FATF, FIUs and International Cooperation

A bank rarely sees an entire financial-crime network. One institution may see the customer who initiates a transfer, another the beneficiary account, another the foreign-exchange leg, another a virtual-asset conversion, while an authority may hold intelligence that changes the meaning of every transaction. This fragmented view is one reason the global anti-money-laundering and counter-terrorist-financing system depends on cooperation as much as it depends on individual bank controls.

The practical architecture is easier to understand when the different roles are kept separate. The Financial Action Task Force, or FATF, develops international standards and assesses how jurisdictions implement them. Countries and regions turn those standards into law, regulation, supervisory requirements and institutional arrangements. Banks build customer, payment, monitoring, investigation and reporting controls under the rules that apply to their legal entities. Financial Intelligence Units, or FIUs, receive and analyse financial intelligence under national law. Law-enforcement, prosecutorial, judicial, supervisory and other competent authorities use their own powers and cooperation channels. International mechanisms connect those national systems when money, people, companies, evidence or intelligence cross borders.

That sequence can be summarised as global standard → domestic implementation → bank control → financial intelligence → lawful cooperation → public-sector outcome → control feedback. It is a useful model because it prevents several common mistakes. FATF is not a world regulator approving individual transactions. An FIU is not automatically a police force or sanctions authority. A suspicious report is not a finding of guilt. An intelligence exchange is not automatically courtroom evidence. A correspondent-bank request for information is not the same as a government order. A global bank’s need to share information does not remove local privacy, secrecy or reporting-confidentiality restrictions.

Global operating model showing FATF standards flowing through domestic implementation to bank controls and FIUs, with lawful cooperation connecting intelligence and enforcement outcomes.

1. FATF sets the international architecture, not one universal banking law

FATF is an inter-governmental standard-setting body. Its Recommendations establish a common framework for combating money laundering, terrorist financing and proliferation financing. They cover national risk assessment, criminalisation, confiscation and asset recovery, targeted financial sanctions, customer due diligence, beneficial ownership, correspondent banking, payment transparency, internal controls, suspicious reporting, FIUs, supervision, law-enforcement powers and international cooperation.

The influence is enormous, but the legal path matters. FATF normally does not determine the exact filing deadline for a bank in Bengaluru, London, New York or Sydney. It does not issue a bank’s local licence, decide the statutory wording of tipping-off offences, define every national production-order process or prescribe one universal FIU submission schema. Those obligations arise through national or regional law, regulation and competent-authority guidance.

A multinational bank therefore needs two connected but separate layers of requirements. The first records the international control objective. The second records the binding local implementation: which legal entity is in scope, what activity is covered, what legal source applies, what action is required, what deadline or threshold applies, who has decision authority, what exceptions exist and what evidence must be retained. Combining both layers into a generic statement such as “FATF requires this” makes regulatory change difficult to manage and can cause one jurisdiction’s rule to be applied incorrectly to another.

The FATF Recommendations were last updated in June 2026. That is operationally important because the standards are living documents. A control catalogue should therefore record the source version or effective date used for a requirement. A policy saying only “aligned to FATF” is not enough if nobody can later show which version was assessed or how a subsequent amendment was evaluated.

FATF also operates through a much wider Global Network that includes FATF-style regional bodies. This gives jurisdictions around the world a broadly shared framework while preserving different legal systems, institutional structures and risk environments. For banks, that combination produces a familiar pattern: common objectives, local implementation.

2. The 40 Recommendations work as a connected system

The Recommendations are often taught as forty separate numbers. In practice they form an operating system. A national risk assessment should influence national priorities and supervision. Customer due diligence and beneficial-ownership information help institutions understand who is behind a relationship. Payment transparency improves the data available to financial institutions and authorities. Suspicious reporting feeds the FIU. FIU analysis can support investigations. Law-enforcement and prosecutorial powers can convert intelligence into investigation, restraint, prosecution and confiscation. International cooperation allows those activities to cross borders.

Several Recommendations are particularly important for this chapter. Recommendation 2 addresses national cooperation and coordination. Recommendation 20 addresses suspicious-transaction reporting. Recommendation 29 addresses FIUs. Recommendations 36 to 40 deal with international instruments and cooperation, including mutual legal assistance, extradition and other forms of international cooperation. Recommendation 40 expects competent authorities to be able to provide a wide range of international cooperation rapidly, constructively and effectively, subject to legal safeguards.

The sequence matters more than memorising numbers. A bank can have excellent monitoring but poor customer identifiers. The FIU may then receive a report that cannot be linked reliably to other information. A bank can file high-quality reports but fail to preserve the underlying payment records needed later for a production order. A jurisdiction can have strong laws but weak investigative or confiscation outcomes. Financial-crime effectiveness depends on the whole chain, not one control in isolation.

For business analysts and architects, this means requirements should preserve relationships. The customer, beneficial owner, account, payment, counterparty, alert, case, filing, external request and evidence package should be linkable. The system should not reduce financial-crime work to a set of unrelated forms whose data cannot be reconstructed later.

3. Technical compliance and effectiveness answer different questions

FATF mutual evaluations distinguish technical compliance from effectiveness. Technical compliance asks whether the required laws, regulations, authorities and formal measures exist and meet the technical elements of the Recommendations. Effectiveness asks whether the system works in the jurisdiction’s risk context and delivers the intended results.

The distinction is directly relevant to banks. A transaction-monitoring scenario can be documented, approved and switched on while missing a major payment feed. An FIU reporting interface can successfully create files while silently losing portal acknowledgements. A KYC policy can require beneficial-owner verification while operations accept weak evidence. A sanctions process can contain the right procedure while stale list data makes the control ineffective. Control existence is not the same as control effectiveness.

FATF assesses effectiveness through 11 Immediate Outcomes. The point is not that banks should reproduce the national methodology internally. The useful lesson is that controls should be tested through evidence and outcomes. A requirement marked “implemented” should be supported by coverage, data lineage, operating evidence, quality assurance, exception management and demonstrable remediation.

A mature financial-crime programme therefore asks two questions continuously: Did we design the required control? and Can we prove it works on the real population and real data? The second question is often harder.

4. Mutual evaluations are jurisdiction-level peer reviews

FATF mutual evaluations are in-depth peer reviews of a jurisdiction’s AML/CFT/CPF framework. FATF states that its fifth round began in 2024 under the 2022 Methodology, and that a complete mutual evaluation can take up to 18 months. The current methodology and fifth-round procedures were updated in June 2026.

The process examines risk and context, laws and regulations, institutional arrangements, evidence of effectiveness, and the results produced by the national system. The on-site visit is particularly focused on whether the framework is working. Assessors test evidence, interview authorities and relevant sectors, challenge explanations and evaluate outcomes. Findings and proposed ratings pass through review and plenary processes before publication, followed by post-assessment monitoring and remediation.

Mutual evaluation lifecycle showing risk and context, evidence collection, technical-compliance and effectiveness assessment, on-site review, report adoption and follow-up remediation.

A mutual evaluation is not an audit opinion on every bank in the country. A weak national rating does not prove that a particular bank’s control is defective, and a strong national rating does not prove every bank is effective. The report is nevertheless useful risk intelligence. It can reveal weaknesses in beneficial-ownership transparency, supervision, suspicious reporting, financial intelligence, investigations, asset recovery, terrorist-financing controls or international cooperation.

Banks may also feel the evaluation process indirectly. Domestic supervisors and authorities can request statistics, case studies, risk assessments, suspicious-reporting data, sanctions-control evidence and examples of remediation. A rushed response often exposes data-definition problems that already existed: one team counts alerts, another counts investigations, another counts regulatory reports, and nobody can reconcile the populations. The evaluation did not create the weakness; it made the weakness visible.

Historical ratings also need context. Countries may be assessed under different rounds or still be in follow-up from earlier assessments. A country-risk system should therefore retain assessment date, round, follow-up status and the substance of relevant findings rather than reduce a jurisdiction to one timeless rating.

5. FATF public statements are risk information, not a synonym for sanctions

FATF publishes statements on jurisdictions with strategic deficiencies. Two broad categories matter operationally: jurisdictions under increased monitoring and high-risk jurisdictions subject to a call for action. The current statement must always be read because country status and the requested response can change.

The June 19, 2026 statement on jurisdictions under increased monitoring explicitly says that FATF does not call for enhanced due diligence merely because a jurisdiction is on that list and that the Standards do not envisage indiscriminate de-risking or cutting off entire classes of customers. FATF expects the information to be considered in risk analysis and the response to remain risk based. A bank can still decide that the jurisdiction changes its customer or transaction risk assessment, but it should not misstate that decision as an automatic FATF prohibition.

The June 19, 2026 call-for-action statement is stronger and distinguishes the measures applicable to the named jurisdictions. Some situations involve calls for countermeasures; another may involve proportionate enhanced due diligence without countermeasures. This is exactly why a single internal flag called FATF_BLACKLIST = BLOCK is poor design.

Sanctions are a separate legal discipline. United Nations, national or regional sanctions regimes can create asset freezes, service restrictions, trade restrictions, sectoral measures, licensing requirements or other prohibitions. FATF country statements address strategic AML/CFT/CPF deficiencies and the risk-response framework. The two can overlap geographically, but they should not be collapsed conceptually or technically.

A useful country-risk model therefore separates at least FATF monitoring status, FATF call-for-action status, applicable sanctions programmes, internal exposure, corruption or crime indicators, terrorist-financing and proliferation-financing concerns, payment-corridor experience and other jurisdiction-specific legal or supervisory factors. The outcome should remain explainable.

6. An FIU is a national financial-intelligence centre, not simply a reporting inbox

Recommendation 29 expects countries to establish an FIU that serves as the national centre for receiving and analysing suspicious transaction reports and other relevant information and for disseminating the results of analysis. The exact institutional form differs. The Egmont Group describes administrative, law-enforcement, judicial and hybrid models. Powers, access rights and organisational arrangements are determined by national law.

The word analysis is important. A bank normally sees its own customer and transactions. An FIU can receive reports from multiple institutions and may have access, directly or indirectly according to its legal framework, to financial, administrative, law-enforcement and public information. A payment that looks isolated to one institution may become significant when linked to another report, an ownership record, an investigation or foreign intelligence.

The FIU should also not automatically be described as the body that arrests suspects or determines criminal guilt. In many systems it develops financial intelligence and disseminates relevant analysis to competent authorities. Domestic investigative, prosecutorial or judicial bodies then use their own legal powers. Some countries combine functions more closely, which is another reason local institutional mapping matters.

This distinction should appear in technology. A generic workflow state such as FIU_APPROVED can be misleading if the local FIU does not operate an approval or consent model. An enterprise case platform can be common across jurisdictions, but local states, fields, deadlines and authority interactions must remain configurable.

7. Suspicious reporting connects a bank case to the wider intelligence system

The suspicious-reporting lifecycle normally starts long before a regulatory report exists. A transaction-monitoring alert, fraud referral, screening investigation, KYC review, employee escalation, adverse information, law-enforcement lead or other event creates a reason to review the customer or activity. An investigator gathers facts and tests explanations. The authorised reporting function applies the legal threshold and process for the relevant jurisdiction. If the threshold is met, the required filing is prepared and submitted through the approved channel.

Jurisdictions use different names such as STR, SAR or SMR. The filing trigger, timing, form, confidentiality rule, consent or defence mechanism, supplementary-report process and submission technology can differ. A global system should therefore treat reporting as a configurable obligation, not one worldwide workflow copied from a single country.

Suspicious-report-to-intelligence lifecycle showing detection, investigation, reporting decision, secure FIU submission, FIU analysis, dissemination and feedback or information requests.

A suspicious report communicates suspicion under the applicable legal framework. It should not be represented internally as a conviction. Investigators should distinguish observed facts from inference. A good narrative explains the customer profile, relevant period, activity, counterparties, transaction sequence, departure from expected behaviour, information reviewed, customer explanation where appropriate, and why concerns remain unresolved. It should be usable by another analyst who has never seen the bank’s internal case.

The FIU can then combine the filing with other information. It may connect reports from other institutions, request additional information, receive foreign intelligence, identify a wider network, conduct strategic analysis or disseminate relevant intelligence to competent authorities. The reporting institution may never see the full outcome, which is why filing volume alone is a poor measure of programme effectiveness.

8. A regulatory filing is a controlled data product

Banks sometimes focus almost entirely on the narrative. In reality, the filing is a structured data product. It may contain institution identifiers, subjects, accounts, transactions, linked parties, currencies, dates, payment references, typology indicators, narrative, attachments, filing reasons and jurisdiction-specific fields. Data quality can therefore determine whether the FIU can link the filing effectively.

The internal investigation case and the external filing should be related but not identical objects. The case may contain internal hypotheses, quality-review comments, privileged material, risk scores or data not intended for external disclosure. The filing object should contain only the information approved for submission, plus the schema version, submission status, timestamp, external reference or acknowledgement, amendment history and evidence of the authorised decision.

This separation is valuable during regulatory change. When an FIU changes its submission schema, the bank can transform its canonical case and transaction data into the new local format without rebuilding the investigation engine. It also helps prevent accidental over-disclosure simply because an internal field exists.

Status design matters as well. SUBMITTED should not mean merely that a message entered an outbound queue. Depending on the local channel, a system may need to distinguish APPROVED_FOR_FILING, TRANSMITTED, TECHNICALLY_ACCEPTED, ACKNOWLEDGED, REJECTED, RETRY_PENDING, AMENDED or equivalent states. The exact vocabulary is less important than the ability to prove whether the authority actually received the filing.

Timestamps should preserve both a technically unambiguous value and the local legal context. Alert time, case creation, suspicion decision, approval, transmission and authority acknowledgement are different events. A filing deadline should be calculated from the trigger defined by the applicable framework, not from a convenient enterprise timestamp selected without legal analysis.

9. Operational analysis and strategic analysis create different value

FIU analysis can be operational or strategic. Operational analysis focuses on specific people, entities, accounts, assets, transactions and networks. Strategic analysis looks across larger bodies of information to identify patterns, methods, vulnerabilities and emerging threats.

The distinction is practical. An operational analysis may link a group of mule accounts and counterparties in one investigation. Strategic analysis may reveal a broader increase in newly opened accounts receiving rapid instant-payment credits and moving funds through particular channels. The first can support an active case. The second can influence national priorities, FIU guidance, bank monitoring scenarios and customer-risk design.

This creates a feedback loop. Banks provide intelligence through lawful reporting. FIUs and competent authorities can return typologies, guidance, requests and other feedback. Banks can use that information to improve monitoring, investigation, customer due diligence and training. The loop is strongest when data is structured and traceable rather than buried in unsearchable narratives or disconnected spreadsheets.

10. Confidentiality and tipping-off controls are jurisdiction-specific but operationally critical

Suspicious-reporting information is sensitive. Many jurisdictions restrict disclosure of a filing or related information and prohibit conduct that could improperly tip off a subject or prejudice an investigation. The wording, scope, exceptions and penalties differ. The United States, for example, has specific SAR confidentiality rules; other jurisdictions use different concepts and statutory language.

A global bank therefore needs a jurisdiction-aware confidentiality model. Customer-service and relationship staff may legitimately need to know that a payment is being reviewed without needing access to the fact that a report was filed. An investigator may see case facts that another operational user cannot. Legal, compliance, reporting and authority-liaison teams may have different permissions. Data-science or model teams may need controlled datasets rather than unrestricted copies of case records.

Role-based access, field-level masking, segregation of duties, export controls, logging and periodic access review can support this model. Customer communication also needs approved patterns. A customer may deserve a clear explanation of service impact while the bank remains legally unable to disclose protected investigative or reporting information.

The same need-to-know principle applies to international cooperation. Information received from an authority can carry purpose limitations, confidentiality conditions or restrictions on onward dissemination. Those conditions should travel with the information rather than disappear when data enters an ordinary case-management system.

11. The Egmont Group supports FIU-to-FIU cooperation

The Egmont Group provides a global platform for FIUs to cooperate and exchange financial intelligence securely. Its current public materials describe FIUs as gateways for domestic and international financial-information sharing. Its Principles for Information Exchange, approved in July 2025, address the legal basis for cooperation, exchange on request and spontaneously, proportionality, timeliness, confidentiality, permitted use and secure handling. The Charter was revised in November 2025.

The operating model should not be misunderstood as an unrestricted global database. FIUs exchange information under legal and institutional frameworks and subject to controls over use and dissemination. A domestic bank normally files with its domestic FIU. That FIU can communicate with a foreign counterpart when appropriate and lawful. The bank should not tell staff or customers that filing locally means foreign police automatically gain access to the bank’s complete case file.

The July 2025 Egmont Principles also reinforce an important practical distinction: requests should be sufficiently specific, relevant and proportionate. Cooperation should be timely, but information protection remains fundamental. Those are principles for FIUs, not a universal bank disclosure rule. Banks should apply the legal framework that governs requests made to them.

12. International cooperation runs on several different rails

The phrase international cooperation can conceal very different legal mechanisms. FIU-to-FIU exchange supports financial intelligence. Law-enforcement cooperation can involve police-to-police channels, liaison officers, joint investigations and other operational arrangements. Mutual legal assistance supports more formal cross-border legal processes for evidence and judicial measures. Supervisory cooperation supports oversight of cross-border institutions. Tax, customs, asset-recovery, sanctions and other competent-authority channels may exist for their specific mandates.

Private-sector exchange is different again. Correspondent banks may send requests for information to understand transactions and manage their own risk. Financial groups may share certain information for group AML/CFT purposes. Public-private partnerships may provide authorised mechanisms for sharing typologies or intelligence. None of these relationships should be confused with a government demand.

Cross-border cooperation map separating FIU intelligence exchange, law-enforcement cooperation, mutual legal assistance, supervisory cooperation and private-sector information exchange.

Channel classification determines what the recipient bank should do. Imagine that the same customer is mentioned on the same day in a correspondent RFI, an FIU follow-up, a police production order, a supervisory request and an internal group investigation. The requested data could overlap, but the authority, purpose, deadline, confidentiality, approval and permitted disclosure can differ materially.

A robust intake process records requester identity, authority type, jurisdiction, legal or contractual basis, purpose, scope, deadline, confidentiality classification, required response channel, approval requirement, onward-disclosure restriction and retention rule. Routing everything to a generic external_request queue invites over-disclosure and missed obligations.

13. Intelligence is not automatically evidence

FIU intelligence can identify a lead, account, company, relationship or network. That does not mean the intelligence itself can automatically be used as courtroom evidence. If records are needed for a prosecution, a competent authority may need to obtain them through a formal legal process such as a production order, subpoena, warrant, mutual legal-assistance request or local equivalent.

This distinction matters to banks. A foreign FIU may provide intelligence to the domestic FIU. Domestic law enforcement can then obtain bank records through the process available under national law. The bank should respond to the authority and legal instrument actually served on it. It should not assume that an intelligence exchange between governments authorises the bank to send customer records directly to a foreign authority.

Case systems should preserve this distinction. SOURCE = FOREIGN_FIU should not carry the same disclosure rights or evidential meaning as SOURCE = COURT_ORDER. Provenance, authority, purpose limitation, permitted use and dissemination conditions should be captured explicitly.

The 2025 FATF, Egmont Group, INTERPOL and UNODC handbook on international cooperation is useful here. It promotes faster and more effective cooperation among analysts, investigators and prosecutors, including appropriate informal cooperation, while recognising that formal legal processes remain necessary for particular evidential and judicial outcomes.

14. Group-wide information sharing can improve detection but is not unlimited

A global banking group can often see more risk when information is combined across legal entities. A customer may hold accounts in several countries. A payment pattern that looks ordinary within one entity may become unusual when the group sees rapid movement across entities and products. Basel’s 2026 consolidated AML/CFT guidance emphasises group-wide risk management and robust information sharing, subject to legal constraints.

The key phrase is subject to legal constraints. Privacy, banking secrecy, data localisation, employment law, criminal-procedure rules and suspicious-report confidentiality can affect what information can move, to whom, for what purpose and under what safeguards. Group policy does not automatically override local law.

A useful architecture is policy-aware rather than globally open. Each sensitive information object can carry source legal entity, jurisdiction, classification, purpose, recipient role and sharing restrictions. Access can then be granted based on policy. Where full detail cannot lawfully move, a permitted risk signal or instruction may still be shareable. The permitted design must come from legal analysis, not from technical convenience.

This is particularly important for suspicious-report information. Underlying transaction facts may in some circumstances be shareable while the fact or content of a regulatory filing is more restricted. A single global boolean such as isSAR = true is often too crude to model those differences.

15. Responding to an FIU or authority request should be a controlled workflow

Banks can receive follow-up requests from an FIU, legal orders from law enforcement or courts, supervisory data requests and private-sector RFIs. The first control is classification. Who is asking? Under what authority? For which legal entity? What exactly is requested? What deadline applies? What confidentiality or non-disclosure conditions exist? What data may lawfully be disclosed?

An FIU follow-up may be authorised by local AML law and may require response through a protected channel. A police or court order may need specialist validation of service, jurisdiction and scope. A supervisor may request aggregated information or case evidence under supervisory powers. A correspondent bank may ask about a payment under contractual and risk-management arrangements but generally does not thereby gain the right to a protected suspicious-report narrative.

FIU request workflow moving from validation of authority, scope and deadline through lawful collection and quality review to secure return and feedback.

A strong response record preserves the original request unchanged and separately records the bank’s interpretation. Structured search criteria should identify people, entities, accounts, products, date ranges, currencies, payment references or other scope. The evidence package should record which source systems were searched, the extraction version, product coverage, excluded records, reviewer sign-off, approvals, disclosure channel, transmission time and acknowledgement where applicable.

This becomes important during audit or litigation. Months later the bank may need to answer: exactly what was requested, which records were searched, which data was disclosed, who approved it and under what authority? An email chain and a manually filtered spreadsheet are poor evidence for that question.

A realistic failure illustrates the risk. An FIU requests transactions involving a customer and named beneficiary across six months. An analyst extracts one product from a legacy system and filters by exact beneficiary name. Three transactions from a newer payment rail and a transliteration variant are missed. The failure is not simply an analyst mistake. It is a coverage, lineage and reproducibility defect. A controlled workflow should know which sources and matching logic were used.

16. Data architecture determines whether cooperation is useful

International financial-crime work is fundamentally a relationship-and-lineage problem. A bank should be able to connect customer identifiers, beneficial owners, accounts, payment instruments, transactions, counterparties, financial institutions, alerts, cases, filing decisions, regulatory reports, external requests and evidence objects. Historical relationships should be preserved because the relevant question may be who owned or controlled an entity at the time of a transaction, not who owns it today.

Payment data is especially important. ISO 20022 can provide structured names, addresses, identifiers, parties, agents and references, but richer messages help only when data is populated accurately and preserved through internal transformations. If a structured beneficiary address is flattened into a legacy text field and later truncated, the investigation platform should not pretend the reconstructed value is the original source data.

Useful lineage records the source system, source record, extraction time, transformations and manual overrides. If an investigator corrects a beneficiary name, both the original and corrected value should remain available with the reason for change. If a reporting adapter transforms a case into an FIU schema, the version of the mapping should be reconstructable.

A simple data model can separate four related objects for authority responses: authority, request, evidence and response. The authority object records who can ask and the validated basis. The request object records what was asked. Evidence objects point to source records. The response object records what was actually released. Keeping them distinct supports legal review, minimisation, auditability and version control.

17. Governance must separate legal decision rights from system ownership

FATF, FIUs and international cooperation touch many bank functions. The first line owns customer and transaction activity and operates many controls. Specialist financial-crime investigators analyse alerts and cases. An MLRO or equivalent reporting role may have statutory or policy responsibilities that vary by jurisdiction. Compliance owns or oversees policy and challenges effectiveness. Legal interprets authority and disclosure constraints. Privacy and information-security teams govern sensitive data. Technology and data teams operate platforms, interfaces and lineage. Internal audit provides independent assurance. Senior management and boards oversee risk, resources and remediation.

Participation is not the same as accountability. A suspicious-reporting process needs a named decision authority. An external-authority response process needs validated approval rules. A reporting-channel outage needs a contingency owner. A policy exception needs an owner, rationale, expiry and escalation path.

System ownership should also be kept separate from control ownership. The technology team may own the reporting platform without deciding whether the legal reporting threshold is met. Compliance may own the reporting policy without owning the quality of source payment data. The business may own customer data without owning the FIU gateway. A RACI model helps only after these decision rights are understood.

18. Business-analysis and architecture requirements should be jurisdiction aware

A weak requirement says, “The system shall support FIU reporting.” A useful requirement explains who, what, when, under which jurisdiction and with which evidence.

For example: when an authorised reporting officer approves a case for filing under Legal Entity A’s applicable framework, the platform should create an immutable filing version using the schema configured for that jurisdiction, validate mandatory fields, record the reporting trigger and decision timestamp, transmit through the approved channel, capture technical acceptance or rejection, preserve the authority reference, and retain a link to the originating case without exposing protected filing information to unauthorised users.

That requirement creates real design questions. Which schema version applies by submission date? Can a filing be edited after approval? How are missing mandatory fields handled? Can multiple cases contribute to one filing? Can one investigation lead to filings in more than one jurisdiction? How is a supplementary report linked? What happens if the portal is unavailable near a legal deadline? Which users can see that a filing exists? Which timestamp starts the clock? How is evidence exported without exposing unnecessary internal material?

A global architecture often benefits from a canonical internal model plus local adapters. Common concepts such as customer, account, transaction, case, filing and authority request can be represented consistently. Local adapters then implement report names, mandatory fields, deadlines, schemas, encryption, transmission protocols, acknowledgement handling and other jurisdiction-specific requirements.

The model should not invent global fields that have no meaning in some countries. A field such as consent_status, for example, is useful only where the applicable legal regime contains a relevant consent or defence mechanism. Elsewhere the field should not create a fictional process merely because another jurisdiction uses one.

19. Testing should prove the reporting and cooperation lifecycle, not only the screen

Financial-crime reporting and authority-response platforms are regulatory control systems. Testing should cover permissions, data completeness, jurisdiction logic, decision authority, transmission, acknowledgements, amendment history, duplicate prevention, deadlines, resilience and audit reconstruction.

Jurisdiction tests should confirm that the correct report type, schema, authority and timing logic are selected for the relevant legal entity and event. Data tests should confirm that required customer and transaction fields come from the correct sources and that missing data is visible rather than silently defaulted. Access tests should prove that unauthorised users cannot view protected filing information. Transmission tests should cover acceptance, rejection, timeout and retry, and should distinguish technical transmission from regulatory receipt.

Versioning tests should prove that supplementary or amended reports do not overwrite the original. Duplicate tests should prove that a retry after network failure does not create unintended duplicate filings. Time tests should cover time-zone boundaries and any jurisdiction-specific treatment of business days or holidays. External-request tests should prove that FIU, law-enforcement, supervisory, court and correspondent requests route through different decision rules.

Failure-mode testing is essential. What happens if the FIU portal is unavailable? If an acknowledgement is never returned? If the case-management queue is delayed? If encryption fails? If an authority request arrives for an entity that is not served by the receiving team? If a new payment product is missing from the authority-search index? The system should create controlled exceptions rather than depend on improvised manual workarounds.

User-acceptance testing should include investigators and reporting officers. A technically valid form can still be operationally poor if the user cannot understand the data source, cannot identify a failed filing or is encouraged to copy generic narrative text instead of documenting the facts of the case.

20. A cross-border case shows why no participant sees everything

Consider a fictional manufacturing company, Northbay Components Ltd, which has banked for four years with Bank A in Country A. Its stated business is importing industrial-control equipment for domestic customers. Historically it pays several established suppliers and receives local payments from domestic distributors.

Over six weeks, Northbay begins making larger transfers to a newly incorporated trading company in Country B. Payment descriptions say only “technical supplies”. The beneficiary is not on a sanctions list and screening produces no relevant match. The payments are within available funds, so the issue is not simply fraud or credit exposure.

Bank A’s monitoring nevertheless creates an alert because the beneficiary and corridor are new, values have risen and the pattern no longer aligns well with the expected profile. The investigator obtains invoices and shipping information. The documents are not obviously false, but descriptions are vague and some goods will be trans-shipped through Country C. The investigator also identifies a recent ownership change not yet reflected in the bank’s KYC profile.

After reviewing the available facts, Bank A reaches the applicable legal threshold for suspicion and files the required report with FIU A. The filing does not claim that Northbay committed money laundering or a proliferation offence. It describes the customer, ownership change, payment pattern, counterparties, documents reviewed and the reasons the explanation did not resolve the concern.

FIU A discovers that another domestic institution has reported a related shareholder moving funds through a separate company. FIU A sends a lawful request to FIU B concerning the new trading company. FIU B has reports from two local institutions showing rapid onward distribution to several entities, including one connected to an existing domestic investigation. FIU B shares permitted intelligence back through the relevant FIU cooperation framework.

FIU A disseminates relevant intelligence to a competent domestic law-enforcement authority. Investigators later obtain bank records through the appropriate legal process. Bank A’s authority-response team validates the request, extracts the defined record set, completes legal and quality review and sends the records through the approved channel.

The case demonstrates the boundaries. Bank A did not need to prove the entire criminal network before filing. FIU A could see information Bank A could not. FIU B’s intelligence did not authorise Bank A to access FIU B’s internal files. Law enforcement later obtained evidential records through a separate legal process. The original report was one part of an intelligence chain, not proof of guilt.

It also demonstrates why data quality matters. If Bank A omitted beneficiary account identifiers, ownership details, payment references or shipping-route information, FIU linking could be weaker. If the bank lost its internal case ID during reporting, the later legal response would be harder to reconstruct. Good cooperation begins with good source data.

21. Common failure modes

One common failure is treating FATF as the direct legal authority for every bank rule. This makes jurisdiction mapping weak and can turn international guidance into inaccurate local policy. The remedy is traceability from international standard to domestic implementation and internal control.

Another is treating increased monitoring as an automatic prohibition. FATF’s June 2026 statement explicitly rejects that interpretation. The bank may still apply stronger controls based on its documented risk analysis and local expectations, but the rationale should be stated accurately.

A third is “file and forget”. A suspicious filing does not automatically end the customer relationship or remove the need for ongoing monitoring. New activity may require further review, supplementary reporting, risk-rating changes or response to an FIU request. Relationship restriction or exit should follow the bank’s applicable legal and risk frameworks rather than the assumption that filing itself proves wrongdoing.

A fourth is poor narrative quality. Templates can help with consistency but can also produce paragraphs that repeat generic phrases and hide the facts. Reports should make the transaction chronology and unresolved concern understandable without overstating conclusions.

A fifth is excessive access. If protected reporting information is visible to every KYC, service, fraud and relationship-management user, the bank creates confidentiality and tipping-off risk. Need-to-know access should be designed, logged and periodically reviewed.

A sixth is failure to reconcile the bank’s case system with the external reporting channel. A case can be marked “submitted” while the FIU portal has rejected the filing. Technical acknowledgement and exception reconciliation are therefore control requirements, not convenience features.

A seventh is weak request classification. Routing FIU requests, police orders, supervisory enquiries and correspondent RFIs through one mailbox can cause over-disclosure, missed deadlines and inconsistent decisions.

An eighth is measuring volume instead of quality. More reports can reflect increased risk, broader detection, poor thresholds, duplicate filing or defensive behaviour. Useful management information needs context, timeliness, quality and control-failure measures.

22. Customer and operational impact must remain part of control design

Financial-intelligence cooperation often occurs behind the scenes, but customers experience the consequences. Payments can be delayed for investigation. Accounts can be restricted under a legal or risk decision. Correspondent RFIs can lead to requests for invoices or purpose information. A customer may receive limited explanation because disclosure restrictions apply.

The bank should minimise unnecessary harm while meeting its obligations. A suspicious filing is not proof that a customer is criminal. Restriction, rejection, freezing, exit and reporting are different outcomes with different legal or policy bases. Legitimate remittances, humanitarian activity, vulnerable customers and small businesses can be affected disproportionately by crude country or typology rules.

This is why the risk-based approach and accurate FATF list interpretation matter. Effective financial-crime control does not mean refusing every difficult relationship. It means understanding risk, applying proportionate measures, escalating unresolved concern and documenting the basis for the decision. Blanket de-risking can push activity into less transparent channels and damage legitimate access to finance.

Operations teams also need approved customer-communication patterns. They should know what can be explained, when complaints require escalation and when legal or compliance input is necessary. Customer treatment should be designed into the control, not added after a restriction has already caused harm.

23. What good looks like

A mature bank can explain the complete chain without reconstructing it from memory. It can show which global standard influenced its policy, which local legal source created the obligation, which entities and products are in scope, how suspicion is escalated, who can make the filing decision, what data was submitted, when the authority received it, who can access it, how failures are reconciled and how subsequent requests are linked.

Its country-risk model distinguishes FATF monitoring from sanctions prohibitions. Its investigation platform distinguishes internal cases from regulatory filings. Its external-request workflow distinguishes FIU, law-enforcement, court, supervisory and correspondent requests. Its group information sharing is purposeful and legally controlled. Its investigators understand that a suspicious report communicates suspicion rather than guilt. Its technology teams understand that a successful API response is not enough unless the regulatory outcome is captured and reconciled.

Management information supports that model. Useful measures can include time from the legally relevant decision point to submission, portal rejection rate, unresolved technical failures, filings requiring correction, supplementary-report volumes, quality-review findings, FIU follow-up requests, cases approaching deadlines and access-control exceptions. Every metric needs a clear definition of start event, end event and purpose.

The strongest programmes treat cooperation as part of an intelligence lifecycle rather than a compliance paperwork exercise. High-quality data leaves the institution through a lawful channel. Public-sector intelligence, typologies and requests return through controlled mechanisms. Those insights improve monitoring, KYC and investigations. The system becomes more effective because the learning loop is connected.

24. Practical review questions

Before calling this capability mature, a bank should be able to demonstrate that each reporting and cooperation requirement is mapped to the applicable legal entity, jurisdiction and source; that the current FATF standard is understood without treating FATF as the direct regulator; that technical compliance and effectiveness are tested separately; that FATF increased monitoring, FATF calls for action and sanctions restrictions are not conflated; and that investigators can write evidence-based reports without asserting unproven criminality.

It should also be able to demonstrate that report type, deadline, confidentiality controls and submission schema are jurisdiction aware; that transmission and authority receipt can be reconciled; that protected reporting information is restricted; that external requests are classified by requester and authority; that customer, payment and filing lineage can be reconstructed; that intelligence is distinguished from evidence; that cross-border sharing is controlled by applicable law; and that regulatory change routes through policy, technology, testing and operations with an auditable effective date.

Finally, resilience should be tested. Portal outages, queue failures, duplicate retries, amendments, expired authority credentials, ambiguous data scopes and new payment products should all produce controlled outcomes. A financial-crime programme is not mature because its happy path works. It is mature when the difficult paths are understood before they occur.

25. Key takeaways

FATF provides the international architecture; national and regional frameworks create the obligations a bank must execute. Mutual evaluations test both formal compliance and real effectiveness at jurisdiction level. FATF public statements are important country-risk information but should not be confused with sanctions law or automatic customer prohibition.

FIUs are national centres for receiving, analysing and disseminating financial intelligence, but their institutional models and powers differ. Suspicious reports are intelligence inputs, not findings of guilt. Egmont cooperation allows FIUs to exchange information under controlled frameworks, while law enforcement, mutual legal assistance, supervision and private-sector exchange operate through different channels.

For a bank, the core challenge is controlled information movement. Customer and payment data must remain linked to alerts, cases, filing decisions, regulatory reports, authority requests and evidence. Jurisdiction, legal basis, purpose, permissions, timestamps, acknowledgements and audit history should survive every hand-off.

For compliance professionals, investigators, operations teams, business analysts, architects, developers and testers, the same principle applies: understand who has authority, what information is needed, which legal framework governs the action, what evidence proves the control worked and what must remain confidential. International cooperation becomes useful only when those boundaries are preserved.

Deep practitioner expansion: how the international AML/CFT system works in practice

The international financial-crime framework can look abstract until it is translated into an actual bank workflow. FATF publishes standards. Countries implement those standards through domestic law. Supervisors assess financial institutions. Banks identify and report suspicious activity. Financial intelligence units receive, analyse and disseminate information. Law-enforcement agencies investigate crime. Courts and other authorities may freeze, confiscate or otherwise act on criminal assets. International cooperation connects those national processes when people, money, assets or evidence cross borders.

A bank sits inside this system, not outside it. Customer due diligence, transaction monitoring, sanctions controls, case investigations and suspicious reporting are all mechanisms through which the private sector contributes information and control to a wider public system.

That is why the quality of bank data matters beyond the bank. A poorly structured suspicious report, missing beneficiary details, weak beneficial-ownership records or broken transaction lineage can reduce the usefulness of financial intelligence to public authorities.

FATF standards: global architecture, local law

FATF’s Recommendations are the international standard for combating money laundering, terrorist financing and proliferation financing. They do not create one universal legal code.

Countries have different legal systems, institutional structures and financial markets. FATF therefore sets the expected outcomes and core measures while allowing implementation to be adapted to national circumstances.

For a global bank, this produces a layered policy model.

At the top sits the international standard. The bank then maps each country’s law and regulation. A group policy may establish a common minimum. Local procedures translate that policy into operational steps. Systems and controls implement the procedure. Evidence demonstrates that the control worked.

A good requirement can be traced through this chain.

Why this traceability matters

Suppose a project team is asked to add a new data field to suspicious-reporting workflows. The team should know whether the field is required by law, by the FIU submission schema, by internal policy or simply by an operational preference.

That distinction matters for prioritisation, testing and change control. A legally mandatory field cannot be dropped because a user finds it inconvenient. An internal optional field can be redesigned if it adds little value.

Requirements should therefore carry a clear source and rationale.

FATF Recommendation 1 and national risk understanding

Recommendation 1 establishes the risk-based approach. Countries should identify, assess and understand money-laundering, terrorist-financing and proliferation-financing risks and apply measures proportionate to those risks.

Banks sit downstream from that national risk understanding. National risk assessments can influence supervisory priorities, sector guidance and bank risk assessments.

A bank should not copy a national risk assessment mechanically. It should ask how the identified risks affect its own customers, products, geographies and transaction flows.

For example, if a country identifies fraud proceeds and mule accounts as a major threat, a bank with large instant-payment volumes may need stronger mule detection, beneficiary-risk controls and cross-bank fraud intelligence.

FATF Recommendations as a practical map

The Recommendations cover far more than suspicious reporting.

They address national coordination, criminalisation of money laundering, confiscation, terrorist financing, targeted financial sanctions, customer due diligence, record keeping, politically exposed persons, correspondent banking, new technologies, wire transfers, internal controls, higher-risk countries, suspicious reporting, beneficial ownership, supervision, financial intelligence units, law enforcement and international cooperation.

This breadth explains why financial-crime programmes cross so many bank functions.

KYC supports customer due diligence and beneficial ownership. Payment systems support wire-transfer transparency. Sanctions systems support targeted financial sanctions. Case management supports investigation and reporting. Governance and audit support internal controls. Data retention supports later law-enforcement requests.

Mutual evaluations: technical compliance versus effectiveness

FATF and FATF-style regional bodies assess jurisdictions through mutual evaluations.

Two concepts matter.

Technical compliance asks whether the necessary laws, regulations, authorities and formal requirements exist.

Effectiveness asks whether those measures work in practice.

This distinction should be familiar to banks. A bank can have an AML policy on paper and still be ineffective if customer data is poor, transaction monitoring misses risk, investigators lack capacity or suspicious reports are low quality.

A country can face the same problem at national level.

Why mutual evaluations matter to banks

Evaluation reports can provide useful information for country-risk assessment. They can show weaknesses in supervision, beneficial ownership, FIU capability, prosecution, confiscation, terrorist-financing controls or other areas.

The report should be read for substance rather than reduced to one country score.

A weakness in beneficial-ownership transparency may be particularly relevant to corporate customers. Weak terrorist-financing controls may matter to remittance activity. Weak supervision may affect correspondent banking decisions.

FATF public statements and monitored jurisdictions

FATF publishes lists of jurisdictions under increased monitoring and high-risk jurisdictions subject to a call for action.

The official wording matters.

A jurisdiction under increased monitoring has committed to address identified strategic deficiencies under an action plan. FATF explicitly states that increased monitoring does not itself call for automatic enhanced due diligence and does not support cutting off entire customer classes. Institutions should incorporate the information into risk analysis and respond proportionately.

High-risk jurisdictions subject to a call for action can require stronger measures. FATF’s June 2026 statements distinguish the measures applicable to specific jurisdictions.

For banks, the control should consume the current official FATF statement rather than rely on stale labels such as “grey list” or “black list.”

Financial intelligence units: the national intelligence hub

FATF Recommendation 29 requires countries to establish an FIU that acts as a national centre for receipt and analysis of suspicious transaction reports and other relevant information and for dissemination of the results of that analysis.

The three words receipt, analysis and dissemination are central.

The FIU receives information from reporting entities. It analyses that information, often combining multiple sources. It disseminates relevant intelligence to competent authorities under the national framework.

This is much more than a filing mailbox.

Why FIUs can see more than banks

One bank may see one account. Another bank sees another account. A payment service provider sees an additional leg. A customs authority may have trade data. Law enforcement may have an investigation. A company registry may hold ownership information.

The FIU can bring some of these information sources together.

That is why suspicious reports should contain clear identifiers and explanations. The FIU’s ability to connect reports depends partly on data quality.

Suspicious reporting: the quality of the narrative

A suspicious report should explain the reason for suspicion, not simply repeat transactions.

A useful report describes who is involved, what happened, when it happened, why the activity is unusual, which transactions matter, what the bank knows about the customer, what explanation was provided, what connected parties exist and what action the bank took where disclosure is legally permitted.

Consider two narratives.

The weak version says: “Customer made several suspicious international transfers.”

The stronger version says: “Between 4 and 8 August, a newly opened consulting company received 27 credits from unrelated retail customers totalling EUR 184,000 and transferred EUR 171,000 within 90 minutes of receipt to two companies in another jurisdiction. This activity is inconsistent with the customer’s stated business of domestic IT consulting and expected monthly turnover of EUR 20,000. The customer was unable to provide contracts explaining the third-party credits.”

The second version provides facts that another analyst can use.

Reporting thresholds vary by jurisdiction

Terms such as SAR, STR and UTR are not interchangeable global rules. Jurisdictions use different names, legal thresholds, deadlines, forms and reporting channels.

A global bank therefore needs a jurisdiction-aware reporting process.

The workflow should determine which legal entity owns the customer or activity, which country’s reporting obligation applies, which FIU receives the report, which deadline applies, which approval is required and which confidentiality rules govern the case.

A single global deadline hard-coded into the case system is risky unless it is merely an internal standard that is always shorter than every applicable legal deadline.

Supplemental reporting

Some jurisdictions allow or require supplemental filings when additional relevant information becomes available after the initial report.

A case system should therefore be able to link follow-up information to the original report, preserve submission history and track acknowledgements.

The bank should not treat filing as the end of the investigation lifecycle.

Tipping off and confidentiality

Suspicious-reporting regimes often restrict disclosure to the customer or other unauthorised persons.

This creates a difficult operational problem when the bank needs to ask questions, delay activity or restrict an account.

Customer communication must be designed carefully. A front-line message should not reveal that a suspicious report was filed or that law enforcement is involved where disclosure is prohibited.

Case-management systems should also restrict access. Not every employee who can view an ordinary customer complaint should be able to see suspicious-reporting decisions.

FIU feedback

FIUs may provide typologies, strategic reports, red flags and feedback to reporting institutions.

Banks should use this feedback to improve detection and investigation.

If an FIU highlights a new scam typology, the bank can assess whether transaction monitoring, fraud controls or customer education should change. If public authorities identify particular corporate structures used in laundering, beneficial-ownership reviews can be strengthened.

This creates a feedback loop from public intelligence back into private controls.

Supervisors: testing the bank’s framework

Supervisors assess whether financial institutions meet applicable obligations and manage financial-crime risk effectively.

Supervisory review can include governance, risk assessment, customer due diligence, transaction monitoring, sanctions, suspicious reporting, data quality, model governance, staffing, training, quality assurance and remediation.

The Basel Committee’s 2026 consolidated AML/CFT guidance emphasises that money-laundering and terrorist-financing risk should sit within the bank’s overall risk-management framework and highlights the importance of group-wide and cross-border controls, supervisors and correspondent banking.

Supervisory evidence

A supervisor may ask not only what the policy says but how the bank knows the control works.

Evidence can include system configuration, sample cases, customer files, transaction data, QA results, model validation, committee minutes, risk assessments, training records and remediation plans.

This is why “we have a policy” is never enough.

Law enforcement: investigation and evidence

Law-enforcement agencies investigate criminal offences and may obtain bank information through legally authorised processes such as production orders, subpoenas, warrants or local equivalents.

The bank needs a controlled legal-request process.

Requests should be validated for authenticity and scope. Relevant data should be collected accurately. Access should be restricted. Responses should be logged. Preservation requirements should be followed.

The process should distinguish law-enforcement requests from ordinary customer-service enquiries.

Preservation of evidence

A legal request may arrive long after the transaction occurred.

The original relationship manager may have left the bank. Systems may have migrated. Payment formats may have changed.

The bank therefore needs records that remain reconstructable.

Stable customer identifiers, transaction references, payment messages, account entries, KYC evidence, beneficial-ownership records and case audit trails can all become important.

Technology migration should never silently destroy legally required historical evidence.

Public-private partnerships

Many jurisdictions have developed public-private partnerships to improve financial intelligence sharing.

These arrangements can allow authorities and financial institutions to share typologies or more specific intelligence under controlled legal frameworks.

The benefits can be significant because banks receive more targeted information and authorities receive richer private-sector insight.

But information sharing must be lawful. Privacy, confidentiality, data-protection and tipping-off restrictions still apply.

The correct design is not “share everything.” It is “share the right information through authorised channels with appropriate safeguards.”

FIU-to-FIU cooperation and the Egmont Group

Financial crime crosses borders, so FIUs need ways to cooperate.

The Egmont Group supports cooperation among member FIUs and secure exchange of financial intelligence.

For the reporting bank, this cooperation may be invisible. The bank files domestically. The FIU can then exchange intelligence with a foreign counterpart where the legal framework permits.

Good identifiers improve the chance that reports from different countries can be connected.

Mutual legal assistance

Mutual legal assistance is a formal mechanism through which countries request assistance in criminal matters.

Requests can relate to evidence, searches, freezing, confiscation or other judicial cooperation.

These processes are typically slower and more formal than FIU intelligence exchange.

The difference is useful for bank practitioners: FIU cooperation supports intelligence; mutual legal assistance supports formal legal processes and evidence under applicable treaties and laws.

Extradition and international enforcement

FATF Recommendations also address extradition and international cooperation between competent authorities.

Banks do not manage extradition, but they may hold financial evidence relevant to cross-border cases.

Again, data retention and reconstructability matter.

Correspondent banking: why transparency matters internationally

Correspondent banking is central to cross-border payments because one bank can provide accounts and services to another bank.

The correspondent may not know the respondent’s underlying customers directly. It relies partly on the respondent’s controls while applying its own AML/CFT and sanctions obligations.

This creates a chain of trust and evidence.

The correspondent should understand the respondent’s business, regulatory status, ownership, products, customer base, geographies and AML controls. The respondent should provide transparent payment information and answer due-diligence questions.

Nested relationships and payable-through accounts can create additional risk because activity may originate from institutions or customers further down the chain.

Payment transparency and Recommendation 16

Payment transparency is a major part of the international AML/CFT system.

Originator and beneficiary information allows institutions and authorities to understand who is sending and receiving funds.

FATF Recommendation 16 addresses wire transfers and is undergoing significant modernisation. The current FATF Recommendations page should be treated as authoritative because implementation dates and detailed requirements evolve.

For banks migrating to ISO 20022, the practical opportunity is richer structured party data. But richer formats only help if data is populated accurately, preserved across intermediaries and made available to screening and investigations.

A payment message with excellent data that is truncated in an internal interface provides little benefit.

ISO 20022 and investigations

Structured ISO 20022 data can improve investigation by separating names, addresses, identifiers, parties and agents more clearly than older free-text formats.

However, mapping is critical.

If a bank transforms incoming structured data into an internal legacy record and later reconstructs a message, investigators may not see the original values. Original and transformed values should be distinguishable where relevant.

Payment lineage should connect initiation, screening, clearing, settlement, booking, returns and investigations.

This becomes especially important when authorities request the original payment information months later.

Cross-border case example: multi-bank fraud network

Victims at Bank A send scam payments to accounts at Bank B. Bank B customers immediately send funds to Bank C in another country. Bank C customers purchase virtual assets.

Bank A sees victim complaints and outbound transactions. Bank B sees mule behaviour. Bank C sees international consolidation and conversion.

Each bank may file a report in its own country.

The FIUs can combine the reports, connect identifiers and exchange intelligence internationally. Law enforcement may then request records through formal channels.

The value of the system comes from combining partial views.

Cross-border corruption example

A company in Country X wins a public contract. It sends consulting fees to a company in Country Y. That company sends funds to a property vehicle in Country Z controlled by a relative of a public official.

The banks hold payment data. Corporate registries hold ownership data. Procurement authorities hold contract information. An FIU may receive several reports. Law enforcement may hold witness evidence.

No single actor sees the whole case initially.

International cooperation allows those pieces to be combined.

Cross-border terrorist-financing example

A group of individuals in several countries sends small amounts to a common intermediary. The amounts are not unusual on their own. One FIU has intelligence linking the intermediary to a designated network.

That intelligence can change the significance of otherwise ordinary payments.

This case demonstrates why CFT cannot rely on transaction value alone and why information sharing matters.

Sanctions authorities and FIUs are not the same

Banks should distinguish FIUs from sanctions authorities.

An FIU receives and analyses financial intelligence. A sanctions authority administers sanctions measures, licences and reporting under the relevant legal regime. A supervisor assesses institutional compliance. Law enforcement investigates offences.

In some countries one institution may perform multiple functions, but the workflows remain legally distinct.

A sanctions blocking report should not automatically be treated as a suspicious transaction report unless the applicable law requires both.

Central banks and payment-system authorities

Central banks can also play several roles. They may supervise banks, operate or oversee payment systems, implement monetary policy or act as national competent authorities for particular rules.

Project teams should avoid generic labels such as “send to regulator.” The exact authority and reporting channel matter.

Data protection and international information sharing

Financial-crime information is sensitive.

Global banks often want to centralise investigations and share customer data across borders. That can improve detection, but privacy and banking-secrecy laws may restrict what can be transferred.

The bank needs a legal framework for group-wide information sharing, access control, retention and purpose limitation.

The Basel Committee’s AML/CFT guidance recognises the importance of group-wide and cross-border management while acknowledging legal constraints.

A system should therefore support jurisdiction-specific restrictions rather than assume all case data can be globally visible.

The three lines in regulatory interaction

The first line owns much of the operational evidence. Compliance often coordinates supervisory responses on financial-crime matters. Internal audit provides independent assurance.

During a regulatory examination, all three may contribute.

A strong bank maintains one coherent evidence base rather than producing conflicting numbers from different teams.

Regulatory examinations

A supervisor may ask for customer files, alert samples, sanctions cases, risk assessments, model documentation, committee minutes or remediation evidence.

The bank should have a controlled process for responding.

Requests need owners, deadlines, version control and quality review. Responses should be factual and consistent.

Ad hoc email chains are a weak way to manage major regulatory examinations.

Enforcement and remediation

When authorities identify material deficiencies, the bank may need a remediation programme.

That programme can include customer-file refresh, transaction-monitoring redesign, sanctions tuning, data remediation, model validation, governance changes, staffing and independent testing.

Remediation should address root cause rather than only close individual findings.

For example, if missing beneficial-ownership data affects thousands of customers, fixing five sampled files does not solve the control weakness.

Suspicious reporting technology

A robust reporting platform should support jurisdiction-specific templates, mandatory fields, legal-entity selection, approval workflow, filing deadlines, secure submission, acknowledgements, amendments or supplemental filings and retention.

It should also protect confidentiality.

The system should know which users can see the filing decision and which downstream systems must not expose it.

Validation

Submission should include technical and business validation.

Technical validation checks required format and field constraints. Business validation checks whether required narrative and case data are present.

A technically valid empty-quality narrative is still a poor report.

Reporting deadlines and clocks

Different jurisdictions define reporting clocks differently.

Some deadlines may run from detection, determination of suspicion, transaction date or another event.

Case systems should therefore store the legally relevant trigger and calculate the deadline accordingly.

If a global bank uses one generic “case opened date,” it may miscalculate the deadline.

Management information for reporting

Useful reporting MI can include:

  • reports filed by legal entity and typology;
  • filing timeliness;
  • overdue decisions;
  • supplemental filings;
  • FIU feedback;
  • quality-assurance results;
  • key data-quality defects;
  • law-enforcement follow-up;
  • conversion from alerts to cases to reports;
  • geographic and product trends.

Volumes alone are not evidence of effectiveness.

Effectiveness and FATF Immediate Outcomes

FATF’s assessment methodology evaluates whether AML/CFT systems achieve effective outcomes, not merely whether laws exist.

That philosophy is relevant inside banks.

The bank should ask whether financial-crime controls identify meaningful risk, whether suspicious reports are useful, whether higher-risk customers receive appropriate attention and whether weaknesses are corrected.

A programme can be compliant on paper and ineffective in practice.

Business analyst view of the full reporting chain

A BA should map the reporting process end to end.

  1. What creates the investigation?
  2. Which customer, account and transactions are in scope?
  3. Which legal entity owns the relationship?
  4. Which jurisdiction’s law applies?
  5. What threshold must be assessed?
  6. Who can decide that the threshold is met?
  7. Who approves the filing?
  8. Which FIU or authority receives it?
  9. Which form or schema applies?
  10. What is the deadline trigger?
  11. Which data is mandatory?
  12. How is the narrative created?
  13. How is confidentiality protected?
  14. How is submission acknowledged?
  15. How are supplemental reports handled?
  16. What customer communication is permitted?
  17. What records must be retained?
  18. How does external feedback re-enter monitoring and risk assessment?

If any of those questions is undefined, the operating model has a gap.

Architecture view

Architects should ensure that jurisdiction, legal entity and authority are explicit data attributes.

The case platform should not infer them from user location or a generic business-unit code.

Payment identifiers, customer identifiers, report identifiers and authority acknowledgements should be linked.

External submission interfaces should be resilient and auditable.

Failures should create visible exceptions, not silent data loss.

Testing cross-border reporting

Testing should include more than one jurisdiction.

Scenarios should cover different report forms, different deadlines, different legal entities, multilingual data, incomplete identifiers, supplemental filings, authority acknowledgements, resubmission after technical rejection and restricted user access.

A system that works only for the home-country FIU is not a global reporting platform.

Quality assurance of suspicious reports

QA should assess factual accuracy, relevance, chronology, clarity, completeness and consistency with the case evidence.

Common weaknesses include unsupported conclusions, missing key transactions, unexplained abbreviations, vague references to “suspicious behaviour,” contradictory dates and poor explanation of why the activity differs from expected behaviour.

A good report should allow an external analyst to understand the story without access to the bank’s internal case system.

Public-private intelligence feedback into controls

The strongest programmes use external intelligence actively.

If authorities publish a typology on human trafficking, the bank should assess whether its customer segments and monitoring cover the indicators. If a sanctions authority publishes new evasion methods, screening and trade controls may need review. If an FIU highlights mule-account behaviour, fraud and AML teams should respond together.

The control environment should evolve with the threat environment.

Country risk and unintended consequences

FATF’s June 2026 materials emphasise proportionality and avoiding unnecessary disruption of legitimate humanitarian and remittance flows.

Banks should therefore distinguish high-risk-country exposure from automatic prohibition.

Some jurisdictions require enhanced measures; others require risk analysis. Sanctions rules may create additional restrictions. Humanitarian exemptions may apply.

The control should reflect the exact legal and risk context.

Record keeping and auditability

International cooperation depends on records that survive time and system change.

A bank should preserve the data required by law and policy, including customer identity evidence, ownership information, account history, relevant payment records, case decisions, reports and audit logs.

When systems are decommissioned, retention obligations should be part of migration planning.

Practitioner review questions

A reader should be able to explain why FATF standards are not identical to national law, the difference between technical compliance and effectiveness, why an FIU is more than a filing mailbox, why suspicious reports should contain narrative rather than transaction lists, why reporting workflows must be jurisdiction-aware, why public-private partnerships require legal safeguards, how correspondent banking creates indirect visibility, why ISO 20022 data lineage matters and why a bank’s evidence-retention design affects future international investigations.

If those answers are clear, the reader understands the bank’s place in the international AML/CFT system.

Advanced practice: cooperation as a governed data and decision service

A bank usually discovers that international cooperation is difficult not because the concept is unclear, but because the information is spread across legal entities, systems and teams that were designed for different purposes. The same customer can appear under several internal identifiers, the same payment can be represented differently in the channel, payment hub, sanctions engine and general ledger, and the same external authority can contact the bank through more than one route. A mature operating model therefore treats cooperation as a governed service with defined decision rights, data lineage and evidence standards rather than as a collection of exceptional emails.

Build an authority and legal-gateway matrix before automating

The starting point is an authority matrix. For each legal entity, the bank should know which FIU receives suspicious reports, which supervisor has AML/CFT oversight, which sanctions authority administers relevant measures, which law-enforcement or judicial bodies can compel records, and which cross-border or group information-sharing gateways are available. The matrix should record the source of authority, the type of information that can be requested or shared, approval requirements, confidentiality conditions, response channel and any restriction on onward dissemination.

This is not a static organisational chart. It is decision data. When a request arrives, the workflow should use the requesting authority, legal entity, jurisdiction and request type to select the correct rule set. A request from an FIU asking for additional information after a suspicious report may follow one route. A court order seeking historical statements may require legal validation and document preservation. A foreign group compliance team asking for underlying transaction facts may require a privacy and secrecy assessment. A correspondent bank asking about payment purpose may be answered under contractual and AML risk-management arrangements without revealing protected regulatory-report information.

The advantage of the matrix is consistency. Without it, employees often solve the same legal-routing question repeatedly. Different teams can reach different answers, creating both over-disclosure and under-disclosure risk. The matrix should therefore be version controlled and linked to regulatory-change management. When legislation, FIU powers or a reporting portal change, the bank should know which workflows, interfaces, procedures and test cases are affected.

Make request provenance machine-readable

A useful authority-response case should preserve provenance as structured data. At minimum, the case should identify the requester, authority type, jurisdiction, external reference, received timestamp, channel, legal or contractual basis, affected bank legal entity, requested period, subjects, accounts or transactions, response deadline, confidentiality classification and approval status. The original request should remain attached unchanged.

Structured provenance improves both operational quality and later investigation. If a response is challenged, the bank can show exactly which request was received and how it was interpreted. It also enables automation without hiding judgement. A workflow can flag an expired deadline, wrong legal entity or missing authority identifier, but it should not invent a legal basis where none has been validated.

The same principle applies to information received from another authority or FIU. The source and permitted use should remain attached to the intelligence. If onward dissemination requires consent, the record should carry that condition. If the information can be used only for a defined purpose, access controls and exports should reflect that restriction. Copying sensitive material into ordinary customer notes destroys this context and can expose it to users who were never authorised to see it.

Separate discovery, collection, review and disclosure

Authority-response processes become more auditable when four stages are distinct. Discovery identifies potentially responsive records. Collection retrieves those records from source systems. Review determines whether the records fall within scope and whether redaction, minimisation or legal review is needed. Disclosure creates the final package that is actually transmitted.

This separation matters because search results are not the same as disclosed evidence. A broad search may identify hundreds of records while only a defined subset is responsive to the request. The bank should preserve enough information to reconstruct why records were included or excluded. If an analyst manually changes the scope, the reason should be recorded rather than disappearing in a spreadsheet filter.

For technology teams, this suggests separate objects or statuses for search criteria, evidence candidates and released records. It also suggests immutable versioning for the final response package. If a supplemental response is sent later, it should be linked as a new version rather than silently replacing the original. Hashes, package IDs or other integrity controls can help demonstrate that the retained copy matches what was transmitted.

Use payment identifiers to make cross-border intelligence joinable

International cooperation often succeeds or fails on identifiers. Names alone are weak because spelling, transliteration, abbreviations and corporate naming conventions vary. Payment references, account identifiers, customer IDs, legal-entity identifiers, dates, amounts, currencies, agent details and message references can make separate reports joinable.

ISO 20022 can improve this position because it supports structured party and agent information, but only if the bank preserves the data. A common failure is to receive a rich payment message, flatten it into a legacy internal record, screen the flattened representation and later use that degraded record for investigation or regulatory reporting. The bank should retain the original message or an evidential representation, document transformations and make important original values available to investigators.

Unique references are particularly valuable. A UETR or other transaction reference can help connect payment events across systems. Internal case systems should not generate a new local identifier and then lose the relationship to the originating payment. The objective is not to expose every payment field to every investigator; it is to preserve traceability so the right evidence can be obtained when needed.

Treat FIU feedback as a controlled change input

FIU and law-enforcement feedback can improve bank controls, but only when it enters a governed change process. A typology bulletin, request pattern or recurring feedback about poor report quality should be assessed for relevance to the bank's products, customers and geographies. The response may involve investigator guidance, new data fields, scenario tuning, KYC changes, training, or a decision that no change is required.

The key is traceability. The bank should be able to show which external intelligence was considered, who assessed it, what decision was made and how any change was tested. A typology should not be converted mechanically into a monitoring rule. Public intelligence can be broad, and a bank may not possess the data needed to detect the behaviour reliably. Scenario design should test data availability, expected population, false-positive risk and the relationship between the indicator and the underlying threat.

Feedback can also expose reporting-data weaknesses. If an FIU repeatedly requests missing beneficial-owner details, payment references or counterparty addresses, the bank should not treat every request as an isolated operational inconvenience. The pattern may indicate that the filing model or source-data architecture needs improvement.

Design a resilience path for statutory or authority deadlines

External reporting and response channels can fail. Portals can be unavailable, certificates can expire, network connections can break and internal queues can become backlogged. A resilient design defines what happens before the failure occurs. The contingency should identify who is alerted, whether an alternative approved channel exists, how legal deadlines are assessed, what evidence of the outage is retained and how delayed submissions are reconciled after service restoration.

The system should distinguish a bank-side failure from an authority-side outage. It should also distinguish transmission from receipt. A file placed in an outbound queue is not necessarily a completed filing. Where acknowledgements are provided, unreconciled submissions should remain visible until the bank has evidence of the external result or has followed the approved exception process.

Testing should cover expiring credentials, rejected schemas, duplicate retries, partial response packages, incorrect legal-entity routing, missing source-system coverage and time-zone boundaries. These are not exotic edge cases. They are the situations in which a well-written procedure is most likely to fail operationally.

Mini case: one request, three legal boundaries

Assume Bank Group G has entities in Countries A, B and C. A customer of Entity A sends funds to a beneficiary at Entity B. Entity C hosts the group's central investigation platform. FIU A asks Entity A for information about the customer and the transfer. At the same time, the group investigation team in Entity C wants the full case because the beneficiary has appeared in another investigation.

The payment data may be visible centrally, but that does not answer the legal questions. Entity A must determine the authority and scope of FIU A's request under Country A law. The group must separately determine what information can be shared with Entity C and whether protected filing information is subject to additional restrictions. Entity B may hold beneficiary information that Entity A does not possess and may need its own lawful basis or domestic process before information is transferred.

A strong workflow therefore creates three linked but distinct decisions: the response to FIU A, the internal group-sharing decision, and any request to Entity B. The platform can connect the cases without pretending the legal basis is the same. Each disclosure has its own authority, purpose, approver and evidence trail.

For a business analyst, the acceptance criteria should prove this separation. The system should not allow a central investigator's access rights automatically to authorise external disclosure. It should not allow an FIU request served on Entity A to be treated as a direct order to Entity B. It should preserve the source of every record and the approval for each transfer. This is how an enterprise platform can support international cooperation without erasing legal-entity boundaries.

The practitioner test

A mature capability should answer five questions quickly. Who is asking? Under what authority or permitted purpose? Which legal entity owns the response? Which exact data is responsive and where did it come from? What evidence proves what was disclosed and when? If any of those answers depends on personal memory, an unmanaged mailbox or a spreadsheet with no version history, the cooperation process remains operationally fragile.

Further worked cases and independent practice

These cases explain how reporting and international cooperation work without confusing standards, supervisors, financial intelligence units, law enforcement and sanctions authorities. Read the chapter and explanations first; allow additional time for the exercises and diagram interpretation. Exercise time is additional to the chapter's reading estimate.

FATF sets standards; national systems create obligations

FATF's Recommendations provide the global AML/CFT and proliferation-financing framework. Countries implement that framework through legislation, regulation, competent authorities and supervision. The binding obligation for a bank therefore comes from the legal and regulatory framework applicable to the bank's legal entity and activity, not from a simplistic assumption that every FATF sentence operates identically as domestic law.

This distinction matters when requirements are written. A global standard can say that suspicious transactions should be reported to an FIU. The exact reporting threshold, report type, filing clock, confidentiality rule, responsible legal entity and technology channel are local implementation details. A global bank needs common principles plus jurisdiction-specific mapping.

What an FIU actually does

A financial intelligence unit commonly receives financial intelligence such as suspicious-transaction or suspicious-activity reports, analyses information and disseminates relevant intelligence to competent authorities. The precise structure and powers differ by jurisdiction. Some FIUs sit within finance ministries, police structures, regulators or independent bodies. The operational lesson for a bank is that the FIU is not simply a mailbox for alerts and is not automatically the same as the bank's prudential supervisor, sanctions authority or criminal-investigation agency.

A suspicious report is also not a conviction. It is an intelligence input. A bank should write reports that explain who is involved, what happened, why the activity is suspicious, what values and dates matter and how the transactions can be traced. Vague statements such as "unusual activity detected" create little intelligence value.

Worked case: cross-border fraud proceeds

Victims in Country A send funds to accounts in Country B. Those accounts consolidate value and transfer it through a payment institution in Country C before value reaches accounts and virtual-asset services in Country D. Each institution sees only part of the network.

The banks in Countries A and B can generate fraud and AML intelligence. Their respective FIUs may receive reports under local law. FIUs can exchange information through appropriate international channels, while law-enforcement authorities may use mutual legal assistance, production orders, freezing mechanisms or other legal processes to obtain evidence and assets. None of this means banks should exchange protected suspicious-reporting information informally without legal authority.

The case demonstrates why transaction identifiers, timestamps, originator/beneficiary data, ownership information and account relationships are essential. International cooperation becomes slower and less effective when records are fragmented or payment data is lost during transformations.

FIU feedback and control improvement

Useful FIU or law-enforcement feedback can reveal typologies, priority threats, reporting-quality problems or data fields that materially improve investigations. A mature bank has a controlled way to turn that feedback into scenario changes, investigator guidance, KYC updates and training rather than leaving it inside one compliance team's mailbox.

Feedback should not be treated as a substitute for the bank's own risk assessment. A law-enforcement priority can influence focus, but the bank still needs coverage for its own customers, products, geographies and legal obligations.

Mutual evaluations: technical compliance versus effectiveness

FATF mutual evaluations distinguish whether a jurisdiction has the required legal and institutional framework from whether the system is effective in practice. This is an important learning point for banks. A policy can exist without working. A bank can have a screening procedure, monitoring scenarios and reporting governance but still fail if data is incomplete, alerts are backlogged, analysts lack context or findings are not remediated.

When a country appears on a FATF public list, banks should read the actual statement and apply their risk-based framework. Increased monitoring is not the same as a universal transaction prohibition. FATF's call-for-action list carries a materially stronger risk signal and can be associated with enhanced measures or countermeasures according to the applicable framework. Country status is one input, not the whole customer decision.

Practice exercise — work through this before reading on.

Authority-mapping exercise

For one jurisdiction relevant to a bank, identify the FIU, AML/CFT supervisor, prudential supervisor if different, primary sanctions authority, relevant law-enforcement bodies and the central bank or payments authority. Then map five events: suspicious-activity report, sanctions blocking report, regulatory examination, criminal production order and urgent fraud recovery request.

The exercise should show that different events go to different authorities and carry different confidentiality, response and evidence rules. A case-management system should not use one generic "regulator request" status for everything.

Cross-border information sharing

Banking groups often need to share information across entities for risk management, investigations and group-wide AML/CFT controls. That need can conflict with bank secrecy, data localisation, privacy or suspicious-reporting confidentiality. A robust operating model identifies what data can be shared, for what purpose, under which legal basis, with which access controls and what to do when local law restricts group-wide visibility.

The answer is not to assume that global compliance always overrides local restrictions, nor to allow local fragmentation to create unmanaged risk. Legal and privacy specialists should help design lawful information-sharing patterns and escalation when information cannot move.

Practice exercise — work through this before reading on.

Reporting-quality exercise

Take a hypothetical report with the sentence "customer conducted suspicious transfers to multiple countries." Rewrite it into an intelligence-quality narrative: identify the customer, relationship, relevant period, total value, number of transactions, counterparties, transaction sequence, ownership links, departure from expected activity, customer explanation, evidence checked and the reason suspicion remains.

Then remove every conclusion that is not supported. The report should be useful without pretending the bank has proved the crime.

Final effectiveness test

Explain the difference between FATF, an FIU, a supervisor, law enforcement and a sanctions authority. Explain why a mutual evaluation is not a bank audit but can still affect country-risk understanding. Explain why an FIU report is intelligence rather than proof. Finally, describe how a bank should react when a jurisdiction's FATF status changes without automatically exiting every customer connected to that country.

The strongest learner should be able to connect global standards to local law, local reporting to FIU analysis, FIU intelligence to law-enforcement action and all of those elements back to better bank controls.

References and further reading

The sources below are public, authoritative materials used for the standards, FIU, effectiveness and international-cooperation concepts in this chapter. FATF standards and public statements evolve, and reporting powers, filing thresholds, deadlines, confidentiality restrictions and disclosure permissions are jurisdiction-specific. Practitioners should therefore pair these global materials with the law, regulation, FIU guidance and supervisory requirements applicable to the relevant bank legal entity.

Exact report names, suspicion thresholds, filing clocks, confidentiality duties, consent or defence mechanisms, FIU powers, information-sharing permissions, law-enforcement authorities and evidential rules differ by jurisdiction. The applicable local legal and regulatory framework remains authoritative.