Cash Management, Treasury and Trade Services Financial Crime
Cash management helps a business collect, hold and pay funds; treasury manages liquidity, funding and financial exposures; trade services support commercial transactions through instruments such as documentary credits, collections and guarantees. They can share customers and payment flows while having different mechanics and evidence.
Trade-based money laundering can disguise movement of value through misleading prices, quantities, goods descriptions, invoices or counterparties. A trade document is evidence to evaluate, not proof that goods exist or that value is legitimate. The bank's visibility varies by service; a documentary-credit team sees different information from an ordinary payment processor.
Corporate authority and beneficial ownership are distinct. A signatory may be authorised to instruct a payment without owning the company. A treasury centre may pay for group entities without being the ultimate purchaser. Understand the relationship, mandate, expected business and funding arrangement rather than classifying every third-party payment as suspicious.
FATF Recommendations 10, 16 and 20 provide relevant standards for CDD, payment transparency and reporting. Sanctions, export controls, trade rules and documentary obligations are separate frameworks. Do not assume that a bank's document examination under a trade instrument proves sanctions clearance, AML compliance or shipment authenticity.
Cash management starts with the economic owner
A corporate account can collect thousands of payments without resembling an ordinary trading company's bank statement. Retail chains deposit store takings, manufacturers collect invoices centrally, travel platforms settle transactions with several participants, and groups centralise supplier payments. High turnover and rapid redistribution are therefore normal for some customers. The bank needs to establish whose money is moving, which obligations are being discharged, and whether the account structure preserves enough information to understand those flows. A monitoring rule that simply marks high velocity as suspicious will repeatedly select the product's intended behaviour.
At the start of a relationship, the product manager should distinguish the account holder from operating affiliates, customers of the corporate group, instructed beneficiaries and people entitled to give instructions. These roles are not interchangeable. A holding company may own an operating subsidiary without being entitled to use every subsidiary account. A corporate treasurer may have a valid mandate without owning the funds personally. An outsourced payment administrator may prepare a file without authority to release it. The mandate evidence should say which entity grants authority, which accounts and services it covers, how approvals work and what happens when a person leaves or changes responsibilities.
The business description should explain how money enters and leaves. For a distributor, credits might be receivables from named commercial customers and debits might be supplier invoices, payroll, tax and financing. For a payment factory, the debit population can include obligations of multiple affiliates. For an insurer or property manager, collected amounts may include funds held or administered for others, with legal and contractual implications requiring specialist review. An analyst should not infer the applicable client-money or payment-services regime from the account's marketing name. Determine the customer's activity and legal perimeter before deciding which evidence and segregation arrangements are required.
Physical pooling and notional pooling expose different facts
In a physical cash pool, balances are actually transferred between participating accounts and a concentration account according to the agreed structure. An operating company's overnight surplus may become an intercompany receivable against the treasury entity; a deficit may create an intercompany payable or other funding position. The precise legal and accounting result depends on the agreements and jurisdiction. The bank should understand that result rather than assume every sweep is a supplier payment or that consolidated group ownership eliminates separate entity rights. Participation lists, account maps, funding agreements and sweep parameters provide the starting evidence.
A notional pooling arrangement generally calculates a combined interest position without the same automatic movement of principal between participants. Account balances and legal positions still matter individually. Cross-guarantees, set-off rights, overdrafts and restrictions can vary. A notional total is not a complete picture of who owns money or owes a debt. For financial-crime analysis, compare actual account transactions with the arrangement's intended mechanics. If the system creates synthetic accounting entries or interest allocations, identify them as such so they are not mistaken for external payments, unexplained receipts or transactions with an unrelated party.
Consider a fictional physical pool with three operating companies and one treasury account. The operating accounts sweep 400,000, 250,000 and 150,000 units into treasury overnight. Treasury later pays 500,000 to suppliers on their behalf and leaves 300,000 available for group funding. Reviewing only the 800,000 central credit loses the distinction between the affiliates and their earlier sources. Reviewing only the supplier debit loses which company incurred each obligation. The control should join the sweep to the participant and the external payments to the underlying commercial parties where data is captured. The amounts illustrate the arithmetic, not a reporting threshold.
A sudden addition to a pool deserves a different question from an ordinary change in daily balance. Was the new participant properly authorised, identified and assessed? Is it part of the represented group? Does its activity fit the pool's purpose? Do restrictions apply to transfers between its jurisdiction and the treasury entity? A genuine acquisition can explain a new participant. An unrelated entity using the pool to receive and settle third-party business can change the customer's regulatory and financial-crime profile materially. The product team should route that change for assessment before treating the new account as another routine line in the file.
Virtual accounts are identifiers, not a shortcut around ownership
Virtual-account services can allocate incoming receipts to business units, projects, customers or invoices while money is booked to a physical account. They can greatly improve reconciliation. The label itself does not establish that every virtual account is a separate legal bank account or that its named user is the bank's customer. The implementation and contract determine what the identifier represents. Requirements should capture the physical account, virtual identifier, assigned party, purpose, effective period and any hierarchy between identifiers. Retired identifiers must remain traceable for historical investigations.
A retailer's virtual identifiers for stores create different risk from an intermediary allocating identifiers to unrelated external businesses. The second arrangement can resemble collection services for third parties and may require a different perimeter assessment. If the intermediary alone can create or reassign identifiers, the bank needs a control for material population changes and sufficient access to relevant underlying information under the applicable framework. Do not assume that a technically well-formatted identifier proves the identity, ownership or entitlement of whoever uses it. Technical validation and customer due diligence answer different questions.
A dangerous migration replaces every incoming virtual identifier with the central account number before monitoring. The ledger reconciles, yet customer attribution disappears. The opposite error occurs when the same receipt is counted once against the virtual identifier and again against the physical account, manufacturing twice the economic value. A sensible reconciliation records one economic receipt, its booking account and its allocation relationships. The monitoring population can include multiple relevant entities without duplicating amounts. Investigators should see both the original receipt and the attribution rule used at the time, including later corrections.
Paying and collecting on behalf of group entities
Payment-on-behalf-of arrangements can reduce bank accounts and centralise corporate control. The treasury centre becomes the technical payer while an affiliate remains the underlying buyer or debtor. Collection-on-behalf-of can centralise receipts for sales made by affiliates. Both can be legitimate. The bank should understand the mandate, commercial relationship, internal settlement and information available to identify those roles. A mismatch between invoice buyer and payment-account holder is then a question to resolve, not an automatic finding of layering.
The arrangement can also conceal transactions if underlying affiliate data is omitted or unreliable. A payment factory may submit one bulk file containing payroll, taxes, supplier purchases and intercompany funding. Each transaction has a different purpose and potentially different parties. A central-account risk score cannot replace relevant assessment of the underlying transaction. Equally, the bank cannot invent detail that the service does not receive. Agree what data the customer supplies, how exceptions are handled, which contractual rights permit further inquiry, and whether the resulting visibility is sufficient for the product and risk profile.
Beneficiary changes create a practical meeting point between fraud prevention and AML. The treasury centre may have genuine payment authority while a supplier-change request is fraudulent. A supplier's trading name may differ legitimately from its legal or banking name. Verification should use an appropriate independent channel and preserve the change request, verifier, approval and effective date. A repaired payment message should not erase the original beneficiary. If a customer explanation resolves the operational name difference, that does not by itself resolve a sanctions connection, suspicious funds source or compromised instruction.
Treasury funding and conversion require commercial understanding
Treasury services can include foreign-exchange execution, deposits, funding and hedging around commercial activity. A group purchasing goods in one currency and collecting revenue in another may legitimately transact at high frequency. Currency conversion is not evidence of laundering. Analyse why exposure arises, which entity carries it, how transactions relate to that exposure and who funds settlement. A cash-management account with significant FX settlement can be consistent with the customer's trade model, while unexplained third-party funding of the same trades creates an additional question.
A derivative's notional value is not automatically the amount of cash transferred. Collateral, premiums, settlements and close-out amounts have separate meanings. Comparing a hedge's notional to bank-account credits can generate a false mismatch. Net settlement can reduce several contractual positions to one payment, so the analyst may need the underlying schedule to understand counterparties and obligations. Requirements should preserve gross transaction information where held and clearly label the actual cash amount. Risk analysis must use the appropriate measure rather than choose the largest available number.
Standards, law and commercial rules must remain distinct
FATF provides international standards; countries implement them through their legal frameworks. The June 2025 revisions to Recommendation 16 and the associated June 2026 consultation illustrate why change status matters. FATF expects countries to be ready to implement the revisions by the end of 2030, while the June 2026 guidance text was issued for consultation, which FATF now marks as closed. The consultation document does not itself create national bank obligations. Existing payment-information duties can already apply under local law. A bank should preserve useful structured party information now, but must not describe every field in a draft guidance document as a universally binding requirement already in force.
Trade-finance practice also uses contractual instrument rules and voluntary financial-crime principles. A documentary undertaking's incorporated rules determine document handling, while sanctions, export controls and AML duties follow their own applicable legal bases. The ICC, Wolfsberg Group and BAFT Trade Finance Principles are an industry control reference, not a substitute for national legislation. The chapter's operating examples teach how a bank can connect evidence across products; the legal and contractual requirements for a particular entity, branch, payment or instrument still need to be identified explicitly.
Relevant official context: FATF payment-transparency consultation, June 2026, and ICC, Wolfsberg and BAFT Trade Finance Principles.
Customer, document and payment context
At onboarding identify the group's business, operating entities, treasury structure, ownership, signatories, expected currencies and trade corridors. For pooling or payment-on-behalf-of services, map which entity owns funds and incurs obligations. A central account can obscure underlying activity if entity identifiers are lost.
For a trade transaction examine parties, goods, values, routes, documents and payment terms within the bank's actual service scope. Unexpected intermediaries, implausible prices, duplicate invoices or mismatched goods may require inquiry. Price differences can have legitimate causes, including quality, delivery terms and market movement; avoid treating a single benchmark deviation as proof of laundering.
Keep instruction, trade document, financing, payment and settlement records linked. A message confirming a payment instruction is not proof of final settlement, and a loan disbursement is not proof that goods shipped. Trade operations, payments, compliance and treasury should share relevant facts while keeping each decision's basis clear.
Exception handling must distinguish document discrepancies, customer risk, sanctions restrictions, operational repairs and suspicion. A documentary discrepancy can be waived under the relevant contractual framework without waiving a legal prohibition. A sanctions issue cannot be resolved merely by changing document wording.
Documentary credit, collection and open-account payment are different exposures
A documentary credit can provide a bank undertaking against a qualifying presentation under its terms and incorporated rules. A collection normally involves handling documents and obtaining payment or acceptance according to instructions, with a different level of bank commitment. An open-account sale can be paid through an ordinary transfer with no trade instrument at all. Guarantees and standby undertakings add further structures. The bank's financial-crime control needs to reflect its actual role: issuing, advising, confirming, nominated, collecting, reimbursing, financing or merely processing a payment. A generic label of trade finance is too coarse for evidence design.
The distinction affects what the bank can know. An issuing bank can have its customer's application and credit terms. A bank examining a presentation can see the documents submitted, subject to its role. A payment processor may see parties, accounts, agents and remittance text without an invoice or bill of lading. A correspondent financing another bank's trade activity may not see each underlying commercial transaction. State those limits. Insisting that every transaction have a document pack can be impossible for some products; assuming no pack is needed for a bank-funded receivable can miss a material financing risk.
Document examination and financial-crime review should connect without collapsing into one decision. A document discrepancy may concern dates, descriptions, amounts or presentation requirements. Some discrepancies may be accepted through the relevant contractual process. That acceptance does not authorise a prohibited transaction or determine whether activity is suspicious. Conversely, a legitimate operational discrepancy is not proof of laundering. The trade officer should state the discrepancy and contractual status, while the appropriate specialist separately records sanctions, export-control or AML conclusions and any required action.
Price, quantity and shipment evidence need compatible measures
Trade-based value transfer can involve misleading prices, quantities, descriptions or invoicing. It is tempting to automate a price anomaly by comparing an invoice with a market average. That comparison can be technically unsound. Commodity grade, unit, packaging, processing, delivery terms, insurance, credit period, currency, date and market movement can all affect price. An industrial component with a service warranty cannot be compared directly with an unassembled spare part. An apparent excess should generate a defined question using genuinely comparable data rather than a categorical allegation of over-invoicing.
Quantity analysis has similar pitfalls. A purchase order may show kilograms, the transport document cartons and the invoice individually priced units. Gross shipment weight includes packaging; net weight may measure only goods. Partial shipments and split invoices can be ordinary. A data pipeline that interprets all numbers as the same quantity will produce convincing but false anomalies. The investigator should retain the original unit, any conversion factor, its source and the reason for using it. If a reliable conversion is unavailable, record the limitation rather than calculate a misleading ratio.
Shipment evidence also has a time dimension. A financing application can precede production; an invoice can precede departure; a payment can be an advance rather than settlement of delivered goods. Delayed shipping can reflect normal commercial conditions or a substantive concern. Compare the chronology with contractual milestones and customer explanations. A completed financing drawdown does not prove delivery, and a document stating shipment does not prove physical inspection by the bank. Each record contributes a different fact that should be attributed to its source.
A numerical example of what a variance actually shows
Suppose a fictional equipment importer requests financing for 120 units at 8,000 currency units each, giving an invoice total of 960,000. A benchmark extract shows 5,500 per unit. An analyst should first ask whether the benchmark refers to the same model, configuration, delivery period and included services. If the invoiced package includes installation, training and replacement parts worth a credibly evidenced 240,000, comparing the entire package with bare equipment can overstate the difference. The calculation is a way to organise evidence, not a tolerance threshold authorising an automatic report.
Now suppose the customer cannot explain 300,000 of the package and the supplier is controlled by a relative of the buyer's owner. That combination is more informative than the raw benchmark difference. Related-party trade can be legitimate, but it changes the independence of the price evidence and may justify additional corroboration. Review contracts, supplier capability, shipment records available to the bank, historic comparable purchases and the final payment route. If concern remains, the narrative should identify the unexplained component and relationship rather than claim that every invoiced unit was fictitious.
The bank should also separate credit protection from AML assurance. It may have enough collateral or a guarantor to recover a loan while still lacking a credible explanation for the trade. The reverse can occur when a transaction appears commercially genuine but the credit is poor. A credit approval is not a laundering clearance. The two teams can use shared invoice and ownership evidence while recording different questions, criteria and decisions. A financier's comfort that it will be repaid must not prevent assessment of suspicious origin or intended use.
Duplicate invoices, repeat financing and legitimate reuse of references
A repeated invoice number can be a warning but is not necessarily duplicate financing. Suppliers may restart numbering by branch or year; a credit note may refer to the original invoice; partial funding may legitimately use the same commercial reference. Matching should include issuer, buyer, issue date, currency, amount and the transaction's lifecycle. Normalise identifiers for detection while preserving originals for evidence. A false duplicate conclusion can disrupt a real supplier, while a weak matching scheme can allow the same receivable to be financed repeatedly.
In a hypothetical receivables programme, Bank A finances an invoice for 400,000 and later receives a second request for the same buyer obligation through another supplier entity. Shared ownership and identical document characteristics justify inquiry. The bank cannot automatically know whether Bank B also financed it. Customer declarations, programme controls and lawful third-party information can provide evidence, but public claims that a ledger prevents all duplicate finance should be challenged. A closed technical registry can show only records within its own participation and data coverage.
The control should follow repayments and invoice adjustments as well as origination. A supplier can finance a genuine invoice, receive a credit note reducing the receivable, and fail to disclose the change. A buyer can dispute goods while the financed balance remains unchanged. Reconciliation between invoice, adjustment, payment and funding outstanding is both credit and crime-control evidence. Define who supplies changes, who assesses them and how the programme handles a material discrepancy. Do not confuse a routine commercial dispute with proven fraud, but do not allow an unresolved change to disappear into a financing status field.
Supply-chain finance changes the evidence balance
A buyer-led payables-finance arrangement may provide evidence that the buyer approved an obligation. That approval is useful; it does not establish the supplier's lawful ownership, the origin of goods or the absence of collusion. Understand how suppliers are admitted, whether approval can be reversed, who authenticates payment instructions, and how financing proceeds reach the entitled party. An unexpected switch to a third-party beneficiary should be assessed against assignment, agency and contractual arrangements rather than dismissed because the buyer is a large reputable company.
Receivables purchase can expose the bank to the seller, debtor and the relevant commercial flow. A programme servicing many debtors needs risk segmentation that fits volume and available data. It may be reasonable to investigate a material concentration or outlier rather than require a complete physical-goods examination for every small invoice. But a volume-based model should still recognise structural changes: new countries, unrelated debtors, implausible turnover, recurring credit notes, unusual payment destinations or suppliers with common controllers. Programme visibility and escalation rights should be explained in the control design.
The voluntary ICC, Wolfsberg and BAFT principles include open-account techniques and bank-to-bank trade loans. Their value is showing that controls should fit the instrument and relationship. They do not turn a financing bank into a customs authority. Nor do they remove the bank's own applicable responsibilities simply because another party performs checks. Identify what diligence is done by the bank, what information it obtains from the customer or counterparty, and what it cannot corroborate. Those distinctions matter particularly where several financial institutions support the same economic transaction.
Goods, routes and parties raise separate legal questions
A goods description can be too broad for sanctions or export-control analysis. Words such as machinery or electronics may not identify a controlled item, while an apparently precise commodity code can be incorrect. Where goods risk is material, route the available description and technical evidence to competent specialists. A payment officer should not invent a classification from a vague invoice. A sanctions designation match, ownership/control connection, prohibited sector and controlled-goods issue can have different legal tests. Preserve the specific test and legal nexus rather than store a single generic trade-risk answer.
A transhipment hub can be commercially sensible because of freight networks, consolidation or storage. An unusual route becomes more concerning when contradicted by the customer's explanation, combined with opaque intermediaries, or associated with credible diversion information. Vessel names can change; persistent identifiers and effective dates are preferable where the bank holds them. Screening a shipping party at presentation does not necessarily establish that an earlier or later party was clear. Determine the relevant process stages and information updates required by applicable law and the product's risk model.
A guarantee can also be misused without visible goods. Unexplained amendments, a beneficiary switch, a sudden claim or repayment funded by unrelated parties can merit review. The contractual claim process and financial-crime inquiry should proceed under clearly assigned roles. Legal duties concerning an undertaking may constrain unilateral refusal; a sanctions prohibition may separately constrain payment. The bank needs timely specialist analysis rather than an improvised instruction to stop every unusual claim. This is a practical reason to maintain legal, trade and financial-crime escalation together.
Bank responsibility is evidence-specific
The FFIEC's US trade-finance examination material discusses customer understanding, transaction scrutiny and monitoring in this area. It is a US supervisory reference, not a globally applicable statute. FATF and Egmont's risk indicators are prompts for investigation rather than proof. A defensible bank model converts relevant indicators into product-specific questions, combines them with customer context and documents what evidence was available. It should be able to explain a legitimate closure as well as an escalation. Detection quality is weakened when every document inconsistency receives the same criminal label.
Official references for the distinctions in this deep dive: FFIEC trade-finance overview, FATF and Egmont TBML risk indicators, and ICC trade-finance principles.
Testing interconnected services
Test a corporate payment-on-behalf-of, intercompany loan, duplicate invoice, changed beneficiary, unusual goods route and delayed shipment. Verify that analysts see the relevant entity and transaction context rather than only the central treasury account.
Reconcile population coverage across cash-management, trade-finance and treasury systems. Products booked outside the main payment hub may be omitted from monitoring. Preserve original values and currencies when aggregation or conversion is used.
Control testing should identify the bank's actual visibility limitations. A lender may need additional evidence for financing risk, while a payment processor may have a narrower document set. Record limitations and escalation rather than inventing information the bank does not hold.
Treasury transactions need more than a large-value alert
Corporate treasury can transact substantial amounts without generating revenue of the same size. Rolling deposits, foreign-exchange hedges, internal funding and liquidity movements can be many times operating sales. A monitoring model should understand those activities separately. Comparing gross treasury turnover with last year's revenue can be a useful prompt only if the comparison has economic meaning. A group treasury centre can process affiliates' flows, refinance existing debt and roll a hedge without creating a new commercial sale. The analyst needs a product map before interpreting the numbers.
The treasury profile should identify who owns the exposure, who instructs the deal and who settles it. A central treasury entity may hedge a subsidiary's purchases under an agency or intercompany arrangement. The currency exposure can belong to the operating subsidiary while the bank's trading counterparty is treasury. Document how that relationship works and which information the bank holds. A payment from a different affiliate may be explained by group funding, but an unexplained unrelated payer is a distinct question. Do not force both through the same third-party-payment assumption.
FX example: four measures that should not be mixed
A fictional importer agrees to buy 900,000 units of foreign currency for a future supplier payment. The dealer record holds both currencies and the agreed exchange rate. The cash settlement record identifies amounts actually debited and credited. A collateral record may contain a much smaller margin amount. The supplier payment can occur later through another channel. These are four linked events, not four independent commercial purchases of 900,000. An investigation should reconstruct the sequence and use the amount relevant to each question.
If the importer closes and rebooks the hedge after an order change, gross dealing volume rises without necessarily increasing physical imports. The bank should review why the change occurred and how it affects settlement, not conclude that high volume alone proves circular laundering. Repeated unexplained cancellation, third-party settlement and movement into unrelated accounts can change the hypothesis. The case should explain which pattern departs from the customer's model. Preserve the original trade and its replacement linkage so the analyst can distinguish genuine amendment from multiple outstanding positions.
Hedging terminology must not become automatic reassurance. A customer may describe speculative activity as hedging, or finance a position using money inconsistent with its known business. Assess declared purpose against transaction characteristics and available evidence. The bank should not pretend it can verify every underlying customer contract if it does not receive them. It can establish whether the transaction is reasonably coherent with the represented exposure, evaluate material contradictions and seek additional evidence when risk justifies it. The legal perimeter and suitability obligations, where applicable, remain separate from AML analysis.
Settlement instructions are a critical evidence boundary
Standing settlement instructions reduce operational work but can become a fraud vector. The bank needs to know whose instructions they are, which product and counterparty they cover, who may amend them and when the change becomes effective. An instruction update supplied through a compromised mailbox should not be accepted merely because an earlier message used the same address. Verification should follow the bank's controls and use an appropriate trusted route. Keep original and amended values, approval evidence and the transaction population affected by the change.
An instruction can be valid for one legal entity without being valid for another group company. A treasury user can have dealing authority but no authority to change the beneficiary account. These entitlements should be represented separately. The customer-facing portal should not silently grant both privileges when adding a deal maker. Where a third-party settlement is proposed, determine the party's role and the bank's applicable product policy rather than invent a universal ban. A custodian, agent or contractual assignee may be legitimate; an unexplained personal account warrants a different assessment.
Settlement confidence also needs precise states. A deal agreed, confirmation matched, payment queued, account debited and funds received by a counterparty are different events. A message acknowledging acceptance of an instruction does not prove final receipt. A return, rejection or cancellation can change the cash outcome while leaving an important attempted transaction. Investigation systems should link every state transition and amount. Removing a failed transaction from financial-crime evidence because the final ledger has no debit can hide an attempted prohibited or suspicious movement.
Netting explains arithmetic, not legitimacy
Group netting can replace many bilateral intercompany obligations with fewer settlement payments. In a fictional netting cycle, Entity A owes B 120,000 and C 80,000, while C owes A 150,000. A's gross obligations are 200,000 but its net position is a 50,000 payment, assuming those are the only obligations and the arrangement permits that treatment. Reviewing the net debit alone cannot identify all commercial relationships. Reviewing the gross schedule as if every line were an external cash payment overstates account movement. The system should label obligations and cash settlement distinctly.
A netting file should retain participants, source obligations, original currencies, conversion methodology, valuation date and allocation results where captured. Independent validation of the arithmetic can identify errors; it does not verify that each invoice or obligation is genuine. A fictitious obligation can be mathematically netted perfectly. For material exceptions, ask who supplied and approved the obligation and what evidence supports it. The bank's role may be narrower than the group's internal netting administration, so requirements must identify which schedules the bank actually receives and what inquiries it can make.
An additional entity outside the represented group can materially change the arrangement. It may be a lawful commercial participant under the service's terms, or it may indicate undeclared payment intermediation. Review the contractual model and regulatory perimeter rather than rely solely on a matching corporate name. Customer ownership trees can be stale after acquisitions, disposals or restructurings. Store effective dates so an entity that left the group is not still automatically treated as an eligible affiliate. Historical participation should remain visible after removal.
Deposits, collateral and credit-linked cash
Corporate deposits can hold operating surplus, financing proceeds, sale proceeds or funds collected for others. Source-of-funds analysis should follow material risk and the represented purpose. A large deposit after a business sale can be legitimate; a contract and incoming credit may establish the immediate source without fully explaining historical wealth. A deposit-backed loan can similarly look low risk from a credit perspective while leaving questions about the deposit's origin or third-party ownership. Security coverage is not a substitute for understanding the money.
Collateral movements require their own data labels. Cash collateral, securities collateral, margin calls and collateral releases are not interchangeable. A return to an entitled counterparty can be routine, while a request to redirect released collateral to an unrelated account can create operational, fraud and AML questions. The legal and contractual entitlement needs to be checked by the relevant product and legal specialists. Monitoring should recognise the event and connected agreements rather than classify every collateral release as a new loan or a commercial refund.
Close-out and early termination can also concentrate value. The bank should understand how the amount was calculated and who is entitled to receive it. A transaction can be economically unusual because market conditions changed, because a customer restructures financing, or because a purported commercial purpose was false. Comparing a termination payment with original notional without examining terms and valuation can be misleading. Preserve the calculation source and any independent challenge applicable to the product; an analyst's suspicion assessment should distinguish valuation uncertainty from verified manipulation.
Cash collection and distribution have operational signatures
Cash-intensive corporates can use branch deposits, cash-in-transit providers, smart safes or central collection arrangements. Expected patterns depend on store count, opening days, seasonality and the settlement model. A retailer can have many small deposits and one large central credit without those being unrelated events. The bank should know whether a service-provider settlement represents aggregated store takings and whether store attribution is available. Reconcile the economic collection with book entries to avoid selecting the same cash repeatedly as unexplained layering.
A material change can be more useful than the baseline pattern. A retailer's cash grows while sales and store count fall; a depot outside the represented network begins depositing; refunds repeatedly go to an owner's personal account; or cash-in-transit reconciliations do not support the credit totals. Each change requires specific evidence. Cash itself is not proof of crime. Source-system documentation should explain adjustments, counting differences, shortages, timing lags and insurance recoveries so legitimate operational corrections do not automatically become suspicious additional receipts.
Designing a treasury investigation handoff
When an alert spans FX, cash management and trade finance, assign a person to reconstruct the economic sequence without taking over every specialist decision. The evidence package should include relevant entities and authority, deal and settlement identifiers, source obligations, original and changed instructions, actual cash movements, financing records and available commercial evidence. Separate direct bank facts from customer descriptions and external intelligence. The product specialist can explain a netting or collateral mechanism; the investigator should still assess whether the customer's explanation fits the observed facts.
A useful escalation states exactly what is unresolved. For example, a hedge fits expected currency exposure, but 70% of its funding came from an unrelated company that the customer cannot explain. That is stronger than saying the hedge is unusual. Likewise, a payment factory has valid group mandates, but two beneficiary changes were approved through an account subsequently confirmed compromised. That finding triggers a fraud response and potentially a proceeds investigation; it does not imply every transaction in the file is tainted. Granularity helps the bank act on affected flows while preserving legitimate business.
Quality review should check both false assurance and false accusation. Treasury status, strong collateral and a well-known buyer do not answer every source question. High notional, net settlement and many affiliates do not prove layering. Cases should show which evidence supports the relationship and purpose, where visibility stops, what contradictory facts remain and who owns the next action. A reviewer who cannot distinguish the customer obligation from the bank settlement should seek clarification before approving the narrative. The resulting decision should remain tied to applicable law and institution policy.
Worked treasury-centre case
A fictional treasury centre pays a supplier for an affiliate. The invoice names another group company, and the payment goes to a newly substituted account. Confirm the payment-on-behalf-of mandate, underlying commercial relationship and account-change authority. Consider fraud, sanctions and AML concerns separately.
Explain which discrepancy may be legitimate and which evidence is needed before the payment decision can be defended.
Case one: a pool participant becomes a collection business
The following cases are original fictional banking examples. Their names, amounts and service specifications are teaching assumptions. They do not establish legal thresholds or describe a real customer's conduct.
Opal Bank provides physical pooling to Cedar Foods Group. Four operating subsidiaries sell packaged food to commercial buyers, sweep daily surplus into a treasury account and obtain short-term funding from that account when needed. The onboarding evidence identifies the participants, group ownership, mandates, currencies and expected suppliers. Monitoring receives external receipts and payments as well as pool sweeps. After a small acquisition, a fifth participant is added with valid account-opening documents. Its technical onboarding succeeds and the sweeps reconcile.
Three months later, a review shows the new participant receiving payments from dozens of businesses not known as food buyers. Funds reach treasury overnight and are paid onward the following morning to multiple beneficiaries. The group explains that the acquired company supplies a collection service to independent franchise operators. That can be a legitimate business, but it differs from the represented operating model. The analyst should not stop at the new company's membership of the group. Ownership of the company does not establish ownership of every receipt it administers.
The relationship manager obtains the service contracts, participant details and an explanation of who is entitled to the funds. Product and legal specialists assess whether the existing service and customer perimeter permit this activity and which further requirements apply. Operations determines whether underlying franchise attribution is retained when receipts reach treasury. The investigation compares the collection-and-payout pattern with the contracts and identifies two beneficiaries absent from the customer-supplied distribution schedule. Those discrepancies warrant specific follow-up, without establishing that all franchise collections are illicit.
One explanation is a legitimate service expanded faster than the bank's profile update. Another is that the acquired company has taken on undeclared unrelated settlement activity. A third is that genuine collections are being diverted internally. The case should test those possibilities separately. Useful evidence includes contract dates, entitlement to balances, fee arrangements, payout instructions, the acquired company's operating staff and reconciliation of sampled receipts to distributions. Avoid demanding that every franchise prove itself directly to the bank if that is outside the relationship and legal model. Determine what risk-based evidence the bank needs and can lawfully obtain.
The immediate operating response depends on facts and applicable rights. The bank may need to pause adding more underlying users to the service, obtain additional information or apply agreed transaction review while the model is reassessed. A blanket freezing instruction would be inappropriate without the corresponding legal basis. If transactions meet a suspicious-reporting threshold, the designated reporting function decides under local law; that does not replace the product-perimeter decision. An accurately explained legitimate distribution should remain distinguishable from an unresolved payment in the same pool.
For technology acceptance, the bank seeds one external franchise receipt and follows it through the operating account, overnight sweep, central allocation and onward payment. The evidence must show one economic receipt and the relevant attribution at each step. A second test reassigns a virtual identifier after a franchise closes. Historical records must still identify the former user. A third introduces a new distribution beneficiary not authorised by the service contract and verifies the correct exception route. These tests evaluate the actual visibility defect rather than merely confirm that the pool total balances.
Case two: correct corporate authority, corrupted beneficiary information
Terra Components Group uses a treasury centre to pay suppliers for six manufacturing affiliates. An invoice identifies Affiliate West as buyer, while the treasury centre is the payment-account holder. That difference is expected under the documented payment-on-behalf-of arrangement. A supplier emails a notice saying its account has changed. An outsourced administrator updates the payment template and a genuine corporate approver releases a 620,000-unit transfer. Later the supplier says it has not received payment and its account details never changed.
The investigator first preserves the invoice, mandate, original supplier account, change notice, administrator actions, approval evidence, instruction and settlement records. The account-holder difference should not become the main suspicious feature merely because it is easy to see. The stronger question is how the new beneficiary was verified. If both the administrator and approver relied on the same compromised email, two approvals did not supply independent confirmation. Authentication records can show who used the channel or passed its checks without proving the commercial information was genuine.
Fraud operations pursues the recovery channels available for the rail and jurisdiction, recording amounts, times, responses and any remaining funds. The beneficiary institution may have different information about the receiving account, including prior reports and onward transfers. Lawful cooperation can connect the perspectives. The sending bank should preserve uncertainty about the receiver's role: criminal controller, recruited intermediary and account-takeover victim require different customer treatment. A fraud report is important evidence of criminal proceeds but does not automatically prove the receiving account holder's intent.
AML review runs alongside recovery where the evidence warrants it. The treasury centre may be the victim's legitimate payment administrator rather than a laundering participant. Its control weakness can still require remediation. The case should identify affected templates and transactions rather than assume the entire corporate population is compromised. A sanctions specialist separately assesses any relevant party or destination connection using applicable law. Neither a recovery request nor the fact that the group owes a real supplier debt authorises a prohibited payment.
A product remediation test creates two beneficiary-change requests. One is verified through a trusted independent route and supported by entitlement evidence; the other comes from a newly changed contact and has no independent confirmation. The workflow must distinguish them without requiring a universal value-based block. Another test gives an administrator permission to prepare files but not change settlement instructions. Attempted amendment should follow the configured authority controls. The final test checks that the bank retains the original beneficiary after repair and makes the fraud evidence available to authorised investigators.
Case three: a genuine trade document does not settle every question
A fictional polymer distributor, Marlin Materials, requests working-capital financing for an imported shipment. Its invoice states 240 tonnes of a specified resin grade at 1,250 units per tonne, giving a total of 300,000. A transport document reports 252 tonnes gross weight. An analyst initially flags the difference as overstatement. The customer produces packing information showing the extra weight consists of packaging and pallets. That resolves the specific weight comparison; it is evidence of a legitimate explanation, not a general clearance of the relationship.
A separate concern remains. The financing proceeds are requested to an intermediary rather than the invoicing supplier. The intermediary's contract says it arranges procurement and collects supplier payments. The bank tests the role, entitlement, ownership and route against the transaction. A valid agency explanation may resolve the beneficiary difference. If the intermediary has no credible function or the customer cannot explain why it receives all funds, that unresolved gap should be identified precisely. The bank should not recycle the corrected weight anomaly to make the case sound stronger.
Monitoring then finds a second financing request using the same supplier reference. It relates to a later partial shipment and a new invoice date. Operations checks outstanding funding, prior shipment allocations, credit notes and repayment. The reference alone does not establish duplicate financing. Suppose the customer instead supplies the identical invoice and cannot reconcile the full receivable with the existing loan. That supports a different concern requiring credit and AML escalation. The investigation should preserve both outcomes as part of the evidence: one apparent anomaly was resolved, another was not.
When repayment arrives from an unrelated company, establish whether it is a documented debtor, guarantor, assignee or other entitled party. A repayment can reduce credit exposure without explaining the payer or source. The bank needs to link it to the financed obligation and assess any contradiction with the customer's earlier account. Credit officers may be pleased the loan was repaid; investigators must still consider residual suspicious circumstances. A report, if required, should describe the available financial evidence without claiming the resin never existed merely because financing information was inconsistent.
The acceptance pack should include a legitimate gross-versus-net weight difference, a verified procurement-agent payment, a genuine partial-shipment reference reuse and a seeded unresolved duplicate financing request. The system should keep distinctions between documentary discrepancy, financing exposure and suspicious pattern. An automated model that escalates all four identically has not shown useful discrimination. Reviewers should inspect original evidence, the comparison basis and the reason for disposition rather than judge the control by alert count alone.
Case four: a net settlement hides a material participant change
A corporate treasury service submits a monthly netting schedule and one resulting settlement instruction. A new participant appears with a name resembling an existing subsidiary. Matching software joins it to that subsidiary despite a different registration identifier. The amounts balance and the instruction is signed by an authorised user. Technical reconciliation therefore succeeds while entity attribution is wrong. This illustrates why arithmetic and authority are necessary facts that cannot substitute for accurate identity.
The bank reviews the original participant record, source obligations and customer explanation. The new company may be an authorised affiliate after restructuring, or the similarity may conceal an unrelated party. Entity resolution should preserve the competing records until reliable evidence settles the match. If the payment has already occurred, retain the original decision data and investigate the affected flow; do not silently rewrite history to the corrected entity. Product owners determine whether the service can continue under existing controls, while reporting and legal specialists handle any separate obligations arising from the findings.
The senior escalation should quantify the affected scope: which cycles, participants, payments and funding positions used the wrong match; what evidence remains accessible; and what immediate safeguards are feasible. It should not say that every netting transaction is unsafe. A bounded remediation can require verified registration identifiers for material participant changes and review similar existing joins. Closure needs evidence that historic attribution was corrected where supportable and current flows now reach the right control population. A screenshot of the revised customer name alone does not demonstrate that repair.
Delivery and operating hand-offs
Capture legal entity, ordering party, ultimate commercial parties where available, account mandate, invoice references, goods context, financing and settlement identifiers. Avoid discarding underlying party information when the treasury centre is the technical sender.
Acceptance tests include missing affiliate identifiers, repaired messages, document changes, duplicate payments and prohibited counterparties. Operations need a clear route to product, fraud, sanctions, legal and reporting specialists without treating every exception as the same hold.
The control model is effective when it explains the economic transaction and preserves distinct operational and legal decisions.
Specify the service before specifying the control
A delivery team should begin with an agreed product map. List the account and treasury services offered, the trade instruments supported, the bank's role in each and the customer populations covered. Distinguish booked loans, account payments, trade undertakings, collections, FX deals and collateral movements. A contract type called corporate services can cover several very different workflows. If the project cannot explain which events produce actual cash movements and which produce obligations, it is not ready to specify reliable monitoring or investigation interfaces.
For each service, identify the decisive source records. Cash pools need participant and sweep records. Virtual accounts need allocation histories. Payment factories need underlying-party information actually supplied. Treasury deals need confirmations, settlement instructions and lifecycle links. Receivables finance needs obligations, adjustments and funding outstanding. Documentary transactions need the presentation and relevant examination record. The same bank account can support several services, so account identification alone cannot determine which business meaning an event has. Product codes and event types should be reliable enough to select the correct interpretation.
An evidence model should preserve relationships and states
Useful objects include the corporate customer, operating affiliate, authorised person, account, virtual identifier, pool, payment batch, individual instruction, commercial obligation, trade instrument, document, financing exposure, treasury deal and settlement event. The model should not force these into one record with an amount and description. An invoice can support more than one partial payment, a financing can cover several receivables, and one net settlement can discharge multiple obligations. Relationships need type, source, effective period and confidence, particularly when created through matching rather than explicit customer data.
Identifiers should connect systems without erasing originals. A channel batch identifier can group instructions but cannot replace each payment's reference. A trade reference may be reused for amendments; store version and amendment relationships. A supplier identifier created by the customer may not be unique across affiliates. A dealer trade identifier may change on rebooking. Document every transformation and retain source-system keys. A requirement saying all transactions must have a common identifier is incomplete unless it explains how the identifier is created, what it means and how exceptions are resolved.
Evidence states need careful design. A document received is not necessarily examined; examined is not necessarily accepted; accepted under instrument rules is not a financial-crime decision. A requested loan is not disbursed, and a disbursement is not a shipment confirmation. A payment acknowledgement is not final receipt. Event timestamps should distinguish business occurrence, bank receipt, processing and later correction where those differ. Investigators must be able to reconstruct what the control saw at decision time, even if current data is cleaner or more complete.
Population reconciliation is more than a payment total
Build a population reconciliation across source systems for an agreed period. Account credits and debits establish cash booking; trade and treasury systems establish exposures and events outside the ordinary payment population. Compare records, amounts where comparable, currencies, status and expected joins. Reconcile by product and legal entity rather than declare success from a group-level total. An omitted product can be hidden by duplicate entries elsewhere. A financial-crime system can balance in aggregate while missing every transaction from one small branch or one trade-finance booking channel.
Interpret exceptions economically. A treasury cancellation and replacement may change gross record counts without doubling outstanding exposure. An internal cash sweep can appear as a debit and credit but represent one value movement within the arrangement. A trade obligation can remain outstanding before any payment occurs. Set explicit reconciliation rules for each event type, supported by product specialists. Do not remove unusual records solely to force the total to match. Unexplained differences require ownership, investigation and a documented conclusion about control coverage.
A useful release test deliberately omits a financing channel with ten seeded disbursements while leaving core-account payments intact. The expected result is a visible population discrepancy and the correct owner being alerted, not a normal coverage report. Another test duplicates virtual-account allocations and confirms that the economic amount is counted once. A third delays a participant update and checks whether the affected transaction receives a transparent exception rather than a silently accepted join. These are original acceptance examples; their counts are not statutory requirements.
Route exceptions to the person who can decide them
Operations should have distinct paths for a missing party identifier, a documentary discrepancy, a beneficiary-change concern, a potential legal restriction and suspicious financial behaviour. An incident can need more than one path. For example, an incomplete payment may require operational repair while the proposed beneficiary also needs sanctions analysis. Resolving the formatting error must not close the sanctions referral automatically. Conversely, a cleared name match should not erase an independent question about unexplained funding. Each outcome needs an owner, evidence, date and applicable basis.
Authority should follow the decision being made. A trade officer can process contractual documentary decisions within delegated authority. A payments operator can repair an instruction within controlled permissions. Fraud specialists can pursue recovery and protective steps available under the relevant framework. Sanctions and legal specialists determine restrictions and permissions in their remit. The designated AML reporting function decides external reporting under local law. A customer relationship manager supplies context and coordinates communication but should not resolve a protected reporting decision merely because the client is commercially important.
Customer communication should explain operational status accurately while respecting applicable confidentiality. A customer may need to provide an invoice or verify changed settlement details. That request is different from disclosing a SAR/STR or protected intelligence. Record which information can be used in outreach and which requires restricted handling. Do not create a blanket global prohibition on customer questions when the law does not require it, and do not put protected reporting status into unrestricted service notes. The applicable jurisdiction and source restrictions determine the boundary.
Observe control behaviour through meaningful acceptance tests
For payment-on-behalf-of, submit a valid instruction containing a treasury sender and a different documented underlying buyer. The case view should retain both roles and avoid automatically classifying the difference as illicit. Then submit an instruction whose purported affiliate is absent from the authorised service population and confirm the appropriate exception. For pooling, add a legitimate acquired subsidiary with complete evidence, and separately seed an unrelated participant with no explained role. The test should show how authority, identity and service eligibility are evaluated, not simply whether the system can add an account.
For trade pricing, use two invoices with identical totals but different units and included services. A comparison should either normalise them using supported assumptions or identify that they are not comparable. For financing, seed a genuine credit note, a partial shipment and an unresolved duplicate receivable. Verify that the system links adjustments to outstanding funding and retains the original obligation. For treasury, cancel and rebook a hedge, change settlement instructions and return a failed payment. Investigators must be able to reconstruct the economic sequence without multiplying cash values or losing the attempted movement.
Failure tests should target the service's real dependencies. Interrupt the virtual-account mapping feed, deliver a trade amendment after the related payment, remove a supplier identifier and make a treasury confirmation unavailable. Define what operators see, which transactions remain covered, whether manual evidence is possible and who authorises continued service under policy. A degraded mode should be understood and evidenced. A dashboard that silently substitutes an empty field and continues to show complete control coverage is an assurance failure even if the application remains technically available.
Assurance and senior decisions should focus on the product exposure
Independent review should sample linked chains, not only isolated alerts. Select a pool receipt through distribution, a financed invoice through adjustment and repayment, and a treasury deal through settlement and return. Check whether source records agree with the investigation view and whether legitimate explanations were tested. Challenge claims of shipment authenticity, supplier independence or final settlement when the evidence establishes less. Also challenge under-escalation where credit repayment or documentary acceptance was treated as sufficient reassurance. Both directions matter for banking quality.
Senior management should receive specific information about unresolved service exposure. Report omitted participants, missing underlying-party attribution, unexplained financing reconciliation, ageing settlement-change exceptions and material failures of document or deal linkage. Explain affected volumes and evidence limits using comparable measures. A high number of alerts cannot demonstrate effective trade scrutiny, and a low fraud-loss figure cannot prove treasury source-of-funds controls work. The decision should state whether the affected product or population can operate with current safeguards, what remediation is required and what evidence will establish closure.
Closure should be tested against the original defect. If virtual attribution disappeared, demonstrate historical reconstruction where supportable and current end-to-end preservation. If invoice adjustments failed to reach funding systems, replay representative changes and reconcile exposures. If authority permitted an administrator to change settlement details improperly, verify corrected entitlements and affected historic actions. A policy revision alone is insufficient for a broken data path. The release-ready outcome is a service whose money, obligations, parties and decisions can be explained reliably, with its genuine limitations visible to the people responsible for them.
References and further reading
Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.
-
FATF Recommendations, updated June 2026 — relevant anchors: 10, 16 and 20.
-
FATF/Egmont trade-based money laundering risk indicators, March 2021. Non-exhaustive indicators require product and customer context; an indicator is not proof of crime.
-
Wolfsberg Group, ICC and BAFT Trade Finance Principles. Voluntary industry principles on controls, escalation and role-specific limitations; not a universal statute.
-
FFIEC BSA/AML Manual: Trade Finance Activities. US examination context and product-role distinctions; national requirements remain separate.
-
FATF Recommendation 16 draft-guidance consultation, June 2026. Consultation closed 21 August 2026. Guidance remains draft on this page; adopted June 2025 standard changes have end-2030 implementation readiness, not a new immediate global bank deadline.