Organized Crime: Mission Domain Intelligence Guide
Organised crime leaves paperwork. Not confessions, but a notary who appears in eleven unrelated share transfers, a haulage firm with three lorries and a container throughput that would need thirty, and a restaurant that banks like a casino.
Organised crime leaves paperwork. Not confessions, but a notary who appears in eleven unrelated share transfers, a haulage firm with three lorries and a container throughput that would need thirty, and a restaurant that banks like a casino.
What Organized Crime covers as a mission domain
Organised crime intelligence addresses durable criminal networks that operate across markets and jurisdictions: mafia-type associations, poly-crime networks, clan-based groups and the professional facilitators who service them. Analytical practice centres on network reconstruction rather than individual offences. Analysts resolve entities across company registries, court records, land registries, leaked datasets and open reporting, then apply social network analysis to identify brokers, cut-points and single points of failure, and financial analysis to trace how proceeds are layered and integrated.
The critical layer is not the violent core but the enablers: lawyers who form structures, accountants who create the paperwork, notaries who certify it, customs and port staff who move it, and bankers who accept it. Markets converge, with the same logistics and laundering infrastructure carrying narcotics one month and counterfeit goods the next. Structures are increasingly fluid networks contracted for specific tasks rather than standing hierarchies.
Why it matters
Beyond direct offending, organised crime distorts legitimate economies: property markets absorb laundered capital, public procurement is captured, and rival businesses cannot compete against subsidised pricing. Where groups embed in local governance, the harm becomes governance failure rather than crime statistics. Communities experience it as intimidation, extortion and violence, while institutions experience it as corrosion of the institutions that would otherwise respond.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- The same directors, nominee shareholders or registered agents recurring across formally unrelated companies in multiple jurisdictions
- Cash-intensive businesses reporting turnover implausible for their footprint, staffing, supplier invoices or utility consumption
- Property acquired through layered special purpose vehicles with rapid resale at unexplained valuation changes
- Repeated use of a specific notary, law firm or company formation agent across otherwise disconnected corporate structures
- Trade-based laundering indicators: mispriced invoices, phantom shipments and commodity flows inconsistent with mirror trade statistics
- Violence patterns tracking territorial or market disputes rather than individual grievance, clustering around specific logistics nodes
- Corporate structures dissolved and re-registered with near-identical names and the same officers after an enforcement action
- Port, airport or haulage staff with access to manifest systems appearing in association data with importers under investigation
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- Europol SOCTA — Periodic European assessment of serious and organised crime structures, markets and threat prioritisation
- UNODC research and treaty body reporting — Global typologies, market estimates and the legal framework under the Palermo Convention
- OCCRP Aleph — Searchable aggregation of registries, leaks, court records and watchlists supporting cross-border entity resolution
- ICIJ Offshore Leaks database — Beneficial ownership links from offshore leak datasets, useful as a lead source rather than as evidence
- FATF and regional body mutual evaluation reports — Jurisdiction-level anti-money-laundering weaknesses that explain why structures cluster where they do
- GI-TOC Global Organized Crime Index — Comparative country scoring on criminal markets, criminal actors and resilience for strategic framing
- National company and land registries — Primary evidence on directors, ownership, charges and property transfers, with variable but citable reliability
- Court judgments and sentencing remarks — Judicially tested facts about structures, roles and methods, safe to cite and often highly detailed
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Bound the network — Define seed entities and stopping rules before collection, otherwise the graph expands until every commercial relationship in a country is included.
- Resolve entities rigorously — Match across registries, court records and leaks accounting for transliteration, patronymics, common names and date-of-birth collisions.
- Analyse network structure — Use centrality and brokerage measures to find the people whose removal fragments the network, which is rarely the most visible figure.
- Reconstruct financial layering — Trace value from predicate offence through placement, layering and integration, identifying the professional who created each structure.
- Corroborate against judicial record — Anchor findings in court documents, regulatory decisions or seizure records before any assertion about an individual is made.
- Produce a disruption package — Set out options beyond arrest: licensing action, asset recovery, tax investigation, regulatory referral and supplier de-risking, with evidence for each.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Criminal Intelligence — Intelligence Supporting Criminal Investigation
- Financial Intelligence — Following Value Through the Financial System
- Threat Actor Intelligence — Tracking Adversary Groups Over Time
- Human Intelligence — Information from People, Ethically Obtained
- Social Media Intelligence — Intelligence from Social Platforms and Networks
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Corporate Intelligence — Understanding Companies, Structure, and Control
Worked in these data points
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Phone Number — Telephone number for voice, SMS, or messaging identification.
- Messaging Handle — An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
- Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Adjacent mission domains
- Drug Trafficking
- Gangs & Street Crime
- Human Trafficking
- Weapons Trafficking
- Anti-Money Laundering
- Fraud & Identity
- Corruption & Governance
Inside the platform: where Organized Crime lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=org— Organized Crime dashboardtheater.php?d=org— Threat theater viewsearch.php— Person / Name profileblockchain.php— Cryptocurrency Address profilephone-profile.php— Phone Number profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Organized Crime:
- Cryptocurrency Tracing — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Human Trafficking Triage — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Export STIX/MISP
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Bound the network is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Analyse network structure turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Produce a disruption package feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Organized Crime
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts encounter organised crime in stabilisation and expeditionary settings, where criminal networks fund armed groups, control logistics corridors and corrupt host nation institutions. Understanding the network is a force protection and mission success issue: convoy routes, contractor vetting and local partner reliability all depend on it. Products feed intelligence preparation of the operational environment and counter threat finance work. Constraints include the boundary between military intelligence and host nation law enforcement, restrictions on collection against civilians, and the requirement to hand criminal matters to the appropriate authority rather than treating them as targets.
🕵 National intelligence
National services track organised crime for its intersection with state interests: sanctions evasion services, corruption of officials, cyber crime infrastructure and networks that states use as deniable instruments. Requirements focus on structure and chokepoints rather than individual offences: the facilitators, the financial architecture and the small number of people whose removal degrades the network. Fusion of financial intelligence, human reporting and open source corporate data is the working method. Handling questions arise where intelligence must reach law enforcement without contaminating the evidential chain, which is a recurring practical problem in this domain.
👮 Law enforcement
This is the core of serious organised crime policing. Analysis supports investigation strategy: identifying the network's structure, its money, its chokepoints and the individuals whose prosecution would cause most disruption. Evidence has to be gathered through lawful process, with communications, financial and corporate records obtained under production orders, warrants and mutual legal assistance. Analytic products such as network charts and problem profiles inform tasking, but must be clearly distinguished from evidence. Charging decisions frequently rest on financial and corporate documentation rather than on testimony, given witness intimidation risk, so early asset tracing and restraint planning matter.
🔍 Private investigation and corporate security
Corporate and legal sector investigators meet organised crime in due diligence, supply chain compliance, fraud recovery and litigation support. The practical questions are whether a counterparty is controlled by criminal interests, whether a business is a laundering vehicle, and where assets are located for recovery. Work runs on registries, filings, court records, insolvency material, leaks in the public domain and licensed screening data. A private actor cannot compel disclosure, may not obtain data by pretext, and must avoid conduct that could constitute harassment or unlawful surveillance. Safety planning matters, since subjects in this domain sometimes respond to investigation with intimidation.
📰 Journalism and OSINT media
Investigative journalism has produced much of the public record on transnational criminal networks, usually through corporate documents and cross border collaboration. Verification standards should be explicit: documents authenticated, ownership traced through primary records, and allegations put to subjects with adequate time. Legal risk is high, as is physical risk, and both need managing before publication rather than after. Source protection is critical because the pool of insiders is small. Ethics include care with people named incidentally in leaked material, and awareness that publication can expose local reporters and sources long after an international outlet has moved on.
🌍 NGO, humanitarian and human rights
Civil society organisations document the effects of organised crime on communities: extortion, displacement, environmental destruction and the capture of local institutions. Practice is protective, because witnesses and community members face retaliation that outlives any report. Documentation for accountability should follow a repeatable method so it can support later prosecution or international mechanisms. Do no harm requires assessing whether publication increases risk to identified communities and consulting them about it. Duty of care extends to local staff and partners, who bear the greatest exposure and often remain in place after international attention fades.
🎓 University and research
Research covers network structure, illicit economies, governance capture and the effects of enforcement. Methodological care is needed because samples are drawn from prosecuted cases, which represent the least competent segment of any criminal population. Network analysis based on arrest records systematically distorts structure. Ethics approval is required for fieldwork, which carries real risk to researchers and participants, and data management must protect participants from identification. Publish coding frames and network construction rules, share data through controlled access where identification risk exists, and be explicit about the enforcement bias in any dataset used.
Playbook: working Organized Crime end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the network boundary and the question
Decide what you are analysing: a family, a market, a corridor or a service. Networks have no natural edges, so state the inclusion rule and stick to it. Establish what decision the work supports, whether disruption, prosecution, due diligence or policy. A good output is a scope statement that tells you which relationships to record and, more usefully, which to leave out, because unbounded network work never finishes.
Phase 2 — Build the entity base
Resolve people and companies across registries, beneficial ownership records, court and insolvency files, property records and sanctions lists. Record identifiers, dates of birth where lawfully held, addresses, aliases and transliteration variants. Attach a source to every attribute. The output is a clean entity set where duplicates have been merged deliberately with evidence, since bad entity resolution corrupts every subsequent inference.
Phase 3 — Map relationships with evidence
Record each relationship type separately: shareholding, directorship, family, co-defendant, shared address, shared professional adviser, transaction. Date each edge and cite its source. Distinguish documented, inferred and reported relationships visually and in the data. A good output lets a reader ask why two people are connected and receive a document reference rather than an assertion. Date every edge, because a relationship that ended in 2016 supports a very different claim.
Phase 4 — Find the facilitators
Identify the lawyers, accountants, company formation agents, notaries, bankers and logistics operators who service the network. They are usually more durable than principals, appear across unrelated cases, and are more susceptible to regulatory action. The output is a facilitator list with the cases each appears in, which frequently reveals that several apparently separate networks share a single professional enabler. Check whether the same adviser appears in cases your organisation has already worked.
Phase 5 — Follow the money architecture
Trace the flow: cash generation, placement, layering through corporate structures and jurisdictions, and integration into assets. Identify the accounts, the correspondent relationships and the asset classes used. Note where value moves outside the banking system through trade based methods, informal value transfer or virtual assets. A good output identifies the specific points where the flow becomes visible to a regulated institution, because that is where intervention is possible.
Phase 6 — Locate the chokepoints
Analyse which nodes, if removed, would most degrade the network's ability to operate: a specific broker, a corrupt official, a single laundering channel, a logistics route. Betweenness in a graph is a hint, not an answer, because the graph reflects your collection rather than reality. Test each candidate against what the network could substitute. The output is a short list of disruption options with an assessment of substitutability for each.
Phase 7 — Assess corruption and institutional capture
Establish where the network's protection comes from: police, customs, judiciary, local government or political funding. This determines what enforcement action is realistic and whether local partners can safely be involved. Handle this assessment with strict compartmentation. A good output states which institutions can be relied upon and which cannot, with the evidence, because an operation planned without that knowledge is likely to be compromised.
Phase 8 — Separate intelligence from evidence
Maintain two records: the analytic picture and the evidential material, with a documented process for converting one into the other through lawful collection. Never allow intelligence sourcing to leak into a case file. Plan the evidential route early: which production orders, which mutual legal assistance requests, which jurisdictions and how long each takes. The output is a case strategy that anticipates disclosure and protects sensitive sourcing properly.
Phase 9 — Plan asset identification and restraint
Identify assets early and in parallel with the investigation, because restraint is time critical and assets move once an investigation becomes visible. Map property, corporate holdings, vehicles, accounts and virtual assets to specific legal owners in specific jurisdictions. A good output is a restraint plan ready to execute at the moment of arrest, since post arrest asset tracing usually recovers a fraction of what pre arrest work identifies.
Phase 10 — Protect witnesses and communities
Assess intimidation risk before any step that reveals the investigation, and plan protective measures for witnesses, victims of extortion and community members who cooperated. This includes anonymity in proceedings, relocation where warranted, and honest conversations about what protection can and cannot be provided. The output is a protection plan agreed with the responsible authority before exposure occurs, not after a threat is received.
Phase 11 — Coordinate across jurisdictions
Establish the cooperation route early: joint investigation team, liaison officer, Europol or Interpol channel, or bilateral arrangement. Understand differences in evidential rules, since material lawfully obtained in one jurisdiction may be inadmissible in another. Agree who leads and how disclosure will be handled. A good output is an agreed operational plan rather than parallel investigations that discover each other late and compromise both.
Phase 12 — Measure disruption, not activity
After action, assess what actually changed: did the market price move, did the route shift, did the facilitator stop operating, did a successor emerge within weeks. Arrests and seizures are inputs. The output is an evaluation that tells the organisation whether the disruption model works, which is the only way this discipline improves rather than repeating expensive operations with no measurable effect.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OpenCorporates | Registration | Company records aggregated from official registers worldwide with officers, addresses and filing history. | Primary tool for resolving corporate structures and finding shared directors and agents. |
| OCCRP Aleph | Registration | Searchable archive of registries, leaks, court records and documents assembled for investigative work. | Locating names across document collections no single registry search would reach. Access is granted to journalists and investigators under terms. |
| ICIJ Offshore Leaks Database | Open | Structured data from major offshore leaks linking entities, officers and intermediaries across jurisdictions. | Identifying offshore vehicles and the intermediaries who created them for a target network. |
| Europol SOCTA and operational reporting | Open | European strategic assessment of serious organised crime, network typologies and market analysis. | Strategic framing, typology definitions and identification of priority criminal markets. Also identifies which markets European agencies are prioritising. |
| UNODC research and threat assessments | Open | Global research on transnational organised crime markets, trafficking flows and governance impacts. | Authoritative baseline data on market scale and flows for strategic products. Also useful for challenging inflated market size claims. |
| FATF mutual evaluation reports | Open | Country by country assessment of anti money laundering and counter terrorist financing effectiveness. | Understanding which jurisdictions have weak controls and where laundering concentrates. Effectiveness ratings matter more than technical compliance ratings. |
| OpenSanctions | Open | Aggregated sanctions, politically exposed person and enforcement data reconciled into a single model. | Screening network members and their companies against designations and enforcement records. Alias handling is stronger than in most single source lists. |
| Court records and unsealed indictments | Open | Charging documents, judgments and evidentiary summaries describing network structure and methods. Often the most detailed public account of a network's structure. | The most reliable open documentation of how a specific network actually operated. |
| Global Initiative Against Transnational Organized Crime | Open | Research on criminal economies, illicit markets and the resilience of affected communities. | Analytical framing and country level context on markets and governance capture. Includes country level indices covering criminal markets and resilience. |
| Land and property registries | Registration | Official records of property ownership, charges and transfers, coverage varying widely by jurisdiction. | Locating assets and identifying laundering through real estate for restraint planning. Access rules and coverage vary sharply between jurisdictions. |
| Beneficial ownership registers | Registration | Official registers of ultimate beneficial owners where they exist, with variable coverage and verification. | Testing whether declared ownership matches evidence from other records. Access has been restricted in several jurisdictions following litigation. |
| Trade and shipping records | Licensed | Bill of lading data, vessel movements and customs records for jurisdictions that publish them. | Tracing logistics used for smuggling and trade based money laundering. Coverage is strongest for jurisdictions that publish customs records. |
| Transparency International and Global Witness research | Open | Investigative and index based research on corruption, professional enablers and illicit finance. | Context on corruption risk and documented cases of enabler behaviour. Useful for identifying enabler behaviour already documented publicly. |
| Insolvency and litigation databases | Registration | Records of insolvencies, judgments, disqualifications and civil litigation involving companies and directors. | Surfacing prior conduct, disqualified directors and disputes that reveal network relationships. Disqualification records are frequently overlooked and highly informative. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Organized Crime. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Link analysis platforms — Build and query entity relationship graphs across large document and record sets. Limitation: visual density suggests certainty the underlying sourcing may not support.
- Entity resolution engines — Merge records referring to the same person or company across sources. Limitation: aggressive matching merges distinct individuals, which corrupts every downstream inference.
- Document processing and optical character recognition — Makes scanned registry filings and court documents searchable. Limitation: accuracy on poor scans and non Latin scripts remains a significant constraint.
- Financial analysis and transaction mapping — Reconstructs flows across accounts and jurisdictions from disclosed records. Limitation: depends entirely on obtaining records through legal process, which is slow across borders.
- Blockchain analytics — Traces virtual asset movements to services that respond to legal process. Limitation: attribution is probabilistic and only useful where a regulated intermediary is reached.
- Case management with disclosure tracking — Manages evidence, unused material and disclosure obligations across a complex multi defendant case. Limitation: disclosure failures remain a leading cause of collapsed prosecutions regardless of tooling.
- Geospatial mapping — Plots routes, properties and incident locations to reveal territorial control and logistics. Limitation: address data quality is poor in exactly the jurisdictions where it matters most.
- Machine translation with specialist review — Enables work with foreign language filings and judgments. Limitation: legal and corporate terminology is frequently mistranslated in ways that invert meaning.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Export STIX/MISP — Streams the selection in CTI standard formats for sharing with partners and ISACs.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Graph centrality reflects your collection, not the network. The most connected node in a chart built from arrest records is often the most arrested person, who is rarely the most important one.
- Professional enablers are the durable target. Principals are replaced within months; the formation agent, the notary and the correspondent banking relationship persist across decades and multiple unrelated networks.
- Enforcement bias distorts every dataset. Prosecuted cases represent the least competent operators, so structural conclusions drawn from them describe failure rather than the market.
- Identify assets before the investigation becomes visible. Restraint planning done after arrest recovers a fraction of what pre arrest tracing identifies, because assets move within hours of exposure.
- Assess institutional capture before involving local partners. Operations planned without an honest judgement about which agencies are compromised are the ones that leak, and the consequences fall on local witnesses.
- Measure substitutability before choosing a disruption target. Removing a node the network can replace in a week is activity; removing one it cannot replace for a year is disruption, and the difference is knowable in advance.
- Keep the intelligence and evidence records physically and procedurally separate. Cross contamination is the most common way sensitive sourcing ends up in disclosure and a case is lost or a source endangered.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Organized Crime is producing anything, and they are worth baselining before you change process or tooling.
- Change in the criminal market after disruption, measured through price, availability or route displacement rather than arrest counts.
- Time to replacement for disrupted nodes, which measures whether the chokepoint analysis was correct. Measure replacement in weeks, using the same evidence base as the original analysis.
- Value of assets identified before arrest as a proportion of assets ultimately restrained or recovered.
- Proportion of network relationships in the analytic product traceable to a dated primary document. Inferred and reported links should be counted separately.
- Number of professional enablers subject to regulatory or criminal action arising from network analysis. Regulatory action against enablers is frequently faster than prosecution.
- Witness and community protection measures in place before any step that revealed the investigation. Agreed in advance with the authority responsible for delivering them.
- Cross jurisdiction cooperation lead time, from identification of a need to usable material received. Measured separately for preservation requests and for full assistance requests.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Imposing a hierarchy on what is a fluid contracting network, then targeting a nominal boss whose removal changes nothing
- Guilt by association, where sharing an address or a lawyer becomes an allegation rather than a lead requiring corroboration
- Name-matching errors from transliteration and common names, which have wrongly linked innocent people to serious allegations
- Treating leaked datasets as current and complete, when they are snapshots with known gaps and no verification process
- Repeating media allegations as established fact, particularly where local media is itself captured or subject to pressure
- Focusing on the violent core while ignoring the professional enablers, who are more replaceable in principle and more disruptive in practice
Legal and ethical considerations
Naming individuals engages presumption of innocence, defamation exposure and data protection obligations including accuracy and the right to object. Leaked data may be lawful to analyse in some jurisdictions and not others, and its provenance must be disclosed in any product that relies on it. Cross-border evidence requires mutual legal assistance rather than informal exchange if it is to be usable. Asset recovery follows its own statutory route with distinct evidential thresholds, and analysts should be clear which standard a given product is written to meet.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Organized Crime, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 7 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
How do you decide who to target in a network?
By substitutability rather than seniority. Ask what the network would have to do if a given node disappeared: recruit a replacement in a week, or rebuild a banking relationship over years. Leaders are visible and often replaceable, whereas a specific corrupt official, a laundering channel or a licensed professional may be very hard to replace. Test each candidate against the network's demonstrated adaptability, and consider whether removal simply hands the market to a more violent competitor. Record the reasoning, because it lets you evaluate afterwards whether the disruption model was right.
Why do organised crime charts so often mislead?
Because they reflect collection rather than structure. Charts built from arrests, informants and seizures over represent the people who get caught and the relationships that generate records. Family ties and co-defendant links are easy to document, while a critical financial relationship conducted through a single lawyer may leave almost no trace. Visual density also implies confidence. The corrective is to record relationship types and evidence quality explicitly, show inferred links differently from documented ones, and state which parts of the picture rest on a single source.
What does a private investigator do when a subject turns out to be linked to organised crime?
Reassess scope and safety immediately. Inform the client of the change in risk profile, take advice on reporting obligations including suspicious activity reporting where applicable, and stop any activity that could be construed as surveillance or harassment. Physical risk to the investigator and to sources becomes a live consideration and should be managed rather than absorbed. Continue only within registry and documentary research unless there is a compelling reason otherwise. Where criminal offences are apparent, the appropriate route is referral to law enforcement, not continued private investigation.
How useful are beneficial ownership registers in practice?
Useful as a starting point and unreliable as proof. Coverage varies widely, verification is often minimal, and nominee arrangements are common, so a declared owner may be a placeholder. Their real value is in contradiction: where the register says one thing and property records, litigation, bank documents or public statements say another, that discrepancy is an investigative lead. Several jurisdictions have restricted public access following court rulings, so check current availability. Never present a register entry as established ultimate ownership without corroboration from independent records.
What makes cross border cases fail?
Time and admissibility. Mutual legal assistance can take many months, by which time records are deleted, assets have moved and momentum is lost, so preservation requests must go out immediately rather than waiting for the full request. Evidence lawfully obtained under one jurisdiction's rules may be inadmissible in another, particularly around interception and covert methods. Disclosure obligations differ. The practical mitigations are early engagement with liaison channels, joint investigation teams where available, and a case strategy that identifies the evidential route in each jurisdiction before collection begins.
Is it possible to measure whether disruption worked?
Yes, but it requires committing to a measure before the operation. Useful indicators include price and purity in the affected market, shifts in routing, time to replacement of the removed function, and whether the associated violence increased or decreased. These require baseline data collected in advance, which is the step most organisations skip. Arrest and seizure counts measure effort, not effect, and can move in the opposite direction to harm. Building the evaluation into the operational plan is what turns individual operations into an improving capability.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- UN Convention against Transnational Organized Crime and its protocols, the principal international framework for cooperation and offence definitions.
- UN Convention against Corruption, governing bribery offences, asset recovery and international assistance.
- FATF Recommendations, setting international standards on money laundering, beneficial ownership and asset confiscation.
- Mutual legal assistance treaties and the Budapest Convention where electronic evidence is involved.
- Proceeds of crime legislation such as the UK Proceeds of Crime Act and equivalent regimes governing restraint and confiscation.
- Europol and Eurojust joint investigation team frameworks for coordinated cross border investigation.
- National intelligence management models governing grading, tasking and the separation of intelligence from evidence.
- Disclosure regimes such as the Criminal Procedure and Investigations Act, which govern unused material in prosecutions.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Serious and Organised Crime Threat Assessment — Europol. Strategic assessment of criminal networks and markets in Europe.
- Research on transnational organized crime — UN Office on Drugs and Crime. Global market and flow analysis across criminal economies.
- FATF Recommendations and mutual evaluations — Financial Action Task Force. International anti money laundering standards and country assessments.
- Offshore Leaks Database — International Consortium of Investigative Journalists. Structured offshore entity data from major document leaks.
- Aleph investigative data archive — OCCRP. Searchable archive of registries, leaks and public documents.
- Global Organized Crime Index — Global Initiative Against Transnational Organized Crime. Comparative country level assessment of criminal markets and resilience.
- OpenCorporates company data — OpenCorporates. Aggregated official company register data across jurisdictions.
- UN Convention against Transnational Organized Crime — United Nations. Principal international instrument on organised crime cooperation.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: resolves corporate and personal networks across registries, leaks and court records to expose facilitators and chokepoints. Explore the platform, or browse the rest of the library by following any tag above.