Offshore Financial Centres and Secrecy Jurisdictions

An offshore company, trust, foundation or investment vehicle is not automatically suspicious. Cross-border structures are used for legitimate investment, estate planning, fund administration, aircraft and shipping ownership, joint ventures, treasury, securitisation, intellectual-property management and many other ordinary commercial purposes. The financial-crime problem begins when the structure makes it unnecessarily difficult to understand who ultimately owns or controls the assets, why the structure exists, where the economic activity takes place, how the money was generated, and whether the transactions match the declared purpose.

That distinction is the central mental model for this chapter. A bank should not ask, “Is this customer offshore?” and treat the answer as a verdict. It should ask, “What does this cross-border structure make harder to see, and can the bank resolve that uncertainty with reliable evidence?” The answer may be completely satisfactory. It may require enhanced due diligence. It may reveal a tax-reporting problem, a sanctions or corruption exposure, a money-laundering concern, or a structure the bank cannot understand well enough to accept. The control is therefore about transparency, rationale and behaviour, not about a geographic label by itself.

The terminology also needs care. “Offshore financial centre” is used by governments, international organisations, academics and the market in different ways; there is no single universal legal category that determines a bank’s customer outcome. “Secrecy jurisdiction” is similarly a risk or policy description, not a FATF legal classification. Some financial centres have sophisticated supervision, beneficial-ownership registers, tax-information exchange arrangements and mature professional-services sectors. Others may have material transparency or cooperation weaknesses. A bank must use current, credible jurisdiction information rather than inherited stereotypes.

This chapter explains how to turn that principle into a real banking control. It connects customer due diligence, beneficial ownership, source of wealth and funds, tax transparency, sanctions and PEP screening, transaction monitoring, corporate-registry data, case management, escalation, suspicious-activity processes, data architecture and testing. It is written for compliance teams, investigators, operations, relationship managers, business analysts, architects, developers, testers, product owners and learners who need to understand the whole control chain.

Cross-border structure map showing how a bank looks through legal layers to the natural persons, purpose, assets and activity behind an offshore arrangement.

Start with the right question: opacity, not geography

The practical risk is opacity that cannot be reasonably explained or resolved. A customer incorporated in a well-known international financial centre may be low or moderate risk when its owners are transparent, its commercial purpose is clear, its audited accounts and tax position are coherent, and its transactions match the business model. A domestically incorporated company can be higher risk if it is owned through several opaque entities, uses nominee arrangements, has unexplained controllers, receives third-party funds and cannot show the economic purpose of its activity. Geography matters, but it is only one part of the evidence.

This is why an “offshore = high risk” rule is weak control design. It creates unnecessary customer friction, pushes analysts toward checkbox behaviour and can cause indiscriminate de-risking. FATF’s risk-based approach expects institutions to identify, assess and understand risk and apply measures that are commensurate with it. FATF has also repeatedly warned against wholesale termination of entire customer classes without assessing individual risk and available mitigants.

A better assessment separates several questions.

Who is behind the structure? The bank needs the natural persons who ultimately own or control the customer, together with the ownership and control chain that connects them to the account-holding entity. Percentage ownership may be relevant, but control can also arise through voting rights, agreements, trustee powers, protector rights, appointment rights or other means. The exact legal tests depend on the applicable AML and sanctions framework.

Why does the structure exist? A credible explanation should connect the legal arrangement to an economic, investment, financing, family, regulatory or operational purpose. “Tax efficiency” may be a legitimate part of a structure, but it is not a complete answer if the bank cannot understand the underlying activity, tax residence, asset ownership or controlling persons.

Where is the real activity? The place of incorporation, management, employees, customers, suppliers, assets, tax residence and banking can be different. Those differences are not inherently wrong. They become important when they contradict the stated purpose or create unexplained gaps.

Where did the value come from? Source of wealth explains how the customer or beneficial owner accumulated overall wealth. Source of funds explains the origin of the specific money entering a relationship or transaction. For higher-risk structures, both may matter. The bank should seek evidence proportionate to the risk rather than merely collect a declaration.

How does the money move? Transaction behaviour can validate or contradict the onboarding story. A holding company may legitimately receive dividends and make investments. A trading company should normally show activity consistent with trade. A special-purpose vehicle should show flows consistent with the transaction it was created to support. Repeated unrelated third-party payments, rapid pass-through, circular transfers or unexplained loans can change the risk view.

These questions produce a much more defensible result than a country score alone.

What FATF expects from beneficial-ownership transparency

FATF Recommendation 24 addresses transparency and beneficial ownership of legal persons. The standard was strengthened in 2022, and FATF’s March 2023 guidance explains the expectation that competent authorities should be able to obtain adequate, accurate and up-to-date beneficial-ownership information. FATF promotes a multi-pronged approach because no single source is always complete or reliable. Company information, registries, regulated-service-provider records and other sources can complement one another.

For banks, the practical lesson is simple: a registry result is evidence, not infallible truth. The bank may be required by local law to consult a beneficial-ownership register, but it should still resolve material inconsistencies with customer documents, ownership charts, corporate filings and other reliable sources. The right approach is not to distrust every register; it is to understand the evidence quality and the bank’s legal obligation in the relevant jurisdiction.

Recommendation 25 performs a similar transparency function for trusts and other legal arrangements. FATF strengthened the standard in 2023 and published updated guidance in March 2024. Trusts require a different mental model from companies because legal ownership of assets may sit with trustees while economic benefit and control can involve settlors, beneficiaries, protectors and other persons. The bank’s data model therefore needs relationship roles, not just a flat shareholder percentage.

Recommendations 24 and 25 are global standards implemented through national law. They do not create one universal ownership threshold, one universal registry model or one universal definition of control for every bank. The bank must preserve the jurisdiction-specific rule that drove its decision.

FATF Recommendation 10 on customer due diligence is also central. A bank is expected to identify the customer, identify and take reasonable measures to verify the beneficial owner, understand the purpose and intended nature of the relationship, and conduct ongoing due diligence. Higher-risk situations call for enhanced measures. The exact legal wording and thresholds come from the bank’s local framework, but the operating principle is consistent: understand the person and purpose behind the account, then keep that understanding current.

Tax transparency changes what “secrecy” means

The global tax-transparency environment has changed substantially over the last decade. The OECD-hosted Global Forum on Transparency and Exchange of Information for Tax Purposes monitors the Exchange of Information on Request standard and automatic exchange frameworks. Under the EOIR standard, jurisdictions are expected to make ownership, beneficial-ownership, accounting and banking information available to competent authorities and to have mechanisms that allow information to be exchanged when properly requested.

The Common Reporting Standard adds automatic exchange of financial-account information for participating jurisdictions. The previous chapter covers FATCA and CRS in detail, so this chapter does not repeat classification and reporting mechanics. The relevant point here is that an “offshore” structure cannot be assessed using a 1990s assumption that cross-border ownership is necessarily invisible to tax authorities. Many financial centres participate in CRS, EOIR and beneficial-ownership frameworks.

At the same time, formal participation in an international standard does not prove perfect effectiveness. The Global Forum’s peer reviews repeatedly examine whether beneficial-ownership information is actually adequate, accurate and up to date; whether accounting information is available; whether competent authorities can access it; and whether exchange works in practice. Its 2025 and 2026 monitoring material shows that jurisdictions continue to strengthen registers, supervision and verification. That evidence is more useful than simplistic labels because it identifies the type of transparency weakness that could matter to a bank.

The bank should also keep separate concepts separate. A customer’s incorporation in an international financial centre is not the same as being resident in a FATF high-risk jurisdiction. FATF’s public lists concern strategic deficiencies in AML, counter-terrorist-financing and counter-proliferation-financing regimes. They are dynamic and should be used exactly as FATF describes them. A bank should not create an informal “offshore blacklist” by merging tax, sanctions, corruption and FATF categories into one uncontrolled country flag.

Legitimate structures and abuse can look similar at first

Financial-crime controls are difficult because many abusive arrangements borrow the appearance of legitimate structures.

A shell company generally has little or no independent physical operation. That can be perfectly legitimate. Special-purpose entities are often intentionally narrow. Holding companies may have no staff. Securitisation and financing vehicles can exist primarily to hold assets or contractual rights. The risk is not “no employees”; the risk is whether the entity’s purpose, ownership, transactions and counterparties make economic sense.

A shelf company is a company formed and left dormant until later sale or activation. Shelf companies can have lawful uses, but an older incorporation date can create a misleading impression of business history. A bank should therefore distinguish the age of the legal entity from the age and evidence of the underlying business.

Nominee shareholders or directors can be legitimate features of corporate administration, confidentiality or professional-services arrangements. They can also obscure the person actually exercising control. The bank needs to understand the nominee relationship, the principal, the authority granted and whether the arrangement is permitted and transparent under applicable law.

Trusts and foundations can support succession planning, philanthropy, family governance and asset protection. They can also make ownership analysis more complex because different persons can create, control, administer and benefit from the arrangement. The control should capture the legally relevant parties and understand how decisions about assets are made.

Private investment companies, family investment vehicles and special-purpose vehicles can be ordinary wealth-management structures. The relevant questions are the source of wealth, source of funds, investment purpose, governance, assets, tax status and relationships between the beneficial owners, advisers and counterparties.

Partnerships and fund structures can create additional layers because legal personality, management and investor rights vary by jurisdiction. A fund administrator, general partner, investment manager, trustee or custodian may hold different information. The bank should not assume that one “owner” field captures the structure.

Abuse often appears when these legitimate building blocks are combined with inconsistent or unverifiable facts: unexplained nominee layers, frequent changes of directors, addresses shared across unrelated entities, ownership transfers shortly before onboarding, circular funding, false invoices, back-to-back loans, assets that do not fit the customer’s profile, professional intermediaries who resist disclosure, or a stated business purpose that has little connection with the payment activity.

A practical risk model for offshore and secrecy structures

A bank can organise the assessment around six dimensions without turning them into a mechanical score.

1. Ownership and control transparency

The starting point is whether the bank can identify the natural persons required by its beneficial-ownership rules and understand how control works. Complexity by itself is not misconduct, but every material layer should have a reason. Analysts should be able to explain the chain from the account holder through intermediate entities or arrangements to the people who ultimately own, control or benefit.

Risk increases when ownership information is contradictory, when customer-provided charts omit entities found in reliable records, when nominees cannot be connected to principals, when control rights do not match stated ownership, or when ownership changes repeatedly without commercial explanation.

2. Commercial purpose and economic substance

The bank should understand what the structure does and why the selected jurisdictions and entities are needed. Evidence may include constitutional documents, contracts, group structure, business plans, investment mandates, board minutes, audited accounts, tax advice where appropriate, regulatory licences, employee and premises information, and details of assets and counterparties.

Economic substance does not mean every company needs employees and offices. An SPV may legitimately have almost none. The question is whether the observed substance is appropriate for the entity’s stated function. A passive holding company with no staff is different from a purported manufacturer with no premises, employees or suppliers.

3. Jurisdiction and cooperation risk

Jurisdiction analysis should use credible current information: FATF statements, mutual evaluations, sanctions regimes, corruption and predicate-crime exposure, Global Forum tax-transparency reviews, regulatory quality and the bank’s approved country-risk framework. The reason for the jurisdiction matters. Incorporation in a financial centre because a fund uses a recognised legal framework is different from adding multiple unrelated jurisdictions that appear to make ownership harder to trace.

The bank should avoid “country stacking” where every geographic risk indicator simply adds points without context. A stronger model records the specific concern: strategic AML weakness, sanctions exposure, limited beneficial-ownership transparency, weak exchange of information, corruption exposure, conflict risk, or another defined factor.

4. Source of wealth and source of funds

For higher-risk private, corporate or wealth relationships, source-of-wealth and source-of-funds analysis can be decisive. Wolfsberg guidance treats these as important risk-management tools where appropriate. The bank should establish a coherent wealth story and test it against credible evidence.

A founder who sold a business may support the story with sale agreements, corporate records and bank statements. Inherited wealth may be supported by probate or estate documents. Investment returns may be supported by portfolio statements and tax records. The exact evidence should be proportionate and sensitive to legitimate confidentiality, but unexplained wealth routed through multiple entities cannot be resolved by a one-line declaration.

5. Product and channel exposure

Private banking, custody, trust services, corporate accounts, trade finance, securities, lending against investment assets, cross-border payments and correspondent banking can expose different parts of the structure. The bank needs to know what it can actually observe.

A custody bank may see assets and investment flows but little operating activity. A transaction bank may see payments but not the full investment portfolio. A lender may see collateral and financing documents. Controls should combine information where lawful and technically possible, rather than assuming every product team has the same visibility.

6. Transaction behaviour

Ongoing activity should make sense for the declared role of the entity. Important patterns include unexpected third-party payments, rapid movement through the account, transactions with no apparent connection to the stated business, frequent transfers between related entities without documented purpose, loan repayments that do not match loan agreements, excessive use of suspense or omnibus arrangements, unexplained cash equivalents, and funds moving repeatedly between jurisdictions with no clear economic event.

No single pattern proves laundering or tax crime. The strength comes from convergence: ownership opacity plus weak business rationale plus unusual transaction behaviour is more meaningful than any one factor alone.

Decision flow for distinguishing a transparent legitimate cross-border structure from a case that needs enhanced due diligence, escalation or exit.

Onboarding: build a structure the bank can later monitor

The best time to understand a complex structure is before the relationship becomes operational. The onboarding process should capture the legal and economic facts in structured data, not only in uploaded documents.

For an entity customer, that normally includes legal name, incorporation jurisdiction, registration number, registered and operating addresses, legal form, business activity, expected products, expected transaction profile, tax residence where relevant, regulatory status, ownership and control relationships, directors or equivalent office holders, authorised signatories, and the beneficial owners required by the applicable framework. For trusts and similar arrangements, the relevant roles should be captured separately.

The bank should also capture why the structure exists. A free-text answer can be useful but is hard to monitor. Better designs combine a structured purpose category with narrative evidence. For example: family investment holding, fund/SPV, operating subsidiary, treasury entity, asset-holding vehicle, joint venture, estate-planning vehicle or another approved category. The system can then compare expected flows with actual behaviour.

Documents should have provenance and effective dates. An ownership chart prepared by the customer, an extract from a corporate registry, a trust deed, a certificate of incumbency and an audited financial statement do not have the same evidential role. The case record should show the source, date, version and reviewer conclusion. This matters later when ownership changes or an investigator needs to reconstruct what the bank knew at a specific time.

A complex relationship should not be approved merely because every document slot is filled. The reviewer should be able to answer four questions in plain language: Who controls the customer? Why does the structure exist? How was the wealth or transaction funding generated? What activity should the bank expect to see?

Enhanced due diligence should resolve specific uncertainty

Enhanced due diligence is most useful when it is targeted. “Obtain more documents” is not a control objective. The bank should identify the unresolved risk and ask for evidence that can answer it.

If the concern is beneficial ownership, the EDD step may involve registry extracts, shareholder registers, constitutional documents, trust or foundation documents, nominee agreements, control rights, independent database checks and confirmation from a regulated professional intermediary.

If the concern is source of wealth, the bank may need audited accounts, sale documents, investment statements, inheritance records, tax returns or other evidence appropriate to the source. The objective is to understand plausibility, not to accumulate paper.

If the concern is economic purpose, the bank may review contracts, financing agreements, board documents, group accounts, business activity, employees, premises, counterparties and the reason for the chosen jurisdictions.

If the concern is tax transparency, specialist tax-reporting teams may need to validate tax residence, CRS/FATCA classification, controlling-person status or self-certification. A documentation defect is not automatically tax evasion. It becomes a financial-crime matter when facts indicate deliberate concealment, deception, facilitation or suspicious movement of value.

If the concern is corruption or sanctions evasion, the case may require PEP analysis, adverse information, sanctions ownership/control analysis, public-contract exposure, source-of-wealth testing, intermediary review or payment investigation.

This problem-specific approach reduces unnecessary customer friction and produces clearer audit evidence.

Professional intermediaries: useful evidence, not outsourced judgement

Offshore structures often involve lawyers, accountants, corporate-service providers, trustees, fiduciaries, tax advisers, fund administrators and wealth managers. These professionals can be valuable sources of verified information and may themselves be regulated. Their involvement can also create a false sense of security if the bank assumes that another professional has already solved the financial-crime risk.

The bank should understand the intermediary’s role. Is the firm introducing the customer, administering a company, acting as trustee, providing registered-office services, preparing accounts, giving tax advice or controlling transactions? What information does it hold? Can the bank rely on its due diligence under local law and policy, and if so, what conditions apply? Who remains accountable for the bank’s customer decision?

Resistance to ordinary beneficial-ownership disclosure is an important signal, especially when confidentiality is invoked in a way that prevents the bank from satisfying its legal obligations. Legitimate professional privilege and confidentiality rules must be respected, but they do not convert an unverified structure into an acceptable customer.

Monitoring should test the onboarding story

Ongoing monitoring is not simply a separate transaction-monitoring engine. It is the process of comparing new facts with the bank’s existing understanding.

A holding company expected to receive dividends may generate a review if it begins receiving high-volume payments from unrelated retail counterparties. An investment vehicle expected to hold securities may warrant review if it begins making large trade payments. A family trust may trigger refresh if trustees, protectors or beneficiaries change. A corporate customer may need event-driven review if ownership changes, a jurisdiction is added to a relevant risk list, adverse information emerges, or the customer changes its tax residence or business activity.

Detection scenarios can use several signal families:

  • relationship changes, such as new beneficial owners, directors, signatories or addresses;
  • structural changes, such as new holding layers, mergers, redomiciliation or transfers into trusts;
  • transaction changes, such as rapid pass-through, circularity, unrelated third parties or unexplained intercompany loans;
  • geographic changes, such as new high-risk corridors or counterparties in jurisdictions inconsistent with the business;
  • documentary changes, such as expired evidence, contradictory registry data or unexplained differences between customer and external data;
  • network changes, such as shared directors, addresses, devices, counterparties or professional intermediaries across apparently unrelated customers.

Monitoring should generate a question, not an automatic accusation. The analyst still needs to understand the economic event.

Payment and accounting patterns that deserve explanation

Complex structures often use ordinary accounting labels. That makes context essential.

Intercompany loans can be a normal way to fund subsidiaries. Risk increases when loan terms are absent, repayments do not match agreements, parties are not actually related, loans are repeatedly rolled over without rationale, or funds move immediately to unrelated parties.

Dividends and capital contributions can legitimately move value across a group. The bank should be able to connect them to ownership, available profits or corporate actions and the declared group structure.

Management, consulting and royalty fees can be legitimate, but vague invoices, repeated round amounts, payments to entities with no apparent capability, or fees disproportionate to the underlying business can warrant review.

Back-to-back lending can serve legitimate treasury or financing purposes. It can also obscure the origin or beneficiary of funds if one entity deposits assets and another connected entity receives credit without a clear commercial reason.

Property and luxury-asset transactions can be legitimate wealth-management activity. They may also be used to integrate illicit wealth. The bank should connect the purchase to source of funds, beneficial owner, seller, financing and expected customer profile.

Securities and investment flows may involve custodians, brokers, funds and nominees. Analysts should avoid interpreting normal settlement chains as suspicious simply because several entities appear. The question is whether the chain is consistent with the instrument and the customer’s mandate.

Circular transfers become more concerning when money returns to the originator or connected parties without a clear economic event, especially after crossing several entities or jurisdictions.

A well-designed alert presents the relationship context alongside the transactions. Investigators should not have to reconstruct the corporate tree manually for every case.

Control architecture linking onboarding, ownership data, tax and screening services, transaction monitoring, case management and periodic review.

Data architecture: the ownership graph is a first-class banking object

Flat KYC records are a major source of weakness. A field called beneficialOwnerName cannot represent a multi-layer structure, changing ownership percentages, trusts, nominee relationships and different forms of control.

A stronger model treats the customer as a graph. Nodes can represent natural persons, companies, trusts, foundations, partnerships, funds, accounts and relevant professional intermediaries. Edges represent relationships such as legal ownership, beneficial ownership, voting control, trustee, settlor, protector, beneficiary, director, authorised signatory, general partner, investment manager or nominee/principal.

Each relationship should carry the facts needed to reconstruct the decision: percentage where meaningful, control basis, effective-from and effective-to dates, source of evidence, verification status, jurisdiction, reviewer, and the rule or policy context under which the person was considered in scope. Historical states should be retained. An investigator reviewing a transaction from 18 months ago may need the ownership structure as it existed then, not today’s version.

External-data integration should preserve provenance. Registry data, customer declarations, commercial databases, screening providers and tax systems may disagree. The platform should not silently overwrite one source with another. It should record the conflict, route it for resolution where material, and retain the conclusion.

The same architecture improves sanctions screening. If a newly designated person is linked to a customer through ownership or control, the bank needs to identify potentially affected entities and apply the legal rules relevant to the sanctions regime. The sanctions conclusion must remain separate from the AML beneficial-ownership conclusion because ownership/control tests differ across regimes.

Event-driven review is stronger than calendar-only review

Periodic review remains important, but complex structures can change quickly. Event-driven triggers include:

  • change in beneficial ownership or control;
  • appointment or removal of trustee, protector, director or signatory;
  • redomiciliation or change in registered office;
  • creation of a new intermediate holding entity;
  • acquisition or disposal that changes the business profile;
  • a material change in source of wealth or funding;
  • new PEP, sanctions or adverse-information result;
  • tax-residence or FATCA/CRS status change;
  • large transaction outside the expected profile;
  • law-enforcement, FIU or regulatory request;
  • material change in a jurisdiction’s risk status.

The workflow should identify which facts are affected. A new director may require screening but not full re-underwriting of source of wealth. A new controlling shareholder may require a much broader review. Risk-based orchestration avoids both under-response and unnecessary full re-KYC.

Evidence timeline showing how ownership, purpose, wealth and transaction evidence must remain reconstructable from onboarding through later change events.

From alert to investigation and reporting

An alert should be triaged against the customer’s known structure and purpose. If the issue is a simple data mismatch, the outcome may be remediation. If the activity can be reasonably explained with evidence, the alert may close. If material questions remain, the case can escalate to an investigation.

A good investigation reconstructs both structure and value flow. The investigator identifies the relevant entities and people, maps the relationships, reviews source of wealth and funds, analyses transactions, checks counterparties, reviews screening and adverse information, and looks for inconsistencies between the stated purpose and observed activity.

Network analysis is especially useful. Several companies may share a director, address, professional intermediary, device, counterparty or payment beneficiary. Shared features can be innocent in a corporate-services environment; the value comes from combining them with transaction behaviour and customer facts.

The reporting threshold for a suspicious activity report or suspicious transaction report is jurisdiction-specific. The investigator should not treat “offshore” status as suspicion. The decision should be based on the facts and the applicable legal standard. The case file should record the indicators, explanations considered, evidence obtained, unresolved concerns, decision owner and any required confidentiality controls.

Customer action is also separate from reporting. A bank may file a report and continue the relationship subject to controls, restrict certain activity, decline a transaction, or exit the relationship depending on law, risk appetite and the circumstances. Staff must respect local tipping-off and confidentiality rules.

Governance: separate ownership of risk from specialist advice

Clear decision rights prevent complex cases from circulating indefinitely.

The relationship or business team owns accurate customer information and the commercial explanation. KYC or onboarding operations collect and verify required evidence. Financial-crime compliance sets policy, provides challenge and handles escalations. Tax specialists interpret FATCA/CRS and tax-reporting issues. Sanctions teams decide sanctions-specific questions. Legal advises on legal uncertainty. Investigations teams assess suspicious activity. Senior risk committees may approve high-risk relationships or exceptions. Internal audit independently assesses design and effectiveness.

The MLRO or equivalent role should not become the default owner for every offshore question. Many cases can be resolved through ordinary CDD/EDD. Escalation is most effective when the first-line case identifies the exact unresolved issue.

Management information should therefore measure quality, not only volume. Useful indicators include unresolved ownership cases, ageing EDD requests, percentage of complex structures with verified ownership graphs, recurring external-data discrepancies, event-driven review completion, high-risk relationship exceptions, transaction-alert outcomes, repeat findings, and customer complaints linked to evidence requests.

Governance map showing how the business, KYC, tax, AML, sanctions, legal, investigations and assurance functions share distinct responsibilities.

Customer impact and proportionality

Complex-structure controls can create significant friction for legitimate customers. Requests for trust deeds, family wealth evidence, ownership charts or tax information are sensitive. Poorly designed processes repeatedly ask for the same document, fail to explain why information is needed, or impose the same evidence burden on every offshore relationship.

A mature bank explains the purpose of requests in appropriate language, reuses verified information where lawful, protects sensitive documents, limits access, and asks only for evidence needed to resolve the risk. It should provide a route for customers to clarify unusual structures rather than treating lack of familiarity as wrongdoing.

Privacy and data-transfer rules also matter. Beneficial-ownership and tax data can contain personal and sensitive information. Cross-border banking groups need a lawful basis, access controls, retention rules and controlled sharing. A global KYC utility should not assume that every legal entity can see every document.

Proportionality also protects the control itself. Analysts who receive too many low-value “offshore” alerts become less able to focus on genuinely opaque or inconsistent cases. Better segmentation improves both customer experience and financial-crime effectiveness.

Business-analysis and architecture requirements

A business analyst working on this control should resist vague requirements such as “perform enhanced due diligence on offshore customers.” A buildable requirement identifies the trigger, population, data, decision logic, owner, evidence, outcome and audit trail.

Useful requirements include:

  • the platform shall represent multi-layer ownership and control relationships with effective dates and evidence provenance;
  • the platform shall distinguish legal owner, beneficial owner, controller, trustee, settlor, protector, beneficiary, director, signatory and nominee/principal roles;
  • jurisdiction-risk factors shall be effective-dated and traceable to the approved source or policy version;
  • an ownership change shall trigger the review actions configured for the affected relationship type rather than automatically initiating every review;
  • external-data conflicts shall be retained as separate observations until resolved rather than silently overwriting customer data;
  • investigators shall be able to view the ownership graph as of the transaction date;
  • the case system shall record why EDD was triggered, what question the additional evidence was intended to answer and how the reviewer resolved it;
  • screening and tax-classification results shall remain separate from AML customer-risk decisions even when they use shared customer data;
  • relationship restrictions, approvals and exceptions shall carry an owner, reason, effective date and review date;
  • reports and MI shall distinguish offshore-structure risk from FATF high-risk-jurisdiction exposure, sanctions risk and tax-reporting exceptions.

Those requirements convert policy into testable system behaviour.

Testing the control

Testing should use realistic structures, not only single-company happy paths.

A positive test can use a transparent investment holding company with two layers, verified beneficial owners, a legitimate investment rationale and transactions that match the mandate. The control should allow the relationship without unnecessary escalation.

A boundary test can use a trust where the settlor, trustee, protector and beneficiaries have different jurisdictions and one role changes after onboarding. The event should update the graph, trigger the correct screening and review, preserve history and avoid duplicating unrelated tasks.

A negative test can use an entity whose ownership chart conflicts with registry data and where the customer cannot explain a newly inserted company. The case should remain unresolved until the material discrepancy is addressed.

A transaction test can use documented intercompany loans followed by a payment to an unrelated third party. The system should present the ownership and expected-purpose context to the analyst rather than flagging only the amount.

A data-lineage test can change an external registry source and verify that the platform records the new observation, the old evidence, the difference and the reviewer’s resolution.

A failure-mode test should cover unavailable registry data, stale vendor feeds, screening downtime, missing tax data, duplicate entities, delayed customer response and inconsistent identity resolution.

The test evidence should show not just that a case was created, but that the correct decision facts were available and historically reconstructable.

Mini case study: the structure is legitimate until the behaviour stops making sense

Consider a fictional customer, Harbour Atlas Investments Ltd, incorporated in an established international financial centre. It is owned by a discretionary family trust. The trustee is a regulated professional firm. A family member is the settlor, two adult children are discretionary beneficiaries, and an independent protector has limited powers over trustee changes. The company opens a custody and multi-currency account to hold proceeds from the family’s sale of a manufacturing business and invest globally.

At first sight the structure is complex. Complexity is not enough to decline it. The bank obtains the trust deed and relevant extracts, verifies the parties required by policy, confirms the trustee’s regulated status, reviews the business-sale documents, establishes source of wealth, validates the initial funding from the sale account and records the investment mandate. The customer’s tax-reporting status is handled through the bank’s FATCA/CRS process. Screening identifies no sanctions concern. The commercial rationale is coherent.

For eighteen months, activity matches the profile: custody purchases, distributions from investments, professional fees and occasional transfers to disclosed family accounts.

Then the customer instructs a large transfer to an unrelated consulting company in another jurisdiction. The payment narrative says “strategic advisory,” but the investment manager cannot explain the service, the amount is far larger than previous professional fees, and the recipient shares a director with a company named in adverse reporting about public-procurement corruption.

The correct response is not “offshore structure = suspicious.” The investigator separates the questions. The original ownership and source-of-wealth evidence remain credible. The new payment creates a transaction-specific corruption and money-laundering concern. The bank requests the contract, invoice and business rationale, reviews the recipient and connected parties, checks PEP exposure, maps the network, and applies the relevant payment and investigation controls.

If the explanation and evidence are inadequate, the case may meet the local suspicious-reporting threshold. The bank may also decide whether the payment can proceed and whether the relationship risk has changed. The important lesson is that a legitimate structure can later display suspicious behaviour, while a complex offshore structure can be legitimate when ownership, purpose and activity are transparent.

What good looks like

A strong offshore-structure control does not try to eliminate complexity. It makes complexity understandable.

The bank can identify and verify the people who matter under the applicable rules. It can explain why the entities and jurisdictions are present. It can evidence the source of wealth and funds where risk requires it. It can compare actual activity with the declared purpose. It can distinguish a tax-reporting defect from suspected tax crime. It can distinguish a FATF jurisdiction issue from an “offshore” label. It can preserve historical ownership and evidence. It can escalate material uncertainty without creating blanket exclusion.

Most importantly, it can explain its decision later. A regulator, auditor or investigator should be able to see what the bank knew, what it did not know, what it asked, what evidence it relied on, what changed, who decided, and why the outcome was proportionate.

That is the real control objective: not “no offshore customers,” but no unexplained opacity.

Operational deep dive: proving ownership, purpose and transparency

The base chapter established the core principle: the risk is not “offshore” as a label but opacity that the bank cannot resolve. This deep dive focuses on the evidence chain. It explains how a bank should treat beneficial-ownership sources, professional intermediaries, cross-border records and tax-transparency information when the same structure appears differently in different systems.

No single source is enough

FATF’s strengthened Recommendation 24 framework emphasises adequate, accurate and up-to-date beneficial-ownership information and supports a multi-pronged approach. That matters operationally because corporate information is fragmented by design. A company registry may show legal shareholders and directors. A beneficial-ownership register may contain natural persons reported under local rules. A regulated corporate-service provider may hold underlying declarations and identity evidence. A bank may hold its own ownership chart and customer explanation. Tax authorities may have information that is not available to the bank.

The bank should therefore classify evidence by purpose. A registry extract can establish legal existence and recorded officers. It may or may not prove the current ultimate beneficial owner. A customer-signed chart can explain the structure but requires verification. A trust deed can establish legal roles but may not show every later appointment or distribution. Audited accounts can validate activity and assets but do not automatically prove control. Screening data can identify external risk signals but should not overwrite core identity facts without review.

This is why a simple “registry matched: yes/no” field is inadequate. The case should preserve the observations separately and record the conclusion reached after comparison.

Beneficial-ownership registers improve transparency but do not eliminate due diligence

Beneficial-ownership registers are an important part of the transparency ecosystem. The OECD Global Forum’s 2025 and 2026 monitoring work describes increasing use of central registers and continued efforts to improve accuracy, verification and supervision. FATF’s Recommendation 24 guidance similarly recognises registries or alternative mechanisms within a broader system.

For a bank, three limitations remain.

First, definitions differ. The natural person who must be reported to a register under company law may not map perfectly to the person the bank must identify under AML law, tax reporting or sanctions ownership/control rules.

Second, information can be stale, incomplete or incorrectly submitted. A recent ownership transfer may not yet be reflected. A filing may contain an error. A nominee relationship may require additional explanation.

Third, access differs. Some registers are public, some are restricted, and some provide different data to competent authorities and private-sector obliged entities.

The practical rule is to use the register as a high-value source while preserving independent judgement. If the register and customer information disagree on a material fact, the bank needs a controlled discrepancy workflow. It should identify the difference, establish which information is current, obtain supporting evidence, update records where appropriate and retain the audit trail.

Mapping trusts and similar arrangements

Trusts expose the weakness of shareholder-only data models. A bank may need to understand the settlor, trustee, protector, beneficiaries or classes of beneficiaries, and any other natural person exercising ultimate effective control, subject to the applicable legal framework.

The evidence is also different. The trust deed, supplemental deeds, letters of wishes, trustee resolutions and professional-trustee records may each answer different questions. The bank should not demand every document in every case. It should identify the roles and powers that are material to its due-diligence requirement and ask for the evidence needed to verify them.

A change of trustee is not the same event as adding a beneficiary. A protector with power to remove trustees creates a different control question from a protector with only advisory rights. Systems should capture powers and role types, not merely names.

Nominees and professional corporate services

Nominee arrangements require the bank to distinguish the person appearing in a formal role from the person for whom the nominee acts. A nominee director may have genuine legal duties and still act within a professional-services arrangement. A nominee shareholder may hold legal title for an underlying principal. The bank’s task is to identify the principal or controlling person required by law and policy and to understand the agreement.

Professional corporate-service providers can reduce or increase uncertainty. A well-regulated provider with clear records may give the bank a strong evidence path. A provider that refuses ordinary ownership questions, uses unexplained sub-agents, changes entities frequently or provides inconsistent documents can create additional risk. The institution should assess the provider’s role and evidence rather than treating the mere presence of a professional intermediary as a risk mitigant.

Cross-border documents and identity resolution

Names, legal forms and registration identifiers differ across jurisdictions. The same entity may appear with translated names, abbreviations or historical names. Addresses may represent registered offices shared by thousands of companies. Directors may serve on many entities as part of professional administration.

Entity resolution must therefore use more than text similarity. Registration number, jurisdiction, date of incorporation, registered office, former names, LEI where available, tax identifiers, director combinations and ownership relationships can all help establish whether two records refer to the same entity.

False merging is dangerous. Combining two similarly named companies can create incorrect sanctions exposure, wrong ownership conclusions or false suspicious links. False separation is also dangerous because the bank may fail to connect related structures. Matching logic should expose confidence and evidence to reviewers instead of hiding uncertainty behind a binary result.

Tax transparency is a control input, not a criminal verdict

CRS, FATCA and exchange-of-information frameworks can help expose hidden offshore assets to tax authorities, but a bank must not convert a reporting issue into a tax-crime conclusion without evidence.

A missing TIN, invalid self-certification or uncertain entity classification belongs first in the tax-reporting remediation process. It becomes a financial-crime concern when surrounding facts suggest deliberate concealment or deception, such as false residency claims, unexplained ownership transfers designed to avoid reporting, contradictory statements about control, fabricated documents, or movement of funds inconsistent with the declared tax and commercial position.

The bank should therefore preserve a referral boundary. Tax operations can resolve documentation and classification. Financial-crime teams investigate suspected evasion, laundering or facilitation. The two teams should exchange relevant facts without making each other’s legal conclusions.

Network analysis: shared infrastructure can be signal or noise

Offshore structures often share infrastructure. Hundreds of legitimate entities may use the same corporate-service provider, registered office, trustee or director. A graph that flags every shared address will produce noise.

Network analysis becomes useful when shared infrastructure combines with other facts. Several unrelated customers using the same introducer, paying the same recipient, using nearly identical invoices and moving funds through the same sequence of jurisdictions is much stronger than a shared registered office alone.

A mature graph therefore distinguishes relationship types and strength. It can show that a director is a professional nominee, that an address is a registered-office service, that an account is jointly controlled, or that two companies share the same beneficial owner. Analysts can then decide whether the connection is expected or meaningful.

Evidence quality standard

A defensible complex-structure file should allow another reviewer to reconstruct:

  1. the legal customer and all material intermediate entities or arrangements;
  2. the natural persons identified as beneficial owners or controllers under the applicable rule;
  3. the commercial or family rationale for the structure;
  4. the jurisdictions and why they are used;
  5. source of wealth and source of funds where required;
  6. key evidence sources, dates and discrepancies;
  7. expected products and activity;
  8. material changes after onboarding;
  9. the reason for any EDD, investigation, restriction or escalation; and
  10. the final decision, owner and review date.

The standard is not “more documents.” It is a coherent evidence chain that connects facts to a proportionate decision.

Advanced practice: architecture, detection and control testing

Complex offshore structures become difficult when policy is translated into technology. The architecture must support legal entities, legal arrangements, natural persons, changing ownership, multiple regulatory lenses and transaction behaviour without collapsing them into one risk flag.

Build an effective-dated relationship graph

The customer master should store entity and person relationships as effective-dated records. At minimum, each relationship needs a role, source, verification status and date range. Ownership percentage is useful where applicable, but systems also need non-percentage forms of control.

A practical relationship object might contain:

  • fromPartyId and toPartyId;
  • relationship type such as shareholder, beneficial owner, controller, trustee, settlor, protector, beneficiary, director, signatory or nominee principal;
  • ownership or voting percentage where relevant;
  • control basis;
  • jurisdiction;
  • effective-from and effective-to dates;
  • evidence source and document reference;
  • verification status and reviewer;
  • confidence or unresolved-discrepancy status;
  • policy or rule version used for the conclusion.

This lets the bank reconstruct the graph as of any historical date. It also avoids the common error of replacing an old owner with a new one and losing the evidence needed for historical transaction investigation.

Separate facts, risk factors and decisions

A strong architecture has three layers.

Facts are observable data: incorporation jurisdiction, owner, percentage, trustee, account, transaction, address, tax residence, registry record.

Risk factors are interpretations: complex ownership, unexplained nominee, FATF-listed jurisdiction exposure, PEP connection, weak tax-transparency evidence, unusual pass-through activity.

Decisions are governed outcomes: standard CDD, EDD, approval, restriction, investigation, report, decline or exit.

Mixing the three layers makes models impossible to explain. For example, offshoreRisk = high tells an investigator almost nothing. A transparent fact such as incorporationJurisdiction = X, combined with a policy factor such as ownershipTransparencyConcern = unresolved, is much more useful.

Rule orchestration and event triggers

Rules should be configurable and effective-dated. Jurisdiction status changes, local legal thresholds change and bank policies evolve. Historical cases must retain the rule version used at the time.

Event triggers should include ownership change, new controller, new trust party, tax-status change, address change, new high-risk geography, new adverse information, material change in transaction profile, new sanctions match and expiry of critical evidence. The orchestration layer determines which reviews are actually needed.

The system should not automatically classify every incorporation in a financial centre as EDD. It should combine factors such as ownership complexity, customer type, product, geography, source of wealth, professional intermediary, external-data discrepancies and behaviour.

Detection scenarios that add value

Useful detection scenarios include:

Pass-through mismatch. An entity described as a holding or investment vehicle receives and forwards frequent unrelated commercial payments with little retained balance.

Circular related-party movement. Funds move across several connected entities and return to the original group without a documented corporate event.

Purpose-to-payment mismatch. A passive investment vehicle begins paying suppliers or consultants unrelated to its declared mandate.

Ownership-change proximity. A material ownership or control change occurs shortly before a large incoming or outgoing transfer.

Unexplained third-party funding. Initial or subsequent funding comes from parties not connected to the known beneficial owners or commercial counterparties.

Intermediary concentration. Multiple apparently unrelated customers introduced by the same intermediary display similar transaction patterns and common beneficiaries.

Documentation contradiction. Registry, customer and commercial-database ownership data disagree on a material person and remain unresolved.

Scenarios should be calibrated by customer type. A fund administrator, family office, trading company and SPV have different expected patterns.

Acceptance criteria for delivery teams

Business and technology teams can turn the policy into testable acceptance criteria.

A relationship graph must display the ownership/control chain from the customer to the natural persons in scope and identify unresolved breaks. The graph must support trust roles without forcing them into shareholder fields. Historical views must reproduce the structure at a selected date. External registry updates must create a new observation rather than overwrite the customer record. A material discrepancy must create a task with a defined owner and resolution status.

Transaction-monitoring alerts must include the relevant current and historical structure, expected activity and material risk factors. Analysts must be able to open the evidence supporting a relationship conclusion without searching multiple unmanaged drives.

A jurisdiction-risk update must be effective-dated. The system must identify affected relationships and apply the configured review logic without retroactively changing the recorded rationale for older decisions.

Test the difficult boundaries

Quality assurance should include:

  • two entities with similar names but different registration numbers to test false merging;
  • one entity with former names and redomiciliation to test continuity;
  • a trust where the protector changes but beneficial ownership does not;
  • a nominee shareholder where the principal is known and verified;
  • a legitimate SPV with no employees to test false “lack of substance” escalation;
  • a customer whose registry ownership differs because the register is stale;
  • a customer that becomes exposed to a newly listed FATF jurisdiction after onboarding;
  • a large related-party loan that is fully documented and should not alert as suspicious;
  • a superficially similar loan with no agreement and rapid onward transfer that should escalate;
  • missing external-data feeds to test controlled degraded operation.

The objective is not simply to prove that alerts fire. It is to prove that the control distinguishes legitimate complexity from unresolved opacity.

Control effectiveness

Management should measure whether the control improves understanding and outcomes. Useful metrics include unresolved beneficial-ownership discrepancies, EDD ageing, repeat document requests, percentage of complex structures with complete relationship graphs, event-driven review timeliness, false-positive rates by scenario, investigations arising from structural signals, quality-assurance findings and customer complaints.

A lower number of offshore alerts can be a positive result if segmentation is better and high-risk cases receive more attention. Volume is not effectiveness. The outcome to optimise is accurate, explainable risk differentiation.

Practice close: review questions, failure modes and delivery checklist

A learner should be able to apply the chapter without memorising a list of “offshore countries.” The practical skill is to identify what is unclear, what evidence can resolve it and what decision belongs to which control.

Five review questions for any complex cross-border structure

1. Can we identify the people who ultimately own, control or benefit from the structure under the rules that apply to this relationship?

If not, identify the exact break in the chain. Do not hide it inside a generic high-risk score.

2. Can we explain why each material entity, arrangement and jurisdiction is present?

Complexity can be legitimate. The test is whether the structure has a coherent purpose consistent with the customer’s business, wealth and products.

3. Can we connect the money to a credible source and expected activity?

Source of wealth, source of funds and transaction behaviour should tell compatible stories.

4. Are we using current, specific jurisdiction evidence?

FATF lists, sanctions regimes, Global Forum transparency reviews and local supervisory information answer different questions. Do not merge them into one uncontrolled blacklist.

5. If challenged in two years, can we reconstruct what we knew and why we decided?

Effective dates, evidence provenance, ownership history and decision records matter as much as today’s snapshot.

Common failure modes

A bank should treat the following as control weaknesses even if no suspicious activity has yet been found.

Country-label substitution. The policy says “offshore customers are high risk” but cannot explain which risk the geography represents.

Document collection without resolution. The file contains certificates, deeds and charts, but nobody reconciles contradictory ownership.

Registry overreliance. A registry match is treated as conclusive even when customer information shows a material change.

Shareholder-only modelling. Trusts, nominees and control rights are forced into percentage-ownership fields, losing the real relationship.

No historical graph. New ownership overwrites old ownership, making past transactions impossible to investigate properly.

Tax/AML conflation. A CRS remediation issue is treated as tax evasion, or credible evasion indicators remain trapped in tax operations without a governed referral.

False substance rules. Every SPV with no employees is escalated even though its purpose is intentionally passive.

Alert context loss. Transaction monitoring sends an amount and country to the analyst but not the ownership structure or expected customer purpose.

Uncontrolled de-risking. Entire customer categories are exited without considering individual facts or mitigants.

Unclear decision ownership. Relationship teams, tax, AML, sanctions and legal each assume another function owns the final answer.

Analyst decision exercise

A customer is a holding company in a financial centre. It is owned through two intermediate companies by a natural person whose identity and source of wealth are verified. The structure was created for an international joint venture and the agreements support that purpose. The company receives dividends and pays documented investment costs.

The fact pattern does not become suspicious merely because there are several jurisdictions. The analyst should confirm the ownership chain, expected activity and relevant country risks, then apply the institution’s risk framework.

Now change three facts: one intermediate owner cannot be verified; a nominee shareholder refuses to identify its principal; and the account begins receiving unrelated third-party payments that are forwarded within hours.

The risk is materially different because transparency and behaviour have changed. The correct next step is targeted EDD and, depending on the evidence, investigation. The important skill is being able to say exactly what changed.

BA and tester checklist

Before a change is released, confirm that the implementation can:

  • represent companies, trusts and natural persons without flattening all roles;
  • preserve effective-dated ownership and control;
  • distinguish customer facts from risk factors and final decisions;
  • store evidence provenance and material discrepancies;
  • show the graph as of a historical transaction date;
  • trigger event-driven review when material relationships change;
  • keep FATCA/CRS, AML, sanctions and PEP outcomes separately governed;
  • provide investigators with ownership, purpose, expected activity and transaction context;
  • prevent silent overwrites from external data;
  • apply jurisdiction changes prospectively with controlled effective dates;
  • record EDD questions and how they were resolved;
  • restrict sensitive documents to authorised roles;
  • test legitimate complex structures as well as suspicious ones;
  • verify diagram and document links on mobile and desktop;
  • preserve a complete audit trail.

Final takeaway

Offshore financial centres and cross-border structures are part of normal global finance. The control objective is not to remove them from banking. It is to prevent legal complexity from becoming a hiding place for ownership, illicit wealth, corruption proceeds, sanctions evasion or deliberate tax concealment.

A bank reaches the right outcome when it can see through the structure, understand the purpose, follow the money, explain the risk and preserve the evidence. When it cannot, the uncertainty itself becomes something that must be resolved or escalated.

Masterclass: when a transparent structure develops a hidden side channel

This case is fictional but combines patterns that financial institutions encounter in complex cross-border relationships. The purpose is to show how a bank can avoid two opposite mistakes: rejecting a customer simply because the structure is offshore, or accepting later suspicious activity simply because onboarding was once satisfactory.

The onboarding story

Northbridge Heritage Holdings Ltd is incorporated in an international financial centre and owned by a family trust. The customer says the vehicle exists to hold proceeds from the founder’s sale of a regional logistics company and to invest in listed securities, private funds and commercial property.

The trustee is a licensed professional firm. The founder is the settlor. The founder and spouse are within the class of beneficiaries, with adult children added later. An independent protector can approve a change of trustee but cannot direct individual investments. The bank maps those roles separately rather than forcing them into shareholder percentages.

Source of wealth is supported by the sale agreement, audited accounts of the sold business, tax documentation available under the customer’s circumstances and bank statements showing the sale proceeds. Initial funding comes from the disclosed sale account. The structure’s legal and tax advisers provide a coherent explanation for the holding arrangement. Screening and adverse-information checks reveal no material concern. The relationship is approved subject to the bank’s normal higher-risk wealth controls.

This is a good example of legitimate complexity. If the bank’s policy treated every trust-owned offshore company as unacceptable, it would lose a transparent customer without improving financial-crime outcomes.

The change event

Two years later, the relationship manager notices that a new company, Meridian Advisory Partners Ltd, has begun receiving quarterly “strategic consulting” payments from Northbridge. The amounts are large compared with previous professional fees. Meridian is not in the customer’s known adviser list.

The first payment alone is not proof of wrongdoing. The monitoring system creates a case because the pattern is new and outside the expected profile. The analyst finds three additional facts:

  1. Meridian was incorporated only six months before the first payment.
  2. A director of Meridian is also a director of a company linked in credible media to a public-procurement investigation.
  3. Shortly after each Northbridge payment, most funds leave Meridian for two unrelated entities in different jurisdictions.

The ownership of Northbridge has not changed. Its original source of wealth remains credible. The risk comes from a new payment channel.

The investigation

The bank asks for the consulting agreement, invoices, description of services and evidence of deliverables. The customer provides a short contract describing “government-market access and strategic support” but cannot provide meaningful work product. The founder says the consultant was introduced by a long-standing business acquaintance.

The investigator expands the network. The business acquaintance is connected to a politically exposed person through a joint venture. The PEP is not a Northbridge owner or signatory and is not automatically implicated, but the connection raises the corruption-risk question. Screening teams confirm there is no sanctions prohibition. The tax team confirms the customer’s tax-reporting file is complete; the problem is not a CRS defect.

The case is escalated to the bank’s financial-crime investigation function. It examines payment timing, counterparties, public-contract exposure, the consultant’s corporate records and the customer’s explanation. The investigator documents both supporting and adverse facts rather than writing “offshore structure” as the rationale.

The outcome

The evidence does not establish what offence, if any, occurred. It does establish unexplained payments, weak service evidence, a politically exposed network connection and rapid onward movement. The bank applies the suspicious-reporting standard of the booking jurisdiction and makes the required confidential decision through the authorised reporting process.

Separately, the relationship-risk forum considers whether the bank can continue the relationship and what restrictions or remediation are appropriate. Those decisions follow local law and bank policy. The original trust structure remains relevant context, but it is not the reason for the investigation outcome.

Lessons

The case demonstrates why offshore controls must remain dynamic. A well-evidenced structure can later create suspicious transactions. A complex structure can be legitimate. A tax-reporting file can be clean while an AML or corruption concern exists. A PEP connection can require investigation without proving bribery. A sanctions check can be clear while other financial-crime risks remain.

The bank succeeds when its systems and teams can keep those questions separate and then join the evidence into one coherent case.

References and further reading

FATF global AML/CFT standards and beneficial ownership

OECD Global Forum and tax transparency

Practitioner guidance

  • Wolfsberg Group, Source of Wealth and Source of Funds FAQs. Practical private-banking and wealth-management guidance on applying source-of-wealth and source-of-funds controls where appropriate to risk: https://wolfsberg-group.org/resources/195/32
  • Wolfsberg Group, Guidance on the Risk-Based Approach. Practitioner guidance on customer type, ownership structure, commercial rationale and higher-risk jurisdiction factors: https://wolfsberg-group.org/resources/195/205

These sources provide global standards and practical guidance. Binding customer-due-diligence, beneficial-ownership, tax-reporting, suspicious-reporting, privacy and secrecy obligations arise from the law and regulatory framework applicable to the bank entity, customer, product and jurisdiction. Use the bank’s approved local policy and legal interpretation for transaction-level decisions.