Criminal Proceeds and Predicate Offences

Money laundering starts with value that has a criminal connection. That sounds obvious, but it is one of the most important ideas in financial-crime work because a bank rarely sees the whole crime. It sees pieces of the financial story: a credit from a victim, an invoice that does not fit the customer's business, a cash deposit, a new beneficiary, an opaque company, a sudden change in payment behaviour, a property purchase, a virtual-asset exchange or a network of accounts moving money between themselves.

The crime that generates or gives rise to the value is commonly called the predicate offence. Fraud can create stolen funds. Bribery can create secret commissions or kickbacks. Drug trafficking can generate cash and account balances. Criminal tax evasion can leave value that should not lawfully have been retained. Human trafficking, environmental crime, cybercrime, theft, smuggling, market abuse and organised crime can all create economic value that may later be moved, converted, concealed, spent or invested.

For a bank, the key challenge is not to become a police force or a court. The bank normally does not have all the witness evidence, search powers, forensic access or criminal-procedure tools needed to prove the underlying offence. Its task is to understand the financial activity it can see, connect that activity to customer and counterparty context, assess whether a reasonable financial-crime concern or suspicion exists under the applicable framework, and take the action required by law and policy.

That distinction should remain visible throughout the chapter. A red flag is not proof. An alert is not suspicion. Suspicion is not a conviction. A suspicious activity report is not a finding of guilt. A customer explanation is not automatically evidence merely because it sounds plausible. Good AML work is strong precisely because it is careful about what is known, what is inferred and what remains uncertain.

Lifecycle showing how suspected underlying criminal conduct can create proceeds, how value may change form, what a bank observes and how an AML decision is reached.

The simplest mental model: offence, value, movement, evidence, decision

The most useful way to think about predicate offences is as a chain. Some underlying conduct produces, obtains, retains or controls economic value. That value may become proceeds of crime under the applicable law. The value can then move or change form. As it touches bank products and payment channels it leaves evidence. The bank uses that evidence to reach a proportionate decision.

The first link is the underlying conduct. It can happen completely outside the bank. A victim may be deceived on a social-media platform. A procurement official may receive a benefit through an intermediary. Illegal mining may occur in a remote region. A ransomware operator may compromise an organisation. A tax offence may depend on declarations and records the bank never sees. This is why transaction data alone often cannot identify the exact crime.

The second link is the value. FATF uses a broad concept of property and proceeds. The practical point for a banker is that criminal value is not limited to cash. It can be represented by balances, securities, real estate, vehicles, commodities, receivables, virtual assets, company shares or other economic benefits. It can be received directly from the offence or derived indirectly after the original proceeds have been exchanged, invested or transformed.

The third link is movement or transformation. Funds can be split, converted, transferred, commingled with legitimate revenue, placed into a company, invested, used to buy assets, repaid as an apparent loan or moved through several institutions. A change in form does not automatically remove the relevance of provenance. At the same time, the legal treatment of transformed or mixed property is jurisdiction-specific, so an investigator should preserve the facts rather than invent a universal legal formula.

The fourth link is evidence. A bank can observe account entries, payment messages, customers, beneficial owners, devices, counterparties, documents, cards, merchants, trade activity, investments and case history. Each item has a source and an evidential weight. A transaction record is not the same as a customer statement. A verified registry record is not the same as an unverified internet claim. A fraud referral is not the same as a transaction-monitoring score.

The fifth link is the decision. The bank may close an alert, seek more information, increase monitoring, refer a case, file a suspicious activity or transaction report, restrict a product or relationship where policy and law permit, or take another legally required action. Different actions can have different legal bases. AML suspicion alone should not be treated as a universal power to freeze funds.

What “proceeds” means for a bank investigator

A direct proceeds example is easy to understand. A victim is deceived into sending EUR 15,000 to an account controlled by a fraud network. If the receiving bank has reliable victim-linked intelligence, the incoming credit can be examined as possible direct fraud proceeds.

Indirect proceeds are more difficult. Suppose the recipient sends the money to a virtual-asset service provider, exchanges it, later converts it back into fiat and transfers it to another bank. The second bank may never see the original victim payment. It sees value that has passed through another form and another institution.

Property creates a similar problem. Criminal value may be used to buy an asset, the asset may be held for years, and the eventual sale proceeds may arrive from a reputable lawyer or conveyancer. The immediate payer can look entirely legitimate. The financial-crime question is broader: what is the economic lineage of the value and is the customer's overall explanation credible?

Commingling makes the analysis harder still. A business can earn genuine revenue and also receive criminal proceeds. A restaurant can have real customers and still be used to introduce illicit cash. A consultancy can perform legitimate assignments while receiving one corrupt payment. An online seller can make normal sales while selected transactions are linked to fraud. An investigator should avoid the simplistic conclusion that the entire account is either clean or criminal.

The bank's practical task is therefore to identify the value and relationships that create concern, preserve the evidence trail and apply the relevant legal and policy framework. Where the treatment of mixed property matters to a legal decision, specialist legal interpretation may be required.

Predicate offence is a legal concept, not an AML dropdown

FATF Recommendation 3 sets the international architecture for criminalising money laundering. It expects countries to apply money-laundering offences to all serious offences with a view to covering the widest range of predicate offences, and it identifies designated categories that national frameworks should cover. Countries implement this architecture through their own criminal law.

That distinction matters in a global bank. A group-wide taxonomy can use categories such as fraud, corruption, tax crime, trafficking, environmental crime or cybercrime to support analytics, training and management information. But a group taxonomy is not itself the legal definition of a predicate offence in every country.

One jurisdiction may use an all-crimes approach. Another may use a seriousness threshold, a list of qualifying offences or a combination of approaches. The elements of the money-laundering offence, reporting threshold, treatment of self-laundering, cross-border conduct and evidential rules can differ. The same bank therefore needs common control principles alongside local legal mapping.

A case-management system should reflect this uncertainty. It is useful to record a suspected predicate-offence category and the evidence supporting the hypothesis. It is usually unsafe to force the investigator to declare that a specific underlying crime has been proven when the bank only has financial indicators.

Topic map of major predicate-offence families that may generate criminal proceeds, with a jurisdiction filter because domestic law defines the actual offences.

Major predicate-offence families and how their financial traces differ

Predicate offences are not operationally identical. The type of underlying conduct influences what data is likely to matter.

Fraud proceeds often move quickly. A victim may send an instant payment, card transfer or other electronic payment to a mule account. The receiving account may then pass funds onward within minutes, withdraw cash, buy virtual assets or distribute value to several beneficiaries. Fraud referrals, beneficiary intelligence, device data and shared downstream counterparties can become especially important.

Corruption can look slower and more commercial. Payments may be described as consultancy fees, success fees, sponsorships, commissions or subcontractor charges. The useful evidence may sit in beneficial ownership, PEP relationships, procurement timing, contract purpose and the economic role of intermediaries. A PEP connection is a risk factor, not proof of bribery.

Tax crime requires careful language. Lawful tax planning, civil disputes, administrative errors and criminal tax evasion are not the same thing. Offshore structures can be legitimate. A bank should focus on indicators such as deliberate concealment, false documentation, sham transactions, inconsistent economic purpose or relevant official intelligence, always within the applicable legal framework.

Human trafficking and exploitation can produce patterns that are subtle rather than spectacular. Multiple accounts may share contact data, wages may be rapidly transferred to a controller, cash patterns may be unusual, or business activity may not fit the stated purpose. Some account holders may themselves be victims. Customer-protection and safeguarding considerations can be as important as financial-crime escalation.

Environmental crime can hide inside otherwise legitimate commodity and trade flows. Illegal logging, mining, waste trafficking, wildlife crime or illegal fishing may involve companies that appear to trade in genuine goods. Ownership opacity, route anomalies, documentation, pricing, permits and reliable external intelligence may be more useful than a simple payment keyword.

Cybercrime can generate proceeds at digital speed. Business email compromise, account takeover, malware, ransomware and investment scams can create bank and virtual-asset flows across several institutions. The financial institution may see only one part of the chain, which makes lawful information sharing and fraud-to-AML handoffs important.

Organised criminal networks can combine several offence types. A network may be involved in fraud, narcotics, extortion, illicit trade and professional laundering simultaneously. A bank therefore should not assume that one customer, one alert or one typology maps neatly to one underlying crime.

Why banks often see the proceeds before they understand the offence

The financial system is frequently downstream from the harm.

Consider an authorised push-payment scam. The victim bank can see the payer's authentication and payment instruction. The receiving bank can see the beneficiary account. A third bank may see the onward transfer. If each institution looks only at its own event, no one institution has the complete picture.

The receiving bank may nevertheless hold valuable intelligence. It can see whether multiple unrelated senders pay the same customer, whether value leaves rapidly, whether beneficiaries are shared with other suspicious accounts, whether a dormant account suddenly changes behaviour or whether fraud referrals have already identified some incoming credits.

The same asymmetry exists in corruption. The bank may see an advisory payment but not the private agreement behind it. In environmental crime, the bank may see trade payments but not illegal extraction. In tax crime, it may see offshore transfers but not the customer's filings. In ransomware, it may see a virtual-asset exchange but not the intrusion.

Good investigations do not fill those gaps with confident storytelling. They document the gaps and ask what additional evidence can reasonably be obtained.

Facts, indicators, hypotheses and conclusions

A reliable AML investigation separates four layers.

Facts are directly supported by reliable records. An account received eleven credits. A customer was onboarded as a student. A company was incorporated on a specific date. A payment was sent to a named beneficiary. A device change occurred.

Indicators are facts interpreted as potentially relevant to risk. Rapid pass-through activity, an unexpected geography, a new beneficiary or a sudden turnover increase may be indicators. They still require context.

Hypotheses are possible explanations. The account may be receiving fraud proceeds. The customer may have started a legitimate new business. The company may be acting as an undisclosed payment intermediary. A payment may be linked to corruption. Each hypothesis should be testable against evidence.

Conclusions are the decisions reached after the evidence and alternatives have been assessed. The case may be reasonably explained, may need additional due diligence, may remain suspicious, or may require a particular report or control action under the applicable framework.

This structure prevents circular reasoning. “The customer is laundering because the payments are layering” is not analysis. A better statement explains the exact payments, timing, counterparties, customer profile and unresolved explanation.

Decision model separating facts, risk indicators, hypotheses and bank decisions so that an indicator does not become an accusation.

Customer understanding provides the baseline

Predicate-offence investigations become much harder when KYC and KYB data is vague.

For an individual, useful context can include occupation, expected income, residence, products, countries, typical counterparties and source-of-funds or source-of-wealth information where required by risk. For a business, the bank needs to understand what the company does, who owns and controls it, who its customers and suppliers are, what products it uses, where it operates and what payment patterns are expected.

The point is not to predict every transaction. The baseline allows the bank to recognise meaningful change. A student's account suddenly receiving dozens of unrelated credits presents a different question from a payment processor receiving similar volumes. A commodity trader making cross-border supplier payments is different from a local professional-services company doing the same thing.

Event-driven review is important when facts change. Ownership, directors, business activity, geography, expected turnover or counterparties can all change the risk picture. The historical state should remain reconstructable because an investigator reviewing an old transaction needs to know what the bank understood at that time.

Beneficial ownership and network context

Criminal proceeds often move through entities that are legally separate but economically connected.

A company may receive funds, another company may hold an asset, and a natural person may ultimately control both. Nominees, trusts, family relationships and corporate-service providers can add layers. These structures are not inherently criminal, but they make accurate ownership and control data important.

Network analytics can reveal shared beneficiaries, directors, addresses, devices, phone numbers or transaction paths. The strength of a link matters. A verified common beneficial owner is stronger evidence than two companies using the same registered-office provider. A shared device can be meaningful, but families and assisted customers can legitimately share devices.

The system should therefore preserve the source and confidence of relationships. Investigators should be able to see why two customers were linked rather than receiving a black-box statement that they are “connected.”

Following value across products and systems

Criminal value can move through a bank in ways that cross organisational boundaries.

A retail payment may become an FX conversion. Funds may move from a current account to securities, then to a custody account, then to a property payment. Trade finance can introduce invoices and shipping documents. Cards and wallets can create merchant or device data. Virtual-asset relationships can introduce exchanges, brokers or wallet information where lawfully available.

The investigator should be able to follow that movement through stable identifiers. Customer, account, payment, trade, security, case and counterparty data should not become disconnected because different platforms use different keys.

Data lineage is also about transformation. If a payment message contains structured party data but a monitoring engine receives a normalised string, the bank should be able to understand the transformation. If an ETL process aggregates transactions for a monitoring scenario, the alert should be traceable back to source records.

Without lineage, a bank may know that a control fired without being able to prove what data produced the result.

Evidence lineage connecting a proceeds hypothesis to source customer, ownership, account, payment, channel and document records, external intelligence, case reconstruction and the final decision.

Monitoring should detect financial behaviour, not pretend to identify crimes

Transaction monitoring usually does not detect a predicate offence directly. It detects behaviour that may be associated with suspicious movement of value.

A rapid-pass-through scenario can identify funds entering and leaving within a short period. It does not prove fraud. A cash scenario can identify unusual deposits or structuring-like behaviour. It does not prove drug trafficking or tax evasion. A peer-group model can identify a customer behaving differently from similar customers. It does not prove criminality.

Scenario documentation should therefore state the risk hypothesis rather than claim a legal conclusion. It should explain which customer segments are in scope, which data elements are used, what patterns are being sought, what legitimate lookalikes are expected and what the alert gives an investigator.

Testing needs both suspicious and legitimate examples. A mule-account scenario should be tested against marketplace sellers, family transfers and other lawful high-velocity behaviour. A corruption-risk scenario should include legitimate consultants. A trade-related scenario should include complex but genuine supply chains.

A rule that fires exactly as coded can still be a poor control if the data is incomplete, the segmentation is wrong or the business explanation is ignored.

Fraud-to-AML handoffs

Fraud and AML often meet at the proceeds.

Fraud operations may identify a victim payment and try to stop or recover funds. AML investigators may need to examine the receiving account, linked customers and historical flows. Customer-risk teams may need to reassess the relationship. These are connected tasks, but the legal and operational outcomes remain distinct.

A useful handoff contains more than the word “fraud.” It should identify the transaction, victim-linked intelligence where it can lawfully be shared, relevant account and beneficiary data, timing, recovery status and any known network links. The receiving AML team should be able to trace the referral to evidence.

A mature bank also feeds AML findings back to fraud prevention. If several mule accounts share a beneficiary, device or onboarding pattern, that intelligence can improve front-end controls.

Customer explanations and corroboration

Contacting a customer can resolve genuine anomalies, but explanation and evidence are different things.

If a customer says multiple credits are repayments from friends, the bank can compare the explanation with payment descriptions, counterparties, history and amounts. If a company says a large credit came from selling a business, corporate records, contracts or other independent evidence may be relevant according to risk.

The bank should not demand unnecessary evidence for every anomaly. Proportionality matters. But material explanations should be corroborated when the decision depends on them.

Customer contact also needs legal and operational guardrails. Tipping-off, confidentiality and law-enforcement considerations differ by jurisdiction. Analysts should not improvise sensitive disclosures. Approved scripts, escalation routes and legal guidance help protect both the investigation and the customer.

When the exact predicate offence is unknown

It is common for a bank to suspect criminal proceeds without knowing whether the original crime was fraud, corruption, tax crime or something else.

That uncertainty should not be hidden. The investigator can describe the financial pattern precisely even when the predicate-offence category remains broad. The narrative can identify unexplained funds, rapid movement, ownership concerns, linked counterparties, failed explanations and relevant external intelligence.

FATF's framework recognises that money-laundering enforcement should not depend on first obtaining a separate conviction for the underlying predicate offence. Domestic criminal-law and suspicious-reporting tests still vary, so the bank should apply its local threshold rather than convert this international principle into one universal operational rule.

“Unknown predicate offence” should never mean “unknown activity.” The financial intelligence can still be useful to an FIU or competent authority because it explains who moved value, when, through which accounts, with which counterparties and why the activity raised concern.

Reporting and control actions must be separated

One case can lead to several actions, but each action needs its own legal or policy basis.

A suspicious-activity or suspicious-transaction report may be required when the local reporting threshold is met. A fraud process may attempt a recall or recovery. A sanctions issue may create a separate blocking, rejection, freezing or notification obligation under an applicable sanctions regime. A court or authority order can impose another requirement. The relationship team may also consider monitoring, restriction or exit under governance and risk-appetite rules.

These decisions should not be collapsed into one status such as case = suspicious. Doing so creates serious operational risk. A bank may file a report and still have no legal basis to freeze funds. Another case may involve an immediate legal restriction even before a full AML investigation is complete.

Case architecture should therefore retain action type, legal basis, owner, decision time, effective date, approvals and evidence.

A realistic composite case: from victim credits to a network hypothesis

Consider a fictional retail customer who has held an account for eighteen months. Historical activity consists mainly of salary, rent, household payments and modest card spending.

Over one weekend the account receives nine instant payments from unrelated people. The total is far above the customer's normal monthly turnover. Most of the money leaves within two hours to two newly added beneficiaries, and a smaller amount is withdrawn in cash. A new device was registered the day before the first unusual credit.

A fraud team then receives a notice from another bank confirming that one of the incoming payments is associated with a scam complaint. That fact materially changes the case, but it does not prove that all nine payments are fraud proceeds.

The AML investigator reconstructs the chronology. The other senders are new counterparties. The customer has no known business activity. One outbound beneficiary receives payments from four other bank customers that have generated fraud referrals. Two of those customers share a device identifier.

The investigator now has several independent evidence types: customer-profile mismatch, rapid pass-through, known victim-linked funds, shared beneficiaries and a device relationship. The strongest hypothesis is that the account is being used in a mule network.

The investigator should still avoid overclaiming. The account holder may be knowingly involved, may have surrendered control of the account or may have been deceived. The bank can form a financial-crime conclusion about suspicious handling of funds without determining the customer's criminal intent beyond what the evidence supports.

The case can then follow the bank's local reporting, fraud-recovery, customer-risk and account-control processes. Those paths may run in parallel, but each has its own legal and governance basis.

A second composite case: corruption risk behind a commercial label

A long-standing engineering company wins a public infrastructure contract. Three weeks later it begins paying an overseas consultancy described as providing “market-entry advice.”

The consultancy was formed recently, has two employees and is beneficially owned by a close associate of a public official connected to the contracting authority. The payments are calculated as a percentage of project milestones. The company provides a short consultancy agreement but little evidence of deliverables.

None of these facts alone proves bribery. The investigator should test the commercial explanation: what service was required, why this adviser was selected, whether the fee is proportionate, whether similar advisers were used before, who controls the consultancy and what happens to the funds after receipt.

Suppose part of the money then moves to a property company controlled by a relative of the official. The corruption hypothesis becomes stronger because timing, ownership, economics and flow of funds point in the same direction. The case still needs careful language. The bank can document unresolved corruption risk and suspicious activity without asserting a criminal conviction.

Operational impact and customer fairness

Financial-crime controls protect customers and the financial system, but poor controls can also harm legitimate people.

An innocent customer can experience a payment delay, repeated requests for information, product restriction or relationship exit. A vulnerable person can be mistaken for a willing mule. A legitimate cash business can generate repeated alerts. A multinational company's treasury activity can look unusual if the KYC profile does not describe it properly.

This is why proportionality and evidence quality matter. Investigators should use information the bank already holds before repeatedly asking for the same documents. False positives should be closed with reasons that can improve future rules. Restrictions should follow the correct legal and governance process rather than being used as an automatic response to every alert.

Good financial-crime effectiveness is not measured by the number of customers blocked. It is measured by whether meaningful risk is identified and handled accurately, lawfully and sustainably.

Roles and governance

Predicate-offence risk crosses organisational boundaries.

Relationship and operations teams understand customer activity and product behaviour. Fraud teams can provide victim and scam intelligence. AML teams investigate suspicious movement of value. Sanctions teams apply separate sanctions rules. Trade specialists understand documents, goods and logistics. Legal teams advise on jurisdiction-specific obligations. Data and technology teams maintain the systems and lineage. Internal audit provides independent assurance.

Governance needs clear ownership when these functions meet. A fraud-mule case can involve customer protection, recall, AML investigation, suspicious reporting, account restriction and linked-account analysis at the same time. If every team assumes another team owns the decision, risk sits in the gaps.

Management information should therefore show more than alert volumes. Useful measures include major predicate-risk themes, source channels, fraud referrals, linked-account cases, case age, reporting outcomes, QA findings, data gaps and control coverage.

What business analysts and architects should design for

A requirement such as “detect predicate offences” is not implementable. A BA should translate the risk into observable behaviour and evidence.

The requirement should explain the risk hypothesis, in-scope customers and products, source data, timing, transformations, missing-data behaviour, detection logic, investigator context, decision outcomes and audit trail. It should identify what the bank can genuinely know and what remains inference.

Architects should preserve stable identifiers across customer, account, transaction, counterparty, device, document and case domains. Original data and transformed data should both be traceable where relevant. Effective dates matter for ownership and customer state.

Case-management systems should support uncertainty. A typology tag such as “possible fraud proceeds” should not automatically become a final legal conclusion. The system should separately capture evidence, hypothesis, disposition, report, restriction and approval data.

Access controls are equally important. Sensitive reports and law-enforcement information should be available only to authorised roles. Audit logs should show who viewed, changed and approved key decisions.

Testing and quality assurance

Testing should prove the control works end to end.

For detection, testers should verify data completeness, joins, currencies, timestamps, duplicates, thresholds, segmentation and event ordering. Positive test cases should represent the intended risk pattern. Negative cases should represent legitimate activity that looks similar.

For investigations, testing should cover assignment, evidence retrieval, linked-party views, notes, approvals, customer-contact restrictions, report creation, confidentiality controls and audit history.

Data-quality failure modes should be tested deliberately. What happens if one payment channel stops feeding the monitoring engine? What happens if beneficial ownership is stale? What happens if a device identifier is absent? A control should not silently appear healthy when its input has disappeared.

Quality assurance should review reasoning as well as workflow completion. The analyst should distinguish facts from inference, consider plausible alternative explanations, cite important evidence and avoid unsupported accusations.

Investigation decision flow

A practical investigation can be organised as a disciplined sequence.

Start with the trigger and verify it. Scope the customer, accounts, transactions and relationships involved. Establish the customer baseline. Build a chronology of value movement. Add ownership, counterparties, devices, documents and relevant external intelligence. State the risk hypothesis. Test legitimate explanations. Identify missing evidence. Apply the jurisdiction-specific suspicion and reporting threshold. Separately determine whether any other legal or policy basis exists for restriction, freezing, exit or information sharing.

The sequence is not perfectly linear. New evidence can send the investigator back to earlier steps. The purpose of the model is not bureaucracy; it is to prevent an initial alert from becoming the conclusion before the evidence has been examined.

Investigation flow from trigger and fact scoping through evidence, alternative explanations, legal tests and proportionate bank outcomes.

What strong case writing looks like

Weak case writing says: “Customer appears to be laundering money.”

Strong case writing explains the evidence: “Between 4 and 6 September the account received eleven credits from unrelated individuals totalling EUR X. Nine senders were new counterparties. Within six hours, 88% of the value was transferred to two beneficiaries not previously used by the customer. One incoming payment was identified by the sending institution as associated with a scam complaint. The pattern is inconsistent with the customer's historical salary-and-household profile, and the customer did not provide evidence supporting the stated explanation of personal loans.”

The second version is useful even if the exact predicate offence is not proven. Another analyst, QA reviewer, auditor or authority can see what happened and why it mattered.

Good writing is also fair. It attributes information to its source, distinguishes confirmed facts from allegations and records uncertainty. “Reliable fraud referral identifies payment X as victim-linked” is different from “all incoming funds are scam proceeds.” “Beneficial owner is a relative of official Y” is different from “the owner received a bribe.”

Final perspective

Predicate offences explain where criminal value comes from. Proceeds analysis explains how that value can appear, move and change form. The bank joins the two through evidence rather than assumption.

The strongest AML operating model therefore connects customer understanding, beneficial ownership, transactions, fraud intelligence, monitoring, network analysis, case evidence and local legal interpretation. It preserves data lineage and effective dates. It gives investigators enough context to test alternative explanations. It keeps reporting, sanctions, fraud recovery and customer restrictions as distinct decisions even when they arise from the same case.

The most important habit is simple: be precise about what is known, explicit about what is inferred, and disciplined about the legal threshold for the action being taken.

Deep practitioner expansion: following criminal value from offence to financial evidence

A bank investigator usually starts in the middle of the story. The original crime may have happened somewhere else, to another person, through another institution or in a non-financial setting. What reaches the bank is a financial consequence: money arriving, money leaving, an account being opened, an entity being used, an asset being purchased, a trade payment being made or a relationship between customers becoming visible.

That is why understanding predicate offences matters. The investigator is not expected to prosecute the offence, but the nature of the possible underlying crime changes what financial traces are likely to exist, which red flags matter, what supporting evidence is useful and which external intelligence could change the assessment.

A fraud network and a corruption scheme may both produce money laundering, but their banking footprints can be very different. Scam proceeds may arrive from many unrelated retail victims and move rapidly through mule accounts. Corruption proceeds may be disguised inside plausible commercial invoices, consultancy payments or ownership structures. Environmental crime may appear through commodity trade, logistics companies and cross-border corporate payments. Cybercrime may generate proceeds that move quickly into virtual assets. Human trafficking may create repeated low-value payment patterns, cash usage and network relationships rather than one dramatic transaction.

The common thread is that value has a criminal connection and the financial system can create evidence as that value is received, moved, converted, stored or spent.

Predicate offence does not mean the bank must prove the offence

One of the most important practical distinctions is between criminal proof and bank suspicion.

A court may need evidence sufficient to prove an offence to the criminal standard applicable in that jurisdiction. A bank’s suspicious-reporting obligation normally operates at a different threshold. The precise statutory wording differs by country, but a financial institution generally does not need to establish beyond doubt which predicate offence occurred before it can recognise and report suspicious activity.

This matters because bank analysts often feel pressure to name the crime. That pressure can lead to weak reasoning. If the facts support the conclusion that activity is inconsistent, unexplained and potentially linked to criminal proceeds, the analyst should document those facts clearly. It is better to write that the customer received multiple payments from unrelated individuals, moved most funds within minutes and provided an explanation inconsistent with account history than to assert that the customer is laundering scam proceeds without evidence supporting that specific offence.

The bank’s job is to preserve and explain the financial facts it can observe.

Facts, indicators, hypotheses and conclusions

A strong investigation separates four layers.

Facts are objectively supported. The account received twelve credits. The customer was onboarded as a student. Three devices accessed the account. Funds were sent to two virtual-asset service providers. The company was incorporated six weeks earlier.

Indicators are risk-relevant patterns. Rapid pass-through, unexplained third-party funding, sudden changes in behaviour, complex ownership and inconsistent payment purposes are indicators.

Hypotheses are possible explanations. The account may be acting as a mule. The company may be an undisclosed payment intermediary. The transactions may reflect legitimate marketplace activity. The payments may be linked to fraud proceeds.

Conclusions are the decisions reached after evidence is assessed. The activity is reasonably explained; additional due diligence is required; suspicion remains; the relationship exceeds risk appetite; reporting is required under the applicable framework.

Keeping those layers separate improves both case quality and regulatory defensibility.

Fraud proceeds: from victim payment to laundering network

Fraud is a major source of illicit proceeds because digital banking allows money to move quickly. The receiving side of fraud is particularly important for AML.

Imagine ten victims across three banks are manipulated into sending instant payments. Each victim bank sees one customer being scammed. The receiving bank may see all ten payments arriving at two mule accounts. Those accounts then split the money across several beneficiaries, withdraw part in cash and send part to a virtual-asset exchange.

The receiving bank therefore has a different intelligence position. It can see aggregation, common beneficiaries and repeat behaviour that the sending banks cannot.

A mature investigation should consider:

  • whether inbound payments are linked to known fraud complaints;
  • whether senders are unrelated to the account holder;
  • how quickly funds leave after arrival;
  • whether there are recurring downstream beneficiaries;
  • whether the customer retains a percentage;
  • whether devices, IP addresses, phone numbers or addresses overlap with other accounts;
  • whether the customer profile supports the volume and type of activity;
  • whether the account changed behaviour shortly after opening;
  • whether cash withdrawal, card spending or virtual-asset conversion follows the credits.

The laundering risk is not limited to the first receiving account. Network analysis can reveal recruiters, controllers, consolidators and cash-out points.

Business email compromise and invoice diversion

Business email compromise is useful for teaching the boundary between fraud and laundering. A legitimate company intends to pay a genuine supplier. An attacker compromises or impersonates an email account and changes the bank details on an invoice. The payer authorises the payment, so the transaction may be technically authorised, but the beneficiary is controlled by the fraudster.

The victim bank sees a manipulated payment. The receiving bank may see a corporate account suddenly receiving funds that do not fit its stated business. If those funds are rapidly moved onward, the receiving institution has both fraud intelligence and potential money-laundering indicators.

For AML investigators, invoice-diversion cases show why payment narrative alone is weak evidence. A transfer labelled “INV 4821” may look commercially normal. The surrounding customer behaviour, beneficiary history, device data and fraud reports provide the meaning.

Corruption and bribery proceeds

Corruption can be harder to detect because payments are often wrapped in legitimate-looking commercial activity.

A bribe may appear as a consultancy fee, commission, success fee, sponsorship, charitable payment, agent payment, procurement expense or subcontractor invoice. The recipient may be a family member, close associate or company connected to a public official rather than the official directly.

The bank may therefore need to understand:

  • the customer’s relationship to public-sector contracts;
  • the commercial role of intermediaries;
  • beneficial ownership and control of receiving entities;
  • whether fees are proportionate to services;
  • whether payment timing aligns with contract awards or approvals;
  • whether funds move to relatives or associates of public officials;
  • whether source of wealth changes materially after public-sector events;
  • whether entities exist in jurisdictions unrelated to the underlying commercial activity.

PEP data helps identify risk but does not prove corruption. The analytical value comes from combining political exposure with transaction context, ownership and economic rationale.

Source of wealth in corruption investigations

Source of wealth analysis is especially important where a customer’s assets or lifestyle appear inconsistent with known lawful income. A public official may have a modest salary but control substantial property, investments or corporate interests. That gap can justify deeper review, but the bank should seek evidence rather than rely on assumptions.

Potential evidence can include business ownership, inheritance, investment history, sale of assets, family wealth, audited accounts, tax records where lawfully available and credible public information. The objective is to understand whether the customer’s overall economic position is plausible.

Tax evasion as a predicate offence

Tax matters require careful legal treatment because not every tax-efficient structure is unlawful. The line between avoidance and evasion depends on the applicable legal framework and facts.

Potential indicators of criminal tax evasion may include deliberate concealment of beneficial ownership, false invoices, sham entities, undeclared business receipts, circular loans, unexplained offshore payments or documentation that misrepresents the nature of a transaction.

For a bank, the key questions are whether the conduct could constitute a predicate offence under applicable law and whether the financial activity creates suspicion. Separate tax-reporting regimes may also apply, but they should not be confused with AML obligations.

A common analytical error is to treat the presence of an offshore entity as suspicious in itself. Offshore structures can have legitimate commercial, investment, succession or tax-planning purposes. The risk arises when ownership, purpose or flow of value lacks a credible explanation.

Human trafficking and exploitation

Human trafficking can generate financial patterns that are subtle. Victims may not control the accounts in their own names. Controllers may use multiple cards, phones or addresses. Businesses such as hotels, transport providers, labour agencies or online advertising platforms may appear in transaction history.

Potential indicators can include unusual cash deposits, repeated payments at certain times, many unrelated individuals connected to common contact data, wages immediately transferred to another person, travel patterns inconsistent with the customer profile, or commercial accounts receiving activity inconsistent with stated business.

These are indicators, not proof. Many legitimate customers can display one or more of these behaviours. Investigators need to combine financial evidence with customer information and, where available, reliable external intelligence.

A bank should also consider customer vulnerability. Some account holders may themselves be victims rather than willing participants. Financial-crime controls should support safe escalation rather than automatically treating every unusual customer as an offender.

Drug trafficking and organised crime

Drug trafficking remains a major predicate offence globally, but modern laundering associated with organised crime can use both traditional and digital channels.

Cash remains important in some markets. Cash-intensive businesses can be used to introduce proceeds into accounts. Money service businesses and informal value-transfer systems may be misused. Trade can move value through over- or under-invoicing. Property and luxury goods can store wealth. Digital assets can provide another conversion route.

Organised crime also diversifies. The same network may participate in drugs, fraud, illegal gambling, extortion, cybercrime and trafficking. This means the bank should avoid designing detection around one offence in isolation.

Environmental crime and illegal commodities

Illegal logging, mining, wildlife trafficking, waste trafficking and other environmental crimes can produce significant proceeds. Their financial traces often overlap with legitimate commodity trade, which makes context important.

A customer may legitimately buy minerals from a high-risk region. The risk increases when supplier ownership is opaque, shipment routes are unusual, prices are inconsistent with market norms, documentation is weak, counterparties change frequently or the customer’s stated business cannot explain the activity.

Trade-finance teams, AML investigators and sanctions specialists may all contribute. Environmental crime can also intersect with corruption, because permits, customs or extraction rights may be obtained through bribery.

Cybercrime and ransomware

Cybercrime can move from offence to laundering within minutes. Stolen credentials, ransomware, malware, business email compromise and investment scams can generate proceeds that are transferred through bank accounts and virtual assets.

Ransomware is a useful example because the initial payment may be made in virtual assets. The banking exposure can occur when funds are converted to or from fiat, when infrastructure providers are paid, when exchanges or brokers interact with banks, or when associated entities move proceeds.

Investigators should avoid assuming that virtual-asset exposure itself is suspicious. The relevant question is whether the counterparties, transaction pattern, customer profile or external intelligence indicate illicit activity.

Market abuse and securities-related proceeds

Market manipulation, insider dealing and other market offences can create criminal proceeds in jurisdictions where they are predicate offences.

A retail or private-banking account may receive unusual investment gains connected to information not publicly available. Corporate accounts may be used to move proceeds from manipulative trading. Securities and cash movements may span multiple brokers or custodians.

The AML function may need intelligence from market-surveillance teams. Again, the strongest operating model connects specialist detection without collapsing distinct legal disciplines into one generic alert.

Counterfeiting, intellectual-property crime and illicit trade

Counterfeit goods and intellectual-property crime can generate proceeds that look like ordinary e-commerce revenue. Payment activity may involve marketplace platforms, merchant acquiring, logistics companies, payment processors and cross-border suppliers.

Risk can emerge through high refund rates, inconsistent merchant descriptions, unusual chargeback patterns, unexplained cross-border supplier payments or adverse intelligence on products and trading entities.

The banking signal may therefore be commercial inconsistency rather than a direct indicator of counterfeiting.

Professional gatekeepers

Lawyers, accountants, company-service providers, trust and corporate-service providers, real-estate professionals and other intermediaries can perform legitimate services that are also useful to people seeking to obscure ownership or source of funds.

Banks should not treat professional intermediaries as inherently suspicious. The risk is higher where the structure lacks economic purpose, the professional’s role is unclear, funds pass through client accounts without a credible explanation, or beneficial ownership is difficult to establish.

A common investigative question is: why is this intermediary in the payment chain? If the answer is commercially sensible and supported, the risk may be reduced. If the intermediary appears to exist only to add opacity, further review may be justified.

Commingling: when legitimate and illicit money share the same account

Commingling is one reason AML investigations are difficult. A business can be mostly legitimate and still be used to launder proceeds.

A restaurant may have real customers and real expenses but introduce illicit cash into daily takings. A construction company may complete genuine projects but use some subcontractor invoices to move bribe proceeds. An online business may make legitimate sales while receiving scam proceeds through selected accounts.

This means the analyst cannot simply classify the whole account as clean or criminal. The task is to identify which activity is plausible, which is inconsistent and whether the unexplained part creates suspicion.

Business-model understanding becomes essential. Revenue patterns, margins, seasonality, supplier relationships, staffing, geography and payment methods can help determine whether account activity makes commercial sense.

Layering does not always look complex

The textbook description of layering often involves many transfers, currencies and jurisdictions. That can happen, but modern layering can also be simple and fast.

A fraud victim sends money to a mule. The mule immediately sends it to a crypto exchange. That is only two steps, but the conversion and onward transfer may make recovery more difficult.

Conversely, a complex legitimate treasury structure can involve dozens of accounts and currencies without any criminal purpose.

Complexity is therefore a context variable, not a conclusion.

Integration and apparent legitimacy

Integration refers to criminal value returning to the economy in a form that appears legitimate. Property, investments, businesses, loans, luxury assets and professional fees are common teaching examples.

A useful banking example is a sham loan. Criminal proceeds are moved to an offshore company and later returned to the beneficial owner as a “loan.” The incoming payment now appears to have a contractual basis. The bank’s ability to understand beneficial ownership and source of funds determines whether the circularity is visible.

Another example is property. Funds can be routed through companies, lawyers or family members before being used for a purchase. The bank may see only the transfer to a property professional unless it links the prior account history and ownership structure.

Tracing value across transformations

Investigators should think of value as something that can change form without losing its economic lineage.

Cash can become a bank deposit. A deposit can become securities. Securities can be sold and used to buy property. Fiat currency can become virtual assets and later return as fiat. Funds can become a loan receivable or equity investment.

The bank may not be able to trace every transformation, but internal data should preserve as much lineage as possible.

For payments, useful identifiers include internal instruction ID, end-to-end reference, account entries, dates, amounts, currencies and counterparties. For securities, trade and settlement references matter. For virtual-asset-related flows, exchange counterparties and wallet information may be relevant where lawfully available.

Beneficial ownership: who ultimately benefits?

Predicate-offence proceeds are often separated from the offender through companies, trusts, nominees or relatives.

Beneficial ownership analysis therefore asks who ultimately owns or controls the entity and who economically benefits from the relationship. The legal definitions and thresholds differ by jurisdiction, so banks need both structured data and local rule interpretation.

A practical ownership review should look for:

  • direct and indirect ownership percentages;
  • control through voting rights or agreements;
  • directors and authorised signers;
  • trusts, foundations or nominee arrangements;
  • common addresses and contact details;
  • changes in ownership around significant transactions;
  • links to PEPs, sanctioned persons or adverse intelligence.

A bank should preserve ownership history. Knowing that a sanctioned or high-risk person used to control an entity can be relevant even if the current structure is different.

Shell, shelf and front companies

These terms are often used loosely.

A shell company generally has little or no independent operational activity. It can be legitimate, for example as a holding or special-purpose vehicle. A shelf company is incorporated and kept inactive until later use. A front company conducts genuine business while also being used to conceal criminal activity.

The risk is not the label. It is whether the entity’s purpose, ownership, financial activity and economic substance make sense.

Indicators can include minimal staff, no credible premises, large transaction volumes inconsistent with size, rapidly changing directors, many unrelated businesses at one address, payment activity unrelated to stated business or unexplained cross-border flows.

Trade-based laundering and predicate offences

Trade-based money laundering can be used to move or disguise value through goods and invoices. Predicate offences can include smuggling, corruption, fraud, customs crime or other illicit activity.

Techniques may involve over-invoicing, under-invoicing, multiple invoicing, misdescription of goods or phantom shipments. Banks rarely have enough information to prove these practices from payment data alone. Trade documents, customer history, pricing context and shipment information become important.

The best control is risk-based. Not every invoice should become a forensic investigation. Higher-risk customers, goods, routes and inconsistencies should receive deeper review.

Real estate and high-value assets

Property and luxury goods can store significant value and can create an appearance of legitimate wealth.

Banks may see property purchases through lawyers, escrow agents, developers or mortgage products. Risk increases where source of funds is unclear, third parties provide the purchase money, ownership is obscured through entities or the transaction is inconsistent with the customer’s known wealth.

Again, high value alone is not suspicious. The question is whether the economic story is credible.

A full worked case: retail mule network

Consider a customer who opened a current account eight months ago. For six months the account received salary and was used for normal household spending. Over the next fourteen days, the pattern changes dramatically.

Twenty-three inbound instant payments arrive from unrelated individuals. Most are between EUR 700 and EUR 3,000. Within minutes of each credit, funds are transferred to three beneficiaries. Several cash withdrawals occur from ATMs in another city. The account holder’s device changes twice. A second phone number appears in authentication logs.

A weak investigation might say “many transfers; possible mule.”

A stronger investigation would reconstruct the timeline. It would identify the senders, check whether any are linked to fraud complaints, compare the activity with the customer profile, review device and contact changes, identify common downstream beneficiaries and examine whether those beneficiaries receive funds from other bank customers.

Suppose the bank discovers that seven other customers send money to one of the same beneficiaries and three share the same device fingerprint. The case has now moved from a single-account anomaly to a network hypothesis.

The analyst should still document uncertainty. The account holder may be knowingly participating, may have surrendered control of the account or may have been deceived. The bank can identify suspicious handling of proceeds without determining the customer’s criminal intent with certainty.

A full worked case: corruption through consulting fees

A construction company wins a government infrastructure contract. Three months later it begins making payments to an overseas consultancy. The consultancy has two employees, was formed shortly before the first payment and is owned by a close associate of a public official involved in approving the project.

The invoices describe “strategic advisory services” but provide little detail. Payment amounts are calculated as a percentage of contract milestones. The consultancy transfers part of the funds to a property company owned by a relative of the public official.

Potential explanations exist. The consultancy may provide legitimate services. The ownership connections may be coincidental. The property payment may be unrelated.

The investigator should therefore gather evidence: contract documents, customer explanation, service deliverables, beneficial ownership, payment chronology, PEP relationships, source-of-wealth information and any reliable adverse media.

The strength of the case comes from the combination of timing, ownership, economics and flow of funds, not from any single red flag.

A full worked case: environmental crime and commodity payments

A trading company states that it imports timber from several jurisdictions. Its account shows growing payments to new suppliers in a region associated with illegal logging. Invoices describe generic “wood products,” shipment routes are indirect and several suppliers share directors with recently incorporated companies.

The bank cannot determine whether the timber is illegal from payments alone. But it can identify risk: opaque suppliers, changing counterparties, unusual routing and activity inconsistent with previous business patterns.

The investigator may request additional trade documentation, understand supplier due diligence, review ownership and compare the activity with the customer’s expected profile. If concerns remain, escalation may be appropriate.

This case illustrates why environmental crime often requires collaboration between AML, trade finance and external-intelligence functions.

A full worked case: ransomware conversion

A technology-services company receives several credits from virtual-asset exchanges and immediately sends funds to accounts in multiple countries. The company’s stated business does not involve virtual assets. Its directors have little visible history in the sector.

External intelligence later links one of the exchange deposit clusters to ransomware activity.

The bank should distinguish what it knows from what it infers. Exchange transactions are facts. Inconsistency with business profile is an indicator. External intelligence raises the risk. Whether the customer knowingly launders ransomware proceeds is a hypothesis requiring evidence.

The investigation may consider ownership, source of funds, customer explanation, counterparties, transaction timing, connected accounts and law-enforcement information where available.

Investigation chronology: build the story before writing the conclusion

A reliable technique is to build a chronology before deciding the narrative.

Start with onboarding. When was the customer created? What purpose and expected activity were declared? Who owned or controlled the relationship?

Then identify the change. When did behaviour begin to diverge? Was there an ownership, device, geography or product change?

Then trace the value. Where did money come from? How long was it held? Where did it go? Was it converted or withdrawn?

Then map relationships. Which parties recur? Which accounts, devices, addresses or directors overlap?

Finally, test explanations. Does the customer’s explanation fit the facts? What evidence supports or contradicts it?

Chronology prevents investigators from cherry-picking transactions that support an initial suspicion.

Evidence quality and provenance

Not all evidence has equal reliability.

Verified KYC documents are different from customer statements. Official corporate registries are different from social-media claims. Reputable journalism is different from anonymous internet allegations. Internal fraud intelligence is different from an unverified alert.

Case systems should ideally preserve evidence provenance: source, date, confidence and who reviewed it. This helps future investigators and supervisors understand why the bank relied on a fact.

Data lineage and predicate-offence analysis

Technical teams play a major role in whether predicate-offence investigation succeeds.

If payment messages are truncated, investigators lose counterparty detail. If customer IDs change during migration, historical activity becomes fragmented. If beneficial-ownership data sits in unsearchable documents, network analysis is weakened. If fraud cases are not linked to receiving accounts, AML teams miss known proceeds.

A good data model therefore connects party, account, product, transaction, device, document, case and external-intelligence entities through stable identifiers.

What a BA should ask when designing a predicate-offence control

A BA should begin with the typology or risk question, not with a system feature.

What behaviour is the bank trying to detect? Which data supports that hypothesis? At what point in the lifecycle does the data exist? Is the data structured and reliable? Which customer segments are relevant? What creates an alert? What context does an investigator need? What outcome can the case produce? How does the result feed back into fraud, KYC or monitoring?

If the requirement cannot answer those questions, it is probably too generic.

What testers should challenge

Testers should verify that scenario logic works across realistic edge cases.

A retail mule scenario should not only test one large transfer. It should test multiple small credits, rapid onward movement, account history changes, multiple beneficiaries and peer behaviour. A corruption scenario should test ownership links and PEP relationships. A trade scenario should test inconsistent goods or geographies. A virtual-asset scenario should test legitimate activity as well as suspicious patterns to ensure the control does not simply flag every exchange payment.

Negative testing is particularly important. The bank needs confidence that legitimate behaviour can be recognised and closed with evidence.

Effectiveness: did the control find useful risk?

A predicate-offence typology is useful only if it improves detection or investigation.

Teams should review whether alerts correspond to meaningful cases, whether new external intelligence changes detection, whether false positives cluster in certain customer segments and whether case outcomes feed back into model tuning.

A scenario that has existed for years but produces no useful outcomes should be challenged. A scenario with a high conversion rate should also be challenged to ensure it is not merely detecting already-known cases.

Effectiveness is about learning, not preserving every rule forever.

Avoiding narrative bias

Investigators are human and can become anchored on the first explanation they see. If the case title says “suspected mule,” every later fact may be interpreted through that lens.

A disciplined review asks what evidence would disprove the hypothesis. Could the unrelated credits be marketplace sales? Could the rapid transfers be normal treasury activity? Could the consulting company genuinely provide services? Could the offshore structure have a legitimate investment purpose?

The objective is not to argue against every suspicion. It is to ensure that the conclusion survives reasonable alternative explanations.

The role of network analytics

Predicate offences increasingly involve networks rather than isolated customers. Network analytics can identify common beneficiaries, devices, addresses, directors, phone numbers and transaction paths.

A network view is especially useful for mule rings, shell-company structures, fraud proceeds and corruption intermediaries.

But network links must be interpreted carefully. Two customers using the same office address may simply use a corporate-service provider. Many customers paying the same beneficiary may be normal for a utility company. Relationship does not equal criminal association.

The value of network analytics lies in prioritising questions, not declaring guilt.

Customer restriction and exit

When suspicious activity is identified, the bank may consider restrictions or exit in addition to reporting. Those decisions should be governed separately.

A suspicious report does not always require immediate account closure. Premature closure can disrupt law-enforcement interest or push activity to another institution. Conversely, continuing a relationship with unmanageable risk may expose the bank.

The correct decision depends on legal requirements, law-enforcement guidance where applicable, customer risk, product exposure and the bank’s risk appetite.

The decision and rationale should be documented independently from the reporting decision.

Record retention and future investigations

Predicate-offence cases can become relevant years later. Law enforcement may request records long after the original transaction. A bank migration may have occurred in the meantime.

Retention design should preserve the information required by law and policy, including transaction records, customer evidence, case decisions and relevant audit trails.

The practical lesson for architects is simple: historical reconstructability is part of financial-crime control.

Practitioner review questions

A reader should be able to explain why a bank can report suspicious activity without proving the predicate offence; why fraud complaints at one bank can become AML intelligence at another; why a PEP connection is a risk factor rather than proof of corruption; why offshore ownership is not automatically suspicious; how commingling complicates analysis; why network relationships require context; why chronology matters; and why the strongest case narratives distinguish facts from hypotheses.

If those distinctions are clear, the reader is ready to move from typology recognition into risk-based control design.

Practitioner mastery extension: criminal proceeds and predicate offences

This extension deepens the chapter through evidence reconstruction, predicate-offence reasoning, network analysis and case-writing practice. The objective is not to memorise a catalogue of crimes. It is to understand how value generated by an underlying offence can become visible in banking data, how an investigator can reason from incomplete evidence, and how to preserve the distinction between a financial-crime hypothesis and a proven criminal allegation.

Predicate offence is a legal concept, not a bank shortcut

A predicate offence is an underlying crime capable of generating proceeds or otherwise forming the criminal foundation for money laundering under the applicable legal framework. Fraud, corruption, drug trafficking, tax crime, cybercrime, environmental crime, human trafficking and many other offences can produce value that later enters financial channels. FATF Recommendation 3 expects predicate offences to cover all serious offences and, at a minimum, a range within the FATF-designated categories; the exact domestic offence definitions and legal thresholds remain matters of national law.

The bank's operational task is normally narrower. It does not need to prosecute the predicate offence. It needs to understand the observed financial activity, assess whether the funds may represent criminal proceeds, decide whether suspicion exists under the applicable framework and preserve or report relevant information where required. That distinction is important because a bank case is not a criminal judgment, and a suspicious-activity report is not a finding of guilt.

Facts, indicators, hypotheses and conclusions

A strong investigation keeps four layers separate. Facts are directly supported by bank records or reliable evidence: amounts, dates, counterparties, account ownership, payment messages, login events or verified corporate data. Indicators are facts that may be relevant to risk, such as rapid pass-through, unexplained third-party funding or ownership opacity. A hypothesis is a possible explanation, such as fraud proceeds, corruption or professional laundering. A conclusion is the investigator's reasoned decision after testing the evidence.

This distinction prevents circular reasoning. Writing "customer is laundering because the payments are layering" simply restates a conclusion. Writing "EUR 480,000 entered from five unrelated companies, 94% moved within 24 hours to entities controlled by the same beneficial owner, and no commercial explanation was established" gives another reviewer something testable.

Worked case: business-email-compromise proceeds

A small company receives EUR 170,000 from a corporate payer it has never dealt with before. The payer later reports that an employee was deceived by a fraudulent supplier-email instruction. The receiving company transfers most of the funds within hours to two personal accounts and a virtual-asset service provider.

The confirmed victim report materially strengthens the evidential context because the inbound funds are now linked to an alleged fraud event. The receiving bank should reconstruct the timeline, identify who controlled the recipient account, review device and authentication evidence, examine onward beneficiaries, and determine whether other victim-linked credits exist. The company may be complicit, recruited, compromised or otherwise misused; those possibilities should be tested rather than assumed.

The February 2026 FATF paper on cyber-enabled fraud is a useful current reminder that fraud is not merely a front-end customer-loss problem. FATF describes cyber-enabled fraud as a major illicit-finance threat and focuses on the need to follow, detect and disrupt the proceeds as they move through increasingly digital financial channels. For a bank, this strengthens the case for joining fraud intelligence with AML investigation rather than allowing the victim-side and receiving-side stories to remain in separate operational silos.

Worked case: corruption and apparent consultancy income

A consultancy owned by a close associate of a public official receives large payments from contractors shortly after public contracts are awarded. The company has limited staff and sends funds to property sellers and investment accounts. None of those facts alone proves bribery. The useful analysis asks whether services were actually provided, whether payment values and timing are commercially plausible, how the company is owned and controlled, whether counterparties have public-procurement exposure and whether source-of-wealth information is consistent.

PEP status is a risk factor, not proof of corruption. An investigation should avoid stating that the payments are bribes unless there is evidence supporting that conclusion. The bank can still identify unresolved financial-crime risk and suspicious activity without proving the predicate offence.

Transformations do not erase provenance

Criminal value can change form many times: cash becomes a bank deposit; a bank balance becomes foreign currency; funds purchase securities; securities are sold; proceeds fund property; property is refinanced; loan proceeds are then used for ordinary-looking expenditure. The immediate source of a payment may therefore be a legitimate bank or broker account while the broader source of wealth remains problematic.

Investigators should follow economic value rather than only the latest transaction label. A payment description such as "loan," "dividend," "consulting fee" or "property sale" is a customer claim. It becomes stronger evidence only when the underlying relationship and economic event are credible.

This is also why the data model matters. If the bank can connect payment IDs, account entries, securities transactions, foreign-exchange conversions, customer parties, beneficial owners and case records through stable identifiers, an investigator can follow value across transformations. When those links are lost during system migration or message transformation, the control problem becomes evidential rather than merely technical.

Practice exercise — work through this before reading on.

Evidence-classification exercise

Take a case with an invoice, customer explanation, registry extract, adverse-media article, transaction history, vendor risk score and law-enforcement request. Classify each item as bank-generated fact, customer-provided evidence, independent public information, model or vendor inference, or protected official information. Then ask what each item actually proves and what it does not prove.

For example, an invoice can support that a document was presented; it does not by itself prove that goods or services existed. A registry can establish recorded legal ownership but may not establish current effective control. A vendor score is an analytical input, not a criminal finding. This discipline is essential for defensible case writing.

Network and beneficial-ownership reasoning

Criminal proceeds frequently move through entities that look independent at account level but are linked through ownership, directors, devices, addresses or payment destinations. Effective-dated ownership matters because today's shareholders may not be the same people who controlled an entity when a historical transaction occurred.

A strong network tool should therefore distinguish verified relationships from inferred ones. A shared professional registered office is weaker evidence than a verified common beneficial owner. A shared device can be important but may also reflect family or assisted-banking use. Relationship confidence should be visible to investigators.

Beneficial ownership is especially important where proceeds are deliberately separated from the offender. A company can receive funds, another company can hold an asset, and a natural person can still be the person who ultimately owns, controls or benefits from the arrangement. The applicable legal definitions and thresholds vary, so the system should preserve ownership facts and effective dates rather than embed one global legal conclusion into a single flag.

Environmental crime and other non-obvious predicate offences

Predicate-offence reasoning should not stop with fraud, drugs and corruption. FATF's designated categories include environmental crime, and FATF's environmental-crime work shows why financial institutions need to consider the proceeds from illegal logging, wildlife trafficking, illegal mining, waste trafficking and related activity. The banking evidence may resemble normal commodity or trade activity until ownership, route, pricing, documentation and customer purpose are considered together.

This is a useful control-design lesson. A transaction-monitoring scenario labelled "environmental crime" is unlikely to work if it has no access to customer sector, trade counterparties, geography or relevant intelligence. Typology detection depends on the data that expresses the typology.

Final judgement test

Consider five patterns: a customer receiving stolen funds; a company paying a related entity for real services; a high-value property purchase funded by inheritance; a circular loan through entities under common control; and a business receiving cash far above plausible turnover. For each, write one paragraph containing only verified facts, one paragraph containing the risk hypothesis and one paragraph stating what additional evidence would resolve the uncertainty.

The goal is to learn that banks can act on suspicion without pretending to have proved the underlying crime. The strongest financial-crime analysis is precise about what is known, what is inferred and why the remaining uncertainty matters.

BA, architecture and testing close

For a business analyst, the key requirement is traceability from risk hypothesis to evidence. A detection requirement should say which data elements create the signal, which source system owns them, how missing data is handled, which customer or product segments are in scope, how the alert links to the underlying transactions and what evidence the investigator must see. A requirement that says only "detect predicate offences" is not implementable because a bank does not receive a reliable predicate-offence label with each payment.

Architects should preserve original payment and party data, stable customer and account identifiers, ownership relationships, device or channel context where lawfully available, case links and effective dates. Transformations should be reconcilable. The investigator should be able to move from a case to the source transaction and back to the customer state that existed when the event occurred.

Testing should include both suspicious and legitimate lookalikes. A mule scenario should be tested against genuine marketplace sellers and family transfers. A corruption-risk scenario should include legitimate consultancy arrangements. A trade-related scenario should include ordinary complex supply chains. The objective is not merely to prove that a rule fires, but to show that the control distinguishes meaningful risk from normal complexity using the information it was designed to consume.

References and further reading

The sources below are the main public authorities used for this chapter. They should be read together with the law, regulatory guidance and reporting rules applicable to the bank legal entity handling the customer or transaction.

Jurisdiction note: FATF provides the common international architecture, but the definition of a predicate offence, the legal meaning of criminal property or proceeds, evidential standards, suspicious-reporting thresholds, confidentiality duties, asset-handling powers and customer-action rules are jurisdiction-specific. A global bank can use common risk concepts and data structures, but every legal conclusion and operational action must be mapped to the law and supervisory expectations applying to the relevant legal entity, customer, product and transaction.