top of page

Where AML and Fraud Converge: Protecting Vulnerable Customers in a Real-Time World

  • Writer: FinScan
    FinScan
  • 2 days ago
  • 8 min read

Updated: 1 day ago

In From Data to Decisions: Protecting the Vulnerable in a Real-Time World, speaker, author and recovering banker Leda Glyptis moderated a discussion between Becki LaPorte, Principal of AML Strategy and Innovation at FinScan, Victoria Martin, Head of Legal, Risk and Compliance at Bourn, and Renata Galvão, Partner Manager at LSEG Risk Intelligence.







Money laundering and fraud are often managed by separate teams, funded from separate budgets, and reported against separate frameworks. Conversely, many criminal enterprises are one continuous operation. An identity stolen from a child becomes a synthetic profile that clears onboarding, an account that receives scam proceeds, and a mule in a laundering network. Institutions that examine data in isolation see unrelated, unremarkable events.


Below are the key takeaways from the panel conversation.


More Regulation Does Not Automatically Mean More Protection


Becki LaPorte opened with a statement that questioned how the industry usually talks about rulemaking: Additional regulation, written without reference to criminal behavior, can widen the gap rather than close it.For example, in the case of beneficial ownership, disclosure is a global expectation. Firms with legitimate ownership structures meet it. Criminals do not. So, they supply a name that is not the real one.


Ultimately, the unintended consequence is that the regulation adds work for the customers least likely to cause a problem and can create confidence about the rest that the underlying data does not support. An ownership record is only as reliable as the incentive of the party filing it, which is why verification against independent sources matters more than collection.


Another example LaPorte gave is operational. Regulated institutions need approvals, notice periods, and documented sign-off before they can change a control. A criminal group has an idea in the morning and is running it that afternoon. Differences between jurisdictions widen the gap further, because a criminal operation working across borders must only find the weakest requirement.



Paper Compliance No Longer Satisfies the Regulator


Martin highlighted two recent FCA enforcement actions against UK fintechs: Starling Bank, fined £28.96 million in 2024, and Monzo, fined £21.1 million highlight the move from check-the-box compliance to effectiveness. In both cases the firms had policies, procedures, and a control framework that presented well on paper. Both had also agreed to voluntary requirements and then breached them.


What the FCA found in each case was a control environment that stayed roughly the same size while the customer base multiplied. Starling grew from around 43,000 customers in 2017 to 3.6 million in 2023.


"Growth is no longer a mitigating factor. Your controls have to grow with the business." Victoria Martin

Of note in Starling’s case was the failure of the controls themselves. The bank's automated sanctions screening had been running against only a fraction of the full sanctions list since 2017, and the gap was found by an internal review. In other words, screening configuration that is wrong produces clean results indefinitely. Alert volumes look healthy, match rates look normal, and nothing in the reporting reveals that the list being searched is incomplete.


In Monzo’s case, accounts were opened against implausible addresses, and beneficial owners were not consistently verified on business accounts.



Technology is Only as Good as the Data Behind It


Investment in AI is real and useful, but it does not resolve financial crime on its own because a model can only work with the data it is given. Party data that is incomplete, duplicated, or out of date produces decisions of the same quality, and no amount of sophistication in the detection layer compensates for a name, date of birth, or address that was wrong when it entered the system.


Before selecting a system, firms need to establish which crime they are trying to stop and which data describes it. Tools bought without that step tend to be pointed at the activity that is easiest to measure rather than the activity causing the most harm.

 


Criminals Move Toward the Weakest Control, and the Risk Rating Is Often Part of It


Galvão brought a criminological frame to the discussion, drawing on Gary Becker's work on rational choice. Offenders weigh reward, risk, opportunity, and consequence, and they move toward whichever control is weakest relative to the return available. In financial services, onboarding is frequently that control, because it is the point where an institution knows the least about the person and is under the most commercial pressure to approve quickly.


Martin noted that digital onboarding journeys at fintechs see fraud rates in the range of 30 to 40 percent, and that criminals study those journeys closely enough to work them systematically.


The profile that attracts the most criminal attention is one where direct deposit arrives on schedule, bills are paid, they take one holiday a year and have no unusual activity. That customer is rated low risk and passes through controls without friction, which is precisely what makes them targets. Romance scams are built around the recently divorced or bereaved who fit this profile exactly.


Connecting these ideas is another common scenario. A customer loses a job, the direct deposit stops, and funds start arriving from accounts associated with a money mule network. At that moment the customer has moved from a fraud victim to a laundering participant, knowingly or otherwise. The risk rating assigned at onboarding no longer describes that person, and nothing in the process forces a re-examination.



Children Are Vulnerable Customers Even Though They Hold No Assets


Panelist Renata Galvão has her own case. At six years old, living in Brazil, her name and national ID number were used to register two companies in the United States. The man who used them had poor credit and an open tax fraud case, which left him unable to register anything himself. The companies failed, he left the country, and the debts and claims from defrauded parties attached to her name.


From the age of 18, her wages were repeatedly blocked by court orders against debt she had no part in creating. She cleared her name at 27, with help from her mother, having handed over years of earnings to settle it.


The detail that matters for AML teams is what those companies were. Two corporate entities were registered to a person who could not have consented, could not have been verified, and did not exist as an adult. Any due diligence performed on those companies would have traced ownership to a real, clean identity with no adverse findings.


"Children don't have assets. What they have is what a criminal is looking for, which is a clean identity." Renata Galvao

One in fifty children, or roughly 1.5 million a year in the United States, are affected by identity theft. Children hold no assets, which is why they fall outside most definitions of a vulnerable customer. What they hold is an identity with no credit history and nobody checking it, often for a decade or more. Social security numbers taken in bulk from breaches are sold on that basis, and they are the raw material for synthetic identities that sit dormant before use.


She founded Child Without Debt in Brazil, which has assisted more than 30,000 children with company registrations and debt attached to their names.


Few onboarding processes test whether the identity presented could plausibly belong to a person of the stated age, or whether it has any history at all. A synthetic profile built on a child's identifier will not fail a sanctions screen, will not generate adverse media, and will not appear in a PEP list. It fails only against the question of whether this person has existed for as long as the application claims.



Vulnerability Is a Condition, Not a Customer Segment


Martin suggested the UK's Consumer Duty as a model worth studying, on the basis that it is principle-based and assessed on customer outcomes rather than on process completion.


For example, vulnerability cannot be treated as a fixed population. Bereavement, illness, job loss, and coercion can affect anyone at any point in their lives, which means a firm cannot identify its vulnerable customers at the design stage and build for them separately. Vulnerability must be a factor of the design of the product itself, with outcomes measured afterward to establish whether it worked.


There is a fine line, though. Customers resent processes that treat them as incapable, and journeys such as power of attorney are frequently at their most difficult at the moment the customer is least able to manage them.



Information Sharing Remains the Largest Structural Gap


Glyptis asked what the answer looks like if it is not more regulation. LaPorte identified the inability of institutions to share information with each other.


Nobody wants organizations sharing customer data unless it is authorized by the customer themselves. But who would have an issue with one institution being able to tell another that an identity presented as an adult has no record of existing more than three years ago? Or that a device has appeared in confirmed cases. Privacy protections have been drawn so tightly that the gatekeepers positioned to see the pattern cannot share it. Cross-border is harder even though financial crime itself does not organize by jurisdiction.


“I'm all about protecting privacy. But we are protecting it so much that we can't protect the customer." Becki LaPorte

Martin added that the same gap exists on the reporting side. Suspicious activity is escalated to the National Crime Agency in the UK, and nothing comes back. The institution that filed the report learns nothing about whether its suspicion was correct, which means the typology it detected cannot be refined and cannot be passed to the firm that will see the same behavior next week.



Small Transactions Can Carry the Greatest Harm


The panel emphasized that detection calibrated to large-value movement misses the typologies that cause the most damage. For example, human trafficking rarely produces large wire transfers. The money moves in amounts that sit below every threshold, through accounts that individually look ordinary. The signal exists in the relationships between accounts rather than in the size of any one payment.


In the case of sextortion of minors, an adult poses as a child, obtains images, and demands payment. The payments generally run $20 to $25 to a peer-to-peer application, repeating over weeks. The financial loss may total a few hundred dollars, which places it far below any threshold worth investigating on a bottom-line basis. The consequence for the child can be fatal.


To bring this point home, Galvão shared the story of a compliance professional who escalated a pattern of payments into a large number of young women's accounts. The relationship was later connected to Jeffrey Epstein, and the institution was eventually held accountable. The signal was visible to someone looking for patterns.


What Next? Operationalizing the Information


Several practical themes ran through the session.


Test whether controls perform, not whether they exist. 

The enforcement actions discussed involved firms with complete documentation. What failed was configuration, coverage, and capacity relative to volume. Sanctions screening in particular can produce a clean output for years while matching against an incomplete list, and the reporting will not show it.

Screening, risk scoring, and customer due diligence all inherit the condition of the party data behind them. Duplicate records, missing identifiers, and stale addresses limit performance regardless of how sophisticated the detection layer is.

Beneficial ownership declarations are supplied by the party with the strongest interest in their being wrong. Independent verification is what separates a UBO record from a filing.

A synthetic profile built on a stolen child identifier will clear a sanctions screen and an adverse media search. It fails only against the question of whether the identity has a history consistent with the age claimed.

A rating assigned at onboarding describes a customer at one moment. The panel gave several examples of customers whose exposure shifted sharply, including from victim to mule, while their rating stayed where it was.

Trafficking, sextortion, and child identity theft generate low transaction values and severe consequences. Controls calibrated only to financial exposure will not surface them.



bottom of page