Financial Crime: Mission Domain Intelligence Guide
Most financial crime cases are not cracked by a clever trade reconstruction. They are cracked by an entity that should not exist, filing accounts that do not add up, at an address shared with forty others.
Most financial crime cases are not cracked by a clever trade reconstruction. They are cracked by an entity that should not exist, filing accounts that do not add up, at an address shared with forty others.
What Financial Crime covers as a mission domain
Financial crime intelligence covers offences committed through or against the financial system: securities and investment fraud, market manipulation, insider dealing, accounting fraud, embezzlement, tax evasion, insolvency abuse, payment fraud and the professional enabling of all of them. The discipline is documentary and structural. It reads filings, transaction patterns and corporate architecture to expose the gap between what an entity claims to do and what it could possibly be doing. It overlaps with money laundering and corruption work but focuses on the predicate offence and the harm to victims and markets.
Analysts separate scheme types by mechanics: Ponzi and affiliate-marketed investment schemes; boiler-room and pump-and-dump equity manipulation; invoice and trade-based fraud; procurement and payroll embezzlement inside organisations; and misconduct by regulated firms, such as mis-selling or misappropriation of client assets. Enablers form a distinct target set because they are reusable across schemes: company formation agents, accountants, auditors, lawyers and payment processors.
Why it matters
Losses run to hundreds of billions annually and fall hardest on retail investors, pensioners and small businesses with no capacity to absorb them. Corporate accounting fraud destroys employment and pension value; procurement fraud drains public budgets; payment fraud has become the dominant volume crime in several countries. Beyond direct loss, financial crime degrades trust in markets and institutions, which raises the cost of capital for every legitimate business in the same sector.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Returns advertised as consistent and uncorrelated with any market, with redemptions paid promptly to early investors and quietly delayed for later ones.
- An audit firm far smaller than the client it signs off, or an auditor change immediately preceding a period of rapid reported revenue growth.
- Revenue growth unaccompanied by proportionate headcount, premises, working capital or receivables collection.
- Directors with a trail of dissolved companies, strike-offs or disqualification history reappearing behind newly registered entities.
- Share price and volume spikes preceded by coordinated promotional content and followed by insider disposals within the same window.
- Payment processing routed through a merchant category code inconsistent with the product actually being sold.
- Persistently late filings, dormant accounts filed by a company claiming substantial turnover, or unexplained restatements of prior periods.
- Client money held in an operating account rather than segregated, or intercompany transfers that circle back to their source.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- SEC EDGAR — Full-text searchable US issuer filings including current reports, restatements and auditor change disclosures.
- Companies House — UK incorporation, officer, charge and filing history data, available free and in bulk.
- OpenCorporates — Cross-jurisdiction company records enabling officer, address and shareholding linkage at scale.
- SEC litigation releases and administrative proceedings — Case-level narrative of scheme mechanics, timelines and named participants.
- FCA Register and warning list — Authorisation status, permissions and clone-firm warnings for entities soliciting UK consumers.
- FinCEN advisories — Typology guidance and red-flag sets derived from suspicious activity reporting across sectors.
- Court records (PACER and national court services) — Pleadings, judgments and insolvency filings documenting schemes in evidential detail.
- IOSCO Investor Alerts Portal — Aggregated regulator warnings on unauthorised firms and cross-border solicitation.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- State the claimed business model — Write down precisely how the target says it makes money, then identify what would have to be true for that to work.
- Test capacity against claim — Compare declared revenue with headcount, premises, licences, counterparties and infrastructure, looking for the physically impossible.
- Reconstruct the architecture — Map entities, officers, shareholders and addresses across jurisdictions to locate the control point and the value-extraction route.
- Trace flows and beneficiaries — Follow investor funds, intercompany transfers and dividends through filings, bank records and processors to establish who is actually paid.
- Profile the enablers — Identify formation agents, accountants, auditors and payment processors involved, and check each for reuse across other known schemes.
- Quantify harm and recoverability — Establish loss, victim cohort and traceable assets, since this largely determines whether regulators or police will act at all.
- Build the referral — Assemble a chronology, exhibit index and clear offence hypothesis matched to the receiving authority's statutory remit.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Financial Intelligence — Following Value Through the Financial System
- Cryptocurrency Intelligence — Tracing Value on Public Ledgers
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
Worked in these data points
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Transaction Hash — A blockchain transaction identifier for tracing fund flows.
- Bank Account / IBAN — A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Corporate Filing — A regulatory or corporate filing (SEC, Companies House, court).
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
Adjacent mission domains
- Anti-Money Laundering
- Fraud & Identity
- Sanctions Evasion
- Cyber Crime
- Corruption & Governance
- Organized Crime
Inside the platform: where Financial Crime lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
blockchain.php— Financial Crime dashboarddomain.php?d=fin— Mission domain hubtheater.php?d=fin— Threat theater viewsearch.php— Company / Organization profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Financial Crime:
- Cryptocurrency Tracing — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Business Email Compromise — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Export STIX/MISP
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. State the claimed business model is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Reconstruct the architecture turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Build the referral feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Financial Crime
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence use is narrower here but real: contractor integrity, procurement fraud and the financial vetting of local partners on deployment. Analysis of a bidder's filings, ownership and litigation history supports contract award decisions and prevents payment of public funds to shell entities. A second application is counter-threat finance, where the same documentary techniques identify the commercial structures supporting an adversary's logistics. Products feed contracting officers, the defence audit function and, where fraud is suspected, service investigative branches. Constraints are procurement law and contractual due process: an analytical suspicion is not grounds for exclusion without following the prescribed challenge and appeal procedure, and errors here generate expensive litigation.
🕵 National intelligence
National services use financial crime analysis to understand state-linked commercial networks, sanctions-adjacent financing, and the professional enablers who service multiple hostile actors. Requirements typically concern structures rather than individual frauds. Fusion joins financial intelligence unit disclosures, corporate registry work, securities filings, litigation records and commercial data. Classification questions arise mainly around the source of financial reporting rather than around the analysis itself, and mixing FIU-derived material with open-source products can contaminate handling. Dissemination priorities are regulators, prosecutors and, for policy customers, assessments of how a jurisdiction's corporate transparency regime is being exploited.
👮 Law enforcement
Financial crime prosecutions are documentary, and the case is usually won or lost on reconstruction. Priorities are securing original records with continuity, obtaining banking material through production orders or mutual legal assistance early, and restraining assets before they move. Expert accounting evidence must be reproducible from the underlying records. Charging decisions typically rest on a small number of clearly evidenced transactions rather than the full scheme, so identify the strongest sample early. Victim evidence is required for most fraud offences, and in mass-victim cases the practical constraint is how to prove loss at scale without calling thousands of witnesses, which shapes the whole investigative design.
🔍 Private investigation and corporate security
This is core private-sector work: pre-transaction due diligence, litigation support, asset tracing, insolvency investigation and internal fraud response. The deliverable is a documented assessment of whether an entity's stated business is consistent with its filings, structure, premises and personnel. A private actor may not access banking records without a court order, obtain data by pretext, hack accounts, or bribe employees for information, and in most jurisdictions may not misrepresent identity to obtain personal data. The recurring professional risk is the client who wants a report that supports a decision already taken; document your limitations and your unverified items explicitly.
📰 Journalism and OSINT media
Financial investigations demand documentary rigour: filings, court records, land registries, procurement records and, where lawfully obtained, leaked material. Corroborate any claim of impropriety with at least two independent document sources, and distinguish carefully between what is unusual, what is unlawful and what is merely aggressive. Protect whistleblowers absolutely and consider the personal legal exposure they face, including under employment contracts and secrecy laws. Right of reply must be specific and give adequate time, since the response frequently changes the story. Pre-publication legal review is essential in this domain, as it attracts the best-resourced litigation of any investigative area.
🌍 NGO, humanitarian and human rights
Civil society organisations use financial crime analysis to expose harm to public funds, pension holders, small investors and consumers, and to campaign for corporate transparency. Practice should be victim-informed, particularly in mass investment fraud where losses concentrate among older people and small savers who face shame as well as financial ruin. Documentation should support regulator complaints and group litigation, meaning clear provenance and preservation. Duty of care applies to whistleblowers and to staff facing legal intimidation, which is common; ensure legal support is arranged before publication rather than after the first letter arrives.
🎓 University and research
Research spans forensic accounting, securities regulation, white-collar criminology and network analysis of corporate structures. Methodology benefits from the unusual availability of structured data: filings, enforcement actions and court records support reproducible quantitative work. Ethics approval is needed for interviews with offenders, victims or regulators, with attention to distress in victim samples. Reproducibility is served by publishing extraction code against public filing systems and by documenting entity resolution rules, which drive most results in network studies. Data sharing must respect that named individuals in enforcement data may have been acquitted, and citation should reflect current case status rather than the position at filing.
Playbook: working Financial Crime end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — State the question and the standard
Fix what is being tested: whether an entity is real, whether reported performance is plausible, where funds went, or who benefited. Then fix the standard the output must meet: internal decision, regulator complaint, civil claim or criminal referral. These have very different evidential thresholds and different tolerance for inference. Output is a scope note naming the question, the standard and the decision it supports. Stop when you can state what finding would change the decision.
Phase 2 — Build the entity picture
Resolve the target into a full corporate picture: incorporation date and history, registered and trading addresses, officers and their other appointments, shareholders, persons of significant control, charges and security, filing punctuality and auditor history. Note name changes and dormant periods. The purpose is to establish what the entity is before assessing what it claims. Stop when you can describe the group structure and identify every entity with a material role.
Phase 3 — Read the accounts properly
Analyse filed financial statements for the standard tells: revenue growth unsupported by headcount or premises, receivables growing faster than revenue, related-party transactions, unusual accounting policies, auditor changes, late filings, and cash flow that does not track reported profit. Compare to sector norms. Where accounts are abridged, the absences are themselves informative. Output is a documented set of anomalies with the specific figures cited.
Phase 4 — Test operational plausibility
Compare claimed activity against observable reality: premises and their size, employee counts and public professional profiles, licensing where required, warehousing, website and infrastructure age, customer references, and physical presence. Many schemes fail this test immediately, because the claimed business would require resources that demonstrably do not exist. Stop when you can state whether the stated business is physically possible at the claimed scale.
Phase 5 — Reconstruct the money movement
Where records are available lawfully, build a transaction reconstruction: sources, destinations, timing, round-sum and circular patterns, and the point at which funds leave the visible perimeter. Where they are not available, identify precisely which records would resolve the question and what legal instrument obtains them. Output is either a reconstruction or a specified evidence request, never speculation dressed as tracing.
Phase 6 — Identify the enablers
Name the professionals: company formation agents, accountants, auditors, lawyers, payment processors and introducers. Enablers are reusable across schemes and are frequently the most productive investigative target, because a single formation agent may appear behind dozens of unrelated frauds. Check regulatory registers and disciplinary records. Stop when you can identify which enablers appear in more than one matter.
Phase 7 — Quantify victim harm
Establish loss with method: number of victims, amounts, whether funds were ever invested as claimed, and what has been recovered. Distinguish paper losses from realised ones and headline figures from provable ones. In mass-victim cases, design the quantification so it can be proven by sampling and records rather than by individual testimony. This figure will be attacked, so build it to survive.
Phase 8 — Trace and preserve assets
Identify recoverable assets early: property through land registries, vehicles, shareholdings, cryptocurrency holdings and funds in identified accounts. Asset dissipation is fast once a subject knows they are under investigation, so the sequencing of freezing applications against evidence gathering is a strategic decision, not an administrative one. Output is an asset schedule with jurisdiction and available preservation mechanism for each item.
Phase 9 — Test alternative explanations
Deliberately construct the innocent account: incompetence, cash flow pressure, legitimate but unusual industry practice, or a genuine business that failed. Then test it against the evidence. Most weak financial crime allegations fail here, and doing it yourself before a regulator or defence lawyer does is what separates a credible report from an embarrassing one. Document why each alternative was rejected.
Phase 10 — Package for the chosen forum
Write to the recipient: a regulator wants breaches of specific rules with evidence references, a prosecutor wants elements of an offence, a civil claimant wants pleadable facts and a defendant with assets, a board wants control failures and remediation. One underlying analysis, several packages. Include a schedule of source documents with provenance for every assertion.
Phase 11 — Support the process to conclusion
Financial matters run for years. Maintain the evidence set, update as new filings and enforcement actions appear, and be prepared to explain the methodology under challenge. Track parallel proceedings in other jurisdictions, since findings there frequently unlock material here. Stop only when the matter concludes or the client formally closes it, and archive so a successor analyst can reconstruct the reasoning.
Phase 12 — Convert findings into controls
Feed the mechanics back into prevention: onboarding checks that would have caught the entity, transaction monitoring rules matching the observed pattern, procurement controls, and audit committee questions. Schemes recur with the same mechanics and different names. Output is a small set of specific control changes with owners, not a general recommendation to improve diligence.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| SEC EDGAR | Open | Full text of US securities filings including annual reports, ownership disclosures, prospectuses and enforcement-related exhibits. | Establishes issuer disclosures, related party transactions, auditor history and ownership positions in US-listed matters. |
| Companies House | Open | UK statutory registry with accounts, officers, persons of significant control, charges and filing history. | Provides the primary documentary basis for UK entity structure, financial filings and directorship networks. |
| OpenCorporates | Registration | Aggregated registry data across many jurisdictions with officers, addresses and cross-jurisdiction entity linking. | Detects shared officers, addresses and successor entities across borders where single-registry search would miss them. |
| GLEIF Legal Entity Identifier data | Open | Global register of legal entity identifiers with parent relationship data for entities in financial transactions. | Resolves counterparty identity consistently across markets and establishes reported group parent relationships. |
| FCA registers and enforcement notices | Open | UK register of authorised firms and individuals, warning list of unauthorised firms, and published enforcement decisions. | Confirms whether a firm is authorised for the activity claimed and surfaces prior regulatory findings against it. |
| FINRA BrokerCheck and disciplinary records | Open | US registration, employment and disciplinary history for brokers and brokerage firms. | Identifies recidivist salespeople and firms with prior findings, a strong predictor in investment fraud matters. |
| US Securities and Exchange Commission enforcement | Open | Litigation releases, administrative proceedings and trading suspensions with detailed factual allegations. | Provides scheme mechanics precedent and confirms whether an entity or principal has prior enforcement history. |
| Serious Fraud Office case reporting | Open | UK prosecutions of serious and complex fraud, bribery and corruption with published case outcomes. | Supplies precedent on charging approach and evidential standards for complex UK fraud matters. |
| PCAOB inspection and enforcement records | Open | Inspection reports and disciplinary actions concerning registered audit firms and individual auditors. | Assesses the credibility of an audit opinion by reference to the firm's inspection findings and sanctions history. |
| ESMA registers and warnings | Open | European securities markets registers, sanctions data and investor warnings on unauthorised firms. | Establishes authorisation status and existing regulator warnings across EU markets for cross-border schemes. |
| CFTC enforcement and advisories | Open | US derivatives and commodities enforcement actions, including fraud in forex, metals and digital asset trading. | Covers scheme types outside securities regulation that frequently appear in retail investment fraud. |
| Court record systems including PACER and national equivalents | Registration | Filed pleadings, judgments, insolvency records and asset disclosures from civil and criminal proceedings. | Recovers pleaded facts, prior litigation history and asset information that never appears in registry filings. |
| Land registries and property records | Registration | Title, ownership, charge and transaction records for real property in most jurisdictions. | Identifies recoverable assets and links entities to natural persons through property held in group structures. |
| ICIJ Offshore Leaks database | Open | Searchable index of offshore entities, intermediaries and officers derived from major leak investigations. | Reveals offshore structures and the formation agents behind them where registries provide no ownership data. |
| Aleph by OCCRP | Registration | Cross-searchable archive of leaks, registries, procurement records and court documents from many countries. | Finds mentions of entities and individuals across document sets that no single registry search would return. |
| Financial Stability and market infrastructure data from the BIS | Open | Cross-border banking statistics, payment system data and analytical work on financial system structure. | Provides macro context for corridor analysis and for assessing whether claimed flows are plausible at scale. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Financial Crime. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Filing extraction and XBRL analysis — Automates ratio and anomaly analysis across large sets of filed accounts. Limitation: tagging errors and abridged accounts limit coverage exactly where small fraudulent entities sit.
- Maltego or Linkurious — Graphs directorship, address and shareholding relationships across entities. Limitation: entity resolution errors propagate silently and produce confident but wrong networks.
- Aleph by OCCRP — Cross-searches leaks, registries and court documents in one place. Limitation: document dates and provenance are inconsistent, so every hit needs verification at source.
- Benford and statistical anomaly testing — Screens large transaction sets for distributions inconsistent with natural data. Limitation: produces indicators, never conclusions, and is easily misapplied to unsuitable data.
- Forensic accounting and transaction reconstruction software — Rebuilds ledgers and traces funds across accounts at scale. Limitation: only as good as the completeness of the records obtained, and gaps are usually where the answer sits.
- Blockchain analytics platforms — Traces digital asset movement and identifies exchange deposit points. Limitation: attribution is vendor-derived and probabilistic, requiring corroboration for evidential use.
- Web archive and infrastructure history services — Establishes when a claimed business actually appeared online and how its claims changed. Limitation: coverage gaps for low-traffic sites and easily defeated by exclusion requests.
- Company credit and trade databases — Provide payment behaviour, filings summaries and group linkage. Limitation: derived data with opaque sourcing, so findings must be traced to primary documents before use.
- Document management with hashing and continuity logging — Preserves evidential integrity for material that may reach court years later. Limitation: requires discipline at collection time, which is when analysts are least inclined to apply it.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Test whether the business is physically possible before testing whether the numbers are true. A company reporting substantial revenue from a serviced office address, with two employees and no logistics footprint, has already answered the question, and the accounts merely document how.
- Absences in filings carry as much information as entries. Late accounts, a change of auditor immediately before a bad year, abridged filings for an entity that previously filed fully, and resignations of independent directors are all signals available at no cost.
- Enablers are the durable target. Individual schemes are short-lived, but the formation agent, the introducer and the payment processor persist across many of them, so building the enabler picture yields far more than working each fraud in isolation.
- Build the innocent explanation properly and in writing. The difference between a report that survives and one that collapses is usually whether the analyst tested incompetence, ordinary industry practice and business failure before alleging dishonesty.
- Sequence asset preservation against evidence gathering deliberately. Every investigative step that becomes visible to a subject starts a clock on dissipation, so decide early whether the priority is recovery or the fullest possible case, because you rarely get both.
- In mass-victim cases, design the loss quantification before collecting the victim evidence. Proving loss by sampling and by records, rather than by thousands of statements, determines whether the case is prosecutable at all, and retrofitting it later is usually impossible.
- Related-party transactions are where value leaves. Management fees, licence payments, intercompany loans and property leases to connected entities are lawful in form and are the ordinary mechanism by which a business is hollowed out, so map the counterparties before the amounts.
- Beware derived data. Credit reference summaries, aggregated company profiles and commercial risk scores are convenient and frequently wrong, and a report that cites them rather than the primary filing will fail the first serious challenge.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Financial Crime is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of referrals accepted for regulatory or criminal action, measured against referrals made, as a test of evidential quality rather than volume.
- Value of assets identified and successfully preserved before dissipation, relative to assessed loss.
- Median time from case opening to identification of the entity structure and the enabler set.
- Number of enablers identified appearing in more than one matter, indicating that network-level rather than case-level analysis is developing.
- Rate at which alternative innocent explanations are documented and tested in reports, audited by peer review.
- Proportion of findings that translate into named control changes with owners inside the affected organisation.
- Recovery achieved for victims as a share of proven loss, tracked over multi-year horizons.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Mistaking incompetence and undercapitalisation for fraud, when ordinary business failure is far more common than deliberate deception.
- Anchoring on the named figurehead, since nominee directors are installed precisely to absorb attention and liability.
- Treating regulatory authorisation as validation, when authorised firms commit fraud and clone firms trade on genuine registration numbers.
- Ignoring the timeline, when a scheme's collapse date rather than its start determines recoverability and applicable limitation periods.
- Building a case on transaction volume without establishing the underlying deception, since volume alone is not an offence.
Legal and ethical considerations
Findings about identifiable people are defamatory if wrong and market-moving if right, so maintain a documented evidentiary standard and separate established fact from inference in every product. Bank and tax records are generally obtainable only through lawful process; do not solicit or accept them informally. Where a regulated entity is involved, tipping-off, market-abuse and confidentiality obligations may constrain what can be disclosed and to whom. Victim data attract data-protection duties and careful handling, particularly where victims are vulnerable.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Financial Crime, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
What is the fastest reliable test that a company is not what it claims?
Compare claimed scale against observable resources. Take reported revenue and ask what headcount, premises, inventory, logistics and licensing that level of activity would require in that sector, then check whether any of it exists. Filed accounts, professional networking profiles, premises imagery, licensing registers and web infrastructure age answer this within an hour for most entities. Schemes are usually caught by this basic plausibility test long before any transaction analysis, and it costs nothing. The corollary is that a genuine but failing business will pass it, which is exactly the distinction you want to make early.
How do you investigate when you cannot get banking records?
Work the perimeter. Corporate filings, charges and security registrations, land registry entries, court and insolvency records, procurement awards, shipping and customs data, litigation exhibits and regulatory filings all record money movement indirectly. Establish what you can prove without bank data, then specify precisely which accounts and periods would resolve the remaining questions, so that a regulator, prosecutor or civil claimant can obtain them with a targeted instrument. A well-specified evidence request is often the most valuable output a private analyst can produce, and speculation offered as tracing destroys credibility.
Where is the line between aggressive and criminal in financial structuring?
Deception. Tax planning, group structuring and asset protection are lawful activities, and unusual is not unlawful. The line is crossed by misrepresentation to a party entitled to the truth, whether an investor, a lender, a regulator, an auditor or a revenue authority, and by the taking of property to which the taker is not entitled. Analysts should state which specific representation was false, to whom, and why it mattered, rather than describing complexity as if complexity were itself evidence of wrongdoing. Sophisticated structures are common and mostly legal.
Why do enablers matter more than perpetrators?
Because they are reusable and they scale. A single company formation agent, introducer or payment processor may service dozens of unconnected schemes, so identifying and addressing them removes capability from many future frauds rather than one past one. They are also more accessible: they are frequently regulated, have professional obligations, keep records, hold insurance and have assets and licences to lose. Enforcement against enablers changes behaviour across an entire market segment in a way that convicting one promoter, who will be replaced within a month, does not.
How should crypto-denominated fraud be handled differently?
The tracing is easier and the recovery is harder. Public chains give visibility into movement that no bank would provide without an order, so reconstruction can often be done immediately and at no cost. The difficulty is at the edges: attributing addresses to people requires exchange records obtained by legal process, and once funds reach non-cooperative services or cross into privacy-preserving mechanisms, the trail degrades. Speed matters more than in fiat matters because there is no clearing delay to exploit, so preservation requests to exchanges should go out within hours rather than days.
What makes a referral actually get taken up?
Doing the recipient's early work for them. Set out the elements of the suspected offence or rule breach, identify the specific evidence supporting each, provide a document schedule with provenance, name the entities and individuals with identifiers, state the jurisdiction and any limitation issues, and identify what further material exists and who holds it. Agencies triage on resource cost, so a package that shows a viable case with a bounded evidential burden competes well. A narrative report describing suspicion, however compelling to read, generally does not.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- International Financial Reporting Standards and national GAAP equivalents, which define how the accounts under analysis were supposed to be prepared.
- International Standards on Auditing, particularly those governing the auditor's responsibilities relating to fraud, which frame what an audit did and did not test.
- IOSCO Objectives and Principles of Securities Regulation, the international benchmark for market conduct supervision and enforcement.
- FATF Recommendations, which set the anti-money-laundering and beneficial ownership standards that predicate offence investigations rely on.
- UK Fraud Act and Companies Act, US mail, wire and securities fraud statutes, and the equivalent national offences that define the elements to be proved.
- UK Criminal Procedure and Investigations Act disclosure obligations and equivalent regimes, governing what investigators must retain and reveal.
- ACFE fraud examination methodology, widely used as the professional standard for structuring and documenting fraud investigations.
- ISO 37001 anti-bribery management systems and ISO 37301 compliance management, where the question concerns organisational control failure.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- EDGAR full-text filing system — US Securities and Exchange Commission. Primary source for US issuer disclosures and enforcement exhibits.
- UK company register and filing history — Companies House. Statutory filings, officers, control disclosures and charges for UK entities.
- Financial Services Register and warning list — UK Financial Conduct Authority. Authorisation status and published warnings on unauthorised firms.
- BrokerCheck disciplinary records — FINRA. Registration and disciplinary history for US brokers and firms.
- Inspection reports on registered audit firms — Public Company Accounting Oversight Board. Evidence on audit quality relevant to reliance on an audit opinion.
- Case outcomes in serious and complex fraud — UK Serious Fraud Office. Published prosecutions establishing charging and evidential precedent.
- Global Legal Entity Identifier register — GLEIF. Standardised entity identification with reported parent relationships.
- Offshore Leaks database — International Consortium of Investigative Journalists. Offshore entity and intermediary records from major leak investigations.
- Principles of securities regulation — IOSCO. International benchmark for market conduct regulation and enforcement.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: reconciles filings, corporate structure and money flow to show whether a business can do what it claims. Explore the platform, or browse the rest of the library by following any tag above.