{
  "moduleCode": "IFF719",
  "title": "Financial intelligence analytics and typology detection",
  "levelCode": "L-04",
  "levelName": "Mastery",
  "nqf": 7,
  "credits": 15,
  "notionalHours": 150,
  "lessons": [
    {
      "id": "l4m5-1",
      "title": "From STRs/SARs to intelligence: report quality, triage and disseminable product",
      "readingMinutes": 30,
      "objectives": [
        "Distinguish a raw suspicious transaction report from a disseminable intelligence product.",
        "Assess the causes and consequences of defensive filing on FIU triage capacity.",
        "Reconstruct a triage scoring model incorporating typology, reliability and cross-match criteria.",
        "Evaluate the FIC's post-Zondo reform agenda against Egmont Group effectiveness principles."
      ],
      "keyTakeaways": [
        "An STR is raw material, not intelligence, and the analytical value is added through triage, enrichment and disseminable packaging.",
        "Rising STR volume is not, on its own, evidence of a healthier AML system and can mask defensive over-filing.",
        "Egmont Group's secure exchange network allows domestic triage to be enriched with foreign-held intelligence before analyst hours are committed."
      ],
      "keyTerms": [
        {
          "term": "Suspicious transaction/activity report (STR/SAR)",
          "definition": "A mandatory filing by an accountable institution flagging a transaction or activity inconsistent with expected customer behaviour or risk profile."
        },
        {
          "term": "Defensive filing",
          "definition": "Reporting driven by fear of regulatory sanction rather than genuine risk assessment, inflating volume while diluting evidentiary value."
        },
        {
          "term": "Triage model",
          "definition": "A scoring methodology that prioritises incoming reports for analyst attention based on reliability, typology match and existing intelligence links."
        },
        {
          "term": "Egmont Group",
          "definition": "The global network of financial intelligence units enabling secure, principle-based exchange of financial intelligence between member states."
        },
        {
          "term": "Disseminable intelligence product",
          "definition": "The FIU's finished analytical output, chronology, entity mapping, typology classification and identified gaps; provided to law enforcement or prosecutors."
        }
      ]
    },
    {
      "id": "l4m5-2",
      "title": "Network and link analysis: entity resolution, graph construction and analytical fallacies",
      "readingMinutes": 31,
      "objectives": [
        "Explain entity resolution and distinguish false-merge from false-split error types.",
        "Reconstruct a transaction-and-registry network graph and apply degree, betweenness and eigenvector centrality.",
        "Identify the common analytical fallacies of hub-node contamination and centrality-as-guilt reasoning.",
        "Assess the evidentiary limits of network diagrams in investigative versus prosecutorial contexts."
      ],
      "keyTakeaways": [
        "Network analysis fails far more often on faulty entity resolution than on the sophistication of its centrality measures.",
        "Betweenness centrality frequently identifies professional enablers because their structural function is to connect otherwise unrelated clusters.",
        "Common infrastructure nodes such as utilities or payment aggregators must be pruned to avoid false network contamination.",
        "A network diagram is a hypothesis-generation tool whose edges must trace to independently verifiable documents before use as evidence."
      ],
      "keyTerms": [
        {
          "term": "Entity resolution",
          "definition": "The process of determining when records from different sources refer to the same real-world person or legal entity, using probabilistic or deterministic matching."
        },
        {
          "term": "False merge/false split",
          "definition": "Entity-resolution errors that either wrongly combine distinct entities or wrongly separate a single entity into apparent duplicates."
        },
        {
          "term": "Degree centrality",
          "definition": "A graph measure counting an entity's direct connections, useful for identifying transactional hub accounts."
        },
        {
          "term": "Betweenness centrality",
          "definition": "A graph measure identifying entities on the shortest path between otherwise unconnected clusters, often flagging professional enablers."
        },
        {
          "term": "Hub-node contamination",
          "definition": "The analytical fallacy of treating shared use of common infrastructure (utilities, payment aggregators) as evidence of a substantive relationship."
        }
      ]
    },
    {
      "id": "l4m5-3",
      "title": "Rules, models and machine learning in transaction monitoring",
      "readingMinutes": 32,
      "objectives": [
        "Distinguish rules-based, statistical and machine-learning approaches to transaction monitoring.",
        "Assess the false-positive economics driving scenario-tuning decisions in resource-constrained compliance functions.",
        "Reconstruct the core elements of a model risk governance framework applicable to AML monitoring models.",
        "Evaluate explainability and fairness obligations arising under POPIA and GDPR-equivalent automated-decision provisions."
      ],
      "keyTakeaways": [
        "The overwhelming majority of untuned rules-engine alerts resolve as false positives, making documented scenario tuning an operational necessity.",
        "Machine-learning monitoring models inherit and can entrench historical labelling biases unless independently validated.",
        "Model risk governance for AML models increasingly mirrors Basel-style credit-risk model governance in its validation and ownership requirements.",
        "POPIA and GDPR-equivalent regimes require meaningful explanation and human review wherever automated scoring materially affects a customer."
      ],
      "keyTerms": [
        {
          "term": "Scenario tuning",
          "definition": "Evidence-based adjustment of transaction-monitoring rule thresholds and logic using historical alert-disposition data, documented with rationale."
        },
        {
          "term": "False-positive economics",
          "definition": "The operational cost trade-off between conservative thresholds generating high manual-review volume and tighter thresholds risking missed true positives."
        },
        {
          "term": "Model risk governance",
          "definition": "A framework requiring independent validation, ongoing monitoring, documented inventory and accountable ownership for analytical models used in compliance."
        },
        {
          "term": "Explainability",
          "definition": "The capacity to articulate, at least at a high level, why a model produced a given output, particularly where the output materially affects a customer."
        },
        {
          "term": "Automated decision-making fairness obligation",
          "definition": "Legal constraints, under instruments such as POPIA or GDPR, requiring meaningful information and human review for automated decisions with significant effect on individuals."
        }
      ]
    },
    {
      "id": "l4m5-4",
      "title": "Data sharing, privacy and public-private partnerships",
      "readingMinutes": 30,
      "objectives": [
        "Explain the legal basis and function of private-sector information-sharing gateways such as JMLIT.",
        "Assess the effectiveness and institutional asymmetries of public-private partnerships in financial intelligence.",
        "Distinguish the constraints POPIA and GDPR place on domestic and cross-border AML data use.",
        "Evaluate the potential of privacy-enhancing technologies to reconcile data pooling with data-protection obligations."
      ],
      "keyTakeaways": [
        "A launderer's technique of spreading activity across institutions specifically exploits the structural partiality of any single institution's transactional view.",
        "JMLIT's statutory gateway under the UK's Criminal Finances Act 2017 has become the international template for private-sector-law enforcement information sharing.",
        "POPIA and GDPR impose purpose-limitation and data-minimisation constraints on domestic analytical use, not only cross-border transfer."
      ],
      "keyTerms": [
        {
          "term": "Information-sharing gateway",
          "definition": "A statutory legal basis permitting reporting institutions to exchange customer or typology information that ordinary confidentiality or data-protection law would otherwise restrict."
        },
        {
          "term": "Public-private partnership (AML)",
          "definition": "A structured, ongoing collaboration embedding law enforcement, FIU and private-sector analysts on thematic financial-crime operations, exemplified by the UK's JMLIT."
        },
        {
          "term": "Data minimisation / purpose limitation",
          "definition": "POPIA and GDPR principles requiring that only data necessary for a defined purpose be processed, constraining even domestic analytical use of customer data."
        },
        {
          "term": "Privacy-enhancing technology (PET)",
          "definition": "Technical methods such as secure multi-party computation, federated learning or homomorphic encryption enabling joint analysis without exposing raw underlying data."
        },
        {
          "term": "Data pooling",
          "definition": "The collective analysis of data contributed by multiple institutions or jurisdictions, requiring a clear legal basis and embedded proportionality safeguards under FATF guidance."
        }
      ]
    }
  ],
  "caseStudy": {
    "title": "The shell-hub remittance network",
    "jurisdiction": "Composite, Southern African corridor",
    "summary": "A composite investigation traces how a professional company-formation agent used a cluster of shelf companies, a regional remittance platform and a co-opted junior compliance analyst to launder proceeds of tax-refund fraud, illustrating how financial intelligence analytics — from STR triage through network mapping to model-flagged alerts — eventually converged on the enabler rather than the nominal account holders.",
    "facts": [
      "Six shelf companies, each registered by the same company-formation agent within an eleven-month window, shared a single registered address and two overlapping director names drawn from a small pool of nominees.",
      "Transaction-monitoring rules initially flagged only isolated cash-structuring alerts on individual company accounts, each closed as a false positive by an overstretched compliance team.",
      "A machine-learning alert-scoring layer, deployed eighteen months into the scheme, deprioritised the network because historical training labels had systematically under-flagged the sector the shell companies claimed to operate in.",
      "Entity resolution work by the FIU, cross-matching company registry data against remittance-platform KYC records, revealed that four of the six 'independent' companies shared an identical registered mobile number used at onboarding.",
      "Betweenness-centrality analysis of the reconstructed transaction network identified the company-formation agent's personal account as the sole node connecting all six shell companies to a single offshore remittance corridor.",
      "A public-private information-sharing exchange between two banks, conducted under a domestic gateway modelled on JMLIT principles, confirmed that both institutions held STRs referencing the same registered address independently, neither aware of the other's filing."
    ],
    "investigativeQuestions": [
      "At which stage of the STR triage process should the shared registered address have been surfaced, and what data source would have made that link visible earlier?",
      "How did the machine-learning model's inherited historical bias contribute to the network evading detection for eighteen months, and what governance step would have caught this?",
      "What entity-resolution technique would you apply to confirm or refute that the six companies constitute a single beneficial-ownership network?",
      "What evidentiary weight, if any, should the betweenness-centrality finding carry in a prosecutorial brief, and what underlying documents would need to accompany it?",
      "What legal gateway would be required domestically to formalise the ad hoc information exchange between the two banks into a recurring public-private partnership?"
    ],
    "learningPoints": [
      "Rules-based monitoring can systematically miss network-level patterns that only become visible once accounts are analysed jointly rather than in isolation.",
      "Machine-learning alert scoring can entrench, rather than correct, historical under-investigation of specific sectors or customer segments.",
      "Entity resolution using cross-source data (registry records plus KYC onboarding data) is often the single technique that converts isolated suspicion into a mapped network.",
      "Two institutions independently holding corroborating intelligence without a sharing mechanism represents a structural, not simply operational, failure of the AML system."
    ]
  },
  "quiz": [
    {
      "number": 1,
      "type": "multiple_choice",
      "points": 1,
      "question": "Under FATF guidance and Egmont Group practice, why is a rising STR/SAR volume not, on its own, evidence of a healthier AML system?",
      "options": [
        "Because FIUs are legally capped in how many reports they may receive annually",
        "Because rising volume can reflect defensive filing that dilutes analytical value rather than genuine risk-based reporting",
        "Because STR volume is confidential and cannot be measured by regulators",
        "Because only cross-border reports are counted in FATF effectiveness assessments"
      ],
      "correctIndex": 1,
      "correctAnswer": "Because rising volume can reflect defensive filing that dilutes analytical value rather than genuine risk-based reporting",
      "rationale": "Defensive filing inflates volume while lowering average report quality, which is why FATF effectiveness assessments look at dissemination outcomes rather than raw filing counts."
    },
    {
      "number": 2,
      "type": "multiple_choice",
      "points": 1,
      "question": "What is the primary evidentiary risk of presenting a network diagram directly to a court without further substantiation?",
      "options": [
        "Network diagrams are inadmissible in every jurisdiction",
        "The diagram is a hypothesis-generation tool and its edges must be traceable to independently verifiable documents",
        "Courts require diagrams to be produced only by machine-learning software",
        "Network diagrams cannot legally include natural persons"
      ],
      "correctIndex": 1,
      "correctAnswer": "The diagram is a hypothesis-generation tool and its edges must be traceable to independently verifiable documents",
      "rationale": "A network diagram visualises hypothesised relationships; each depicted edge must be grounded in underlying documentary or testimonial evidence before it carries probative weight."
    },
    {
      "number": 3,
      "type": "multiple_choice",
      "points": 1,
      "question": "A false merge in entity resolution results in which outcome?",
      "options": [
        "Two distinct real-world entities are wrongly treated as a single entity, contaminating the network with unrelated transactions",
        "A single entity is split into two apparently unrelated records",
        "A transaction is duplicated in the ledger",
        "A beneficial-ownership register entry is deleted"
      ],
      "correctIndex": 0,
      "correctAnswer": "Two distinct real-world entities are wrongly treated as a single entity, contaminating the network with unrelated transactions",
      "rationale": "A false merge wrongly combines two distinct entities, introducing unrelated transactional data into the network and generating false positives."
    },
    {
      "number": 4,
      "type": "multiple_choice",
      "points": 1,
      "question": "Why is betweenness centrality particularly useful for identifying professional enablers in a laundering network?",
      "options": [
        "It measures the total transaction value processed by an entity",
        "It identifies entities positioned on the shortest path between otherwise unconnected clusters, matching the structural role enablers play",
        "It only applies to entities with the highest transaction frequency",
        "It automatically confirms criminal intent"
      ],
      "correctIndex": 1,
      "correctAnswer": "It identifies entities positioned on the shortest path between otherwise unconnected clusters, matching the structural role enablers play",
      "rationale": "Professional enablers often exist structurally to connect clusters that would otherwise have no reason to interact, which is exactly what betweenness centrality measures."
    },
    {
      "number": 5,
      "type": "multiple_choice",
      "points": 1,
      "question": "What governance failure allowed the machine-learning alert-scoring layer in the case study to deprioritise the shell-company network?",
      "options": [
        "The model was never validated and inherited historical under-investigation bias from its training labels",
        "The model used only rules-based logic",
        "The model was deployed without any regulatory approval process anywhere in the world",
        "The model exclusively monitored cash transactions"
      ],
      "correctIndex": 0,
      "correctAnswer": "The model was never validated and inherited historical under-investigation bias from its training labels",
      "rationale": "Models trained on historical alert-disposition labels inherit whatever blind spots existed in that history; independent validation is designed to catch precisely this failure mode."
    },
    {
      "number": 6,
      "type": "multiple_choice",
      "points": 1,
      "question": "Under POPIA and GDPR-equivalent frameworks, what obligation typically arises when an automated model materially affects a customer, such as through an account restriction?",
      "options": [
        "No obligation arises if the model is proprietary",
        "The institution must provide meaningful information about the logic involved and generally ensure human review of the decision",
        "The customer must be charged a fee for an explanation",
        "The model's source code must be published publicly"
      ],
      "correctIndex": 1,
      "correctAnswer": "The institution must provide meaningful information about the logic involved and generally ensure human review of the decision",
      "rationale": "Both POPIA and GDPR-equivalent regimes require meaningful information about automated-decision logic and, typically, a right to human review where the decision has significant effect."
    },
    {
      "number": 7,
      "type": "multiple_choice",
      "points": 1,
      "question": "What was the primary legal innovation of the UK's Joint Money Laundering Intelligence Taskforce (JMLIT)?",
      "options": [
        "It eliminated the requirement to file STRs entirely",
        "It created a statutory gateway allowing banks, law enforcement and the FIU to share information under protection from ordinary confidentiality constraints",
        "It centralised all UK bank data into a single government-owned database",
        "It replaced FATF Recommendation 16 with a UK-specific standard"
      ],
      "correctIndex": 1,
      "correctAnswer": "It created a statutory gateway allowing banks, law enforcement and the FIU to share information under protection from ordinary confidentiality constraints",
      "rationale": "JMLIT, enabled by the Criminal Finances Act 2017, provided a statutory basis for cross-institutional and law-enforcement information sharing that would otherwise breach confidentiality or data-protection law."
    },
    {
      "number": 8,
      "type": "multiple_choice",
      "points": 1,
      "question": "Why might secure multi-party computation be preferred over full data pooling for cross-institution AML analytics?",
      "options": [
        "It is always faster than any other computational method",
        "It allows a joint result to be computed without any institution disclosing its raw underlying customer data",
        "It removes the need for any legal basis to process personal data",
        "It is required under all FATF Recommendations"
      ],
      "correctIndex": 1,
      "correctAnswer": "It allows a joint result to be computed without any institution disclosing its raw underlying customer data",
      "rationale": "Secure multi-party computation enables institutions to jointly compute an analytical result while each retains control of its own raw data, reducing the privacy trade-off of centralised pooling."
    },
    {
      "number": 9,
      "type": "multiple_choice",
      "points": 1,
      "question": "In the false-positive economics of transaction monitoring, what is the central operational trade-off compliance functions must manage?",
      "options": [
        "Between hiring more analysts and closing the compliance function entirely",
        "Between tightening thresholds to reduce false positives (risking missed true positives) and leaving thresholds conservative (accepting high manual-review cost)",
        "Between using only cash-based rules and only wire-based rules",
        "Between reporting to the FIU and reporting to the central bank exclusively"
      ],
      "correctIndex": 1,
      "correctAnswer": "Between tightening thresholds to reduce false positives (risking missed true positives) and leaving thresholds conservative (accepting high manual-review cost)",
      "rationale": "Scenario tuning requires an explicit, documented trade-off between reducing analyst workload from false positives and the risk of introducing false negatives."
    },
    {
      "number": 10,
      "type": "multiple_choice",
      "points": 1,
      "question": "What structural failure did the two banks' independent STR filings referencing the same registered address illustrate in the case study?",
      "options": [
        "A failure of individual analyst competence at each bank",
        "A structural failure of the AML system to enable information sharing between institutions holding corroborating intelligence",
        "A failure of the company-formation agent to conceal the address adequately",
        "A failure of the remittance platform's currency conversion process"
      ],
      "correctIndex": 1,
      "correctAnswer": "A structural failure of the AML system to enable information sharing between institutions holding corroborating intelligence",
      "rationale": "Both banks independently held relevant intelligence; the absence of a sharing mechanism, not analyst error, is what allowed the corroborating link to go unrecognised for so long."
    }
  ],
  "essayPrompts": [
    {
      "number": 1,
      "prompt": "Argue whether the shift from rules-based to machine-learning transaction monitoring represents a net gain or a net governance liability for under-resourced FIUs in the ESAAMLG region.",
      "wordGuide": "1200-1500",
      "weightingPercent": 30
    },
    {
      "number": 2,
      "prompt": "Assess whether privacy-enhancing technologies can genuinely reconcile the analytical benefits of cross-institution data pooling with POPIA- and GDPR-style data-protection obligations, or whether the tension is irreducible.",
      "wordGuide": "1200-1500",
      "weightingPercent": 30
    },
    {
      "number": 3,
      "prompt": "Defend or challenge the proposition that FIU effectiveness should be measured primarily by dissemination quality rather than STR/SAR volume received.",
      "wordGuide": "1200-1500",
      "weightingPercent": 30
    },
    {
      "number": 4,
      "prompt": "Evaluate whether public-private partnerships modelled on JMLIT are likely to entrench, rather than reduce, the structural advantage of the largest financial institutions in shaping national AML intelligence priorities.",
      "wordGuide": "1200-1500",
      "weightingPercent": 30
    }
  ],
  "assignment": {
    "prompt": "Produce an 1,800–2,200 word financial intelligence case memorandum built around a hypothetical or anonymised composite network of at least eight linked entities, in which you must: construct and describe an entity-resolution methodology for the network; present a network diagram (described in prose or as an appended sketch) with at least one centrality measure calculated and interpreted; identify at least two transaction-monitoring alerts that a rules engine and a machine-learning scoring layer would likely treat differently, explaining why, and conclude with a one-page dissemination-ready intelligence summary addressed to a hypothetical prosecuting authority, explicitly stating remaining intelligence gaps and the further investigative powers required to close them.",
    "wordGuide": "2000-2500",
    "weightingPercent": 35
  },
  "rubric": {
    "criteria": [
      {
        "criterion": "Legal and regulatory accuracy",
        "weight": 25
      },
      {
        "criterion": "Typology and mechanism analysis",
        "weight": 25
      },
      {
        "criterion": "Evidence and application to the facts",
        "weight": 20
      },
      {
        "criterion": "Investigative or policy judgement",
        "weight": 15
      },
      {
        "criterion": "Structure, referencing and professional expression",
        "weight": 15
      }
    ],
    "bands": [
      {
        "band": "Distinction",
        "range": "75-100"
      },
      {
        "band": "Meritorious",
        "range": "65-74"
      },
      {
        "band": "Competent",
        "range": "50-64"
      },
      {
        "band": "Marginal",
        "range": "40-49"
      },
      {
        "band": "Not competent",
        "range": "0-39"
      }
    ],
    "subMinimum": "40% in the assignment component"
  },
  "exportedAt": "2026-08-14T13:05:13.196Z"
}
