International Cooperation, Mutual Legal Assistance and Extradition
Cross-border investigations need cooperation because people, accounts, companies and assets can sit in different legal systems. Mutual legal assistance (MLA) is formal cooperation between competent authorities to obtain evidence or execute other authorised measures. FIU intelligence sharing, supervisory cooperation and police cooperation use different channels and safeguards. Extradition concerns surrendering a person under applicable law, not transferring account records.
FATF Recommendations 37 to 40 address MLA, asset-recovery cooperation, extradition and other cooperation. They establish standards for countries; they do not authorise a bank to send records directly to any foreign official who asks. Treaties, domestic law, competent-authority powers, confidentiality, privilege and data protection determine the lawful route.
A bank can receive a domestic production order connected to a foreign investigation, a foreign request, a supervisory inquiry or an FIU request. The form matters. Verify the requesting authority, legal instrument, scope, service and response deadline through approved channels. A plausible email signature does not establish jurisdiction or compel disclosure.
Preserve relevant information promptly within applicable duties, but separate preservation from disclosure. A legal hold keeps evidence available; it does not itself authorise transfer. Equally, an investigative request does not automatically authorise freezing or confiscation. Each action needs its own valid basis.
Start with the requested act, then identify the lawful route
A request becomes manageable when the bank identifies the act it is being asked to perform. Finding an account, preserving a recording, producing a statement, explaining a payment message, restricting withdrawals and transferring a balance are different acts. Each can involve different permissions, systems and decision makers. An investigator may describe them together because they serve one investigation. The receiving bank must separate them before assigning operational work. Otherwise a valid request for information can become an unsupported instruction to move customer money.
The first assessment records the requester, receiving bank entity, subject, records or assets, purpose, period and requested action. It then asks which instrument or gateway supports that action for that entity. A domestic order connected with a foreign investigation may be directly actionable after validation. A foreign official's letter may require another route. Some jurisdictions permit direct cooperation in defined circumstances; others require formal recognition or transmission through designated authorities. The lesson is to validate the available route, rather than assume either that every foreign request is invalid or that every official letter is sufficient.
An operational coordinator can assemble these questions without attempting a legal determination. Legal counsel identifies the applicable powers and constraints. The records team explains what information exists. Financial crime specialists consider reporting confidentiality and related risk. Payments or account operations implement only an approved customer action. This distribution avoids the common failure in which the employee who receives an urgent email becomes the accidental decision maker for disclosure, account restriction and asset transfer simultaneously.
The initial record should preserve uncertainty. If an account identifier is incomplete, describe that limitation. If the legal instrument names one subsidiary but the requested records sit in another, identify both facts. If the requested completion time precedes feasible archive retrieval, record the dependency and escalate promptly. A reasoned intake note is useful even before an answer is available: it tells the next reviewer what requires resolution and prevents an unverified interpretation from becoming an instruction merely through repeated forwarding.
Five cooperation channels and what a bank should distinguish
Formal mutual legal assistance concerns cooperation between competent authorities for investigative or judicial purposes. It can support obtaining evidence or executing authorised measures under the relevant framework. FIU cooperation concerns financial intelligence and analysis, often with restrictions on use or dissemination. Supervisory cooperation concerns regulated entities and supervisory responsibilities. Police cooperation may provide investigative leads or coordination. Asset recovery cooperation concerns identifying, restraining or recovering property through applicable powers. These channels can overlap in one case, but their outputs are not interchangeable.
For a bank, the useful question is what has arrived through the channel and what it authorises locally. An intelligence lead may justify investigation under the bank's own responsibilities without being a court finding. A domestic production instrument may require delivery of specified records without requiring account closure. A supervisory request may seek a control description rather than criminal evidence. An asset restraint instrument may require a particular operational restriction whose scope differs from the records request. Label each obligation separately in the case record.
Coordination can reduce duplication without erasing these distinctions. Suppose a domestic authority requests statements while the FIU asks questions about a related reporting narrative. The bank can use a common source extraction where lawful, but maintain separate approval, access and delivery controls. The statement package may be disclosable through one route while the reporting material has additional protections. A shared case identifier supports consistency; it does not make every linked document suitable for every recipient.
FATF standards encourage effective international cooperation by countries and competent authorities. They do not give a branch employee a universal authority to send customer records overseas. The bank should maintain jurisdiction-specific procedures explaining valid recipients, service arrangements, permitted disclosure, legal escalation and record retention. Those procedures need owners and change control. They should help employees identify the right specialist quickly, including outside office hours, while leaving legal determinations with the authorised function.
Evidence, intelligence and conclusions carry different weight
A cross-border intelligence message might identify an account as potentially connected with laundering. The bank should treat that information according to its lawful purpose and reliability, then examine its own records. It should not describe the customer as convicted or the funds as criminal proceeds merely because the message uses an investigative allegation. A useful working record separates the external assertion, the bank's verified observations, analysis and unresolved questions. This distinction protects both investigative quality and fair customer treatment.
Bank-generated records also require explanation. A statement can show a debit without explaining whether it represents a payment, fee, reversal or internal correction. A payment message may contain customer-supplied names that the bank did not independently verify. An onboarding document can evidence what was provided at a particular time, while current ownership differs. A reviewer should specify the provenance and meaning of each record instead of attaching a collection of files and expecting the recipient to infer system semantics.
An analytical chart is particularly easy to overstate. An arrow between accounts could mean a confirmed settled transfer, an attempted payment, common ownership or an analyst's hypothesis. Label the relationship and retain the source identifier. If several currencies are combined, explain any conversion date and rate. If records use different time zones, retain original timestamps alongside the agreed presentation convention. A chart that looks precise while concealing these choices may mislead an investigator more than an incomplete narrative would.
The bank's answer should stay within its competence. It can explain its records and collection process, identify gaps and provide authorised factual material. It should avoid deciding foreign admissibility, criminal liability or whether an extradition condition is met. Those decisions belong to competent authorities and courts under applicable law. The disciplined boundary is practical: produce a reliable, intelligible account of what the bank knows, while making clear what it has not established.
Cooperation does not determine the customer outcome by itself
An investigation can coexist with a legitimate account relationship. Receiving a request does not automatically require exit, payment rejection or disclosure to the customer. Conversely, a valid records request does not remove the bank's separate duties concerning sanctions, suspicious activity or fraud. The case owner should identify the independent decision frameworks that may apply and route them to their authorised owners. Joining the facts is useful; combining the legal bases into one vague instruction is not.
Consider a request concerning a company's former director. Account restrictions aimed at the company could affect payroll, tax payments and unrelated counterparties. Before implementing a restriction, operations needs the relevant authority, account scope, affected rights, effective time and permitted exceptions. Where the bank makes its own risk decision, the rationale should follow the applicable policy and law rather than imply that an investigator instructed it. Where a legal instrument requires action, the record should distinguish mandatory terms from discretionary implementation choices.
Customer communication requires similar care. A routine service enquiry may arise while records are being collected. Staff need a lawful, approved response that avoids misleading explanations and protects any confidentiality or non-disclosure requirements. They should not invent a universal phrase such as 'international law requires silence'. The appropriate response depends on the instrument, applicable protections and the actual service impact. Escalation should be available when the customer asks a question that the prepared response does not cover.
Review points prevent temporary decisions from becoming permanent by inertia. A preservation hold may remain until an authorised release decision. A restriction may have a different review mechanism or expiry. An enhanced monitoring decision may need reassessment when facts change. The case register should track these separately, with named owners. Closing the records-production task is not sufficient evidence that every associated customer or asset measure can be removed, and continuing one measure does not justify retaining all others indefinitely.
Handling an authority request at a bank
Register the request, original documents, arrival time, entity addressed, accounts or persons specified, period and deadline. Legal validates authority and any need for domestic recognition or an MLA route. Operations locate records; compliance identifies reporting or confidentiality issues; security controls access and transmission. Assign a single accountable coordinator without hiding the separate decision rights.
Resolve identity carefully. Compare identifiers, dates, ownership and account history rather than returning records for every same-name customer. Record matching assumptions and unresolved ambiguity. If scope is unclear, seek clarification through the approved authority channel and preserve the relevant population while the question is resolved.
Produce evidence that can be understood and traced: account-opening records, statements, transaction details, relevant ownership changes and system explanations requested by the instrument. Preserve native records, metadata and transformation notes. A converted spreadsheet should explain time zones, currencies and excluded fields so an investigator does not misread it.
Check whether SARs, privileged material or other protected information have special handling requirements. Do not include them automatically because they are linked to the account. Record the legal basis and approving authority for the actual disclosure, use a secure agreed channel and retain proof of delivery. Where a foreign request lacks a valid direct route, explain the appropriate process rather than improvising a transfer.
Authenticate the requester without disclosing the answer during verification
Authentication begins with independently established contact details and an approved process. A convincing signature, official-looking seal or familiar name in an email is not enough. Employees should preserve the original communication and verify the sender through a trusted directory, known authority contact or another approved route. They should avoid using only a telephone number supplied in the request itself. Verification activity should also avoid inadvertently confirming that the named person holds an account before authority to disclose has been established.
The bank needs to distinguish identity from authority. A real official may lack the power to request particular information from this bank entity through the chosen channel. A valid institution may send a document whose scope does not cover the requested period. A legitimate representative may seek urgent cooperation that requires domestic steps first. Recording the outcome as 'sender verified' should therefore not automatically change the disclosure status to 'approved'. Separate fields make that distinction visible to operators.
Service and document integrity matter too. Retain the received instrument, attachments and relevant transmission details. If clarification changes a date range or subject list, preserve both versions and the authority for the change. Informal telephone clarification can be useful operationally, but the bank should capture it through the permitted process and obtain appropriate confirmation where necessary. Staff should not silently edit the original request to make it easier to fulfil, because later reviewers need to see which requirement the bank actually answered.
An authentication failure should trigger a measured response. Stop unauthorised disclosure and funds movement, preserve relevant evidence under the bank's procedures, and escalate suspected impersonation through appropriate security or fraud channels. Do not send a full customer dossier as a way of asking whether the official recognises the case. Where urgency may be real, use the approved escalation contact to resolve authority quickly. Good authentication supports timely cooperation by preventing the team from spending its response window on a fabricated demand.
Convert legal scope into an executable collection plan
Once the request is validated, translate its scope into a collection plan that operations can execute. Identify the legal entity, account or customer identifiers, products, systems, date range, requested record categories and any permitted exclusions. State whether closed accounts, linked accounts, attachments or historical versions are included. List what remains uncertain and who can resolve it. A plan should be specific enough that two competent analysts would search the same intended population rather than interpret a general phrase such as 'all relevant records' differently.
System fields require careful mapping. An order may identify an international account number while the archive indexes a legacy account key. A customer may have changed name or merged with another company. The bank may have separate identifiers for a party, agreement and payment account. The collection plan should preserve the supplied identifiers and show how they map to internal identifiers, including confidence and exclusions. Avoid relying on name matches alone when stronger identifiers are available.
Date boundaries also need interpretation. Does the authorised period concern booking date, execution date, receipt time or record creation? A payment submitted shortly before midnight may settle the following day in another time zone. The legal owner and data owner should agree the relevant basis, and the extract should disclose the convention used. Where uncertainty could omit responsive material, escalate it; do not select the smaller population simply because it is easier to retrieve.
The plan becomes the quality-control reference. A reviewer should reconcile requested categories with produced categories, explain unavailable records and confirm that unrelated material was excluded appropriately. Changes need version control and approval rather than casual instructions in a chat thread. This is especially valuable when several teams contribute: account operations, payment operations and archives can each complete their local task while still leaving a gap in the overall response unless one owner checks the integrated scope.
Preserve records while keeping the disclosure decision separate
Preservation protects information from routine deletion or alteration where the bank has a lawful basis and applicable duty to retain it. It does not itself establish a basis to disclose the information to a particular recipient. The bank should distinguish preservation scope, collection scope and production scope. A cautious preservation measure may cover information whose relevance is still being assessed; only the approved production population should leave the controlled environment. These distinctions should be visible in the case record and access permissions.
A practical hold identifies the systems and records affected, the reason, authorising function, effective time, responsible custodians and review mechanism. It also identifies processes that might destroy responsive information, such as archive rotation, mailbox deletion or replacement of historical customer documents. The records team should confirm what the system can actually preserve. A policy instruction to 'retain everything' is not proof that a short-lived log survived. Record implementation evidence and any limitations promptly.
Preservation should minimise avoidable operational impact. A legal hold on statements should not be mistaken for an account debit block. Holding a copy of onboarding records need not prevent legitimate profile corrections; instead preserve the earlier version and the change history where relevant. The bank should retain authenticity and chronology while continuing lawful business processes. If a proposed preservation technique changes production data, involve the system owner and legal function before implementation.
Release requires its own decision. The expiry of an internal task date, departure of the investigator or completion of an export does not necessarily end the hold. Equally, a hold should not survive forever because nobody owns closure. Maintain review dates and an authorised release process that checks applicable obligations, related matters and retention policies. Record the reason and systems affected by release. This supports proportionate retention and makes later explanations possible if a record was lawfully deleted after the hold ended.
Search linked identities without turning association into allegation
An investigation may concern a person who appears across several customer records as director, beneficial owner, signatory or payment beneficiary. These roles create different relationships. A search should identify the role and relevant period, rather than place every associated account in one undifferentiated suspect list. A former signatory may have no current authority. A beneficial owner may not have initiated the transaction under review. A beneficiary name in a message may reflect payer input rather than an established customer relationship.
Identity resolution should use multiple identifiers where available, document the method and retain ambiguous results for review. Names can vary through transliteration, spacing, abbreviations and changes after marriage or corporate restructuring. Date of birth, incorporation details, address history and official identifiers can distinguish unrelated parties, but each field has its own reliability and provenance. An analyst should record why a match was accepted or excluded, not merely cite a screening score whose meaning the recipient cannot inspect.
The authorised scope limits how far linked-account work can extend. A request for one account may not authorise production of every account associated with a relative or business partner. The bank can identify a potential scope issue and seek clarification through the approved route. It should avoid expanding the response simply because a graph tool makes additional relationships easy to discover. Internal analysis under a separate lawful responsibility may be legitimate, but its products still require a disclosure decision before inclusion.
Quality review should test both false positives and missed links. Select examples of accepted matches and exclusions; compare the supporting identifiers and historical periods. Check whether system migrations changed party keys or lost relationship dates. Retain a clear explanation when a requested identity cannot be resolved. A documented, appropriately qualified negative result is more useful than an unsupported statement that 'no relationship exists', especially when the search covered only some bank entities or a limited retention period.
Produce records that retain their original meaning
An export is a representation of source data, not automatically a faithful substitute for every feature of the source system. The collecting team should explain the record type, source system, extraction date, relevant field definitions and material transformations. A statement export may omit transaction descriptions visible in the customer interface. A payment file may contain message fields that differ from the posted ledger. A scanned document may lack its original upload metadata. Identify these differences before presenting the package as complete.
Retain original formats where appropriate and provide readable versions when needed through the approved scope. Explain whether a file is native, a rendering or a reconstructed report. Do not overwrite originals with translated labels or analyst annotations. If translation is required, keep the original, identify the translator or process and distinguish translation from interpretation. If a legacy code needs explanation, provide the contemporaneous or validated definition instead of substituting a modern code with a similar name.
Reconciliation can expose material errors. Compare transaction counts and totals against a trusted source for the authorised period, allowing for reversals, pending items and currency differences. Confirm that attachments are linked to the correct parent records and that statement pages are continuous. Inspect representative rows containing non-Latin characters, long identifiers and negative amounts. Spreadsheet formatting can drop leading zeros or convert identifiers into scientific notation; a technically successful export can still damage evidential meaning.
The response should identify limitations clearly. If an archived message body is unavailable but the ledger entry remains, describe the distinction and the search undertaken. If a field records customer-provided information, say so. Avoid filling gaps from memory or using an analyst's reconstruction as an unmarked original. A transparent limitation helps the requesting authority decide what further assistance is needed. Concealing the gap with a neat-looking report can create an inaccurate account of the bank's evidence.
Build a chain of custody that an independent reviewer can follow
Chain of custody records how material was identified, collected, handled and delivered. For a banking response, the record should connect the approved scope to source systems, extraction operators, timestamps, storage locations, transformations, review and transmission. The aim is an understandable history, not an impressive collection of technical terms. A reviewer should be able to identify who handled a file and why, and whether the delivered file corresponds to the approved version.
File hashes can support integrity checks where suitable, but they do not establish truth, completeness or legal authority. A hash can show that a file has not changed between two recorded points. It cannot show that the original search omitted nothing, that the data field means what the analyst claims, or that disclosure was permitted. Use hashes alongside collection logs, scope reconciliation and review evidence. Avoid presenting a cryptographic checksum as a substitute for these substantive controls.
The production manifest should list the files or record groups, their descriptions, relevant date ranges, version and any approved omissions. Record transformation steps, such as combining monthly statements or converting a format for readability. Retain the authorised package in a controlled location rather than reconstruct it from individual team folders later. Access should reflect need and role, with audit trails for retrieval and changes. Sending the same package again should use the approved version, not a convenient local copy.
If an error is discovered after production, preserve the original production record and follow an authorised correction process. Determine whether the issue concerns an omitted file, an incorrect interpretation, unauthorised material or a corrupted transfer. Notify the appropriate internal owners promptly and agree the lawful external correction. Record what changed and which earlier information is superseded. Quietly replacing a file can conceal the sequence and leave the authority working from an inaccurate version already distributed elsewhere.
Handle protected reporting material and privilege deliberately
An account record, an internal investigation note and a suspicious activity report are different document categories. A broad request may touch all three, but their disclosure rules can differ. The production team should use a classification and review process that identifies reporting confidentiality, privilege or professional secrecy, personal information and other applicable protections. It should not assume that attaching every related file is the most cooperative response. Lawful cooperation requires recognising both the power to obtain records and the limits on particular material.
Legal privilege is not created simply by copying counsel into an email or marking a document confidential. Its application depends on the relevant law and circumstances. Equally, an ordinary business record does not automatically become privileged because it was discussed with counsel. The authorised legal function should assess disputed material and record the basis for treatment through the appropriate process. Operational staff should avoid making these determinations informally or deleting potentially protected documents to remove the issue.
Reporting confidentiality must be handled under the applicable jurisdiction's rules. Underlying account facts can have a different status from the existence or contents of a protected report. The bank should identify the actual category and permitted route, rather than import a rule from another country's regime. A records-production package should be reviewed for hidden references, attachment names or analyst comments that might reveal protected reporting unintentionally. The risk may lie in context and metadata as well as an explicitly labelled report.
Where material is withheld, redacted or referred for clarification, record the authorised reasoning and method. Keep an audit trail that allows the bank to explain the response without unnecessarily reproducing protected content in a widely accessible register. Redaction should be checked for technical effectiveness and readability, including layers, searchable text and metadata where relevant. The final reviewer should confirm that the package follows the approved treatment and that any explanation of exclusions is lawful and accurate.
Apply information-use conditions through the approved framework
Information received through international cooperation may carry conditions concerning purpose, recipient, dissemination or security. The bank should record and respect the conditions communicated through its authorised route, then obtain specialist advice before using the information for a materially different purpose. A lead received for analysis should not automatically be copied into a general customer database, distributed to every group entity or attached to another authority's request. Permitted use is a separate question from whether the information seems operationally useful.
The Egmont Group revised its FIU information-exchange principles in July 2025. That framework includes a defined approach to dissemination consent and the authorities identified in a request; it should not be reduced to an outdated claim that a separate explicit consent is always required. These principles concern FIUs within that framework. They do not create a bank's general permission to disclose. Bank procedures must follow the actual applicable law, authorised communication and case-specific conditions rather than infer a new entitlement from a principle addressed to authorities.
A useful controls record identifies the received information, source route, permitted purpose, access group, stated recipient conditions and unresolved restrictions. Where a bank's own investigation produces independent evidence, preserve that provenance separately. It may be possible to use the independently obtained record through another lawful route, but describing an external intelligence claim as an internal finding does not remove restrictions. Analysts should be able to show which conclusion follows from which evidence.
If conditions are unclear or conflict with another request, escalate promptly. Seek clarification through the established authority contact and legal owner; do not treat silence from an individual correspondent as a universal approval. The bank should also avoid inventing stricter blanket restrictions unsupported by the current framework, because that can obstruct lawful cooperation. The practical standard is documented, current and specific: identify the rule and conditions that apply to this information, this proposed use and this recipient.
Deliver securely and close the production task with proof
Delivery is a controlled stage of the response. Confirm the authorised recipient and channel, approved package, access arrangements and any necessary handling instructions. A secure file-transfer tool does not solve recipient or scope errors. An encrypted package sent to the wrong official remains a serious problem. The release reviewer should check both the technical mechanism and the legal-operational approval before transmission, using the procedure appropriate to the sensitivity and volume of the material.
Large packages may need staged production. If that is permitted, document which categories are included in each stage, what remains outstanding and the agreed completion approach. Ensure that partial delivery is not described as the final complete response. Use consistent identifiers across stages so the recipient can reconcile them. If access credentials expire or a file cannot be opened, coordinate a controlled retry; do not switch casually to personal email, an unapproved cloud account or an unsecured messaging service to meet a deadline.
Proof of dispatch and proof of successful receipt are different. Preserve the transmission log and obtain the appropriate acknowledgement or delivery evidence where available. Clarify any failed or incomplete transfer promptly. If the authority reports a missing attachment, compare its description against the manifest and approved package rather than assemble a fresh selection from memory. This protects consistency and helps distinguish a delivery problem from a collection omission.
Closure should confirm completion of the particular production obligation, retained evidence of review and delivery, and ownership of residual matters. A follow-up question, continuing preservation hold, reporting decision or account restriction may remain open. Record those tasks explicitly instead of marking the entire investigation closed because the export succeeded. A supervisor should be able to reconstruct the response from the register, approved package and evidence trail without depending on the recollection of the employee who sent it.
Intelligence versus evidence
Information shared between FIUs may have restrictions on use, onward dissemination or evidential use. A bank should respect the conditions attached to intelligence it receives and avoid treating a lead as a court finding. Further corroboration and formal evidence collection may be required.
International asset cooperation is distinct from ordinary data production. Validate whether a restraint or freezing order is enforceable locally, which assets and entities it covers, and who can authorise variation or release. Extradition decisions belong to competent state authorities; the bank's role normally concerns relevant information or asset measures.
Test unauthenticated requests, overbroad scopes, conflicting deadlines, inaccessible archived records and attempted disclosure through a personal email. Each test should demonstrate preservation, legal escalation and a controlled response rather than silent refusal or indiscriminate cooperation.
Fictional case: an urgent foreign email seeks records and a balance transfer
In this fictional case, a branch receives an email from a person claiming to be an overseas investigator. The message names a commercial customer, attaches a formal-looking letter and says that a fraud victim needs an immediate transfer of the customer's remaining balance. It also asks for onboarding records and all payment messages. The sender says any delay will allow the suspect to escape and provides a mobile number for confirmation. No employee has previously dealt with this sender.
The receiving employee preserves the communication and routes it to the approved response function. The coordinator separates four questions: whether the requester is authentic, whether any disclosure route is valid for the receiving entity, whether relevant records should be preserved, and whether any funds action is legally authorised. The supplied mobile number is not used as the sole authentication channel. No account confirmation or balance is disclosed while these questions remain unresolved. The urgency is recorded and escalated rather than accepted as a source of legal power.
Legal counsel checks the document and available routes. The records team can identify potentially relevant systems without exporting information to the sender. Security assesses the suspected impersonation indicators through its own process. The financial crime function considers whether the facts raise a separate suspicious activity concern under applicable rules. Each activity has its own owner and rationale. The team does not assume that declining an unsupported transfer means it must ignore the possible fraud allegation.
Suppose verification establishes that the named authority exists, but the document was not issued by it. The bank stops the attempted disclosure and funds action, retains appropriate incident evidence and follows its fraud-response procedure. Any preservation or internal investigation continues only under a valid basis and proportionate scope. Customer communication is decided through the relevant functions, taking account of applicable reporting confidentiality and the incident facts. Staff do not accuse the customer of fraud merely because a fabricated letter named it.
Now change one fact: the authority confirms the request is genuine, but says it expects the bank to cooperate voluntarily. That authentication result still does not resolve disclosure or funds movement. Counsel assesses the jurisdiction-specific gateway and any necessary domestic process. The bank uses the verified authority contact to clarify the next lawful steps and operational timing. The case record states which acts remain unapproved. There is no universal rule that the authority must use one particular treaty route, but equally no general permission created by genuine official status.
The learning test is whether the employee can explain the decisions without relying on the word 'urgent'. Which act was requested? What established identity? Which entity held the records? What authorised preservation, disclosure and asset action separately? What was communicated and through which channel? A successful response protects customer assets and information while making appropriate cooperation possible. Simply sending everything quickly, or deleting the email because it looked suspicious, would each leave a serious control gap.
Fictional case: a domestic production instrument concerns a foreign fraud network
In this fictional case, the bank receives a domestic production instrument relating to a foreign fraud investigation. Legal validates its application to the bank entity and confirms the required record categories and period. The named customer held a business account that closed after a system migration. Investigators seek statements, onboarding records and payment information for a defined historical period. The account number in the instrument is the former number, while current archives use a replacement internal identifier.
The coordinator creates a collection plan rather than sending the instrument separately to each team. Account operations maps the legacy account number to the archive identifier and records the supporting relationship. The onboarding team identifies historical profile versions, not just the final closure record. Payments operations identifies the relevant message archive and its retention limits. The plan distinguishes the booking dates used for statements from the execution timestamps used for messages, and seeks legal clarification where the authorised period could be interpreted differently.
The first extract appears complete by row count, but quality review finds that one migration batch contains truncated descriptions. A second source retains the full descriptions for part of the period. The team documents which source supplied each field and does not overwrite the original extract without retaining its provenance. Where the full description cannot be recovered, the response explains the limitation and collection steps. An analyst must not create a plausible narrative from counterparty names and label it as the missing original description.
The production package contains a manifest, readable records and explanations of material codes and transformations. It also includes a clear account of unavailable categories where authorised and appropriate. The legal reviewer checks whether internal reporting references have entered filenames or comments. A second operator confirms that statement pages, attachments and message identifiers reconcile with the approved scope. These checks are substantive: a technically valid archive export is not enough when migration has changed the meaning or completeness of the record.
After delivery, the requesting authority asks why one transaction appears twice. The records team compares the delivered package with the retained approved version. It identifies an original posting and a reversal, then provides an authorised explanation supported by system definitions. It does not remove the second line to make the totals look simpler. If the original explanation was incomplete, the correction is versioned and linked to the first production so the authority can understand what changed.
The case illustrates how cooperation depends on banking data knowledge. Legal validation enables the task but cannot identify every archive defect. Data owners understand system semantics but do not determine foreign admissibility. The coordinator integrates both. The evidence test is whether an independent reviewer can trace each delivered record to the scope, source, extraction and review, and understand any gap without questioning the employee who remembers the migration. That is stronger than a register entry saying only 'records sent on time'.
Fictional case: FIU intelligence identifies a lead with limited onward use
In this fictional case, the bank receives a request through its domestic FIU concerning an account linked to intelligence from another jurisdiction. The communication states a defined purpose and handling conditions. It asks the bank to explain a set of transactions and supply specified underlying records through the authorised domestic route. A relationship manager hears that an international investigation exists and asks for the intelligence message to brief a commercial partner about the customer.
The response owner first identifies who may access the communication within the bank and what the request actually requires. The commercial partner is not an authorised recipient merely because it has business concerns about the customer. The bank does not copy the intelligence message into a generally accessible customer record. Analysts can examine the bank's own records under the applicable responsibilities, but they keep external assertions distinct from verified observations. Any request to use the information more widely is escalated for lawful assessment.
The analysis finds three transfers described in the message, but one beneficiary name differs. The analyst checks original message fields, the customer's instructions and the posted ledger. The difference may reflect abbreviation rather than a different recipient, but the bank cannot establish that from the available records alone. It responds with the verified fields and the limitation, rather than repeating the foreign intelligence as confirmation. The request can then be clarified through the appropriate authority channel.
A domestic law-enforcement team later seeks related records for another purpose. The bank must assess that new request on its own authority and scope. Independently held account records may be producible through a valid route. The foreign-derived intelligence message may have additional conditions. The team should not conceal its origin by copying its wording into an internal memo and treating the memo as independent evidence. Provenance remains relevant even when information has been reformatted.
The legal owner uses the current applicable framework, including communicated conditions, rather than a remembered rule from an older training slide. The July 2025 Egmont principles include a revised dissemination-consent approach for FIUs and authorities identified in requests. That is relevant background for the authority framework, but the bank still follows its own lawful route. It neither claims every onward use needs a separately signed foreign consent nor assumes that FIU arrangements authorise unrestricted bank sharing.
The case is successful when the requested factual response is accurate, the information remains within permitted handling arrangements and useful independent analysis is preserved. A manager should be able to explain which conclusions came from account records and which remained external allegations. The customer decision, if any, is made under its proper framework. International cooperation then strengthens the bank's understanding without converting a restricted intelligence lead into a widely circulated accusation.
Fictional case: two group entities receive overlapping requests
In this fictional case, a banking group has subsidiaries in Country A and Country B. Each receives a request from its own domestic authority concerning the same corporate network. The requests overlap but cover different periods and account populations. A group coordinator proposes one combined folder so both teams can respond quickly. The convenience is apparent: customer names recur, several systems are shared and duplicate exports seem wasteful. The legal and operational assessment must still distinguish the two entities' obligations.
Each local response owner validates the applicable instrument and receiving entity. The group coordinator creates a cross-reference showing overlap without automatically granting both teams access to every document. Some records are held by one subsidiary; others sit on a shared platform operated by a service company. The location of the server does not by itself resolve which entity controls the record or what disclosure is permitted. Legal, records and technology owners identify the relevant responsibilities and permitted access arrangements.
The teams agree a common data-definition sheet for payment fields, date conventions and legacy customer identifiers. This improves consistency without forcing the scopes to be identical. Country A's response covers a longer historical period; Country B's concerns a narrower account set. Each production manifest identifies its own scope and review. Where one extraction can lawfully support both tasks, the retained record shows which subsets were approved for each recipient. The coordinator avoids creating an unrestricted master dossier simply because both cases concern financial crime.
A conflict emerges when one authority requests confidentiality while another asks about the existence of related proceedings. The employees do not attempt to solve it by choosing the more senior official or the earlier deadline. The authorised legal functions assess the actual instruments and constraints and coordinate through permitted channels. The case register records the issue, escalation and decision without exposing protected details to everyone with access to the group tracker. Unresolved constraints are visible to the people who need to manage them.
The shared-platform vendor reports that an archive retrieval will take longer than expected. Both local owners receive an accurate dependency update, but the group coordinator does not promise extensions on their behalf. Each follows the applicable process for clarifying timing or seeking relief where available. Partial production, if permitted, is documented separately. One team's timely response does not justify marking the other complete, and a common extraction does not eliminate each entity's final approval and delivery evidence.
The case tests whether group efficiency supports local accountability. Good coordination produces consistent definitions, controlled reuse and fewer unexplained differences. Poor coordination produces one large folder, excessive access and responses whose legal bases nobody can reconstruct. The group should be able to show which entity answered which request, using which records and permissions. That explanation matters more than whether the investigation network can be drawn as a single attractive diagram.
Fictional case: an asset request accompanies a records request
In this fictional case, a bank receives a validated domestic records request relating to an overseas case. A separate communication asks the bank to prevent withdrawal of a named customer's balance while authorities consider asset recovery measures. The customer's account also receives payroll for employees and payments for several unrelated contracts. The team must determine what, if anything, authorises a restriction and how its scope applies. The records request alone does not answer those questions.
Legal assesses the separate communication and the available locally effective powers. Operations provides the account structure, balance composition and relevant processing capabilities. The financial crime function assesses any independent reporting, sanctions or fraud responsibilities. The team records the separate bases and avoids describing a discretionary risk action as court-ordered. If a valid restraint instrument arrives, its actual terms guide implementation, including covered property, timing, permitted dealings and the process for clarification or exceptions.
Implementation requires more than a flag on the customer profile. The account may have pending payments, linked facilities, automated fees, incoming credits and branch channels. Operations identifies which processes must respond to the approved restriction and which remain permitted. The approved instruction should be precise enough to prevent accidental release of covered funds without blocking unrelated activity unnecessarily. Where the system cannot express the legal scope directly, an authorised compensating process and escalation are needed rather than an improvised blanket block.
Customer and third-party effects are considered through the applicable framework. The bank should not assume it can grant an exception because a payment is sympathetic, nor refuse a permitted exception simply because the account carries an investigation marker. Questions about payroll, fees or third-party rights go to the authorised owner. Communication follows the actual confidentiality requirements and operational facts. Frontline staff receive sufficient lawful instructions to handle service enquiries without disclosing protected case information.
The records-production team continues its separate work. Statements should reflect actual events, including any lawful restriction-related processing, and should not be retrospectively altered to make the asset history simpler. The hold register and production register cross-reference one another where appropriate, but have distinct completion criteria. A delivered evidence package does not release the restraint; a restraint does not make every internal investigation document disclosable. Follow-up and review dates remain owned.
The final test concerns release and accountability. If an authority changes or lifts a measure through the valid process, the bank confirms the operative instruction, implements it across affected channels and records the outcome. If uncertainty remains, it escalates promptly rather than allowing a restriction to continue without an owner. The bank's role is careful implementation of lawful measures and its independent obligations. It does not decide guilt or distribute assets to a claimed victim merely because an international investigation exists.
Worked foreign-request case
A fictional overseas investigator emails a branch asking for all records for a customer and immediate transfer of the balance. The bank should authenticate the request and route it to legal. Account information, preservation and movement of funds are separate actions requiring separate legal analysis. A request's urgency does not create jurisdiction.
Explain what can be preserved immediately under the bank's policy, which competent-authority route may be needed for disclosure or restraint, and how the bank records its response without tipping off where prohibited.
Laboratory: classify a mixed request before assigning work
Use this fictional exercise to practise separating actions. The intake package contains a foreign investigator's letter, a domestic authority's covering message and a spreadsheet of names. It requests account identification, six years of statements, a copy of any suspicious reporting, an immediate debit block and confirmation that the bank will not inform customers. The exercise does not supply a jurisdiction-specific legal conclusion. Learners should identify the facts and decisions required, rather than invent a universal answer.
Create an action matrix with one row for each requested act. For each row record the receiving entity, requester, instrument or proposed gateway, scope, legal owner, operational owner and unresolved issue. Distinguish authentication from authority. Identify records that may need preservation under a valid basis before production is approved. Flag reporting material for specialist confidentiality review. Treat a debit block and a non-disclosure instruction as separate matters requiring their own assessment. The matrix should reveal dependencies instead of displaying one overall green status.
Now introduce an account held by a sister subsidiary and a name that matches two unrelated customers. Explain how the collection plan changes. The subsidiary question requires entity and gateway analysis; the ambiguous name requires identity clarification. Neither is resolved by enlarging the response to include everything. Decide which teams can carry out preliminary searches lawfully and how results remain restricted. Document what clarification would allow the response to proceed and through which approved contact it should be sought.
Assess the completed matrix by asking whether an operator could implement an approved task without guessing. A row saying 'cooperate urgently' fails because it lacks a defined act and authority. A row identifying a validated statement-production task, its population and reviewer is executable. The facilitator should challenge unsupported assumptions, including claims that all foreign requests require the same formal route or that a domestic covering message automatically validates every attachment. The outcome is a controlled plan, with unresolved legal questions visible and assigned.
Laboratory: reconcile identities, dates and transaction meanings
In this fictional exercise, an authorised request names a company under its former name and covers transactions between two dates. The archive contains a legacy account key, a current customer identifier and two similarly named companies. Some payment records use local submission time, while ledger records use booking date. The learner receives a small sample containing a reversal and an internal transfer. The task is to design an accurate response method, not to infer criminal conduct from the sample.
Build an identity table linking the requested subject to internal identifiers with supporting evidence and historical periods. Record the reason for excluding the similarly named company. Explain whether the former name remains relevant after a corporate change and identify facts that need clarification. Then prepare a date-convention note distinguishing submission, execution and booking fields. Show how boundary transactions would be considered under the approved interpretation. Retain original timestamp values alongside any presentation conversion rather than silently normalising them.
Reconcile the transaction sample to the ledger, preserving reversals and explaining internal movements. Do not count a reversed instruction as a completed external transfer. Do not describe an internal transfer as money leaving the banking group unless the records support that conclusion. Identify the source and meaning of the beneficiary fields. If the archive export truncates a description, record the limitation and the proposed retrieval check. A neat total without these explanations would be an inadequate evidence product.
The assessment requires a collection plan, reconciliation note and draft manifest. A reviewer should be able to repeat the method on the full population. Challenge any unsupported certainty in the language: 'no other accounts exist' may exceed the systems searched; 'same beneficiary' may exceed available identity evidence. Successful work is precise about scope and meaning while still producing a usable answer. This exercise links familiar banking operations to international evidence quality, where small date or identifier errors can change the apparent sequence of events.
Laboratory: correct an error discovered after delivery
In this fictional exercise, a bank has delivered an approved package through a secure channel. The authority reports that one file cannot be opened. Internal review then finds that another file contains an unrelated customer's page and that the explanatory note used an incorrect time-zone label. These are three distinct issues: delivery usability, potentially unauthorised disclosure and substantive interpretation. Learners should avoid treating them as one technical retry that can be solved by uploading a replacement folder.
Create a response plan that preserves the original package and dispatch evidence, restricts further access where appropriate and escalates the exposure through the relevant legal, security and privacy procedures. Determine the authorised external communication and correction route. Identify what can be resent unchanged and what needs a newly approved version. Record affected recipients and known onward distribution where relevant. Do not erase the original production record merely because it contains an error; the sequence must remain explainable.
Prepare a correction manifest identifying the earlier files, the corrected versions and the nature of each change without unnecessarily repeating exposed information. Test the readable file before retransmission and verify the recipient and channel again. The time-zone correction should explain whether the underlying timestamps changed or only the label was wrong, because the authority may have relied on the previous chronology. The unrelated page requires its own incident response, rather than a note saying that the package is now cleaner.
Finally identify the control failures and proportionate improvements. A reviewer may need better page-level checks, an export tool may need a boundary fix, or the handoff may have omitted a source definition. Re-training everyone is not a complete answer if a system defect caused the error. Measure whether the improvement prevents recurrence in representative packages. The exercise is passed when the bank can correct the response lawfully, preserve an honest history and demonstrate a targeted repair, while keeping customer impact and authority use in view.
Systems and evidence custody
The request register should link the legal instrument, scope, holds, collection tasks, approvals, production version and delivery record. Limit access to the authorised team. Audit logs should show who searched, exported, transformed and transmitted the material.
For archived records, test retrieval and reconstruction before a live request arrives. Preserve original timestamps and explain displayed time-zone conversions. When data is unavailable, document the reason, affected period and steps taken; recreating missing evidence from memory is unacceptable.
Effective cooperation means a timely, accurate and lawfully authorised response. Fast disclosure without a valid gateway can undermine both the investigation and the bank's obligations.
Design the cooperation register around decisions and evidence
A useful cooperation register is more than a list of incoming letters and due dates. It should link the request identity, receiving entity, authority validation, scope interpretation, preservation measures, collection plan, production versions, approvals and delivery evidence. Sensitive documents can remain in controlled repositories with appropriate references in the register. The register's purpose is to show the decision trail without spreading protected case information more widely than necessary. Access and field design should reflect that purpose.
Separate statuses prevent false completion. Authentication, legal assessment, collection, quality review, release approval and delivery are different stages. Holds and customer measures have their own lifecycle. An overall dashboard can summarise progress, but it should allow authorised users to see a blocked dependency and responsible owner. 'Awaiting legal' is too vague if the unresolved issue is a specific cross-entity disclosure question that requires local counsel and an authority clarification.
Evidence references should be durable. Link an approval to the actual package version, not to a folder whose contents can change. Record the source of deadline changes and scope amendments. Preserve explanations for unavailable records and negative search results, including the population searched. If several requests use one extraction, record the relationship while retaining separate production scopes. These features allow the bank to answer later questions about what it knew and sent at a particular time.
Retention and access need periodic review. The register itself can expose investigation patterns, protected reporting references and personal information. Give each role only the access necessary for its task, and audit sensitive retrieval or changes. Define who can close, reopen or release associated holds. Test whether cases remain intelligible after personnel changes. A sophisticated dashboard is weak if its key decisions exist only in an employee's mailbox or its links fail after an archive migration.
Make the response service resilient without diluting authority controls
International requests can arrive outside the receiving bank's normal office hours and may involve archives, specialist products or unfamiliar languages. Resilience starts with a clear intake route, escalation contacts and trained alternates. An emergency process should identify who can authenticate, assess authority and approve operational action, rather than grant every overnight employee broad discretion. Speed comes from prepared ownership, reliable retrieval and concise evidence, not from skipping the decision that makes the action lawful.
Technology and vendors should be included in readiness testing. Confirm that the bank can retrieve retained records after migration, access encrypted archives and explain legacy field definitions. Understand where a service provider stores information and how the bank can obtain it within applicable obligations. Outsourcing retrieval does not remove the bank's responsibility for scope, review and delivery. Contractual service levels should be supported by tested capability and clear escalation when a provider cannot supply the expected record.
Exercise realistic failure combinations. A primary contact may be absent while a transfer service fails and a requester seeks an urgent clarification. The exercise should test controlled handover, access to approved package versions, lawful alternate channels and honest communication about limitations. A team that can recover only by sending a personal copy through an unapproved tool is not resilient. Capture the failure and fix the process or dependency rather than celebrating that someone managed to improvise a response.
Review lessons across cases without distributing confidential facts unnecessarily. Recurrent archive gaps, ambiguous account mappings or correction patterns can guide targeted improvement. Create sanitised examples for training and validate that they no longer identify customers or reveal protected reporting. Measure whether repairs improve source quality and execution, not just whether employees attended a session. The operational objective is dependable, lawful cooperation that remains accurate when the case is urgent, unusual or handed to a new team.
Assess effectiveness and keep the limits of the bank's role clear
Timeliness matters, but a response sent quickly can still be incomplete, unlawful or misleading. An effectiveness review should consider scope completeness, accuracy, explainable limitations, secure delivery, correction quality and observance of applicable conditions. Use request types and complexity when interpreting turnaround figures. An archive-heavy historical request should not be compared mechanically with a simple current statement request. Track avoidable delay separately from time spent resolving a genuine legal or identity issue.
Review samples against the actual production record. Did the authority receive the approved version? Were all requested categories addressed or appropriately explained? Did the bank reconcile identifiers and dates? Were protected categories handled under the approved decision? Did a restriction remain open after its review trigger? These questions test outcomes rather than whether a checklist contains signatures. They also identify whether a failure came from scope interpretation, system capability, supervision or an external dependency.
Keep role boundaries explicit when reporting success. The bank can demonstrate that it supplied reliable authorised records or implemented a lawful measure. It should not claim to have established criminal guilt, ensured a foreign conviction or decided extradition. Extradition concerns the surrender of a person under the applicable state and judicial framework; it is not an account-transfer procedure. Asset identification, restraint and recovery also involve different stages and powers. Banking participation can be important without turning the bank into the authority responsible for those outcomes.
Useful terminology supports this discipline. A request is the demand received; an instrument or gateway is the basis assessed; preservation protects records; collection gathers the scoped material; production releases the approved package; dissemination concerns further sharing; restraint limits dealings under applicable authority; confiscation concerns deprivation through the relevant legal process. Intelligence is not automatically evidence admissible in court, and an allegation is not a finding. A mature response function uses these distinctions consistently in instructions, records and management reports, making cooperation both effective and reviewable.
References and further reading
Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.
- FATF Recommendations, updated June 2026 — relevant anchors: 37, 38, 39 and 40.
- Egmont Group principles for information exchange between FIUs, July 2025 — current FIU framework, including information-use safeguards and the revised dissemination-consent approach. These principles apply within the FIU framework and do not give banks a general disclosure power.
- UNODC teaching material on mutual legal assistance — international cooperation background. The valid bank response route, service, disclosure powers, privilege and asset measures remain matters for the applicable domestic framework and competent legal assessment.
- UNODC manual on mutual legal assistance and extradition — a practical authority-level reference; not a universal bank operating rule or current jurisdiction-specific legal opinion.