L-04 · Mastery

Financial intelligence analytics and typology detection

Examines how raw suspicious-transaction reporting becomes disseminable financial intelligence — through triage, network analysis, monitoring-model governance and lawful data sharing — and equips analysts to judge the quality of each stage.

Module lecturer: Dr. Collen Lediga, Ruhr-Universität Bochum

Module progress
0 / 4 lessons123 min remaining

Visual overview

Interactive figure

Placement · Layering · Integration

The three-stage laundering cycle

Click any node · hover for tooltip

PlacementCash → systemLayeringMove · disguiseIntegrationClean re-entryClick each stage · red flags · example

Lessons

LESSON 0130 min read

From STRs/SARs to intelligence: report quality, triage and disseminable product

Figure 4.1 · Trade mispricing

A widening gap between declared and market price

Copper concentrate exports from a single exporter-importer pair. Every dollar of daylight is a dollar re-routed abroad.

$1.00$2.00$3.00$4.00$5.00JANFEBMARAPRMAYJUNMarketDeclared$3.30 / lb re-routed in June

Source · Simulated dataset; benchmark: LME cash settlement

I begin every training on financial intelligence with a blunt observation: a suspicious transaction report is not intelligence, it is a raw material, and the gap between the two is where most FIUs either earn their institutional relevance or lose it. South Africa's FIC Act 38 of 2001, as amended by the General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act 22 of 2022, obliges accountable and reporting institutions to file both suspicious transaction reports and suspicious activity reports with the Financial Intelligence Centre, but the statute is silent on what happens to that report once it lands in the Centre's case-management system, and it is precisely that silence that separates a functioning FIU from a filing cabinet with a database attached. Egmont GroupEgmont GroupThe global network of financial intelligence units enabling secure, principle-based exchange of financial intelligence between member states. principles, which govern the secure exchange of financial intelligence between the roughly 175 member FIUs worldwide, describe the FIU's core function as receiving, analysing and disseminating, three distinct verbs that map onto three distinct failure points I have observed repeatedly in ESAAMLG mutual evaluations across the region.

Report quality is the first failure point, and it begins upstream of the FIU entirely, in the compliance function of the reporting institution. A narrative field populated with "customer conducted unusual transaction, please investigate" tells an analyst nothing actionable; a narrative that specifies the counterparties, the instruments used, the deviation from expected account behaviour, and the specific typology indicator triggered is analytically useful on the day it arrives. I tell compliance officers that a narrative should let a stranger who has never met the customer understand, in under two minutes, why this transaction crossed the suspicion threshold. FATF's guidance on effective supervision and its mutual evaluation methodology both treat STR/SAR quality as a proxy for the maturity of an entire AML system, because poor narratives cascade: they slow triage, they generate false leads, and over time they train analysts to discount reports from the worst-performing institutions, which is itself a supervisory blind spot.

Defensive filingDefensive filingReporting driven by fear of regulatory sanction rather than genuine risk assessment, inflating volume while diluting evidentiary value. compounds the quality problem from a different direction. Where an institution's compliance culture is driven by fear of regulatory sanction rather than genuine risk judgment, the volume of STRs rises while their individual evidentiary value falls; analysts describe this as "SAR fatigue" or, less charitably, as reporting institutions using the FIU as a liability shield. The FIC and its counterparts across the SADC region have had to develop feedback loops precisely to counter this, issuing typology guidance and sector-specific red-flag indicators so that reporting entities calibrate toward genuinely risk-relevant filing rather than reflexive over-reporting. The perverse economics are well documented globally: FATF's 2021 report on effectiveness and its subsequent guidance both note that a rising STR count is not, on its own, evidence of a healthier system, and several jurisdictions with extremely high per-capita filing rates paradoxically produce fewer prosecutable cases than jurisdictions filing a fraction of the volume but with materially higher narrative quality.

Triage is the analytical discipline that converts a queue of variable-quality reports into a prioritised worklist, and it is where I see the most institutional variation across the FIUs I have advised. A mature triage modelTriage modelA scoring methodology that prioritises incoming reports for analyst attention based on reliability, typology match and existing intelligence links. scores incoming reports against a combination of factors, the reporting institution's historical reliability, the presence of known typology indicators, cross-matches against existing subjects of interest, prior law-enforcement requests, and links to designated persons or entities under UN Security Council sanctions regimes — and routes the highest-scoring reports to case officers within hours rather than weeks. Egmont GroupEgmont GroupThe global network of financial intelligence units enabling secure, principle-based exchange of financial intelligence between member states.'s secure information-exchange network exists specifically to let an FIU enrich a domestic report with foreign-held intelligence at the triage stage, before committing analyst hours to a case that a counterpart FIU could have told them, in an afternoon, was already the subject of an active foreign investigation.

The disseminable intelligence productDisseminable intelligence productThe FIU's finished analytical output, chronology, entity mapping, typology classification and identified gaps; provided to law enforcement or prosecutors. is the FIU's actual output, and it looks nothing like the original STR. A well-constructed dissemination to a prosecuting authority or to SARS's criminal investigations unit typically packages transaction chronology, entity and beneficial-ownership mapping, cross-referenced typology classification, and an explicit statement of the intelligence gaps that further investigative powers (subpoena, search warrant, production order) would need to close. UNODC and the World Bank's joint work on FIU effectiveness has repeatedly found that the single strongest predictor of an FIU's downstream conviction impact is not the volume of reports received but the quality of this final dissemination product and the strength of institutional relationships between the FIU and the agencies that receive it — a lesson South Africa's own post-Zondo Commission reform agenda for the FIC has taken seriously, given the Commission's findings on the institutional fragmentation that allowed state capture-era flows to go undetected for years despite substantial reporting volume already sitting in the system.

The practical discipline I ask officials to internalise is that intelligence value is created, not merely stored, at every stage from receipt through triage to dissemination, and that measuring an FIU by report volume alone measures the wrong variable entirely.

Sequenced stepsVERITAS · Dr. Lediga
1Receipt
STR/SAR filed by accountable institution under FIC Act obligations.
2Triage and scoring
Prioritised by reliability, typology match and cross-referencing against existing subjects.
3Enrichment
Domestic and Egmont-network foreign intelligence layered onto the initial report.
4Dissemination
Packaged product delivered to prosecutors or law enforcement with stated intelligence gaps.

From report to disseminable product

ComparisonVERITAS · Dr. Lediga
Risk-calibrated filing01
Narrative specifies typology indicator
02
Volume tracks genuine risk signal
03
Feedback loop from FIU shapes future filing
04
Higher downstream case conversion
Defensive filing01
Generic 'unusual transaction' narratives
02
Volume driven by fear of sanction
03
Analyst discounting of low-value sources
04
Lower prosecutable-case yield despite volume

Risk-calibrated versus defensive reporting culture

Key terms

Suspicious transaction/activity report (STR/SAR)
A mandatory filing by an accountable institution flagging a transaction or activity inconsistent with expected customer behaviour or risk profile.
Defensive filing
Reporting driven by fear of regulatory sanction rather than genuine risk assessment, inflating volume while diluting evidentiary value.
Triage model
A scoring methodology that prioritises incoming reports for analyst attention based on reliability, typology match and existing intelligence links.
Egmont Group
The global network of financial intelligence units enabling secure, principle-based exchange of financial intelligence between member states.
Disseminable intelligence product
The FIU's finished analytical output, chronology, entity mapping, typology classification and identified gaps; provided to law enforcement or prosecutors.

Exercise

Take three anonymised STR narratives of varying quality (or draft composites) and rewrite the weakest as an analyst would need it written; then draft a one-page triage score sheet with five weighted criteria you would apply before assigning any of the three to a case officer.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-02

  1. 01FIC Act 38 of 2001 as amended by Act 22 of 2022Parliament of South Africa, 2022.Reporting obligations and Financial Intelligence Centre functions.
  2. 02Egmont Group Principles for Information ExchangeEgmont Group of Financial Intelligence Units, 2013.Governs secure inter-FIU exchange underpinning enrichment and triage.
  3. 03Report on the effectiveness of AML/CFT systemsFATF, 2021.Discusses STR volume versus quality as an effectiveness indicator.
  4. 04Judicial Commission of Inquiry into State Capture (Zondo Commission) reportsGovernment of South Africa, 2022.Findings on institutional fragmentation affecting FIC responsiveness during state capture-era flows.
Full bibliography →
LESSON 0231 min read

Network and link analysis: entity resolution, graph construction and analytical fallacies

Figure 1.2 · Anatomy

From dirty source to clean asset

Illicit proceeds converge in an offshore layer of shells and trusts, then re-emerge as respectable holdings. Ribbon width is proportional to share of flow.

OFFSHORE LAYERGrand corruptionTax evasionNarcotics & traffickingLondon real estateLuxury assetsShell equity portfoliosLAYERING§shells · trusts · nominees

Source · Schematic based on FATF typology reports

Once a case moves beyond a single suspicious transaction, the working unit of analysis becomes the network rather than the transaction, and this is where financial intelligence analytics converges with graph theory. A network in this context is nothing more exotic than a set of entities, natural persons, legal persons, accounts, addresses, devices — connected by edges representing transactions, shared attributes, or documented relationships such as directorship or beneficial ownership. The discipline of building that graph accurately, before any clever algorithm is applied to it, is called entity resolutionEntity resolutionThe process of determining when records from different sources refer to the same real-world person or legal entity, using probabilistic or deterministic matching., and I have never seen a network analysis fail for want of a sophisticated centrality measure; I have seen dozens fail for want of correct entity resolutionEntity resolutionThe process of determining when records from different sources refer to the same real-world person or legal entity, using probabilistic or deterministic matching. at the outset.

Entity resolutionEntity resolutionThe process of determining when records from different sources refer to the same real-world person or legal entity, using probabilistic or deterministic matching. is the deceptively difficult task of determining when two records — a name on a bank account, a name on a company registry extract, a name on a property deed, refer to the same real-world entity. In a jurisdiction where identity documents are inconsistently captured, where common surnames are shared across unrelated families, and where beneficial-ownership registers such as the one established under South Africa's Companies Act 71 of 2008 (as strengthened by 2023 regulatory amendments implementing FATF Recommendation 24 in response to the February 2023 greylisting) are still maturing in data quality, resolution errors run in both directions. A false merge treats two distinct people as one, contaminating a network with unrelated transactions and producing false positives that waste investigative capacity. A false split treats the same person as two distinct entities across different documents, causing an investigator to miss the very link the analysis was meant to surface. Probabilistic matching; using combinations of name, date of birth, national identification number, and address similarity scored jointly rather than any single field in isolation, reduces both error types relative to naive exact-string matching, but it never eliminates the requirement for an analyst to sanity-check automated merges against primary source documents before a network diagram is treated as evidentiary rather than investigative.

Once entities are correctly resolved, graph construction proceeds by drawing edges from transaction records (who paid whom, and how much, and how often) and from registry data (who directs which company, who owns which property, who is a signatory on which account). The resulting graph supports centrality measures borrowed from social network analysis: degree centralityDegree centralityA graph measure counting an entity's direct connections, useful for identifying transactional hub accounts. identifies the entities with the most direct connections, useful for spotting a hub account through which many seemingly unrelated parties transact; betweenness centralityBetweenness centralityA graph measure identifying entities on the shortest path between otherwise unconnected clusters, often flagging professional enablers. identifies entities that sit on the shortest path between otherwise disconnected clusters, which is often exactly where a professional enabler — an accountant, attorney or company-formation agent — sits in a layering network, because their structural role is precisely to connect clusters that would otherwise have no reason to interact, and eigenvector centrality weights an entity's importance by the importance of its connections, useful for identifying a network's true controlling node even where that node transacts relatively infrequently itself, delegating the bulk of transactional volume to lower-tier nominees.

The analytical fallacies that recur in this work deserve as much attention as the techniques, because a compelling graph visualisation carries a persuasive power that frequently outstrips its actual evidentiary weight. The first fallacy is mistaking correlation of activity for a substantive relationship: two accounts that both transact with a common utility company or a common bulk-payment aggregator will appear connected in a naive graph, without that connection carrying any meaning beyond both entities using the same ordinary service provider. Analysts must prune graphs of these "hub" nodes that represent common infrastructure rather than a meaningful relationship, or every network in a country will appear connected to every other network through the local electricity utility or a dominant mobile-money platform. The second fallacy is treating centrality as guilt: a high-betweenness node may be a launderer's professional enabler, but it may equally be a legitimate high-volume remittance agent or a bank itself, and centrality is an investigative prioritisation signal, not a finding. The third fallacy, particularly dangerous in prosecutorial contexts, is presenting a network diagram in court or to a magistrate as though it were self-evidently probative; a graph is a hypothesis-generation tool, and every edge it displays must be traceable back to an underlying document or testimony that would independently satisfy an evidentiary standard, a discipline the FATF's guidance on financial investigations and asset recovery explicitly urges practitioners to maintain.

I encourage analysts to treat network analysis as an iterative loop rather than a single output: build the initial graph from confirmed transactional and registry data, apply centrality measures to prioritise which nodes warrant deeper investigation, resolve any newly discovered entities with the same rigour applied at the outset, and repeat, expanding the graph only as each new edge is independently verified. Done well, this iterative discipline is what allows an FIU or investigative unit to move from a single suspicious account to a mapped criminal network with named principals, professional enablers and identified asset holdings, which is the actual objective of the exercise, not the visual elegance of the diagram itself.

Sequenced stepsVERITAS · Dr. Lediga
1Build initial graph
From confirmed transactional and registry data only.
2Apply centrality measures
Degree, betweenness and eigenvector centrality to prioritise nodes.
3Resolve new entities
Apply the same probabilistic-matching rigour to any newly surfaced node.
4Verify and expand
Add edges only once independently documented, then repeat the loop.

The iterative network-analysis loop

ComparisonVERITAS · Dr. Lediga
Degree centrality01
Counts direct connections
02
Flags transactional hub accounts
03
Sensitive to high-volume legitimate nodes
04
Best for initial triage of busy accounts
Betweenness centrality01
Measures position on shortest paths
02
Often surfaces professional enablers
03
Less distorted by raw transaction volume
04
Best for identifying structural bridges

Degree versus betweenness centrality in practice

Key terms

Entity resolution
The process of determining when records from different sources refer to the same real-world person or legal entity, using probabilistic or deterministic matching.
False merge/false split
Entity-resolution errors that either wrongly combine distinct entities or wrongly separate a single entity into apparent duplicates.
Degree centrality
A graph measure counting an entity's direct connections, useful for identifying transactional hub accounts.
Betweenness centrality
A graph measure identifying entities on the shortest path between otherwise unconnected clusters, often flagging professional enablers.
Hub-node contamination
The analytical fallacy of treating shared use of common infrastructure (utilities, payment aggregators) as evidence of a substantive relationship.

Exercise

Using a small anonymised or hypothetical transaction dataset (15–20 entities), construct a network diagram by hand, calculate degree and betweenness centrality for each node, and write a half-page memo identifying which high-centrality node most plausibly represents a professional enabler and what document you would need to confirm that hypothesis.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-02

  1. 01Companies Act 71 of 2008 beneficial-ownership regulations (2023 amendments)Companies and Intellectual Property Commission, South Africa, 2023.Strengthened beneficial-ownership register data feeding entity resolution.
  2. 02Operational Issues: Financial Investigations GuidanceFATF, 2012.Guidance on financial-investigation techniques including network mapping and evidentiary discipline.
  3. 03Anti-money laundering and counter-terrorist financing measures; South Africa Mutual Evaluation ReportESAAMLG / FATF, 2021.Assessment of analytical capacity underpinning South Africa's 2023 greylisting.
  4. 04Egmont Group Analytical Guidance for FIUsEgmont Group of Financial Intelligence Units, 2019.Standards for network and link-analysis methodology in FIU casework.
Full bibliography →
LESSON 0332 min read

Rules, models and machine learning in transaction monitoring

Figure 3.2 · Composition

Vehicle mix inside a typical layered portfolio

Where the money actually sits, aggregated across seven leaked incorporator datasets. British Virgin Islands entities remain dominant.

1,240ENTITIES · 7 LEAKSBritish Virgin Islands shellsRANK 01 · 42% of portfolioDelaware LLCsRANK 02 · 21% of portfolioCayman trustsRANK 03 · 15% of portfolioLuxembourg SARLsRANK 04 · 12% of portfolioOther vehiclesRANK 05 · 10% of portfolio

Source · ICIJ leak datasets (Panama, Paradise, Pandora); n = 1,240 entities

Transaction monitoring systems sit at the centre of every reporting institution's AML programme, and their evolution from static rule sets to statistical models to machine-learning classifiers has been the most consequential technical shift in compliance practice over the past decade. A rules-based scenario is, at its simplest, a threshold condition: flag any account receiving more than a specified number of cash deposits below a reporting threshold within a rolling thirty-day window, or flag any wire to a jurisdiction on a defined high-risk list above a specified value. Rules are transparent, auditable and easy to explain to a regulator or a court, which is precisely why FATF's risk-based approach guidance still treats a well-tuned rules layer as a legitimate and often necessary component of any monitoring programme, not a legacy technology to be discarded.

The persistent problem with rules-based monitoring is the false-positive economicsFalse-positive economicsThe operational cost trade-off between conservative thresholds generating high manual-review volume and tighter thresholds risking missed true positives., and this is where I ask officials to think like an operations manager rather than only like an investigator. Industry studies consistently find that the overwhelming majority of alerts generated by an untuned rules engine, frequently cited in the 90–95 percent range across multiple bank self-assessments and regulatory reviews — resolve as false positives after manual review, meaning that a compliance analyst's day is spent overwhelmingly on alerts that will never become an STR. Each alert carries a real marginal cost in analyst time, and a bank facing genuine resource constraints, which describes most institutions operating in the ESAAMLG region, must make an explicit choice between tuning scenarios to reduce false positives (accepting some risk of missed true positives, a false-negative cost) and leaving thresholds conservative (accepting the operational cost of exhaustive manual review). Scenario tuningScenario tuningEvidence-based adjustment of transaction-monitoring rule thresholds and logic using historical alert-disposition data, documented with rationale. is the disciplined, evidence-based process of adjusting thresholds and logic using historical alert-disposition data, and a mature compliance function documents every tuning decision with a rationale tying the change to observed false-positive or false-negative rates, precisely because an undocumented threshold change is indistinguishable, to a supervisor, from an attempt to suppress inconvenient alerts.

Statistical and machine-learning models layer on top of, or in some institutions increasingly replace, simple rules by learning patterns from historical data rather than relying on a human analyst's a priori threshold. A supervised model trained on historical alerts labelled as true or false positives can, in principle, rank new alerts by predicted likelihood of being a genuine suspicious activity, allowing an institution to focus scarce analyst hours on the highest-probability alerts first — a real and demonstrated efficiency gain reported by several global banks in their public disclosures. But this capability introduces a distinct governance burden that a pure rules engine does not carry: model risk. A model trained on historical labels inherits whatever biases and blind spots existed in the historical labelling process, and if analysts historically under-investigated a particular business type, geography or customer segment, a machine-learning model trained on that history will learn to systematically deprioritise exactly that segment going forward, entrenching rather than correcting the original blind spot.

Model risk governanceModel risk governanceA framework requiring independent validation, ongoing monitoring, documented inventory and accountable ownership for analytical models used in compliance. frameworks, of the kind the Basel Committee has long required for credit-risk models and which several regulators are now extending explicitly to AML monitoring models, typically require independent model validation prior to deployment, ongoing performance monitoring against both false-positive and false-negative proxies, a documented model inventory, and a defined model owner accountable for periodic revalidation. ExplainabilityExplainabilityThe capacity to articulate, at least at a high level, why a model produced a given output, particularly where the output materially affects a customer. is a further obligation layered onto this governance structure, and it is not just good practice but, in several jurisdictions applying the EU's general data-protection framework and analogous provisions, potentially a legal requirement: where a model's output materially affects a customer (for instance, triggering an account restriction or an exit decision), the institution may need to be able to articulate, at least at a high level, why the model produced that output, which is considerably harder for a complex ensemble or deep-learning model than for a transparent rules engine or a simple logistic-regression score.

Fairness obligations compound the explainabilityExplainabilityThe capacity to articulate, at least at a high level, why a model produced a given output, particularly where the output materially affects a customer. question specifically in jurisdictions with strong data-protection or anti-discrimination law. South Africa's Protection of Personal Information Act (POPIA) and the EU's General Data Protection Regulation both constrain automated decision-making that produces legal or similarly significant effects on a data subject, requiring, at minimum, a right to meaningful information about the logic involved and, in some formulations, a right to contest a purely automated decision. For a transaction-monitoring model, this means an institution cannot simply deploy an opaque classifier and treat its output as final; there must be a human-in-the-loop review for any action with material consequence for the customer, and the institution must be able to demonstrate, to a regulator, and potentially to the data subject — that the model does not produce systematically disparate outcomes correlated with protected characteristics or their proxies, such as geography standing in for ethnicity or nationality standing in for a protected class. I tell compliance officers that the discipline required here is not fundamentally different from the discipline good statisticians have always demanded of any classification model; what has changed is that regulators are now willing to ask for the paperwork.

The realistic synthesis I offer at the end of this lesson is that rules, statistical models and machine learning are complementary layers rather than a linear progression in which the newest technology simply replaces the last. A mature monitoring programme retains transparent rules for legally mandated or high-confidence typologies, uses statistical or machine-learning scoring to prioritise the resulting alert queue, and wraps the entire system in a model risk governanceModel risk governanceA framework requiring independent validation, ongoing monitoring, documented inventory and accountable ownership for analytical models used in compliance. structure robust enough to satisfy both a prudential supervisor asking about model risk and a data-protection regulator asking about automated-decision fairness.

ComparisonVERITAS · Dr. Lediga
Rules-based scenarios01
Transparent and easily auditable
02
Simple threshold logic
03
High false-positive volume if untuned
04
Legally straightforward to explain
Machine-learning scoring01
Learns patterns from historical labels
02
Can prioritise highest-probability alerts
03
Risks inheriting historical bias
04
Requires explainability and validation infrastructure

Rules-based versus machine-learning monitoring

Sequenced stepsVERITAS · Dr. Lediga
1Independent validation
Model tested against held-out data before deployment.
2Documented inventory
Every model recorded with purpose, owner and scope.
3Ongoing performance monitoring
Tracking false-positive and false-negative proxies over time.
4Periodic revalidation
Scheduled review by an accountable model owner, with explainability sign-off.

Model risk governance lifecycle

Key terms

Scenario tuning
Evidence-based adjustment of transaction-monitoring rule thresholds and logic using historical alert-disposition data, documented with rationale.
False-positive economics
The operational cost trade-off between conservative thresholds generating high manual-review volume and tighter thresholds risking missed true positives.
Model risk governance
A framework requiring independent validation, ongoing monitoring, documented inventory and accountable ownership for analytical models used in compliance.
Explainability
The capacity to articulate, at least at a high level, why a model produced a given output, particularly where the output materially affects a customer.
Automated decision-making fairness obligation
Legal constraints, under instruments such as POPIA or GDPR, requiring meaningful information and human review for automated decisions with significant effect on individuals.

Exercise

Draft a one-page model risk governance checklist for a hypothetical bank introducing a machine-learning alert-scoring layer on top of its existing rules engine, covering validation, ongoing monitoring, explainability and POPIA/GDPR-consistent human review, and identify probably the most likely source of inherited historical bias in its training data.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-02

  1. 01Guidance on the Risk-Based ApproachFATF, 2014.Frames rules-based monitoring as a legitimate component of a risk-based programme.
  2. 02Principles for the Sound Management of Operational RiskBasel Committee on Banking Supervision, 2021.Basis for extending model risk governance principles to AML monitoring models.
  3. 03Protection of Personal Information Act 4 of 2013 (POPIA)Parliament of South Africa, 2013.Constrains automated decision-making with significant effect on data subjects.
  4. 04General Data Protection Regulation (EU) 2016/679European Union, 2016.Comparative automated-decision-making and explainability provisions (Article 22).
Full bibliography →
LESSON 0430 min read

Data sharing, privacy and public-private partnerships

Figure 4.2 · Attrition

From a million transactions to nine convictions

At every step, orders of magnitude are lost. The final ratio — under one-in-a-hundred-thousand — is the compliance system's honest self-portrait.

Transactions monitored1,200,000Rules-based alerts42,0003.5%Analyst-reviewed6,10014.5%STR / SAR filed84013.8%Referred to prosecutor627.4%Convictions / recoveries914.5%

Source · European FIU composite, 2018–2022

The single greatest structural constraint on financial intelligence analytics today is not analytical technique but institutional and legal access to data, and this final lesson addresses the frameworks that govern how information moves, or fails to move — between reporting institutions, FIUs, law enforcement and across borders. Financial crime, almost by definition, spans institutional and jurisdictional boundaries that were never designed with information sharing in mind, and every genuine advance in this space over the past decade has been an advance in a legal or technical gateway rather than in analytical sophistication as such.

Information-sharing gateways between private-sector institutions are the first and most contested category. Historically, data-protection and banking-secrecy law in most jurisdictions prevented one bank from sharing customer information with another bank, even where both suspected the same customer of the same underlying criminal conduct, because each institution's duty of confidentiality ran to its own customer and there was no statutory safe harbour permitting disclosure to a competitor. The United Kingdom's Joint Money Laundering Intelligence Taskforce (JMLIT), established in 2015 as a public-private partnership bringing together banks, law enforcement and the FIU under a legal gateway created by the Criminal Finances Act 2017, became the template many other jurisdictions have since sought to replicate: a structured forum in which private-sector analysts can share typology and, in defined circumstances, customer-level information with law enforcement and with each other, under statutory protection from the ordinary confidentiality and data-protection constraints that would otherwise apply. FATF's 2022 guidance on private-sector information sharing formalised the case for this model globally, framing it as a necessary complement to the traditional STR-based reporting channel precisely because a single institution's transactional view of a customer is structurally partial, and a launderer's typical technique of spreading activity across several institutions is specifically designed to exploit that partiality.

Public-private partnerships extend this logic further, embedding law enforcement and FIU analysts alongside bank compliance teams on defined thematic operations — human trafficking-linked flows, or a specific professional-enabler network, for example, rather than confining cooperation to the episodic exchange of individual STRs. The evidence base on effectiveness, reviewed by the World Bank and by FATF's own effectiveness assessments, points toward a genuine uplift in both the speed and the actionability of intelligence produced through these partnerships relative to the traditional unilateral-reporting model, though the same evidence also flags a persistent asymmetry: partnerships require sustained institutional investment, tend to be dominated by the largest banks with the analytical capacity to participate meaningfully, and can leave smaller institutions and, by extension, the customer segments and corridors those institutions serve, outside the most effective intelligence-sharing arrangements.

Cross-border data sharing operates under a separate, and in some respects more constrained, set of rules. POPIA in South Africa and the GDPR in the European Union both restrict the transfer of personal information outside their respective jurisdictions unless an adequate level of protection exists at the destination or a specific derogation applies; POPIA additionally imposes its own conditions for lawful processing; including purpose limitation and data minimisation, that an FIU or bank must satisfy even for purely domestic analytical use of customer data, not only for cross-border transfer. These constraints are not incidental friction to be engineered around; they exist to prevent exactly the kind of unchecked financial surveillance that a poorly governed AML data-sharing regime could otherwise enable, and I am consistently clear with officials that privacy law is a legitimate constraint on this work, not an obstacle to be minimised. FATF's own 2021 guidance on data poolingData poolingThe collective analysis of data contributed by multiple institutions or jurisdictions, requiring a clear legal basis and embedded proportionality safeguards under FATF guidance. and collaborative analytics for AML purposes explicitly grapples with this tension, encouraging jurisdictions to adopt clear legal bases for pooled analytics while insisting that any pooling arrangement embed proportionality, purpose limitation and independent oversight rather than treating financial-crime prevention as an automatic override of data-protection law.

Privacy-enhancing technologies (PETs) have emerged as the most promising technical response to this tension, and they deserve serious attention from analysts rather than dismissal as a compliance gimmick. Techniques such as secure multi-party computation allow multiple institutions to jointly compute a result — for instance, whether a given customer appears as a red-flagged entity across several banks' books — without any institution disclosing its underlying raw customer data to the others or to a central pooling body; the computation itself, rather than a shared database, produces the answer. Federated learning allows a machine-learning model to be trained across data held separately by multiple institutions, with only model parameters rather than raw data ever leaving each institution's own systems. Homomorphic encryption, though still computationally expensive for many production use cases as of 2026, permits computation directly on encrypted data. FATF's guidance and a growing body of pilot projects run through organisations including the Bank for International Settlements' Innovation Hub have begun testing these approaches specifically for cross-institution and cross-border AML analytics, on the reasoning that PETs can, in principle, deliver much of the analytical benefit of data poolingData poolingThe collective analysis of data contributed by multiple institutions or jurisdictions, requiring a clear legal basis and embedded proportionality safeguards under FATF guidance., spotting a launderer who spreads activity deliberately across institutions specifically to defeat single-institution monitoring; without requiring the underlying privacy trade-off that full data centralisation demands.

The lesson I want officials to carry forward is that data-sharing architecture is not a peripheral legal-compliance topic bolted onto financial intelligence work; it is the actual rate-limiting factor on how good financial intelligence analytics can become, and the frontier of this field over the next several years will be defined less by more sophisticated algorithms than by whether legal gateways, institutional partnerships and privacy-enhancing technologies mature quickly enough to let analysts see across the institutional silos that criminal networks already routinely exploit.

Enumerated setVERITAS · Dr. Lediga
1
Institutional silo
Single-bank view is structurally partial and easily exploited.
2
Legal gateway
Statutory basis (e.g. Criminal Finances Act 2017) required to permit lawful sharing.
3
Privacy constraint
POPIA/GDPR purpose limitation and minimisation apply regardless of intent.
4
Technical solution
PETs allow joint analytics while limiting raw data exposure.

Layers of the data-sharing problem

ComparisonVERITAS · Dr. Lediga
Centralised data pooling01
Raw data physically consolidated
02
High analytical power, high privacy risk
03
Requires strong legal derogation
04
Single point of failure for breach
Privacy-enhancing technologies01
Raw data remains with originating institution
02
Joint computation or shared model parameters only
03
Reduces but does not eliminate legal complexity
04
Still maturing for production-scale AML use in 2026

Traditional data pooling versus privacy-enhancing analytics

Key terms

Information-sharing gateway
A statutory legal basis permitting reporting institutions to exchange customer or typology information that ordinary confidentiality or data-protection law would otherwise restrict.
Public-private partnership (AML)
A structured, ongoing collaboration embedding law enforcement, FIU and private-sector analysts on thematic financial-crime operations, exemplified by the UK's JMLIT.
Data minimisation / purpose limitation
POPIA and GDPR principles requiring that only data necessary for a defined purpose be processed, constraining even domestic analytical use of customer data.
Privacy-enhancing technology (PET)
Technical methods such as secure multi-party computation, federated learning or homomorphic encryption enabling joint analysis without exposing raw underlying data.
Data pooling
The collective analysis of data contributed by multiple institutions or jurisdictions, requiring a clear legal basis and embedded proportionality safeguards under FATF guidance.

Exercise

Design a one-page proposal for a national public-private information-sharing pilot modelled loosely on JMLIT, specifying the legal gateway required under existing South African law, the categories of information to be shared, and one privacy-enhancing technology you would deploy to limit raw data exposure between participating institutions.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-02

  1. 01Best Practices on Beneficial Ownership for Legal Persons (context: private-sector information sharing)FATF, 2022.Guidance formalising private-sector information-sharing partnerships as complementary to STR reporting.
  2. 02Criminal Finances Act 2017United Kingdom Parliament, 2017.Statutory gateway underpinning the Joint Money Laundering Intelligence Taskforce (JMLIT).
  3. 03Protection of Personal Information Act 4 of 2013 (POPIA)Parliament of South Africa, 2013.Domestic data-protection constraints on analytical processing and cross-border transfer.
  4. 04General Data Protection Regulation (EU) 2016/679European Union, 2016.Comparative cross-border transfer and adequacy framework.
  5. 05Partnering in the Fight Against Financial Crime: Data Collaboration and Privacy-Enhancing TechnologiesFATF, 2022.Guidance addressing data pooling, proportionality and privacy-enhancing technologies for AML analytics.
Full bibliography →

Case study

The shell-hub remittance network

Jurisdiction: Composite, Southern African corridor

A composite investigation traces how a professional company-formation agent used a cluster of shelf companies, a regional remittance platform and a co-opted junior compliance analyst to launder proceeds of tax-refund fraud, illustrating how financial intelligence analytics — from STR triage through network mapping to model-flagged alerts — eventually converged on the enabler rather than the nominal account holders.

Facts

  • Six shelf companies, each registered by the same company-formation agent within an eleven-month window, shared a single registered address and two overlapping director names drawn from a small pool of nominees.
  • Transaction-monitoring rules initially flagged only isolated cash-structuring alerts on individual company accounts, each closed as a false positive by an overstretched compliance team.
  • A machine-learning alert-scoring layer, deployed eighteen months into the scheme, deprioritised the network because historical training labels had systematically under-flagged the sector the shell companies claimed to operate in.
  • Entity resolution work by the FIU, cross-matching company registry data against remittance-platform KYC records, revealed that four of the six 'independent' companies shared an identical registered mobile number used at onboarding.
  • Betweenness-centrality analysis of the reconstructed transaction network identified the company-formation agent's personal account as the sole node connecting all six shell companies to a single offshore remittance corridor.
  • A public-private information-sharing exchange between two banks, conducted under a domestic gateway modelled on JMLIT principles, confirmed that both institutions held STRs referencing the same registered address independently, neither aware of the other's filing.

Investigative questions

  1. At which stage of the STR triage process should the shared registered address have been surfaced, and what data source would have made that link visible earlier?
  2. How did the machine-learning model's inherited historical bias contribute to the network evading detection for eighteen months, and what governance step would have caught this?
  3. What entity-resolution technique would you apply to confirm or refute that the six companies constitute a single beneficial-ownership network?
  4. What evidentiary weight, if any, should the betweenness-centrality finding carry in a prosecutorial brief, and what underlying documents would need to accompany it?
  5. What legal gateway would be required domestically to formalise the ad hoc information exchange between the two banks into a recurring public-private partnership?

Learning points

  • Rules-based monitoring can systematically miss network-level patterns that only become visible once accounts are analysed jointly rather than in isolation.
  • Machine-learning alert scoring can entrench, rather than correct, historical under-investigation of specific sectors or customer segments.
  • Entity resolution using cross-source data (registry records plus KYC onboarding data) is often the single technique that converts isolated suspicion into a mapped network.
  • Two institutions independently holding corroborating intelligence without a sharing mechanism represents a structural, not simply operational, failure of the AML system.

Where the field disagrees

Machine learning in FIUs: fewer false positives, or new blind spots?

Supervised models learn from historical STR outcomes, so they reproduce the typologies analysts already knew and can be blind to novel structures by construction. Explainability requirements in several jurisdictions further constrain what may be deployed. The efficiency gains are real; treat the coverage claims with more caution than vendors invite.

Lecturer's note · not examinable, but argue it in your essay

Assessment

Module quiz

10 multiple-choice questions. Pass at 70%. Scores are saved to your dashboard.

Begin quiz →

Written work

Essay prompts

  • Q1Argue whether the shift from rules-based to machine-learning transaction monitoring represents a net gain or a net governance liability for under-resourced FIUs in the ESAAMLG region.
  • Q2Assess whether privacy-enhancing technologies can genuinely reconcile the analytical benefits of cross-institution data pooling with POPIA- and GDPR-style data-protection obligations, or whether the tension is irreducible.
  • Q3Defend or challenge the proposition that FIU effectiveness should be measured primarily by dissemination quality rather than STR/SAR volume received.
  • Q4Evaluate whether public-private partnerships modelled on JMLIT are likely to entrench, rather than reduce, the structural advantage of the largest financial institutions in shaping national AML intelligence priorities.
Submit essay →

Assignment

"Produce an 1,800–2,200 word financial intelligence case memorandum built around a hypothetical or anonymised composite network of at least eight linked entities, in which you must: construct and describe an entity-resolution methodology for the network; present a network diagram (described in prose or as an appended sketch) with at least one centrality measure calculated and interpreted; identify at least two transaction-monitoring alerts that a rules engine and a machine-learning scoring layer would likely treat differently, explaining why, and conclude with a one-page dissemination-ready intelligence summary addressed to a hypothetical prosecuting authority, explicitly stating remaining intelligence gaps and the further investigative powers required to close them."