Financial Intelligence (FININT): Intelligence Discipline Guide
Follow the money is a cliche because it works. Financial intelligence is the discipline of following value through the institutions that are legally required to remember it.
Follow the money is a cliche because it works. Financial intelligence is the discipline of following value through the institutions that are legally required to remember it.
What Financial Intelligence is as a discipline
Financial intelligence is the analysis of payments, accounts and financial relationships to detect and investigate illicit finance: money laundering, fraud, sanctions evasion, terrorist financing and corruption. Inside regulated institutions it works from transaction monitoring output, customer due diligence records, payment messages and correspondent banking data. In open-source practice it works from public evidence of financial relationships, including filings, court records, property and asset registers, procurement awards, enforcement actions and published investigative datasets. The output identifies patterns inconsistent with any stated economic purpose.
Sub-methods include typology-based detection covering structuring, layering, trade-based laundering and mule networks; network analysis of accounts and counterparties; source-of-funds and source-of-wealth assessment; and asset tracing for recovery. Maturity progresses from rule-based alerting, through behavioural and network analytics with properly tuned thresholds, to intelligence-led investigation where typologies are derived from real cases and fed back into detection. Suspicious activity reporting is the formal output wherever a regulated institution is involved.
Why it matters
Financial intelligence answers what the money was actually for and who benefited. Criminal activity is optional, but moving proceeds is not. Payment records are retained under regulation, tied to identity through customer due diligence, and reachable through legal process, which makes them the most reliable evidentiary trail in most investigations. It also establishes relationships between parties who share no other visible connection, and quantifies harm in a way that supports both prosecution and asset recovery.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Structuring, meaning multiple transactions deliberately sized below reporting thresholds across accounts, branches or short time windows
- Rapid pass-through activity where funds arrive and leave within days, leaving negligible balance and no economic rationale
- Counterparty networks inconsistent with the customer stated business, geography or expected transaction profile at onboarding
- Trade-based indicators such as invoice values inconsistent with market prices, phantom shipments and repeated mis-invoicing
- Ownership opacity, with payments routed through shell entities, nominees or jurisdictions offering limited transparency
- Politically exposed person involvement and asset acquisition disproportionate to declared income or official salary
- Correspondent and cross-border patterns using intermediaries that add cost and delay without any commercial explanation
- Property, vehicle, vessel and aircraft registry acquisitions evidencing unexplained wealth and providing concrete recovery targets
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- FATF typologies and evaluations — Authoritative laundering methodologies, red flags and jurisdiction-level risk assessments updated regularly
- OFAC, EU and UN sanctions lists — Designated parties, vessels and addresses with published ownership and control guidance
- OpenSanctions — Consolidated sanctions, politically exposed person and watchlist data with cross-source entity matching
- FinCEN advisories and enforcement actions — Red-flag indicator sets and detailed case narratives drawn from US regulatory practice
- SEC EDGAR and national registries — Ownership, related-party and financing disclosure for entities under investigation
- Land and asset registries — UK Land Registry, vessel and aircraft registers reveal ownership of high-value recoverable assets
- Court dockets and forfeiture complaints — Evidenced financial flows disclosed through litigation, including account-level tracing narratives
- OCCRP Aleph and ICIJ datasets — Published investigative material on offshore structures, intermediaries and cross-border flows
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Define subject and question — Fix which persons, entities and accounts are in scope and what specific financial question the investigation must answer.
- Establish expected behaviour — Document the stated business, income and purpose, because suspicion is deviation from a documented baseline rather than a feeling.
- Reconstruct the flows — Build a timeline of transactions or documented financial relationships with amounts, dates, counterparties and instruments used.
- Apply typologies — Test the observed pattern against known laundering and fraud methodologies, recording which fit and which are positively excluded.
- Map the network — Link accounts, entities and individuals through shared addresses, signatories, ownership and recurring payment relationships.
- Assess source of wealth — Compare acquired assets and total flows against documented lawful income, isolating the unexplained residual for follow-up.
- Report through lawful channels — File suspicious activity reports where required, refer to law enforcement, and preserve records with intact provenance and hashes.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
- Cyber Crime
- Organized Crime
- Drug Trafficking
- Human Trafficking
- Kidnap, Hostage & Extortion
- Financial Crime
- Anti-Money Laundering
- Sanctions Evasion
- Fraud & Identity
- Corruption & Governance
Operates on these data points
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Phone Number — Telephone number for voice, SMS, or messaging identification.
- Messaging Handle — An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
- Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
- Bank Account / IBAN — A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
Related disciplines
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Cryptocurrency Intelligence — Tracing Value on Public Ledgers
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
- Sanctions Intelligence — Screening, Designations, and Evasion Detection
Inside the platform: where Financial Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=FININT— Discipline hubsource-catalog.php?disc=FININT— Source catalogue filtered to this disciplinesearch.php— Person / Name profileblockchain.php— Cryptocurrency Address profilephone-profile.php— Phone Number profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Export STIX/MISP
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define subject and question is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Reconstruct the flows turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report through lawful channels feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Financial Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence practitioners apply financial intelligence as counter-threat finance: understanding how an armed group, a proliferation network or a criminal facilitator moves and stores value in an operating area. The authority is analytic and advisory, working from open sources, partner reporting and information shared through the proper channels, since defence organisations do not hold account-level data. Products support commander understanding of adversary sustainment, identification of nodes whose disruption is achievable through legal and financial means rather than force, and vetting of local contractors and payment channels. Constraint: designations, freezing and account action belong to treasury and law enforcement authorities, and a defence analyst can nominate but not act.
🕵 National intelligence
National services run financial intelligence as a requirements-driven discipline covering proliferation financing, sanctions evasion, terrorist financing and strategic corruption. The distinctive method is fusing financial intelligence unit reporting, information from partner services, open corporate and trade data and sensitive collection into a picture of the network rather than a picture of transactions. Because much of the underlying material is protected by statute and by the Egmont principles on onward sharing, handling is unusually constrained: financial intelligence unit product frequently cannot be used as evidence or shared beyond the receiving agency without consent. Products are written so the assessment can move even where the source cannot.
👮 Law enforcement
Investigators use financial intelligence to prove the money element of an offence and to restrain assets. Suspicious activity reporting is intelligence and generally not evidence, so it directs enquiry rather than proving it. Evidential material comes through production orders and account monitoring orders to institutions, search warrants, and mutual legal assistance for foreign records, with preservation requests issued early because retention is finite. The analytic product is the reconstructed flow showing who controlled which account, what was moved and when, and how it connects to the predicate offence. Disclosure obligations are significant, and tipping off restrictions constrain what can be said to whom during the investigation.
🔍 Private investigation and corporate security
Corporate practitioners practise financial intelligence inside regulated institutions as transaction monitoring, customer due diligence and investigations, and outside them as open-source financial research. Inside the institution the authority comes from the customer relationship and the regulatory regime, and the output is suspicious activity reporting to the financial intelligence unit, plus internal exit decisions. Outside, a private actor has no access to account data and must not seek it: obtaining bank records by pretext or paid insider is an offence and destroys any downstream process. Tipping off is a criminal offence in most regimes, so what may be said to a customer is tightly constrained.
📰 Journalism and OSINT media
Journalists practise financial intelligence through documents rather than accounts: leaked banking records, court filings, corporate registries, procurement data and sanctions listings. Verification means tracing every claim to a document, understanding what a payment record does and does not prove, and having a forensic accountant review the reconstruction. Handling leaked banking data raises real legal exposure and requires secure storage, restricted access and legal review before publication. Protect sources rigorously, since the population with access to a given record set is often small. Give named individuals and institutions a right of reply setting out the specific transactions, and publish substantive responses.
🌍 NGO, humanitarian and human rights
Accountability and humanitarian organisations use financial intelligence to trace stolen public funds, document conflict financing and protect their own programmes against diversion. Practice is document-based and built for onward use by regulators, prosecutors and courts, using registries, procurement records, sanctions data and audit findings rather than account access. Internally the discipline supports due diligence on partners and vendors in high-risk environments, where diversion risk is real and where over-cautious de-risking can also cut communities off from aid. Duty of care matters because tracing funds of powerful actors attracts litigation and physical risk, so legal review and analyst anonymity are standard.
🎓 University and research
Researchers study illicit finance as a measurement and effectiveness problem: how much suspicious activity reporting leads to enforcement, whether typologies detect what they claim, how sanctions and de-risking affect flows, and how criminal networks structure payments. The central methodological difficulty is data access, since the informative material is protected. Approved routes are administrative data agreements with regulators or financial intelligence units under strict disclosure control, court records, and published enforcement actions. Ethics review is required, and any work on identifiable individuals needs particular care given the reputational consequences of a suspicion. Publish methodology and aggregate results, never case-level detail.
Playbook: working Financial Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Establish authority and legal basis
Determine before anything else what you are entitled to see and to do. Inside a regulated institution that means the regulatory basis for monitoring and the internal escalation route; in law enforcement it means which orders and warrants are needed for which records; in open-source practice it means recognising that account data is simply not available and structuring the work accordingly. Record tipping off constraints and disclosure obligations. A good output is a written basis covering collection, retention and onward sharing. Stop when every planned step has an identified authority.
Phase 2 — Define the financial question
State what must be established: whether funds derive from a predicate offence, who controls an account, where value came to rest, whether a payment breaches sanctions, or whether a network is being financed. Different questions need different records and different standards of proof. Identify what would satisfy the decision maker, whether that is an intelligence judgement, a suspicious activity report or evidence to a criminal standard. A good output is a written question with the required standard stated. Stop when the question is specific enough that you know which records would answer it.
Phase 3 — Map the subject financial footprint
Build the picture of who and what you are following: individuals, corporate entities, accounts, payment instruments, and the institutions and jurisdictions involved. Use corporate registries, sanctions and enforcement data, court records and, inside an institution, customer records and account relationships. Identify the intermediaries, since money laundering is characterised by the layer of vehicles between origin and destination. A good output is an entity and account map with the evidence for each link. Stop when the map covers the subject known financial presence and the unknowns are listed.
Phase 4 — Assemble the transaction record
Obtain the transaction data through the lawful route available: internal monitoring output and account histories inside an institution, production orders and account monitoring orders in law enforcement, or documented open-source substitutes such as court exhibits, procurement payments and filed accounts. Normalise into a consistent structure with date, amount, currency, counterparty, instrument and narrative field. Preserve originals with hashes. A good output is a reconciled transaction dataset traceable to source documents. Stop when the period of interest is covered continuously and gaps are identified as gaps.
Phase 5 — Reconstruct the flow
Build the flow from origin to destination, tracing through accounts and entities and recording what each hop achieves for the launderer: placement, layering or integration. Apply and declare a tracing convention where funds commingle, because the choice materially changes the answer. Quantify in original currency with conversion documented. Identify the point where value leaves the traceable system, whether into cash, property, goods or a jurisdiction that will not respond. A good output is a quantified flow with a convention statement. Stop when funds reach a resting point or the trace hits a documented barrier.
Phase 6 — Test against typologies
Compare observed behaviour against recognised typologies: structuring below reporting thresholds, rapid pass-through with minimal balance retention, round-sum payments with no commercial documentation, trade mispricing, use of professional service providers as intermediaries, and inconsistency between account activity and declared business. Typologies focus enquiry; they do not prove anything, and treating a pattern match as a conclusion is a standard failure. A good output is a typology assessment identifying which patterns are present and what would distinguish them from legitimate behaviour. Stop when the alternative innocent explanations have been named.
Phase 7 — Build the commercial rationale test
For each significant transaction or relationship, ask what legitimate commercial purpose it serves and seek the evidence that would confirm it: contracts, invoices, shipping documents, filed accounts, licences, corresponding trade statistics. Absence of any commercial rationale for a substantial recurring payment is the strongest single indicator in the discipline, and it is also the finding most likely to survive challenge. A good output is a rationale table listing each material flow, the claimed purpose and the corroborating evidence or its absence. Stop when every material flow is explained or its unexplained status is documented.
Phase 8 — Screen sanctions and designation exposure
Screen every party in the flow against sanctions, export control, debarment and enforcement data, applying ownership and control rules by aggregation rather than looking at each holder separately. A designated party anywhere in the chain changes the legal position immediately for every institution touching it. Escalate matches at once rather than completing the analysis first. A good output is a screening record covering all parties with dispositions and dates. Stop when every party has been screened and every match resolved or escalated to compliance and counsel.
Phase 9 — Report and refer correctly
Route the output through the correct channel. Inside a regulated institution, that is a suspicious activity report to the financial intelligence unit, drafted so a reader with no context can understand the suspicion, the parties, the amounts and the reasoning, and filed within the statutory window. In law enforcement it is an intelligence product or an evidential statement depending on the material. Observe tipping off restrictions absolutely. A good output is a report that generates action rather than acknowledgement. Stop when the report is filed and the internal decisions on the relationship are recorded.
Phase 10 — Support restraint and recovery
Where assets can be preserved, act quickly, because value moves faster than process. Support restraint, freezing and forfeiture applications with the flow reconstruction and the source documents, identify where assets have come to rest in a form that can be restrained, and coordinate with counterparts in the relevant jurisdictions. Recovery is the measure of the discipline, not reports filed. A good output is an application supported by a documented, reproducible reconstruction. Stop when the assets are restrained or the barrier to restraint is documented.
Phase 11 — Preserve evidence and manage disclosure
Maintain continuity for every document and dataset: source, retrieval or production date, hash, and every analytic transformation applied. Keep working papers on the assumption they will be disclosed, because in most jurisdictions they will be. Distinguish clearly in the file between intelligence that cannot be used evidentially, such as financial intelligence unit product, and evidence that can. A good output is a file that a defence expert could examine without finding an unexplained step. Stop when the reconstruction can be reproduced by another analyst from the exhibits alone.
Phase 12 — Feed detection back
Convert what the case taught into monitoring improvement: new or refined detection scenarios, threshold changes, additional data attributes to capture, and typology updates shared with the sector where permitted. Measure whether the change produces useful alerts rather than volume, since poorly tuned scenarios flood investigators and reduce overall effectiveness. A good output is a specific tuning change with measured effect on alert quality. Stop when the change is in production and its effect on true positive yield has been measured.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Financial Action Task Force | Open | International standard setter publishing the recommendations, typology reports, mutual evaluations and jurisdiction risk listings. | Authoritative typologies and the standards against which institutional controls and jurisdictional risk are assessed. |
| FinCEN | Open | United States financial intelligence unit publishing advisories, alerts, typologies, enforcement actions and reporting guidance. | Advisories that define red flag sets for specific threats and the reporting obligations attached to them. |
| Egmont Group | Open | Association of financial intelligence units publishing principles for information exchange and operational cooperation between units. | Governs whether and how financial intelligence received from a foreign unit may be used or shared onward. |
| OFAC sanctions programmes | Open | United States designation lists, sectoral measures, general licences and guidance including ownership and control interpretation. | Determines whether any party in a flow is designated, which changes the legal position for every institution involved. |
| OpenSanctions | Open | Consolidated sanctions, politically exposed person, debarment and enforcement datasets with cross-source entity resolution. | Screens all parties in a reconstructed flow against multiple designating authorities in a single pass. |
| Wolfsberg Group | Open | Association of international banks publishing principles and guidance on correspondent banking, due diligence and payment transparency. | Sets the industry expectation for correspondent banking due diligence and payment message transparency. |
| SWIFT | Open | Operator of the interbank messaging network publishing message standards, sanctions screening practice and payment transparency initiatives. | Explains the structure and limitations of payment messages, which determines what a wire record can prove. |
| ISO 20022 | Open | Financial messaging standard defining structured payment message formats with richer party and purpose data. | Governs the payment data fields increasingly available for analysis and screening in modern payment systems. |
| Companies House | Open | United Kingdom statutory registry with filing history, officers, charges and persons with significant control declarations. | Identifies the corporate vehicles and controllers used as intermediaries in a laundering structure. |
| GLEIF | Open | Global register of legal entity identifiers with verified parent relationship records used in payment and reporting systems. | Resolves counterparty identity across payment messages and corporate records using a common identifier. |
| OCCRP Aleph | Registration | Searchable archive of leaks, registries, court records and procurement data assembled for investigative research. | Locates documents connecting intermediaries and beneficiaries where statutory registries disclose nothing useful. |
| UNODC | Open | United Nations office publishing research, model legislation and standards on money laundering, asset recovery and organised crime. | Frames asset recovery routes and international cooperation mechanisms available in a given case. |
| Europol | Open | European law enforcement agency publishing organised crime threat assessments and operational results including asset seizures. | Establishes current criminal financing methodologies and provides the route for European operational cooperation. |
| UK National Crime Agency | Open | United Kingdom agency hosting the financial intelligence unit and publishing suspicious activity reporting guidance and threat assessments. | Defines United Kingdom reporting requirements, defence against money laundering requests and national threat picture. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Financial Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Transaction monitoring systems — Apply rule and behaviour scenarios across account activity to generate alerts. Limitation: poorly tuned scenarios produce alert volume that overwhelms investigators and hides real cases.
- Sanctions and watchlist screening engines — Match parties in payments and customer records against designation datasets. Limitation: fuzzy matching trades false positives against missed variants, and ownership rules need separate logic.
- Link analysis platforms — Model relationships between accounts, entities and people to reveal network structure. Limitation: visual density is persuasive irrespective of evidential strength.
- Payment message parsers — Extract structured party and purpose fields from wire and messaging formats for analysis. Limitation: legacy free-text fields are inconsistent and frequently truncated in transmission.
- Case management and reporting systems — Hold investigations, decisions and suspicious activity reports with audit trails for regulatory inspection. Limitation: quality depends on narrative discipline, which is where most reports fail.
- Entity resolution tooling — Deduplicate and match customers, counterparties and corporate entities across data sources. Limitation: transliteration and name variation drive both false merges and missed matches.
- Blockchain analytics platforms — Extend tracing where value moves into or out of digital assets. Limitation: proprietary heuristics are not independently verifiable and attribution decays over time.
- Statistical and anomaly detection tooling — Surface unusual behaviour that fixed rules miss, such as structuring patterns and pass-through behaviour. Limitation: unexplainable model outputs are difficult to justify to regulators and courts.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Absence of commercial rationale is the strongest single indicator. A substantial recurring payment with no contract, invoice, shipping document or corresponding trade record behind it survives challenge better than any statistical pattern.
- Suspicious activity reporting is intelligence, not evidence, and in most regimes cannot be used as evidence or disclosed. Build the evidential case from records obtained under order and keep the two streams separate in the file.
- Declare your tracing convention when funds commingle. First in first out, last in first out and proportional attribution produce materially different attributions of the same pooled balance, and an undeclared choice is a hidden assumption.
- Typology matches focus enquiry and prove nothing. Legitimate businesses structure payments for tax, treasury and commercial reasons, so the analytic work is identifying what distinguishes this instance from the innocent version.
- Move on preservation before analysis is complete. Value leaves the traceable system far faster than investigations progress, and a restraint order obtained on partial evidence often preserves what a perfect reconstruction would have lost.
- Tipping off is a criminal offence in most regimes and is committed accidentally. Establish before contact with a customer or counterparty exactly what may be said, because a well-intentioned enquiry can end an investigation.
- Screen for ownership-based designation by aggregation, not by individual holder. Entities blocked through combined designated ownership are routinely missed by screening engines that check each shareholder separately.
- Write the suspicious activity report for a stranger. The recipient has no context, receives enormous volume, and acts on clarity, so a report that states the parties, the amounts, the behaviour and the reasoning plainly is worth more than a long one.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Financial Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Value of assets restrained, frozen or recovered as a result of the capability, rather than the number of reports filed or alerts generated.
- Proportion of suspicious activity reports that result in law enforcement action or feedback, tracked by scenario to identify which detections work.
- Alert to case conversion rate and investigator time per alert, which together measure whether monitoring tuning is helping or obstructing.
- Median time from detection of suspicious activity to filing, measured against the statutory window rather than an internal target.
- Share of reconstructions independently reproducible from exhibited source documents by another analyst without reference to the original author.
- Number of parties in reported flows that were subsequently found to be designated but were missed at screening, which should be zero.
- Rate of tipping off incidents and disclosure failures, which are control failures rather than performance measures.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Alert-driven investigation that never questions whether the underlying rule reflects a real typology, generating volume without detection
- Confusing unusual with suspicious, when legitimate businesses have irregular, seasonal and structurally odd payment patterns
- Defensive reporting to reduce institutional risk, which floods financial intelligence units and degrades signal for everyone
- Investigating without a baseline of expected behaviour, so nothing can be judged anomalous with any analytical rigour
- Tipping off the subject, which is a criminal offence in most anti-money-laundering regimes and destroys the investigation
- Treating a sanctions name match as a hit without resolving date of birth, jurisdiction and ownership aggregation rules
Legal and ethical considerations
This is heavily regulated territory. Transaction data is confidential and its use is constrained by banking secrecy, data protection and anti-money-laundering law, and access outside a regulated institution requires legal process. Tipping off a subject about a suspicious activity report is a criminal offence in most jurisdictions. Suspicion thresholds, reporting deadlines and record retention periods are set by statute rather than preference. Open-source financial investigation must avoid pretexting, which can constitute fraud or unlawful obtaining of personal data, and findings alleging criminality belong in lawful reporting channels.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Financial Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 data points, 10 mission domains, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Can a suspicious activity report be used as evidence?
Generally no. In most regimes the report is protected intelligence, its existence may not be disclosed, and disclosing it can itself be an offence. It directs investigative enquiry, and the evidence must then be obtained independently through production orders, account monitoring orders, warrants or mutual legal assistance. Keep the two streams separate in the case file so that protected material never contaminates the evidential bundle, since that contamination causes disclosure problems and can collapse a prosecution. Where a report contains the only record of a fact, the underlying institutional records must be obtained through the proper order.
What can be established without any account access?
More than practitioners expect, though never the transaction detail. Corporate registries establish the vehicles and their controllers; procurement and contract awards evidence payments from public bodies; court filings and insolvency documents frequently reproduce banking records; property and vehicle registers show where value came to rest; customs and trade statistics evidence the goods leg of trade-based laundering; and sanctions and enforcement actions document known conduct. The result is a network and rationale picture strong enough to support a referral, a designation nomination or a story, but not a transaction-level proof.
How do I choose a tracing convention?
Choose according to the legal framework in the jurisdiction where the claim will be made, since some regimes prescribe an approach for mixed funds, and otherwise choose the convention that is most conservative against your own case. Whichever you choose, declare it, apply it consistently, and show the effect of the main alternative so the reader can see how much the conclusion depends on the choice. Where a pooled account mixes legitimate and illicit funds, be explicit that attribution to specific downstream payments is an accounting convention rather than a physical fact about the money.
What makes a good suspicious activity report?
Clarity and completeness for a reader with no context. State who, what, when, how much, through which accounts and institutions, and precisely why it is suspicious, in plain language and in a logical order. Include the identifiers that let the receiving unit link it to other reporting: full names, dates of birth, addresses, account numbers, entity registration numbers. Say what you checked and what you could not establish. Avoid boilerplate and avoid burying the suspicion in a chronology. A short, specific, well-identified report generates action; a long defensive one is filed and forgotten.
Is de-risking an acceptable response?
It is a legitimate commercial decision but a poor systemic answer, and regulators increasingly say so. Exiting an entire customer category removes visibility, pushes activity into less transparent channels, and causes real harm where it cuts off remittance corridors, humanitarian organisations and correspondent relationships for whole jurisdictions. Where risk is manageable through enhanced due diligence, monitoring and restrictions, that is preferable to exit. Where exit is genuinely necessary, document the rationale, consider the wider consequences and, in humanitarian contexts, engage with the relevant authorities on licensing rather than simply withdrawing.
How do sanctions ownership rules interact with screening?
Badly, unless configured deliberately. Screening engines typically match names against lists and will not catch an entity that is unlisted but blocked because designated persons collectively hold enough of it. You need ownership data and logic that aggregates designated holdings through intermediate entities, plus a separate assessment of control, which several regimes treat independently of shareholding. Build this as a distinct check rather than assuming the screening tool does it, review it when structures change, and document the calculation, because supervisors will ask how the determination was reached.
When should assets be restrained rather than investigated further?
Earlier than instinct suggests. Value leaves the traceable system quickly, through cash extraction, property purchase, conversion to goods or transfer to a jurisdiction that will not cooperate, and once it has gone the perfect reconstruction is worth nothing. Where the legal threshold for restraint is met on the evidence you already hold, act, and continue investigating afterwards. The considerations that argue for delay, such as preserving covert enquiry, are real but must be weighed explicitly against dissipation risk, and that judgement should be recorded rather than made by default.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- The FATF Forty Recommendations, which set the international standard for anti-money laundering and counter-terrorist financing controls.
- The EU anti-money laundering directives and the UK Money Laundering Regulations 2017, which govern due diligence, monitoring and reporting duties.
- The UK Proceeds of Crime Act 2002, which governs money laundering offences, reporting, tipping off and asset restraint and confiscation.
- The US Bank Secrecy Act and its implementing regulations, which govern reporting obligations and record keeping for United States institutions.
- The Egmont Group principles on information exchange, which govern use and onward disclosure of intelligence received from foreign financial intelligence units.
- The Wolfsberg Principles on correspondent banking and due diligence, which set industry expectations for cross-border relationships.
- ISO 20022, which governs the structured payment message data available for screening and analysis.
- The UN Convention against Corruption and the Convention against Transnational Organized Crime, which govern mutual legal assistance and asset recovery.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- The FATF Recommendations and typology reports — Financial Action Task Force. International anti-money laundering standards and recognised laundering typologies
- Advisories and enforcement actions — Financial Crimes Enforcement Network. United States financial intelligence unit guidance, red flags and reporting requirements
- Principles for information exchange between financial intelligence units — Egmont Group. Rules governing use and onward sharing of foreign financial intelligence
- Sanctions programmes and ownership guidance — US Office of Foreign Assets Control. Designation lists and the ownership rules determining blocked status
- Correspondent banking principles — Wolfsberg Group. Industry standards for cross-border due diligence and payment transparency
- Suspicious activity reporting guidance — UK National Crime Agency. United Kingdom reporting requirements and defence against money laundering process
- Asset recovery and anti-money laundering resources — United Nations Office on Drugs and Crime. International cooperation mechanisms and model provisions for asset recovery
- Serious and Organised Crime Threat Assessment — Europol. European assessment of criminal financing methods and asset seizure outcomes
- ISO 20022 financial messaging standard — ISO 20022 Registration Authority. Structured payment message standard defining party and purpose data
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: detects typology patterns, maps networks and builds provenance-preserved case files for lawful referral. Explore the platform, or browse the rest of the library by following any tag above.