Suspicion, and the threshold that is lower than people think
The reporting obligation in most regimes is triggered by knowledge or suspicion, and in many by reasonable grounds to suspect. That last formulation is objective: it does not matter that the individual did not personally suspect, if the facts were such that a reasonable person in that position would have.
Suspicion is a low bar. It is more than speculation and considerably less than proof. It does not require evidence, a completed investigation, or an identified predicate offence. The common failure is the opposite belief: teams that delay reporting while they build a case, or that close a matter because they could not establish what the underlying crime was.
The practical consequence is that reporting is not an accusation and should not be treated internally as one. It is a disclosure of information to a financial intelligence unit, which has powers, data and context the operator does not.
The mechanics
The nominated officer, variously titled money laundering reporting officer or equivalent, is the individual to whom internal reports are made and who decides whether to make an external report. The role is usually a legal requirement, usually requires regulatory approval, and carries personal exposure. It must sit at a level with authority to act, must have unrestricted access to information, and must be able to decide without commercial clearance.
Internal reporting is how a member of staff discharges their own obligation. Any employee with knowledge or suspicion reports internally to the nominated officer. The internal report protects the individual whether or not an external report follows, which is why the route must be easy, documented and free of any sense that raising something is a nuisance.
External reporting goes from the nominated officer to the financial intelligence unit, in the prescribed form and timeframe. Quality matters: a report that states the facts, the pattern observed, what the operator did and what it concluded is actionable; a report consisting of a transaction dump is not.
Consent and defence regimes. Several jurisdictions provide a mechanism by which an operator can seek a defence before dealing with funds it suspects are criminal property. Where such a regime exists, the sequencing is critical, because acting on the funds first can commit the offence the report was about.
Tipping off prohibits disclosing that a report has been made or that an investigation is contemplated where it might prejudice matters. This shapes customer communication, internal communication and the wording of account restriction messages, and staff need a prepared form of words rather than improvisation.
Records
Record-keeping obligations are unglamorous and are the thing most often found deficient, because a control you cannot evidence is a control you did not have.
The scope typically covers identification and verification evidence, due diligence assessments and their conclusions, transaction records, the reasoning behind decisions including decisions not to report, internal and external reports, training records, and the risk assessment and its revisions. Retention periods are set by jurisdiction and are commonly five years from the end of the relationship or the transaction, but the period is one of the details to check rather than recall.
Two qualities separate a usable record from a compliant-looking one.
It records the conclusion and the reasoning, not only the artefact. "Bank statement obtained" is an artefact. "Bank statement shows salary of X, deposits over the period were Y, the ratio is consistent with the declared position, no further action, review at Z" is a record.
It is retrievable. A supervisor asking for every enhanced due diligence file from a given period, or the full history on one customer, expects it within days. Firms that store the evidence across four systems with no case reference discover this the hard way.
Governance
The arrangements that make the framework operate are the same shape as in any risk discipline, and the failures are the same.
Board accountability. A named individual at board level is responsible, receives information capable of supporting a decision, and can stop something. Reporting that consists of alert counts and report volumes describes activity; reporting that shows where the framework is failing, what the overdue review population is, what the closure quality sampling found, and what the financial crime consequences are of the products and markets being added, supports a decision.
Independence of the second line. The nominated officer and the financial crime function must be able to restrict or exit a relationship without the agreement of the person whose revenue it is. Where they cannot, every individual decision will look reasonable and the aggregate will be a customer processed for years.
Three lines, actually staffed. The business owns the risks it creates, which includes payments, VIP and B2B partnerships. The second line sets policy and challenges. Internal audit tests both, independently, on a defined cycle, reporting to the audit committee.
Training that is role-specific. Generic annual e-learning satisfies a box and changes nothing. A payments analyst, a VIP manager and a customer support agent encounter different typologies and need different training, and the people most likely to see the first indicator are usually the most junior.
Independent testing. Most regimes require an independent audit of the framework, proportionate to size. The value is entirely in its independence: an audit conducted by the function it examines is a self-assessment with a different cover page.
Why enforcement keeps finding the same things
Published financial crime enforcement in this sector is repetitive, and the repetition is the lesson.
Source of funds requested and not assessed. Documents on file, no conclusion, activity continued. The commonest finding of all.
Thresholds inherited, not derived. Triggers nobody could justify, frequently set high enough that the largest customers never crossed them.
The customer risk rating that did nothing. Calculated at onboarding, stored, never used to change a threshold, a review interval or an approval.
Alerts closed without assessment. Volume beyond the team's capacity, closure rates reported upward as evidence of performance.
Commercial override. The most valuable customers subject to less scrutiny rather than more, with escalations resolved in favour of the relationship.
Third-party deposits accepted. A control failure that requires no sophistication to prevent and appears repeatedly.
Reviews overdue. A periodic review programme with a backlog is a documented failure to operate a stated control.
Group brands not joined. One person, several accounts across the operator's own brands, each below every threshold.
Read any published notice against that list and most of it will be there. The uncomfortable implication is that these are not hard problems. They are problems of authority, capacity and incentive, and they persist because the fix costs revenue in the short term.
What good looks like
A framework worth defending has a small number of observable properties.
The risk assessment is current, the reasoning is written down, and any control can be traced back to a risk in it. Thresholds have documented rationales produced before their commercial impact was known. Customer risk ratings change something concrete. Alert volume is matched to review capacity and the mismatch, where it exists, is acknowledged and being addressed. Closure quality is sampled and the result is reported. Source of funds files contain conclusions. Sanctions screening has been tested with seeded near-misses. B2B partners and affiliates are screened. Reviews are on time. The nominated officer has exited a relationship in the last year against commercial preference, and the board knows about it.
None of that is exotic. All of it is checkable in an afternoon, which is precisely how a supervisor will approach it.