Investigating Complex ABC & Tax Predicates

A bank rarely receives a neat alert saying, “this payment is the proceeds of bribery” or “this customer has committed a tax crime.” Complex anti-bribery and corruption, or ABC, and tax-predicate investigations start with fragments: a consultancy payment with a vague purpose, an unexplained connection to a public official, a supplier whose ownership changed shortly before a contract award, an unusually large dividend, a false-looking invoice, a tax authority request, an internal whistleblowing allegation, or funds that do not fit the customer’s declared source of wealth. The investigator’s job is to turn those fragments into an evidence-led financial story without assuming that suspicion is proof.

That distinction is fundamental. Bribery and corruption are designated categories of predicate offences in the FATF framework, as are tax crimes related to direct and indirect taxes. But domestic law decides exactly which conduct is criminal, which offences qualify as money-laundering predicates, what reporting threshold applies, and what information a bank may share. A suspicious transaction report is not a conviction. A tax discrepancy is not automatically tax evasion. A payment to a consultant is not automatically a bribe. The bank must identify facts, test plausible explanations, understand the legal and policy context, and decide whether the activity creates a reportable or otherwise unacceptable financial-crime risk.

The practical mental model is predicate conduct, benefit or proceeds, movement, concealment, and bank decision. The suspected predicate conduct may be bribery, embezzlement, abuse of office, fraudulent tax reporting, criminal tax evasion, customs or VAT fraud, or another locally defined offence. The benefit may be cash, a contract, a tax saving, property, shares, a debt release or another economic advantage. The money may then move through customer accounts, third parties, shell companies, professional intermediaries, family members, trusts, property transactions or investment products. At each stage, the bank sees only part of the picture. Investigation means joining those parts carefully enough to explain what the bank knows, what it does not know, and why the final decision is reasonable.

How a suspected bribery or tax predicate can create value, move through financial channels and reach a bank investigation.

Why this investigation is difficult

ABC and tax-predicate cases are difficult because legitimate commerce and illicit conduct often use the same infrastructure. Companies legitimately hire agents, consultants and distributors. Groups legitimately use holding companies, trusts and special-purpose vehicles. Wealthy customers legitimately receive dividends, sell businesses and move money across borders. Businesses legitimately dispute tax positions. A transaction becomes more concerning when the facts do not cohere: the service cannot be evidenced, the fee is disproportionate, ownership is concealed, the beneficiary is connected to an official, the timing mirrors a public decision, funds are rapidly redistributed, or tax explanations conflict with independent information.

The investigator therefore needs a hypothesis rather than a keyword. “Consultancy payment” is not a hypothesis. “The customer may be using a sham consultancy contract to transfer part of a public-contract margin to a company controlled by a decision-maker’s relative” is a hypothesis. “Offshore transfer” is not a hypothesis. “The customer may be moving undeclared taxable income to an entity that has no apparent operating purpose and then returning value through a shareholder loan” is a hypothesis. A good hypothesis is specific enough to test and modest enough to change when evidence points elsewhere.

Complex cases often contain more than one possible predicate. A false invoice used to conceal a bribe may also create accounting or tax consequences. A corruption scheme may involve procurement fraud, tax offences and money laundering. Conversely, a tax irregularity may arise from error, interpretation or civil non-compliance rather than crime. The case file should keep these possibilities separate. It should not stretch one weak indicator into several criminal labels merely because multiple risk categories are available.

FATF’s current Recommendations, as amended in June 2026, continue to require a framework that covers a wide range of serious predicate offences. The FATF glossary includes corruption and bribery and tax crimes related to direct and indirect taxes among the designated categories. FATF also stresses that countries implement the standard through their own legal systems. OECD guidance on fighting tax crime likewise explains that jurisdictions define the criminal tax offences and elements that make them serious; this is why a global bank must map local law instead of using a single universal “tax crime threshold.”

The investigation starts with the trigger, not the conclusion

A trigger may originate in transaction monitoring, KYC review, PEP screening, adverse information, whistleblowing, internal audit, tax reporting operations, fraud teams, relationship management, sanctions review, law-enforcement contact or an ABC compliance process. Each trigger carries different strengths and weaknesses. A transaction-monitoring alert provides behaviour but may lack motive. A whistleblowing allegation may provide motive but need corroboration. A public enforcement announcement may be reliable about an investigation but not prove that the customer committed an offence. A tax authority request may be legally significant but the bank still needs to follow the exact scope and confidentiality rules applicable to that request.

The first investigator task is to capture the trigger faithfully. Record who or what raised the concern, the date, the underlying event, the source, the original wording where material, and any urgency. Do not rewrite an allegation into a fact. “Anonymous source alleged payments were used to influence procurement” and “payments were bribes” are very different statements. Preserving that difference protects both the customer and the quality of the investigation.

Next, define the questions that matter. Which customer, account, legal entity, beneficial owner or connected person is in scope? Which transaction period matters? What business event may explain the payment? Is there a public official, tax liability, procurement decision, licence, concession, customs event or other relevant external event? What evidence would support the suspicious hypothesis, and what evidence would support an innocent explanation? What information can the bank obtain lawfully from its own systems, the customer, reliable public sources or another group entity?

A hypothesis-led decision flow prevents investigators from treating an initial allegation as a proven predicate offence.

From predicate conduct to proceeds

For AML purposes, the bank is interested not only in whether misconduct may have happened but in the financial consequence. Corruption can generate proceeds directly, such as stolen public funds, or indirectly, such as profits from a contract secured through a bribe. Tax crime can involve value retained through deliberate criminal evasion, false refund claims, fraudulent deductions, VAT carousel activity, customs fraud or other offences defined by local law. The financial trail may therefore begin before, during or after the suspected predicate event.

Investigators should build the economic story. What did the customer obtain or avoid paying? Who benefited? What amount can reasonably be linked to the event? How did value enter the banking system? Where did it move next? Which payments represent normal business costs and which appear unnecessary, circular, disguised or personally beneficial? A case is stronger when the money movement makes sense in the context of the suspected conduct rather than merely looking unusual in isolation.

Corruption investigations often require attention to third-party intermediaries. Agents, advisers, introducers, distributors and subcontractors can be legitimate. Risk rises when the intermediary was appointed without a clear commercial need, lacks relevant capability, receives success-based or unusually high fees, uses vague invoices, requests payment to a different entity or country, has political or family connections, or receives funds close to a regulatory or procurement decision. None of these features alone proves bribery. Together, especially when supported by ownership or communication evidence, they may justify escalation.

Tax-predicate investigations require similar discipline. A bank should distinguish suspicious proceeds from ordinary tax planning, civil disputes and administrative mistakes. If the concern is criminal tax evasion, the investigator should identify the behaviour that may be criminal under the relevant law: deliberate concealment of income, false documentation, sham arrangements, fraudulent refund claims or another locally defined offence. Where the bank does not have enough information to characterise the tax issue, the case should say so rather than inventing certainty.

Evidence triangulation

Complex cases are rarely solved by one document. Triangulation means asking whether independent categories of evidence tell the same story. The strongest case files usually combine customer and KYC information, ownership and control data, transaction records, accounting or invoice evidence, external events and relationship context.

Customer evidence establishes the expected business model, declared wealth, products, markets, counterparties and ownership. Payment evidence shows amount, date, currency, originator, beneficiary, agents, references and subsequent movement. Corporate evidence may reveal directors, shareholders, related entities and historical changes. Documentary evidence may include contracts, invoices, purchase orders, proof of service, tender records, tax documents or audited accounts where the bank is entitled to obtain them. External evidence may include official company registries, court or enforcement records, procurement announcements and credible media. The investigator should record provenance and effective dates because ownership, public-office status and corporate relationships change over time.

Timing can be as important as amount. A consultancy agreement signed days before a licence award, a commission paid immediately after a tender decision, a company incorporated shortly before it receives funds, a beneficial-owner change just before an enforcement announcement, or a “loan repayment” shortly after suspected proceeds arrive may be meaningful. A chronology helps prevent reviewers from missing relationships that are obvious only when events are placed side by side.

Source of wealth and source of funds are also different evidence questions. Source of funds asks where the specific money in the transaction came from. Source of wealth asks how the customer accumulated overall economic wealth. In a corruption case, a public official’s family member may be able to identify the immediate source of a transfer while still failing to explain the economic origin of the broader wealth. In a tax case, a company may show that funds came from an affiliate, while the underlying income or tax treatment remains unexplained. Investigators should not accept a banking transfer receipt as proof of legitimate economic origin.

Data and system architecture

A bank-grade investigation needs more than narrative. The case system should preserve identifiers that allow facts to be reconstructed: customer and account IDs, legal-entity and beneficial-owner relationships, transaction IDs, timestamps, source systems, document versions, screening or monitoring alert IDs, external-source references, reviewer actions, approvals and outcome codes. When evidence is updated, the bank should be able to see what the investigator knew at the time of the decision rather than only the latest version of the data.

Relationship data is especially important. Complex ABC and tax cases frequently involve a person who is not the direct customer: an official, family member, intermediary, director, shareholder, professional adviser or connected company. A relationship graph should distinguish verified ownership from alleged or inferred relationships and record effective dates. That avoids the common error of displaying every connection as equally certain.

Transaction reconstruction should support both account-level and network-level views. Account-level review explains inflows, outflows, balances and changes against expected activity. Network review reveals pass-through movement, common beneficiaries, circular flows and concentration around intermediaries. Analysts should be able to trace value without losing the original payment attributes, currencies or dates through repeated aggregation.

Document systems should preserve original files and extracted attributes separately. If an invoice amount or beneficiary is captured through OCR or manual entry, the case should identify the source and allow a reviewer to return to the original document. A system-generated interpretation is evidence about the document, not a replacement for it.

A complex ABC or tax-predicate investigation depends on joined but separately governed data from KYC, payments, documents, ownership, external sources and case workflow.

Detection and monitoring patterns

There is no single “bribery transaction” or “tax evasion transaction,” so monitoring should focus on combinations of context and behaviour. Examples include unexplained payments to newly created intermediaries; round-sum or repeated payments described as consulting, marketing or facilitation; payments to countries unrelated to the contract; rapid onward transfer to individuals or connected entities; excessive commissions relative to the underlying transaction; flows inconsistent with declared business activity; sudden wealth that conflicts with known income; circular shareholder loans; or funds moving through entities with no obvious economic role.

The bank should be cautious with rules based only on occupation, nationality, PEP status or offshore location. Such rules create noise and can lead to unfair customer outcomes. A better design combines customer risk, relationship context, payment behaviour and evidence of the underlying business event. A PEP connection may increase the relevance of a consultancy payment, but it does not by itself make the payment suspicious. An offshore company may be legitimate; the question is whether its role, ownership and economics can be understood.

For tax-related risk, monitoring scenarios should avoid trying to calculate a customer’s tax liability from incomplete banking data. Banks typically do not have the full facts needed to determine tax due. More useful detection focuses on patterns consistent with concealment or fraud: repeated transfers to undisclosed related entities, unexplained movement between personal and business accounts, false-looking invoice chains, circular funds, activity inconsistent with tax-residency information the bank lawfully holds, or suspicious refund-related flows. Any tax conclusion must remain within the bank’s mandate and local legal framework.

Investigation workflow and decision discipline

A mature workflow separates facts, analysis, hypotheses, gaps and decision. Facts are verifiable observations: a payment occurred, an entity was incorporated, a person held a role, an invoice says a service was provided. Analysis explains relevance: the service description is vague and the payee appears unrelated to the project. Hypotheses are propositions to test: the invoice may conceal a payment made to influence a contract award. Gaps are unresolved questions: the bank has no evidence of work performed. The decision explains what the evidence supports and what action follows.

Investigators should actively look for disconfirming evidence. A consultant may initially look suspicious but later provide a credible scope of work, market-rate fee, staff records and deliverables that align with the project. A large transfer may initially appear to represent undeclared income but later be supported by a documented asset sale. Closing a concern with strong contrary evidence is a successful investigation, not a failure to find wrongdoing.

Where concerns remain, escalation can involve enhanced due diligence, additional monitoring, restriction of a transaction where permitted, customer-risk reclassification, ABC compliance review, tax-specialist or legal advice, employee investigation, relationship-exit consideration, and suspicious transaction or activity reporting under the applicable regime. These outcomes are not interchangeable. Filing an STR does not automatically require account closure. Account exit does not replace reporting. A tax-reporting correction does not resolve an AML concern. Each outcome needs its own authority and rationale.

Suspicious reporting thresholds and filing deadlines are jurisdiction-specific. The investigator does not generally need to prove the predicate offence to the criminal standard before escalating suspicion, but the exact legal threshold must come from local law and the bank’s approved policy. The case record should avoid language such as “customer committed bribery” unless there is a proper basis for that assertion. Safer and more accurate wording distinguishes observed facts from suspected conduct.

Confidentiality, privilege and information sharing

Complex ABC and tax investigations can involve legally sensitive information. Whistleblower identities, employee investigations, legal advice, tax data, suspicious-reporting information and law-enforcement requests may each have specific confidentiality controls. Cross-border groups may also face data-localisation, privacy, bank-secrecy or professional-privilege restrictions. The correct response is not to block information sharing reflexively, but to route it through approved legal and information-sharing rules.

Within a financial group, teams should know which information can be shared for AML risk management, which information requires access restrictions, and which records must not be disclosed to the customer. Investigators should never improvise around tipping-off rules. Customer requests for information, complaints and relationship-manager conversations need scripts and escalation paths that protect legal obligations while avoiding unnecessary or misleading statements.

Building the event timeline

A chronology is one of the best tools for complex investigations because it aligns business, financial and external events. Start with the earliest relevant relationship or transaction and plot changes in ownership, customer profile, public-office status, contracts, invoices, payments, withdrawals, investments, tax events, alerts and external developments. Keep the source behind each event so another investigator can verify it.

The timeline should not be built to “prove” the preferred hypothesis. It should include facts that weaken it. If a consultant was appointed two years before the public tender, that matters. If a customer disclosed the relevant entity at onboarding, that matters. If a tax authority later confirms a civil settlement rather than criminal proceedings, that matters. Balanced timelines improve the credibility of escalation and closure decisions alike.

A chronology can expose or weaken the suspected link between business events, invoices, payments, ownership changes and later movement of value.

Roles and governance

No single team owns every conclusion in these cases. The financial-crime investigator owns the AML investigation within delegated authority. The MLRO or equivalent reporting officer owns suspicious-reporting decisions where local governance assigns that role. ABC compliance may own bribery-risk policy and internal escalation. Tax specialists may explain tax-reporting structures without deciding the AML outcome. Legal advises on law, privilege, employment issues, information sharing and enforcement contact. Fraud, sanctions, security and employee-investigations teams may have parallel concerns. Relationship managers provide customer and business context but should not control an independent suspicious-activity decision.

The governance design needs explicit boundaries. The bank should know who can request further customer information, who can restrict an account, who can approve exit, who can file a report, who may contact authorities, and who can access sensitive investigation records. For high-impact cases, a multidisciplinary forum can be valuable, but the forum should not blur statutory decision rights or create groupthink.

Quality assurance should test reasoning, not just form completion. Reviewers should ask whether the hypothesis is clear, whether evidence is sourced, whether alternative explanations were considered, whether legal claims are appropriately scoped, whether the transaction analysis supports the narrative, and whether the outcome follows policy. Repeated weaknesses should feed back to training, data quality, scenario calibration and process design.

Complex predicate investigations need clear decision rights across AML, ABC, tax, legal, business, fraud and assurance functions.

What good looks like

A strong complex ABC or tax-predicate case is not the longest case. It is the case in which a later reviewer can answer five questions quickly. What triggered the investigation? What possible predicate conduct was considered and under which jurisdictional assumptions? What financial benefit or proceeds may be involved? Which evidence supports and contradicts the concern? Why did the bank choose its final reporting, monitoring, restriction, remediation or relationship decision?

That standard protects the bank from two opposite failures. The first is under-reaction: accepting vague invoices, opaque intermediaries or unexplained wealth because no single fact proves a crime. The second is over-reaction: treating political exposure, tax complexity or offshore structures as guilt. Good investigation sits between those extremes. It uses the bank’s unique view of customers and money movement to form a defensible suspicion where warranted while preserving the discipline to close concerns that are properly explained.

The next supplements take this operating model deeper into evidence engineering, system requirements, testing and a realistic multi-stage case.

Operational deep dive: evidence engineering for complex predicate cases

Complex ABC and tax-predicate investigations become difficult when the case crosses several evidence domains at once. The customer file may look ordinary, the payment may have a plausible description, the beneficial owner may be several layers away, and the suspected misconduct may have happened in another country. The investigator therefore needs an evidence model that can connect business purpose, ownership, payment behaviour, public or tax events and later movement of value without pretending that any one source is conclusive.

Start with an investigation hypothesis and evidence matrix

A useful case begins with a testable proposition. Suppose a corporate customer won a public infrastructure contract and, shortly afterwards, paid a large “advisory fee” to a newly incorporated company. The payment alone proves little. A better working hypothesis is that the advisory company may have been used to divert part of the contract value to a person connected to the award process. The investigator can then identify what evidence would increase or reduce that concern.

Evidence supporting the concern might include a close temporal link to the award, no meaningful deliverables, an unusually high fee, ownership or control connected to an official, onward movement to the official or family, false descriptions in invoices, or a payment route inconsistent with the stated service. Evidence weakening the concern might include a long-standing adviser relationship, credible specialist staff, documented work, market-rate pricing, normal tax treatment and payment to the contracted entity in its operating jurisdiction.

The same discipline applies to tax predicates. “Customer has offshore entities” is not a useful hypothesis. A more specific hypothesis may be that the customer deliberately diverted taxable business income to a related shell company, represented the transfers as deductible consulting expenses, and later returned value through shareholder loans. Investigators should then test whether the entities performed real services, whether the customer disclosed them, whether the payment flows align with the purported service, and whether the relevant conduct could constitute a criminal tax offence under the applicable law. Tax specialists or legal counsel may be required to interpret the legal threshold; the AML investigator should not improvise it.

An evidence matrix helps keep reasoning honest. For each question, record the relevant source, what it shows, reliability, date, whether the evidence supports or contradicts the hypothesis, and what remains unresolved. That structure prevents a dramatic adverse-media article from dominating stronger contrary evidence, and it exposes cases where investigators are repeating the same underlying allegation across several sources rather than obtaining independent corroboration.

Payment analysis: follow value, not just payment descriptions

Payment narratives are useful but weak evidence on their own. A transfer marked “consultancy,” “loan,” “marketing,” “tax,” or “commission” should be tested against the customer’s business model and other records. Investigators should look at the full payment chain: funding source, payer, beneficiary, receiving bank, currency, timing, connected payments, cash withdrawals, securities purchases, property-related transfers and rapid onward movements.

A bribery scheme may use several layers. A corporate customer pays an agent under a legitimate-looking agreement. The agent pays another company described as a subcontractor. That company sends funds to a family member of a public official or pays for property, education, travel or another benefit. The bank may see only one or two legs. The investigator should therefore distinguish direct evidence from inference. If the bank cannot see the final beneficiary, the case should state that the available pattern is consistent with possible onward transfer rather than asserting a completed bribery chain.

Round-sum payments, unusual percentages, repeated fee amounts just under approval thresholds, back-to-back transfers and rapid depletion can be relevant, but none is inherently corrupt. Context gives them meaning. A 5% commission may be normal in one sector and extraordinary in another. A payment to another jurisdiction may reflect a regional service centre. Investigators should avoid arbitrary numerical rules unless the bank has validated them for the relevant population.

Tax-predicate analysis likewise benefits from value reconstruction. The question is often whether apparent business payments have genuine substance or whether funds were diverted, concealed or returned to the beneficial owner. Look for mismatches between invoice dates and service periods, repeated transfers to dormant or newly incorporated entities, payments to personal accounts, circular loans, unexplained capital contributions and rapid return of funds. Where the concern involves VAT, customs, payroll or another indirect-tax mechanism, investigators should involve specialists rather than infer tax liability from account data alone.

Invoices, contracts and proof of service

False or misleading documentation is a common feature in both bribery and tax-crime cases, but banks need a proportionate review standard. Not every invoice needs forensic examination. The depth should respond to the risk. When an intermediary payment is material and the commercial purpose is unclear, useful questions include: What service was contracted? Who performed it? Why was the intermediary needed? What deliverable exists? How was the fee calculated? Which business unit approved it? Does the beneficiary match the contract? Are the dates consistent? Is the invoice wording specific enough to explain value received?

A document that looks professional may still be weak evidence. Repeated generic descriptions, inconsistent fonts, impossible dates, missing company details or reused invoice numbers may create questions, but visual appearance should not substitute for substantive verification. A genuine invoice can document a sham service, and a poorly formatted invoice can support a legitimate small business transaction. The investigator’s focus should remain on economic substance and corroboration.

Books-and-records issues can also be relevant to ABC controls. A payment recorded as “marketing” when it was actually a government-relations success fee may indicate that internal accounting did not reflect the real purpose, even if the bank cannot determine whether a bribery offence occurred. Such facts may require escalation to ABC compliance or internal audit while the AML team separately considers whether criminal proceeds or suspicious activity are involved.

Ownership, control and related-party analysis

Complex cases often depend on who truly benefits from an entity. Current KYC data may not be enough because ownership can change around the time of the suspected conduct. Investigators should reconstruct ownership and control as of the transaction date where possible. Corporate registries, customer documentation, group records and reliable external sources may all contribute.

The case file should separate legal ownership, beneficial ownership, control and other relationships. A public official’s sibling being a director is not the same as the official owning the company. A nominee arrangement may be alleged but unverified. A family connection may increase risk without establishing beneficial ownership. Precision matters because weak relationship labels can turn an uncertain association into an apparently definitive corruption conclusion when the case is reviewed later.

Historical relationship graphs are especially valuable. The system should preserve effective dates so investigators can see that a shareholder transferred ownership shortly before a tender, or that an intermediary was incorporated immediately before receiving the first payment. The same graph can reveal that a relationship actually predates the suspected event by years and therefore weakens the theory of a newly created conduit.

Source of wealth, source of funds and unexplained enrichment

Source-of-wealth review should be evidence-led rather than formulaic. A customer may have legitimate wealth from business ownership, inheritance, investments, employment or asset sales. The investigator needs to understand whether the customer’s known economic history can reasonably support the observed assets or flows. Where wealth has increased sharply around suspected corrupt activity, the timing and source deserve attention, but the bank should not make an “illicit enrichment” legal finding unless applicable law and evidence support it.

Source of funds is transaction-specific. A statement showing that money came from Company A answers only the immediate question. If Company A is controlled by the customer and was funded moments earlier from an unexplained third party, the deeper source remains unresolved. Complex investigations should trace through superficial funding labels until the bank reaches a credible economic origin or identifies the point where visibility ends.

For tax cases, the same distinction helps avoid false closure. A customer may prove that a transfer came from a foreign company but not explain whether the underlying income was declared, whether the entity performed real economic activity or whether funds were being returned through a disguised loan. The AML team should document the gap and, where policy allows, obtain tax-specialist input rather than trying to adjudicate tax compliance itself.

Public officials, PEPs and corruption risk

PEP status is a risk factor, not evidence of wrongdoing. FATF PEP standards support enhanced risk management because public functions can create exposure to bribery, embezzlement and abuse of office. In investigation practice, the useful question is not simply “is someone a PEP?” but “what role did this person have at the relevant time, and could that role connect to the customer’s economic event?”

An official responsible for an unrelated ministry may have little relevance to a private procurement payment. A lower-profile official who had direct influence over a licence may be far more relevant. Investigators should capture role, authority, dates and relationship to the business event. Former officials, family members and close associates require similar temporal care because status and influence may change.

Tax crimes: keep criminality separate from tax complexity

OECD’s Ten Global Principles explain that tax crimes are treated as money-laundering predicates internationally, but each jurisdiction defines the offences and seriousness thresholds in domestic law. This matters greatly for banks. Aggressive tax planning, an uncertain tax position, late filing, a civil audit adjustment and deliberate criminal evasion are not the same thing.

Investigators should therefore avoid generic statements such as “tax avoidance is money laundering.” The case should identify the behaviour that creates concern and the legal basis, if known. If the bank has evidence of false invoices, concealed income or fraudulent refund claims, that may support a tax-crime hypothesis. If the issue is merely an unusual structure with no evidence of criminal conduct, the bank should not manufacture a predicate offence to justify escalation.

Tax secrecy and information-sharing rules also vary. A group entity may hold tax-reporting data that another investigator cannot automatically access. Data obtained for CRS, FATCA or local tax-reporting purposes may have use restrictions depending on jurisdiction and implementation. Design should therefore include clear entitlement and legal-purpose controls rather than assuming that every dataset in the bank is available for every investigation.

External information and adverse media

External information can transform a case, but source quality needs explicit assessment. Official court records, regulator announcements, public procurement databases and company registries generally carry different evidential weight from anonymous posts or republished allegations. Credible journalism may reveal relationships or events not yet reflected in official sources, but the investigator should trace claims to the earliest reliable source where possible.

A common failure is source multiplication: ten news articles all repeat the same unverified allegation, and the case summary treats them as ten independent confirmations. The evidence matrix should identify common origin and distinguish repetition from corroboration. Another failure is temporal mismatch. A person may have become a director after the suspicious transactions, or an enforcement action may concern a different period. Effective dates should be recorded for every relationship that materially supports the hypothesis.

Requests for information and customer contact

Requests for information should be targeted. Asking a customer for “all documents about this transaction” can create volume without clarity and may reveal too much about the concern. Better requests focus on ordinary due-diligence needs: contract, invoice, service description, relationship to counterparty, ownership, proof of delivery, business rationale or source of funds. The wording must follow local rules, especially where suspicious-reporting confidentiality or tipping-off restrictions apply.

The investigator should plan before contacting the customer. Which hypothesis is being tested? What answers would resolve the concern? Which answers would require escalation? Does another team already hold the information? Could the request prejudice an internal or law-enforcement investigation? Is legal approval required? This prevents repeated, inconsistent customer contact and protects the integrity of sensitive cases.

From evidence to conclusion

A defensible conclusion is calibrated to what the evidence shows. It can say that the bank identified unexplained third-party payments closely linked in time to a public procurement decision, that the intermediary’s ownership is connected to a relevant official’s family, and that no credible service evidence was provided. It should not say the official accepted a bribe unless the bank has a proper basis for that claim.

The conclusion should also explain alternative explanations considered and why they were accepted or rejected. If the customer provided evidence that partly resolves the concern, record it. If the bank cannot verify a key relationship, say so. Suspicion often rests on a coherent accumulation of facts rather than one decisive document. Transparent uncertainty makes the case stronger because it shows that the investigator is analysing rather than prosecuting.

Finally, map the outcome to the bank’s authorities: suspicious-reporting consideration, enhanced monitoring, customer-risk change, ABC referral, tax-specialist review, employee investigation, restriction, remediation or relationship decision. A complex case may need several outcomes, but each should have a named owner and separate rationale.

Advanced practice: architecture, controls and assurance

Complex predicate investigations fail as often through weak data and workflow as through weak investigator judgement. A bank may have excellent policy but still produce poor outcomes if ownership history is overwritten, invoice evidence is stored outside the case, transaction links cannot be reconstructed, or ABC and AML teams reach separate decisions without seeing each other’s facts. Advanced practice therefore treats the investigation as a controlled information system as well as a compliance process.

Design the case around entities, events and evidence

The core data model should separate entities, relationships, events, evidence items and decisions. Entities include customers, accounts, companies, natural persons, counterparties and external organisations. Relationships include ownership, control, family connection, employment, public office, agency and payment relationship. Events include onboarding, ownership changes, public decisions, contracts, invoices, transfers, alerts, reviews and enforcement developments. Evidence items point to their original source and capture date. Decisions record the authorised owner, rationale, policy basis and effective time.

This structure matters because complex cases change over time. A company that is innocuous today may have had a different owner when the suspicious transfer occurred. A person who is no longer a public official may have held decision-making authority at the relevant date. A customer may provide a new document after an initial escalation. The system should preserve the historical state rather than silently rewriting the past with current data.

A useful architecture also distinguishes asserted, verified and inferred relationships. If adverse media alleges that a director is acting for a public official, that is not the same as a registry-confirmed beneficial owner. Investigators can use both, but the confidence level must travel with the relationship. Otherwise graph visualisation can create false certainty simply because every edge looks identical on screen.

Evidence provenance and lineage

Every material fact should be traceable. If an investigator states that a payment beneficiary was owned by a relative of an official, the reviewer should be able to identify the source, date, entity identifiers and verification status. If a monitoring scenario uses tax-residency or PEP data, the bank should know which upstream system supplied it and whether the value was current when the alert fired.

For documents, preserve the original file, extracted fields and any analyst correction. OCR may read an invoice number incorrectly. A data-enrichment service may return a stale director. A public registry may later amend a filing. The case should show both the original observation and the correction. This is particularly important when a report has already been filed or an account restricted on the basis of earlier evidence.

Data minimisation still applies. The case should not become an uncontrolled repository for every tax, employee or whistleblower record the bank can technically access. Entitlements, retention and purpose restrictions should be designed with legal and privacy teams. Sensitive data may require compartmentalised access while still allowing the AML decision-maker to understand the relevant conclusion.

BA requirements that are specific enough to build

A requirement such as “the system shall support corruption investigations” is not buildable. A stronger requirement identifies the user, trigger, data, decision and audit outcome. For example: when an investigator links an external person to a customer as a possible family member of a public official, the system must capture relationship type, source, confidence, effective dates and reviewer status; it must not automatically convert that relationship into beneficial ownership or PEP status.

For transaction reconstruction, specify how investigators search by account, counterparty, amount, period and reference; how linked transfers are grouped; how currency conversion is displayed; how exports preserve transaction IDs; and how reviewers return from a case narrative to the underlying payment. For evidence, specify immutable source references, version history, access controls and the ability to mark a document as superseded without deleting it.

Workflow requirements should define who can create hypotheses, request information, change risk ratings, recommend reporting, approve reporting, restrict transactions or close a case. High-risk actions should not depend on free-text conventions. The system should enforce segregation where policy requires it and record emergency overrides with reason and approval.

Detection design without pretending to identify the crime

Analytics can help find cases but should not label customers as corrupt or tax criminals. A useful model might detect an unusual combination: high-risk intermediary, recent incorporation, public-contract timing, payment amount outside peer behaviour and rapid onward transfer. The output should be a reviewable signal explaining the features that contributed to detection.

Scenario design should include negative populations. Legitimate consultants, government contractors, international tax structures and PEP-connected customers need to be represented in testing so the bank can measure unnecessary friction and bias. A model that detects every foreign consultancy payment may appear sensitive but will overwhelm operations and encourage mechanical closure.

Feedback from investigations should improve detection, but closure codes need quality. “False positive” is too broad. The bank benefits from knowing whether the alert was explained by a long-standing supplier, documented service, known group treasury arrangement, data error, mistaken relationship, or another reason. This allows calibration teams to reduce noise without suppressing genuinely risky patterns.

Test the evidence chain, not only the screen

Positive testing should use realistic end-to-end cases. Seed a customer with known ownership, a newly created intermediary, an invoice, a public-procurement event and a sequence of payments. Verify that the alert is generated, the investigator can see all material facts, the graph preserves effective dates, evidence can be attached, the reporting decision is routed correctly and the audit trail records every material action.

Negative testing should prove that legitimate activity can be explained. A well-documented consultancy arrangement with appropriate ownership, real deliverables and market-rate fees should not become a permanent high-risk case simply because a public-sector customer is involved. A cross-border holding company with fully evidenced business purpose should not fail because the architecture treats “offshore” as a risk outcome.

Boundary testing matters for tax cases. Test civil tax adjustments, voluntary corrections and aggressive but lawful tax planning alongside deliberate false-document scenarios. The system should allow investigators to express uncertainty and seek specialist advice rather than forcing a binary “tax crime yes/no” field.

Temporal tests are essential. Change the beneficial owner after the suspicious payment and verify that the historical case still shows who owned the entity at the payment date. Add a new PEP role after case closure and test whether event-driven review is triggered according to policy. Remove an external-source record and confirm that the bank retains the evidence snapshot needed to explain its earlier decision, subject to lawful retention requirements.

Failure-mode testing should simulate unavailable registries, incomplete KYC, duplicated transactions, delayed PEP updates, missing documents, contradictory customer information and case-management outages. The operational procedure needs a safe fallback for each condition. Investigators should know when they may proceed with documented limitations and when missing evidence requires escalation or a temporary hold under applicable policy.

Human oversight of automation

Summarisation, entity resolution and graph analytics can reduce investigator effort, but they create new control risks. A language model may turn an allegation into a fact, merge two people with similar names, omit a contradictory document or produce a confident legal statement from incomplete information. Automated summaries should therefore point back to source evidence and be reviewable before they enter the formal rationale.

Entity-resolution tools need thresholds and human challenge. Matching a director to a public official’s family member can be highly consequential. Name, date of birth, address, nationality, identifiers and relationship evidence should be considered according to the bank’s approved matching methodology. Investigators must be able to reject a suggested match and preserve the reason.

No automated score should decide suspicious reporting by itself. Models can prioritise cases and identify patterns, but the final decision depends on legal threshold, context and evidence. Governance should document what the model does, training or rule sources, limitations, change control, performance monitoring and override processes.

Quality assurance and management information

QA should sample both escalations and closures. If review focuses only on filed reports, the bank may never discover that strong cases are being closed early. Samples should cover different products, jurisdictions, customer types, investigators and outcomes. Findings should distinguish factual errors, reasoning gaps, policy errors, missing evidence, weak writing and system defects because each needs a different remediation owner.

Useful management information goes beyond case volume. Track ageing by risk, unresolved information requests, repeat intermediaries, linked customers, outcome distribution, report quality, reopen rates, QA failures, system-data gaps and customer-impact measures. High volumes of “no concern” closures may indicate poor detection calibration; high report rates may indicate over-escalation or genuinely severe risk. Numbers need interpretation rather than targets that encourage investigators to file or close at a predetermined rate.

Governance for intersecting disciplines

ABC, AML and tax functions should share relevant facts without collapsing their roles. ABC compliance may conclude that a third-party appointment breached internal policy even when the AML threshold for suspicion is not met. Tax specialists may identify a reporting error without concluding it is criminal. AML may file a suspicious report while employment or disciplinary proceedings remain unresolved. Legal may restrict how parts of the information can be shared.

A governance map should therefore assign each decision explicitly. The case owner coordinates facts; specialist functions provide scoped conclusions; the MLRO or delegated officer owns the reporting decision where required; business leaders own commercial risk within their authority; and audit or independent testing assesses whether the whole framework works. Escalation forums should record decisions and dissent rather than producing a vague collective outcome that nobody owns.

The strongest implementation is one where a regulator, auditor or successor investigator can reconstruct the case years later: what the bank saw, what it believed, what uncertainty remained, who decided, and how the bank changed its controls after learning from the case.

Practice close: making the investigation defensible

A complex ABC or tax-predicate investigation should leave the next reviewer with a coherent evidence trail rather than a pile of documents. Before closing or escalating, step through the case as if you knew nothing about it. The trigger, hypothesis, evidence, alternative explanations, jurisdictional assumptions, financial trail and decision should all be understandable without relying on the original investigator’s memory.

Reviewer questions

The first question is whether the case has identified a possible predicate rather than merely a risky customer characteristic. Political exposure, offshore structures, consultants, high taxes or tax complexity are context, not criminal conduct. The file should explain the suspected act: for example, an intermediary payment potentially connected to a public decision, or a sham expense potentially used to conceal taxable income. If the file cannot state the hypothesis clearly, more analysis may be needed before severe action is justified.

The second question is whether the financial consequence is understood. What value may have been generated, retained or moved? Does the transaction trail actually connect to the suspected conduct, or has the analyst simply found unrelated unusual payments? The answer need not be complete, but the limits of visibility should be explicit.

The third question is evidence quality. Are ownership relationships verified or alleged? Are dates effective at the time of the transaction? Does a media story trace to an official record, named source or another article? Are invoices supported by contracts and deliverables? If a tax conclusion is mentioned, has a qualified specialist or approved legal interpretation been used where necessary?

The fourth question is balance. What innocent explanation was considered? What evidence contradicts the suspicious theory? A case that records only adverse facts is vulnerable to confirmation bias. Investigators should be willing to close concerns when credible evidence explains the activity, and equally willing to escalate when explanations remain inconsistent or unsupported.

The fifth question is whether each outcome has the right owner. Suspicious reporting, customer restrictions, relationship exit, ABC remediation, tax correction, employee discipline and law-enforcement response are separate decisions. One does not automatically trigger the others. The case should name the accountable owner and policy or legal basis for each action.

Practical acceptance criteria for delivery teams

A BA or tester can turn those reviewer questions into acceptance criteria. The case workflow should preserve the original trigger and source. It should allow more than one hypothesis without forcing a criminal conclusion. Relationships should carry type, source, confidence and effective dates. Material evidence should be versioned and traceable. Transaction exports should preserve identifiers. Reviewers should be able to see the chronology, follow linked entities, inspect the underlying evidence and distinguish facts from analyst interpretation.

Testing should include a genuine corruption-risk case, a genuine tax-predicate case, a mixed case, and legitimate activity that resembles each. It should also include incomplete and contradictory evidence. The expected behaviour is not simply “alert fires.” The expected behaviour is that the bank reaches a reasoned outcome without losing data, overstating the facts or bypassing required authority.

A negative test is especially valuable. Give the investigator a politically connected consultant who has a long operating history, credible staff, detailed deliverables, market-rate fees and no unexplained onward movement. The system and procedure should support a documented closure rather than effectively requiring suspicion because PEP context is present.

For a tax boundary test, provide a customer with a complex structure and a known civil tax dispute but no evidence of deliberate falsity or concealment. The investigator should be able to record the issue, obtain specialist advice and close the criminal-tax hypothesis if appropriate. A control that converts every tax dispute into suspected money laundering is not risk-based and will damage both customers and investigative quality.

Common misconceptions to avoid

A bank does not need to act as prosecutor before considering a suspicious report, but it also should not describe suspicion as proven guilt. The legal reporting threshold is local and must be applied through approved policy.

A PEP connection raises relevance but does not establish bribery. A success fee can be legitimate. An offshore company can have genuine substance. A tax adjustment can be civil. A false-looking invoice can still reflect a real service. Conversely, genuine services do not automatically rule out an improper side purpose. Complex investigations require the combined evidence, not shortcuts.

Tax crimes are included in the FATF designated categories of predicate offences, but domestic implementation varies. Investigators should not assume that the same conduct, threshold or reporting consequence applies in every jurisdiction. OECD guidance is particularly clear that countries define their criminal tax offences within domestic law.

The FATF framework and anti-corruption standards are mutually reinforcing, but AML, ABC and tax controls remain distinct. The best bank response is coordinated, not collapsed into one generic “financial crime” verdict.

Final mental model

Remember the sequence: suspected conduct → economic benefit or proceeds → people and entities → movement of value → evidence and alternative explanation → bank decision. Build the chronology, preserve provenance, test both sides of the hypothesis and state uncertainty plainly.

If a later reviewer can see why the concern arose, which facts matter, which facts do not, what remained unknown, and why the chosen actions were proportionate, the investigation is doing its job. If the file relies on labels such as “high risk,” “offshore,” “PEP,” “tax issue” or “consultant” without showing the economic and evidential story, it is not finished.

Masterclass: the infrastructure contract, the adviser and the hidden tax story

This case is fictional but constructed from recurring features described in public corruption, tax-crime and money-laundering guidance. It is designed to show how investigators reason through uncertainty. No single fact is treated as proof, and the final banking outcome is separated from any criminal-law conclusion.

Stage 1: an ordinary-looking customer

Northport Engineering is a long-standing corporate customer of a multinational bank. It builds transport infrastructure and receives most revenue from private and public-sector projects. KYC shows a stable ownership structure, audited accounts, several operating subsidiaries and expected cross-border supplier payments. The company is not itself a PEP and has no material adverse information at onboarding.

Two years into the relationship, Northport wins a large municipal rail contract in Country A. The contract award is publicly announced. Three weeks later, the company pays EUR 2.4 million to Meridian Strategic Advisory Ltd in Country B. The payment reference says “market-entry and stakeholder advisory.” Meridian was incorporated eight months earlier. The payment is not automatically suspicious: infrastructure companies legitimately use consultants, and cross-border advisory fees can be substantial.

A transaction-monitoring alert fires because the beneficiary is new, the amount is far above Northport’s historic consultancy payments and the funds are sent to a jurisdiction unrelated to the rail project. The analyst checks the customer file. Northport had never listed Meridian as a key supplier or intermediary. The first hypothesis is therefore modest: the payment may not be adequately explained by the known business profile and should be investigated.

Stage 2: the commercial explanation is thin

The relationship manager obtains a consultancy agreement and two invoices. The agreement says Meridian will provide “strategic access, stakeholder mapping and relationship facilitation.” It does not identify specific deliverables. The fee equals 2.0% of the rail contract’s initial value and is payable after the public award. Northport says this is a standard success fee for market-entry advice.

The investigator does not assume a success fee is a bribe. Instead, the evidence matrix asks whether Meridian appears capable of delivering the stated work and whether its role is commercially coherent. Public registry data shows one director and no obvious operating footprint. The address is shared with many entities. The bank has no payroll or operating account data for Meridian because it is not a customer.

A credible media report then states that Meridian’s director previously worked for a business owned by the brother of Country A’s deputy transport minister. The article does not say the minister owns or controls Meridian. This is a relevant relationship but not verified beneficial ownership. The case records it as an external-source connection, not as a fact that the official controls the company.

The hypothesis becomes more specific: Meridian may have been used as an intermediary to transfer value connected to the contract award, but the bank does not yet know who ultimately benefited or whether a bribery offence occurred.

Stage 3: the payment trail adds weight

Northport’s payment is followed, according to correspondent information available to the bank, by two transfers from Meridian: EUR 650,000 to a property company in Country C and EUR 400,000 to another advisory business. The bank cannot see the final owners of those recipients from its internal data. It therefore avoids calling them bribe recipients.

An internal group search identifies the property company as a customer of another branch, subject to local information-sharing permissions. Its beneficial owner is the deputy minister’s adult sibling. That fact materially strengthens the potential official nexus, but it still does not establish that the property transfer benefited the minister or was funded by Northport’s money. Timing and amount are consistent with a possible link; transaction-level tracing and legal interpretation are still needed.

The investigator builds a chronology: contract tender, Meridian agreement, public award, Northport invoice, Northport payment, Meridian onward payments, and subsequent property acquisition by the related company. The chronology makes the relationship visible without overstating causation.

Stage 4: a tax issue appears

During enhanced review, Northport provides internal management accounts showing that the Meridian fee was recorded as a deductible consulting expense. An internal whistleblower separately alleges that several “market-access” invoices were created to reduce taxable profit and move money to executives and intermediaries. The whistleblower provides no evidence that the particular Meridian invoice was fabricated.

This creates a second hypothesis, but the team keeps it separate. The possible corruption predicate concerns whether value was transferred to influence or reward a public decision. The possible tax predicate concerns whether Northport deliberately used false or sham expenses in a way that constitutes a criminal tax offence under the relevant law. The same invoice may be relevant to both, but the legal elements are different.

Tax specialists explain that a disallowed deduction or aggressive tax position is not automatically criminal. They need more evidence about intent, falsity and the applicable Country A and group tax rules. The AML investigator records that advice rather than writing “tax evasion confirmed.”

Stage 5: disconfirming evidence must be tested

Northport produces presentations, stakeholder reports and emails that appear to show some work by Meridian. Several documents pre-date the contract award. This evidence weakens a simple “no services existed” theory. It does not fully resolve the case because the fee still appears large, success-linked and connected to a politically exposed network.

The investigator asks a more precise question: were genuine services used as a cover for an additional improper purpose? This is common in complex investigations. A contract can be partly real and still be misused. Equally, an unusual commercial relationship can be legitimate even when a counterparty has political connections.

The team compares deliverables with the invoiced fee, checks approval records, reviews payment authorisation, maps known relationships and identifies whether similar success-fee arrangements exist in Northport’s other markets. It finds that Northport commonly uses advisers but normally pays fixed monthly fees and records detailed deliverables. Meridian is the only recent adviser paid a large post-award percentage.

Stage 6: banking outcomes

The accumulated facts create a defensible suspicion for AML escalation: a material success-based payment made immediately after a public contract award; an intermediary with limited apparent substance; a credible connection into the relevant political network; onward movement toward a company beneficially owned by the official’s sibling; and incomplete explanation for the economic value of the fee. The bank still does not claim it has proved bribery.

Under the relevant booking entity’s law and policy, the case is referred to the MLRO for suspicious-reporting consideration. ABC compliance separately opens a review of Northport’s intermediary governance. Tax specialists assess whether the invoice treatment creates a potential criminal-tax concern or only a tax-compliance issue. Legal controls communication because the whistleblower material and cross-border information have access restrictions.

The relationship is not exited automatically. Senior governance considers the customer’s response, remediation, future public-sector exposure and risk appetite. The bank imposes enhanced monitoring and requires additional approval for certain intermediary payments while the review continues. Whether those controls are permissible and appropriate depends on local law, contract and policy.

What the case teaches

The case works because no team tries to solve every legal question with one label. The AML investigation asks whether the bank has reasonable grounds for suspicion under its local reporting regime. ABC specialists assess intermediary and corruption-control concerns. Tax specialists determine what the tax facts may mean. Legal manages disclosure, privilege and cross-border constraints. Business leaders decide commercial risk within their authority.

The most important evidence is relational and temporal rather than dramatic: who was connected to whom at the relevant date, what business event occurred, when money moved, how the payment was described, what economic service can be evidenced, and where value went next. Complex predicate investigations become defensible when those facts are joined into a transparent chain while uncertainty remains visible.

References and further reading

These sources support the chapter's treatment of predicate offences, corruption proceeds, financial investigation, tax crime, bribery and cross-functional investigation. Transaction-level legal decisions must still follow the law and approved policy of the relevant jurisdiction and bank entity.