhy it mattersFAQsRead more 1989 Year the FATF was founded to set global AML standards Source: FATF $3B Paid by TD Bank to US authorities over AML failures (2024) Source: US Department of Justice $800B to $2T Laundered globally each year that AML aims to stop Source: UNODC What is anti-money laundering (AML)? Anti-money laundering is everything firms and governments do to stop criminals cleaning dirty money. It combines laws, regulations, and day-to-day checks inside banks, payment firms, and other regulated businesses. The point is to catch money laundering before or as it happens, then report it. A firm that ignores this risk can face fines, license loss, and criminal liability for its officers. Read more: see how a real program comes together in how to build an AML program. AML vs KYC: how they fit together AML is the wider program. KYC is one part of it. People often use the terms as if they mean the same thing, but they do not. KYC confirms who a customer is and how risky they are. AML is the whole system: KYC plus monitoring, reporting, training, and governance. KYC AML Scope Customer identity and risk The full anti-laundering program When Mostly at onboarding and review Continuous, across the customer life Includes ID checks, risk rating, screening KYC plus monitoring, reporting, training Read more: the practical side of KYC is covered in our KYC onboarding guide. Check how ready your AML setup is Get an indicative read on your money laundering exposure across customers, products, channels, and geographies. Try the AML Risk Assessment → What an AML program includes An AML program has a few standard parts that regulators expect to see. Miss one and the whole control set gets weaker. Risk assessment. A written view of where the firm’s laundering risk is highest. Customer due diligence. Verifying identity and assigning a customer risk level. Transaction monitoring. Flagging unusual activity for review. Suspicious activity reporting. Reporting suspicion to the authorities. Independent testing. Checking the controls actually work. A named officer owns the program, and staff get regular training. Worth knowing. Buying monitoring software does not make you compliant. Regulators look at whether your rules match your real risks and whether someone reviews the alerts. A tool with nobody acting on its output is a finding waiting to happen. Key AML laws and who enforces them AML rules differ by country, but the shape is similar everywhere. Most trace back to the FATF standard, then get written into national law. United States. The Bank Secrecy Act of 1970 and the USA PATRIOT Act, administered by FinCEN, with OFAC running sanctions. United Kingdom. The Proceeds of Crime Act 2002 and the Money Laundering Regulations 2017, supervised by the FCA. European Union. The AML directives and the 2024 package that created the AMLA supervisor. Global standard. The FATF, founded in 1989, with 40 Recommendations used across more than 200 jurisdictions (FATF). A country that falls short can land on the FATF grey list, which raises costs for its banks. Read more:the FATF 40 Recommendations explained. Start your AML policy in minutes Answer a short set of questions and generate a tailored AML policy draft you can adapt and keep for your records. Open the AML Policy Generator → What an AML check involves An AML check confirms a customer is who they say they are and is safe to deal with. It runs at onboarding and again when risk changes. Verify identity. Confirm the customer with reliable documents or data. Screen the name. Check against sanctions lists, PEP data, and adverse media. Apply deeper checks. Use enhanced due diligence for higher-risk cases, including source of funds. Rate and monitor. Assign a risk level, then re-screen as lists and circumstances change. Use the tool:Combined AML Screening runs sanctions, PEP, and adverse media in one search and shows the source and date. Why AML matters AML matters because the cost of getting it wrong is high, and it is rising. Fines, remediation, and lost banking relationships add up fast. In 2024, TD Bank agreed to pay about $3 billion to US authorities, including a record $1.3 billion FinCEN penalty, over Bank Secrecy Act failures (US Department of Justice, 2024). Beyond fines, weak AML lets the money behind trafficking, fraud, and corruption move freely. Screen a customer before you onboard Run one search across sanctions, PEP, and adverse media sources and see the result with its data source and date. Try Sanctions and PEP Screening → Frequently asked questions What is AML in simple terms? AML, or anti-money laundering, is the set of laws and checks that stop criminals turning dirty money into clean-looking funds. Banks and other regulated firms verify customers, watch transactions, and report anything suspicious. The aim is to catch money laundering early and keep criminal money out of the financial system. What is the difference between AML and KYC? KYC is part of AML. Know your customer covers verifying a customer’s identity and risk level. AML is the wider program that also includes transaction monitoring, suspicious activity reporting, staff training, and governance. KYC answers who the customer … Read more

Professional money laundering

Professional money laundering Professional money laundering is when an individual, organisation or network launders criminal proceeds for a fee, as a service, rather than laundering their own crime’s proceeds. The Financial Action Task Force formally described the phenomenon in a dedicated 2018 report, distinguishing professional launderers from the criminals who hire them. The professionals usually aren’t involved in the underlying crime at all. Key takeaways Professional money laundering means laundering criminal proceeds for a fee, as a service, rather than laundering your own crime’s proceeds. FATF’s 2018 report found professional launderers are typically not involved in the predicate crime itself. Operations range from a single individual to formally structured organisations to looser networks of associates. Common techniques include trade-based laundering, layered account networks, and underground banking. PML isn’t limited to lawyers or accountants; underground bankers and unlicensed advisers appear just as often in FATF’s case studies. PML transactions are designed to look ordinary, which is why pattern-based network analysis catches more of it than single-transaction review. On this page What makes money laundering “professional”Individual PMLs, organisations, and networksThe roles inside a laundering networkTechniques PMLs actually useWhy “professional” doesn’t mean a protected professionHow PMLs market and price their servicesWhy professional money laundering is hard to prosecuteWhat this means for financial institutionsFAQsRead more What makes money laundering “professional” What makes laundering “professional” isn’t formal qualifications. It’s that the person or network is in the money laundering business specifically, offering the service to multiple criminal clients rather than laundering the proceeds of a single crime they committed themselves. FATF’s 2018 report on the subject makes a sharp distinction: professional money launderers are typically not involved in the predicate crime at all. They’re hired afterward, specifically to move and clean the proceeds, in exchange for a fee or commission. Individual PMLs, organisations, and networks FATF’s report identifies three structural levels. An individual professional money launderer works alone, often building a reputation within criminal circles over years. A professional money laundering organisation has internal structure: defined roles, hierarchy, and specialisation. A professional money laundering network is looser, a set of associates and contacts, sometimes including two or more organisations, who work together on specific operations without being formally merged. Which structure a criminal client encounters often depends on the scale and complexity of what needs laundering. Moving a small amount of cash locally looks nothing like laundering hundreds of millions across multiple jurisdictions. The roles inside a laundering network Larger operations divide labour the way any specialised business would. FATF’s case studies describe distinct functions: money transport and cash controllers who physically move or manage bulk cash, IT specialists who build the technical infrastructure, and “straw men,” informal nominee shareholders and directors controlling companies on behalf of someone else entirely. One case in the FATF report describes a network’s IT specialists building a custom interface, accessible through the Tor browser, that automatically switched between e-wallets to process payments and obscure the money trail. That’s a level of technical sophistication most people don’t associate with money laundering. Worth knowing. One network described in FATF’s report built a custom interface, accessible only through the Tor browser, that automatically switched between digital wallets to process drug payments and obscure the money trail. That’s the level of technical sophistication some professional laundering operations now run at. Techniques PMLs actually use Trade-based money laundering disguises value through manipulated invoices and shipping documents. Account management mechanisms use networks of bank accounts, often across multiple jurisdictions, to layer and move funds quickly. Underground banking and alternative remittance systems move value without it ever crossing a formal banking system at all. Shell companies and layered international transfers are common structural elements across most of these techniques, chosen specifically because they make it harder for any single financial institution to see the full picture of where money is coming from and going to. Why “professional” doesn’t mean a protected profession It’s a common misconception that professional money laundering is mostly a problem involving lawyers, accountants, and other regulated professionals abusing their position. FATF’s report is explicit that PML isn’t limited to protected professions at all. Underground bankers and unlicensed tax advisers show up in the case studies just as often as anyone in a regulated role. That said, occupational professionals genuinely matter to the picture, because using a banker, lawyer, or accountant gives a laundering operation a veneer of legitimacy that criminals moving cash themselves can’t easily replicate. How PMLs market and price their services PMLs market their services largely through word of mouth, inside informal criminal networks built on prior engagement and trust rather than public advertising. Reputation is the product; a PML who gets caught or who fails a client damages their ability to get repeat business from other criminal groups. Pricing, according to FATF’s research, tends to scale with the risk the PML is taking on: higher commission rates for riskier jurisdictions, larger sums, or situations that require more layers of obfuscation to pull off cleanly. Why professional money laundering is hard to prosecute FATF’s own mutual evaluations found that many countries weren’t sufficiently investigating or prosecuting professional and third-party money laundering, as distinct from prosecuting the underlying predicate crime. Part of the difficulty is structural: a PML network can operate transnationally, deliberately exploiting weaknesses in specific countries or specific businesses, which makes gathering evidence and coordinating prosecution across borders genuinely hard. There’s also a detection problem. A PML’s whole value proposition to criminal clients is making laundered money look ordinary, which means the transactions themselves are specifically designed not to trigger the red flags a standard monitoring system looks for. Academic research backs this up: a Dutch study combining police registrations of 264 professional money launderers connected to drug trafficking with suspicious activity reports filed by reporting entities found that a large share of that activity never generated a report at all. What this means for financial institutions For a bank or other regulated firm, the practical implication is that some of the most dangerous laundering activity moving through … Read more

Machine Learning in AML

Machine learning in AML uses software that learns from data to help detect money laundering. Its main job is to spot suspicious patterns and cut the huge number of false alerts that rules-based systems produce, so analysts can focus on the cases that matter. Key takeaways Machine learning in AML uses software that learns from data to spot risk. Its biggest use is cutting false positives in transaction monitoring. It also supports screening, risk scoring, and finding hidden patterns. Rules-based systems flag huge volumes of alerts, most of them false. The main limits are explainability, bias, and data quality. It is a technique within regulatory technology, not a replacement for people. On this page What it isHow it is usedWhy firms use itSupervised and unsupervisedBenefitsLimits and risksMachine learning and regulatorsVs rules-basedFAQsRead more ~20% a year Estimated growth of the RegTech market that ML powers Source: Grand View Research $800B to $2T Laundered worldwide each year that ML helps detect Source: UNODC $3B Paid by TD Bank in 2024 after monitoring failures Source: US Department of Justice What is machine learning in AML? Machine learning in AML is the use of software that learns from data to help find money laundering. Instead of following only fixed rules, it studies patterns in past activity and uses them to judge new activity. The appeal is that laundering evolves, and a system that learns can keep up better than one that only does what it was told. In practice, most AML machine learning is aimed at the flood of alerts that older systems produce. It is one technique within a wider field. Read more: it sits inside regulatory technology, the broader use of tech in compliance. How machine learning is used in AML Machine learning shows up across several parts of AML work. Each use plays to its strength in spotting patterns. Cutting false positives. Ranking monitoring alerts so analysts see the real risks first. Transaction monitoring. Finding unusual patterns that fixed rules would miss. Risk scoring. Turning customer data into a more accurate risk rating. Screening. Improving name matching to reduce false hits. Network analysis. Spotting links between accounts that suggest a scheme. The common thread is pattern recognition, done at a scale and speed no team could match by hand. Why firms use machine learning Firms turn to machine learning mainly because of one number: the false positive rate. Rules-based monitoring flags enormous volumes of activity, and most of it turns out to be innocent. Industry estimates often put the false positive rate in transaction monitoring above 90 percent, meaning the vast majority of alerts waste an analyst’s time. Machine learning helps by ranking alerts so the real risks rise to the top, which lets a team spend its hours where they count. The second driver is volume. Digital banking produces far more transactions than any team can review, and a learning system helps manage that scale. See accurate screening in action Run one search across sanctions, PEP, and adverse media data and see how good matching cuts false hits. Try Combined AML Screening → Supervised and unsupervised learning Machine learning in AML usually comes in two broad forms. The difference is whether it learns from labeled examples. Supervised learning. Trained on past cases marked as suspicious or not, so it learns to recognize known patterns. Unsupervised learning. Left to find unusual patterns on its own, useful for spotting new methods no one has labeled yet. Supervised learning is good at catching what has been seen before, while unsupervised learning helps find the new tricks. Many firms use both together. Neither is magic. Both depend on the data behind them, and both produce suggestions that a person still has to judge before anything is acted on. Benefits of machine learning in AML Used well, machine learning brings real gains to an AML program. The benefits center on accuracy and scale. Fewer false positives. Less time wasted on innocent alerts. Better detection. Patterns that fixed rules would miss. Scale. The ability to handle volumes no team could review. Sharper focus. Analysts spend their time on the cases that matter. Limits and risks Machine learning is not a cure-all, and its limits matter as much as its benefits. A few risks stand out. Explainability. A model that cannot explain its decisions is hard to defend to a regulator. Bias. A model trained on biased data can produce unfair or skewed results. Data quality. Poor or thin data leads to poor decisions, however good the model. Over-reliance. Treating the model as the final word, with no human check. Worth knowing. The biggest hurdle for machine learning in AML is not accuracy, it is explainability. A regulator will ask why a customer was flagged, or why one was not, and a black box that cannot answer is a problem. This is why many firms favor models whose reasoning can be understood and shown. Machine learning and regulators Regulators are open to machine learning, but they set conditions. The main one is that a firm must be able to explain what its model does. A firm cannot hide behind an algorithm. It has to show that the model is sound, that its decisions can be understood, and that people still review the output. Regulators have encouraged responsible use of new technology, while making clear that accountability stays with the firm, not the software. In practice, this pushes firms toward a middle path. They use machine learning to rank and prioritize, but keep people making the final calls and keep records of why. That way a firm gets the efficiency without losing the ability to explain itself. Machine learning vs rules-based systems Machine learning and rules-based systems are often set against each other, but the best programs use both. The difference is how they decide. Rules-based Machine learning How it decides Fixed, written rules Patterns learned from data Strength Clear and explainable Adapts and finds new patterns Weakness Rigid, many false alerts Harder to explain A common … Read more

Debarment

Debarment is being formally excluded from contracts or programs because of misconduct. A debarred firm or person cannot win the affected work for a set period. It is used heavily against fraud, corruption, and collusion in public and development-bank contracting. Key takeaways Debarment is exclusion from contracts or programs due to misconduct. A debarred party cannot win the affected work for a set period. It is used against fraud, corruption, collusion, and serious wrongdoing. The World Bank and many governments maintain debarment lists. It differs from a fine: it is an exclusion, not a payment. Firms screen against debarment lists as part of due diligence. On this page What it isHow it worksTypes of debarmentDebarment vs a fineWhy it mattersWhat triggers itDebarment and screeningHow firms manage itFAQsRead more 600+ Firms and individuals sanctioned by the World Bank since 2001 Source: World Bank 2007 Year the World Bank set up its Office of Suspension and Debarment Source: World Bank $800B to $2T Laundered worldwide each year, linked to the crimes debarment targets Source: UNODC What is debarment? Debarment is a formal ban on doing certain business. A firm or person that is debarred is shut out from a defined set of contracts or programs, usually because they were caught in serious misconduct. It is not a fine or a criminal charge. It is an exclusion: a decision that, for a period, this party cannot take part in the affected work. The point is to keep those who cheat away from the funds and contracts they abused. It sits alongside financial crime as a serious integrity tool. Read more: the misconduct behind it often overlaps with financial crime. How debarment works Debarment works through lists and time limits. An authority decides a party should be excluded and places them on a list for a set period. Misconduct is found. An investigation establishes fraud, corruption, or similar. A decision is made. The authority decides to debar the party. They are listed. The party is added to a debarment list for a defined period. They are excluded. During that period, they cannot win the affected work. The exclusion usually has an end date, and in some systems a party can be released early by meeting conditions, such as improving its controls. Types of debarment Debarment exists in several systems, each covering its own contracts. The best-known operate at the international and national levels. World Bank debarment. Exclusion from World Bank-financed contracts for misconduct on its projects. Government debarment. Exclusion from a country’s public contracts, such as US federal contracting. Cross-debarment. One development bank recognizing another’s debarment, so exclusion spreads. Sector debarment. Exclusion from a specific program or industry. The World Bank has publicly sanctioned more than 600 firms and individuals since 2001, and its debarment list is a key reference for anyone vetting partners on development work. Debarment vs a fine Debarment and a regulatory fine are both consequences of misconduct, but they work very differently. One takes money; the other takes opportunity. A fine is a financial penalty: the firm pays and carries on. Debarment is an exclusion: the firm cannot win the affected work at all, whatever it is willing to pay. For a business that depends on public or development contracts, debarment can be far more damaging than a fine, because it cuts off future revenue rather than taking a one-time sum. Debarment Regulatory fine What it does Excludes from contracts Takes a financial penalty Effect Loss of future work A one-time cost Worst for Firms reliant on those contracts Any firm, as a direct cost The two can go together, but debarment is often the consequence a contractor fears most. Screen a partner against watchlists Run one search across sanctions, PEP, and adverse media data to check a partner or supplier. Try Combined AML Screening → Why debarment matters Debarment matters because, for many firms, contracts are the business. Losing access to them can be an existential blow. A company that relies on government or development-bank work can be crippled by debarment, since its main source of revenue is suddenly closed off. The reputational damage compounds this, as being publicly debarred signals to everyone that the firm was caught in misconduct. This is exactly why debarment is such a powerful deterrent against fraud and corruption in contracting. It threatens not a firm’s cash but its future, which for many contractors is the more frightening loss. What triggers debarment Debarment is reserved for serious integrity failures, not minor slips. A defined set of misconduct tends to trigger it. Fraud. Deception to win or profit from a contract. Corruption. Bribery or improper payments. Collusion. Secret agreements to rig a process. Coercion or obstruction. Threats, or blocking an investigation. These are the kinds of conduct that undermine the integrity of contracting, which is what debarment is designed to protect. Debarment and screening For a firm doing due diligence, debarment lists are an important thing to check. They flag partners who have been caught in misconduct. Before working with a supplier, contractor, or partner, especially on public or development projects, firms screen them against debarment lists such as the World Bank’s and national exclusion lists like the US System for Award Management. A match is a serious red flag. Checking these lists is part of building a full picture of who a firm is dealing with, alongside sanctions and adverse media screening. Worth knowing. Debarment and money laundering are more connected than they first appear. The same conduct that leads to debarment, fraud and corruption, generates proceeds that then need laundering. A firm debarred for corruption on a project may well have dirty money to move. This is why debarment lists sit alongside sanctions and adverse media checks in a thorough due diligence process. How firms manage debarment risk Firms manage debarment risk from two directions: avoiding it themselves and screening for it in others. A few priorities matter. Run strong integrity controls. Prevent the misconduct that leads to debarment. Screen partners. Check … Read more

Network analysis

Network analysis Network analysis, also called link analysis, is the practice of mapping relationships between people, accounts, businesses and transactions to reveal connections that aren’t visible when each entity is reviewed on its own. In AML work, it’s how investigators spot money mule networks, shell company chains, and layering schemes that look unremarkable one transaction at a time. The value is in the pattern across many entities, not any single one. Key takeaways Network analysis (or link analysis) maps relationships across people, accounts and entities to reveal patterns a single-entity review would miss. It depends on accurate entity resolution first; if the same person appears as multiple “different” entities, the network graph is wrong from the start. Common patterns it surfaces include money mule hubs, shell company chains, and shared identifiers like addresses or devices linking unrelated accounts. The signal is in the pattern across many entities, not in any single transaction looked at alone. It’s used well beyond money laundering, including fraud rings and sanctions evasion networks. Machine learning is increasingly layered on top of network graphs to flag anomalous structures automatically. On this page What network analysis actually doesWhy single-entity review misses so muchWhat network analysis relies on: entity resolution firstCommon patterns network analysis surfacesHow investigators build and read a network graphWhere network analysis fits in an AML programmeFAQsRead more What network analysis actually does Network analysis takes individual data points, people, accounts, addresses, devices, transactions, and plots them as a graph of connections. Patterns that are invisible when you review one customer’s file in isolation often become obvious once you see how that customer connects to dozens of others. Why single-entity review misses so much A traditional case review looks at one customer or one transaction at a time. A money mule sending a modest transfer looks unremarkable alone. The same transfer, seen as one of fifty similar transfers converging on the same destination account from otherwise unconnected senders, looks completely different. What network analysis relies on: entity resolution first None of this works without accurate entity resolution first. If the same real person or business appears as several different “unique” entities across a firm’s records, due to typos, name variants, or duplicate onboarding, the resulting network graph is wrong before analysis even starts. Getting entity resolution right is the foundation, not an afterthought. Common patterns network analysis surfaces Typical findings include mule networks organised around a small number of hub accounts, layering chains that route funds through several shell companies before reaching a final destination, and shared identifiers, the same address, phone number or device, linking accounts that otherwise look completely unrelated. Worth knowing. A shared phone number, address or device ID across accounts that otherwise look unconnected is one of the clearest signals network analysis surfaces, and one a transaction-by-transaction review would never catch on its own. How investigators build and read a network graph Modern tools plot entities as nodes and relationships as edges, then let an investigator visually trace paths between them. Graph databases and visualisation software make this practical at scale, and increasingly machine learning is layered on top to flag structurally unusual patterns automatically, rather than relying purely on manual review. Where network analysis fits in an AML programme It typically sits downstream of alert generation, used by investigators working escalated cases rather than as a first-line screening step. It’s especially valuable for typologies that depend on coordination across many accounts, such as money mule operations, where no single transaction tells the full story. Frequently asked questions What is network analysis in AML? Network analysis, or link analysis, maps relationships between people, accounts, businesses and transactions to reveal connections that aren’t visible when each entity is reviewed on its own, such as money mule networks or shell company chains. What is the difference between network analysis and link analysis? The terms are generally used interchangeably in AML investigation work, both describing the practice of mapping relationships across entities to surface hidden patterns. Why does network analysis need entity resolution first? If the same person or business appears as multiple separate “entities” in a firm’s records due to typos or duplicate onboarding, the resulting network graph will be wrong from the start. Accurate entity resolution has to come first. What red flags does network analysis typically reveal? Common findings include hub-and-spoke mule networks, layering chains routed through several shell companies, and shared identifiers such as an address, phone number or device linking accounts that otherwise look unconnected. Is network analysis only useful for money laundering? No. The same technique is widely used to investigate fraud rings, sanctions evasion networks, and other financial crime that depends on coordination across multiple accounts or entities. Read more: our ultimate guides, whitepapers and templates Related guides and resources to help you act on what you just read. Entity ResolutionThe foundation it depends on.Read guide →Money Laundering TypologiesWhat patterns look like.Read guide →Money MuleA common network target.Read guide →Corporate Family TreeMapping ownership chains.Read guide → Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team Key takeaway: Network analysis, also called link analysis, is the practice of mapping relationships between people, accounts, businesses and transactions to reveal connections that aren’t visible when each entity is reviewed on its own. In AML work, it’s how investigators spot money mule networks, shell company chains, and layering schemes that look unremarkable one transaction at a time. The value is in the pattern across many entities, not any single one.

Model validation

Model validation Model validation is the independent testing of a detection model, checking that it works as intended and performs well on real data, both before it goes live and on an ongoing basis afterward. It’s the practical mechanism through which a firm delivers the “effective challenge” that regulatory guidance such as SR 11-7 expects. Validation is carried out by people who didn’t build the model, not the model’s own developers. Key takeaways Model validation is independent testing, not a self-check by the team that built the model. SR 11-7 frames validation around three elements: conceptual soundness, ongoing monitoring, and outcomes analysis. Above-the-line testing checks the alerts a system did generate; below-the-line testing checks the transactions it didn’t flag. Below-the-line testing is how firms catch false negatives a pure alert review would never surface. Validation should happen before a model goes live and periodically afterward, not as a one-off exercise. Weak or missing validation is a recurring theme in AML enforcement findings tied to transaction monitoring failures. On this page What model validation actually checksWhy validation has to be independentThe three core elements of validationAbove-the-line and below-the-line testingValidation before launch vs ongoing validationWhat weak validation looks like to a regulatorFAQsRead more What model validation actually checks Validation asks three related questions: is the model’s underlying logic sound, does it keep performing as expected once it’s running, and do its actual outputs match what really happened when checked against real transactions and outcomes. Why validation has to be independent A team that built a model has a natural blind spot toward its own assumptions. Independent validators, people or teams separate from development, are far more likely to catch flaws the builders talked themselves past, which is why SR 11-7 treats independence as a core requirement, not a nice-to-have. The three core elements of validation Regulatory guidance frames validation around three elements: conceptual soundness, reviewing the theory and logic behind the model’s design; ongoing monitoring, checking the model keeps performing as intended over time; and outcomes analysis, comparing what the model predicted against what actually happened. Above-the-line and below-the-line testing Above-the-line testing reviews the alerts a monitoring system actually generated, checking whether they were accurate and well-calibrated. Below-the-line testing does the opposite: it samples transactions the system did not flag, to check whether genuine risk slipped through unnoticed. Both matter. A validation that only looks at generated alerts can look thorough while still missing the risk a below-the-line sample would catch. Worth knowing. Below-the-line testing, sampling transactions the system never flagged, is the only reliable way to catch false negatives. A validation exercise that only reviews generated alerts can look thorough while still missing the risk that matters most. Validation before launch vs ongoing validation A model needs validating before it goes live, to catch design flaws before they affect real decisions, and periodically afterward, since data patterns and criminal behaviour both shift over time. A model validated once at launch and never revisited is a common finding in AML enforcement actions tied to transaction monitoring failures. What weak validation looks like to a regulator Supervisors typically flag validation that’s performed by the same team that built the model, validation that only reviews above-the-line alerts, and validation documentation that can’t show what was actually tested or when it was last refreshed. Frequently asked questions What is model validation? Model validation is the independent testing of a detection model, checking that it works as intended on real data, both before it goes live and periodically afterward. Who should perform model validation? Validation should be carried out by people or teams independent of whoever built and runs the model day to day, so they can identify flaws without the blind spots that come from having built it themselves. How often should a model be validated? A model should be validated before it goes live and then periodically afterward, since data patterns and the behaviour a model is trying to detect both change over time. What is above-the-line testing? Above-the-line testing reviews the alerts a monitoring system actually generated, checking whether they were accurate and well-calibrated. What is below-the-line testing? Below-the-line testing samples transactions the system did not flag, checking whether genuine risk slipped through unnoticed. It’s the main way firms catch false negatives. Read more: our ultimate guides, whitepapers and templates Related guides and resources to help you act on what you just read. Model RiskThe problem validation manages.Read guide →Above-the-Line TestingChecking what alerted.Read guide →Below-the-Line TestingChecking what didn’t.Read guide →Independent AML AuditThe wider check.Read guide →Machine Learning in AMLWhere validation matters most.Read guide → Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team Key takeaway: Model validation is the independent testing of a detection model, checking that it works as intended and performs well on real data, both before it goes live and on an ongoing basis afterward. It’s the practical mechanism through which a firm delivers the “effective challenge” that regulatory guidance such as SR 11-7 expects. Validation is carried out by people who didn’t build the model, not the model’s own developers.

AML Policy

An AML policy is a written document that sets out how a firm prevents, detects, and reports money laundering. It records the firm’s rules for customer checks, monitoring, reporting, and record-keeping, turning anti-money laundering law into instructions staff can follow. Key takeaways An AML policy is the written rulebook a firm uses to meet its anti-money laundering duties. It sits inside the wider AML compliance program and is not the same thing. A sound policy covers risk assessment, customer due diligence, monitoring, reporting, and training. Every regulated firm needs one, scaled to its size and risk. Regulators expect the policy to be followed in practice, not just filed away. A stale policy is a common finding, so it should be reviewed regularly and when risk changes. On this page What it isPolicy vs programWhat to includeWho needs oneHow to write oneKeeping it currentCommon mistakesFAQsRead more 1989 Year the FATF set the standard AML policies follow Source: FATF $3B Paid by TD Bank in 2024 after AML failures Source: US Department of Justice $800B to $2T Laundered worldwide each year policies aim to stop Source: UNODC What is an AML policy? An AML policy is the document that tells a firm’s people how to fight money laundering. It sets the rules for onboarding customers, watching transactions, reporting suspicion, and keeping records. The policy translates law into practice. A rule such as verifying a customer’s identity becomes a specific instruction: what to collect, how to check it, and what to do when something does not add up. A good policy is written for the people who use it, not just for the regulator who inspects it. Read more: the policy is one piece of a larger AML compliance program. AML policy vs AML compliance program An AML policy and an AML program are often confused, but they are different. The policy is the written rulebook. The program is the whole system that puts those rules into action. Think of it this way. The policy says what should happen. The program is the people, tools, monitoring, and testing that make it happen and prove it happened. AML policy AML program What it is A written document of rules The full operating system Answers What should happen How it happens and is proven Includes Procedures, roles, thresholds The policy plus people, tools, monitoring, testing A firm can have a polished policy and still fail, if nobody follows it. That gap between the document and daily practice is what examiners probe first. What an AML policy must include A complete AML policy covers the full life of a customer relationship. The exact wording varies, but the parts below are standard. Purpose and scope. Who the policy applies to and which laws it meets. Risk-based approach. How the firm rates risk and matches controls to it. See the risk-based approach. Customer due diligence. How the firm verifies identity and applies enhanced due diligence for higher risk. Transaction monitoring. How the firm watches activity and handles alerts. Sanctions and PEP screening. How names are checked against sanctions and PEP lists. Suspicious activity reporting. When and how the firm files a suspicious activity report. Record-keeping. What records are kept and for how long. Roles and responsibilities. Who owns the program, usually the MLRO or compliance officer. Training. How staff are trained and how often. Worth knowing. The most useful line in any AML policy is the escalation path: exactly who a staff member tells when they see something wrong, and how fast. Policies that describe controls in detail but leave escalation vague are the ones where real suspicion gets stuck at the front line. Start your AML policy in minutes Answer a short set of questions and generate a tailored AML policy draft you can adapt and keep for your records. Open the AML Policy Generator → Who needs an AML policy? Every regulated firm needs an AML policy. That includes banks, payment firms, crypto businesses, and many professional services such as accountants, lawyers, and estate agents. Size changes the length, not the need. A global bank may run hundreds of pages across many teams, while a small firm may need only a few well-written ones. What matters is that the policy fits the firm’s real risk. A firm that operates in more than one country has to meet each local rulebook while keeping one coherent policy. Read more: our guide to AML regulations in the US sets out the detail. Base your policy on real risk Get an indicative read on where your money laundering risk is concentrated before you write the policy. Try the AML Risk Assessment → How to write an AML policy Writing a policy follows a clear order. Each step builds on the one before. Start from a risk assessment. Base the policy on the risks the firm actually faces. Our AML risk assessment gives a starting point. Map the customer journey. Set rules for onboarding, ongoing monitoring, and exit. Write for the user. Use plain instructions a new joiner could follow. Set clear thresholds. Say when a check, an alert, or a report is triggered. Name the owners. Give each duty to a role, not a vague team. Get sign-off. Have senior management approve the policy and record it. Use the tool: screen customers as part of onboarding with Combined AML Screening, which checks sanctions, PEP, and adverse media in one search. How to keep your AML policy current A policy is not a one-time task. It has to keep pace with the firm and the rules around it. Review it on a set schedule, and again whenever something changes. Common triggers include a new product, a new market, a new customer type, a regulatory change, or a lesson from an incident. Scheduled review. Reassess the policy at least once a year for most firms. Trigger-based review. Update it when the business or the law shifts. Version control. Keep dated versions so you can show what applied and when. Board oversight. … Read more

Geographic Risk

In anti-money laundering, geographic risk is the risk that comes from where a customer, transaction, or business is located or connected. Some countries carry higher risk because of weak controls, corruption, sanctions, or conflict, and firms weigh this location risk as part of their wider assessment. Key takeaways Geographic risk is the money laundering risk tied to location. It looks at where a customer, their funds, or their business are connected. Higher-risk factors include weak AML controls, corruption, sanctions, and conflict. Firms use sources such as FATF lists, sanctions lists, and corruption indexes. It is one factor in the risk-based approach, not the whole picture. A high-risk country does not make every customer from there guilty. On this page What it isWhy geography mattersWhat raises riskSources firms useHow firms assess itIn the risk-based approachLimits and fairnessHow to manage itFAQsRead more 180 Countries scored by Transparency International’s corruption index Source: Transparency International $800B to $2T Laundered worldwide each year, unevenly across regions Source: UNODC 1989 Year the FATF was founded to set the global standard Source: FATF What is geographic risk? Geographic risk is the part of money laundering risk that comes from location. It asks a simple question: does where this customer, business, or payment is connected make crime more likely? The term also appears in insurance and investing with different meanings. In anti-money laundering, it is specifically about the financial crime risk tied to a country or region. Location is one of the strongest signals a firm has. Read more: it feeds directly into an AML risk assessment. Why geography matters in AML Geography matters because financial crime is not spread evenly across the world. Some countries have strong controls and low corruption, while others have weak rules that criminals exploit. A payment to or from a country with little oversight carries more risk than the same payment within a well-controlled system. The same is true of a customer whose wealth comes from a high-risk region. Weighing location lets a firm spot risk that a name or amount alone would hide. It is one of the first things any assessment considers. It is also one of the easiest factors to check. A name can be common and an amount can look ordinary, but a country either sits on a high-risk list or it does not, which gives a firm a clear, defensible starting point. What makes a country higher risk? Several factors can raise a country’s risk. They often overlap, and the more that apply, the higher the risk. Weak AML controls. Countries on the FATF grey or black lists for control failures. Sanctions. Countries under international sanctions or embargoes. High corruption. Places that score poorly on corruption indexes. Conflict and instability. Zones where oversight has broken down. Drug production or trafficking. Major sources or transit routes for drugs. Tax haven features. Secrecy and low transparency that hide ownership. No single factor decides it. A country can be high risk for one reason and ordinary in every other respect. Check a country’s financial crime risk Look up a country against FATF, sanctions, and corruption data to see its risk profile in one place. Try the Country Risk Checker → Sources firms use Firms do not judge country risk on instinct. They lean on a set of respected, public sources, usually combined into a single view. FATF lists. The grey and black lists of countries with control weaknesses. EU high-risk list. The EU’s list of high-risk third countries. Sanctions lists. OFAC, UN, EU, and UK sanctions programs. Corruption indexes. Transparency International’s index, which scores 180 countries. Basel AML Index. A country ranking of money laundering risk. Combining sources gives a fuller picture than any one list alone. A country may sit on no sanctions list yet score badly for corruption. The sources also serve different purposes. Sanctions lists are about legal prohibitions, while corruption indexes and the Basel Index describe the broader environment. A firm reads them together rather than treating any one as the last word. How firms assess geographic risk Assessing geographic risk means turning these sources into a rating a firm can act on. The method is straightforward. Map the exposure. Identify which countries a customer, their funds, and their business touch. Check the sources. Look each country up against the lists and indexes above. Rate the country. Assign a risk level based on the combined picture. Feed it into the customer rating. Use it as one input to the overall customer risk rating. Use the tool: get an indicative read on your overall exposure with the AML Risk Assessment. Geographic risk in the risk-based approach Geographic risk is one factor among several, not a verdict on its own. It works alongside customer, product, and channel risk to build a full picture. A customer in a higher-risk country may still be low risk overall if every other factor is clean. Equally, a customer in a low-risk country can be high risk for other reasons. The skill is weighing location together with everything else. Worth knowing. Geographic risk cuts both ways. It is not only about where a customer lives, but where their money comes from, where it goes, and where their business partners sit. A local customer with a supplier in a high-risk country carries geographic risk that a glance at their address alone would miss. Limits and fairness Geographic risk has to be used with care. Treating everyone from a country as suspicious is both unfair and a mistake. A high-risk country rating is a reason to look more closely, not to refuse a whole nationality. Doing the latter is a form of de-risking that regulators discourage. The point is proportionate care, not blanket exclusion. Getting this balance right protects both the firm and its customers. Over-caution shuts out honest people and pushes their money into less visible channels, while under-caution lets real risk through. The aim is a rating that guides attention, not one that decides guilt. How to manage geographic risk Managing geographic … Read more