Skip to content
iGaming Times

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Lesson 7 of 7 · 17 min

Reporting, Records and Why Enforcement Repeats

The suspicion threshold is lower than people think. The nominated officer, the record that defends you, and the short list of failures published notices keep finding.

In this lesson

  • Apply the suspicion threshold correctly, including the objective reasonable-grounds formulation
  • Describe the roles of the nominated officer, internal reporting and external reporting, and the constraints around consent and tipping off
  • Write records that carry the conclusion and the reasoning, not only the artefact
  • Read a published enforcement notice for the structural failure, and audit your own framework against the recurring list

Suspicion, and the threshold that is lower than people think

The reporting obligation in most regimes is triggered by knowledge or suspicion, and in many by reasonable grounds to suspect. That last formulation is objective: it does not matter that the individual did not personally suspect, if the facts were such that a reasonable person in that position would have.

Suspicion is a low bar. It is more than speculation and considerably less than proof. It does not require evidence, a completed investigation, or an identified predicate offence. The common failure is the opposite belief: teams that delay reporting while they build a case, or that close a matter because they could not establish what the underlying crime was.

The practical consequence is that reporting is not an accusation and should not be treated internally as one. It is a disclosure of information to a financial intelligence unit, which has powers, data and context the operator does not.

The mechanics

The nominated officer, variously titled money laundering reporting officer or equivalent, is the individual to whom internal reports are made and who decides whether to make an external report. The role is usually a legal requirement, usually requires regulatory approval, and carries personal exposure. It must sit at a level with authority to act, must have unrestricted access to information, and must be able to decide without commercial clearance.

Internal reporting is how a member of staff discharges their own obligation. Any employee with knowledge or suspicion reports internally to the nominated officer. The internal report protects the individual whether or not an external report follows, which is why the route must be easy, documented and free of any sense that raising something is a nuisance.

External reporting goes from the nominated officer to the financial intelligence unit, in the prescribed form and timeframe. Quality matters: a report that states the facts, the pattern observed, what the operator did and what it concluded is actionable; a report consisting of a transaction dump is not.

Consent and defence regimes. Several jurisdictions provide a mechanism by which an operator can seek a defence before dealing with funds it suspects are criminal property. Where such a regime exists, the sequencing is critical, because acting on the funds first can commit the offence the report was about.

Tipping off prohibits disclosing that a report has been made or that an investigation is contemplated where it might prejudice matters. This shapes customer communication, internal communication and the wording of account restriction messages, and staff need a prepared form of words rather than improvisation.

Records

Record-keeping obligations are unglamorous and are the thing most often found deficient, because a control you cannot evidence is a control you did not have.

The scope typically covers identification and verification evidence, due diligence assessments and their conclusions, transaction records, the reasoning behind decisions including decisions not to report, internal and external reports, training records, and the risk assessment and its revisions. Retention periods are set by jurisdiction and are commonly five years from the end of the relationship or the transaction, but the period is one of the details to check rather than recall.

Two qualities separate a usable record from a compliant-looking one.

It records the conclusion and the reasoning, not only the artefact. "Bank statement obtained" is an artefact. "Bank statement shows salary of X, deposits over the period were Y, the ratio is consistent with the declared position, no further action, review at Z" is a record.

It is retrievable. A supervisor asking for every enhanced due diligence file from a given period, or the full history on one customer, expects it within days. Firms that store the evidence across four systems with no case reference discover this the hard way.

Governance

The arrangements that make the framework operate are the same shape as in any risk discipline, and the failures are the same.

Board accountability. A named individual at board level is responsible, receives information capable of supporting a decision, and can stop something. Reporting that consists of alert counts and report volumes describes activity; reporting that shows where the framework is failing, what the overdue review population is, what the closure quality sampling found, and what the financial crime consequences are of the products and markets being added, supports a decision.

Independence of the second line. The nominated officer and the financial crime function must be able to restrict or exit a relationship without the agreement of the person whose revenue it is. Where they cannot, every individual decision will look reasonable and the aggregate will be a customer processed for years.

Three lines, actually staffed. The business owns the risks it creates, which includes payments, VIP and B2B partnerships. The second line sets policy and challenges. Internal audit tests both, independently, on a defined cycle, reporting to the audit committee.

Training that is role-specific. Generic annual e-learning satisfies a box and changes nothing. A payments analyst, a VIP manager and a customer support agent encounter different typologies and need different training, and the people most likely to see the first indicator are usually the most junior.

Independent testing. Most regimes require an independent audit of the framework, proportionate to size. The value is entirely in its independence: an audit conducted by the function it examines is a self-assessment with a different cover page.

Why enforcement keeps finding the same things

Published financial crime enforcement in this sector is repetitive, and the repetition is the lesson.

Source of funds requested and not assessed. Documents on file, no conclusion, activity continued. The commonest finding of all.

Thresholds inherited, not derived. Triggers nobody could justify, frequently set high enough that the largest customers never crossed them.

The customer risk rating that did nothing. Calculated at onboarding, stored, never used to change a threshold, a review interval or an approval.

Alerts closed without assessment. Volume beyond the team's capacity, closure rates reported upward as evidence of performance.

Commercial override. The most valuable customers subject to less scrutiny rather than more, with escalations resolved in favour of the relationship.

Third-party deposits accepted. A control failure that requires no sophistication to prevent and appears repeatedly.

Reviews overdue. A periodic review programme with a backlog is a documented failure to operate a stated control.

Group brands not joined. One person, several accounts across the operator's own brands, each below every threshold.

Read any published notice against that list and most of it will be there. The uncomfortable implication is that these are not hard problems. They are problems of authority, capacity and incentive, and they persist because the fix costs revenue in the short term.

What good looks like

A framework worth defending has a small number of observable properties.

The risk assessment is current, the reasoning is written down, and any control can be traced back to a risk in it. Thresholds have documented rationales produced before their commercial impact was known. Customer risk ratings change something concrete. Alert volume is matched to review capacity and the mismatch, where it exists, is acknowledged and being addressed. Closure quality is sampled and the result is reported. Source of funds files contain conclusions. Sanctions screening has been tested with seeded near-misses. B2B partners and affiliates are screened. Reviews are on time. The nominated officer has exited a relationship in the last year against commercial preference, and the board knows about it.

None of that is exotic. All of it is checkable in an afternoon, which is precisely how a supervisor will approach it.

Key terms

Reasonable grounds to suspect
An objective test: liability can arise where the facts were such that a reasonable person in that position would have suspected, whether or not the individual actually did.
Nominated officer
The individual who receives internal reports and decides on external reporting. Usually a regulated role carrying personal exposure, and one that must be able to act without commercial clearance.
Internal report
The disclosure by which an employee discharges their own reporting obligation to the nominated officer. Protects the individual regardless of what follows.
Independent testing
An audit of the AML framework by someone outside the function being examined. An audit conducted by the function itself is a self-assessment with a different cover page.
Overdue review population
Customers whose periodic review is past due. One of the first things a supervisor asks to see, because a backlog is a documented failure to operate a stated control.

Key takeaways

  • Suspicion is more than speculation and much less than proof. Delaying a report to build a case is the common failure, and reporting is not an accusation.
  • The nominated officer must be able to decide without commercial clearance, and internal reporting protects the individual employee whether or not an external report follows.
  • A record that names the artefact is not a record. It has to carry the conclusion, the reasoning and the review trigger, and it has to be retrievable within days.
  • Generic annual e-learning changes nothing. The people most likely to see the first indicator are usually the most junior, and they need typology training for their own role.
  • The recurring findings are not hard problems. They persist because fixing them costs revenue in the short term, which is what the governance arrangements exist to override.

Check your understanding

3 questions · answer them all, then check.

  1. 1. A team suspects laundering but cannot establish which predicate offence generated the funds. What should happen?

  2. 2. Which record would actually defend an operator under review?

  3. 3. Which recurring enforcement finding is entirely within an operator’s own control and requires no new technology?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

Reporting, Records and Why Enforcement Repeats - Learning hub | iGaming Times